Blockchain transaction retrieval method, and device
Patent Information
- Application Number
- PCT/CN2025/131161
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-26
- Filing Date
- 2025-10-30
- Publication Date
- 2026-10-01
Smart Images

Figure CN2025131161_01102026_PF_FP_ABST
Abstract
Description
A blockchain transaction retrieval method and device
[0001] This application claims priority to Chinese Patent Application No. 202510371415.8, filed on March 26, 2025, entitled "A Blockchain Transaction Retrieval Method and Device", the entire contents of which are incorporated herein by reference. Technical Field
[0002] The embodiments in this specification belong to the field of blockchain technology, and in particular relate to a blockchain transaction retrieval method and device. Background Technology
[0003] Blockchain is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and cryptographic algorithms. In a blockchain system, data blocks are sequentially linked to form a chain-like data structure, and a distributed ledger is cryptographically guaranteed to be immutable and unforgeable. Due to its decentralized, immutable, and autonomous characteristics, blockchain has received increasing attention and has been widely applied in numerous fields. Summary of the Invention
[0004] The purpose of this invention is to provide a blockchain transaction retrieval method and device that can prevent the leakage of user privacy data due to the leakage of the user's real key by the proxy node when performing blockchain transaction retrieval based on hidden address through proxy node, thereby improving the security of blockchain transaction retrieval based on hidden address through proxy node and overcoming the shortcomings of the prior art.
[0005] To achieve the above objectives, this specification provides a blockchain transaction retrieval method in the first aspect. In the blockchain, a first group generated by a first generator, a second group generated by a second generator, and a third group are pre-determined. Elements in the first and second groups are mapped to the third group based on a preset bilinear mapping function. The public keys of the blockchain participants are pre-generated based on the private keys of the blockchain participants and the first generator. The method includes: a first party among the blockchain participants determines a first value belonging to the second group based on the second generator, and a second value belonging to the second group based on its own private key and the second generator; sending the first and second values to a proxy node; a second party among the blockchain participants determines a third value belonging to the first group based on the first generator, and a fourth value belonging to the first group based on the public key of the recipient; sending a first transaction based on the target hidden address of the recipient represented by the third and fourth values; and the proxy node obtains the first transaction and verifies the first, second, third, and fourth values based on the bilinear mapping function to determine whether the first transaction was sent to the first party.
[0006] A second aspect of this specification provides a computing device, including: a processor; and a memory storing a program that, when the processor executes the executable code, implements the method described in the first aspect.
[0007] In a blockchain transaction retrieval scheme provided in this specification, a first group and a second group, generated by a first generator and a second generator respectively, can be pre-determined in the blockchain. Elements in the first and second groups are mapped to a third group based on a preset bilinear mapping function, and the public keys of the participating parties are pre-generated based on their private keys and the first generator. Therefore, the first party in the blockchain can determine a first value belonging to the second group based on the second generator, and a second value belonging to the second group based on its own private key and the second generator; it then sends the first and second values to a proxy node. The second party in the blockchain can determine a third value belonging to the first group based on the first generator, and a fourth value belonging to the first group based on the recipient's public key; it then sends a first transaction based on the recipient's hidden address represented by the third and fourth values. Furthermore, the proxy node can obtain the first transaction and verify the first, second, third, and fourth values based on the bilinear mapping function to determine whether the first transaction was sent to the first party. This method can prevent the leakage of user privacy data due to the disclosure of the user's real key by the proxy node when performing blockchain transaction retrieval based on hidden addresses through proxy nodes, thereby improving the security of blockchain transaction retrieval based on hidden addresses through proxy nodes. Attached Figure Description
[0008] To more clearly illustrate the technical solutions of the embodiments in this specification, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0009] Figure 1 shows a blockchain architecture diagram in one embodiment;
[0010] Figure 2 is a schematic diagram of a transaction retrieval scheme based on hidden addresses;
[0011] Figure 3 is a schematic diagram of a transaction retrieval scheme in one embodiment of this specification;
[0012] Figure 4 is a flowchart of a blockchain transaction retrieval method according to an embodiment of this specification;
[0013] Figure 5 is a schematic diagram of a blockchain transaction retrieval method in one embodiment of this specification. Detailed Implementation
[0014] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0015] Figure 1 illustrates a blockchain architecture diagram in one embodiment. As shown in Figure 1, the blockchain contains, for example, 8 nodes. The connections between nodes schematically represent P2P (Peer-to-Peer) connections. These nodes can store the entire ledger, that is, the state of all blocks and all accounts. Each node in the blockchain generates the same state by executing the same transactions, and each node stores the same state database. It is understood that although Figure 1 shows a blockchain with 8 nodes, the embodiments in this specification are not limited to this, and may include other numbers of nodes. Specifically, the nodes included in the blockchain can satisfy the Byzantine Fault Tolerance (BFT) requirement. The Byzantine Fault Tolerance requirement can be understood as the existence of Byzantine nodes within the blockchain, while the blockchain does not exhibit Byzantine behavior externally. Generally, some Byzantine Fault Tolerance algorithms require the number of nodes to be greater than 3f+1, where f is the number of Byzantine nodes, such as the Practical Byzantine Fault Tolerance (PBFT) algorithm.
[0016] In the blockchain field, a transaction refers to a unit of task executed and recorded within the blockchain. A transaction typically includes a From field, a To field, and a Data field. Specifically, in the case of a transfer transaction, the From field represents the account address initiating the transaction (i.e., initiating a transfer task to another account), the To field represents the account address receiving the transaction (i.e., receiving the transfer), and the Data field includes the transfer amount. In the case of a transaction calling a smart contract on the blockchain, the From field represents the account address initiating the transaction, the To field represents the account address of the contract called by the transaction, and the Data field includes the function name in the called contract and the parameters passed to that function, which is used to retrieve and execute the function's code from the blockchain during transaction execution.
[0017] Currently, to protect the privacy of the recipient's identity, some blockchain solutions use hidden addresses to ensure the anonymity of the recipient. The principle of hidden addresses is that the sender generates a one-time address for each transaction, so even if multiple transactions are made with the same recipient, unrelated parties cannot distinguish between them. Therefore, hidden addresses help protect the privacy of cryptocurrency payment recipients and their asset details. Figure 2 is a schematic diagram of a transaction retrieval scheme based on hidden addresses. As shown in Figure 2, the recipient B of a blockchain transaction can possess a public-private key pair (PK). B SK B ), where PK B =SK B·g, where g is the generator of the elliptic curve. The sender A of the transaction can determine a random number r. A , and according to r A Determine the pair (R) A ,T A The hidden address of the receiver identified by ) where R A =r A g,T A =H(r) A ·PK B Let g be a hash function, and H(·) be a hash function. Then, party A can sign the transaction and send it to the blockchain. Afterwards, recipient B can scan the transaction from the blockchain and extract T from its recipient address field. A Using our private key SK B Calculate T′ A =H(SK) B ·R A G. If T′ A =T A If the transaction is sent to this party, then it can be determined that the transaction was sent to this party, and the party can receive the transaction. Otherwise, the transaction is determined not to have been sent to this party. Party B can also scan all on-chain transactions to identify all transactions sent to this party. Since each hidden address is generated based on a one-time random number, the hidden address sent each time is different from the previous one, so the actual recipient of the transaction cannot be determined based on the address. Furthermore, the recipient knows the element R in the hidden address tuple. A The ownership of a transaction can then be verified. However, this type of hidden address scheme also has the following problem: the search time is linearly related to the total number of all hidden address transactions. This makes it very difficult for local clients with limited computing resources to retrieve data from a large number of transactions.
[0018] To enable users to quickly retrieve transactions sent to them from a large volume of transactions, some transaction retrieval schemes based on hidden addresses use proxy computation. This involves directly transmitting the user's private key to an on-chain proxy node, which then performs the retrieval calculation on behalf of the user's local client to identify each transaction sent to the user, as shown in Figure 3. However, this scheme has a problem: while directly handing the user's private key to the proxy node can utilize the proxy node's computing resources to speed up transaction retrieval, negligence or malicious intent on the part of the proxy node could lead to the leakage of the user's key to individuals or organizations other than the user. This could allow others to retrieve transactions sent to the user, resulting in privacy breaches and other security issues. Furthermore, there is the possibility of the proxy initiating transactions using the private key, leading to the transfer of user assets.
[0019] Another transaction retrieval scheme based on hidden addresses sets the user's public-private key pair as a monitoring public-private key pair (including a monitoring public key and a monitoring private key) and a spending public-private key pair (including a spending public key and a spending private key). The spending private key is used to sign transactions initiated by the user, while the monitoring private key is used to detect transactions related to the user on the blockchain. Thus, the user can send the monitoring private key to a proxy node, allowing the proxy node to retrieve transactions sent to the user from the blockchain using the monitoring private key. However, this scheme still has the following problems: Although this scheme limits the scope of the monitoring private key, preventing its use for transaction signing and thus preventing issues such as proxy nodes transferring user assets, if the proxy node is negligent or malicious and leaks the user's monitoring private key to someone other than the user, the user's transaction privacy can still be compromised.
[0020] To address the aforementioned issues, this specification provides a blockchain transaction retrieval method. Using this method, for example, receiver B selects a random number to blind their private key, generating a proxy key which is then transmitted to a proxy node. The proxy node can use this proxy key to iterate and compare each on-chain transaction, determining the transaction sent to B based on the comparison results. The hidden address sent by the transaction sender is an element of a bilinear group, transforming the conventional hidden address scheme's method of verifying transaction ownership through the user's private key into a method of verifying transaction ownership by determining whether the bilinear mapping equation of the group element holds.
[0021] The advantages of this method are: it not only improves the efficiency of transaction retrieval by allowing proxy nodes to retrieve transactions where the recipient is the target user, but also allows the proxy node to verify whether any transaction on the chain belongs to the target user without revealing the user's original private key. This solves the problem of privacy breaches that can occur when directly sending the user's private key to the proxy node for proxy retrieval.
[0022] The following further describes a blockchain transaction retrieval method provided by an embodiment of this specification. Figure 3 is a flowchart of a blockchain transaction retrieval method according to an embodiment of this specification. In the blockchain, a first group generated by a first generator, a second group generated by a second generator, and a third group are predetermined. Elements in the first and second groups are mapped to the third group based on a preset bilinear mapping function. Furthermore, the public keys of the blockchain participants are pre-generated based on the private keys of the blockchain participants and the first generator. As shown in Figure 4, the method includes at least the following steps:
[0023] Step S401: The first party among the participants in the blockchain determines a first value belonging to the second group based on the second generator, and determines a second value belonging to the second group based on its own private key and the second generator; and sends the first value and the second value to the proxy node.
[0024] Step S403: The second party among the participants in the blockchain determines a third value belonging to the first group based on the first generator, and determines a fourth value belonging to the first group based on the public key of the receiver; and sends a first transaction based on the target hidden address of the receiver represented by the third and fourth values.
[0025] Step S405: The proxy node obtains the first transaction and verifies the first value, second value, third value, and fourth value based on the bilinear mapping function to determine whether the first transaction is a transaction sent to the first party.
[0026] First, in step S401, the first party among the blockchain participants determines a first value belonging to the second group based on the second generator, and determines a second value belonging to the second group based on its own private key and the second generator. Depending on the implementation, the blockchain in this step can be of different specific types, and this specification does not limit this.
[0027] A group is a mathematical structure, typically consisting of a set of elements and an operation (e.g., addition or multiplication), satisfying the following conditions: Closure: Performing an operation on any two elements in the set results in a result still within the set. Associativity: The order of operations does not affect the result. Identity Element: There exists a special element in the set that, when operated on with other elements, does not change the other elements. Inverse Element: Every element in the set has an "opposite" element such that operations on them result in an identity element. A bilinear mapping function for a group is a function defined on two input groups that maps their element-pairs to an element in the output group, maintaining a linear relationship with respect to each input group. Specifically, a bilinear mapping function e can be represented, for example, as e: G1 × G2 → G T Where G1 and G2 are the input groups, G T Let × denote the Cartesian product as the output group. This function satisfies the following computational properties: Bilinear: This means that for any element P belonging to G1 and element Q belonging to G2, (aP, bQ) = e(aP, Q). b =e(P,bQ) a =e(P,Q) ab This means that the mapping is linear with respect to both inputs. Non-degeneracy: This means that if g1 and g2 are generators of G1 and G2, then e(g1,g2) is a function of G. TThe generators. Computational efficiency: The mapping e(aP,bQ) can be computed efficiently.
[0028] As mentioned earlier, in this blockchain, a first group generated by a first generator, a second group generated by a second generator, and a third group can be predetermined. Elements in the first and second groups can be mapped to the third group based on a preset bilinear mapping function. The first and second generators are used to generate elements in the first and second groups, respectively. In different implementations, the specific values of the first and second generators can be different. In different implementations, the bilinear mapping function used to map elements in the first and second groups to the third group can also be different specific mapping functions, and this specification does not impose any restrictions on this.
[0029] Each participant in the blockchain can also pre-generate their own public key based on their private key and a first generator, for example, the product of their private key and the first generator, and then disclose their public key to other parameter parties. Figure 5 is a schematic diagram of a blockchain transaction retrieval method according to an embodiment of this specification. In the example shown in Figure 5, for example, participant A can pre-generate their own public-private key pair (PK). A SK A ), and publicly disclose the party's public key PK. A Among them, PK A =SK A g1 is the first generator of the first group. For example, participant B can also pre-generate their public-private key pair (PK). B SK B ), and publicly disclose the party's public key PK. B Among them, PK B =SK B g1.
[0030] In one implementation, the first group and the second group can be q-order additive cyclic groups, and the third group is a q-order multiplicative cyclic group. A cyclic group is a group whose elements can all be obtained by repeated operations on a specific generator. The order of a group refers to the number of elements in the group. A q-order additive cyclic group is a cyclic group containing q (and q is a prime number) elements, with addition as the operation. A q-order multiplicative cyclic group is a cyclic group containing q elements, with multiplication as the operation.
[0031] In different implementations, the specific methods by which the first party determines the first and second values can differ. In one implementation, the first value belonging to the second group can be determined based on the first party's first random number and second generator, and the second value belonging to the second group can be determined based on the first random number, the first party's private key, and the second generator. In another specific implementation, the second value can be determined based on the product of the first random number, the first party's private key, and the second generator.
[0032] Specifically, in the example shown in Figure 5, for example, the first party (participant B) can generate a random number s and determine the private key SK based on s. B proxy key k B The proxy key k B It can be in binary form, represented as k B = (k1, k2), where k1 = s·g2, k2 = (SK B ·s)·g2.
[0033] After determining the first and second values, they can be sent to the proxy node. A proxy node is a node that can perform specific operations or tasks on behalf of a user client or a node belonging to the user. Depending on the implementation, the proxy node can be different types of computing devices, such as physical or logical computers, or other devices with computing and storage capabilities.
[0034] Then, in step S403, the second party among the blockchain participants can determine a third value belonging to the first group based on the first generator, and a fourth value belonging to the first group based on the receiver's public key. Furthermore, the first transaction is sent based on the receiver's target hidden address represented by the third and fourth values. In different implementations, the specific transaction type or purpose of the first transaction may differ, and this specification does not limit this. In one implementation, the first transaction may be a digital collectible ownership transfer transaction.
[0035] In different implementations, the specific methods by which the second party determines the third and fourth values can differ. In one implementation, the third value belonging to the first group can be determined based on the second random number and the first generator of the second party, and the fourth value belonging to the first group can be determined based on the second random number and the public key of the receiver.
[0036] Specifically, in the example shown in Figure 5, for instance, the second party (Party A) can obtain the public key PK of Party B. B And determine a random number t. Generate a one-time hidden address Y = (Y1, Y2) represented by a tuple based on t, where Y1 = t·g1, Y2 = t·PK B Then, the hidden address Y can be appended to the recipient address field of transaction T, and transaction T can be sent in the blockchain.
[0037] Subsequently, in step S405, the proxy node can obtain the first transaction. Then, based on the bilinear mapping function, the first, second, third, and fourth values are verified to determine whether the first transaction was sent to the first party.
[0038] Specifically, in one implementation, a first mapping result can be determined based on the bilinear mapping function, the third value, and the second value; a second mapping result can be determined based on the bilinear mapping function, the fourth value, and the first value; if the first mapping result is equal to the second mapping result, then the recipient of the first transaction is determined to be the first party. In another implementation, if the first mapping result is not equal to the second mapping result, then the recipient of the second transaction is determined not to be the first party.
[0039] For example, in the example shown in Figure 5, the proxy node can obtain on-chain transaction T, whose recipient address field is Y = (Y1, Y2). Then, based on the preset mapping function e, it can calculate the bilinear mappings U = e(Y1, k2) and V = e(Y2, k1). Next, it determines whether the equation U = V holds true. If the equation holds true, it is determined that transaction T was sent to participant B. If the equation does not hold true, it is determined that transaction T was not sent to participant B.
[0040] This scheme overcomes the shortcomings of existing methods that send user private keys or user monitoring private keys to proxy nodes for transaction retrieval. The proxy key is generated based on the actual user key but is not the actual user key. It allows retrieval of keys sent to the user without revealing the user key. When retrieval is not needed, the proxy key can be easily invalidated without changing the actual user key, making it difficult to cause user privacy leaks even if the random key is leaked. For subsequent retrievals, a new proxy key can be regenerated based on the actual user key. The specific method of invalidating the random key can vary in different implementations. In one implementation, the participant can send a random key invalidation command to the blockchain system after sending the random key to the proxy node. Upon receiving the command, the system marks the random key as invalid, making it unusable for transaction retrieval. In another implementation, the random key can be invalidated, for example, after a predetermined time after the participant sends the random key to the proxy node.
[0041] This specification also provides a computing device, including: a processor; and a memory storing a program, wherein, when the processor executes the program, any of the methods described above are implemented.
[0042] This specification also provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform any of the methods described above.
[0043] This specification also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement any of the methods described above.
[0044] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0045] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0046] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. A typical implementation device is a server system. Of course, this application does not exclude the possibility that, with the future development of computer technology, the computer implementing the functions of the above embodiments can be, for example, a personal computer, a laptop computer, an in-vehicle human-machine interaction device, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0047] While one or more embodiments of this specification provide the operational steps of the methods described in the embodiments or flowcharts, more or fewer operational steps may be included based on conventional or non-inventive means. The order of steps listed in the embodiments is merely one possible order of execution among many steps and does not represent the only possible order. In actual device or end product execution, the methods shown in the embodiments or drawings may be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment, or even a distributed data processing environment). The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitations, the presence of other identical or equivalent elements in the process, method, product, or apparatus that includes the elements is not excluded. For example, the use of terms such as "first," "second," etc., is to denote names and does not indicate any particular order.
[0048] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, when implementing one or more of these specifications, the functions of each module can be implemented in one or more software and / or hardware components, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between devices or units, and may be electrical, mechanical, or other forms.
[0049] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.
[0050] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0051] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0052] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0053] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0054] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage, graphene storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0055] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0056] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can reside in local and remote computer storage media, including storage devices.
[0057] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, system embodiments are basically similar to method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments. In the description of this specification, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this specification. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described can be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0058] The above description is merely an embodiment of one or more embodiments of this specification and is not intended to limit the scope of these embodiments. Various modifications and variations can be made to these embodiments by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims.
Claims
1. A blockchain transaction retrieval method, wherein in the blockchain, a first group generated by a first generator, a second group generated by a second generator, and a third group are predetermined, and elements in the first group and the second group are mapped to the third group based on a preset bilinear mapping function; Furthermore, the public keys of the participants in the blockchain are pre-generated based on the private keys of the participants in the blockchain and a first generator, the method comprising: The first party among the participants in the blockchain determines a first value belonging to the second group based on the second generator, and determines a second value belonging to the second group based on its own private key and the second generator; and sends the first value and the second value to the proxy node. The second party among the participants in the blockchain determines a third value belonging to the first group based on the first generator, and determines a fourth value belonging to the first group based on the public key of the receiver. Based on the target hidden address of the receiver represented by the third and fourth values, send the first transaction; The proxy node obtains the first transaction and verifies the first, second, third, and fourth values based on the bilinear mapping function to determine whether the first transaction was sent to the first party.
2. The method according to claim 1, wherein, The first, second, third, and fourth values are verified based on the bilinear mapping function to determine whether the first transaction was sent to the first party, including: Based on the bilinear mapping function, the third value, and the second value, a first mapping result is determined; based on the bilinear mapping function, the fourth value, and the first value, a second mapping result is determined; if the first mapping result is equal to the second mapping result, then the recipient of the first transaction is determined to be the first party.
3. The method according to claim 2, further comprising: If the first mapping result is not equal to the second mapping result, then it is determined that the recipient of the second transaction is not the first party.
4. The method according to claim 1, wherein, Based on the second generator, determine the first value belonging to the second group, and based on the private key and the second generator, determine the second value belonging to the second group, including: Based on the first random number and the second generator of the first party, a first value belonging to the second group is determined, and based on the first random number, the first party's private key, and the second generator, a second value belonging to the second group is determined.
5. The method according to claim 1, wherein, The third value belonging to the first group is determined based on the first generator, and the fourth value belonging to the first group is determined based on the receiver's public key, including: Based on the second random number from the second party and the first generator, determine the third value belonging to the first group, and based on the second random number and the receiver's public key, determine the fourth value belonging to the first group.
6. The method according to claim 4, wherein, Determine the second value belonging to the second group based on the first random number, the private key of the first party, and the second generator, including: determining the second value based on the product of the first random number, the private key of the first party, and the second generator.
7. The method according to claim 1, wherein, The public key of the participants in the blockchain is generated in advance based on the private key of the participants in the blockchain and a first generator, including: generating the public key of the participants in advance based on the product of the private key of the participants and the first generator.
8. The method according to claim 1, wherein, The first transaction was a transfer of ownership of digital collectibles.
9. The method according to claim 1, wherein, The first group and the second group are q-order additive cyclic groups of prime numbers, and the third group is a q-order multiplicative cyclic group.
10. A computer device, comprising: processor; And a memory storing executable code, wherein when the processor executes the executable code, it implements the method of any one of claims 1-9.