A Cloud-based Secure Transaction Method for Multi-party Data in the Field

By adopting system public parameters and encryption technology in the multi-party data trading system on the cloud, data privacy and security issues are solved, and data value is maximized and privacy protection is protected, which is suitable for streaming data transactions.

CN118229285BActive Publication Date: 2025-07-29UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410166555.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-06
Publication Date
2025-07-29
Estimated Expiration
2044-02-06

AI Technical Summary

Technical Problem

In the existing cloud-based multi-party data on-site trading system, data privacy and security issues have not been effectively resolved, making it difficult to protect the privacy of data owners and middlemen, and the data value has not been maximized.

Method used

The cloud-based multi-party data in-site secure transaction method is adopted to generate system public parameters and public private keys to realize end-to-end encrypted communication between data owners and middlemen, and use symmetric keys and public key searchable encryption technology to ensure the security and privacy protection of data transmission.

Benefits of technology

It maximizes the release of data value, while ensuring the privacy and security of data owners and middlemen. It is suitable for streaming data transactions, especially subscription data transactions, reducing communication and storage costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118229285B_ABST
    Figure CN118229285B_ABST
Patent Text Reader

Abstract

The present invention discloses a cloud-based secure multi-party data in-field trading method, which relates to the field of information security technology. The method includes: S1. Generating system public parameters according to security parameters, and the exchange, data owner, buyer, and middleman generate their own required public and private keys; S2. Each data owner and middleman respectively establish end-to-end communication; S3. The data owner encrypts the data and keywords and uploads them to the cloud, and sells them to the middleman; S4. The middleman encrypts the symmetric key and uploads the ciphertext to the cloud server; S5. The buyer submits data requirements, and the middleman generates a search trapdoor for the cloud server to perform keyword ciphertext matching; S6. The buyer calculates the intermediate parameters and sends them to the middleman, the middleman generates the corresponding re-encryption key and sends it to the cloud server, and the cloud server calculates the re-encrypted ciphertext and sends it to the buyer, and the buyer decrypts it to obtain the file plaintext. The present invention ensures the maximum release of data value during the trading process while protecting the privacy of data owners and middlemen, and has high efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to a cloud-based secure multi-party data in-field trading method. Background Art

[0002] In-field data trading, which refers to data trading assisted or supervised by an exchange (Exchange-assisted datatrading, EADT), plays a crucial role in releasing the value of data. Existing EADT generally adopts a three-layer model, namely a group of data owners, a middleman, and a group of buyers: the middleman collects a large amount of data from the data owners, processes it to obtain data products, and then sells the products (or some related services) to the buyers. In many fields (such as statistical analysis), cross-domain data combinations can always enhance the value of data. Therefore, the above example enables owners, middlemen, and buyers to greatly benefit from data trading. In the current EADT system, cloud storage services are a key component for delivering data products, which exempts data owners, middlemen, and buyers from transmitting data products in an end-to-end manner, greatly saving communication and storage costs. With the booming development of data-intensive applications such as electronic medical systems and industrial Internet of Things, cloud-based EADT has shown great advantages and potential in reality, such as accelerating discovery and training better models.

[0003] However, serious threats to data security and privacy have also emerged. In existing EADT systems, data products are outsourced to cloud servers in plain text. The cloud server can directly access the data content as needed, and malicious insiders working for the cloud service provider can easily violate the privacy of the owners and the interests of the brokers. Even worse, malicious cloud servers may also abuse data products without the authorization of the owners and brokers. Despite having strict policies as passive measures to protect interests and privacy, since they are all controlled by the cloud service provider, owners and middlemen still worry about privacy infringement, and there is currently a lack of technical solutions. In many cloud-based EADT systems, cloud storage services are provided by the exchange itself, further exacerbating the problems of data abuse and privacy leakage.

[0004] In summary, it is necessary to design a cloud-based secure multi-party data in-field trading method to maximize the release of data value while protecting the privacy of data owners and middlemen. Summary of the Invention

[0005] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a cloud-based secure multi-party data in-field trading method to ensure the maximum release of data value during the trading process while protecting the privacy of data owners and middlemen.

[0006] The object of the present invention is achieved by the following technical solutions:

[0007] A cloud-based multi-party in-field secure data trading method, which is applied to a multi-party trading system. The multi-party trading system includes a cloud server, an exchange, a data owner, a buyer, and a middleman. The method includes:

[0008] S1. Generate system public parameters according to security parameters. The exchange, the data owner, the buyer, and the middleman generate their own public and private keys.

[0009] S2. Each data owner and middleman respectively establish end-to-end communication.

[0010] S3. The data owner encrypts the data and keywords and uploads them to the cloud and sells them to the middleman.

[0011] S4. The middleman encrypts the symmetric key and uploads the ciphertext to the cloud server.

[0012] S5. The buyer submits data requirements. The middleman generates a search trapdoor for the cloud server to perform keyword ciphertext matching.

[0013] S6. The buyer calculates intermediate parameters and sends them to the middleman. The middleman generates the corresponding re-encryption key and sends it to the cloud server. The cloud server calculates the re-encrypted ciphertext and sends it to the buyer. The buyer decrypts it to obtain the file plaintext.

[0014] Preferably, the step S1 includes:

[0015] S11. Generate system public parameters PP = {p, P, G, G T , e, H1, H2, H3, H4, h, ρ, Enc( ), Dec( ), E( ), D( )} according to security parameter l; where G represents a p-order additive cyclic group composed of points on an elliptic curve, P is a generator of G; e is a bilinear mapping G×G→G T ; H1( ): G→Z p , H2( ), H3( ): {0, 1} * →G, H4( ): G T →{0, 1} lg ; E( ) and D( ) are a pair of symmetric cryptographic algorithms;

[0016] S12. The exchange generates a master private key s and the corresponding master public key Q; the data owner generates identity public and private keys (IK b , ik b ), a signature pre-shared public key SPK b , and uploads the identity public key IK b and the signature pre-shared public key SPK b , and the middleman generates and uploads the identity public key IKa , the signature pre-shared public key SPK a and a number of one-time public keys {OPK1, OPK2…, OPK m}; The middleman selects two random numbers and generates a proxy re-encryption key pair sk a = (a0, a r ) and pk a = (a0P, a r P), as well as the secret a. The buyer selects two random numbers and generates a proxy re-encryption key pair sk b = (b0, b r ) and pk b = (b0P, b r P), as well as the secret b; The middleman generates a searchable encryption key pair as (sk, pk) = (η, ηP);

[0017] S13. The exchange saves local logs to record the number of times ρ that the data owner and the middleman apply for keyword enhancement S and ρ D , with the upper limit being ρ.

[0018] Preferably, the step S2 includes:

[0019] S21. The data owner creates a temporary key pair (ek b , EK b ), and obtains the middleman's identity public key IK a , the signature pre-shared public key SPK a and the one-time public key OPK a from the cloud server;

[0020] S22. The data owner uses the Diffie-Hellman protocol to calculate the negotiation key Then calculate the root key SK0 = KDF(DH1, DH2, DH3, DH4), where KDF is a key derivation function;

[0021] S23. The data owner calculates a set of associated data AD according to the identity keys of himself and the middleman, and encrypts it with authenticated encryption;

[0022] S24. The data owner sends the start message {IK b , EK b , SPK a , OPK a , AD} for creating a session to the middleman;

[0023] After the middleman receives the start message, the same root key SK0 is calculated according to the Diffie-Hellman protocol and the KDF function;

[0024] S26. In each subsequent round of data transmission, the data owner selects a secret x t , t = 1, 2,..., and generates a negotiation key according to the Diffie-Hellman public key sent by the middleman Generated negotiation key And use it together with the root key SK t-1 As the input of the KDF function to obtain the output, a part of the output is used as the new root key SK t , and the other part is used as the current round key CK of the sending chain t ; And send its own Diffie-Hellman public key To the middleman; After the middleman receives the public key , calculate the negotiation key And use it together with the root key SK t-1 As the input of the KDF function to obtain the output, a part of the output is used as the new root key SK t , and the other part is used as the current round key CK of the sending chain t .

[0025] Preferably, the step S3 includes:

[0026] S31. The data owner uniformly selects a random number And calculates the first blinded value ω′ = rH2(ω) of the keyword ω and sends it to the exchange;

[0027] S32. The exchange verifies ρ S <ρ, then calculates the signature σ′ of ω′ ω = s·ω′ and returns it to the data owner, sets ρ S ++;

[0028] S33. The data owner verifies the validity of the signature σ′ according to e(σ′ ω , P) = e(ω′, Q), then calculates σ ω = r ω1 σ′ -1 And verifies its validity according to e(σ ω , P) = e(H2(ω), Q); Finally, calculates the enhanced keyword sd ω1 = F1(H1(ω), ω); ω = F1(H1(ω), ω);

[0029] S34. The data owner uniformly selects a random number Calculates τ = e(H3(sd ω),χ·pk) and encrypt sd ω Get the ciphertext of keyword ω

[0030] S35. The data owner queries the current round key CK of the sending chain t Use the key to encrypt the file f to be traded to obtain the ciphertext c f =E(CK t ,f);

[0031] S36. The data owner will ciphertext Upload to the cloud server.

[0032] Preferably, step S4 includes:

[0033] S41. Middleman uniformly selects random numbers and h←G, and calculate c a,1 =a0kP,

[0034] S42. The middleman announces h and c k =(c a,1 ,c a,2 ) to the cloud server.

[0035] Preferably, step S5 includes:

[0036] S51. The middleman uniformly selects a random number based on the keyword ω requested by the buyer Calculate the second blinded value ω″=γH2(ω) and send ω″ to the exchange;

[0037] S52. Exchange Verification ρ D <ρ, then calculate the signature σ″ of ω″ ω =s·ω″ and returns it to the middleman, setting ρ D ++;

[0038] S53. The middleman shall follow the principle of e(σ″ ω ,P)=e(ω″,Q)Verify signatureσ″ ω The effectiveness of , and then calculate σ ω2 =γ -1 σ″ ω And according to e(σ ω2 ,P)=e(H2(ω),Q) to verify its effectiveness; finally calculate the enhanced keyword sd ω =F1(H1(ω),ω);

[0039] S54. Middleman calculation search trapdoor td ω =sk·H3(sd ω ) and sent to the cloud server;

[0040] For cloud servers and td ω as input, verify H4(e(td ω , A)) = B. If the equation holds, send the random number h corresponding to the relevant keyword to the buyer; otherwise, output no matching value.

[0041] Preferably, the step S6 includes:

[0042] S61. The buyer receives h sent by the server, calculates bh using the secret b, and sends it to the middleman.

[0043] S62. The middleman obtains the public key pk of the buyer b and calculates the re-encryption key and then sends rk to the cloud server.

[0044] S63. The cloud server calculates and sets c′ k = (c b,1 , c b,2 ), and then sends {c f , c′ k} to the buyer.

[0045] S64. The buyer decrypts c′ k to obtain the symmetric key and then decrypts c t using CK f to obtain the file plaintext f = D(CK t , c f ).

[0046] The beneficial effects of the present invention are:

[0047] 1) The present invention proposes a cloud-based multi-party data in-field secure trading scheme. The middleman can integrate and process the data of multiple data owners, and realizes the confidentiality of the data for the exchange and the cloud server, ensuring the privacy of the data owners and the middleman.

[0048] 2) In the present invention, the trading data uses symmetric encryption, and the symmetric key is generated by double ratchets, ensuring the forward and backward security of the symmetric key, realizing the end-to-end communication security between the data owner and the middleman, and being applicable to the trading of streaming data, especially subscription-based data trading.

[0049] 3) In the present invention, the keyword uses public key searchable encryption, and the keyword is strengthened by the exchange, which can resist keyword guessing attacks, and ensures the data preference privacy of the data owner and the data buyer for the exchange and the server.

[0050] 4) In the cloud-based multi-party data trading system constructed by the present invention, the trading venue is a lightweight node, and all data is stored on the cloud server side, which has certain advantages in the storage overhead required by each role. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a flowchart of an embodiment of the multi-party data security trading method in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] Next, the technical solutions of the present invention will be described clearly and completely in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0053] Refer to Figure 1 , the present invention provides a technical solution:

[0054] A cloud-based multi-party data in-field security trading method, which is applied to a multi-party trading system. The multi-party trading system includes a cloud server, a trading venue, a data owner, a buyer, and a middleman. The method includes:

[0055] S1. Generate system public parameters according to security parameters. The trading venue, data owner, buyer, and middleman generate their own public and private keys.

[0056] Specifically, step S1 includes:

[0057] S11. Generate system public parameters PP = {p, P, G, G T , e, H1, H2, H3, H4, h, ρ, Enc( ), Dec( ), E( ), D( )} according to security parameter l; where G represents an additive cyclic group of order p composed of points on an elliptic curve, P is a generator of G; e is a bilinear mapping G×G→G T ; H1( ): G→Z p , H2( ), H3( ): {0, 1} * →G, H4( ): G T →{0, 1} lgp ; E( ) and D( ) are a pair of symmetric cryptographic algorithms;

[0058] S12. The trading venue generates a master private key s and the corresponding master public key Q; the data owner generates identity public and private keys (IK b , ik b ), a signature pre-shared public key SPK b , and uploads the identity public key IK b and the signature pre-shared public key SPKb , the middleman generates and uploads the identity public key IK a , the signature pre-shared public key SPK a and a number of one-time public keys {OPK1, OPK2…, OPK m}; the middleman selects two random numbers and generates the proxy re-encryption key pair sk a = (a0, a r ) and pk a = (a0P, a r P), as well as the secret a. The buyer selects two random numbers and generates the proxy re-encryption key pair sk b = (b0, b r ) and pk b = (b0P, b r P), as well as the secret b; the middleman generates the searchable encryption key pair as (sk, pk) = (η, ηP); where the signature pre-shared public key is used for authentication with the identity key signature, and the private key corresponding to the public key is represented by the corresponding lowercase letter.

[0059] S13. The exchange saves the local log to record the number of times ρ S and ρ D that the data owner and the middleman apply for keyword enhancement respectively, with the upper limit being ρ.

[0060] S2. Each data owner and the middleman establish end-to-end communication respectively.

[0061] Specifically, step S2 includes:

[0062] S21. The data owner creates a temporary key pair (ek b , EK b ), and obtains the middleman's identity public key IK a , the signature pre-shared public key SPK a and the one-time public key OPK a from the cloud server;

[0063] S22. The data owner uses the Diffie-Hellman protocol to calculate the negotiation key Then calculate the root key SK0 = KDF(DH1, DH2, DH3, DH4), where KDF is the key derivation function;

[0064] S23. The data owner calculates a set of associated data AD based on the identity keys of himself and the middleman, and encrypts it with authenticated encryption;

[0065] S24. The data owner sends the start message {IK b , EKb , SPK a , OPK a , AD};

[0066] S25. After the middleman receives the start message, the same root key SK0 is calculated according to the Diffie-Hellman protocol and the KDF function;

[0067] S26. In each subsequent round of data transmission, the data owner selects a secret x t , t = 1, 2,..., and generates a negotiated key according to the Diffie-Hellman public key sent by the middleman Generated negotiation key And use it together with the root key SK t-1 As the input of the KDF function to obtain the output, a part of the output is used as the new root key SK t , and the other part is used as the current round key CK of the sending chain t ; And send its own Diffie-Hellman public key To the middleman; After the middleman receives the public key , calculate the negotiated key And use it together with the root key SK t-1 As the input of the KDF function to obtain the output, a part of the output is used as the new root key SK t , and the other part is used as the current round key CK of the sending chain t .

[0068] S3. The data owner encrypts and uploads the data and keywords to the cloud and sells them to the middleman.

[0069] Specifically, step S3 includes:

[0070] S31. The data owner evenly selects a random number And calculates the first blinded value ω′ = rH2(ω) of the keyword ω and sends it to the exchange;

[0071] S32. The exchange verifies ρ S <ρ, and then calculates the signature σ′ of ω′ ω = s·ω′ and returns it to the data owner, and sets ρ S ++;

[0072] S33. The data owner verifies the validity of the signature σ′ according to e(σ′ ω , P) = e(ω′, Q), and then calculates σ ω And then calculates σ ω1 = r -1 σ′ ω And according to e(σ ω1, P) = e(H2(ω), Q) to verify its effectiveness; finally, calculate the enhanced keyword sd ω = F1(H1(ω), ω);

[0073] S34. The data owner uniformly selects a random number Calculate τ = e(H3(sd ω ), χ·pk) and encrypt sd ω Get the ciphertext of the keyword ω

[0074] S35. The data owner queries the current round key CK of the sending chain t Use it as the key to encrypt the file f to be traded to get the ciphertext c f = E(CK t , f);

[0075] S36. The data owner uploads the ciphertext to the cloud server.

[0076] S4. The middleman encrypts the symmetric key and uploads the ciphertext to the cloud server.

[0077] Specifically, step S4 includes:

[0078] S41. The middleman uniformly selects a random number and h ← G, and calculates c a,1 = a0kP,

[0079] S42. The middleman publishes h and uploads c k = (c a,1 , c a,2 ) to the cloud server.

[0080] S5. The buyer submits data requirements, and the middleman generates a search trapdoor for the cloud server to perform keyword ciphertext matching.

[0081] Specifically, step S5 includes:

[0082] S51. According to the keyword ω requested by the buyer, the middleman uniformly selects a random number and calculates the second blinding value ω″ = γH2(ω), and sends ω″ to the exchange;

[0083] S52. The exchange verifies ρ D <ρ, and then calculates the signature σ″ of ω″ ω = s·ω″ and returns it to the middleman, and sets ρ D ++;

[0084] S53. The middleman according to e(σ″ ω, P) = e(ω″, Q) to verify the signature σ″ ω for validity, and then calculate σ ω2 = γ -1 σ″ ω and verify its validity according to e(σ ω2 , P) = e(H2(ω), Q); finally, calculate the enhanced keyword sd ω = F1(H1(ω), ω);

[0085] S54. The middleman calculates the search trapdoor td ω = sk·H3(sd ω ) and sends it to the cloud server;

[0086] S55. The cloud server uses and td ω as inputs to verify H4(e(td ω , A)) = B. If the equation holds, send the random number h corresponding to the relevant keyword to the buyer; otherwise, output no matching value.

[0087] In the present invention, keywords are encrypted using public key searchable encryption, and the keywords are enhanced by the exchange, which can resist keyword guessing attacks and ensure the data preference privacy of the data owner and the data buyer for the exchange and the server.

[0088] S6. The buyer calculates intermediate parameters and sends them to the middleman. The middleman generates the corresponding re-encryption key and sends it to the cloud server. The cloud server calculates the re-encrypted ciphertext and sends it to the buyer, and the buyer decrypts it to obtain the file plaintext.

[0089] Specifically, step S6 includes:

[0090] S61. The buyer receives h sent by the server, calculates bh using the secret b, and sends it to the middleman;

[0091] S62. The middleman obtains the public key pk b of the buyer and calculates the re-encryption key and then sends rk to the cloud server;

[0092] S63. The cloud server calculates and sets c′ k = (c b,1 , c b,2 ), and then sends {c f , c ′ k} to the buyer;

[0093] S64. The buyer decrypts c′ k to obtain the symmetric key and then decrypts c using CK ω ​f Obtain the plaintext of the file f = D(CK t , c f ).

[0094] In the present invention, the transaction data is encrypted symmetrically, and the symmetric key is generated by a double ratchet, which ensures the forward and backward security of the symmetric key, realizes the end-to-end communication security between the data owner and the middleman, and is applicable to the transaction of streaming data, especially the subscription-based data transaction. The middleman can integrate and process the data of multiple data owners, and realizes the confidentiality of the data for the exchange and the cloud server, ensuring the privacy of the data owner and the middleman.

[0095] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. And the changes and modifications made by those skilled in the art that do not depart from the spirit and scope of the present invention should all be within the protection scope of the appended claims of the present invention.

Claims

1. A cloud-based secure multi-party data in-field trading method, characterized in that, Applied to a multi-party transaction system, the multi-party transaction system includes a cloud server, an exchange, a data owner, a buyer, and an intermediary, the method includes: S1. Generate system public parameters based on security parameters. Exchanges, data owners, buyers, and intermediaries generate their own required public and private keys. S2. Each data owner and intermediary establish end-to-end communication; S3. The data owner encrypts the data and keywords and uploads them to the cloud, selling them to a middleman. S4. The middleman encrypts the symmetric key and uploads the ciphertext to the cloud server. S5. The buyer submits data requirements, the intermediary generates a search trap, and the cloud server performs keyword ciphertext matching. S6. The buyer calculates the intermediate parameters and sends them to the middleman. The middleman generates the corresponding re-encryption key and sends it to the cloud server. The cloud server calculates the re-encrypted ciphertext and sends it to the buyer. The buyer decrypts it to obtain the plaintext file.

2. The cloud-based multi-party data intra-venue secure transaction method according to claim 1, characterized in that: The step S1 comprises: S11. Generate system public parameters PP = {p, P, G, G according to security parameters l. T ,e,H1,H2,H3,H4,h,ρ,Enc(),Dec(),E(),D()}; where G represents the p-order additive cyclic group of points on the elliptic curve, P is the generator of G; e is the bilinear mapping G×G→G T ;H1():G→Z p ,H2(),H3():{0,1} * →G,H4():G T →{0,1} 1gp ; E() and D() are a pair of symmetric cryptographic algorithms; S12. The exchange generates a master private key s and a corresponding master public key Q; the data owner generates an identity public and private key (IK b ,ik b ), Signature pre-shared public key SPK b , and upload the identity public key IK b and signature pre-shared public key SPK b , the middleman generates and uploads the identity public key IK a , Signature pre-shared public key SPK a and several one-time public keys {OPK1, OPK2…, OPK m }; The middleman selects two random numbers And generate the proxy re-encryption key pair sk a =(a0,a r ) and pk a =(a0P,a r P), and secret a, the buyer picks two random numbers And generate the proxy re-encryption key pair sk b =(b0,b r ) and pk b =(b0P,b r P), and secret b; the middleman generates a searchable encryption key pair as (sk, pk) = (η, ηP); S13. The exchange saves local logs to record the number of times the data owner and the intermediary apply for keyword enhancement ρ S and ρ D , with an upper limit of ρ.

3. The cloud-based multi-party data intra-venue secure transaction method according to claim 2, characterized in that: The step S2 comprises: S21. The data owner creates a temporary key pair (ek b , EK b ), and obtains the identity public key IK of the middleman from the cloud server a , the signature pre-shared public key SPK a and the one-time public key OPK a ; S22. The data owner uses the Diffie-Hellman protocol to calculate the negotiated key Then calculate the root key SK0 = KDF(DH1, DH2, DH3, DH4), where KDF is the key derivation function; S23. The data owner calculates a set of accompanying data AD based on his or her own and the intermediary's identity keys and encrypts it using authenticated encryption; S24. The data owner sends a start message for creating a session to the middleman {IK b , EK b , SPK a , OPK a , AD}; S25. After receiving the initial message, the middleman calculates the same root key SK0 according to the Diffie-Hellman protocol and the KDF function; S26. In each subsequent round of data transmission, the data owner selects the secret x t , t = 1, 2, …, and generates a negotiated key according to the Diffie-Hellman public key sent by the middleman and uses it together with the root key SK t-1 as the input of the KDF function to obtain an output. A part of the output is used as the new root key SK t , and the other part is used as the current round key CK of the sending chain t ; and sends its own Diffie-Hellman public key to the middleman; after receiving the public key , the middleman calculates the negotiated key and uses it together with the root key SK t-1 as the input of the KDF function to obtain an output. A part of the output is used as the new root key SK t , and the other part is used as the current round key CK of the sending chain t .​ 4. A cloud-based multi-party data in-field secure transaction method according to claim 3, characterized in that: The step S3 comprises: S31. The data owner uniformly selects a random number and calculates the first blinded value ω′ = rH2(ω) of the keyword ω and sends it to the exchange; S32. The exchange verifies ρ S <ρ, and then calculates the signature σ′ of ω′ ω = s·ω′ and returns it to the data owner, setting ρ S ++ S33. The data owner shall ω ,P)=e(ω′,Q) to verify the signature σ′ ω The effectiveness of , and then calculate σ ω1 =r -1 σ′ ω And according to e(σ ω1 ,P)=e(H2(ω),Q) to verify its effectiveness; finally calculate the enhanced keyword sd ω =F1(H1(ω),ω); S34. The data owner evenly selects random numbers Calculate τ = e(H3(sd ω ), χ·pk) and encrypt sd ω to obtain the ciphertext of keyword ω S35. The data owner queries the current round key CK of the sending chain t Use the key to encrypt the file f to be traded to obtain the ciphertext c f =E(CK t ,f); S36. The data owner will ciphertext Upload to the cloud server.

5. The cloud-based multi-party data secure transaction method according to claim 3, characterized in that: The step S4 comprises: S41. The middleman evenly selects a random number and h ← G, and calculate c a,1 = a0kP, S42. The middleman announces h and uploads c k =(c a,1 , c a,2 ) to the cloud server.

6. The method for secure multi-party data in-field transaction based on cloud according to claim 5, characterized in that: The step S5 comprises: S51. The middleman uniformly selects a random number based on the keyword ω requested by the buyer Calculate the second blinded value ω″=γH2(ω) and send ω″ to the exchange; S52. Exchange Verification ρ D <ρ, then calculate the signature σ″ of ω″ ω =s·ω″ and returns it to the middleman, setting ρ D ++; S53. The middleman shall follow the principle of e(σ″ ω ,P)=e(ω″,Q)Verify signatureσ″ ω The effectiveness of , and then calculate σ ω2 =γ -1 σ″ ω And according to e(σ ω2 ,P)=e(H2(ω),Q) to verify its effectiveness; finally calculate the enhanced keyword sd ω =F1(H1(ω),ω); S54. Middleman calculates search trapdoor td ω = sk·h3(sd ω ) and sends it to the cloud server; For cloud server and td ω are used as inputs to verify H4(e(td ω , A)) = B. If the equation holds, send the random number h corresponding to the relevant keyword to the buyer; otherwise, output no matching value.

7. A cloud-based multi-party data in-field secure trading method according to claim 6, characterized in that: The step S6 comprises: S61. The buyer receives h from the server, calculates bh using the secret b, and sends it to the middleman. S62. The middleman obtains the public key pk of the buyer b and calculates the re-encryption key Then the rk is sent to the cloud server; S63. Cloud Server Computing c b,2 =c a,2 And let c′ k =(c b,1 ,c b,2 ), then {c f ,c′ k }Send to buyer; The buyer decrypts c'. k Obtain the symmetric key Then use CK t To decrypt c f To obtain the plaintext file f = D(CK t , c f ).

Citation Information

Patent Citations

  • Authorized identity-based search encryption method with a keyword

    CN109614818A

  • Method to establish a secure channel

    EP4175219A1