A blockchain rewrite method for supporting traitor tracing and bilateral access control functions
By introducing a one-time chameleon hash function and bilateral access strategy into the blockchain, combined with encryption technology based on traceable attributes, the problem that blockchain transactions cannot be modified is solved, and the fine-grained one-time rewrite of blockchain transactions is realized, and the rebellious tracking and bilateral access control functions are provided.
Patent Information
- Application Number
- CN202211256404.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-14
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-10-14
AI Technical Summary
The existing blockchain technology cannot be modified once the transaction is uploaded at the application level, resulting in the problem of application impact.
A blockchain rewritable method is proposed to support rebellious tracking and bilateral access control functions. Through one-time chameleon hash function, bilateral access strategy and encryption technology based on traceable attributes, the fine-grained one-time rewrite of blockchain transactions is realized.
It realizes fine-grained one-time rewrite of transactions at blockchain application level. Only authorized user nodes that meet a given access strategy can modify the transaction data stored on the blockchain and only once, and have rebellious tracking and bilateral access control functions.
Smart Images

Figure CN115632784B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of privacy protection in blockchain, and specifically relates to a blockchain rewriting method for supporting traitor tracing and bilateral access control functions. Background Art
[0002] Blockchain is a new technology that emerged along with Bitcoin. Its essence is a distributed database with core technologies such as distributed ledger, asymmetric encryption, smart contracts, and consensus mechanisms. In recent years, blockchain technology has developed rapidly from Bitcoin to other fields, the industrial system has gradually become more perfect, and the integration perspective has also become more diversified. However, due to the lack of blockchain correction technology, in the famous The Dao incident, hackers exploited vulnerabilities in smart contracts to conduct more than 200 attacks, directly leading to the fork of Ethereum. Therefore, with the needs of applications, it is very necessary, and even required by law, to study the mechanism for rewriting blockchain under control. Under certain specific conditions, it is necessary to modify, update, or even rewrite the content stored in the blockchain, such as the legislative requirements for data protection, vulnerabilities in smart contracts, etc. For example, inappropriate data (such as child abuse images) stored in blockchain transactions may need to be deleted to avoid violating the regulations on illegal content.
[0003] At present, there are mainly two types of methods to achieve transaction rewriting on the application layer of blockchain: modifying the blockchain at a coarse-grained level by introducing a chameleon hash function; achieving fine-grained rewriting of the blockchain by introducing a policy-based chameleon hash function. However, through the above methods, users with trapdoors can modify the blockchain infinitely. Therefore, how to design a blockchain with a one-time rewriting function is the key problem to be solved currently. Summary of the Invention
[0004] The purpose of the present invention is to solve the problem that once a transaction on the application layer of the blockchain is uploaded, it cannot be modified, which affects the application, and to propose a blockchain rewriting method for supporting traitor tracing and bilateral access control functions.
[0005] To solve the above problems, the technical solution adopted by the present invention is:
[0006] A blockchain rewriting method for supporting traitor tracing and bilateral access control functions, including the following steps:
[0007] (1) PPGen PCH (1 κ ) → (pk PCH , sk PCH ): Input the security parameter κ, and the system initialization algorithm calls the RSA algorithm and the traceable attribute-based encryption scheme of the pairing-based attribute-based encryption MABE, where PPGenPCH (1 κ ) represents the public parameter generation algorithm, pk PCH represents the generated public key, sk PCH represents the generated private key, and the specific execution is as follows:
[0008] 1) Run the key generator RSAKGen(1 κ ), select different large prime numbers p1, q1 of 1024 bits, and calculate N1 = p1q1. Select a parameter l greater than 2048 bits, and select e > 2 l , calculate d1 that satisfies the condition ed1 ≡ 1 mod(p1 - 1)(q1 - 1) and X0 = x0 e mod N1, where Select a symmetric encryption algorithm (KGen SE , Enc SE , Dec SE )(where KGen SE represents the symmetric key generation algorithm, Enc SE represents the symmetric encryption algorithm, Dec SE represents the symmetric decryption algorithm), tag τ, and two hash functions, and Set the hash public key and collision private key of the one-time chameleon hash function with a temporary trapdoor to be:
[0009]
[0010] 2) Run the algorithm BilGen(1 κ ), and output the bilinear group parameters The authority KGC randomly selects α, β ∈ Z p , four hash functions, H1: Ω snd → G, H2: Ω rcv → G, H3: {0, 1} * → G, H4: {0, 1} * → Z p and a symmetric encryption algorithm Enc μ with the symmetric key as μ, where H3 is a collision-resistant hash function, and H1 and H2 are random oracles. Then set the public key mpk ABE and private key msk ABE to be:
[0011]
[0012] Combining 1) and 2), set the system public key pk PCH and private key sk PCH to be respectively:
[0013] pk PCH =(mpk ABE ,pk CHET ),sk PCH =(msk ABE ,sk CHET ); (3)
[0014] (2)KGen PCH (sk PCH ,S,R,R ID )→(ek,dk): The key generation algorithm KGen PCH (sk PCH ,S,R,R ID ), input the attribute set S of the sender, and the receiver submits the identity R to the KGC ID and the attribute set R. The KGC generates the encryption key ek associated with the attribute set S of the sender, and the identity R ID and the attribute set R of the receiver to generate the decryption key dk, specifically as follows:
[0015] 1) EKGen PCH (sk PCH ,S)→ek: The temporary key generation algorithm EKGen PCH (sk PCH ,S) Input the attribute set S = {att snd,1 ,S and,2 ,...S and,k},The encryption key algorithm selects r ∈ R Z p , and calculates the temporary key ek as follows:
[0016] ek=(S,{ek 1,i =g α H1(att snd,i ) r}}, ek2 = g i∈[k] ) (4)
[0017] The KGC sends ek to the sender;
[0018] 2) DKGen PCH (sk PCH ,R,R ID )→dk: The decryption key generation algorithm DKGen PCH (sk PCH ,R,R ID ) Input the attribute set R = {att rcv,1 ,att rcv,2 ,...att rcv,l}, the KGC calculates a = Enc μ (RID ), for \(j\in[l]\), the decryption key algorithm selects \(b\) j \(\in\) R \(\mathbb{Z}\) p , and calculates the decryption key \(dk\) as follows:
[0019]
[0020] The KGC sends \((dk, sk\) CHET ) to the receiver;
[0021] (3) Hash PCH (\(pk\) PCH , \(ek, R, S', m, (N, \pi))\to(h, r)\): The hash value generation algorithm Hash PCH (\(pk\) PCH , \(ek, R, S', m, (N, \pi))\) parses the system public key \(pk\) PCH , the encryption key \(ek\), the message \(m\), and the access policy structure \((N, \pi)\) of the receiver, where the matrix The mapping function \(\pi:[l]\to\Omega\) rcv , then, the data owner calculates as follows:
[0022] 1) Run the key generator \(RSAKGen(1\) κ ), generate \(N_2 = p_2q_2\), \(d_2\) satisfies \(ed_2\equiv1\bmod(p_2 - 1)(q_2 - 1)\), calculate \(X_2 = x_2\) e \(\bmod N_2\), where Select the hash function:
[0023] 2) Calculate Select Let Given \(pk\) PCH , \(\tau, m\in\mathbb{Z}\) e , and finally calculate and Denote \(h'=(h_1, h_2)\);
[0024] 3) Select \(r\in\{0, 1\}\) κ 、\(k\in KGen\) SE (1\) κ ) and an invertible encoding function \(encode\), and calculate \(s = H_4(r, N)\), select a set of vectors Calculate For each \(i\in[l]\), select and take \(r', t\in\mathbb{Z}\) p , denote \(S'=\{att\) snd,1 , \(att\) snd,2 ,... \(att\) snd,k′}\), where In addition, the function π(i) maps the i-th row of the matrix N to the corresponding attribute R i as follows:
[0025]
[0026] K = encode(k, r),
[0027] Let For each i' ∈ [k'], since So there must be a j such that S i ' = S j and is calculated as follows:
[0028]
[0029] Denote Take Calculate f = H5(C'), Denote the ciphertext and (h, r) = ((h', N2, CT), r');
[0030] (4) Verify PCH ((M, ρ), CT) → 0 or 1: Verification algorithm Verify PCH ((M, ρ), CT) parses the sender's access policy structure (M, ρ), where the matrix Mapping function ρ: [l] → Ω snd , select a set of vectors Calculate Denote I = {i | i ∈ [l], ρ(i) = S}, and a set of parameters {w i} i∈I such that Then, calculate the following equation:
[0031]
[0032] If the above equation holds, the algorithm returns 1, otherwise, the algorithm returns 0;
[0033] (5) Adapt PCH (pk PCH , sk PCH , m, m', (h, r)) → r': Adaptation algorithm Adapt PCH (pk PCH , sk PCH , m, m', (h, r)) inputs the public key pk PCH 、private key sk PCH, the messages m and m', and (h, r), and then perform the following calculations:
[0034] 1) The algorithm parses the public key pk PCH , the message m, and (h, r), and verifies the following two conditions:
[0035]
[0036]
[0037] If both conditions are satisfied, the algorithm returns 1; otherwise, the algorithm returns 0.
[0038] 2) Only when the receiver's attribute set R satisfies the corresponding access policy (N, π) in the ciphertext CT, the receiver parses sk CHET = d1, denote J = {j|j ∈ [l], π(j) = R}, and can find a set of parameters {η j} j∈J such that Then, calculate the following equation:
[0039] Let
[0040] (k′, r′) = encode -1 (K′) (11)
[0041] 3) Calculate s′ = H4((r′, N)), f′ = H5(C′), and Verify whether it holds. If it holds, then calculate Otherwise, terminate the algorithm.
[0042] 4) From formulas (9) and (10), it is known that the two conditions are satisfied. The algorithm parses the tag τ, the message m, and the message m′, and selects Then, calculate the following expressions:
[0043]
[0044]
[0045] Denote
[0046] 5) If or then the algorithm returns ⊥; otherwise, the algorithm returns Therefore, the user can successfully modify the message m to m′.
[0047] Verification of correctness:
[0048]
[0049]
[0050] (6) KeyCheck(mpk ABE , dk) → 0 or 1: The key check algorithm KeyCheck(mpk ABE , dk) inputs the public key mpk ABE and the decryption key dk. The KGC checks whether the key dk meets the following three conditions:
[0051] 1) The form of dk satisfies dk = (dk′, {dk 0,j , dk 1,j , dk 2,j}}, and dk′ ∈ Z j∈[l] , dk p , dk 0,j , dk 1,j ∈ G, {dk 2,j}} j∈[l] ∈ G;
[0052] 2)
[0053] 3) If all of the above three conditions hold, the key check algorithm outputs 1; otherwise, it returns 0;
[0054] (7) Trace(dk) → R ID or ⊥: If the result of the key check by the trace decryption key algorithm Trace(dk) is 1, it indicates that the decryption key dk is a key with the correct form, and the KGC can extract R ID = Dec μ (dk′); otherwise, the trace algorithm outputs the termination symbol ⊥.
[0055] The solution proposed by the present invention is based on one-time chameleon hash functions, bilateral access policies, and attribute-based encryption for traceability. The present invention supports fine-grained one-time rewriting of transactions at the blockchain application level, where only authorized user nodes that meet the given access policy can modify the transaction data stored on the blockchain and only once. The present invention can also trace legitimate users who leak keys to illegal users. In addition, the proposed bilateral access policy enables fog nodes to retrieve valid ciphertexts from a large number of ciphertexts uploaded by sender nodes, thereby reducing the workload of the receiver. The advantages of the present invention are as follows: by utilizing policy-based chameleon hash functions and having the function of only correcting transactions in the blockchain application layer once; by introducing attribute policies for senders and receivers, thereby flexibly implementing bilateral access policies; by introducing the identity of the sender, realizing a blockchain rewritable method for traitor tracing. Using attribute-based encryption technology to achieve fine-grained controllable and rewritable functions for the blockchain provides a basis for ensuring the privacy protection of the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 is a flowchart of a one-time rewritable blockchain solution that supports traitor tracing and bilateral access control;
[0057] Figure 2 is a schematic diagram of a one-time rewritable blockchain system that supports traitor tracing and bilateral access control;
[0058] Figure 3 Performance diagrams of each stage of a one-time rewritable blockchain solution that supports traitor tracing and bilateral access control. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] As Figures 1 to 3 shown, a blockchain rewritable method for supporting traitor tracing and bilateral access control functions in this embodiment includes the following steps:
[0060] (1) PPGen PCH (1 κ ) → (pk PCH , sk PCH ): Input the security parameter κ, and the system initialization algorithm calls the RSA algorithm and the traceable attribute-based encryption scheme of the pairing-based attribute-based encryption MABE. Among them, PPGen PCH (1 κ ) represents the public parameter generation algorithm, pk PCH represents the generated public key, and sk PCH represents the generated private key. The specific execution is as follows:
[0061] 1) Run the key generator RSAKGen(1 κ), select different large prime numbers p1, q1 of 1024 bits, and calculate N1 = p1q1. Select a parameter l greater than 2048 bits, and select e > 2 l , calculate d1 that satisfies the condition ed1 ≡ 1 mod(p1 - 1)(q1 - 1) and X0 = x0 e mod N1, where Select a symmetric encryption algorithm (KGen SE , Enc SE , Dec SE )(where KGen SE represents the symmetric key generation algorithm, Enc SE represents the symmetric encryption algorithm, Dec SE represents the symmetric decryption algorithm), tag τ, and two hash functions, and Set the hash public key and collision private key of the one-time chameleon hash function with a temporary trapdoor to be:
[0062]
[0063] 2) Run the algorithm BilGen(1 κ ), and output the bilinear group parameters The authority KGC randomly selects α, β ∈ Z p , four hash functions, H1: Ω snd → G, H2: Ω rcv → G, H3: {0, 1} * → G, H4: {0, 1} * → Z p and a symmetric encryption algorithm Enc μ with the symmetric key as μ, where H3 is a collision-resistant hash function, and H1 and H2 are random oracles. Then set the public key mpk ABE and private key msk ABE to be:
[0064]
[0065] Combining 1) and 2), set the system public key pk PCH and private key sk PCH to be respectively:
[0066] pk PCH =(mpk ABE , pk CHET ), sk PCH =(msk ABE , sk CHET ); (3)
[0067] (2) KGenPCH (sk PCH , S, R, R ID ) → (ek, dk): Key generation algorithm KGen PCH (sk PCH , S, R, R ID ), the input is the attribute set S of the sender, and the receiver submits the identity R to the KGC ID and the attribute set R. The KGC generates the encryption key ek associated with the sender's attribute set S and the decryption key dk associated with the receiver's identity R ID and the attribute set R as follows:
[0068] 1) EKGen PCH (sk PCH , S) → ek: Temporary key generation algorithm EKGen PCH (sk PCH , S) The input attribute set S = {att snd,1 , S and,2 ,... S and,k}, the encryption key algorithm selects r ∈ R Z p , and calculates the temporary key ek as follows:
[0069] ek = (S, {ek 1,i = g α H1(att snd,i ) r}, ek2 = g i∈[k] ) (4) r )
[0070] The KGC sends ek to the sender;
[0071] 2) DKGen PCH (sk PCH , R, R ID ) → dk: Decryption key generation algorithm DKGen PCH (sk PCH , R, R ID ) The input attribute set R = {att rcv,1 , att rcv,2 ,... att rcv,l}, the KGC calculates a = Enc μ (R ID ), for j ∈ [l], the decryption key algorithm selects b j ∈ R Z p , and calculates the decryption key dk as follows:
[0072]
[0073] KGC sends (dk, sk CHET ) to the receiver;
[0074] (3) Hash PCH (pk PCH , ek, R, S′, m, (N, π)) → (h, r): Generate the hash value algorithm Hash PCH (pk PCH , ek, R, S′, m, (N, π)) parses the system public key pk PCH , the encryption key ek, the message m, and the access policy structure (N, π) of the receiver, where the matrix mapping function π: [l] → Ω rcv , then, the data owner calculates as follows:
[0075] 1) Run the key generator RSAKGen(1 κ ), generate N2 = p2q2, d2 satisfies ed2 ≡ 1 mod(p2 - 1)(q2 - 1), calculate X2 = x2 e mod N2, where Select the hash function:
[0076] 2) Calculate Select Let Given pk PCH , τ, m ∈ Z e , finally calculate and Record h′ = (h1, h2);
[0077] 3) Select r ∈ {0, 1} κ , k ∈ KGen SE (1 κ ) and an invertible encoding function encode, and calculate s = H4(r, N), select a set of vectors Calculate For each i ∈ [l], select and take r′, t ∈ Z p , record S′ = {att snd,1 , att snd,2 ,... att snd,k′} where In addition, the function π(i) maps the i-th row of the matrix N to the corresponding attribute R i as follows:
[0078]
[0079] K = encode(k, r),
[0080] Let For each \(i'\in[k']\), since So we can surely find a \(j\) such that \(S\) i ' = \(S\) j , and the calculation is as follows:
[0081] Denote Take Calculate \(f = H5(C')\), Denote the ciphertext and \((h,r)=((h',N2,CT),r')\);
[0082] (4)Verify PCH \(((M,\rho),CT)\to0\ or\ 1)\): Verification algorithm Verify PCH \(((M,\rho),CT)\) parses the sender's access policy structure \((M,\rho)\), where the matrix Mapping function \(\rho:[l]\to\Omega\) snd , select a set of vectors Calculate Denote \(I = \{i|i\in[l],\rho(i)=S\}\), and can find a set of parameters \(\{w\) i}\) i∈I such that Then, calculate the following equation:
[0083]
[0084] If the above equation holds, the algorithm returns 1, otherwise, the algorithm returns 0;
[0085] (5)Adapt PCH (pk PCH ,sk PCH ,m,m',(h,r))\to r': Adaptation algorithm Adapt PCH (pk PCH ,sk PCH ,m,m',(h,r)) inputs the public key pk PCH , the secret key sk PCH , the messages m and m' and \((h,r)\), and then performs the following calculations:
[0086] 1) The algorithm parses the public key pk PCH , the message m and \((h,r)\), and verifies the following two conditions:
[0087]
[0088]
[0089] If all conditions are satisfied, the algorithm returns 1; otherwise, the algorithm returns 0.
[0090] 2) Only when the attribute set R of the receiver satisfies the corresponding access policy (N, π) in the ciphertext CT, the receiver parses sk CHET = d1, denote J = {j|j ∈ [l], π(j) = R}, and can find a set of parameters {η j} j∈J such that Then, calculate the following equation:
[0091] Let
[0092] (k′, r′) = encode -1 (K′) (11)
[0093] 3) Calculate s′ = H4((r′, N)), f′ = H5(C′) and Verify whether it holds. If it holds, then calculate Otherwise, terminate the algorithm;
[0094] 4) From formulas (9) and (10), it is known that the two major conditions are satisfied. The algorithm parses the tag τ, the message m and the message m′, and selects Then, calculate the following expressions:
[0095]
[0096]
[0097] Denote
[0098] 5) If or then the algorithm returns ⊥; otherwise, the algorithm returns Therefore, the user can successfully modify the message m to m′;
[0099] Correctness verification:
[0100]
[0101]
[0102] (6) KeyCheck(mpk ABE , dk) → 0 or 1: The key verification algorithm KeyCheck(mpk ABE , dk) takes the public key mpk ABE and the decryption key dk as input. The KGC checks whether the key dk satisfies the following three conditions:
[0103] 1) The form of dk satisfies dk = (dk′, {dk 0,j , dk 1,j , dk 2,j}}, j∈[l] ) and dk′ ∈ Z p , dk 0,j 、dk 1,j ∈ G, {dk 2,j}} j∈[l] ∈ G;
[0104] 2)
[0105] 3) If all of the above three conditions are satisfied, the key check algorithm outputs 1; otherwise, it returns 0;
[0106] (7) Trace(dk) → R ID or ⊥: If the result of the key check by the trace decryption key algorithm Trace(dk) is 1, it indicates that the decryption key dk is a key with the correct form, and the KGC can extract R ID = Dec μ (dk′), otherwise, the trace algorithm outputs the termination symbol ⊥.
[0107] The present invention is deployed on a client on 64-bit Windows 10, and the client has a processor of 2.90GHz Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz and 12GB of memory. The present invention implements a once-rewritable blockchain scheme using the JPBC library under the platform IDEA.
[0108] In the experiment, the number of attributes is set to increase linearly from 10 to 100 in increments of 10, and all six stages of the scheme are run 1000 times, and finally the average value is taken as the result of each stage. As Figure 3 shown, in the system parameter initialization stage, the public parameters are constants and do not increase with the growth of the number of attributes, and the time is approximately 0.01s. Therefore, the generation time of the initialization parameters tends to be stable. The Hash PCH algorithm and the access policies of the sender and receiver used in the Verify PCH algorithm are both related to the attribute set, so the running time of the algorithm will increase with the growth of the number of attributes. In the Adapt PCH algorithm, when the number of attributes increases, the running time for calculating a hash collision also increases. When implementing the Trace algorithm, since the KeyCheck algorithm is incorporated, the cost of tracing malicious users is also related to the attributes.
Claims
1. A blockchain rewritable method for supporting traitor tracing and bilateral access control functions, characterized in that: Including the following steps: (1) PPGen PCH (1 κ ) → (pk PCH , sk PCH ) : Input the security parameter κ. The system initialization algorithm calls the RSA algorithm and the traceable attribute-based encryption scheme of the pairing-based attribute-based encryption MABE, where PPGen PCH (1 κ ) represents the public parameter generation algorithm, pk PCH represents the generated public key, sk PCH represents the generated private key. The specific execution is as follows: 1) Run the key generator RSAKGen(1 κ ), select different large prime numbers p1, q1 of 1024 bits, and calculate N1 = p1q1. Select a parameter l greater than 2048 bits, and select e > 2 l , calculate d1 that satisfies the condition ed1 ≡ 1 mod(p1 - 1)(q1 - 1) and X0 = x0 e mod N1, where Select a symmetric encryption algorithm (KGen SE , Enc SE , Dec SE ): where KGen SE represents the symmetric key generation algorithm, Enc SE represents the symmetric encryption algorithm, Dec SE represents the symmetric decryption algorithm, label τ, and two hash functions, and Set the hash public key and collision private key of the one-time chameleon hash function with a temporary trapdoor to be respectively: 2) Run the algorithm BilGen(1 κ ), and output the bilinear group parameters The authority KGC randomly selects α, β ∈ Z p , four hash functions, H1: Ω snd → G, H2: Ω rcv → G, H3: {0, 1} * → G, H4: {0, 1} * → Z p and a symmetric encryption algorithm Enc with the symmetric key μ μ , where H3 is a collision-resistant hash function, H1 and H2 are random oracles, and then set the public key mpk ABE and the private key msk ABE as follows: Based on 1) and 2), set the system public key pk PCH and the private key sk PCH respectively as follows: pk PCH =(mpk ABE , pk CHET ), sk PCH =(msk ABE , sk CHET ); (3) (2) KGen PCH (sk PCH , S, R, R ID ) → (ek, dk): Key generation algorithm KGen PCH (sk PCH , S, R, R ID ), input the attribute set S of the sender, and the receiver submits the identity R to the KGC ID and the attribute set R. The KGC generates the encryption key ek associated with the sender's attribute set S, and the identity R of the associated receiver ID and the attribute set R generate the decryption key dk, specifically as follows: 1) EKGen PCH (sk PCH , S) → ek: The temporary key generation algorithm EKGen PCH (sk PCH , S) inputs the attribute set S = {att snd,1 , S and,2 ,...S and,k}, selects r ∈ R Z p for the encryption key algorithm, and calculates the temporary key ek as follows: ek=(S,{ek 1,i =g α H1(att snd,i ) r} i∈[k] , ek2 = g r ) (4) KGC sends ek to the sender; 2) DKGen PCH (sk PCH , R, R ID ) → dk: Decryption key generation algorithm DKGen PCH (sk PCH , R, R ID ) Input attribute set R = {att rcv,1 , att rcv,2 ,... att rcv,l}, KGC calculates a = Enc μ (R ID ). For j ∈ [l], the decryption key algorithm selects b j ∈ R Z p and calculates the decryption key dk as follows: KGC sends (dk, sk CHET ) to the receiver; (3)Hash PCH (pk PCH , ek, R, S′, m, (N, π)) → (h, r): The hash value generation algorithm Hash PCH (pk PCH , ek, R, S′, m, (N, π)) parses the system public key pk PCH , the encryption key ek, the message m, and the access policy structure (N, π) of the receiver, where the matrix The mapping function π: [l] → Ω rcv , then, the data owner calculates as follows: 1) Run the key generator RSAKGen(1 κ ), generate N2 = p2q2, where d2 satisfies ed2 ≡ 1 mod (p2 - 1)(q2 - 1), and calculate X2 = x2 e mod N2, where Select a hash function: 2) Calculate Select Let Given pk PCH , τ, m ∈ Z e , finally calculate and Denote h′ = (h1, h2); 3) Select r ∈ {0, 1} κ , k ∈ KGen SE (1 κ ) and an invertible encoding function encode, and compute s = H4(r, N), select a set of vectors Compute For each i ∈ [l], select and take r′, t ∈ Z p , and denote S′ = {att snd,1 , att snd,2 ,... att snd,k′}, where In addition, the function π(i) maps the i-th row of the matrix N to the corresponding attribute R i as follows: Let For each \(i'\in[k']\), since So one must be able to find \(j\) such that \(S i ' = S j , and calculate as follows: ek 1,i′ = ek 1,j H1(att snd,i′ ) r′ = g α H1(att snd,i′ ) r+r′ , C 5,i′ = ek 1,i′ H3(C 1-4 ) t = g α H1(att snd,i′ ) r+r′ H3(C 1-4 ) t (7) Record Fetch Calculate f = H5(C′), Record the ciphertext and (h, r) = ((h′, N2, CT), r′); (4)Verify PCH ((M,ρ),CT)→0 or 1: Verification algorithm Verify PCH ((M,ρ),CT) parses the sender's access policy structure (M,ρ), where the matrix mapping function ρ: [l] → Ω snd , select a set of vectors Calculate Let I = {i|i ∈ [l], ρ(i) = S}, and be able to find a set of parameters {w i} i∈I such that Then, calculate the following equation: If the above equation holds, the algorithm returns 1; otherwise, the algorithm returns 0; (5) Adapt PCH (pk PCH , sk PCH , m, m', (h, r)) → r′: The adaptation algorithm Adapt PCH (pk PCH , sk PCH , m, m', (h, r)) takes as input the public key pk PCH , the secret key sk PCH , the messages m and m' and (h, r), and then performs the following calculations: 1) Analyze the public key pk of the algorithm PCH , the message m, and (h, r), and verify the following two conditions: If all conditions are met, the algorithm returns 1; otherwise, the algorithm returns 0; 2) The receiver can decrypt sk only when the set of attributes R of the receiver satisfies the corresponding access policy (N, π) in the ciphertext CT CHET = d1, denote J = {j|j ∈ [l], π(j) = R}, and can find a set of parameters {η j} j∈J such that Then, calculate the following equation: (k′, r′) = encode -1 (K′) (11) 3) Calculate s′ = H4((r′, N)), f′ = H5(C′) and Verify whether it holds. If it holds, then calculate Otherwise, terminate the algorithm; 4) From equations (9) and (10), it is known that the two major conditions are satisfied. The algorithm analyzes the tag τ, the message m, and the message m′, and selects Then, calculate the following expressions: Record 5) If or Then the algorithm returns ⊥, otherwise, the algorithm returns Therefore, the user can successfully modify the message m into m′; Correctness verification: (6) KeyCheck(mpk ABE , dk) → 0 or 1: The key check algorithm KeyCheck(mpk ABE , dk) inputs the public key mpk ABE and the decryption key dk. The KGC checks whether the key dk meets the following three conditions: 1) The form of dk satisfies dk = (dk′, {dk 0,j , dk 1,j , dk 2,j}), and dk′ ∈ Z j∈[l] , and dk p , dk 0,j , dk 1,j ∈ G, {dk 2,j} j∈[l] ∈ G; 2) 3) If all of the above three conditions are met, the key check algorithm outputs 1; otherwise, it returns 0. (7)Trace(dk)→R ID or ⊥: If the result of the key check in the Trace(dk) decryption key algorithm is 1, it means that the decryption key dk is a key with the correct format, and the KGC can extract R ID =Dec μ (dk′), otherwise, the trace algorithm outputs the termination symbol ⊥.