A data privacy sharing method, system, device and medium based on proxy re-encryption and blockchain

By employing a data privacy sharing method based on proxy re-encryption and blockchain, the security and privacy issues of power data sharing in smart grids are resolved, enabling secure data transmission and efficient processing, and supporting homomorphic operations to meet user needs.

CN119484118BActive Publication Date: 2025-10-21GUANGXI POWER GRID CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411655286.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-10-21
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

In smart grids, existing technologies lack solutions that efficiently combine blockchain and proxy re-encryption, leading to problems such as the inability to trace the authenticity of data sources and the ease with which data can be leaked or tampered with during power data sharing. This affects data security and privacy, making it difficult to optimize grid operation.

Method used

A data privacy sharing method based on proxy re-encryption and blockchain is adopted. By generating a data sharing request, a second cloud server is used to perform ciphertext conversion and proxy re-encryption to ensure the security of data during transmission and processing, and data sharing is realized through the SCT ciphertext conversion protocol.

Benefits of technology

It improves the security and efficiency of data processing, prevents data leakage, and ensures the security, privacy, and immutability of power grid data, while supporting users to perform homomorphic operations as needed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484118B_ABST
    Figure CN119484118B_ABST
Patent Text Reader

Abstract

The application is suitable for the technical field of data processing, and provides a data privacy sharing method, system, device and medium based on proxy re-encryption and a block chain, which comprises the following steps: generating a data sharing request based on target power grid data searched by a user, and sending the data sharing request to a target power company; uploading second-level ciphertext corresponding to the target power grid data to a second cloud server by the target power company; converting the second-level ciphertext into first-level ciphertext encrypted by a public key of a first cloud server by the second cloud server, and performing ciphertext calculation; converting the calculation result of the first-level ciphertext encrypted by the public key of the first cloud server into second-level ciphertext encrypted by the public key of the first cloud server based on a set SCT ciphertext conversion protocol; and performing proxy re-encryption by the second cloud server to obtain first-level ciphertext corresponding to the target power grid data, so that a user generates a shared data vector after decryption based on the first-level ciphertext. The application guarantees the security of data in transmission and processing, and improves the efficiency of data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a data privacy sharing method, system, device and medium based on proxy re-encryption and blockchain. Background Art

[0002] Smart grids generate massive amounts of data during operation, containing sensitive information about individuals and organizations. This data is often stored on third-party cloud servers. Furthermore, technologies such as machine learning, deep learning, and data mining rely on this private data to create more accurate portraits of individuals and organizations, accelerating the development of smart cities, smart energy, and multi-station integration projects. The outsourced storage, sharing, and transmission of private power data pose additional challenges to data security, privacy, and immutability. Traditional data sharing solutions currently face challenges such as the inability to trace data source authenticity and the vulnerability of data to leakage or tampering. This makes grid data sharing extremely difficult, leading to the phenomenon of "information silos" for power data and hindering the optimization of grid operations and the realization of data's potential value.

[0003] To prevent power grid data from being leaked during sharing, some existing research has proposed an identity-based private data sharing scheme for big data online social networks. This scheme employs attribute-based conditional proxy re-encryption to ensure that only data disseminators whose attributes satisfy the access policy can disseminate data to their own social space. Others have proposed a privacy-preserving scheme for identity-based broadcast proxy re-encryption, using Lagrange interpolation polynomials to maintain the privacy of the recipients of the broadcast re-encrypted ciphertext. Others have proposed a privacy-preserving proxy re-encryption scheme for public cloud access control, providing attribute-based proxy re-encryption of encrypted data while protecting the privacy of the recipients. A novel proxy re-encryption data sharing method has been proposed, which enhances the security of data sharing by binding public keys to user identities through the introduction of identity hashing during key generation. Finally, a regulated blockchain-based data sharing system has been proposed to fully protect the privacy of transaction data and determine data access rights by controlling proxy re-encryption key parameters. Although blockchain technology and proxy re-encryption schemes have been widely used in data sharing, an efficient solution combining the two remains lacking in smart grid applications.

[0004] In view of this, a data privacy sharing method, system, device and medium based on proxy re-encryption and blockchain are proposed. Summary of the Invention

[0005] The embodiments of the present application provide a data privacy sharing method, system, device and medium based on proxy re-encryption and blockchain, which are used to solve the problem of insufficient security of data privacy sharing.

[0006] A first aspect of an embodiment of the present application provides a data privacy sharing method based on proxy re-encryption and blockchain, comprising:

[0007] Generate a data sharing request based on the target power grid data searched by the user, and send the data sharing request to the target power company;

[0008] The target power company uploads the secondary ciphertext corresponding to the target power grid data to a second cloud server, where the second cloud server includes the proxy re-encryption keys of all power companies and the first cloud server;

[0009] The second cloud server converts the second-level ciphertext into a first-level ciphertext encrypted by the public key of the first cloud server, and performs ciphertext calculation on the first-level ciphertext encrypted by the public key of the first cloud server;

[0010] Converting the calculation result of the first-level ciphertext encrypted by the first cloud server public key into the second-level ciphertext encrypted by the first cloud server public key based on the set SCT ciphertext conversion protocol;

[0011] The second cloud server performs proxy re-encryption on the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user generates a shared data vector after decrypting the first-level ciphertext.

[0012] Furthermore, the generating of a data sharing request based on the target power grid data searched by the user and sending the data sharing request to the target power company includes:

[0013] The target power grid data is determined based on the search data input by the user, the search data is the keyword of the search table set in the power alliance chain, and the keyword is the keyword extracted from the first-level ciphertext corresponding to the target power grid data.

[0014] Furthermore, before the target power company uploads the secondary ciphertext corresponding to the target power grid data to the second cloud server, the method further includes:

[0015] The target power company determines whether the identity information of the user meets a preset condition. If so, the target power company extracts the ciphertext data corresponding to the target power grid data locally.

[0016] Furthermore, the target power company uploads the secondary ciphertext corresponding to the target power grid data to the second cloud server, and the second cloud server includes the proxy re-encryption keys of all power companies and the first cloud server, including:

[0017] The target power company decrypts the ciphertext data corresponding to the target power grid data to obtain plaintext data;

[0018] Perform secondary encryption on the plaintext data to obtain secondary ciphertext encrypted by the public key of the target power company, and upload the secondary ciphertext encrypted by the public key of the target power company to the second cloud server.

[0019] Furthermore, the second cloud server converts the second-level ciphertext into a first-level ciphertext encrypted by the public key of the first cloud server, and performs ciphertext calculation on the first-level ciphertext encrypted by the public key of the first cloud server, including:

[0020] The second cloud server performs proxy re-encryption on the secondary ciphertext to generate a proxy key;

[0021] The second cloud server takes the second-level ciphertext and the proxy key as input, and converts the second-level ciphertext into the first-level ciphertext encrypted by the public key of the first cloud server through the RKG algorithm;

[0022] Perform ciphertext calculation on the first-level ciphertext encrypted by the first cloud server public key based on the ciphertext algorithm set by the user.

[0023] Furthermore, the conversion of the calculation result of the first-level ciphertext encrypted by the first cloud server public key into the second-level ciphertext encrypted by the first cloud server public key based on the set SCT ciphertext conversion protocol includes:

[0024] The expression of the SCT ciphertext conversion protocol is as follows:

[0025]

[0026] in: The secondary ciphertext encrypted by the first cloud server's public key, The first-level ciphertext encrypted by the public key of the first cloud server (pk A ,sk A ) is the key pair of the first cloud server.

[0027] Furthermore, after the second cloud server performs proxy re-encryption on the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user decrypts the first-level ciphertext to generate a shared data vector, the method further includes:

[0028] When the user has an objection to the shared data vector, receiving ciphertext data corresponding to the shared data vector;

[0029] The encrypted data is compared with the encrypted data in the power alliance chain, and whether there is an error in the shared data vector is determined based on the comparison result.

[0030] A second aspect of the embodiments of the present application provides a data privacy sharing system based on proxy re-encryption and blockchain, including:

[0031] a data sharing request sending unit, configured to generate a data sharing request based on the target power grid data searched by the user, and send the data sharing request to the target power company;

[0032] a ciphertext uploading unit, configured for the target power company to upload the secondary ciphertext corresponding to the target power grid data to a second cloud server, wherein the second cloud server includes proxy re-encryption keys of all power companies and the first cloud server;

[0033] a ciphertext conversion unit, configured for the second cloud server to convert the second-level ciphertext into a first-level ciphertext encrypted by the public key of the first cloud server, and to perform ciphertext calculation on the first-level ciphertext encrypted by the public key of the first cloud server;

[0034] a ciphertext calculation result conversion unit, configured to convert the calculation result of the first-level ciphertext encrypted by the first cloud server public key into the second-level ciphertext encrypted by the first cloud server public key based on a set SCT ciphertext conversion protocol;

[0035] A shared data vector generating unit is configured to cause the second cloud server to proxy re-encrypt the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user generates a shared data vector after decrypting the first-level ciphertext.

[0036] A third aspect of the embodiments of the present application provides a computer device, including:

[0037] memories, transceivers, processors, and bus systems;

[0038] Wherein, the memory is used to store programs;

[0039] The processor is configured to execute the program in the memory, including executing the data privacy sharing method based on proxy re-encryption and blockchain as described above;

[0040] The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.

[0041] A fourth aspect of an embodiment of the present application provides a readable storage medium comprising instructions, which, when executed on a computer, enables the computer to execute the data privacy sharing method based on proxy re-encryption and blockchain as described above.

[0042] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:

[0043] In this invention, a user generates a sharing request based on the target grid data they are looking for and sends it to the target power company. The target power company then uploads the secondary ciphertext of the target grid data to a second cloud server that holds the proxy re-encryption keys of all relevant parties. The second cloud server converts the secondary ciphertext into a primary ciphertext encrypted with the public key of the first cloud server and performs ciphertext calculations. The calculation results are then converted into secondary ciphertext encrypted with the public key of the first cloud server according to the SCT ciphertext conversion protocol. Finally, the second cloud server re-encrypts the proxy to obtain the primary ciphertext corresponding to the target grid data, allowing the user to decrypt it and generate a shared data vector. This invention not only ensures the security of data during transmission and processing, preventing data leakage, but also improves the efficiency of data processing.

[0044] Other advantages, objects, and features of the present invention will be described in part in the following description and, in part, will be apparent to those skilled in the art based on an examination of the following or may be learned from the practice of the invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 This is a flow chart of an embodiment of a data privacy sharing method based on proxy re-encryption and blockchain in the present invention;

[0046] Figure 2 This is a model architecture diagram of a data privacy sharing method based on proxy re-encryption and blockchain in the present invention;

[0047] Figure 3 This is a comparison chart of data encryption time in the present invention;

[0048] Figure 4 This is a comparison chart of data aggregation time in the present invention;

[0049] Figure 5 This is a comparison chart of data decryption time in the present invention. DETAILED DESCRIPTION

[0050] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the numbers used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can, for example, be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "corresponding to" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0051] Example 1

[0052] See also Figures 1 to 2 , an embodiment of a data privacy sharing method based on proxy re-encryption and blockchain in the present invention includes the following steps:

[0053] S11. Generates a data sharing request based on the target grid data found by the user and sends the data sharing request to the target power company;

[0054] In this embodiment, step S11 includes:

[0055] The target power grid data is determined based on the search data input by the user. The search data is the keyword of the search table in the set power alliance chain, and the keyword is the keyword extracted from the first-level ciphertext corresponding to the target power grid data.

[0056] After step S11, the method further includes:

[0057] The target power company determines whether the user's identity information meets the preset conditions. If so, the target power company extracts the ciphertext data corresponding to the target power grid data locally.

[0058] Specifically, when all power companies upload power data, they encrypt the plaintext power data to obtain the ciphertext. Let the ciphertext be Extract keywords to build a search table and upload it to the power alliance chain. At the same time, generate a data keyword search table and broadcast it so that users can search for data through keywords. In this way, when users query the required power grid data, they can select the power grid data to be shared according to the search table. The system will generate a data sharing request based on the target power grid data that the user is looking for, and send the data sharing request to the target power company, which is the corresponding power company. In addition, the power company also needs to verify whether the user's identity information meets the preset conditions, which are the preset validity, to decide whether to provide data to the user. When the user identity verification is passed, the corresponding power company EPC i Search for encrypted data from the consortium chain based on keywords and extract it locally.

[0059] S12. The target power company uploads the secondary ciphertext corresponding to the target grid data to the second cloud server, which includes the proxy re-encryption keys of all power companies and the first cloud server;

[0060] In this embodiment, step S12 includes:

[0061] 1. The target power company decrypts the ciphertext data corresponding to the target power grid data to obtain the plaintext data;

[0062] 2. Perform secondary encryption on the plaintext data to obtain the secondary ciphertext encrypted by the target power company's public key, and upload the secondary ciphertext encrypted by the target power company's public key to the second cloud server.

[0063] Specifically, after the target power company extracts the ciphertext data to the local computer, it decrypts the ciphertext data to obtain the plaintext data that the user wants to share, and performs secondary encryption on the plaintext data, that is, the secondary ciphertext is in Finally, the secondary ciphertext Upload to the second cloud server, assuming the second cloud server is S1.

[0064] It should be noted that the second cloud server S1 includes the proxy re-encryption keys of all power companies and the first cloud server, and the first cloud server is set to S0. During the system initialization phase, each power company entity contains data X i , where i∈[1,n] represents the identity of the power company. In addition, each entity has a key pair (pk i ,sk i ) and upload it to the power alliance chain in the form of a contract. The power company calculates the proxy re-encryption key And send it to the second cloud server S1. The first cloud server S0 has a key pair (pk A ,sk A), calculate the proxy re-encryption key And send it to the second cloud server S1. Assume that there are m users in the system, and each user u j Have your own key pair Where j∈[1,m] is the user identity.

[0065] S13. The second cloud server converts the secondary ciphertext into the primary ciphertext encrypted by the public key of the first cloud server and performs ciphertext calculation on the primary ciphertext encrypted by the public key of the first cloud server;

[0066] In this embodiment, step S13 includes:

[0067] 1. The second cloud server performs proxy re-encryption on the secondary ciphertext to generate a proxy key;

[0068] 2. The second cloud server takes the secondary ciphertext and the proxy key as input and converts the secondary ciphertext into the primary ciphertext encrypted with the first cloud server's public key using the RKG algorithm.

[0069] 3. Perform ciphertext calculation on the first-level ciphertext encrypted by the first cloud server public key based on the ciphertext algorithm set by the user.

[0070] Specifically, when the second cloud server S1 receives the secondary ciphertext, it sets the data ciphertext corresponding to the secondary ciphertext Where t represents the number of users requesting sharing, pk t represents [X′ t ]The public key of the corresponding power company.

[0071] Perform proxy re-encryption to generate a proxy key Then and As the algorithm input, through the RKG algorithm Converted to the first-level ciphertext encrypted by the first cloud server public key During the entire process, there is no interaction between the second cloud server S1 and the first cloud server S0.

[0072] After the ciphertext conversion is completed, the second cloud server S1 performs ciphertext calculations on the first-level ciphertext encrypted by the public key of the first cloud server based on the ciphertext algorithm set by the user, such as ciphertext addition operations, ciphertext multiplication operations, etc., to obtain the calculation results. The calculation results are

[0073] S14. Based on the set SCT ciphertext conversion protocol, the calculation result of the first-level ciphertext encrypted by the first cloud server public key is converted into the second-level ciphertext encrypted by the first cloud server public key;

[0074] Specifically, since the calculation result is a first-level ciphertext encrypted with the public key of the first cloud server S0, the user cannot directly decrypt it after receiving it. Therefore, the second cloud server S1 is required to cooperate with the first cloud server S0 to execute the SCT ciphertext conversion protocol to convert the first-level ciphertext encrypted with the public key of the first cloud server S0 into the first-level ciphertext encrypted with the public key of the first cloud server S0. Converted into the secondary ciphertext encrypted by the public key of the first cloud server S0 The expression of the SCT ciphertext conversion protocol is:

[0075] S15. The second cloud server performs proxy re-encryption on the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user can decrypt the first-level ciphertext and generate a shared data vector.

[0076] In this embodiment, after step S15, the following steps are further included:

[0077] When the user has objections to the shared data vector, the user receives the ciphertext data corresponding to the shared data vector;

[0078] Compare the encrypted data with the encrypted data in the power alliance chain, and determine whether there is an error in the shared data vector based on the comparison results.

[0079] Specifically, the second cloud server S1 uses the RKG algorithm to Perform proxy re-encryption to obtain the first-level ciphertext encrypted based on the public key of the shared user based on different requests These ciphertexts are distributed to the corresponding users and uploaded to the power alliance chain for user verification. In the ciphertext decryption and result verification phase, user u j Received Then, use your own private key Perform decryption operations Get the calculated shared data vector X ret .

[0080] If a user objects to the decryption result, they can request verification from the power chain. First, the user uploads the ciphertext corresponding to the disputed result to the corresponding consortium chain node. After receiving the ciphertext data sent by the user, the corresponding node in the power consortium chain searches for the ciphertext in the power chain and compares the two to see if they are identical. If they are, the calculation result is correct; otherwise, the second cloud server S1 is penalized.

[0081] See also Figure 3-Figure 5The figures are respectively a comparison diagram of the data encryption, aggregation and decryption time after using the method of this embodiment. According to the experimental comparison diagram, it can be seen that the scheme proposed in this embodiment not only realizes the user power data sharing in the multi-key scenario, but also can achieve a computational overhead very close to that of the BFV homomorphic encryption algorithm.

[0082] The above embodiment encrypts power company data and uploads it to the power alliance chain for storage, ensuring the security, privacy, immutability, and verifiability of power grid data. By adopting proxy re-encryption technology and a secure ciphertext conversion protocol, homomorphic operations on ciphertext can be performed according to user needs while ensuring the privacy of power data.

[0083] Example 2

[0084] An embodiment of a data privacy sharing system based on proxy re-encryption and blockchain in the present invention includes the following steps:

[0085] a data sharing request sending unit, configured to generate a data sharing request based on the target power grid data searched by the user, and send the data sharing request to the target power company;

[0086] A ciphertext uploading unit, configured to enable the target power company to upload the secondary ciphertext corresponding to the target power grid data to the second cloud server, where the second cloud server includes the proxy re-encryption keys of all power companies and the first cloud server;

[0087] A ciphertext conversion unit, configured for the second cloud server to convert the second-level ciphertext into the first-level ciphertext encrypted by the public key of the first cloud server, and to perform ciphertext calculation on the first-level ciphertext encrypted by the public key of the first cloud server;

[0088] a ciphertext calculation result conversion unit, configured to convert a calculation result of the first-level ciphertext encrypted by the first cloud server public key into a second-level ciphertext encrypted by the first cloud server public key based on a set SCT ciphertext conversion protocol;

[0089] The shared data vector generation unit is used for the second cloud server to perform proxy re-encryption on the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user can generate a shared data vector after decrypting the first-level ciphertext.

[0090] For the specific definition of the system, please refer to the definition of the method above and will not be repeated here. Each module in the above system can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software so that the processor can call and execute the operations corresponding to each of the above modules.

[0091] Example 3

[0092] The present invention provides a computer device, comprising a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the above method are implemented.

[0093] Those skilled in the art will appreciate that the units of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0094] In the embodiments provided herein, it should be understood that the division of units is merely a logical functional division. In actual implementation, other division methods may be employed, such as combining multiple units into one unit, splitting a unit into multiple units, or ignoring certain features. Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically as a separate unit, or two or more units may be integrated into a single unit. These integrated units may be implemented in either hardware or software functional units.

[0095] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nly Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc., various media that can store program code.

[0096] It can be understood that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and description of the present invention.

Claims

1. A data privacy sharing method based on proxy re-encryption and blockchain, characterized in that: include: Generate a data sharing request based on the target power grid data searched by the user, and send the data sharing request to the target power company; The target power company uploads the secondary ciphertext corresponding to the target power grid data to a second cloud server, where the second cloud server includes the proxy re-encryption keys of all power companies and the first cloud server; The second cloud server converts the second-level ciphertext into a first-level ciphertext encrypted by the public key of the first cloud server, and performs ciphertext calculation on the first-level ciphertext encrypted by the public key of the first cloud server; Converting the calculation result of the first-level ciphertext encrypted by the first cloud server public key into the second-level ciphertext encrypted by the first cloud server public key based on the set SCT ciphertext conversion protocol; The second cloud server performs proxy re-encryption on the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user generates a shared data vector after decrypting the first-level ciphertext.

2. The data privacy sharing method based on proxy re-encryption and blockchain according to claim 1 is characterized in that: The step of generating a data sharing request based on the target power grid data searched by the user and sending the data sharing request to the target power company includes: The target power grid data is determined based on the search data input by the user, the search data is the keyword of the search table set in the power alliance chain, and the keyword is the keyword extracted from the first-level ciphertext corresponding to the target power grid data.

3. The data privacy sharing method based on proxy re-encryption and blockchain according to claim 1 is characterized in that: Before the target power company uploads the secondary ciphertext corresponding to the target power grid data to the second cloud server, the method further includes: The target power company determines whether the identity information of the user meets a preset condition. If so, the target power company extracts the ciphertext data corresponding to the target power grid data locally.

4. The data privacy sharing method based on proxy re-encryption and blockchain according to claim 3 is characterized in that: The target power company uploads the secondary ciphertext corresponding to the target power grid data to the second cloud server. The second cloud server includes the proxy re-encryption keys of all power companies and the first cloud server, including: The target power company decrypts the ciphertext data corresponding to the target power grid data to obtain plaintext data; Perform secondary encryption on the plaintext data to obtain secondary ciphertext encrypted by the public key of the target power company, and upload the secondary ciphertext encrypted by the public key of the target power company to the second cloud server.

5. The data privacy sharing method based on proxy re-encryption and blockchain according to claim 1 is characterized in that: The second cloud server converts the second-level ciphertext into a first-level ciphertext encrypted by the public key of the first cloud server, and performs ciphertext calculation on the first-level ciphertext encrypted by the public key of the first cloud server, including: The second cloud server performs proxy re-encryption on the secondary ciphertext to generate a proxy key; The second cloud server takes the second-level ciphertext and the proxy key as input, and converts the second-level ciphertext into the first-level ciphertext encrypted by the public key of the first cloud server through the RKG algorithm; Perform ciphertext calculation on the first-level ciphertext encrypted by the first cloud server public key based on the ciphertext algorithm set by the user.

6. The data privacy sharing method based on proxy re-encryption and blockchain according to claim 1 is characterized in that: The converting, based on the set SCT ciphertext conversion protocol, the calculation result of the first-level ciphertext encrypted by the first cloud server public key into the second-level ciphertext encrypted by the first cloud server public key includes: The expression of the SCT ciphertext conversion protocol is as follows: in: The secondary ciphertext encrypted by the first cloud server's public key, The first-level ciphertext encrypted by the public key of the first cloud server (pk A ,sk A ) is the key pair of the first cloud server.

7. The data privacy sharing method based on proxy re-encryption and blockchain according to claim 2 is characterized in that: After the second cloud server performs proxy re-encryption on the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user decrypts the first-level ciphertext to generate a shared data vector, the method further includes: When the user has an objection to the shared data vector, receiving ciphertext data corresponding to the shared data vector; The encrypted data is compared with the encrypted data in the power alliance chain, and whether there is an error in the shared data vector is determined based on the comparison result.

8. A data privacy sharing system based on proxy re-encryption and blockchain, characterized in that: include: a data sharing request sending unit, configured to generate a data sharing request based on the target power grid data searched by the user, and send the data sharing request to the target power company; a ciphertext uploading unit, configured for the target power company to upload the secondary ciphertext corresponding to the target power grid data to a second cloud server, wherein the second cloud server includes proxy re-encryption keys of all power companies and the first cloud server; a ciphertext conversion unit, configured for the second cloud server to convert the second-level ciphertext into a first-level ciphertext encrypted by the public key of the first cloud server, and to perform ciphertext calculation on the first-level ciphertext encrypted by the public key of the first cloud server; a ciphertext calculation result conversion unit, configured to convert the calculation result of the first-level ciphertext encrypted by the first cloud server public key into the second-level ciphertext encrypted by the first cloud server public key based on a set SCT ciphertext conversion protocol; A shared data vector generating unit is configured to cause the second cloud server to proxy re-encrypt the second-level ciphertext encrypted by the public key of the first cloud server to obtain the first-level ciphertext corresponding to the target power grid data, so that the user generates a shared data vector after decrypting the first-level ciphertext.

9. A computer device, characterized in that: include: memories, transceivers, processors, and bus systems; Wherein, the memory is used to store programs; The processor is configured to execute the program in the memory, including executing the data privacy sharing method based on proxy re-encryption and blockchain according to any one of claims 1 to 7; The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.

10. A readable storage medium, characterized in that: The method comprises instructions which, when executed on a computer, cause the computer to execute the data privacy sharing method based on proxy re-encryption and blockchain as claimed in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data sharing method and system based on decentration and distributed proxy re-encryption

    CN113556363A

  • Certificateless dynamic data sharing system and method based on proxy re-encryption

    CN116192433A