Subscription-based Data Security Transaction Method for Anti-Stress in Uncontrolled and Highly Competitive Environments
Through the Diffie-Hellman key exchange and security authentication encryption algorithm combined with the bulletin board and the pigeon cage communication mechanism, the security and privacy protection problems of data transactions in an uncontrolled and strong confrontation environment are solved, and reliable data transmission and transaction security are achieved under coercion.
Patent Information
- Application Number
- CN202411160817.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-22
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2044-08-22
AI Technical Summary
In an uncontrolled and strong confrontation environment, data sales are at risk of coercion, and existing technologies are difficult to achieve anonymous communication, privacy protection and coercion, resulting in insufficient security of data transactions.
The Diffie-Hellman key exchange function, security authentication encryption algorithm and key derivation function are used, combined with the bulletin board and the pigeon cage communication mechanism, and data transactions are used to use anonymous networks to complete demand matching through privacy set interception technology, and the anti-depression message sending algorithm is run under coercion situations.
It realizes security and privacy protection of data transactions in an uncontrolled and strong confrontation environment, ensuring that the data seller can reliably send subscribed data to the data buyer, resists the coercion of opponents, and protects the identity information of the transaction entity.
Smart Images

Figure CN119048082B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to data security transaction technology, and particularly to a coercion-resistant subscription-based data security transaction method in an uncontrolled and highly adversarial environment. Background Art
[0002] Data is a new type of production factor alongside land, labor, capital, and technology. Data transactions can promote the circulation, development, and utilization of data factors, and release the value of data factors at a deeper level. Currently, the three-layer data transaction of "data seller - third-party platform - data buyer" is one of the most popular data transaction architectures. In the three-layer data transaction architecture, data buyers and data sellers complete data transactions through the platform. When conducting subscription-based data transactions, data sellers in an uncontrolled and highly adversarial environment often face the risk of being coerced by adversaries. After an adversary attacks a data seller, the adversary masters the secret information of the coerced data seller, monitors the communication behavior of the coerced data seller, and requests the coerced data seller to send false data. Summary of the Invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a coercion-resistant subscription-based data security transaction method in an uncontrolled and highly adversarial environment, so as to achieve functions such as anonymous communication, privacy protection, and coercion resistance, and ensure the safe conduct of data transactions in an uncontrolled and highly adversarial environment.
[0004] The purpose of the present invention is achieved through the following technical solutions:
[0005] A coercion-resistant subscription-based data security transaction method in an uncontrolled and highly adversarial environment includes the following steps:
[0006] S1 System initialization stage: Initialize the system according to system parameters, and confirm the public parameter set of the system; select the Diffie-Hellman key exchange function, a secure authenticated encryption algorithm, and a key derivation function; the platform selects a public-private key pair for signature and maintains a bulletin board and a pigeonhole; platform users authenticate and register on the platform and select a short-term public-private key pair; platform users run a key initialization algorithm to perform key initialization operations;
[0007] S2 Credential issuance stage: The user selects a short-term signature public-private key pair, connects to the platform to complete authentication, and requests the platform to issue a credential; the platform determines whether the user authentication result passes. If it passes, the platform sends a blinded signature of the short-term signature public key to the user. Otherwise, the platform rejects this credential issuance operation; the user performs a blinding removal operation on the blinded credential to obtain a signature of the short-term signature public key and generates a one-time credential;
[0008] S3 Attribute Publishing Phase: The user blinds the data attributes to generate a set of tags, combines the short-term public key, the set of tags, and the data count generated in the initialization phase into a public record, and calculates the signature of the public record using the short-term private key generated in the initialization phase; The user combines the public record, the signature of the public record, the short-term signature public key, and the signature of the short-term signature public key into an attribute entry and uploads it to the platform's bulletin board;
[0009] S4 Requirement Publishing Phase: The user generates a set of requirements and blinds the elements of the set of requirements; The user calculates the overall signature of the blinded set of requirements and the user's short-term public key using the short-term signature private key, combines the blinded set of requirements, the short-term public key generated in the initialization phase, the overall signature, the short-term signature public key, and the signature of the short-term signature public key into a requirement entry, and uploads the requirement entry to the platform's bulletin board;
[0010] S5 Attribute Response Phase: The user on the platform retrieves the requirement entry on the bulletin board and determines whether the requirement entry corresponds to a legitimate platform. If it is legitimate, continue with the operation; Otherwise, retrieve the next requirement entry and repeat the determination operation again; The user enters the sending state and updates to obtain a new chain key; The user calculates the pigeonhole address of the corresponding buyer user, authenticates and encrypts the re-blinded set of requirements using the chain key, and sends the ciphertext to the pigeonhole address corresponding to the platform;
[0011] S6 Attribute Confirmation Phase: The user on the platform enters the receiving state and updates to obtain a new chain key; The user calculates the pigeonhole address of the corresponding data seller user and obtains the ciphertext of the re-blinded set of requirements at the corresponding pigeonhole address; The user decrypts and de-blinds the ciphertext of the re-blinded set of requirements using the symmetric key to obtain the blinded set of requirements and takes the intersection with the set of tags of the corresponding data seller user; If the number of intersections is equal to the number of required attributes, the user confirms that there is data that meets the requirements at the corresponding data seller user and obtains the index set of the data that can meet the requirements at the corresponding data seller user;
[0012] S7 Data Request Phase: The user on the platform adds the index set of the data that meets the requirements at the data seller user to the communication queue of the corresponding data seller user, runs the covert public-private key update algorithm to obtain a covert public-private key pair, and then runs the message sending algorithm;
[0013] S8 Data Sending Phase: The user on the platform runs the message receiving algorithm to receive the index set of data sent by the data buyer user and adds the corresponding data to the communication queue of the corresponding data buyer user;
[0014] S9 Data Receiving Phase: The user on the platform runs the message receiving algorithm to receive the data sent by the data seller user;
[0015] S10 Subscription Interaction Phase: The users of the platform confirm whether to conduct a subscription-based transaction with the corresponding data seller according to the reliability and usage of the data traded with the data seller users; the subscription-based data transaction buyer users add the data length to the communication queue of the corresponding subscription-based data transaction seller users; the subscription-based data transaction data sellers add a series of concealed public keys to be used to the communication queue of the corresponding subscription-based data transaction buyer users;
[0016] S11 Coercion Sending Phase: The coerced subscription-based data transaction seller users terminate the operation of the message sending algorithm; the coerced subscription-based data transaction seller users add the specified content required by the adversary to the communication queue of the corresponding subscription-based data transaction buyer users; the coerced subscription-based data transaction seller users put the data they want to send under the state of being coerced by the adversary into the data queue and run the anti-coercion message sending algorithm;
[0017] S12 Coercion Receiving Phase: The coerced subscription-based data transaction buyer users terminate the operation of the message sending algorithm and run the anti-coercion message receiving algorithm.
[0018] Furthermore, the system initialization phase specifically includes:
[0019] Step S101: Determine the system public parameter set according to the security parameters Among them, p is a prime number, is a cyclic group of order p, e: is a bilinear mapping, g1 is a generator of, H1: H2: H3: {0,1} * → {0,1} 8 is a secure hash function, H3 maps a string of any length to a string of one-byte length, mlen is the fixed length of the message, and l is the security parameter;
[0020] Step S102: Select to use the Diffie-Hellman key exchange function DH(sk,pk), the secure authenticated encryption scheme AE = {AE.enc, AE.dec} and the key derivation functions KDF1, KDF2; among them, the definition formula of the Diffie-Hellman key exchange function is: The encryption function of the authenticated encryption scheme is defined as: AE.enc(k,m), which is used to encrypt the message m with the key k to obtain the ciphertext c. The decryption function of the authenticated encryption scheme is defined as: AE.dec(k,c), which is used to decrypt the ciphertext c with the key k to obtain the message m. The length of the message m is a fixed value mlen; KDF1(in) is used to output key1 based on the input in, and KDF2(key,in) is used to output key1 and key2 based on the inputs key and in;
[0021] Step S103: The platform Completes the initialization operation according to the following steps: Uniformly and randomly selects the private key Calculates the public key The platform Provides a bulletin board BB and a pigeonhole ph;
[0022] Step S104: The platform The n users at Respectively complete the initialization operation, including: The user At Authenticates and registers; The user Uniformly and randomly selects a short-term private key The user Calculates the short-term public key User U i Generates the corresponding short-term public and private keys (pk i ,sk i ); The user Sends the short-term public key pk i To the platform The platform After receiving the short-term public key pk i , Publishes pk i To the bulletin board BB;
[0023] Step S105: The platform The n users at Respectively complete the key initialization operation, including:
[0024] The user Uniformly and randomly selects Calculates: The user Sends IK i ,EK i ,SPK i To the platform The platform After receiving IK i ,EK i ,SPK iAfter that, IK i , EK i , SPK i are published to the bulletin board BB;
[0025] Step S106: n users at the platform respectively run the root key initialization algorithm to obtain the root key of other users at the platform and the initial chain key where [1, n]\i represents the subset of [1, n] excluding the index value i;
[0026] The root key initialization algorithm includes: the user obtains IK of other users from the bulletin board BB of the platform j , EK j , SPK j ; calculate: DH1 (i,j) = DH(ik i , SPK j ), DH2 (i,j) = DH(ek i , IK j ), DH3 (i,j) = DH(ek i , SPK j ), rk0 (i,j) = KDF1(DH1 (i,j) || DH2 (i,j) || DH3 (i,j) ); Obtain the initial root key rk0 shared with (i,j) ; Calculate the DH initial key dh_k (i,j) = DH(sk i , pk j ); Run KDF2(rk0 (i,j) , dh_k (i,j) ) to obtain (rk (i,j) , ck (i,j) ), where rk (i,j) is the new root key; Run KDF1(ck (i,j) ) to obtain the initial chain key ck (i,j) .
[0027] Furthermore, the credential issuance stage is specifically that the platform n users at respectively obtain the platform at the beginning of a time period issued one-time vouchers: including:
[0028] Step S201: Uniformly and consistently select a short-term signature private key
[0029] Step S202: Calculate the short-term signature public key
[0030] Step S203: Generate the corresponding short-term signature public and private key pair (pk T (i) , sk T (i) );
[0031] Step S204: Connect to and complete the authentication, and request the platform to issue a voucher;
[0032] Step S205: Judge whether the authentication result passes. If it passes, continue the operation; otherwise, terminate the current voucher issuance operation;
[0033] Step S206: Uniformly and consistently select Calculate Send Ran T (i) to
[0034] Step S207: Calculate the blinded signature of the short-term signature public key Send C T (i) to
[0035] Step S208: Generate the signature of the short-term signature public key and the one-time voucher token T (i) =(sk T (i) , C Y (i)′ ).
[0036] Furthermore, the attribute release phase is specifically that n users at the platform n users at respectively publish the blinded data attributes to the platform on the bulletin board at
[0037] Step S301: The user respectively holds N i pieces of data For each piece of data the corresponding attribute set is uniformly and consistently select calculate the tag set TC i ={H1(j||(H2(attr k (i,j) ))) s )|j∈[1,N1],k∈[1,m (i,j)};
[0038] Step S302: The user generates a public record Rec i =(pk i ,TC i ,N i ), calculates the overall signature of Rec i generates an attribute entry ent =(Rec i ,σ i ,σ Rec (i) ,pk T (i) ,C T (i)′ ), and sends ent i to
[0039] Step S303: After receiving the attribute entry ent i , parse ent i into the form of ent i =(Rec i ,σ Rec (i) ,pk T (i) ,C T (i)′ ) and publish it on the bulletin board.
[0040] Furthermore, the requirement publishing stage is specifically that n users at the platform publish their requirements for data to including:
[0041] Step S401: generate a requirement set where mi is the number of elements in the demand set;
[0042] Step S402: Uniform selection calculate
[0043] Step S403: calculate and pk i Overall signature Generate query entries And ent i Send to
[0044] Step S404: Receive query entry ent i After that, ent i Parsed as in the form of and posted on the bulletin board.
[0045] Furthermore, the attribute response stage is specifically the platform n users at will be about The attribute response of the data requirement is published to the platform Above, including:
[0046] Step S501: Search for public query requests on the bulletin board
[0047] Step S502: The validity of the requirement items is determined by verifying the following two equations:
[0048]
[0049] If the above two equations hold and pk T (j) If it is the first occurrence, continue with the following operations; otherwise, retrieve the next requirement item and return to step S501 to continue execution;
[0050] Step S503: calculate And R (i,j) Fill to the length of mlen to get R (i,j) ';
[0051] Step S504: Enter the sending state and update the new chain key ck (i,j) ;
[0052] Step S505: Calculate the address addr (i,j) = H1('addr' || ck (i,j) )
[0053] Step S506: Calculate c (i,j) = AE.enc(ck (i,j) , R (i,j) '), and Establish an anonymous connection and request to place c (i,j) at the address addr corresponding to the pigeonhole ph (i,j) ;
[0054] Step S507: After receiving the anonymous request, place c (i,j) at the address addr corresponding to the pigeonhole ph (i,j) ;
[0055] Furthermore, the attribute confirmation phase is specifically that n users at the platform will respectively confirm whether the data attributes of other users at the platform meet the requirements, including:
[0056] Step S601: Enter the receiving state and update to obtain a new chain key ck (i,j) ;
[0057] Step S602: Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0058] Step S603: And Establish an anonymous connection and request the ciphertext c (i,j) at the address addr corresponding to the pigeonhole ph (i,j) ;
[0059] Step S604: After receiving the anonymous request, send c (i.j) at the address addr corresponding to the pigeonhole ph (i,j) to
[0060] Step S605: When receives c (i,j) then calculate R (i,j) ' = AE.dec(ck (i,j), c (i,j) ), and remove the padding of R (i,j) ' to obtain the original message R (i,j) ;
[0061] Step S606: For each piece of data j in the tag set TC 's attribute set d k (j) , calculate the number of intersection elements and obtain the data index set that meets the
[0062] Furthermore, the data request phase specifically includes:
[0063] Step S701: Add the index set to the corresponding communication queue queue (i,j) ;
[0064] Step S702: Run the stealth public-private key update algorithm to obtain the short-term stealth public-private key pair (sk c (i) , pk c (i) ), and then run the message sending algorithm;
[0065] The message sending algorithm includes:
[0066] Step A1: After waiting for time t c , if perform the following operations:
[0067] Enter the sending state and update to obtain a new chain key ck (i,j) ;
[0068] Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0069] Take out the first element e of queue (i,j) , pad e to the length of mlen to get e', and calculate c = AE.enc(ck (i,j) , e');
[0070] Delete e from queue (i,j) ;
[0071] Connect anonymously with and request to place c at the address addr corresponding to the pigeonhole ph (i,j)location;
[0072] Step A2: If perform the following operations:
[0073] If the short-term public-private key is updated or the hidden public-private key pair is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck (i,j) ; otherwise, run the hidden chain key update algorithm to obtain a new hidden chain key cck (i,j) ;
[0074] Calculate the address addr (i,j) = H1('addr' || cck (i,j) );
[0075] Generate a fake message e (dummy) , and fill e (dummy) to the length of mlen to get e (dummy)′ , and calculate c = AE.enc(cck (i,j) , e (dummy)′ );
[0076] Establish an anonymous connection with and request to place c at the address addr corresponding to the pigeonhole ph (i,j) location;
[0077] Step A3: Repeat steps A1 - A2 until offline.
[0078] Furthermore, the data sending phase specifically includes:
[0079] Step S801: Run the message receiving algorithm to receive the data request of the user corresponding to pk j and obtain the data index set ;
[0080] Step S802: Generate a data set and add the data set to the communication queue;
[0081] The message receiving algorithm includes:
[0082] Step B1: Enter the receiving state and update to obtain a new chain key ck (i,j) ;
[0083] Step B2: Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0084] Step B3: Establish an anonymous connection and request the ciphertext c at the address addr corresponding to the pigeonhole ph ; (i,j) at (i,j) ;
[0085] Step B4: When c is received (i,j) calculate e' = AE.dec(ck (i,j) , c (i,j) ), and remove the padding of e' to obtain the original message e;
[0086] Step B5: Repeat steps B1 - B4 until there is no content at the address corresponding to addr (i,j) .
[0087] Furthermore, the subscription interaction phase is specifically that n users at the platform confirm the data seller for subscription - based data transactions according to the reliability and usage of the data traded with the data seller user where φ represents the index set of the subscription - based data sellers corresponding to the user i including:
[0088] Step S1001: Generate a negotiation message where `subscription' is a string and is the byte length of the steganographic message;
[0089] Step S1002: Put tr (i,j) into the head of the corresponding communication queue queue (i,j) ;
[0090] Step S1003: Run the message receiving algorithm to receive the message at the corresponding i of pk ;
[0091] Step S1004: If the negotiation message tr (i,j) is obtained confirm that oneself is The subscription-based data trading seller, and put a series of hidden public keys to be used into the corresponding communication queue queue (i,j) at the head of the queue;
[0092] Step S1005: Run the message receiving algorithm to receive the hidden public key from ...
[0093] Furthermore, the coercion sending stage includes:
[0094] Step S1101: Terminate the operation of the message sending algorithm;
[0095] Step S1102: Add the specific content specified by the adversary to be sent to the head of the corresponding communication queue queue (i,j) ;
[0096] Step S1103: Put the data to be sent under the coercion of the adversary into the data queue d_queue (i,j) , and run the anti-coercion message sending algorithm;
[0097] The anti-coercion message sending algorithm includes:
[0098] Step C1: Uniformly and consistently select
[0099] Step C2: Take out the first element TM of d_queue (i,j) , delete TM from d_queue (i,j) , and calculate C (i,j) =(g1 r ,pk j r ·TM);
[0100] Step C3: Maintain a counter counter = 1 for C (i,j) , C (i,j) [counter] corresponds to the counter-th byte in C (i,j) ;
[0101] Step C4: After waiting for time t c , if perform the following operations:
[0102] Enter the sending state and update to obtain a new chain key ck (i,j) ;
[0103] Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0104] Fetch the first element e of queue (i,j) , pad e to the length of mlen to obtain e', and calculate c = AE.enc(ck (i,j) );
[0105] If H3(c) ≠ C (i,j) [counter], re-run c = AE.enc(k (i,j) ); Otherwise, update counter = counter + 1, delete e from queue (i,j) , and establish an anonymous connection, and request to place c at the address addr corresponding to pigeonhole ph (i,j) ;
[0106] Step C5: If perform the following operations:
[0107] If the short-term public-private key of is updated or (i,j) the concealed public-private key pair of (i,j) is updated, run the concealed root key update algorithm to obtain the new concealed chain key cck
[0108] Calculate the address addr (i,j) = H1('addr' || cck (i,j) );
[0109] Generate a fake message e (dummy) , and (dummy) pad e to the length of mlen to obtain e (dummy)′ , and calculate c = AE.enc(k (i,j) , e (dummy)′ );
[0110] If H3(c) ≠ C (i,j) [counter], re-run c = AE.enc(k (i,j) ); Otherwise, update counter = counter + 1, and establish an anonymous connection, and request to place c at the address addr corresponding to pigeonhole ph (i,j) ;
[0111] Step C6: Repeat steps C4 to C7 until Reset counter = 1 and complete the transmission operation of data TM in the current coercion state;
[0112] Step C7: Repeat steps C6 to C7 until Offline.
[0113] Furthermore, the coercion receiving phase includes:
[0114] Step S1201: Terminate the operation of the message receiving algorithm;
[0115] Step S1202: Run the anti-coercion message receiving algorithm to receive the data at the corresponding j corresponding to obtain data M (i,j) ;
[0116] The anti-coercion message receiving algorithm includes:
[0117] Step D1: Maintain the data counter counter = 1 for the anti-coercion state;
[0118] Step D2: Enter the receiving state and update to obtain a new chain key ck (i,j) ;
[0119] Step D3: Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0120] Step D4: Establish an anonymous connection with and request the ciphertext c at the address addr corresponding to the pigeonhole ph (i,j) ; (i,j) ;
[0121] Step D5: If the short-term public-private key of is updated or (i,j) the hidden public-private key pair of (i,j) is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck
[0122] Step D6: Calculate the address addr (i,j) = H1('addr' || cck(i,j) )
[0123] Step D7: Establish an anonymous connection and request the address addr corresponding to the pigeonhole ph and the ciphertext c at (i,j) ; (i,j) ;
[0124] Step D8: Repeat steps D2 to D7 and simultaneously perform the following steps;
[0125] Step D9: When the requested ciphertext is received, process the ciphertext according to the time when the ciphertext is placed in the pigeonhole ph until calculate C[counter] = H3(c (i,j) ), and update counter = counter + 1;
[0126] Step D10: Repeat steps D2 to D9 until offline.
[0127] The beneficial effects of the present invention are:
[0128] 1) By adopting the data steganography technology, the security data trading technology against coercion is broken through, which supports the data seller to send reliable subscription data to the data buyer under the coerced state in an uncontrolled and highly adversarial environment.
[0129] 2) The platform provides a bulletin board and a pigeonhole communication mechanism, uses an anonymous network for communication, completes anonymous data transactions, and protects the identity information of the entities conducting data transactions.
[0130] 3) By adopting the private set intersection technology, it is ensured that both the data buyer and the data seller can complete the demand matching operation without disclosing the data buyer's purchase requirements and the data seller's supply capacity, so that the data buyer cannot know any information about the seller's supply capacity except the matching result. BRIEF DESCRIPTION OF THE DRAWINGS
[0131] Figure 1 It is a schematic flowchart of a subscription data security trading method against coercion in an uncontrolled and highly adversarial environment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0132] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present invention.
[0133] Refer to Figure 1 , the present invention provides a technical solution:
[0134] A subscription-based data security trading method for anti-coercion in an uncontrolled and highly adversarial environment, comprising the following steps:
[0135] S1 System initialization stage: Initialize the system according to system parameters, and confirm the public parameter set of the system; Select the Diffie-Hellman key exchange function, a secure authenticated encryption algorithm, and a key derivation function; The platform selects the public and private key pairs for signature and maintains the bulletin board and the pigeonhole; The platform users authenticate and register on the platform and select short-term public and private key pairs; The platform users run the key initialization algorithm to perform the key initialization operation;
[0136] S2 Credential issuance stage: The user selects short-term signature public and private key pairs, connects to the platform to complete authentication, and requests the platform to issue credentials; The platform determines whether the user authentication result passes. If it passes, the platform sends the blinded signature of the short-term signature public key to the user. Otherwise, the platform rejects the current credential issuance operation; The user performs de-blinding operation on the blinded credential to obtain the signature of the short-term signature public key and generates a one-time credential;
[0137] S3 Attribute publishing stage: The user blinds the data attributes to generate a set of tags, synthesizes the short-term public key generated in the initialization stage, the set of tags, and the data quantity into a public record, and calculates the signature of the public record using the short-term private key generated in the initialization stage; The user synthesizes the public record, the signature of the public record, the short-term signature public key, and the signature of the short-term signature public key into an attribute entry and uploads it to the bulletin board of the platform;
[0138] S4 Requirement publishing stage: The user generates a set of requirements and performs a blinding operation on the elements of the set of requirements; The user calculates the overall signature of the blinded set of requirements and the user's short-term public key using the short-term signature private key, synthesizes the blinded set of requirements, the short-term public key generated in the initialization stage, the overall signature, the short-term signature public key, and the signature of the short-term signature public key into a requirement entry, and uploads the requirement entry to the bulletin board of the platform;
[0139] S5 Attribute response stage: The users on the platform retrieve the requirement entries on the bulletin board and determine whether the requirement entry corresponds to a legitimate platform. If it is legitimate, continue the operation; Otherwise, retrieve the next requirement entry and repeat the determination operation again; The user enters the sending state and updates to obtain a new chain key; The user calculates the pigeonhole address of the corresponding buyer user, authenticates and encrypts the re-blinded set of requirements using the chain key, and sends the ciphertext to the corresponding pigeonhole address of the platform;
[0140] S6 Attribute Confirmation Phase: The user of the platform enters the receiving state, updates to obtain a new chain key; the user calculates the pigeonhole address of the corresponding data seller user, and goes to the corresponding pigeonhole address to obtain the ciphertext of the re-blindening requirement set; the user uses the symmetric key to decrypt and de-blind the ciphertext of the re-blindening requirement set to obtain the blindening requirement set and takes the intersection with the label set of the corresponding data seller user; if the number of intersections is equal to the number of required attributes, the user confirms that there is data that meets the requirements at the corresponding data seller user, and obtains the index set of the data that can meet the requirements at the corresponding data seller user.
[0141] S7 Data Request Phase: The user of the platform adds the index set of the data that meets the requirements at the data seller user to the communication queue of the corresponding data seller user, runs the covert public-private key update algorithm to obtain a covert public-private key pair, and then runs the message sending algorithm.
[0142] S8 Data Sending Phase: The user of the platform runs the message receiving algorithm to receive the data index set sent by the data buyer user, and adds the corresponding data to the communication queue of the corresponding data buyer user.
[0143] S9 Data Receiving Phase: The user of the platform runs the message receiving algorithm to receive the data sent by the data seller user.
[0144] S10 Subscription Interaction Phase: The user of the platform confirms whether to conduct a subscription-based transaction with the corresponding data seller according to the reliability and usage of the data traded with the data seller user; the buyer user of the subscription-based data transaction adds the data length to the communication queue of the corresponding subscription-based data transaction seller user; the data seller of the subscription-based data transaction adds a series of covert public keys to be used to the communication queue of the corresponding subscription-based data transaction buyer user.
[0145] S11 Coercion Sending Phase: The coerced subscription-based data transaction seller user terminates the operation of the message sending algorithm; the coerced subscription-based data transaction seller user adds the specified content required by the adversary to the communication queue of the corresponding subscription-based data transaction buyer user; the coerced subscription-based data transaction seller user puts the data to be sent under the state of being coerced by the adversary into the data queue, and runs the anti-coercion message sending algorithm.
[0146] S12 Coercion Receiving Phase: The buyer user of the coerced subscription-based data transaction terminates the operation of the message sending algorithm and runs the anti-coercion message receiving algorithm.
[0147] In this embodiment, the system initialization phase specifically includes:
[0148] Step S101: Determine the system public parameter set according to the security parameter where p is a prime number is a cyclic group of order p, e: is a bilinear mapping, and g1 is a generator of, H1: H2: H3: {0, 1} * → {0, 1} 8 is a secure hash function. H3 maps a string of any length to a string of one-byte length. mlen is the fixed length of the message, and l is the security parameter;
[0149] Step S102: Select to use the Diffie-Hellman key exchange function DH(sk, pk), the secure authenticated encryption scheme AE = {AE.enc, AE.dec}, and the key derivation functions KDF1 and KDF2; among them, the definition formula of the Diffie-Hellman key exchange function is: The encryption function definition formula of the authenticated encryption scheme is: AE.enc(k, m), which is used to encrypt the message m with the key k to obtain the ciphertext c. The decryption function definition formula of the authenticated encryption scheme is: AE.dec(k, c), which is used to decrypt the ciphertext c with the key k to obtain the message m. The length of the message m is a fixed value mlen; KDF1(in) is used to output key1 based on the input in, and KDF2(key, in) is used to output key1 and key2 based on the inputs key and in;
[0150] Step S103: The platform completes the initialization operation as follows: Uniformly and randomly select the private key Calculate the public key The platform provides a bulletin board BB and a pigeonhole ph;
[0151] The pigeonhole is a hash table composed of key-value pairs. The key in the first column is the address index value, and the value in the second column is the message. When the buyer and seller communicate using the pigeonhole, they put the message into the entry corresponding to the address index value, and the entity that can calculate the same address index value can obtain the message from the corresponding entry.
[0152] Step S104: The n users at respectively complete the initialization operation, including: The user authenticates and registers at ; The user uniformly and randomly selects a short-term private key The user calculates the short-term public key The user generates the corresponding short-term public and private keys (pki ,sk i ); The user sends the short-term public key pk i to the platform The platform receives the short-term public key pk i and then publishes pk i to the bulletin board BB; It should be noted that the user at the platform has the attributes of both data buyer and data seller at the same time.
[0153] Step S105: The n users at the platform respectively complete the key initialization operation, including:
[0154] The user uniformly and consistently selects ik i ,ek i , and calculates: The user sends IK i ,EK i ,SPK i to the platform The platform receives IK i ,EK i ,SPK i and then publishes IK i ,EK i ,SPK i to the bulletin board BB;
[0155] Step S106: The n users at the platform respectively run the root key initialization algorithm to obtain the root key of other users at the platform and the initial chain key where [1,n]\i represents the subset of [1,n] excluding the index value i;
[0156] The root key initialization algorithm includes: The user obtains the IK of other users from the bulletin board BB of the platform j ,EK j ,SPK j ; and calculates: DH1 (i,j) =DH(ik i ,SPK j ), DH2(i,j) = DH(ek i , IK j );, DH3 (i,j) = DH(ek i , SPK j );, rk0 (i,j) = KDF1(DH1 (i,j) || DH2 (i,j) || DH3 (i,j) ); Obtain the initial root key rk0 shared with ; (i,j) Calculate the DH initial key dh_k (i,j) = DH(sk i , pk j ); Run KDF2(rk0 (i,j) , dh_k (i,j) ) to obtain (rk (i,j) , ck (i,j) ), where rk (i,j) is the new root key; Run KDF1(ck (i,j) ) to obtain the initial chain key ck (i,j) .
[0157] Furthermore, the credential issuance stage is specifically that n users at the platform obtain the one-time credentials issued by the platform respectively at the beginning of a period, including:
[0158] Step S201: Uniformly and consistently select the short-term signature private key
[0159] Step S202: Calculate the short-term signature public key
[0160] Step S203: Generate the corresponding short-term signature public-private key pair (pk T (i) , sk T (i) );
[0161] Step S204: Connect to and complete the authentication, and request the platform to issue the credential;
[0162] Step S205: Judge Whether the identity verification result is passed, if passed, continue the operation; otherwise, terminate the certificate issuance operation;
[0163] Step S206: Uniform selection calculate Ran T (i) Send to
[0164] Step S207: Calculate the blinded signature of the short-term signature public key C T (i) Send to
[0165] Step S208: Generate a signature for a short-lived public key and one-time credential tokens T (i) =(sk T (i) ,C T (i)′ ).
[0166] In this embodiment, the attribute publishing stage is specifically the platform n users at Publish the blinded data attributes to the platform separately The notice board at the office includes:
[0167] Step S301: User Hold N i Data Each piece of data The corresponding attribute set is Uniform selection Calculate the tag set TC i ={H1(j||(H2(attr k (i,j) )) s )|j∈[1,N1],k∈[1,m (i,j) ]};
[0168] Step S302: User Generate public record Rec i =(pk i ,TC i ,N i ), calculate Rec i Overall signature Generate attribute entry ent i=(Rec i ,σ Rec (i) ,pk T (i) ,C T (i)′ ), and ent i Send to
[0169] Step S303: Received attribute entry ent i After that, ent i Parsed as ent i =(Rec i ,σ Rec (i) ,pk T (i) ,C T (i)′ ) and posted on the bulletin board.
[0170] In this embodiment, the demand release stage is specifically the platform n users at Post the data request to Above, including:
[0171] Step S401: Generate a requirements set Among them, m i is the number of elements in the demand set;
[0172] Step S402: Uniform selection calculate
[0173] Step S403: calculate and pk i Overall signature Generate query entries And ent i Send to
[0174] Step S404: Receive query entry ent i After that, ent i Parsed as in the form of and posted on the bulletin board.
[0175] In this embodiment, the attribute response stage is specifically the platform n users at Publish the attribute response regarding the data requirements at to the platform, including:
[0176] Step S501: Retrieve the public query requirement entries on the bulletin board
[0177] Step S502: Judge the validity of the requirement entry by verifying the following two equations:
[0178]
[0179] If the above two equations hold and pk T (j) appears for the first time, continue with the following operations; otherwise, retrieve the next requirement entry and go back to Step S501 to continue;
[0180] Step S503: Calculate and fill R (i,j) to the length of mlen to obtain R (i,j) ';
[0181] Step S504: Enter the sending state and update to obtain a new chain key ck (i,j) ; In a specific embodiment, updating to obtain a new chain key ck (i,j) includes: judging whether the state has changed. If it has changed, run the state transition algorithm to obtain a new chain key ck (i,j) ; Otherwise, run the chain key update algorithm to obtain a new chain key ck (i,j) ;
[0182] Among them, the state transition algorithm includes:
[0183] Step a1: Run the short-term public-private key update algorithm between the sender and to obtain a new short-term public-private key pair;
[0184] Among them, the short-term public-private key update algorithm includes:
[0185] Step b1: Uniformly and consistently select the short-term private key
[0186] Step b2: Calculate the short-term public key
[0187] Step b3: Generate the corresponding short-term public and private keys (pk i ′, sk i ′);
[0188] Step b4: Send the short-term public key pk i ′ to
[0189] Step b5: After receiving the short-term public key pk i ′, publish pk i ′ on the bulletin board.
[0190] Step a2: Calculate the new DH key dh_k (i,j) = DH(sk i , pk j );
[0191] Step a3: Run KDF2(rk (i,j) , dh_k (i,j) ) to obtain (rk (i,j) , ck (i,j) ), where rk (i,j) is the new root key;
[0192] Step a4: Run KDF1(ck (i,j) ) to obtain the new chain key ck (i,j) .
[0193] The chain key update algorithm includes: Run KDF1(ck (i,j) ) to obtain the new chain key ck (i,j) .
[0194] Step S505: Calculate the address addr (i,j) = H1( ′ addr′||ck (i,j) );
[0195] Step S506: Calculate c (i,j) = AE.enc(ck (i,j) , R (i,j) ′), and Establish an anonymous connection and request to place c (i,j) at the address addr (i,j) corresponding to the pigeonhole ph;
[0196] Step S507: After receiving the anonymous request, c(i,j) Place it at the address addr corresponding to pigeonhole ph (i,j) .
[0197] In this embodiment, the attribute confirmation stage is specifically that n users at will respectively confirm whether the data attributes of other users at meet the requirements, including:
[0198] Step S601: Enter the receiving state and update to obtain a new chain key ck (i,j) ; In a specific embodiment, the step of updating to obtain a new chain key ck (i,j) is similar to step S504, including: judging whether the state has changed. If it has changed, run the state transition algorithm to obtain a new chain key ck (i,j) ; Otherwise, run the chain key update algorithm to obtain a new chain key ck (i,j) ;
[0199] Step S602: Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0200] Step S603: Establish an anonymous connection with and request the ciphertext c at the address addr corresponding to pigeonhole ph (i,j) ; (i,j)
[0201] Step S604: After receiving the anonymous request, send the c at the address addr corresponding to pigeonhole ph (i.j) to (i,j)
[0202] Step S605: When receives c (i,j) , calculate R (i,j) ' = AE.dec(ck (i,j) , c (i,j) ), and remove the padding of R (i,j) ' to obtain the original message R (i,j) ;
[0203] Step S606: For each data in the tag set TC j of the attribute set d k (j) , calculate the number of intersection elements and obtain the data index set that meets the requirements
[0204] In this embodiment, the data request phase specifically includes:
[0205] Step S701: Add the index set to the corresponding communication queue queue (i,j) ;
[0206] Step S702: Run the stealth public-private key update algorithm to obtain a short-term stealth public-private key pair (sk c (i) , pk c (i) ), and then run the message sending algorithm;
[0207] In a specific embodiment, the stealth public-private key update algorithm includes:
[0208] Step c1: After waiting for time t k , Uniformly and randomly select a short-term stealth private key [[ID=4,2]]
[0209] Step c2: Calculate the short-term stealth public key
[0210] Step c3: Send pk c (i) to
[0211] Step c4: After receiving the short-term stealth public key pk c (i) , publish pk c (i) to the bulletin board;
[0212] Step c5: Repeat steps c1 to c4 until u i goes offline.
[0213] Specifically, the message sending algorithm includes:
[0214] Step A1: After waiting for time t c , if perform the following operations:
[0215] Enter the sending state and update to obtain a new chain key ck (i,j) ; Similarly, update to obtain a new chain key ck (i,j) including: judging whether the state has changed. If it has changed, run the state transition algorithm to obtain a new chain key ck (i,j) ; Otherwise, run the chain key update algorithm to obtain a new chain key ck (i,j) ;
[0216] Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0217] Take out the first element e of queue (i,j) , pad e to the length of mlen to get e', and calculate c = AE.enc(ck (i,j) , e');
[0218] Delete e from queue (i,j) ;
[0219] Establish an anonymous connection with and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ;
[0220] Step A2: If perform the following operations:
[0221] If the short-term public-private key of is updated or the hidden public-private key pair of
[0222] is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck (i,j) ; Otherwise, run the hidden chain key update algorithm to obtain a new hidden chain key cck (i,j) ; The hidden root key update algorithm includes: Step d1: Calculate the new hidden DH key cdh_k (i,j) = DH(csk i , pk j ); Step d2: If this algorithm is run for the first time, run KDF2(rk0 (i,j) , cdh_k (i,j) ) to obtain (crk (i,j) , cck (i,j) ), where crk (i,j) is the new hidden root key; Otherwise, run KDF2(crk (i,j) , cdh_k(i,j) , cck (i,j) ); Step d3: u i Run KDF1(cck (i,j) ) to obtain a new covert chain key cck (i,j) .
[0223] The covert chain key update algorithm includes: Run KDF1(cck (i,j) ) to obtain a new covert chain key cck (i,j) .
[0224] Calculate the address addr (i,j) = H1('addr' || cck (i,j) );
[0225] Generate a fake message e (dummy) , and fill e (dummy) to the length of mlen to obtain e (dummy)′ , and calculate c = AE.enc(cck (i,j) , e (dummy)′ );
[0226] And Establish an anonymous connection and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ;
[0227] Step A3: Repeat steps A1 - A2 until Offline.
[0228] Furthermore, the data sending phase specifically includes:
[0229] Step S801: Run the message receiving algorithm to receive the data request from the user corresponding to pk j and obtain the data index set
[0230] Step S802: Generate a data set and add the data set to the communication queue;
[0231] The message receiving algorithm includes:
[0232] Step B1: Enter the receiving state and update to obtain a new chain key ck (i,j) ;
[0233] Step B2: Calculate address addr (i,j) = H1('addr' || ck (i,j) );
[0234] Step B3: Establish an anonymous connection and request the ciphertext c at the address addr corresponding to the pigeonhole ph ; (i,j) (i,j) ;
[0235] Step B4: When c is received (i,j) calculate e' = AE.dec(ck (i,j) , c (i,j) ), and remove the padding of e' to obtain the original message e;
[0236] Step B5: Repeat steps B1 - B4 until there is no content at the address corresponding to addr (i,j)
[0237] In this embodiment, the subscription interaction phase is specifically that n users at the platform confirm the data seller for subscription - based data trading according to the reliability and usage of the data traded with the data - selling user where φ represents the index set of the subscription - based data sellers corresponding to the users i including:
[0238] Step S1001: Generate a negotiation message tr (i,j) = (`subscription', e ct ), where `subscription' is a string and e ct is the byte length of the steganographic message;
[0239] Step S1002: Put tr (i,j) at the head of the corresponding communication queue queue (i,j) ;
[0240] Step S1003: Run the message - receiving algorithm to receive the message at U corresponding to pk i ; i
[0241] Step S1004: If the negotiation message tr (i,j) is obtained confirm that oneself is The subscription-based data trading seller, and put a series of concealed public keys to be used into the corresponding communication queue queue (i,j) at the head of the queue;
[0242] Step S1005: Run the message receiving algorithm to receive the concealed public key from ...
[0243] Furthermore, the coercion sending phase includes:
[0244] Step S1101: Terminate the operation of the message sending algorithm;
[0245] Step S1102: Add the specific content specified by the adversary to be sent to the head of the corresponding communication queue queue (i,j) ;
[0246] Step S1103: Put the data to be sent in the state of being coerced by the adversary into the data queue d_queue (i,j) , and run the anti-coercion message sending algorithm;
[0247] The anti-coercion message sending algorithm includes:
[0248] Step C1: Uniformly and consistently select
[0249] Step C2: Take out the first element TM of d_queue (i,j) , delete TM from d_queue (i,j) , and calculate C (i,j) =(g1 r , pk j r ·TM);
[0250] Step C3: Maintain a counter counter = 1 for C (i,j) , C (i,j) [counter] corresponds to the counter-th byte in C (i,j) ;
[0251] Step C4: Wait for time t c After that, if perform the following operations:
[0252] Enter the sending state and update to obtain a new chain key ck (i,j) ;
[0253] Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0254] Fetch the first element e of queue (i,j) , pad e to the length of mlen to get e', and calculate c = AE.enc(ck (i,j) );
[0255] If H3(c) ≠ C (i,j) [counter], re-run c = AE.enc(k (i,j) ); Otherwise, update counter = counter + 1, delete e from queue (i,j) , establish an anonymous connection with P, and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ;
[0256] Step C5: If Perform the following operations:
[0257] If the short-term public-private key of is updated or the hidden public-private key pair of (i,j) is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck (i,j) ; Otherwise, run the hidden chain key update algorithm to obtain a new hidden chain key cck
[0258] Calculate the address addr (i,j) = H1('addr' || cck (i,j) );
[0259] Generate a fake message e (dummy) , pad e (dummy) to the length of mlen to get e (dummy)′ , and calculate c = AE.enc(k (i,j) , e (dummy)′ );
[0260] If H3(c) ≠ C (i,j) [counter], re-run c = AE.enc(k (i,j) ); Otherwise, update counter = counter + 1, establish an anonymous connection with P, and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ;
[0261] Step C6: Repeat steps C4 to C7 until Reset counter = 1 and complete the transmission operation of data TM in the current coercion state;
[0262] Step C7: Repeat steps C6 to C7 until Go offline.
[0263] In this embodiment, the coercion receiving stage includes:
[0264] Step S1201: Terminate the operation of the message receiving algorithm;
[0265] Step S1202: Run the anti-coercion message receiving algorithm to receive the data at the corresponding j corresponding to obtain data M (i,j) ;
[0266] The anti-coercion message receiving algorithm includes:
[0267] Step D1: Maintain the data counter counter = 1 for the anti-coercion state;
[0268] Step D2: Enter the receiving state and update to obtain a new chain key ck (i,j) ;
[0269] Step D3: Calculate the address addr (i,j) = H1('addr' || ck (i,j) );
[0270] Step D4: Establish an anonymous connection with and request the ciphertext c at the address addr corresponding to the pigeonhole ph (i,j) ; (i,j) ;
[0271] Step D5: If the short-term public-private key of is updated or (i,j) the hidden public-private key pair of (i,j) is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck
[0272] Step D6: Calculate the address addr (i,j) = H1('addr' || cck (i,j) );
[0273] Step D7: Establish an anonymous connection and request the address addr corresponding to the pigeonhole ph and the ciphertext c at (i,j) ; (i,j) ;
[0274] Step D8: Repeat steps D2 to D7 and simultaneously perform the following steps;
[0275] Step D9: When the requested ciphertext is received, process the ciphertext according to the time when the ciphertext is placed in the pigeonhole ph until counter = l ct : Calculate C[counter] = H3(c (i,j) ) and update counter = counter + 1;
[0276] Step D10: Repeat steps D2 to D9 until offline.
[0277] In order to complete secure data transactions in the case where the subscription - type data seller is coerced, the present invention designs a mechanism for the subscription - type data seller to complete secure data transactions in an uncontrolled and highly adversarial environment by introducing data steganography technology. The real data content is hidden in the false data specified by the adversary to be sent. When the coerced data seller sends the false data specified by the adversary, it can inform the data buyer of the current coercion state and continue to transmit reliable subscription data, thus realizing a secure data transaction method that resists coercion.
[0278] In addition, in an uncontrolled and highly adversarial environment, information such as the identity information, purchasing power, and supply capacity of the two parties in a data transaction often does not want to be made public to avoid targeted attacks by the adversary. In scenarios such as when investigative journalists collect news materials on topics such as illegal crimes / folitical corruption and police collect evidence of crimes, where data transactions occur in an uncontrolled and highly adversarial environment, information such as the identity information, purchasing power, and supply capacity of the two parties in a data transaction becomes auxiliary information for the adversary to select attack targets. To solve the privacy problem of the purchasing needs and supply capacity of the two parties in a data transaction, the present invention introduces the private set intersection technology. When the buyer and seller match their demands, the data seller and the platform cannot obtain specific information about the data buyer's purchasing needs, and the data buyer can only know the intersection of the data seller's supply capacity and purchasing needs without obtaining any additional information about the data seller's supply capacity. To protect the identity information of the two parties in a data transaction, the present invention uses the bulletin board and pigeonhole communication mechanism provided by the platform to communicate through an anonymous network, realizing the privacy protection of the identity information of the two parties in a data transaction.
[0279] The present invention breaks through the subscription-based data security transaction technology for anti-coercion in an uncontrolled strong confrontation environment, realizes functions such as anonymous communication, privacy protection, and resistance to coercion, and can ensure the safe conduct of data transactions in an uncontrolled strong confrontation environment.
[0280] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications, and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. And the changes and alterations made by those skilled in the art that do not depart from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.
Claims
1. A subscription-based data security trading method for resisting coercion in an uncontrolled and highly adversarial environment, characterized in that: It includes the following steps: S1 System initialization phase: Initialize the system according to system parameters, and confirm the public parameter set of the system; Select the Diffie-Hellman key exchange function, secure authentication and encryption algorithms, and key derivation functions; The platform selects the public and private key pairs for signature, and maintains the bulletin board and pigeonhole; Platform users authenticate and register on the platform, and select short-term public and private key pairs; Platform users run the key initialization algorithm to perform key initialization operations; S2 Credential issuance phase: Users select short-term signature public and private key pairs, connect to the platform to complete authentication, and request the platform to issue credentials; The platform determines whether the user authentication result passes. If it passes, the platform sends the blinded signature of the short-term signature public key to the user. Otherwise, the platform rejects this credential issuance operation; Users perform de-blinding operations on the blinded credentials to obtain the signature of the short-term signature public key, and generate one-time credentials; S3 Attribute publishing phase: Users blind the data attributes to generate a set of tags, synthesize the short-term public key generated in the initialization phase, the set of tags, and the number of data into a public record, and calculate the signature of the public record using the short-term private key generated in the initialization phase; Users synthesize the public record, the signature of the public record, the short-term signature public key, and the signature of the short-term signature public key into an attribute entry, and upload it to the bulletin board of the platform; S4 Requirement publishing phase: Users generate a set of requirements and perform blinding operations on the elements of the set of requirements; Users calculate the overall signature of the blinded set of requirements and the user's short-term public key using the short-term signature private key, synthesize the blinded set of requirements, the short-term public key generated in the initialization phase, the overall signature, the short-term signature public key, and the signature of the short-term signature public key into a requirement entry, and upload the requirement entry to the bulletin board of the platform; S5 Attribute response phase: Users on the platform retrieve the requirement entry on the bulletin board and determine whether the requirement entry corresponds to a legal platform. If it is legal, continue the operation; Otherwise, retrieve the next requirement entry and repeat the judgment operation again; Users enter the sending state and update to obtain a new chain key; Users calculate the pigeonhole address of the corresponding buyer user, authenticate and encrypt the re-blinded set of requirements using the chain key pair, and send the ciphertext to the pigeonhole address corresponding to the platform; S6 Attribute confirmation phase: Users on the platform enter the receiving state and update to obtain a new chain key; Users calculate the pigeonhole address of the corresponding data seller user, and obtain the ciphertext of the re-blinded set of requirements at the corresponding pigeonhole address; Users decrypt and de-blind the ciphertext of the re-blinded set of requirements using the symmetric key to obtain the blinded set of requirements and intersect it with the set of tags of the corresponding data seller user; If the number of intersections is equal to the number of required attributes, the user confirms that there is data that meets the requirements at the corresponding data seller user, and obtains the index set of the data that can meet the requirements at the corresponding data seller user; S7 Data request phase: Users on the platform add the index set of the data that meets the requirements at the data seller user to the communication queue of the corresponding data seller user, run the covert public and private key update algorithm to obtain the covert public and private key pair, and then run the message sending algorithm; S8 Data Sending Phase: The user of the platform runs the message receiving algorithm to receive the data index set sent by the data buyer user, and adds the corresponding data to the communication queue of the corresponding data buyer user; S9 Data Receiving Phase: The user of the platform runs the message receiving algorithm to receive the data sent by the data seller user; S10 Subscription Interaction Phase: The user of the platform confirms whether to conduct a subscription-based transaction with the corresponding data seller according to the reliability and usage of the data traded with the data seller user; The subscription-based data transaction buyer user adds the data length to the communication queue of the corresponding subscription-based data transaction seller user; The subscription-based data transaction data seller adds a series of hidden public keys to be used to the communication queue of the corresponding subscription-based data transaction buyer user; S11 Coercion Sending Phase: The coerced subscription-based data transaction seller user terminates the operation of the message sending algorithm; The coerced subscription-based data transaction seller user adds the specified content required by the adversary to the communication queue of the corresponding subscription-based data transaction buyer user; The coerced subscription-based data transaction seller user puts the data to be sent under the state of being coerced by the adversary into the data queue and runs the anti-coercion message sending algorithm; S12 Coercion Receiving Phase: The buyer user of the coerced subscription-based data transaction terminates the operation of the message sending algorithm and runs the anti-coercion message receiving algorithm.
2. The anti-coercion subscription-based data security trading method in an uncontrolled strong adversarial environment according to claim 1, characterized in that: The system initialization phase specifically includes: Step S101: Determine the system public parameter set according to the security parameter where p is a prime number, is a cyclic group of order p, e: is a bilinear mapping, g1 is a generator of, H1: {0, 1} * → {0, 1} l , H2: H3: {0, 1} * → {0, 1} 8 is a secure hash function, H3 maps a string of any length to a string of one-byte length, mlen is the fixed length of the message, and l is the security parameter; Step S102: Select to use the Diffie-Hellman key exchange function DH(sk, pk), the secure authenticated encryption scheme AE = {AE.enc, AE.dec}, and the key derivation functions KDF1 and KDF2; among them, the definition formula of the Diffie-Hellman key exchange function is: The definition formula of the encryption function of the authenticated encryption scheme is: AE.enc(k, m), which is used to encrypt the message m with the key k to obtain the ciphertext c. The definition formula of the decryption function of the authenticated encryption scheme is: AE.dec(k, c), which is used to decrypt the ciphertext c with the key k to obtain the message m. The length of the message m is a fixed value mlen; KDF1(in) is used to output key1 based on the input in, and KDF2(key, in) is used to output key1 and key2 based on the inputs key and in; Step S103: Platform Complete the initialization operation according to the following steps: uniformly and consistently select a private key Calculate the public key Platform Provide a bulletin board BB and a pigeonhole ph; Step S104: Platform The n users at the each complete the initialization operation, including: the user authenticates and registers at the uniformly and consistently selects a short-term private key The user calculates the short-term public key The user generates the corresponding short-term public and private keys (pk i , sk i ); the user sends the short-term public key pk i to the platform The platform after receiving the short-term public key pk i posts pk i to the bulletin board BB; Step S105: Platform n users at respectively complete the key initialization operation, including: User Uniformly select Calculate: User Send IK i , EK i , SPK i To the platform Platform Receive IK i , EK i , SPK i After that, send IK i , EK i , SPK i Post to the bulletin board BB; Step S106: Platform n users at respectively run the root key initialization algorithm to obtain the other users at the platform root key of and the initial chain key where [1,n]\i represents the subset of the set [1,n] excluding the index value of i; The root key initialization algorithm includes: From the platform BB bulletin board to get other users IK j ,EK j ,SPK j ; Calculation: DH1 (i,j) =DH(ik i ,SPK j ), DH2 (i,j) =DH(ek i ,IK j ), DH3 (i,j) =DH(ek i ,SPK j ),rk0 (i,j) =KDF1(DH1 (i,j) ||DH2 (i,j) ||DH3 (i,j) ); Get with Shared initial root key rk0 (i,j) ; Calculate the DH initial key dh_k (i,j) =DH(sk i ,pk j ); Run KDF2(rk0 (i,j) ,dh_k (i,j) ) get (rk (i,j) ,ck (i,k) ), where rk (i,j) is the new root key; Run KDF1(ck (i,j) ) Get the initial chain key ck (i,j) .
3. The anti-coercion subscription-based data security trading method in an uncontrolled and highly adversarial environment according to claim 2, characterized in that: The specific voucher issuance stage is that n users at the platform respectively obtain the one-time vouchers issued by the platform at the beginning of a time period: including: at the beginning of a time period issued one-time vouchers: including: Step S201: Uniformly and consistently select a short-term signature private key Step S202: Calculate the short-term signature public key Step S203: Generate the corresponding short-term signature public and private key pair (pk T (i) , sk T (i) ); Step S204: Connect to complete authentication, and request the platform to issue a credential; Step S205: Determine whether the authentication result passes. If it passes, continue with the operation; otherwise, terminate the current credential issuance operation. Step S206: Select uniformly Calculate Send Ran T (i) To Step S207: Calculate the blinded signature of the short-term signature public key Send C Y (i) to Step S208: Generate a signature of the short-term signature public key and the one-time credential token T (i) =(sk T (i) , C T (i)′ ).
4. The method for anti-coercion subscription-based data security transaction in an uncontrolled strong adversarial environment according to claim 3, characterized in that: The attribute publishing phase is specifically that n users at respectively publish the blinded data attributes to the bulletin board at, including: Step S301: The user holds N i data pieces For each data piece the corresponding attribute set is uniformly and consistently select calculate the tag set TC i ={H1(j||(H2(attr k (i,j) )) s )|j∈[1,N1],k∈[1,m (i,j)}; Step S302: The user generates a public record Rec i =(pk i , TC i , N i ), and calculates the overall signature of Rec i Generate an attribute entry ent =(Rec i , σ i Rec (i) , pk T (i) , C T (i)′ ), and send ent i to Step S303: After receiving the attribute entry ent i , parse ent i into the form of ent i = (Rec i , σ Rec (i) , pk T (i) , C T (i)′ ), and post it on the bulletin board.
5. The method for anti-coercion subscription-based data security transactions in an uncontrolled and highly adversarial environment according to claim 4, wherein: The requirement release stage is specifically the platform where n users publish the requirements for data to including: Step S401: Generate a requirement set where m i is the number of elements in the requirement set; Step S402: Select uniformly Calculate Step S403: Calculate and pk i overall signature Generate a query entry and send ent i to Step S404: After receiving the query entry ent i ent is i parsed into and published on the bulletin board.
6. The anti-coercion subscription-based data security trading method in an uncontrolled and highly adversarial environment according to claim 5, wherein: The specific attribute response phase is that the platform n users at will publish the attribute responses regarding the data requirements at to the platform as follows: Step S501: Retrieve the publicly queried requirement entries on the bulletin board Step S502: Determine the validity of the requirement entry by verifying the following two equations: If the above two equations hold and pk T (j) appears for the first time, continue with the following operations; otherwise, retrieve the next requirement entry and return to step S501 to continue execution; Step S503: Calculate and fill R (i,j) to the length of mlen to obtain R (i,j) '; Step S504: Enter the sending state and update to obtain a new chain key ck (i,j) ; Step S505: Calculate the address addr (i,j) = H1('addr' || ck (i,j) ) Step S506: Calculate c (i,j) = AE.enc(ck (i,j) , R (i,j) '), and Establish an anonymous connection and request to place c (i,j) at the address addr corresponding to the pigeonhole ph (i,j) ; Step S507: After receiving an anonymous request, put c (i,j) at the address addr corresponding to the pigeonhole ph (i,j) .
7. The anti-coercion subscription-based data security transaction method in an uncontrolled strong confrontation environment according to claim 6, characterized in that: The specific attribute confirmation stage is that n users at will respectively confirm whether the data attributes of other users at meet the requirements, including: Step S601: Enter the receiving state and update to obtain a new chain key ck (i,j) ; Step S602: Calculate the address addr (i,j) = H1('addr' || ck (i,j) ); Step S603: Establish an anonymous connection and request the address addr corresponding to the pigeonhole ph and the ciphertext c at (i,j) ; (i,j) ; Step S604: After receiving an anonymous request, send the c at the address addr corresponding to the pigeonhole ph (i.j) to (i,j) send to Step S605: When receiving c (i,j) , calculate R (i,j) ′ = AE.dec(ck (i,j) , c (i,j) ), and remove the padding of R (i,j) ′ to obtain the original message R (i,j) ; Step S606: For each piece of data j in the tag set TC with the attribute set d k (j) , calculate the number of intersection elements and obtain the data index set that meets the 8. The anti-coercion subscription-based data security trading method in an uncontrolled strong adversarial environment according to claim 7, characterized in that: The data request phase specifically includes: Step S701: Add the index set to the corresponding communication queue queue (i,j) ; Step S702: Run the stealth public-private key update algorithm to obtain a short-term stealth public-private key pair (sk c (i) , pk c (i) ), and then run the message sending algorithm; The message sending algorithm includes: Step A1: waiting time t c after which, if perform the following operations: Enter the sending state and update to obtain a new chain key ck (i,j) ; Calculate the address addr (i,j) = H1('addr' || ck (i,j) ); Take out the queue (i,j) The first element e of, fill e to the length of mlen to get e′, calculate c = AE.enc(ck (i,j) , e′); Delete e from the queue (i,j) ; With Establish an anonymous connection and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ; Step A2: If Perform the following operations: If the short-term public-private key is updated or the hidden public-private key pair is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck (i,j) ; Otherwise, run the hidden chain key update algorithm to obtain a new hidden chain key cck (i,j) ; Calculate the address addr (i,j) = H1('addr' || cck (i,j) ) Generate a fake message e (dummy) , and fill e (dummy) to the length of mlen to obtain e (dummy)′ , and calculate c = AE.enc(cck (i,j) , e (dummy)′ ); and establish an anonymous connection and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ; Step A3: Repeat steps A1 to A2 until offline.
9. The anti-coercion subscription-based data security trading method in an uncontrolled and highly adversarial environment according to claim 8, characterized in that: The data sending phase specifically includes: Step S801: Run the message receiving algorithm to receive pk j The corresponding user The data request at, and obtain the data index set Step S802: Generate a data set and add the data set to the communication queue; The message receiving algorithm includes: Step B1: Enter the receiving state and update to obtain a new chain key ck (i,j) ; Step B2: Calculate the address addr (i,j) = H1('addr' || ck (i,j) ); Step B3: Establish an anonymous connection and request the address addr corresponding to the pigeonhole ph ; (i,j) for the ciphertext c at (i,j) ; Step B4: When receiving c (i,j) , calculate e' = AE.dec(ck (i,j) , c (i,j) ), and remove the padding of e' to obtain the original message e; Step B5: Repeat steps B1 - B4 until (i,j) there is no content at the corresponding address.
10. The anti-coercion subscription-based data security trading method in an uncontrolled and highly adversarial environment according to claim 9, wherein: The specific subscription interaction stage is as follows: the platform n users at Based on the reliability and usage of the data traded with the data seller users, confirm the data sellers for subscription-based data transactions where φ i represents the user corresponding index set of subscription-based data sellers, including: Step S1001: Generate a negotiation message tr (i,j) = (`subscription′, l ct ), where `subscription′ is a string and l ct is the byte length of the steganographic message; Step S1002: Put tr (i,j) into the head of the corresponding communication queue queue (i,j) ; Step S1003: Run the message receiving algorithm to receive pk i corresponding message at Step S1004: If the negotiation message tr is obtained (i,j) , confirm that oneself is the subscription-based data trading seller, and place a series of hidden public keys to be used at the head of the corresponding communication queue queue (i,j) ; Step S1005: Run the message receiving algorithm to receive the concealed public key from 11. The anti-coercion subscription-based data security trading method in an uncontrolled and highly adversarial environment according to claim 10, characterized in that: The coercion sending phase includes: Step S1101: Terminate the running of the message sending algorithm; Step S1102: Add the specific content specified by the adversary to be sent to the head of the corresponding communication queue queue (i,j) ; Step S1103: Put the data to be sent under the state of being coerced by the adversary into the data queue d_queue (i,j) , and run the anti-coercion message sending algorithm; The anti-coercion message sending algorithm includes: Step C1: Select uniformly Step C2: Take out the first element TM of d_queue (i,j) , delete TM from d_queue (i,j) , and calculate C (i,j) = (g1 r , pk j r ·TM); Step C3: Maintain a counter counter = 1 for C (i,j) where [counter] corresponds to the counter-th byte in C (i,j) [counter] corresponds to the counter-th byte in C (i,j) ; Step C4: waiting time t c after, if perform the following operations: Enter the sending state and update to obtain a new chain key ck (i,j) ; Calculate address addr (i,j) = H1('addr' || ck (i,j) ); Take out the queue (i,j) The first element e of, fill e to the length of mlen to get e′, calculate c = AE.enc(ck (i,j) , e′); If H3(c) ≠ C (i,j) [counter], re-run c = AE.enc(k (i,j) , e′); otherwise, update counter = counter + 1, delete e from queue (i,j) and establish an anonymous connection, and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ; Step C5: If perform the following operations: If the short-term public-private key is updated or the hidden public-private key pair is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck (i,j) ; otherwise, run the hidden chain key update algorithm to obtain a new hidden chain key cck (i,j) ; Calculate the address addr (i,j) = H1('addr' || cck (i,j) ) Generate a fake message e (dummy) , and pad e (dummy) to the length of mlen to obtain e (dummy)′ . Calculate c = AE.enc(k (i,j) , e (dummy)′ ); If h3(c) ≠ C (i,j) [counter], re-run c = AE.enc(k (i,j) , e′); otherwise, update counter = counter + 1, and establish an anonymous connection and request to place c at the address addr corresponding to the pigeonhole ph (i,j) ; Step C6: Repeat steps C4 to C7 until Reset counter = 1 and complete the transmission operation of data TM in the current stress state; Step C7: Repeat steps C6 to C7 until offline.
12. The method for anti-coercion subscription-based data security transaction in an uncontrolled strong confrontation environment according to claim 11, wherein: The coercion receiving phase includes: Step S1201: Terminate the operation of the message receiving algorithm; Step S1202: Run the anti-stress message receiving algorithm to receive pk j corresponding data at to obtain data M (i,j) ; The anti-coercion message receiving algorithm includes: Step D1: Maintain a data counter counter = 1 in the stress-resistant state; Step D2: Enter the receiving state and update to obtain a new chain key ck (i,j) ; Step D3: Calculate the address addr (i,j) = H1('addr' || ck (i,j) ); Step D4: Establish an anonymous connection with to request the address addr corresponding to the pigeonhole ph (i,j) and the ciphertext c at (i,j) ; Step D5: If the short-term public-private key is updated or the hidden public-private key pair is updated, run the hidden root key update algorithm to obtain a new hidden chain key cck (i,j) ; Otherwise, run the hidden chain key update algorithm to obtain a new hidden chain key cck (i,j) ; Step D6: Calculate the address addr (i,j) = H1('addr' || cck (i,j) ); Step D7: Establish an anonymous connection and request the address addr corresponding to the pigeonhole ph and the ciphertext c at (i,j) ; (i,j) ; Step D8: Repeat steps D2 to D7 and simultaneously perform the following steps; Step D9: When After receiving the requested ciphertext, process the ciphertext according to the time when the ciphertext is placed in the pigeonhole ph until counter = l ct : Calculate C[counter] = H3(c (i,j) ), and update counter = counter + 1; Step D10: Repeat steps D2 to D9 until offline.
Citation Information
Patent Citations
Data security transaction method and system based on block chain and attribute encryption
CN115082055A
Cloud-based multi-party data intra-field secure transaction method
CN118229285A