An Oblivious Transfer Method for Accessing Commodity Information Based on Blockchain

The integration of DH key exchange with signature authentication in an n-to-1 oblivious transfer protocol on the blockchain addresses vulnerabilities in existing protocols, enabling secure and private customer browsing of goods without revealing selections, and preventing information tampering.

CN115914293BActive Publication Date: 2025-07-15NANJING NORMAL UNIVERSITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211416441.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-12
Publication Date
2025-07-15
Estimated Expiration
2042-11-12

AI Technical Summary

Technical Problem

In the existing blockchain technology, it is difficult to protect customer privacy when inquiring product information, and the inadvertent transmission method of DH chooses one and is vulnerable to intermediate intrusion attacks, resulting in information leakage.

Method used

Based on the DH two-choice one inadvertent transmission method, combined with signature authentication, an inadvertent transmission method based on the authentication DH is constructed. Through the blockchain, the index information and interactive information are stored, so as to realize the privacy protection and intermediate intrusion attack prevention of customer selection and product browsing.

Benefits of technology

It realizes privacy protection for browsing customer product information, prevents merchants from knowing and choosing product serial numbers, prevents intermediate intrusion attacks, ensures information security and prevents tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115914293B_ABST
    Figure CN115914293B_ABST
Patent Text Reader

Abstract

The present invention relates to an oblivious transfer method for accessing commodity information based on blockchain. The method involves two objects: merchants and customers, and the method includes the following steps: S1: The merchant uploads the index information to the blockchain; S2: The customer retrieves the keyword and obtains the merchant address information; S3: The customer applies to the merchant to view the commodity information, the merchant sends the commodity information to the customer, and the customer selects one of them. This method constructs an n-out-of-one oblivious transfer based on the DH-based two-out-of-one oblivious transfer. Therefore, in terms of security, it inherits the security of the two-out-of-one oblivious transfer, that is, in each round, the merchant does not know whether the customer has selected the former or the latter. Among n data, the merchant cannot know which one the customer has selected, achieving privacy protection for browsing commodity information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a transmission method, in particular to an oblivious transfer method for accessing commodity information based on blockchain, belonging to the technical field of blockchain. Background Art

[0002] Blockchain privacy protection has always been taken seriously by people, and there have been more and more studies on the privacy protection of the transaction content between both parties. Currently, most blockchain queries are for plaintext requests, and there is no protection for the privacy of the requesting party. Browsing information on the Internet may expose personal privacy. The commodity information queried through the Internet may infer personal shopping preferences and thus make promotions. For the case of information interaction, both sending parties may also cause the leakage of information or keys due to the attack of the middleman.

[0003] The one-out-of-two oblivious transfer method based on the DH key exchange protocol can well enable the receiver to select one of the senders, and the sender does not know which one the receiver has selected. However, this method does not consider the middle intrusion attack, which will change the keys sent by both parties, resulting in information leakage. This method is also only used for the one-out-of-two scenario. Summary of the Invention

[0004] The present invention precisely aims at the problems existing in the prior art and provides an oblivious transfer method for accessing commodity information based on blockchain. This technical solution is constructed on the basis of the DH one-out-of-two oblivious transfer method and combined with signature authentication to form an n-out-of-1 oblivious transfer method based on authenticated DH. Customers can select one commodity from the commodity information sent by the merchant for information browsing, and the merchant does not know which one the customer has selected. At the same time, when both parties of the information interaction send information, signature authentication is used to determine the identity information of the other party, prevent middle intrusion attacks, effectively protect the privacy of customers, and store the interactive information between both parties on the blockchain to prevent information tampering.

[0005] To achieve the above object, the technical solution of the present invention is as follows. An oblivious transfer method for accessing commodity information based on blockchain, characterized in that,

[0006] This method involves two objects: the merchant and the customer, and the method includes the following steps:

[0007] S1: The merchant uploads the index information to the blockchain;

[0008] S2: The customer retrieves the keyword and obtains the merchant address information;

[0009] S3: The customer applies to the merchant to view the commodity information, the merchant sends the commodity information to the customer, and the customer selects one of them.

[0010] As an improvement of the present invention, in S1, merchant V extracts keywords of items in its own database and the address information of the merchant as data indexes and stores them in the blockchain. The merchant stores information about n items: m1, …, m n {0, 1} c (where c is the number of bits of the information).

[0011] As an improvement of the present invention, in S2, customer U finds the corresponding index in the blockchain through the keywords of the product, thereby obtaining the address information of merchant V, and applies to the merchant to view the product. Customer U holds i ∈ {1, 2, …, n}, indicating the serial number of the product that the customer wants to select.

[0012] As an improvement of the present invention, in S3, when the customer applies to the merchant to view the product information, the merchant sends the product information to the customer, and the customer selects one of them, including the following steps:

[0013] The present invention uses a certificate usually signed by a trusted authority TA. Each user U has a signature method, and its signature algorithm is denoted as sig U , and the verification algorithm is denoted as ver U , and TA also has a signature method, and its public verification algorithm is ver TA , each user has a certificate Cert(U) = (ID(U), ver U , sig TA (ID(U), ver U ))), where ID(U) here is the identification information of user U.

[0014] The public domain parameters include a group (G, ·) and an element α ∈ G of order n

[0015] 3-1. Customer U sends a request to merchant V to view the product

[0016] 3-2. After merchant V receives the request, it generates a random number a, and the customer generates a random number b. The merchant calculates A = α a

[0017] 3-3. The merchant sends A and Cert(V) to the customer. If the customer hopes to obtain the previous data item, then the customer calculates B = α b , and if the customer hopes to obtain the latter data item, the customer calculates B = α b α a , and the customer sends Cert(U), as well as the signature information Y U = sig U (ID(V)||B||A), B to the merchant

[0018] 3-4. The merchant uses the verification algorithm ver UTo verify Y U , if the signature is invalid, the merchant will reject the request; otherwise, the request will be accepted.

[0019] 3-5. The merchant generates r0 = 0 c and randomly generates r j ∈{0, 1} c , j = 1, …, n, (c represents the number of bits of the information). The merchant encrypts r0 using the negotiated key and sends it to the customer. The customer also decrypts it using the negotiated key to obtain r0

[0020] 3-6. The merchant and the customer perform an oblivious transfer of two alternatives based on authenticated DH n times. In the jth operation, the merchant provides as the previous data item j and r as the next data item.

[0021] The merchant calculates the keys h0 = Hash(B a ), h1 = Hash((B / α a ) a )

[0022] The merchant calculates the ciphertexts of the two data items E1 = Enpt h1 (r j )

[0023] and sends E0 and E1 to the customer. At the same time, it calculates the signed message Y V = sig V (ID(U)||A||B) and sends it to the customer. The customer uses the verification algorithm ver V to verify Y V . If the signature is invalid, it rejects the received message; otherwise, it receives the message and selects one of them;

[0024] 3-7. According to the merchant's encryption rule, if the customer needs to query m i , then the customer needs to select the next data item every time in the (j - 1)th round, that is, when j < i, to obtain r1…r j-1 . At the same time, in the jth time, that is, when j = i, it selects the previous data item to solve the commodity information m i .

[0025] Compared with the prior art, the present invention has the following advantages: 1. This method constructs an n - out - of - one oblivious transfer based on the two - out - of - one oblivious transfer of DH. Therefore, in terms of security, it inherits the security of the two - out - of - one oblivious transfer. That is to say, in each round, the merchant does not know whether the customer has chosen the former or the latter. Among n data, the merchant cannot know which one the customer has chosen, achieving privacy protection for the browsing of commodity information;

[0026] 2. The authentication method is a secure interactive identification method. By verifying the signature to confirm the identity of the other party, it can prevent man - in - the - middle intrusion attacks and prevent the tampering of keys;

[0027] 3. Storing the index information and interactive information on the blockchain can make the index information publicly available to everyone, facilitating customers' inquiries and at the same time preventing the tampering of information. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 : Schematic diagram of the overall process of the present invention

[0029] Figure 2 : Schematic diagram of the oblivious transfer for accessing commodity information. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] To deepen the understanding of the present invention, the following detailed description of this embodiment is made in conjunction with the accompanying drawings.

[0031] Embodiment 1: Refer to Figure 1 , an oblivious transfer method for accessing commodity information based on the blockchain. This method involves two objects: merchants and customers. The method includes the following steps:

[0032] S1: The merchant uploads the index information to the blockchain;

[0033] S2: The customer retrieves the keyword and obtains the merchant's address information;

[0034] S3: The customer applies to the merchant to view the commodity information. The merchant sends the commodity information to the customer, and the customer selects one of them.

[0035] In S1, the merchant V extracts the keywords of the items in its own database and the address information of the merchant as data indexes and stores them in the blockchain. The merchant stores information about n commodities: m1,…,m n {0, 1} c (c is the number of bits of the information).

[0036] In S2, the customer U finds the corresponding index in the blockchain through the keyword of the commodity, thereby obtaining the address information of the merchant V, and applies to the merchant to view the commodity. The customer U holds i ∈ {1, 2,…, n}, indicating the serial number of the commodity that the customer wants to select.

[0037] In S3, the customer applies to the merchant to view product information, and the merchant sends the product information to the customer. The customer selects one of them, which includes the following steps:

[0038] The present invention uses a certificate usually signed by a trusted authority TA. Each user U has a signature method, and its signature algorithm is denoted as sig U , and the verification algorithm is denoted as ver U , and TA also has a signature method, and its public verification algorithm is ver TA , each user has a certificate Cert(U) = (ID(U), ver U , sig TA (ID(U), ver U ))), where ID(U) is the identification information of user U.

[0039] The public domain parameters include the group (G, ·) and the element α ∈ G of order n

[0040] 3-1. Customer U applies to merchant V to view the product request,

[0041] 3-2. After receiving the request, merchant V generates a random number a, and customer generates a random number b. Merchant calculates A = α a

[0042] 3-3. Merchant sends A and Cert(V) to the customer. If the customer hopes to obtain the previous data, then the customer calculates B = α b , if the customer hopes to obtain the latter data, the customer calculates B = α b α a , the customer sends Cert(U), and the signature information Y U = sig U (ID(V)||B||A), B to the merchant,

[0043] 3-4. Merchant uses the verification algorithm ver U to verify Y U , if the signature is invalid, the merchant will reject the request, otherwise accept the request.

[0044] 3-5. Merchant generates r0 = 0 c and randomly generates r j ∈{0, 1} c , j = 1, …, n, (c represents the number of bits of the information). The merchant encrypts r0 using the negotiated key and sends it to the customer. The customer also decrypts r0 using the negotiated key to obtain r0

[0045] 3-6. The merchant and the customer perform an alternative operation of n authenticated DH oblivious transfers. In the j-th operation, the merchant provides as the previous data item and r j as the next data item. At the same time, the merchant encrypts the two data items to be sent each time, where Hash() is the encryption function of the key agreed upon by both parties, and Enpt() is the encryption function of the ciphertext. The key and the ciphertext correspond to each other. The encryption method is as follows:

[0046] The merchant calculates the keys h0 = Hash(B a ), h1 = Hash((B / α a ) a )

[0047] The merchant calculates the ciphertexts of the two data items E1 = Enpt h1 (r j )

[0048] and sends E0 and E1 to the customer. At the same time, the merchant calculates the signed message Y V = sig V (ID(U)||A||B) and sends it to the customer. The customer uses the verification algorithm ver V to verify Y V . If the signature is invalid, the customer rejects the received message; otherwise, the customer receives the message and selects one of them;

[0049] 3-7 According to the merchant's encryption rules, if the customer needs to query m i , then the customer needs to select the latter data item every time in the (j - 1)-th round, that is, when j < i, so as to obtain r1…r j-1 . At the same time, in the j-th time, that is, when j = i, the customer selects the former data item, so as to solve the commodity information m i .

[0050] Security analysis:

[0051] Considering that the customer selects the former data item for the first time in the i-th time. For the customer when j < i, the customer selects the latter data item, so the customer will not obtain any information about the commodity information m i . If the customer selects the former when j > i, that is, the customer obtains The customer can obtain at most (assuming that the customer has obtained r i+1 …r j-1 ) by selecting the latter before. However, the customer does not know the random number r i generated by the merchant. Therefore, the customer ultimately wants to know the commodity information m iNor can it be known, ensuring that customers can only select one piece of product information for browsing.

[0052] The merchant has no way of knowing whether the customer selects the previous data or the latter data in each round. Therefore, the merchant has no way of knowing the serial number of the product selected by the customer, inheriting the security of one-out-of-two oblivious transfer.

[0053] It should be noted that the above embodiments are not intended to limit the protection scope of the present invention, and equivalent transformations or substitutions made on the basis of the above technical solutions all fall within the protection scope of the claims of the present invention.

Claims

1. An oblivious transfer method for accessing commodity information based on blockchain, characterized in that the method involves two objects: merchants and customers, and the method includes the following steps: S1: The merchant uploads the index information to the blockchain; S2: The customer retrieves the keyword and obtains the merchant address information; S3: The customer applies to the merchant to view the commodity information, the merchant sends the commodity information to the customer, and the customer selects one of them; In S1, merchant V extracts keywords of the products in its own database and the address information of the merchant as data indexes and stores them in the blockchain. The merchant stores information about n products: m1, …, m n {0, 1} c , where c is the number of bits of the information In S2, customer U finds the corresponding index in the blockchain through the keyword of the commodity, thereby obtaining the address information of merchant V, and applies to the merchant to view the commodity. Customer U holds i ∈ {1, 2,..., n}, indicating the serial number of the commodity that the customer wants to select; In S3, the customer applies to the merchant to view the commodity information, the merchant sends the commodity information to the customer, and the customer selects one of them, including the following steps: 3-1. Customer U applies to merchant V for a request to view the commodity 3-2. After merchant V receives the request, it generates a random number a, the customer generates a random number b, and the merchant calculates A = α a ; 3-3. The merchant sends A and Cert(V) to the customer. If the customer wishes to obtain the former data, then the customer calculates B = α b , if the customer wishes to obtain the latter data, the customer calculates B = α b α a , the customer sends Cert(U), and the signature information Y U = sig U (ID(V)||B||A), B to the merchant, 3-4. The merchant uses the verification algorithm ver U to verify Y U . If the signature is invalid, the merchant will reject the request; otherwise, the request will be accepted. 3-5. The merchant generates r0 = 0 c and randomly generates r j ε{0, 1} c , j = 1, …, n, c represents the number of bits of the information. The merchant encrypts r0 using the negotiated key and sends it to the customer. The customer also decrypts it using the negotiated key to obtain r0; 3-6. The merchant and the customer perform an alternative operation of n authenticated DH oblivious transfers. In the j-th operation, the merchant provides r0⊕...⊕r j-1 ⊕m j as the previous data item and r j as the next data item. At the same time, the merchant encrypts the two data items to be sent each time. Here, Hash() is the encryption function of the key agreed upon by both parties, and Enpt() is the encryption function of the ciphertext. The key and the ciphertext correspond to each other. The encryption method is as follows: The merchant calculates the secret keys h0 = Hash(B a ), h1 = Hash((B / α a ) a ) The merchant separately calculates the ciphertexts E0 = Enpt h0 (r0⊕...⊕r j-1 ⊕m j ), E1 = Enpt h1 (r j ) Send E0 and E1 to the customer, and calculate the signed message Y at the same time V = sig V (ID(U)||A||B) to the customer, and the customer uses the verification algorithm ver V to verify Y V , if the signature is invalid, reject the received message, otherwise receive the message and select one of them; 3-7. According to the merchant's encryption rule, if the customer needs to query m i , then the customer needs to select the latter item of data every time in the (j - 1)-th round, that is, when j < i, so as to obtain r1…r j-1 , and at the j-th time, that is, j = i, select the former item of data, so as to solve the commodity information m i .

Citation Information

Patent Citations

  • E-commerce product quick comparison method based on block chain

    CN112001728A