Data transaction method and system fusing block chain and proxy re-encryption
By integrating blockchain and proxy re-encryption technology in data transactions, the confidentiality, traceability and integrity issues in data transactions are solved, and the security, transparency and reliability of data transactions are achieved.
Patent Information
- Application Number
- CN202510445792.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
There are problems with the confidentiality, traceability and integrity of data transactions in the existing data trading environment, which makes it difficult to guarantee data security and transaction transparency.
The data transaction method that integrates blockchain and proxy re-encryption is adopted, and the transaction process and data rights confirmation certificate are recorded through the blockchain. The proxy re-encryption technology is used to convert data from one user's encryption domain to another user's encryption domain without decrypting the original data.
It enhances the security of data and the transparency of transactions, ensures the legitimacy and reliability of data, reduces transaction risks, and improves the efficiency and credibility of data transactions.
Smart Images

Figure CN119991125A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data transaction technology, and in particular to a data transaction method and system integrating blockchain and proxy re-encryption. Background Art
[0002] In the digital age, data has become a key productivity factor, strongly promoting the development of new productivity. Data transactions not only promote the free flow of information, but also inject strong impetus into the digital economy, giving rise to new business opportunities and value. However, data transactions are accompanied by security risks such as data leakage, tampering and abuse, which must be taken seriously. Therefore, ensuring the security, authenticity, credibility, privacy, traceability, standardization and fairness of data transactions is extremely important for maintaining the healthy development of the digital economy. To this end, effective measures need to be taken to ensure transaction security and promote the continued prosperity of the data economy.
[0003] There are some problems in the current data trading environment, which are summarized as follows: 1. Confidentiality of data transactions: The confidentiality of data transactions is related to the security of sensitive information. The transaction process is vulnerable to external attacks and there is a risk of illegal theft and leakage, making it difficult to protect the rights and interests of data owners and affecting the stable development of the data transaction market.
[0004] 2. Traceability of data transactions: In data transactions, it may be impossible to trace the source of the data, making it difficult to determine whether the data was obtained through legal means. When data is leaked or abused, it is difficult to determine the responsible party and to conduct effective accountability if it cannot be traced.
[0005] 3. Data integrity issues: Data may be damaged for various reasons during the transaction process, and its integrity is difficult to guarantee. Transmission errors, malicious tampering, and storage device failures may cause partial data loss or damage, affecting the availability and reliability of data and reducing the quality and value of data transactions. Summary of the invention
[0006] In view of the above-mentioned deficiencies in the prior art, the present invention provides a data transaction method and system integrating blockchain and proxy re-encryption.
[0007] In order to achieve the above-mentioned object of the invention, the technical solution adopted by the present invention is: In a first aspect, the present invention proposes a data transaction method integrating blockchain and proxy re-encryption, comprising the following steps: Obtaining registration information submitted by the user, generating a public-private key pair, and sending the public-private key pair to the corresponding user through a secure channel; the user includes the data owner and the data user; Obtain the data confirmation application form submitted by the data owner, verify the digital signature of the data confirmation application form before confirming the data, generate a data confirmation certificate, send it to the data owner and record it on the blockchain; Obtain the data transaction instructions and transaction data ciphertext generated by the data owner after digitally signing and verifying the data ownership certificate, and record the data transaction instructions on the blockchain; Obtain the data transaction order generated by the data user's data transaction application, verify the digital signature of the data transaction order, record it on the blockchain and send it to the data owner; Obtain the re-encryption key generated by the data owner after receiving the data transaction order, perform proxy re-encryption based on the re-encryption key, and then send the re-encrypted ciphertext to the data user; Obtain the data transaction confirmation slip generated by the data user after decrypting the re-encrypted ciphertext and verifying the data integrity, record the data transaction confirmation slip on the blockchain and send it to the data owner.
[0008] Preferably, generating a public-private key pair includes: Randomly select parameters ; According to the parameters Calculate the private key and the public key , expressed as:
[0009]
[0010]
[0011]
[0012] in, is the key parameter, The user's identity. , To expose parameter set parameters, is a base point on the elliptic curve.
[0013] As a preferred method, the data confirmation application form submitted by the data owner is obtained, the data confirmation application form is digitally signed and verified before the data confirmation is performed, and a data confirmation certificate is generated and sent to the data owner and recorded on the blockchain, including: Obtain the data ownership confirmation application form submitted by the data owner and the digital signature generated by the private key on the data ownership confirmation application form; Verify the digital signature of the data rights confirmation application form, then confirm the data rights based on the data rights confirmation application form and generate a data rights confirmation certificate; Digitally sign the data ownership certificate, send the data ownership certificate and the corresponding digital signature to the data owner, and record the data ownership certificate on the blockchain.
[0014] As a preferred method, the data transaction instructions and transaction data ciphertext generated by the data owner after the data owner has verified the digital signature of the data confirmation certificate are obtained, and the data transaction instructions are recorded on the blockchain, including: Obtain the data transaction instructions and transaction data ciphertext generated after the data owner verifies the digital signature of the data ownership certificate; Obtain the digital signature generated by the data owner on the data transaction instructions; After the digital signature of the data transaction specification is verified, the data transaction specification is recorded on the blockchain.
[0015] As a preferred method, a data transaction order generated by a data user initiating a data transaction application is obtained, and the data transaction order is digitally signed and verified before being recorded on the blockchain and sent to the data owner, including: Obtain the data transaction order generated by the data user initiating the data transaction application, and the digital signature generated by signing the data transaction order; After the digital signature of the data transaction order is verified, the data transaction order is recorded on the blockchain and sent to the data owner.
[0016] Preferably, obtaining a re-encryption key generated by the data owner after receiving the data transaction order, performing proxy re-encryption according to the re-encryption key and sending the re-encrypted ciphertext to the data user includes: Obtain the re-encryption key generated by the data owner based on the data user's identity, as well as the digital signature generated for the re-encryption key; After the digital signature of the re-encryption key is verified, proxy re-encryption is performed on the transaction data ciphertext to generate the re-encrypted ciphertext and send it to the data user.
[0017] Preferably, the data transaction confirmation slip generated by the data user after decrypting the re-encrypted ciphertext and verifying the data integrity is obtained, and the data transaction confirmation slip is recorded on the blockchain and sent to the data owner, including: Obtain the data transaction confirmation slip generated after the data user uses the private key to decrypt the re-encrypted ciphertext to obtain the plaintext of the transaction data and complete the data integrity verification, as well as the digital signature generated by signing the data transaction confirmation slip; After the digital signature of the data transaction confirmation form is verified, the data transaction confirmation form is recorded on the blockchain and sent to the data owner.
[0018] Preferably, before obtaining the registration information submitted by the data owner and the data user, the following steps are also included: Initialize the system and generate the required keys and parameters.
[0019] Preferably, the system is initialized to generate the required keys and parameters, including: Based on safety parameters generate ;in Cyclic group and message space The order of , hash map function , for identity space; make for Two different generators in, randomly selected , generate key parameters , public parameter set .
[0020] In the second aspect, the present invention proposes a data transaction system integrating blockchain and proxy re-encryption, comprising: Data owners are used to submit registration information to the data transaction management platform and obtain the public-private key pair sent by the data transaction management platform through a secure channel; submit a data rights confirmation application form to the data transaction management platform and obtain a data rights confirmation certificate sent by the data transaction management platform; perform digital signature verification on the data rights confirmation certificate to generate a data transaction description and send it to the data transaction management platform; obtain a data transaction order sent by the data transaction management platform, generate a re-encryption key and send it to the data transaction management platform; The data transaction management platform is used to obtain the registration information submitted by the user, generate a public-private key pair, and send the public-private key pair to the corresponding user through a secure channel; the users include data owners and data users; obtain the data right confirmation application form submitted by the data owner, perform data right confirmation after digital signature verification on the data right confirmation application form, generate a data right confirmation certificate and send it to the data owner and record it on the blockchain; obtain the data transaction instructions and transaction data ciphertext sent by the data owner, record the data transaction instructions on the blockchain; obtain the data transaction order sent by the data user, perform digital signature verification on the data transaction order, record it on the blockchain and send it to the data owner; obtain the re-encryption key sent by the data owner, perform proxy re-encryption according to the re-encryption key, and send the re-encrypted ciphertext to the data user; obtain the data transaction confirmation form sent by the data user, record the data transaction confirmation form on the blockchain and send it to the data owner; Data users are used to submit registration information to the data transaction management platform and obtain the public-private key pair sent by the data transaction management platform through a secure channel; initiate data transaction applications and generate data transaction orders, and submit data transaction orders to the data transaction management platform; use the private key to decrypt the heavily encrypted ciphertext and perform data integrity verification on the plaintext of the transaction data, then generate a data transaction confirmation form and send the data transaction confirmation form to the data transaction management platform.
[0021] The present invention has the following beneficial effects: 1. Enhanced data security: The proxy re-encryption technology is used to avoid the process of users uploading data in plain text to untrusted data trading platforms. This not only simplifies the encryption domain conversion process, making the entire transaction process more concise and efficient, but also effectively protects the data, enhancing its security and credibility.
[0022] 2. Enhance the transparency of data transactions: Using the distributed ledger of blockchain to record the complete transaction process ensures the transparency and traceability of transactions, reduces transaction risks, and also strengthens the supervision and auditing of data transactions to ensure the traceability of transactions.
[0023] 3. Ensure the legitimacy and reliability of data: By confirming the ownership of data and generating a data confirmation certificate, it not only clarifies the ownership of the data, but also helps to establish a trust mechanism for data transactions, effectively promoting the healthy and orderly development of the data transaction market. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 A flowchart of a data transaction method integrating blockchain and proxy re-encryption is shown; Figure 2 A swimlane diagram of a data transaction method that integrates blockchain and proxy re-encryption. DETAILED DESCRIPTION
[0025] The specific implementation modes of the present invention are described below so that those skilled in the art can understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific implementation modes. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the attached claims, these changes are obvious, and all inventions and creations utilizing the concept of the present invention are protected.
[0026] The present invention aims at the problems of data authenticity, data privacy and data transaction security in data transactions, and provides a data transaction method and system integrating blockchain and proxy re-encryption, which adopts the following technologies: First, Proxy Re-encryption (PRE) allows a third-party agent to convert data from one user's encryption domain to another user's encryption domain without decrypting the original data, greatly reducing the risk of data leakage. Secondly, Blockchain is a decentralized distributed ledger technology with the characteristics of decentralization, immutability, security, transparency, and traceability. It provides the necessary security guarantee for the data transaction process. Finally, Digital Signature is a technology used to verify the authenticity, integrity, and source reliability of digital messages or documents. In data transactions, the use of digital signatures can accurately verify the identity of users and ensure the authenticity of the data source.
[0027] In combination with the above technologies, the present invention provides a data transaction method and system that integrates blockchain and proxy re-encryption, which combines proxy re-encryption technology, blockchain and digital signature to solve the problems of security, transparency, traceability, data rights confirmation, etc. in data transactions. This process improves the efficiency of data transactions and reduces costs by optimizing the steps of data transactions, so as to promote the standardization and healthy development of the data transaction market. With the continuous advancement of technology and the deepening of its application, the present invention is expected to be vigorously promoted in all walks of life, providing a solid technical foundation for the healthy development of data transactions, and promoting the construction of a more secure and open data transaction environment.
[0028] Reference Figure 1 and Figure 2 , a data transaction method integrating blockchain and proxy re-encryption provided by an embodiment of the present invention includes the following steps S1 to S6: S1. Obtain the registration information submitted by the user, generate a public-private key pair, and send the public-private key pair to the corresponding user through a secure channel; the user includes the data owner and the data user; S2. Obtain the data confirmation application form submitted by the data owner, verify the digital signature of the data confirmation application form, and then confirm the data rights. Generate a data confirmation certificate and send it to the data owner and record it on the blockchain; S3. Obtain the data transaction instructions and transaction data ciphertext generated by the data owner after digital signature verification of the data ownership certificate, and record the data transaction instructions on the blockchain; S4. Obtain the data transaction order generated by the data user initiating the data transaction application, verify the digital signature of the data transaction order, record it on the blockchain and send it to the data owner; S5. Obtain the re-encryption key generated by the data owner after receiving the data transaction order, perform proxy re-encryption according to the re-encryption key, and then send the re-encrypted ciphertext to the data user; S6. Obtain the data transaction confirmation slip generated by the data user after decrypting the re-encrypted ciphertext and verifying the data integrity, record the data transaction confirmation slip on the blockchain and send it to the data owner.
[0029] In an optional embodiment of the present invention, before step S1, the present embodiment further includes: S0. Initialize the system and generate the required keys and parameters.
[0030] In this embodiment, a trusted key generation center (KGC) completes initialization and generates required keys and parameters.
[0031] This embodiment is based on security parameters Generate a bilinear map, denoted by ;in Cyclic group and message space The order of , hash map function , for identity space; make for Two different generators in, randomly selected , generate key parameters , public parameter set .
[0032] In an optional embodiment of the present invention, the users in this embodiment include data owners and data users, and the registration steps performed by both on the data transaction management platform are the same. The user submits registration information to KGC and KGC returns a public-private key pair to the user through a secure channel.
[0033] In this embodiment, the user submits basic registration information to KGC (including user name, user password, individual or enterprise, data owner or data user, uploaded identity certificate, etc.), and KGC generates a unique identity for the user. , expressed as:
[0034] The identities of data owners and data users are .
[0035] Step S1 of this embodiment is executed by KGC. Input key key parameters , Public parameter set and identity , including the following steps: Randomly select parameters ; According to the parameters Calculate the private key and the public key , expressed as:
[0036]
[0037]
[0038]
[0039] in, is the key parameter, The user's identity. , To expose parameter set parameters, is the base point on the elliptic curve.
[0040] Can get the private key of the data owner and the public key .
[0041] Similarly, the private key of the data user , public key .
[0042] In the private key middle, For decryption calculation, For re-encryption key construction, As a public-private key pair to perform digital signatures, the private key Same reason.
[0043] KGC will Sent to the data owner through a secure channel Sent to data users through a secure channel.
[0044] In an optional embodiment of the present invention, a data confirmation application form submitted by a data owner is obtained, the data confirmation application form is digitally signed and then the data confirmation is performed, a data confirmation certificate is generated and sent to the data owner and recorded on the blockchain, including: Obtain the data ownership confirmation application form submitted by the data owner and the digital signature generated by the private key on the data ownership confirmation application form; Verify the digital signature of the data rights confirmation application form, then confirm the data rights based on the data rights confirmation application form and generate a data rights confirmation certificate; Digitally sign the data ownership certificate, send the data ownership certificate and the corresponding digital signature to the data owner, and record the data ownership certificate on the blockchain.
[0045] In this embodiment, the data owner (DO) submits a data confirmation application to the Data Confirmation Center (RCC). The RCC confirms the data received based on the information in the application form, generates a data confirmation certificate, sends it to the DO, and records it on the blockchain (BC).
[0046] DO receive the private key Then the data to be released is encrypted, expressed as:
[0047] Step S2 performs data encryption and is executed by DO. Input key parameters , Public parameter set , transaction data plain text as well as , including the following steps: Random Selection ; calculate , , ; Output ciphertext .
[0048] Step S2: Apply for data rights confirmation. DO generates a data rights confirmation application form. Sent to RCC, represented by:
[0049] in is the identity of DO, A summary of the transaction data. is the transaction data type, is the transaction data attribute, is the transaction data size, The validity period of transaction data. For the rights and interests of transaction data, To confirm the application time, For data acquisition method, H () is a hash function, The hash value obtained by hashing the transaction data ciphertext.
[0050] Generate in DO Then, using its private key And the national secret SM2 signature algorithm Digitally sign, that is:
[0051] After signing, Sent to the data transaction center.
[0052] When performing data verification in step S2, after receiving the data confirmation application information sent by DO, RCC first uses the national secret SM2 signature verification algorithm to verify the digital signature, namely:
[0053] After the digital signature verification is passed, RCC will continue to execute data confirmation, otherwise DO's data confirmation application will be rejected.
[0054] Step S2: When confirming data ownership, RCC sends an application form via DO Confirm the data ownership and generate a data confirmation number ,as follows:
[0055] in is the RCC's institutional identification number, The hash value of the data rights confirmation application form. The data confirmation time. Then the data confirmation certificate is generated. ,as follows:
[0056] in For data introduction, The validity period of the data.
[0057] After that, RCC uses the national secret SM2 signature algorithm to Digitally sign and The signature is sent to DO and recorded on BC.
[0058] In an optional embodiment of the present invention, the data transaction instructions and transaction data ciphertext generated by the data owner after the data owner performs digital signature verification on the data confirmation certificate are obtained, and the data transaction instructions are recorded on the blockchain, including: Obtain the data transaction instructions and transaction data ciphertext generated after the data owner verifies the digital signature of the data ownership certificate; Obtain the digital signature generated by the data owner on the data transaction instructions; After the digital signature of the data transaction specification is verified, the data transaction specification is recorded on the blockchain.
[0059] In this embodiment, DO receives After completing the digital signature verification using the national secret SM2 signature verification algorithm, a data transaction instruction will be generated to facilitate other users to complete data transactions based on the data transaction instruction. The data transaction instruction and the transaction data ciphertext will then be sent to the data transaction center, and the data transaction instruction will be recorded on the BC.
[0060] When generating the transaction instructions in step S3, DO completes the verification using the national secret SM2 signature verification algorithm. After the digital signature is verified, a data transaction description is generated It is convenient for other users to initiate transaction applications according to the instructions, as follows:
[0061] in The rights and obligations of the data user (DU), i.e., the data rights and related responsibilities obtained by the DU after successfully purchasing the data; The data transaction price.
[0062] When data is released in step S3, DO Use the national secret SM2 signature algorithm to complete the digital signature and send it to the data transaction center. After the data transaction center successfully verifies the signature, Once recorded on BC, the transaction data is released.
[0063] In an optional embodiment of the present invention, a data transaction order generated by a data user initiating a data transaction application is obtained, and the data transaction order is digitally signed and verified, recorded on the blockchain, and sent to the data owner, including: Obtain the data transaction order generated by the data user initiating the data transaction application, and the digital signature generated by signing the data transaction order; After the digital signature of the data transaction order is verified, the data transaction order is recorded on the blockchain and sent to the data owner.
[0064] In this embodiment, after DU completes registration at the data transaction center, it can retrieve relevant data on BC and initiate a data transaction application, generate a data transaction order, send it to the data transaction center and record it on BC.
[0065] DU generates a transaction order by searching on BC and selecting the data it wants to purchase. ,as follows:
[0066] in is the identity of DU, The time the order was generated.
[0067] DU uses the national secret SM2 digital signature algorithm to Digitally sign and send to the data transaction center.
[0068] In an optional embodiment of the present invention, obtaining a re-encryption key generated by a data owner after receiving a data transaction order, performing proxy re-encryption according to the re-encryption key, and sending the re-encrypted ciphertext to the data user includes: Obtain the re-encryption key generated by the data owner based on the data user's identity, as well as the digital signature generated for the re-encryption key; After the digital signature of the re-encryption key is verified, proxy re-encryption is performed on the transaction data ciphertext to generate the re-encrypted ciphertext and send it to the data user.
[0069] In this embodiment, the data transaction center successfully completes the verification using the national secret SM2 signature verification algorithm. After the signature is verified, it is recorded in BC and sent to DO. DO The information generates a re-encryption key and is sent to the data trading center for proxy re-encryption. After re-encryption is completed, the trading center sends the re-encrypted ciphertext to the DU, which decrypts and verifies it using the private key.
[0070] When generating a re-encryption key in step S5, DO generates a re-encryption key through the identity of DU, which is expressed as:
[0071] This step is run by DO. Enter DO's private key as well as , including the following steps: Random Selection ; calculate , ; Output re-encryption key ; DO Use the national secret SM2 digital signature algorithm to complete the digital signature and send it to the data transaction center.
[0072] When performing proxy re-encryption in step S5, the data transaction center completes the verification through the national secret SM2 signature verification algorithm. After the digital signature is verified, the ciphertext Perform proxy re-encryption, expressed as:
[0073] This step is run by the data trading center. Enter the ciphertext and the re-encryption key , and calculate:
[0074] Output re-encrypted ciphertext .
[0075] The data trading center will Send to DU.
[0076] In an optional embodiment of the present invention, obtaining a data transaction confirmation slip generated after the data user decrypts the re-encrypted ciphertext and verifies the data integrity, recording the data transaction confirmation slip on the blockchain and sending it to the data owner includes: Obtain the data transaction confirmation slip generated after the data user uses the private key to decrypt the re-encrypted ciphertext to obtain the plaintext of the transaction data and complete the data integrity verification, as well as the digital signature generated by signing the data transaction confirmation slip; After the digital signature of the data transaction confirmation form is verified, the data transaction confirmation form is recorded on the blockchain and sent to the data owner.
[0077] In this embodiment, the DU obtains the re-encrypted ciphertext, decrypts the re-encrypted ciphertext using the private key, and verifies the data integrity of the transaction data plaintext. After successful verification, the DU generates a transaction confirmation sheet and sends it to the data transaction center again, and records it on the blockchain.
[0078] When decrypting the ciphertext in step S6, the DU obtains the re-encrypted ciphertext sent by the data transaction center and decrypts it using the private key, which is expressed as:
[0079] This step is run by DU. Enter the re-encrypted ciphertext And the private key of DU , the output result is data plain text The restored plaintext is calculated using the following formula:
[0080] When step S6 performs data integrity verification, the plaintext After that, DU uses the transaction instructions Hash value right Verify the integrity of, calculate and judge:
[0081] If the formula is established, it means that the data has not been tampered with and the data integrity is verified. Otherwise, feedback is given to the data transaction center.
[0082] When generating a transaction confirmation sheet in step S6, DU generates a data transaction confirmation sheet after completing decryption and verification. Sent to the data transaction center, expressed as:
[0083] in The time when the confirmation form is generated. For transaction results.
[0084] DU Pair It is digitally signed using the national secret SM2 signature algorithm and sent to the data transaction center.
[0085] When recording the transaction results in step S6, DU After the digital signature is completed, it is sent to the data transaction center. After the data transaction center successfully verifies the signature using the national secret SM2 signature verification algorithm, the data transaction confirmation form is sent to the data owner and recorded on the BC. This completes the entire transaction process.
[0086] Reference Figure 2 , an embodiment of the present invention further provides a data transaction system integrating blockchain and proxy re-encryption, including: Data owners are used to submit registration information to the data transaction management platform and obtain the public-private key pair sent by the data transaction management platform through a secure channel; submit a data rights confirmation application form to the data transaction management platform and obtain a data rights confirmation certificate sent by the data transaction management platform; perform digital signature verification on the data rights confirmation certificate to generate a data transaction description and send it to the data transaction management platform; obtain a data transaction order sent by the data transaction management platform, generate a re-encryption key and send it to the data transaction management platform; The data transaction management platform is used to obtain the registration information submitted by the user, generate a public-private key pair, and send the public-private key pair to the corresponding user through a secure channel; the users include data owners and data users; obtain the data right confirmation application form submitted by the data owner, perform data right confirmation after digital signature verification on the data right confirmation application form, generate a data right confirmation certificate and send it to the data owner and record it on the blockchain; obtain the data transaction instructions and transaction data ciphertext sent by the data owner, record the data transaction instructions on the blockchain; obtain the data transaction order sent by the data user, perform digital signature verification on the data transaction order, record it on the blockchain and send it to the data owner; obtain the re-encryption key sent by the data owner, perform proxy re-encryption according to the re-encryption key, and send the re-encrypted ciphertext to the data user; obtain the data transaction confirmation form sent by the data user, record the data transaction confirmation form on the blockchain and send it to the data owner; Data users are used to submit registration information to the data transaction management platform and obtain the public-private key pair sent by the data transaction management platform through a secure channel; initiate data transaction applications and generate data transaction orders, and submit data transaction orders to the data transaction management platform; use the private key to decrypt the heavily encrypted ciphertext and perform data integrity verification on the plaintext of the transaction data, then generate a data transaction confirmation form and send the data transaction confirmation form to the data transaction management platform.
[0087] The present invention innovatively provides a data transaction method and system that integrates blockchain and proxy re-encryption. The method solves the following problems: 1. Secure data transaction: This invention introduces proxy re-encryption technology. The data owner publishes detailed information of the data for sale in the data transaction center, covering data type, data attribute, data size, data price, etc., without disclosing the plain text of the data. The data owner only needs to send the ciphertext and its corresponding re-encryption key to the data transaction center, thereby effectively ensuring the security and reliability of data transactions.
[0088] 2. Traceable data transactions: In the present invention, relevant information of the data transaction process is recorded in the distributed ledger of the blockchain. The characteristics of the blockchain can ensure that the entire transaction process is highly transparent, has good traceability and strong security. In this way, the traceability of the transaction can be fully demonstrated, providing strong support for the fairness of data transactions, and thus promoting the steady development of data transactions in a healthy and orderly direction.
[0089] 3. Complete data protection: During the data transmission process, the data source and integrity are guaranteed by adopting hash calculation and the national secret SM2 digital signature algorithm, which effectively prevents data loss and tampering, and ensures that the data always remains intact during the transaction.
[0090] Compared with the prior art, the data transaction method and system integrating blockchain and proxy re-encryption provided by the present invention has the following beneficial effects: 1. Enhanced data security: The proxy re-encryption technology is used to avoid the process of users uploading data in plain text to untrusted data trading platforms. This not only simplifies the encryption domain conversion process, making the entire transaction process more concise and efficient, but also effectively protects the data, enhancing its security and credibility.
[0091] 2. Enhance the transparency of data transactions: Using the distributed ledger of blockchain to record the complete transaction process ensures the transparency and traceability of transactions, reduces transaction risks, and also strengthens the supervision and auditing of data transactions to ensure the traceability of transactions.
[0092] 3. Ensure the legitimacy and reliability of data: By confirming the ownership of data and generating a data confirmation certificate, it not only clarifies the ownership of the data, but also helps to establish a trust mechanism for data transactions, effectively promoting the healthy and orderly development of the data transaction market.
[0093] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0094] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0095] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0096] The present invention uses specific embodiments to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
[0097] Those skilled in the art will appreciate that the embodiments described herein are intended to help readers understand the principles of the present invention, and should be understood that the protection scope of the present invention is not limited to such specific statements and embodiments. Those skilled in the art can make various other specific variations and combinations that do not deviate from the essence of the present invention based on the technical revelations disclosed by the present invention, and these variations and combinations are still within the protection scope of the present invention.
Claims
1. A data transaction method integrating blockchain and proxy re-encryption, characterized in that: The following steps are involved: Obtaining registration information submitted by the user, generating a public-private key pair, and sending the public-private key pair to the corresponding user through a secure channel; the user includes the data owner and the data user; Obtain the data confirmation application form submitted by the data owner, verify the digital signature of the data confirmation application form before confirming the data, generate a data confirmation certificate, send it to the data owner and record it on the blockchain; Obtain the data transaction instructions and transaction data ciphertext generated by the data owner after digitally signing and verifying the data ownership certificate, and record the data transaction instructions on the blockchain; Obtain the data transaction order generated by the data user's data transaction application, verify the digital signature of the data transaction order, record it on the blockchain and send it to the data owner; Obtain the re-encryption key generated by the data owner after receiving the data transaction order, perform proxy re-encryption based on the re-encryption key, and then send the re-encrypted ciphertext to the data user; Obtain the data transaction confirmation slip generated by the data user after decrypting the re-encrypted ciphertext and verifying the data integrity, record the data transaction confirmation slip on the blockchain and send it to the data owner.
2. A data transaction method integrating blockchain and proxy re-encryption according to claim 1, characterized in that: Generating a public-private key pair includes: Randomly select parameters ; According to the parameters Calculate the private key and the public key , expressed as: in, is the key parameter, The user's identity. , To expose parameter set parameters, is the base point on the elliptic curve.
3. According to claim 1, a data transaction method integrating blockchain and proxy re-encryption is characterized in that: Obtain the data confirmation application form submitted by the data owner, verify the digital signature of the data confirmation application form before confirming the data, generate a data confirmation certificate and send it to the data owner and record it on the blockchain, including: Obtain the data ownership confirmation application form submitted by the data owner and the digital signature generated by the private key on the data ownership confirmation application form; Verify the digital signature of the data rights confirmation application form, then confirm the data rights based on the data rights confirmation application form and generate a data rights confirmation certificate; Digitally sign the data ownership certificate, send the data ownership certificate and the corresponding digital signature to the data owner, and record the data ownership certificate on the blockchain.
4. According to claim 1, a data transaction method integrating blockchain and proxy re-encryption is characterized in that: Obtain the data transaction instructions and transaction data ciphertext generated by the data owner after digital signature verification of the data ownership certificate, and record the data transaction instructions on the blockchain, including: Obtain the data transaction instructions and transaction data ciphertext generated after the data owner verifies the digital signature of the data ownership certificate; Obtain the digital signature generated by the data owner on the data transaction instructions; After the digital signature of the data transaction specification is verified, the data transaction specification is recorded on the blockchain.
5. A data transaction method integrating blockchain and proxy re-encryption according to claim 1, characterized in that: Obtain the data transaction order generated by the data user's data transaction application, verify the digital signature of the data transaction order, record it on the blockchain and send it to the data owner, including: Obtain the data transaction order generated by the data user initiating the data transaction application, and the digital signature generated by signing the data transaction order; After the digital signature of the data transaction order is verified, the data transaction order is recorded on the blockchain and sent to the data owner.
6. A data transaction method integrating blockchain and proxy re-encryption according to claim 1, characterized in that: Obtain the re-encryption key generated by the data owner after receiving the data transaction order, perform proxy re-encryption based on the re-encryption key, and send the re-encrypted ciphertext to the data user, including: Obtain the re-encryption key generated by the data owner based on the data user's identity, as well as the digital signature generated for the re-encryption key; After the digital signature of the re-encryption key is verified, proxy re-encryption is performed on the transaction data ciphertext to generate the re-encrypted ciphertext and send it to the data user.
7. A data transaction method integrating blockchain and proxy re-encryption according to claim 1, characterized in that: Obtain the data transaction confirmation form generated by the data user after decrypting the re-encrypted ciphertext and verifying the data integrity, record the data transaction confirmation form on the blockchain and send it to the data owner, including: Obtain the data transaction confirmation slip generated after the data user uses the private key to decrypt the re-encrypted ciphertext to obtain the plaintext of the transaction data and complete the data integrity verification, as well as the digital signature generated by signing the data transaction confirmation slip; After the digital signature of the data transaction confirmation form is verified, the data transaction confirmation form is recorded on the blockchain and sent to the data owner.
8. A data transaction method integrating blockchain and proxy re-encryption according to claim 1, characterized in that: Before obtaining the registration information submitted by the data owner and data user, it also includes: Initialize the system and generate the required keys and parameters.
9. A data transaction method integrating blockchain and proxy re-encryption according to claim 1, characterized in that: Initialize the system and generate the required keys and parameters, including: Based on safety parameters generate ;in Cyclic group and message space The order of , hash map function , for identity space; make for Two different generators in, randomly selected , generate key parameters , public parameter set .
10. A data transaction system integrating blockchain and proxy re-encryption, characterized in that: include: Data owners use this to submit registration information to the data transaction management platform and obtain the public and private key pairs sent by the data transaction management platform through a secure channel; Submit a data rights confirmation application form to the data transaction management platform and obtain a data rights confirmation certificate from the data transaction management platform; perform digital signature verification on the data rights confirmation certificate to generate a data transaction description and send it to the data transaction management platform; obtain a data transaction order from the data transaction management platform, generate a re-encryption key and send it to the data transaction management platform; The data transaction management platform is used to obtain the registration information submitted by the user, generate a public-private key pair, and send the public-private key pair to the corresponding user through a secure channel; the users include data owners and data users; obtain the data right confirmation application form submitted by the data owner, perform data right confirmation after digital signature verification on the data right confirmation application form, generate a data right confirmation certificate and send it to the data owner and record it on the blockchain; obtain the data transaction instructions and transaction data ciphertext sent by the data owner, record the data transaction instructions on the blockchain; obtain the data transaction order sent by the data user, perform digital signature verification on the data transaction order, record it on the blockchain and send it to the data owner; obtain the re-encryption key sent by the data owner, perform proxy re-encryption according to the re-encryption key, and send the re-encrypted ciphertext to the data user; obtain the data transaction confirmation form sent by the data user, record the data transaction confirmation form on the blockchain and send it to the data owner; Data users, used to submit registration information to the data transaction management platform and obtain the public and private key pairs sent by the data transaction management platform through a secure channel; Initiate a data transaction application and generate a data transaction order, submit the data transaction order to the data transaction management platform; use the private key to decrypt the re-encrypted ciphertext and perform data integrity verification on the plaintext of the transaction data, then generate a data transaction confirmation form, and send the data transaction confirmation form to the data transaction management platform.
Citation Information
Patent Citations
Data transaction method and system, platform and storage medium
CN109754250A
Blockchain data transaction system and method based on proxy re-encryption and smart contract
CN110430186A
Improved block chain proxy re-encryption method and system based on lattice password
CN117118600A
Block chain-based security data market management system and method
CN117749349A
Blockchain-based supervision system and method, device, and medium
WO2024011812A1