Internet of Things puncturable attribute-based encryption method based on block chain and Bloom filter

By combining the punctureable attribute-based encryption method of blockchain and Bloom filter, the problem of efficient revoking permissions and reliable traceability in dynamic environments is solved, and lightweight permission management and trusted audit are realized, suitable for IoT devices with resource-constrained.

CN120528685APending Publication Date: 2025-08-22GUILIN UNIV OF ELECTRONIC TECH
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510843355.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

It is difficult for IoT devices to achieve efficient revocation of permissions and reliable traceability in dynamic environments. Traditional CP-ABE solutions have high computing overhead, high communication costs, and lack a trusted audit mechanism. The existing blockchain and attribute-based encryption integration solutions have failed to meet the needs of low latency and efficient revocation at the same time.

Method used

The punable attribute-based encryption method based on blockchain and Bloom filter is adopted, combining the immutable recording of blockchain and the efficient verification of Bloom filter to realize the lightweight puncture mechanism, optimize the undo verification through Bloom filter, reduce the computational complexity, and ensure the immutability and traceability of access control operations through blockchain.

Benefits of technology

Significantly reduce the computational complexity of revoking verification, is suitable for IoT devices with resource-constrained, realizes fine-grained access control and dynamic permission management, and enhances the audit capability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528685A_ABST
    Figure CN120528685A_ABST
Patent Text Reader

Abstract

The invention discloses an Internet of Things puncturable attribute-based encryption method based on a block chain and a Bloom filter, and is used for solving the problems of low dynamic permission revocation efficiency and difficult operation auditing in an Internet of Things environment. The method realizes a core function through the following steps: an authorization mechanism initializes system parameters and segments a master key; a data owner defines an access strategy and initializes the Bloom filter during encryption; when the permission is revoked, a puncture tuple containing a label binding component, a strategy binding component and a cross validation component is generated, and the ciphertext is updated after verification of a block chain smart contract; and during decryption, the cloud server firstly screens the validity of the user tag through a Bloom filter, and then decrypts the data in combination with an attribute strategy. The method has the advantages that the complexity of puncture verification is reduced by the Bloom filter, and the resource consumption is remarkably reduced; two-factor binding and cross validation ensure that puncture operation cannot be forged; and the block chain completely records key generation, puncture and decryption operations, so that operation transparency and auditing performance are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of data security and access control, and in particular to a pierceable attribute-based encryption method and system based on blockchain and probabilistic filters, which is suitable for secure data sharing and fine-grained access control in an Internet of Things environment. Background Art

[0002] With the rapid development of IoT technology and the proliferation of smart devices, the number of IoT devices is growing exponentially. These devices continuously generate large amounts of sensitive data, necessitating secure and efficient access control mechanisms. However, IoT systems face unique challenges in data protection and access control, including large system scale, high device heterogeneity, strong network dynamics, and strict resource constraints. Most IoT devices have limited computing resources and battery life, necessitating lightweight cryptographic solutions while maintaining reliable security. With the proliferation of IoT devices, traditional centralized access control mechanisms are no longer able to meet the demands of large-scale, dynamic IoT environments. In particular, in scenarios involving sensitive data sharing and multi-party collaboration, traditional approaches lack sufficient flexibility and security.

[0003] Ciphertext Policy Attribute-Based Encryption (CP-ABE), a technology that provides fine-grained access policies and efficient key management, has become an important solution for IoT access control. However, traditional CP-ABE schemes face significant challenges in implementing efficient revocation mechanisms, especially in dynamic IoT environments where rapid revocation of permissions is crucial. Current attribute revocation methods in CP-ABE systems primarily focus on the following approaches: direct revocation, which requires periodic key updates; indirect revocation, which involves time-based mechanisms; and proxy re-encryption, which relies on semi-trusted proxies. These solutions often result in high computational overhead, significant communication costs, delayed revocation effectiveness, and complex key management issues, making them unsuitable for resource-constrained IoT devices.

[0004] On the other hand, existing solutions lack a trusted audit mechanism for access control operations. In a multi-party IoT environment, the lack of trusted records for critical operations (such as key distribution and permission revocation) makes it difficult to track and audit security incidents in the system, limiting the system's reliability and accountability in practical applications.

[0005] In recent years, blockchain technology has garnered widespread attention due to its decentralization, immutability, and traceability, and is considered a promising technology for enhancing IoT security. However, existing integration schemes of blockchain and attribute-based encryption often lack efficiency optimization for revocation operations, limiting overall system performance. Most solutions fail to simultaneously achieve traceability and efficient revocation of access control, making it difficult to maintain security while meeting the low-latency requirements of IoT environments.

[0006] Therefore, a new solution is needed that can simultaneously solve the problems of efficient revocation verification and reliable traceability, which is particularly suitable for resource-constrained IoT environments to meet the needs of fine-grained access control, dynamic permission management and system auditability in IoT applications. Summary of the Invention

[0007] To address the above technical issues, the present invention proposes a puncturable attribute-based encryption method based on blockchain and Bloom filters. This method combines the immutable record-keeping capabilities of blockchain with the efficient verification mechanism of Bloom filters, enabling efficient access control and dynamic permission revocation in IoT environments. This invention provides a lightweight puncture mechanism and ensures an immutable record of access control operations through blockchain technology. By utilizing Bloom filter optimization in puncture verification, this invention significantly reduces the computational complexity of revocation verification, making it particularly suitable for resource-constrained IoT devices.

[0008] To achieve the above objectives, the present invention provides the following technical solutions:

[0009] A pierceable attribute-based encryption method based on blockchain and Bloom filter, comprising the following steps:

[0010] A: System initialization Setup is performed by the authorized agency to generate system parameters Param and master key MSK. The authorized agency uses a (m,n) threshold secret sharing scheme based on polynomial interpolation to divide the master key into key fragments.

[0011] B: User key generation Keygen, performed by an authorized institution; takes system parameters Param, the user's global identifier GIDu, the user's attribute set S', and the tag set T as input; the output is the user's private key SKu, which contains the basic key component, attribute component, and tag component; the user obtains the private key through the blockchain, which acts as a bridge between the user and the cloud platform, using smart contracts to record key generation operations;

[0012] C: Encryption information Encrypt, executed by the data owner; takes system parameters Param, access tree Γ, plaintext M and access structure A as input; output is the ciphertext CT related to the plaintext M, including access policy A, encrypted data component C, attribute component set {C 1,i ,C 2,i}, puncture component set PC and Bloom filter BF;

[0013] D: Puncture, performed by the data owner; based on the puncture strategy P, the ciphertext is modified for a specific tag, so that the user with the punctured tag cannot decrypt the data; for each tag τ, the tag hash h is calculated τ and policy hash hp , construct puncture components P1, P2, P3, P4 and P5, where puncture component P5 is used for cross-verification; add the label hash to the Bloom filter; the data owner records the puncture operation on the blockchain, which is verified and executed by the smart contract; and outputs the modified ciphertext;

[0014] E: Decryption is performed by the cloud server on behalf of the user, which will obtain the ciphertext; first, it quickly checks whether the user tag is punctured through the Bloom filter; if the tag may be punctured, it further verifies the puncture component; if the attribute match is successful and the user tag is not punctured, it decrypts the plaintext M; if the attribute match fails or the user tag is punctured, it returns an invalid flag ⊥; the blockchain records the decryption request and result.

[0015] The step A comprises the following specific steps:

[0016] A1: The authorized agency generates system parameters, including group parameters G, GT and bilinear mapping e;

[0017] A2: The authorized institution randomly selects three anti-collusion hash functions H: {0,1} * →G, as well as Map attributes to group elements;

[0018] A3: Random selection by the authorized agency As the master key of the system, α is used for basic encryption, β is used for label binding, and γ is used for policy binding;

[0019] A4: The authorized agency calculates the system parameters Param, including the group element g and the bilinear mapping parameters e(g,g) α and related public key elements, and provide them to the blockchain network; the master key MSK contains the encryption master key, label binding key and policy binding key.

[0020] Described step B comprises the following specific steps:

[0021] B1: The user submits identity and attribute information to the authorized institution and applies for a key;

[0022] B2: The authorization agency generates a private key for the user based on the user attribute set S and the tag set T. The private key SKu contains the basic key component (K, L), the attribute component {(K x ,L x )} x∈S and the label component {(K τ ,L τ )} τ∈T ;

[0023] B3: The authorized institution securely transmits the user's private key to the user and records the hash value and timestamp of the key generation operation on the blockchain without leaking the actual key information;

[0024] B4: Blockchain uses smart contracts to verify the legitimacy of key generation operations and record operation logs.

[0025] Described step C comprises the following specific steps:

[0026] C1: The data owner converts access policy A into an access structure tree with threshold gates;

[0027] C2: Data owner randomly selected Calculate the encryption component C = M·e(g,g α ) s and policy binding component C0=g s ;

[0028] C3: For each attribute i in the access structure, the data owner uses the secret sharing mechanism to calculate the polynomial sharing λ i , then generate the attribute sharing component C1, and

[0029] C4: The data owner initializes an empty Bloom filter BF, whose parameters are calculated based on the expected number of puncture tags and the target false alarm rate; initializes the puncture component set PC to be empty;

[0030] C5: The data owner records the metadata of the encryption operation on the blockchain and verifies and records it using smart contracts.

[0031] Described step D comprises the following specific steps:

[0032] D1: The data owner selects the set of tags that need to be punctured according to the puncture strategy P;

[0033] D2: For each label τ, calculate the label hash value h τ =H(τ) and the policy hash value h p =H(P);

[0034] D3: Random Selection Construct the puncture assembly: P5 is used to ensure the integrity and correctness of the puncture component;

[0035] D4: Hash the label h τ Add to the Bloom filter BF and puncture components (P1, P2, P3, P4, P5, h p ) is stored in the puncture component set PC of the ciphertext;

[0036] D5: The data owner submits a puncture request through the blockchain. The smart contract verifies the legitimacy of the request and records the puncture operation, including the puncture policy hash and timestamp.

[0037] D6: Returns the updated ciphertext, including the newly added puncture component and the updated Bloom filter.

[0038] The step E comprises the following specific steps:

[0039] E1: The user submits a decryption request to the cloud server through the blockchain. The smart contract verifies the user's identity and records the request.

[0040] E2: For each tag τ of the user, the cloud server first checks the tag hash h through the Bloom filter BF τ Whether it is likely to be punctured;

[0041] E3: If the Bloom filter indicates that the tag may be punctured, further verify the puncture component and check the relationship

[0042] E4: If verification succeeds, the tag is punctured and decryption fails. Return ⊥; if verification fails or the Bloom filter indicates that the tag is not punctured, attribute-based decryption is performed;

[0043] E5: The decryption process is implemented by recursively calculating the DecryptNode function, starting from the leaf node for verification and calculation, and finally decrypting the plaintext M;

[0044] E6: The cloud server records the decryption results on the blockchain, and the smart contract records the operation log.

[0045] Furthermore, the initialization of the Bloom filter BF includes:

[0046] According to the expected number of punctured tags n and the preset false alarm rate p, the optimal size of the Bloom filter m = -n log(p) / (log(2)) 2 and the number of hash functions k = (m / n)·log(2) to optimize the puncture verification efficiency and memory usage.

[0047] Positive and beneficial effects: The present invention achieves efficient permission revocation through the puncture mechanism optimized by the Bloom filter, significantly reducing computing overhead, and is particularly suitable for IoT devices with limited resources. The puncture mechanism ensures the integrity and non-forgeability of the puncture operation through two-factor binding and cross-validation. At the same time, combined with blockchain technology, it records the metadata of all key operations to ensure the transparency, immutability and traceability of access control operations, and enhances the audit capability and security of the system. The attribute-based access control mechanism allows data owners to define precise access policies to achieve fine-grained protection of data. The puncture operation and decryption performance of the present invention are superior to existing solutions in both theoretical and experimental analysis. The overall design takes into account the characteristics of the IoT environment, optimizes computing and communication efficiency while ensuring security, and is particularly suitable for IoT devices with limited computing resources. The high efficiency of the Bloom filter and the fact that it does not produce false negatives further ensure the security and efficiency of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 This is a framework diagram of the system model of the invention. DETAILED DESCRIPTION

[0049] The present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0050] The specific contents are as follows

[0051] like Figure 1 As shown, the system model of the present invention includes five entities: authorization center (AC), cloud server (CS), blockchain (BC), data owner (DO) and data user (DU).

[0052] The Authorization Center (AC) is a trusted authority responsible for system initialization and key generation. The AC maintains the master key and generates attribute-based private keys for users. It is also responsible for defining system parameters and access policies.

[0053] The Cloud Server (CS) provides storage and computing services for the system. The CS stores encrypted data from IoT devices and performs puncture operations upon receiving a valid revocation request. The server maintains a Bloom filter for efficient revocation checking.

[0054] Blockchain (BC) acts as a bridge between users and cloud servers, responsible for forwarding and recording user puncture and access requests, ensuring the immutability and traceability of operations. Blockchain can adopt a consortium chain architecture, such as Hyperledger Fabric, to ensure efficient transaction processing and fine-grained access control.

[0055] Data Owner (DO) is the entity that owns and generates sensitive data. DO protects data through attribute-based encryption and fine-grained access policies, and performs puncture operations when permissions need to be revoked.

[0056] Data User (DU) is an entity that requests access to encrypted IoT data. Each user has a private key containing attributes and tags assigned by the AC, and their access rights are determined by the attributes and tags in the private key.

[0057] The specific implementation of the present invention includes steps A (system initialization Setup), B (user key generation KeyGen), C (encryption information Encryption), D (puncture Puncture) and E (decryption Decryption). Each step is described in detail below.

[0058] Step A: System Initialization Setup

[0059] In step A1, the authorization center defines a bilinear map e:G0×G0→G1 and a hash function H:{0,1} * →G0, bilinear group G0, whose generator and prime order are g and p respectively. Bilinear mapping needs to satisfy three properties: bilinearity (for all u,v∈G0 and There is e(u a ,v b )=e(u,v) a·b , non-degeneracy (there exists g∈G0 such that e(g,g)≠1) and computability. In practical implementation, the Type-A pairing curve can be chosen, which is a supersingular elliptic curve with a 512-bit base field and embedding degree 2.

[0060] In step A2, the authorization center randomly selects three anti-collusion hash functions H: {0,1} * →G, as well as Mapping attributes to group elements. In actual implementation, these hash functions can be based on cryptographic hash functions such as SHA-256, and use appropriate mapping techniques to map the hash output to the corresponding group or domain.

[0061] In step A3, the authorization center randomly selects As the master key of the system, α is used for basic encryption, β is used for label binding, and γ is used for policy binding. These three parameters form the basis of system security and need to be generated using a cryptographically secure random number generator to ensure that they are Evenly distributed and unpredictable.

[0062] In step A4, the authorization center calculates the system public key and master key Among them, G2 can be another randomly selected element of G0. The authorization center also uses a (m,n) threshold secret sharing scheme based on polynomial interpolation to divide the master key MSK into key fragments to enhance system security. Specifically, for the value of α in the master key, the authorization center can select an m-1 degree polynomial f(x) = α + a1x + a2x 2 +…+a m-1 x m-1 , where the coefficients are Then, the secret share α is calculated for each participant i. i =f(i).

[0063] After initialization is completed, the authorization center will set the system parameters Broadcast to all participating entities, including data owners, cloud servers, and blockchain networks. The master key MSK must be stored securely and cannot be disclosed to any unauthorized entity.

[0064] Step B: User key generation Keygen

[0065] In step B1, the user submits identity and attribute information to the authorization center and applies for a key. The user generates a globally unique identifier GID u , which can be a hash of the user's public key or other unique identifier, and then the GID u , the requested attribute set S and tag set T are sent to the authorization center through a secure channel.

[0066] In step B2, the authorization center generates a private key for the user. First, randomly select and calculate the base key component For each attribute x∈S, randomly select And calculate the property component and Similarly, for each label τ∈T, randomly select And calculate the label component and

[0067] In step B3, the authorization center converts the user's private key SK into (K, L, {(K x ,L x )} x∈S ,{(K τ ,L τ )} τ∈T) is securely transmitted to the user, while metadata about the key generation operation is recorded on the blockchain, including the user's public key hash or identity identifier, the hash value of the key generation operation, a timestamp, and the digital signature of the authorized center. These records do not contain the actual key content, ensuring traceability and non-repudiation of operations while protecting users' sensitive information.

[0068] In step B4, the blockchain uses a smart contract to verify the legitimacy of the key generation operation and record the operation log. The smart contract verifies the signature of the authorization center, checks the format and integrity of the operation request, and permanently stores the operation record on the blockchain after verification.

[0069] Step C: Encrypt

[0070] In step C1, the data owner converts access policy A into an access structure tree with threshold gates. The access structure tree is a hierarchical structure used to represent complex access policies. Each internal node represents a threshold gate, defined as (k, n), where n is the number of child nodes and k is the minimum number of child nodes required to satisfy the policy (1 ≤ k ≤ n). When k = 1, the node represents an OR gate; when k = n, the node represents an AND gate. Leaf nodes represent attributes.

[0071] In step C2, the data owner randomly selects And calculate the encryption component C = M·e(g,g α ) s and policy binding component C0=g s The random value s is the core random factor of encryption and should be selected using a cryptographically secure random number generator to ensure that it Evenly distributed and unpredictable.

[0072] In step C3, the data owner calculates the polynomial sharing λ for each attribute i in the access structure i And generate attribute sharing components. The secret sharing process starts by accessing the root node of the structure tree and assigning a polynomial q to each node. x For the root node R, set q R (0) = s, and randomly select d R =k R -1 coefficient, where k R is the threshold of node R. For each non-root node x, set q x (0) = q parent(x) (index(x)), and randomly select d x =k x -1 coefficient. Then, for each attribute i, generate the attribute sharing component and where λi =q

[0073] In step C4, the data owner initializes an empty Bloom filter BF. A Bloom filter is a space-efficient probabilistic data structure used to test whether an element is a member of a set. In the present invention, a Bloom filter is used to quickly check whether a user tag has been punctured. The parameters of the Bloom filter are calculated based on the expected number of punctured tags n and the target false alarm rate p: filter size m = -n·log(p) / (log(2)) 2 , the number of hash functions k = (m / n)·log(2). For example, for n = 1000 and p = 0.01, the size of the Bloom filter is approximately 9586 bits, requiring 7 hash functions. At the same time, the data owner initializes the puncture component set PC to empty. This set will store the puncture components in subsequent puncture operations.

[0074] In step C5, the data owner converts the final ciphertext CT = (A, C, C0, {C 1,i ,C 2,i The data owner then uploads the encrypted data (PC, BF) to the cloud server CS. The cloud server stores the encrypted data and returns a unique URL identifier. To ensure the integrity and traceability of the encrypted data, the data owner calculates a cryptographic hash value for the encrypted data, signs the hash value with their private key, and then packages the encrypted data URL, hash value, signature, and timestamp into a transaction and submits it to the blockchain network. The blockchain network verifies the validity of the transaction through smart contracts and records it on the blockchain.

[0075] Step D: Puncture

[0076] In step D1, the data owner selects the set of tags to be punctured based on the puncture policy P. The puncture policy can be an expression based on various conditions, such as "permission revoked due to security incident", "user resignation", or "project completion".

[0077] In step D2, when the data owner submits the puncture policy P to the blockchain network, the data owner prepares a puncture request, which includes the URL or identifier of the ciphertext, the puncture policy P, a timestamp, and the data owner's digital signature. The blockchain verifies the authenticity and legitimacy of the request by verifying the data owner's digital signature and authorization. Only the original creator of the ciphertext or an authorized entity can initiate a puncture operation. Once verified, the blockchain forwards the puncture request to the cloud server by sending the operation command and the corresponding ciphertext URL.

[0078] In step D3, after receiving the authentication request, the cloud server uses the URL to retrieve the target ciphertext, parses the puncture strategy P to extract all the tags that need to be punctured, and calculates the tag hash value h for each tag τ in P. τ =H(τ) and the policy hash value hp =H(P). Then, the cloud server randomly selects Cryptographic randomness is introduced into each puncture instance. The random values ​​r1 and r2 are unique for each puncture instance, ensuring that the puncture component is unpredictable and resistant to replay attacks.

[0079] For each label τ, the cloud server constructs a puncture component with cross-validation guarantees, including a label-bound random basis Tag Binding Component This component associates the tag hash with the system master key β; it also includes a policy-bound random basis Policy Binding Component This component associates the policy hash with the system master key γ; finally, it includes the cross-validation component Used to ensure consistency between tag binding and policy binding.

[0080] This puncture component structure implements two-factor binding, binding each puncture operation to both a specific label and a specific policy. The cross-validation component P5 provides a cryptographic link between the label and policy bindings, ensuring the integrity of the puncture operation. The puncture component is unforgeable; without knowing the system master keys β and γ, a valid puncture component cannot be created. Each puncture component is unique to a specific label-policy pair and cannot be reused.

[0081] In step D4, in order to achieve efficient revocation checking during the decryption process, the system hashes the tag h τ Added to the Bloom filter BF, it is convenient for quick preliminary verification. The addition operation consists of calculating k hash functions on the label hash h τ The system also punctures the components (P1, P2, P3, P4, P5, h p ) is stored in the puncture component set PC of the ciphertext, through h τ Index for efficient lookup during decryption.

[0082] In step D5, after the puncture operation is completed, the cloud server returns a confirmation to the blockchain, including the operation status, the number of tags processed, the hash digest of the operation, and a timestamp. The blockchain records this operation, along with its timestamp and operation hash, for future auditing. This recording mechanism ensures transparency and traceability of the puncture operation, ensuring that any unauthorized modifications can be detected.

[0083] In step D6, the system returns the updated ciphertext CT', which contains the newly added puncture component and the updated Bloom filter. The updated ciphertext structure is: CT'=(A,C,C0,{C 1,i ,C 2,i},PC',BF'), where PC' is the updated set of punctured components and BF' is the updated Bloom filter. The puncture operation does not require re-encrypting the original data; it only needs to add additional punctured components and update the Bloom filter, which greatly improves the efficiency of the operation, especially for large datasets.

[0084] Step E: Decrypt

[0085] In step E1, the user submits a decryption request to the cloud server via the blockchain. The decryption request contains the URL or identifier of the encrypted text, the user's identity credentials, a timestamp, and the user's digital signature. The blockchain smart contract first verifies the user's identity and the legitimacy of the request, including verifying the user's digital signature, checking whether the user has permission to access the requested data, verifying the request format and integrity, and recording metadata about the access request. Once the smart contract passes verification, the blockchain forwards the decryption request to the cloud server.

[0086] In step E2, for each tag τ of the user, the cloud server first checks the tag hash h through the Bloom filter BF τ Is it possible to be punctured? The Bloom filter check includes calculating the hash value h of the label τ τ =H(τ), calculate k hash functions in h τ The value on the tag is checked to see if the corresponding bits in the Bloom filter are all 1. If any bit is 0, the tag is definitely not punctured; if all bits are 1, the tag may be punctured and further verification is required.

[0087] In step E3, if the Bloom filter indicates that the tag may be punctured, the cloud server needs to further verify the puncture component. For each potentially punctured tag τ, the cloud server retrieves the tag hash h from the puncture component set PC. τ Associated puncture components (P1, P2, P3, P4, P5, h p If the corresponding puncture component cannot be found, the tag is not punctured; if the puncture component is found, check the verification relationship: The system also verifies the cross-binding relationship of the puncture components: e(P5,g2)=e(P1,g2)·e(P3,g2), ensuring the consistency between label binding and policy binding.

[0088] In step E4, if verification succeeds, the tag is punctured, and decryption fails, and a ⊥ is returned. If verification fails or the Bloom filter indicates that the tag is not punctured, attribute-based decryption is performed. This two-stage judgment mechanism ensures a balance between system efficiency and security.

[0089] In step E5, if all of the user's tags have not been punctured, the system enters the attribute-based decryption phase. The decryption process is recursive, starting from the leaf nodes of the access tree and working upward to the root node. The system defines a recursive decryption function DecryptNode(CT,SK,x), where CT is the ciphertext, SK is the user's private key, and x is a node in the access tree.

[0090] If x is a leaf node, corresponding to attribute i, and the user has attribute i (i∈S), then calculate:

[0091] If the user does not have attribute i, that is, Then it returns ⊥, and the decryption fails.

[0092] If x is an internal node, the system recursively calculates the DecryptNode(CT,SK,z) value of all child nodes z and stores the result as F z Let S x is of size k x The set of child nodes that satisfies all z∈S x All have F z ≠⊥. If such a set S x If it does not exist, it returns ⊥ and the decryption fails. Otherwise, calculate: Where i = index(z), S' x ={index(z):z∈S x}, is the Lagrange coefficient.

[0093] Through the Lagrange interpolation method, if the user's attribute set meets the access policy, the final result at the root node R is: F R =e(g,g2) αs

[0094] With this value, the system recovers the plaintext by the following calculation:

[0095] In step E6, the cloud server records the decryption result on the blockchain, and the smart contract records the operation log. The record includes the requesting user's identity identifier, the operation result, the identifier of the accessed resource, a timestamp, and a hash digest of the operation. The operation log on the blockchain provides a complete access audit trail, enabling system administrators to monitor system usage, detect abnormal activity, and investigate security incidents.

[0096] This invention, centered around puncturable ciphertext policy attribute-based encryption, innovatively proposes a highly efficient puncture mechanism for revoking permissions. Through two-factor binding and cross-validation techniques, it enables precise and secure dynamic adjustment of user access rights. Furthermore, the invention cleverly integrates Bloom filters as a rapid screening tool for puncture verification, significantly improving verification efficiency. Furthermore, it incorporates blockchain technology as a trusted platform for operation records, enhancing the transparency and auditability of the system. This organic combination of core mechanisms and supporting technologies ensures high security while significantly reducing computational overhead, making it particularly suitable for resource-constrained IoT environments.

[0097] The puncture-resistant encryption technology of the present invention provides a flexible and efficient solution for IoT data access control and can be widely applied in fields such as intelligent manufacturing, healthcare, energy management, intelligent transportation, and urban management. Through the puncture mechanism of the present invention, system administrators can accurately revoke the access rights of specific users without affecting other users, thus achieving fine-grained permission management. The contents described in this specification are only exemplary embodiments of the present invention. Those skilled in the art may make various modifications and changes without departing from the spirit and scope of the present invention, and such modifications and changes should be deemed to fall within the scope of protection of the present invention.

Claims

1. A puncturable attribute-based encryption method based on blockchain and Bloom filter, characterized in that: The following steps are involved: A: System initialization Setup is performed by the authorized agency to generate system parameters Param and master key MSK. The authorized agency uses a (m,n) threshold secret sharing scheme based on polynomial interpolation to divide the master key into key fragments. B: User key generation Keygen, executed by the authorized agency; using system parameters Param, user's global identifier GIDu, user attribute set S' and tag set T as input; The output is the user's private key SKu, which includes a basic key component, an attribute component, and a tag component. The user obtains the private key through the blockchain, which acts as a bridge between the user and the cloud platform and uses smart contracts to record key generation operations. C: Encryption information Encrypt, executed by the data owner; takes system parameters Param, access tree Γ, plaintext M and access structure A as input; The output is the ciphertext CT associated with the plaintext M, which contains the access policy A, the encrypted data component C, and the attribute component set {C 1,i ,C 2,i }, puncture component set PC and Bloom filter BF; D: Puncture, performed by the data owner; Based on the puncture strategy P, the ciphertext is modified for a specific tag so that the user with the punctured tag cannot decrypt the data; for each tag τ, the tag hash h is calculated. τ and policy hash h p , construct puncture components P1, P2, P3, P4 and P5, where puncture component P5 is used for cross-verification; add label hash to Bloom filter; The data owner records the puncture operation on the blockchain, verifies and executes it through smart contracts, and outputs the modified ciphertext; E: Decryption, performed by the cloud server on behalf of the user, obtains the ciphertext. It first quickly checks whether the user tag has been punctured through a Bloom filter. If the tag may have been punctured, it further verifies the puncture component. If the attribute match succeeds and the user tag has not been punctured, it decrypts the plaintext M. If the attribute matching fails or the user tag is punctured, an invalid identifier is returned; the blockchain records the decryption request and result.

2. The puncturable attribute-based encryption method based on blockchain and Bloom filter according to claim 1 is characterized in that: The step A comprises the following specific steps: A1: The authorized agency generates system parameters, including group parameters G, GT and bilinear mapping e; A2: The authorized institution randomly selects three anti-collusion hash functions H: {0,1} * →G, as well as , mapping attributes to group elements; A3: Random selection by the authorized agency As the master key of the system, α is used for basic encryption, β is used for label binding, and γ is used for policy binding; A4: The authorized agency calculates the system parameters Param, including the group element g and the bilinear mapping parameters e(g,g) α and related public key elements, and provide them to the blockchain network; the master key MSK contains the encryption master key, label binding key and policy binding key.

3. The puncturable attribute-based encryption method based on blockchain and Bloom filter according to claim 1 is characterized in that: Described step B comprises the following specific steps: B1: The user submits identity and attribute information to the authorized institution and applies for a key; B2: The authorization agency generates a private key for the user based on the user attribute set S and the tag set T. The private key SKu contains the basic key component (K, L), the attribute component {(K x ,L x )} x∈S and the label component {(K τ ,L τ )} τ∈T ; B3: The authorized institution securely transmits the user's private key to the user and records the hash value and timestamp of the key generation operation on the blockchain without leaking the actual key information; B4: Blockchain uses smart contracts to verify the legitimacy of key generation operations and record operation logs.

4. The puncturable attribute-based encryption method based on blockchain and Bloom filter according to claim 1 is characterized in that: Described step C comprises the following specific steps: C1: The data owner converts access policy A into an access structure tree with threshold gates; C2: Data owner randomly selected Calculate the encryption component C = M·e(g,g α ) s and policy binding component C0=g s ; C3: For each attribute i in the access structure, the data owner uses the secret sharing mechanism to calculate the polynomial sharing λ i , then generate the attribute sharing component C1, and C4: The data owner initializes an empty Bloom filter BF, whose parameters are calculated based on the expected number of puncture tags and the target false alarm rate; initializes the puncture component set PC to be empty; C5: The data owner records the metadata of the encryption operation on the blockchain and verifies and records it through smart contracts.

5. The puncturable attribute-based encryption method based on blockchain and Bloom filter according to claim 1 is characterized in that: Described step D comprises the following specific steps: D1: The data owner selects the set of tags that need to be punctured according to the puncture strategy P; D2: For each label τ, calculate the label hash value h τ =H(τ) and the policy hash value h p =H(P); D3: Random Selection Construct the puncture assembly: P5 is used to ensure the integrity and correctness of the puncture component; D4: Hash the label h τ Add to the Bloom filter BF and puncture components (P1, P2, P3, P4, P5, h p ) is stored in the puncture component set PC of the ciphertext; D5: The data owner submits a puncture request through the blockchain. The smart contract verifies the legitimacy of the request and records the puncture operation, including the puncture policy hash and timestamp. D6: Returns the updated ciphertext, including the newly added puncture component and the updated Bloom filter.

6. The puncturable attribute-based encryption method based on blockchain and Bloom filter according to claim 1 is characterized in that: The step E comprises the following specific steps: E1: The user submits a decryption request to the cloud server through the blockchain. The smart contract verifies the user's identity and records the request. E2: For each tag τ of the user, the cloud server first checks the tag hash h through the Bloom filter BF τ Whether it is likely to be punctured; E3: If the Bloom filter indicates that the tag may be punctured, further verify the puncture component and check the relationship E4: If verification succeeds, the tag is punctured and decryption fails. Return ⊥; if verification fails or the Bloom filter indicates that the tag is not punctured, attribute-based decryption is performed; E5: The decryption process is implemented by recursively calculating the DecryptNode function, starting from the leaf node for verification and calculation, and finally decrypting the plaintext M; E6: The cloud server records the decryption results on the blockchain, and the smart contract records the operation log.

7. The puncturable attribute-based encryption method based on blockchain and Bloom filter according to claim 1 is characterized in that: The initialization of the Bloom filter BF includes: According to the expected number of punctured tags n and the preset false alarm rate p, the optimal size of the Bloom filter m = -n log(p) / (log(2)) 2 and the number of hash functions k = (m / n)·log(2) to optimize the puncture verification efficiency and memory usage.

8. The puncturable attribute-based encryption method based on blockchain and Bloom filter according to claim 1 is characterized in that: The proposed method achieves the following security goals: fine-grained access control through attribute-based encryption, tag-based dynamic revocation through a puncture mechanism, transparency and traceability of operations through blockchain technology, automated verification and execution through smart contracts, and optimized puncture verification efficiency through Bloom filters.

9. A puncturable attribute-based encryption system based on blockchain and Bloom filter, characterized in that: The system includes: an authorization center module for system initialization and key generation; a blockchain network module for maintaining distributed ledgers, executing smart contracts, and recording operation logs, serving as a bridge between users and the cloud platform; an encryption module for encrypting data based on access policies; a puncture module for performing label-based selective revocation; a cloud server module for storing ciphertext data and performing decryption operations; and a Bloom filter module for optimizing the puncture verification process.

10. The puncturable attribute-based encryption system based on blockchain and Bloom filter according to claim 9 is characterized in that: The system is applied to secure data sharing and access control in the IoT environment, significantly reducing computing overhead while ensuring efficient access control, and is suitable for IoT devices with limited computing resources.

Citation Information

Cited By

  • Attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations

    CN120956419A

  • Policy hidden access control method and system based on distributed Cuckou filter

    CN121567488A