Large-scale manufacturing industry privacy data protection and supervision system and method
The system addresses data privacy and monitoring challenges in product traceability by using attribute-based encryption and multi-party secure computation to ensure secure and fine-grained access control, enhancing data privacy and decentralized monitoring.
Patent Information
- Application Number
- CN202211382680.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-07
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-11-07
AI Technical Summary
The existing blockchain traceability system has the risk of privacy leakage in data privacy protection and supervision, and lacks effective regulatory technical means, which makes it difficult to establish data security and trust relationships, affecting the reliability of data sharing and supervision.
Using attribute encryption measures and multi-party security calculation algorithms, multiple regulators conduct power checks and balances on corporate regulators, and introducing multi-party regulatory decision-making modules and attribute key generation systems to ensure data privacy protection and achieve fine-grained access control.
It realizes effective protection of data privacy, ensures control of data owners, and at the same time, through decentralized multi-party secure computing, data leakage is avoided and regulatory reliability and accuracy are improved.
Smart Images

Figure CN116015618B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a privacy data protection and supervision system and method for large-scale manufacturing industries. Background Art
[0002] Quality wins credibility, and credibility wins benefits. That is to say, quality issues are the lifeline of industries and enterprises. Globally, however, quality problems occur frequently. To solve these problems, countries around the world have successively studied and established various quality traceability systems relying on product supply chains to achieve shared storage of traceability data.
[0003] In recent years, blockchain has provided new technologies and ideas for the construction of product traceability systems. However, storing, supervising, and distributing data on a blockchain with equal parties among multiple parties faces frequent privacy leaks and frequent quality and safety incidents, causing consumers to lose trust in the traceability system. In addition, enterprises or institutions with a large amount of data are extremely cautious about opening their internal data, especially core data, considering many factors such as data ownership, data leakage, and their own commercial interests. When large-scale quality problem events break out, data is often tampered with and maliciously forged, resulting in the problem of low reliability of enterprise traceability systems.
[0004] The main reasons for the above problems are as follows. First, the data privacy of supply chain participants cannot be effectively protected, making it difficult to establish trust relationships among participants. Second, the regulatory authorities lack safe and effective regulatory technical means and cannot effectively supervise the complete supply chain data. It can be seen that the contradiction between data privacy protection and efficient sharing in enterprise quality traceability systems is becoming increasingly prominent, and data security issues remain the difficulties and pain points restricting the secure sharing and supervision of product traceability data. The reason lies in the imperfect data privacy protection and access control technologies of the traceability system.
[0005] In recent years, researchers have focused on integrating supervision into enterprise traceability systems to strengthen supervision while protecting privacy. For example, an enterprise can create a privacy protection scheme for traceable ledger transactions, which can effectively achieve the tracking of user identities by supervisors. In addition, some people have also designed the decryption of anonymous certificates of users by the regulatory party to achieve supervision.
[0006] However, the intervention of regulatory authorities will also bring certain risks to data privacy and security. Most existing supervisable schemes conduct supervision of transactions or data by introducing a single administrator role. At this time, the administrator has absolute authority, but if the administrator is malicious, it may lead to the leakage of user privacy.
[0007] Currently available technologies include CN202210722709.7, a system, method and device for secure multi-party computing of data based on blockchain. This patent designs public and private keys based on attribute encryption to protect the security of blockchain data, but does not consider effective supervision. CN202110343257.7, a multi-chain forensics method for alliance chains based on a threshold signature decision-making system. This patent disperses the power of on-chain information supervision to multiple regulatory agencies, and performs hierarchical processing of illegal information through voting arbitration, but ignores the security issues of privacy data. The above method does not simultaneously consider the multi-party restrictive supervision issues and data security issues brought about by blockchain supervision and traceability. Summary of the invention
[0008] In view of the shortcomings of the existing technology, the present invention provides a privacy data protection and supervision system and method for the large-scale manufacturing industry, which protects the user's data privacy through attribute encryption measures, and checks and balances the power of regulators by using a multi-party secure computing algorithm, introducing multiple regulators to grant authority to supervise the enterprise.
[0009] On the one hand, a privacy data protection and supervision system for a large-scale manufacturing industry includes a registration module, a multi-party supervision decision module, an attribute key generation system module, and a large-scale manufacturing blockchain module;
[0010] In the registration module, each regulator submits information to the enterprise for registration, and the enterprise sets a key for it; the registration module belongs to the enterprise, and records the information of the regulator according to the attribute set submitted by the regulator;
[0011] In the multi-party supervision decision module, the supervisory authority within the supervision department actively supervises or, due to the request of the customer or manufacturer, decides to authorize a supervisor to perform supervision; after the decision is made, a certificate, i.e., a supervision certificate, will be given; the multi-party supervision decision module belongs to the supervision department, and multiple people vote on the same supervision request to generate a supervision certificate, and give the supervision right to a supervisor to perform supervision;
[0012] The attribute key generation system module belongs to the enterprise. It verifies the identity of the regulator and generates an attribute key based on the registration information and regulatory proof submitted by the registration module and the multi-party regulatory decision module. The enterprise uses the attribute key to upload the traceability content that the regulator needs to view to the chain;
[0013] The large-scale manufacturing blockchain module receives the chain information of the attribute key generation system module, which specifically includes the main chain and the sub-chain; the main chain is composed of various enterprises, and various regulatory departments have reserved nodes on the main chain; the sub-chain is composed of various departments of various manufacturers, and traceability is based on the blockchain architecture.
[0014] The cloud service provider module: Each manufacturer reaches an agreement with the cloud service provider. The off-chain data enterprise will store encrypted data in the cloud according to the storage service provided by the cloud service provider module.
[0015] On the other hand, a method for protecting and regulating privacy data in the large-scale manufacturing industry, implemented based on the aforementioned large-scale manufacturing industry privacy data protection and regulatory system, includes the following steps:
[0016] Step 1: The supervisor registers the enterprise in the enterprise privacy data protection and regulatory system;
[0017] Step 1.1: Initialize the enterprise data;
[0018] Step 1.1.1: Set g2 as the generator of G, that is, g2 ∈ G, g1 is generated by the isomorphic mapping of g2, and g1 = ψ(g2), where ψ(*) refers to the isomorphic mapping. Select and δ1, such that u, where refers to the set of non-negative integers less than p, p is a constant, R refers to randomly selecting according to the uniform distribution method, h, δ1, and δ2 are random parameters obtained after being selected in the way of R, used to form the group tracing key, u, v are the generators of G1, and G and G1 are multiplicative groups of order prime p > 2 k ;
[0019] Step 1.1.2: Select t enterprise administrators in the consensus stage, t ≥ 1. The enterprise privacy data protection and regulatory system distributes the public key Y to each enterprise administrator. The key of each enterprise administrator, that is, the private key of the enterprise administrator, is set as: and let where w j is used to form the subsequent group public key, and j is one of the t enterprise administrators, j ∈ [1, t].
[0020] Step 1.1.3: Set the group public key gpk = (g1, g2, h, u, v, {w j |1 ≤ j ≤ t}), and the group tracing key is gmsk = (δ1, δ2);
[0021] Step 1.1.4: Set the supervisor attribute set of the enterprise attribute key generation system as S j = {s1, s2,..., s n}, where s n corresponds to the attributes of n supervisors.
[0022] Initialize an empty revocation list RL and a voting value T t , where RL is used to store the revocation marks of revoked users, and Tt Used to collect the support or opposition of regulators on the issue of tracing;
[0023] Step 1.2: Register the identities of the regulators.
[0024] Regulator i submits the attribute set S = {s i ,..., s n}.
[0025] Each enterprise administrator generates a private key fragment x j ∈Z p for regulator i, and sends the private key fragment to regulator i through a secure channel, where Z p is the set of non - negative integers less than the constant p, and x j is a randomly selected number from it;
[0026] Regulator i calculates its own private key:
[0027] Regulator i calculates its own ID:
[0028] The enterprise generates the attribute private key SK for the regulator: where s is an attribute in the attribute set S submitted by the regulator, t is a non - negative integer random number less than the constant p, is the attribute - corresponding key set by the enterprise according to the regulator's attribute set;
[0029] Step 2: When customers without on - chain nodes cannot trace, or when other enterprises involve the privacy of other enterprises during the trace of quality problems and have no right to access data off - chain, a regulatory trace is initiated to the regulatory department;
[0030] Step 3: The regulatory agency executes secure multi - party computation to grant permissions to regulators.
[0031] The regulatory agency executes secure multi - party computation to grant permissions to regulators; if there are m authorized personnel in the regulatory agency and the threshold is set as weight, at least authorized persons need to agree to legally supervise; where P = {P1, P2,..., P m} is the set of m regulatory authorizers;
[0032] Set a bulletin board, which is used to publicize information. All regulators can see the information publicized on the bulletin board. Only the bulletin board administrator Dealer has the permission to change and update the content on the bulletin board, and others can only read or download.
[0033] Step 3.1: Specific work of Dealer:
[0034] Step 3.1.1: Select secure large prime numbers p and q, and calculate to satisfy y = p * q, where y is a positive integer;
[0035] Step 3.1.2: Select e such that Find d to satisfy where gcd(*) is the GCD function, that is, it returns the greatest common divisor of two or more integers, is the Euler's totient function, e, d, and l refer to certain constants that satisfy the conditions, and mod is a mathematical operation symbol, referring to the modulo operator;
[0036] Step 3.1.3: Select a one-way function H(.), such that the range H(.) ∈ [y δ , where 0 ≤ δ ≤ 1 is a security parameter, and [*] means the data set composed of numbers greater than or equal to 1 and less than or equal to the number in the parentheses. For example, [y] = {1, 2,..., y}.
[0037] Step 3.1.4: Select sample information where, is the set of non - negative integers less than y.
[0038] Step 3.1.4.1: Randomly construct a polynomial of degree p0 - 1: where, is a non - negative integer less than the constant ; is a random one in
[0039] Step 3.1.4.2: Calculate each sub - secret information and the content announced on the bulletin board where i = 1, 2,..., m.
[0040] Step 3.1.4.3: The Dealer secretly sends d i to the regulatory authorizer P i , and announces W1, W2,..., W m , and the sample information w on the bulletin board, where, is the content on the bulletin board calculated from the coefficients of the polynomial of degree p0 - 1 and the sample information.
[0041] Step 3.1.4.4: Each regulatory authorizer P i verifies the correctness of the secret information d i by the following formula: where i = 1, 2,..., m. If the above formula holds, then the regulatory authorizer Pi Accept d i as a sub-secret; otherwise, reject d i , where d, d i are both confidential and will be destroyed when the regulatory authorization ends, along with p and q.
[0042] Step 3.2: Generation of authorization vouchers:
[0043] Let K = {K1, K2,..., K r} be the set of authorization proofs shared by m authorizers in the set P = {P1, P2,..., P m}. The Dealer randomly selects a random constant
[0044] such that any P0 individuals among P1, P2,..., P m can reconstruct the authorization voucher K j . The Dealer calculates the encrypted authorization voucher which will be sent to the regulator applying for supervision later.
[0045] Step 3.3; Recovery of authorization vouchers:
[0046] Any set of P0 regulatory authorizers where D ∈ P. After agreeing to this supervision request, each regulatory authorizer P in the set A i calculates the sub-key:
[0047] Selects random parameters δ1, δ2 are security parameters, and 0 ≤ δ1, δ2 ≤ 1. Calculate the encrypted sample information and the encrypted information on the number of authorizers The above various parameters w, m j , S ij , W i , w′, m′ pass through the one-way function H(*) to form the encrypted information b ij = H(w, m j , S ij , W i , w′, m′). Calculate another encrypted information θ ij = C ij + b ij d i , b ij and θ ij are used to form the verification value;
[0048] Any set D of P0 regulatory authorizers announces the verification values: {θ i , b ij , bij}, and obtain the authorized sub - key information set {m j , S ij} and send it to the supervisor who applies for supervision for supervision execution. The supervisor verifies the P i provided sub - key S ij for correctness by the following formula:
[0049] The supervisor takes ρ = m!, and calculates on the integer cyclic group Z: and α i = ρ * β i ;
[0050] The supervisor obtains the supervision proof K through the following calculation j : Since then where j = 1, 2,..., r;
[0051] If the Dealer allows m participants P1, P2,..., P m to share the new supervision proof K r+1 , then randomly select m r+1 and values are announced on the bulletin board.
[0052] Step 4: The supervisor who has obtained the supervision right executes supervision;
[0053] The supervisor who has obtained the supervision right submits the supervision proof K j , and the identity attribute information, and requests supervision;
[0054] Step 5: The relevant enterprise checks the supervision proof submitted by the supervisor and confirms whether the identity certificate exists.
[0055] The enterprise checks the supervision proof submitted by the supervisor and confirms whether its attribute certificate exists;
[0056] Step 6: After the enterprise confirms the identity, generate the data to be chained for supervision traceability;
[0057] Step 6.1: The enterprise first generates a temporary key pair (R, r), where R = rG, G is the multiplicative cyclic group set during previous registration, and r is a random number. This key pair is transmitted with the transaction; then calculate the shared secret ty: ty = H(r·ID B ) = H(ID B ·R), and encrypt ty using the group public key, where ID B is the ID number of the supervisor B. The enterprise uses to generate the temporary address S.A of the supervisor.
[0058] Step 6.2: The enterprise selects the exponent α, Calculate T1←u α , T2←v β , Randomly select the blinding factor r α , r β , r x , where refers to the bilinear mapping. Calculate:
[0059]
[0060]
[0061]
[0062]
[0063]
[0064] Step 6.3: Use the hash function to calculate the query value c←H(M||T1||T2||T3||R1||R2||R3||R4||R5).
[0065] Step 6.4: Generate the parameter s according to c α , s β , s x , where
[0066] σ1←xα
[0067] σ2←xβ
[0068] s α ←r α +cα
[0069] s β ←r β +cβ
[0070] s x ←r x +cx
[0071]
[0072]
[0073] Step 6.5: The enterprise generates the Bulletproofs zero - knowledge proof of the revocation mark, and verifies the legality of the enterprise's identity without obtaining the visitor's revocation mark. The steps are as follows:
[0074] Step 6.5.1: The enterprise constructs two random numbers aL , a R , such that < a L , 2 >= reg, a R = a L -1. Construct a L , a R 's commitment proof: Among them, < a1, a2 > refers to the inner product of a1 and a2, and g is a random number.
[0075] Step 6.5.2: Randomly select a blinding factor θ ∈ Z p , γ, t i (i = 1, 2), τ1 and τ2 are non - negative random integer coefficients less than a constant p, construct s L , s R 's commitment Calculate the relevant parameters τ(x), ε, t(x), l(x), r(x) of the zero - knowledge proof:
[0076] y = H(A, S)
[0077] z = H(A, S, y)
[0078] x = H(T1, T2, z)
[0079]
[0080] l = l(x) = a L -z + s L ·x
[0081] r = r(x) = y n (a R +z + s R ·x)+2z 2
[0082] t(x) = < l(x), r(x) >
[0083] τ(x) = τ1·x + τ2·x 2 +z 2 ·γ, γ ∈ Z p
[0084] ε = α + α·x
[0085] Step 6.5.3: Construct a commitment V = g reg h γ , to obtain the zero - knowledge proof η = {τ(x), ε, t(x), l(x), r(x)};
[0086] Step 6.6: The signature of the enterprise privacy data is: σ←(M, T1, T2, T3, c, s α ,s β ,s x ,s σ1 ,s σ2 , SA, t, η), where M is a 1×n access matrix;
[0087] Step 6.7: Input plaintext m, i.e. the data to be encrypted, gmsk, and access policy (M, λ), M i The function λ in the i-th row of the matrix M converts M i Map to attributes, record λ{1, 2, ...l}→{1, 2, ..., n}, and output ciphertext CT: Among them, ty is the shared secret and p is a random value.
[0088] Step 6.8: The enterprise broadcasts the ciphertext CT, the zero-knowledge proof η of the revocation mark, the encrypted shared secret ty, and the signature to each node after the data is uploaded to the chain.
[0089] Step 7: After receiving the broadcast information, the regulator verifies the legitimacy of the message.
[0090] Step 7.1: First, verify the zero-knowledge proof η to determine whether the user’s identity is legitimate. Issued to enterprises;
[0091] Step 7.2: Enterprise Inspection: Judgment Is it established? Is it established? Determine whether t(x)=<l(x), r(x)> is established. If all the above judgments are established, the identity of the regulator is legal. If not, the identity information of the regulator is wrong, does not meet the regulatory traceability request, and is punished.
[0092] Step 7.3: After verification, calculate: Then, calculate if If the signature is valid, the verified information will be uploaded to the blockchain. Otherwise, if it is invalid, the traceability request will be rejected and the step will terminate.
[0093] Step 8: The regulator conducts legal tracing of the data requested by the customer or manufacturer on the blockchain traceability platform.
[0094] Step 9: Conduct regulatory tracing until the off-chain database is found and the traceability information is checked.
[0095] When a viewing application is sent, the system first decrypts the ciphertext CT under the user's attribute private key and access policy (M, λ). If the user's attribute set can meet the data access policy, the user is allowed to access the data and the plaintext m is output; otherwise, the access fails. Plaintext m:
[0096] The beneficial effects produced by adopting the above technical solution are as follows:
[0097] The present invention provides a large-scale manufacturing industry privacy data protection and supervision system and method, having the following beneficial effects:
[0098] 1. The secure multi-party computing technology is used, which has the following advantages: (1) Decentralization. The status of each participating party is equal, and there is no participation of a third party with privileges; (2) Input data security. The data inputs of all parties are independent during the secure multi-party computing process, and no local original data is leaked during the calculation; (3) Accurate calculation results. The results obtained by the secure multi-party computing algorithm are consistent with the local calculation results of the original plaintext data.
[0099] 2. It can effectively solve the problem of data privacy protection in the system. On this basis, the present invention solves the problem of key leakage caused by the transmission of symmetric encryption keys by using the attribute encryption algorithm. In addition, fine-grained access control of encrypted data is realized, that is, the data owner can specify who can access the encrypted data, and the data owner has full control over the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0100] Figure 1 It is the system structure diagram in the embodiment of the present invention.
[0101] Figure 2 It is the method flow diagram in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0102] The following combines the drawings and embodiments to further describe in detail the specific embodiments of the present invention. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention.
[0103] On the one hand, a large-scale manufacturing industry privacy data protection and supervision system, as Figure 1 shown, includes a registration module, a multi-party supervision decision-making module, an attribute key generation system module, and a large-scale manufacturing blockchain module;
[0104] In the registration module, each supervisor submits information to the enterprise for registration, and the enterprise sets a key for it; the registration module belongs to the enterprise, and records the information of the supervisor according to the attribute set submitted by the supervisor;
[0105] In the multi-party supervision decision-making module, the supervision authorizer within the supervision department actively conducts supervision or, upon the request of a customer or a manufacturer, authorizes a certain supervisor to execute supervision through decision-making; a certificate, i.e., a supervision certificate, will be given after the decision-making ends; the multi-party supervision decision-making module belongs to the supervision department, and multiple individuals vote on the same supervision request to generate a supervision certificate and assign the supervision power to a supervisor to execute supervision;
[0106] The attribute key generation system module belongs to an enterprise. According to the registration information and the supervision certificate submitted by the registration module and the multi-party supervision decision-making module, it verifies the identity of the supervisor and generates an attribute key. The enterprise uses this attribute key to upload the traceability content that the supervisor needs to view to the chain;
[0107] The large-scale manufacturing blockchain module receives the information uploaded by the attribute key generation system module, specifically including the main chain and the sub-chains; the main chain is composed of various enterprises, and each supervision department has reserved nodes on the main chain; the sub-chains are composed of various departments of each manufacturer (such as suppliers, manufacturers, transporters, and sellers, etc.), and traceability is carried out based on the blockchain architecture.
[0108] The cloud service provider module: An agreement is reached between each manufacturer and the cloud service provider, and the off-chain data enterprise will store encrypted data in the cloud according to the storage services provided by the cloud service provider module.
[0109] On the other hand, a method for protecting and supervising the privacy data of the large-scale manufacturing industry, as Figure 2 shown, is implemented based on the aforementioned large-scale manufacturing industry privacy data protection and supervision system, and includes the following steps:
[0110] Step 1: The supervisor conducts enterprise registration in the enterprise privacy data protection and supervision system;
[0111] Step 1.1: Initialize the enterprise data;
[0112] Step 1.1.1: Set g2 as the generator of G, i.e., g2 ∈ G, and g1 is generated by the isomorphic mapping of g2, with g1 = ψ(g2), where ψ(*) refers to the isomorphic mapping. Select and δ1, such that u, where refers to the set of non-negative integers less than p, p is a constant, R refers to randomly selecting in the uniform distribution manner, and h, δ1, and δ2 are random parameters obtained after being selected in the manner of R and are used to form the group tracing key. u and v are the generators of G1, and G and G1 are multiplicative groups of prime order p > 2 k ;
[0113] Step 1.1.2: Select t enterprise administrators during the consensus phase, where t ≥ 1. The enterprise privacy data protection and supervision system distributes the public key Y to each enterprise administrator, and the key of each enterprise administrator, i.e., the private key of the enterprise administrator, is set as: And let where w j is used to form the subsequent group public key, and j is one of the t enterprise administrators, j ∈ [1, t].
[0114] Step 1.1.3: Set the group public key gpk = (g1, g2, h, u, v, {w j | 1 ≤ j ≤ t}), and the group tracing key is gmsk = (δ1, δ2);
[0115] Step 1.1.4: Set the supervisor attribute set of the enterprise attribute key generation system as S j = {s1, s2,..., s n}, where s n corresponds to the attributes of n supervisors.
[0116] Initialize an empty revocation list RL and a voting value T r , where RL is used to store the revocation marks of revoked users, and T r is used to collect the support or not of supervisors on the tracing issue;
[0117] Step 1.2: Register the identities of the supervisors.
[0118] Supervisor i submits the attribute set S = {s i ,..., s n}.
[0119] Each enterprise administrator generates the private key fragment x j ∈ Z p , and sends the private key fragment to the supervisor i through a secure channel, where Z p is a non - negative integer less than the constant p, and x j is a randomly selected number;
[0120] Supervisor i calculates its own private key:
[0121] Supervisor i calculates its own ID:
[0122] The enterprise generates the attribute private key SK for the supervisor: where s is one in the attribute set S submitted by the supervisor, and t is a non - negative integer random number less than the constant p, The key corresponding to the attribute set by the enterprise for the regulator attribute;
[0123] Step 2: Customers without on-chain nodes cannot conduct traceability, or when other enterprises trace quality problems and involve the privacy of other enterprises, and when they cannot access data off-chain, they initiate regulatory traceability to the regulatory department;
[0124] Step 3: The regulatory agency executes secure multi-party computation to grant permissions to the regulator.
[0125] The regulatory agency executes secure multi-party computation to grant permissions to the regulator; if there are m authorized personnel in the regulatory agency and the threshold is set to weight, then at least authorized persons need to agree to conduct legal supervision; where P = {P1, P2,..., P m} is a set of m regulatory authorizers;
[0126] Set up a bulletin board, where the bulletin board is used to publicize information, and each regulator can see the information publicized on the bulletin board. Only the bulletin board administrator, Dealer, has the permission to change and update the content on the bulletin board, and others can only read or download it.
[0127] Step 3.1: The specific work of Dealer:
[0128] Step 3.1.1: Select two large prime numbers p and q, and calculate to make y = p * q satisfied, where y is a positive integer;
[0129] Step 3.1.2: Select e such that Find d such that where gcd(*) is the GCD function, that is, it returns the greatest common divisor of two or more integers, is the Euler's totient function, e, d, l refer to certain constants that satisfy the conditions, and mod is a mathematical operation symbol, referring to the modulo operator;
[0130] Step 3.1.3: Select a one-way function H(.), such that the value range H(.) ∈ [y δ , where 0 ≤ δ ≤ 1 is a security parameter, and the meaning of [*] is the data set composed of numbers greater than or equal to 1 and less than or equal to the number in the parentheses. For example, [y] = {1, 2,..., y}.
[0131] Step 3.1.4: Select sample information where, is the set of non-negative integers less than y.
[0132] Step 3.1.4.1: Randomly construct a polynomial of degree p0 - 1: where, is non-negative and less than the constant an integer is a random one of
[0133] Step 3.1.4.2: Calculate each sub-secret information and the content announced on the bulletin board where i = 1, 2,..., m
[0134] Step 3.1.4.3: The Dealer sends d i secretly to the regulatory authorizer P i , and announces W1, W2,..., W m , and the sample information w, where is the content on the bulletin board calculated from the coefficients of the polynomial of degree p0 - 1 and the sample information
[0135] Step 3.1.4.4: Each regulatory authorizer P i verifies the correctness of the secret information d i by the following formula: where i = 1, 2,..., m. If the above formula holds, the regulatory authorizer P i accepts d i as the sub-secret; otherwise, rejects d i , where d, d i are both confidential and are destroyed after the regulatory authorization ends, and p, q are destroyed
[0136] Step 3.2: Generation of authorization vouchers:
[0137] Let K = {K1, K2,..., K r} be the set of authorization proofs shared by m authorizers in the set P = {P1, P2,..., P m}. The Dealer randomly selects random constants
[0138] such that any P0 individuals among P1, P2,..., P m can reconstruct the authorization voucher K j . The Dealer calculates the encrypted authorization voucher which will be sent to the regulator applying for supervision later
[0139] Step 3.3; Recovery of authorization vouchers:
[0140] Any set of P0 regulatory authorizers where D ∈ P. After agreeing to this supervision request, each regulatory authorizer P in the set A i calculates the sub-key:
[0141] Select random parameters δ1 and δ2 are security parameters, and 0 ≤ δ1, δ2 ≤ 1. Calculate the encrypted sample information and the encrypted number information of the authorizers The above various parameters w, m j , S ij , W i , w′, m′ pass through the one-way function H(*) to form the encrypted information b ij = H(w, m j , S ij , W i , w′, m′), and calculate another encrypted information θ on the integer ring ij = C ij + b ij d i , b ij and θ ij are used to form the verification value;
[0142] For any set D of P0 regulatory authorizers, P i Announce the verification value: {θ ij , b ij}, and obtain the set of authorized sub-key information {m j , S ij} and send it to the supervisor applying for supervision for execution. The supervisor verifies the correctness of the sub-key S i provided by P ij by the following formula:
[0143] The supervisor takes ρ = m!, and calculates on the integer cyclic group Z: and α i = ρ * β i ;
[0144] The supervisor obtains the supervision proof K j through the following calculation: Since then where j = 1, 2,..., r;
[0145] If the Dealer allows m participants P1, P2,..., P m to share the new supervision proof K r+1 , then randomly selected m r+1 and values are announced on the bulletin board.
[0146] Step 4: The supervisor who has obtained the supervision right executes the supervision;
[0147] The regulator who has obtained the regulatory power submits the regulatory certificate K j , as well as the identity attribute information, and requests regulation;
[0148] Step 5: The relevant enterprise checks the regulatory certificate submitted by the regulator and confirms whether the identity certificate exists.
[0149] The enterprise checks the regulatory certificate submitted by the regulator and confirms whether its attribute certificate exists;
[0150] Step 6: After the enterprise confirms its identity, it generates on-chain data for regulatory traceability;
[0151] Step 6.1: The enterprise first generates a temporary key pair (R, r), where R = rG, G is the multiplicative cyclic group set during previous registration, and r is a random number. This key pair is transmitted with the transaction; then it calculates the shared secret ty: ty = H(r·ID B ) = H(ID B ·R), and encrypts ty using the group public key, where ID B is the ID number of regulator B. The enterprise uses to generate the temporary address S.A of this regulator.
[0152] Step 6.2: The enterprise selects the exponent α, calculates T1←u α , T2←v β , T3←A i h α+β , randomly selects blinding factors r α , r β , r x , where refers to the bilinear mapping. Calculate:
[0153]
[0154]
[0155]
[0156]
[0157]
[0158] Step 6.3: Use the hash function to calculate the query value c←H(M||T1||T2||T3||R1||R2||R3||R4||R5).
[0159] Step 6.4: Generate the parameters s α 、sβ , s x , wherein
[0160] σ1 ← xα
[0161] σ2 ← xβ
[0162] s α ← r α + cα
[0163] s β ← r β + cβ
[0164] s X ← r x + cx
[0165]
[0166]
[0167] Step 6.5: The enterprise generates a Bulletproofs zero - knowledge proof of the revocation mark and verifies the legitimacy of the enterprise's identity without obtaining the visitor's revocation mark. The steps are as follows:
[0168] Step 6.5.1: The enterprise constructs two random numbers a L , a R , such that <a L , 2> = reg, a R = a L - 1. Construct a commitment proof of a L , a R : where <a1, a2> refers to the inner product of a1 and a2, and g is a random number.
[0169] Step 6.5.2: Randomly select blinding factors γ, t i (i = 1, 2), τ1 and τ2 are non - negative random integer coefficients less than a constant p, and construct s L , s R 's commitment Calculate the relevant parameters τ(x), ε, t(x), l(x), r(x) of the zero - knowledge proof:
[0170] y = H(A, S)
[0171] z = H(A, S, y)
[0172] x = H(T1, T2, z)
[0173]
[0174] l = l(x) = a L -z + s L ·x
[0175] r = r(x) = y n (a R +z + s R ·x) + 2z 2
[0176] t(x) = <l(x), r(x)>
[0177] τ(x) = τ1·x + τ2·x 2 +z 2 ·γ, γ ∈ Z p
[0178] ε = α + θ·x
[0179] Step 6.5.3: Construct the commitment V = g reg h γ , to obtain the zero - knowledge proof η = {τ(x), ε, t(x), l(x), r(x)};
[0180] Step 6.6: The signature of the enterprise's private data is: σ ← (M, T1, T2, T3, c, s α , s β , s x , s σ1 , s σ2 , S.A, t, η), where M is a 1×n access matrix;
[0181] Step 6.7: Input the plaintext m, that is, the data to be encrypted, gmsk, and the access policy (M, λ), M i represents the i - th row function in matrix M. λ maps M i to the attribute, denoted as λ{1, 2,...l} → {1, 2,..., n}, and output the ciphertext CT: where, ty is the shared secret and p is a random value.
[0182] Step 6.8: The enterprise broadcasts the ciphertext CT, the zero - knowledge proof η of the revocation mark, the encrypted shared secret ty, and the signature to each node after uploading the data to the chain.
[0183] Step 7: After receiving the broadcast information, the supervisor verifies the legality of the message.
[0184] Step 7.1: First, verify the zero - knowledge proof η to determine whether the user's identity is legal. The supervision executor calculates and send it to the enterprise;
[0185] Step 7.2: Enterprise inspection: Determine whether it holds. Determine whether it holds. Determine whether t(x) = <l(x), r(x)> holds. If all of the above judgments hold, the identity of the supervisor is legal. If not, the supervisor's identity information is incorrect, does not meet the regulatory traceability request, and punishment is given.
[0186] After passing the verification, calculate: Then, calculate If then the signature is valid, otherwise it is invalid. If the signature is valid, upload the information that passed the verification to the blockchain. Otherwise, if it is invalid, reject the traceability request and the process terminates.
[0187] Step 8: The supervisor legally traces the data requested by the customer or manufacturer on the blockchain traceability platform.
[0188] Step 9: Conduct regulatory traceability until the off-chain database is found and the traceability information is viewed.
[0189] Send a viewing application. The system first decrypts the ciphertext CT under the user's attribute private key and access policy (M, λ). If the user's attribute set can meet the data access policy, allow the user to access the data and output the plaintext m; otherwise, the access fails. Plaintext m:
[0190] The regulatory model proposed in the embodiments of the present invention mainly realizes multi-party secure regulatory authorization and regulatory traceability under privacy protection, so it focuses on whether user identity access control can be achieved. This regulatory model can reflect its functions and roles by simulating the following scenarios. Include: An authorized supervisor or enterprise conducts illegal regulatory traceability on private data, a supervisor who has not obtained regulatory authorization conducts supervision on private data, whether the signature of a malicious node can pass verification, whether the signature of a legitimate user can achieve identity tracking, whether a supervisor who does not conform to the identity can trace and track data, and whether the attribute policy can control the user's access to data for correctness testing of the solution. Six scenarios are preset in this embodiment for testing:
[0191]
[0192]
[0193] In this embodiment, six scenario test experiments were conducted on the security of the system, the effectiveness of privacy protection, and the enforceability of supervision. During the test, we simulated malicious nodes that would sign messages, initiate supervision requests, execute supervision tracing functions, and so on. We judged the effectiveness of the solution based on the number of tests that passed in the end.
[0194] According to the test, the present invention has significant advantages in terms of solution effectiveness, privacy protection security, and supervision rationality, indicating the feasibility of the present invention solution in industrial privacy protection and supervision system implementation.
[0195] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solution formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solution formed by mutually replacing the above features with technical features having similar functions (but not limited to) disclosed in the embodiments of the present disclosure.
Claims
1. A large-scale manufacturing industry privacy data protection and supervision system, characterized in that, It includes a registration module, a multi-party supervision decision-making module, an attribute key generation system module, and a large-scale manufacturing blockchain module; In the registration module, each supervisor submits information to the enterprise for registration, and the enterprise sets a key for it; The enterprise to which the registration module belongs records the information of the supervisor according to the attribute set submitted by the supervisor; In the multi-party supervision decision-making module, the supervision authorizer within the supervision department actively supervises or, due to the request of the customer or manufacturer, decides to authorize a certain supervisor to execute the supervision; after the decision is made, a voucher will be given, that is, a supervision certificate; The multi-party supervision decision-making module belongs to the supervision department. Multiple people vote on the same supervision request to generate a supervision certificate and assign the supervision power to a supervisor to execute the supervision; The attribute key generation system module belongs to the enterprise. According to the registration information and supervision certificate submitted by the registration module and the multi-party supervision decision-making module, it verifies the identity of the supervisor and generates an attribute key; the enterprise uses this attribute key to upload the traceability content that the supervisor needs to view to the blockchain; The large-scale manufacturing blockchain module receives the information uploaded by the attribute key generation system module, specifically including the main chain and the sub-chain; the main chain is composed of each enterprise, and each supervision department has a reserved node on the main chain; the sub-chain is composed of each department of each manufacturer and conducts traceability based on the blockchain architecture; Cloud service provider module: Each manufacturer reaches an agreement with the cloud service provider. For the data off the chain, the enterprise will store the encrypted data in the cloud according to the storage service provided by the cloud service provider module.
2. A method for protecting and supervising privacy data in a large-scale manufacturing industry, which is implemented based on the large-scale manufacturing industry privacy data protection and supervision system described in claim 1, and is characterized in that Specifically, it includes the following steps: Step 1: The supervisor registers with the enterprise privacy data protection and supervision system; Step 2: Customers without on-chain nodes cannot conduct traceability, or when other enterprises trace quality problems and involve the privacy of other enterprises and are unable to access the data off the chain when tracing, they initiate supervision and traceability to the supervision department; Step 3: The supervision agency executes secure multi-party computing to grant permissions to the supervisor; The supervision agency executes secure multi-party computing to grant permissions to the supervisor; If the number of authorized personnel of the regulatory agency is m and the threshold is set as weight, then at least authorized persons need to agree in order to conduct legal supervision; where P = {P1, P2,..., P m} is the set of m regulatory authorized persons; Set up a bulletin board. Here, the bulletin board is used to publicize information. All supervisors can see the information publicized on the bulletin board. Only the bulletin board administrator, Dealer, has the permission to change and update the content on the bulletin board, and others can only read or download; Step 4: The supervisor who has obtained the supervision power executes the supervision; The regulator with regulatory power submits a regulatory certificate K to the relevant enterprise j , as well as identity attribute information, and requests supervision; Step 5: The relevant enterprise checks the supervision certificate submitted by the supervisor to confirm whether the identity certificate exists; Step 6: After the enterprise confirms the identity, it generates data for uploading to the blockchain for supervision and traceability; Step 7: After receiving the broadcast information, the supervisor verifies the legality of the message; Step 8: The supervisor legally traces the data requested by the customer or manufacturer on the blockchain traceability platform; Step 9: Conduct supervision and traceability until the off-chain database is found to view the traceability information.
3. A method for protecting and supervising privacy data in large-scale manufacturing industries according to claim 2, characterized in that, The specific steps of Step 1 are as follows: Step 1.1: Initialize the enterprise data; Step 1.1.1: Set \(g_2\) as the generator of \(G\), i.e., \(g_2\in G\), and \(g_1\) is generated by the isomorphic mapping of \(g_2\), so \(g_1 = \psi(g_2)\), where \(\psi(*)\) refers to the isomorphic mapping. Select and \(\delta_1\), such that \(u\), where refers to the set of non - negative integers less than \(p\), \(p\) is a constant, \(R\) means randomly selecting in a uniform distribution manner, and \(h,\delta_1,\delta_2\) are random parameters obtained after being selected in the way of \(R\) and are used to form the group tracing key. \(u,v\) are the generators of \(G_1\), and \(G\) and \(G_1\) are multiplicative groups of order prime number \(p>2\) k ; Step 1.1.2: Select t enterprise administrators in the consensus phase, where t ≥ 1. The enterprise privacy data protection and supervision system distributes the public key Y to each enterprise administrator. The key of each enterprise administrator, that is, the private key of the enterprise administrator, is set as: And let where w j is used to form the subsequent group public key, j is one of the t enterprise administrators, and j ∈ [1, t]; Step 1.1.3: Set the group public key gpk = (g1, g2, h, u, v, {w j |1 ≤ j ≤ t}), and the group tracing key is gmsk = (δ1, δ2); Step 1.1.4: Set the supervisor attribute set of the enterprise attribute key generation system to S j ={s1, s2, …, s n}, where s n corresponds to the attributes of n supervisors respectively; Initialize an empty revocation list RL and a voting value T r , where RL is used to store the revocation marks of revoked users, and T r is used to collect the support or opposition of supervisors on the tracking issue; Step 1.2: Register the identities of the supervisors; Supervisor i submits the attribute set S = {s i , …, s n}; Each enterprise administrator generates a private key fragment of supervisor i and sends the private key fragment to the supervisor i through a secure channel, where Z p is a non - negative integer less than the constant p, and x j is a randomly selected number among them; The supervisor i calculates its own private key: Supervisor i calculates its own ID: The enterprise generates the attribute private key SK for the supervisor: where s is one in the attribute set S submitted by the supervisor, and t is a non-negative integer random number less than the constant p. is the key corresponding to the attribute set by the supervisor's attributes for the enterprise.
4. A method for protecting and supervising privacy data in large-scale manufacturing industries according to claim 2, characterized in that The specific steps of Step 3 are as follows: Step 3.1: The specific work of Dealer: Step 3.1.1: Select secure large prime numbers p and q, and calculate to satisfy y = p * q, where y is a positive integer; Step 3.1.2: Select e such that Find d such that it satisfies where gcd(*) is the GCD function, that is, it returns the greatest common divisor of two or more integers. is the Euler's totient function, e, d, and l refer to certain constants that satisfy the conditions, and mod is a mathematical operation symbol, referring to the modulo operator; Step 3.1.3: Select a one-way function H(.), such that the range H(.) ∈ [y δ , where 0 ≤ δ ≤ 1 is a security parameter, and [*] means the data set consisting of numbers greater than or equal to 1 and less than or equal to the number within the parentheses. For example, [y] = {1, 2,..., y}; Step 3.1.4: Select sample information Among them, is the set of non-negative integers less than y; Step 3.1.4.1: Randomly construct a polynomial of degree p0 - 1: wherein, is a non - negative integer less than the constant ; is a random one in; Step 3.1.4.2: Calculate each sub-secret information and the content announced on the bulletin board where i = 1, 2,..., m; Step 3.1.4.3: The Dealer secretly sends d i to the regulatory authority P i , and publishes it on the bulletin board along with the sample information w, where is the content of the bulletin board calculated from the coefficients of the polynomial of degree p0 - 1 and the sample information; Step 3.1.4.4: Each regulatory authorizer P i verifies the correctness of the secret information d i by the following formula: where i = 1, 2,..., m; if the above formula holds, then the regulatory authorizer P i accepts d i as a sub-secret; otherwise, rejects d i , where both d and d i are confidential and are destroyed after the regulatory authorization ends, along with p and q; Step 3.2: Generation of authorization credentials: Let \(K = \{K_1, K_2, \ldots, K r \}\) be the set of authorized proofs shared by \(m\) authorizers \(P=\{P_1, P_2, \ldots, P m \}\). The Dealer randomly selects a random constant To enable any P0 individuals among P1, P2,..., P m to reconstruct the authorization credential K j , the Dealer calculates the encrypted authorization credential and will send this authorization credential to the supervisor who applies for supervision later; Step 3.3; Recovery of authorization credentials: Any set of P0 regulatory authorizers where D ∈ P; after agreeing to this regulatory request, each regulatory authorizer P in set A i Calculate the sub-key: Select random parameters δ1 and δ2 are security parameters, and 0 ≤ δ1, δ2 ≤ 1. Calculate the encrypted sample information and the encrypted number of authorizers information The above parameters w, m j , S ij , W i , w′, m′ are used to form the encrypted information b through the one-way function H(*) ij = H(w, m j , S ij , W i , w′, m′), and calculate another encrypted information on the integer ring b ij and are used to form the verification value; Among any set D of P0 regulatory authorizers, P i Publish the verification value: And obtain the set of authorized sub-key information {m j , S ij} and send it to the regulator applying for supervision for performing supervision. The regulator verifies the P i Provided sub-key S ij For correctness, by the following formula: The supervisor takes ρ = m!, and calculates on the integer cyclic group Z: and α i = ρ * β i ; The supervisor obtains the supervision certificate K through the following calculations j : Since then where j = 1, 2,..., r; If the Dealer wants to let m participants P1, P2,..., P m share a new regulatory proof K r+1 , then randomly selected m r+1 and values are published on the bulletin board.
5. A method for protecting and supervising privacy data in a large-scale manufacturing industry according to claim 2, characterized in that, The specific steps of step 6 are as follows: Step 6.1: The enterprise first generates a temporary key pair (R, r), where r = rG, G is the multiplicative cyclic group set during previous registration, and r is a random number; this key pair is transmitted along with the transaction; then it calculates the shared secret ty: ty = H(r·ID B ) = H(ID B ·R), and encrypts ty using the group public key, where ID B is the ID number of supervisor B; the enterprise uses to generate the temporary address S.A of this supervisor; Step 6.2: The enterprise selects the exponent α, Calculate T1←u α , T2←v β , T3←A i h α+β , randomly select the blinding factor r α , α β , r x , where refers to the bilinear mapping; calculate: Step 6.3: Use the hash function to calculate the query value c ← H(M||T1||T2||T3||R1||R2||R3||R4||R5); Step 6.4: Generate parameter s according to c α and s β and s x and where σ1←xα σ2←xβ s α ←r α +cα s β ←r β +cβ s x ←r x +cx Step 6.5: The enterprise generates a Bulletproofs zero-knowledge proof of the revocation mark, and verifies the legitimacy of the enterprise's identity without obtaining the visitor's revocation mark. The steps are as follows: Step 6.5.1: The enterprise constructs two random numbers a L , a R , such that <a L , 2> = reg, a R = a L -1; construct a L , a R 's commitment proof: Among them, <a1, a2> refers to the inner product of a1 and a2, and g is a random number; Step 6.5.2: Randomly select blinding factors θ ∈ Z p , γ, t i (i = 1, 2), τ1 and τ2 are non - negative random integer coefficients less than the constant p, and construct s L , s R commitment of Calculate the relevant parameters τ(x), ε, t(x), l(x), r(x) of the zero - knowledge proof: y = H(A,S) z = H(A,S,y) x = H(T1,T2,z) l = l(x) = a L -z + s L ·x r = r(x) = y n (a R + z + s R · x) + 2z 2 t(x) = <l(x),r(x)> τ(x) = τ1·x + τ2·x 2 + z 2 ·γ, γ ∈ Z p ε = α + θ·x Step 6.5.3: Construct the commitment V to reg = g reg h γ , and obtain the zero-knowledge proof η = {τ(x), ε, t(x), l(x), r(x)}; Step 6.6: The signature of the enterprise privacy data is: σ←(M,T1,T2,T3,c,s α ,s β ,s x ,s σ1 ,s σ2 ,S.A,t,η), where M is a 1×n access matrix; Step 6.7: Input the plaintext m, i.e., the data to be encrypted, gmsk, and the access policy (M, λ), where M i represents the i-th row function in matrix M, and the function λ maps M i to the attributes. Denote λ{1,2,…l}→{1,2,…,n}, and output the ciphertext CT: where ty is the shared secret and p is a random value; Step 6.8: After the enterprise broadcasts the ciphertext CT, the zero-knowledge proof η of the revocation mark, the encrypted shared secret ty, and the signature to each node after uploading the data to the chain.
6. A method for protecting and supervising privacy data in a large-scale manufacturing industry according to claim 2, characterized in that, The specific steps of step 7 are as follows: Step 7.1: First, verify the zero-knowledge proof η to determine whether the user's identity is legal; the regulatory executor calculates and send it to the enterprise; Step 7.2: Enterprise inspection: Determine whether holds; determine whether holds; determine whether t(x) = <l(x), r(x)> holds; if all of the above judgments hold, the identity of the supervisor is legal; if not, the supervisor identity information is incorrect, does not meet the supervision and traceability request, and punishment is given; Step 7.3: After verification is passed, calculate: Then, calculate If The signature is valid, otherwise it is invalid; if the signature is valid, upload the verified information to the blockchain; otherwise, if it is invalid, reject the traceability request and the process terminates.
7. A method for protecting and supervising privacy data in large-scale manufacturing industries according to claim 2, characterized in that, The specific step 9 is to send a viewing application. The system first decrypts the ciphertext CT under the user's attribute private key and access policy (M,λ); if the user's attribute set can meet the data access policy, the user is allowed to access the data, and the plaintext m is output; Otherwise, the access fails, where the plaintext m is:
Citation Information
Patent Citations
Multi-chain evidence obtaining method of alliance chain based on threshold signature decision system
CN113079020A
System, method, device, medium and equipment for data security multi-party computing based on blockchain
CN115037548B
Supervisory blockchain system and method
CN107483198A
Blockchain data supervision method and system based on attribute encryption
CN111859444A