Blockchain-enabled smart logistics authorization cloud-assisted PSI-CA method and electronic device
The PSI-CA method, which utilizes blockchain and cloud servers in collaboration to create an intelligent logistics authorization cloud, addresses the computational and storage pressures of large-scale data sharing in the logistics industry, ensuring data security and transparency, and achieving efficient data sharing and audit tracking.
Patent Information
- Application Number
- CN202411696240.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-11-25
AI Technical Summary
In the logistics industry, traditional privacy set intersection cardinality technology suffers from problems such as high computational and storage pressure, insufficient protection of user rights, difficulty in ensuring data confidentiality and integrity, and difficulty in monitoring data misuse. This is especially true in scenarios involving large-scale data sharing and multiple participants, which affects data processing efficiency and security.
The PSI-CA method, which supports blockchain-based smart logistics authorization cloud, uses a blockchain network for strict access control and data encryption, cloud servers for complex calculations, and zero-knowledge proofs and digital signatures to achieve obfuscated data transmission and authorization verification, providing a complete audit trail mechanism.
It reduces the computing and storage burden on enterprises, ensures that only authorized users participate in data processing, prevents data eavesdropping and tampering, provides transparency and security in data use, supports the tracing of data breaches, and offers flexibility and efficient response to dynamic market demands.
Smart Images

Figure CN119622828B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a blockchain-supported smart logistics authorization cloud-assisted PSI-CA method and an electronic device. Background Technology
[0002] In recent years, the e-commerce and logistics industries have experienced significant growth. Logistics-related companies urgently need advanced data-sharing technologies to achieve modernization and intelligent transformation, thereby improving business efficiency and service quality to meet rapidly changing market demands. However, against the backdrop of the rapid development of the digital economy, data breaches have become frequent security incidents globally. Logistics data in the Internet of Things (IoT) involves a large amount of sensitive information, such as customer privacy, pricing strategies, inventory levels, and operational information. In the IoT, companies face many situations where the degree of data overlap needs to be quantified, while simply obtaining statistical information is sufficient. Therefore, how to maximize the value of this information while protecting privacy is a pressing issue that the logistics industry needs to address.
[0003] Private Set Intersection Cardinality (PSI-CA) offers a solution. It refers to a computational approach where participating parties only collaborate to calculate the number of elements in the intersection of their sets, without revealing any information related to their respective sets during the calculation process (except for the intersection cardinality). This technology effectively prevents data leakage, ensuring data confidentiality while enabling data sharing. However, in logistics data sharing, traditional private set intersection cardinality still has many limitations:
[0004] (1) Computational and storage pressure. Although privacy-preserving set intersection-cardinality techniques have lower computational and storage overhead compared to other data processing methods, logistics data is often massive and complex. Especially in scenarios with large data volumes and many participants, traditional privacy-preserving set intersection-cardinality techniques place high demands on the enterprise's local computing power and storage resources, which can easily lead to bottlenecks in computing power and make it difficult to meet the needs of efficient data processing.
[0005] (2) Protection of User Rights. Access control mechanisms can ensure that only authorized entities can access user data, reducing the risk of data leakage and privacy violations, and protecting users' privacy rights. However, related technologies have failed to provide strict authorization verification, which may allow unauthorized entities to participate in data computation, harming the legitimate rights and interests of legitimate users and undermining the security and transparency of the collaborative environment.
[0006] (3) Data confidentiality and integrity. Data transmission between participating parties and servers may face risks of eavesdropping or tampering, especially when sensitive privacy data is involved. Furthermore, external servers are semi-trusted and may make calculation errors or falsify data, affecting the credibility of the calculation results. Currently, privacy set intersection cardinality techniques fail to monitor external servers and verify the correctness and integrity of transmission results, posing a significant threat to secure data sharing within enterprises.
[0007] (4) Data misuse. Authorized malicious users may expose private data to others for personal gain. Current privacy set intersection-cardinality techniques lack built-in auditing mechanisms, making it difficult to effectively monitor and record data usage. This makes it difficult to trace the source of problems in the event of data leakage or misuse, increasing security and legal risks. Summary of the Invention
[0008] This invention aims to at least partially address one of the technical problems in related technologies. Therefore, the objective of this invention is to propose a blockchain-supported smart logistics authorization cloud-assisted PSI-CA method and electronic device to improve the security of user data.
[0009] To achieve the above objectives, a first aspect of the present invention proposes a blockchain-supported smart logistics authorization cloud-assisted PSI-CA method, comprising multiple entities: data owner DO, data user DU, blockchain BC, a first cloud server C1, and a second cloud server C2; the method includes: Step 1, the consensus node of BC takes the security parameter λ as input and outputs the public parameter PP; the accounting node of BC takes the public parameter PP and the parameter r uploaded by DO as input and outputs the parameter P required by each participant. DO ,P DU ,pp,γ,DO,C1 and C2 set their respective signature keys (pk B ,sk B ), and Step 2: DU submits credentials α and β to the system consensus node for registration. After successful registration, it obtains the required parameters from the chain, generates a signature verification key pair, and publishes the public key. Step 3: DO and DU each select a random number as a blind factor and use the public parameter PP and the blind factor to encrypt the data, generating obfuscated ciphertexts A, A′, T, Q. After signing the obfuscated ciphertexts A, A′, T, Q, they package the data according to class and send it to C1 and C2 respectively. Step 4: C1 and C2 send the packaged data (A, a, σ) of DO and DU to each other. A ), (A′,a,σ′ A ), (T, σ B ), (Q, σ′ BThe system takes the public key pk of the corresponding user as input and outputs a boolean value of 1 or 0. When all results are 1, C1 and C2 take the packaged data sent by DO and DU and the permutation matrices M1 and M2 as input, respectively, to generate obfuscated ciphertexts U and W. In step 5, C1 and C2 perform authorization verification on DU. After successful verification, they send the obfuscated ciphertexts U and W to DU. After receiving the data, DU performs signature verification and zero-knowledge proof verification. In step 6, after all verifications in step 5 are successful, DU performs statistical information analysis based on the received data. In step 7, when the authorization verification is successful, the system takes the identity information of DU, the tracking key k, and the data digest H(Y) as input and outputs the access record AR, which is then signed by DO. In step 8, when a security event such as data leakage occurs, the applicant who meets the application conditions initiates an audit request to trace the access record for auditing purposes.
[0010] In addition, the blockchain-supported smart logistics authorization cloud-assisted PSI-CA method of this invention may also have the following additional technical features:
[0011] According to an embodiment of the present invention, the specific process of step 1 is as follows: Step 1.1, overall initialization: the consensus node of BC generates public parameters PP={e,p,g1,g2,G1,G2,G... T Let {G, H, H1, H2, λ} be a bilinear mapping e: G1 × G2 → G T Among them, G1, G2 and G T Let G be a group of order p with large prime numbers, and g1 and g2 be generators of the group G1 and G2. Define three collision-resistant hash functions: H: {0, 1} * →{0,1} λ H1: {0,1} * →G, H2: G→{0,1} λ Where G is the elliptic curve group, λ is the security parameter representing the fixed length of the binary string used to output the final pseudo-random value; Step 1.2, Node Initialization: Different ledger nodes on BC are responsible for different parameter generation and distribution. First, the parameters of DU are generated. Next, generate the parameters for DO. And the parameters required for zero-knowledge proofs pp = Setup(1 λ C), track the key k, and finally generate the key γ of the unintentional pseudo-random function for authentication; Step 1.3, DO initialization: select a random number Upload it to BC to generate parameter P DO Next, set the DO's signature key pair (pk B ,sk B Finally, a data digest H(Y) = (H(y1), H(y2), ..., H(y...) is generated.n Step 1.4, C1 and C2 initialization: C1 and C2 generate corresponding signature key pairs. and Used for digital signatures on data.
[0012] According to an embodiment of the present invention, the specific process of step 2 is as follows: DU randomly selects authorization parameters α and β as its identity credentials for system registration, and after successful registration, obtains the required parameters from the chain; generates the corresponding signature key pair (pk A ,sk A ), and publish the public key pk A .
[0013] According to an embodiment of the present invention, the specific process of step 3 is as follows: Step 3.1, DU performs preprocessing: DU first preprocesses its private data and selects random numbers. The ciphertext is calculated as follows:
[0014]
[0015] Let A′=(A -1 A -2 ,...,A -m Next, calculate a = H1(α). β , for ciphertext A and A -i Generate signature σ respectively A =Sign(sk A ,A), σ′ A =Sign(sk A ,A′), finally, DU will (A,a,σ A Send (A′,a,σ′) to C1, and pass (A′,a,σ′) to C1. A Send to C2; Step 3.2, DO performs data preprocessing: DO selects random numbers. The ciphertext is calculated as follows:
[0016]
[0017] Next, let T = (T1, T2, ..., T n ),Q=(Q1,Q2,...,Q n Generate signatures σ for T and Q respectively. B =Sign(sk B ,T),σ′ B =Sign(sk B Ultimately, DO will (T, σ). B ), (Q, σ′ B Send them to C1 and C2 respectively.
[0018] According to an embodiment of the present invention, the specific process of step 4 is as follows: Step 4.1, signature verification: After C1 and C2 receive data from DO and DU, they perform signature verification. C1 calculates SVerify(pk) A ,A,a,σ A ),SVerify(pk B ,T,σ B C2 calculates SVerify(pk) A ,A′,a,σ′ A ),SVerify(pk B ,Q,σ′ B When all results are 1, the verification passes; otherwise, the verification fails. If the verification passes, C1 and C2 execute the delegated computation task; otherwise, the process terminates. Step 4.2: Execute the delegated computation task: For C1 calculates U j =H(e(T) j The result is multiplied by the permutation matrix M1 to obtain U = (U1, U2, ..., U...). n ),for C2 calculates W ij =H(e(Q) j A -i The result is then multiplied by the permutation matrix M2 to obtain W = (W 11 W 12 ,...,W mn Step 4.3, Generate zk-SNARKs proofs: After completing the delegated computing task, the cloud server needs to prove the computing operations and results performed. C1 and C2 respectively call the zero-knowledge concise non-interactive knowledge proof generation algorithm to generate proofs π1=Prove(pp,(T,A),U,ω1) and π2=Prove(pp,(Q,A′),W,ω2); Step 4.4, Sign the data: C1 and C2 summarize all the corresponding data in parallel, package and sign them to generate signatures.
[0019] It should be noted that zk-SNARKs are an effective zero-knowledge proof tool that allows verifiers to prove the truth of a statement to other verifiers without disclosing any additional information.
[0020] According to an embodiment of the present invention, the specific process of step 5 is as follows: Step 5.1, Authorization Verification: The cloud server performs identity authentication on the DU. If the user is an authorized user, access to the data is allowed; otherwise, the data access application is rejected. Specifically, C1 and C2 calculate the verification information v = F. DH-OPRF (α) and token b = a γThen, token b is sent to DU; DU uses token b issued by the cloud server to randomize the corresponding account information into verification code v', i.e., calculates... Then, v′ is sent to cloud servers C1 and C2 respectively; finally, C1 and C2 verify whether the verification code v′ of DU matches its corresponding verification information v. If v = v′, C1 will package the data. Send to DU, C2 will package the data Send to DU; if v≠v′, the protocol terminates; Step 5.2, Data correctness and integrity verification: After receiving the packaged data from the cloud server, DU performs operation verification and signature verification. If the verification passes, it continues the calculation, as follows: DU uses the cloud server's public key. calculate and The signature verification is performed. If all results are 1, the verification is successful and the calculation continues. After the signature verification is successful, DU verifies the zk-SNARKs proof of the cloud server by calculating PVerify(pp,(T,A),U,π1) and PVerify(pp,(Q,A′),W,π2) respectively. If all results are 1, the verification is successful and the user accepts the result returned by the cloud server.
[0021] According to an embodiment of the present invention, the specific process of step 6 is as follows: DU performs intersection cardinality calculation based on the received data to obtain the required statistical information. Finally, DU outputs the following information:
[0022]
[0023] According to an embodiment of the present invention, the specific process of step 7 is as follows: After successful authorization verification, the identity information of the DU is encrypted and an access record is generated and stored off-chain, specifically as follows: The identity information of the DU is encrypted using the AES encryption mechanism to obtain the ciphertext ID = Enc(k, ID), where k is the key, and the access record is defined as: AR = (ID, H(Y)); Next, the DO needs to sign the access record to obtain the signature σ = Sign(sk A Finally, DU uploads the data digest H(Y) to the blockchain, stores (AR, σ) off-chain, and implements a rotation mechanism for the logs. During rotation, it ensures that each access record contains the cryptographic hash value of the previous log to ensure the integrity of the log chain. Old logs are archived to cold storage to reduce access frequency.
[0024] According to an embodiment of the present invention, the specific process of step 8 is as follows: Application conditions: DO or DU that has passed authorization verification and correctly submitted the data digest; The requesting party that meets the conditions applies to obtain the access log, triggering the audit process: DO first performs signature verification and calculates SVerify(pk AIf the result is 1, the verification is successful. After successful verification, the ciphertext is decrypted to obtain id = Dec(k, ID), and the plaintext access log is finally provided for review; otherwise, an additional file corruption warning will be returned.
[0025] To achieve the above objectives, a second aspect of the present invention provides an electronic device including a memory, a processor, and a computer program stored in the memory. When the computer program is executed by the processor, it implements the above-described blockchain-supported smart logistics authorization cloud-assisted PSI-CA method.
[0026] The beneficial effects of this invention are as follows: 1. By leveraging the computing power and scalability of cloud servers, this application can not only process large amounts of data but also reduce enterprise IT expenses, enhancing the system's flexibility and responsiveness to dynamic market demands. 2. This application introduces an access control mechanism to ensure that only authorized users can participate in privacy-preserving set computations, preventing unauthorized access and improving data privacy and user trust. 3. This application includes data encryption, outsourcing verification, and transmission verification measures to ensure the accuracy and reliability of the results returned by the cloud service, avoiding the risks of data eavesdropping and tampering during transmission, and further protecting data security. 4. This application provides a complete audit trail mechanism to monitor data access records and computational operations, helping users trace the source in case of data leakage or misuse, enhancing the transparency and security of data use. 5. This application delegates complex bilinear pairing computations to cloud servers. Clients only need to complete some lightweight computational tasks, making it more suitable for practical applications in smart logistics. Attached Figure Description
[0027] Figure 1 This is a flowchart illustrating a blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to an embodiment of the present invention.
[0028] Figure 2 This is a schematic diagram of entity interaction according to an embodiment of the present invention;
[0029] Figure 3(a) is a schematic diagram comparing the computational overhead of DO according to an embodiment of the present invention;
[0030] Figure 3(b) is a schematic diagram comparing the computational overhead of DU according to an embodiment of the present invention;
[0031] Figure 3(c) is a schematic diagram comparing the total computational overhead of an embodiment of the present invention;
[0032] Figure 4(a) is a schematic diagram comparing the communication overhead of DO according to an embodiment of the present invention;
[0033] Figure 4(b) is a schematic diagram comparing the communication overhead of DU according to an embodiment of the present invention;
[0034] Figure 4(c) is a schematic diagram comparing the total communication overhead of an embodiment of the present invention;
[0035] Figure 5(a) is a schematic diagram comparing transaction throughput according to an embodiment of the present invention;
[0036] Figure 5(b) is a schematic diagram comparing CPU utilization and storage usage in an embodiment of the present invention;
[0037] Figure 5(c) is a schematic diagram comparing memory usage in an embodiment of the present invention. Detailed Implementation
[0038] The following describes embodiments of the present invention in detail, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and are not to be construed as limiting the present invention.
[0039] Different logistics companies and related service providers can optimize operations and improve service quality through logistics data sharing. However, logistics data contains a large amount of private information, and once leaked, companies will face serious consequences such as legal action, damage to brand image, and customer loss. Ensuring data security during data sharing and timely response to security incidents have always been important issues in intelligent logistics systems.
[0040] The following description, with reference to the accompanying drawings, describes an embodiment of the blockchain-supported smart logistics authorization cloud-assisted PSI-CA method and electronic device.
[0041] Figure 1 This is a flowchart illustrating a blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to an embodiment of the present invention.
[0042] It should be noted that the blockchain-supported smart logistics authorization cloud-assisted PSI-CA method in this embodiment includes multiple types of entities: data owner DO, data user DU, blockchain BC, first cloud server C1, and second cloud server C2.
[0043] Specifically, such as Figure 2As shown, the data owners are logistics companies or related service providers, such as suppliers, manufacturers, distributors, and retailers. These companies collect a large amount of private information through the Internet of Things (IoT) in logistics; however, data silos between these organizations limit the possibility of joint analysis of this data. When a company is the data owner, the system uses an Oblivious Pseudorandom Function (OPRF) to strictly control access to data users, ensuring that sensitive information is only accessed by authorized units or personnel, thus protecting the company's information security. The Data Owner (DO) is responsible for generating data summaries to facilitate auditing. Simultaneously, the DO digitally signs access records to ensure secure storage of access records, thereby protecting the company's data security.
[0044] Data users: Logistics companies or related service providers, such as suppliers, manufacturers, distributors, and retailers. Through this application, companies can integrate data without exposing specific data, thereby optimizing operations. When accessing statistical data from various organizations is required, the user must first submit credentials (α,β) to the consensus node for system registration and obtain the necessary parameters. After successful registration, the user submits a verification code v' generated from token b and the corresponding user credentials (α,β) to cloud servers C1 and C2. After authentication, DU receives the calculation results returned by the cloud server and can further calculate the required statistical information according to its own needs. During this process, each company will not see any plaintext messages except for its own information, effectively protecting the data security of other companies. In the event of a data breach or other security incident, companies involved in the dangerous data can initiate a tracking application to the system. Upon approval of the application, the system can provide access logs for auditing.
[0045] Blockchain: A blockchain network is established among the protocol participants, using a permissioned blockchain designed specifically for enterprise applications: Hyperledger Fabric. In this application, it will serve as an infrastructure providing computing power support and security guarantees. Smart contracts written in Go are used to generate initialization parameters and process tracking requests, and are deployed on Hyperledger Fabric network nodes. The InterPlanetary File System (IPFS) is used to manage access records, enabling audit trails for data usage. The transparency and immutability of the blockchain ensure the fairness of the parameter generation process and the credibility of the audit results. The decentralized nature avoids dependence on a single, easily corruptible third party, enhancing the reliability of data processing and improving system robustness. Through the automated execution of smart contracts, the system can achieve efficient function implementation, improving enterprise operational efficiency.
[0046] Cloud server: Assuming C1 and C2 are malicious, they may make calculation errors, leak data, or tamper with data. In this application, all data uploaded to the cloud server is encrypted and obfuscated, effectively avoiding the security risks of directly exposing data to the cloud server. The cloud server possesses powerful computing power and abundant storage resources, primarily responsible for performing complex bilinear pairing calculations, significantly improving enterprise operational efficiency.
[0047] like Figure 1 As shown, the blockchain-supported smart logistics authorization cloud-assisted PSI-CA method includes:
[0048] Step 1: The consensus node of BC takes the security parameter λ as input and outputs the common parameter PP; the accounting node of BC takes the common parameter PP and the parameter r uploaded by DO as input and outputs the parameter P required by each participant. DO ,P DU ,pp,γ,DO,C1 and C2 set their respective signature keys (pk B ,sk B ), and And publish the public key.
[0049] Specifically, the process of step 1 is as follows:
[0050] Step 1.1, Overall Initialization: The consensus node of BC generates common parameters PP = {e, p, g1, g2, G1, G2, G}. T Let {G, H, H1, H2, λ} be a bilinear mapping e: G1 × G2 → G T Among them, G1, G2 and G T Let G be a group of order p with large prime numbers, and g1 and g2 be generators of the group G1 and G2. Define three collision-resistant hash functions: H: {0, 1} * →{0,1} λ H1: {0,1} * →G, H2: G→{0,1} λ , where G is the elliptic curve group, λ is the security parameter representing the fixed length of the binary string, used to output the final pseudo-random value.
[0051] Step 1.2, Node Initialization: Different ledger nodes on BC are responsible for generating and distributing different parameters. First, the parameters of DU are generated. Next, generate the parameters for DO. And the parameters required for zero-knowledge proofs pp = Setup(1 λ C), track the key k, and finally generate the key γ of the invisible pseudo-random function for identity authentication.
[0052] Step 1.3, DO initialization: Select a random number. Upload it to BC to generate parameter P DO Next, set the DO's signature key pair (pk B ,sk B Finally, a data digest H(Y) = (H(y1), H(y2), ..., H(y...) is generated. n )).
[0053] Step 1.4, C1 and C2 initialization: C1 and C2 generate corresponding signature key pairs. and Used for digital signatures on data.
[0054] Step 2: DU submits credentials α and β to the system consensus node for registration. After successful registration, it obtains the required parameters from the chain, generates a signature verification key pair, and publishes the public key.
[0055] Specifically, step 2 involves the following process: DU randomly selects authorization parameters α and β as its identity credentials for system registration. After successful registration, it retrieves the required parameters from the blockchain; and generates the corresponding signature key pair (pk). A ,sk A ), and publish the public key pk A Note: Parameters α and β are unique.
[0056] Step 3: DO and DU each select a random number as a blind factor, and use the common parameter PP and the blind factor to encrypt the data, generating obfuscated ciphertext A,A′,T,. After signing the obfuscated ciphertext A,A′,T,Q, the data is packaged according to class and sent to C1 and C2 respectively.
[0057] Specifically, the process of step 3 is as follows:
[0058] Step 3.1, DU preprocesses: DU first preprocesses its private data by selecting random numbers. The ciphertext is calculated as follows:
[0059]
[0060] Let A′=(A -1 A -2 ,...,A -m Next, calculate a = H1(α). β , for ciphertext A and A -i Generate signature σ respectively A =Sign(sk A ,A), σ′ A =Sign(sk A ,A′), finally, DU will (A,a,σA Send (A′,a,σ′) to C1, and pass (A′,a,σ′) to C1. A Send to C2.
[0061] Step 3.2, DO performs data preprocessing: DO selects random numbers. The ciphertext is calculated as follows:
[0062]
[0063] Next, let T = (T1, T2, ..., T n ),Q=(Q1,Q2,...,Q n Generate signatures σ for T and Q respectively. B =Sign(sk B ,T),σ′ B =Sign(sk B Ultimately, DO will (T, σ). B ), (Q, σ′ B Send them to C1 and C2 respectively.
[0064] Step 4, C1 and C2 will pack the data of DO and DU (A, a, σ) A ), (A′,a,σ′ A ), (T, σ B ), (Q, σ′ B The corresponding user's public key pk is used as input, and the output is a boolean value of 1 or 0. When all results are 1, C1 and C2 take the packaged data sent by DO and DU and the permutation matrix M1 and M2 as input, respectively, to generate the obfuscated ciphertexts U and W.
[0065] Specifically, the process of step 4 is as follows:
[0066] Step 4.1, Signature Verification: After C1 and C2 receive data from DO and DU, they perform signature verification. C1 calculates SVerify(pk) A ,A,a,σ A ),SVerify(pk B ,T,σ B C2 calculates SVerify(pk) A ,A′,a,σ′ A ),SVerify(pk B ,Q,σ′ B If all results are 1, the verification passes; otherwise, the verification fails. If the verification passes, C1 and C2 will execute the delegated calculation task; otherwise, the process will terminate.
[0067] Step 4.2, Execute the delegated calculation task: For C1 calculates U j=H(e(T) j The result is multiplied by the permutation matrix M1 to obtain u = (U1, U2, ..., U...). n ),for C2 calculates W ij =H(e(Q) j A -i The result is then multiplied by the permutation matrix M2 to obtain W = (W 11 W 12 ,...,W mn ).
[0068] Step 4.3, Generate zk-SNARKs proofs: After completing the delegated computing task, the cloud server needs to prove the computing operations and results performed. C1 and C2 respectively call the zero-knowledge concise non-interactive knowledge proof generation algorithm to generate proofs π1=Prove(pp,(T,A),U,ω1) and π2=Prove(pp,(Q,A′),W,ω2).
[0069] Step 4.4, Sign the data: C1 and C2 aggregate all the corresponding data in parallel, package and sign them to generate a signature.
[0070] Step 5: C1 and C2 perform authorization verification on DU. After successful verification, they send the obfuscated ciphertext U and W to DU. After receiving the data, DU performs signature verification and zero-knowledge proof verification.
[0071] Specifically, the process of step 5 is as follows:
[0072] Step 5.1, Authorization Verification: The cloud server authenticates the DU's identity. If the user is authorized, access to the data is allowed; otherwise, the data access request is rejected. Specifically: C1 and C2 calculate the verification information v = F. DH-OPRF (α) and token b = a γ Then, token b is sent to DU; DU uses token b issued by the cloud server to randomize the corresponding account information into verification code v', i.e., calculates... Then, v′ is sent to cloud servers C1 and C2 respectively; finally, C1 and C2 verify whether the verification code v′ of DU matches its corresponding verification information v. If v = v′, C1 will package the data. Send to DU, C2 will package the data Send to DU; if v≠v′, the protocol terminates.
[0073] Step 5.2, Data Correctness and Integrity Verification: After receiving the packaged data from the cloud server, DU performs operation verification and signature verification. If the verification passes, the calculation continues, as follows: DU uses the cloud server's public key. calculate and The signature verification is performed. If all results are 1, the verification is successful and the calculation continues. After the signature verification is successful, DU verifies the zk-SNARKs proof of the cloud server by calculating PVerify(pp,(T,A),U,π1) and PVerify(pp,(Q,A′),W,π2) respectively. If all results are 1, the verification is successful and the user accepts the result returned by the cloud server.
[0074] Step 6: After all the verifications in Step 5 are passed, Du performs statistical information analysis based on the received data.
[0075] Specifically, the process of step 6 is as follows:
[0076] DU performs intersection cardinality calculation based on the received data to obtain the required statistical information. Finally, DU outputs the following information:
[0077]
[0078] Step 7: After successful authorization verification, the access record AR is output using the DU's identity information, tracking key k, and data digest H(Y) as input, and then the DO signs it.
[0079] Specifically, the process of step 7 is as follows:
[0080] After successful authorization verification, the DU's identity information is encrypted and an access record is generated and stored off-chain, as follows: The DU's identity information is encrypted using the AES encryption mechanism to obtain the ciphertext ID = Enc(k, ID), where k is the key. The access record is defined as: AR = (ID, H(Y)). Next, the DO needs to sign the access record to obtain the signature σ = Sign(sk). A Finally, DU uploads the data digest H(Y) to the blockchain, stores (AR, σ) off-chain, and implements a rotation mechanism for the logs. During rotation, each access record is guaranteed to contain the cryptographic hash value of the previous log to ensure the integrity of the log chain. Old logs are archived to cold storage to reduce access frequency. At the same time, segmented storage further enhances data security.
[0081] Step 8: When a security incident such as a data breach occurs, applicants who meet the application requirements initiate an audit request to trace access records for audit purposes.
[0082] Specifically, step 8 involves the following process: Application conditions: DO or DU that has passed authorization verification and correctly submitted the data digest; A qualified requester applies to obtain the access log, triggering the audit process: The DO first performs signature verification and calculates SVerify(pk) A If the result is 1, the verification is successful. After successful verification, the ciphertext is decrypted to obtain id = Dec(k, ID), and the plaintext access log is finally provided for review; otherwise, an additional file corruption warning will be returned.
[0083] Next, we will compare and analyze the application with related technologies from three aspects: theoretical analysis, functional comparison and experimental evaluation, to illustrate the advantages of this application. Among them, the related technologies include: [1] Y. Yang, Y. Yang, X. Chen, X. Dong, Z. Cao, and J. Shen, “Dmpsi: Efficient scalable delegated multiparty psi and psi-ca with oblivious prf,” IEEE Transactions on Services Computing, 2024; [2] A. Wu, X. Xin, J. Zhu, W. Liu, C. Song, and G. Li, “Cloud-assisted laconic private set intersectioncardinality,” IEEE Transactions on Cloud Computing, 2024; [3] AA Jolfaei, H. Mala, and M. Zarezadeh, “Eo-psi-ca: Efficient out sourced private set intersectioncardinality,” Journal of Information Security and Applications, vol.65, p.102996, 2022; [4] S.Lv, J.Ye, S.Yin, X.Cheng, C.Feng, X.Liu, R.Li, Z.Li, Z.Liu, andL.Zhou, "Unbalanced private set intersection cardinality protocol with low communication cost," Future Generation Computer Systems, vol.102, pp.1054–1061, 2020; [5] S.Sharma, Y.Li, S.Mehrotra, N.Panwar, P.Gupta, and D.Ghosh, “Prism: Privacy-preserving and verifiable set computation over multiowner secret sharedoutsourced databases,” IEEE Transactions on Dependable and Secure Computing, vol.21, no.3, pp.1355–1371, 2023;[6]X.Liu,R.Wang,L.Peng,D.Luo,G.Xu,X.-B.Chen,N.Xiong,and .
[0084] First, in terms of theoretical analysis: this application is compared with related technologies. These schemes utilize different techniques, including OPRF, Bloom filters, homomorphic encryption, NTRU encryption, secret sharing, etc. The computational and communication complexities are shown in Table 1, while Table 2 compares the computational costs of this application with other schemes.
[0085] Table 1 Complexity Analysis
[0086]
[0087] Scheme [3] proposes two protocols with OPRF as the main component. This application only compares it with the cardinality calculation related protocol (DMPSI-CA). The computational complexity of this protocol is mainly determined by the hash, PRF calculation and set intersection operation at each stage. The final complexity is about O(m·d). The communication complexity is proportional to the dataset size m or n. The overall complexity is O(m·d·ω), where d is the size of the hash bucket and ω is the size of the PRF output. In Scheme [2], the sender needs to perform exponential operation and bilinear mapping operation during the protocol execution process. The complexity of bilinear pairing is O(n). 2 Here, n is the number of data elements involved in the operation. The receiving end also needs to perform similar exponentiation and hash operations. Since m > n, the overall computational complexity is denoted as O(m). 2 In terms of communication costs, the sender transmits a series of encrypted messages to the cloud server in each session, and the communication complexity is proportional to the data size n. Similarly, the receiver receives and processes messages sent from the cloud server and other senders. Therefore, the communication complexity is related to the dataset size m and the total number of messages received, and the communication complexity can be expressed as O(m). Overall, the computational operation of this protocol is relatively fast, and the overall complexity is moderate. The communication complexity is linearly related to the dataset size and the number of participants. In addition, in the scheme [5], the addition and multiplication properties of secret sharing are used to preload data onto the server, and its computational complexity is higher than that of the scheme in this application.
[0088] Table 2 Total computation time cost for different protocols
[0089]
[0090] Note: T Exp ,T Hash and T Mul These represent the time required for an exponentiation, hash, and multiplication operation, respectively.
[0091] When analyzing the communication complexity of the proposed protocol, the focus is on the amount of information exchanged between the participants. Assuming the protocol involves the transmission of multiple data sets, with the amount of data sent by each party proportional to the size of the data set, the communication complexity is O(n+m), where n and m are the sizes of the data sets for each participant. Simultaneously, the data owner only needs to perform a single message transmission, requiring no subsequent participation, thus significantly reducing overall communication overhead during multiple protocol executions. Regarding computational costs, since the costly bilinear pairing computation is delegated to the cloud server, the computational complexity of ILS is mainly concentrated on data processing such as generating data digests and encryption operations by the participants. Similarly, the data owner only needs to perform one computation, which can be reused multiple times during subsequent protocol executions, greatly reducing the amortized computational costs across multiple protocol executions. Overall, this application demonstrates high efficiency and is well-suited to the practical needs of the logistics industry.
[0092] Second, in terms of functional comparison: see Table 3 for functional comparison. Scheme [6] cannot compute and store data in the cloud, which is not conducive to large-scale data computation in practical applications. Schemes [1], [2], and [4] introduce cloud servers to alleviate the local computing burden, but these protocols are all based on the assumption that the cloud server is honest. In practice, this is weaker than other protocols. Scheme [5] takes this into account and realizes the verification of cloud server computation, but this protocol does not consider the verification of transmission results and requires a secure channel to transmit data to prevent potential attacks from eavesdroppers.
[0093] Table 3. Functional Comparison of Different Schemes
[0094]
[0095] Where: √ indicates support, and × indicates the opposite. F n1 Data outsourcing; F n2 Verifiable; F n3 Insecure channel transmission; F n4 Access control; F n5 Audit trail.
[0096] This application randomizes private data before uploading it to the server, eliminating the need for any trusted entity to perform calculations on the plaintext data. This makes the data stored in the cloud appear as indistinguishable random numbers, thus achieving privacy and security. Secondly, this application verifies the integrity and correctness of the transmission results through signature verification. Even if a network attacker intercepts and corrupts the transmitted data, they cannot obtain the true information, and the recipient can detect the attacker's actions. Furthermore, the protocol supports server-side authorization verification of user identities, which enhances the protection of server computing resources and ensures the security of private information. Finally, this application supports visitor tracking, ensuring traceability and accountability for data usage. Overall, these functions collectively construct a robust security architecture, effectively reducing the risks associated with data interception, unauthorized access, untrusted servers, or computational errors. It ensures the integrity and confidentiality of shared logistics information and is suitable for practical applications by logistics-related enterprises.
[0097] Third, in terms of experimental evaluation: the application is compared with related technologies through experiments. The experimental environment is configured on a machine equipped with an AMD Ryzen 5 3500U processor, 16-GB RAM and Linux operating system. The protocol is written in Python language, and bilinear pairing is instantiated by bls12_381 elliptic curve based on the py_ecc library, providing about 128 bits of security. The selected hash function is SHA-256. Hyperledger Composer is used for blockchain development, and the chaincode is written in Go language. Hyperledger Fabric is managed by containerization through Docker and Docker Compose. In terms of network configuration, the default port setting is used to facilitate communication between containers. In ILS, cloud servers have a large amount of computing resources and communication bandwidth. Therefore, when evaluating performance, only the computing burden and communication cost of the data owner and user are considered. In addition, for the scheme [1], let k=7 and sp=112 to minimize the false positive probability of the Bloom filter and achieve the best overall performance.
[0098] As shown in Figure 3, this application is compared with schemes [1], [2], [3] in terms of 2 10 to 2 20The computational cost under different set sizes. As can be seen from Figure 3(a), the computational complexity of the data owner in each protocol is polynomial. However, in practical applications, when an enterprise faces multiple protocol execution requests, as the data owner, there is no need to recalculate the required data, and the message can be updated quickly. Then, as the number of protocol executions increases, the amortized computational cost of a protocol will decrease. As can be seen from Figure 3(b), the computational cost of the data user is linearly related to the size of the input data. Overall, as shown in Figure 3(c), Scheme [2] and Scheme [3] have higher computational costs compared to our protocol. As the amount of data increases, the total computational cost of the participants in Scheme [1] is lower than that of this application. However, in practical applications, when facing large set data, this application still has better computational burden performance, and has more practical characteristics than Scheme [1] which only performs intersection calculation operations.
[0099] Figure 4 shows the communication cost comparison of various protocols. As can be seen from Figure 4, the communication overhead of each party increases linearly with the increase in the amount of input data. Among them, scheme [1] has the highest communication burden, especially when the input dataset size is 2... 10 In the previous case, it cost approximately 10MB. In this application, because the data user needs to interact with the cloud server for authorization and authentication, the communication cost is slightly higher than that of the data owner. As shown in Figure 4(c), overall, the communication cost of this application is similar to that of the solution [2], but in practical applications, this application can resist malicious attacks and has higher security.
[0100] Finally, Figure 5 shows that the user dataset size is fixed at 2. 10 The performance of the blockchain is tested. Figure 5(a) shows the trend of transaction throughput under different loads. This application simulates multiple transaction requests with different numbers of concurrent users and records the transaction success rate and response time under each condition. It can be seen that the blockchain transaction throughput of ILS shows a trend of first increasing and then stabilizing with the increase of concurrent users. When the number of concurrent users reaches about 15, it reaches saturation, the transaction processing speed begins to decrease, resulting in a slight decrease in throughput. The resource consumption is shown in Figures 5(b) and 5(c), and the resource consumption under different loads is recorded using Docker resource monitoring. The indicators shown in Figure 5 show that as the number of concurrent users increases, the usage of CPU, memory, and storage increases within a reasonable range. This indicates that ILS can effectively utilize CPU resources to handle the increased concurrent requests, and the blockchain design is relatively efficient.
[0101] In summary, this application has low computational and communication overhead, while maintaining high security, making it suitable for logistics companies with scarce computing resources and large amounts of data.
[0102] Corresponding to the above embodiments, the present invention also proposes an electronic device, which includes a memory, a processor, and a computer program stored in the memory. When the computer program is executed by the processor, it implements the above-described blockchain-supported smart logistics authorization cloud-assisted PSI-CA method.
[0103] The electronic device of this invention improves the security of user data by implementing the blockchain-supported smart logistics authorization cloud-assisted PSI-CA method.
[0104] It should be noted that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.
[0105] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0106] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0107] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A blockchain-supported smart logistics authorization cloud-assisted PSI-CA method, characterized in that, It includes multiple types of entities: data owner DO, data user DU, blockchain BC, first cloud server C1 and second cloud server C2; The method includes: Step 1: The consensus node of BC takes the security parameter λ as input and outputs the common parameter PP; the accounting node of BC takes the common parameter PP and the parameter r uploaded by DO as input and outputs the parameter P required by each participant. DO ,P DU ,pp,γ,DO,C1 and C2 set their respective signature keys (pk B ,sk B ), and And publish the public key; Step 2: DU submits credentials α and β to the system consensus node for registration. After successful registration, it obtains the required parameters from the chain, generates a signature verification key pair, and publishes the public key. Step 3: DO and DU each select a random number as a blind factor, and use the common parameter PP and the blind factor to encrypt the data, generating obfuscated ciphertexts A, A′, T, Q. After signing the obfuscated ciphertexts A, A′, T, Q, the data is packaged according to class and sent to C1 and C2 respectively. Step 4, C1 and C2 will pack the data of DO and DU (A, a, σ) A ), (A′,a,σ′ A ), (T, σ B ), (Q, σ′ B The corresponding user's public key pk is used as input, and the output is a boolean value of 1 or 0. When all results are 1, C1 and C2 take the packaged data sent by DO and DU and the permutation matrix M1 and M2 as input, respectively, to generate the obfuscated ciphertext U and W. Step 5: C1 and C2 perform authorization verification on DU. After successful verification, they send the obfuscated ciphertext U and W to DU. After receiving the data, DU performs signature verification and zero-knowledge proof verification. Step 6: After all the verifications in Step 5 are passed, DU performs statistical information analysis based on the received data; Step 7: After successful authorization verification, the access record AR is output using the DU's identity information, tracking key k, and data digest H(Y) as input, and then the DO signs it. Step 8: When a data breach security incident occurs, applicants who meet the application requirements initiate an audit request to trace access records for audit purposes.
2. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 1, characterized in that, The specific process of step 1 is as follows: Step 1.1, Overall Initialization: The consensus node of BC generates common parameters PP = {e, p, g1, g2, G1, G2, G}. T Let {G, H, H1, H2, λ} be a bilinear mapping e: G1 × G2 → G T Among them, G1, G2 and G T Let G be a group of order p with large prime numbers, and g1 and g2 be generators of the group G1 and G2. Define three collision-resistant hash functions: H: {0, 1} * →{0,1} λ H1: {0,1} * →G, H2: G→{0,1} λ , where G is the elliptic curve group, λ is the security parameter, representing the fixed length of the binary string, used to output the final pseudo-random value; Step 1.2, Node Initialization: Different ledger nodes on BC are responsible for generating and distributing different parameters. First, the parameters of DU are generated. Next, generate the parameters for DO. And the parameters required for zero-knowledge proofs pp = Setup(1 λ C), track the key k, and finally generate the key γ of the unintentional pseudo-random function for identity authentication; Step 1.3, DO initialization: Select a random number. Upload it to BC to generate parameter P DO Next, set the DO's signature key pair (pk B ,sk B Finally, a data digest H(Y) = (H(y1), H(y2), ..., H(y...) is generated. n )); Step 1.4, C1 and C2 initialization: C1 and C2 generate corresponding signature key pairs. and Used for digital signatures on data.
3. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 2, characterized in that, The specific process of step 2 is as follows: DU randomly selects authorization parameters α and β as its identity credentials for system registration. After successful registration, it retrieves the required parameters from the blockchain and generates the corresponding signature key pair (pk). A ,sk A ), and publish the public key pk A .
4. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 3, characterized in that, The specific process of step 3 is as follows: Step 3.1, DU preprocesses: DU first preprocesses its private data by selecting random numbers. The ciphertext is calculated as follows: Let A′=(A -1 A -2 ,...,A -m Next, calculate a = H1(α). β , for ciphertext A and A -i Generate signature σ respectively A =Sign(sk A ,A), σ′ A =Sign(sk A ,A′), finally, DU will (A,a,σ A Send (A′,a,σ′) to C1, and pass (A′,a,σ′) to C1. A Send to C2; Step 3.2, DO performs data preprocessing: DO selects random numbers. The ciphertext is calculated as follows: Next, let T = (T1, T2, ..., T n ),Q=(Q1,Q2,...,Q n Generate signatures σ for T and Q respectively. B =Sign(sk B ,T),σB′ B =Sign(sk B Finally, DO will (T, σ) B ), (Q, σ′ B Send them to C1 and C2 respectively.
5. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 4, characterized in that, The specific process of step 4 is as follows: Step 4.1, Signature Verification: After C1 and C2 receive data from DO and DU, they perform signature verification. C1 calculates SVerify(pk) A ,A,a,σ A ),SVerify(pk B ,T,σ B C2 calculates SVerify(pk) A ,A′,a,σ′ A ),SVerify(pk B ,Q,σ′ B If all results are 1, the verification passes; otherwise, the verification fails. If the verification passes, C1 and C2 will execute the delegated calculation task; otherwise, the process will terminate. Step 4.2, Execute the delegated calculation task: For Calculate U j =H(e(T) j The result is multiplied by the permutation matrix M1 to obtain U = (U1, U2, ..., U...). n ),for j∈[n], C2 calculates W ij =H(e(Q) j A -i The result is then multiplied by the permutation matrix M2 to obtain W = (W 11 W 12 ,...,W mn ); Step 4.3, Generate zk-SNARKs proofs: After completing the delegated computing task, the cloud server needs to prove the computing operations and results performed. C1 and C2 respectively call the zero-knowledge concise non-interactive knowledge proof generation algorithm to generate proofs π1=Prove(pp,(T,A),U,ω1) and π2=Prove(pp,(Q,A′),W,ω2). Step 4.4, Sign the data: C1 and C2 aggregate all the corresponding data in parallel, package and sign them to generate a signature.
6. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 5, characterized in that, The specific process of step 5 is as follows: Step 5.1, Authorization Verification: The cloud server authenticates the DU's identity. If the user is authorized, access to the data is allowed; otherwise, the data access request is rejected. Specifically: C1 and C2 calculate the verification information v = F. DH-OPRF (α) and token b = a γ Then, token b is sent to DU; DU uses token b issued by the cloud server to randomize the corresponding account information into verification code v', i.e., calculates... Then, v′ is sent to cloud servers C1 and C2 respectively; finally, C1 and C2 verify whether the verification code v′ of DU matches its corresponding verification information v. If v = v′, C1 will package the data. Send to DU, C2 will package the data Send to DU; if v≠v′, the protocol terminates. Step 5.2, Data Correctness and Integrity Verification: After receiving the packaged data from the cloud server, DU performs operation verification and signature verification. If the verification passes, the calculation continues, as follows: DU uses the cloud server's public key. calculate and The signature verification is performed. If all results are 1, the verification is successful and the calculation continues. After the signature verification is successful, DU verifies the zk-SNARKs proof of the cloud server by calculating PVerify(pp,(T,A),U,π1) and PVerify(pp,(Q,A′),W,π2) respectively. If all results are 1, the verification is successful and the user accepts the result returned by the cloud server.
7. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 6, characterized in that, The specific process of step 6 is as follows: DU performs intersection cardinality calculation based on the received data to obtain the required statistical information. Finally, DU outputs the following information:
8. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 7, characterized in that, The specific process of step 7 is as follows: After successful authorization verification, the DU's identity information is encrypted and an access record is generated and stored off-chain, as follows: The DU's identity information is encrypted using the AES encryption mechanism to obtain the ciphertext ID = Enc(k, ID), where k is the key. The access record is defined as: AR = (ID, H(Y)). Next, the DO needs to sign the access record to obtain the signature σ = Sign(sk). A Finally, DU uploads the data digest H(Y) to the blockchain, stores (AR, σ) off-chain, and implements a rotation mechanism for the logs. During rotation, it ensures that each access record contains the cryptographic hash value of the previous log to ensure the integrity of the log chain. Old logs are archived to cold storage to reduce access frequency.
9. The blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to claim 7, characterized in that, The specific process of step 8 is as follows: Application requirements: DO or DU that has passed authorization verification and correctly submitted data summary; Eligible requesters request access logs, triggering the audit process: DO first performs signature verification, then calculates SVerify(pk) A If the result is 1, the verification is successful. After successful verification, the ciphertext is decrypted to obtain id = Dec(k, ID), and the plaintext access log is finally provided for review; otherwise, an additional file corruption warning will be returned.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, When the computer program is executed by the processor, it implements the blockchain-supported smart logistics authorization cloud-assisted PSI-CA method according to any one of claims 1-9.
Citation Information
Patent Citations
Private data sharing method and device
CN117278236A
Power data privacy protection and privacy intersection method and system based on block chain
CN118821202A