Privacy enhanced access control method for industrial Internet of Things

By dynamically generating Paillier homomorphic encryption private keys in an industrial Internet of Things environment and combining blockchain smart contracts for access control, the problems of insufficient data privacy protection and insecure key management are solved, and efficient and secure data access management is achieved.

CN119995935APending Publication Date: 2025-05-13HARBIN INST OF TECH +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411991036.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

There are problems in the industrial Internet of Things environment with insufficient data privacy protection, insecure key management, and lack of transparency and traceability of access control.

Method used

The physical non-clone function (PUF) is used to dynamically generate and recover Paillier homomorphic encryption private keys, and distributed access control and auditing are combined with blockchain smart contracts to ensure secure storage and access management of data in an encrypted state.

Benefits of technology

It effectively improves the security and efficiency of the system, ensures the transparency and traceability of data privacy protection and access control, and solves the security and privacy protection problems in the prior art.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995935A_ABST
    Figure CN119995935A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy enhanced access control method for an industrial internet of things. The method comprises the following steps: step 1, generating and registering a key; step 2, data encryption and storage; step 3, access control and verification; and step 4, data calculation and decryption. According to the method, the security of a private key is protected through the uniqueness and non-replicability of a physical unclonable function (PUF), encryption state data operation is realized in combination with Paillier homomorphic encryption, and distributed access control and auditing are performed by using a block chain smart contract, so that security storage, access management and privacy protection of device data are realized, the security and efficiency of a system are effectively improved, and the security of the system is improved. The problems of security and privacy protection in the prior art are solved, and a more perfect security solution is provided for an industrial Internet of Things environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of industrial Internet of Things communication security, and relates to a data access control method, and specifically to a privacy protection and security access control method in an industrial Internet of Things environment. Background Art

[0002] With the rapid development of Industrial Internet of Things (IIoT) and intelligent manufacturing technology, industrial systems are gradually realizing equipment interconnection, data sharing and intelligent collaborative operation. Large-scale industrial sensors, actuators and industrial control equipment build a highly complex distributed industrial ecosystem through the network, forming an industrial Internet of Things environment with massive data interaction, dynamic topological structure changes and diverse node identities. However, this environment also faces many challenges in terms of security and privacy protection, mainly in terms of key management, data privacy protection, access control and efficiency.

[0003] At present, industrial equipment nodes such as programmable logic controllers, sensors, and gateways mainly rely on preset secret keys or software certificates for identity authentication and data encryption. However, secret key files are easy to leak and be physically stolen, and it is difficult to resist side channel attacks and hardware detection, resulting in threats to the security of equipment and data. At the same time, industrial data is highly sensitive. Although traditional symmetric or asymmetric encryption schemes have achieved data protection, they are difficult to support encrypted operations. The data after plaintext decryption is easy to be abused, and there are obvious shortcomings in privacy protection. In addition, the access rights of devices and users in the industrial Internet of Things vary greatly. A single centralized access control strategy is difficult to adapt to dynamic application scenarios and lacks transparency and global traceability. Although homomorphic encryption can support encrypted computing, its high computational complexity makes it difficult to apply efficiently on resource-constrained edge nodes. Existing solutions fail to effectively combine homomorphic encryption with blockchain storage, smart contract access control, and device-side private key management.

[0004] Therefore, there is an urgent need for an efficient, reliable and scalable solution that can achieve secure management and dynamic recovery of private keys, support access control and computing of data in an encrypted state, and combine blockchain to provide distributed storage and tamper-proof access auditing to meet the comprehensive needs of security, privacy and performance in the industrial Internet of Things environment. Summary of the invention

[0005] In view of the problems of insufficient data privacy protection, insecure key management, lack of transparency in access control, etc. in the industrial Internet of Things, the present invention provides a privacy-enhanced access control method for the industrial Internet of Things. The method protects the security of private keys through the uniqueness and non-replicability of the Physical Unclonable Function (PUF), combines Paillier homomorphic encryption to realize encrypted data operations, and uses blockchain smart contracts for distributed access control and auditing, so as to realize the secure storage, access management and privacy protection of device data, effectively improve the security and efficiency of the system, solve the security and privacy protection problems in the prior art, and provide a more complete security solution for the industrial Internet of Things environment.

[0006] The objective of the present invention is achieved through the following technical solutions:

[0007] A privacy-enhanced access control method for industrial Internet of Things, comprising the following steps:

[0008] Step 1: Key generation and registration

[0009] The device inputs the challenge value through the PUF module, calculates the unique response value, and generates a random seed based on the preset salt value. The public key and private key of the Paillier homomorphic encryption system are generated based on the random seed. The private key is securely stored in the PUF module. The device uses the generated public key and device identifier to apply for a digital certificate from a trusted authority (Certification Authority, CA), and then records the device's public key, identifier and digital certificate in the blockchain to complete the device registration and ensure the uniqueness and credibility of the device identity.

[0010] Step 2: Data encryption and storage:

[0011] After collecting data, the device uses its own Paillier public key to encrypt the data to generate ciphertext, and then uploads the encrypted ciphertext and related access control attributes to the blockchain through the edge server for storage. The distributed storage characteristics of the blockchain ensure the integrity and immutability of data records, preventing data from being maliciously tampered with or forged;

[0012] Step 3: Access control and verification:

[0013] The data accessor submits an access request to the blockchain smart contract. The request content includes the target data identifier, the accessor's identity attributes and the accessor's digital certificate. The smart contract first verifies the validity of the accessor's digital certificate, and then matches the identity and attributes according to the preset access control policy. After the verification is passed, the smart contract records the access request and decision results in the blockchain to ensure traceability and auditability in the future.

[0014] Step 4: Data calculation and decryption:

[0015] If the access request is allowed, in the scenario of data aggregation and statistical analysis requirements, the smart contract will retrieve the encrypted data ciphertext uploaded by multiple devices from the blockchain. Without decrypting the data, the system directly performs data aggregation calculations in the encryption domain through the characteristics of Paillier homomorphic encryption and generates encrypted result ciphertext. This process does not require the exposure of plaintext data, effectively protecting data privacy, while supporting collaborative computing of multi-device data; if the visitor obtains decryption permission, the device recovers the private key through the PUF module, thereby decrypting the encrypted calculation result and obtaining the final plaintext data; in the cross-subject data decryption scenario, the visitor uses the private key authorized by the CA for secure decryption to ensure the legitimacy and security of data access rights.

[0016] Compared with the prior art, the present invention has the following advantages:

[0017] (1) The present invention dynamically generates and restores the Paillier homomorphic encryption private key through PUF, without the need to store the private key for a long time, effectively improving the security and reliability of key management. The uniqueness and non-replicability of PUF ensure the security attributes of the private key. At the same time, combined with the device public key registration and authentication mechanism of the blockchain, it reduces the single point of failure and key leakage risks that may exist in traditional key management solutions.

[0018] (2) The present invention uses Paillier homomorphic encryption technology to achieve data aggregation and calculation in an encrypted state, avoiding exposure of plaintext data and ensuring data privacy security. In a multi-device collaborative computing scenario, the system can directly use ciphertext calculation results to meet the privacy protection requirements for sensitive data in the industrial Internet of Things and support efficient data analysis and aggregation operations.

[0019] (3) The present invention provides a flexible and fine-grained access control framework by integrating the attribute-based access control model with blockchain smart contract technology. The present invention automatically performs access rights verification and policy matching through smart contracts, making the access control process transparent and automated. At the same time, the access request and results are recorded in the blockchain to ensure that the data cannot be tampered with and is traceable, thereby improving the efficiency and security of distributed device management in the Industrial Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 Flowchart of the privacy-enhanced access control method for industrial Internet of Things.

[0021] Figure 2 The figure is a specific flow chart of the privacy-enhanced access control method for industrial Internet of Things.

[0022] Figure 3The timing diagram for key generation and registration.

[0023] Figure 4 This is a timing diagram for data encryption and storage.

[0024] Figure 5 This is a timing diagram for access control and authentication.

[0025] Figure 6 Timing diagram for data calculation and decryption. DETAILED DESCRIPTION

[0026] The technical solution of the present invention is further described below in conjunction with the accompanying drawings, but is not limited thereto. Any modification or equivalent replacement of the technical solution of the present invention without departing from the spirit and scope of the technical solution of the present invention should be included in the protection scope of the present invention.

[0027] The present invention provides a privacy-enhanced access control method for industrial Internet of Things. The method realizes data privacy protection and efficient access management through four steps of key generation and registration, data encryption and storage, access control and verification, and data calculation and decryption. In the key generation and registration step, the device uses a PUF module to generate a unique hardware response value and a random seed, dynamically generates a public and private key of the Paillier encryption system, and the public key and the device identifier are registered and stored in the blockchain. In the data encryption and storage step, the device encrypts the data by the public key, and stores the ciphertext and access attributes in the blockchain to ensure the integrity and non-tamperability of the data. In the access control and verification step, the smart contract verifies the identity and authority of the visitor, determines whether to authorize access through policy matching, and records the operation results. In the data calculation and decryption step, the Paillier homomorphic encryption technology is used to directly aggregate or calculate the ciphertext to ensure the security of data privacy throughout the life cycle. If the visitor has the decryption authority, the device recovers the private key through the PUF to decrypt and obtain the plaintext; in the cross-subject scenario, the visitor completes the decryption operation after authorization by the CA and the smart contract. The present invention improves the security, privacy and traceability of data access control and is suitable for scenarios with high requirements for data security and privacy in the industrial Internet of Things. Figure 1 and Figure 2 As shown, the specific steps include:

[0028] Step 1: Key generation and registration:

[0029] The device inputs the challenge value through the PUF module, calculates the unique response value, and generates a random seed based on the preset salt value. The public key and private key of the Paillier homomorphic encryption system are generated based on the random seed. The private key is securely stored in the PUF module, and there is no need to save the file for a long time, which improves the security of key management. Subsequently, the device uses the generated public key and device identifier to apply for a digital certificate from the CA, and then records the device's public key, identifier and digital certificate to the blockchain to complete the device registration and ensure the uniqueness and credibility of the device identity. The specific steps are as follows:

[0030] Step 1. Generate private key:

[0031] CA randomly selects several random numbers to form the challenge set C h , and the challenge set C h Sent to the device, the device will receive the challenge set C h Input the PUF module, which calculates the hardware response value R based on the input challenge value. Then, the device concatenates R with the preset salt value salt and calculates the random seed Seed through the hash function:

[0032] Seed=Hash(R||salt)

[0033] Based on the random seed Seed, the device generates two prime numbers p and q and calculates the following formula:

[0034] n=p·q

[0035] g=n+1

[0036] λ(n)=lcm(p-1,q-1)

[0037] The Paillier public key (n, g) and private key λ(n) are obtained through the above calculation. The device stores the private key λ(n) securely in the PUF module to ensure that it will not be leaked even if the device is powered off. When the device enters the same challenge set C again h , the same Seed can be generated through the same response R, thereby recovering the original identical Paillier private key λ(n).

[0038] Step 1 and 2: Public key registration:

[0039] The device uses the random seed Seed generated from the PUF response value and the salt value to derive a set of key pairs for digital signatures through a secure random number generation and key derivation process. The device uses the signature private key to digitally sign its own public key (n, g) and device identification ID, and submits the public key (n, g) and signature information to the CA. After the CA verifies the device identity and the validity of the signature, it issues a public key certificate, and then uploads the public key (n, g), device identification ID and the certificate issued by the CA to the blockchain, generates a registration transaction and records it on the chain.

[0040] Step 2: Data encryption and storage:

[0041] After collecting data, the device uses its own Paillier public key to encrypt the data to generate ciphertext, and then uploads the encrypted ciphertext and related access control attributes to the blockchain through the edge server for storage. The distributed storage characteristics of the blockchain ensure the integrity and immutability of data records, and prevent the data from being maliciously tampered or forged. The specific steps are as follows:

[0042] Step 21: Data encryption:

[0043] Before uploading the data to the chain, the device uses its own Paillier public key (n, g) to encrypt the collected data to ensure the privacy and security of the data. The specific calculation formula is as follows:

[0044] C D =Enc (n,g) (D) = g D ·r n modn 2

[0045] Among them, C D Indicates the encrypted ciphertext, Enc (n,g) is the Paillier encryption function, n and g are components of the public key, D is the plaintext data to be encrypted, and r is a random number used to ensure the randomness of the encryption result.

[0046] Step 22: Upload data:

[0047] The device will encrypt the ciphertext C D The data and related access control attributes are uploaded to the edge server, which then stores the relevant information on the blockchain to ensure the integrity and non-repudiation of the data.

[0048] Step 3: Access control and verification:

[0049] The data accessor submits an access request to the blockchain smart contract. The request content includes the target data identifier, the accessor's identity attributes, and the accessor's digital certificate. The smart contract first verifies the validity of the accessor's digital certificate, and then matches the identity and attributes according to the preset access control policy. After the verification is passed, the smart contract records the access request and decision results in the blockchain to ensure traceability and auditability in the future. The specific steps are as follows:

[0050] Step 31: Control strategy deployment:

[0051] The administrator configures access control rules in the smart contract and stores the policy on the chain. When an access request is initiated, the smart contract automatically matches the requester's permissions based on the policy.

[0052] Step 32: Access Request:

[0053] The visitor submits a data access request to the smart contract on the blockchain. The request content includes the target data identifier, the visitor's identity attributes, and the visitor's digital certificate.

[0054] Step 3: Attribute verification:

[0055] The smart contract verifies the validity of the visitor's digital certificate and identity attributes, retrieves relevant data resource attributes and access control policies from the blockchain, and if the access control policy matches successfully, the smart contract records the access operation results and returns the corresponding access rights or data reference information to the visitor; if the match fails, the access request is rejected, and finally the results of the access decision are recorded in the blockchain for subsequent auditing and tracing.

[0056] Step 4: Data calculation and decryption:

[0057] If the access request is allowed, in the scenario of data aggregation and statistical analysis, the smart contract will retrieve the encrypted data ciphertext uploaded by multiple devices from the blockchain. Without decrypting the data, the system directly performs data aggregation calculations in the encryption domain through the characteristics of Paillier homomorphic encryption and generates encrypted result ciphertext. This process does not need to expose plaintext data, effectively protects data privacy, and supports collaborative calculation of multi-device data. If the visitor obtains decryption permission, the device recovers the private key through the PUF module, thereby decrypting the encrypted calculation result and obtaining the final plaintext data. In the cross-subject data decryption scenario, the visitor uses the private key authorized by the CA for secure decryption to ensure the legitimacy and security of data access rights. The specific steps are as follows:

[0058] Step 41: Encrypted data calculation:

[0059] If the visitor needs to perform encrypted calculations on the data, the visitor can retrieve the encrypted data of multiple devices from the blockchain through smart contracts.D1 ,C D2 ,...,C Dk , and then perform homomorphic operations in the ciphertext domain to achieve the summation of encrypted data without decryption. The specific formula is as follows:

[0060]

[0061] Among them, C sum Represents the homomorphic computation result of encrypted data on multiple devices, C Di is the encrypted data ciphertext generated by device i, D i is the plaintext data of device i, and k represents the total number of devices participating in the homomorphic summation calculation.

[0062] Step 42: Decryption permission check:

[0063] If the visitor needs the plaintext calculation result, the smart contract first verifies the visitor's legal decryption authority to the target data. If the access control policy determines that the visitor has access to the corresponding private key, the decryption operation is allowed.

[0064] Step 43: Private key recovery and decryption:

[0065] When the subject who needs to decrypt is the original owner of the data and the device is still running locally, the device can call the PUF module to recover the private key λ(n) and decrypt the encrypted ciphertext C sum To decrypt:

[0066]

[0067] Among them, m represents the plaintext data obtained by decryption, λ(n) is the decrypted private key, and L(·) is the auxiliary function used in the decryption process.

[0068] Step 44: Cross-subject decryption:

[0069] If the access control policy allows other devices or users to perform decryption operations, the visitor must obtain authorization to use a valid key through the CA and the smart contract module. After obtaining authorization, the private key can be used to decrypt the ciphertext.

[0070] Example:

[0071] In order to better illustrate the implementation process of the present invention, the following numerical example is given through the privacy-enhanced access control of a smart sensor device in an industrial Internet of Things environment. The specific implementation steps are as follows:

[0072] Step 1: Key generation and registration:

[0073] During the system initialization phase, the smart sensor device uses the built-in PUF module to input the challenge value Ch ={1101,0110,1010}, and calculates a unique response value R ={3211,2420,3101}. The device generates a random seed in combination with the randomly generated salt value salt = 87456. The device uses the random seed to generate the public key {n,g} = {1022117,1022118} and the private key λ(n) = 255024 of the Paillier encryption system, where the private key λ(n) is securely stored in the PUF module to avoid leakage. Subsequently, the device uses the public key and identifier ID = SENSOR_XYZ to generate a digital signature and applies for a digital certificate from the CA. After the CA verifies the identity of the device, it records the device's public key, identifier, and digital certificate in the blockchain to ensure the uniqueness and credibility of the data.

[0074] Step 2: Data encryption and storage:

[0075] During the data collection process, the intelligent sensor device measures the humidity data of the current environment D = 62%. The device uses the generated Paillier public key to encrypt the data, the random number r = 83811, and generates the ciphertext C D =499088308559. The encrypted data ciphertext, access control attribute information and device signature are uploaded to the blockchain through the edge server. The blockchain records the relevant data to ensure the data is tamper-proof and transparent.

[0076] Step 3: Access control and verification:

[0077] An industrial manager (data accessor) submits an access request to the blockchain smart contract through a user terminal, including the target data identifier DATA ID =HUMIDITY 001 , identity attributes and digital signatures. After the smart contract verifies the validity of the manager’s digital certificate, it matches permissions according to the access control policy. After a successful match, the smart contract records the access result and grants permissions to the manager, allowing him to obtain the relevant data ciphertext.

[0078] Step 4: Data calculation and decryption:

[0079] Assume that multiple sensor devices upload humidity data at the same time, which are:

[0080] Sensor device 1: D1 = 62%

[0081] Sensor device 2: D2 = 70%

[0082] Sensor device 3: D3 = 68%

[0083] The encrypted ciphertext generated by each device is:

[0084] CD1 =499088308559

[0085] C D2 =577459601494

[0086] C D3 =657608064716

[0087] The smart contract performs the aggregate sum operation in an encrypted state and calculates the encrypted sum ciphertext C SUM =111339983347.

[0088] If the access personnel requests to view the aggregated data plaintext results, after the smart contract authority verification, the device recovers the private key λ(n) through the PUF module and performs the aggregation ciphertext C SUM Decryption is performed to obtain the plaintext result SUM=200 of the aggregated humidity data.

Claims

1. A privacy-enhanced access control method for industrial Internet of Things, characterized in that The method comprises the following steps: Step 1: Key generation and registration The device inputs the challenge value through the PUF module, calculates the unique response value, and generates a random seed based on the preset salt value. The public key and private key of the Paillier homomorphic encryption system are generated based on the random seed. The private key is securely stored in the PUF module. The device uses the generated public key and device identifier to apply for a digital certificate from the CA, and then records the device's public key, identifier and digital certificate into the blockchain to complete the device registration and ensure the uniqueness and credibility of the device identity. Step 2: Data encryption and storage: After collecting data, the device uses its own Paillier public key to encrypt the data to generate ciphertext, and then uploads the encrypted ciphertext and related access control attributes to the blockchain through the edge server for storage. The distributed storage characteristics of the blockchain ensure the integrity and immutability of data records, preventing data from being maliciously tampered with or forged; Step 3: Access control and verification: The data accessor submits an access request to the blockchain smart contract. The request content includes the target data identifier, the accessor's identity attributes and the accessor's digital certificate. The smart contract first verifies the validity of the accessor's digital certificate, and then matches the identity and attributes according to the preset access control policy. After the verification is passed, the smart contract records the access request and decision results in the blockchain to ensure traceability and auditability in the future. Step 4: Data calculation and decryption: If the access request is allowed, in the scenario of data aggregation and statistical analysis, the smart contract will retrieve the encrypted data ciphertext uploaded by multiple devices from the blockchain. Without decrypting the data, the system directly performs data aggregation calculations in the encryption domain through the characteristics of Paillier homomorphic encryption and generates encrypted result ciphertext. This process does not need to expose plaintext data, effectively protects data privacy, and supports collaborative calculation of multi-device data. If the visitor obtains decryption permission, the device recovers the private key through the PUF module, thereby decrypting the encrypted calculation results and obtaining the final plaintext data. In the cross-subject data decryption scenario, the visitor performs secure decryption through the private key authorized by the CA to ensure the legitimacy and security of data access rights.

2. The privacy-enhanced access control method for industrial Internet of Things according to claim 1 is characterized in that The specific steps of step one are as follows: Step 1. Generate private key: CA randomly selects several random numbers to form the challenge set C h , and the challenge set C h Sent to the device, the device will receive the challenge set C h Input the PUF module, and the PUF module calculates the hardware response value R according to the input challenge value. Then, the device concatenates R with the preset salt value salt, and calculates the random seed Seed through the hash function. Based on the random seed Seed, the device generates two prime numbers p and q, and calculates the following formula: n=p·q g=n+1 λ(n)=lcm(p-1,q-1) The Paillier public key (n, g) and private key λ(n) are obtained through the above calculation. The device stores the private key λ(n) securely in the PUF module to ensure that it will not be leaked even if the device is powered off. When the device enters the same challenge set C again h , generate a consistent Seed through the same response R, thereby recovering the original identical Paillier private key λ(n); Step 1 and 2: Public key registration: The device uses the random seed Seed generated from the PUF response value and the salt value to derive a set of key pairs for digital signatures through a secure random number generation and key derivation process. The device uses the signature private key to digitally sign its own public key (n, g) and device identification ID, and submits the public key (n, g) and signature information to the CA. After the CA verifies the device identity and the validity of the signature, it issues a public key certificate, and then uploads the public key (n, g), device identification ID and the certificate issued by the CA to the blockchain, generates a registration transaction and records it on the chain.

3. The privacy-enhanced access control method for industrial Internet of Things according to claim 2 is characterized in that In the step 1, the calculation formula of the random seed Seed is as follows: Seed = Hash(R||salt).

4. The privacy-enhanced access control method for industrial Internet of Things according to claim 1 is characterized in that The specific steps of step 2 are as follows: Step 21: Data encryption: Before uploading the data to the chain, the device uses its own Paillier public key (n, g) to encrypt the collected data to ensure the privacy and security of the data; Step 22: Upload data: The device will encrypt the ciphertext C D The data and related access control attributes are uploaded to the edge server, which then stores the relevant information on the blockchain to ensure the integrity and non-repudiation of the data.

5. The privacy-enhanced access control method for industrial Internet of Things according to claim 4 is characterized in that In step 21, the specific calculation formula for data encryption is as follows: C D =Enc (n,g) (D)=g D ·r n modern 2 Among them, C D Indicates the encrypted ciphertext, Enc (n,g) is the Paillier encryption function, n and g are components of the public key, D is the plaintext data to be encrypted, and r is a random number used to ensure the randomness of the encryption result.

6. The privacy-enhanced access control method for industrial Internet of Things according to claim 1 is characterized in that The specific steps of step three are as follows: Step 31: Control strategy deployment: The administrator configures access control rules in the smart contract and stores the policy on the chain. When an access request is initiated, the smart contract automatically matches the requester's permissions according to the policy. Step 32: Access Request: Visitors submit data access requests to smart contracts on the blockchain; Step 3: Attribute verification: The smart contract verifies the validity of the visitor's digital certificate and identity attributes, retrieves relevant data resource attributes and access control policies from the blockchain, and if the access control policy matches successfully, the smart contract records the access operation results and returns the corresponding access rights or data reference information to the visitor; if the match fails, the access request is rejected, and finally the results of the access decision are recorded in the blockchain for subsequent auditing and tracing.

7. The privacy-enhanced access control method for industrial Internet of Things according to claim 1 is characterized in that The specific steps of step 4 are as follows: Step 41: Encrypted data calculation: If the visitor needs to perform encrypted calculations on the data, the visitor retrieves the encrypted data of multiple devices from the blockchain through the smart contract C D1 ,C D2 ,...,C Dk , and then perform homomorphic operations in the ciphertext domain to achieve the summation of encrypted data without decryption; Step 42: Decryption permission check: If the visitor needs the plaintext calculation result, the smart contract first verifies the visitor's legal decryption authority to the target data. If the access control policy determines that the visitor has the corresponding private key access right, the decryption operation is allowed; Step 43: Private key recovery and decryption: When the subject who needs to decrypt is the original owner of the data and the device is still running locally, the device calls the PUF module to recover the private key λ(n) and decrypts the encrypted ciphertext C sum Decryption is performed; Step 44: Cross-subject decryption: If the access control policy allows other devices or users to perform decryption operations, the visitor must obtain authorization to use a valid key through the CA and smart contract module. After obtaining authorization, the visitor uses the private key to decrypt the ciphertext.

8. The privacy-enhanced access control method for industrial Internet of Things according to claim 7 is characterized in that In step 41, the specific formula for calculating the encrypted data is as follows: Among them, C sum Represents the homomorphic computation result of encrypted data on multiple devices, C Di is the encrypted data ciphertext generated by device i, D i is the plaintext data of device i, and k represents the total number of devices participating in the homomorphic summation calculation.

9. The privacy-enhanced access control method for industrial Internet of Things according to claim 8 is characterized in that In step 43, the decryption formula is as follows: Among them, m represents the plaintext data obtained by decryption, λ(n) is the decrypted private key, and L(·) is the auxiliary function used in the decryption process.

Citation Information

Cited By

  • Certificate authorization access control system and method based on face encryption features, and camera holder

    CN120547003A