A Blockchain-Based Hierarchical Sharing Method for Medical Data
By employing a blockchain-based hierarchical sharing method and utilizing the sorting of Boolean and weighted attributes, medical data is encrypted and decrypted in layers. This solves the problems of complex permission verification and high computational resource consumption, and achieves secure and efficient medical data sharing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANHUI NORMAL UNIV
- Filing Date
- 2024-11-08
- Publication Date
- 2026-05-26
AI Technical Summary
In existing medical data access processes, permission verification is complex and consumes a lot of computing resources, resulting in high decryption costs, and repetitive ciphertext decryption calculations increase the burden on equipment.
A blockchain-based hierarchical sharing approach is adopted. By sorting Boolean and weighted attributes, an access structure is constructed to perform hierarchical encryption and decryption of medical data. 0-1 encoding and HVE encoding are used to represent flexible access strategies. Blockchain nodes manage key generation and attribute authorization to achieve hierarchical access control.
It reduces the computational costs of decryption and verification, supports permission comparison of hidden attributes, solves the single point of failure problem, and achieves secure multi-level data sharing.
Smart Images

Figure CN119760734B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data sharing technology, and more specifically, this invention relates to a blockchain-based hierarchical sharing method for medical data. Background Technology
[0002] Medical data helps individuals better understand their health and also assists healthcare professionals in more effectively assessing and diagnosing patients' health conditions, leading to better medical decisions and treatment plans. Because medical data collection utilizes numerous applications, generating vast amounts of data daily, services for sharing and storing this data are crucial. Furthermore, sharing medical data can facilitate better collaboration and coordination; healthcare professionals can share and access patient medical data, improving communication and coordination within the healthcare team.
[0003] The emergence of cloud computing has made it easy to store and process large amounts of medical data. Cloud service providers (CSPs) offer the infrastructure for processing and data storage at a certain cost. Such services reduce the cost of building and maintaining systems. Therefore, third-party storage and computing services are often used. However, if medical data is generated and outsourced to cloud servers, patients do not own it; it is accessed by healthcare providers as needed for treatment. This makes integrity protection a challenging issue, especially in cases of medical malpractice where healthcare institutions might collude with cloud servers to compromise outsourced medical data to cover up misdiagnosis. Linking data access control with blockchain technology and combining it with data encryption can enable secure data sharing, transaction traceability, irreversible alteration, non-repudiation, and large-scale collaborative computing, as well as identity and data privacy protection. Due to its attractive characteristics, blockchain technology is seen as a powerful solution to address these challenges in cloud-assisted healthcare systems.
[0004] In current medical data access processes, most only a single file with access permissions is decrypted. When multiple files need to be accessed, they must be accessed and decrypted one by one. Since permission verification is required for each access, the permission verification process is relatively complex. Therefore, permission verification often consumes a lot of computing resources, and repeated ciphertext decryption calculations will bring huge storage and computing overhead to the device. Summary of the Invention
[0005] This invention provides a blockchain-based hierarchical sharing method for medical data, aiming to improve the above-mentioned problems.
[0006] This invention is implemented as follows: a blockchain-based hierarchical sharing method for medical data, the method being as follows:
[0007] Data for all users U DODefine Boolean and weighted attributes for each file in the batch medical data F. Sort the files by permissions based on these attributes, and build an access structure for each file sequentially from lowest to highest permissions. Encrypt the corresponding files based on their access structures. After all files in the batch medical data F are encrypted, generate an index for F. Upload the index and the encrypted batch medical data F to a cloud server for storage. The cloud server then returns the storage address to all users U. DO ;
[0008] Access to medical data: Data access user U DU A query request is sent to the cloud server, and the query request includes the requesting user U. DU The cloud server receives the pre-decryption key TK and the requested batch of medical data. Based on the received decryption key, it pre-decrypts the requested batch of medical data within the authorized scope, obtains the pre-decrypted ciphertext of the medical data within the authorized scope, and returns it to the data access user U. DU Data access user U DU The pre-decrypted ciphertext of the authorized medical data is decrypted using the private key to obtain the plaintext of the authorized medical data.
[0009] Furthermore, the process of obtaining the pre-decryption key TK is as follows:
[0010] Registered users send a registration request to the blockchain, which includes the user's weighted attribute S. * and Boolean property w * ;
[0011] The blockchain generates a pre-decryption key TK = {L} for each registered user. θ The function is defined in the datasets K1 and K2, and broadcast. K1 = g γ K2 = h β ;
[0012] Among them, Att θ,q Represents a blockchain node BN θ The q-th Boolean attribute of the management, u and h are random numbers in the system public parameter PP, β is the private key of the registered user, h is a random number, and r θ,q For Boolean attribute set A θ The q-th boolean attribute in the expression selects a random number, and based on the random number r... θ,q Calculation parameters ATT θ Att is the Boolean attribute contained in user U. θ,q The summation result, R θ r is the Boolean attribute contained in user U θ,q The summation result, parameter vγ The specific process for obtaining it is as follows:
[0013] BN for each node θ Choose a random number γ θ Calculate and broadcast parameters and parameters Using parameters respectively parameter As a secret share, after a node receives secret shares broadcast by k or more other nodes, each node obtains the parameter g using the Pedersen secret sharing protocol. γ and parameter v γ .
[0014] Furthermore, data access user U DU The specific process for determining batch medical data within the authorized scope is as follows:
[0015] Sort the files in the batch medical data F according to the weighted attribute values from smallest to largest. When the weighted attribute values are the same, arrange the Boolean attributes contained in the HVE vector of each file in order from fewest to most.
[0016] Based on the reverse order of the files in the batch medical data F, identify users whose weighted attributes are lower than those of data access users U. DU The file with the highest permissions based on weighted attributes; starting from the found file with the highest permissions, for user U... DU The boolean attributes of the user are validated against the boolean attributes of the corresponding file. If the validation passes, the permissions of the corresponding file and the file listed first in the file order are lower than those of user U. DU Batch medical data within the authorized scope.
[0017] Furthermore, registered users send registration requests to the blockchain, which then processes these requests based on the registered user's weighted attribute S. * Constructing weighted coding for users The 0 code for registered user U, The 1-code for registered user U;
[0018] Data for all users U DO Weighted encoding of each file is constructed based on the weighted attributes of each file in the uploaded batch medical data F. For the i-th file F i 0-code and 1-code;
[0019] User U DU 1 encoding With file 0 encoding Intersection If the intersection contains no duplicate elements, then verify the weighted attribute Φ of the next file. k-1 If the intersection contains the same element, it means that user U DU The weighted attribute permissions are greater than the weighted attributes of the corresponding file.
[0020] Furthermore, registered users send registration requests to the blockchain, and the blockchain constructs the user's Boolean attribute vector Ψ based on the registered user's own Boolean attributes. U ={D1,D2,D′}, D1 = {Y j ,L j}, D2={E j ,E′ j}, D′={μ j =t j / r j ,μ′ j =h j / m j},
[0021]
[0022]
[0023] Data for all users U DO Construct a Boolean attribute vector for each file based on the Boolean attributes of the uploaded batch medical data F.
[0024]
[0025]
[0026] Calculate the verification value Δ=e(Γ) ij E j )e(Γ′ ij ,E′ j If Δ equals 1, it indicates that x exists. ij=1 And y j =1, will replace encrypted CT i C Λ C′ Λ With Ψ i Perform the calculation: Then verify C′ Λ Does it contain H(m′)? i If it is included, the verification passes.
[0027] Furthermore, the encryption process for the corresponding file based on the access structure is as follows:
[0028] Determine file F iGiven a Boolean attribute set w′, obtain the HVE vector corresponding to the Boolean attribute set w′, and construct file F according to the LSSS encryption scheme. i Access structure P i P i = (M, ρ), where M is an l x n matrix, each row of which corresponds to an attribute in the attribute set, and ρ is the mapping function corresponding to the matrix. When j ∈ {1, 2, ..., l}, ρ(M j )∈w′ j , of which M j Let w′ be the j-th row of matrix M. j For file F i The j-th element in the HVE vector corresponding to the Boolean genus set;
[0029] User U DO Generate a random vector ν = (s i ,y2,...,y n ) T , where s is randomly selected i ,y2,...,y n , Randomly drawn from the field of p-order integers, s i For each row M of the access matrix, a randomly selected secret value is used for LSSS encryption. j Calculate the shared share λ j =M j ·v;
[0030] User U DO Use the key and public parameters to assign permissions to each file in ascending order of permissions. i The plaintext is encrypted to generate ciphertext CT. i ={C,C1,C2,C 3,θ C x ,C' x C Θ C Λ ,C' Λ};
[0031] in, α*s represents the result of the bilinear mapping e of g and g. i The power of, C1 = g c C2 = v c , Among them, ATT θ For file F i Boolean attribute Att θ',q' The summation result, θ′ is the file F i The management nodes for each Boolean attribute, where q′ is the set of Boolean attributes corresponding to the Boolean attribute in the management node θ′. θ′Sorting within; C' x =g d c and d are random numbers.
[0032] For each file F i Select random value Calculate C Λ =m i Z -b C' Λ =H1(m i Select the (i-1)th file F from the index array Index. i-1 The secret value s i-1 ,calculate α*(s) represents the result of the bilinear mapping e of g and g. i +s i-1 ) times.
[0033] Furthermore, the specific process of generating the index for the batch medical data F is as follows:
[0034] The ciphertext of all files is compiled into a ciphertext set CT, and user U DO Index for generating the ciphertext set CT kw is the key to the ciphertext.
[0035] Furthermore, data access user U DU The specific process of retrieving data from the query request is as follows:
[0036] Access User U DU A search trap is generated based on the ciphertext key "kw" and the private key "SK".
[0037] User U DU Select the timestamp Time′ of the trapdoor generation time to generate a search transaction. in, sign′=Sign SK (ζ), The user will search transaction TX search Package and upload to the blockchain for consensus, Sign SK (ζ) indicates that user U is used. DU The private key SK is used to encrypt the parameter ζ;
[0038] Smart contracts use the encrypted key kw to search and calculate the parameter ζ = Verify. PK (sign), parameter ζ′=H(H(T0)||Time′), if ζ=ζ′, then calculate the parameter. if Then verify e(Index,PK) = e(MSK,T0). If the verification passes, the storage address addr is returned to the user U. DU ;
[0039] Among them, Verify PK (sign) indicates that the search transaction encrypted with the encryption function Sign is decrypted using the public key PK and the corresponding decryption function Verify. e(Index,PK) indicates that Index and PK are mapped using the mapping function in the bilinear mapping. e(MSK,T0) indicates that MSK and T0 are mapped using the mapping function in the bilinear mapping.
[0040] Furthermore, the pre-decryption process of the ciphertext is as follows:
[0041] Regarding the found encrypted CT scan i The cloud server finds a set of constants. Make λ j To access the shared shares of the matrix rows, then compute the ciphertext CT. i Pre-decrypted ciphertext CT i ′:
[0042]
[0043] Furthermore, pre-decrypted ciphertext CT i The decryption process of ' is as follows:
[0044] User U DU Use the private key SK to decrypt the ciphertext CT. i Decryption yields B i :
[0045]
[0046] Find the ciphertext CT that precedes the ciphertext set. i-1 , obtain B i-1 :
[0047]
[0048] Repeat the above steps, user U DU Obtain the data set {B1,...,B i-1 B i};
[0049] Plain text data Obtain batch plaintext data F = {F1, F2, ..., F i}
[0050] The blockchain-based hierarchical sharing method for medical data provided by this invention has the following beneficial effects:
[0051] (1) Design a hierarchical access control method to integrate the ciphertext part of low-sensitivity files into high-sensitivity files, thereby achieving hierarchical access control of files and reducing decryption and verification computation costs.
[0052] (2) A flexible access policy representation method is proposed based on 0-1 encoding and HVE encoding. This method supports the expression and comparison of hidden attributes. Compared with the traditional attribute encryption method that requires finding a fixed constant to determine whether it conforms to the access policy, this method can compare permissions without disclosing file and user attributes.
[0053] (3) Use blockchain nodes as attribute authorization institutions to realize key generation and attribute management, and solve the single point of failure problem. Attached Figure Description
[0054] Figure 1 This is a schematic diagram illustrating the access structure of the doctor's department corresponding to the Boolean attribute provided in an embodiment of the present invention.
[0055] Figure 2 A flowchart illustrating a blockchain-based hierarchical sharing method for medical data, as provided in an embodiment of the present invention. Detailed Implementation
[0056] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings, so as to help those skilled in the art to have a more complete, accurate and in-depth understanding of the inventive concept and technical solution of the present invention.
[0057] To facilitate comparison of hidden attributes, this invention divides user attributes in the medical data sharing system into weighted attributes and Boolean attributes. The weighted attribute represents the doctor's position within the department, with permissions 1-6 assigned to hospital director, department head, chief physician, associate chief physician, attending physician, and nurse, respectively. The Boolean attribute refers to information such as the doctor's department and ward. The specific access structure is divided as follows: Figure 1 As shown.
[0058] (1) 0-1 encoding
[0059] Let s = s n s n-1 ...s1 is a binary string of length n containing the value of a certain attribute dimension, and the 0 encoding in s is defined as such a set. The 1-code of s is such a set
[0060] For example, let x be 5 and y be 6. As shown in Table 1, the 1 encoding of x starts from the binary string of x. Each time a '1' is encountered, the string is added to the 1 encoding set of x. For example, if the binary representation of x is 011, the first '1' is "01", the second '1' is "011", and so on. Therefore, the 1 encoding set of x is {01, 011}. The 0 encoding of x starts from the binary string. Each time a '0' is encountered, it is flipped to a '1' and added to the 0 encoding set. For example, if the first '0' in x is encountered, it is "0", and then the '0' is flipped to a '1', so the 0 encoding is "1". Since 011 contains only one '0', the 0 encoding set is {1}.
[0061] In the system, the weighted attributes of users are represented using 0-1 encoding. When determining x < y, it is only necessary to check that at least one element in the set of 0 codes for x and 1 codes for y is the same, that is: As shown in Table 1, all of them contain the element "011", so we can conclude that x < y.
[0062]
[0063] Table 1. 0-1 encoding of weighted attributes
[0064] (2) Hidden vector encryption;
[0065] Let vector x = {x1, x2, ..., xn} l} is used for encryption, y = {y1, y2, ..., y l The vector} is used for decryption. Decryption is considered possible only if two vectors match; that is, for each position, the two vectors must have the same letter. In this scheme, vector x represents the attribute set of the ciphertext policy, and vector y represents the attribute set of the private key. For these two vectors, if an attribute in U is contained within the corresponding attribute set of the vector, then the attribute at the corresponding position in the vector has a value of 1. For example, if the system's global attributes are U = {A, B, C, D, E, F}, and the attribute set of the ciphertext policy is W = {A, C, F}, then the policy's HVE vector is x = {1, 0, 1, 0, 0, 1}.
[0066] Since the access structure is a monotonic access structure, during the file sorting and comparison phase, we only need to compare the number of 1s in each file vector to sort the files on the user side. During the decryption and matching phase, a transformation step is required during comparison. As shown in Table 2, if the user's attributes are S = {A, B, C, F}, then the vector is y1 = {1, 1, 1, 0, 0, 1}, and the private key satisfies the following conditions: The strategy is as follows. However, since vector y1 does not match vector x, HVE decryption does not work. To achieve correct decryption, we stipulate that when "(x) i =0 and (y1) i When =1", y i Setting it to "0" will transform the vector into y2, while leaving it unchanged in other cases.
[0067] U A B C D E F x 1 0 1 0 0 1 <![CDATA[y1]]> 1 1 1 0 0 1 <![CDATA[y2]]> 1 0 1 0 0 1
[0068] Table 2 Decryption Matching Based on Hidden Vectors
[0069] Figure 2 A flowchart of a blockchain-based hierarchical sharing method for medical data is provided in this embodiment of the invention. The method is as follows:
[0070] (1) System initialization phase: The blockchain generates system parameters, and each node calculates the value of the corresponding attribute;
[0071] Blockchain with security parameters 1 λ For input, choose G and a prime number of order p. T g∈G is a generator, e:G×G→G T It is a bilinear mapping, choosing a hash function. and H:{0,1} * →G, and random numbers g, h, u, v∈G, Let G be a field of prime integers of order p, and let G denote a group of order q.
[0072] All nodes randomly generate and broadcast their secret share α. θ A node receives secret shares broadcast by k or more other nodes and obtains the same shared secret parameters using the Pedersen secret sharing protocol.
[0073] The medical system has a total of l Boolean attributes, which constitute the global attributes. For the j-th boolean attribute w in the global attribute W j Randomly select a random number: Where j∈[1,l], all Boolean attributes in the global attribute W are traversed, and the system common parameters are constructed based on random numbers. Where, e(g,g) α Let α be the result of the bilinear mapping e of g and g raised to the power of α.
[0074] Calculate master key parameters based on random numbers: Z = e(g, g) z Construct the master key based on the master key parameters Among them, g α In this context, α is the shared secret parameter, and g is a random number.
[0075] The medical system has n blockchain nodes, including one master node and multiple slave nodes. Each slave blockchain node (referred to as a slave node) manages at least one boolean attribute in the global attribute W. The number of nodes is BN. θ The set of Boolean attributes A of management θ ={Att θ,1 ,...,Att θ,q}, Att θ,q Represents a blockchain node BN θ The q-th Boolean attribute is managed by a node, where Boolean attributes in each set do not overlap, and a Boolean attribute can only be managed by one node. Node BN θ Input system common parameter PP, which is a Boolean attribute set A θ Select a random number for each boolean attribute in the array. And based on random number r θ,q Calculation parameters BN for each node θ Choose a random number Calculate and broadcast parameters and parameters Using parameters respectively parameter As a secret share, after a node receives secret shares broadcast by k or more other nodes, each node obtains the parameter g using the Pedersen secret sharing protocol. γ and parameter v γ ;
[0076] (2) During the user registration phase, the registered user key generates a pre-decryption key TK and an access retrieval key K;
[0077] Registered user U inputs their own weighted attribute S * and Boolean property w * The public parameters PP and the system master key MSK are used by the blockchain to calculate and broadcast a pre-decryption key TK = {L} for each user requesting registration. θ ,K1,K2}, where, K1 = g γ K2 = h β h β In this context, β represents the user's private key, h represents a random number, and ATT represents the total number of ATT points θ Att is the Boolean attribute contained in user U. θ,q The summation result, R θ r is the Boolean attribute contained in user U θ,q The summation result.
[0078] The main blockchain node (referred to as the master node) is based on the weighted attribute S of the registered user U. * Generate 0-1 encoding of weighted attributes in, The 0 encoding for registered user U is generated according to the following rule: starting from the left of the binary encoding of the weighted attribute, every time a "0" is taken, it is flipped to a "1", and the string including all the encodings before it (including the currently flipped 1) is added to the 0 encoding set until the binary encoding traversal is completed. The generation rule for the 1 encoding of registered user U is as follows: starting from the left of the binary encoding of the weighted attribute, every time a '1' is taken, the string including all the encodings before it is added to the 1 encoding set of x (the subsequent 0-1 encoding value rules are as described above).
[0079] The master node is based on the user's own boolean attribute w * Generate an l-bit HVE vector y∈{0,1} l The HVE vector generation rule is as follows: Based on a comparison between the user's existing boolean attributes and the global boolean attributes, if the user has the specified boolean attribute, the element at the corresponding position in the HVE vector is set to 1; otherwise, the element at the corresponding position is set to 0. For an HVE vector y∈{0,1}... l Each element y in j Randomly select a random number z j Choose a random number ε. And satisfy z is a random number. Calculate the parameters respectively: D1={Y j ,L j}, D2={E j ,E′ j}, D′={μ j =t j / r j ,μ′ j =h j / m j}, finally output Ψ U ={D1,D2,D′};
[0080]
[0081]
[0082] The blockchain will be used for the pre-decryption key TK, and the access retrieval key K = {Φ} U Ψ U Returned to registered user U.
[0083] Registered user U randomly selects a private key SK=β. And calculate the public key PK = gβ , Generate a public-private key pair.
[0084] (3) Data owner user U DO Sort the permissions of each file in the uploaded batch of plaintext data;
[0085] When data belongs to user U DO (Patient) uploads batch plaintext data F = {F1, F2, F...} i ...,F k The batch plaintext data is the current medical data. The Boolean attribute w′ and weighted attribute S′ of the file access allowed object are defined as file attributes, so each file has Boolean attributes and weighted attributes.
[0086] File upload user U DO (One of the registered users U) for the i-th file F i Weighted attribute generation encoding in These are the 0 encoding and 1 encoding of the i-th file, respectively.
[0087] File upload user U DO Determine file F i The Boolean attribute set w′ is used to generate an l-bit HVE vector x for each file based on the global attribute W. i For each element x of the vector ij Random selection generate
[0088]
[0089]
[0090] Where, when x ij When = 1, select a random number. When x ij When = 0, select a random number.
[0091] User U DO Use Φ i With x i To sort the file permissions in the file set, files with lower permissions are ranked first. Files with lower weighted attribute values and fewer boolean attributes are considered to have lower permissions. The specific sorting process is as follows: first sort based on the weighted attribute values, and if the weighted attribute values are the same, sort based on the boolean attributes.
[0092] Different files Φ i of Other files F s of Perform an intersection comparison, that is If no duplicate elements are found, the weighted attributes of the next file are verified. If duplicate elements are found, the file's weighted attribute permission is lower than other files, and this file is placed first. Files with the same weighted attributes are then compared using Boolean attributes. When comparing Boolean attributes, the number of 1s in the HVE vector is counted; fewer 1s indicate lower permissions for the corresponding file, and it will be placed first. The sorted file IDs are then used to generate an array J[k] based on permissions from lowest to highest.
[0093] (4) Based on file permissions, each file is encrypted sequentially to form an index. The encrypted data and its index are uploaded to the cloud server for storage. The cloud server returns the data storage address addr.
[0094] Determine file F i The Boolean attribute set w′ is obtained, and then the HVE vector corresponding to the Boolean attribute set w′ is obtained. The file F is constructed according to the LSSS encryption scheme. i Access structure P i P i = {M, ρ), where M is an l x n matrix, each row of which corresponds to an attribute in the attribute set, i.e., there are l attributes in total, and ρ is the mapping function corresponding to the matrix, which satisfies that when j∈{1,2,...,l}, ρ(M) = {M, ρ(ρ)} j )∈w′ j , of which M j Let w′ be the j-th row of matrix M. j For file F i The j-th element in the HVE vector corresponding to the Boolean genus.
[0095] User U DO Generate a random vector ν = (s i ,y2,...,y n ) T , where s is randomly selected i ,y2,...,y n , Randomly drawn from the field of p-order integers, s i For each row M of the access matrix, a randomly selected secret value is used for LSSS encryption. j Calculate the shared share λ j =M j ·v;
[0096] User U DO Use the key and public parameters to assign permissions to each file in ascending order of permissions. i The plaintext is encrypted to generate ciphertext CT. i ={C,C1,C2,C3,θ C x ,C' x C Θ C Λ ,C' Λ};
[0097] in, α*s represents the result of the bilinear mapping e of g and g. i Power: Security parameter for encrypted files, C1 = g c C2 = v c , Among them, ATT θ For file F i Boolean attribute Att θ′,q′ The summation result, θ′ is the file F i The management nodes for each Boolean attribute, where q′ is the set of Boolean attributes corresponding to the Boolean attribute in the management node θ′. θ′ Sorting within; C′ x =g d Where c and d are random numbers,
[0098] For each file F i Select random value Calculate C Λ =m i Z -b C′ Λ =H1(m i Select the (i-1)th file F from the index array Index. i-1 The secret value s i-1 ,calculate α*(s) represents the result of the bilinear mapping e of g and g. i +s i-1 ) times.
[0099] The ciphertext of all files is compiled into a ciphertext set CT, and user U DO Index for generating the ciphertext set CT kw is the key to the ciphertext, and user U DO The encrypted text set CT and its index Index are uploaded to the cloud server for storage, and the cloud server returns the data storage address addr;
[0100] (5) The cloud server receives access from user U DU The query request determines the storage address of the data requested by the query request;
[0101] Access User U DU (The doctor) generated a search trap based on the encrypted keyword kw and the private key SK.
[0102] User U DU Select the timestamp Time′ of the trapdoor generation time to generate a search transaction. in, sign′=Sign SK (ζ), Then the user will search transaction TX search Package and upload to the blockchain for consensus, Sign SK (ζ) indicates that user U is used. DU The private key SK is used to encrypt the parameter ζ.
[0103] Smart contracts use the encrypted key kw to search and calculate the parameter ζ = Verify. PK (sign), parameter ζ′=H(H(T0)||Time′), if ζ=ζ′, then calculate the parameter. if Then verify e(Index,PK) = e(MSK,T0). If the verification passes, the storage address addr is returned to the user U. DU Verify PK (sign) indicates that the search transaction encrypted with the encryption function Sign is decrypted using the public key PK and the corresponding decryption function Verify. e(Index,PK) indicates that Index and PK are mapped using the mapping function in the bilinear mapping. e(MSK,T0) indicates that MSK and T0 are mapped using the mapping function in the bilinear mapping.
[0104] (6) For accessing user U DU The requested data is pre-decrypted, and the pre-decrypted ciphertext is returned to the accessing user U. DU ;
[0105] User U DU Send the pre-decryption key TK, the access retrieval key RK, and the storage address addr to the cloud server.
[0106] The cloud server uses the access key RK to search starting from the last element of the array J[k] to determine the user U. DU Do the attributes meet the standards of the access structure?
[0107] Suppose we have a set of encrypted CT files. i User U DU 1 encoding With each document holding a 0 code Perform an intersection comparison, that is If no duplicate elements are found, then continue to verify the weighted attributes of the next file. If duplicate elements are found in all of them, then it represents user U. DU If the weighted attribute permissions are greater than the corresponding file, continue comparing Boolean attributes.
[0108] When comparing boolean attributes, the file vector x needs to be determined. i Does the position corresponding to the user vector y need to be transformed? Calculate the verification value Δ = e(Γ). ij E j )e(Γ′ ij ,E′ j ), e(Γ ij E j ) indicates that for Γ ij E j The mapping is performed using the mapping function in bilinear mapping, e(Γ′). ij ,E′ j ) indicates that Γ′ ij 、E' j The mapping is performed using the mapping function in bilinear mapping. If Δ equals 1, it indicates that x exists. ij=1 And y j =1, then replace encrypted CT i C Λ C' Λ With Ψ i Perform the calculation: e(X ij ,Y j ) represents X ij Y j The mapping is performed using the mapping function in bilinear mapping, e(Q) ij ,L j ) indicates that for Q ij L j The mapping is performed using the mapping function in bilinear mapping, and then C' is verified. Λ Does it contain H(m′)? i If it exists, the verification passes, and the number of bits in the record array is I = i. Find the ciphertext CT whose number of bits in the array is less than i. n For the found ciphertext CT, n≤i i The cloud server finds a set of constants. Make λ j To access the shared shares of the matrix rows, then compute the ciphertext CT. i Pre-decrypted ciphertext CT i ′:
[0109]
[0110] The cloud server will return the pre-decryption result, the ciphertext set, and the array index to the user. DU .
[0111] (7) For accessing user U DU The returned pre-decrypted ciphertext is decrypted in batches to obtain the corresponding plaintext data.
[0112] User U DU Use the private key SK to decrypt the ciphertext CT. i Decryption yields B i :
[0113]
[0114] Based on this, if a user wants to obtain more data within their permissions, they can find the data CT that is the first element in the ciphertext set based on the number of bits I=i in the returned record array. i-1 The intermediate ciphertext B is obtained. i-1 :
[0115]
[0116] And so on, user U DU Finally, we can obtain the set {B1,...,B}. i-1 B i}
[0117] User U DU The final plaintext data can be obtained through simple calculations.
[0118] By repeating this step, the user can obtain a batch of plaintext data F = {F1, F2, ..., F...} i}
[0119] This invention encrypts files with monotonic access structures according to different sensitivities. A secret value is passed upwards through a sharing method, transferring the secret value of a low-sensitivity ciphertext to a high-sensitivity ciphertext. During the data decryption phase, a rapid comparison is performed to find the file with the highest sensitivity that the user can satisfy, followed by a pre-decryption. This makes it easier to decrypt sensitive files in the file set, improving access control and effectively reducing the number of decryption steps in the medical data sharing process. This truly achieves multi-level attribute data sharing while ensuring privacy and security.
[0120] The present invention has been described by way of example. Obviously, the specific implementation of the present invention is not limited to the above-described manner. Any non-substantial improvements made using the inventive concept and technical solution of the present invention, or the direct application of the inventive concept and technical solution of the present invention to other occasions without modification, are all within the protection scope of the present invention.
Claims
1. A blockchain-based medical data hierarchical sharing method, characterized in that, The method is as follows: Uploading medical data: Data for all users Set up batch medical data The system analyzes the Boolean and weighted attributes of each file, sorts file permissions based on these attributes, and builds an access structure for each file in ascending order of permissions. Finally, it encrypts the corresponding files based on this access structure, enabling batch processing of medical data. After all files are encrypted, batch medical data is generated. The index will contain the index and encrypted bulk medical data. The data is uploaded to a cloud server for storage, and the cloud server returns the storage address to all users. ; Access to medical data: Data access users A query request is sent to the cloud server, and the query request includes the requesting user. pre-decryption key The cloud server, based on the received decryption key, pre-decrypts the requested batch of medical data within the authorized scope, obtaining the pre-decrypted ciphertext of the authorized medical data, and returns it to the data access user. Data access users Decrypt the pre-decrypted ciphertext of the authorized medical data using the private key to obtain the plaintext of the authorized medical data. Registered users send a registration request to the blockchain, which includes the user's own weighted attributes. and Boolean properties ; Registered users send registration requests to the blockchain, which then processes them based on the registered user's weighted attributes. Constructing weighted coding for users , The 0 code for registered user U, The 1-code for registered user U; Data for all users Based on uploading batch medical data The weighted attributes of each file are used to construct the weighted encoding of the corresponding file. , The i-th file 0 encoding and 1 encoding; File Weighted encoding In Other documents In weighted encoding Intersection If the intersection contains no duplicate elements, then verify the weighted attribute of the next file. If the intersection contains identical elements, then the document... The weighted attribute permissions are less than those of other files. .
2. The blockchain-based hierarchical sharing method for medical data as described in claim 1, characterized in that, Pre-decryption key The specific process for obtaining it is as follows: The blockchain generates a pre-decryption key for each registered user. And broadcast it, among which, , , ; in, For the Boolean attributes contained in user U The summation result For the Boolean attributes contained in user U The summation result Represents a blockchain node The first management A boolean attribute, , For system common parameters Random numbers in the data, For registered users' private keys, For Boolean attribute sets Select a random number for the q-th boolean attribute and calculate the parameter. ,parameter and The specific process for obtaining it is as follows: Each node Choose a random number Calculate and broadcast parameters and parameters , respectively with parameters ,parameter As a secret share, after receiving the secret shares broadcast by k other nodes, each node obtains parameters using the Pedersen secret sharing protocol. and parameters .
3. The blockchain-based hierarchical sharing method for medical data as described in claim 1, characterized in that, Data access users The specific process for determining batch medical data within the authorized scope is as follows: Batch medical data The files in the file are sorted in ascending order according to the weighted attribute S, where S represents the weighted attribute of the current file. When the weighted attribute values are the same, the Boolean attributes contained in the HVE vectors of each file are used to determine the weighted attribute values. Arrange them in ascending order of quantity. This is a boolean attribute of the current file; Based on batch medical data Iterate through the files in reverse order to find the user whose weighted attribute is lower than that of the data access user. The file with the highest permissions based on weighted attributes; starting from the file with the highest permissions found, for users... The boolean attributes of the user are validated against the boolean attributes of the corresponding file. If the validation passes, the permissions of the corresponding file and the files listed before it are lower than those of the user. Batch medical data within the authorized scope.
4. The blockchain-based hierarchical sharing method for medical data as described in claim 3, characterized in that, Registered users send registration requests to the blockchain, and the blockchain constructs a Boolean attribute vector for the user based on the user's own Boolean attributes. , , , , ; ; ; ; in, This represents a random number among the system's common parameters. These are random numbers generated for the j-th boolean attribute. This refers to each element in the HVE vector. A randomly selected random number that satisfies , It is a random number. Represents random numbers; data for all users. Based on uploading batch medical data Construct a Boolean attribute vector for each file based on its Boolean attributes. : , ; ; ; Among them, based on global attributes Generate each file HVE vector For each element of the vector Random selection ,when When selecting a random number ,when When selecting a random number ; Calculate the verification value ,if If the value is 1, it indicates that it exists. and , will replace , ; ciphertext middle , and Perform the calculation: Then verify Does it contain If it is included, the verification passes; in, Indicates to The mapping is performed using the mapping function in bilinear mapping. Indicates to The mapping is performed using the mapping function in bilinear mapping. Indicates to The mapping is performed using the mapping function in bilinear mapping. Indicates to The mapping is performed using the mapping function in bilinear mapping, for each file Select random value ,calculate , ; express Input hash function The hash value output later.
5. The blockchain-based hierarchical sharing method for medical data as described in claim 1, characterized in that, The encryption process for the corresponding file based on the access structure is as follows: Confirm file Boolean property set Get Boolean attribute set The corresponding HVE vector is used to construct the file based on the LSSS encryption scheme. Access structure , ,in, For one A matrix with n rows and n columns, a matrix Each row corresponds to one attribute in the attribute set. Let be the mapping function corresponding to the matrix, when hour, ,in, For matrix The j-th line in For the file The j-th element in the HVE vector corresponding to the Boolean genus set; user Generate random vectors Among them, random selection , Randomly selected from the field of p-order integers. For each row of the access matrix, a randomly selected secret value is used for LSSS encryption. Calculate shared shares ; user Use the key and public parameters to process each file in ascending order of permissions. The plaintext is encrypted to generate ciphertext. ; in, , The result of the bilinear mapping e of g and g is... Power of 1 , , ,in, For the file Boolean properties The summation result For the file The management nodes for each Boolean attribute, For the corresponding boolean attribute in the management node Boolean property set Sorting within; , , , It is a random number. ; For each file Select random value ,calculate , Select the index in the Index array. files Secret Value ,calculate , The result of the bilinear mapping e of g and g is... Power of 1.
6. The blockchain-based hierarchical sharing method for medical data as described in claim 1, characterized in that, Batch medical data index The generation process is as follows: The ciphertext of all files is combined into a ciphertext set CT, and the user... Index for generating the ciphertext set CT , The key to the ciphertext is , where This indicates that secret parameters are shared.
7. The blockchain-based hierarchical sharing method for medical data as described in claim 1, characterized in that, Data access users The specific process of retrieving data from the query request is as follows: Access User Based on ciphertext keywords and private key Generate search trapdoor ; user Select the timestamp of the time the trapdoor was generated. Generate search transactions ,in, , , Users will search for transactions Package and upload to the blockchain for consensus. Indicates user private key For parameters Encrypt; Smart contracts use encrypted keys Perform a search and calculate parameters. ,parameter ,if Then calculate the parameters ,if Then verify If the verification passes, the storage address will be... Returned to the user ; in, Indicates the use of a public key Encryption function Encrypted search transactions are performed using the corresponding decryption function. Decryption is required. Indicates to The mapping is performed using the mapping function in bilinear mapping. Indicates to The mapping is performed using the mapping function in bilinear mapping.
8. The blockchain-based hierarchical sharing method for medical data as described in claim 5, characterized in that, The pre-decryption process of the ciphertext is as follows: Regarding the found ciphertext The cloud server finds a set of constants. , making , To access the shared shares of the matrix rows, the ciphertext is then computed for the user. Pre-decrypted ciphertext : 。 9. The blockchain-based hierarchical sharing method for medical data as described in claim 8, characterized in that, Pre-decrypted ciphertext The decryption process is as follows: user Use private key For pre-decrypted ciphertext Decryption : ; Find the ciphertext preceding the first character in the ciphertext set. ,get : ; Repeat the above steps, user Obtain the data set ; Plain text data Obtain batch plaintext data .