Privacy protection method for alliance chain agricultural product supply chain traceability

By adopting attribute-based encryption technology and dual pseudonym mechanism in the traceability of agricultural products supply chains, the conflict between transparency and privacy protection is solved, the privacy protection of data on the alliance chain and the anonymity of entities are achieved, and the credibility and privacy of traceability information are ensured.

CN120128376APending Publication Date: 2025-06-10CHONGQING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510276232.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing agricultural product supply chain traceability technology faces a conflict between transparency and privacy protection, which leads to the participants refusing to upload key traceability information due to concerns about the leakage of commercial information, affecting the effectiveness of consumer traceability.

Method used

The attribute-based encryption technology and the dual pseudonym mechanism are adopted to generate private attribute keys and dynamic pseudonyms through the key management center to ensure the privacy protection of data on the alliance chain, while achieving entity anonymity and solving trust and privacy issues.

Benefits of technology

It effectively protects the identity and data security of agricultural product supply chain entities, solves the trust and privacy issues between entities on the alliance chain, and ensures the credibility and privacy of traceable information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128376A_ABST
    Figure CN120128376A_ABST
Patent Text Reader

Abstract

The invention relates to a privacy protection method for alliance chain agricultural product supply chain traceability, and belongs to the technical field of information security. The method comprises the following steps: a registration stage: a supply chain entity participating in traceability registers by using own identity information, and a key management center generates a pseudonym by using the identity information and sends the pseudonym to the supply chain entity; an access structure defining stage: the supply chain entity sends an attribute set of the traceability information to a key management center, the key management center generates a private attribute key and a dynamic pseudonym for the supply chain entity, and the supply chain entity defines a decryption access structure according to the private attribute key; a data encryption stage: the supply chain entity encrypts data by using the private attribute key, and sends an encryption result and a dynamic pseudonym to a supervision department; in the data decryption stage, the supervision department decrypts and audits the received data, and the supply chain entity links the encrypted traceability information; and the supply chain entity with the traceability demand checks the traceability information of the agricultural products in the supply chain by decrypting the data on the chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and relates to a privacy protection method for traceability of agricultural product supply chains oriented to consortium blockchains. Background Art

[0002] With the development of the complexity and globalization of agricultural product supply chains, food safety supervision faces challenges such as fragmented traceability information and insufficient data credibility. The current technical solutions are mainly divided into two categories: centralized and decentralized systems, but their technical characteristics and application limitations urgently need to be optimized.

[0003] (1) Technical bottlenecks of centralized agricultural product supply chain traceability solutions: 1) Advantages of the technical architecture and defects in information management: Centralized solutions integrate data from production, processing, logistics and other links through a unified database, and use technologies such as barcodes, RFID, and DNA markers to achieve full-process tracking. Although the supervision system strengthens the traceability ability of responsible entities, the following problems exist: ① Information silos: The data standards between different regulatory departments or enterprises are not unified, resulting in difficulty in intercommunication of traceability information. ② Insufficient transparency: Consumers can only obtain limited information (such as inspection reports) and cannot verify the authenticity of the whole-chain data. ③ Security risks: The central database is vulnerable to cyberattacks, which may lead to data tampering or leakage. 2) Limitations in practical applications: Centralized systems rely on enterprises to actively upload information, but some participants may selectively submit low-value data (such as supplier cost structures) to avoid exposing trade secrets, weakening the effectiveness of traceability.

[0004] (2) Innovations and existing contradictions of decentralized solutions: Blockchain technology constructs a decentralized traceability system through features such as distributed ledgers and smart contracts. For example: ① Improved data credibility: The single-node upload and multi-node verification mechanism of blockchain ensures that information cannot be tampered with. For example, the "Shennong Chain" in Shanghai has achieved full-process evidence preservation from watermelon seed sources to sales. ② Optimized collaboration efficiency: Blockchain supports real-time data sharing among supply chain participants (producers, logistics providers, retailers), reducing communication costs. However, existing blockchain solutions still face two core contradictions: 1) Conflict between transparency and privacy protection: Although the open and transparent characteristics of blockchain enhance trust, the analysis of transaction address correlations may lead to the exposure of enterprise identities (such as mapping high-frequency trading nodes to specific suppliers). Due to concerns about the leakage of commercial information (such as pricing strategies, production capacity data), participants may refuse to upload key traceability information, ultimately resulting in the failure of consumer traceability. 2) Imbalance between technical characteristics and business logic: If supply chain participants only upload low-value information (such as general production standards instead of specific operation logs), the immutability of blockchain will instead solidify invalid data, exacerbating the consumer trust crisis. For example, a traceability system shows "meeting national standards" but lacks actual fertilization records, making it difficult to meet the needs of refined traceability.

[0005] The above contradictions indicate that building a traceability system for agricultural product supply chains that takes into account privacy, transparency, and practicality remains the core challenge in technology research and development and industrial implementation. Summary of the Invention

[0006] In view of this, the purpose of the present invention is to provide a privacy protection method for traceability of agricultural product supply chains in consortium blockchains by combining attribute-based encryption and double pseudonyms to protect the identity privacy and data security of each entity in the consortium blockchain. Specifically, regarding how to effectively achieve privacy protection in the process of traceability of agricultural product supply chains based on consortium blockchains, attribute-based encryption technology is used to protect the privacy of data on the chain. By introducing double pseudonyms, the anonymity of entities in the agricultural product supply chain is achieved on the premise of ensuring regulatory compliance, which helps to solve the trust and privacy problems among entities on the chain.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] A privacy protection method for traceability of agricultural product supply chains in consortium blockchains includes the following stages:

[0009] Registration stage: Supply chain entities participating in traceability register using their own identity information, and the key management center generates pseudonyms using the identity information and sends them to the supply chain entities;

[0010] Define access structure stage: Supply chain entities send the attribute set of traceability information to the key management center, and the key management center generates private attribute keys and dynamic pseudonyms for them. Supply chain entities define the decryption access structure according to the private attribute keys;

[0011] Data encryption stage: Supply chain entities encrypt data using private attribute keys and send the encryption results and dynamic pseudonyms to the regulatory department;

[0012] Data decryption stage: The regulatory department decrypts and audits the received data, and supply chain entities upload the encrypted traceability information to the chain. After the data is uploaded to the chain, supply chain entities with traceability requirements can view the traceability information of agricultural products in the supply chain by decrypting the data on the chain.

[0013] Furthermore, the registration stage specifically includes: Assuming that the supply chain entity U i has an identity information set I i ={I i1 , I i2 , …, I in}, where I ij represents the j-th item of identity information of entity U i , and n is the number of information items;

[0014] First, in order to ensure the security of identity information during the transmission process, entity U iHash the identity information set of itself; H(·) represents the hash function used, then: H(I i ) = H(I i1 ||I i2 …||I in ), where || represents the concatenation operation, and the hash value H(I i ) represents the encrypted digest of the entity's identity information;

[0015] Then, entity U i sends the generated hash value H(I i ) to the Key Management Center (KMC);

[0016] Finally, after receiving the hash value H(I i ), the KMC generates a digital pseudonym P i according to this hash value and using an encryption algorithm or a pseudorandom function; for example, the KMC uses the encryption algorithm E k (·) to generate the digital pseudonym: P i = E k (H(I i ))), where k is the private key of the Key Management Center, and P i is the digital pseudonym generated for entity U i ; to ensure that the digital pseudonym of each entity is unique in the supply chain, the KMC needs to maintain a list of already generated digital pseudonyms {P 1 , P 2 , …, P m}, where m is the current number of generated digital pseudonyms; when generating a new digital pseudonym P i , the KMC needs to ensure If P i already exists, it needs to be regenerated or appropriately adjusted to ensure uniqueness.

[0017] Furthermore, the stage of defining the access structure specifically includes: Assume that the supply chain entity U i needs to upload the traceability information M to the chain and define an attribute set A i for it, where A i = {a i1 , a i2 , …, a in}, each attribute a ij represents a specific attribute of the traceability information M, and n is the number of attributes;

[0018] First, the system randomly selects a security parameter λ and uses the initialization function Setup(λ) to generate the system public parameters P and the master key Mk;

[0019] Secondly, the KMC is based on U iThe provided set of attributes A i , using the master key MK and the key generation function KeyGen(A i , MK) to generate the corresponding private attribute key SK Ai ;

[0020] Then, the supply chain entity U i defines an access structure tree T. In CP-ABE (ciphertext policy attribute-based encryption), the access structure T is a logical expression that defines which combinations of attribute sets can satisfy the decryption condition, and can be a combination of logical operations such as AND, OR, etc. This structure specifies which participating parties corresponding to which attribute sets can decrypt the data ciphertext. For example: T = (a i1 ∧a i2 )∨(a i3 ∧a i4 ), this access structure means that it is necessary to satisfy at least the simultaneous presence of a i1 and a i2 , or the simultaneous presence of a i3 and a i4 to decrypt;

[0021] Finally, the supply chain entity takes its own public identity information (Uploader) d1, the public identity information of the regulatory department (Verifier) d2, the timestamp (Timestamp) d3, and the nonce (Nonce) d4 as the leaf nodes of the Merkle tree (for convenience of representation, the above information is represented by d1, d2, d3, d4). First, perform the H(·) hash operation on the leaf nodes to obtain the corresponding hash values H 1 , H 2 , H 3 , H 4 ; then calculate the parent nodes of adjacent leaf nodes: H 1,2 = H(H 1 ||H 2 ), H 3,4 = H(H 3 ||H 4 ), where || represents the operation of concatenating two hash values; finally, the root node H root = H(H 1,2 ||H 3,4 ), and the root node is the dynamic pseudonym D. Because the timestamp and the nonce change at all times, the pseudonym generated each time is different, thus realizing the dynamic nature of the pseudonym and protecting the identity privacy of the supply chain entity.

[0022] Furthermore, the data encryption stage specifically includes the following steps:

[0023] S31: The system selects a random value wherein is the set of integers modulo p, where p is a large prime number;

[0024] S32: Calculate the session key K = g s , and use symmetric encryption to encrypt the traceability information M to generate the ciphertext fragment C data = E AES (K, M), where E AES is the AES symmetric encryption algorithm;

[0025] S33: Use the public parameter P and the access structure T generated in the defining access structure phase to encrypt the session key K into the ciphertext fragment C key = Encrypt(T, P, K);

[0026] S34: Combine C data with C key to form the ciphertext C = (C data , C key );

[0027] S35: Bind the dynamic pseudonym D generated in the defining access structure phase to the ciphertext C, and the final data packet form is: D set = (C, D).

[0028] Furthermore, the data decryption phase specifically includes the following steps:

[0029] S41: The decryptor provides its own attribute set A i , and the key management center (KMC) uses the master key MK and the attribute key generation function KeyGen = (A i , MK) to generate the private attribute key For a ij ∈ A i , generate the key component wherein, g is the group generator, H is the hash function, and r is the random value;

[0030] S42: The decryptor inputs the attribute set A i , the private attribute key SK Ai and the ciphertext C. If A i satisfies the access structure T specified by the encryptor during encryption, the session key K = Decrypt(SK Ai , A i , C key ) will be successfully restored, where Decrypt(·) represents the decryption algorithm;

[0031] S43: The decrypting party uses the session key K to decrypt the data ciphertext C data , and recover the traceability information M = D AES (K, C data ), where D AES (·) represents the AES decryption algorithm.

[0032] The beneficial effects of the present invention are as follows: The present invention utilizes attribute-based encryption technology and a dynamic pseudonym mechanism to ensure the identity and data security of entities in the agricultural product supply chain, and solves the trust and privacy problems among entities on the consortium blockchain. The dynamic pseudonym mechanism designed by the present invention can isolate the real identity and the identity of the node on the chain, thereby achieving the purpose of protecting the identity privacy of entities on the chain.

[0033] Other advantages, objectives, and features of the present invention will be described to some extent in the subsequent specification, and to some extent, will be obvious to those skilled in the art based on the study of the following text, or can be taught from the practice of the present invention. The objectives and other advantages of the present invention can be realized and obtained through the following specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be described in preferred detail below in conjunction with the drawings, where:

[0035] Figure 1 is a schematic diagram of the architecture model based on the method of the embodiment of the present invention;

[0036] Figure 2 is the overall flowchart of the privacy protection method for traceability of agricultural product supply chain facing the consortium blockchain provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] The following uses specific specific examples to illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present invention schematically, and the following embodiments and the features in the embodiments can be combined with each other without conflict.

[0038] Please refer to Figures 1 to 2 , the embodiment of the present invention provides a privacy protection method for traceability of agricultural product supply chain facing the consortium blockchain, mainly aiming at the consortium blockchain application of agricultural product supply chain traceability, including participating parties such as supply chain entities, regulatory departments, key management centers (KMCs), and consortium blockchains.

[0039] Supply chain entities are responsible for encrypting and uploading traceability data to the consortium blockchain. Meanwhile, they can initiate traceability requests to trace information of other links in the supply chain.

[0040] Regulatory authorities are responsible for verifying the authenticity and validity of the identities of registrants during the registration phase, ensuring the credibility of the identities of consortium blockchain nodes. Meanwhile, they decrypt and review the traceability data to be uploaded by supply chain entities, ensuring the credibility of the traceability information on the chain.

[0041] The key management center is responsible for uploading static pseudonyms for supply chain entities based on identity information. When a supply chain entity initiates an on-chain transaction request, it generates private attribute keys and dynamic pseudonyms for this transaction according to the transaction attributes provided, enabling on-chain entities to customize decryption attributes and protecting identity privacy and data security.

[0042] This method mainly includes a registration phase, a definition of access structure phase, a data encryption phase, and a data decryption phase.

[0043] (1) Registration phase

[0044] All supply chain entities participating in traceability send their own identity information to the regulatory authorities for review. After the regulatory authorities pass the review, they send the identity information to the key management center. The key management center generates pseudonyms using the received identity information and returns them to the supply chain entities. During the registration phase, the key management center selects the identity information set I i ={I i1 ,I i2 ,…,I in} as input and outputs static pseudonyms P i Then it maintains a pseudonym list {P 1 ,P 2 ,…,P m}.

[0045] A1: Suppose supply chain entity U i has an identity information set I i ={I i1 ,I i2 ,…,I in}, where I ij represents the j-th item of identity information of entity U i and n is the number of information items.

[0046] A2: To ensure the security of identity information during transmission, entity U i will perform a hash operation on its own identity information set. H(·) represents the hash function used, then: H(I i )=H(I i1 ||I i2 …||I in), where || represents the concatenation operation, and the hash value H(I i ) represents the encrypted digest of the entity identity information.

[0047] A3: Entity U i Send the generated hash value H(I i ) to the Key Management Center KMC.

[0048] A4: After the Key Management Center KMC receives the hash value H(I i ), it generates a digital pseudonym P i . The process of generating the digital pseudonym is based on an encryption algorithm or a pseudorandom function. For example, KMC uses the encryption algorithm E k (·) to generate the digital pseudonym: P i = E k (H(I i ))), where k is the private key of the Key Management Center, and P i is the digital pseudonym generated for entity U i .

[0049] A5: To ensure that the digital pseudonyms of each entity are unique in the supply chain, KMC needs to maintain a list of already generated digital pseudonyms {P 1 , P 2 , …, P m}, where m is the current number of generated digital pseudonyms. When generating a new digital pseudonym P i , KMC needs to ensure that: If P i already exists, it needs to be regenerated or appropriately adjusted to ensure uniqueness.

[0050] (2) Defining the access structure phase

[0051] After the supply chain entity successfully registers and joins the consortium chain using a static pseudonym, it sends the attribute set of the current transaction request to the Key Management Center before initiating a request to upload the traceability information to the chain. The Key Management Center takes the attribute set as input, outputs and returns the private attribute key SK Ai , and then the supply chain entity defines an access structure tree and generates a dynamic pseudonym based on SK Ai , and then initiates a request to upload data in the identity of the dynamic pseudonym.

[0052] B1: Assume that the supply chain entity U i needs to upload the traceability information M to the chain and defines an attribute set A i , where: A i = {a i1 , a i2 , …, a in}, and each attribute a ijRepresents a specific attribute of the traceability information M, and n is the number of attributes;

[0053] B2: The system randomly selects a security parameter λ and uses the initialization function Setup(λ) to generate the system public parameter P and the master key MK;

[0054] B3: The KMC is based on U i The provided set of attributes A i , and uses the master key MK and the key generation function KeyGen(A i , MK) to generate the corresponding private attribute key SK Ai ;

[0055] B4: The supply chain entity U i Defines the access structure tree T. In CP-ABE, the access structure T is a logical expression that defines which combinations of attribute sets can satisfy the decryption condition, and can be a combination of logical operations such as AND, OR, etc. This structure specifies which participating parties corresponding to the attribute sets can decrypt the data ciphertext;

[0056] B5: Using a fixed pseudonym to participate in blockchain transactions for a long time may make it easy for attackers to infer the relationship between the pseudonym and the participant's identity information through correlation analysis. To avoid identity information leakage, this solution uses a Merkle hash tree to generate dynamic pseudonyms for participants to conduct activities on the chain. The participants join the consortium chain with their static pseudonyms and conduct various transaction affairs on the chain with their dynamic pseudonyms, preventing attackers from inferring the true identities of the participants through correlation analysis. At the same time, when the participants verify each other's identities, because they use dynamic pseudonyms, even if they know the identity corresponding to the dynamic pseudonym, they will not expose the correspondence between the static pseudonym and the true identity. The supply chain entity takes its own public identity information Uploader, the public identity information Verifier of the regulatory department, the timestamp Timestamp, and the random number Nonce as the leaf nodes of the Merkle tree (for convenience of representation, the above information is represented by d1, d2, d3, d4). First, perform the H(·) hash operation on the leaf nodes to obtain the corresponding hash values H 1 , H 2 , H 3 , H 4 . Then calculate the parent nodes of adjacent leaf nodes: H 1,2 = H(H 1 || H 2 ), H 3,4 = H(H 3 || H 4 ), where || represents the operation of concatenating two hash values. Finally, the root node H root = H(H 1,2 || H3,4 ) The root node is the dynamic pseudonym. Since the timestamp and random number change constantly, each generated pseudonym is different, thus realizing the dynamics of the pseudonym and protecting the identity privacy of supply chain entities.

[0057] (3) Data encryption stage

[0058] After completing the definition of the access structure, the supply chain entity inputs the access structure T, the public parameter P, and the traceability information M to be encrypted, and uses the encryption function Encrypt(T, P, M) to generate the ciphertext C.

[0059] C1: The system selects a random value where p is a large prime number;

[0060] C2: Calculate the session key K = g s , and use symmetric encryption to encrypt the traceability information M to generate the ciphertext segment C data = E AES (K, M), where E AES is the AES symmetric encryption algorithm;

[0061] C3: Use the public parameter P (generated in step B2) and the access structure T (generated in step B4) to encrypt the session key K into the ciphertext segment C key = Encrypt(T, P, K);

[0062] C4: Combine C data with C key to form the ciphertext C = (C data , C key );

[0063] C5: Bind the dynamic pseudonym D (generated in step B5) to the ciphertext C, and the final data packet form is: D set = (C, D).

[0064] D: Data decryption stage

[0065] After the encrypting party completes the encryption of the traceability information, it sends the encrypted information to the regulatory agency for review. The regulatory agency decrypts the information using its own private attribute key, and the traceability information can be uploaded to the chain only after the review work is completed. After the data is uploaded to the chain, supply chain entities with traceability requirements decrypt the data on the chain to view the traceability information of agricultural products in the supply chain.

[0066] D1: The decrypting party provides its own attribute set A i , and the KMC uses the master key MK and the attribute key generation function KeyGen = (A i , MK) to generate the private attribute key For a ij ∈Ai , generate key components where g is a group generator, H is a hash function, and r is a random value;

[0067] D2: The decryptor inputs the attribute set A i , the private attribute key SK Ai , and the ciphertext C. If A i satisfies the access structure T specified by the encryptor during encryption, the session key K = Decrypt(SK Ai , A i , C key ) will be successfully restored;

[0068] D3: The decryptor uses the session key K to decrypt the data ciphertext C data , and restores the traceability information M = D AES (K, C data ).

[0069] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the present technical solution, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A privacy protection method for traceability of agricultural product supply chain in alliance chain, characterized in that: The following phases are included: Registration phase: Supply chain entities participating in traceability register using their own identity information. The key management center generates a pseudonym using the identity information and sends it to the supply chain entity. Access structure definition stage: The supply chain entity sends the attribute set of the traceability information to the key management center, which generates a private attribute key and a dynamic pseudonym for it. The supply chain entity defines the decryption access structure based on the private attribute key. Data encryption stage: Supply chain entities use private attribute keys to encrypt data and send the encryption results and dynamic pseudonyms to regulatory authorities; Data decryption stage: The regulatory authorities decrypt and review the received data, and the supply chain entities upload the encrypted traceability information to the chain. After the data is uploaded to the chain, supply chain entities with traceability needs can view the traceability information of agricultural products in the supply chain by decrypting the on-chain data.

2. The privacy protection method for traceability of agricultural product supply chain in alliance chain according to claim 1 is characterized in that: The registration phase specifically includes: assuming that the supply chain entity U i With identity information set I i = {I i1 ,I i2 ,…,I in }, where I ij Representing entity U i The jth identity information, n is the number of information items; First, the entity U i Perform a hash operation on your identity information set; H(·) represents the hash function used, then: H(I i )=H(I i1 ‖I i2 …‖I in ), where ‖ represents the concatenation operation, and the hash value H(I i ) represents a cryptographic digest of entity identity information; Then, entity U i The generated hash value H(I i ) is sent to the key management center; Finally, the key management center receives the hash value H(I i ), a digital pseudonym P is generated based on the hash value and an encryption algorithm or a pseudo-random function i ; In order to ensure that the digital pseudonym of each entity is unique in the supply chain, the key management center needs to maintain a list of generated digital pseudonyms {P1, P2, ..., P m }, where m is the number of digital pseudonyms currently generated; when a new digital pseudonym P is generated i The key management center needs to ensure If P i If it already exists, it needs to be regenerated or adjusted to ensure uniqueness.

3. The privacy protection method for traceability of agricultural product supply chain in alliance chain according to claim 1 is characterized in that: The access structure definition stage specifically includes: assuming that the supply chain entity U i It is necessary to put the traceability information M on the chain and define the attribute set A for it i , where A i ={a i1 ,a i2 ,…,a in }, each attribute a ij represents a specific attribute of the traceability information M, and n is the number of attributes; First, the system randomly selects a security parameter λ and uses the initialization function Setup(λ) to generate the system public parameter P and the master key MK; Secondly, the key management center is based on U i Provided attribute set A i , using the master key MK and the key generation function KeyGen(A i ,MK) generates the corresponding private attribute key SK Ai ; Then, the supply chain entity U i Define the access structure T. In CP-ABE, the access structure T is a logical expression that defines which combinations of attribute sets can satisfy the decryption conditions. It is a combination of logical operations. The structure specifies which attribute sets correspond to which participants can decrypt the data ciphertext. Finally, the supply chain entity uses its own public identity information d1, the public identity information d2 of the regulatory department, the timestamp d3, and the random number d4 as the leaf nodes of the Merkle tree. First, the leaf nodes are hashed H(·) to obtain the corresponding hash values ​​H1, H2, H3, and H4; then the parent nodes of the adjacent leaf nodes are calculated: H 1,2 =H(H1||H2),H 3,4 =H(H3||H4), where ‖ represents the concatenation of two hash values; finally, the root node H root =H(H 1,2 ||H 3,4 ), the root node is the dynamic pseudonym D.

4. The privacy protection method for alliance chain agricultural product supply chain traceability according to claim 3 is characterized in that: The data encryption stage specifically includes the following steps: S31: System selects a random value in, is the set of integers modulo p, where p is a large prime number; S32: Calculate session key K=g s , use symmetric encryption to encrypt the traceability information M to generate the ciphertext fragment C data =E AES (K,M), where E AES It is AES symmetric encryption algorithm; S33: Use the public parameters P and access structure T generated in the access structure definition phase to encrypt the session key K into the ciphertext fragment C through CP-ABE key =Encrypt(T,P,K); S34: C data With C key Combining into ciphertext C=(C data ,C key ); S35: Bind the dynamic pseudonym D generated in the access structure definition phase to the ciphertext C. The final data packet is in the form of: D set =(C,D).

5. The privacy protection method for traceability of agricultural product supply chain in alliance chain according to claim 4 is characterized in that: The data decryption stage specifically includes the following steps: S41: The decryption party provides its own attribute set A i The key management center uses the master key MK and the attribute key generation function KeyGen = (A i ,MK) Generate private attribute key For a ij ∈A i , generate key components Among them, g is the group generator, H is the hash function, and r is a random value; S42: The decryption party inputs attribute set A i , private attribute key SK Ai and ciphertext C, if A i If the access structure T specified by the encryptor during encryption is satisfied, the session key K = Decrypt(SK Ai ,A i ,C key ), where Decrypt(·) represents a decryption algorithm; S43: The decryption party uses the session key K to decrypt the data ciphertext C data , restore the traceability information M=D AES (K,C data ), where D AES (·) indicates the AES decryption algorithm.

Citation Information

Cited By

  • Attack tracing method and system for optical communication end-to-end data transmission

    CN121907617A