A blockchain access control method based on SM9 attribute-based encryption
By implementing SM9-based attribute-based encryption on blockchain network and IPFS, the inefficiency problem of traditional access control solutions in multi-user scenarios is solved, efficient one-to-many ciphertext sharing and fine-grained access control are realized, ensuring data security and auditability.
Patent Information
- Application Number
- CN202211658824.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-22
AI Technical Summary
The traditional access control scheme and public key encryption system have problems such as large computing overhead, high communication costs and low work efficiency in multi-user scenarios. The attribute-based encryption scheme based on SM9 lacks explanation for data secure storage and is insufficient in generalization.
A blockchain access control method based on SM9 is proposed. By implementing attribute-based encryption on blockchain network and IPFS, using SM9 IBE as a building block, an attribute-based access control solution is designed, and combining blockchain and IPFS technology to ensure secure storage and access control of data.
It realizes efficient one-to-many ciphertext sharing and fine-grained access control in a multi-user environment, reduces computing overhead and communication costs, and ensures data confidentiality, integrity and auditability.
Smart Images

Figure CN116232568B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of public key encryption system, and specifically to a blockchain access control method based on SM9 attribute-based encryption. Background Art
[0002] SM9 is an identification cryptographic algorithm standard independently developed by my country (see "GM / T0044-2016SM9 Identification Cryptographic Algorithm" standard, National Cryptography Administration, March 2016), which defines a set of identity-based cryptographic schemes, including signature, encryption and key algorithms and protocols. SM9 is an identity-based public key cryptographic algorithm, but it is different from the common RSA public key cryptographic algorithm. The public key of the identification cryptographic algorithm is a user's identity identifier, such as mobile phone number, ID card number, etc. The user's private key is generated by the user's identity identifier and the system master key. Because the public key of the identification cryptographic algorithm is the user's identity identifier, it is not necessary to obtain the other party's public key certificate to ensure that the public key is valid when decrypting ciphertext or verifying signatures. This simplifies the cumbersome PKI interaction process of traditional public key cryptographic algorithms to a certain extent. However, the identification cryptographic algorithm also has certain problems, that is, it may cause the leakage of user information during the encryption process, and cannot meet the needs of privacy protection.
[0003] Attribute-based encryption was first developed from fuzzy identity-based encryption. It is an encryption technology that binds user identity to a series of attributes. By setting attribute sets and access structures for user private keys or ciphertexts, decryption can only be achieved when the attribute sets match the access structures, thereby achieving one-to-many encrypted data sharing and fine-grained access control. Current attribute encryption can be divided into key-policy attribute encryption (KP-ABE) and ciphertext-policy attribute encryption (CP-ABE). In KP-ABE, the policy is embedded in the key and the attribute is embedded in the ciphertext; while in CP-ABE, the policy is embedded in the ciphertext and the attribute is embedded in the key. Attribute-based encryption based on CP-ABE allows data owners to customize the access policy of ciphertexts. Compared with KP-ABE, it is more suitable for distributed storage and access control environments where the decryption party is uncertain, and can meet the needs of fine-grained access control and one-to-many data sharing.
[0004] As an emerging integrated technology, blockchain has the characteristics of decentralization, confirmation of ownership, and immutability, which can enable individuals or organizations to establish trusted data access control in a weak trust network environment. The alliance chain platform Hyperledger Fabric is an open source, enterprise-level, permissioned distributed ledger platform. Its original design is for enterprise-level applications. It has complete permission control. Members need to pass identity authentication to join the network, taking into account data sharing and privacy protection. At the same time, Fabric uses channels to isolate ledgers. Members who are not in the relevant channels cannot access any transactions or information on the channel. The ledger of each node is maintained by blockchain stripes and world states. The blockchain stripes save all transaction histories of each smart contract on a specific channel, and the world state maintains the current state of variables for each specific smart contract, so that any member's access to block information and any operation will be recorded.
[0005] IPFS (InterPlanetary File System) is a peer-to-peer distributed file system. Its principle is to use content-based addresses instead of domain-based addresses. Simply put, users are looking for content stored somewhere, not a certain address. They only need to confirm the hash of the verified content and find the corresponding content through the hash. Compared with traditional third-party servers, such as cloud servers, storage methods are prone to single point failures, high storage costs, slow data upload and download speeds, and low security performance. IPFS, as a distributed storage, improves storage space utilization and increases upload and download speeds. Secondly, IPFS also uses a series of encryption technologies such as blockchain technology, hash functions, and zero-knowledge proofs to avoid single point failures, prevent data tampering, and ensure data security.
[0006] 2) Problems with existing technologies:
[0007] Traditional access control schemes and public key encryption systems are not suitable for multi-user scenarios. For example, the number of access control policies tends to increase with the increase of user scale. The public key encryption system relies on the public key infrastructure PKI, which needs to obtain the public key information of each user in access control and needs to send the ciphertext information to the corresponding user one-to-one, which will cause problems such as high computing overhead, high communication cost, and low work efficiency.
[0008] In the existing technical solutions, there are very few attribute-based encryption schemes based on SM9. Among them, although the attribute-based encryption scheme based on SM9 proposes a data sharing scheme, it does not explain the secure storage of data. Secondly, the access structure used in the attribute base part of the scheme is a tree structure, and its universality is not as good as the linear secret sharing scheme (LSSS) matrix to a certain extent. For this reason, we propose a blockchain access control method based on attribute-based encryption of SM9. Summary of the invention
[0009] 1. Technical issues to be solved
[0010] In view of the deficiencies in the prior art, the present invention provides a blockchain access control method based on attribute-based encryption of SM9 to solve the above-mentioned problems.
[0011] (II) Technical solution
[0012] To achieve the above-mentioned purpose, the present invention provides the following technical solution: a blockchain access control method based on attribute-based encryption of SM9, comprising the following steps:
[0013] Step 1: Blockchain networking, select multiple blockchain nodes to build the Fabric alliance blockchain network;
[0014] Step 2: Deploy IPFS on the host or server to access the IPFS public chain node;
[0015] Step 3: The trusted center initializes the system and obtains the system parameters required by the SM9-based attribute encryption method;
[0016] Step 4: The trusted center generates the system master public key MPK published by the trusted center and the system master private key MSK secretly stored by the trusted center;
[0017] Step 5: Based on the request of user B, the trusted center combines the system master private key MSK and user B's attribute set Attr B , user B's group identity GID and system parameters to generate the user attribute private key SK U And send it to user B;
[0018] Step 6: Based on user A’s request, the trusted center generates a symmetric key SK and sends it to user A;
[0019] Step 7: User A uses the symmetric key SK to encrypt file M. f Perform SM4 ECB mode encryption and generate the ciphertext CT f Upload to IPFS for storage, IPFS returns the hash value M h To user A;
[0020] Step 8: User A encrypts the symmetric key SK with the system master public key MPK, the group identity GID of user B and the system parameters and uploads the generated ciphertext CT to the Fabric alliance blockchain for storage;
[0021] Step 9: Based on the request of user B, the Fabric alliance blockchain sends the ciphertext CT to user B, and user B uses the attribute private key SK U Decrypt the ciphertext CT in combination with the system parameters to obtain the decryption result SK′;
[0022] Step 10: IPFS sends CT based on user B’s request f To user B;
[0023] Step 11: User B uses SK′ to calculate CT f Decryption results in decryption result M′ f .
[0024] Preferably, the first step includes the following:
[0025] S1: Use the host or server as a blockchain node to build a Hyperledger Fabric blockchain network and start running the BYFN sample network;
[0026] S2: Add new organizations to the BYFN sample network according to alliance needs, and generate MSP files and organization definition files;
[0027] S3: The authentication center CA node registers the identities of user A and user B according to the administrator through the blockchain node.
[0028] Preferably, the fourth step includes the following contents:
[0029] S1: The trusted center randomly generates α, a∈Z p , and let MSK = α||a, as the system master private key, where α and a are both components of the system master private key, and p represents the group G1, G2, G T The order, Z p represents a finite field modulo a prime number p, G1 and G2 both represent additive cyclic groups, G T represents the multiplicative cyclic group, the groups G1, G2 and G T have the same order;
[0030] S2: The trusted center calculates the system master public key MPK based on the components α and a of the selected master private key. MPK = {α·P1, a·P2}, and lets PK1 = α·P1 represent one of the components of the system master public key, and let PK2 = a·P2 represent the second component of the system master public key. P1 represents the generator of group G1, and P2 represents the generator of group G2.
[0031] Preferably, the fifth step includes the following contents:
[0032] S1: User B sets a group identity GID and sends it to the trusted center to request the attribute private key;
[0033] S2: Verify the validity of the GID and whether user B is in the group GID. If the verification is successful, the trusted center selects a random number t∈Z for user B. p , combined with the system master private key MSK = α||a, user B's attribute set Attr B , User B's group identity GID calculates part of User B's attribute private key:
[0034]
[0035] sk2=(t·a -1 )·P1;
[0036] sk1 represents one of the components of the attribute private key of user B, sk2 represents the second component of the attribute private key of user B, H1 represents a cryptographic function derived from a secure cryptographic hash function, hid represents an encryption private key generation function identifier, hid=3;
[0037] S3: For the attribute set Attr B For each attribute x in , the following formula is used as another part of the attribute private key of user B:
[0038] sk x =(t·a -1 )·h(x);
[0039] a -1 represents the inverse of a modulo p, sk x It represents the third component of the attribute private key of user B, and h() represents the secure SM3 hash algorithm;
[0040] S4: The trusted center generates the attribute private key of user B And send it to user B through a secure channel;
[0041] S5: User B accepts and secretly saves the attribute private key SK U .
[0042] Preferably, the seventh step includes the following contents:
[0043] S1: User A calculates the file M using the following formula with the symmetric key SK f Ciphertext CT f :
[0044] CT f =Enc(SK,M f);
[0045] Enc() represents the ECB mode encryption algorithm of SM4;
[0046] S2: User A sends CT f Upload to IPFS for storage;
[0047] S3: IPFS returns the hash value M h To user A.
[0048] Preferably, the specific content of the eighth is:
[0049] S1: User A sets a group identity GID for encryption. Assuming that when matching user B, the following is used as the encryption intermediate value:
[0050] Q B =H1(GID||hid,p)·P1+PK1;
[0051] S2: User A randomly selects s∈Z p , the calculation formula is as follows:
[0052] C1=s·Q B ;
[0053] g=e(PK1,P2);
[0054] ω=g s =e(α·P1,P2) s =e(P1,P2) αs ;
[0055] C1 represents one of the components of the ciphertext, g represents the encrypted intermediate result, and e represents the number of cells from G1×G2 to G T Bilinear pairings of ;
[0056] S3: Use the random number s selected by user A as the secret value and construct an access structure (MA, ρ); in the access structure, MA is an L×N matrix, and ρ represents the function that associates the rows of MA with the attributes; user A randomly selects the vector And construct the vector vector and the i-th row M of the matrix MA i Satisfies the following formula:
[0057]
[0058] λ i Indicates the share of each attribute in the secret value;
[0059] S4: For each attribute i in the attribute encryption strategy, randomly select r i ∈Zp , and use the following formula to calculate the ciphertext part C of the attribute encryption i and D i :
[0060] C i =λ i PK2+(-r i )·h(i);
[0061] D i =r i P1;
[0062] C i and D i Indicates the attribute components of the ciphertext, and h() represents the secure SM3 hash algorithm;
[0063] S5: User A calculates:
[0064] K=KDF(C1||ω||GID,Klen1+Klen2);
[0065] K represents a derived key, KDF() represents a key derivation function used to generate a message encryption key and a message authentication key, GID represents the group identity set by user A in step h1, Klen1 represents the bit length of the bit string K1, K1 represents the key used for SM4 symmetric encryption, Klen2 represents the bit length of the bit string K2, and K2 represents the key used to generate a message authentication code;
[0066] Let K1 be the first Klen1 bits of the derived key K, K1 represents the SM4 symmetric encryption key, and K2 be the following Klen2 bits. If K1 is all 0 bits, jump to step S2, otherwise go to step S6;
[0067] S6: User A calculates the encrypted intermediate value C2 and the message authentication code C3 using the following formula, and outputs the ciphertext CT = {C1||C3||C2, (C i ,D i ) i∈{1,...,L}};
[0068] C2=Enc(K1,SK);
[0069] C3=h(K2||C2);
[0070] C2 represents the second component of the ciphertext, C3 represents the third component of the ciphertext, Enc() represents the ECB mode encryption algorithm of SM4, where L represents the number of rows of the matrix MA in the access structure, that is, the attribute set of the access policy;
[0071] S7: User A outputs the ciphertext CT = {C1||C3||C2, (Ci ,D i ) i∈{1,...,L}} and the hash value M returned by IPFS h Package them together and upload them to the Fabric alliance blockchain for storage.
[0072] Preferably, the content of the ninth step is:
[0073] S1: User B submits a request to the Fabric consortium blockchain, and Fabric sends the ciphertext CT to user B;
[0074] S2: After receiving the ciphertext CT, user B uses the following formula to decrypt the access structure of the ciphertext and obtains the decryption result DecrypteMatrix(CT,SK U ):
[0075]
[0076] I represents the index set I={i:ρ(i)∈Attr B}, Attr B is the attribute set of user B;
[0077] S3: If and only if Attr B When the required properties in the access structure are satisfied, user B can find a set of constants {w i ∈Z p} i∈I So that Σ i∈I w i λ i =s, and continue to decrypt through S2, the results are:
[0078] DecrypteMatrix(CT,SK U )=e(P1,P2) ts ;
[0079] Among them, DecrypteMatrix represents one of the intermediate results obtained in the decryption stage;
[0080] Now calculate:
[0081]
[0082] ω * Indicates the second intermediate result obtained in the decryption stage;
[0083] S4: User B calculates K′=KDF(C1||ω *||GID,Klen1+Klen2), where K′ represents the third intermediate result obtained in the decryption stage, and the first Klen1 bits K′1 and the last Klen2 bits K′2 of K′ are taken. K′1 represents the decryption key obtained in the decryption stage, and K′2 represents the authentication key obtained in the decryption stage. If K′1 is all 0, the decryption system reports an error and exits, otherwise it enters S5;
[0084] S5: User B calculates SK′=Enc(K′1,C2) and C′3=h(K′2||C2), where SK′ is the decryption result and C′3 represents the message authentication code obtained during the decryption process. It is compared with C3. If C′3 is not equal to C3, the decryption system reports an error and exits, otherwise it outputs the decryption result SK′.
[0085] Preferably, the tenth step includes the following contents:
[0086] S1: User B sends M h To IPFS;
[0087] S2: IPFS receives the M sent by user B. h Query the corresponding CT f And CT f Sent to user B.
[0088] (III) Beneficial effects
[0089] Compared with the prior art, the present invention provides a blockchain access control method based on SM9 attribute-based encryption, which has the following beneficial effects:
[0090] 1. The blockchain access control method based on SM9 attribute-based encryption uses SM9 IBE as a building module to design an attribute-based access control scheme, realizes the national encryption of attribute-based encryption, and can effectively solve the problems existing in traditional access control and public key encryption systems.
[0091] 2. The blockchain access control method based on SM9 attribute-based encryption allows data owners to customize access policies for data as needed. Users whose attributes do not meet the access policies cannot access their own data, thereby achieving efficient one-to-many ciphertext sharing and fine-grained access control in a multi-user environment.
[0092] 3. The blockchain access control method based on SM9 attribute-based encryption uses the LSSS matrix optimized by the monotone spanning scheme as the access structure in the attribute base part, so that the access structure can have good versatility and the access strategy will not increase with the increase of the number of users, which is easy to manage.
[0093] 4. The blockchain access control method based on SM9 attribute-based encryption combines blockchain and IPFS technology on the basis of the attribute-based encryption scheme, so that user data cannot be tampered with and is auditable, realizing efficient and secure storage and access control of data, and ensuring the confidentiality and integrity of system data and the high response of system operation.
[0094] 5. The blockchain access control method based on SM9 attribute-based encryption combines blockchain and IPFS technology on the basis of the attribute-based encryption scheme, so that user data cannot be tampered with and is auditable, realizing efficient and secure storage and access control of data, and ensuring the confidentiality and integrity of system data and the high response of system operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0095] Figure 1 It is a schematic diagram of the process of the present invention;
[0096] Figure 2 This is a schematic diagram of the blockchain networking process;
[0097] Figure 3 Schematic diagram of user attribute private key and symmetric key generation;
[0098] Figure 4 Schematic diagram for file encryption;
[0099] Figure 5 A schematic diagram of the schematic process of building an access matrix for an access policy;
[0100] Figure 6 Schematic diagram of the file decryption process. DETAILED DESCRIPTION
[0101] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0102] See also Figure 1-6 , a blockchain access control method based on SM9 attribute-based encryption, comprising the following steps:
[0103] Step 1: Blockchain networking to register identities for users;
[0104] Step 2: Start IPFS and connect it to the public chain node;
[0105] Step 3: Initialize the system and obtain the system parameters required by the SM9-based attribute encryption method;
[0106] Step 4: Generate the system master key. The trusted center generates the system master private key MSK and generates the system master public key MPK based on the system parameters.
[0107] Step 5: Generate the user attribute private key and symmetric key. Based on the request of user B, the trusted center combines the system master private key MSK and user B's attribute set Attr B , user B's group identity GID and system parameters to generate the user attribute private key SK U And send it to user B; based on user A's request, the trusted center generates a symmetric key SK and sends it to user A;
[0108] Step 6: File encryption: User A uses the symmetric key SK to encrypt file M. f Perform SM4 ECB mode encryption and generate the ciphertext CT f Upload to IPFS for storage, IPFS returns the hash value M h To user B;
[0109] Step 7: Symmetric key encryption: User A encrypts the symmetric key SK with the system master public key MPK, the group identity GID of user B, and the system parameters, and uploads the generated ciphertext CT to the Fabric alliance blockchain for storage;
[0110] Step 8: Symmetric key decryption, user B uses the attribute private key SK U Decrypt the ciphertext CT in combination with the system parameters to obtain the decryption result SK′;
[0111] Step 9: File decryption, IPFS sends CT based on user B’s request f To user B, user B uses SK′ to f Decryption results in decryption result M′ f .
[0112] The practical application cases of the present invention are as follows:
[0113] Step 1: Blockchain Networking: Figure 2 As shown, it mainly configures the related services of the blockchain network.
[0114] Step 1.1: Use the host or server as a blockchain node to build a Hyperledger Fabric blockchain network and start running the BYFN sample network;
[0115] Step 1.2: Add new organizations to the BYFN sample network according to alliance needs, and generate MSP files and organization definition files;
[0116] Step 1.3: The authentication center CA node registers the identities of user A and user B through the blockchain node according to the administrator. The registered users can log in to the blockchain network.
[0117] Step 2: IPFS startup: Deploy IPFS on the host or server in step 1 and connect it to the public chain node.
[0118] Step 3, system initialization: This step is mainly used to generate the parameters required for the entire encryption system. The present invention is based on the improvement and optimization of the SM9 encryption algorithm, and the cryptographic function algorithms used are all commercial cryptographic algorithms, so the same system parameters are used as SM9. The groups G1 and G2 used in this patent are both additive cyclic groups, and group G T is a multiplicative cyclic group, p represents the cyclic group G1, G2, G T The order, Z p represents the finite field modulo the prime number p, P1 represents the generator of the group G1, and P2 represents the generator of the group G2.
[0119] Step 4: Generate system master key: The trusted center generates the system master public key MPK and the system master private key MSK, where the system master public key MPK is made public by the trusted center, and the system master private key MSK is kept secret by the trusted center.
[0120] The specific process is as follows:
[0121] Step 4.1: The trusted center randomly generates α, a∈Z p , and let MSK = α||a, as the system master private key;
[0122] Step 4.2: The trusted center calculates the system master public key MPK according to the component α, a of the selected master private key through the formula MPK = {α·P1,a·P2};
[0123] Wherein, α and a are both components of the system master private key; let PK1 = α·P1 represent one of the components of the system master public key, and let PK2 = a·P2 represent the second component of the system master public key;
[0124] Step 5: Generate user attribute private key and symmetric key: This step is divided into obtaining user B's attribute private key and user A's symmetric key.
[0125] like Figure 3 As shown, the specific process is as follows:
[0126] Step 5.1: Obtain the attribute private key of user B;
[0127] Step 5.1.1: User B sends his group identity GID to the trusted center and requests the attribute private key;
[0128] Step 5.1.2: After receiving the request from user B, the trusted center verifies the validity of the GID and whether user B is in the group GID; if the verification is successful, the trusted center selects a random number t∈Z for user B p , and combined with the generated system master private key MSK = α||a, user B's attribute set Attr B , User B's group identity GID calculates part of User B's attribute private key:
[0129]
[0130] sk2=(t·a -1 )·P1
[0131] Wherein, sk1 represents one of the components of the attribute private key of user B, sk2 represents the second component of the attribute private key of user B, H1 represents the cryptographic function derived from the secure cryptographic hash function, hid represents the encryption private key generation function identifier, hid=3;
[0132] Step 5.1.3: For the attribute set Attr B For each attribute x in , the following formula is used as another part of the attribute private key of user B:
[0133] sk x =(t·a -1 )·h(x)
[0134] Among them, a -1 represents the inverse of a under modulus p, and h() represents the secure SM3 hash algorithm;
[0135] Step 5.1.4: The trusted center generates the attribute private key of user B And send it to user B through a secure channel;
[0136] Step 5.1.5: User B accepts and secretly saves the attribute private key SK sent by the trusted center U .
[0137] Step 5.2: Based on user A’s request, the trusted center generates a symmetric key SK and sends it to user A.
[0138] Step 6, file encryption: User A encrypts the file with the symmetric key SK and uploads the ciphertext to IPFS for storage. The present invention stores the ciphertext of the file on IPFS instead of directly on the blockchain, which can save a lot of storage overhead and communication overhead caused by the synchronization of blocks in the blockchain and improve storage efficiency.
[0139] like Figure 4 As shown, the specific process is as follows:
[0140] Step 6.1: User A calculates the file M by combining the symmetric key SK through the following equation f Ciphertext CT f :
[0141] CT f =Enc(SK,M f )
[0142] Wherein, Enc() represents the ECB mode encryption algorithm of SM4;
[0143] Step 6.2: User A sends CT f Upload to IPFS for storage;
[0144] Step 6.3: IPFS returns the hash value M h To user A.
[0145] Step 7, symmetric key encryption: This step is mainly used by user A to encrypt the symmetric key SK obtained in step 5.2 to generate the ciphertext CT. This encryption step is basically the same as the encryption process in the SM9 encryption algorithm, but the attribute-based encryption part with the matrix as the access structure is embedded in the ciphertext. The selection of a universal access matrix as the access structure is one of the main innovations of the present invention. Secondly, by encrypting the symmetric key, only the symmetric key can be decrypted to decrypt the file ciphertext on IPFS, which can ensure the confidentiality and integrity of the file ciphertext stored on IPFS, thereby ensuring the confidentiality and integrity of the file information. The specific process is as follows:
[0146] Step 7.1: User A sets a group identity GID for encryption. Assuming that user B is matched, the following calculation formula is used as the encryption intermediate value:
[0147] Q B =H1(GID||hid,p)·P1+PK1
[0148] Step 7.2: User A randomly selects s∈Z p , as shown in the following calculation formula:
[0149] C1=s·Q B
[0150] g=e(PK1,P2)
[0151] ω=g s =e(α·P1,P2) s =e(P1,P2) αs
[0152] Among them, C1 represents one of the components of the ciphertext, g represents the encrypted intermediate result, and e represents the number of steps from G1×G2 to G TBilinear pairings of ;
[0153] Step 7.3: Use the random number s selected by user A as the secret value to construct an access structure (MA, ρ); in the access structure, MA is an L×N matrix, and ρ represents the function that associates the rows of MA with the attributes. The schematic process of constructing the access matrix by the access policy is as follows: Figure 5 As shown in the example, the access policy is ((a,b,2), (c,d,1), e,2). Expand the attribute elements from left to right. (a,b,2) means that two attributes a and b must be satisfied, and (c,d,1) means that one attribute c and d must be satisfied. User A randomly selects vector And construct the vector vector and the i-th row M of the matrix MA i Satisfies the following equation:
[0154]
[0155] Among them, λ i Indicates the share of each attribute in the secret value;
[0156] Step 7.4: For each attribute i in the attribute encryption strategy, randomly select r i ∈Z p , and use the following formula to calculate the ciphertext part C of the attribute encryption i and D i :
[0157] C i =λ i PK2+(-r i )·h(i)
[0158] D i =r i P1
[0159] Among them, C i and D i Indicates the attribute components of the ciphertext, and h() represents the secure SM3 hash algorithm;
[0160] Step 7.5: User A calculates:
[0161] K=KDF(C1||ω||GID,Klen1+Klen2)
[0162] Wherein, K represents a derived key, KDF() represents a key derivation function used to generate a message encryption key and a message authentication key, GID represents the identity of the group to which user B belongs, Klen1 represents the bit length of the bit string K1, K1 represents the symmetric key used for ECB mode encryption of SM4, Klen2 represents the bit length of the bit string K2, and K2 represents the key used to generate a message authentication code;
[0163] Let K1 be the first Klen1 bits of the derived key K, K1 represents the SM4 symmetric encryption key, and K2 be the following Klen2 bits. If K1 is all 0 bits, jump to step h2, otherwise go to step 7.6;
[0164] Step 7.6: User A calculates the encryption intermediate value C2 and the message authentication code C3 through the following equation, and outputs the ciphertext CT = {C1||C3||C2, (C i ,D i ) i∈{1,...,L}};
[0165] C2=Enc(K1,SK)
[0166] C3=h(K2||C2)
[0167] Wherein, C2 represents the second component of the ciphertext, C3 represents the third component of the ciphertext, Enc() represents the ECB mode encryption algorithm of SM4, and L represents the number of rows of the matrix MA in the access structure, that is, the attribute set of the access policy;
[0168] Step 7.7: User A outputs the ciphertext CT = {C1||C3||C2,ω,(C i ,D i ) i∈{1,...,L}} and the hash value M returned by IPFS h Package them together and upload them to the Fabric alliance blockchain for storage.
[0169] Step 8, Symmetric key decryption: This step is mainly used by user B to decrypt the ciphertext CT stored on the blockchain and generate the decrypted symmetric key SK′. The specific decryption process is as follows:
[0170] Step 8.1: User B submits a request to the Fabric consortium blockchain, and Fabric sends the ciphertext CT to user B;
[0171] Step 8.2: After receiving the ciphertext CT, user B first uses the following equation to decrypt the access structure of the ciphertext and obtains the decryption result DecrypteMatrix(CT,SK U ):
[0172]
[0173] Where I represents the index set I = {i:ρ(i)∈Attr B}, Attr B is the attribute set of user B;
[0174] Step 8.3: If and only if Attr B When the required properties in the access structure are satisfied, user B can find a set of constants {w i ∈Z p} i∈I So that Σ i∈I w i λ i =s, continue decryption, the results are:
[0175] DecrypteMatrix(CT,SK U )=e(P1,P2) ts
[0176] Among them, DecrypteMatrix represents one of the intermediate results obtained in the decryption stage;
[0177] Now calculate:
[0178]
[0179] Among them, ω * Indicates the second intermediate result obtained in the decryption stage;
[0180] It can be proved that * Equal to ω, the proof process witnesses the following formula:
[0181]
[0182] Step 8.4: User B calculates K′=KDF(C1||ω * ||GID,Klen1+Klen2), where K′ represents the third intermediate result obtained in the decryption stage, the first Klen1 bits K1′ and the last Klen2 bits K′2 of K′ are taken, K1′ represents the decryption key obtained in the decryption stage, and K′2 represents the authentication key obtained in the decryption stage. If K1′ is all 0, the decryption system reports an error and exits, otherwise it goes to step 8.5;
[0183] Step 8.5: User B calculates SK′=Enc(K1′,C2) and C′3=h(K′2||C2), where SK′ is the decryption result and C′3 represents the message authentication code obtained during the decryption process. It is compared with C3. If C′3 is not equal to C3, the decryption system reports an error and exits, otherwise it outputs the decryption result SK′.
[0184] Step 9, file decryption: This stage is mainly used by user B to decrypt the file ciphertext CT stored on IPFS using the key SK′ obtained in step 8 f .
[0185] like Figure 6 As shown, the specific process is as follows:
[0186] Step 9.1: User B sends M h To IPFS;
[0187] Step 9.2: IPFS receives the M sent by user B. h Query the corresponding CT f And CT f Send to user B;
[0188] Step 9.3: User B calculates M′ based on SK′ f =Enc(SK′,CT f ), where M′ f The decrypted file result
[0189] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A blockchain access control method based on SM9 attribute-based encryption, characterized in that: The following steps are involved: Step 1: Blockchain networking, select multiple blockchain nodes to build the Fabric alliance blockchain network; Step 2: Deploy IPFS on the host or server to access the IPFS public chain node; Step 3: The trusted center initializes the system and obtains the system parameters required by the SM9-based attribute encryption method; Step 4: The trusted center generates the system master public key MPK published by the trusted center and the system master private key MSK secretly stored by the trusted center; Step 5: Based on the request of user B, the trusted center combines the system master private key MSK and user B's attribute set Attr B , user B's group identity G ID and system parameters to generate the user attribute private key SK U And send it to user B; Step 6: Based on user A’s request, the trusted center generates a symmetric key SK and sends it to user A; Step 7: User A uses the symmetric key SK to encrypt file M. f Perform SM4 ECB mode encryption and generate the ciphertext CT f Upload to IPFS for storage, IPFS returns the hash value M h To user A; Step 8: User A encrypts the symmetric key SK with the system master public key MPK, the group identity GID of user B and the system parameters and uploads the generated ciphertext CT to the Fabric alliance blockchain for storage; Step 9: Based on the request of user B, the Fabric alliance blockchain sends the ciphertext CT to user B, and user B uses the attribute private key SK U Decrypt the ciphertext CT in combination with the system parameters to obtain the decryption result SK′; Step 10: IPFS sends CT based on user B’s request f To user B; Step 11: User B uses SK′ to calculate CT f Decryption results in decryption result M′ f .
2. A blockchain access control method based on SM9 attribute-based encryption according to claim 1, characterized in that: The first step includes the following: S1: Use the host or server as a blockchain node to build a Hyperledger Fabric blockchain network and start running the BYFN sample network; S2: Add new organizations to the BYFN sample network according to alliance needs, and generate MSP files and organization definition files; S3: The authentication center CA node registers the identities of user A and user B according to the administrator through the blockchain node.
3. A blockchain access control method based on SM9 attribute-based encryption according to claim 2, characterized in that: The fourth step includes the following contents: S1: The trusted center randomly generates α, a∈Z p , and let MSK = α||a, as the system master private key, where α and a are both components of the system master private key, and p represents the group G1, G2, G T The order, Z p represents a finite field modulo a prime number p, G1 and G2 both represent additive cyclic groups, G T represents the multiplicative cyclic group, the groups G1, G2 and G T have the same order; S2: The trusted center calculates the system master public key MPK based on the components α and a of the selected master private key. MPK = {α·P1, a·P2}, and lets PK1 = α·P1 represent one of the components of the system master public key, and let PK2 = a·P2 represent the second component of the system master public key. P1 represents the generator of group G1, and P2 represents the generator of group G2.
4. A blockchain access control method based on SM9 attribute-based encryption according to claim 3, characterized in that: The fifth step includes the following contents: S1: User B sets a group identity GID and sends it to the trusted center to request the attribute private key; S2: Verify the validity of the GID and whether user B is in the group GID. If the verification is successful, the trusted center selects a random number t∈Z for user B. p , combined with the system master private key MSK = α||a, user B's attribute set Attr B , User B's group identity GID calculates part of User B's attribute private key: sk2=(t·a -1 )·P1; sk1 represents one of the components of the attribute private key of user B, sk2 represents the second component of the attribute private key of user B, H1 represents a cryptographic function derived from a secure cryptographic hash function, hid represents an encryption private key generation function identifier, hid=3; S3: For the attribute set Attr B For each attribute x in , the following formula is used as another part of the attribute private key of user B: en x =(t·a -1 )·h(x); a -1 represents the inverse of a modulo p, sk x It represents the third component of the attribute private key of user B, and h() represents the secure SM3 hash algorithm; S4: The trusted center generates the attribute private key of user B And send it to user B through a secure channel; S5: User B accepts and secretly saves the attribute private key SK U .
5. According to claim 4, a blockchain access control method based on SM9 attribute-based encryption is characterized in that: The seventh step includes the following contents: S1: User A calculates the file M using the following formula with the symmetric key SK f Ciphertext CT f : CT f =Enc(SK,M f ); Enc() represents the ECB mode encryption algorithm of SM4; S2: User A sends CT f Upload to IPFS for storage; S3: IPFS returns the hash value M h To user A.
6. A blockchain access control method based on SM9 attribute-based encryption according to claim 5, characterized in that: The specific content of the eighth step is: S1: User A sets a group identity GID for encryption. Assuming that when matching user B, the following is used as the encryption intermediate value: Q B =H1(GID||hid,p)·P1+PK1; S2: User A randomly selects s∈Z p , the calculation formula is as follows: C1=s·Q B ; g=e(PK1,P2); ω=g s =e(α·P1,P2) s =e(P1,P2) αs ; C1 represents one of the components of the ciphertext, g represents the encrypted intermediate result, and e represents the number of cells from G1×G2 to G T Bilinear pairings of ; S3: Use the random number s selected by user A as the secret value and construct an access structure (MA, ρ), where MA is an L×N matrix and ρ represents the function that associates the rows of MA with the attributes; User A randomly selects the vector And construct the vector vector and the i-th row M of the matrix MA i Satisfies the following formula: λ i Indicates the share of each attribute in the secret value; S4: For each attribute i in the attribute encryption strategy, randomly select r i ∈Z p , and use the following formula to calculate the ciphertext part C of the attribute encryption i and D i : C i =λ i ·PK2+(-r i )·h(i); D i =r i ·P1; C i and D i Indicates the attribute components of the ciphertext, and h() represents the secure SM3 hash algorithm; S5: User A calculates: K=KDF(C1||ω||GID,Klen1+Klen2); K represents a derived key, KDF() represents a key derivation function used to generate a message encryption key and a message authentication key, GID represents the group identity set by user A in step h1, Klen1 represents the bit length of the bit string K1, K1 represents the key used for SM4 symmetric encryption, Klen2 represents the bit length of the bit string K2, and K2 represents the key used to generate a message authentication code; Let K1 be the first Klen1 bits of the derived key K, K1 represents the SM4 symmetric encryption key, and K2 be the following Klen2 bits. If K1 is all 0 bits, jump to step S2, otherwise go to step S6; S6: User A calculates the encrypted intermediate value C2 and the message authentication code C3 using the following formula, and outputs the ciphertext CT = {C1||C3||C2, (C i ,D i ) i∈{1,...,L} }; C2=Enc(K1,SK); C3=h(K2||C2); C2 represents the second component of the ciphertext, C3 represents the third component of the ciphertext, Enc() represents the ECB mode encryption algorithm of SM4, where L represents the number of rows of the matrix MA in the access structure, that is, the attribute set of the access policy; S7: User A outputs the ciphertext CT = {C1||C3||C2, (C i ,D i ) i∈{1,...,L} } and the hash value M returned by IPFS h Package them together and upload them to the Fabric alliance blockchain for storage.
7. A blockchain access control method based on SM9 attribute-based encryption according to claim 6, characterized in that: The content of the ninth step is: S1: User B submits a request to the Fabric consortium blockchain, and Fabric sends the ciphertext CT to user B; S2: After receiving the ciphertext CT, user B uses the following formula to decrypt the access structure of the ciphertext and obtains the decryption result DecrypteMatrix(CT,SK U ): I represents the index set I={i:ρ(i)∈Attr B }, Attr B is the attribute set of user B; S3: If and only if Attr B When the required properties in the access structure are satisfied, user B can find a set of constants {w i ∈Z p } i∈I So that Σ i∈I w i λ i =s, and continue to decrypt through S2, the results are: DecrypteMatrix(CT,SK U )=e(P1,P2) ts ; Among them, DecrypteMatrix represents one of the intermediate results obtained in the decryption stage; Now calculate: ω * Indicates the second intermediate result obtained in the decryption stage; S4: User B calculates K′=KDF(C1||ω * ||GID,Klen1+Klen2), where K′ represents the third intermediate result obtained in the decryption stage, the first Klen1 bits K1′ and the last Klen2 bits K′2 of K′ are taken, K1′ represents the decryption key obtained in the decryption stage, and K′2 represents the authentication key obtained in the decryption stage; if K1′ is all 0, the decryption system reports an error and exits, otherwise it enters S5; S5: User B calculates SK′=Enc(K1′,C2) and C′3=h(K′2||C2), where SK′ is the decryption result and C′3 represents the message authentication code obtained during the decryption process. It is compared with C3. If C′3 is not equal to C3, the decryption system reports an error and exits, otherwise it outputs the decryption result SK′.
8. A blockchain access control method based on SM9 attribute-based encryption according to claim 7, characterized in that: The tenth step includes the following contents: S1: User B sends M h To IPFS; S2: IPFS receives the M sent by user B. h Query the corresponding CT f And CT f Sent to user B.
Citation Information
Patent Citations
Attribute-based encryption and block chain combined trusted data access control scheme
CN112836229A
Mail user identity authentication and key distribution method, system and device and medium
CN113067823A