Data Security Sharing Method for Ground Simulation Device of Space Environment Based on Blockchain
By adopting a blockchain-based data security sharing method in the ground simulation device of the spatial environment, the difficulty of confirming rights and data security problems in the data sharing process are solved, and the secure and reliable sharing of data and fine-grained access control are realized.
Patent Information
- Application Number
- CN202310255904.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-16
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2043-03-16
AI Technical Summary
During the data sharing process, the ground simulation device of space environment has difficulties in confirming shared data rights and is easily illegally acquired by malicious nodes, which has led to the threat of data security and reliability.
The blockchain-based data security sharing method is adopted to realize data encryption, access policy definition and fine-grained access control through the synergy between attribute authoritative organizations, data owners, interstellar file system and blockchain Fabric.
Ensure the security and reliability of data during the sharing process, realize fine-grained access control of shared data, and prevent malicious nodes from illegally obtaining data.
Smart Images

Figure CN116318630B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of big data sharing, and relates to a method for secure sharing of data of a space environment ground simulation device, and particularly to a method for secure sharing of data of a space environment ground simulation device based on blockchain. Background Art
[0002] With the increasingly in-depth exploration of space by humans, it is urgent to conduct in-depth research on aspects such as the space environment effects of spacecraft materials, devices and their functional systems. The space environment ground simulation device (hereinafter referred to as "device") is a basic scientific research platform in the fields of space technology and space science, including a space comprehensive environment simulation and research system, a space magnetic environment simulation and research system, a space plasma environment simulation and research system, a numerical simulation and central monitoring system, construction projects and supporting public facilities, etc., which can provide important support for studying the interaction between the space environment and materials, devices and living organisms, and is of great significance for ensuring the smooth development of human space exploration activities, breaking through the limitations of single-factor ground simulation, and comprehensively understanding the effects and influences of comprehensive space environment factors on substances.
[0003] In order to give full play to the resource aggregation advantage of the device platform and open up a collection and distribution center for aerospace datasets. As a major scientific research platform in the aerospace field, it will be committed to opening up a collection and distribution center for scientific research data and research results in this field. On the premise of ensuring national security and protecting intellectual property rights, research and develop a method for secure sharing of device data, so that users have the right to apply for sharing of scientific research data and results, and realize the effective circulation of knowledge. Summary of the Invention
[0004] In order to solve the problems of difficult confirmation of rights for shared data, easy illegal acquisition by malicious nodes and resulting losses during the sharing of space environment ground simulation device data, the present invention provides a method for secure sharing of data of a space environment ground simulation device based on blockchain. This method can ensure the secure and reliable sharing of device data and perform fine-grained access control on the shared data.
[0005] The object of the present invention is achieved by the following technical solutions:
[0006] A role for secure sharing of data of a space environment ground simulation device based on blockchain includes an Attribute Authority AA, a Data Owner DO, the InterPlanetary File System IPFS, the blockchain Fabric, and a Data Requester / User DR, wherein:
[0007] The attribute authority AA is a fully trusted party that manages and maintains multiple attribute sets, follows protocol specifications to perform any assigned tasks and outputs correct results; is responsible for handling user registration, generating system parameters for each system user. Users interact with AA by calling the blockchain smart contract. AA sends the public key PK to the DO, sends the private key SK to the DR, and generates update keys UK j→w 、UK' j 、UK” j ;
[0008] The data owner DO is the data provider for data sharing. It encrypts the data to be shared using the AES symmetric encryption algorithm, encrypts the AES key using the blockchain-based attribute updatable attribute-based encryption algorithm, and uploads the result to IPFS; has the right to decide which DRs can access the data, defines an access structure according to the data access policy, and then encrypts the AES key under this structure using the system public key PK returned by AA
[0009] The InterPlanetary File System IPFS provides data storage and computing services, is responsible for updating the ciphertext related to the updated attributes, and stores the file storage address in the blockchain
[0010] The blockchain Fabric is responsible for providing user access rules, authenticating AA nodes, and realizing the interaction between DO and DR and AA by calling smart contracts
[0011] The data requester DR is the data request party. It downloads the ciphertext of the data to be requested in IPFS. When the DR is not in the revocation list set by the DO and its attribute set satisfies the access structure embedded in the given ciphertext, it decrypts to obtain the AES symmetric key, and then decrypts to obtain the data plaintext
[0012] A method for secure data sharing of a space environment ground simulation device based on blockchain using the above sharing roles includes the following steps
[0013] Step S101: The DO encrypts the data M to be shared using the AES symmetric encryption algorithm to obtain the ciphertext Eck(M). The symmetric encryption key used for AES encryption is called ck
[0014] Step S102: The DO formulates an access policy according to the characteristics of the data to be shared
[0015] Step S103: The DO requests the system public key {PK} from AA by calling the blockchain Fabric smart contract
[0016] Step S104: AA performs system initialization Setup(1k ,L) → (PK, MSK), generate the system public key PK and the system master private key MSK, and return the public key set {PK} to the DO;
[0017] Step S105: The DO encrypts the AES-encrypted symmetric encryption key ck using the blockchain-based attribute updatable attribute-based encryption algorithm Encrypt(PK, ck, τ, RL) → CT' according to the public key set {PK} returned by the AA, the access structure τ formulated by the DO, and the revoked user list RL, to obtain the AES symmetric key ciphertext CT';
[0018] Step S106: Combine the hash fingerprint H of the data M to be shared M , the AES encrypted ciphertext Eck(M), and the AES symmetric key ciphertext CT' into CT = {H M , Eck(M), CT'}, and save it in the IPFS system, and record the mapping relationship in the blockchain;
[0019] Step S107: In order to access the data M to be shared, the DR needs to send its own ID to the AA by calling the blockchain Fabric smart contract;
[0020] Step S108: The AA executes KeyGen(MSK, ID, S) → SK to generate the private key SK for the DR, and sends it to the DR by calling the blockchain Fabric smart contract;
[0021] Step S109: The DR finds the address of the data to be requested in the blockchain, and obtains the ciphertext CT in the IPFS system by addressing;
[0022] Step S110: The DR uses the attribute private key SK and executes the algorithm Decrypt(PK, CT', SK) → ck to obtain the AES-encrypted symmetric encryption key ck;
[0023] Step S111: The DR uses ck to decrypt the ciphertext CT to obtain the plaintext M.
[0024] Compared with the prior art, the present invention has the following advantages:
[0025] The present invention applies blockchain technology to data sharing, and effectively solves the problem of data right confirmation for data sharing between institutions through mechanisms such as distributed ledger and data privacy and security. In addition, the attribute-based encryption algorithm is used to achieve fine-grained access control for the shared data. Finally, considering the problem of user attribute update, the present invention proposes a blockchain-based attribute updatable attribute-based encryption algorithm and applies it to the space environment ground simulation device, which can provide a more secure and reliable data sharing solution for the space environment ground simulation device. Description of the Drawings
[0026] Figure 1 It is the data sharing service flow chart of the space environment ground simulation device;
[0027] Figure 2 It is the flow chart of the data security sharing method for the space environment ground simulation device based on blockchain;
[0028] Figure 3 It is the block data structure diagram;
[0029] Figure 4 It is the interaction structure diagram of the user with the blockchain and the attribute authority;
[0030] Figure 5 It is the interaction flow chart of the user with the blockchain and the attribute authority. Specific implementation manners
[0031] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings, but it is not limited thereto. Any modification or equivalent replacement of the technical solution of the present invention without departing from the spirit and scope of the technical solution of the present invention shall be covered by the protection scope of the present invention.
[0032] The present invention provides a data security sharing role for the space environment ground simulation device based on blockchain. The sharing role usually consists of 5 parts, namely Attribute Authority (AA), Data Owner (DO), InterPlanetary File System (IPFS), blockchain (Fabric), and Data Requester / User (DR). Among them: DO uses the AES symmetric encryption algorithm to encrypt the data to be shared, formulates the access policy for the data to be shared, encrypts the AES key using the blockchain-based attribute updatable attribute-based encryption algorithm, saves the data ciphertext and the AES key ciphertext into IPFS, and records the file address information and the information digest into the blockchain; DR accesses IPFS through the blockchain to obtain the ciphertext information. When its attributes meet the access policy formulated by DO, it calls the blockchain smart contract to request the private key from AA, decrypts the AES key ciphertext using the private key to obtain the AES key, and finally decrypts the data using the AES key.
[0033] In the present invention, the Attribute Authority (AA) is a fully trusted party that manages and maintains multiple attribute sets, and follows protocol specifications to perform any assigned tasks and output correct results. It is mainly responsible for handling user registration, generating system parameters for each system user. Users interact with the AA by calling the blockchain smart contract. The AA sends the public key PK to the DO, sends the private key SK to the DR, and generates update keys UK j→w , UK' j , UK” j .
[0034] In the present invention, the Data Owner (DO) is the data provider for data sharing. The data to be shared is encrypted by the AES symmetric encryption algorithm, and the AES key is encrypted by the blockchain-based attribute updatable attribute-based encryption algorithm. The result is uploaded to IPFS. It has the right to determine which DRs can access the data, defines an access structure according to the data access policy, and then encrypts the AES key under this structure according to the system public key PK returned by the AA
[0035] In the present invention, the InterPlanetary File System (IPFS) mainly provides services such as data storage and computing. It is also responsible for updating the ciphertext related to the updated attributes and storing the file storage address in the blockchain
[0036] In the present invention, the blockchain (Fabric) is mainly responsible for providing user access rules, authenticating AA nodes, and realizing the interaction between the DO and the DR and the AA by calling the smart contract
[0037] In the present invention, the Data Requester (DR) is the data requesting party. It downloads the ciphertext of the data to be requested in IPFS. When the DR is not in the revocation list set by the DO and its attribute set satisfies the access structure embedded in the given ciphertext, it can decrypt to obtain the AES symmetric key and then decrypt to obtain the data plaintext. In addition, the attributes of the DR may change at any time. The DR is divided into the updated data requester (UpdatedDR) and the data requester to be updated (Non-updatedDR). Updated users are those whose attributes (referred to as attributes to be updated) are updated by the AA to new attributes, and users to be updated are those marked with updated attributes but whose attributes have not been updated
[0038] In the present invention, the blockchain-based attribute updatable attribute-based encryption algorithm is mainly divided into 5 stages
[0039] Stage 1: System Initialization Setup(1 k,L) → (PK, MSK): The system initialization algorithm in the blockchain-based attribute-updatable attribute-based encryption algorithm accepts the security parameter k and the attribute domain L, and outputs the public key PK and the master secret key MSK;
[0040] Phase 2: Key Generation KeyGen(MSK, ID, S) → SK: When a user requests to join the system, the AA assigns an attribute set to the user according to the user's identity ID. The key generation algorithm in the blockchain-based attribute-updatable attribute-based encryption algorithm receives the master secret key MSK, the identity ID, and the attribute set S that describes the key, and outputs the key SK;
[0041] Phase 3: File Encryption Encrypt(PK, ck, τ, RL) → CT': To achieve high encryption efficiency, the DO first uses the symmetric encryption algorithm key ck to encrypt the given file. Then, it uses the file encryption algorithm in the blockchain-based attribute-updatable attribute-based encryption algorithm to encrypt the symmetric encryption algorithm key ck. It receives PK, the symmetric encryption algorithm key ck, the access policy τ, and the revocation user list RL, and outputs the ciphertext CT';
[0042] Phase 4: File Decryption Decrypt(PK, CT', SK) → ck: The system user first downloads the ciphertext from IPFS; if his key satisfies the access policy τ, he will obtain ck by running the file decryption algorithm in the blockchain-based attribute-updatable attribute-based encryption algorithm; the file decryption algorithm in the blockchain-based attribute-updatable attribute-based encryption algorithm receives PK, CT', and SK, and outputs ck; if SK matches the access policy τ, the user can recover the symmetric encryption algorithm key ck, otherwise the decryption fails;
[0043] Phase 5: Attribute Update: The user's attribute j is now updated by the AA to the new attribute w. The attribute update phase includes 4 steps: AA updates the key generation (UKeyGen), updates the user's updated key update (SKUpdate1), updates the non-updated user's key update (SKUpdate2), and updates the ciphertext (CTUpdate), where:
[0044] UKeyGen(PK, MSK, j, w) → (UK j→w , UK' j , UK” j ): The update key generation algorithm is run by the AA to update the user's attribute j to the attribute w. It receives PK, MSK, the attribute j, and w, and outputs 3 update keys UK j→w 、UK' j and UK” j ;
[0045] SKUpdate1(SK, UK j→w) → SK u : The key update algorithm SKUpdate1 is run by the updated user, which obtains the current key SK of the updated user and the update key UK j→w , and outputs a new key SK u ;
[0046] SKUpdate2(SK, UK' j ) → SK nu : The key update algorithm SKUpdate2 is run by the non-updated user, which receives the current key SK of the non-updated user and the update key UK' j , and outputs a new key SK nu ;
[0047] The ciphertext update algorithm CTUpdate is run by IPFS, which receives the ciphertext marked with the update attribute j and the update key UK” j , and outputs a new ciphertext
[0048] The present invention also provides a method for secure data sharing of a space environment ground simulation device based on blockchain, and the method includes the following steps:
[0049] Step S101: DO encrypts the data M to be shared using the AES symmetric encryption algorithm to obtain the ciphertext Eck(M), and the symmetric encryption key used for AES encryption is called ck;
[0050] Step S102: DO formulates an access policy according to the characteristics of the data to be shared;
[0051] Step S103: DO requests the system public key {PK} from AA by calling the blockchain Fabric smart contract;
[0052] Step S104: The attribute authority AA performs system initialization Setup(1 k , L) → (PK, MSK), generates the system public key and the system master private key, and returns the public key set {PK} to DO;
[0053] Step S105: DO encrypts the AES encryption symmetric encryption key ck using the blockchain-based attribute updatable attribute-based encryption algorithm Encrypt(PK, ck, τ, RL) → CT' according to the public key set {PK} returned by AA, the access structure τ formulated by DO, and the revoked user list RL, to obtain the AES symmetric key ciphertext CT';
[0054] Step S106: The hash fingerprint H of the data M M, the AES encrypted ciphertext Eck(M) and the AES symmetric key ciphertext CT’ are combined into CT = {H M , Eck(M), CT'}, and saved into the IPFS system, and the mapping relationship is recorded in the blockchain;
[0055] Step S107: To access the data M, DR needs to send its own ID to the attribute authority AA by calling the blockchain Fabric smart contract;
[0056] Step S108: The attribute authority AA executes KeyGen(MSK, ID, S) → SK to generate the private key SK for DR, and sends it to DR by calling the blockchain Fabric smart contract;
[0057] Step S109: DR finds the address of the data to be requested in the blockchain, and obtains the ciphertext CT in the IPFS system by addressing;
[0058] Step S110: DR uses the attribute private key SK and executes the algorithm Decrypt(PK, CT', SK) → ck to obtain the AES encrypted symmetric encryption key ck;
[0059] Step S111: DR uses ck to decrypt the ciphertext CT to obtain the plaintext M.
[0060] In the present invention, as Figure 3 shown, the block data of the blockchain in step S106 is divided into two parts: a block header and a block body, where: the block header contains the hash value of the previous block, the blockchain number, the timestamp, the Merkle root, the version number, etc., and the hash value of the current block, the random number; the block body, as the carrier for actually storing data, contains the file storage address, the hash fingerprint of the data M, and the DO information record; for each transaction record in the block, a corresponding hash value is generated through the hash algorithm, and then the unique Merkle root of the current block is generated according to the Merkle construction rule and recorded in the block header; multiple blocks are combined in chronological order of generation to form a chained structure that is connected before and after, and each block is given a hash identifier by using the hash algorithm to ensure that the block is not tampered with.
[0061] In the present invention, as Figure 4 shown, the blockchain Fabric described in step S107 and step S108 mainly includes 5 parts, namely Fabric-CA, abc-CA, CA-Chaincode, AA-Chaincode, and the remaining nodes, where:
[0062] The Fabric-CA is one of the service roles of the Hyperledger Fabric, and its purpose is to provide access rules for users in the consortium. When the DR joins the Hyperledger blockchain, it requests the Fabric-CA and will obtain the corresponding authentication certificate and personal public-private key {PK DR , SK DR}. In the future, when the DR accesses the blockchain, it needs to use the certificate and personal public-private key to access the blockchain;
[0063] The role of the abc-CA is to authenticate the nodes AA that join the decentralized attribute-based encryption scheme as attribute authorities. Only the AA that passes the abc-CA authentication and is recorded on the blockchain can be considered a trusted AA, and this blockchain provides a strong trust endorsement for the AA;
[0064] The CA-Chaincode is a smart contract that establishes a trust bridge between the DR and the AA and the abc-CA. If the DR needs to access the information of the corresponding AA, it can obtain it by calling the chain code CA-Chaincode; for the AA to act as an attribute authority, it needs to execute the work of Setup(1 k , L)→(PK, MSK), generate the public key PK of the system and the master private key MSK of the system, and after the execution is completed, it also calls the chain code CA-Chaincode to let the abc-CA sign and endorse itself;
[0065] The AA-Chaincode is the chain code for the DR to communicate with the attribute authority AA;
[0066] The remaining nodes, including peer, orderer, and Raft, are all nodes for data storage and consensus in the Hyperledger blockchain Fabric environment.
[0067] In the present invention, as Figure 5 shown, the specific process of the DR interacting with the attribute authority cluster AA through the blockchain Fabric described in steps S107 and S108 is as follows:
[0068] Step S201: If the DR wants to communicate with an AA in the AA set and let it generate an attribute private key SK for itself, it first needs to call the CA-Chaincode;
[0069] Step S202: The CA-Chaincode obtains the DR's request, forwards the request to the abc-CA, and records the content of the request on the blockchain as an operation trace;
[0070] Step S203: abc-CA determines whether AA is legal according to the AA table it maintains. If it is trustworthy, it signs the response to this request and writes it into the blockchain, and proceeds to step S204; otherwise, it proceeds to step S211;
[0071] Step S204: DR calls the chaincode to obtain information about AA;
[0072] Step S205: DR sends its own ID and attribute set S to AA-Chaincode, and specifies that AA performs the operation KeyGen(MSK, ID, S) → SK for itself to generate DR's attribute private key SK;
[0073] Step S206: After obtaining DR's request, AA-Chaincode calls the interface of the chaincode to communicate with Fabric-CA;
[0074] Step S207: Fabric-CA determines whether DR is legal? If DR is legal, it proceeds to step S208; otherwise, it proceeds to step S211;
[0075] Step S208: AA-Chaincode then sends the request to AA, allowing AA to execute the attribute private key pair generation method KeyGen(MSK, ID, S) → SK for DR;
[0076] Step S209: AA returns the generated private key SK. AA-Chaincode encrypts it with DR's public key PK DR to obtain the encrypted private key pair E(SK), and then signs E(SK) to get {Sign AA , E(SK)}, and writes it into the blockchain as an interaction trace;
[0077] Step S210: DR calls the chaincode AA-Chaincode to obtain the information {Sign AA , E(SK}. DR verifies the legality of the signature Sign AA , and then obtains the encrypted private key pair E(SK). DR decrypts it with its own private key SK DR to get SK;
[0078] Step S211: Reject the request and end the process.
[0079] Example:
[0080] In this embodiment, the space environment ground simulation device includes a numerical simulation and central monitoring system (referred to as the "numerical simulation and central control system"), and seven experimental (sub) systems, among which: the seven experimental (sub) systems are the comprehensive environment simulation sub-system (referred to as the "comprehensive sub-system"), the space life science sub-system (referred to as the "life sub-system"), the device ion irradiation sub-system (referred to as the "device sub-system"), the micro-mechanism analysis sub-system (referred to as the "micro sub-system"), the ion accelerator sub-system, the space magnetic environment simulation and research system (referred to as the "magnetic system"), and the space plasma environment simulation and research system (referred to as the "plasma system").
[0081] In this embodiment, the data sharing of the space environment ground simulation device can be divided into internal data sharing and external data sharing. As Figure 1 shown, the internal data sharing of the space environment ground simulation device mainly refers to the data sharing among the seven experimental (sub) systems. The person in charge of the experimental (sub) system submits their shared data, formulates corresponding access policies, encrypts the data, and then hands the ciphertext to the person in charge of the numerical simulation and central control system. The person in charge of the numerical simulation and central control system stores the data in the IPFS distributed storage node. In addition, there is an attribute management server in the numerical simulation and central control system, which is used to manage the attributes of each subject. When the person in charge of other experimental (sub) systems wants to obtain this data, they need to access the IPFS distributed storage node of the numerical simulation and central control system. Only when they meet the access policies can they decrypt the data to obtain the plaintext. In addition, in order to ensure the supervision of the shared data within the system, there is also a data sharing management department, which is used to monitor and manage the data shared by the data sharing system. The external data sharing of the space environment ground simulation device mainly refers to the sharing of the space environment ground simulation device with the achievement sharing users, among which: the achievement sharing users refer to the relevant data requesters of the space department, space companies, and scientific research institutes.
[0082] In this embodiment, the data security sharing roles of the space environment ground simulation device based on blockchain are composed of five parts, namely the Attribute Authority (AA), the Data Owner (DO), the InterPlanetary File System (IPFS), the Blockchain (Fabric), and the Data Requester / User (DR), among which:
[0083] The Attribute Authority (AA) is a fully trusted party that manages and maintains multiple attribute sets, and follows protocol specifications to perform any assigned tasks and output correct results; it is mainly responsible for handling user registration, generating system parameters for each system user. Users interact with the AA by calling the blockchain smart contract. The AA sends the public key PK to the DO, sends the private key SK to the DR, and generates update keys UK j→w , UK' j , UK” j ;
[0084] The Data Owner (DO) is the data provider for data sharing. It encrypts the data to be shared using the AES symmetric encryption algorithm, and encrypts the AES key using the blockchain-based attribute-updatable attribute-based encryption algorithm, and uploads the result to IPFS; it has the right to decide which DRs can access the data, defines an access structure according to the data access policy, and then encrypts the AES key under this structure according to the system public key PK returned by the AA;
[0085] The InterPlanetary File System (IPFS) mainly provides services such as data storage and computing. It is also responsible for updating the ciphertext related to the updated attributes and storing the file storage address in the blockchain;
[0086] The blockchain (Fabric) is mainly responsible for providing user access rules, authenticating AA nodes, and realizing the interaction between the DO and the DR and the AA by calling smart contracts;
[0087] The Data Requester (DR) is the data requesting party. It downloads the ciphertext of the data to be requested in IPFS. When the DR is not in the revocation list set by the DO and its attribute set satisfies the access structure embedded in the given ciphertext, it can decrypt to obtain the AES symmetric key and then decrypt to obtain the data plaintext; in addition, the attributes of the DR may change at any time. The DR is divided into the updated data requester (Updated DR) and the data requester to be updated (Non-updated DR); updated users are those whose attributes (referred to as attributes to be updated) are updated by the AA to new attributes, and users to be updated are those marked with updated attributes but whose attributes have not been updated yet.
[0088] In this embodiment, the Attribute Authority is located in the attribute management server of the numerical simulation central control system of the space environment ground simulation device; the Data Owner (DO) is the person in charge of sharing data for each experiment (sub-)system of the space environment ground simulation device; the nodes of the InterPlanetary File System (IPFS) are distributed in the data sharing database server of the numerical simulation central control system of the space environment ground simulation device.
[0089] In this embodiment, for the internal data sharing of the space environment ground simulation device, the DR is usually the person in charge who requests data for each experiment (sub-)system; for the external data sharing of the space environment ground simulation device, the DR is usually the user who shares the results.
[0090] As Figure 2 shown, the specific steps of the data security sharing method for the space environment ground simulation device based on blockchain are as follows:
[0091] S101: DO encrypt the data M to be shared using the AES symmetric encryption algorithm to obtain the ciphertext Eck(M), and the symmetric encryption key used for AES encryption is called ck;
[0092] S102: DO formulate an access policy according to the characteristics of the data to be shared;
[0093] In a specific embodiment, the access policy usually exists in the form of an access tree structure. The attributes of the access policy are divided into subject attributes and environmental attributes, which are as follows:
[0094] (1) Subject attributes: mainly refer to the user attributes of accessing the data, including the user's affiliated unit, department, title, and other user identity information;
[0095] (2) Environmental attributes: mainly refer to the time information of the user's access and the spatial information of the user's access. The time information can be mainly divided into on-the-job time, off-the-job time, working time, and non-working time; the spatial information mainly includes the visitor's IP address information, port information, MAC address information, etc.;
[0096] S103: DO request the system public key {PK} from AA by calling the blockchain Fabric smart contract;
[0097] S104: The attribute authority cluster AA performs system initialization Setup(1 k ,L)→(PK,MSK), generates the system public key and the system master private key, and returns the public key set {PK} to DO;
[0098] S105: DO encrypt the AES encrypted symmetric encryption key ck using the attribute encryption algorithm Encrypt(PK,ck,τ,RL)→CT' according to the public key set {PK} returned by AA, the access structure τ formulated by DO, and the revoked user list RL, to obtain the AES symmetric key ciphertext CT';
[0099] S106: Combine the hash fingerprint H of the data M M , the AES encrypted ciphertext Eck(M), and the AES symmetric key ciphertext CT' into CT = {H M,Eck(M), CT'}, and save it to the IPFS system, and record the mapping relationship in the blockchain;
[0100] S107: To access data M, DR needs to send its own ID to the attribute authority cluster AA by calling the blockchain Fabric smart contract;
[0101] S108: The attribute authority AA executes KeyGen(MSK, ID, S) → SK to generate the private key SK for DR, and sends it to DR by calling the blockchain Fabric smart contract;
[0102] S109: DR finds the address of the data to be requested in the blockchain and obtains the ciphertext CT in the IPFS system by addressing;
[0103] S110: DR uses the attribute private key SK and executes the algorithm Decrypt(PK, CT', SK) → ck to obtain the AES-encrypted symmetric encryption key ck;
[0104] S111: DR uses ck to decrypt the ciphertext CT to obtain the plaintext M.
Claims
1. A data security sharing role for a ground simulation device of the space environment based on blockchain, characterized in that the sharing role includes an Attribute Authority AA, a Data Owner DO, the InterPlanetary File System IPFS, blockchain Fabric, and a Data Requester / User DR, where: The attribute authority AA is a fully trusted party that manages and maintains multiple attribute sets, and follows protocol specifications to execute any assigned tasks and output correct results; it is responsible for handling user registration, generating system parameters for each system user, and users interact with AA by calling blockchain smart contracts. AA sends the public key PK to the DO, sends the private key SK to the DR, and generates update keys UK j→w , UK' j , UK” j ; The Data Owner DO is the data provider for data sharing. The data to be shared is encrypted by the AES symmetric encryption algorithm, and the AES key is encrypted by the blockchain-based attribute updatable attribute-based encryption algorithm, and the result is uploaded to IPFS; it has the right to determine which DRs can access the data, and defines an access structure according to the data access policy, and then encrypts the AES key according to the system public key PK returned by AA under this structure; The blockchain-based attribute updatable attribute-based encryption algorithm is divided into 5 stages: Phase 1: System Initialization Setup(1 k , L) → (PK, MSK): The system initialization algorithm in the blockchain-based attribute-updatable attribute-based encryption algorithm accepts the security parameter k and the attribute domain L, and outputs the public key PK and the master secret key MSK; Stage 2: Key Generation KeyGen(MSK, ID, S) → SK: When a user requests to join the system, AA assigns an attribute set to the user according to the user's identity ID. The key generation algorithm in the blockchain-based attribute updatable attribute-based encryption algorithm receives the master private key MSK, the identity ID, and the attribute set S describing the key, and outputs the key SK; Stage 3: File Encryption Encrypt(PK, ck, τ, RL) → CT': To achieve high encryption efficiency, DO first encrypts the given file with the symmetric encryption algorithm key ck, and then uses the file encryption algorithm in the blockchain-based attribute updatable attribute-based encryption algorithm to encrypt the symmetric encryption algorithm key ck, receives PK, the symmetric encryption algorithm key ck, the access policy τ, and the revoked user list RL, and outputs the ciphertext CT'; Stage 4: File Decryption Decrypt(PK, CT', SK) → ck: The system user first downloads the ciphertext from IPFS; if his key satisfies the access policy τ, he will obtain ck by running the file decryption algorithm in the blockchain-based attribute updatable attribute-based encryption algorithm; the file decryption algorithm in the blockchain-based attribute updatable attribute-based encryption algorithm receives PK, CT', and SK, and outputs ck; if SK matches the access policy τ, the user can recover the content key ck, otherwise the decryption fails; Stage 5: Attribute Update: The attribute j of the user is now updated by AA to the new attribute w, including 4 steps: AA updates the key generation UKeyGen, updates the user update key update SKUpdate1, updates the non-updated user update key update SKUpdate2, and updates the ciphertext CTUpdate, where: UKeyGen(PK, MSK, j, w) → (UK j→w , UK' j , UK” j ): The update key generation algorithm is run by AA, which updates the user's attribute j to attribute w. It receives PK, MSK, attribute j, and w, and outputs three update keys UK j→w , UK' j and UK” j ; SKUpdate1(SK,UK j→w )→SK u : The key update algorithm SKUpdate1 is run by the updated user, which obtains the current key SK and the updated key UK of the updated user j→w , and outputs a new key SK u ; SKUpdate2(SK, UK') j ) → SK nu : The key update algorithm SKUpdate2 is run by the unupdated user, which receives the current key SK of the unupdated user and the update key UK' j , and outputs a new key SK nu ; The ciphertext update algorithm CTUpdate is run by IPFS, which receives ciphertexts with update attribute j and update key UK” j tagged and outputs new ciphertexts The InterPlanetary File System IPFS provides data storage and computing services, is responsible for updating the ciphertext related to the updated attributes, and stores the file storage address in the blockchain; The blockchain Fabric is responsible for providing user access rules, authenticating AA nodes, and realizing the interaction between DO and DR and AA by calling smart contracts; The data requester DR is the data requesting party. It downloads the encrypted data ciphertext to be requested in IPFS according to the requirements. When the DR is not in the revocation list set by the DO and its attribute set satisfies the access structure embedded in the given ciphertext, it decrypts to obtain the AES symmetric key, and then decrypts to obtain the data plaintext.
2. The data security sharing role of the ground simulation device for the space environment based on the blockchain according to claim 1, characterized in that the DR is divided into the updated data requester UpdatedDR and the data requester to be updated Non-updatedDR.
3. A method for data security sharing of the ground simulation device for the space environment based on the blockchain using the sharing role described in any one of claims 1-2, characterized in that the method includes the following steps: Step S101: The DO encrypts the data M to be shared using the AES symmetric encryption algorithm to obtain the ciphertext Eck(M), and the symmetric encryption key used for AES encryption is called ck; Step S102: The DO formulates an access policy according to the characteristics of the data to be shared; Step S103: The DO requests the system public key {PK} from the AA by calling the blockchain Fabric smart contract; Step S104: AA performs system initialization Setup(1 k ,L) → (PK, MSK), generates the system public key PK and the system master private key MSK, and returns the public key set {PK} to the DO; Step S105: The DO encrypts the symmetric encryption key ck of the AES encryption using the blockchain-based attribute-updatable attribute-based encryption algorithm Encrypt(PK, ck, τ, RL) → CT' according to the public key set {PK} returned by the AA, the access structure τ formulated by the DO, and the revoked user list RL to obtain the AES symmetric key ciphertext CT'; Step S106: Combine the hash fingerprint H of the data M to be shared M , the AES encrypted ciphertext Eck(M), and the AES symmetric key ciphertext CT' into CT = {H M , Eck(M), CT'}, save it in the IPFS system, and record the mapping relationship in the blockchain; Step S107: In order to access the data M to be shared, the DR sends its own ID to the AA by calling the blockchain Fabric smart contract; Step S108: The AA executes KeyGen(MSK, ID, S) → SK to generate the private key SK for the DR and sends it to the DR by calling the blockchain Fabric smart contract; Step S109: The DR finds the address of the data to be requested in the blockchain and obtains the ciphertext CT in the IPFS system by addressing; Step S110: The DR uses the attribute private key SK to execute the algorithm Decrypt(PK, CT', SK) → ck to obtain the symmetric encryption key ck of the AES encryption; Step S111: The DR uses ck to decrypt the ciphertext CT to obtain the plaintext M.
4. The method for data security sharing of the ground simulation device for the space environment based on the blockchain according to claim 3, characterized in that In step S106, the block data of the blockchain is divided into two parts: a block header and a block body. Specifically: the block header contains the hash value of the previous block, the blockchain number, the timestamp, the Merkle root, the version number, as well as the hash value of the current block and the nonce; the block body, as the carrier for actual data storage, contains the file storage address, the hash fingerprint of data M, and the DO information record; for each transaction record in the block, a corresponding hash value is generated through the hash algorithm, and then the unique Merkle root of the current block is generated according to the Merkle construction rule and recorded in the block header; multiple blocks are combined in chronological order of generation to form a chained structure that connects front and back, and each block is given a hash identifier using the hash algorithm to ensure that the block cannot be tampered with.
5. The data security sharing method for the space environment ground simulation device based on blockchain according to claim 3, characterized in that in steps S107 and S108, the blockchain Fabric mainly includes five parts, namely Fabric-CA, abc-CA, CA-Chaincode, AA-Chaincode, and the remaining nodes. Specifically: The Fabric-CA is one of the service roles of Hyperledger Fabric, and its purpose is to provide access rules for users in the consortium. When the DR joins the Hyperledger blockchain, requesting the Fabric-CA will obtain the corresponding authentication certificate and the personal public and private key {PK DR , SK DR}. In the future, when the DR accesses the blockchain, it needs to use the authentication certificate and the personal public and private key to access the blockchain; the function of abc-CA is to authenticate the nodes AA that join the decentralized attribute-based encryption scheme as attribute authority institutions. Only the AA that passes the abc-CA authentication and is recorded on the blockchain can be considered a trusted AA; The CA-Chaincode is a smart contract that builds a trust bridge between the DR and the AA and the abc-CA. The DR needs to access the information of the corresponding AA and obtains it by calling the chaincode CA-Chaincode; as an attribute authority, the AA executes the work of Setup(1 k ,L)→(PK,MSK), generates the public key PK of the system and the system master private key MSK. After the execution is completed, it calls the chaincode CA-Chaincode to let the abc-CA sign and endorse for itself; the AA-Chaincode is the chaincode for DR to communicate with the attribute authority institution AA; the remaining nodes include peer, orderer, and Raft, which are all nodes for data storage and consensus in the Hyperledger blockchain Fabric environment.
6. The data security sharing method for the space environment ground simulation device based on blockchain according to claim 3, characterized in that in steps S107 and S108, the specific process of DR interacting with the attribute authority cluster AA through the blockchain Fabric is as follows: Step S201: When DR wants to communicate with an AA in the AA set and asks it to generate an attribute private key SK for itself, it first needs to call CA-Chaincode; Step S202: CA-Chaincode obtains DR's request, forwards the request to abc-CA, and records the content of the request on the blockchain as an operation trace; Step S203: abc-CA determines whether the AA is legal according to the AA table it maintains. If it is trusted, it signs the response to this request and writes it into the blockchain, and enters step S204. Otherwise, it enters step S211; Step S204: DR calls the chaincode to obtain the information of AA; Step S205: DR sends its own ID and attribute set S to AA-Chaincode, and specifies that AA performs the KeyGen(MSK, ID, S)→SK operation for itself to generate DR's attribute private key SK; Step S206: After obtaining DR's request, AA-Chaincode calls the interface of the chaincode to communicate with Fabric-CA; Step S207: Fabric-CA determines whether the DR is legal. If the DR is legal, proceed to step S208; otherwise, proceed to step S211. Step S208: AA-Chaincode sends the request to AA, and asks AA to execute the property private key generation method KeyGen(MSK, ID, S)→SK for the DR. Step S209: AA returns the generated private key SK, and AA-Chaincode uses the public key PK of DR DR to encrypt to obtain the encrypted private key pair E(SK), and then sign E(SK) to obtain {Sign AA , E(SK)}, and write it into the blockchain as an interaction trace; Step S210: DR calls chain code AA-Chaincode to obtain information {Sign AA , E(SK}, and DR verifies the legality of the signature Sign AA . After that, the encrypted private key pair E(SK) is obtained, and DR decrypts it with its own private key SK DR to obtain SK; Step S211: Reject the request and end the process.
Citation Information
Patent Citations
Cross-domain access control method and system based on block chain
CN115426136A
Private data cross-domain sharing method based on PURH-CP-ABE under block chain
CN115714669A