Data exchange method and device based on Hash time lock, equipment and medium
By combining hash time locks and public key encryption technology with semantic matching and identity verification, the problems of privacy leakage and inefficient matching in data exchange are solved, and secure, accurate data exchange and compliant circulation are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MERCHANTS FINANCE HLDG CO LTD
- Filing Date
- 2025-12-19
- Publication Date
- 2026-04-24
AI Technical Summary
Existing data exchange models suffer from problems such as privacy leaks, inefficient matching, and breaches of trust in transactions, which hinder the compliant flow and value release of data elements. Furthermore, traditional encryption technologies are unable to achieve accurate retrieval and matching.
A data exchange method based on hash time locks is adopted, which generates irreversible hash values through hash functions. Combined with public key encryption and time limit constraints, the security and accuracy of data exchange are ensured. Semantic matching and identity approval processes are used to achieve accurate matching of data supply and demand and compliant circulation.
It improves the security and matching accuracy of data exchange, ensures the atomicity and fairness of the exchange, avoids the risks of data leakage and transaction breach of trust, and realizes the legitimate circulation and value release of data.
Smart Images

Figure CN121923862A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of blockchain technology, and in particular to a data exchange method, apparatus, device, and medium based on hash time locks. Background Technology
[0002] In today's rapidly developing digital economy, data assets have become a core production factor for enterprises, and cross-entity data exchange and sharing have become a key path to promote industrial collaboration and enhance business value. However, current issues such as privacy leaks, inefficient matching, and transaction breaches in the data exchange process severely restrict the compliant circulation and value release of data elements, becoming a core bottleneck for industry development.
[0003] In traditional data exchange models, to achieve supply and demand matching, enterprises often need to expose raw data or core data characteristics, leading to the risk of leakage of trade secrets and user privacy. While some solutions employ simple encryption techniques, encrypted data is difficult to retrieve accurately, failing to achieve effective matching while protecting privacy, creating a "protection equals unusability" dilemma. The inadequacy of accuracy and efficiency in data supply and demand matching is equally prominent. Existing matching methods mostly rely on keyword retrieval or simple tag matching, lacking a deep understanding of the semantic features of the data. As the data scale expands and business scenarios become more complex, matching deviations or omissions are prone to occur. Summary of the Invention
[0004] This invention provides a data exchange method, apparatus, computer equipment, and medium based on hash time locks to solve the problems of low security and poor matching degree of various data exchange methods currently on the market.
[0005] Firstly, a data exchange method based on hash time locks is provided, including: Obtain the first hash value calculated by the first data exchange party based on the preset first random preimage, and send the first hash value to the second data exchange party; Obtain first encrypted data generated by the first data exchange party according to a preset first public key, and obtain second encrypted data generated by the second data exchange party according to a preset second public key; If it is detected that the first data exchange party uploads the first random preimage within a preset first time limit, then calculate the first hash value to be verified of the first random preimage. If the first hash value to be verified is the same as the first hash value, obtain the second hash value calculated by the second data exchange party according to the preset second random preimage, and send the second hash value to the first data exchange party; If it is detected that the second data exchange party uploads a preset second random preimage within a preset second time limit, then the second hash value to be verified of the second random preimage is calculated. If the second hash value to be verified is the same as the second hash value, the first encrypted data is sent to the second data exchange party, and the second encrypted data is sent to the first data exchange party; Obtain first decryption feedback information from the first data exchange party when decrypting the second encrypted data using a preset first private key; obtain second decryption feedback information from the second data exchange party when decrypting the first encrypted data using a preset second private key; and confirm whether the data exchange is complete based on the first decryption feedback information and the second decryption feedback information.
[0006] Secondly, a data exchange device based on a hash time lock is provided, comprising: The hash sending module is used to obtain the first hash value calculated by the first data exchange party based on the preset first random preimage, and send the first hash value to the second data exchange party; The ciphertext acquisition module is used to acquire the first encrypted data generated by the first data exchange party according to the preset first public key, and to acquire the second encrypted data generated by the second data exchange party according to the preset second public key; The hash verification module, if it detects that the first data exchange party uploads the first random preimage within a preset first time limit, calculates the first hash value to be verified of the first random preimage; if the first hash value to be verified is the same as the first hash value, obtains the second hash value calculated by the second data exchange party based on the preset second random preimage, and sends the second hash value to the first data exchange party; if it detects that the second data exchange party uploads the preset second random preimage within a preset second time limit, calculates the second hash value to be verified of the second random preimage. The encrypted exchange module, if the second hash value to be verified is the same as the second hash value, sends the first encrypted data to the second data exchange party and sends the second encrypted data to the first data exchange party; The decryption feedback information module is used to obtain first decryption feedback information of the first data exchange party decrypting the second encrypted data according to a preset first private key, obtain second decryption feedback information of the second data exchange party decrypting the first encrypted data according to a preset second private key, and confirm whether the data exchange is completed based on the first decryption feedback information and the second decryption feedback information.
[0007] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described data exchange method based on hash time lock.
[0008] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the above-described data exchange method based on a hash time lock.
[0009] In the aforementioned data exchange method, apparatus, computer equipment, and storage medium based on hash time locks, the first hash value calculated by the first data exchange party based on a preset first random preimage can be obtained and sent to the second data exchange party. Leveraging the irreversibility and uniqueness of the hash function, the exchange commitment of the first data exchange party is locked in advance, ensuring that it cannot tamper with the core agreement related to the preimage. Simultaneously, the first party's explicit exchange intention is conveyed to the second data exchange party, laying the foundation for subsequent identity and commitment verification, ensuring the credibility of the exchange starting point. The first encrypted data generated by the first data exchange party based on a preset first public key and the second encrypted data generated by the second data exchange party based on a preset second public key are obtained, preventing data from being stolen or cracked by unauthorized entities during transmission and storage, thus ensuring data privacy and security. If the first data exchange party is detected uploading the first random preimage within a preset first time limit, the first hash value to be verified of the first random preimage is calculated. Calculating the hash value to be verified provides a basis for subsequent verification of the preimage's authenticity, preventing the first party from submitting a false preimage to interfere with the exchange. If the first hash value to be verified... If the hash value is the same as the first hash value, the second hash value calculated by the second data exchange party based on the preset second random preimage is obtained, and the second hash value is sent to the first data exchange party. If it is detected that the second data exchange party uploads the preset second random preimage within the preset second time limit, the second hash value to be verified of the second random preimage is calculated. If the second hash value to be verified is the same as the second hash value, the first encrypted data is sent to the second data exchange party, and the second encrypted data is sent to the first data exchange party. Encrypted data is bidirectionally distributed only after both preimages pass verification, realizing the atomicity of data exchange and ensuring the fairness and integrity of the exchange. The first decryption feedback information of the first data exchange party decrypting the second encrypted data based on the preset first private key is obtained, and the second decryption feedback information of the second data exchange party decrypting the first encrypted data based on the preset second private key is obtained. The completion of data exchange is confirmed based on the first decryption feedback information and the second decryption feedback information. A closed-loop judgment is formed based on the feedback from both parties to clarify the exchange results and avoid the ambiguous state of "data has been sent but not successfully decrypted", ensuring that the exchange results are traceable and verifiable. This improves the security and matching degree of data exchange. Attached Figure Description
[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a schematic diagram of an application environment for a data exchange method based on a hash time lock according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating a data exchange method based on a hash time lock according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a data exchange device based on a hash time lock according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 5 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation
[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0013] The data exchange method based on hash time lock provided in this invention can be applied to, for example... Figure 1In this application environment, the client communicates with the server via a network. The server, leveraging the client's expertise, achieves multiple beneficial effects by integrating a hash time-lock mechanism, asymmetric encryption technology, natural language processing semantic matching, and identity verification processes. This includes ensuring privacy and security of data transmission and storage through public-key encryption, guaranteeing the atomicity of data exchange through hash value verification and time constraints, and significantly improving the accuracy and efficiency of data supply and demand matching by extracting data digest features and using semantic matching and multi-dimensional filtering strategies, thus overcoming the bias and omission problems of traditional matching models. Simultaneously, identity verification and smart contract on-chain mechanisms ensure the legitimacy of participants and the traceability of processes. Matching and exchange can be completed without exposing the original data, effectively breaking the "protection equals unavailability" dilemma. Ultimately, this comprehensively improves the security, matching accuracy, and compliance of data exchange, promoting the legal circulation and value release of data elements. A preset first random preimage is used. The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will be described in detail below through specific embodiments.
[0014] Please see Figure 2 As shown, Figure 2 A flowchart illustrating a data exchange method based on hash time locks provided in an embodiment of the present invention includes the following steps: S1. Obtain the first hash value calculated by the first data exchange party based on the preset first random preimage, and send the first hash value to the second data exchange party.
[0015] In this embodiment of the invention, the data exchange party refers to an entity (usually an enterprise or other organization) that is willing to share and interact with data in an on-chain data exchange scenario based on hash time locks. It needs to participate in data exchange by uploading data summaries, completing identity verification, and following hash time lock rules. The core is to achieve accurate matching and compliant circulation of data supply and demand while ensuring data privacy and security.
[0016] In detail, the first data exchange party is the party that actively initiates the data exchange request or takes the lead in providing relevant basic information for exchange. For example, Company A, which focuses on collecting operational data of new energy vehicle batteries, has a large amount of core data such as battery charging and discharging efficiency and range degradation. It hopes to obtain driving habit data of new energy vehicle users through data exchange to optimize battery management algorithms. Therefore, Company A actively uploads a data summary containing the data features it can provide, initiates a data exchange request, and generates a first random preimage and a corresponding first hash value. At this time, Company A is the first data exchange party.
[0017] Furthermore, the second data exchange party is another party selected by the system through semantic matching of data digests that meets the requirements of the first data exchange party and possesses the corresponding exchange data. For example, the system searches the digest set of all data exchange parties and finds a company B that operates a new energy vehicle travel platform. Its uploaded data digest contains "driving habits of new energy vehicle users," and after matching with natural language processing technology, its data characteristics highly match the exchange requirements of company A. After screening, company B is confirmed as a qualified exchange partner, and at this time, company B is the second data exchange party.
[0018] In this embodiment of the invention, the preset first random preimage is a preimage randomly generated based on the data to be exchanged by the first data exchange party.
[0019] In detail, the preimage is a combination of randomly generated numbers and letters.
[0020] In this embodiment of the invention, before obtaining the first hash value calculated by the first data exchanger based on a preset first random preimage and sending the first hash value to the second data exchanger, the method further includes: Obtain the data digest uploaded by the first data exchange party to obtain the first data digest; Obtain data digests uploaded by other data exchange partners to obtain a data digest set; Based on the first data digest, a data digest that meets the data exchange requirements is retrieved from the data digest set to obtain a second data digest; The data exchange party corresponding to the second data digest is confirmed to be the second data exchange party.
[0021] In detail, the process of obtaining the data digest uploaded by the first data exchange party, where the first data exchange party is an enterprise willing to provide data exchange, allows other participants to query and understand the data by uploading a data digest representing the data characteristics, while ensuring the privacy and security of the original data.
[0022] In detail, the step of retrieving a data digest that meets the data exchange requirements from the data digest set based on the first data digest to obtain the second data digest is a search conducted within the entire data digest set, using the first data digest provided by the first data exchange party (representing the data it can provide) as a benchmark. The aim is to find a company capable of providing the data required or provided by the first data exchange party. This matching logic can be simple keyword matching or more complex business logic matching.
[0023] In this embodiment of the invention, after the first data exchange party and the second data exchange party confirm the data exchange, they need to sign a data exchange agreement through a smart contract. The agreement includes specific hash time lock rules, data exchange verification timeout, which data will be exchanged (data ID), and the enterprise information of both parties. All information will be stored on the blockchain to form a blockchain.
[0024] In this embodiment of the invention, the step of retrieving a data digest that meets the data exchange requirements from the data digest set based on the first data digest to obtain a second data digest includes: Extract the data exchange demand characteristics from the first data digest; Data features are extracted from each data digest in the data digest set to obtain a data feature set; Semantic matching is performed on the data exchange requirement features and the data feature set to obtain a matching result; A candidate data summary list is obtained from the data summary set based on the matching results; The optimal data summary from the candidate data summary list is obtained according to a pre-set filtering strategy to obtain the second data summary.
[0025] In detail, the extraction of data exchange requirement features from the first data digest is achieved by analyzing the metadata associated with the first data digest (such as textual information like data titles, descriptions, tags, and business domains). Using natural language processing technology, the system extracts key concepts, themes, and intentions from this text to form a structured requirement feature vector, i.e., the data exchange requirement features.
[0026] In detail, data features are extracted from each data summary in the data summary set to obtain a data feature set. The same operation as extracting the data exchange demand features from the first data summary is performed on all other data summaries published by all other enterprises in the data summary set, generating a standardized data feature vector for each exchangeable data.
[0027] In detail, the step of semantically matching the data exchange demand feature and the data feature set to obtain the matching result is to use a natural language processing model to calculate the semantic similarity between the data exchange demand feature and each feature in the data feature set.
[0028] In detail, the step of obtaining a candidate data summary list from the data summary set based on the matching result is achieved by setting a threshold (for example, selecting only data with a similarity higher than 80%), and then filtering out the corresponding data summaries from the data summary set to form a candidate data summary list sorted by matching score.
[0029] In detail, obtaining the optimal data summary from the candidate data summary list according to a pre-set filtering strategy to obtain the second data summary can be achieved by directly selecting the data summary with the highest semantic matching score. Alternatively, it can be a weighted decision that comprehensively considers multiple factors such as the reputation rating of the data exchange party corresponding to each data summary, the latest update time of the data, and the data size.
[0030] S2. Obtain the first encrypted data generated by the first data exchange party according to the preset first public key, and obtain the second encrypted data generated by the second data exchange party according to the preset second public key.
[0031] In this embodiment of the invention, before obtaining the first encrypted data generated by the first data exchange party according to a preset first public key, the method further includes: Obtain the enterprise information of the first data exchange party; Obtain the approval result of the first data exchange party's identity verification based on the enterprise information; When it is determined from the approval result that the first data exchange party has passed the identity approval, the public key and private key of the first data exchange party are generated, and the first public key and the first private key are obtained.
[0032] In detail, the enterprise information typically includes authoritative data that can uniquely identify and confirm the enterprise's legal identity, such as the enterprise name, unified social credit code, registered address, and legal representative.
[0033] In detail, when the first data exchange party is determined to have passed the identity verification based on the approval result, a public key and a private key for the first data exchange party are generated, resulting in a first public key and a first private key. The system only generates a public key and a private key pair for the enterprise when the approval result is "passed". Specifically, the first public key will be made public and recorded on the blockchain as the enterprise's public identity credential in the network, and other enterprises can use this public key to encrypt data to be sent to it; while the first private key is strictly kept secret by the enterprise itself and used to decrypt received ciphertext or perform digital signatures.
[0034] S3. Determine whether the first data exchange party has uploaded the first random preimage within a preset first time limit.
[0035] If it is detected that the first data exchange party has not uploaded the first random preimage within the preset first time limit, then execute S4 to terminate the exchange process.
[0036] If it is detected that the first data exchange party uploads the first random preimage within a preset first time limit, then S5 is executed to calculate the first hash value to be verified for the first random preimage. In this embodiment of the invention, the preset first time limit needs to be set according to specific data exchange requirements.
[0037] In this embodiment of the invention, before calculating the first hash value to be verified of the first random preimage, the method further includes: If it is detected that the first data exchange party has not uploaded the first random preimage within a preset first time limit, a random symmetric key is generated; After encrypting the first encrypted data and the second encrypted data twice using the random symmetric key, the random symmetric key is destroyed.
[0038] In this embodiment of the invention, after encrypting the first encrypted data and the second encrypted data a second time using the random symmetric key, the random symmetric key is destroyed. This ensures that the data is permanently unrecoverable, allowing the data to be stored on the chain in an irreversible encrypted form, thus avoiding the risk of data retention or leakage due to incomplete transactions.
[0039] In this embodiment of the invention, calculating the first hash value to be verified of the first random preimage includes: Encode the preset first random preimage into a byte sequence; The byte sequence is hashed using a predefined hash function to obtain a byte representation in the form of a hash value. The byte representation is converted into a hexadecimal string format to obtain the first hash value to be verified.
[0040] S6. Determine whether the first hash value to be verified is the same as the first hash value. If the first hash value to be verified is different from the first hash value, then return to S4 and terminate the exchange process.
[0041] If the first hash value to be verified is the same as the first hash value, then execute S7, obtain the second hash value calculated by the second data exchange party according to the preset second random preimage, and send the second hash value to the first data exchange party.
[0042] In this embodiment of the invention, once the preimage submitted by the first data exchange party is verified to be correct (i.e., the calculated first hash value to be verified matches the pre-calculated first hash value), it indicates that the first data exchange party has fulfilled its primary commitment, and the exchange process can proceed. At this point, the system automatically obtains the pre-calculated second hash value from the second data exchange party and sends this hash value to the first data exchange party. This is equivalent to formally locking the second data exchange party into the same exchange contract, laying a equitable foundation for the subsequent submission of its preimage by the second data exchange party, thereby ultimately unlocking the data in both directions and completing the data exchange, ensuring the atomicity and fairness of the entire process.
[0043] S8. Determine whether the second data exchange party has uploaded the preset second random preimage within the preset second time limit.
[0044] If it is detected that the second data exchange party has not uploaded the preset second random preimage within the preset second time limit, then return to S4 and terminate the exchange process.
[0045] If it is detected that the second data exchange party uploads a preset second random preimage within a preset second time limit, then execute S9 and calculate the second hash value to be verified for the second random preimage.
[0046] In this embodiment of the invention, the second time limit is a value slightly larger than the preset first time limit, which may be exceeded due to network and contract execution exceeding the unlocking time.
[0047] In this embodiment of the invention, subsequent steps will only be executed when it is detected that both the data exchange party and the second data exchange party have completed the operation of uploading the random preimage within a preset time limit, so as to ensure the integrity and fairness of the exchange and prevent unilateral breach of contract.
[0048] S10. Determine whether the second hash value to be verified is the same as the second hash value.
[0049] If the second hash value to be verified is different from the second hash value, then return to S4 and terminate the exchange process.
[0050] If the second hash value to be verified is the same as the second hash value, then execute S11, send the first encrypted data to the second data exchange party, and send the second encrypted data to the first data exchange party.
[0051] In this embodiment of the invention, when the second hash value to be verified is the same as the second hash value, the first encrypted data is sent to the second data exchange party, and the second encrypted data is sent to the first data exchange party. This forces the second data exchange party to fulfill its commitment and actively participate in the exchange within a specified time to prevent the transaction from stalling. Ultimately, this ensures the atomicity of the data exchange (i.e., either both parties successfully exchange data, or the transaction fails and a security circuit breaker is triggered due to either party's timeout). This completely eliminates the risk that one party has provided data while the other party refuses to fulfill its obligations.
[0052] S12. Obtain first decryption feedback information of the first data exchange party decrypting the second encrypted data according to the preset first private key, obtain second decryption feedback information of the second data exchange party decrypting the first encrypted data according to the preset second private key, and confirm whether the data exchange is completed based on the first decryption feedback information and the second decryption feedback information.
[0053] In this embodiment of the invention, confirming whether data exchange is complete based on the first decryption feedback information and the second decryption feedback information includes: Based on the first decryption feedback information, determine whether the first data exchange party has successfully decrypted the data; If the first data exchange party fails to decrypt, the data exchange is deemed to have failed. If the first data exchanger successfully decrypts the data, then the second data exchanger's success in decryption is determined based on the second decryption feedback information. If the second data exchange party fails to decrypt, the data exchange is deemed to have failed. If the second data exchange party successfully decrypts the data, the data exchange is considered complete.
[0054] As can be seen, in the above scheme, the first data exchange party uploads a data digest representing data characteristics (i.e., the first data digest). The system extracts its data exchange requirement characteristics (generating a structured feature vector based on metadata using natural language processing technology), and performs the same feature extraction on the data digest sets uploaded by other exchange parties. Through semantic similarity calculation, threshold screening, and weighted decision-making (comprehensive reputation, data timeliness, etc.), the system matches the second data digest and the corresponding second data exchange party. After confirmation by both parties, an exchange agreement containing information such as hash time lock rules is signed through a smart contract and uploaded to the blockchain. Subsequently, the identity of the exchange party's enterprise information is verified. After approval, a public key and private key are generated, and both parties generate encrypted data based on their respective public keys. The system first monitors... The process involves checking whether the first exchange party uploads a preset first random preimage within a first time limit. If not, a random symmetric key is generated to re-encrypt the encrypted data between both parties, and then the key is destroyed. If uploaded, the first hash value to be verified of the preimage is calculated. If it matches the first hash value previously sent to the second exchange party, the second hash value of the second exchange party is obtained and sent to the first exchange party. Then, the process monitors whether the second exchange party uploads a preset second random preimage within a second time limit. If the second hash value to be verified matches the second hash value, the encrypted data is sent to the other party in both directions. Finally, based on the feedback results of both parties decrypting with their respective private keys, it is determined whether the data exchange is complete. The entire process ensures data privacy and exchange atomicity through blockchain, asymmetric encryption, and hash time lock mechanisms.
[0055] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0056] In one embodiment, a data exchange device based on a hash time lock is provided, which corresponds one-to-one with the data exchange method based on a hash time lock described in the above embodiments. For example... Figure 3 As shown, the data exchange device based on hash time lock includes a hash sending module 101, a ciphertext acquisition module 102, a hash verification module 103, a ciphertext exchange module 104, and a decryption feedback information module 105. Detailed descriptions of each functional module are as follows: The hash sending module 101 is used to obtain the first hash value calculated by the first data exchange party according to the preset first random preimage, and send the first hash value to the second data exchange party; The ciphertext acquisition module 102 is used to acquire the first encrypted data generated by the first data exchange party according to the preset first public key, and to acquire the second encrypted data generated by the second data exchange party according to the preset second public key; The hash verification module 103, if it detects that the first data exchange party uploads the first random preimage within a preset first time limit, calculates the first hash value to be verified of the first random preimage; if the first hash value to be verified is the same as the first hash value, obtains the second hash value calculated by the second data exchange party based on the preset second random preimage, and sends the second hash value to the first data exchange party; if it detects that the second data exchange party uploads the preset second random preimage within a preset second time limit, calculates the second hash value to be verified of the second random preimage. The encrypted exchange module 104, if the second hash value to be verified is the same as the second hash value, sends the first encrypted data to the second data exchange party and sends the second encrypted data to the first data exchange party; The decryption feedback information module 105 is used to obtain first decryption feedback information of the first data exchange party decrypting the second encrypted data according to the preset first private key, obtain second decryption feedback information of the second data exchange party decrypting the first encrypted data according to the preset second private key, and confirm whether the data exchange is completed based on the first decryption feedback information and the second decryption feedback information.
[0057] In one embodiment, before performing the steps of obtaining the first hash value calculated by the first data exchanger based on a preset first random preimage and sending the first hash value to the second data exchanger, the hash sending module 101 is further configured to: Obtain the data digest uploaded by the first data exchange party to obtain the first data digest; Obtain data digests uploaded by other data exchange partners to obtain a data digest set; Based on the first data digest, a data digest that meets the data exchange requirements is retrieved from the data digest set to obtain a second data digest; The data exchange party corresponding to the second data digest is confirmed to be the second data exchange party.
[0058] In one embodiment, the hash sending module 101, when performing the step of retrieving a data digest that meets the data exchange requirements from the data digest set based on the first data digest to obtain a second data digest, is specifically used for: Extract the data exchange demand characteristics from the first data digest; Data features are extracted from each data digest in the data digest set to obtain a data feature set; Semantic matching is performed on the data exchange requirement features and the data feature set to obtain a matching result; A candidate data summary list is obtained from the data summary set based on the matching results; The optimal data summary from the candidate data summary list is obtained according to a pre-set filtering strategy to obtain the second data summary.
[0059] In one embodiment, before performing the step of obtaining the first encrypted data generated by the first data exchange party according to a preset first public key, the ciphertext acquisition module 102 is further configured to: Obtain the enterprise information of the first data exchange party; Obtain the approval result of the first data exchange party's identity verification based on the enterprise information; When it is determined from the approval result that the first data exchange party has passed the identity approval, the public key and private key of the first data exchange party are generated, and the first public key and the first private key are obtained.
[0060] In one embodiment, before performing the calculation of the first hash value to be verified for the first random preimage, the hash verification module 103 is further configured to: If it is detected that the first data exchange party has not uploaded the first random preimage within a preset first time limit, a random symmetric key is generated; After encrypting the first encrypted data and the second encrypted data twice using the random symmetric key, the random symmetric key is destroyed.
[0061] In one embodiment, the hash verification module 103, when performing the calculation of the first hash value to be verified of the first random preimage, is specifically used for: Encode the preset first random preimage into a byte sequence; The byte sequence is hashed using a predefined hash function to obtain a byte representation in the form of a hash value. The byte representation is converted into a hexadecimal string format to obtain the first hash value to be verified.
[0062] In one embodiment, the decryption feedback information module 105, when performing the step of confirming whether data exchange is complete based on the first decryption feedback information and the second decryption feedback information, is specifically used for: Based on the first decryption feedback information, determine whether the first data exchange party has successfully decrypted the data; If the first data exchange party fails to decrypt, the data exchange is deemed to have failed. If the first data exchanger successfully decrypts the data, then the second data exchanger's success in decryption is determined based on the second decryption feedback information. If the second data exchange party fails to decrypt, the data exchange is deemed to have failed. If the second data exchange party successfully decrypts the data, the data exchange is considered complete.
[0063] This invention provides a data exchange device based on hash time locks. A first data exchange party uploads a data digest representing data characteristics (i.e., the first data digest). The system extracts its data exchange requirement features (generating a structured feature vector based on metadata using natural language processing technology). The same feature extraction is performed on the data digest sets uploaded by other exchange parties. Through semantic similarity calculation, threshold filtering, and weighted decision-making (combining reputation, data timeliness, etc.), a second data digest and corresponding second data exchange party are matched. After confirmation by both parties, an exchange agreement containing hash time lock rules and other information is signed via a smart contract and uploaded to the blockchain. Subsequently, the identity of the exchange party's enterprise information is verified. Upon approval, a public and private key is generated, and both parties generate encryption based on their respective public keys. The system first monitors whether the first exchange party uploads a preset first random preimage within a first time limit. If not, it generates a random symmetric key to re-encrypt the encrypted data of both parties and then destroys the key. If uploaded, it calculates the first hash value to be verified of the preimage. If it matches the first hash value previously sent to the second exchange party, it obtains the second hash value of the second exchange party and sends it to the first exchange party. Then, it monitors whether the second exchange party uploads a preset second random preimage within a second time limit. If the second hash value to be verified matches the second hash value, it sends the encrypted data to the other party in both directions. Finally, based on the feedback results of both parties decrypting with their respective private keys, it determines whether the data exchange is complete. The entire process uses blockchain, asymmetric encryption, and hash time lock mechanisms to ensure data privacy and exchange atomicity.
[0064] Specific limitations regarding the data exchange device based on hash time locks can be found in the limitations of the data exchange method based on hash time locks mentioned above, and will not be repeated here. Each module in the aforementioned data exchange device based on hash time locks can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0065] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a hash-time lock-based data exchange method on the server side.
[0066] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements client-side functions or steps of a hash-time lock-based data exchange method.
[0067] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: Obtain the first hash value calculated by the first data exchange party based on the preset first random preimage, and send the first hash value to the second data exchange party; Obtain first encrypted data generated by the first data exchange party according to a preset first public key, and obtain second encrypted data generated by the second data exchange party according to a preset second public key; If it is detected that the first data exchange party uploads the first random preimage within a preset first time limit, then calculate the first hash value to be verified of the first random preimage. If the first hash value to be verified is the same as the first hash value, obtain the second hash value calculated by the second data exchange party according to the preset second random preimage, and send the second hash value to the first data exchange party; If it is detected that the second data exchange party uploads a preset second random preimage within a preset second time limit, then the second hash value to be verified of the second random preimage is calculated. If the second hash value to be verified is the same as the second hash value, the first encrypted data is sent to the second data exchange party, and the second encrypted data is sent to the first data exchange party; Obtain first decryption feedback information from the first data exchange party when decrypting the second encrypted data using a preset first private key; obtain second decryption feedback information from the second data exchange party when decrypting the first encrypted data using a preset second private key; and confirm whether the data exchange is complete based on the first decryption feedback information and the second decryption feedback information.
[0068] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor: Obtain the first hash value calculated by the first data exchange party based on the preset first random preimage, and send the first hash value to the second data exchange party; Obtain first encrypted data generated by the first data exchange party according to a preset first public key, and obtain second encrypted data generated by the second data exchange party according to a preset second public key; If it is detected that the first data exchange party uploads the first random preimage within a preset first time limit, then calculate the first hash value to be verified of the first random preimage. If the first hash value to be verified is the same as the first hash value, obtain the second hash value calculated by the second data exchange party according to the preset second random preimage, and send the second hash value to the first data exchange party; If it is detected that the second data exchange party uploads a preset second random preimage within a preset second time limit, then the second hash value to be verified of the second random preimage is calculated. If the second hash value to be verified is the same as the second hash value, the first encrypted data is sent to the second data exchange party, and the second encrypted data is sent to the first data exchange party; Obtain first decryption feedback information from the first data exchange party when decrypting the second encrypted data using a preset first private key; obtain second decryption feedback information from the second data exchange party when decrypting the first encrypted data using a preset second private key; and confirm whether the data exchange is complete based on the first decryption feedback information and the second decryption feedback information.
[0069] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0070] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0071] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0072] Finally, it should be noted that if any software tools or components not belonging to this company appear in the embodiments of the application, they are merely illustrative examples and do not represent actual use. The embodiments described above are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A data exchange method based on hash time lock, characterized in that, include: Obtain the first hash value calculated by the first data exchange party based on the preset first random preimage, and send the first hash value to the second data exchange party; Obtain first encrypted data generated by the first data exchange party according to a preset first public key, and obtain second encrypted data generated by the second data exchange party according to a preset second public key; If it is detected that the first data exchange party uploads the first random preimage within a preset first time limit, then calculate the first hash value to be verified of the first random preimage. If the first hash value to be verified is the same as the first hash value, obtain the second hash value calculated by the second data exchange party according to the preset second random preimage, and send the second hash value to the first data exchange party; If it is detected that the second data exchange party uploads a preset second random preimage within a preset second time limit, then the second hash value to be verified of the second random preimage is calculated. If the second hash value to be verified is the same as the second hash value, the first encrypted data is sent to the second data exchange party, and the second encrypted data is sent to the first data exchange party; Obtain first decryption feedback information from the first data exchange party when decrypting the second encrypted data using a preset first private key; obtain second decryption feedback information from the second data exchange party when decrypting the first encrypted data using a preset second private key; and confirm whether the data exchange is complete based on the first decryption feedback information and the second decryption feedback information.
2. The data exchange method based on hash time lock as described in claim 1, characterized in that, Before obtaining the first hash value calculated by the first data exchanger based on a preset first random preimage and sending the first hash value to the second data exchanger, the method further includes: Obtain the data digest uploaded by the first data exchange party to obtain the first data digest; Obtain data digests uploaded by other data exchange partners to obtain a data digest set; Based on the first data digest, a data digest that meets the data exchange requirements is retrieved from the data digest set to obtain a second data digest; The data exchange party corresponding to the second data digest is confirmed to be the second data exchange party.
3. The data exchange method based on hash time lock as described in claim 2, characterized in that, The step of retrieving a data digest that meets the data exchange requirements from the data digest set based on the first data digest to obtain a second data digest includes: Extract the data exchange demand characteristics from the first data digest; Data features are extracted from each data digest in the data digest set to obtain a data feature set; Semantic matching is performed on the data exchange requirement features and the data feature set to obtain a matching result; A candidate data summary list is obtained from the data summary set based on the matching results; The optimal data summary from the candidate data summary list is obtained according to a pre-set filtering strategy to obtain the second data summary.
4. The data exchange method based on hash time lock as described in claim 1, characterized in that, Before obtaining the first encrypted data generated by the first data exchange party according to the preset first public key, the method further includes: Obtain the enterprise information of the first data exchange party; Obtain the approval result of the first data exchange party's identity verification based on the enterprise information; When it is determined from the approval result that the first data exchange party has passed the identity approval, the public key and private key of the first data exchange party are generated, and the first public key and the first private key are obtained.
5. The data exchange method based on hash time lock as described in claim 1, characterized in that, Before calculating the first hash value to be verified of the first random preimage, the method further includes: If it is detected that the first data exchange party has not uploaded the first random preimage within a preset first time limit, a random symmetric key is generated; After encrypting the first encrypted data and the second encrypted data twice using the random symmetric key, the random symmetric key is destroyed.
6. The data exchange method based on hash time lock as described in claim 1, characterized in that, The calculation of the first hash value to be verified of the first random preimage includes: Encode the preset first random preimage into a byte sequence; The byte sequence is hashed using a predefined hash function to obtain a byte representation in the form of a hash value. The byte representation is converted into a hexadecimal string format to obtain the first hash value to be verified.
7. The data exchange method based on hash time lock as described in claim 1, characterized in that, The step of confirming whether data exchange is complete based on the first decryption feedback information and the second decryption feedback information includes: Based on the first decryption feedback information, determine whether the first data exchange party has successfully decrypted the data; If the first data exchange party fails to decrypt, the data exchange is deemed to have failed. If the first data exchanger successfully decrypts the data, then the second data exchanger's success in decryption is determined based on the second decryption feedback information. If the second data exchange party fails to decrypt, the data exchange is deemed to have failed. If the second data exchange party successfully decrypts the data, the data exchange is considered complete.
8. A data exchange device based on a hash time lock, characterized in that, include: The hash sending module is used to obtain the first hash value calculated by the first data exchange party based on the preset first random preimage, and send the first hash value to the second data exchange party; The ciphertext acquisition module is used to acquire the first encrypted data generated by the first data exchange party according to the preset first public key, and to acquire the second encrypted data generated by the second data exchange party according to the preset second public key; The hash verification module, if it detects that the first data exchange party uploads the first random preimage within a preset first time limit, calculates the first hash value to be verified of the first random preimage; if the first hash value to be verified is the same as the first hash value, obtains the second hash value calculated by the second data exchange party based on the preset second random preimage, and sends the second hash value to the first data exchange party; if it detects that the second data exchange party uploads the preset second random preimage within a preset second time limit, calculates the second hash value to be verified of the second random preimage. The encrypted exchange module, if the second hash value to be verified is the same as the second hash value, sends the first encrypted data to the second data exchange party and sends the second encrypted data to the first data exchange party; The decryption feedback information module is used to obtain first decryption feedback information of the first data exchange party decrypting the second encrypted data according to a preset first private key, obtain second decryption feedback information of the second data exchange party decrypting the first encrypted data according to a preset second private key, and confirm whether the data exchange is completed based on the first decryption feedback information and the second decryption feedback information.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the data exchange method based on hash time lock as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the data exchange method based on a hash time lock as described in any one of claims 1 to 7.