Data sharing method, device, equipment and storage medium based on broadcast encryption

By introducing smart contract and ring signature technology into the broadcast encryption system, combined with onion routing technology, the problem of identity privacy information leakage during data sharing is solved, and the concealment of the identity of the data recipient and the security of data sharing is improved.

CN119652671BActive Publication Date: 2025-05-23HUNAN TIAN HE GUO YUN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510163951.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-23
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

The existing broadcast encryption methods have problems with identity privacy information leakage during data sharing, resulting in low security of data sharing.

Method used

By introducing smart contracts into the broadcast encryption system, determining the transmission path collection, and using ring signature and onion routing technology, ensuring the identity of data recipients is hidden and improving the security of data sharing.

Benefits of technology

It realizes the concealment of the identity of the data recipient, ensures that the data provider uses its own private key and the data recipient collection to generate ring signatures, and uses anonymous transmission paths to transmit data, ensuring that the identity of the data recipient cannot be tracked, and ensuring the authenticity and integrity of the shared data, thereby improving the security of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652671B_ABST
    Figure CN119652671B_ABST
Patent Text Reader

Abstract

The present application is applicable to the field of information security technology, and provides a data sharing method, apparatus, device and storage medium based on broadcast encryption, the method comprising: determining a set of data providers and data recipients; using a smart contract to determine a set of transmission paths based on the set of data recipients; the data provider encrypts the data to be shared based on a master public key to obtain a ciphertext, and generates a ring signature based on the ciphertext, the set of data recipients and a first private key of the data provider; the data provider encrypts the data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain target encrypted data to be transmitted; decrypts and transmits the target encrypted data to be transmitted based on the second private key of each target relay node until the target data recipient receives the data to be transmitted; the target data recipient obtains the data to be shared based on the corresponding first private key and the data to be transmitted, thereby improving the security of data sharing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of information security technology, and in particular, relates to a data sharing method, device, equipment and storage medium based on broadcast encryption. Background Art

[0002] Broadcast encryption is an encryption method for group communication that allows the sender to broadcast an encrypted message to a group of receivers, and only authorized receivers can decrypt and read the message. In broadcast encryption, the message is encrypted once and sent to multiple receivers, avoiding the overhead of encrypting each receiver separately, effectively protecting data confidentiality while improving broadcast efficiency.

[0003] The existing broadcast encryption method includes: the broadcast encryption system generates the system's public key and master private key, and makes the public key public; the private key generation center generates a user private key for each broadcast authorized receiving user and sends it secretly to the broadcast authorized receiving user; the broadcast publisher generates a public key, a private key, and a broadcast ciphertext header, then encrypts the plaintext information and generates a ciphertext, and finally sends the ciphertext and the broadcast ciphertext header to the broadcast authorized receiving user; after receiving the ciphertext and the broadcast ciphertext header, the broadcast authorized receiving user recovers the public key and private key based on the user private key and the broadcast ciphertext header, and then decrypts the ciphertext to recover the plaintext information. However, in this method, there is a problem of leakage of the identity privacy information of the broadcast authorized receiving user, resulting in low security of data sharing.

[0004] Therefore, how to ensure that the identity and privacy information of data recipients is not leaked during the data sharing process and improve the security of data sharing has become an urgent problem to be solved. Summary of the invention

[0005] The embodiments of the present application provide a data sharing method, apparatus, device and storage medium based on broadcast encryption, aiming to improve the security of data sharing.

[0006] In a first aspect, an embodiment of the present application provides a data sharing method based on broadcast encryption, the method comprising: determining a data provider and a data recipient set from a user set of a broadcast encryption system, the data recipient set comprising an actual data recipient set and a virtual data recipient set; using a smart contract to determine a transmission path set based on the data recipient set, the transmission path set comprising transmission paths corresponding to each data recipient in the data recipient set, each transmission path comprising at least one relay node; the data provider encrypts the shared data based on the master public key of the broadcast encryption system to obtain a ciphertext, and generates a ring signature based on the ciphertext, the data recipient set, and the first private key of the data provider. ; The data provider encrypts the data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted, the target transmission path is any transmission path in the transmission path set, and the data to be transmitted includes the ciphertext and the ring signature; the target encrypted data to be transmitted is transmitted through the target transmission path, and during the transmission process, the target encrypted data to be transmitted is decrypted based on the second private key of each target relay node until the target data recipient receives the data to be transmitted, the target data recipient is the data recipient corresponding to the target transmission path; the target data recipient obtains the data to be shared based on the corresponding first private key and the data to be transmitted.

[0007] In one possible implementation, the target transmission path includes k target relay nodes, k is an integer greater than or equal to 1; the data provider encrypts the data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted, including: the data provider uses the second public key of the first target relay node in the target transmission path to encrypt the data to be transmitted to obtain first encrypted data to be transmitted; the data provider uses the second public key of the second target relay node in the target transmission path to encrypt the first encrypted data to be transmitted to obtain second encrypted data to be transmitted; the data provider repeats the above encryption process until the data to be transmitted is encrypted using the second public key of each of the k target relay nodes in the target transmission path to obtain the target encrypted data to be transmitted.

[0008] In a possible implementation, the target encrypted data to be transmitted is transmitted through the target transmission path, and during the transmission process, the target encrypted data to be transmitted is decrypted based on the second private key of each target relay node until the target data recipient receives the data to be transmitted, including: the data provider transmits the target encrypted transmission data to the first target relay node; the first target relay node uses the corresponding second private key to decrypt the target encrypted data to be transmitted to obtain first decrypted data to be transmitted, and transmits the first decrypted data to be transmitted to the second target relay node; the second target relay node uses the corresponding second private key to decrypt the first decrypted data to be transmitted to obtain second decrypted data to be transmitted, and transmits the second decrypted data to be transmitted to the next target relay node in the target transmission path; the above data transmission and decryption process is repeated until each of the k target relay nodes in the target transmission path performs a decryption operation based on the corresponding second private key to obtain the data to be transmitted, and transmits the data to be transmitted to the target data recipient.

[0009] In a possible implementation, the target data recipient obtains the data to be shared based on the corresponding first private key and the data to be transmitted, including: the target data recipient verifies the ring signature in the data to be transmitted; when the ring signature verification passes, the target data recipient obtains the ciphertext, and decrypts the ciphertext based on the first private key corresponding to the target data recipient to obtain the data to be shared.

[0010] In a possible implementation, before determining the data provider and the data receiver set from the user set of the broadcast encryption system, the method also includes: using a smart contract to generate a master private key and a master public key of the broadcast encryption system, the master public key is publicly stored on the blockchain, and the master private key is secretly stored by the smart contract; using a smart contract, based on the master private key, the master public key and the identity information of each user in the user set, determining the first private key and the first public key of each user; using a smart contract to determine a relay node set, and generating a second private key and a second public key of each relay node in the relay node set, the second public key is publicly stored on the blockchain, and the second private key is locally stored by each relay node.

[0011] In a possible implementation, the use of a smart contract to determine the first private key and the first public key of each user based on the master private key, the master public key and the identity information of each user in the user set includes: using a smart contract to generate the first private key of each user based on the identity information of each user and the master private key; and determining the first public key of each user based on the identity information of each user and the master public key.

[0012] In one possible implementation, the use of a smart contract to determine a set of transmission paths based on the set of data recipients includes: using a smart contract to randomly generate a corresponding transmission path for each of the data recipients in the set of data recipients based on the set of relay nodes to obtain the set of transmission paths.

[0013] In a second aspect, an embodiment of the present application provides a data sharing device based on broadcast encryption, the device comprising: a first determination module, used to determine a data provider and a data recipient set from a user set of a broadcast encryption system, the data recipient set comprising an actual data recipient set and a virtual data recipient set; a second determination module, used to determine a transmission path set based on the data recipient set using a smart contract, the transmission path set comprising transmission paths corresponding to each data recipient in the data recipient set, each of the transmission paths comprising a plurality of relay nodes; a first encryption module, used for the data provider to encrypt the shared data based on the master public key of the broadcast encryption system to obtain a ciphertext, and to generate a ring signature based on the ciphertext, the data recipient set, and the first private key of the data provider; A second encryption module is used for the data provider to encrypt the target data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted, wherein the target transmission path is any transmission path in the transmission path set, and the data to be transmitted includes the ciphertext and the ring signature; a data transmission module is used to transmit the target encrypted data to be transmitted through the target transmission path, and decrypt the target encrypted data to be transmitted based on the second private key of each target relay node during the transmission process until the target data recipient receives the data to be transmitted, and the target data recipient is the data recipient corresponding to the target transmission path; a data processing module is used for the target data recipient to obtain the data to be shared based on the corresponding first private key and the data to be transmitted.

[0014] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method described in the first aspect or any one of the implementation methods thereof is implemented.

[0015] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first aspect or any one of the implementation methods thereof is implemented.

[0016] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the method described in the first aspect or any one of the implementation methods thereof.

[0017] Compared with the prior art, the embodiments of the present application have the following beneficial effects: a data provider and a data recipient set are determined from a user set of a broadcast encryption system, the data recipient set includes an actual data recipient set and a virtual data recipient set, virtual data recipients are added to the data recipient set, the scope of participants of the ring signature is expanded, and the uncertainty of recipient identity protection is enhanced; a transmission path set is determined based on the data recipient set by using a smart contract, the transmission path set includes transmission paths corresponding to each data recipient in the data recipient set, and each transmission path includes multiple relay nodes; the data provider encrypts the shared data based on the master public key of the broadcast encryption system to obtain a ciphertext, and generates a ring signature based on the ciphertext, the data recipient set, and the first private key of the data provider. The data provider encrypts the data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted; the target encrypted data to be transmitted is transmitted through the target transmission path, and during the transmission process, the target encrypted data to be transmitted is decrypted based on the second private key of each target relay node until the target data receiver obtains the data to be transmitted; the target data receiver obtains the data to be shared based on the corresponding first private key and the data to be transmitted, thereby realizing the anonymity of the identity of the data receiver. The data provider generates a ring signature using its own private key and the data receiver set, and uses an anonymous transmission path for data transmission, thereby ensuring that the identity of the data receiver cannot be tracked, while ensuring the authenticity and integrity of the shared data, thereby improving the security of data sharing.

[0018] It can be understood that the data sharing device, electronic device, computer-readable storage medium and computer program product based on broadcast encryption provided in the embodiments of the present application have the same beneficial effects as the above-mentioned data sharing method based on broadcast encryption, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A flowchart of a data sharing method based on broadcast encryption provided in one embodiment of the present application;

[0021] Figure 2 A flowchart of another data sharing method based on broadcast encryption provided in one embodiment of the present application;

[0022] Figure 3 A structural block diagram of a data sharing device based on broadcast encryption provided in one embodiment of the present application;

[0023] Figure 4 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0024] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.

[0025] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.

[0026] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0027] As used in the specification of this application and the appended claims, the term "if" may be construed, depending on the context, as "when" or "once" or "in response to determining" or "in response to detecting". Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, to mean "once determined" or "in response to determining" or "once [the described condition or event] is detected" or "in response to detecting [the described condition or event]".

[0028] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are used only for distinguishing descriptions and cannot be construed as indicating or implying relative importance.

[0029] Reference to "one embodiment" or "some embodiments" or the like described in the specification of this application means that a particular feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0030] For ease of understanding, some concepts related to the embodiments of this application will be described first.

[0031] Smart contract: A smart contract is an automated program stored on a blockchain network that can automatically execute the terms of a contract according to pre-set conditions. Smart contracts are written in programming languages. When certain trigger conditions are met, the content of the contract will be automatically executed, and the execution process does not depend on human intervention. Since smart contracts are stored on the blockchain, they have immutability and transparency, ensuring the credibility of contract execution. Typical applications of smart contracts include automated payments, financial derivatives trading, supply chain management, real estate, and legal contracts, etc. The advantages of smart contracts are reducing trust costs, improving efficiency, reducing intermediary institutions, and ensuring security during the contract execution process through a consensus mechanism.

[0032] Broadcast encryption technology: Broadcast encryption is an encryption method for group communication that allows the sender to broadcast encrypted messages to a group of receivers, and only authorized receivers can decrypt and read the messages. In the broadcast encryption process, the message is encrypted once and sent to multiple receivers, avoiding the overhead of encrypting each receiver separately. This technology can effectively protect the confidentiality of data while improving broadcast efficiency. In distributed networks and blockchain applications, broadcast encryption can be used for publishing on-chain transaction information, sharing data, and notifying multiple nodes of messages. Its core advantage is to protect the privacy of multiple receivers through one encryption, and unauthorized receivers cannot decrypt the data even if they receive it. In addition, broadcast encryption is widely used in scenarios such as digital copyright protection, video streaming transmission, and IoT device communication.

[0033] Ring signature: Ring signature is an anonymous digital signature technology that allows a signer to generate a signature from a group of potential signers, but the outside world cannot know exactly who generated the signature. The key feature of ring signature is that it provides anonymity and untraceability. Each ring signature is generated from a group of potential signers, and all members participating in the signature can be signers, but only the real signer knows that he has generated the signature. The implementation method of ring signature ensures that even if the signature is public, third parties cannot distinguish the real signer from other members.

[0034] Onion routing: Onion routing is an anonymous communication technology that allows users to communicate securely without revealing their identities. The key feature of onion routing is that it provides privacy protection and data untraceability through multi-layer encryption and multi-hop transmission. In onion routing, data passes through multiple relay nodes, and each node only knows the previous and next nodes of the data, but cannot know the source and destination of the data. Even if a node is attacked, the attacker cannot obtain complete communication information, thereby protecting the privacy of both parties in the communication.

[0035] The technical solution of the present application will be described in detail below with reference to the accompanying drawings.

[0036] Figure 1 This is a flow chart of a data sharing method based on broadcast encryption provided in an embodiment of the present application. For the sake of convenience, only the part related to the present embodiment is shown. The method provided in the present embodiment specifically includes the following steps:

[0037] S110, determining a data provider and a data receiver set from a user set of the broadcast encryption system, where the data receiver set includes an actual data receiver set and a virtual data receiver set.

[0038] Specifically, the broadcast encryption system is a security mechanism that allows data providers to securely distribute data content to authorized data receivers through broadcast channels. The broadcast encryption system can ensure that all authorized users obtain the information master key to decrypt the received encrypted broadcast information, while unauthorized users cannot obtain the information master key and therefore cannot decrypt and obtain the data content.

[0039] In one possible implementation, before executing step S110, a master private key and a master public key of the broadcast encryption system are first generated by a smart contract, the master public key is publicly stored on the blockchain, and the master private key is secretly stored by the smart contract; the first private key and the first public key of each user are determined based on the master private key, the master public key and the identity information of each user in the user set using the smart contract; the relay node set is determined using the smart contract, and the second private key and the second public key of each relay node in the relay node set are generated, the second public key is publicly stored on the blockchain, and the second private key is locally stored by each relay node.

[0040] As an example, using smart contracts to preset The algorithm generates the master key of the broadcast encryption system ( ) and the master public key ( ). Master public key It is publicly stored on the blockchain for all users to query, and the master private key It is securely kept by smart contracts and cannot be accessed by any outsider.

[0041] As an example, a smart contract is used to generate each user's first private key based on the user's identity information and master private key in the broadcast encryption system; and each user's first public key is determined based on the user's identity information and master public key.

[0042] In the specific implementation, when a new user joins the broadcast encryption system, the user submits his identity ID to the smart contract, and the smart contract The algorithm is based on the user's identity ID and the system's master private key , automatically generate the user's first private key , and returns it to the user in encrypted form; the user's first public key Through the identity ID and the system's master public key To express or define indirectly.

[0043] For example, assuming that the user's first public key can be generated by a public key generation function Generate, then the first public key is expressed as .

[0044] As an example, the set of relay nodes for onion routing is dynamically and randomly determined through a smart contract. The smart contract calls a key generation algorithm to generate a unique second private key and second public key for each relay node to ensure the security and independence of the keys. The second public key will be publicly recorded on the blockchain, enabling data providers to encrypt and transmit data based on the second public key of the relay node. The second private key is stored locally by each relay node and protected to prevent external access or leakage.

[0045] In a specific implementation, according to actual data sharing needs, any user is selected from the user set of the broadcast encryption system as the data provider of this data sharing task, and the data provider determines the data recipient set.

[0046] As an example, the data provider selects the actual data recipient set , the first public key corresponding to the actual data recipient is ; At the same time, the data provider introduces a set of virtual data receivers ,in is a randomly generated virtual identity, the first public key of each virtual data recipient It is also generated based on the system's master public key and is expressed as , .

[0047] S120, using a smart contract to determine a transmission path set based on a data recipient set, the transmission path set includes transmission paths corresponding to each data recipient in the data recipient set, and each transmission path includes at least one relay node.

[0048] In a specific implementation, a smart contract is used to randomly generate a corresponding transmission path for each data receiver in a data receiver set based on a relay node set to obtain a transmission path set.

[0049] As an example, based on the data recipient set and the relay node set, the smart contract generates a transmission path consisting of multiple relay nodes for each data recipient, that is, a multi-hop path of onion routing. Each transmission path contains multiple relay nodes, and a path is formed by multiple relay nodes, and finally reaches the data recipient. The transmission path of each data recipient is randomly generated by the smart contract based on the relay node set, and the second public key of each relay node in the transmission path is based on the master public key of the system. generate.

[0050] S130, the data provider encrypts the shared data based on the master public key of the broadcast encryption system to obtain a ciphertext, and generates a ring signature based on the ciphertext, a set of data recipients, and a first private key of the data provider.

[0051] In the specific implementation, the data provider uses the system's master public key Treating shared data To encrypt, use the following formula to generate ciphertext :

[0052] ;

[0053] At the same time, the data provider uses his first private key , use the ring signature algorithm to generate a ring signature , to ensure the source and integrity of the data to be shared, specifically, in ciphertext , Data recipient collection , the first private key of the data provider and random numbers As input, the ring signature is obtained using the following formula:

[0054] .

[0055] S140, the data provider encrypts the data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted, the target transmission path is any transmission path in the transmission path set, and the data to be transmitted includes a ciphertext and a ring signature.

[0056] In one possible implementation, the target transmission path includes k target relay nodes, k is an integer greater than or equal to 1, and the data provider uses the second public key of the first target relay node in the target transmission path to encrypt the data to be transmitted to obtain first encrypted data to be transmitted; the data provider uses the second public key of the second target relay node in the target transmission path to encrypt the first encrypted data to be transmitted to obtain second encrypted data to be transmitted; the data provider repeats the above encryption process until the data to be transmitted is encrypted using the second public key of each of the k target relay nodes in the target transmission path to obtain the target encrypted data to be transmitted.

[0057] In the specific implementation, each relay node in the target transmission path will treat the transmission data (Ciphertext and ring signature) are encrypted to form a multi-layer encryption structure. The specific process is as follows:

[0058] 1) First layer of encryption

[0059] The data provider will transmit the data Encrypted into one layer, using the second public key of the first target relay node , generate the first encrypted data to be transmitted, expressed as ,at this time, becomes the second public key passed through the first target relay node For encrypted content, only the first target relay node can decrypt this layer.

[0060] 2) Second layer of encryption

[0061] Data providers continue to Use the second public key of the second target relay node Encryption is performed to obtain the second encrypted data to be transmitted, which is expressed as ,at this time, For the data encrypted at the second layer, only the second target relay node can decrypt this layer.

[0062] 3) Repeat this process until the kth layer

[0063] The data provider will continue to use the second public key of each target relay node for encryption until all k target relay nodes on the target transmission path have encrypted one level of the data to be transmitted.

[0064] Assume that the last target relay node is ,but is the result of k-layer encryption, expressed as ;at this time, It contains k layers of encryption, and each layer can only be decrypted by the corresponding target relay node.

[0065] S150, transmit the target encrypted data to be transmitted through the target transmission path, and decrypt the target encrypted data to be transmitted based on the second private key of each target relay node during the transmission process until the target data receiver receives the data to be transmitted, and the target data receiver is the data receiver corresponding to the target transmission path.

[0066] In one possible implementation, the data provider transmits the target encrypted transmission data to the first target relay node; the first target relay node uses the corresponding second private key to decrypt the target encrypted data to be transmitted, obtains the first decrypted data to be transmitted, and transmits the first decrypted data to be transmitted to the second target relay node; the second target relay node uses the corresponding second private key to decrypt the first decrypted data to be transmitted, obtains the second decrypted data to be transmitted, and transmits the second decrypted data to be transmitted to the next target relay node in the target transmission path; the above data transmission and decryption process is repeated until each of the k target relay nodes in the target transmission path performs a decryption operation based on the corresponding second private key, obtains the data to be transmitted, and transmits the data to be transmitted to the target data recipient.

[0067] In the specific implementation, the target data recipient uses the transmission path information provided by the smart contract to decrypt the data layer by layer through the multi-hop decryption mechanism of onion routing, including:

[0068] 1) Decryption by the first target relay node

[0069] When the target encrypted data to be transmitted reaches the first target relay node ( ), the first target relay node uses its own second private key Decrypt the first layer, and obtain the first decrypted data to be transmitted after decryption And transmitted to the second target relay node, the first decrypted data to be transmitted is represented as .

[0070] 2) Second target relay node decryption

[0071] The second target relay node receives the first decrypted data to be transmitted Then, use your second private key Decrypt the second layer to obtain the second decrypted data to be transmitted And pass it to the next target relay node, the second decrypted data to be transmitted is expressed as .

[0072] 3) Decryption of the kth target relay node

[0073] The k target relay nodes in the target transmission path decrypt layer by layer in the above manner until the target receiver receives the fully decrypted data to be transmitted. , namely, ciphertext CT and ring signature .

[0074] S160: The target data receiver obtains the data to be shared based on the corresponding first private key and the data to be transmitted.

[0075] In a possible implementation, the target data recipient first verifies the ring signature in the data to be transmitted; when the ring signature verification passes, the target data recipient obtains the ciphertext, and decrypts the ciphertext based on the first private key corresponding to the target data recipient to obtain the data to be shared.

[0076] In the specific implementation, the target data recipient first uses the ring signature verification algorithm to confirm the validity of the ring signature. Only after the ring signature verification is passed can the target data recipient obtain the ciphertext , continue the decryption operation, the ring signature verification calculation formula is as follows:

[0077] ;

[0078] If the verification is successful, If true, the target data receiver can obtain the ciphertext , and continue the decryption operation; if the verification fails, the target data recipient will be refused decryption and report an error to prevent the processing of unverified or tampered data.

[0079] After verification, when the target data recipient is the actual data recipient, the target data recipient uses his or her first private key , the ciphertext is Decrypt and obtain the data to be shared :

[0080] ;

[0081] If the decryption fails, a decryption failure flag is returned to indicate that the decryption failed.

[0082] In addition, when the data receiver sets When a change occurs (such as a new member joining or an old member being revoked), the smart contract will automatically trigger the key update mechanism, for example, deleting the key information of the revoked member from the data recipient set or adding the key information of the new member to the data recipient set, and distributing it to the legitimate data recipients through the blockchain. After each key update operation is completed, the smart contract will write the update information to the blockchain, for example, the update information includes the updated user list, the new key version number, the event that triggered the key update, and detailed information of all related operations.

[0083] The technical solution provided by this embodiment determines the data provider and the data recipient set from the user set of the broadcast encryption system. The data recipient set includes the actual data recipient set and the virtual data recipient set. The virtual data recipient is added to the data recipient set, which expands the scope of participants of the ring signature and enhances the uncertainty of the recipient identity protection. The smart contract is used to determine the transmission path set based on the data recipient set. The transmission path set includes transmission paths corresponding to each data recipient in the data recipient set, and each transmission path includes multiple relay nodes. The data provider encrypts the shared data based on the master public key of the broadcast encryption system to obtain the ciphertext, and generates the ring signature based on the ciphertext, the data recipient set, and the first private key of the data provider. The provider encrypts the data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted; transmits the target encrypted data to be transmitted through the target transmission path, and decrypts the target encrypted data to be transmitted based on the second private key of each target relay node during the transmission process until the target data recipient obtains the data to be transmitted; the target data recipient obtains the data to be shared based on the corresponding first private key and the data to be transmitted, thereby realizing the anonymity of the identity of the data recipient. The data provider generates a ring signature using its own private key and the data recipient set, and uses an anonymous transmission path for data transmission, thereby ensuring that the identity of the data recipient cannot be tracked, while ensuring the authenticity and integrity of the shared data, thereby improving the security of data sharing.

[0084] Figure 2 This is a flow chart of another data sharing method based on broadcast encryption provided in an embodiment of the present application. For the sake of convenience, only the part related to this embodiment is shown. The method provided in this embodiment specifically includes the following steps:

[0085] Step 1: Data sharing initialization

[0086] In data sharing based on broadcast encryption technology, smart contracts are first used to The algorithm generates the master key of the broadcast encryption system ( ) and the master public key ( ). Master public key It is publicly stored on the blockchain for all users to query, and the master private key It is securely kept by smart contracts and cannot be accessed by any outsider.

[0087] Step 2: Generate private and public keys

[0088] (1) User key pair generation

[0089] When a new user joins the system, the user submits his or her identity ID to the smart contract. The algorithm is based on the user's ID and the system's master private key , automatically generate the user's private key , and returns it to the user in encrypted form. The user's public key Through the identity ID and master public key To express or define indirectly.

[0090] For example, assuming that the user's public key can be generated by the public key generation function Generate, expressed as:

[0091] .

[0092] (2) Relay node key pair generation

[0093] The onion routing relay node set is dynamically and randomly determined through smart contracts. The smart contract calls the key generation algorithm to generate a unique public-private key pair for each relay node to ensure the security and independence of the key. The public key will be publicly recorded on the blockchain, enabling data providers to encrypt and transmit data based on the public key of the relay node. The private key is stored locally by each relay node and protected to prevent external access or leakage.

[0094] Step 3: Determination of recipient set and anonymous transmission path

[0095] (1) Determination of the receiver set

[0096] The data provider selects the actual set of receivers , the public key corresponding to the receiver is .

[0097] At the same time, the data provider introduces a virtual receiver set ,in It is a randomly generated virtual identity. The public key of each virtual identity It is also generated based on the master public key and is expressed as , .

[0098] The final ring signature participant set Q is the actual recipient set and virtual set The user public key union is expressed as:

[0099] .

[0100] (2) Anonymous transmission path determination

[0101] Based on the set of recipients, the smart contract generates a virtual relay node path for each recipient, i.e., a multi-hop path for onion routing. Each path contains multiple virtual relay nodes and forms a path that eventually reaches the target recipient of the data. The routing path for each recipient is randomly generated by the smart contract, and the public key of each relay node in the path is based on the master public key. .

[0102] Step 4: Data Encryption

[0103] (1) Generate ciphertext and ring signature

[0104] The data provider uses the master public key Treating shared data Encrypt and generate ciphertext ,in, At the same time, the data provider uses his own private key , use the ring signature algorithm to generate a ring signature , ensuring the source and integrity of data, where the input includes ciphertext , receiver set , the data provider's private key and random numbers , ring signature .

[0105] (2) Constructing onion structure encryption

[0106] Each relay node in the transmission path will treat the transmitted data The encryption process is as follows:

[0107] 1) First layer of encryption

[0108] The data provider will transmit the data Encrypted into one layer, using the public key of the first relay node , generate a new ciphertext At this time, the data It becomes the first relay node public key For encrypted content, only the first relay node can decrypt this layer.

[0109] 2) Second layer of encryption

[0110] Data providers continue to Use the public key of the second relay node Encrypt and get At this time, the data It is the second layer of encrypted data, and only the second relay node can decrypt this layer.

[0111] 3) Repeat this process until the last layer

[0112] The data provider will continue to encrypt the ciphertext at each hop until all relay nodes on the path have encrypted the ciphertext by one level. Assume that the last relay node is , then the final ciphertext is the result of multiple layers of encryption. At this stage, the ciphertext Multiple layers of encryption are included, and each layer can only be decrypted by the corresponding relay node.

[0113] Step 5: Data Transfer

[0114] Ciphertext The data will be transmitted in the onion routing network, and the data will be transmitted through a multi-hop encrypted path. Each relay node will decrypt according to the preset path. Each relay node only decrypts the layer it is responsible for, and cannot decrypt the layers of other nodes, nor can it know the transmission path or content of the entire data.

[0115] Step 6: Data Decryption

[0116] (1) Information Reception

[0117] The data recipient uses the relay path information provided by the smart contract to decrypt the data layer by layer through the multi-hop decryption mechanism of onion routing. The detailed decryption process includes:

[0118] 1) First hop relay node

[0119] When the data reaches the first relay node ( ), it receives the ciphertext , which is the ciphertext after being encrypted by multiple relay nodes. The first relay node uses its own private key Decrypt the first layer and send the decrypted ciphertext Pass it to the next relay node.

[0120] 2) Second hop relay node

[0121] The second relay node receives , using your own private key Decrypt the second layer and send the decrypted result Pass it to the next relay node.

[0122] 3) Continue decrypting until the last node

[0123] Each relay node in the transmission path decrypts layer by layer in the above manner until the final data recipient receives the fully decrypted original data to be transmitted. , namely, ciphertext CT and ring signature .

[0124] (2) Ring Signature Verification

[0125] Each data recipient first uses the ring signature verification algorithm to confirm the validity of the ring signature. Only after the ring signature verification is passed can the data recipient obtain the ciphertext , and continue to decrypt. The ring signature verification calculation formula is as follows:

[0126] ;

[0127] If the verification passes, If true, the data receiver can obtain the ciphertext , and continue the decryption operation; if the verification fails, the data recipient will be refused decryption and report an error to prevent the processing of unverified or tampered data.

[0128] (3) Obtaining original data

[0129] After verification, the actual data recipient uses his own private key The ciphertext is ciphered by Decrypt and obtain the data to be shared :

[0130] ;

[0131] If decryption fails, it returns " " to indicate unsuccessful decryption.

[0132] Step 7: Key Update

[0133] When the receiver sets When a change occurs (such as a new member joining or an old member being revoked), the smart contract will automatically trigger the key update mechanism, generate a new key and distribute it to the legitimate recipient through the blockchain. After each key update operation is completed, the smart contract will write the update information to the blockchain, including the updated user list, the new key version number, the event that triggered the key update, and detailed information of all related operations.

[0134] To sum up, the data sharing method based on broadcast encryption proposed in this application consists of two parts: a decentralized key management method and a data encryption optimization strategy.

[0135] Specifically, the decentralized key management method includes: when the data provider transmits messages to multiple users through broadcast encryption technology, the identity information and key updates of the recipients are automatically managed through smart contracts to ensure dynamic management and secure distribution of keys, enhance privacy protection and security in the data sharing process, and store key update records and other content through blockchain technology, as well as transmit encrypted ciphertext and ring signatures.

[0136] Specifically, the data encryption optimization strategy includes: when sharing data, the data needs to be encrypted. The data provider will first perform a ring signature operation and select his own private key. and a complete set of participants including both real and virtual recipients , generate a ring signature In the ring signature process, a method for dynamically adjusting the recipient set is designed to add virtual recipients to expand the scope of participants in the ring signature, and then the ring signature is sent to the And the ciphertext The data is encrypted layer by layer and transmitted to the data sharing recipients (actual recipients and virtual recipients) through the onion routing network. The data decryption process starts with the layer-by-layer decryption process of the onion routing. The recipient removes the outer layers of the onion encryption structure one by one until the ciphertext is restored. and ring signatures ; Subsequently, the data recipient verifies the validity of the ring signature, and can only continue to operate to obtain the ciphertext after the verification is passed , thereby obtaining the original data to be shared .

[0137] The technical solution provided by this application has the following advantages:

[0138] Eliminate single point failures and key leakage problems: The decentralized key management method proposed in this application uses blockchain and smart contracts to eliminate the risks of human operations and achieve decentralized key management.

[0139] 2) Solve the privacy issue of the recipient's user identity: The data encryption optimization strategy proposed in this application uses ring signature technology, onion routing technology and dynamic adjustment of the recipient set method to conceal the recipient's identity when encrypting data sharing, thereby protecting the personal privacy of users in the receiving set.

[0140] Figure 3 This is a structural block diagram of a data sharing device based on broadcast encryption provided by an embodiment of the present application. For the sake of convenience, only the part related to the embodiment of the present application is shown. Figure 3The data sharing device 300 based on broadcast encryption may include a first determination module 301 , a second determination module 302 , a first encryption module 303 , a second encryption module 304 , a data transmission module 305 and a data processing module 306 .

[0141] The first determination module 301 is used to determine a data provider and a data receiver set from a user set of the broadcast encryption system, where the data receiver set includes an actual data receiver set and a virtual data receiver set.

[0142] The second determination module 302 is used to determine a transmission path set based on a data recipient set by using a smart contract, where the transmission path set includes transmission paths corresponding to each data recipient in the data recipient set, and each transmission path includes multiple relay nodes.

[0143] The first encryption module 303 is used for the data provider to encrypt the shared data based on the master public key of the broadcast encryption system to obtain a ciphertext, and to generate a ring signature based on the ciphertext, a set of data recipients, and a first private key of the data provider.

[0144] The second encryption module 304 is used for the data provider to encrypt the data to be transmitted based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted. The target transmission path is any transmission path in the transmission path set, and the data to be transmitted includes ciphertext and ring signature.

[0145] The data transmission module 305 is used to transmit the target encrypted data to be transmitted through the target transmission path, and decrypt the target encrypted data to be transmitted based on the second private key of each target relay node during the transmission process until the target data recipient receives the data to be transmitted. The target data recipient is the data recipient corresponding to the target transmission path.

[0146] The data processing module 306 is used for the target data recipient to obtain the data to be shared based on the corresponding first private key and the data to be transmitted.

[0147] A data sharing device based on broadcast encryption provided in an embodiment of the present application has the same beneficial effects as the above-mentioned data sharing method based on broadcast encryption.

[0148] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.

[0149] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.

[0150] Figure 4 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Figure 4 As shown, the electronic device 4 of this embodiment includes: at least one processor 40 ( Figure 4 Only one is shown in the figure), a memory 41, and a computer program 42 stored in the memory 41 and executable on at least one processor 40, the processor 40 executes the computer program 42 to implement the above Figure 1 or Figure 2 The steps in the method embodiment, or the implementation of the above Figure 3 Functions of each module / unit in the device embodiment.

[0151] The electronic device 4 may be a computing device such as a desktop computer, a notebook, a PDA, or a cloud server. The electronic device 4 may include but is not limited to a processor 40 and a memory 41. Those skilled in the art will appreciate that Figure 4 It is only an example of the electronic device 4 and does not constitute a limitation on the electronic device 4. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, etc.

[0152] The processor 40 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0153] In some embodiments, the memory 41 may be an internal storage unit of the electronic device 4, such as a hard disk or memory of the electronic device 4. In other embodiments, the memory 41 may also be an external storage device of the electronic device 4, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 4. Further, the memory 41 may also include both an internal storage unit and an external storage device of the electronic device 4. The memory 41 is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as program codes of a computer program. The memory 41 may also be used to temporarily store data that has been output or is to be output.

[0154] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0155] When an integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above method embodiments of this application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can at least include: any entity or device that can carry the computer program code to an electronic device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electrical carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disc, etc.

[0156] A computer-readable storage medium provided by an embodiment of this application has the same beneficial effects as the above-mentioned method for data sharing based on broadcast encryption.

[0157] An embodiment of this application provides a computer program product. The computer program product includes a computer program. When the computer program is executed by a processor, the steps in the above method embodiments can be implemented.

[0158] A computer program product provided by an embodiment of this application has the same beneficial effects as the above-mentioned method for data sharing based on broadcast encryption.

[0159] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0160] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0161] In the embodiments provided in the present application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are merely schematic, for example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0162] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0163] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A data sharing method based on broadcast encryption, characterized in that: The method comprises: Determining a data provider and a data receiver set from a user set of the broadcast encryption system, wherein the data receiver set includes an actual data receiver set and a virtual data receiver set; Determine a transmission path set based on the data recipient set by using a smart contract, wherein the transmission path set includes transmission paths corresponding to each data recipient in the data recipient set, and each transmission path includes at least one relay node; The data provider encrypts the shared data based on the master public key of the broadcast encryption system to obtain a ciphertext, and generates a ring signature based on the ciphertext, the data recipient set, and the first private key of the data provider; The data provider encrypts the data to be transmitted respectively based on the second public key of each target relay node in the target transmission path to obtain target encrypted data to be transmitted, the target transmission path is any transmission path in the transmission path set, and the data to be transmitted includes the ciphertext and the ring signature; The target encrypted data to be transmitted is transmitted through the target transmission path, and during the transmission process, the target encrypted data to be transmitted is respectively decrypted based on the second private key of each target relay node until the target data recipient receives the data to be transmitted, and the target data recipient is the data recipient corresponding to the target transmission path; The target data receiver obtains the data to be shared based on the corresponding first private key and the data to be transmitted.

2. The method according to claim 1, characterized in that The target transmission path includes k target relay nodes, where k is an integer greater than or equal to 1; The data provider encrypts the data to be transmitted respectively based on the second public key of each target relay node in the target transmission path to obtain the target encrypted data to be transmitted, including: The data provider encrypts the data to be transmitted using the second public key of the first target relay node in the target transmission path to obtain first encrypted data to be transmitted; The data provider encrypts the first encrypted data to be transmitted using the second public key of the second target relay node in the target transmission path to obtain second encrypted data to be transmitted; The data provider repeatedly performs the above encryption process until the data to be transmitted is encrypted using the second public key of each target relay node in the k target relay nodes in the target transmission path to obtain the target encrypted data to be transmitted.

3. The method according to claim 2, characterized in that The step of transmitting the target encrypted data to be transmitted through the target transmission path, and decrypting the target encrypted data to be transmitted based on the second private key of each target relay node during the transmission process until the target data recipient receives the data to be transmitted, includes: The data provider transmits the target encrypted data to be transmitted to the kth target relay node; The k-th target relay node decrypts the target encrypted data to be transmitted using the corresponding second private key to obtain first decrypted data to be transmitted, and transmits the first decrypted data to be transmitted to the k-1-th target relay node; The k-1th target relay node decrypts the first decrypted data to be transmitted using the corresponding second private key to obtain second decrypted data to be transmitted, and transmits the second decrypted data to be transmitted to the next target relay node in the target transmission path; Repeat the above data transmission and decryption process until each of the k target relay nodes in the target transmission path performs a decryption operation based on the corresponding second private key to obtain the data to be transmitted, and transmit the data to be transmitted to the target data recipient.

4. The method according to claim 1, characterized in that: The target data receiver obtains the data to be shared based on the corresponding first private key and the data to be transmitted, including: The target data receiver verifies the ring signature in the data to be transmitted; When the ring signature verification passes, the target data recipient obtains the ciphertext, and decrypts the ciphertext based on the first private key corresponding to the target data recipient to obtain the data to be shared.

5. The method according to claim 1, characterized in that Before determining the data provider and the data receiver set from the user set of the broadcast encryption system, the method further includes: Using smart contracts to generate a master private key and a master public key of a broadcast encryption system, wherein the master public key is publicly stored on the blockchain, and the master private key is secretly stored by the smart contract; Determine, by using a smart contract, a first private key and a first public key of each user based on the master private key, the master public key and identity information of each user in the user set; A smart contract is used to determine a relay node set, and a second private key and a second public key of each relay node in the relay node set are generated, wherein the second public key is publicly stored on the blockchain, and the second private key is locally stored by each relay node.

6. The method according to claim 5, characterized in that The using of the smart contract to determine the first private key and the first public key of each user based on the master private key, the master public key and the identity information of each user in the user set includes: Using a smart contract, based on the identity information of each user and the master private key, a first private key of each user is generated; Based on the identity information of each user and the master public key, a first public key of each user is determined.

7. The method according to claim 5, characterized in that The using of the smart contract to determine the set of transmission paths based on the set of data recipients includes: By using a smart contract, a corresponding transmission path is randomly generated for each of the data receivers in the data receiver set based on the relay node set to obtain the transmission path set.

8. A data sharing device based on broadcast encryption, characterized in that: The device comprises: A first determination module, used to determine a data provider and a data receiver set from a user set of the broadcast encryption system, wherein the data receiver set includes an actual data receiver set and a virtual data receiver set; A second determination module, configured to determine a transmission path set based on the data recipient set by using a smart contract, wherein the transmission path set includes transmission paths corresponding to respective data recipients in the data recipient set, and each transmission path includes a plurality of relay nodes; A first encryption module, configured for the data provider to encrypt the shared data based on the master public key of the broadcast encryption system to obtain a ciphertext, and to generate a ring signature based on the ciphertext, the data recipient set, and the first private key of the data provider; A second encryption module, used for the data provider to encrypt the data to be transmitted respectively based on the second public key of each target relay node in the target transmission path to obtain target encrypted data to be transmitted, wherein the target transmission path is any transmission path in the transmission path set, and the data to be transmitted includes the ciphertext and the ring signature; a data transmission module, configured to transmit the target encrypted data to be transmitted through the target transmission path, and decrypt the target encrypted data to be transmitted respectively based on the second private key of each target relay node during the transmission process, until the target data recipient receives the data to be transmitted, the target data recipient being the data recipient corresponding to the target transmission path; The data processing module is used for the target data recipient to obtain the data to be shared based on the corresponding first private key and the data to be transmitted.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Cryptlet smart contract

    US20180330343A1

  • Relational distributed ledger for smart contracts

    US20190325044A1