Cloud chain collaborative data secure transmission method and device with verifiable timeliness
By generating multiple pseudo-identities for users and embedding Bloom filters, the problem of timeliness management and tracking in cloud chain data transmission is solved, and data security and timeliness are guaranteed in the case of user private key leakage.
Patent Information
- Application Number
- CN202510443508.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-10
AI Technical Summary
The prior art is difficult to effectively solve the problem of timeliness management and tracking in cloud chain data transmission, especially in the case of user private key leakage, and data security and timeliness cannot be guaranteed.
By generating multiple pseudo-identities for each user and embedding the Bloom filter into the private key of each pseudo-identity, each signed-in file generated, the private key is updated based on the Bloom filter to ensure the security of the private data.
It can still ensure the security and timeliness of data when the user's private key is leaked, prevent malicious users from signing the same message again with private keys, and ensure the confidentiality, integrity and non-forgery of data.
Smart Images

Figure CN119996073A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain, and in particular to a method and device for secure transmission of cloud-chain collaborative data with verifiable timeliness. Background Art
[0002] With the continuous advancement of new generation information technology, the data transmitted by wireless networks covers a lot of private information such as personal identity information, health records, device usage, etc. Once these sensitive data are accessed or leaked without authorization, it will not only expose personal privacy, but also cause property losses and even endanger people's lives. The security issues in data transmission are becoming more and more prominent.
[0003] Signcryption technology can implement digital signature and public key encryption in the same logical step. Compared with the "sign first, then encrypt" method, it is more efficient and more suitable for resource-constrained environments. It has become an important means to ensure secure data transmission.
[0004] However, in recent years, side channel and other attack methods have emerged. If the user's private key is leaked, malicious users can use it to generate legal signatures for any message, which will cause serious data security problems. For this reason, some solutions have introduced blockchain to deal with these situations. Blockchain, as a decentralized public distributed ledger, is tamper-proof. For example, China Invention Patent 202110192016.7 records the public key and the signed data on the blockchain. However, due to the transparency of the blockchain, it is difficult for the data owner to control which users can obtain the public key and decrypt the data, which can easily cause privacy data leakage; China Invention Patent 201910591183.1 proposes a blockchain signcryption method with access control, which formulates access policies based on user attributes to achieve access control purposes, but the scheme cannot trace the historical signcryption results, which is not conducive to the timeliness management and tracking of the signed files, and there is no way to supervise and trace malicious users. In addition, ensuring that the terminal device is within the time limit is also a key guarantee for secure data transmission. Verifying the timeliness of the signed files can prevent expired users from maliciously transmitting messages.
[0005] To solve the problem of limited local storage space, many users store data in the cloud, which allows users to access data on different devices and locations, improving data transmission efficiency. However, this also brings about trust issues with cloud servers, which may access user privacy data without authorization, and also create opportunities for malicious attackers. Although blockchain technology can achieve reliable data sharing, it is limited by the number of transactions per second (TPS), making it difficult to store complete data on the chain. Summary of the invention
[0006] The embodiments of the present application provide a time-verifiable cloud chain collaborative data security transmission method and device, which generates multiple pseudo-identities for each user and embeds a Bloom filter into the private key of each pseudo-identity. Each time a signed file is generated, the private key is updated based on the Bloom filter to ensure the security of the privacy data.
[0007] In a first aspect, an embodiment of the present application provides a method for secure transmission of cloud chain collaborative data with verifiable timeliness, the method comprising: Generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; Generate a public key and a private key pair for each pseudo-identity of each user based on the master key, construct a Bloom filter for each user, embed the Bloom filter into the private key of each pseudo-identity of the corresponding user, and store the public key of each pseudo-identity on the chain; A sender user and a receiver user are defined in the blockchain. The transmission data is signed with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and then uploaded to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the status of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
[0008] In a second aspect, the embodiment of the present application provides a cloud chain collaborative data security transmission device with verifiable timeliness, including: A generation module, used to generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; A construction module generates a public key and a private key for each pseudo-identity of each user based on the master key to form a public-private key pair, constructs a Bloom filter for each user, embeds the Bloom filter into the private key of each pseudo-identity of the corresponding user, and stores the public key of each pseudo-identity on the chain; The transmission module is used to define a sender user and a receiver user in the blockchain, and to sign the transmission data with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user, and then upload it to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the state of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
[0009] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute a time-verifiable cloud chain collaborative data security transmission method.
[0010] In a fourth aspect, an embodiment of the present application provides a readable storage medium, in which a computer program is stored. The computer program includes a program code for controlling a process to execute a process, and the process includes a time-verifiable cloud chain collaborative data security transmission method.
[0011] The main contributions and innovations of the present invention are as follows: The embodiment of the present application embeds the Bloom filter into the private key of the user's pseudo identity. After the user signs a specific message, the Bloom filter is used to update the user's private key, thereby preventing malicious users from using the private key to sign the same message again, ensuring the confidentiality, integrity and unforgeability of private data, and ensuring the security of data in the event of private key leakage; the embodiment of the present application generates multiple meta-associated pseudo identities for each user, and uses the user's anonymous information to generate a public-private key pair, thereby effectively binding the user's anonymous identity information with the signed message. At the same time, an on-chain storage method based on a dynamic accumulator is adopted, and only the accumulated value of each group is saved on the chain, which solves the problem of large communication and on-chain storage overhead caused by uploading all the public key information of all anonymous identities to the blockchain, and realizes on-chain evidence storage to achieve data traceability; the embodiment of the present application adopts a cloud-chain collaborative architecture, stores the signed files and some decryption parameters on the cloud server, and stores the signed files in the form of a summary on the blockchain. Users can quickly compare the consistency of the data on the chain and off the chain through smart contracts, and verify whether it is within the time limit through the cloud server to achieve the time verifiability of the data.
[0012] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings: Figure 1 It is a logic flow chart of a time-validated cloud chain collaborative data security transmission method according to an embodiment of the present application; Figure 2 It is a structural block diagram of a cloud chain collaborative data security transmission device with verifiable timeliness according to an embodiment of the present application; Figure 3It is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0014] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with one or more embodiments of this specification. Instead, they are merely examples of devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.
[0015] It should be noted that: in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may be combined into a single step for description in other embodiments.
[0016] Embodiment 1 The embodiment of the present application provides a time-validated cloud chain collaborative data security transmission method, by generating multiple pseudo identities for each user, and embedding a Bloom filter into the private key of each pseudo identity, and each time a signcryption file is generated, the private key is updated based on the Bloom filter to ensure the security of the private data. Specifically, refer to Figure 1 , the method comprising: Generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; Generate a public key and a private key pair for each pseudo-identity of each user based on the master key, construct a Bloom filter for each user, embed the Bloom filter into the private key of each pseudo-identity of the corresponding user, and store the public key of each pseudo-identity on the chain; A sender user and a receiver user are defined in the blockchain. The transmission data is signed with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and then uploaded to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the status of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
[0017] In some embodiments, users are divided into multiple groups based on the entity attributes of each user on the blockchain, where the entity attributes include computing power, functions undertaken, and physical location. Users with the same entity attributes are regarded as users in the same group. When the public key of each pseudo-identity is stored on the chain, a dynamic accumulator is used to accumulate the public keys of all pseudo-identities of users in the same group and upload them to the blockchain for storage.
[0018] Specifically, computing power refers to the user's computing and processing capabilities. In the blockchain network, different computing and processing capabilities will affect the efficiency of its contribution to the network and its performance in some scenarios that require territory competition. Function refers to the function that the user is specifically responsible for or can perform in the blockchain system. For example, some users may act as full nodes, which must completely save all the ledger data of the blockchain, verify transactions, broadcast information, etc., and undertake important functions such as maintaining the stable operation of the entire blockchain network and ensuring data consistency. Some users may only be light nodes, which only need to save some key data and are mainly used for simple functions such as querying transactions. They do not need to handle a lot of complex maintenance work like full nodes. Different functions reflect the different roles played by users in the blockchain system architecture and the corresponding roles they play. The physical location refers to the actual geographical location of the user, which can be the city where a data center is located, a specific office address, etc.
[0019] That is to say, the same entity attributes in this solution refer to the computing power being in the same range, having the same functions and being in the same physical location.
[0020] For example, the groups can be divided into , where C c Indicates the computing power range; according to the functions undertaken, it can be divided into , where F f Indicates different functions; grouped according to physical location , where L l Represents different physical locations. If there is a grouping of user i, it is expressed as , it means that the user is divided into computing power group 1, responsible for function groups 3 and 4, and physical location group 2. That is to say, the user's computing power is within the C1 range, the functions he is responsible for are F3 and F4, and the physical location information is L2.
[0021] Specifically, a dynamic accumulator is used to accumulate the public keys of all pseudo-identities of users in the same group and upload them to the blockchain for storage. Compared with conventional storage of public keys one by one, the dynamic accumulator can integrate the public keys of multiple pseudo-identities and aggregate them into a relatively compact representation and store them on the blockchain, which greatly reduces the space occupied by storing these public keys on the chain. Especially in the complex situation where a large number of users have multiple pseudo-identities and correspond to numerous public keys, it can effectively avoid the storage resource shortage caused by too much public key data storage, and optimize the storage resource utilization efficiency of the entire blockchain.
[0022] Furthermore, since a user may undertake multiple functions, when grouping users, they will be grouped according to each function they undertake, and only users who undertake exactly the same functions will be grouped into one group.
[0023] Furthermore, the user customizes the validity period, establishes a user information tag for each user based on the user group, user pseudo-identity information, the public key corresponding to the pseudo-identity information, and the validity period of each user, and stores the user information tag of each user on the blockchain, and the blockchain does not respond to any queries about users whose validity period has expired.
[0024] Specifically, the generated user information tag is represented as , where PID represents the user's pseudo identity information, and pk represents the public key corresponding to the pseudo identity information. is the validity period, and Block is the user group.
[0025] Specifically, the user's validity period is customized by the user himself, that is, after joining the blockchain, the user will define a validity period, such as 2025 / 3 / 10. The user can only accept transactions during the validity period. After the validity period expires, the blockchain will not respond to any queries about the user. In other words, after the validity period expires, the transaction information and transfer files of the expired user cannot be queried in the blockchain, and the public key of the expired user cannot be obtained, which is equivalent to "deleting" the user in the blockchain.
[0026] Specifically, blockchain manages each user's user information tag through smart contracts.
[0027] In some embodiments, the key generation center KGC selects two groups G and GT of prime order p, and satisfies the operation: e: G×G→GT, g is the generator of G, and given the pseudo identity of user A Predefined collection of and the set of all possible signcryption results , given 3 Hash functions: , , , select a random group element , generate 2 random vectors and , randomly selected , generating parameters , and let msk= as the master key.
[0028] Specifically, the key generation center is responsible for generating the master key and distributing the public and private key pairs through the master key to complete transaction authentication in the blockchain.
[0029] In some specific embodiments, the data sender generates a user information tag access tree and constructs a Bloom filter based on the user information tags of potential receivers that meet the data decryption requirements. , and embed the Bloom filter into the private key of each pseudo-identity of all users. The formula is expressed as:
[0030] is the user's private key, is a Bloom filter, Depend on , as well as constitute.
[0031] In the process of generating the user's private key, the user's pseudo-identity Mapped to a predefined set of pseudo-identities , then initialize the Bloom filter and select the randomizer , for any integer Calculate the user's partial private key as follows:
[0032]
[0033]
[0034] in, , is a non-zero multiplication group composed of a key generation center based on a large prime number p, x A is the secret parameter of user A, used to generate user A's own private key, UA is the random vector generated by the key generation center, ui is the parameter related to element i in UA, is the exponential parameter of ui, and is a random number generated randomly based on the generator g.
[0035] In some embodiments, during the process of signencrypting the transmission data with the private key of any pseudo identity of the sender user and the public key of any pseudo identity of the receiver user, if it is found in the Bloom filter that the transmission data has been signencrypted, the signencryption is terminated.
[0036] Furthermore, since the Bloom filter is embedded in the user's private key in this scheme, during the sign-encryption process, the transmission data is added to the Bloom filter and the status of the Bloom filter is updated in order to determine whether the transmission data has been sign-encrypted. If it is determined according to the Bloom filter that the transmission data has not been sign-encrypted, it is sign-encrypted. If the transmission data exists in the Bloom filter, it means that the transmission data has been sign-encrypted, and the sign-encryption is terminated.
[0037] Specifically, since the Bloom filter is embedded in the private key of each pseudo-identity of the corresponding user, when the state of the Bloom filter is updated, the private key of the pseudo-identity is also updated accordingly. Since the update of the pseudo-identity is reflected in the Bloom filter, it will not affect the decryption of the receiving user.
[0038] Specifically, a Bloom filter is a probabilistic data structure that can efficiently determine whether an element is in a set. When adding a message, a hash function is used to map the message to the bit array, changing the corresponding bit state, that is, updating the state of the Bloom filter.
[0039] For example, according to the private key of the sender user and transfer data ,make , then add M to the set of Bloom filters, update its state, and output the updated private key .
[0040] Furthermore, when the transmission file needs to be re-signed, the single element in the Bloom filter is deleted and then the sign-encryption is performed.
[0041] In some embodiments, after the transmission data is signed and uploaded to the cloud server using the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the recipient user, the decryption parameters and the signed file certificate are stored on the blockchain.
[0042] Specifically, the decryption parameters are key information to restore the ciphertext to the original data. Usually, only with the correct decryption parameters can the ciphertext be decrypted to obtain the original data. This solution stores some decryption parameters on the blockchain because the blockchain has the characteristics of being tamper-proof and traceable, which can ensure the security and integrity of these decryption parameters. Decryption through the decryption parameters stored on the blockchain can prevent the decryption parameters from being tampered with or lost at will.
[0043] Specifically, the signed document certificate contains some key information that can prove the legitimacy and authenticity of the signed document, such as digital signature information. Storing the signed document certificate on the blockchain also utilizes the characteristics of the blockchain, so that at any time, you can query the blockchain to verify whether the signed document is indeed issued by the claimed subject and whether it has been tampered with during the transmission process, thereby enhancing the security and credibility of the entire file processing process.
[0044] In some embodiments, in the signcryption step, the public key of any pseudo-identity of the recipient user is used Send a message to the recipient user , then do the following: calculate ,calculate ,calculate ,calculate ,calculate ,calculate , integration , , , , , Get the complete signcryption .
[0045] In some embodiments, in the step of decrypting the transmission data using the private key of the pseudo-identity corresponding to itself and the public key of the pseudo-identity corresponding to the sender, the blockchain transmits the decryption parameters to the cloud server, the cloud server partially decrypts the transmission data based on the decryption parameters, and then sends the partially decrypted transmission data to the receiving user. The receiving user completely decrypts the partially decrypted transmission data with the private key of the pseudo-identity corresponding to itself to obtain the original transmission data, and verifies the validity of the signcryption of the transmission data using the public key of the pseudo-identity corresponding to the sender.
[0046] Specifically, the formula for completely decrypting the partially decrypted transmission data using the private key corresponding to the pseudo-identity to obtain the original transmission data is as follows:
[0047] Among them, M is the original transmission data, , , is the signcrypted information, and sk is the private key corresponding to the pseudo identity.
[0048] Specifically, the formula for verifying the validity of the signcryption of the transmitted data using the public key of the sender's corresponding pseudo-identity is as follows:
[0049] in, , , is the signcryption information, pk is the public key of the sender corresponding to the pseudo identity. If the above formula is established, it means that the signcryption is valid, otherwise the signcryption is invalid.
[0050] Embodiment 2 Based on the same idea, refer to Figure 2 , the present application also proposes a cloud chain collaborative data security transmission device with verifiable timeliness, including: A generation module, used to generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; A construction module generates a public key and a private key for each pseudo-identity of each user based on the master key to form a public-private key pair, constructs a Bloom filter for each user, embeds the Bloom filter into the private key of each pseudo-identity of the corresponding user, and stores the public key of each pseudo-identity on the chain; The transmission module is used to define a sender user and a receiver user in the blockchain, and to sign the transmission data with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user, and then upload it to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the state of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
[0051] Embodiment 3 This embodiment also provides an electronic device, referring to Figure 3 , comprises a memory 404 and a processor 402, wherein the memory 404 stores a computer program, and the processor 402 is configured to run the computer program to execute the steps in any of the above method embodiments.
[0052] Specifically, the processor 402 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0053] Among them, the memory 404 may include a large capacity memory 404 for data or instructions. For example, but not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disk, a magneto-optical disk, a tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In appropriate cases, the memory 404 may include a removable or non-removable (or fixed) medium. In appropriate cases, the memory 404 may be inside or outside the data processing device. In a specific embodiment, the memory 404 is a non-volatile memory. In a specific embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (Programmable Read-Only Memory, PROM for short), an erasable PROM (Erasable Programmable Read-Only Memory, EPROM for short), an electrically erasable PROM (Electrically Erasable Programmable Read-Only Memory, EEPROM for short), an electrically alterable ROM (Electrically Alterable Read-Only Memory, EAROM for short) or a flash memory (FLASH) or a combination of two or more of these. In appropriate circumstances, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), wherein the DRAM may be a fast page mode dynamic random access memory 404 (FPMDRAM), an extended data output dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0054] The memory 404 may be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402 .
[0055] The processor 402 reads and executes the computer program instructions stored in the memory 404 to implement any one of the time-verifiable cloud chain collaborative data security transmission methods in the above embodiments.
[0056] Optionally, the electronic device may further include a transmission device 406 and an input / output device 408 , wherein the transmission device 406 is connected to the processor 402 , and the input / output device 408 is connected to the processor 402 .
[0057] The transmission device 406 can be used to receive or send data via a network. Specific examples of the above-mentioned network may include a wired or wireless network provided by a communication provider of the electronic device. In one example, the transmission device includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 406 can be a radio frequency (Radio Frequency, referred to as RF) module, which is used to communicate with the Internet wirelessly.
[0058] The input / output device 408 is used to input or output information. In this embodiment, the input information may be a pseudo identity, a public / private key pair of each pseudo identity, etc., and the output information may be a decryption result of the transmitted data, etc.
[0059] Optionally, in this embodiment, the processor 402 may be configured to perform the following steps through a computer program: Generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; Generate a public key and a private key pair for each pseudo-identity of each user based on the master key, construct a Bloom filter for each user, embed the Bloom filter into the private key of each pseudo-identity of the corresponding user, and store the public key of each pseudo-identity on the chain; A sender user and a receiver user are defined in the blockchain. The transmission data is signed with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and then uploaded to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the status of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
[0060] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation modes, and this embodiment will not be described in detail here.
[0061] In general, various embodiments may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects of the invention may be implemented in hardware, while other aspects may be implemented in firmware or software executed by a controller, microprocessor, or other computing device, but the invention is not limited thereto. Although various aspects of the invention may be shown and described as block diagrams, flow charts, or using some other graphical representation, it should be understood that, as non-limiting examples, the boxes, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.
[0062] Embodiments of the present invention can be implemented by computer software, which is executable by a data processor of a mobile device, such as in a processor entity, or implemented by hardware, or implemented by a combination of software and hardware. Computer software or programs (also referred to as program products) including software routines, applets and / or macros can be stored in any device readable data storage medium, and they include program instructions for performing specific tasks. A computer program product may include one or more computer executable components configured to perform an embodiment when the program is running. One or more computer executable components may be at least one software code or a part thereof. Software may be stored in physical media such as memory chips or storage blocks implemented in a processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and data variants thereof, CDs. Physical media are non-transient media.
[0063] Those skilled in the art should understand that the technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0064] The above embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A cloud chain collaborative data security transmission method with verifiable timeliness, characterized in that: The following steps are involved: Generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; Generate a public key and a private key pair for each pseudo-identity of each user based on the master key, construct a Bloom filter for each user, embed the Bloom filter into the private key of each pseudo-identity of the corresponding user, and store the public key of each pseudo-identity on the chain; A sender user and a receiver user are defined in the blockchain. The transmission data is signed with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and then uploaded to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the status of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
2. According to claim 1, a method for secure transmission of cloud chain collaborative data with verifiable timeliness, characterized in that: Based on the entity attributes of each user on the blockchain, users are divided into multiple groups. The entity attributes include computing power, functions undertaken, and physical locations. Users with the same entity attributes are regarded as users in the same group. When the public key of each pseudo-identity is stored on the chain, a dynamic accumulator is used to accumulate the public keys of all pseudo-identities of users in the same group and upload them to the blockchain for storage.
3. According to claim 2, a method for secure transmission of cloud chain collaborative data with verifiable timeliness is characterized in that: The user defines the validity period, establishes a user information tag for each user based on each user's user group, user pseudo-identity information, the public key corresponding to the pseudo-identity information, and the validity period, and stores each user's user information tag on the blockchain. The blockchain does not respond to any queries about users whose validity period has expired.
4. According to a time-validated cloud chain collaborative data security transmission method according to claim 1, it is characterized in that: In the process of signing the transmission data with the private key of any pseudo identity of the sender user and the public key of any pseudo identity of the receiver user, if it is found in the Bloom filter that the private key has been signed, the sign-encryption is terminated.
5. According to a time-validated cloud chain collaborative data security transmission method according to claim 1, it is characterized in that: After the transmission data is signed and encrypted with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and uploaded to the cloud server, some decryption parameters and the signed file certificate are stored on the blockchain.
6. A time-validated cloud chain collaborative data secure transmission method according to claim 1, characterized in that: In the step of decrypting the transmitted data using the private key corresponding to the pseudo-identity and the public key corresponding to the pseudo-identity of the sender, the validity of the signcryption of the transmitted data is verified by the public key corresponding to the pseudo-identity of the sender.
7. According to claim 1, a method for secure transmission of cloud chain collaborative data with verifiable timeliness, characterized in that: In the step of decrypting the transmission data using the private key corresponding to the pseudo-identity and the public key corresponding to the pseudo-identity of the sender, the blockchain transmits the decryption parameters to the cloud server, the cloud server partially decrypts the transmission data based on the decryption parameters, and then sends the partially decrypted transmission data to the receiving user, and the receiving user completely decrypts the partially decrypted transmission data with the private key corresponding to the pseudo-identity to obtain the original transmission data.
8. A cloud chain collaborative data security transmission device with verifiable timeliness, characterized in that: include: A generation module, used to generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; A construction module generates a public key and a private key for each pseudo-identity of each user based on the master key to form a public-private key pair, constructs a Bloom filter for each user, embeds the Bloom filter into the private key of each pseudo-identity of the corresponding user, and stores the public key of each pseudo-identity on the chain; The transmission module is used to define a sender user and a receiver user in the blockchain, and to sign the transmission data with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user, and then upload it to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the state of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
9. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute a time-verifiable cloud chain collaborative data security transmission method as described in any one of claims 1-7.
10. A readable storage medium, characterized in that: A computer program is stored in the readable storage medium, and the computer program includes a program code for controlling a process to execute a process, and the process includes a time-verifiable cloud chain collaborative data security transmission method according to any one of claims 1-7.
Citation Information
Patent Citations
Encryption and signature verification method in block chain
CN110417556A
Blockchain technology-based key signature method
CN112910640A
Key management method and device
CN113691376A
Lightweight block chain security protection device and data encryption method
CN116956313A
System and method for role validation in identity management artificial intelligence systems using analysis of network identity graphs
US10862928B1