Decentralization group communication authentication broadcast encryption method based on block chain
By using a blockchain-based decentralized group communication authentication broadcast encryption method, the problems of single point of failure and poor scalability caused by reliance on a central institution in existing technologies are solved, achieving efficient and secure group communication that can adapt to dynamic group changes.
Patent Information
- Application Number
- CN202511789691.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-02-10
AI Technical Summary
Existing group communication methods rely on a central institution, which poses a single point of failure risk, has poor scalability, and is difficult to effectively defend against active attacks and malicious behavior in dynamic groups.
A decentralized group communication authentication and broadcast encryption method based on blockchain is adopted. Public parameters and CRS are generated through smart contracts. After user initialization, the public key is published on the blockchain. The sender encrypts and signs the message, and the receiver decrypts and verifies it, so that key negotiation and broadcast encryption are completed in one round of communication.
It enables key negotiation and broadcast encryption to be completed in one round of communication without the need for a central institution, and has high security, high efficiency and good scalability, resists malicious attacks and adapts to dynamic group changes.
Smart Images

Figure CN121509030A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of blockchain and cryptography, and in particular to a blockchain-based decentralized group communication authentication broadcast encryption method. Background Technology
[0002] In current digital collaboration scenarios, group-oriented applications (GOAs) have been widely deployed in various fields such as collaborative work environments, distributed sensor networks, and remote video conferencing. Typical examples include remote office tools such as Zoom and Google Meet, which support real-time communication, file sharing, and project collaboration among multiple parties. The core challenge of these applications lies in building an efficient and secure end-to-end group communication system, which must simultaneously meet four key attributes: confidentiality, authentication, scalability, and decentralization. Confidentiality requires that information exchanged within the group is accessible only to authorized members; authentication must ensure the legitimacy of participants to prevent malicious impersonation; scalability requires adapting to dynamic changes in group size while avoiding performance degradation; and decentralization requires eliminating dependence on trusted third parties and avoiding single points of failure and the risk of privilege abuse.
[0003] However, the implementation of group communication mainly relies on three key methods, all of which have significant technical bottlenecks: Group Key Distribution (GKD): A shared key is distributed to all members through a trusted group key manager (GKM) to establish a basic secure channel for group communication. However, the centralized architecture has a fatal single point of failure. Once the GKM is attacked or tampered with, the confidentiality of the entire group communication will be completely lost. Moreover, when members change, new keys need to be redistributed to all participants. In dynamic group scenarios, the communication and computing overhead increases linearly with the group size, resulting in extremely poor scalability. Group Key Negotiation (GKA): As an extension of two-party key negotiation, it supports members to jointly generate keys without the need for a central authority, thus improving the degree of decentralization and system resilience. However, traditional GKA schemes involve multiple rounds of interaction and computationally intensive encryption operations, which significantly increase overhead as the group size expands. Changes in members within a dynamic group require re-execution of the entire protocol, leading to a substantial decrease in efficiency in large-scale scenarios or those with frequent member changes. Furthermore, most schemes only defend against passive attacks and lack protection against active attacks. Broadcast Encryption (BE), on the other hand, allows the sender to choose the authorized receiver set, with only authorized members able to decrypt broadcast messages, eliminating the need to send keys to each member individually, resulting in better efficiency and scalability. However, traditional BE relies on a central institution to generate a Public Reference String (CRS), which can access all group messages, posing a serious risk of message leakage. While existing Distributed Broadcast Encryption (DBE) schemes introduce some decentralization at the key management level, allowing users to generate public and private keys based on a centralized CRS and submit them to a public bulletin board, they still remain dependent on the centralized CRS. Some schemes optimize by using multi-institutional key generation, but collusion among institutions or single-point unavailability can jeopardize system security, and they do not address security vulnerabilities caused by malicious behaviors such as submission order manipulation and bias attacks, failing to achieve true decentralization.
[0004] In conclusion, it is essential to propose a method that eliminates the need for a central authority, enables key negotiation and broadcast encryption in a single round of communication, and balances security, efficiency, and scalability. Summary of the Invention
[0005] The purpose of this invention is to provide a decentralized group communication authentication and broadcast encryption method based on blockchain, which achieves the goal of completing key negotiation and broadcast encryption in one round of communication without the need for a central institution, while taking into account security, efficiency and scalability.
[0006] To achieve the above objectives, this invention employs a blockchain-based decentralized group communication authentication broadcast encryption method, comprising the following steps: The system is initialized by inputting the security parameter λ and the number of slots L. The smart contract generates a cyclic group G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G1, G1, G2, G3, G1, G3, G4, G5, G6, G7, G8, G1, G1, G1, G2, G3, G1, G1, G2, G3, G3, G4, G5, G6, G7, G8, G1 ...7, G8, G1, G1, G1, G2, G3, G3, G7, G8, G1, G1, G1, G2, G3, G3, G3, G4, G5, G6, G7, G1, G1, G2, G3, G3, G7, G8, G1, G1, G1, G2, G3, G3, G3, G4, G5, G6, G7, G1, G1, G2, G3, G3, G3, G7, G8, G1, G1, G1, G2, G3 t Each of the generators g1, g2, g tAnd the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies bilinearity, nondegeneracy and efficient computability; User initialization is divided into a commitment phase and a commit phase. The user inputs the public parameter pp and randomly selects the secret index α. i ∈ Locally compute the G1 power sequence S1={c ij} j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij} j∈[2L],j≠L+1 (dij=[ ]2∈G2); After generating the CRS, the smart contract receives all user-submitted (seq, proof) sequences and sequentially verifies the validity of π1 and π2, as well as the homology between S1 and S2. It then verifies e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij (j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 d iL )=e(g1,d i(L+2) The S1 and S2 sequences of all valid users are aggregated to form a global CRS vector CRS=(CRS1, CRS2) and stored in the blockchain. If the verification fails, ⊥ is returned. Joining the network, the user inputs public parameters pp, CRS, and index i, and randomly selects secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upk ik)=e([1]1,upk iL (k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i ; Through signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (t j +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts Output the ciphertext ct=(C1, C2, C3, C4) and send it to the blockchain. The total fixed size of the ciphertext is 608 bytes, and additional [log2L] bits of receiver set information are transmitted. Verification and decryption: The receiver inputs the public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return ⊥.
[0007] During system initialization, the security parameter λ and the number of slots L are input. The smart contract generates a cyclic group G1, G2, G3, G4 containing a prime number p and three cyclic groups G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G1, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G1, G3, G1, G2, G3, G3, G4, G5, G6, G7, G8, G9, G1, G1, G1, G2, G3 ... t Each of the generators g1, g2, g tAnd the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies the bilinearity, non-degeneracy, and efficient computability in the following steps: The public parameter pp is generated based on the BN254 elliptic curve, the security parameter λ is set to 128 bits, the symmetric encryption adopts the AES-256 standard algorithm, and the hash functions H0 and H1 both adopt SHA256. All parameters are publicly available and can be queried.
[0008] The user initialization process is divided into a commitment phase and a submission phase. The user inputs a public parameter pp and randomly selects a secret index α. i ∈ Locally compute the G1 power sequence S1={c ij} j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij} j∈[2L],j≠L+1 (dij=[ In the steps of ]2∈G2): The two-phase user initialization design is used to prevent commit order manipulation attacks and bias attacks. The commitment phase ensures that the user locks their choice before knowing the parameters of others, and the commit phase ensures the authenticity of the sequence through hash consistency verification. Commitment Phase: Calculate the commitment value C=H0(S1, S2) using the hash function H0, submit C to the smart contract, and after the contract records all user commitments, proceed to the next phase; Submission Phase: Using the Chaum-Pedersen protocol combined with the Fiat-Shamir transformation, a non-interactive zero-knowledge proof proof=(π1,π2) is generated to verify the consistency of the exponents of adjacent elements in S1 and S2. The tuple(seqi,proof) is submitted to the on-chain smart contract. After the contract verifies that H0(S1,S2) is consistent with the commitment value C, the user index i is returned.
[0009] In the process of generating the CRS, after the smart contract receives all user-submitted (seq, proof) data, it sequentially verifies the validity of π1 and π2 and the homology of S1 and S2, and verifies e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij (j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 diL )=e(g1,d i(L+2) The process involves aggregating the S1 and S2 sequences of all valid users to form a global CRS vector CRS=(CRS1, CRS2) and storing it in the blockchain. If verification fails, the process returns to the previous step. The global CRS vector is formed by aggregating the S1 and S2 sequences of all verified users, satisfying CRS1=(∏ i∈[L] [ ]1)(j∈[L])CRS2=(∏ i ∈[L][ ]2) (j∈[L]∪[L+2,2L]), and stored in the blockchain for subsequent use by all participants.
[0010] In this process, when joining the network, the user inputs common parameters pp, CRS, and index i, and randomly selects secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upk ik )=e([1]1,upk iL (k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i In the steps: The smart contract is deployed on the Ethereum Sepolia testnet and verifies the public key upk through multiple pairings. i The effectiveness of this ensures the legitimacy of network participants' identities, and eliminates the need to re-execute the entire protocol when the group size changes dynamically.
[0011] Among them, after signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (tj +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts The ciphertext ct = (C1, C2, C3, C4) is output and sent to the blockchain. The total fixed size of the ciphertext is 608 bytes. The additional step of transmitting [log2L] bits of receiver set information is as follows: The ciphertext size is fixed and unaffected by the size of the receiver set S. On-chain gas consumption changes minimally with group size, which is within the range of 2^S. 8 -1 to 2 256 When the value is within the range of -1, the gas consumption remains between 243641 and 244223.
[0012] Among them, the verification and decryption process involves the recipient inputting public parameters pp, CRS, the recipient set S, and the recipient public key set {upk}. j} j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return to the step ⊥. The key reconstruction process relies solely on the recipient's own private key, the CRS stored on the blockchain, and the public key information. No other recipients need to participate in the collaboration. The execution time for decryption and verification increases linearly with the size of the recipient set.
[0013] This invention discloses a blockchain-based decentralized group communication authentication broadcast encryption method. First, system initialization is performed, inputting security parameters λ and the number of slots L. The smart contract then generates a cyclic group G1, G2, and G3 containing a prime number p and three cyclic groups G1, G2, and G3 of order p. t Each of the generators g1, g2, g tAnd the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies bilinearity, nondegeneracy and efficient computability; Then, user initialization is performed, which is divided into a commitment phase and a commit phase. The user inputs the public parameter pp and randomly selects the secret index α. i ∈ Locally compute the G1 power sequence S1={c ij} j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij} j∈[2L],j≠L+1 (dij=[ [2∈G2); generate CRS, after the smart contract receives all user-submitted (seq, proof) data, it sequentially verifies the validity of π1 and π2 and the homology of S1 and S2, and verifies e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij (j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 d iL )=e(g1,d i(L+2) The S1 and S2 sequences of all valid users are aggregated to form a global CRS vector CRS=(CRS1, CRS2) and stored in the blockchain. If verification fails, ⊥ is returned. Then, the user joins the network, inputs public parameters pp, CRS and index i, and randomly selects secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upk ik )=e([1]1,upk iL(k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i Through signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (t j +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts The ciphertext ct = (C1, C2, C3, C4) is output and sent to the blockchain. The total fixed size of the ciphertext is 608 bytes, with an additional [log2L] bits of receiver set information transmitted. Verification and decryption are performed by the receiver inputting the public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return ⊥. Based on the dBDHE and CDH assumptions of bilinear groups, it possesses chosen-ciphertext attack security (SC-IND-CCA) and unforgeability (SC-EUF-CMA) under the random oracle model. External entities can send encrypted messages to the group based on the publicly available CRS of the blockchain. In this way, key negotiation and broadcast encryption can be completed in one round of communication without a central institution, taking into account security, efficiency and scalability. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 This is a flowchart of the blockchain-based decentralized group communication authentication broadcast encryption method of the present invention.
[0016] Figure 2 This is a flowchart illustrating the steps of the blockchain-based decentralized group communication authentication broadcast encryption method of the present invention. Detailed Implementation
[0017] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application.
[0018] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0019] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0020] Please see Figure 1 and Figure 2 This invention provides a blockchain-based decentralized group communication authentication broadcast encryption method, comprising the following steps: S100: Perform system initialization, input security parameter λ and number of slots L, and the smart contract generates a cyclic group G1, G2, G3, G4 containing a prime number p and three cyclic groups G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G1, G3, G4, G5, G6, G7, G8, G9, G1, G1, G1, G2, t Each of the generators g1, g2, g tAnd the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies bilinearity, nondegeneracy and efficient computability; S200: User initialization is performed, which is divided into the commitment phase and the commit phase. The user inputs the public parameter pp and randomly selects the secret index α. i ∈ Locally compute the G1 power sequence S1={c ij} j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij} j∈[2L],j≠L+1 (dij=[ ]2∈G2); S300: Generate CRS. After the smart contract receives all user-submitted (seq, proof) data, it sequentially verifies the validity of π1 and π2 and the homology of S1 and S2, verifying e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij (j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 d iL )=e(g1,d i(L+2) The S1 and S2 sequences of all valid users are aggregated to form a global CRS vector CRS=(CRS1, CRS2) and stored in the blockchain. If the verification fails, ⊥ is returned. S400: Join the network. The user inputs common parameters pp, CRS, and index i, and randomly selects secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upkik )=e([1]1,upk iL (k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i ; S500: Through signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (t j +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts Output the ciphertext ct=(C1, C2, C3, C4) and send it to the blockchain. The total fixed size of the ciphertext is 608 bytes, and additional [log2L] bits of receiver set information are transmitted. S600: Verification and decryption: The receiver inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return ⊥.
[0021] In the above process, the system is first initialized by inputting the security parameter λ and the number of slots L. The smart contract then generates a cyclic group G1, G2, and G3 containing a prime number p and three cyclic groups of order p. t Each of the generators g1, g2, g tAnd the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies bilinearity, nondegeneracy and efficient computability; Then, user initialization is performed, which is divided into a commitment phase and a commit phase. The user inputs the public parameter pp and randomly selects the secret index α. i ∈ Locally compute the G1 power sequence S1={c ij} j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij} j∈[2L],j≠L+1 (dij=[ [2∈G2); generate CRS, after the smart contract receives all user-submitted (seq, proof) data, it sequentially verifies the validity of π1 and π2 and the homology of S1 and S2, and verifies e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij (j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 d iL )=e(g1,d i(L+2) The S1 and S2 sequences of all valid users are aggregated to form a global CRS vector CRS=(CRS1, CRS2) and stored in the blockchain. If verification fails, ⊥ is returned. Then, the user joins the network, inputs public parameters pp, CRS and index i, and randomly selects secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upk ik )=e([1]1,upk iL(k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i Through signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (t j +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts The ciphertext ct = (C1, C2, C3, C4) is output and sent to the blockchain. The total fixed size of the ciphertext is 608 bytes, with an additional [log2L] bits of receiver set information transmitted. Verification and decryption are performed by the receiver inputting the public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return ⊥. Based on the dBDHE and CDH assumptions of bilinear groups, it possesses chosen-ciphertext attack security (SC-IND-CCA) and unforgeability (SC-EUF-CMA) under the random oracle model. External entities can send encrypted messages to the group based on the publicly available CRS of the blockchain. In this way, key negotiation and broadcast encryption can be completed in one round of communication without a central institution, taking into account security, efficiency and scalability.
[0022] Furthermore, during system initialization, the security parameter λ and the number of slots L are input. The smart contract generates a cyclic group G1, G2, and G3 containing a prime number p and three cyclic groups G1, G2, and G3 of order p. t Each of the generators g1, g2, g t And the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies the bilinearity, non-degeneracy, and efficient computability in the following steps: The public parameter pp is generated based on the BN254 elliptic curve, the security parameter λ is set to 128 bits, the symmetric encryption adopts the AES-256 standard algorithm, and the hash functions H0 and H1 both adopt SHA256. All parameters are publicly available and can be queried.
[0023] Furthermore, during user initialization, which is divided into a commitment phase and a commit phase, the user inputs a public parameter pp and randomly selects a secret index α. i ∈ Locally compute the G1 power sequence S1={c ij} j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij} j∈[2L],j≠L+1 (dij=[ In the steps of ]2∈G2): The two-phase user initialization design is used to prevent commit order manipulation attacks and bias attacks. The commitment phase ensures that the user locks their choice before knowing the parameters of others, and the commit phase ensures the authenticity of the sequence through hash consistency verification. Commitment Phase: Calculate the commitment value C=H0(S1, S2) using the hash function H0, submit C to the smart contract, and after the contract records all user commitments, proceed to the next phase; Submission Phase: Using the Chaum-Pedersen protocol combined with the Fiat-Shamir transformation, a non-interactive zero-knowledge proof proof=(π1,π2) is generated to verify the consistency of the exponents of adjacent elements in S1 and S2. The tuple(seqi,proof) is submitted to the on-chain smart contract. After the contract verifies that H0(S1,S2) is consistent with the commitment value C, the user index i is returned.
[0024] Furthermore, after generating the CRS and receiving all user-submitted (seq, proof) data, the smart contract sequentially verifies the validity of π1 and π2 and the homology of S1 and S2, verifying e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij(j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 d iL )=e(g1,d i(L+2) The process involves aggregating the S1 and S2 sequences of all valid users to form a global CRS vector CRS=(CRS1, CRS2) and storing it in the blockchain. If verification fails, the process returns to the previous step. The global CRS vector is formed by aggregating the S1 and S2 sequences of all verified users, satisfying CRS1=(∏ i∈[L] [ ]1)(j∈[L])CRS2=(∏ i ∈[L][ ]2) (j∈[L]∪[L+2,2L]), and stored in the blockchain for subsequent use by all participants.
[0025] Furthermore, upon joining the network, the user inputs public parameters pp, CRS, and index i, and randomly selects secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upk ik )=e([1]1,upk iL (k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i In the steps: The smart contract is deployed on the Ethereum Sepolia testnet and verifies the public key upk through multiple pairings. i The effectiveness of this ensures the legitimacy of network participants' identities, and eliminates the need to re-execute the entire protocol when the group size changes dynamically.
[0026] Furthermore, after signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}.j} j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (t j +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts The ciphertext ct = (C1, C2, C3, C4) is output and sent to the blockchain. The total fixed size of the ciphertext is 608 bytes. The additional step of transmitting [log2L] bits of receiver set information is as follows: The ciphertext size is fixed and unaffected by the size of the receiver set S. On-chain gas consumption changes minimally with group size, which is within the range of 2^S. 8 -1 to 2 256 When the value is within the range of -1, the gas consumption remains between 243641 and 244223.
[0027] Furthermore, through verification and decryption: the receiver inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j} j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return to the step ⊥. The key reconstruction process relies solely on the recipient's own private key, the CRS stored on the blockchain, and the public key information. No other recipients need to participate in the collaboration. The execution time for decryption and verification increases linearly with the size of the recipient set.
[0028] Beneficial effects: Fully Decentralized: A general framework is built based on the dBDHE assumption. The CRS is generated collaboratively by all users through blockchain smart contracts, without the need for any central institution or trusted third party. Key distribution achieves equal participation of nodes through a distributed algorithm, and message decryption relies on the user's local private key, completely eliminating the single point of failure risk and trust dependence brought by a central institution, significantly improving system robustness; Highly Efficient Communication Features: The communication process for users joining the network and key negotiation is simplified, greatly reducing communication overhead and avoiding efficiency losses caused by multiple rounds of interaction, adapting to the needs of frequent member changes in dynamic group scenarios; High Security: Based on the dBDHE and CDH assumptions of bilinear groups, it is rigorously proven to possess security against chosen ciphertext attacks (SC-IND-CCA) and strong unforgeability under chosen message attacks (SC-EUF-CMA) under the random oracle model. CRS generation employs a two-phase commit-commit mechanism and bilinear pairing verification to ensure sequence consistency, effectively resisting malicious acts such as commit order manipulation and bias attacks, and guaranteeing the confidentiality and integrity of keys and messages. It boasts excellent scalability: the ciphertext size for the signature / encryption steps is fixed, and increasing group size has minimal impact on gas consumption and execution time, adapting to various group application scenarios from small-scale collaborations to large-scale distributed networks. Furthermore, it protects privacy: zero-knowledge proof technology ensures that user secret indices and private keys are not disclosed, verifying only the validity of statements. The combination of blockchain transparency and cryptographic encryption achieves a balance between privacy protection and verifiability.
[0029] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.
[0030] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A blockchain-based decentralized group communication authentication broadcast encryption method, characterized in that, Includes the following steps: The system is initialized by inputting the security parameter λ and the number of slots L. The smart contract generates a cyclic group G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G1, G1, G2, G3, G1, G3, G4, G5, G6, G7, G8, G1, G1, G1, G2, G3, G1, G1, G2, G3, G3, G4, G5, G6, G7, G8, G1 ... t Each of the generators g1, g2, g t And the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies bilinearity, nondegeneracy and high computability; User initialization is divided into a commitment phase and a commit phase. The user inputs the public parameter pp and randomly selects the secret index α. i ∈ Locally compute the G1 power sequence S1={c ij } j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij } j∈[2L],j≠L+1 (dij=[ ]2∈G2); After generating the CRS, the smart contract receives all user-submitted (seq, proof) sequences and sequentially verifies the validity of π1 and π2, as well as the homology between S1 and S2. It then verifies e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij (j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 d iL )=e(g1,d i(L+2) The S1 and S2 sequences of all valid users are aggregated to form a global CRS vector CRS=(CRS1, CRS2) and stored in the blockchain. If the verification fails, ⊥ is returned. Joining the network, the user inputs public parameters pp, CRS, and index i, and randomly selects secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upk ik )=e([1]1,upk iL (k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i ; Through signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j } j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (t j +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts Output the ciphertext ct=(C1, C2, C3, C4) and send it to the blockchain. The total fixed size of the ciphertext is 608 bytes, and an additional [log2L] bits of receiver set information are transmitted. Verification and decryption: The receiver inputs the public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j } j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return ⊥.
2. The blockchain-based decentralized group communication authentication broadcast encryption method as described in claim 1, characterized in that, During system initialization, the security parameter λ and the number of slots L are input. The smart contract generates a cyclic group G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G4, G5, G6, G7, G8, G9, G1, G1, G2, G3, G1, G1, G2, G3, G1, G3, G4, G5, G6, G1, G1, G2, G3, G3, G4, G5, G6, G7, G8, G1 ...7, G8, G1, G1, G1, G2, G3, G3, G3, G4, G5, G6, G7, G7, G8, t Each of the generators g1, g2, g t And the common parameter pp of the bilinear pairing e: G1×G2→Gt, where p is a prime number of λ bits, the bilinear pairing e satisfies the bilinearity, non-degeneracy, and efficient computability in the following steps: The public parameter pp is generated based on the BN254 elliptic curve, the security parameter λ is set to 128 bits, the symmetric encryption adopts the AES-256 standard algorithm, and the hash functions H0 and H1 both adopt SHA256. All parameters are publicly available and can be queried.
3. The blockchain-based decentralized group communication authentication broadcast encryption method as described in claim 1, characterized in that, User initialization is divided into a commitment phase and a commit phase. The user inputs a public parameter pp and randomly selects a secret index α. i ∈ Locally compute the G1 power sequence S1={c ij } j ∈[L](c ij =[ The power sequence S2={d} of G1∈G1) and G2 is also known as d. ij } j∈[2L],j≠L+1 (dij=[ In the steps of ]2∈G2): The two-phase user initialization design is used to prevent commit order manipulation attacks and bias attacks. The commitment phase ensures that the user locks their choice before knowing the parameters of others, and the commit phase ensures the authenticity of the sequence through hash consistency verification. Commitment Phase: Calculate the commitment value C=H0(S1, S2) using the hash function H0, submit C to the smart contract, and the contract records all user commitments before proceeding to the next phase; Submission Phase: Using the Chaum-Pedersen protocol combined with the Fiat-Shamir transformation, a non-interactive zero-knowledge proof proof=(π1,π2) is generated to verify the consistency of the exponents of adjacent elements in S1 and S2. The tuple(seqi,proof) is submitted to the on-chain smart contract. After the contract verifies that H0(S1,S2) is consistent with the commitment value C, the user index i is returned.
4. The blockchain-based decentralized group communication authentication broadcast encryption method as described in claim 1, characterized in that, After generating the CRS, the smart contract receives all user-submitted (seq, proof) data and sequentially verifies the validity of π1 and π2, as well as the homology of S1 and S2. It then verifies e(c) through pairing. i1 ,[1]2)=e([1]1,d i1 ), and verify e(c ij g2) = e(g1, d ij (j∈[L]), e(c) i1 d ij )=e(g1,d i(j+1) (j∈[1, L-1, L+2, 2L]) and e(c i2 d iL )=e(g1,d i(L+2) The process involves aggregating the S1 and S2 sequences of all valid users to form a global CRS vector CRS=(CRS1, CRS2) and storing it in the blockchain. If verification fails, the process returns to the previous step. The global CRS vector is formed by aggregating the S1 and S2 sequences of all verified users, satisfying CRS1=(∏ i∈[L] [ ]1)(j∈[L])CRS2=(∏ i ∈[L][ ]2) (j∈[L]∪[L+2,2L]), and stored in the blockchain for all participants to call later.
5. The blockchain-based decentralized group communication authentication broadcast encryption method as described in claim 1, characterized in that, When joining the network, the user inputs public parameters pp, CRS, and index i, and randomly selects a secret ti∈ Calculate the private key usk i =[t i ·α (L+1—i) ]2 and public key upk i =([t i ]1, [t i α]2,[t i α 2 ]2,...,[t i α L ]2), put upk i Published to the blockchain, the smart contract verifies e(upk) through pairing. i0 , [α L ]2)=e([α (L—k) ]1,upk ik )=e([1]1,upk iL (k∈[0,L]) Verify validity; if verification passes, store upk. i User local storage USK i In the steps: The smart contract is deployed on the Ethereum Sepolia testnet and verifies the public key upk through multiple pairings. i The validity of the protocol ensures the legitimacy of network participants' identities, and the entire protocol does not need to be re-executed when the group size changes dynamically.
6. The blockchain-based decentralized group communication authentication broadcast encryption method as described in claim 1, characterized in that, After signing and encryption, the sender inputs public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j } j∈S Sender's private key (usk) s And message M, randomly select s∈ Calculate C1=[s]1 and C2=[s·Σ j∈S (t j +α j )]1, Generate key K=[sα (L+1) ] t Encrypt M to obtain C3=K·M, generate a hash value h using the hash function H1(K,M), and combine it with usk. s Calculate the signature C4=h ts The ciphertext ct = (C1, C2, C3, C4) is output and sent to the blockchain. The total fixed size of the ciphertext is 608 bytes. The additional step of transmitting [log2L] bits of receiver set information is as follows: The ciphertext size is fixed and unaffected by the size of the receiver set S. On-chain gas consumption changes minimally with group size, typically around 2^S. 8 -1 to 2 256 When the value is within the range of -1, the gas consumption remains between 243641 and 244223.
7. The blockchain-based decentralized group communication authentication broadcast encryption method as described in claim 1, characterized in that, After verification and decryption: the receiver inputs the public parameters pp, CRS, receiver set S, and receiver public key set {upk}. j } j∈S Self-index i, private key usk i And the ciphertext ct, reconstruct the key K=e(C2, [α (L+1—i) ]2)·e(C1 -1 usk i · ∏ j∈S ([t j ·α (L+1—i) ]2·[α (L+1+j-i )]2)), decrypt C3 to get M ′ =C3·K -1 Through H1(K, M) ′ Generate h ′ And verify e e(h′, If the verification passes, output M; otherwise, return to the step ⊥. The key reconstruction process relies solely on the recipient's own private key, the CRS stored on the blockchain, and the public key information. No other recipients need to participate in the collaboration. The execution time for decryption and verification increases linearly with the size of the recipient set.