A privacy data sharing method and system based on blockchain
By adopting a blockchain-based privacy data sharing method in the social network of vehicles, the lack of distributed and decentralized security in the existing technology is solved, data traceability and user privacy protection are realized, and data sharing is improved.
Patent Information
- Application Number
- CN202211580454.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-12-09
AI Technical Summary
The lack of distributed and decentralized security in the social network of vehicles has led to third parties' potential to initiate dishonest behavior, and data sharing lacks access control, user privacy is threatened, and data sources are difficult to track.
A blockchain-based privacy data sharing method is adopted, and a large attribute set is defined through a trusted organization and a public parameter is constructed, a vehicle attribute is collected and an attribute base key is issued, the blockchain is started between the fog nodes, the access control policy, symmetric key and ciphertext is generated and uploaded, and the roadside unit is verified whether the requested object is the shared data of the vehicle.
It realizes distributed and decentralized security, provides data traceability, avoids dishonest behavior by third parties, protects user privacy, and improves the security and efficiency of data sharing.
Smart Images

Figure CN115913546B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to a privacy data sharing method and system based on blockchain. Background Art
[0002] Social Internet of Vehicles (SIoV) can improve traffic safety and alleviate traffic congestion by sharing vehicle perception data, and even provide comprehensive social services. However, traditional data sharing does not provide distributed and decentralized security, making it possible for third parties to initiate dishonest behavior. In addition, data sharing in SIoV lacks access control, which easily leads to unauthorized data sharing, threatening user privacy, and making it difficult to trace the source of leaked data. Summary of the invention
[0003] The present invention aims to solve at least one of the technical problems existing in the prior art. To this end, the present invention proposes a privacy data sharing method and system based on blockchain, which can provide distributed and decentralized security, and can trace the source of shared data to avoid dishonest behavior that may be initiated by a third party.
[0004] In a first aspect, an embodiment of the present invention provides a method for sharing private data based on blockchain, and the method for sharing private data based on blockchain includes:
[0005] Defining a large attribute set through a trusted institution and constructing public parameters based on the large attribute set;
[0006] Collecting vehicle attributes according to the large attribute set of constructed public parameters, and issuing attribute base keys of the vehicle;
[0007] The blockchain is started between preset fog nodes through the trusted institution; the fog nodes include a file server, a data server and an audit server;
[0008] Acquiring the shared data of the vehicle, and generating an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle; the symmetric key is encrypted by the attribute base key;
[0009] The access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle are uploaded to the roadside unit; the roadside unit is used to save the access control policy and symmetric key corresponding to the shared data of the vehicle to the data server and save the ciphertext corresponding to the shared data of the vehicle to the file server;
[0010] When receiving a request for obtaining shared data of the vehicle, verifying by the roadside unit whether an object of the request for obtaining is the shared data of the vehicle;
[0011] If the object of the acquisition request is the shared data of the vehicle, the ciphertext corresponding to the shared data of the vehicle is decrypted according to the access control policy and symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle; the record of replying the shared data of the vehicle will be saved to the audit server through the roadside unit.
[0012] The method according to the embodiment of the present invention has at least the following beneficial effects:
[0013] A large attribute set is defined by a trusted institution, and public parameters are constructed based on the large attribute set. Then, the attributes of the vehicle are collected, the trusted institution and the vehicle are initialized, one-to-many data sharing is achieved, the user's privacy is protected, and the flexibility of the system is increased. The blockchain is started between preset fog nodes by a trusted institution, and all transactions and new states of smart contracts can be verified through the fog nodes, and they can be uploaded to the blockchain according to the consensus mechanism, ensuring that the user's identity and data privacy are protected during the data sharing process, providing a highly secure and integrated environment for sharing data. The shared data of the vehicle, the acquisition request for verifying the shared data of the vehicle, and the shared data of the shared vehicle are divided into three categories of storage through the roadside unit. Each party only stores a complete backup of the data related to itself and collaborates with each other, which improves security and effectively reduces the storage and communication overhead of nodes in data sharing.
[0014] According to some embodiments of the present invention, defining a large attribute set through a trusted institution and constructing a public parameter according to the large attribute set includes:
[0015] The large attribute set is defined by the trusted institution, and a group generator algorithm is run to obtain a group and a bilinear map; the group and the bilinear map are used to describe the large attribute set;
[0016] A plurality of groups of elements are selected according to the large attribute set to form the public parameters; the public parameters are used for CP-ABE encryption of the large attribute set.
[0017] According to some embodiments of the present invention, the collecting the attributes of the vehicle according to the large attribute set of the constructed public parameters and issuing the attribute base key of the vehicle includes:
[0018] The attributes of the vehicle are collected according to the large attribute set of constructed public parameters; the attributes of the vehicle include the real identity of the owner, the occupation of the owner, the hobbies of the owner and the places the owner often visits; the real identity of the owner is the unique identifier of the vehicle;
[0019] Adding the real identity of the owner of the vehicle to an identity mapping table; the identity mapping table is used to obtain all attributes of the vehicle according to the real identity of the owner of the vehicle;
[0020] An attribute base key of the vehicle is calculated and issued through the trusted authority and all attributes of the vehicle.
[0021] According to some embodiments of the present invention, the acquiring the shared data of the vehicle and generating an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle include:
[0022] Customizing the access control policy of the shared data of the vehicle through the LSSS linear secret sharing scheme;
[0023] The symmetric key and ciphertext of the shared data of the vehicle are calculated through the access control policy of the shared data of the vehicle.
[0024] According to some embodiments of the present invention, uploading the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit includes:
[0025] Signing an index of the shared data of the vehicle to obtain a verifiable signature of the shared data of the vehicle;
[0026] The verifiable signature, access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle are uploaded to the roadside unit; the roadside unit verifies the legitimacy of the verifiable signature, access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle through the verifiable signature of the shared data of the vehicle.
[0027] According to some embodiments of the present invention, when receiving a request for obtaining shared data of the vehicle, verifying by the roadside unit whether an object of the request for obtaining is the shared data of the vehicle includes:
[0028] Comparing, by the roadside unit, an index of the request for obtaining the shared data of the vehicle with an index of the shared data of the vehicle;
[0029] If the index of the acquisition request for the shared data of the vehicle matches the index of the shared data of the vehicle, then the object of the acquisition request is the shared data of the vehicle.
[0030] According to some embodiments of the present invention, decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and the symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle includes:
[0031] Finding a storage address in the file system of the file server according to an index of the acquisition request of the shared data of the vehicle;
[0032] Obtaining the ciphertext address and symmetric key of the shared data of the vehicle according to the storage address;
[0033] A symmetric key for decrypting the shared data of the vehicle using the attribute base key of the vehicle;
[0034] The ciphertext corresponding to the ciphertext address of the shared data of the vehicle is decrypted according to the symmetric key of the decrypted shared data of the vehicle, and the shared data of the vehicle is obtained and replied.
[0035] According to some embodiments of the present invention, after decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and the symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle, the method further includes:
[0036] When a complaint is received that the shared data of the vehicle contains false content, the identity of the vehicle is traced.
[0037] According to some embodiments of the present invention, the step of tracing the identity of the vehicle includes:
[0038] Identity tracing is performed through the verifiable signature of the shared data of the vehicle and the real identity of the vehicle in the identity mapping table.
[0039] In a second aspect, an embodiment of the present invention provides a privacy data sharing system based on blockchain, and the privacy data sharing system based on blockchain includes:
[0040] A large attribute set module, used to define a large attribute set through a trusted institution and construct public parameters according to the large attribute set;
[0041] A vehicle attribute collection module, used for collecting vehicle attributes according to the large attribute set of constructed public parameters, and issuing an attribute base key of the vehicle;
[0042] A blockchain startup module, used to start the blockchain between preset fog nodes through the trusted institution; the fog nodes include a file server, a data server and an audit server;
[0043] A vehicle shared data acquisition module, used to acquire the shared data of the vehicle and generate an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle; the symmetric key is encrypted by the attribute base key;
[0044] The uploading roadside unit module is used to upload the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit; the roadside unit is used to save the access control policy and symmetric key corresponding to the shared data of the vehicle to the data server and save the ciphertext corresponding to the shared data of the vehicle to the file server;
[0045] a request object verification module, configured to, upon receiving a request for obtaining shared data of the vehicle, verify through the roadside unit whether the object of the request for obtaining is the shared data of the vehicle;
[0046] A data sharing module is used to obtain and reply the shared data of the vehicle by decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and symmetric key corresponding to the shared data of the vehicle provided by the roadside unit if the object of the acquisition request is the shared data of the vehicle; the record of replying the shared data of the vehicle will be saved to the audit server through the roadside unit.
[0047] It should be noted that the beneficial effects between the second aspect of the present invention and the prior art are the same as the beneficial effects of the blockchain-based privacy data sharing method of the first aspect, and will not be described in detail here.
[0048] Other features and advantages of the present invention will be set forth in the description which follows, and in part will be apparent from the description, or may be learned by practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0050] Figure 1 This is a flowchart of a privacy data sharing method based on blockchain provided by an embodiment of the present invention;
[0051] Figure 2 A flowchart of defining a large attribute set through a trusted institution and constructing public parameters according to the large attribute set provided by an embodiment of the present invention;
[0052] Figure 3 It is a flow chart of collecting vehicle attributes and issuing vehicle attribute base keys according to a large attribute set of constructed public parameters provided by an embodiment of the present invention;
[0053] Figure 4 It is a flowchart of obtaining shared data of a vehicle and generating an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle provided by an embodiment of the present invention;
[0054] Figure 5It is a flow chart of uploading the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit provided by an embodiment of the present invention;
[0055] Figure 6 It is a flowchart of verifying whether the object of the acquisition request is the shared data of the vehicle through the roadside unit according to an embodiment of the present invention;
[0056] Figure 7 It is a flowchart of obtaining and replying the shared data of the vehicle by decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and symmetric key corresponding to the shared data of the vehicle provided by the roadside unit according to an embodiment of the present invention;
[0057] Figure 8 A flowchart of tracing the identity of a vehicle when receiving a complaint that the shared data of the vehicle is false is provided by an embodiment of the present invention;
[0058] Fig. 9 It is a structural diagram of a privacy data sharing system based on blockchain provided by one embodiment of the present invention;
[0059] Fig.10 This is a schematic diagram of a system model of a privacy data sharing method based on blockchain provided by an embodiment of the present invention;
[0060] Fig.11 This is a schematic diagram of a blockchain-based privacy data sharing method provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0061] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be understood as limiting the present invention.
[0062] In the description of the present invention, if there is a description of first, second, etc., it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features.
[0063] In the description of the present invention, it should be understood that descriptions involving orientation, such as orientation or positional relationship indicated as up, down, etc., are based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present invention.
[0064] In the description of the present invention, it should be noted that, unless otherwise clearly defined, terms such as setting, installing, connecting, etc. should be understood in a broad sense, and technicians in the relevant technical field can reasonably determine the specific meanings of the above terms in the present invention in combination with the specific content of the technical solution.
[0065] The technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described below are only some embodiments of the present invention, not all embodiments.
[0066] Reference Figure 1 In some embodiments of the present invention, a privacy data sharing method based on blockchain is provided, comprising:
[0067] Step S100: define a large attribute set through a trusted institution, and construct public parameters based on the large attribute set.
[0068] Step S200: Collect the attributes of the vehicle according to the large attribute set of the constructed public parameters, and issue the attribute base key of the vehicle.
[0069] Step S300: Start the blockchain between preset fog nodes through a trusted organization; the fog nodes include a file server, a data server and an audit server.
[0070] Step S400: Acquire the shared data of the vehicle, and generate an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle; the symmetric key is encrypted by the attribute base key.
[0071] Step S500, uploading the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit; the roadside unit is used to save the access control policy and symmetric key corresponding to the shared data of the vehicle to the data server and save the ciphertext corresponding to the shared data of the vehicle to the file server.
[0072] Step S600: When receiving a request for obtaining shared data of a vehicle, verify through a roadside unit whether the object of the request is the shared data of the vehicle.
[0073] Step S700: If the object of the acquisition request is the shared data of the vehicle, the ciphertext corresponding to the shared data of the vehicle is decrypted according to the access control policy and symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle; the record of the replied shared data of the vehicle will be saved to the audit server through the roadside unit.
[0074] Step S100 and step S200 define a large attribute set through a trusted institution, construct public parameters based on the large attribute set, and then collect the attributes of the vehicle, initialize the trusted institution and the vehicle, realize one-to-many data sharing, protect the privacy of users, and increase the flexibility of the system; step S300 starts the blockchain between preset fog nodes through the trusted institution, and can verify the new status of all transactions and smart contracts through the fog nodes, and upload them to the blockchain according to the consensus mechanism, to ensure that the user's identity and data privacy are protected during the data sharing process, and provide a highly secure and integrated environment for sharing data; step S400, step S500, step S600, and step S700 divide the acquisition of vehicle shared data, verification of vehicle shared data acquisition request and shared vehicle shared data into three categories of storage through roadside units, and each party only stores a complete backup of data related to itself and cooperates with each other, which improves security and effectively reduces the storage and communication overhead of nodes in data sharing.
[0075] It should be noted that, in order to facilitate the understanding of the embodiments, the meanings of the parameters in the subsequent embodiments are shown in Table 1:
[0076] Table 1
[0077]
[0078] Reference Figure 2 In some embodiments of the present invention, a large attribute set is defined by a trusted institution, and public parameters are constructed according to the large attribute set, including:
[0079] Step S101: define a large attribute set through a trusted institution, and run a group generator algorithm to obtain a group and a bilinear map; the group and the bilinear map are used to describe the large attribute set.
[0080] Step S102: Select multiple groups of elements to form public parameters according to the large attribute set; the public parameters are used for CP-ABE encryption of the large attribute set.
[0081] TA defines a large attribute set U = Z p , and run the group generator algorithm to obtain the group and bilinear mapping g(lλ) description U=(P,G1,G2,e), where G1 and G2 are two cyclic groups of prime order P, satisfying the bilinear mapping e:G1×G1→G2. Then TA randomly selects parameters g,u,h,f,b∈G1 and α,a∈Z p , where u, h generate HASH in the attribute layer, f is used to ensure the secret randomness r and s, b is used to bind the attribute layer and the secret sharing layer, and the master private key Msk={α,a},H:{0,1} * →Z p is a hash function with a fixed output range, and finally obtains the public parameters:
[0082] p={U,H,g,u,h,f,b,g a ,e(g,g)α}.
[0083] It should be noted that the trusted third-party organization TA generates public parameters based on the large attribute set CP-ABE construction. The large attribute set construction consists of two independent layers, namely the attribute layer and the secret sharing layer. The public parameters consist of six groups of elements (g,u,h,f,b,e(g,g) α ) to achieve secure CP-ABE encryption of large attribute sets. In the "attribute layer", the parameters u,h provide a hash function of the form Boneh-Boyen[] (u A h), while in the secret sharing layer, parameter f holds the share of the secret randomness r during key generation and guarantees the secret randomness s during the shared encryption phase. Parameter b is used to bind the two layers together. Parameters g and e(g,g) α It is used to generate the master key function and allow correct decryption. Then, the trusted third party TA will authenticate the blockchain nodes and authorize them to participate in the consensus process. Here, it is assumed that TA has selected some trusted fog servers to participate in the consensus process in advance, and the blockchain is started between the pre-set server nodes according to the RAFT (Leader Election Consensus Algorithm) consensus mechanism.
[0084] The attribute layer and secret sharing layer constructed through a large attribute set further strengthen the security of shared data, and bind the two together to eliminate the problem of tampering with data without being detected, thereby improving trust.
[0085] Reference Figure 3 In some embodiments of the present invention, the attributes of a vehicle are collected according to a large attribute set of constructed public parameters, and an attribute base key of the vehicle is issued, including:
[0086] Step S201, collecting vehicle attributes based on the large attribute set of constructed public parameters; the vehicle attributes include the real identity of the owner, the owner's occupation, the owner's hobbies and interests, and the places the owner often visits; the real identity of the owner is the unique identifier of the vehicle.
[0087] Step S202: Add the real identity of the vehicle owner to the identity mapping table; the identity mapping table is used to obtain all attributes of the vehicle according to the real identity of the vehicle owner.
[0088] Step S203: Calculate and issue the attribute base key of the vehicle through the trusted institution and all attributes of the vehicle.
[0089] It should be noted that the real identity VID of the vehicle owner is collected i, as the unique identifier of the car owner, as well as the owner's occupation, hobbies, frequented places and other information are sent to TA. Then TA generates a random number According to the real identity VID of the vehicle i Generating identity embeddings And add it to the identity mapping table TA obtains the attribute set A = {A1, A2, ..., A n}, then TA selects n+1 random indices r,r1,r2,...,r n ∈Z p , then calculate N1=g r , for every ξ∈[n], we have:
[0090] N ξ,2 =g rξ ,N ξ,3 =(u Aξ h) rξ b -r ;
[0091] Calculate the decryption key:
[0092]
[0093] Finally, TA converts the public parameters p and sK id Loaded into the vehicle OBU.
[0094] By further collecting the attributes of the vehicle, the falsification of vehicle attributes can be prevented. The unique identification of the vehicle owner can provide a fast and accurate comparison identification for subsequent traceability, reducing the fluke mentality of falsifying vehicle sharing data and improving the authenticity of falsification of vehicle sharing data.
[0095] Reference Figure 4 In some embodiments of the present invention, obtaining the shared data of the vehicle and generating the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle include:
[0096] Step S401: Customize the access control policy of the shared data of the vehicle through the LSSS linear secret sharing scheme.
[0097] Step S402: Calculate the symmetric key and ciphertext of the shared data of the vehicle through the access control policy of the shared data of the vehicle.
[0098] Use the LSSS linear secret sharing scheme to customize access policies and calculate where M is the secret policy matrix, ρ:[l]→Z p is the secret sharing matrix, and then randomly selects the secret sharing vector Where s is the shared random secret share, y j is a random number. Then the vehicle V i Enter common parameters to calculate get Among them, M i is the i-th row of the secret strategy matrix. Then, l indices t1, t2, t3, ..., t are randomly selected. l ∈Z p , and calculate C = sd·e(g,g) sα ,C0=g s , for each ξ∈[l], we have
[0099] C ξ,1 =f λξ b tξ ,C ξ,2 =(u ρ(ζ) h) -tξ ,C ξ,3 =g tξ ;
[0100] Finally, the ciphertext is obtained:
[0101]
[0102] Customizing the access control policy of the vehicle's shared data through the LSSS linear secret sharing scheme can protect the user's identity and data privacy and ensure the security of the vehicle's shared data.
[0103] Reference Figure 5 In some embodiments of the present invention, uploading the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit includes:
[0104] Step S501: Sign the index of the shared data of the vehicle to obtain a verifiable signature of the shared data of the vehicle;
[0105] Among them, for vehicle V i Sign the data index to generate a verifiable signature:
[0106] Sig i (Γ) = e(g ci ,gη)
[0107] Among them, η=H(Γ||timestamp), the vehicle will eventually {Sig i (Γ),CT sd ,ct,Γ,timestamp} is uploaded to the nearby RSU nodes.
[0108] Step S502: Upload the verifiable signature, access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit; the roadside unit verifies the legitimacy of the verifiable signature, access control policy, symmetric key and ciphertext uploaded corresponding to the shared data of the vehicle through the verifiable signature of the shared data of the vehicle;
[0109] Among them, RSU passes Sig i (Γ) Verify the legitimacy of the uploaded vehicle. First, calculate η′=H(Γ′||timestamp′), and then send the result to the fog node for verification. The fog node calculates Then calculate The information is compared with the information stored in the blockchain. If it exists, it means that the vehicle is legal, and a message of successful authentication is returned to the RSU. The RSU then uploads the ciphertext to the file system, which is mounted on the blockchain and can store the ciphertext uploaded by the vehicle to ensure that the message is not tampered with. The file system stores the data ciphertext ct and generates the corresponding storage address indexaddr based on ct and the data index Γ. The RSU stores the data index and the symmetric key CT encrypted by the attribute base. sd Upload to the data chain and record transaction TX provide :
[0110] RSU i →blockchain:{Γ,CT sd ,TX provide}.
[0111] Fine-grained access control is achieved through verifiable signatures to prevent malicious nodes from uploading, and the source and validity of the data are ensured through the unforgeability of the signature.
[0112] Reference Figure 6 In some embodiments of the present invention, when receiving a request for obtaining shared data of a vehicle, verifying whether the object of the request is the shared data of the vehicle by a roadside unit includes:
[0113] Step S601: Compare the index of the vehicle's shared data acquisition request with the index of the vehicle's shared data through a roadside unit.
[0114] Step S602: If the index of the request for obtaining the shared data of the vehicle matches the index of the shared data of the vehicle, the object of the acquisition request is the shared data of the vehicle.
[0115] It should be noted that comparing the index of the vehicle's shared data acquisition request with the index of the vehicle's shared data by the roadside unit includes:
[0116] Send a request to a nearby RSU:
[0117] Req={Request||Sig y (Γ)||timestamp}
[0118] The request includes the time, purpose and content of the requested data, index ID, etc. y (Γ) content, is the vehicle V y Generated verifiable signature;
[0119] After the vehicle is authenticated, the RSU finds the storage address from the file system according to the index requested by the vehicle, and then sends the encrypted symmetric private key CT sd And the ciphertext address {CT,indexaddr} is sent to the vehicle:
[0120] RSU x →V y :{CT sd ,indexaddr};
[0121] RSU is also responsible for recording the request transaction Tr i And save the shared records in the blockchain. Shared records are used to achieve data sharing record traceability, user self-certification and non-repudiation. Shared records include data uploader V i Signature of data requester V y The signature, timestamp and request Req:
[0122] RSU x →blockchain:Tri={Sigi(Γ)||Sigy(Γ)||timestamp||Req}.
[0123] Reference Figure 7 In some embodiments of the present invention, decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and the symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle includes:
[0124] Step S701: Find a storage address in a file system in a file server according to an index of a request for obtaining shared data of a vehicle.
[0125] Step S701: Obtain the ciphertext address and symmetric key of the shared data of the vehicle according to the storage address.
[0126] Step S703: decrypt the symmetric key of the shared data of the vehicle using the attribute base key of the vehicle.
[0127] Step S704: decrypt the ciphertext corresponding to the ciphertext address of the shared data of the vehicle according to the symmetric key of the decrypted shared data of the vehicle, and obtain and reply the shared data of the vehicle.
[0128] It should be noted that the specific steps are as follows: First, decrypt CT using its attribute private key sd Get the symmetric key sd. V y First, we compute a set of row vectors in M that are generated by the attributes in A, namely If the attribute set A is not the authorized set of the access policy, then it cannot satisfy the access structure of (M,ρ) and this step ends. Otherwise, construct a {ω j ∈Z p} j∈l The constant vector is of the form ∑ j∈I ω j M j =(1,0,...,0), where M i is the i-th row of the matrix M. If S is the set of authorized accesses, then ∑ j∈I ω j λ j =s, there may be other different ways to choose ω j The value of is used to satisfy this, and then the following calculation is performed:
[0129]
[0130] Where ξ is the attribute set The index of the attribute vector in (depends on j);
[0131] Calculation correctness:
[0132]
[0133] in,
[0134] Finally, the symmetric key sd can be calculated:
[0135]
[0136] After the vehicle obtains the symmetric key sd, the vehicle V finds the address of the ciphertext ct from the file system through the address indexaddr and downloads the ciphertext ct. Then the vehicle V y Decrypt the ciphertext ct using the symmetric key sd, and finally get the plaintext data:
[0137] D=Dec sd (ct).
[0138] Reference Figure 8 In some embodiments of the present invention, after decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and the symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle, it also includes:
[0139] Step S800: When a complaint is received that the shared data of a vehicle contains false content, the identity of the vehicle is traced.
[0140] It should be noted that traceability ensures the authenticity of tracking through the immutability of blockchain and prevents malicious users from denying it.
[0141] By tracing the identity of the vehicle, the user's identity and data privacy are protected during the data sharing process, and the real identity of malicious users who provide false information can be tracked.
[0142] In some embodiments of the present invention, the identity of a vehicle is traced, including:
[0143] Identity traceability is achieved through the verifiable signature of the vehicle’s shared data and the vehicle’s real identity in the identity mapping table.
[0144] It should be noted that the algorithm for identity tracing is shown in Table 2:
[0145] Table 2
[0146]
[0147]
[0148] Reference Fig.10 and Fig.11 In order to facilitate the understanding of those skilled in the art, a specific embodiment of the present invention provides a privacy data sharing method based on blockchain, including:
[0149] The first step is to prepare the system model.
[0150] The system model mainly involves: trusted institutions, fog servers, RSUs, vehicles, and file systems.
[0151] (1) Trusted Authority
[0152] As a fully trusted third-party organization, TA believes that TA has nearly unlimited computing power and will not collude with other entities. It is responsible for the initialization of the entire system, key generation and distribution, initialization of the alliance chain and deployment of smart contracts, vehicle identity registration, and TA is also responsible for the traceability of vehicle identity.
[0153] (2) Vehicles
[0154] The vehicle has an OBU (On board Unit) device. This article assumes that the content in the OBU is completely secure and cannot be obtained by external attacks. The identities of the vehicle in this system are divided into data providers and data requesters, which provide data and receive shared data respectively, and the vehicle can switch its identity freely. The uploader encrypts and uploads some road information, traffic information, route information, and some information collected by vehicle sensors, and only users with specific access rights can decrypt it.
[0155] (3) RSU (Road Side Unit)
[0156] RSU is considered to be an edge node with computing and communication capabilities. RSU collects real-time requests from data providers and data requesters, verifies the legitimacy of users' identities, and is also responsible for uploading data indexes, data ciphertexts, and keys to the fog nodes in the blockchain.
[0157] (4) Fog Server
[0158] The fog server is composed of a computer cluster with weaker performance and more decentralized than the cloud server. The fog server stores the identity authentication information of the vehicle and forms a consortium blockchain between them. TA divides the fog nodes into three categories according to computing power and storage capacity, namely file server (FS), data server (DS) and audit server (AS). The three types of nodes together form a lightweight ledger blockchain system. A fog server corresponds to multiple RSUs, which are responsible for maintaining blockchain nodes. Each fog server maintains a shared ledger (only hash values are saved). In addition, FS is responsible for maintaining a complete copy of the ciphertext data, DS is responsible for maintaining a copy of the key and data index, and AS is responsible for maintaining a copy of the data sharing record.
[0159] Only TA can trace, update, and revoke the identity of malicious users, as well as update and revoke smart contracts. Authorized institutions can access information in the blockchain at any time. Assuming that TA is in a dormant state after initialization except for tracing and updating identities, it does not affect the computing power of the entire system and does not violate the decentralized nature of the blockchain. At the same time, the fog server can verify all transactions and the new status of smart contracts, and can upload them to the blockchain according to the consensus mechanism.
[0160] The second step is to initialize the system.
[0161] Perform system initialization, including trusted institution initialization, vehicle initialization, and blockchain initialization.
[0162] (1) Trusted institution initialization.
[0163] TA defines a large attribute set U = Zp , and run the group generator algorithm to obtain the group and bilinear mapping g(lλ) description U=(P,G1,G2,e), where G1 and G2 are two cyclic groups of prime order P, satisfying the bilinear mapping e:G1×G1→G2. Then TA randomly selects parameters g,u,h,f,b∈G1 and α,a∈Z p , where u, h generate HASH in the attribute layer, f is used to ensure the secret randomness r and s, b is used to bind the attribute layer and the secret sharing layer, and the master private key Msk={α,a},H:{0,1} * →Z p is a hash function with a fixed output range, and finally obtains the public parameters:
[0164] p={U,H,g,u,h,f,b,g a ,e(g,g)α}.
[0165] (2) Vehicle initialization.
[0166] Collect the real identity VID of the vehicle owner i , as the unique identifier of the car owner, as well as the owner's occupation, hobbies, frequented places and other information are sent to TA. Then TA generates a random number According to the real identity VID of the vehicle i Generating identity embeddings And add it to the identity mapping table TA obtains the attribute set A = {A1, A2, ..., A n}, then TA selects n+1 random indices r,r1,r2,...,r n ∈Z p , then calculate N1=g r , for every ξ∈[n], we have:
[0167] N ξ,2 =g rξ ,N ξ,3 =(u Aξ h) rξ b -r ;
[0168] Calculate the decryption key:
[0169]
[0170] Finally, TA converts the public parameters p and sK id Loaded into the vehicle OBU.
[0171] (3) Blockchain initialization.
[0172] TA starts the blockchain and deploys smart contracts between pre-set fog nodes according to the consensus mechanism. These smart contracts will obtain their unique addresses and can be called using transactions with appropriate permissions. TA generates H(e(g,g) ci ) and stored in the blockchain for subsequent vehicle identity authentication.
[0173] Step 3: Data sharing.
[0174] Data sharing includes: generating data indexes, uploading data, obtaining data, decrypting data and identity tracing.
[0175] (1) Generate data index.
[0176] Data ProviderV i Data is collected while driving and stored in the vehicle. The data mainly includes two categories: one is the data detected by the vehicle, and the other is the data observed by the user. Generate an index of the shared data segment for retrieval by data requesters. Generate an index:
[0177] Γ={Tar,MD}
[0178] Among them, Tar is the object that the data provider wants to share data with, and MD is the description of the shared data segment, including the size, type, data description, storage address, upload time and other contents of the shared data segment:
[0179] MD={size||des||addr||timestamp||other}.
[0180] (2)Upload data.
[0181] The vehicle selects the data it wants to share and uploads it. First, V i Generate a symmetric key sd and use sd to encrypt the original data Encrypt to generate ciphertext:
[0182] ct=Enc sd (D);
[0183] Then, according to the object you want to share, customize the access policy, decide who can decrypt the data, and use the attribute-based encryption symmetric key sd. The specific steps are as follows:
[0184] Use the LSSS linear secret sharing scheme to customize access policies and calculate where M is the secret policy matrix, ρ:[l]→Z p is the secret sharing matrix, and then randomly selects the secret sharing vector Where s is the shared random secret share, y jis a random number. Then the vehicle V i Enter common parameters to calculate get Among them, M i is the i-th row of the secret strategy matrix. Then, l indices t1, t2, t3, ..., t are randomly selected. l ∈Z p , and calculate C = sd·e(g,g) sα ,C0=g s , for each ξ∈[l]:
[0185] C ξ,1 =fλξb tξ ,C ξ,2 =(uρ(ζ)h) -tξ ,C ξ,3 =g tξ ;
[0186] Finally, the ciphertext is obtained:
[0187]
[0188] Then the vehicle V i Sign the data index to generate a verifiable signature:
[0189] Sig i (Γ) = e(g ci ,gη)
[0190] Among them, η=H(Γ||timestamp), the vehicle will eventually {Sig i (Γ),CT sd ,ct,Γ,timestamp} is uploaded to the nearby RSU nodes;
[0191] RSU by Sig i (Γ) Verify the legitimacy of the uploaded vehicle. First, calculate η′=H(Γ′||timestamp′), and then send the result to the fog node for verification. The fog node calculates Then calculate The information is compared with the information stored in the blockchain. If it exists, it means that the vehicle is legal, and a message of successful authentication is returned to the RSU. The RSU then uploads the ciphertext to the file system, which is mounted on the blockchain and can store the ciphertext uploaded by the vehicle to ensure that the message is not tampered with. The file system stores the data ciphertext ct and generates the corresponding storage address indexaddr based on ct and the data index Γ. The RSU stores the data index and the symmetric key CT encrypted by the attribute base. sd Upload to the data chain and record transaction TX provide :
[0192] RSU i →blockchain:{Γ,CT sd ,TX provide}.
[0193] (3) Obtain data.
[0194] Data Requester V y Retrieve the blockchain index, find the data you want to obtain, and confirm the object shared by the data through Tar to see if you match it. Then send a request to the nearby RSU:
[0195] Req={Request||Sig y (Γ)||timestamp}
[0196] The request includes the time, purpose and content of the requested data, index ID, etc. y (Γ) content, is the vehicle V y Generated verifiable signature.
[0197] After the vehicle is authenticated, the RSU finds the storage address from the file system according to the index requested by the vehicle, and then sends the encrypted symmetric private key CT sd And the ciphertext address {CT,indexaddr} is sent to the vehicle:
[0198] RSU x →V y :{CT sd ,indexaddr};
[0199] RSU is also responsible for recording the request transaction Tr i And save the shared records in the blockchain. Shared records are used to achieve data sharing record traceability, user self-certification and non-repudiation. Shared records include data uploader V i Signature of data requester V y The signature, timestamp and request Req:
[0200] RSU x →blockchain:Tri={Sigi(Γ)||Sigy(Γ)||timestamp||Req}.
[0201] (4) Decrypt the data.
[0202] Received message {CT sd ,indexaddr} first decrypts CT using its attribute private key sd Get the symmetric key sd. V yFirst, we compute a set of row vectors in M that are generated by the attributes in A, namely If the attribute set A is not the authorized set of the access policy, then it cannot satisfy the access structure of (M,ρ) and this step ends. Otherwise, construct a {ω j ∈Z p} j∈l The constant vector is of the form ∑ j∈I ω j M j =(1,0,...,0), where M i is the i-th row of the matrix M. If S is the set of authorized accesses, then ∑ j∈I ω j λ j =s, there may be other different ways to choose ω j The value of is used to satisfy this, and then the following calculation is performed:
[0203]
[0204] Where ξ is the attribute set The index of the attribute vector in (depends on j).
[0205] Correctness:
[0206]
[0207] in,
[0208] Finally, the symmetric key sd can be calculated:
[0209]
[0210] After the vehicle obtains the symmetric key sd, the vehicle V finds the address of the ciphertext ct from the file system through the address indexaddr and downloads the ciphertext ct. Then the vehicle V y Decrypt the ciphertext ct using the symmetric key sd, and finally get the plaintext data:
[0211] D=Dec sd (ct).
[0212] (5) Identity tracing.
[0213] When a data requester finds a false message, he can complain to the TA. For example, if the data requester receives data saying that a traffic accident occurred in a certain place, but finds that no traffic accident occurred when he arrives at the place, he can initiate an identity tracing request, including a request to track the vehicle with a data index. Then the TA and the blockchain will work together to reveal their identity. The TA first finds the signature of the data uploader based on the records stored in the blockchain.i (Γ), due to the immutability of the blockchain, the authenticity of the tracking is ensured to prevent malicious users from denying it. Then, according to the identity mapping relationship stored in TA, its real identity VID i To trace back, first the data requester V y Initiate an identity tracking request Trace to TA. After receiving the request, TA initiates a query on the blockchain for the shared record of data index Γ. If the index does not exist, it returns that the index does not exist. Otherwise, the blockchain returns the data sharing record Tr to TA. i . Then TA is verified from Tr i Extract the data provider's signature Sig i (Γ), and compared with the identity mapping stored locally:
[0214]
[0215] If there is no c i If the equation is satisfied, the real identity is returned to the vehicle. If it exists, c i If the equation is satisfied, the corresponding real identity VID is output i , complete the tracking.
[0216] It should be noted that this specific embodiment uses a fragmented ledger for storage instead of storing all shared data in a shared ledger, that is, each party only stores a complete backup of the data related to itself, and the shared ledger only stores the hash value. For example, a fog server that provides data sharing services may not be interested in the content of the shared records, so there is no need to keep the content in the shared ledger. On the contrary, since the audit server keeps the data sharing records in its fragmented ledger, it is sufficient to keep the proof of the data (i.e., the hash value) in the shared ledger. Therefore, in this specific embodiment, all participants in the blockchain network will reach a consensus on the shared ledger, but each party will only save a backup of the data related to itself.
[0217] Each participant only maintains relevant information that is different from other participants. Specifically, the difference between the shared ledger and the segmented ledger will be in the data sharing details. In this specific embodiment, there are three participants, namely the file system, the audit server and the data server. The file system is responsible for storing the ciphertext information uploaded by the user, the data server is responsible for storing the data index and the encrypted symmetric key, and the audit server is responsible for storing the data sharing records for subsequent identity tracking. Users may not want to store the shared records in the data server because this behavior may expose personal privacy and leak information such as the user's interests and hobbies. Therefore, this specific embodiment sets up an audit server, and TA pre-designates some blockchain nodes as audit nodes. These nodes only maintain data sharing records. When an arbitration event occurs, TA can query the data sharing records from the audit node to track malicious users. However, in the event of an arbitration event, TA will disclose this data as needed, and the blockchain meets its integrity.
[0218] Through specific implementation examples, one-to-many anonymous data sharing and fine-grained access control are achieved. The user's identity and data privacy are protected during data sharing, and the real identity of malicious users who provide false information can be tracked. The blockchain of the lightweight ledger records data indexes, data ciphertexts and shared records. The blockchain nodes are divided into several categories according to their functions. Each party only stores a complete backup of the data related to itself and cooperates with each other, which improves security and effectively reduces the storage and communication overhead of nodes in data sharing.
[0219] Reference Fig. 9 , one embodiment of the present invention also provides a privacy data sharing system based on blockchain, including a large attribute set module 1001, a vehicle attribute collection module 1002, a blockchain startup module 1003, a vehicle shared data acquisition module 1004, an upload roadside unit module 1005, a request object verification module 1006 and a data sharing module 1007, wherein:
[0220] The large attribute set module 1001 is used to define a large attribute set through a trusted institution and construct public parameters according to the large attribute set.
[0221] The vehicle attribute collection module 1002 is used to collect the attributes of the vehicle according to the large attribute set of constructed public parameters and issue the attribute base key of the vehicle.
[0222] The blockchain startup module 1003 is used to start the blockchain between preset fog nodes through a trusted organization; the fog nodes include a file server, a data server and an audit server.
[0223] The vehicle shared data acquisition module 1004 is used to acquire the shared data of the vehicle and generate an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle; the symmetric key is encrypted by an attribute base key.
[0224] The upload roadside unit module 1005 is used to upload the access control policy, symmetric key and ciphertext corresponding to the vehicle's shared data to the roadside unit; the roadside unit is used to save the access control policy and symmetric key corresponding to the vehicle's shared data to the data server and save the ciphertext corresponding to the vehicle's shared data to the file server.
[0225] The request object verification module 1006 is used to verify whether the object of the request is the shared data of the vehicle through the roadside unit when receiving the request for obtaining the shared data of the vehicle.
[0226] The data sharing module 1007 is used to obtain and reply the shared data of the vehicle by decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and symmetric key corresponding to the shared data of the vehicle provided by the roadside unit if the object of the acquisition request is the shared data of the vehicle; the record of the replied shared data of the vehicle will be saved to the audit server through the roadside unit.
[0227] It should be noted that since the blockchain-based privacy data sharing system in this embodiment and the above-mentioned blockchain-based privacy data sharing method are based on the same inventive concept, the corresponding content in the method embodiment is also applicable to the device embodiment and will not be described in detail here.
[0228] It will be appreciated by those skilled in the art that all or some of the steps and systems in the disclosed method above may be implemented as software, firmware, hardware and appropriate combinations thereof. Some physical components or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or a non-transitory medium) and a communication medium (or a temporary medium). As known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing data (such as computer-readable instructions, data structures, program modules or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that may be used to store desired data and may be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically embodies computer readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any data delivery media.
[0229] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "illustrative embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0230] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.
Claims
1. A privacy data sharing method based on blockchain, characterized in that: The blockchain-based privacy data sharing method includes: Defining a large attribute set through a trusted institution and constructing public parameters based on the large attribute set; Collecting vehicle attributes according to the large attribute set of constructed public parameters, and issuing attribute base keys of the vehicle; The blockchain is started between preset fog nodes through the trusted institution; the fog nodes include a file server, a data server and an audit server; Acquiring the shared data of the vehicle, and generating an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle; the symmetric key is encrypted by the attribute base key; The access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle are uploaded to the roadside unit; the roadside unit is used to save the access control policy and symmetric key corresponding to the shared data of the vehicle to the data server and save the ciphertext corresponding to the shared data of the vehicle to the file server; When receiving a request for obtaining shared data of the vehicle, verifying by the roadside unit whether an object of the request for obtaining is the shared data of the vehicle; If the object of the acquisition request is the shared data of the vehicle, the ciphertext corresponding to the shared data of the vehicle is decrypted according to the access control policy and symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle; the record of replying the shared data of the vehicle will be saved to the audit server through the roadside unit.
2. The method for sharing private data based on blockchain according to claim 1, characterized in that: The step of defining a large attribute set through a trusted institution and constructing public parameters according to the large attribute set includes: The large attribute set is defined by the trusted institution, and a group generator algorithm is run to obtain a group and a bilinear map; the group and the bilinear map are used to describe the large attribute set; A plurality of groups of elements are selected according to the large attribute set to form the public parameters; the public parameters are used for CP-ABE encryption of the large attribute set.
3. The method for sharing private data based on blockchain according to claim 1, characterized in that: The collecting of vehicle attributes according to the large attribute set of constructed public parameters and issuing the attribute base key of the vehicle comprises: The attributes of the vehicle are collected according to the large attribute set of constructed public parameters; the attributes of the vehicle include the real identity of the owner, the occupation of the owner, the hobbies of the owner and the places the owner often visits; the real identity of the owner is the unique identifier of the vehicle; Adding the real identity of the owner of the vehicle to an identity mapping table; the identity mapping table is used to obtain all attributes of the vehicle according to the real identity of the owner of the vehicle; An attribute base key of the vehicle is calculated and issued through the trusted authority and all attributes of the vehicle.
4. The method for sharing private data based on blockchain according to claim 1, characterized in that: The obtaining of the shared data of the vehicle and generating an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle include: Customizing the access control policy of the shared data of the vehicle through the LSSS linear secret sharing scheme; The symmetric key and ciphertext of the shared data of the vehicle are calculated through the access control policy of the shared data of the vehicle.
5. The method for sharing private data based on blockchain according to claim 1, characterized in that: The uploading of the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit includes: Signing an index of the shared data of the vehicle to obtain a verifiable signature of the shared data of the vehicle; The verifiable signature, access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle are uploaded to the roadside unit; the roadside unit verifies the legitimacy of the verifiable signature, access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle through the verifiable signature of the shared data of the vehicle.
6. The method for sharing private data based on blockchain according to claim 1, characterized in that: When receiving the acquisition request of the shared data of the vehicle, verifying by the roadside unit whether the object of the acquisition request is the shared data of the vehicle includes: Comparing, by the roadside unit, an index of the request for obtaining the shared data of the vehicle with an index of the shared data of the vehicle; If the index of the acquisition request for the shared data of the vehicle matches the index of the shared data of the vehicle, then the object of the acquisition request is the shared data of the vehicle.
7. The method for sharing private data based on blockchain according to claim 1, characterized in that: The decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and the symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle includes: Finding a storage address in the file system of the file server according to an index of the acquisition request of the shared data of the vehicle; Obtaining the ciphertext address and symmetric key of the shared data of the vehicle according to the storage address; A symmetric key for decrypting the shared data of the vehicle using the attribute base key of the vehicle; The ciphertext corresponding to the ciphertext address of the shared data of the vehicle is decrypted according to the symmetric key of the decrypted shared data of the vehicle, and the shared data of the vehicle is obtained and replied.
8. The method for sharing private data based on blockchain according to claim 1, characterized in that: After decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and the symmetric key corresponding to the shared data of the vehicle provided by the roadside unit to obtain and reply the shared data of the vehicle, the method further includes: When a complaint is received that the shared data of the vehicle contains false content, the identity of the vehicle is traced.
9. The method for sharing private data based on blockchain according to claim 8, characterized in that: The tracing of the identity of the vehicle comprises: Identity tracing is performed through the verifiable signature of the shared data of the vehicle and the real identity of the vehicle in the identity mapping table.
10. A privacy data sharing system based on blockchain, characterized in that: The blockchain-based privacy data sharing system includes: A large attribute set module, used to define a large attribute set through a trusted institution and construct public parameters according to the large attribute set; A vehicle attribute collection module, used for collecting vehicle attributes according to the large attribute set of constructed public parameters, and issuing an attribute base key of the vehicle; A blockchain startup module, used to start the blockchain between preset fog nodes through the trusted institution; the fog nodes include a file server, a data server and an audit server; A vehicle shared data acquisition module, used to acquire the shared data of the vehicle and generate an access control policy, a symmetric key and a ciphertext corresponding to the shared data of the vehicle; the symmetric key is encrypted by the attribute base key; The uploading roadside unit module is used to upload the access control policy, symmetric key and ciphertext corresponding to the shared data of the vehicle to the roadside unit; the roadside unit is used to save the access control policy and symmetric key corresponding to the shared data of the vehicle to the data server and save the ciphertext corresponding to the shared data of the vehicle to the file server; a request object verification module, configured to, upon receiving a request for obtaining shared data of the vehicle, verify through the roadside unit whether the object of the request for obtaining is the shared data of the vehicle; A data sharing module is used to obtain and reply the shared data of the vehicle by decrypting the ciphertext corresponding to the shared data of the vehicle according to the access control policy and symmetric key corresponding to the shared data of the vehicle provided by the roadside unit if the object of the acquisition request is the shared data of the vehicle; the record of the reply to the shared data of the vehicle will be saved to the audit server through the roadside unit.
Citation Information
Patent Citations
Data security traceability and access control system under cloud computing framework
CN111327620A
Electric power transaction system based on block chain, transaction method and bill query method
CN112019549A