Supply chain privacy data sharing scheme based on hierarchical attribute password
By adopting a hierarchical structure-based attribute cryptography scheme and blockchain technology in supply chain management, hierarchical encryption and dynamic access control of data are solved, and the problem of difficult to effectively realize data permission control and privacy protection in the existing technology is solved, and fine-grained permission control and privacy protection of data is realized.
Patent Information
- Application Number
- CN202311459097.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-03
- Publication Date
- 2025-05-06
AI Technical Summary
In supply chain management, it is difficult for the existing technology to effectively realize fine-grained permission control and privacy protection of data, especially in data exchange scenarios where multiple parties participate.
The attribute cryptography scheme based on a hierarchical structure is adopted and combined with blockchain technology to realize hierarchical encryption and dynamic access control of data. By declaring attributes and generating attribute keys, users encrypt and decrypt data according to access control policies, ensuring that only users who meet the policy can access the data.
It realizes fine-grained permission control and privacy protection of data, improves the flexibility and security of data access, and meets the data exchange needs of multiple parties in the supply chain.
Smart Images

Figure CN119939643A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of attribute cryptography, and in particular relates to a supply chain privacy data sharing solution based on hierarchical attribute cryptography and blockchain. Background Art
[0002] As the social division of labor becomes increasingly clear, more and more companies are creating market-competitive products by gathering the advantages of all parties and relying on a larger supply chain network. Maintaining information security and privacy protection in the supply chain has become an important link.
[0003] As a representative of one-to-many encryption system, attribute encryption is very suitable for large-scale data exchange scenarios in the supply chain. It can realize fine-grained permission control of multiple participants and enable participants to access data on demand. Attribute cryptography allows the encryption and decryption of data to depend on the attributes of users or data. Only users who meet the access policy can decrypt the data, thereby realizing fine-grained data access control and encryption. Attribute cryptography originated from fuzzy identity encryption. The fuzzy identity encryption scheme describes the identity as a set of attributes, and realizes the function of decryption when the identity key used for encryption is similar to the identity key used for decryption. Later researchers built key policy-based attribute encryption based on the fuzzy identity encryption scheme, and divided attribute encryption into key policy-based attribute encryption and ciphertext policy-based attribute encryption according to the different association methods between keys and ciphertexts and attributes and policies. The attribute cryptography scheme based on the hierarchical structure considers the hierarchical access control relationship of encrypted files, and integrates the access policies related to hierarchical files into a single access structure with multiple levels. Each layer of the access structure represents the access policy of a file. With this hierarchical access structure, it is possible to obtain different plaintexts after a single ciphertext is decrypted using different attribute key sets, truly realizing one-to-many encryption. Compared with the attribute encryption scheme based on key policy, the attribute encryption scheme based on hierarchical structure has greater flexibility and efficiency in specifying policies and managing user attributes.
[0004] Blockchain is a distributed ledger technology. Its core concept is to store data in a string of data structures called "blocks" and use cryptographic methods to link each block together to form an unalterable and unforgeable chain. Each block on the blockchain contains the hash value of the block and the hash value of the parent block, ensuring that the linked blocks are unalterable.
[0005] Hyperledger Fabric is an open source blockchain framework under the Linux Foundation. It is a modular platform for building enterprise-level blockchain solutions. Hyperledger Fabric aims to provide flexibility, scalability and privacy, enabling enterprises to build secure and efficient blockchain applications. Hyperledger Fabric adopts a modular design, allowing users to customize blockchain networks as needed. It supports multiple consensus algorithms, authentication services, storage implementations and smart contract engines, allowing users to flexibly configure and customize blockchain networks. It provides a strong privacy and permission control mechanism. It supports parallel execution of smart contracts and isolates transactions using container technology to improve throughput and performance. In addition, it also supports horizontal expansion of distributed nodes to meet growing needs. It allows users to choose a suitable consensus algorithm to reach consensus. Currently supported consensus mechanisms include Kafka, Raft, etc. These algorithms can be configured according to application scenarios and performance requirements. It provides identity authentication and access control based on MSP (Membership Service Provider) to ensure that only authorized participants can join the network and execute transactions. In addition, data is encrypted during transmission and storage. It supports the development of smart contracts in multiple programming languages. Currently supported smart contract languages include Golang, JavaScript, TypeScript and Java. Summary of the invention
[0006] The purpose of this invention is to propose an attribute encryption and supply chain privacy data sharing scheme based on a hierarchical structure, aiming to provide innovative solutions for information security and privacy protection in the supply chain field and promote the development of digital supply chain management.
[0007] The scheme based on hierarchical attribute encryption proposed in this invention is different from the general attribute encryption scheme. It is an innovative scheme that covers the characteristics of decentralization, hierarchical encryption, dynamic access control, etc. The overall model of the scheme is as follows: Figure 1 shown.
[0008] As the end point of data storage, blockchain stores encrypted user information and data uploaded by users. Smart contracts on the chain automatically complete business logic, including system initialization, user registration, user data upload and data access. Smart contracts ensure that data cannot be tampered with and that all parties involved reach a consensus.
[0009] As the owner and user of data, users can initiate operations related to data upload and access. After the system is initialized, users can initiate registration, and the smart contract on the blockchain ensures the uniqueness of the user and completes the registration. Then, users can declare the attributes they own and use their own attribute sets to download data on the chain. At the same time, they can also upload data and formulate corresponding access control policies for other users in the system to access and use.
[0010] The authority center is responsible for managing and issuing user attributes in attribute encryption, verifying and issuing attributes declared by users, maintaining the accuracy of attributes, participating in generating keys required for attribute encryption, and performing permission control and identity authentication when necessary.
[0011] The workflow of the supply chain privacy data sharing solution based on hierarchical attribute encryption in this invention is as follows: Figure 2 As shown: The specific workflow is:
[0012] (1) First, the system initializes public parameters and uploads public parameters and other information to the chain;
[0013] (2) The user performs initialization and uploads user information to the chain;
[0014] (3) Users as data users declare their own attributes as needed and then upload the attribute information to the chain;
[0015] (4) As the data owner, the user specifies the data encryption policy, uploads the data to be encrypted, and the encrypted data is uploaded to the blockchain;
[0016] (5) As the data owner, the user can specify sub-data and corresponding sub-encryption strategies, implement hierarchical encryption of data, and upload the encrypted data to the blockchain;
[0017] (6) Users who are data users use their own attributes to generate attribute keys and access shared data;
[0018] (7) The encryption and decryption module decrypts the data according to the attribute key of the user who is the data user, and returns the decryption result to the data user. If the attribute set conforms to the access control structure, the plaintext of the data can be obtained; if the attribute set does not conform to the access control structure, a decryption failure message is returned.
[0019] Attached photos
[0020] Figure 1 The figure shows the overall model of the scheme.
[0021] Figure 2 A flowchart of the program.
[0022] Figure 3 The figure shows the overall system architecture.
[0023] Figure 4 This is a system timing diagram. DETAILED DESCRIPTION
[0024] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below based on specific embodiments and drawings, but the protection scope of the present invention is not limited to the following embodiments.
[0025] The smart contract on the blockchain described in the present invention is divided into three modules: initialization, attribute management, encryption and decryption, and specifically includes 5 algorithms:
[0026] (1) Public parameter initialization: The authority center uses the generator to select the security parameter δ, and selects the bilinear groups G1 and G according to the security parameter δ. r , the order of G1 is p; then, randomly select a generator g∈G1 for the bilinear group, and randomly select α, β∈Z p , and calculate g β , e(g, g) α , select the hash function H used to map the attribute to the bilinear group; thus, the public key PK of the system is obtained as follows: T ,e,p,g,g β , H, e(g, g) α} and master key MSK = {β, g α};
[0027] (2) Attribute key generation: The authority selects a random index r∈Z p , and calculate the key component D for each attribute i in the user's attribute set γ i =H(i) r ; At the same time, calculate the key component D = g α g βr and key component D0 = g r ; Get the attribute key
[0028] (3) Policy merging: Users merge access control policies with similar structures. and According to the access control policy Generate access control tree Γ A , according to the access control policy Generate access control tree Γ B , for the access control tree Γ A Traverse each non-leaf node in and record the index of the non-leaf node. If the subtree with the node as the root is consistent with the access control tree Γ B If they are the same, they can be merged and the information M′ can be added to the information group {M1, M2, ..., M |X|}, the subscript used by the information M′ is the index of the non-leaf node;
[0029] (4) Information encryption: The user first enters the hierarchical access control policy and the information group to be encrypted {M1, M2, ..., M |x|}, the authority center generates an access control tree Γ according to the access control policy; starting from the root node A of the access control tree Γ, a polynomial qx is generated for each non-leaf node x in the access control tree from top to bottom; for each non-leaf node x, a random index q is selected x (0)∈Z p As the secret value of the root node A, and then randomly select the polynomial q A The coefficients of the other terms, the total number of other terms is d A Item; for other non-leaf nodes x other than the root node, calculate q x (0) = q x (index(x)), where the function index(x) returns the index of the non-leaf node x; the polynomial q x The other items of are consistent with the generation mode of the root node polynomial; set the non-leaf node set of the access control tree Γ to X, and generate a random index R for each element in X x ∈Z p , use the symmetric encryption algorithm AES to encrypt R x As a symmetric key to the information M x Encrypt and get the AES algorithm ciphertext K x , and then calculate the ciphertext component and where σ x =q x (0); Set the leaf node set of the access control tree Γ to Y, and generate a random index r for each element in Y y ∈Z p , calculate the ciphertext component and C′ y =gr y ; After the information is encrypted, the ciphertext CT is obtained:
[0030]
[0031] (5) Information decryption: Given the public key PK, ciphertext CT, attribute set γ, and attribute private key SK as input, the decryption algorithm is run to decrypt the ciphertext; the authority center decrypts the ciphertext according to the access control policy. Generate access control tree Γ; define function att(x) only when x is a leaf node and has associated attributes; then, for each node y in the leaf node set Y, define recursive function DecrpytNode(x), let i = att(y), if i∈γ, then calculate if Then the node is not calculated; the calculation result of DecrpytNode(x) is recorded as F x ; Then, for each non-leaf node x, the recursive algorithm DecrpytNode(x) is calculated according to the following rules: Let the child node of node x be x′, let S x If it can be decrypted, then F can be calculated. x The set of x′, the size of which is k x ; If this set cannot be generated, the algorithm returns empty; otherwise, let j = index(x′), S′ x ={index(x′):x′∈S x},calculate The Lagrange interpolation calculation results in Recalculate You can get R x Finally, R x and ciphertext component k x Substitute it into the AES decryption algorithm to get the information Mx.
[0032] According to the above scheme, the present invention implements an efficient sharing system of private data on cloud storage on MacOS 13.5.2 operating system. The processor is Apple Ml Pro, 32G memory, Fabric version is v2.5.2, and the blockchain node is started through the Docker container, and the selected Docker version is 20.10.21. This paper builds two peer nodes and one order node, and Raft communication is used between nodes. The overall architecture of the system is as follows: Figure 3 shown.
[0033] The application layer is the interface for users to interact with the system. It is responsible for presenting data, receiving user input, and passing requests to the business layer for processing. The application layer includes the user interface, interaction logic, and front-end components that interact with users. This system uses JavaScript language combined with the vue3Web front-end framework to provide an interactive interface for supply chain participants, allowing participants to simply encrypt files through the interface, share files in the system, and download decrypted files from the system.
[0034] The business layer is responsible for handling the core business logic of the system. It receives requests from the application layer, processes data, executes business rules for information encryption upload and information decryption download, and passes necessary operations to the contract layer to call smart contracts on the blockchain. The business layer of this system uses Java language combined with Spring Boot framework and Hyperledger Fabric SDK to build a backend platform to implement business logic for functions such as user registration, attribute management, and file encryption.
[0035] The contract layer is the deployment and management area of smart contracts. Smart contracts are code snippets based on blockchain technology that are used to perform automated operations and ensure security. In the supply chain information exchange system, the contract layer includes the implementation of attribute passwords for access control, data encryption and decryption, etc. The system uses the Golang language to build an attribute encryption algorithm module for the business layer to call.
[0036] The storage layer is responsible for persisting data and providing data reading and writing interfaces. In the supply chain information exchange system, the storage layer uses the Hyperledger Fabric consortium chain as the end point of data storage, storing encrypted information of supply chain participants, user data, etc.
[0037] Take user Bob (data owner) authorizing user Alice (data user) to share his data as an example. Figure 4 shown.
[0038] User registration / login: When registering, the user’s necessary information should be collected, the user should be initialized, and the user information should be uploaded to the chain; when logging in, the password should be verified to be correct.
[0039] Attribute authorization: Users can create their own attributes as needed, apply for attributes from an authorized agency, and then the authorized agency will upload the attribute information to the chain.
[0040] Data encryption: Users select an access control structure to encrypt plaintext information. The system uploads the ciphertext to the cloud storage specified by the user, and also uploads relevant information such as the ciphertext summary to the chain.
[0041] Attribute private key generation: The system generates the corresponding attribute key based on the attributes created by the user.
[0042] Data decryption and data sharing: User Bob can directly obtain and decrypt his own data from the cloud; if user Alice has been authorized to use the attributes corresponding to the ciphertext, she can use the corresponding attribute key to decrypt the ciphertext data and achieve data sharing.
[0043] Under different numbers of attributes, the algorithm efficiency of each major stage of the system was simulated, and the results are shown in the following table:
[0044]
Claims
1. A supply chain privacy data sharing scheme based on hierarchical attribute cryptography and blockchain, characterized in that: It is mainly divided into three entities: blockchain, users, and authoritative centers; among them: The blockchain, the end point of data storage, adopts the Hyperledger Fabric consortium chain architecture to store encrypted user information and data uploaded by users. The smart contract on the chain automatically completes the business logic, including system initialization, user registration, user data upload and data access, etc. The smart contract ensures that the data cannot be tampered with and that all participants reach a consensus. The user, i.e. the participant in the supply chain, can initiate operations on uploading and accessing private data in the supply chain. After the system is initialized, the user can initiate registration, and the smart contract on the blockchain ensures the uniqueness of the user and completes the registration. Then, the user can declare the attributes he owns and use his own attribute set to download the data on the chain. At the same time, he can also upload data and formulate corresponding access control policies for other users in the system to access and use. The authoritative center is the role of managing and issuing user attributes in attribute encryption; the authoritative center is used to verify and issue attributes declared by users, maintain the accuracy of attributes, participate in generating keys required for attribute encryption, and perform permission control and identity authentication when necessary.
2. According to the scheme of claim 1, its working process is as follows: (1) First, the system initializes public parameters and uploads public parameters and other information to the chain; (2) The user performs initialization and uploads user information to the chain; (3) Users as data users declare their own attributes as needed and then upload the attribute information to the chain; (4) As the data owner, the user specifies the data encryption policy, uploads the data to be encrypted, and the encrypted data is uploaded to the blockchain; (5) As the data owner, the user can specify sub-data and corresponding sub-encryption strategies, implement hierarchical encryption of data, and upload the encrypted data to the blockchain; (6) Users who are data users use their own attributes to generate attribute keys and access shared data; (7) The encryption and decryption module decrypts the data according to the attribute key of the user who is the data user, and returns the decryption result to the data user. If the attribute set conforms to the access control structure, the plaintext of the data can be obtained; if the attribute set does not conform to the access control structure, a decryption failure message is returned.
3. According to the solution workflow described in claim 2, the smart contract in the blockchain is divided into three modules: initialization, attribute management, encryption and decryption, which specifically include 5 algorithms: (1) Public parameter initialization: The authority center uses the generator to select the security parameter δ, and selects the bilinear groups G1 and G according to the security parameter δ. T , the order of G1 is p; then, randomly select a generator g∈G1 for the bilinear group, and randomly select α, β∈Z p , and calculate g β , e(g, g) α , select the hash function H used to map the attribute to the bilinear group; thus, the public key PK of the system is obtained as follows: T ,e,p,g,g β , H, e(g, g) α } and master key MSK = {β, g α }; (2) Attribute key generation: The authority selects a random index r∈Z p , and calculate the key component D for each attribute i in the user's attribute set γ i =H(i) r ; At the same time, calculate the key component D = g α g βr and key component D0 = g r ; Get the attribute key (3) Policy merging: Users merge access control policies with similar structures. and According to the access control policy Generate access control tree Γ A , according to the access control policy Generate access control tree Γ B , for the access control tree Γ A Traverse each non-leaf node in and record the index of the non-leaf node. If the subtree with the node as the root is consistent with the access control tree Γ B If they are the same, they can be merged and the information M′ can be added to the information group {M1, M2, ..., M |X| }, the subscript used by the information M′ is the index of the non-leaf node; (4) Information encryption: The user first enters the hierarchical access control policy and the information group to be encrypted {M1, M2, ..., M |X| }, the authority center generates an access control tree Γ according to the access control policy; starting from the root node A of the access control tree Γ, a polynomial q is generated for each non-leaf node x in the access control tree from top to bottom x ; For each non-leaf node x, choose a random index q x (0)∈Z p As the secret value of the root node A, and then randomly select the polynomial q A The coefficients of the other terms, the total number of other terms is d A Item; for other non-leaf nodes x other than the root node, calculate q x (0) = q x (index(x)), where the function index(x) returns the index of the non-leaf node x; the polynomial q x The other items of are consistent with the generation mode of the root node polynomial; set the non-leaf node set of the access control tree Γ to X, and generate a random index R for each element in X x ∈Z p , use the symmetric encryption algorithm AES to encrypt R x As a symmetric key to the information M x Encrypt and get the AES algorithm ciphertext K x , and then calculate the ciphertext component and where σ x =q x (0); Set the leaf node set of the access control tree Γ to Y, and generate a random index r for each element in Y y ∈Z p , calculate the ciphertext component and C′ y =g ry ; After the information is encrypted, the ciphertext CT is obtained: (5) Information decryption: Given the public key PK, ciphertext CT, attribute set γ, and attribute private key SK as input, the decryption algorithm is run to decrypt the ciphertext; the authority center decrypts the ciphertext according to the access control policy. Generate access control tree Γ; define function att(x) only when x is a leaf node and has associated attributes; then, for each node y in the leaf node set Y, define recursive function DecrpytNode(x), let i = att(y), if i∈γ, then calculate if Then the node is not calculated; the calculation result of DecrpytNode(x) is recorded as F x ; Then, for each non-leaf node x, the recursive algorithm DecrpytNode(x) is calculated according to the following rules: Let the child node of node x be x′, let S x If it can be decrypted, then F can be calculated. x The set of x′, the size of which is k x ; If this set cannot be generated, the algorithm returns empty; otherwise, let j = index(x′), S′ x ={index(x′):x′∈S x },calculate The Lagrange interpolation calculation results in Recalculate You can get R x Finally, R x and the ciphertext component K x Substitute into the AES decryption algorithm to get information M x .