A Blockchain-Based Method for Power Data Privacy Protection and Access Control
Through the blockchain-based power data privacy protection and access control method, power line data connection network is used to generate and manage user attribute keys, the problem of insufficient network security of traditional power systems is solved, data encryption and decryption is realized, and data security of power systems is improved.
Patent Information
- Application Number
- CN202010540608.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-12
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-06-12
AI Technical Summary
The network security of traditional smart power systems is not high, and data confidentiality cannot be guaranteed, which is easy to be cracked by criminals, resulting in user data leakage.
The power data privacy protection and access control method based on blockchain is adopted, and the system public parameters are generated through the first node in the blockchain system, and the power line data connection network is used to generate and manage user attribute keys, and data encryption and decryption are carried out to ensure data security.
Improve data security in the power system, prevent user data leakage, and enhance network security.
Smart Images

Figure CN113806755B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain, and in particular, to a method, device, and computer-readable storage medium for protecting power data privacy and access control based on blockchain. Background Art
[0002] With the rapid development of Internet technology, the application of intelligent technology and blockchain technology in the power system is becoming more and more extensive. However, the network security of traditional intelligent power systems is not high, and it is impossible to ensure the confidentiality of data. Lawbreakers can easily crack user keys through user attributes, thereby accessing the data in the power system and causing user data leakage. Summary of the Invention
[0003] The present application discloses a method, device, and computer-readable storage medium for protecting power data privacy and access control based on blockchain, which can improve the data security in the power system.
[0004] In a first aspect, the present application provides a method for protecting power data privacy and access control based on blockchain. The method is applied to a blockchain system based on a data connection network of power lines, and the method includes:
[0005] A first node in the blockchain system generates system public parameters based on user attributes;
[0006] The first node sends the user attributes to a second node in the blockchain system through a data connection network based on power lines, so that the second node generates a system key based on the user attributes and the system public parameters;
[0007] The first node responds to a user registration request, instructs the second node to generate a user attribute key, and sends the user attribute key to a third node in the blockchain system through a data connection network based on power lines;
[0008] The first node obtains the target data sent by the third node, encrypts the target data based on the system key to obtain a data ciphertext, and stores the data ciphertext;
[0009] The first node receives a user access request, decrypts the data ciphertext using the user attribute key, and sends the target data to the third node through a data connection network based on power lines.
[0010] In a second aspect, the present application provides a data access control device based on blockchain, including:
[0011] A generating unit for a first node in the blockchain system to generate system public parameters based on user attributes;
[0012] The generating unit is further configured to send the user attributes from the first node of the power line-based data connection network to the second node in the blockchain system through the power line-based data connection network, so that the second node generates a system key based on the user attributes and the system public parameters;
[0013] The indicating unit is configured to, in response to a user registration request by the first node, instruct the second node to generate a user attribute key, and send the user attribute key to a third node in the blockchain system through the power line-based data connection network;
[0014] The encrypting unit is configured to obtain target data sent by the third node by the first node, encrypt the target data based on the system key to obtain a data ciphertext, and store the data ciphertext;
[0015] The decrypting unit is configured to receive a user access request by the first node, decrypt the data ciphertext using the user attribute key, and send the target data to the third node through the power line-based data connection network.
[0016] In a third aspect, the present application provides a blockchain-based data access control device, including a processor, a memory, and a communication interface, where the processor, the memory, and the communication interface are interconnected. Among them, the memory is used to store a computer program, the computer program includes program instructions, and the processor is configured to call the program instructions to execute the blockchain-based data access control method described in the first aspect above.
[0017] In a fourth aspect, the present application provides a computer-readable storage medium storing one or more instructions, and the one or more instructions are adapted to be loaded and executed by a processor to execute the blockchain-based data access control method described in the first aspect above.
[0018] In the present application, the first node in the blockchain system generates system public parameters based on user attributes; the first node sends user attributes to the second node through the power line-based data connection network, so that the second node generates a system key based on the user attributes and the system public parameters; the first node responds to a user registration request, instructs the second node to generate a user attribute key, and sends the user attribute key to a third node in the blockchain system based on the power line-based data connection network; the first node obtains the target data sent by the third node, encrypts the target data based on the system key to obtain a data ciphertext, and stores the data ciphertext; the first node receives a user access request, decrypts the data ciphertext using the user attribute key, and sends the target data to the third node based on the power line-based data connection network. This improves the data security in the power system. Description of the Drawings
[0019] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0020] Figure 1 It is a scenario architecture diagram of a blockchain system provided by an embodiment of the present application;
[0021] Figure 2 It is a flowchart of a method for power data privacy protection and access control based on blockchain provided by an embodiment of the present application;
[0022] Figure 3 It is a schematic structural diagram of a data access control device based on blockchain provided by an embodiment of the present application;
[0023] Figure 4 It is a schematic structural diagram of another data access control device based on blockchain provided by an embodiment of the present application. Detailed implementation manners
[0024] The following will describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings.
[0025] The embodiments of the present application relate to blockchain and blockchain systems. Among them, blockchain (Block Chain) is a chain-like data structure formed by combining data blocks in sequence according to time order, and is a distributed ledger that uses cryptographic methods to ensure the immutability and non-forgery of data. Blockchain is essentially a decentralized database, a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block. Blockchain can include the blockchain underlying platform, the platform product service layer, and the application service layer. The blockchain system based on the power line data connection network is applied to the power system.
[0026] A blockchain system is a distributed application architecture that distributes tasks and workloads among peers, and is a networking or network form formed by the peer computing model at the application layer. Generally, a blockchain system includes multiple interconnected computers, which are also called node devices of the blockchain system. In the blockchain system environment, these multiple interconnected computers are in an equal position with each other, each computer has the same function, there is no master-slave distinction. One computer can act as a server to set shared resources for other computers in the network to use; it can also act as a workstation. Generally speaking, the entire network does not rely on a dedicated central server, nor does it have a dedicated workstation. Each computer in the network can act as a requester of network services and also respond to requests from other computers, providing resources, services, and content. Figure 1 This is a scenario architecture diagram of a blockchain system provided by an embodiment of the present application. As Figure 1 shown, the blockchain system includes a first node 101 corresponding to the server in the power system, a second node 102 corresponding to the weak center in the power system, and a third node 103 corresponding to the client. Figure 1 The number of each node in the blockchain system shown is only for example. For example, the first node 101, the second node 102, and the third node 103 can be multiple. There may also be a fourth node, a fifth node, etc. in the blockchain system. The present application does not limit the number of each node. Among them, the third node 103 corresponding to the client can be any one of the following: a terminal, an independent application, an API (Application Programming Interface), or an SDK (Software Development Kit). Among them, the terminal can include but is not limited to: a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a portable personal computer, a mobile Internet device (abbreviated as MID), etc. The embodiments of the present invention do not make limitations. The type of node device can include but is not limited to a full node, a simplified payment verification (SPV) node, or other node types in the blockchain system.
[0027] It should be noted that there is a core chain in the blockchain system for storing the complete data of the power system. It can be understood that only the third node 103 has the permission to view all the data of the core chain.
[0028] In Figure 1In the blockchain system shown, the process of data access control based on the blockchain mainly includes: ① The first node 101 in the blockchain system generates system public parameters based on user attributes. ② The first node 101 sends the user attributes to multiple second nodes 102 in the blockchain system through a power line-based data connection network, so that the second nodes 102 generate system keys based on the user attributes and the system public parameters. ③ In response to a user registration request, the first node 101 instructs the second nodes 102 to generate user attribute keys, and sends the user attribute keys to a third node 103 in the blockchain system through a power line-based data connection network. ④ The first node 101 obtains the target data sent by the third node 103, encrypts the target data based on the system key to obtain a data ciphertext, and stores the data ciphertext. ⑤ The first node 101 receives a user access request, decrypts the data ciphertext using the user attribute key, and sends the target data to the third node 103 through a power line-based data connection network
[0029] Through the above data access control method based on the blockchain, a data access control method, device, and computer-readable storage medium based on the blockchain are provided. The method includes: The first node in the blockchain system generates system public parameters based on user attributes; the first node sends the user attributes to the second node in the blockchain system through a power line-based data connection network, so that the second node generates a system key based on the user attributes and the system public parameters; in response to a user registration request, the first node instructs the second node to generate a user attribute key, and sends the user attribute key to the third node in the blockchain system through a power line-based data connection network; the first node obtains the target data sent by the third node, encrypts the target data based on the system key to obtain a data ciphertext, and stores the data ciphertext; the first node receives a user access request, decrypts the data ciphertext using the user attribute key, and sends the target data to the third node through a power line-based data connection network
[0030] Next, a method for protecting power data privacy and access control based on the blockchain provided by this application will be introduced in detail
[0031] Please refer to Figure 2 , Figure 2 which is a flowchart of a method for protecting power data privacy and access control based on the blockchain provided by an embodiment of this application. This data access control method based on the blockchain can be implemented through the interaction of the first node 101, the second node 102, and the third node 103 shown as follows; as Figure 1 shown, the data access control method based on the blockchain includes but is not limited to the following steps S201 to step S205: Figure 2 shown, the data access control method based on the blockchain includes but is not limited to the following steps S201 to step S205:
[0032] S201. The first node in the blockchain system generates system public parameters based on user attributes
[0033] At system initialization, a prime number p, G and G T are two multiplicative cyclic groups of prime order q, is a generator of g, and the bilinear mapping e: G×G→G T The first node selects the system threshold t and calculates the public parameters through the following formula:
[0034] 1) Hash function
[0035] 2) Public parameters params = {G, G T , p, g, e, t, H};
[0036] Among them, t is the decryption threshold preset by the system, that is, the user attribute set x and the decryption policy set f must have at least t identical attributes for the user x to decrypt. The user attribute set is a set of multiple user attributes. The user attribute set is determined according to the application scenario of the power system. Power systems for different purposes include different attributes, and different user attribute sets contain user attribute information in multiple dimensions. For the power system, it includes different roles, such as: power company employees, household electricity users, industrial electricity users, administrators, power suppliers, etc. The user attribute set included in this power system includes: identity dimension attributes, such as: household electricity user attributes, industrial electricity user attributes, power supplier attributes, etc. In addition, it can also include regional attributes, etc.
[0037] S202. The first node sends user attributes to the second node in the blockchain system through the data connection network based on the power line, so that the second node generates a system key based on the user attributes and the system public parameters.
[0038] In one implementation, the first node distributes the user attributes in the user attribute set to the second node in the blockchain system through the data connection network based on the power line. The first node selects any user attribute set A = {att1,..., att n} according to the power grid demand, where att i is the user attribute among them. The number of second nodes in the blockchain system is also n, and each second node is assigned a user attribute.
[0039] In one implementation, the calculation process of the second node ID i generating a system key based on the user attributes and the system public parameters includes: randomly selecting Calculating Broadcast the calculation result to each second node. For each attribute j∈S, select the hash function H for attribute encryption, calculate the parameter h according to formula 3), and add the parameter h to the public parameter params;
[0040] 3)
[0041] Each second node ID i Randomly select two polynomials of t - 1 according to the received common parameters. The polynomials are: f i (x) = a i0 + a i1 x +... + a i(t-1) x t-1 、f′ i (x) = b i0 + b i1 x +... + b i(t-1) x t-1 。
[0042] Each second node ID i Calculate and broadcast to each second node in combination with formula 4);
[0043] 4) where k = 0,..., t - 1;
[0044] Each second node ID i Calculate in combination with formulas 5) and 6), where j = 1,..., n, and then the second node ID i Send s ij and s ij ′ to ID j , where i ≠ j;
[0045] 5)s ij = f i (j)(mod p);
[0046] 6)s' ij = f′ i (j)(mod p);
[0047] The second node ID i After receiving s ij Verify through the equation If the equation holds, then consider this second node ID i as an honest second node, otherwise request retransmission.
[0048] The first node instructs the second node to repeat the steps of randomly selecting two polynomials of t - 1 according to the received common parameters, and combining formulas 4), 5), 6) and verifying that the second node ID i is an honest second node, where At this time, each weak center calculates and discloses
[0049] The first node calculates according to the equation
[0050] Second Node ID i Random Selection And calculate separately where s i As the system private key, S i As the system public key.
[0051] The first node calculates the sum of the private keys of each system and obtains the system master private key where s i It is kept separately by each second node, and s is the private key unknown to all second nodes.
[0052] The first node calculates the sum of the public keys of each system and obtains the system master public key The first node sends the system master public key to each second node.
[0053] S203. The first node responds to the user registration request, instructs the second node to generate a user attribute key, and sends the user attribute key to the third node in the blockchain system based on the data connection network of the power line.
[0054] In one embodiment, after completing the initialization of the blockchain system of the power line-based data connection network, the target user initiates a registration request to the first node through the third node 103. The user registration request carries the user identity information of the target user. After the first node determines the target user attributes based on the user identity information, it sends an indication message to the second node corresponding to the target user attributes. The indication message is used to instruct the second node to generate a user attribute key.
[0055] The first node instructs the second node to repeat the execution according to the instruction information by randomly selecting two t-1 polynomials according to the received public parameters (the polynomials are: f i (x) = a i0 +a i1 x+...+a i(t-1) x t-1 、f i ′(x)=b i0 +b i1 x+...+b i(t-1) x t-1 ), and combined with formula 4), 5), 6) and verify the second node ID i For the steps of the honest second node, a preset decryption threshold t is set at this time according to the needs. Each weak center calculates Where l = 1, ..., n. Each second node ID i Generator polynomial q i (x) = d i0 +d i1x +... + d in x n 。
[0056] The first node indicates each second node ID i Calculate the user attribute key according to the indication information And send the calculation result to the third node 103 corresponding to the target user, so that the client can generate its own user attribute key
[0057] S204. The first node obtains the target data sent by the third node, encrypts the target data based on the system key to obtain the data ciphertext, and stores the data ciphertext.
[0058] In one implementation, the data center in the blockchain system based on the power line data connection network obtains the target data m through the first node, where the target data is sent by the user to the first node through the third node, and the first node determines the multiple user attributes required to decrypt the target data as the decryption policy set f for decrypting the target data, that is, determines which user attributes are required to obtain the target data.
[0059] The first node randomly selects Perform encryption calculation on the target data through formula 7) to obtain the data ciphertext, and the first node sends the data ciphertext to the database of the power system for storage.
[0060] 7)
[0061] S205. The first node receives the user access request, decrypts the data ciphertext using the user attribute key, and sends the target data to the third node through the power line data connection network.
[0062] In one implementation, the first node in the blockchain system based on the power line data connection network receives the user access request of the target user sent by the third node. The user access request carries the target data ciphertext c that the target user needs to access and the user attribute key of the target user The first node decrypts the target data ciphertext c according to the user attribute key, and the decryption formula is 8):
[0063]
[0064] If the decryption is successful, the first node sends the target data ciphertext c to the third node for the target user to access.
[0065] Through the above blockchain-based data access control method, the first node in the blockchain system generates system public parameters based on user attributes; the first node sends the user attributes to the second node in the blockchain system through a power line-based data connection network, enabling the second node to generate system keys based on the user attributes and the system public parameters; the first node responds to a user registration request, instructs the second node to generate user attribute keys, and sends the user attribute keys to the third node in the blockchain system through a power line-based data connection network; the first node obtains the target data sent by the third node, encrypts the target data based on the system keys to obtain a data ciphertext, and stores the data ciphertext; the first node receives a user access request, decrypts the data ciphertext using the user attribute keys, and sends the target data to the third node through a power line-based data connection network. This improves the data security in the power system.
[0066] The above details the method of the embodiments of the present application. To facilitate better implementation of the above solutions of the embodiments of the present application, correspondingly, the following provides the devices of the embodiments of the present application.
[0067] Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of a blockchain-based data access control device provided by an embodiment of the present application. The blockchain-based data access control device can be mounted on the first node 101 in the above method embodiment. Figure 3 The shown blockchain-based data access control device can be used to execute some or all of the functions in the above Figure 2 described method embodiment. Among them, the detailed descriptions of each unit are as follows:
[0068] The generation unit 301 is used for the first node in the blockchain system to generate system public parameters based on user attributes;
[0069] The generation unit 301 is also used for the first node to send the user attributes to the second node in the blockchain system through a power line-based data connection network, enabling the second node to generate system keys based on the user attributes and the system public parameters;
[0070] The indication unit 302 is used for the first node to respond to a user registration request, instruct the second node to generate user attribute keys, and send the user attribute keys to the third node in the blockchain system through a power line-based data connection network;
[0071] The encryption unit 303 is used for the first node to obtain the target data sent by the third node, encrypt the target data based on the system keys to obtain a data ciphertext, and store the data ciphertext;
[0072] The decryption unit 304 is configured to receive a user access request at the first node, decrypt the data ciphertext using the user attribute key, and send the target data to the third node through the power line-based data connection network.
[0073] In one embodiment, the generating unit 301 is further configured to:
[0074] The first node calculates the multiplicative cyclic group using bilinear mapping to obtain a bilinear group; determines the decryption threshold based on the user attributes and the decryption policy set; calculates the bilinear group and the decryption threshold using a hash function; and determines the calculation result as the generated common parameter.
[0075] In one embodiment, the generating unit 301 is further configured to:
[0076] The first node distributes user attributes to multiple second nodes in the blockchain system; the first node performs attribute encryption calculation based on the user attributes and the common parameter; determines whether the second node meets the verification condition according to the calculation result; if the second node meets the verification condition, determines the second node as an honest second node.
[0077] In one embodiment, the generating unit 301 is further configured to:
[0078] The first node receives a user registration request of a target user, and the user registration request carries the user identity information of the target user; the first node determines the target user attributes according to the user identity information; the first node sends indication information to the second node corresponding to the target user attributes, and the indication information is used to indicate the second node to generate a user attribute key.
[0079] In one embodiment, the indicating unit 302 is further configured to:
[0080] The first node responds to a user registration request sent by the third node, and the user registration request carries the user identity information of the target user; the first node determines the target user attributes according to the user identity information; the first node instructs the second node corresponding to the target user attributes to calculate a user attribute key according to a preset decryption threshold.
[0081] In one embodiment, the encryption unit 303 is further configured to:
[0082] The first node obtains the target data sent by the third node; the first node determines the user attributes required to decrypt the target data; determines the multiple user attributes required to decrypt the target data as the decryption policy set; and performs encryption calculation on the target data according to the decryption to obtain the data ciphertext.
[0083] According to an embodiment of the present application, Figure 2 Some or all of the steps involved in the data access control method based on blockchain shown can be performed byFigure 3 executed by each unit in the blockchain - based data access control device shown. For example, Figure 2 Steps S201 and S202 shown in Figure 3 can be executed by the generation unit 301 shown in Figure 3 Step S203 can be executed by the indication unit 302 shown in Figure 3 Step S204 can be executed by the encryption unit 303 shown in Figure 3 Step S205 can be executed by the decryption unit 304 shown in Figure 3 Each unit in the blockchain - based data access control device shown can be separately or all combined into one or several other units to form, or some of them can be further split into multiple smaller functional units to form, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. The above - mentioned units are divided based on logical functions. In actual applications, the function of one unit can also be realized by multiple units, or the functions of multiple units can be realized by one unit. In other embodiments of the present application, the blockchain - based data access control device may also include other units. In actual applications, these functions can also be assisted by other units and can be realized by the cooperation of multiple units.
[0084] According to another embodiment of the present application, it can be achieved by running a computer program (including program code) capable of executing the respective steps involved in the corresponding methods shown in Figure 2 and Figure 3 on a general - purpose computing device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random - access storage medium (RAM), and a read - only storage medium (ROM), to construct the blockchain - based data access control device shown in Figure 4 and to implement the blockchain - based data access control method of the embodiments of the present application. The user attribute key, and send the user attribute key to the third node in the blockchain system based on the data connection network of the power line. The computer program can be recorded on a computer - readable recording medium, for example, and loaded into the above - mentioned computing device through the computer - readable recording medium and run therein.
[0085] Based on the same inventive concept, the principle of solving problems and the beneficial effects of the blockchain - based data access control device provided in the embodiments of the present application are similar to the principle of solving problems and the beneficial effects of the blockchain - based data access control device in the method embodiments of the present application. The principle and beneficial effects of the method implementation can be referred to. For the sake of concise description, they will not be elaborated here.
[0086] Please refer to Figure 4 , Figure 4The figure shows a schematic structural diagram of a data access control device based on a blockchain provided by an exemplary embodiment of the present application. The data access control device based on the blockchain at least includes a processor 401, a communication interface 402, and a memory 403. Among them, the processor 401, the communication interface 402, and the memory 403 can be connected through a bus 404 or other means. In the embodiment of the present application, the connection through the bus is taken as an example. Among them, the processor 401 (or Central Processing Unit, CPU) is the computing core and control core of the terminal. It can parse various instructions in the terminal and process various data of the terminal. For example, the CPU can be used to parse the power-on and power-off instructions sent by the user to the terminal and control the terminal to perform power-on and power-off operations; for another example, the CPU can transmit various interactive data between the internal structures of the terminal, and so on. The communication interface 402 can optionally include a standard wired interface, a wireless interface (such as WI-FI, a mobile communication interface, etc.), and can be used to send and receive data under the control of the processor 401; the communication interface 402 can also be used for the transmission and interaction of internal data of the terminal. The memory 403 (Memory) is a memory device in the terminal, used to store programs and data. It can be understood that the memory 403 here can include both the built-in memory of the terminal and, of course, the extended memory supported by the terminal. The memory 403 provides a storage space, and this storage space stores the operating system of the terminal, which can include but is not limited to: Android system, iOS system, Windows Phone system, etc. The present application does not make any limitations in this regard.
[0087] In the embodiment of the present application, the processor 401 performs the following operations by running the executable program code in the memory 403:
[0088] The first node in the blockchain system generates system public parameters based on user attributes;
[0089] For the first node to respond to a user registration request through the communication interface 402, instruct the second node to generate a user attribute key, and send the user attribute key to the third node in the blockchain system through a power line-based data connection network;
[0090] The first node obtains the target data sent by the third node through the communication interface 402, encrypts the target data based on the system key to obtain a data ciphertext, and stores the data ciphertext;
[0091] The first node receives a user access request through the communication interface 402, decrypts the data ciphertext using the user attribute key, and sends the target data to the third node through the power line-based data connection network using the communication interface 402.
[0092] As an alternative implementation, the processor 401 also performs the following operations by running the executable program code in the memory 403:
[0093] The first node calculates a multiplicative cyclic group using a bilinear mapping to obtain a bilinear group; determines a decryption threshold value based on user attributes and a decryption policy set; calculates the bilinear group and the decryption threshold value using a hash function; and determines the calculation result as the generated public parameter.
[0094] In one implementation, the processor 401 also performs the following operations by running the executable program code in the memory 403:
[0095] The first node distributes user attributes to multiple second nodes in the blockchain system; the first node performs attribute encryption calculation based on the user attributes and the public parameter; determines whether the second node meets the verification condition according to the calculation result; and if the second node meets the verification condition, determines the second node as an honest second node.
[0096] In one implementation, the processor 401 also performs the following operations by running the executable program code in the memory 403:
[0097] The first node receives a user registration request from a target user, and the user registration request carries the user identity information of the target user; the first node determines the target user attributes according to the user identity information; and the first node sends indication information to a second node corresponding to the target user attributes, where the indication information is used to instruct the second node to generate a user attribute key.
[0098] In one implementation, the processor 401 also performs the following operations by running the executable program code in the memory 403:
[0099] The first node responds to a user registration request sent by a third node, and the user registration request carries the user identity information of the target user; the first node determines the target user attributes according to the user identity information; and the first node instructs a second node corresponding to the target user attributes to calculate a user attribute key according to a preset decryption threshold value.
[0100] In one implementation, the processor 401 also performs the following operations by running the executable program code in the memory 403:
[0101] The first node obtains target data sent by a third node; the first node determines the user attributes required to decrypt the target data; determines the multiple user attributes required to decrypt the target data as a decryption policy set; and performs encryption calculation on the target data according to the decryption to obtain a data ciphertext.
[0102] Based on the same inventive concept, the principle and beneficial effects of the blockchain-based data access control device provided in the embodiments of the present application are similar to those of the blockchain-based data access control device in the method embodiments of the present application. For the principle and beneficial effects of the method, reference can be made to the embodiments of the method. For the sake of brevity, they will not be described herein again.
[0103] The embodiments of the present application further provide a computer-readable storage medium, in which one or more instructions are stored, and the one or more instructions are suitable for being loaded and executed by a processor to perform the blockchain-based data access control method in the above method embodiments.
[0104] The embodiments of the present application further provide a computer program product containing instructions, which, when running on a computer, causes the computer to execute the blockchain-based data access control method in the above method embodiments.
[0105] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0106] The steps in the method embodiments of the present application can be adjusted, combined, and deleted according to actual needs.
[0107] The modules in the device embodiments of the present application can be combined, divided, and deleted according to actual needs.
[0108] Those of ordinary skill in the art can understand that all or part of the steps in the above various methods can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. The readable storage medium can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.
[0109] The above-disclosed is only a preferred embodiment of the present application. Of course, the scope of rights of the present application cannot be limited thereby. Those of ordinary skill in the art can understand all or part of the processes of implementing the above embodiments, and the equivalent changes made according to the claims of the present application still fall within the scope covered by the invention.
Claims
1. A blockchain-based method for power data privacy protection and access control, characterized in that, The method is applied to a blockchain system of a power line-based data connection network, and the method includes: A first node in the blockchain system generates system public parameters based on user attributes; The first node sends the user attributes to a second node in the blockchain system through the power line-based data connection network, so that the second node generates a system key based on the user attributes and the system public parameters; The first node responds to a user registration request, instructs the second node to generate a user attribute key, and sends the user attribute key to a third node in the blockchain system through the power line-based data connection network; The first node obtains the target data m sent by the third node, determines the user attributes required to decrypt the target data m, determines the multiple user attributes required to decrypt the target data m as the decryption policy set f, encrypts the target data m based on the decryption policy set f to obtain a data ciphertext, and stores the data ciphertext, where the first node randomly selects , and performs an encryption calculation on the target data m through the following formula to obtain a target data ciphertext c; , where S is the system public key, g is the generator, is the attribute; The first node receives a user access request of a target user sent by the third node, where the user access request carries the target data ciphertext c that the target user needs to access and the user attribute key of the target user , A is any set of user attributes, is the set of user attributes corresponding to the target user in the any set of user attributes, is the user attribute key calculated by the first node instructing the second node according to the indication information. The first node uses the user attribute key to decrypt the target data ciphertext c, and the decryption formula is , where t is the decryption threshold preset by the system; Send the target data m to the third node through the power line-based data connection network.
2. The method according to claim 1, characterized in that, The first node in the blockchain system generates system public parameters based on user attributes, including: The first node calculates a multiplicative cyclic group using a bilinear mapping to obtain a bilinear group; Determine a decryption threshold based on the user attributes and the decryption policy set; Calculate the bilinear group and the decryption threshold using a hash function; Determine the calculation result as the system public parameters.
3. The method according to claim 1, wherein The first node sends the user attributes to a second node in the blockchain system through the power line-based data connection network, so that the second node generates a system key based on the user attributes and the system public parameters, including: The first node distributes the user attributes to multiple second nodes in the blockchain system; The first node performs attribute encryption calculation based on the user attributes and the public parameters; Judge whether the second node meets the verification condition according to the calculation result; If the second node meets the verification condition, determine the second node as an honest second node.
4. The method according to claim 3, wherein The first node sends the user attributes to a second node in the blockchain system through the power line-based data connection network, so that the second node generates a system key based on the user attributes and the system public parameters, including: The first node calculates the system private key and the system public key of each honest second node respectively; The first node calculates the sum of the system private keys to obtain a system master private key, and the system master private key is kept confidential for each second node; The first node calculates the sum of the system public keys to obtain a system master public key, and the first node sends the system master public key to each second node.
5. The method according to claim 1, wherein The first node responds to a user registration request, instructs the second node to generate a user attribute key, and sends the user attribute key to a third node in the blockchain system through the power line-based data connection network, including: The first node receives the user registration request of the target user, and the user registration request carries the user identity information of the target user; The first node determines the target user attributes according to the user identity information; The first node sends the indication information to the second node corresponding to the target user attributes, and the indication information is used to instruct the second node to generate the user attribute key.
6. The method according to claim 5, wherein The first node responds to a user registration request, instructs the second node to generate a user attribute key, and sends the user attribute key to a third node in the blockchain system based on a data connection network of a power line, including: The first node responds to a user registration request sent by the third node, where the user registration request carries user identity information of the target user; The first node determines the target user attribute according to the user identity information; The first node instructs a second node corresponding to the target user attribute to calculate the user attribute key according to a preset decryption threshold value.
7. A data access control device based on blockchain, characterized in that, The device is applied to a blockchain system based on a data connection network of a power line and includes: A generation unit, configured to generate system public parameters by a first node in the blockchain system based on user attributes; The generation unit is further configured to send the user attributes by the first node to a second node in the blockchain system through a data connection network of a power line, so that the second node generates a system key based on the user attributes and the system public parameters; An instruction unit, configured to, when the first node responds to a user registration request, instruct the second node to generate a user attribute key, and send the user attribute key to a third node in the blockchain system through a data connection network of a power line; An encryption unit is used for the first node to obtain the target data m sent by the third node, determine the user attributes required for decrypting the target data m, determine the multiple user attributes required for decrypting the target data m as the decryption policy set f, encrypt the target data m based on the decryption policy set f to obtain a data ciphertext, and store the data ciphertext, where the first node randomly selects , and performs an encryption calculation on the target data m through the following formula to obtain a target data ciphertext c; , where S is the system public key and g is the generator, is the attribute; A decryption unit is configured to receive, at the first node, a user access request of a target user sent by the third node. The user access request carries the target data ciphertext c that the target user needs to access and the user attribute key of the target user , where A is any set of user attributes is the set of user attributes corresponding to the target user in the any set of user attributes is the user attribute key calculated by the first node instructing the second node according to the indication information. The first node uses the user attribute key to decrypt the target data ciphertext c. The decryption formula is , where t is the decryption threshold value preset by the system; Send the target data m to the third node through a data connection network of a power line.
8. A data access control device based on blockchain, characterized in that, It includes a processor, a memory, and a communication interface, where the processor, the memory, and the communication interface are interconnected. The memory is configured to store a computer program, the computer program includes program instructions, and the processor is configured to call the program instructions to execute the blockchain-based data access control method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more instructions, and the one or more instructions are adapted to be loaded and executed by a processor to execute the blockchain-based data access control method according to any one of claims 1 to 6.
Citation Information
Patent Citations
A blockchain data access control method and device based on attribute encryption
CN109711184A
Data access control method and system in large-scale cloud storage based on block chain
CN110493347A