Ciphertext Data Security Sharing and Access Control Method Based on Zero-Knowledge Proof

Through the proxy re-encryption and transaction aggregation mechanism based on zero-knowledge proof, the problems of low key management efficiency and high Gas consumption in blockchain networks are solved, efficient ciphertext data secure sharing and access control are realized, and the scalability and convergence of blockchain are improved.

CN118264398BActive Publication Date: 2025-07-04YUNNAN UNIVERSITY OF FINANCE AND ECONOMICS +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410080181.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-07-04
Estimated Expiration
2044-01-19

AI Technical Summary

Technical Problem

The existing blockchain-driven attribute-based encryption methods have low key management and distribution efficiency, large computing overhead, lack of key correctness verification, and fail to effectively solve the scalability and Gas consumption problems of the blockchain network, resulting in low overall integration with blockchain.

Method used

The ciphertext data security sharing method based on zero-knowledge proof is adopted, and distributed key management services with proxy re-encryption are used to realize on-chain verified re-encryption with zero-knowledge proof, and a transaction aggregation mechanism is designed to improve the scalability of the blockchain network and reduce Gas consumption.

Benefits of technology

It realizes that data users can manage and distribute keys securely, improves the scalability and convergence of the blockchain network, reduces on-chain Gas consumption, and ensures data availability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118264398B_ABST
    Figure CN118264398B_ABST
Patent Text Reader

Abstract

The present invention provides a method for secure sharing and access control of ciphertext data based on zero-knowledge proof, belonging to the field of information security technology. The method includes: first, initializing the system and encrypting the data of the data owner; generating a re-encryption key, and the proxy re-encryption node uses the received legitimate re-encryption key fragments combined with the public key to create a random symmetric key; then re-decrypting the data; calculating the key and generating the key; subsequently decrypting the data. The present invention also establishes a transaction aggregation mechanism and a re-encryption correctness proof mechanism, which can not only improve the scalability of the blockchain network, but also effectively reduce the on-chain Gas consumption, and further improve the integration with the blockchain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security, and in particular relates to a method for secure sharing and access control of ciphertext data based on zero-knowledge proof. Background Art

[0002] With the advent of the digital age, blockchain technology has gradually become an Internet infrastructure. The combination of ciphertext access control and blockchain mainly enhances ciphertext policy attribute-based encryption using blockchain, while achieving decentralized key management, solving the single-point risk of centralized authorization in a distributed environment, and enhancing the authentication capabilities of the principal and object, the control rights of data, and the auditing capabilities of keys. For example, Tian Youliang et al. proposed a blockchain-based CP-ABE traceability algorithm to solve the problem of difficult dynamic sharing of traceability information and achieved transaction privacy protection; Yan Xixi et al. proposed an attribute-based encryption method with verifiable search results based on blockchain to achieve fine-grained access control of shared keys; Giao et al. used blockchain as an entity for authentication, designed a distributed key generation algorithm, and homomorphically encrypted user attributes; Niu Shufen et al. proposed an on-chain attribute-based search encryption method for the problem of centralized cloud data storage to grant users fine-grained keyword search permissions; Ba Yang et al. proposed a blockchain-based policy-hidden attribute-based encrypted data sharing method to solve the privacy leakage problem caused by access policies in attribute-based encryption algorithms; Nakanishi et al. proposed an access control technology combining IOTA technology and CP-ABE for the security of Internet of Things authorization and the limitations of blockchain technology. By encrypting and authorizing Tokens using the CP-ABE algorithm and storing them in the IOTA Tangle, fine-grained access control that is one-to-many, distributed, and scalable is achieved; Zhang Xiaohong et al. proposed a blockchain attribute proxy re-encryption data sharing method that supports keyword retrieval, without the participation of a central authorization agency, improving the information sharing efficiency and the access pressure on cloud storage; Zhai Sheping et al. proposed an attribute-based encryption method for the problems such as centralization in traditional data sharing methods and designed a blockchain distributed generation algorithm that supports periodic key updates.

[0003] In the above blockchain-driven attribute-based encryption methods, the methods still retain the authorization agency, and the keys are still centrally managed by the authorization agency. There are also problems such as low efficiency of key management and distribution, large computational overhead, and lack of key correctness verification. In addition, when utilizing the anti-tampering, traceability, and decentralization characteristics of blockchain, all of the above methods do not consider indicators such as the scalability of the blockchain network and Gas consumption, resulting in problems such as low overall scalability of the method and large Gas consumption on the chain, and the overall integration of the method with blockchain is not high. With the advent of the blockchain 3.0 era, more challenges will be faced in aspects such as the privacy and scalability of blockchain. Summary of the Invention

[0004] The objective of the embodiments of the present invention is to provide a secure sharing method for ciphertext data based on zero - knowledge proof, so as to improve the scalability of the secure sharing method for ciphertext data, reduce the Gas consumption on the blockchain, and solve the problem that the overall integration degree of the existing method with the blockchain is not high.

[0005] To solve the above - mentioned technical problems, the technical method adopted by the present invention is a secure sharing and access control method for ciphertext data based on zero - knowledge proof, which specifically includes the following steps:

[0006] S1. The data owner takes the system security parameters, access control matrix, and attribute set as the input of the Setup function, outputs a key pair (PK, MSK), and sends the master key MSK to the proxy re - encryption node, where PK is the system public key;

[0007] S2. Encrypt the data of the data owner;

[0008] S3. The data owner inputs the private key of the data owner, the public key of the data user, the total number of fragments, and the threshold value, generates n re - encryption key fragments kFrag and sends them to the proxy re - encryption node;

[0009] S4. The proxy re - encryption node uses the received legal re - encryption key fragments kFrag combined with the public key pk of the data owner A , creates a random symmetric key ε K , and uses ε K to encrypt the system master key MSK into a re - encryption ciphertext CT MSK , and at the same time outputs a capsule and fragments cFrag of the capsule;

[0010] S5. Input the public key pk of the data owner A , the private key sk of the data user B and a set of t re - encryption ciphertext sets i represents the i - th in the re - encryption ciphertext set. First, aggregate each cFrag i to calculate the symmetric key ε K , and then use ε K to decrypt the MSK from the re - encryption ciphertext CT MSK ; where cFrag i represents the i - th fragment of the capsule;

[0011] S6. Key calculation;

[0012] S7. The data user inputs the attribute hash value and the user attribute set into the KeyGen function, and calculates the user attribute private key SK;

[0013] S8. Decrypt the ciphertext and establish a re-encryption verification mechanism and a transaction aggregation mechanism.

[0014] Furthermore, in S5, for each cFrag i Perform aggregation and calculate the symmetric key ε K The correctness of the re-encryption result is verified before.

[0015] Furthermore, the S2 encryption stage is as follows:

[0016] S201, randomly select integers s, y2, ..., y n ∈Z N , forming an n-dimensional vector space A column vector in Used to split the shared key and calculate the original ciphertext components

[0017]

[0018] Among them, Z N represents a positive integer set with N elements, e represents a bilinear map, α and δ are random parameters, g is a generator, C′ and C are original ciphertext components, and m represents the data plaintext;

[0019] S202: Randomly select an integer r from the i-th row of the access control matrix M. i ∈Z N , respectively calculated and in is the i-th share obtained by splitting the secret s, ρ(i) represents the i-th attribute mapping, represents the vector represented by the i-th row of the matrix M, β is the randomly generated private key, let

[0020]

[0021] Then the generated ciphertext is CT = (C, C′, Ψ);

[0022] Among them, Ψ, C i , D i , C is the ciphertext component, It is the encrypted part related to user attributes and policies. is based on the random value r i and policy adjustments to the encrypted portion, Used for decryption when combined with the secret key of the user who complies with the policy, l represents the lth row of the access control matrix.

[0023] Furthermore, the specific steps of S3 are as follows:

[0024] S301. The private key of the input data owner, the public key of the data user, the total number of fragments, and the threshold value.

[0025] S302. Select representing a group of order q, where id is the node identifier; and y are random parameters used to increase the analysis difficulty;

[0026] S303. For each re-encryption key fragment kFrag, it is defined as where the parameter: rk is the key of proxy re-encryption, is an intermediate parameter, Q1 represents the power operation on the generator Q, and S1 and S2 are the signatures of kFrag;

[0027] S304. Define Q1 = Q rk , S2 = y - a·S1; where H l4 is a hash function; is an intermediate parameter, pk B represents the public key of node B, pk A represents the public key of node A; a is a random parameter used to increase the analysis difficulty;

[0028] S305. Output the re-encryption key KF ∈ {kFrag}.

[0029] Further, the specific steps of S4 are as follows:

[0030] S401. Input the re-encryption key fragment kFrag, the public key pk A and the system master key MSK;

[0031] S402. Select random parameters representing a group of order q; the random parameters τ, u are used to increase the difficulty of ciphertext data analysis;

[0032] S403. Calculate the composition parameters P, D, ξ of the capsule;

[0033] S404. Create a random symmetric key ε K ; γ K is a random symmetric key generation function;

[0034] S405. Create capsule = (P, D, ξ);

[0035] S406. Encrypt the system master key MSK using the symmetric key ε K , and calculate the re-encrypted ciphertext CT MSK = ε K · MSK;

[0036] S407. Verify the validity of the capsule by checking whether the formula holds; denotes blinding the generator g1, denotes a publicly verifiable blind argument for P, ξ is the blinding factor, and H l2 denotes the hash function;

[0037] S408. If the formula holds, i.e., the capsule is valid, then calculate the composition parameters P1 = P rk and D1 = D rk ; D rk , P rk are the calculation results of the composition parameters P1 and D1, where rk is the key for proxy re-encryption;

[0038] S409. Output the fragment capsule = (P, D, ξ) and the re-encrypted ciphertext CT MSK = ε K · MSK.

[0039] Furthermore, the specific steps of S5 are as follows:

[0040] S501. Input the public key pk A of the data owner, the private key sk B of the data user, and a set of t re-encrypted ciphertexts

[0041] S502. Define Z1 as the set of z x,i , representing the hash value of each segmented sub-secret; pk B represents the public key of node B, represents the public key of node A encrypted with a random number, id i represents the id of the i-th node, id represents the node identifier, and H l6 , H l5 denote the hash functions;

[0042] S503. For each z x,i in the set Z1, calculate the segmented sub-parameters

[0043]

[0044] where, represents the product of t shares of the hash values of the segmented sub-secrets, t represents t elements, j represents starting from the j-th element, and z x,j represents the j-th hash value of the segmented sub-secret;

[0045] S504. Calculate the symmetric key ε K Composition parameters of

[0046]

[0047] P 1,i represents the i-th sub-secret value after splitting P1, D 1,i represents the i-th sub-secret value after splitting D1, D′ represents the product of t sub-secrets after splitting D1, and P′ represents the product of t sub-secrets after splitting P1;

[0048] Constitute

[0049]

[0050] γ is a composition parameter of the random symmetric key generation function, H l3 represents the hash function, and are variables used for temporary calculation inside the algorithm to prevent forgery, tampering, and deception during the key aggregation process.

[0051] S505. Use the symmetric key ε K Decrypt MSK from the re-encrypted ciphertext CT MSK .

[0052] Furthermore, the specific process of the S6 key calculation stage is as follows:

[0053] CptKey(PK, MSK, e, S) → {K, L, {h x}, E}

[0054] Among them, {h x} represents the hash value of the attribute x, K and L are components of the user attribute private key, and E is an intermediate parameter

[0055] Input the system key pair (PK, MSK), randomly select t, u ∈ Z p , gcd(e, u) = 1 indicates that e and u are relatively prime, and E = te, where E is the result of encrypting t;

[0056] (K, L) = (g α g βt , g t )

[0057] Among them, K and L are components of the user attribute private key.

[0058] Furthermore, the specific process of the decryption in S8 is as follows:

[0059] Suppose the attribute set S satisfies the access structure (M, ρ);

[0060] Let \(M\) be the access control matrix and \(\rho\) be the attribute mapping function;

[0061] Since \(I = \{i:\rho(i)\in S\}\), let \(\{\omega i \in\mathbb{Z} p |i\in I\}\). If \(\{\lambda i \}\) is a valid share, then where \(\omega i \) is a set of recovery coefficients, and \(\mathbb{Z} p \) represents a group of order \(p\). The data plaintext \(m\) is decrypted from the ciphertext through the following formula:

[0062]

[0063] where \(e\) is the bilinear pairing operation, \(C i \), \(L\), \(D i \) are the components of the ciphertext, \(I\) represents the set of authorized attributes, \(\omega_i\) is the recovery coefficient, \(\rho(i)\) represents the \(i\)-th attribute mapping, and \(K ρ(i) \) represents the partial user attribute private key of \(\rho(i)\).

[0064] Furthermore, the process of establishing the re-encryption verification mechanism in \(S8\) is specifically as follows:

[0065] S801. The proxy re-encryption node inputs the capsule, capsule fragment \(cFrag\), and re-encryption key fragment \(kFrag\) into the CreatNIZKP function. The CreatNIZKP function is defined to adopt the security and non-interactive characteristics of the Fiat-Shamir technique. Through this function, the proxy node can generate a publicly verifiable zero-knowledge proof \(\pi\) to ensure the correctness and privacy of the re-encryption process, and at the same time support efficient consensus verification in the blockchain environment;

[0066] S802. Select a random number

[0067] S803. Calculate the parameters for generating the zero-knowledge proof;

[0068] S804. Calculate the hash value of the generated zero-knowledge proof;

[0069] S805. Calculate the parameters for generating the zero-knowledge proof;

[0070] S806. Output the zero-knowledge proof \(\pi\).

[0071] Furthermore, after the proxy re-encryption node outputs the zero-knowledge proof \(\pi\) in \(S806\), it broadcasts the generated proof \(\pi\) to all nodes in the blockchain network and triggers the smart contract. Each node uses the VerifyNIZKP smart contract to perform consensus verification on each \(cFrag\). The specific process is as follows:

[0072] S807. All network nodes input the capsule, capsule fragments cFrag, and zero - knowledge proof π into the VerifyNIZKP smart contract;

[0073] S808. Verify whether the signature (S1, S2) is correct. If it is correct, calculate the hash value;

[0074] S809. Verify the correctness of cFrag;

[0075] S810. Output the verification result Result Verification 。

[0076] Furthermore, the transaction aggregation mechanism includes a Trading contract, a Processing contract, and an Operator node; the Trading contract is used for collecting transactions and verifying the integrity of the collected transactions, and the Processing contract and the Operator node are used for aggregating, executing, and submitting for verification the transactions collected in the Trading contract.

[0077] The beneficial effect of the present invention is to propose a secure sharing method for ciphertext data based on zero - knowledge proof. By using a distributed key management service based on proxy re - encryption to securely manage and distribute keys for data users, and realizing on - chain verifiable re - encryption based on zero - knowledge proof, the designed transaction aggregation mechanism can not only improve the scalability of the blockchain network while ensuring data availability, but also effectively reduce the on - chain Gas consumption, and further improve the integration with the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] In order to more clearly illustrate the technical methods in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following - described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0079] Figure 1 is the architecture diagram of the secure sharing system for blockchain ciphertext data based on zero - knowledge proof;

[0080] Figure 2 is the time - point configuration diagram;

[0081] Figure 3 is the simulation experiment architecture diagram;

[0082] Figure 4 is the key generation time curve graph;

[0083] Figure 5 It is a time curve graph of the proportion of strategy attributes in each stage;

[0084] Figure 6 It is a calculation overhead curve graph of the encryption stage;

[0085] Figure 7 It is a calculation overhead curve graph of the re-encryption stage;

[0086] Figure 8 It is a calculation overhead curve graph of the decryption stage;

[0087] Figure 9 It is a curve graph of the query performance test results;

[0088] Figure 10 It is a curve graph of the Gas consumption for executing relevant smart contracts. Detailed implementation manners

[0089] Next, the technical methods in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0090] As Figure 1 , the blockchain system architecture based on zero-knowledge proof of the present invention includes the following modules:

[0091] Data owner: When the data owner shares data, it creates an access policy through the LSSS matrix to grant access rights to the data user, and executes the system initialization function to generate global parameters, encrypt the shared data, etc.;

[0092] Data user: When the data user accesses the shared data, it must first request the master key from the blockchain node to generate the user attribute private key, and then decrypt the ciphertext;

[0093] Proxy re-encryption node: Composed of blockchain nodes, it provides a distributed key management service based on proxy re-encryption to enhance the security and privacy of the master key distribution;

[0094] Operator node: Composed of blockchain nodes, it collects the transactions generated during the operation of the system, and performs execution, aggregation, and generates corresponding zero-knowledge proofs to prove the validity of the account state transfer;

[0095] InterPlanetary File System: It provides a distributed storage service for encrypted data and stores the hash address on the blockchain;

[0096] Blockchain: It consists of other participating nodes such as proxy re-encryption nodes. While recording the public parameters of the system and performing operations such as consensus verification, it also realizes the traceability and auditability of the transaction transfer of the scheme parameters.

[0097] In order to securely obtain the master key in the absence of a central authority or a trusted third party, while implementing efficient data sharing and fine-grained access control using the blockchain-based ciphertext-policy attribute-based encryption algorithm, the present invention further uses a distributed key management service based on proxy re-encryption to manage and distribute the master key for data users. The data owner uses a random symmetric key ε K to encrypt the master key MSK. At the same time, each proxy re-encryption node is responsible for securely storing and managing the re-encryption key fragments. The data user can decrypt CT n only when obtaining at least the threshold t key fragments cFrag MSK to obtain MSK, and then generate a user attribute private key SK that matches the access policy, decrypt the ciphertext CT downloaded from IPFS, and finally obtain the data plaintext m, completing the secure and traceable data sharing. In addition, in order to improve the efficiency and scalability of the blockchain network and reduce the on-chain Gas consumption, the present invention also designs a transaction aggregation mechanism based on zk-SNARKs.

[0098] Zero-knowledge proof is used to prove the truth of a certain statement without revealing the specific information of the statement. Zero-knowledge proof has three important properties, which are respectively:

[0099] (1) Completeness: If the statement is true, then the prover can successfully generate a legal proof, and the verifier will accept this proof as true.

[0100] (2) Soundness: If the statement is false, then even if the prover tries to deceive the verifier, the probability that the verifier can only accept the correct proof is very small.

[0101] (3) Zero-knowledge: The prover can successfully prove the truth of the statement to the verifier, but in this process, the prover does not disclose any detailed information of the statement.

[0102] The method for secure sharing and access control of ciphertext data based on zero-knowledge proof in the present invention specifically includes the following steps:

[0103] S1. System initialization phase:

[0104] Setup(1 k , U) → (PK, MSK).

[0105] Input the system security parameter \(k\), the attribute set \(U\) with size denoted as \(|U|\). Let \(p\) be a large prime number. Input the access control matrix \(M\), distribute random exponents, output the key pair \((PK, MSK)\), and send the master key \(MSK\) to the proxy re-encryption node.

[0106] \(g\in G_0,\alpha,\beta\in Z\) p

[0107] \(e:G_0\times G_0\rightarrow G_1\)

[0108] \(PK = \{g, e(g, g) α , g β , h_1, h_2,..., h |u| \}\)

[0109] \(MSK=(g α )\)

[0110] S2. Encryption stage:

[0111] \(Encrypt(PK, A=(M,\rho), m,\delta)\rightarrow CT\).

[0112] Given that \(M\) is an \(l\times n\) access matrix, \(\rho\) is a mapping from the row index set \(\{1,2,...,l\}\) of matrix \(M\) to attributes, denoted as \(\rho(i)\). Let \(I = \{i:\rho(i)\in S\}\), where \(S\) represents the user attribute set. The specific encryption process is as follows:

[0113] ① Randomly select integers \(s,y_2,...,y n \in Z N , forming a column vector in the \(n -\)dimensional vector space to split the shared key, and calculate the original ciphertext component \(C = m\cdot e(g, g) , C' = g αsδ ; sδ

[0114] ② For the \(i -\)th row of matrix \(M\), randomly select an integer \(r i \in Z N , and calculate respectively and where is the \(i -\)th share obtained by splitting \(s\), \(C i is associated with the \(\rho(i)-\)th attribute, represents the vector represented by the \(i -\)th row of matrix \(M\), \(\beta\) is a randomly generated private key, and let

[0115]

[0116] Then the generated ciphertext is \(CT=(C, C',\Psi)\).

[0117] S3. Re-encryption key generation stage:

[0118] ReKeyGen(sk A ,pk B ,N,t) → KF。

[0119] The private key sk of the input data owner A , the public key of the data user, the total number of fragments, and the threshold value, generate n re-encryption key fragments kFrag and send them to the proxy re-encryption node. The specific algorithm is as follows:

[0120] S301. Input the private key of the data owner, the public key of the data user, the total number of fragments N, and the threshold value t;

[0121] S302. Select a random number

[0122] S303. For each re-encryption key fragment kFrag, calculate its composition parameters;

[0123] S304. Calculate the composition parameter rk = f(μ x ), Q1 = Q rk , S2 = y - a·S1;

[0124] S305. Define the re-encryption key fragment as

[0125] S306. Output the re-encryption key KF = KF ∪ {kFrag}, and form the key from the key fragments;

[0126] S4. Re-encryption phase

[0127] ReEncrypt(pk A , MSK, kFrag) → (CT MSK , capsule, cFrag)

[0128] The proxy re-encryption node uses the received legitimate re-encryption key fragment kFrag combined with Alice's public key pk A , to create a random symmetric key ε K , and use it to encrypt the system master key MSK into the re-encrypted ciphertext CT MSK , and at the same time output the capsule and the fragment cFrag of the capsule. The specific process is as follows:

[0129] S401. Input the re-encryption key fragment kFrag, the public key pk A and the system master key MSK;

[0130] S402. Select a random number

[0131] S403. Calculate the composition parameters of the capsule ξ = u + τ·H l2 (P, D);

[0132] S404. Create a random symmetric key ε K = γ K ((pk A ) τ+u );

[0133] S405. Create capsule = (P, D, ξ);

[0134] S406. Encrypt the system master key MSK using the symmetric key ε K , and calculate the re-encrypted ciphertext CT MSK = ε K ·MSK;

[0135] S407. Verify the validity of the capsule by checking whether the formula holds;

[0136] S408. If the formula holds, that is, the capsule is valid, then calculate the composition parameters of the fragment cFrag of the capsule: P1 = P rk and D1 = D rk , where rk is the key for proxy re-encryption;

[0137] S409. Output the fragment capsule = (P, D, ξ) and the re-encrypted ciphertext CT MSK = ε K ·MSK;

[0138] S5. Re-decryption phase

[0139]

[0140] Input the public key pk of the data owner A , the private key sk of the data user B and a set of t re-encrypted ciphertexts First, aggregate each cFrag i to calculate the symmetric key ε K . Before that, verify the correctness of the re-encryption result. After passing the verification, then execute the above steps, and then use ε K to decrypt MSK from the re-encrypted ciphertext CT MSK . The specific process is as follows:

[0141] S501. Input the public key pk of the data owner A, the private key sk of the data user B and a set of t re-encrypted ciphertexts

[0142] S502. Define Z1 as the set of z x,i . represents each fragment hash value; pk B represents the public key of node B, represents the public key of node A encrypted with a random number, id i represents the id of the i-th node, id represents the node identifier, H l6 and H l5 represent hash functions;

[0143] S503. For each element z in the set Z1 x,i , calculate the parameter

[0144]

[0145] S504. Calculate the composition parameters of the key ε K .

[0146]

[0147] constitute

[0148]

[0149] γ is a composition parameter of the random symmetric key generation function, H l3 represents a hash function, and are variables used for temporary calculations inside the algorithm to prevent forgery, tampering, and deception during the key aggregation process.

[0150] S505. Use the symmetric key ε K to decrypt the MSK from the re-encrypted ciphertext CT MSK .

[0151] S6. Key calculation stage:

[0152] CptKey(PK, MSK, e, S) → {K, L, {h x}}, E}

[0153] where, {h x} represents the hash value of the attribute x, K and L are components of the user attribute private key, and E is an intermediate parameter

[0154] Input the system key pair (PK, MSK), randomly select t, u ∈ Z p , gcd(e, u) = 1 indicates that e and u are relatively prime, and E = te, where E is the result of encrypting t.

[0155] (K, L) = (g α g βt , g t )

[0156] Among them, K and L are components of the user attribute private key.

[0157] S7. Key Generation Phase

[0158] KeyGen(h x , d, E, S) → SK. Input E, the attribute hash value h x and the user attribute set S, and obtain the modular inverse element d of e with respect to p, and calculate the user attribute private key SK.

[0159]

[0160] SK = (S, K, L, K x )

[0161] SK = (S, K, L, K x ) is the user attribute private key, and the content in the parentheses is the component of SK, K′ x , K x are intermediate parameters.

[0162] S8. Decryption Phase

[0163] Decrypt(SK, CT, δ) → m. Assume that the attribute set S satisfies this access structure. From the above, I = {i: ρ(i) ∈ S}. Let {ω i ∈ Z p | i ∈ I}. If {λ i} is a valid share, then Among them, ω i is a set of recovery coefficients, which is not unique.

[0164] Use the following formula to decrypt the data plaintext m from the ciphertext CT.

[0165]

[0166] To achieve verifiable re-encryption, the present invention designs a re-encryption correctness proof mechanism based on non-interactive zero-knowledge proof. This proof is generated by the proxy re-encryption node. First, let Then input cFrag and capsule, and generate a correctness proof π for cFrag. The specific process is as follows:

[0167] S801. Input the capsule capsule = (P, D, ξ), the capsule fragment Re-encryption key fragment Among them, the CreatNIZKP function is defined to adopt the security and non-interactive characteristics of the Fiat-Shamir technology. Through this function, the proxy node can generate a publicly verifiable zero-knowledge proof π to ensure the correctness and privacy of the re-encryption process, and at the same time support efficient consensus verification in the blockchain environment;

[0168] S802. Select a random number

[0169] S803. Calculate and generate the parameter P2 = P of the zero-knowledge proof r D2 = D r Q2 = Q r ;

[0170] S804. Calculate and generate the hash value C = H of the zero-knowledge proof l (P, P1, P2, D, D1, D2, Q, Q1, Q2);

[0171] S805. Calculate and generate the parameter ρ = r + C·rk of the zero-knowledge proof;

[0172] S806. Output the zero-knowledge proof π = (P2, D2, Q1, Q2, S1, S2, ρ);

[0173] The proxy re-encryption node broadcasts the generated proof π to all nodes in the blockchain network and triggers the smart contract. Each node uses the VerifyNIZKP smart contract to perform consensus verification on each cFrag. The specific process is as follows:

[0174] S807. Input the capsule capsule = (P, D, ξ), capsule fragment zero-knowledge proof π = (P2, D2, Q1, Q2, S1, S2, ρ);

[0175] S808. Verify whether the signature (S1, S2) is correct. If it is correct, calculate the hash value C = H l (P, P1, P2, D, D1, D2, Q, Q1, Q2);

[0176] S809. Verify the correctness of cFrag through the verification formula to verify the correctness of cFrag;

[0177] S810. If the formula holds, it means that cFrag is correct. Otherwise, it means that cFrag is incorrect, and output the verification result Result Verification ;

[0178] To improve the scalability of the blockchain network and reduce the on-chain Gas consumption, the present invention designs a transaction aggregation mechanism based on zero-knowledge proof, which mainly includes a Trading contract, a Processing contract, and an Operator node. Among them, the Trading contract is responsible for collecting transactions and verifying the integrity of the collected transactions, and the Processing contract and the Operator node are responsible for aggregating, executing, and submitting for verification the transactions collected in the Trading contract, which are introduced in detail as follows:

[0179] S811. The transaction receiving function ReceiveTx() is used to receive the generated transactions;

[0180] S812. Verify Whether it times out CheckTimeout

[0181] S813. Update the time to UpdateTime();

[0182] S814. The transaction verification function VerifyTx() is used to verify the legality of the received transactions;

[0183] S815. Verify Whether it times out CheckTimeout

[0184] S816. Update the time to UpdateTime();

[0185] S817. The transaction uploading function UploadTx() is used to upload the legal transactions that pass the verification;

[0186] S818. Verify Whether it times out CheckTimeout

[0187] S819. Update the time to UpdateTime();

[0188] S820. The system returns Return();

[0189] S821. Verify Whether it times out CheckTimeout

[0190] S822. Update the time to UpdateTime();

[0191] The Trading contract is as shown above. This contract mainly consists of 4 functions. At the end of each function, we declare a time point to check for timeout events, and these 4 time points satisfy i = 1, 2, 3, and the time interval between them can be determined according to the time interval between two consecutive collections. For example, for the i-th collection and the (i + 1)-th collection, there is At a time point when it ends, the CheckTimeout function checks whether the participating node has completed this event, and the 4 time points are also updated accordingly with the transaction collection process, as During the i-th transaction collection, each participating node P j (j ∈ 1,..., n) sends a transaction to the ReceiveTx function. At the same time, to ensure the integrity of the transaction during the transfer process, a publicly auditable zero-knowledge proof μ is attached. Then, the integrity of the received transaction is verified by executing the VerifyTx function. If the verification passes, it means that the received transaction has not been tampered with during the transfer process. Finally, the successfully verified transaction is uploaded through the UploadTx function.

[0192] In the Processing contract, the time points will be updated to and where, the time required to create a new block between two consecutive transaction collections is denoted as T r ; specifically as follows:

[0193] S823. The aggregation function Deposit() aggregates and executes the transactions;

[0194] S824. Verify whether it times out;

[0195] S825. Update the time to

[0196] S826. The zero-knowledge proof generation function ZKPGen() generates a zero-knowledge proof that the account state transition is valid;

[0197] S827. Verify whether it times out;

[0198] S828. Update the time to

[0199] The submission function Withdraw() submits the previous state root prev_state_root, the next state root next_state_root, and the zero-knowledge proof zk_proof, etc. to the on-chain smart contract for storage and verification;

[0200] S830. Verify Whether it times out, CheckTimeout

[0201] S831. Update the time to

[0202] The specific process of each transaction aggregation is as follows: After receiving a transaction from the Trading contract by the Operator node, it first stores the transaction information in an off-chain Merkle tree, and then aggregates and executes the transaction through the Deposit function. The specific process is as follows:

[0203] S832. Input the transaction set transactions;

[0204] S833. Initialize the Merkle tree merkle_tree = MerkleTree();

[0205] S834. For each transaction in the transaction set for tx in transactions;

[0206] S835. Calculate its hash value tx_hash = sha256(serialize(tx));

[0207] S836. Add the calculated hash value to the Merkle tree merkle_tree.add(tx_hash);

[0208] S837. Return the root hash value of the output Merkle tree return merkle_tree.root_hash;

[0209] After the local transaction is executed, the local Merkle tree root will be converted from the previous state root prev_state_root to the next state root next_state_root and apply for a state update. At the same time, a zero-knowledge proof zk_proof that proves the validity of the account state transfer is generated based on zk-SNARKs. The specific process is as follows.

[0210] S838. Take the transaction set `transactions`, the aggregation circuit `circuit`, the proving key `proving_key`, and the verification key `verification_key` as the inputs of the zero-knowledge proof generation function `ZKPGen()`.

[0211] S839. Use the zksnark cryptographic library to generate a zero-knowledge proof `zk_proof = zksnark_lib.generate_proof(circuit, proving_key, transactions)`.

[0212] S840. Use the `verify_proof` function in the zksnark cryptographic library to verify the validity of the generated zero-knowledge proof `is_valid_proof = zksnark_lib.verify_proof(zk_proof, verification_key)`.

[0213] S841. If the zero-knowledge proof is invalid (`assert is_valid_proof`), output "Invalid zero-knowledge proof!".

[0214] S842. Output and return the generated zero-knowledge proof `return zk_proof`.

[0215] Finally, submit the previous state root `prev_state_root`, the next state root `next_state_root`, the transaction set `transactions`, and the zero-knowledge proof `zk_proof`, etc., to the on-chain smart contract for storage and verification. The specific process is shown in Algorithm 8. After the `zk_proof` submitted to the chain passes the verification, the submitted new state will be written to the chain.

[0216] S843. Take the previous state root `prev_state_root`, the next state root `next_state_root`, the transaction set `transactions`, and the zero-knowledge proof `zk_proof` as the inputs of the `update_chain()` function.

[0217] S844. Send a request to verify the validity of the zero-knowledge proof `require(verify_zkp(zk_proof)"Invalid zk_proof.")`.

[0218] S845. Update the state root of the current Merkle tree update_state_root(prev_state_root, next_state_root, transactions);

[0219] Figure 2 A time point configuration scheme is listed to illustrate the time point relationship between the Trading contract and the Processing contract. Assume that at the i-th collection, the time point is set to The relationship between the three time intervals is

[0220] By designing a transaction aggregation mechanism, the legality of each transaction no longer needs to be verified repeatedly. It only needs to verify the validity of the submitted zero-knowledge proof, and the size and verification time of the generated zero-knowledge proof will not increase with the growth of the number of transactions. In addition, to avoid potential security risks caused by data availability, the necessary transaction data is stored on the chain, and then the global account state is restored. This can not only improve the efficiency of the blockchain network, ensure data availability, but also effectively reduce the Gas consumption on the chain.

[0221] To more deeply evaluate the actual effect of the proposed scheme, the invention conducted a series of experiments. First, the computing time of operations such as key generation, encryption / decryption, and re-encryption was tested; second, the anti-pressure effect of the invention under multi-threaded concurrency and the Gas consumed by executing the signature verification smart contract and the re-encryption result correctness verification smart contract on the chain were tested; finally, the Gas consumption of using the transaction aggregation mechanism was tested.

[0222] The simulation experiment platform of the invention is configured with the Ubuntu 22.10 operating system, the processor is an AMD Ryzen7 6800H CPU with a main frequency of 3.20 GHz and 16.0 GB of RAM. In addition, the pairing-based JPBC cryptographic library and ZoKrates for generating zk-snark circuits are used to build a blockchain virtual network based on Ganache, and the Remix smart contract compilation platform is used for the compilation and deployment of smart contracts. The detailed experimental architecture is as Figure 3 shown. For each experiment, 20 independent experiments are carried out under the condition that all experimental environments are exactly the same, and then the average value is taken as the experimental result.

[0223] As Figure 4As shown in the figure, as the number of attributes increases, the key generation calculation time of the present invention tends to be the same as that of the traditional ciphertext data sharing method; when the number of nodes participating in the calculation is 3, the calculation time required by the present invention is shortened by about three times compared with the traditional ciphertext data sharing method. Therefore, the multi-node joint calculation designed by the present invention can improve the key generation efficiency to a certain extent and has certain advantages in communication overhead.

[0224] As Figure 5 shown, when the number of nodes participating in the calculation is 1, as the number of attributes increases, the decryption time also increases with the increase in the proportion of policy attributes in the total attributes, while the key generation algorithm and encryption algorithm are not affected by the change in the proportion of policy attributes in the total attributes. Therefore, when the number of elements in the access control policy attribute set is large, the present invention has more advantages.

[0225] As Figure 6 、 Figure 7 and Figure 8 shown, as the number of user attributes increases, the calculation overheads of the present invention in the encryption stage, re-encryption stage, and decryption stage also increase, showing a linear growth relationship. Compared with the ciphertext cloud storage data sharing method, the present invention and the attribute proxy re-encryption data sharing method replace a large number of bilinear pairing operations with multiplication operations, so the generated calculation overhead is smaller. However, the present invention requires fewer bilinear pairings to be calculated compared with the attribute proxy re-encryption data sharing method. Therefore, the present invention has more advantages in calculation overhead.

[0226] The present invention uses Ganache to set up 4 nodes to simulate data flow operations such as key generation, distribution, and identity authentication, and conducts a concurrent anti-pressure test on key source query. The query performance test results are as Figure 9 shown. When the number of concurrent requests reaches 110, the response time of a single node is about 25s. Therefore, the present invention can provide a relatively rapid query service.

[0227] In addition, as Figure 10 shown, the present invention also tests the Gas consumed by executing the signature verification smart contract and the re-encryption result correctness verification smart contract on the chain. Among them, the Transaction Cost generated by a single node executing the signature verification smart contract is 1,091,397 Gas, and the Execution Cost is 965,801 Gas; the Transaction Cost generated by executing the re-encryption result correctness verification smart contract is 3,597,371 Gas, and the Execution Cost is 3,300,467 Gas, and the consumed Gas increases with the increase in the number of nodes participating in the verification.

[0228] The Gas consumption of the present invention using the transaction aggregation mechanism is shown in Table 1. As the number of Chunks included in each block increases, the total Gas consumption shows a downward trend, and the reduction rate exceeds 61% compared with the case where this mechanism is not designed. In addition, when considering the reduction in the system concurrency due to this mechanism, its impact becomes more obvious.

[0229] Table 1 Gas consumption at each stage of transaction aggregation

[0230]

[0231] The present invention performs distributed key management on the system master key based on threshold proxy re-encryption, while solving the problem of centralized key escrow, improving the efficiency of key generation, management, and distribution. It realizes verifiable re-encryption on the chain through the design of Sigma non-interactive zero-knowledge proof based on the Fiat-Shamir transformation, further ensuring the security of key management. To improve the efficiency and scalability of the blockchain network and reduce the Gas consumption on the chain, a transaction aggregation mechanism based on zk-SNARKs is designed. By collecting the transactions generated during the operation of the system, batch execution, aggregation, and generation of corresponding zero-knowledge proofs are carried out to prove the validity of the account state transfer. The results of the embodiments of the present invention show that the proposed solution can not only improve the efficiency of key generation and encryption / decryption, but also achieve the traceability and accountability of the encryption process to solve the problem of key abuse, provide a faster query response speed in high-concurrency scenarios, and significantly reduce the Gas consumption on the chain.

[0232] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment.

[0233] The above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.

Claims

1. A method for secure sharing and access control of ciphertext data based on zero-knowledge proof, characterized in that, Specifically, it includes the following steps: S1. The data owner takes the system security parameters, access control matrix, and attribute set as the input of the Setup function, outputs a key pair (PK, MSK), and sends the master key MSK to the proxy re-encryption node, where PK is the system public key; S2. Encrypt the data of the data owner; S3. The data owner inputs the private key of the data owner, the public key of the data user, the total number of fragments, and the threshold value, generates n re-encryption key fragments kFrag and sends them to the proxy re-encryption node; S4. The proxy re-encryption node uses the received legitimate re-encryption key fragment kFrag and the public key pk of the data owner A to create a random symmetric key ε K and uses ε K to encrypt the system master key MSK into a re-encryption ciphertext CT MSK Meanwhile, it outputs a capsule and a fragment cFrag of the capsule; S5, the public key pk of the input data owner A , the private key sk of the data user B and a set of t re-encrypted ciphertexts Let i denote the i-th in the set of re-encrypted ciphertexts. First, aggregate each cFrag i to calculate the symmetric key ε K , and then use ε K to decrypt the MSK from the re-encrypted ciphertext CT MSK ; where cFrag i denotes the i-th fragment of the capsule; S6. Key calculation; The specific process of the S6 key calculation stage is as follows: CptKey(PK, MSK, e, S) → {K, L, {h x}, E} Among them, {h x} represents the hash value of attribute x, K and L are components of the user attribute private key, and E is an intermediate parameter Input the system key pair (PK, MSK), and randomly select t, u ∈ Z p , gcd(e, u) = 1 indicates that e and u are relatively prime, and E = te, where E is the result after encrypting t; (K,L) = (g α g βt , g t ) Among them, K and L are components of the user attribute private key; S7. The data user inputs the attribute hash value and the user attribute set into the KeyGen function to calculate the user attribute private key SK; S8. Decrypt the ciphertext and establish a re-encryption verification mechanism and a transaction aggregation mechanism.

2. The method for secure sharing and access control of ciphertext data based on zero-knowledge proof according to claim 1, wherein, In S5, for each cFrag i perform aggregation and calculate the symmetric key ε K verify the correctness of the re-encryption result before that.

3. A ciphertext data security sharing and access control method based on zero-knowledge proof according to claim 1, characterized in that The specific process of the S2 encryption stage is as follows: S201. Randomly select integers \(s, y_2, \ldots, y\) n \(\in \mathbb{Z}\) N to form a column vector in the \(n\)-dimensional vector space for splitting the shared key and calculating the original ciphertext components ​ C = m·e(g,g) αsδ , C' = g sδ ; where Z N denotes a set of positive integers with N elements, e denotes a bilinear mapping, α and δ are random parameters, g is a generator, C′ and C are original ciphertext components, and m denotes the data plaintext; S202: Randomly select an integer r from the i-th row of the access control matrix M. i ∈Z N , respectively calculated and in is the i-th share obtained by splitting the secret s, ρ(i) represents the i-th attribute mapping, represents the vector represented by the i-th row of the matrix M, β is the randomly generated private key, let Then the generated ciphertext is CT = (C, C′, Ψ); Among them, Ψ, C i , D i , C are components of the ciphertext, is the encrypted part related to user attributes and policies, is the part encrypted according to the random value r i and policy adjustment, which is used for decryption when combined with the secret key of a user who complies with the policy. l represents the l-th row of the access control matrix.

4. A ciphertext data security sharing and access control method based on zero-knowledge proof according to claim 1, characterized in that, The specific steps of S3 are as follows: S301. Input the private key of the data owner, the public key of the data user, the total number of fragments, and the threshold value; S302. Select represents a group of order q, where id is the node identifier; and y are random parameters used to increase the analysis difficulty; S303. For each re-encryption key fragment kFrag, it is defined as where the parameter: rk is the key for proxy re-encryption, is an intermediate parameter, Q1 represents performing a power operation on the generator Q, and S1 and S2 are signatures on kFrag; S304. Define Q1 = Q rk , S2 = y - a·S1; where H l4 is a hash function; is an intermediate parameter, pk B represents the public key of node B, pk A represents the public key of node A; a is a random parameter used to increase the analysis difficulty; S305. Output the re-encryption key KF ∈ {kFrag}.

5. A ciphertext data security sharing and access control method based on zero-knowledge proof according to claim 1, characterized in that, The specific steps of S4 are as follows: S401. Input the re-encryption key fragment kFrag, public key pk A and the system master key MSK; S402. Select random parameters denotes a group of order q; the random parameters τ and u are used to increase the difficulty of ciphertext data analysis; S403. Calculate the composition parameters P, D, ξ of the capsule; S404. Create a random symmetric key ε K ; γ K is a random symmetric key generation function; S405. Create capsule = (P, D, ξ); S406. Use the symmetric key encryption ε for the system master key MSK K , and calculate the re-encrypted ciphertext CT MSK = ε K ·MSK; S407. Verify the validity of the capsule by checking whether the formula holds; represents blinding the generator g1, represents a publicly verifiable blind argument for P, where ξ is the blinding factor, represents a hash function; S408. If the formula holds, that is, the capsule is valid, then calculate the composition parameters P1 = P of the capsule fragment cFrag rk and D1 = D rk ; D rk 、P rk are the calculation results of the composition parameters P1 and D1, where rk is the key for proxy re-encryption; S409. Output fragments Capsule capsule=(P, D, ξ) and re-encrypted ciphertext CT MSK =ε K ·MSK.

6. The method for secure sharing and access control of ciphertext data based on zero-knowledge proof according to claim 1, characterized in that The specific steps of S5 are as follows: S501, the public key pk of the input data owner A , the private key sk of the data user B and a set of t re-encrypted ciphertexts S502. Define Z1 as the set of z x,i The set of represents each split sub-secret hash value; pk B represents the public key of node B, represents the public key of node A encrypted with a random number, id i represents the ID of the i-th node, and id represents the node identifier, represents the hash function; S503. For each z in the set Z1 x,i , calculate the sub-parameters after segmentation Among them, represents the product of t split sub-secret hash value shares, where t represents t elements, j represents starting from the j-th element, and z x,j represents the j-th split sub-secret hash value; S504. Calculate the symmetric key ε K Composition parameters of: P 1,i represents the i-th sub-secret value after splitting P1, D 1,i represents the i-th sub-secret value after splitting D1, D' represents the product of t sub-secrets after splitting D1, and P' represents the product of t sub-secrets after splitting P1; Constitute γ is a parameter of the random symmetric key generation function, represents a hash function, and is a variable used for temporary calculations inside the algorithm to prevent forgery, tampering, and deception during the key aggregation process; S505. Use the symmetric key ε K Decrypt the MSK from the re-encrypted ciphertext CT MSK ​ 7. A ciphertext data security sharing and access control method based on zero-knowledge proof according to claim 1, characterized in that, The specific process of decryption in S8 is as follows: Let the attribute set S satisfy the access structure (M, ρ); M is the access control matrix, and ρ is the attribute mapping function; Since I = {i: ρ(i) ∈ S}, let {ω i ∈ Z p | i ∈ I}, if {λ i} is a valid share, then where ω i is a set of recovery coefficients, Z p represents a group of order p; the data plaintext m is decrypted from the ciphertext through the following formula: where e is a bilinear pairing operation, C i , L, D i are components of the ciphertext, I represents the set of authorized attributes, ω i is the recovery coefficient, ρ(i) represents the mapping of the i-th attribute, and K ρ(i) represents the partial user attribute private key of ρ(i).

8. A ciphertext data security sharing and access control method based on zero-knowledge proof according to claim 1, characterized in that, The specific process of establishing a re-encryption verification mechanism in S8 is as follows: S801. The proxy re-encryption node inputs the capsule, capsule fragment cFrag, and re-encryption key fragment kFrag into the CreatNIZKP function. The CreatNIZKP function is defined to adopt the security and non-interactive characteristics of the Fiat-Shamir technology. Through this function, the proxy node can generate a publicly verifiable zero-knowledge proof π to ensure the correctness and privacy of the re-encryption process, and at the same time support efficient consensus verification in the blockchain environment; S802. Select a random number S803. Calculate the parameters for generating the zero-knowledge proof; S804. Calculate the hash value of the generated zero-knowledge proof; S805. Calculate the parameters for generating the zero-knowledge proof; S806. Output the zero-knowledge proof π.

9. A ciphertext data security sharing and access control method based on zero-knowledge proof according to claim 8, characterized in that, After the S806 outputs the zero-knowledge proof π, the proxy re-encryption node broadcasts the generated proof π to all nodes in the blockchain network and triggers the smart contract. Each node uses the VerifyNIZKP smart contract to perform consensus verification on each cFrag. The specific process is as follows: S807. All nodes in the network input the capsule, capsule fragment cFrag, and zero-knowledge proof π into the VerifyNIZKP smart contract; S808. Verify whether the signature (S1, S2) is correct. If it is correct, calculate the hash value; S809. Verify the correctness of cFrag; S810. Output verification result Result Verification .

10. A ciphertext data security sharing and access control method based on zero-knowledge proof according to claim 1, characterized in that, The transaction aggregation mechanism includes a Trading contract, a Processing contract, and Operator nodes; the Trading contract is used for collecting transactions and verifying the integrity of the collected transactions, and the Processing contract and Operator nodes are used for aggregating, executing, and submitting for verification the transactions collected in the Trading contract.