A Blockchain Data Sharing Method and System Based on Quantum Re-encryption
A two-layer quantum encryption method for zone blockchains addresses vulnerabilities to quantum computing, ensuring data confidentiality and reducing storage pressure while maintaining security and efficiency.
Patent Information
- Application Number
- CN202410162500.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-05
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-02-05
AI Technical Summary
Blockchain's cryptography technology cannot withstand quantum computing attacks, and data is open and transparent on the blockchain, resulting in security and storage cost issues.
The data is encrypted twice using quantum re-encryption technology, and the data is processed using quantum hash values and unitary matrices. The storage method of blockchain distributed application servers and distributed databases is combined to ensure data confidentiality and immutability.
Improve the security and efficiency of data sharing, resist quantum computing attacks, reduce the pressure on blockchain storage, and ensure data confidentiality and integrity.
Smart Images

Figure CN118074898B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of quantum encryption, and particularly relates to a blockchain data sharing method and system based on quantum re-encryption. Background Art
[0002] With the rapid development of information technology, data in all walks of life has grown explosively, and data has become an important resource. However, since data is usually stored by different departments or individuals, a large number of independent data sets are generated, which are prone to forming data islands, resulting in low data utilization. Data sharing can provide one's own data for others to use, fully realizing the value of data. Traditional data sharing models rely on third-party platforms, and data records are provided by third-party platforms, which cannot provide data tracking services for data owners, resulting in poor transparency and lack of security in data transactions. Although this method is easy to manage and maintain, the data stored on third-party platforms is easily tampered with and resold. Blockchain is a decentralized peer-to-peer network that provides a distributed storage and management method, with characteristics such as anti-tampering, traceability, and openness and transparency. Blockchain ensures the integrity and immutability of data on the chain through cryptography and consensus mechanisms. The data stored on the blockchain is jointly maintained by nodes in the network, and any operation on the data by a node will be recorded by the blockchain, realizing the whole-process traceability management of data. Blockchain provides a new idea for solving the problems existing in traditional data sharing models. Combining access control technology and data sharing mechanisms, blockchain data sharing solutions can solve the security problems existing in traditional sharing solutions. Quantum computing uses the quantum properties of qubits to perform calculations, which can accelerate specific types of calculations in some cases and is more secure. Quantum communication is based on quantum mechanics and can provide unconditional security for both communication parties.
[0003] Through the above analysis, the problems and defects existing in the prior art are as follows:
[0004] 1. The cryptographic technology used by blockchain cannot resist the attack of quantum computing, and the security of blockchain cannot be guaranteed in the face of quantum computing. The cryptographic technology used by blockchain, including public key cryptosystems and hash functions, is based on mathematical difficult problems and can resist the attack of classical computers, but these mathematical difficult problems can be solved by quantum computers. Therefore, blockchain based on these cryptographic technologies is not secure.
[0005] 2. The data on the blockchain is open and transparent, and any node participating in the blockchain network can access it. The transparency of the blockchain will bring the risk of data leakage. Authenticated users can all access and use the data stored on the blockchain, and the confidentiality of the data cannot be guaranteed.
[0006] 3. The expansion of data sharing scale leads to increased storage pressure on the chain and higher storage costs. Storing data directly on the blockchain will take up a lot of storage space, reducing sharing efficiency. Summary of the invention
[0007] In response to the problems existing in the prior art, the present invention provides a blockchain data sharing method and system based on quantum re-encryption.
[0008] The present invention is implemented as follows. The present invention encrypts the data twice, the first encryption by the data owner using his own private key and the re-encryption by the blockchain distributed application server using the re-encryption key, and stores the ciphertext data in the distributed database. In addition, the quantum hash value of the data is calculated and stored in the blockchain. The data owner uses the private key and the re-encryption key to calculate the decryption key and provides it to the data accessor to achieve data sharing. A blockchain data sharing scheme based on quantum re-encryption includes the following steps:
[0009] S1, the data owner selects the initial parameters of the quantum walk and uses a hash function based on controlled alternating quantum walks (CAQWs) to calculate the quantum hash value of the data;
[0010] S2, the data owner uses his own private key to encrypt the data, adds decoy particles to the ciphertext data to generate a mixed sequence, and sends the mixed sequence to the blockchain distributed application server;
[0011] S3, the blockchain distributed application server uses the re-encryption key and unitary matrix to re-encrypt the data, and returns the re-encryption key and unitary matrix to the data owner;
[0012] S4, the blockchain distributed application server calls the smart contract to associate the quantum hash value with the ciphertext data, uploads the ciphertext data to the distributed database, and uploads the quantum hash value to the blockchain;
[0013] S5, the data owner calculates the decryption key using the private key, the re-encryption key and the corresponding unitary matrix;
[0014] S6: The data accessor initiates a data access request, and the distributed application server provides the encrypted data and access authorization service, and the data owner provides the decryption key and initial parameters.
[0015] S7, the data accessor decrypts the data, calculates the quantum hash value of the obtained data, and verifies the data integrity.
[0016] Further, step S1 specifically includes the following sub-steps:
[0017] S11, the data owner selects the initial parameters (n, t, θ0, θ1, α, β) of the quantum walk, where θ0, θ1 ∈ (0, π / 2), |α| 2 +β 2 = 1, n represents the number of points in each direction of the two-dimensional space, and t represents the number of walking steps;
[0018] S12, represent the data as a binary sequence S0 = s1s2... s L , prepare the initial state |ψ0> = |0, 0>(α|0> + β|1>), and calculate the coin operators C0, C1 using θ0, θ1:
[0019]
[0020] S13, when s L = 0, |ψ0> is executed under the control of the evolution operator constructed by C0 , when s L = 1, |ψ0> is executed under the control of the evolution operator constructed by C1 , and the final state |ψ t > is obtained after walking t steps. Measure the quantum states at different positions to obtain the probability p at that position, and form an n×n probability matrix;
[0021] S14, perform amplification processing on each element in the probability matrix and take the modulus to obtain the final quantum hash value Hash data .
[0022] Furthermore, step S2 specifically includes the following sub-steps:
[0023] S21, the data owner prepares the quantum sequence S using the ground state encoding according to the initial sequence S0. When s L = 0, generate the quantum state |0>. When s L = 1, generate the quantum state |1>. The quantum state sequence S is represented as |s1>|s2>... |s L >;
[0024] S22, use the quantum random number generator (QRNG) to generate a random L-bit quantum key Randomly select L unitary matrices from {X, Y, Z, H, S, T}
[0025] S23, use K1 and to encrypt S to obtain the sequence S (1) , represented as where
[0026] S24, for S(1) Randomly add L decoy particles |0>, |1>, |+>, |-> to generate sequence S (1)′ , and transmit S (1)′ to the blockchain distributed application server;
[0027] Step S2 also includes performing a security detection on the quantum channel for communication between the data owner and the blockchain distributed application server, specifically:
[0028] After the blockchain distributed application server finishes receiving sequence S (1)′ transmitted by the data owner, the data owner announces the positions and corresponding measurement bases of all decoy particles;
[0029] The blockchain distributed application server measures all decoy state particles according to this measurement basis and announces the measurement results;
[0030] The data owner compares the initial state of the decoy state with the measurement results to determine whether the error probability exceeds a preset threshold; if so, restart the quantum channel protocol for communication between the data owner and the blockchain distributed application server; otherwise, determine that the quantum channel is secure.
[0031] Furthermore, step S3 specifically includes the following sub-steps:
[0032] S31, Use a quantum random number generator (QRNG) to generate a random L-bit quantum key Randomly select L unitary matrices from {X, Y, Z, H, S, T}
[0033] S32, Use K2 and to re-encrypt S (1) to obtain the ciphertext sequence S (2) , where
[0034] S33, First, encode {X, Y, Z, H, S, T}, and the encoding rules are specifically:
[0035] Encode the X gate as 000, the Y gate as 001, the Z gate as 010, the H gate as 011, the S gate as 100, and the T gate as 101. According to the encoding corresponding to the unitary matrix, encode it into sequence U2;
[0036] S34, According to the ground state encoding rules, encode K2 and U2 into quantum states |K2> and |U2>. The length of |K2> is L, and the length of |U2> is 3L;
[0037] S35. Randomly add L decoy particles |0>, |1>, |+>, |-> to |K2> to generate the sequence |K2>', and randomly insert 3L decoy particles |0>, |1>, |+>, |-> into |U2> to generate |U2>'. Send |K2>' and |U2>' to the data owner;
[0038] Step S3 also includes performing a security detection on the quantum channel for communication between the blockchain distributed application server and the data owner, specifically:
[0039] After the data owner receives the sequences |K2>' and |U2>' transmitted by the blockchain distributed application server, the blockchain distributed application server announces the positions of all decoy particles and the corresponding measurement bases;
[0040] The data owner measures all decoy particles according to the measurement bases and records the measurement results;
[0041] The blockchain distributed application server compares the initial states of the decoy particles with the measurement results to determine whether the error probability exceeds a preset threshold; if so, restart the quantum channel protocol for communication between the blockchain distributed application server and the data owner; otherwise, determine that the quantum channel is secure.
[0042] Furthermore, step S4 is specifically:
[0043] The blockchain distributed server receives the quantum ciphertext hash value Hash data , and associates Hash data with S (2) to generate a record file DataFile of the data, which is used to record the basic information of the data and subsequent access situations. Call the "data upload" smart contract to store Hash data on the blockchain and store S (2) in the distributed database.
[0044] Furthermore, step S5 is specifically:
[0045] S51. The data owner removes the decoy particles from |K2>' and |U2>', performs measurements, and recovers K2 and
[0046] S52. Calculate the decryption key U = (U1, U2,..., U K2, ) according to K1, L where
[0047] S53. Encode U1 to U i according to the above encoding rule of the unitary matrix to obtain the decryption key sequence U k .
[0048] S54, encode U into a quantum state |U k > according to the ground state encoding rule, and randomly insert 3L decoy particles |0>, |1>, |+>, |-> into |U k > to generate a sequence |U k >' k >';
[0049] Step S5 also includes performing a security detection on the quantum channel for communication between the data owner and the data accessor, specifically:
[0050] After the data accessor receives the sequence |U k >' transmitted by the data owner, the data accessor announces the positions and corresponding measurement bases of all decoy particles;
[0051] The data accessor measures all decoy particles according to the measurement bases and announces the measurement results;
[0052] The data owner compares the initial states of the decoy particles with the measurement results to determine whether the error probability exceeds a preset threshold; if so, restart the quantum channel protocol for communication between the data owner and the data accessor; otherwise, determine that the quantum channel is secure.
[0053] Furthermore, step S6 is specifically:
[0054] After the data accessor pays to purchase the data, the blockchain distributed application server provides the ciphertext data S (2) to him and generates a unique access credential Cert for him.
[0055] Furthermore, step S7 specifically includes the following sub-steps:
[0056] S71. Apply for the decryption key U from the data owner using Cert;
[0057] S72. Decrypt S (2) using U to obtain S', S' = |s'1>|s'2>...|s' L >, where
[0058]
[0059] S73. Measure S' to obtain S0', and use S0' and the initialization parameters (n, t, θ0, θ1, α, β) to control the quantum walk and calculate Hash data ', and determine whether Hash data ' is equal to Hash data . If they are equal, receive the data; if not, reject the data.
[0060] Another object of the present invention is to provide a blockchain data sharing system based on quantum re-encryption for implementing the above-mentioned blockchain data sharing method based on quantum re-encryption, including:
[0061] A data owner module, which provides data, shares its own data with other users in the network, encrypts the data and calculates a quantum hash value, and calculates and provides a decryption key;
[0062] A quantum hash value calculation module, which is used to calculate the quantum hash value of the data using a hash function based on controlled alternating quantum walks (CAQWs) according to the initial parameters of the quantum walk;
[0063] A mixed sequence generation module, which is used to add decoy particles to the ciphertext data to generate a mixed sequence and send the mixed sequence to the blockchain distributed application server;
[0064] A blockchain distributed application server, which is used to receive the ciphertext data and quantum hash value of the user, perform re-encryption, upload the re-encrypted ciphertext to the distributed database, and upload the quantum hash value to the blockchain; receive and process the data access request of the user, provide the re-encryption key to the data owner, and provide the ciphertext and access credentials to the data visitor;
[0065] A data visitor module, which pays to purchase the ciphertext data, decrypts the ciphertext data using the decryption key, and verifies the data integrity.
[0066] Another object of the present invention is to provide a computer device, which includes a memory and a processor. When a computer program stored in the memory is executed by the processor, the processor executes the steps of the above-mentioned blockchain data sharing method based on quantum re-encryption.
[0067] Another object of the present invention is to provide a computer-readable storage medium, which stores a computer program. When the computer program is executed by the processor, the processor executes the steps of the above-mentioned blockchain data sharing method based on quantum re-encryption.
[0068] Another object of the present invention is to provide an information data processing terminal, which is used to implement the above-mentioned blockchain data sharing system based on quantum re-encryption.
[0069] Combined with the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solutions to be protected by the present invention are:
[0070] First, the present invention utilizes blockchain technology to achieve data sharing among different users. Each user is both a data provider and a data visitor. By encrypting their own data and storing it in the blockchain network, it is provided for other users to use. Since the blockchain realizes decentralized management and sharing of data, it ensures the confidentiality, secrecy, and immutability of the data throughout the sharing process, overcoming the single-point failure problem and data tampering problem existing in the data sharing solution relying on a third-party platform.
[0071] The present invention uses quantum encryption technology to encrypt the data twice. The final decryption key is provided by the data owner. The calculation of the decryption key utilizes the characteristic that the operations of different unitary matrices on quantum states have an identity relationship. The encryption key cannot be obtained based on the decryption key, protecting the security of the key to a certain extent. The present invention realizes that other users can access their own data without providing the private key by the method of the data owner recalculating the decryption key.
[0072] The data owner of the present invention calculates the hash value of the data using a quantum hash function, improving the randomness and collision resistance of the hash value. In the existing data sharing solutions based on blockchain, classical hash functions are used in the blockchain to calculate the hash value of the data, and this hash value cannot resist the attack of quantum computing, so it is insecure in the face of quantum.
[0073] The diffusion speed of the quantum hash function of the present invention is faster, which means that a slight change in the input will also cause a huge change in the output hash value, enhancing the security and encryption strength of the hash value.
[0074] The present invention adopts a data storage method of on-chain and off-chain collaboration, reducing the storage pressure on the blockchain.
[0075] Second, the present invention uses a quantum hash function to calculate the hash value, which has stronger resistance to statistical analysis and birthday attacks. The quantum hash function based on controlled alternating quantum walks (CAQWs) will not have predictable collisions. When the shared data is different, the calculated hash values are also different, which ensures the one-to-one correspondence between the data and the hash values.
[0076] In the solution proposed by the present invention, the data owner performs the first encryption on the data. The quantum key generated by the quantum random number generator (QRNG) is more random. Different unitary operations are selected for the encryption of each quantum bit to improve the security of the encrypted data. Decoy examples are added to the encrypted ciphertext sequence to detect the security of the communication channel. Through security eavesdropping detection, it can be ensured that the blockchain distributed application server receives the correct ciphertext sequence.
[0077] The quantum state of the present invention can only be transmitted in a quantum channel. However, there may be various interferences and the presence of eavesdroppers in the quantum channel. To ensure the security of the transmitted message, further security detections will be performed on any quantum channel. Channel noise interference is inevitable, and security detections can reduce the interference of noise in the transmission channel.
[0078] Once the efficiency of the security eavesdropping detection exceeds the preset threshold, it is considered that there is an eavesdropper, and its interference has caused serious interference to the current data sharing. It is necessary to restart the execution of the protocol. After determining that it does not exceed the preset threshold, the data sharing in this solution can be carried out.
[0079] The blockchain distributed application server of the present invention performs secondary encryption on the ciphertext, and sends the re-encryption key and the unitary matrix to the data owner. Finally, the data owner calculates and provides the decryption key. By using the identity relationship of the unitary matrix to operate on the quantum state to calculate the decryption key, the decryption of the ciphertext data can be achieved without revealing the private key and the re-encryption key.
[0080] The present invention adopts a storage method that combines on-chain and off-chain. On the one hand, it reduces the storage pressure of the blockchain. On the other hand, it stores the ciphertext data in a distributed database instead of directly storing it in the blockchain, reducing the transparency of the data and ensuring that only users with access permissions can obtain the ciphertext data, decrypt it, and access the data. Although the data hash value on the blockchain is visible to all users, users cannot recover the plaintext through the hash value, ensuring the confidentiality of the shared data.
[0081] The decryption key of the present invention is calculated by the data owner and provided for use by the data visitors with access permissions. According to the different values of, the calculation method of U i is different. When is satisfied and the used unitary matrix satisfies the identity relationship, the decryption key can directly use the identity matrix. According to the final decryption key, the specific sub-keys used for the two encryptions cannot be obtained, realizing the decryption of the ciphertext data without revealing the private key.
[0082] The data visitors of the present invention use the decryption key to decrypt and access the data, rather than directly using the private key of the data owner, protecting the security of the data owner's private key. Use the decrypted data to calculate the quantum hash value again to verify the data integrity and ensure that the accessed data is correct.
[0083] Third, the expected benefits and commercial value after the transformation of the technical solution of the present invention are as follows: The present invention uses the quantum re-encryption method in the blockchain-based data sharing solution, which can effectively resist future quantum computing attacks and provide a higher level of security than traditional encryption. This is crucial for protecting sensitive information and data in the blockchain and can be used in fields such as finance, healthcare, and the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS
[0084] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0085] Figure 1 is a framework diagram of a blockchain data sharing method based on quantum re-encryption provided by an embodiment of the present invention;
[0086] Figure 2 is a flowchart of a blockchain data sharing method based on quantum re-encryption provided by an embodiment of the present invention;
[0087] Figure 3 is a quantum re-encryption circuit diagram provided by an embodiment of the present invention;
[0088] Figure 4 is a structural diagram of a blockchain data sharing system based on quantum re-encryption provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0089] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0090] In view of the problems existing in the prior art, the present invention provides a blockchain data sharing solution based on quantum re-encryption. The present invention will be described in detail below with reference to the drawings.
[0091] Two specific application embodiments of the embodiments of the present invention are as follows:
[0092] Embodiment 1: Medical data sharing
[0093] Data encryption and upload: A medical institution (data owner) collects the health information of patients and selects appropriate initial parameters for quantum walks. The quantum hash value of the data is calculated using a hash function based on controlled alternating quantum walks, and then the data is encrypted using the private key of the institution. After encryption, decoy particles are added to the ciphertext to generate a mixed sequence, and the sequence is sent to the blockchain distributed application server.
[0094] Data re-encryption and smart contracts: The blockchain distributed application server uses the re-encryption key and unitary matrix to re-encrypt the data and returns this information to the medical institution. Then, the quantum hash value is associated with the ciphertext data through the smart contract, and the ciphertext data is uploaded to the distributed database, and the quantum hash value is uploaded to the blockchain.
[0095] Data access and decryption: When another medical institution needs to access a patient's health information, it initiates a data access request to the blockchain. The blockchain distributed application server provides ciphertext data and access authorization services, while the original medical institution provides the decryption key and initial parameters. The receiving institution uses this information to decrypt the data and verify the integrity of the data by calculating the quantum hash value.
[0096] This embodiment ensures that patient data remains encrypted during transmission and sharing, and only authorized medical institutions can access and decrypt the data. Through quantum re-encryption technology and smart contracts, efficient and secure cross-institutional data sharing is achieved, promoting the integration and optimization of medical resources.
[0097] Example 2: Cross-border financial transactions
[0098] Transaction encryption and upload: When financial institution A (data owner) conducts cross-border transactions, it first uses quantum hash functions and its own private key to encrypt the transaction data and generate a mixed sequence. Then, the mixed sequence is sent to the blockchain server.
[0099] Data re-encryption and smart contract execution: The blockchain distributed application server re-encrypts the received data, uses smart contracts to record transaction information and related quantum hash values, and stores the re-encrypted data in a distributed database.
[0100] Transaction data access and verification: When financial institution B needs to obtain transaction information, it initiates an access request through the blockchain platform. The blockchain distributed application server provides encrypted transaction data and access authorization, and financial institution A provides the keys and parameters required for decryption. Financial institution B uses this information to decrypt the data and verify the integrity and authenticity of the transaction data through quantum hash values.
[0101] The present invention mainly improves the following problems and defects of the prior art and achieves significant technical progress:
[0102] Insufficient data privacy protection: In traditional blockchain systems, once data is uploaded to the blockchain, its data content may be accessed by any node on the network, which creates the risk of data privacy leakage.
[0103] Data security issues: Although blockchain is tamper-proof, data may still be at risk of interception and tampering during data transmission and sharing, especially during data decryption and re-encryption.
[0104] Efficiency and scalability issues: In traditional blockchain systems, all data sharing and transaction verification processes need to go through each node on the network, which will lead to inefficiency and poor scalability when the amount of data is large and the number of nodes is large.
[0105] In view of the problems existing in the prior art, the technical solution adopted by the present invention is:
[0106] Improved data privacy protection: By using quantum re-encryption technology, data remains encrypted during transmission, and only authorized data accessors can decrypt the data using the decryption key, thereby protecting the privacy of the data.
[0107] Enhanced data security: The introduction of quantum encryption technology, especially the hash function using quantum hashing and controlled alternating quantum walks, improves data security, making it difficult for unauthorized persons to decrypt data even if it is intercepted during transmission.
[0108] Improved efficiency and scalability: Through the re-encryption processing of blockchain distributed application servers and the automatic execution of smart contracts, data sharing and access control become more efficient and automated, thereby improving the overall efficiency and scalability of the system.
[0109] Ensured data integrity verification: After decrypting the data, data accessors can effectively verify the integrity of the data by calculating the quantum hash value and comparing it with the quantum hash value on the blockchain, ensuring that the data has not been tampered with during transmission and sharing.
[0110] like Figure 1 As shown in the figure, the data owner Alice encrypts the data, calculates the quantum hash value of the data, and transmits the initially encrypted ciphertext data and hash value to the Blockchain Distributed Application Server (BDAS). BDAS re-encrypts the ciphertext data and calls the smart contract to upload the ciphertext data and quantum hash value to the distributed database and blockchain respectively. Data accessor Bob initiates a data access request to BDAS based on the data keywords and hash values on the blockchain and pays the access fee. BDAS provides Bob with the ciphertext data and access credential Cert. Bob uses the access credential Cert to apply for the decryption key from Alice, uses the decrypted ciphertext to obtain the plaintext data for access, and verifies the authenticity of the plaintext data.
[0111] like Figure 2As shown, a blockchain data sharing scheme based on quantum re-encryption provided by an embodiment of the present invention includes the following steps S1 to S7:
[0112] S1. The data owner selects the initial parameters of the quantum walk and calculates the quantum hash value of the data using a hash function based on controlled alternating quantum walks (CAQWs);
[0113] In this embodiment, first, the data owner Alice selects the initialization parameters (n, t, θ0, θ1, α, β) of the quantum walk, where θ0, θ1 ∈ (0, π / 2) and are used to construct the coin example; |α| 2 +β 2 = 1, which are the coefficients of the initial quantum state; n represents the number of points in each direction of the two-dimensional space, and t represents the number of walking steps. Alice represents the data M to be shared as a binary sequence S0 = s1s2...s of length L L , and prepares the quantum initial state |ψ0> = |0, 0>(α|0> + β|1>) to perform the quantum walk. Alice calculates the coin operators C0, C1 using θ0, θ1:
[0114]
[0115] The coin operators C0, C1 are used to calculate the evolution operator where S x and S y are displacement operations, defined as:
[0116]
[0117] When s L = 0, |ψ0> is executed under the control of , and when s L = 1, |ψ0> is executed under the control of . After walking k steps, the final state |ψ k > is obtained.
[0118] |ψ k > = U(S0)|ψ0>
[0119] For example, if S0 = 1001, then
[0120]
[0121] After the quantum walk for t steps, the probability of finding the walker at (x, y) in the space is defined as
[0122]
[0123] If there are n points in each direction of the two-dimensional space, then there are n×n possible positions to walk to. Taking the probability value of each position as an element of the matrix, a probability distribution matrix P can be constructed.
[0124]
[0125] Magnify the elements in the probability matrix and take the modulus.
[0126]
[0127] Take the obtained binary string result as the quantum hash value H. M , and the length of the hash value is n×n×k.
[0128] S2. The data owner encrypts the data using their private key, adds decoy particles to the ciphertext data to generate a mixed sequence, and sends the mixed sequence to the blockchain distributed application server;
[0129] In this embodiment, step S2 specifically includes the following sub-steps:
[0130] S21. Alice represents the data M as a binary sequence S0 = s1s2...s of length L L , and encodes S0 into a quantum state sequence S using the ground state encoding. The encoding rule is specifically:
[0131] When s i = 0, then this bit is represented as |0>;
[0132] When s i = 1, then this bit is represented as |1>;
[0133] Finally, S = |s1>|s2>...|s L .
[0134] S22. Alice uses a quantum random number generator (QRNG) to generate a random L-bit key Randomly select L unitary matrices from {X, Y, Z, H, S, T}
[0135] S23. Use K1 and to encrypt S to obtain the ciphertext sequence S (1) , represented as where
[0136] S24. Add decoy particles |0>, |1>, |+>, |-> to S (1) to generate a mixed sequence S (1)′ , and send S(1)′ Transmitted to the blockchain distributed application server BDAS.
[0137] The present invention performs a security detection on the quantum channel between the data owner Alice and the blockchain distributed application server. When BDAS does not receive a certain qubit, it is necessary to request Alice to resend that qubit. The specific process is as follows:
[0138] When BDAS has received all the mixed sequences S transmitted by Alice (1)′ After that, Alice announces the positions of all decoy states and the corresponding measurement bases;
[0139] BDAS measures all decoy states according to the measurement bases announced by Alice and sends the measurement results to Alice;
[0140] Alice compares the initial state of the decoy state with the measurement result to determine whether the error probability exceeds a preset threshold; if so, restart the quantum channel protocol for communication between Alice and BDAS; otherwise, determine that the quantum channel is secure.
[0141] S3. The blockchain distributed application server uses the re-encryption key and the unitary matrix to perform re-encryption processing on the data and returns the re-encryption key and the unitary matrix to the data owner;
[0142] In this embodiment, step S3 specifically includes the following sub-steps:
[0143] S31. The blockchain distributed application server BDAS uses a quantum random number generator (QRNG) to generate a random L-bit quantum key Randomly select L unitary matrices from {X, Y, Z, H, S, T}
[0144] S32. BDAS uses K2 and To re-encrypt S (1) To obtain the ciphertext sequence S (2) , Where
[0145] S33. First, encode {X, Y, Z, H, S, T}, and the encoding rule is specifically:
[0146] Encode the X gate as 000, the Y gate as 001, the Z gate as 010, the H gate as 011, the S gate as 100, and the T gate as 101. According to the encoding corresponding to the unitary matrix, Encoded into the sequence U2;
[0147] S34. According to the ground state encoding rule, encode K2 and U2 into quantum states |K2> and |U2>. The length of |K2> is L, and the length of |U2> is 3L;
[0148] S35. Randomly add L decoy particles |0>, |1>, |+>, |-> to |K2> to generate sequence |K2>'. Randomly insert 3L decoy particles |0>, |1>, |+>, |-> into |U2> to generate |U2>', and send |K2>' and |U2>' to the data owner.
[0149] The present invention performs a security detection on the quantum channel between the blockchain distributed application server BDAS and the data owner Alice. When Alice does not receive a certain particle, she needs to request BDAS to resend that particle. The specific process is as follows:
[0150] After Alice receives |K2>' and |U2>' transmitted by BDAS, BDAS announces the positions of all decoy states and the corresponding measurement bases;
[0151] Alice measures all decoy states according to the measurement bases announced by BDAS and sends the measurement results to BDAS;
[0152] BDAS compares the initial state of the decoy state with the measurement results to determine whether the error probability exceeds a preset threshold; if so, restart the quantum channel protocol for communication between Alice and BDAS; otherwise, determine that the quantum channel is secure.
[0153] S4. The blockchain distributed application server invokes the smart contract to associate the quantum hash value and the ciphertext data, uploads the ciphertext data to the distributed database, and uploads the quantum hash value to the blockchain.
[0154] In this embodiment, step S4 is specifically as follows:
[0155] The blockchain distributed application server BDAS invokes the smart contract to associate the quantum hash value H M and the ciphertext data S (2) Record the file keyword, data owner, and upload time in the data file. Invoke the "data upload" smart contract to upload S (2) to the distributed database and upload H M to the blockchain.
[0156] S5. The data owner calculates the decryption key using the private key, re-encryption key, and the corresponding unitary matrix;
[0157] In this embodiment, step S5 specifically includes the following sub-steps:
[0158] S51. Alice removes the decoy particle from |K2>′, |U2>′, performs measurement, and recovers K2 and
[0159] Alice obtains K2 and U2. According to the encoding rules of Gray code, Alice can recover the unitary matrix used for re-encryption.
[0160] S52, according to K1, K2, Calculate the decryption key
[0161] U=(U1,U2,……U L )
[0162] in
[0163] when hour,
[0164] when hour,
[0165] when hour,
[0166] when When U i =I.
[0167] U i , The identity relationship between them is shown in Table 1.
[0168]
[0169]
[0170] S53, according to the above-mentioned unitary matrix encoding rule, i Encode and get the decryption key sequence U k ;
[0171] S54, according to the ground state encoding rule, U k Encoded into quantum state |U k >. in|U k > randomly insert 3L decoy particles |0>, |1>, |+>, |->, and generate the sequence |U k >′.
[0172] S6. The data accessor initiates a data access request, and the distributed application server provides the data accessor with encrypted data and access authorization services.
[0173] In this embodiment, step S6 is specifically as follows:
[0174] If data accessor Bob wants to access data M, he will initiate a data access application to the blockchain distributed application server BDAS and pay the access fee Fee. BDAS temporarily stores the access fee and generates an access certificate Cert for Bob. BDAS M Retrieve the ciphertext sequence S from the database (2) , access the credentials Cert and S (2) Send to Bob.
[0175] S7. The data accessor applies for the decryption key and initial parameters, decrypts the data, and calculates the quantum hash value of the obtained data to verify the integrity of the data;
[0176] In this embodiment, step S7 specifically includes the following sub-steps:
[0177] S71. Use Cert to apply for decryption key U from the data owner;
[0178] S72, use U to decrypt S (2) We get S′, S′=|s′1>|s′2>……|s′ L >, where
[0179]
[0180] The ciphertext sequence obtained by Bob is S (2) , decryption key U, use U to S (2) Decryption gives S′
[0181] S73, measure S' to get S0', use M' and initialization parameters (n, t, θ0, θ1, α, β) to control quantum walk, and calculate H' M . Determine H′ M Is it equal to H M , if they are equal, the data is accepted, if they are not equal, the data is rejected.
[0182] like Figure 4 As shown, the blockchain data sharing system based on quantum re-encryption provided by an embodiment of the present invention includes:
[0183] The data owner module provides data, shares its own data with other users in the network, encrypts data and calculates quantum hash values, calculates and provides decryption keys;
[0184] A quantum hash value calculation module, used for calculating the quantum hash value of data using a hash function based on controlled alternating quantum walks (CAQWs) according to initial parameters of the quantum walk;
[0185] The mixed sequence generation module is used to add decoy particles to the ciphertext data to generate a mixed sequence, and send the mixed sequence to the blockchain distributed application server;
[0186] The blockchain distributed application server is used to receive the user's ciphertext data and quantum hash value, perform re-encryption, upload the re-encrypted ciphertext to the distributed database, and upload the quantum hash value to the blockchain; receive and process the user's data access request, provide the re-encryption key to the data owner, and provide the ciphertext and access credentials to the data visitor;
[0187] The data visitor module pays to purchase the ciphertext data, decrypts the ciphertext data using the decryption key, and verifies the data integrity.
[0188] An application embodiment of the present invention provides a computer device. The computer device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the steps of the blockchain data sharing method based on quantum re-encryption.
[0189] An application embodiment of the present invention provides a computer-readable storage medium, storing a computer program, and when the computer program is executed by a processor, the processor executes the steps of the blockchain data sharing method based on quantum re-encryption.
[0190] An application embodiment of the present invention provides an information data processing terminal, and the information data processing terminal is used to implement a blockchain data sharing system based on quantum re-encryption.
[0191] Apply this solution to the sharing scenario of medical data. Define the data owner as DataOwner and the data visitor as DataVisitor. Suppose the plaintext data owned by DataOwer is S0 = 1001, and the initial parameters selected for executing CAWQs are
[0192] First, DataOwner prepares Execute CAQWs under the control of S0 to generate a quantum hash value
[0193] DataOwner prepares the quantum state S = |1001> = |1>|0>|0>|1> for S0 according to the ground state encoding. Since L = 4, suppose the private key K1 of DataOwner is 1110, and the selected unitary matrices are respectively The result of the first encryption is S (1) = H|1>Z|0>T|0>|1>, and insert 4 decoy particles into S (1) to form S (1)′ ;
[0194] The BDAS receives S (1)′ , and after correctly removing the decoy particles, S is obtained (1) . Let the re-encryption key of the BDAS be K2 = 1011, The BDAS re-encrypts S (1) The result obtained by re-encryption is S (2) = ZH|1>Z|0>XT|0>Y|1>. In this embodiment, S U = 010100000001. The BDAS provides the re-encryption key K2 and the unitary matrix sequence S to the DataOwner U ;
[0195] The DataOwner recovers the unitary matrix used for re-encryption from S U and calculates the decryption key U according to the decryption key calculation rule and Table 1;
[0196]
[0197] U = (XH, Z, SXT, Y).
[0198] The DataVisitor initiates an access request for the data S0 to the BDAS and pays the access fee. The BDAS provides the ciphertext data S (2) and the access authorization credential
[0199] After the DataVisitor obtains the access authorization, the DataOwner provides it with the decryption key U and the initial parameters The DataVisitor decrypts S (2) and the decryption result is
[0200] S' = XHZH|1>ZZ|0>SXTXT|0>YY|1> = |1001>
[0201] That is, S' = S. The DataVisitor can correctly access the data of the DataOwner
[0202] After detailed security analysis, the present invention can resist external attacks and internal attacks represented by man-in-the-middle attacks, and the key has security
[0203] The present invention can resist man-in-the-middle attacks. Since decoy particles are inserted each time quantum information is sent to detect eavesdropping, assuming that Eve randomly selects a measurement basis to measure the particles, the probability of obtaining the correct quantum bit is When the data length is L bits, the probability that Eve obtains the correct particle sequence is That is, her behavior will be discovered with a probability of. When L is large enough, the probability of discovering Eve's attack behavior approaches 1, and this scheme can resist man-in-the-middle attacks.
[0204] The present invention can resist attacks by data visitors. It is not feasible for a data visitor to infer the decryption key of other data based on the obtained decryption key. Since the keys used for each piece of data are different and are randomly generated, the data visitor cannot obtain the decryption key of unauthorized data by guessing.
[0205] The present invention can resist attacks on the blockchain distributed application server BDAS. Since the private key is securely stored by the data owner, BDAS cannot obtain the plaintext data from the ciphertext without knowing the private key. Based on the quantum hash value, BDAS also cannot obtain the inscription data. Since the CAQWs quantum hash function is irreversible and the initial quantum state is random, BDAS cannot speculate on the plaintext data from the quantum hash value without knowing the initial state.
[0206] All the keys involved in the present invention are secure. The private key of the data owner and the re-encryption key used by BDAS are true random sequences generated by a quantum random number generator, and the corresponding unitary matrices are also randomly selected. Without knowing the plaintext state, only through the ciphertext state, the specific value of the key cannot be speculated. The decryption key is calculated from the private key, the re-encryption key, and the corresponding unitary operation. According to the identity relationship of the unitary operation on the quantum state, the obtained decryption key has no direct corresponding relationship with the unitary operation used for encryption. The security of the decryption key is based on the security of the private key and the re-encryption key, so it is secure.
[0207] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated designed hardware. Those of ordinary skill in the art can understand that the above devices and methods can be implemented using computer-executable instructions and / or included in processor control code, for example, such code is provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and their modules of the present invention can be implemented by hardware circuits of programmable hardware devices such as very large scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, or can be implemented by a combination of the above hardware circuits and software such as firmware.
[0208] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be covered by the protection scope of the present invention.
Claims
1. A blockchain data sharing method based on quantum re-encryption, characterized in that, The following steps are involved: S1, the data owner selects the initial parameters of the quantum walk and uses the hash function based on the controlled alternating quantum walk to calculate the quantum hash value of the data; S2, the data owner uses his own private key to encrypt the data, adds decoy particles to the ciphertext data to generate a mixed sequence, and sends the mixed sequence to the blockchain distributed application server; S3, the blockchain distributed application server uses the re-encryption key and unitary matrix to re-encrypt the data, and returns the re-encryption key and unitary matrix to the data owner; S4, the blockchain distributed application server calls the smart contract to associate the quantum hash value with the ciphertext data, uploads the ciphertext data to the distributed database, and uploads the quantum hash value to the blockchain; S5, the data owner calculates the decryption key using the private key, the re-encryption key and the corresponding unitary matrix; S6: The data accessor initiates a data access request, and the distributed application server provides the encrypted data and access authorization service, and the data owner provides the decryption key and initial parameters. S7, the data accessor decrypts the data, calculates the quantum hash value of the obtained data, and verifies the data integrity; Step S1 specifically includes the following sub-steps: S11, the data owner selects the initial parameters of the quantum walk (n, t, θ0, θ1, α, β), where θ0, θ1 ∈ (0, π / t), |α| t + β t = 1, n represents the number of points in each direction of the two-dimensional space, and T represents the number of walking steps; S12, represent the data as a binary sequence s0 = S1S of length L t ……S l , prepare the initial state |ψ0> = |0, 0>(α|0> + β|1>), and use θ0, θ1 to calculate the coin operators C0, C1: S13, when s L = 0, |ψ0> is executed under the control of the evolution operator constructed by C0 , when s L = 1, |ψ0> is executed under the control of the evolution operator constructed by C1 . After walking t steps, the final state ψ t > is obtained. The quantum states at different positions are measured to obtain the probability p at that position, and an n×n probability matrix is formed; S14, perform amplification processing and modulo operation on each element in the probability matrix to obtain the final quantum hash value Hash data .
2. The blockchain data sharing method based on quantum re-encryption according to claim 1, characterized in that, Step S2 specifically includes the following sub-steps: S21, the data owner prepares a quantum sequence S using ground state encoding according to the initial sequence S0. When s L = 0, generate the quantum state |0>. When s L = 1, generate the quantum state |1>. The quantum state sequence S is represented as |s1>|s t >……|s L >; S22. Generate a random L-bit quantum key using a quantum random number generator (QRNG). Randomly select L unitary matrices from {X, Y, Z, H, S, T}. S23, use k1 and encrypt S to obtain sequence S (1) , denoted as where S24, for S (1) Randomly add L decoy particles |0>, |1>, |+>, |-> to generate sequence S (1)′ , and transmit S (1)′ to the blockchain distributed application server; Step S2 also includes security detection of the quantum channel between the data owner and the blockchain distributed application server, specifically: After the blockchain distributed application server finishes receiving the sequence S transmitted by the data owner (1)′ the data owner announces the positions of all decoy particles and the corresponding measurement bases; The blockchain distributed application server measures all decoy particles according to the measurement basis and publishes the measurement results; The data owner compares the initial state of the decoyed state with the measurement result to determine whether the error probability exceeds the preset threshold; if so, the quantum channel protocol for communication between the data owner and the blockchain distributed application server is restarted; otherwise, the quantum channel is judged to be secure.
3. The blockchain data sharing method based on quantum re-encryption according to claim 1, wherein Step S3 specifically includes the following sub-steps: S31, generate a random L-bit quantum key using a quantum random number generator Randomly select L unitary matrices from {X, Y, Z, H, S, T} S32, utilize K t and to re-encrypt S (1) to obtain the ciphertext sequence S (t) , where S33, first, encode {X, Y, Z, H, S, T}, and the encoding rules are as follows: Encode the X gate as 000, the Y gate as 001, the Z gate as 010, the H gate as 011, the S gate as 100, the T gate as 101, and according to the encoding corresponding to the unitary matrix, is encoded into the sequence U t ; S34. According to the ground state encoding rule, encode K t , U t into the quantum states |K t >, U t , |K t >. The length of |K t > is L, and the length of U t > is 3L; S35, randomly add L decoy particles 0, 1, +, -> in |K t > to generate sequence |K t >'. Randomly insert 3L decoy particles |0>, |1>, |+>, |-> in u t > to generate |U2'. Send |K t >' and |U t >' to the data owner; Step S3 also includes security detection of the quantum channel for communication between the blockchain distributed application server and the data owner, specifically: After the data owner receives the sequence |K t >' and U t ' transmitted by the blockchain distributed application server, the blockchain distributed application server announces the positions of all decoy particles and the corresponding measurement bases; The data owner measures all decoy particles according to the measurement basis and measures the results; The blockchain distributed application server compares the initial state of the decoy particle with the measurement result to determine whether the error probability exceeds a preset threshold; If so, restart the quantum channel protocol for the blockchain distributed application server to communicate with the data owner; otherwise, the quantum channel is judged to be secure.
4. The blockchain data sharing method based on quantum re-encryption according to claim 1, wherein Step S4 is specifically as follows: The blockchain distributed server receives the quantum ciphertext hash value Hash data , and associates Hash data with S (t) to generate a record file DataFile of the data, which is used to record the basic information of the data and subsequent access situations; call the "data upload" smart contract, store hash data to the blockchain, and store the S (t) value in the distributed database.
5. The blockchain data sharing method based on quantum re-encryption according to claim 1, characterized in that Step S5 is specifically as follows: S51, the data owner removes the decoy particles from K t ′, U t >', performs measurements, and recovers K t and S52, according to calculate the decryption key U = (U1, U t , …… U L ), where S53, encode U1 to U according to the encoding rule of the above unitary matrix i to obtain the decryption key sequence U k ; S54, encode U according to the ground state encoding rule k into the quantum state |U k >, randomly insert 3L decoy particles |0>, |1>, |+>, |-> into |U k > to generate the sequence |U k >' Step S5 also includes performing security detection on the quantum channel for communication between the data owner and the data accessor, specifically: After the data visitor finishes receiving the sequence |U k >' transmitted by the data owner, the data visitor announces the positions of all decoy particles and the corresponding measurement bases; The data accessor measures all decoy particles according to the measurement basis and measures the results; The data owner compares the initial state of the decoy particle with the measurement result to determine whether the error probability exceeds a preset threshold; if so, the quantum channel protocol for communication between the data owner and the data accessor is restarted; otherwise, the quantum channel is judged to be secure.
6. The blockchain data sharing method based on quantum re-encryption according to claim 1, wherein Step S6 is specifically as follows: After the data visitor pays to purchase the data, the blockchain distributed application server provides the ciphertext data S to the data visitor (t) , and generates a unique access credential Cert for him.
7. The blockchain data sharing method based on quantum re-encryption according to claim 1, wherein Step S7 specifically includes the following sub-steps: S71. Use Cert to apply for decryption key U from the data owner; S72. Decrypt S using U (t) to obtain S′, where S′ = |s′1>|s′ t >……|s′ L >, where S73. Measure S ′ to obtain S0′, and use S0′ and the initialization parameters (n, t, θ0, θ1, α, β) to control the quantum walk, and calculate Hash data ′, and determine whether Hash data ′ is equal to Hash data . If they are equal, accept the data; if not, reject the data.
8. A blockchain data sharing system based on quantum re-encryption for implementing the blockchain data sharing method based on quantum re-encryption as described in any one of claims 1 to 7, characterized in that include: The data owner module provides data, shares its own data with other users in the network, encrypts the data and calculates the quantum hash value, and calculates and provides the decryption key. The quantum hash value calculation module is used to calculate the quantum hash value of the data by using the hash function based on the controlled alternating quantum walk according to the initial parameters of the quantum walk. The mixed sequence generation module is used to add decoy particles to the ciphertext data to generate a mixed sequence, and send the mixed sequence to the blockchain distributed application server. The blockchain distributed application server is used to receive the ciphertext data and quantum hash value of the user, perform re-encryption, upload the re-encrypted ciphertext to the distributed database, and upload the quantum hash value to the blockchain; receive and process the data access request of the user, provide the re-encryption key to the data owner, and provide the ciphertext and access credentials to the data visitor. The data visitor module pays to purchase the ciphertext data, decrypts the ciphertext data by using the decryption key, and verifies the data integrity.
9. A computer device, which includes a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the blockchain data sharing method based on quantum re-encryption according to any one of claims 1 to 7.
Citation Information
Patent Citations
Distributed data security sharing method and system based on block chain, and computer readable medium
CN113595971A
Block chain data privacy protection and sharing method based on zero knowledge proof
CN114143080A