A reliable and fair attribute encryption outsourcing decryption method based on smart contracts

By uploading ciphertext and conversion keys to smart contracts in segments and combining them with a pay-as-you-go model, the efficiency and fairness issues of outsourced attribute encryption and decryption on mobile devices are solved, reliable decryption is achieved in a smart contract environment, and the fairness of the decryption cloud server and the reliability of users are ensured.

CN119420471BActive Publication Date: 2025-09-26HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411257462.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-09
Publication Date
2025-09-26
Estimated Expiration
2044-09-09

AI Technical Summary

Technical Problem

Existing attribute encryption outsourcing decryption methods cannot efficiently decrypt ciphertext on mobile devices, and cannot guarantee the fairness and reliability of the decryption cloud server. In particular, it is difficult to achieve effective decryption transactions under the gas limit in the smart contract environment.

Method used

The ciphertext and conversion key are uploaded to the smart contract in segments, and the smart contract performs calculations and outputs the converted ciphertext. A pay-as-you-go model is adopted to ensure the fairness and reliability of the decryption cloud server. The master key and public parameters are generated by a trusted authority, and the key encapsulation mechanism is combined to achieve verifiability and defensibility.

Benefits of technology

It achieves efficient decryption under the gasLimit restriction, avoids redundant information checking, ensures the fairness of the decryption cloud server and the reliability of users, and ensures the reasonable distribution of computing power through the pay-as-you-go model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420471B_ABST
    Figure CN119420471B_ABST
Patent Text Reader

Abstract

The present invention discloses a reliable and fair attribute encryption outsourcing decryption method based on smart contracts, comprising the following steps: a master key and public parameters are output by a trusted authority; the trusted authority then calculates and outputs a private key; a sender obtains a ciphertext and transmits it to a storage cloud server; the sender obtains a conversion key and a corresponding retrieval key; the sender obtains a set W, the storage cloud server sends the ciphertext to the smart contract in segments, and the sender sends the conversion key and the set W to the smart contract in segments; a node calculates and outputs a meta-element, the node issues a transaction, uploads the meta-element to the smart contract, and the smart contract calculates and outputs a conversion ciphertext; the sender obtains the encapsulated key through the public parameters, the conversion ciphertext and the retrieval key; the present invention does not introduce redundant information, thus avoiding placing an additional burden on the decryption cloud server and the user to check the validity of the converted ciphertext.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of OABE technology, and in particular to a reliable and fair attribute encryption outsourcing decryption method based on smart contracts. Background Art

[0002] With the development of cloud computing, more and more individuals and businesses are turning to outsourcing their data to cloud servers, which offer vast storage and computing capabilities. Security is one of the main obstacles hindering the widespread deployment of cloud computing. Encryption is a fundamental method for protecting data confidentiality, and attribute-based encryption (ABE) offers a promising approach for providing flexible access control to outsourced encrypted data.

[0003] In attribute-based encryption systems, user data is encrypted using an access policy or attribute set, and the user's private key is generated under the attribute set or access policy. The ciphertext can be decrypted using the private key if and only if the attribute set satisfies the access policy.

[0004] However, one of the main drawbacks of attribute-based encryption is the complex decryption cost, which is proportional to the size of the access policy. This limitation makes attribute-based encryption schemes infeasible for mobile application scenarios where resource-constrained mobile devices (e.g., smartphones) are used to retrieve data from encrypted ciphertext stored in the cloud.

[0005] This problem can be addressed by outsourcing the decryption task to a cloud server. While attribute-encrypted outsourced decryption methods enable mobile devices to efficiently decrypt ciphertext, they cannot prevent a malicious decryption cloud server from returning an incorrectly transformed ciphertext. The decryption cloud server has a strong financial incentive to return an incorrect result because decryption consumes computing resources. The decryption cloud server can simply return a randomly transformed ciphertext to conserve computing resources. However, many current attribute-encrypted outsourced decryption methods cannot guarantee fairness between the decryption cloud server and the data owner. Therefore, a secure, fair, and trustworthy attribute-encrypted outsourced decryption method is needed.

[0006] Intuitively, the current OABE solution can be directly adapted by replacing the decryption cloud server with a smart contract. Unfortunately, due to the special properties of smart contracts, this simple approach is difficult to implement. The main challenges are as follows:

[0007] The first challenge is gasLimit. To protect the system from resource consumption attacks caused by complex transactions, each transaction that calls a smart contract function is subject to a gas consumption cap called gasLimit. Each operation in the call, including sending and storing data and performing calculations, will consume a set amount of gas. Under this limit, the storage and computation steps of a given transaction are relatively limited. Therefore, since the size of ABE ciphertext and conversion key varies with the access structure (i.e., the attribute set), in order to avoid exceeding the gas limit, we divide the ABE ciphertext and conversion key into small pieces. By dividing the ABE ciphertext and conversion key into several blocks and uploading them to the smart contract with enough transactions, the gas consumed by each transaction will be less than the gasLimit. Summary of the Invention

[0008] The purpose of the present invention is to provide a reliable and fair attribute encryption and decryption outsourcing method based on smart contracts to overcome the shortcomings of the existing technology.

[0009] To achieve the above object, the present invention provides the following technical solutions:

[0010] This application discloses a reliable and fair attribute encryption and decryption outsourcing method based on smart contracts, including a sender, nodes in a network, smart contracts, a storage cloud server, and a trusted authority, characterized in that the method comprises the following steps:

[0011] S1: The sender sets the initial state, obtains the general attribute description, and outputs the master key and public parameters through a trusted authority;

[0012] S2: The sender obtains the attribute set, inputs the master key, public parameters, and attribute set, and then executes it through a trusted authority and outputs the private key;

[0013] S3: The sender defines an access mechanism using a set of attributes, obtains the ciphertext using public parameters, encapsulated keys, and access structures, and transmits it to the storage cloud server.

[0014] S4: The sender inputs the public parameters and private key to obtain the conversion key and the corresponding retrieval key;

[0015] S5: The sender obtains the set W, the storage cloud server sends the ciphertext to the smart contract in segments, and the sender sends the conversion key and set W to the smart contract in segments;

[0016] S6: Nodes in the network obtain public parameters, ciphertext, and conversion keys and calculate and output meta-elements; nodes in the network issue transactions, upload meta-elements to the smart contract, and the smart contract calculates and outputs the conversion ciphertext;

[0017] S7: The sender obtains the encapsulated key through the public parameters, the converted ciphertext, and the retrieved key.

[0018] Preferably, step S1 includes the following sub-steps:

[0019] S11: The trusted authority includes a public key generator, which obtains a prime-order cyclic multigroup and a generator of the cyclic multigroup, generates a bilinear pairing parameter, and outputs the bilinear pairing parameter;

[0020] S12: The public key generator initializes a hash function to map attributes to elements in the cyclic multigroup;

[0021] S13: Get a random element a from the integer field;

[0022] S14: The public key generator calculates the master key and public parameters and outputs them.

[0023] Preferably, step S2 includes the following sub-steps:

[0024] S21: The sender inputs the attribute set and the master key to the public key generator;

[0025] S22: The public key generator obtains a random element s from the non-zero elements of the integer field;

[0026] S23: The public key generator calculates the private key through the generator of the prime-order cyclic multigroup, the random element a, the random element s, the attribute set and the hash function, and outputs it.

[0027] Preferably, step S3 includes the following sub-steps:

[0028] S31: The sender defines an access structure through the attribute set and inputs the key and access structure into the smart contract, where the access structure is a row-column matrix M, and the matrix form is ;

[0029] S32: Smart contract obtains random vector ;

[0030] S33: According to the row and column matrix of the access structure, let , for the i The attributes of the row are obtained by combining random vector calculation ,in is the matrix M's i OK;

[0031] S34: According to the row and column matrix of the access structure, for , select several from the integer domain , the smart contract obtains the ciphertext through calculation and outputs it.

[0032] Preferably, step S4 includes the following sub-steps:

[0033] S41: The sender enters the private key into the smart contract;

[0034] S42: The smart contract selects a random element from the non-zero integer field ;

[0035] S43: Smart Contracts through Random Elements Calculate and output the conversion key and the corresponding retrieval key.

[0036] Preferably, step S5 includes the following sub-steps:

[0037] S51: The sender obtains the collection , the set W satisfies ,in is a collection , where the attribute set Satisfy access structure ;

[0038] S52: Divide the ciphertext into n' parts, divide the conversion key into n parts, divide the set W into n'' parts, and send each part separately to the smart contract

[0039] S53: The smart contract obtains n'' sets of sets W respectively, and sums up each set of sets W. After all sets of sets W are obtained, it enters S54;

[0040] S54: The smart contract obtains n conversion keys and sums up each conversion key. After all the conversion keys are obtained, it enters S55.

[0041] S55: The smart contract obtains n' ciphertexts and sums up each ciphertext. After all ciphertexts are obtained, it enters S6.

[0042] Preferably, step S6 includes the following sub-steps:

[0043] S61: The node performs calculations and outputs meta-elements of the converted ciphertext ;

[0044] S62: Node calls transaction to pass meta element Send to the smart contract;

[0045] S63: Smart Contract Acquisition Elements , when all meta elements When all are uploaded to the smart contract, the ciphertext is converted and output.

[0046] Preferably, step S7 includes the following sub-steps:

[0047] S71: The sender inputs public parameters, converts ciphertext and retrieves the key;

[0048] S72: The smart contract obtains public parameters, converts ciphertext, retrieves the key, and outputs the key;

[0049] S73: The sender inputs the converted ciphertext and the recovery key;

[0050] S74: The smart contract obtains the converted ciphertext and the recovery key and outputs data T and the key, where T is all meta-elements The sum of .

[0051] The present application also discloses a reliable and fair attribute encryption outsourcing decryption device based on smart contracts, including a memory and one or more processors, wherein the memory stores executable code, and when the one or more processors execute the executable code, they are used to implement any of the above-mentioned reliable and fair attribute encryption outsourcing decryption methods based on smart contracts.

[0052] The present application also discloses a computer-readable storage medium on which a program is stored. When the program is executed by a processor, it implements any of the above-mentioned reliable and fair attribute encryption and decryption outsourcing methods based on smart contracts.

[0053] Beneficial effects of the present invention:

[0054] (1) The present invention does not introduce redundant information, thus avoiding the additional burden on the decryption cloud server and the user to check the validity of the converted ciphertext;

[0055] (2) The present invention achieves verifiability and defensibility, which allows users to discover improper behavior of the decryption cloud server and prevent malicious accusations from the decryption cloud server;

[0056] (3) The present invention works in a pay-as-you-go model, ensuring that the decryption cloud server is rewarded only when it returns the correctly converted ciphertext;

[0057] (4) The present invention divides large-scale ciphertext data into multiple meta-computation transactions, thereby ensuring that the gas amount of a single transaction is low and the verification calculation amount is small, thereby solving the verifier's dilemma problem.

[0058] The features and advantages of the present invention will be described in detail through embodiments with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 It is a schematic diagram of a reliable and fair attribute encryption and decryption outsourcing method based on smart contracts of the present invention;

[0060] Figure 2 This is a schematic diagram of the structure of a reliable and fair attribute encryption and decryption outsourcing device based on smart contracts in the present invention;

[0061] Figure 3 This is a flowchart of the steps of a reliable and fair attribute encryption and decryption outsourcing method based on smart contracts in the present invention. DETAILED DESCRIPTION

[0062] To make the objectives, technical solutions, and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and examples. However, it should be understood that the specific embodiments described herein are merely illustrative of the present invention and are not intended to limit the scope of the present invention. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the present invention.

[0063] See Figure 1 、 3 The present invention provides a reliable and fair attribute encryption and decryption outsourcing method based on smart contracts. In this work, we propose for the first time a reliable and fair attribute-based encryption and outsourcing decryption (OABE) scheme based on smart contracts. In our scheme, no additional redundant information is required between the original ciphertext and the converted ciphertext, making our scheme more efficient than previous attribute encryption and decryption outsourcing methods. At the same time, the scheme is verifiable and defensible. Finally, the scheme adopts a pay-as-you-go model to achieve fairness between the decryption cloud server and the mobile device. The following is the specific algorithm of the present invention:

[0064] Setup(λ,U). The setup algorithm is executed by a trusted authority. When it inputs a security parameter λ and a general attribute description U, it outputs a master key msk and public public parameters PP.

[0065] KeyGen(PP, msk, The KeyGen algorithm is also executed by a trusted authority. , output the private key sk.

[0066] Encrypt(PP, K, The sender executes the encryption algorithm to generate attribute encrypted ciphertext, and then outsources it to the storage cloud server. Input public parameters PP, a package key K and an access structure As input, output ciphertext CT.

[0067] (PP, sk). The algorithm is executed by the data owner equipped with a mobile device. When inputting the public parameters PP and his private key sk, it outputs the transformation key TK and the corresponding retrieval key RK.

[0068] (PP, CT, TK). The algorithm is executed by nodes in the network. When the public parameter PP, ciphertext CT and conversion key TK are input, the node calculates the meta-element of the converted ciphertext CT , and issue a transaction to convert the meta element Upload to the smart contract. Once all metadata segments are uploaded, the smart contract calculates the transformed ciphertext CT'.

[0069] (PP, CT' , RK). The algorithm is executed locally by the data owner. When the public parameter PP, the transformed ciphertext CT' and the retrieval key RK are input, the encapsulated key K is output.

[0070] In our scheme, we adopt the concept of key encapsulation mechanism (KEM), in which the symmetric key K is encrypted using attribute-based encryption, and the plaintext under the symmetric key K is encrypted using a symmetric key encryption algorithm (e.g., AES). In our architecture, the data owner retrieves the symmetric key K from the KEM ciphertext using the OABE technique. The data owner then downloads the symmetric key encrypted ciphertext from the storage cloud server and decrypts the ciphertext using the symmetric key k. In this paper, we only consider the OABE part. Our construction is based on Green et al.'s CP-ABE and outsourced decryption scheme. We first present a smart contract-based outsourced decryption method and an improved attribute-based encryption scheme, and then give a specific smart contract protocol for the outsourced decryption CP-ABE scheme. The outsourced decryption method CP-ABE we propose is as follows.

[0071] .

[0072] λ refers to the security level of the selected password, for example, the number of bits in the key. U is a holistic summary of the subsequent series of parameters, and is also the sum of the bilinear pairing parameters, hash function, and other parameters in the description.

[0073] Public Key Generator (PKG) generates bilinear pairing parameters ,in is a prime order Cyclic multigroup Generator. PKG initializes a hash function , map the attributes to Then it selects a random element Finally, it sets the master key to and public parameters .

[0074] .

[0075] Enter the master key and a property set , PKG selects a random element and calculate . Output private key .

[0076]

[0077] Enter the symmetric key to be encapsulated and access structures , where M is matrix, Will Each row of is associated with an attribute. The algorithm selects a random vector .for ,calculate ,in yes No. OK. Then it selects , and calculate the ciphertext ,in

[0078]

[0079]

[0080] .

[0081] Enter a private key , the algorithm selects a random element And set in .

[0082] .

[0083] When entering ciphertext and conversion keys The data owner first finds a collection Make ,in is a collection if satisfy , and if Dissatisfied The data owner establishes a smart contract and then , convert the key and Divide into n parts and send each part to the smart contract through transactions so that each transaction fee does not exceed the gasLimit.

[0084] We use the attribute-based encryption (ABE) encryption strategy, which treats each line of the ciphertext as an attribute. All i satisfy the access policy and need to satisfy . And the subsequent calculations also need to use W As input for outsourced decryption.

[0085] .

[0086] implement , which is defined as the output element Next, the meta result is sent by issuing a transaction that calls the smart contract Sent to the smart contract. When all are uploaded to the smart contract, the state of the smart contract is set to meta-computation, which means that the data owner can retrieve the plaintext with these meta elements. Finally, the converted ciphertext is set to .

[0087] .

[0088] The algorithm is executed locally by the data owner. Input public parameters , a converted ciphertext and a retrieval key , output the encapsulated key . Input the converted ciphertext and a recovery key , data owner calculation .

[0089] Init: Set state := INIT and execute the above , , and Get public parameters , ciphertext and conversion keys . And set .

[0090] Create: Upon receiving a of ("create", $deposit, $reward, )back,

[0091] 1. Check if state = INIT,

[0092] 2. Check if $deposit ≥ $reward,

[0093] 3. Check if balance[O]>$deposit,

[0094] 4.balance[O] := balance[O]- $deposit,

[0095] 5. Set state := CREATED.

[0096] UploadTK: Upon receipt of ("uploadTK", , )back, is uploaded to the contract. Note that Need to be divided into Upload a copy. If = 1, then it means this is The first and ,otherwise >1, = .

[0097] 1. Check if state = CREATED,

[0098] 2. Check if msg.sender = ,

[0099] 3. Judgment = 1, if = 1, add ,

[0100] 4. For each ,Add to , and set ,

[0101] 5. Determine whether , if true, set state := TK_UPLOADED.

[0102] Refers to the following The sum of It means that when a single transaction cannot When all uploads are completed, you need to upload them in multiple times. To indicate the number.

[0103] UploadCT: Upon receipt of ("uploadCT", , )back, is uploaded to the contract. Note that It also needs to be divided into Upload a copy. If = 1, then it means this is The first and ,in otherwise >1, = .

[0104] 1. Check if state = TK_UPLOADED,

[0105] 2. Check if msg.sender = ,

[0106] 3. Judgment = 1, if = 1, add ,

[0107] 4. For each ,Add to , and set ,

[0108] 5. Determine whether , if true, set state := CT_UPLOADED.

[0109] UploadShare: Upon receiving the ("uploadShare", )back, is uploaded to the contract. Note that It also needs to be divided into Upload a copy.

[0110] 1. Check if state = CT_UPLOADED,

[0111] 2. Check if msg.sender = ,

[0112] 3. For each ,Add to , and set ,

[0113] 4. Determine whether , if true, set state := SHARE_UPLOADED.

[0114] ComputeMeta: Upon receiving a message from a node N (“computeMeta”, , ),in back,

[0115] 1. Check if state := SHARE_UPLOADED,

[0116] 2. Check $deposit ≥ $reward,

[0117] 3. If ,Then

[0118] i.

[0119] ii. Transfer $reward to node N;

[0120] iii. $deposit $deposit - $reward.

[0121] 4. If = , set state := META_Computed.

[0122] Set state := CLAIMED.

[0123] The present invention provides a reliable and fair attribute encryption and decryption outsourcing method based on smart contracts.

[0124] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions or improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A reliable and fair attribute encryption and decryption outsourcing method based on smart contracts, including a sender, nodes in the network, smart contracts, a storage cloud server, and a trusted authority, characterized by: The method comprises the following steps: S1: The sender sets the initial state, obtains the general attribute description, and outputs the master key and public parameters through a trusted authority; S2: The sender obtains the attribute set, inputs the master key, public parameters, and attribute set, and then executes it through a trusted authority and outputs the private key; S3: The sender defines an access mechanism using a set of attributes, obtains the ciphertext using public parameters, encapsulated keys, and access structures, and transmits it to the storage cloud server. S4: The sender inputs the public parameters and private key to obtain the conversion key and the corresponding retrieval key; S5: The sender obtains the set W, the storage cloud server sends the ciphertext to the smart contract in segments, and the sender sends the conversion key and set W to the smart contract in segments; S6: Nodes in the network obtain public parameters, ciphertext, and conversion keys and calculate and output meta-elements; nodes in the network issue transactions, upload meta-elements to the smart contract, and the smart contract calculates and outputs the conversion ciphertext; S7: The sender obtains the encapsulated key through the public parameters, the converted ciphertext, and the retrieved key.

2. A reliable and fair attribute encryption and decryption outsourcing method based on smart contracts as claimed in claim 1, characterized in that: The step S1 includes the following sub-steps: S11: The trusted authority includes a public key generator, which obtains a prime-order cyclic multigroup and a generator of the cyclic multigroup, generates a bilinear pairing parameter, and outputs the bilinear pairing parameter; S12: The public key generator initializes a hash function to map attributes to elements in the cyclic multigroup; S13: Get a random element a from the integer field; S14: The public key generator calculates the master key and public parameters and outputs them.

3. A reliable and fair attribute encryption and decryption outsourcing method based on smart contracts as claimed in claim 2, characterized in that: The step S2 includes the following sub-steps: S21: The sender inputs the attribute set and the master key to the public key generator; S22: The public key generator obtains a random element s from the non-zero elements of the integer field; S23: The public key generator calculates the private key through the generator of the prime-order cyclic multigroup, the random element a, the random element s, the attribute set and the hash function, and outputs it.

4. The reliable and fair attribute encryption and decryption outsourcing method based on smart contracts according to claim 1, characterized in that: The step S3 includes the following sub-steps: S31: The sender defines an access structure through the attribute set and inputs the key and access structure into the smart contract, where the access structure is a row-column matrix M, and the matrix form is ; S32: Smart contract obtains random vector ; S33: According to the row and column matrix of the access structure, let , for the i The attributes of the row are obtained by combining random vector calculation ,in is the matrix M's i OK; S34: According to the row and column matrix of the access structure, for , select several from the integer domain , the smart contract obtains the ciphertext through calculation and outputs it.

5. The reliable and fair attribute encryption and decryption outsourcing method based on smart contracts according to claim 1, characterized in that: The step S4 includes the following sub-steps: S41: The sender enters the private key into the smart contract; S42: The smart contract selects a random element from the non-zero integer field ; S43: Smart Contracts through Random Elements Calculate and output the conversion key and the corresponding retrieval key.

6. A reliable and fair attribute encryption and decryption outsourcing method based on smart contracts as claimed in claim 4, characterized in that: The step S5 includes the following sub-steps: S51: The sender obtains the collection , the set W satisfies ,in is a collection , where the attribute set Satisfy access structure ; S52: Divide the ciphertext into n' parts, divide the conversion key into n parts, divide the set W into n'' parts, and send each part separately to the smart contract S53: The smart contract obtains n'' sets of sets W respectively, and sums up each set of sets W. After all sets of sets W are obtained, it enters S54; S54: The smart contract obtains n conversion keys and sums up each conversion key. After all the conversion keys are obtained, it enters S55. S55: The smart contract obtains n' ciphertexts and sums up each ciphertext. After all ciphertexts are obtained, it enters S6.

7. The reliable and fair attribute encryption and decryption outsourcing method based on smart contracts according to claim 1, characterized in that: The step S6 includes the following sub-steps: S61: The node performs calculations and outputs meta-elements of the converted ciphertext ; S62: Node calls transaction to pass meta element Send to the smart contract; S63: Smart Contract Acquisition Elements , when all meta elements When all are uploaded to the smart contract, the ciphertext is converted and output.

8. The reliable and fair attribute encryption and decryption outsourcing method based on smart contracts according to claim 1, characterized in that: The step S7 includes the following sub-steps: S71: The sender inputs public parameters, converts ciphertext and retrieves the key; S72: The smart contract obtains public parameters, converts ciphertext, retrieves the key, and outputs the key; S73: The sender inputs the converted ciphertext and the recovery key; S74: The smart contract obtains the converted ciphertext and the recovery key and outputs data T and the key, where T is all meta-elements The sum of .

9. A reliable and fair attribute encryption and decryption outsourcing device based on smart contracts, characterized by: The invention comprises a memory and one or more processors, wherein the memory stores executable code, and when the one or more processors execute the executable code, they are used to implement a reliable and fair attribute encryption and decryption outsourcing method based on a smart contract as described in any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that: A program is stored thereon, and when the program is executed by the processor, it implements a reliable and fair attribute encryption and decryption outsourcing method based on a smart contract as described in any one of claims 1-8.

Citation Information

Patent Citations

  • BGN type cryptograph decryption outsourcing scheme based on attributes

    CN107154845A

  • Multi-keyword searchable encryption method and system supporting Boolean access control strategy

    CN112100649A