A blockchain and proxy re-encryption-based outbound data sampling supervision method

By using a blockchain-based and proxy-based re-encryption method, random checks and decryption management of enterprise data export processes are conducted, solving the problems of privacy leaks and low regulatory efficiency in the process of enterprise data export, and improving regulatory transparency and compliance.

CN119646875BActive Publication Date: 2025-11-25XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411705240.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-11-25
Estimated Expiration
2044-11-26

AI Technical Summary

Technical Problem

In the current technology, there is a lack of effective compliance monitoring means during the process of corporate data leaving the country, which leads to the risk of privacy leakage and low regulatory efficiency. Moreover, the existing sampling inspection methods cannot ensure the compliance and transparency of regulatory authorities while protecting corporate privacy.

Method used

By employing a blockchain-based and proxy-based re-encryption method, public and private key pairs are generated to encrypt data. Random checks are conducted and the data is uploaded to the blockchain. After verification by the re-encryption key on the blockchain node, the data is decrypted, ensuring that regulatory authorities decrypt only within a specific scope. This is combined with the company's declaration records for verification, achieving transparent and fair regulation.

Benefits of technology

This allows regulatory authorities to decrypt data only within the scope of random checks, avoiding large-scale privacy leaks, improving regulatory efficiency and compliance, enhancing corporate privacy protection and regulatory transparency, and ensuring the traceability and credibility of regulatory work.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119646875B_ABST
    Figure CN119646875B_ABST
Patent Text Reader

Abstract

The application relates to a kind of outbound data sampling supervision methods based on blockchain and proxy re-encryption, comprising: generating the first public-private key pair of data outbound enterprise and the second public-private key pair of supervisor according to public parameter;First public-private key pair is used to encrypt plaintext data;The first ciphertext obtained by encryption is sampled, and the second ciphertext is obtained, and the sampling information obtained according to the second ciphertext is sent to the blockchain node;When the re-encryption key is verified, the blockchain node re-encrypts the second ciphertext using the generated re-encryption key;The third ciphertext obtained is decrypted to obtain plaintext data;The plaintext data is checked using the declaration record, and the obtained sampling result is uploaded to the blockchain node.The application avoids the risk of large-scale privacy leakage, improves the supervision efficiency and the effectiveness and reliability of supervision, and can provide sampling information as evidence, improves the transparency of the supervision process, and enhances the trust between enterprises and regulatory authorities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption processing, and more specifically, to a method for random inspection and supervision of outbound data based on blockchain and proxy re-encryption. Background Technology

[0002] Before engaging in cross-border data transfer activities, enterprises are required by relevant policies to declare the details of any important or personal data to regulatory authorities. Only after regulatory approval can the data transfer proceed, allowing the transmission of the declared data overseas. However, most data transmission methods currently employ encryption. If enterprises secretly transmit undeclared, security- and socially sensitive data overseas using encrypted traffic, it could lead to irreparable privacy breaches and financial losses. Furthermore, real-time decryption and monitoring of all outbound data to determine compliance would be extremely resource-intensive for regulatory authorities. Therefore, it is advisable to conduct random or periodic inspections of outbound data and require enterprises to cooperate with regulatory compliance oversight.

[0003] During the cross-border data transfer process by domestic enterprises, regulatory authorities need to monitor the compliance of the transmitted data in real time. However, existing analysis and monitoring technologies for encrypted data traffic lack sufficient accuracy. Conversely, if regulatory authorities had the power to decrypt all encrypted data stored and transmitted by enterprises, it could lead to the risk of privacy leaks and undermine the credibility of regulatory authorities. Furthermore, enterprises might upload the data fingerprints of non-compliant data as legitimate data fingerprints for registration, thereby allowing non-compliant data to be judged as legitimate data and bypass cross-border data compliance monitoring. While sampling inspections of enterprises' plaintext data have become a possible regulatory tool, there is currently a lack of technical solutions that, to a certain extent, protect enterprise privacy while managing access permissions for enterprises' plaintext cross-border data within the scope of sampling inspections. In addition, sampling inspections need to be implemented transparently, fairly, and traceably to ensure that each inspection is auditable. Currently, there are no reasonable technical solutions to address these issues. Summary of the Invention

[0004] To address the aforementioned problems in existing technologies, this invention provides a method for random inspection and supervision of outbound data based on blockchain and proxy re-encryption.

[0005] According to a first aspect of the present invention, a method for random inspection and supervision of outbound data based on blockchain and proxy re-encryption is provided, the method comprising:

[0006] Generate a first public-private key pair for the data exporting company and a second public-private key pair for the regulatory personnel based on public parameters;

[0007] The plaintext data is encrypted using the first public and private key pair to obtain the first ciphertext;

[0008] During data monitoring, the first ciphertext is sampled to obtain the second ciphertext, and the sampling information obtained from the second ciphertext is sent to the blockchain node for on-chain processing.

[0009] Through the blockchain node, a re-encryption key is generated based on the first public-private key and the second public-private key pair;

[0010] After the re-encryption key is verified for integrity and non-repudiation by the blockchain node, the second ciphertext is re-encrypted using the re-encryption key to obtain the third ciphertext.

[0011] The third ciphertext is decrypted to obtain the plaintext data;

[0012] The plaintext data is verified using the declaration records of the outbound enterprises, and the sampling results are obtained and uploaded to the blockchain node.

[0013] Optionally, before decrypting the third ciphertext to obtain the plaintext data, the method further includes:

[0014] The sampling information is updated according to the third encrypted text, and the updated sampling information is returned to the supervisor.

[0015] The third ciphertext is obtained based on the updated sampling information.

[0016] Optionally, the common parameters are PP = (G1, G2, e, g, g1, H); where G1 is a first q-order bilinear group, G2 is a second q-order bilinear group, the bilinear mapping is e: G1 × G1 → G2, g is the generator of G1, g1 is the group element of G1, and the hash function is H: {0, 1}. * →G1.

[0017] Optionally, the first public-private key pair is (PK) i SK i The second public-private key pair is (PK). j SK j );in, SK i =x i , SK j =y j x i For the first randomly selected value, y j The second randomly selected value, Let i represent the group of q-order integers consisting of elements (1,...,q-1), i represent the enterprise exporting the data, and j represent the regulatory personnel.

[0018] Optionally, the first ciphertext is C = (C1, C2, C3); where, r i The third randomly selected value, M represents the plaintext data.

[0019] Optionally, the sampling information is {i,j,PK} j ,C′,time1};where C′ is the second ciphertext, and time1 represents the sampling timestamp.

[0020] Optionally, the re-encryption key is RK. j = (RK1, RK2, RK3), where, r j The fourth randomly selected value,

[0021] Optionally, the third ciphertext is C″=(C1″,C2″,C3″,C4″); where C1″=C1′, C2″=C2′·e(C1′,RK2), C3=RK1, C4″=H(H(C1″)||H(C1″||C2″)||H(C2″||C3″)), C′=(C1′,C2′,C3′) is the second ciphertext, C1′ represents the sampled C1, C2′ represents the sampled C2, and C3′ represents the sampled C3.

[0022] Optionally, the step of verifying the plaintext data using the declaration records of the data exporting enterprise, obtaining the sampling inspection results, and uploading the sampling inspection results to the blockchain node includes:

[0023] The plaintext data is verified using the declaration records of the outbound enterprises to obtain the sampling results and the signature value corresponding to the sampling results;

[0024] The sampling results and the signature value are uploaded to the blockchain node to perform a secondary update on the updated sampling information.

[0025] The technical solution provided by this invention may include the following beneficial effects:

[0026] Through the aforementioned technical solution, employing re-encryption technology, regulatory authorities can grant one-time decryption authorization only for data within the scope of random checks, without needing to decrypt all enterprise data, thus avoiding the risk of large-scale privacy leaks. Simultaneously, since the encrypted text can only be decrypted within a specific inspection scope, it ensures that regulation is conducted only within the necessary range, greatly enhancing enterprise data privacy protection and improving the efficiency of regulatory authorities. By providing regulatory authorities with one-time decryption permissions through proxy re-encryption technology, plaintext access permission management is achieved within a reasonable scope. The re-encryption key is generated only for the inspected data, ensuring that regulatory authorities can only decrypt specific data without requiring enterprises to provide the original decryption key, thus avoiding privacy leaks while improving the effectiveness and reliability of compliance checks. By recording each inspection information on blockchain nodes, all data becomes immutable and traceable, ensuring the openness and fairness of regulatory work, and providing inspection information as evidence in case of disputes, thereby improving the transparency of the regulatory process and enhancing trust between enterprises and regulatory authorities.

[0027] Other features and advantages of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0028] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the following detailed description to explain the invention, but do not constitute a limitation thereof. In the drawings:

[0029] Figure 1 This is a flowchart illustrating an outbound data sampling and supervision method based on blockchain and agent re-encryption, according to an exemplary embodiment.

[0030] Figure 2 This is a flowchart illustrating an outbound data sampling and supervision method based on blockchain and agent re-encryption, according to an exemplary embodiment. Detailed Implementation

[0031] Figure 1 This is a flowchart illustrating an outbound data sampling and supervision method based on blockchain and proxy re-encryption, according to an exemplary embodiment. Figure 1 As shown, the method includes the following steps:

[0032] S101. Generate the first public-private key pair for the data exporting enterprise and the second public-private key pair for the regulatory personnel based on public parameters.

[0033] Optionally, Figure 2 This is a flowchart illustrating an outbound data sampling and supervision method based on blockchain and proxy re-encryption, according to an exemplary embodiment. Figure 2 As shown, the Trust Center provides security parameter 1 through an algorithm. λThe common parameters are PP = (G1, G2, e, g, g1, H); where G1 is the first q-order bilinear group, G2 is the second q-order bilinear group, the bilinear mapping is e: G1 × G1 → G2, g is the generator of G1, g1 is the group element of G1, and the hash function is H: {0, 1}. * →G1.

[0034] Optionally, the first public-private key pair is (PK) i SK i The second public-private key pair is (PK). j SK j );in, SK i =x i , SK j =y j x i For the first randomly selected value, y j The second randomly selected value, Let i represent the group of q-order integers consisting of elements (1,...,q-1), where i represents the enterprise exporting the data and j represents the regulatory personnel.

[0035] S102. Encrypt the plaintext data using the first public and private keys to obtain the first ciphertext.

[0036] S103. When monitoring data, the first ciphertext is sampled to obtain the second ciphertext, and the sampled information obtained from the second ciphertext is sent to the blockchain node for on-chain processing.

[0037] Understandably, referring to Figure 2 Steps S102 to S103 involve uploading the sampled ciphertext to the blockchain. During this stage, the data exporting company has completed its data export declaration, and the relevant declaration records are filed and stored by the regulatory personnel responsible for the data exporting company's business. The data exporting company uses its first public key to encrypt the declared plaintext data and transmits it overseas. Before or during transmission, regulatory personnel can obtain a portion of the ciphertext (second ciphertext) through random sampling and send the sampled second ciphertext and related information to the blockchain node, requesting re-encryption for compliance checks of the export data.

[0038] Optionally, the first ciphertext is C = (C1, C2, C3); where, r i The third randomly selected value, M represents plaintext data.

[0039] Optionally, the sampling information is {i,j,PK}.j ,C′,time1};where C′ is the second ciphertext and time1 represents the sampling timestamp.

[0040] It is understandable that during the encryption phase before data leaves the country, the companies sending the data randomly select [the appropriate data type]. The plaintext data M is encrypted using the first public key to generate the first ciphertext C = (C1, C2, C3);

[0041] The first ciphertext is decrypted using the following calculation steps:

[0042]

[0043] C3 is used for ciphertext integrity and non-repudiation checks:

[0044] After data encryption is completed, companies exporting data can store the first encrypted data in a data center or export the data.

[0045] Assuming regulatory authorities have deployed traffic monitoring equipment at the data export point of the enterprise, or that regulatory personnel have direct access to encrypted information during the data export process, they can conduct scheduled / irregular encrypted data sampling inspections according to relevant sampling inspection frequency rules. Let's say that in a certain system state, the regulatory personnel obtain a second encrypted data C′=(C1′,C2′,C3′) through sampling. This sampling information {i,j,PK} j The encrypted data (C′, time1) is sent to a blockchain node for random checks before being uploaded to the chain. Subsequently, companies exporting data can access the legality of this regulatory record at any time. Because C3 is used for verifying the integrity and non-repudiation of the encrypted data, regulators cannot tamper with the encrypted content.

[0046] S104. Generate a re-encryption key based on the first public-private key and the second public-private key pair through the blockchain node.

[0047] Understandably, during the re-encryption key generation phase, the blockchain node first sends a re-encryption key generation request to the company whose data is being exported. This request mainly contains the regulator's second public key PK. j Companies exporting data across borders use their first private key, SK. i Second public key PK j Execute the re-encryption key generation algorithm and assign the re-encryption key RK j =(RK1,RK2,RK3) are sent to the blockchain node.

[0048] Optionally, the re-encryption key is RK j = (RK1, RK2, RK3), where, rj The fourth randomly selected value,

[0049] S105. After the re-encryption key is verified for integrity and non-repudiation by the blockchain node, the second ciphertext is re-encrypted using the re-encryption key to obtain the third ciphertext.

[0050] Optionally, the third ciphertext is C″=(C1″,C2″,C3″,C4″); where C1″=C1′, C2″=C2′·e(C1′,RK2), C3=RK1, C4″=H(H(C1″)||H(C1″||C2″)||H(C2″||C3″)), and C′=(C1′,C2′,C3′) is the second ciphertext, where C1′ represents the sampled C1, C2′ represents the sampled C2, and C3′ represents the sampled C3. It is worth noting that after the re-encryption key is verified for integrity and non-repudiation by the blockchain nodes, the blockchain nodes use the re-encryption key generated by the outbound enterprise to re-encrypt the second ciphertext to obtain the third ciphertext.

[0051] S106. Decrypt the third ciphertext to obtain the plaintext data.

[0052] Optionally, prior to S106, the method may further include:

[0053] The sampling information is updated according to the third encrypted message, and the updated sampling information is returned to the regulatory personnel.

[0054] The third ciphertext was obtained based on the updated sampling information.

[0055] Understandably, at this stage, the blockchain node receives the re-encryption key RK from the company exporting the data. j After =(RK1,RK2,RK3), the integrity and non-repudiation of the re-encryption key are first verified using the following formula: If the verification passes, the second ciphertext C′=(C1′,C2′,C3′) is re-encrypted to obtain the third ciphertext C″=(C1″,C2″,C3″,C4″).

[0056] Blockchain nodes use a third-party ciphertext to update the sampling information, obtaining the updated sampling information {i,j,PK}. j ,C′,C″,time1}, and return the third ciphertext C″ to the regulator, who will then complete the further decryption and plaintext compliance check phase.

[0057] S107. Verify plaintext data using the declaration records of data exporting enterprises, obtain sampling results, and upload the sampling results to the blockchain node.

[0058] Optionally, S107 may include:

[0059] By using the declaration records of companies exporting data, plaintext data is verified to obtain the sampling results and the corresponding signature values.

[0060] The sampling results and signature values ​​are uploaded to the blockchain node for a second update of the sampling information.

[0061] Understandably, this stage is performed by regulators. After receiving the third ciphertext C″=(C1″,C2″,C3″,C4″) sent by the blockchain node, the regulators first check... If the ciphertext is intact, then use the second private key SK. j The third ciphertext is decrypted using the following algorithm: After obtaining the plaintext data M, the plaintext data M is verified to determine whether it conforms to the original data export declaration record of the data exporting enterprise i, and the result of this sampling inspection and the corresponding signature value are generated. Sig is the digital signature algorithm. Supervisory personnel upload the inspection results and their signature values ​​to the blockchain node. The blockchain node uses these results and signature values ​​to update the inspection information, obtaining {i,j,PK}. j ,C′,C″,time1,result,δ,time2}, where time2 is the timestamp for generating the sampling results. If the sampling results do not match the declared information, corresponding violations will be dealt with.

[0062] The preferred embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the specific details of the above embodiments. Within the scope of the technical concept of the present invention, various simple modifications can be made to the technical solution of the present invention, and these simple modifications all fall within the protection scope of the present invention.

[0063] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, the present invention will not describe the various possible combinations separately.

[0064] Furthermore, various different embodiments of the present invention can be combined in any way, as long as they do not violate the spirit of the present invention, they should also be regarded as the content disclosed by the present invention.

Claims

1. A method for outbound data sampling supervision based on blockchain and proxy re-encryption, characterized in that, The method comprises: According to the public parameter, a first public-private key pair of the data export enterprise and a second public-private key pair of the supervisor are generated; wherein the public parameter is ; wherein, is a first order bilinear group, is a second order bilinear group, and a bilinear mapping , is a generator of , is a group element of , and a hash function ; the first public-private key pair is , and the second public-private key pair is ; wherein, , , , , is a first randomly selected value, is a second randomly selected value, , represents an order integer group composed of elements , represents the data export enterprise, represents the supervisor; The plaintext data is encrypted by using the first public-private key pair to obtain first ciphertext; wherein the first ciphertext is ; wherein, , , , is a third randomly selected value, , is the plaintext data; In the data monitoring, the first ciphertext is sampled to obtain a second ciphertext, and sampling information obtained according to the second ciphertext is sent to a blockchain node for chaining; wherein the sampling information is ; wherein, is the second ciphertext, indicates a sampling timestamp; generating a re-encryption key by the blockchain node according to the first public-private key and the second public-private key; When the re-encryption key is verified by integrity and non-repudiation of the blockchain node, the second ciphertext is re-encrypted by using the re-encryption key to obtain third ciphertext; wherein the re-encryption key is , wherein, , , , is a fourth randomly selected value, ; decrypting the third ciphertext to obtain the plaintext data; wherein the third ciphertext is ; wherein, , , , , is the second ciphertext, represents the , represents the , represents the ; checking the plaintext data by using the declaration record of the data export enterprise, obtaining an inspection result, and uploading the inspection result to the blockchain node; wherein, before the third ciphertext is decrypted to obtain the plaintext data, the method further comprises: updating the inspection information according to the third ciphertext, and returning the updated inspection information to the supervisor; obtaining the third ciphertext according to the updated inspection information; the method of checking the plaintext data by using the declaration record of the data export enterprise, obtaining an inspection result, and uploading the inspection result to the blockchain node comprises: checking the plaintext data by using the declaration record of the data export enterprise, obtaining an inspection result and a signature value corresponding to the inspection result; uploading the inspection result and the signature value to the blockchain node to update the updated inspection information again.

Citation Information

Patent Citations

  • Method and system for combining re-encryption and block chain

    CN111222155A

  • Data sharing method and system based on decentration and distributed proxy re-encryption

    CN113556363A