Cooperative generation method of inspection and detection report based on alliance chain
Through the collaborative generation method of inspection and testing reports based on alliance chain and broadcast encryption, the problems of low report generation efficiency, unreliable data and insufficient supervision in multi-organization collaboration are solved, and efficient and secure report generation and supervision are achieved, supporting hierarchical access and privacy protection.
Patent Information
- Application Number
- CN202510613800.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-07-29
AI Technical Summary
The prior art has low collaboration efficiency, unreliable data, insufficient supervision and security risks in the inspection and testing reports collaborated by multi-agency, especially the lack of standardized processes for multi-party collaboration to generate reports, hierarchical access control of privacy data, and the ability of regulators to directly penetrate and decrypt on-chain data.
The coordinated generation and flexible query solution of electronic inspection and detection reports based on alliance chain and broadcast encryption is adopted, including initialization algorithm, user registration algorithm, report generation algorithm, report query algorithm and penetrating supervision algorithm. The improved Byzantine fault tolerance consensus protocol and broadcast encryption algorithm are used to realize multi-party collaborative generation, hierarchical access and penetrating supervision.
It improves the efficiency of the generation of inspection and testing reports, ensures the reliability and security of reports, realizes hierarchical access and privacy protection, supports flexible query and supervision, and reduces communication and computing overhead.
Smart Images

Figure CN120389862A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the fields of blockchain technology and inspection and testing data management, and specifically relates to a method for collaborative generation, flexible query, and penetrative supervision of inspection and testing reports based on consortium blockchain and broadcast encryption technology, which is applicable to the management scenario of electronic inspection and testing reports for multi-institution collaboration. Background Art
[0002] In recent years, with the increasing global emphasis on data assets and their quality, data digitization has become a major trend, and inspection and testing related to electronic data has become an important category of inspection and testing. Although data digitization has improved the efficiency of generating, transmitting, and querying inspection and testing reports, it has not solved the problem of industry collaboration. Instead, it has brought security risks such as data tampering, forgery, and cyberattacks, damaging the reputation of inspection and testing institutions.
[0003] At the same time, blockchain technology, with its characteristics of decentralized / multi-party consistency, immutability, and traceability, has provided new ideas for solving the key problems faced by electronic data by constructing an inspection and testing industry alliance based on blockchain technology, and has significant potential advantages. First, the distributed ledger technology of blockchain can achieve data sharing among multiple parties, improving collaboration efficiency and information transparency. Second, after inspection and testing data is packaged and uploaded to the blockchain, the immutability of the blockchain can enhance the credibility and security of the data, providing guarantee for the authenticity and integrity of inspection and testing results.
[0004] However, existing research has mostly focused on using blockchain technology to achieve the authenticity verification and secure storage of inspection and testing reports, lacking research on the report generation stage and exploration on promoting collaboration among inspection and testing institutions. In addition, in practical applications, there are different security classification levels and data supervision requirements for data recorded on the blockchain, and there is also a lack of corresponding consideration for the flexible access permission control and data supervision issues of inspection and testing reports on the chain.
[0005] The current inspection and testing industry has the following problems: low collaboration efficiency: there is a lack of mutual trust mechanism among institutions, resulting in a long report generation cycle and a high repeated detection rate. Unreliable data: traditional electronic reports are easily tampered with and lack a multi-party verification mechanism, affecting data credibility. Insufficient supervision: existing technologies are difficult to achieve real-time penetrative supervision of data on the chain, and the authorization management of private data is not flexible. Security risks: traditional encryption technologies cannot meet the hierarchical access requirements, and the mixed storage of public and private data is vulnerable to attacks. Existing solutions mostly focus on the anti-counterfeiting and deposit of blockchain (such as QR code verification), but have the following deficiencies: they do not solve the standardized process for multi-party collaborative report generation; lack a hierarchical authorization access mechanism for private data; and cannot achieve direct penetrative decryption of data on the chain by regulatory agencies. Summary of the Invention
[0006] In response to the problems pointed out in the above background technology, the present invention aims to simultaneously solve the challenging issues of report reliability, consistent generation of reports from multiple parties, data privacy of inspection and testing reports, and penetrable supervision in the electronic inspection and testing report scenario. The present invention proposes a collaborative generation and flexible query solution for electronic inspection and testing reports based on alliance chain and broadcast encryption. The solution specifically includes six algorithms: initialization algorithm, user registration algorithm, report generation algorithm, report query algorithm, and penetrating supervision algorithm.
[0007] (1) Initialization algorithm: 1. Generate initial protocol parameters: Run Setup(1 ksig ) algorithm and disclose public parameters; 2. Each inspection and testing organization generates a public-private key pair; 3. Generate a public-private key pair; 4. Generate initialization parameters for the inspection and testing alliance.
[0008] (2) User registration algorithm: The user prepares the identity information data for registration, and the identity manager runs KeyGen(pp sig ) algorithm to generate signature public and private keys for users and store user-related information in the database; the identity manager generates identity credentials for users and runs the digital signature algorithm to generate signature σ IM =Sign(sk IM ,(CR,pk U )), the message <CR,pk U > σIM and sk U Sent to the user to complete the registration.
[0009] (3) Report generation algorithm: It is divided into five stages: request stage, pre-preparation stage, preparation stage, submission stage, and reply stage:
[0010] 1. User request stage: The user sends a test request to the leading inspection and testing agency.
[0011] 2. Pre-preparation stage: The leading inspection and testing organization generates an inspection and testing report proposal and forwards the proposal and relevant data to other inspection and testing organizations in the inspection and testing alliance;
[0012] 3. Preparation stage: The inspection and testing agency verifies and forwards the proposal of the leading inspection and testing agency:
[0013] 4. Submission stage: The inspection and testing agency verifies whether the proposal of the lead inspection and testing agency can be accepted:
[0014] 5. Response stage: The leading inspection and testing agency returns the report generation results to the user.
[0015] (4) Report query algorithm: The inspection and testing report is divided into a public part and a privacy part. The public part can be read by any report query user who can access the report chain, while the privacy part requires the report query user to interact with any member of the inspection and testing alliance participating in the report generation. The query method for the privacy report is as follows:
[0016] 1. For the query of the privacy part of the report, after the user pays the query fee, the data required for the query is given to any inspection and testing institution participating in the report generation;
[0017] 2. The inspection and testing institution queries and obtains the data on the chain through the data sent by the user and parses it;
[0018] 3. The inspection and testing institution restores its own decryption private key locally through the data sent by the user, and decrypts the privacy report with the decryption private key
[0019] 4. The inspection and testing institution sends the decrypted privacy report to the user, and the user completes the report query.
[0020] (5) Penetrating supervision algorithm: The supervisor obtains the relevant information of the inspection and testing report by accessing the inspection and testing report on the blockchain; the supervisor calculates the supervision key; the inspection and testing institution runs the symmetric encryption algorithm to decrypt the ciphertext in the inspection and testing report.
[0021] Advantages of the present invention:
[0022] This method realizes for the first time the collaborative generation of electronic inspection and testing reports by multiple members in the inspection and testing alliance, the flexible query of the reports on the chain by users, and the penetrating supervision of the reports on the chain. It solves the problems of low multi-party collaboration efficiency, unreliable data, insufficient supervision, etc., and at the same time realizes the hierarchical access and secure storage of data. The specific effects are as follows:
[0023] 1. By adopting an improved Practical Byzantine Fault Tolerance (PBFT) consensus protocol, a collaborative generation mechanism among multiple inspection and testing institutions based on the consortium chain is formed, reducing communication overhead. The computing and communication overhead are reduced by more than 30% compared with the traditional method, realizing efficient collaboration. Through the distributed ledger technology of the blockchain, reliable storage and distribution of reports are ensured.
[0024] 2. By adopting an improved broadcast encryption algorithm, hierarchical access and privacy protection are realized: the report is divided into a public part and a privacy part. The public part can be freely queried, and the privacy part supports authorized access to ensure the security of privacy data.
[0025] 3. The supervisor can directly decrypt the privacy part of the report on the chain to realize penetrating supervision.
[0026] 4. Improve the existing bilinear pairing-based broadcast encryption algorithm to ensure semantic security, and combine it with the revised practical Byzantine fault tolerance consensus protocol to enhance the reliability and efficiency of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 The entity structure of the inspection and detection scenario of the method of the present invention.
[0028] Figure 2 The report chain structure of the method of the present invention.
[0029] Figure 3 The flowchart of the report production in which the algorithm of the method of the present invention participates. DETAILED DESCRIPTION OF THE INVENTION
[0030] In the scenario of collaborative generation and flexible query of inspection and detection reports based on blockchain, it consists of three types of entities: users, government departments, and alliances of inspection and detection institutions. Among them, users include report requesters and report queryers, and government departments include identity managers and supervisors. The structure of the entities in the scenario is as Figure 1 shown, and the definitions of each member are as follows:
[0031] 1. Identity manager: Responsible for the identity management of protocol participants. Generally, the identity manager completes the identity management of all parties participating in the protocol based on the public key infrastructure (PKI, Public Key Infrastructure). Specifically, all parties participating in the protocol obtain their own public-private key pairs by registering with the identity manager; and they can obtain the public keys of other participating members by obtaining the certificates of other participating members.
[0032] 2. Supervisor: Has the right to conduct penetrative supervision on inspection and detection reports on the chain. Specifically, after the supervisor obtains any inspection and detection report that has reached consensus from the inspection and detection report chain, it can directly decrypt the privacy part of the inspection and detection report to implement penetrative supervision.
[0033] 3. Alliance of inspection and detection institutions: An alliance composed of multiple inspection and detection institutions. Each inspection and detection institution has the ability to complete inspection and detection and generate inspection and detection reports. The inspection and detection alliance formed by multiple inspection and detection institutions outputs a blockchain externally to record the inspection and detection reports that have obtained the consensus of the members, also known as valid inspection and detection reports.
[0034] 4. Report requester: The user who initiates a request for generating an inspection and testing report to the inspection and testing alliance, such as an enterprise that needs to prove the qualification of the products produced. First, the report requester interacts with the identity manager to complete registration and obtain their public key certificate. After the report requester successfully registers, they can initiate an inspection and testing request to the inspection and testing agency alliance and submit relevant inspection and testing data. The report requester can pay to complete the consensus on-chain of the electronic inspection and testing report and obtain relevant on-chain information of the electronic inspection and testing report.
[0035] 5. Report querier: The user who requests to view the inspection and testing report, usually an individual who hopes to verify whether a product, service, or environment is qualified. The report querier can query the corresponding inspection and testing report on the report chain through the on-chain information of the report presented by the report requester and directly read the public part of the inspection and testing report. If the report requester needs to obtain the private part of the inspection and testing report, the report querier can interact with any inspection and testing agency participating in the report generation (such as paying) to open the private data of the inspection and testing report.
[0036] To form Figure 1 the inspection and testing report chain in
[0037] In the public report chain released by the inspection and testing alliance, each block contains a series of inspection and testing reports recognized by the inspection and testing alliance. Each inspection and testing report on the inspection and testing report chain is also called a record, and each record includes a public part and a private part. Anyone who can access the report chain can read the public part of the record; if they need to read the private part of the record, they need to interact with the inspection and testing agency according to the protocol.
[0038] The report chain adopts a transaction organization form based on a secure hash function and uses a Merkle Tree to hierarchically organize transactions. The consensus protocol can ensure that any record on the report chain is immutable. The structure of the report chain is as Figure 2 shown.
[0039] The method for collaborative generation and flexible query of inspection and testing reports based on blockchain consists of six algorithms: initialization algorithm, user registration algorithm, report generation algorithm, report consensus on-chain algorithm, report query algorithm, and penetrative supervision algorithm.
[0040] (1) Initialization algorithm
[0041] This algorithm is run by the identity manager, and its main function is to determine the public keys of the members of the inspection and testing institution alliance and the supervisor, and to generate the public parameters of the protocol. The specific steps are as follows:
[0042] 1. Generate the initial parameters of the protocol: Run the algorithm and publicly disclose pp sig .
[0043] 2. Each (assuming there are n - 1 in total) inspection and testing institution generates a public-private key pair: Let all inspection and testing institutions form a set S' = {T1, T2,..., T n-1}, and the identity manager runs the KeyGen(pp i ) algorithm for each T sig (i ∈ {1, 2,..., n - 1}) to generate and return
[0044] 3. Generate a public-private key pair: The identity manager runs the KeyGen(pp sig ) algorithm to generate and return (pk IM , sk IM ).
[0045] Let the supervisor be SP, and use S = {T1, T2,..., T n-1 , SP} to represent the set of inspection and testing institutions and the supervisor in the following text, and |S| = n.
[0046] 4. Generate the initialization parameters for the inspection and testing alliance: The identity manager initializes the broadcast encryption parameters in the set. Since traditional broadcast encryption algorithms do not support penetrative supervision, the BGW broadcast encryption algorithm needs to be modified. The process of the new broadcast encryption initialization algorithm is as follows:
[0047] a) The identity manager selects multiplicative cyclic groups G and G1 of prime order p, and let e: G × G → G1 be a bilinear mapping.
[0048] b) The identity manager selects a random generator g ∈ G and a random number α ∈ Z p , and let
[0049]
[0050] where i ∈ {1, 2,..., n, n + 2,..., 2n}. The identity manager selects a random number γ, calculates ν = g γ ∈ G, generates the broadcast encryption public key PK = (g, g1,..., g n , g n+2 ,..., g 2n , ν) ∈ G 2n+1 , and for the member T iPrivate key where \(i\in\{1,2,\cdots,n - 1\}\). And generate the private key of the supervisor SP
[0051] c) The identity manager calculates \(e(g n+1 ,g)\) and stores the result in the system
[0052] (2) User registration algorithm
[0053] The user prepares the identity information data D for registration ri , and submits the identity information data to the identity manager to initiate a registration application. The identity manager runs the KeyGen(pp sig ) algorithm to generate the signature public and private keys \((pk U ,sk U ) for the user, and stores the user-related information in the database. The identity manager generates the identity credential CR=(D ri ,pk U ), and runs the digital signature Sign algorithm to generate the signature \(\sigma IM = Sign(sk IM ,(CR,pk U )), and sends the message and sk U to the user to complete the registration
[0054] It should be noted that based on the PKI setting widely used in the consortium blockchain, members in the protocol can obtain the public keys of other members in the form of certificates. For example, any inspection and testing institution can obtain the public key information of other inspection and testing institutions, users, supervisors and other members
[0055] (3) Report generation algorithm
[0056] The report generation method proposed by this method is based on the PBFT consensus protocol. Based on the report generation process shown in Figure 3 , it is divided into five stages: request stage, pre-preparation stage, preparation stage, submission stage, and reply stage. The set of inspection and testing institutions participating in generating a report is denoted as Use view to mark the current view. Let \(L(L\in S*)\) represent the leader node of the PBFT protocol under the current view, also known as the leading inspection and testing institution; and use \(T others to represent the set of non-leader (Replica) nodes of the PBFT protocol under the current view, that is, \(T others = S* - L. We define the number of dishonest inspection and testing institutions in the set S* as f, and \(|S*|\geq3f + 1\). Then the inspection and testing institutions return the inspection and testing report to the user U in the following order
[0057] 1. User Request Phase: In this phase, the user sends a detection request to the leading inspection and testing agency.
[0058] 1) The user generates request information <REQUEST, CR, TS, D ins >, where TS is the current timestamp and D ins is the original data to be detected. The user runs the digital signature Sign algorithm to generate a signature After generating the signature, the user sends a request message to the leading inspection and testing agency
[0059] 2) The leading inspection and testing agency receives the request message and verifies whether the signature and the identity credential CR are valid, and whether the timestamp TS is valid. If the verification passes, it enters the pre - preparation phase.
[0060] 2. Pre - preparation Phase: In this phase, the leading inspection and testing agency L generates a proposal for the inspection and testing report and forwards the proposal and related data to other inspection and testing agencies in the inspection and testing alliance.
[0061] 1) The leading inspection and testing agency L marks the sequence number of this report request as vn according to the member set S* and its view number view generated by the current report.
[0062] 2) The leading inspection and testing agency detects the original data D ins , generates the original text of the inspection and testing report check(D ins ) = <m0, m1> = M, where m0 is the original text of the publicly available part of the report and m1 is the original text of the private part of the report.
[0063] 3) The leading inspection and testing agency L randomly selects a random number t in Z p , generates the key k = e(g n+1 , g) t ∈ G1
[0064] Then calculate
[0065] Subsequently, the leading inspection and testing agency L selects a random number r and runs the symmetric encryption algorithm to encrypt the original data m1, generating the ciphertext Generates the inspection and testing report M' = <m0, c>. And generates the proposal data D for the inspection and testing report re = (M, M', Hdr, D ins ).
[0066] 4) The leading inspection and testing agency L generates pre - preparation information <PRE - PREPARE, view, vn, D re>, run the digital signature Sign algorithm to generate a signature where represents the private key of the leading inspection and testing institution, and l is the serial number of the leading inspection and testing institution. The leading inspection and testing institution L generates a signature and broadcasts a pre-prepare message to all other inspection and testing institutions T ∈ T in S* others Broadcast the pre-prepare message
[0067] 5) After receiving a pre-prepare message, the inspection and testing institution performs the following verifications
[0068] A) Whether the signature in the message is a valid signature belonging to the leading inspection and testing institution L
[0069] B) Whether view is the current view and whether other views view have been received
[0070] C) The request serial number vn is consistent
[0071] D) Parse D re , D re =(M, M', Hdr, D ins )=(<m0, m1>, <m0, c>, (C0, C1, C2), D ins )
[0072] Subsequently, verify
[0073] a) M is a valid inspection and testing report for D ins
[0074] b) Verify the bilinear pairing
[0075] Whether it holds. If the result is 1, it means that this report has penetrative supervision
[0076] c) Calculate
[0077] where, assume i is the serial number of the inspection and testing institution T
[0078] d) Verify the consistency between the encrypted inspection and testing report and the original inspection and testing report: Run the symmetric decryption algorithm and obtain m1'. If m1' = m1, and the inspection and testing institution agrees that the original inspection and testing report M is a qualified inspection and testing report for user data
[0079] If all the above verifications pass, locally record this pre-prepare message
[0080] 6) When the inspection and testing institution T records at least 2f + 1 from different T' ∈ T others After the pre-prepare message, generate the message <PREPARE, view, vn, D re , T>.
[0081] 3. Preparation stage: In this stage, the inspection and testing agency T ∈ T others verifies and forwards the proposal of the leading inspection and testing agency, so as to ensure that honest inspection and testing agencies can reach an agreement on valid proposals.
[0082] 1) The inspection and testing agency runs the digital signature Sign algorithm to generate a signature
[0083] 2) After generating the signature, the inspection and testing agency broadcasts the prepare message to all other inspection and testing agencies
[0084]
[0085] 3) When the inspection and testing agency T receives the prepare message sent by other inspection and testing agencies, it performs the following operations
[0086] A) Verify whether the signature of the received prepare message is correct.
[0087] B) Verify whether the data in the received prepare message is consistent with the data in other prepare messages.
[0088] C) Verify whether the data in the received prepare message is consistent with the pre-prepare message received in the pre-preparation stage.
[0089] If all the above verifications pass, locally record this prepare message.
[0090] 4) When the inspection and testing agency T receives at least 2f + 1 prepare messages from different T' ∈ T others after that, generate the message <COMMIT, view, vn, D pre , T>, where D pre = (M', Hdr).
[0091] 4. Submission stage: In this stage, the inspection and testing agency verifies whether it can agree with the proposal of the leading inspection and testing agency.
[0092] 1) The inspection and testing agency T runs the digital signature Sign algorithm to generate a signature
[0093] 2) After generating the signature, the inspection and testing agency sends the commit message commit to the leading inspection and testing agency L:
[0094]
[0095] 5. Reply stage: In this stage, the leading inspection and testing institution L returns the report generation result to the user.
[0096] 1) If the leading inspection and testing institution L receives no less than 2|S*| / 3 valid commit messages (i.e., verifiable signatures) including itself within the specified time, it is considered that the group S* has reached an agreement, that is, the inspection and testing report M' is the result jointly recognized by the group S*, and the inspection and testing report is successfully generated. The leading inspection and testing institution L prepares to reply to the user
[0097] A) Package (M', Hdr) and all valid commits into a transaction and include it in the next block, and record the corresponding record information as D bc 。
[0098] B) The leading inspection and testing institution L generates a successful reply message <REPLY, vn, TS, D bc >, runs the digital signature Sign algorithm to generate a signature
[0099] C) Send a return reply message to the user:
[0100] 2) If the leading inspection and testing institution does not receive enough submission information within the specified time, it is considered that the report generation fails.
[0101] A) The leading inspection and testing institution L generates a failed reply message <REPLY, vn, TS, error>, runs the digital signature Sign algorithm to generate a signature
[0102] B) Send a return reply message to the user:
[0103] (4) Report query algorithm
[0104] The inspection and testing report is divided into a public part and a private part. The public part can be read by any report queryer who can access the report chain, and the private part requires the report queryer to interact with any inspection and testing alliance member participating in the report generation. The following focuses on the query method of the private report:
[0105] 1. For the query of the private part of the report, after the user pays the query fee, the required query data D bc is given to any inspection and testing institution T q ∈S*.
[0106] 2. The inspection and testing institution T qData D sent by the user bc Query and obtain the on-chain data (M', Hdr), and parse it into (<m0, c>, (C0, C1, C2)).
[0107] 3. Inspection and testing institution T q Through the data D sent by the user bc Locally recover its own decryption private key d q , and decrypt the privacy report with the decryption private key:
[0108]
[0109] 4. T q Send m q to the user. The user has completed the query of the report.
[0110] Among them, the correctness verification process of the calculation algorithm of the key k q is as follows:
[0111]
[0112] It is shown by calculation that for any inspection and testing institution T q ∈S*, can calculate Therefore, the key calculated by any inspection and testing institution participating in the report generation with its own private key is k q = k, that is, the inspection and testing institution can recover the key for correctly decrypting the ciphertext, thus verifying the correctness of the report decryption algorithm. The correctness of the algorithm ensures that m q = m1.
[0113] (5) Penetrating supervision algorithm
[0114] The method hopes to achieve the penetrating supervision of the supervisor, and the supervisor has the access right to decrypt any privacy part of the inspection and testing report. The specific process is as follows:
[0115] 1. The supervisor obtains the relevant information M’, Hdr of the inspection and testing report by accessing the inspection and testing report on the blockchain.
[0116] 2. The supervisor calculates
[0117] k n = e(g n , C2) / e(d n , C0)
[0118] 3. The inspection and testing institution runs the symmetric encryption algorithm to decrypt c in the inspection and testing report M’
[0119]
[0120] Among them, the calculation algorithm and verification process of the supervision key are as follows:
[0121]
[0122] The above calculation shows that for the regulatory agency, e(g n , C2) / e(d n , C0) can calculate Therefore, the supervisor can calculate the supervision key through its own private key, that is, the supervisor can recover the correct key for decrypting the ciphertext, thus verifying the correctness of the penetration supervision algorithm.
[0123] By improving the broadcast encryption and adding the verification of bilinear pairing by other consensus nodes in the consensus process, it is ensured that m1” = m1. Therefore, the supervisor can recover the original text of the inspection and testing report to achieve penetration supervision.
[0124] Security Analysis
[0125] In the scenario of this method, some dishonest behaviors may be encountered: including dishonest inspection and testing institutions attempting to evade supervision, unauthorized users accessing the confidentiality of reports, and malicious users attempting to tamper with the reliability of inspection and testing reports. Specifically,
[0126] 1) The attacker of the supervision evasion attack is the leading inspection and testing institution participating in the report generation. When generating a proposal for an inspection and testing report, it may attempt not to grant the inspection and testing institution the decryption permission for the privacy part of the broadcast encryption, thus attempting to evade the supervision of the supervisor when generating an inspection and testing report.
[0127] 2) The attacker of the report confidentiality attack is a user who has not had a designated interaction with the inspection and testing institution and attempts to obtain the original text of the privacy part from the encrypted inspection and testing report.
[0128] 3) The attacker of the report reliability is any entity that attempts to affect the authorized access of users to data on the chain and attempts to modify the report on the chain. This includes both the forgery of reports by nodes participating in the report generation and the forgery and tampering of generated inspection and testing reports by external entities.
[0129] To prove that this method can resist the above attacks, the security attributes required by the method are defined and analyzed one by one. The method security attributes include penetration supervision, confidentiality of reports to unauthorized parties, report accessibility to authorized parties, and report credibility. Among them, report accessibility and report credibility jointly ensure the reliability of the report. If the method satisfies penetration supervision, confidentiality of reports to unauthorized parties, report accessibility to authorized parties, and report credibility, then this method is considered secure.
[0130] Property 1. Penetrating supervision. This property requires that if the inspection and testing report proposal generated by the leading inspection and testing institution lacks correct supervision information, the probability of successful generation of this report is 0.
[0131] Proof: The successful generation of an inspection and testing report means that the inspection and testing report is successfully chained. That is, we need to prove that the probability that any chained inspection and testing report cannot be opened by the regulatory agency is 0. We prove this property by contradiction.
[0132] Before the inspection and testing report is chained, it needs to go through a consensus process initiated by the leader. During this process, according to the security assumptions of the Byzantine fault tolerance protocol, the vast majority (≥2 / 3) of the consensus participants are honest nodes. When an honest inspection and testing institution executes the pre-preparation stage of report generation, a series of verifications will be carried out in step 5) of the 2. pre-preparation stage in the (3) report generation algorithm. Among them, the bilinear pairing verification in step D)-b) of step 5) based on our improved BGW broadcast encryption ensures the penetrating supervision.
[0133] Specifically, assume that a dishonest leading inspection and testing institution generates an inspection and testing report that evades supervision, that is, when generating D re =(M,M',Hdr,D ins )=(<m0,m1>,<m0,c>,(C0,C1,C2),D ins ), the C2 part in Hdr is maliciously modified, denoted as Hdr'=(C0,C1,C2'), with the aim of preventing the regulatory agency from decrypting m1 using C2'. Since the improved BGW broadcast protocol can be regarded as a cascaded BGW protocol, by means of common hybrid proof techniques, the security of the improved BGW broadcast protocol is also based on the decisional BDHE problem. That is, C2' cannot pass the verification of the bilinear pairing e(ν·∏ j∈S* g n+1-j ,C2)=e(C1,ν·g1). Therefore, an honest inspection and testing institution node cannot pass the verification of this D re . And because the number of honest inspection and testing institution nodes is at least 2f + 1. Therefore, in this case, honest inspection and testing institution nodes cannot collect enough pre-prepare information in step 6) of the pre-preparation stage, and the consensus protocol cannot reach an agreement. According to our protocol design, in the reply stage, the leading inspection and testing institution cannot chain an inspection and testing report that has obtained the recognition of enough inspection and testing institutions. This contradicts the assumption that there is an unregulated inspection and testing report on the chain. Q.E.D.
[0134] Property 2. Confidentiality of the report for unauthorized users. This property requires that the probability that an unauthorized entity can obtain the original data of the private part of the report is negligible.
[0135] Proof: For unauthorized users, the on-chain inspection and testing report that can be obtained is (M', Hdr) = (<m0, c>, (C0, C1, C2)). If an unauthorized user can decrypt c and obtain the private part m1 of the inspection and testing report, then the unauthorized user either directly derives m1 from c or obtains the decryption key k for decrypting c from Hdr. We use proof by contradiction to show that both are impossible.
[0136] 1) If an unauthorized user directly derives m1 from c, it means that the unauthorized user has broken the CCA2 security of the symmetric encryption algorithm used, that is, this user can be used as a subroutine to attack the CCA2 property of the symmetric encryption. This contradicts the fact that we use a CCA2-secure symmetric encryption algorithm.
[0137] 2) If an unauthorized user obtains the decryption key k for decrypting c from Hdr, it means that the unauthorized user has broken the semantic security of the improved BGW protocol, that is, this user can be used as a subroutine to act as an unauthorized user of the broadcast encryption algorithm and obtain the plaintext corresponding to the ciphertext of the broadcast encryption. This contradicts the fact that the improved BGW protocol has semantic security.
[0138] Property 3. Report accessibility for authorized users. This property requires that users who have obtained authorization after a specified interaction with the inspection and testing agency can successfully obtain the original data of the private part of the report.
[0139] Proof: For authorized users, the on-chain report data they can directly obtain is (M', Hdr) = (<m0, c>, (C0, C1, C2)). At the same time, authorized users can interact with any inspection and testing agency participating in the report generation and obtain m1 from the inspection and testing agency. This requires that the inspection and testing agencies participating in the report generation must be able to recover the correct m1. Since the correctness of the decryption algorithm of the inspection and testing agency is verified in our query of the report 4, that is, any inspection and testing agency participating in the report generation can recover the correct key for decrypting the ciphertext through its own private key, the correctness of the algorithm guarantees that m q = m1. Thus, the correctness of the algorithm guarantees the report accessibility for authorized users.
[0140] Property 4. Report credibility. This property requires that if there are errors or forged unreliable information in the content of the inspection and testing report, the probability of successful generation of this report is 0, and at the same time, the probability of being tampered with after the successful public release of the report is 0.
[0141] Proof: Our definition of the credibility of a report consists of two aspects. One is the reliability of the report, that is, if the content of the inspection and testing report is unreliable, the probability of the inspection and testing report being successfully uploaded to the chain is 0. The other is the immutability of the report. After the inspection and testing report is successfully uploaded to the chain, the probability of being tampered with is 0. When both the reliability of the report and the immutability of the report are satisfied, we believe that the credibility of the report is achieved.
[0142] Similarly, before the inspection and testing report is uploaded to the chain, it needs to go through a consensus process initiated by the leader, assuming that the vast majority (≥2 / 3) of the consensus participants are honest nodes. When an honest inspection and testing agency executes the pre-preparation stage, a series of verifications will be carried out in step 5). Among them, step D)-d) based on our improved BGW broadcast encryption ensures the reliability of the report. Suppose a dishonest leading inspection and testing agency generates an unreliable inspection and testing report, which includes two cases, that is, when generating D re =(M, M', Hdr, D ins )=(<m0, m1>, <m0, c>, (C0, C1, C2), D ins ), one is that the content of the original inspection and testing report M is incorrect; the other is that the ciphertext c of the privacy part in the encrypted inspection and testing report M' does not correspond to the original text m1 of the privacy part in the original inspection and testing report M. Such an unreliable inspection and testing report cannot pass the verification of this by honest inspection and testing agency nodes in step D)-d). And because the number of honest inspection and testing agency nodes is at least 2f + 1. Therefore, in this case, honest inspection and testing agency nodes cannot collect enough pre-prepare information in the pre-preparation stage - 6), and the consensus protocol cannot reach an agreement. According to the protocol design, in the reply stage, the leading inspection and testing agency cannot upload the inspection and testing report that has obtained the recognition of enough inspection and testing agencies to the chain. This contradicts the assumption that there is an unreliable inspection and testing report on the chain.
[0143] If a malicious node successfully tampers with an inspection and testing report that has been successfully generated, that is, tampers with the data on the chain, it means that the malicious node has destroyed the chain structure of the report chain without being discovered by other nodes. This contradicts the public verifiability and immutability of the blockchain. Therefore, we believe that the public verifiability and immutability of the blockchain guarantee the immutability of the report. Q.E.D.
[0144] Performance Analysis
[0145] Regarding the computational overhead, this method reflects the computational overhead of the method by analyzing the computational complexity of each algorithm. Define λ and λ1 as the single-group multiplication operations on the bilinear groups G and G1 respectively, λ 3 and λ1 3Is the corresponding exponential operation. Define e as a single pairing operation. We define that in the process of generating the inspection and testing report, the number of participating nodes is 3f + 1, that is, the minimum scale to successfully complete the consensus, where the number of Byzantine nodes is f, that is, the maximum scale of the number of dishonest nodes.
[0146] 1) Report generation
[0147] a) In the pre-preparation stage of generating the inspection and testing report, the leading inspection and testing agency L needs to randomly select a random number t in Z p and generate the key k = e(g n+1 , g) t ∈ G1, and the operation requires 1 exponential operation on a group G; when calculating Hdr = (g t , (ν · Π j∈S * g n+1-j ), (ν · g1) t ), the operation requires |S*| - 1 multiplication operations on a group, 1 exponential operation on a group G, and 2 exponential operations on a group G1. Therefore, the computational overhead required for the leading inspection and testing agency to generate the inspection and testing report proposal: C1 = (|S*| - 1) · λ + λ t + 3λ1 3 3
[0148] b) After the inspection and testing agency T receives the pre-prepare message pre-prepare from the leading inspection and testing agency L, it verifies its content. First, the inspection and testing agency verifies the bilinear pairing e(ν · Π j∈S * g n+1-j , C2) = e(C1, ν · g1), and the operation requires |S*| + 1 multiplication operations on G and 2 pairing operations; secondly, calculate where i is the serial number of the inspection and testing agency T, and the operation requires |S*| - 1 multiplication operations on G and 2 pairing operations. And at least 2f + 1 inspection and testing agencies need to perform the above operations. Therefore, the overhead required for the inspection and testing agency to verify the report proposal:
[0149] C2 = (2|S*| · λ + 4e) · (2f + 1)
[0150] From this, the computational overhead of the inspection and testing report generation step can be obtained:
[0151] C rg = C1 + C2 = ((4f + 3) · |S*| - 1) · λ + λ 3 + 3λ1 3 + (8f + 4) · e
[0152] 2) Report privacy part query
[0153] In the report query algorithm, the user applies for a query by specifying an interaction to the inspection and testing institution T q and needs the inspection and testing institution T q to recover the key for decrypting the report. The operation of the inspection and testing institution's calculation requires |S*| + 1 multiplication operations on G and 2 pairing operations. Therefore, the cost required for querying the report privacy part is
[0154] C ri =(|S*| + 1)·λ + 2e
[0155] 3) Penetrating supervision
[0156] In the penetrating supervision algorithm, the supervisor hopes to recover the original text of the report privacy part. The supervisor calculates k n =e(g n , C2) / e(d n , C0), and the operation requires 2 pairing operations. Therefore, the cost required for penetrating supervision is
[0157] C ps =2e
[0158] After analysis, the corresponding computational complexities of each stage are shown in Table 1
[0159] Table 1 Computational costs
[0160]
[0161] The communication cost refers to the total communication volume between network nodes during a complete algorithm execution. In the process of generating an inspection and testing report, the number of participating nodes is defined as 3f + 1, which is the minimum scale for successfully completing consensus, where the number of Byzantine nodes is f, which is the maximum scale of dishonest nodes
[0162] The consensus communication times for report generation in our method are shown in Table 2
[0163] Table 2 Communication times
[0164]
[0165] This method adopts an improved Byzantine fault-tolerant consensus protocol and an improved broadcast encryption algorithm, achieving efficient collaboration among multiple inspection and testing institutions, ensuring the reliability of inspection and testing reports, and realizing penetrative supervision. In addition, this method supports hierarchical access to inspection and testing reports: the public part can be freely queried, while the privacy part supports both authorized access and authorized supervision. Thus, while ensuring data security and privacy protection, the usability of the reports is improved. Security analysis verifies that the method has penetrative supervisability, report confidentiality for unauthorized users, and report reliability, etc. Performance analysis shows that this method has low computational and communication overheads.
Claims
1. A collaborative generation method for inspection and testing reports based on a consortium blockchain, characterized by including six algorithms: an initialization algorithm, a user registration algorithm, a report generation algorithm, a report query algorithm, and a penetrative supervision algorithm: (1) The specific steps of the initialization algorithm are as follows:
1. Generate protocol initial parameters: Run the algorithm and publish pp sig ; 2. Each (assume there are n - 1 in total) inspection and testing agency generates a public-private key pair: Assume that all inspection and testing agencies form a set S' = {T1, T2,..., T n-1}, and the identity manager runs the KeyGen(pp i )(i ∈ {1, 2,..., n - 1}) algorithm for each T sig and generates and returns 3. Generate public and private key pairs: The identity manager runs the KeyGen(pp sig ) algorithm to generate and return (pk IM , sk IM ); Assume the supervisor is SP, and use S = {T1, T2,..., T n-1 , SP} to represent the set of inspection and testing institutions and supervisors, and |S| = n; 4. Generate initialization parameters for the inspection and testing alliance: The identity manager initializes the broadcast encryption parameters in the set: a) The identity manager selects multiplicative cyclic groups G and G1 of prime order p, and lets e: G×G→G1 be a bilinear mapping; b) The identity manager selects a randomly generated element \(g\in G\) and a random number \(\alpha\in Z\). p Let where \(i\in\{1,2,\ldots,n,n + 2,\ldots,2n\}\); the identity manager selects a random number \(\gamma\), computes \(\nu = g γ \in G\), generates the broadcast encryption public key \(PK=(g,g_1,\ldots,g n ,g n+2 ,\ldots,g 2n ,\nu)\in G 2n+1 , and for each member \(T i \) of the set \(S\), the private key \(d i = g i γ \in G\), where \(i\in\{1,2,\ldots,n - 1\}\); and generates the private key \(d n \) of the supervisor \(SP\) as \(d n γ \in G\). c) The identity manager calculates e(g n+1 , g), and stores the result in the system; (2) User registration algorithm: The user prepares the identity information data D for registration ri , and the identity manager runs the KeyGen(pp sig ) algorithm to generate the signature public and private keys (pk U , sk U ) for the user, and stores the user-related information in the database; The identity manager generates an identity credential CR=(D ri , pk U ) for the user, and runs the digital signature Sign algorithm to generate a signature σ IM = Sign(sk IM , (CR, pk U )), sends the message and sk U to the user to complete the registration; (3) Report generation algorithm: It is divided into five stages: request stage, pre-preparation stage, preparation stage, submission stage, and response stage. The set of inspection and testing institutions involved in generating a report is represented as Mark the current view with view; Let \(L (L\in S^{*})\) represent the leader node of the PBFT protocol in the current view, also known as the leader inspection and testing agency; and let \(T\) others represent the set of non - leader nodes of the PBFT protocol in the current view, that is, \(T\) others \(= S^{*}-L\); Define the number of dishonest inspection and testing agencies in the set \(s\) * as \(f\), and \(|S^{*}|\geq3f + 1\); Then the inspection and testing agencies return inspection and testing reports to the user \(U\) in the following order:
1. User request phase: In this phase, the user sends a detection request to the leading inspection and testing agency; a) The user generates request information <REQUEST, CR, TS, D ins >, where TS is the current timestamp, and D ins is the original data to be detected. The user runs the digital signature Sign algorithm to generate a signature After the user generates the signature, the user sends a request message to the leader inspection and testing agency b) The leading inspection and testing institution receives the request message and verifies the signature and whether the identity credential CR is valid and whether the timestamp TS is valid. If the verification passes, it enters the pre-preparation stage; 2. Preparatory phase: In this phase, the leading inspection and testing agency L generates an inspection and testing report proposal and forwards the proposal and related data to other inspection and testing agencies in the inspection and testing alliance; a) The set s of members generated by the leading inspection and testing agency L based on the current report * and its view number view, mark the serial number of this report request as vn; b) Lead the inspection and testing institution to detect the original data D ins , generate the original text of the inspection and testing report check(D ins ) = <m0, m1> = M, where m0 is the original text of the publicly available part of the report, and m1 is the original text of the private part of the report; c) Leading the inspection and testing institution L in Z p Randomly select a random number t in n+1 , and generate a key k = e(g t ∈ G1 Then calculate: Subsequently, the leading inspection and testing institution L selects a random number r and runs a symmetric encryption algorithm to encrypt the original data m1 and generate a ciphertext Generate an inspection and testing report M' = <m0, c>; and generate inspection and testing report proposal data D re = (M, M', Hdr, D ins ); d) The leading inspection and testing institution L generates pre-preparation information <PRE-PREPARE, view, vn, D re >, runs the digital signature Sign algorithm to generate a signature where represents the private key of the leading inspection and testing institution, and l is the serial number of the leading inspection and testing institution; the leading inspection and testing institution L generates a signature and broadcasts the pre-preparation message to all other inspection and testing institutions T ∈ T in S* others : e) After receiving a pre - prepared message, inspection and testing institution T conducts verification: the signature in the message is whether a valid signature belonging to the leading inspection and testing institution L; if so, it determines whether view is the current view and whether other views view have been received; if so, it determines whether the request sequence number vn is consistent; if so, it parses D re : D re =(M, M', Hdr, D ins )=(<m0, m1>, <m0, c>, (C0, C1, C2), D ins ) Subsequently, verify that M is a valid inspection and testing report for D ins ; Verify the bilinear pairing holds; if the result is 1, it means that this report has penetrative supervisability; calculate where i is the serial number of the inspection and testing agency T; verify the consistency between the encrypted inspection and testing report and the original inspection and testing report: run the symmetric decryption algorithm and obtain m1': if m1' = m1, and the inspection and testing agency agrees that the original text M of the inspection and testing report is a qualified inspection and testing report for the user data; if all the above verifications pass, then locally record this pre-prepare message; f) After the inspection and testing institution T records at least 2f + 1 pre-prepare messages from different T' ∈ T others it generates the message <PREPARE, view, vn, D re , T>; 3. Preparation stage: by the inspection and testing institution T ∈ T others Verify and forward the proposal of the leading inspection and testing institution: a) The inspection and testing institution runs the digital signature Sign algorithm to generate a signature b) After the inspection and testing agency generates a signature, it broadcasts a preparation message to all other inspection and testing agencies: c) The inspection and testing institution T receives the prepare message sent by other inspection and testing institutions and verifies the signature of the received prepare message to check whether it is correct; verify whether the data in the received prepare message is consistent with the data in other prepare messages; verify whether the data in the received prepare message is consistent with the pre-prepare message received in the pre-preparation stage; if all the above verifications pass, locally record this prepare message; d) After the inspection and testing institution T receives at least 2f + 1 prepare messages from different T' ∈ T others it generates the information <COMMIT, view, vn, D pre , T>, where D pre = (M', Hdr); 4. Submission phase: The inspection and testing agency verifies whether it can agree with the proposal of the leading inspection and testing agency: a) The inspection and testing agency T runs the digital signature Sign algorithm to generate a signature: b) After the inspection and testing agency generates a signature, it sends a submission message to the leading inspection and testing agency L:
5. Reply phase: The leading inspection and testing agency L returns the report generation result to the user: a) If the leading inspection and testing institution L receives no less than 2|S*| / 3 valid commit messages (i.e., verifiable signatures) including itself within the specified time, it is considered that the group S* has reached an agreement, and the inspection and testing report is successfully generated. The leading inspection and testing institution L is ready to reply to the user: Package (M', Hdr) and all valid commits into a transaction and include it in the next block, and record the corresponding record information as D bc ; The leading inspection and testing institution L generates a successful reply message <REPLY, vn, TS, D bc >, runs the digital signature Sign algorithm to generate a signature Send a return reply message to the user: b) If the leading inspection and testing institution does not receive sufficient submission information within the specified time, it is considered that the report generation fails: The leading inspection and testing institution L generates a failure response message <REPLY, vn, TS, error>, runs the digital signature Sign algorithm, and generates a signature Send a return reply message to the user: (4) Report query algorithm: The inspection and testing report is divided into a public part and a private part. The public part can be read by any report querier who can access the report chain, and the private part requires the report querier to interact with any inspection and testing alliance member participating in the report generation. The query method for the private report:
1. After the user pays the query fee for the report privacy part, the data D required for the query will be bc given to any inspection and testing institution T participating in the report generation q ∈S*; 2. Inspection and Testing Institution T q Through the data D sent by the user bc Query and obtain the on-chain data (M', Hdr), and parse it into (<m0, c>, (C0, C1, C2)); 3. Inspection and Testing Institution T q Recover its own decryption private key d locally through the data D sent by the user bc and decrypt the privacy report with the decryption private key: q 4.T q Send m q to the user, and the user has completed the query of the report; Among them, the secret key k q The verification process of the correctness of the calculation algorithm is as follows: (5) Penetrating supervision algorithm:
1. The supervisor obtains the inspection and testing report-related information M’, Hdr by accessing the inspection and testing report on the blockchain; 2. The supervisor calculates k n = e(g n , C2) / e(d n , C0) 3. The inspection and testing institution runs the symmetric encryption algorithm to decrypt c in the inspection and testing report M': The calculation algorithm of the supervision key and the verification process are as follows: k n = e(g n , C2) / e(d n , C0) =e(g (αn) ,(g γ ·g (α) ) t ) / e(g (αn·γ) ,g t ) = e(g,g) t·αn·(γ+α) / e(g,g) t·αn·γ = e(g,g) t·αn+1 。
Citation Information
Cited By
Storage verification method and storage verification device for detection report and storage medium
CN121770904A