Identity-based privacy protection blockchain data ownership management method

CN117294427BActive Publication Date: 2026-10-09BEIJING INST OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311193762.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-15
Publication Date
2026-10-09
Estimated Expiration
2043-09-15

AI Technical Summary

Technical Problem

[0005]本发明的目的是针对现有技术存在的问题和不足,为了解决基于数字身份的区块链应用场景中数据所有权治理混乱问题、频繁用户撤销和问责问题、用户策略隐私保护问题和大规模数据的数据所有权治理效率与计算开销问题等,创造性地提出一种基于身份的隐私保护区块链数据所有权治理方法

Benefits of technology

[0101] Compared with existing technologies, this method has the advantages of privacy-preserving data ownership governance (i.e., simultaneously governing data readability permissions and data editability permissions) and supporting user revocation and accountability. It also has significant advantages in terms of data ownership governance granularity, user revocation and accountability performance, user privacy protection level, user-side data processing efficiency, and method security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117294427B_ABST
    Figure CN117294427B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of identity-based privacy protection blockchain data ownership governance method, belong to the field of blockchain privacy protection technology.This method uses chameleon hash technology, identity-based encryption technology, proxy re-encryption technology and polynomial function technology, realizes the privacy protection of blockchain data ownership governance function.Facing the blockchain application scene based on digital identity, construct through the controllability of blockchain data editability based on chameleon hash technology, controllability of blockchain data readability based on identity-based encryption technology and polynomial function technology, based on proxy re-encryption technology, realize the privacy protection of blockchain data ownership governance method of user efficient revocation and accountability.This method has the functional advantages of privacy protection data ownership governance and support user revocation and accountability, has significant advantages in data ownership governance granularity, user revocation and accountability performance, user privacy protection degree, user end data processing efficiency and method security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an identity-based privacy-preserving blockchain data ownership governance method, belonging to the field of blockchain privacy protection technology. Background Technology

[0002] As a crucial component of the next generation of network information technology, blockchain holds significant strategic importance for promoting the high-quality and long-term stable development of the digital economy. To date, blockchain has spawned many promising applications based on digital identity, such as blockchain databases and metaverse. However, the transparency and immutability of blockchain present all blockchain applications with a common challenge—chaotic data ownership governance (users cannot control which users can read and edit data), which severely hinders the development of blockchain applications.

[0003] The transparency of blockchain allows all users, including unauthorized users, to publicly access data on the blockchain, leading to chaotic data readability governance. This chaotic readability governance further results in the violation of data confidentiality, posing a significant threat to user data security. Simultaneously, this chaotic readability governance also leads to frequent blockchain data breaches. The immutability of blockchain means that data cannot be edited once uploaded, resulting in chaotic data editability governance. From a user perspective, immutability limits users' ability to edit data, such as updating and deleting user data in the blockchain database. Furthermore, from an application perspective, immutability prevents the removal of malicious data in blockchain applications, severely impacting the blockchain application ecosystem.

[0004] Currently, several editable blockchains supporting editable data governance have been proposed. These methods combine chameleon hashing and attribute encryption to grant editing rights to authorized users in a controlled manner. However, these methods are attribute-based settings. Directly converting to identity-based settings (treating digital identity information as an attribute) could lead to the leakage of user policy information. It's important to note that user policy information includes user identity information; policy leakage means identity leakage. Furthermore, existing editable blockchains neglect blockchain data readability governance, leaving them vulnerable to data confidentiality breaches, data leaks, and misuse of user data by service providers. To simultaneously support readability and editability, a straightforward approach is to extend existing editable blockchain technology with identity-based blockchain readability technology, adding readability governance to editability governance. However, a simple combination cannot simultaneously guarantee backward compatibility of power (i.e., users with editing rights should also have readability rights) and user policy privacy (i.e., users' readability policies and editability policies). Furthermore, existing blockchain data ownership governance methods rarely consider the frequent user revocations and accountability for malicious user behavior in real-world applications, thus limiting their applicability. Therefore, designing an identity-based privacy-preserving blockchain data ownership governance method remains a pressing challenge in identity-based blockchain applications. Summary of the Invention

[0005] The purpose of this invention is to address the problems and shortcomings of existing technologies, and to creatively propose an identity-based privacy-preserving blockchain data ownership governance method to solve issues such as chaotic data ownership governance, frequent user revocation and accountability, user policy privacy protection, and data ownership governance efficiency and computational overhead in large-scale data in blockchain application scenarios based on digital identity.

[0006] This method, while comprehensively protecting user privacy (i.e., data privacy, identity privacy, and policy privacy), achieves data ownership governance (i.e., readability governance and editability governance) and efficient user revocation and accountability in blockchain applications, and strictly guarantees backward compatibility of data ownership. This invention supports both permissioned and permissionless blockchains.

[0007] The innovations of this method include: utilizing chameleon hashing, identity-based encryption, proxy re-encryption, and polynomial function techniques to achieve privacy-preserving blockchain data ownership governance. Specifically, for blockchain applications based on digital identity, a privacy-preserving blockchain data ownership governance method is constructed that controls the editability of blockchain data using chameleon hashing, controls the readability of blockchain data using identity encryption and polynomial function techniques, and enables efficient user revocation and accountability using proxy re-encryption.

[0008] First, users are categorized into multiple levels based on their identity and policies, including unauthorized users, readable users, and editable users. To flexibly and privacy-preservingly govern readable and editable permissions, an identity-based privacy-preserving blockchain data ownership governance method is proposed. This method utilizes polynomial function technology to overcome the bottleneck of traditional identity-based encryption techniques (i.e., policies only include one user), enabling policies to be applied to multiple users.

[0009] Optimized strategies are used to enrich editable blockchains based on chameleon hashes for comprehensive governance of rights. Furthermore, proxy re-encryption techniques are incorporated to support user accountability and revocation.

[0010] To achieve the above objectives, the present invention adopts the following technical solutions.

[0011] First, let's explain the relevant concepts.

[0012] Node: In identity-based blockchain applications (such as Metaverse), a node refers to a service provider within the application. Specifically, based on their roles and functions, nodes are further divided into service nodes and privileged nodes. Service nodes act as computing and storage service providers, requiring real-time online service to the system. Privileged nodes, acting as authoritative regulatory bodies or developers of the blockchain application, are responsible for system initialization and key generation for users. After completing these tasks, privileged nodes are offline.

[0013] Data Owner: Typically refers to an individual or organization that collects raw data and uploads encrypted data to the node.

[0014] Users are typically individuals or organizations. Based on their attributes and the data owner's policies, users are categorized into three roles: unauthorized users, readable users, and editable users. Any user can view the consistency between on-chain hashes and off-chain data in a blockchain application. Furthermore, unauthorized users cannot view data content, readable users can view but not edit data content, and editable users can both view and edit data content.

[0015] In this invention, privileged nodes, acting as regulators of the blockchain application, are fully trusted, while other service nodes are semi-trusted. Users and data owners are also semi-trusted. Considering that blockchain nodes in real-world applications are large service providers who are highly concerned about their social reputation, collusion between blockchain nodes and users is unlikely. However, users can collude to break backward compatibility of permissions. Therefore, this invention is resistant to choice-ciphertext attacks (IND-CCA) under the random oracle model and user collusion attacks.

[0016] An identity-based privacy-preserving blockchain data ownership governance method includes the following steps:

[0017] Step 1: System initialization.

[0018] Privileged nodes, based on a distributed key generation protocol, collaboratively generate a master key and public parameters, and distribute the public parameters to all legitimate user and service nodes. Privileged nodes linked by the distributed key protocol are considered a single entity.

[0019] Specifically, first, given the security parameter λ, privileged nodes are generated. As a bilinear mapping group, λ is a pre-set positive integer, and p represents a group of length 1. λ prime numbers, This represents a multiplicative cyclic group of order p. Let p denote the multiplicative cyclic group of order p, and g denote the multiplicative cyclic group. The generator, e, represents the relation. That is: 2 After performing bilinear operations on the elements, they are mapped to A certain element in.

[0020] Subsequently, the maximum number of elements in the system policy set is set to n, where n is a positive integer. For example, if n = 3, the policy set is {Alice, Bob, Cathy}. Afterward, the privileged node generates n+1 random numbers {r0, r1, ..., r...}. n}, {r0, r1, ..., r n} belongs to random numbers, Let p be the field of all numbers that are coprime to a prime number p and are less than p.

[0021] Based on the above random numbers {r0, r1, ..., r...} n Privileged nodes generate {R0, R1, ..., R}. n}, g is the multiplication cyclic group The generator; i represents the cycle index, with a value ranging from 1 to n.

[0022] Next, the privileged node initializes two hash functions: Where → represents a mapping relationship, {0, 1} * This represents a string consisting of 0s and 1s. Let p be the field of all numbers that are relatively prime to the prime number p. This represents the bilinear mapping group.

[0023] Finally, the privileged node generates the master public key. and the master private key Subsequently, the public key mpk was published to all user and service nodes, while the private key msk was kept private by the privileged node set.

[0024] Step 2: Key generation.

[0025] In blockchain applications, each user can choose a privileged node to register with and obtain a key based on their own preferences (such as geographical location, social reputation, etc.).

[0026] First, users will share their digital identity information. id Send to the privileged node, u id It is the user's digital identity information (such as the user's ID number within the Metaverse application, u id ={111111000000}). After receiving the user's digital identity information, the privileged node first generates a random number. As a user identifier, and a random number As a user's virtual identity account, ∈ represents the set "belongs to" operator, s id and v id Belonging to Random numbers.

[0027] Subsequently, the privileged node calculates the user key. sk represents the user key, i represents the circular index, and r represents the circular index. i This represents an element in the master private key.

[0028] Afterwards, the privileged node sends the user key sk to the user and the user identifier s. id and user virtual identity account v id The new user is sent to the service node. Finally, the privileged node stores the new user in the user list, in the format (u... id s id v id ), u id For users' real digital identity, s id Represents the user identifier, v id This refers to a user's virtual identity account.

[0029] When a user revocation and accountability case occurs, the service node and the privileged node cooperate to find the user's identifier locally and use the user list stored on the privileged node to implement the user revocation and accountability.

[0030] Step 3: Hash generation.

[0031] The data owner generates ciphertext and hash values ​​based on their own data and sends them to the service node.

[0032] Specifically, the data owner generates the data m that needs to be uploaded to the blockchain and the readability access policy P. r and editability access strategy P e Where data m is a string (e.g., "Hello"), and readability strategy P r For the set of user digital identities (e.g., P) that can read this data r ={Alice, Bob, Cathy}), Editability Strategy P e For the set of user identities that can edit this data, and satisfying the following conditions: Editable row strategy P e It is a readability strategy P r subsets of (e.g., P) e ={Alice, Bob}).

[0033] Regarding blockchain data readability, let's assume a readability strategy generated by the data owner. 1 represents the readability strategy P r The number of valid digital identities in the table, where i represents the number of valid identities in the table. i This represents a specific digital identity (e.g., {Alice}). To protect the number of valid digital identities in the policy set, the data owner generates n-1 virtual digital identities. n represents the maximum number of digital identities in the strategy set, I i Representing digital identity. Subsequently, merged. and Generate the final readability strategy Afterwards, the data owner generates three random numbers. And based on the readability strategy P r The generating polynomial function is as follows:

[0034]

[0035] Among them, f r (x) represents a polynomial function, and n represents the maximum number of digital identities in the strategy set, (α0, α1, ..., αn). n ) represents a polynomial function f r The coefficient of (x).

[0036] Based on polynomial coefficients (α0, α1, ..., α) n ), data owner calculation ( C3, C m The details are as follows:

[0037]

[0038]

[0039]

[0040]

[0041] Where (o1, o2, α) are random numbers generated by the data owner; H2[] represents the XOR operation; H2[] represents the hash function; g represents the group. The generator; e() represents the bilinear mapping operation.

[0042] Regarding the editability of blockchain data, let's assume an editability policy generated by the data owner. Where p represents the editability strategy P e The number of valid digital identities in the table, where i represents the number of valid identities in the table. i This represents a specific digital identity (e.g., {Alice}). To protect the number of valid digital identities in the policy set, the data owner generates np virtual digital identities. Where n represents the maximum number of digital identities in the strategy set, I i Represents digital identity. (Merge) and Generate the final editability strategy Finally, the data owner generates three random numbers. And based on the editability strategy P e The generating polynomial function is as follows:

[0043]

[0044] Among them, f e (x) denotes a polynomial function, where n represents the maximum number of digital identities in the strategy set, (β0, β1, ..., β). n ) represents a polynomial function f e The coefficient of (x).

[0045] Based on polynomial coefficients (β0, β1, ..., β) n The data owner generates a random number. Represents a chameleon hash trapdoor, and calculates ( C6, C7, C x )as follows:

[0046]

[0047]

[0048]

[0049] C7 = g x

[0050]

[0051] Where (o3, o4, β) are random numbers generated by the data owner. H2[] represents the XOR operation, H2[] represents the hash function, and g represents the group. The generator of , e() represents the bilinear mapping operation.

[0052] Subsequently, to ensure the integrity of blockchain data, the data owner generates a C... v as follows:

[0053] C v =H1[v id ||C 1,0 ||…||C 1,n ||C 2,0 ||…||C 2,n ||C3||C 4,0 ||…||C 4,n ||C 5,0 ||…||C 5,n ||C6||C7||C x The data owner generates a random number. The chameleon hash value h is calculated as follows:

[0054]

[0055] Among them, o h Representation domain The random number within, where x represents the chameleon hash trapdoor.

[0056] Finally, the data owner synthesizes the ciphertext set C as {v id C3, C m , C6, C7, C x C v}, and send (C, h, o h The hash value (C, h, o) is sent to the service node. The service node then uploads the chameleon hash value h to the blockchain and sends (C, h, o) to the service node. hIt is stored locally on the service node.

[0057] Step 4: Data validation.

[0058] Users in all blockchain applications can verify (C, h, o) h The validity of ). Specifically as follows:

[0059] First, the user utilizes C v The integrity of the ciphertext set C is verified as follows:

[0060]

[0061] Among them, {v id , C3, C m , C6, C7, C x C v} are all elements in the ciphertext set C; symbols This function checks if the values ​​on both sides of the equals sign are equal. If they are equal, it returns 1; otherwise, it returns 0.

[0062] If the above equation verification passes, the user continues to apply Chameleon Hash to verify the integrity of the blockchain data, as follows:

[0063]

[0064] Among them, C v h is an element in the ciphertext set C; h is the chameleon hash value on the blockchain; o h A random number corresponding to the chameleon hash value; g represents the group. generator; symbol This function checks if the values ​​on both sides of the equals sign are equal. If they are equal, it returns 1; otherwise, it returns 0.

[0065] If the above equation holds true, the verification result d v A value of 1 indicates (C, h, o) h ) Valid; if not, the verification result d v A value of 0 indicates (C, h, o) h ) invalid; where d v The result represents the verification result, which is a numerical value.

[0066] Step 5: Traps are generated.

[0067] Users generate a query trapdoor using their own keys and send it to the service node.

[0068] In the key generation stage of step 2, let the key obtained by the user be... First, the user generates a random number. Where t represents the field A random number is generated within the range. The user then calculates the trapdoor. as follows:

[0069] T1 = g t

[0070]

[0071] Where i represents the circular index; n represents the maximum number of digital identities in the strategy.

[0072] Subsequently, the trapdoor T is sent to the service node.

[0073] Step 6: Data matching.

[0074] The service node determines data permissions for the user based on the query trapdoor and returns the corresponding data to the user. Specifically:

[0075] Upon receiving the query trap submitted by the user, the service node first queries the user identifier s corresponding to that user locally. id If the query finds the user, it indicates that the user is a valid user; if it does not find the user, it indicates that the user has been deactivated.

[0076] Then, the service node first determines whether the user has readability permissions, as follows:

[0077]

[0078] in, C3 and the elements in the ciphertext generated for the data owner; T1 and Elements in a user-generated trapdoor; symbols This checks if the values ​​on both sides of the equals sign are equal. It returns 1 if they are equal, and 0 if they are not. If the equation is true, the user can read the data, and d is set. m =1, otherwise, set d m =0. d m It is a numerical value representing user permissions; if d m =1 is true, service node calculation s id This represents the user identifier, and 'i' represents the circular index.

[0079] Next, the service node further determines whether the user has editability permissions, as follows:

[0080]

[0081] in, C6 and the elements in the ciphertext generated for the data owner; T1 and Elements in a user-generated trapdoor; symbols This function checks if the values ​​on both sides of the equals sign are equal. It returns 1 if they are equal and 0 if they are not. If the equation is true, the user can modify the data. (Setting d...) m =2, and calculate s id This represents the user identifier, and 'i' represents the circular index.

[0082] Finally, if d m =1 indicates that the user has permission to read the data, and the service node returns... Give to the user; if d m =2 indicates that the user has both read and modify permissions for the data, and the service node returns... For users.

[0083] Step 7: Data Reading.

[0084] After retrieving the returned data from the service node, the readable user can decrypt the data using their own key. Specifically:

[0085] Suppose that the key obtained by the user from the privileged node during the key generation process is... Combine the data returned by the service node The user performed the calculation as follows:

[0086]

[0087] Where m represents the data owner's data; symbol represents the XOR operation; e represents the bilinear mapping calculation; H2 represents the hash function.

[0088] Step 8: Data editing.

[0089] After retrieving the returned data from the service node, the editable user can use their own key to edit the data. Specifically:

[0090] Suppose that the key obtained by the user from the privileged node during the key generation process is... Due to backward compatibility of power, editable users can read the data, that is, perform step 7, the data reading stage, to decrypt data m.

[0091] If a user wants to edit the data, this is combined with the data returned from the service node. Perform the following calculations:

[0092]

[0093] Where x represents the chameleon hash trapdoor generated by the data owner; symbol Represents the XOR operation; e represents bilinear mapping calculation; H2 represents the hash function; C x This represents an element in the encrypted data belonging to the data owner.

[0094] The user generates a new message m′, where m′ is a string (e.g., "World"). Then, combining this with the hash generation step in step 3, the user selects new random numbers o′1 and α', where o′1 and α' are the elements belonging to... The user generates a new C′ based on the data m′, the random number o′1, and α′. m as follows:

[0095]

[0096] Then, based on C in the original encrypted data of the data owner... m and C v The newly generated C′ m and C′ v Chameleon hash trap x, random number o returned by the service node h The user performs the following calculation process to generate the new C′. m Calculate the new random number o′ h :

[0097]

[0098] Subsequently, the user combined the hash generation step 3 to regenerate the encrypted data. and a new random number o′ h .

[0099] It is important to note that when editing data, users cannot modify C7 (where C7 = g) to ensure that the chameleon hash stored on the chain remains unchanged. x , where x represents a chameleon hash trapdoor.

[0100] Beneficial effects

[0101] Compared with existing technologies, this method has the advantages of privacy-preserving data ownership governance (i.e., simultaneously governing data readability permissions and data editability permissions) and supporting user revocation and accountability. It also has significant advantages in terms of data ownership governance granularity, user revocation and accountability performance, user privacy protection level, user-side data processing efficiency, and method security. Attached Figure Description

[0102] Figure 1 This is a schematic diagram illustrating the implementation of the method of the present invention. Detailed Implementation

[0103] The present invention will now be described in further detail with reference to the accompanying drawings.

[0104] like Figure 1 As shown, an identity-based privacy-preserving blockchain data ownership governance method includes the following steps:

[0105] Step 1: System Initialization. Privileged nodes collaborate based on the existing distributed key generation protocol to generate the master key and public parameters, and then distribute the public parameters to all legitimate user and service nodes. For simplicity, we will treat the privileged nodes linked by the distributed key protocol as a single entity.

[0106] Specifically, before the system officially goes into operation, privileged nodes are generated given a security parameter λ. As the bilinear mapping group used in the method of this invention; λ represents a pre-set positive integer; p represents a length of 1... λ prime numbers; This represents a multiplicative cyclic group of order p; G represents a multiplicative cyclic group of order p; g represents a multiplicative cyclic group. generator; e represents relation That is, 2 After performing bilinear operations on the elements, they are mapped to A certain element in.

[0107] Subsequently, the maximum number of elements in the system policy set is set to n, where n is a positive integer. For example, if n = 3, the policy set would be {Alice, Bob, Cathy}. Afterward, the privileged node generates n+1 random numbers {r0, r1, ..., r...}. n}. Where, {r0, r1, ..., r n} belongs to Random numbers; Let p be the field of all numbers that are coprime to a prime number p and are less than p.

[0108] Based on the above random numbers {r0, r1, ..., r...} n Privileged nodes generate {R0, R1, ..., R}. n}.in g is the multiplication cyclic group The generator; i represents the cycle index, with a value ranging from 1 to n.

[0109] Next, the privileged node initializes two hash functions, namely: and Where → represents a mapping relationship; {0, 1] * This represents a string consisting of 0s and 1s. The field consisting of all numbers relatively prime to the prime number p; This represents the bilinear mapping group.

[0110] Finally, the privileged node generates the master public key. and the master private key Subsequently, the master public key mpk was published to all user and service nodes, while the master private key msk was kept private by a set of privileged nodes. Here, mpk represents the master public key, and msk represents the master private key.

[0111] Step 2: Key Generation. In blockchain applications, each user can choose a privileged node to register with and obtain a key based on their own preferences (such as geographical location, social reputation, etc.).

[0112] If a user wants to join the system, they need to register and obtain a key from a privileged node using their digital identity before joining. The user will then share their digital identity information... id Send to the privileged node. Where u id It is the user's digital identity information, such as the user's ID number within the metaverse application, such as u id ={111111000000}. After receiving the user's digital identity information, the privileged node first generates a random number. As a user identifier and a random number As a user's virtual identity account. Where ∈ represents the set "belongs to" operator; s id and v id Belonging to Random numbers.

[0113] Subsequently, the privileged node calculates the user key. Where sk represents the user key; i represents the circular index; r i This represents an element in the master private key.

[0114] Finally, the privileged node sends the user key sk to the user and the user identifier s. id and user virtual identity account v id Send it to the service node. The privileged node then stores the new user in the user list, in the format (u... id s id v id ), where u id For users' real digital identity, s id Represents the user identifier, v id This represents a user's virtual identity account. In the event of user revocation or accountability, the service node and privileged node collaborate to locally locate the user's identifier and utilize the user list stored on the privileged node to achieve efficient user revocation and accountability.

[0115] Step 3: Hash Generation. The data owner generates ciphertext and hash values ​​based on their data and sends them to the service node. Details are as follows:

[0116] To achieve blockchain data ownership governance, data owners generate a ciphertext set and a chameleon hash value and upload them to the service node. Specifically, the data owner generates the data m that needs to be uploaded to the blockchain, and a readability access policy P. r and editability access strategy P e Where data m is a string, such as "Hello"; readability strategy P r For example, P is a collection of user digital identities that can read this data. r ={Alice, Bob, Cathy}; Editability strategy P e Let be the set of user identities that can edit this data, and satisfy the following conditions: Editable row strategy P e It is a readability strategy P r A subset of, for example, P e ={Alice, Bob}.

[0117] Specifically, regarding blockchain data readability, let's assume a readability strategy generated by the data owner. Where 1 represents the readability strategy P r The number of valid digital identities in the table; i indicates a loop through the table below; I i This represents a specific digital identity, such as {Alice}. Subsequently, to protect the number of valid digital identities in the policy set, the data owner generates (n-1) virtual digital identities. Where n represents the maximum number of digital identities in the strategy set, I i Representing digital identity. Subsequently, merged. and Generate the final readability strategy Next, the data owner generates three random numbers. And based on the readability strategy P r The generating polynomial function is as follows:

[0118]

[0119] Where f r (x) represents a polynomial function; n represents the maximum number of digital identities in the strategy set; (α0, α1, ..., α) n ) represents a polynomial function f r The coefficients of (x). Based on the polynomial coefficients (α0, α1, ..., α... n ), data owner calculation ( C3, C m )as follows:

[0120]

[0121]

[0122]

[0123]

[0124] Where (o1, o2, α) are random numbers generated by the data owner; H2[] represents the XOR operation; H2[] represents the hash function; g represents the group. The generator of ; e(,) denotes the bilinear mapping operation.

[0125] Regarding the editability of blockchain data, let's assume the editability policy is generated by the data owner. Where p represents the editability strategy P e The number of valid digital identities in the table; i indicates a loop through the table below; I i This represents a specific digital identity, such as {Alice}. Subsequently, to protect the number of valid digital identities in the policy set, the data owner generates (np) virtual digital identities. Where n represents the maximum number of digital identities in the strategy set, I i Representing digital identity. Subsequently, merged. and Generate the final editability strategy Next, the data owner generates three random numbers. And based on the editability strategy P e The generating polynomial function is as follows:

[0126]

[0127] Where f e (x) represents a polynomial function; n represents the maximum number of digital identities in the strategy set; (β0, β1, ..., β) n ) represents a polynomial function f e The coefficients of (x). Based on the polynomial coefficients (β0, β1, ..., β). n The data owner generates a random number. This represents a chameleon hash trapdoor, and calculates ( C6, C7, C x )as follows:

[0128]

[0129]

[0130]

[0131] C7 = g x

[0132]

[0133] Where (o3, o4, β) are random numbers generated by the data owner; H2[] represents the XOR operation; H2[] represents the hash function; g represents the group. The generator of ; e(,) denotes the bilinear mapping operation.

[0134] Subsequently, to ensure the integrity of blockchain data, the data owner generates a C... v as follows:

[0135] C v =H1[v id ||C 1,0 ||…||C 1,n ||C 2,0 ||…||C 2,n ||C3||C 4,0 ||…||C 4,n ||C 5,0 ||…||C 5,n ||C6||C7||C x ]

[0136] The data owner generates a random number. Then the chameleon hash value h is calculated as follows:

[0137]

[0138] Among them, o h Representation domain The random number within; h represents the chameleon hash value; x represents the chameleon hash trapdoor.

[0139] Finally, the data owner synthesizes the ciphertext set C as {v id , C3, C m , C6, C7, C x C v}, and send (C, h, o h The hash value (C, h, o) is sent to the service node. The service node then uploads the chameleon hash value h to the blockchain and sends (C, h, o) to the service node. h It is stored locally on the service node.

[0140] Step 4: Data Verification. Users across all blockchain applications can verify (C, h, o). h The validity of ) is determined. The specific calculation process is as follows:

[0141] First, the user utilizes C v The integrity of the ciphertext set C is verified as follows:

[0142]

[0143] Among them, {v id , C3, C m , C6, C7, C x C v} are all elements in the ciphertext set C; symbols This checks if the values ​​on both sides of the equals sign are equal. If they are equal, it returns 1; otherwise, it returns 0. Subsequently, if the above equation verification passes, the user continues to apply Chameleon Hash to verify the integrity of the blockchain data as follows:

[0144]

[0145] Among them, C v h is an element in the ciphertext set C; h is the chameleon hash value on the blockchain; o h A random number corresponding to the chameleon hash value; g represents the group. generator; symbol This function checks if the values ​​on both sides of the equals sign are equal. If they are equal, it returns 1; otherwise, it returns 0.

[0146] If the above equation holds true, the verification result d v A value of 1 indicates (C, h, o) h ) Valid. If not, the verification result d. v A value of 0 indicates (C, h, o) h Invalid. Where d v The result represents the verification result, which is a numerical value.

[0147] Step 5: Trapdoor Generation. The user generates a query trapdoor using their own key and sends it to the service node.

[0148] In step 2, the key generation process, assume the user obtains the key as follows: First, the user generates a random number. Where t represents the field A random number is generated within the range. The user then calculates the trapdoor. as follows:

[0149] T1 = g t

[0150]

[0151] Where i represents the cycle index; n represents the maximum number of digital identities in the strategy. Subsequently, the trapdoor T is sent to the service node.

[0152] Step 6: Data Matching. The service node determines the user's data permissions based on the query trapdoors and returns the data with the corresponding permissions to the user. The specific process is as follows:

[0153] Upon receiving the query trap submitted by the user, the service node first queries the user identifier s corresponding to that user locally. id Among them, s id This represents the user identifier. If the query finds the user, it indicates that the user is a valid user. If the query does not find the user, it indicates that the user has been revoked.

[0154] Next, the service node first determines whether the user has readability permissions as follows:

[0155]

[0156] in, C3 and the elements in the ciphertext generated for the data owner; T1 and Elements in a user-generated trapdoor; symbols This function checks if the values ​​on both sides of the equals sign are equal. It returns 1 if they are equal and 0 otherwise. If the equation is true, the user can read the data, and d is set. m =1. Otherwise, set d. m =0. Where, d m It is a numerical value representing user permissions. If d m =1 is true, service node calculation Among them, s id represents the user identifier; 'i' represents the loop index.

[0157] Next, the service node will determine whether the user has editability permissions as follows:

[0158]

[0159] in, C6 and the elements in the ciphertext generated for the data owner; T1 and Elements in a user-generated trapdoor; symbols This function checks if the values ​​on both sides of the equals sign are equal. It returns 1 if they are equal and 0 otherwise. If the equation is true, the user can modify the data, and d is set. m =2, and calculate Among them, s id represents the user identifier; 'i' represents the loop index.

[0160] Finally, if dm = 1, it indicates that the user has permission to read the data, and the service node returns... Give it to the user. If d m =2 indicates that the user has both read and modify permissions for the data, and the service node returns... For users.

[0161] Step 7: Data Reading. After receiving the returned data from the service node, the readable user decrypts the data using their own key. The specific calculation process is as follows:

[0162] Let the key obtained by the user from the privileged node in step 2, key generation, be... Subsequently, the data returned by the service node was combined. The user performed the calculation as follows:

[0163]

[0164] Where m represents the data owner's data; symbol represents the XOR operation; e represents the bilinear mapping calculation; H2 represents the hash function.

[0165] Step 8: Data Editing. After receiving the returned data from the service node, the editable user can use their own key to edit the data. The specific calculation process is as follows:

[0166] Assume the key obtained by the user from the privileged node in step 2, key generation, is... Due to the downward compatibility of the power, the editable user can read the data, that is, perform step 7, the data reading stage, to decrypt the data m.

[0167] If a user wants to edit the data, this is combined with the data returned from the service node. Perform the following calculations:

[0168]

[0169] Where x represents the chameleon hash trapdoor generated by the data owner; symbol Represents the XOR operation; e represents bilinear mapping calculation; H2 represents the hash function; C x This represents an element in the encrypted data belonging to the data owner.

[0170] The user generates a new message m′. Here, m′ is a string, for example, “World”. Then, in conjunction with the hash generation step 3, the user selects new random numbers o′1 and α'. Here, o′1 and α' are... The user generates a new C′ based on the data m′, the random number o′1, and α′. m as follows:

[0171]

[0172] Next, based on C in the original encrypted data of the data owner... m and C v The newly generated C′ m and C′ v Chameleon hash trap x, random number o returned by the service node h The user performs the following calculations to generate the new C′. m Calculate the new random number o′ h :

[0173]

[0174] Subsequently, the user regenerated the encrypted data using the hash generation step in step 3. and a new random number o′ h It's important to note that when editing data, users cannot modify C7 to ensure the on-chain chameleon hash remains unchanged. Here, C7 = g x ;x represents a chameleon hash trapdoor. Finally, the user uploads the newly generated data to the service node to replace the original data. It's important to note that in a blockchain system, multiple users may simultaneously upload data editing requests. This invention addresses this issue by having the service nodes reach a consensus on the data with the earliest timestamp.

Claims

1. An identity-based privacy-preserving blockchain data ownership governance method, characterized in that, Includes the following steps: Step 1: System initialization; Privileged nodes, based on a distributed key generation protocol, collaboratively generate master keys and public parameters, and distribute the public parameters to all legitimate user and service nodes; privileged nodes linked by the distributed key protocol are treated as a single entity. Step 2: Key Generation; In blockchain applications, each user can choose a privileged node to register with and obtain a key based on their own preferences; Step 3: Hash Generation; The data owner generates ciphertext and hash values ​​based on their data and sends them to the service node; The data owner generates the data m that needs to be uploaded to the blockchain and the readability access policy. and editable access strategy Where data m is a string, readability strategy Editability policy for a set of user digital identities that can read this data For the set of user identities that can edit this data, and satisfying the following conditions: That is, editable line strategy It is a readability strategy A subset of; Regarding blockchain data readability, let's assume a readability strategy generated by the data owner. ,l represents readability strategy The number of valid digital identities in the table, where i represents the number of cycles through the table below. Representing a specific digital identity; to protect the number of valid digital identities in the policy set, the data owner generates nl virtual digital identities. , where n represents the maximum number of numeric identities in the strategy set. Representing digital identity; subsequently, merged. and Generate the final readability strategy Afterwards, the data owner generates three random numbers ( ) And based on readability strategies The generating polynomial function is as follows: in, Let n represent a polynomial function, where n represents the maximum number of digital identities in the strategy set. , , , ) represents a polynomial function The coefficient; Based on polynomial coefficients ( , , , ), data owner calculation ( , , , ), as detailed below: in,( (A random number generated for the data owner) Represents the XOR operation; Represents a hash function; group Generators; This represents the bilinear mapping operation; Regarding the editability of blockchain data, let's assume an editability policy generated by the data owner. Where p represents the editability strategy The number of valid digital identities in the table, where i represents the number of cycles through the table below. This represents a specific digital identity; to protect the number of valid digital identities in the policy set, the data owner generates np virtual digital identities. Where n represents the maximum number of digital identities in the strategy set. Representing digital identity; merging and This generates the final editability strategy. Finally, the data owner generates three random numbers ( ) And based on editability strategy The generating polynomial function is as follows: in, Let n represent a polynomial function, where n represents the maximum number of digital identities in the strategy set. , , , ) represents a polynomial function The coefficient; Based on polynomial coefficients ( , , , The data owner generates a random number x. Represents a chameleon hash trapdoor, and calculates ( , , , , )as follows: in,( (A random number generated for the data owner) This represents the XOR operation. Represents a hash function. group generator, This represents the bilinear mapping operation; Subsequently, to ensure the integrity of blockchain data, the data owner generates... as follows: The data owner generates a random number. The chameleon hash value h is calculated as follows: in, Representation domain The random number within, x represents the chameleon hash trapdoor; Finally, the data owner synthesizes the ciphertext set C as { , , , , , , , , , }, and send (C, h, The service node sends the chameleon hash value h to the blockchain and sends (C, h, ...) to the service node; the service node will upload the chameleon hash value h to the blockchain and send (C, h, ...) to the service node. Stored locally on the service node; Step 4: Data Verification; Users in all blockchain applications can verify (C, h, The validity of ), where C is the ciphertext set, and h is the chameleon hash value on the blockchain, A random number corresponding to the chameleon hash value; Step 5: Trapdoor generation; The user generates a query trapdoor using their own key and sends it to the service node; Step 6: Data matching; The service node determines the data permissions for the user based on the query traps and returns the data with the corresponding permissions to the user; Step 7: Data Reading; After receiving the returned data from the service node, the readable user uses their own key to decrypt the data; Step 8: Data Editing; Users can edit the data using their own keys after receiving the returned data from the service node.

2. The identity-based privacy-preserving blockchain data ownership governance method as described in claim 1, characterized in that, In step 1, the security parameters are first given. Privileged node generation As a group of bilinear mappings, A positive integer pre-set by the system. Indicates length is prime numbers, Indicates the order is Multiplication cyclic group, Indicates the order is Multiplication cyclic group, Represents the multiplication cyclic group generator, Representing relations That is, 2 After performing bilinear operations on the elements, they are mapped to A certain element in; Subsequently, let the maximum number of elements in the system strategy set be n, where n is a positive integer; Privileged nodes generate n+1 random numbers , Belongs to random numbers, The field consisting of all numbers that are coprime to a prime number p and are less than p; Based on the above random numbers Privileged node generation , g is the multiplication cyclic group The generator, i, represents the circular index, and its value ranges from 1 to n; Next, the privileged node initializes two hash functions: , ;in, Indicates the mapping relationship. This represents a string consisting of 0s and 1s. Let p be the field of all numbers that are relatively prime to the prime number p. Denote the bilinear mapping group; Finally, the privileged node generates the master public key. and the master private key Master key The master key msk is made public to all users and service nodes, while the master key msk is kept private by a set of privileged nodes.

3. The identity-based privacy-preserving blockchain data ownership governance method as described in claim 1, characterized in that, In step 2, firstly, the user enters their digital identity information. Send to the privileged node. It is the user's digital identity information; After receiving the user's digital identity information, the privileged node first generates a random number. As a user identifier, and a random number As a user's virtual identity account. The "belongs to" operator represents a set. and Belongs to Random numbers; Subsequently, the privileged node calculates the user key. , Indicates the user key. Indicates a circular index. This represents an element in the master private key; Then, the privileged node will transfer the user key. Send to the user, including the user identifier and user virtual identity accounts The message is sent to the service node; finally, the privileged node stores the new user in the user list, in the following format: , For users' real digital identity, Represents the user identifier. This represents a user's virtual identity account; When a user revocation and accountability case occurs, the service node and the privileged node cooperate to find the user's identifier locally and use the user list stored on the privileged node to implement the user revocation and accountability.

4. The identity-based privacy-preserving blockchain data ownership governance method as described in claim 1, characterized in that, In step 4, firstly, the user utilizes... The integrity of the ciphertext set C is verified as follows: in,{ , , , , , , , , , } are all elements in the ciphertext set C; symbols This function checks if the values ​​on both sides of the equals sign are equal. If they are equal, it returns 1; otherwise, it returns 0. If the above equation verification passes, the user continues to apply Chameleon Hash to verify the integrity of the blockchain data, as follows: in, h represents the element in the ciphertext set C; h is the chameleon hash value on the blockchain; A random number corresponding to the chameleon hash value; group generator; symbol This function checks if the values ​​on both sides of the equals sign are equal. If they are equal, it returns 1; otherwise, it returns 0. If the above equation holds true, the verification result is... A value of 1 indicates (C, h, ) Valid; if not, verify the result. A value of 0 indicates (C, h, ) is invalid; among them, The result represents the verification result, which is a numerical value.

5. The identity-based privacy-preserving blockchain data ownership governance method as described in claim 1, characterized in that, In step 5, during the key generation stage, let's assume the user obtains the key as follows: First, the user generates a random number t. , where t represents the field A random number is generated within the loop; subsequently, the user calculates the trapdoor. as follows: Where i represents the loop index; n represents the maximum number of numeric identities in the strategy; Subsequently, the trapdoor T is sent to the service node.

6. The identity-based privacy-preserving blockchain data ownership governance method as described in claim 1, characterized in that, In step 6, upon receiving a query trap submitted by a user, the service node first queries the user identifier corresponding to that user locally. If the result is found, it means the user is a valid user; if the result is not found, it means the user has been deactivated. Then, the service node first determines whether the user has readability permissions, as follows: in, Elements in the ciphertext generated for the data owner; and Elements in a user-generated trapdoor; symbols This function checks if the values ​​on both sides of the equals sign are equal. It returns 1 if they are equal and 0 if they are not. If the equation is true, the user can read the data. Otherwise, set It is a numerical value representing user permissions. Establishment, service node computing , This represents the user identifier, and 'i' represents the loop index. Next, the service node further determines whether the user has editability permissions, as follows: in, Elements in the ciphertext generated for the data owner; and Elements in a user-generated trapdoor; symbols This function checks if the values ​​on both sides of the equals sign are equal. It returns 1 if they are equal and 0 if they are not. If the equation is true, the user can modify the data. (Settings) And calculate , This represents the user identifier, and 'i' represents the loop index. Finally, if This indicates that the user has permission to read the data, and the service node returns... Give to the user; if This indicates that the user has both read and modify permissions for the data, and the service node returns [the correct information]. For users.

7. The identity-based privacy-preserving blockchain data ownership governance method as described in claim 1, characterized in that, In step 7, suppose the key obtained by the user from the privileged node during the key generation process is... Combined with the data returned by the service node The user performed the calculation as follows: in, Data representing the data owner; symbols Represents the XOR operation; This represents the computation of a bilinear mapping; This represents a hash function.

8. The identity-based privacy-preserving blockchain data ownership governance method as described in claim 1, characterized in that, In step 8, let the key obtained by the user from the privileged node during the key generation process be... The data is editable and can be read by the user; If a user wants to edit data m, this is combined with the data returned from the service node. Perform the following calculations: in, This represents a chameleon hash trapdoor generated by the data owner; symbol Represents the XOR operation; This represents the computation of a bilinear mapping; Represents a hash function; This represents an element in the encrypted data belonging to the data owner. The user generates a new message , The data type is string; subsequently, in conjunction with the hash generation step in step 3, the user selects a new random number. and , and Belongs to Random numbers; user-based data random numbers and Generate new as follows: Then, based on the original encrypted data from the data owner... and Newly generated and Chameleon Hash Trapdoor The random number returned by the service node The user performs the following calculation process for the newly generated Calculate new random numbers : Subsequently, the user combined the hash generation to regenerate the encrypted data. , , , and new random numbers ; To ensure the chameleon hash stored on the blockchain remains unchanged during data editing, users cannot modify it. , , where x represents a chameleon hash trapdoor.