Time-Effectively Verifiable Cloud-Chain Collaborative Data Secure Transmission Method and Device
By generating multiple pseudo-identities for users and embedding Bloom filters, the problems of timeliness management and private key leakage in data security transmission are solved, and the secure transmission and timeliness of data are realized.
Patent Information
- Application Number
- CN202510443508.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-04-10
AI Technical Summary
The prior art is difficult to effectively manage the timeliness of signed documents in data security transmission, and cannot trace the historical signing results, and cannot guarantee the security of data when the user's private key is leaked.
By generating multiple pseudo-identities for each user and embedding the Bloom filter into the private key of each pseudo-identity, each signed-in file generated, the private key is updated based on the Bloom filter to ensure the security of the private data.
It realizes timeliness management and tracking of signed secret files, prevents expired users from maliciously transmitting messages, and ensures data security in the event of private key leakage.
Smart Images

Figure CN119996073B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain, and in particular, to a method and device for securely transmitting cloud-chain collaborative data with verifiable timeliness. Background Art
[0002] With the continuous progress of the new generation of information technology, the data transmitted wirelessly covers a lot of private information such as personal identity information, health records, and device usage. Once these sensitive data are subject to unauthorized access or leakage, it will not only expose personal privacy, but may also cause property losses and even endanger people's lives. The security problems in data transmission are becoming increasingly prominent.
[0003] Signcryption technology can achieve the two steps of digital signature and public key encryption in the same logical step, which is more efficient than the method of "sign first and then encrypt" and is also more suitable for resource-constrained environments. It has become an important means to ensure secure data transmission.
[0004] However, in recent years, attack methods such as side channels have emerged continuously. If a user's private key is leaked, malicious users can use it to generate legal signatures for any message, thus causing serious data security problems. For this reason, some solutions have introduced blockchain to address these situations. As a decentralized public distributed ledger, blockchain has the property of immutability. For example, Chinese invention patent 202110192016.7 records the public key and the data after signcryption on the blockchain. Due to the transparency of the blockchain, it is difficult for data owners to control which users can obtain the public key and decrypt the data, which is likely to cause leakage of private data; Chinese invention patent 201910591183.1 proposes a blockchain signcryption method with access control, which formulates access policies based on user attributes to achieve the purpose of access control. However, this solution cannot trace the historical signcryption results, which is not conducive to the timeliness management and tracking of signcryption files, and it is also impossible to supervise and trace malicious users. Moreover, ensuring that the terminal device is within the time limit is also a key guarantee for secure data transmission. Verifying the timeliness of signcryption files can prevent expired users from maliciously transmitting messages.
[0005] Many users store data in the cloud to solve the problem of limited local storage space, so that users can access data on different devices and at different locations, improving the data transmission efficiency. However, this also brings the problem of trust in cloud servers. Those cloud servers may access users' private data without authorization, creating opportunities for malicious attackers. Although blockchain technology can achieve trusted data sharing, it is limited by the Transactions Per Second (TPS) and it is difficult to store complete data on the chain. Summary of the Invention
[0006] The embodiment of the present application provides a time - effective verifiable cloud - chain collaborative data security transmission method and device. By generating multiple pseudo - identities for each user and embedding a Bloom filter into the private key of each pseudo - identity, each time a sign - cipher file is generated, the private key is updated based on the Bloom filter to ensure the security of private data.
[0007] In a first aspect, the embodiment of the present application provides a time - effective verifiable cloud - chain collaborative data security transmission method, and the method includes:
[0008] Generating a master key through a key generation center and generating multiple pseudo - identities for each user in the blockchain;
[0009] Generating a public - key and a private - key pair for each pseudo - identity of each user based on the master key, constructing a Bloom filter for each user, embedding the Bloom filter into the private key of the corresponding pseudo - identity of each user, and storing the public key of each pseudo - identity on the blockchain.
[0010] Defining a sender user and a receiver user in the blockchain, signing and encrypting the transmission data with the private key of any pseudo - identity of the sender user and the public key of any pseudo - identity of the receiver user and then uploading it to the cloud server. During the signing and encrypting process, adding the transmission data to the Bloom filter and updating the status of the Bloom filter. The receiver user obtains the signed and encrypted transmission data in the cloud server and decrypts the transmission data with the private key of its corresponding pseudo - identity and the public key of the corresponding pseudo - identity of the sender.
[0011] In a second aspect, the embodiment of the present application provides a time - effective verifiable cloud - chain collaborative data security transmission device, including:
[0012] A generation module, configured to generate a master key through a key generation center and generate multiple pseudo - identities for each user in the blockchain;
[0013] A construction module, generating a public - key and a private - key pair for each pseudo - identity of each user based on the master key, constructing a Bloom filter for each user, embedding the Bloom filter into the private key of the corresponding pseudo - identity of each user, and storing the public key of each pseudo - identity on the blockchain.
[0014] A transmission module, configured to define a sender user and a receiver user in the blockchain, sign and encrypt the transmission data with the private key of any pseudo - identity of the sender user and the public key of any pseudo - identity of the receiver user and then upload it to the cloud server. During the signing and encrypting process, adding the transmission data to the Bloom filter and updating the status of the Bloom filter. The receiver user obtains the signed and encrypted transmission data in the cloud server and decrypts the transmission data with the private key of its corresponding pseudo - identity and the public key of the corresponding pseudo - identity of the sender.
[0015] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute a time-effect-verifiable cloud-chain collaborative data security transmission method.
[0016] In a fourth aspect, an embodiment of the present application provides a readable storage medium. A computer program is stored in the readable storage medium. The computer program includes program code for controlling a process to execute the process, and the process includes a time-effect-verifiable cloud-chain collaborative data security transmission method.
[0017] The main contributions and innovations of the present invention are as follows:
[0018] In the embodiment of the present application, by embedding a Bloom filter into the private key of the user's pseudo-identity, after the user signs a specific message, the Bloom filter is used to update the user's private key, thereby preventing malicious users from using the same private key to sign the same message again, ensuring the confidentiality, integrity, and non-forgeability of private data, and guaranteeing the security of data even in the case of private key leakage; the embodiment of the present application generates multiple meta-associated pseudo-identities for each user, generates a public-private key pair using the user's anonymous information, and effectively binds the user's anonymous identity information to the signed and encrypted message. At the same time, a chain-based storage method based on a dynamic accumulator is adopted, and only the accumulated values of each group are saved on the chain, solving the problem of large communication and on-chain storage overhead caused by uploading all the public key information of anonymous identities to the blockchain, and realizing on-chain evidence storage to achieve data traceability; the embodiment of the present application adopts a cloud-chain collaborative architecture, stores the signed and encrypted file and some decryption parameters on the cloud server, and stores the signed and encrypted file in the form of a digest on the blockchain. Users can quickly compare the consistency of data on the chain and off the chain through a smart contract, and verify whether it is within the time limit through the cloud server to achieve time-effect verifiability of data.
[0019] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0021] Figure 1 is a logical flowchart of a time-effect-verifiable cloud-chain collaborative data security transmission method according to an embodiment of the present application;
[0022] Figure 2It is a structural block diagram of a time-effectiveness-verifiable cloud-chain collaborative data security transmission device according to an embodiment of the present application;
[0023] Figure 3 It is a schematic hardware structure diagram of an electronic device according to an embodiment of the present application. Detailed implementation manners
[0024] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with one or more embodiments of this specification. On the contrary, they are merely examples of devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.
[0025] It should be noted that: In other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.
[0026] Embodiment 1
[0027] The embodiment of the present application provides a time-effectiveness-verifiable cloud-chain collaborative data security transmission method. By generating multiple pseudo-identities for each user and embedding a Bloom filter into the private key of each pseudo-identity, each time a signcryption file is generated, the private key is updated based on the Bloom filter to ensure the security of private data. Specifically, referring to Figure 1 , the method includes:
[0028] Generating a master key through a key generation center and generating multiple pseudo-identities for each user in the blockchain;
[0029] Generating a public key and a private key for each pseudo-identity of each user based on the master key to form a public-private key pair, constructing a Bloom filter for each user, embedding the Bloom filter into the private key of each pseudo-identity of the corresponding user, and storing the public key of each pseudo-identity on the chain;
[0030] Define the sender user and the receiver user in the blockchain. Use the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user to sign and encrypt the transmission data, and then upload it to the cloud server. During the sign-encryption process, add the transmission data to the Bloom filter and update the status of the Bloom filter. The receiver user obtains the signed and encrypted transmission data in the cloud server, and uses the private key of its corresponding pseudo-identity and the public key of the sender's corresponding pseudo-identity to decrypt the transmission data.
[0031] In some embodiments, users are divided into multiple groups based on the entity attributes of each user on the blockchain. The entity attributes include computing power, functions undertaken, and physical location. Among them, users with the same entity attributes are regarded as users in the same group. When uploading the public key of each pseudo-identity to the blockchain for storage, a dynamic accumulator is used to accumulate and upload the public keys of all pseudo-identities of users in the same group to the blockchain for storage.
[0032] Specifically, computing power refers to the operation and processing ability of a user. In the blockchain network, different operation and processing abilities will affect its efficiency in contributing to the network and its performance in some scenarios that require layout competition, etc.; functions undertaken represent the specific functions that a user is responsible for or can execute in the blockchain system. For example, some users may act as full nodes, which need to completely store all ledger data of the blockchain, verify transactions, broadcast information, etc., and undertake important functions such as maintaining the stable operation of the entire blockchain network and ensuring data consistency; some users may only be light nodes, only need to store some key data, mainly used for simple functions such as querying transactions, and do not need to handle a large number of complex maintenance tasks like full nodes. Different functions undertaken reflect the different roles played by users in the blockchain system architecture and the corresponding roles they play; the physical location refers to the actual geographical location where the user is located, which can be the city where a certain data center is located, the address of a specific office location, etc.
[0033] That is to say, the same entity attributes in this solution mean that the computing power is in the same interval, the functions undertaken are the same, and the physical location is the same.
[0034] Exemplarily, grouping according to different computing powers can be divided into , where C c represents the computing power interval; grouping according to the functions undertaken can be divided into , where F f represents different functions undertaken; grouping according to the physical location can be divided into , where L l represents different physical locations. If the grouping situation of a user i is expressed as , it means that the user is assigned to the computing power group 1, the function groups 3 and 4, and the physical location group 2. That is to say, the computing power of this user is in C1 Within the interval, the responsible function is F 3 and F 4 , and the physical location information is L 2 .
[0035] Specifically, a dynamic accumulator is used to upload the public keys of all pseudo-identities of users in the same group to the blockchain for storage. Compared with the conventional storage of each public key one by one, the dynamic accumulator can integrate and process the public keys of multiple pseudo-identities, summarize them into a relatively compact representation and store them on the blockchain, greatly reducing the space occupied by storing these public keys on the chain. Especially in the complex situation where a large number of users have multiple pseudo-identities and corresponding numerous public keys, it can effectively avoid the storage resource tension caused by excessive public key data storage and optimize the utilization efficiency of the entire blockchain's storage resources.
[0036] Furthermore, since users may undertake multiple functions, when grouping users, they will be grouped according to each function that a user undertakes. Only users with exactly the same functions are likely to be grouped together.
[0037] Furthermore, the user defines the validity period. Based on each user's user group, user pseudo-identity information, the public key corresponding to the pseudo-identity information, and the validity period, a user information label is established for each user, and the user information label of each user is stored on the blockchain, and the blockchain does not respond to any queries regarding users with expired validity periods.
[0038] Specifically, the generated user information label is expressed as , where PID represents the user's pseudo-identity information, pk represents the public key corresponding to the pseudo-identity information, is the validity period, and Block is the user's group.
[0039] Specifically, the validity period of the user is defined by the user himself. That is to say, after a user joins the blockchain, he will define a validity period, such as 2025 / 3 / 10. The user can only accept transactions within the validity period. After the validity period expires, the blockchain will not respond to any queries about this user. That is to say, after the validity period expires, it is impossible to query the transaction information and transmitted files of the expired user in the blockchain, nor can the public key of the expired user be obtained, which is equivalent to "deleting" the user in the blockchain.
[0040] Specifically, the blockchain manages the user information label of each user through a smart contract.
[0041] In some embodiments, the key generation center KGC selects two groups G and GT with prime order p, and satisfies the operation: e: G×G→GT, g is the generator of G, and given the pseudo-identity of user A Predefined set and the set of all possible signcryption results , given 3 Hash functions: 、 、 , select a random group element , generate 2 random vectors and , randomly select , generate the parameter , and let msk = as the master key.
[0042] Specifically, the key generation center is responsible for generating the master key and distributing the public-private key pair through the master key to complete the transaction authentication in the blockchain.
[0043] In some specific embodiments, the data sender user generates a user information label access tree, constructs a Bloom filter according to the user information labels of potential recipients that meet the data decryption requirements , and embeds the Bloom filter into the private key of each pseudo-identity of all users, which is expressed by the formula:
[0044]
[0045] is the private key of the user, is the Bloom filter, is composed of 、 and .
[0046] In the process of generating the user's private key, map the user's pseudo-identity to the predefined set of pseudo-identities , then initialize the Bloom filter, select a randomizer , for any integer calculate the user's partial private key as follows:
[0047]
[0048]
[0049]
[0050] Among them, , is a non-zero multiplicative group composed of the key generation center based on the large prime number p, x A is the secret parameter of user A, used to generate the private key of user A himself, UA is a random vector generated by the key generation center, and ui is a parameter related to the element i in UA, is the exponential parameter of ui, and is a random number randomly generated according to the generator g.
[0051] In some embodiments, during the process of signcryption of the transmission data using the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user, if it is queried in the Bloom filter that the transmission data has been signcrypted, then this signcryption is terminated.
[0052] Furthermore, since the Bloom filter is embedded in the private key of the user in this solution, during the signcryption process, the purpose of adding the transmission data to the Bloom filter and updating the status of the Bloom filter is to determine whether the transmission data has been signcrypted. If it is determined according to the Bloom filter that the transmission data has not been signcrypted, then signcryption is performed on it. If the transmission data exists in the Bloom filter, it indicates that the transmission data has been signcrypted, and then the signcryption is terminated.
[0053] Specifically, since the Bloom filter is embedded in the private key of each pseudo-identity of the corresponding user, when the status of the Bloom filter is updated, the private key of the pseudo-identity is also updated accordingly. Also, since the update of the pseudo-identity is reflected in the Bloom filter, it will not affect the decryption of the receiver user.
[0054] Specifically, the Bloom filter is a probabilistic data structure that can efficiently determine whether an element is in a set. When adding a message, the message is mapped to a bit array using a hash function, changing the status of the corresponding bit positions, that is, updating the status of the Bloom filter.
[0055] Exemplarily, according to the private key of the sender user and the transmission data , let , then add M to the set of the Bloom filter and update its status, and output the updated private key .
[0056] Furthermore, when it is necessary to re-signcrypt the transmission file, a single element in the Bloom filter is deleted and then signcryption is performed.
[0057] In some embodiments, after signcrypting the transmission data using the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and uploading it to the cloud server, the decryption parameter and the signcryption file proof are stored on the blockchain.
[0058] Specifically, the decryption parameter is the key information for restoring the ciphertext to the original data. Usually, only with the correct decryption parameter can the ciphertext be decrypted to obtain the original data. In this solution, part of the decryption parameter is stored on the blockchain because the blockchain has characteristics such as immutability and traceability, which can ensure the security and integrity of these decryption parameters. Decryption using the decryption parameters stored on the blockchain can prevent the decryption parameters from being arbitrarily tampered with or lost.
[0059] Specifically, the signcryption file proof contains some key information that can prove the legality, source authenticity, etc. of this signcryption file, such as digital signature information. Storing the signcryption file proof on the blockchain also takes advantage of the characteristics of the blockchain, enabling verification at any time through querying the blockchain whether the signcryption file was indeed sent by the claimed entity and whether it was tampered with during the transmission process, enhancing the security and credibility of the entire file processing process.
[0060] In some embodiments, in the signcryption step, the public key of any pseudo-identity of the recipient user is used to send a message to the recipient user , and the following operations are performed at this time:
[0061] Calculate , calculate , calculate , calculate , calculate , calculate , integrate , , , , , to obtain the complete signcryption .
[0062] In some embodiments, in the step of decrypting the transmitted data with the private key corresponding to its own pseudo-identity and the public key corresponding to the sender's pseudo-identity, the blockchain transmits the decryption parameter to the cloud server. The cloud server partially decrypts the transmitted data based on the decryption parameter and then sends the partially decrypted transmitted data to the recipient user. The recipient user completely decrypts the partially decrypted transmitted data with the private key corresponding to its own pseudo-identity to obtain the original transmitted data, and verifies the signcryption validity of the transmitted data through the public key corresponding to the sender's pseudo-identity.
[0063] Specifically, the formula for completely decrypting the partially decrypted transmitted data with the private key corresponding to its own pseudo-identity to obtain the original transmitted data is as follows:
[0064]
[0065] Among them, M is the original transmitted data, , , are signcryption information, and sk is the private key of its corresponding pseudo-identity.
[0066] Specifically, the formula for verifying the signcryption validity of the transmitted data by the public key of the corresponding pseudo-identity of the sender is as follows:
[0067]
[0068] Among them, , , are signcryption information, pk is the public key of the corresponding pseudo-identity of the sender. If the above formula holds, it means the signcryption is valid; otherwise, the signcryption is invalid.
[0069] Embodiment 2
[0070] Based on the same concept, referring to Figure 2 , this application also proposes a time-effect-verifiable cloud-chain collaborative data security transmission device, including:
[0071] A generation module, configured to generate a master key through a key generation center and generate multiple pseudo-identities for each user in the blockchain;
[0072] A construction module, based on the master key, generates a public key and a private key for each pseudo-identity of each user to form a public-private key pair, constructs a Bloom filter for each user, embeds the Bloom filter into the private key of each pseudo-identity of the corresponding user, and stores the public key of each pseudo-identity on the chain;
[0073] A transmission module, configured to define a sender user and a receiver user in the blockchain, signcrypt the transmitted data with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and then upload it to the cloud server. During the signcryption process, add the transmitted data to the Bloom filter and update the status of the Bloom filter. The receiver user obtains the signcrypted transmitted data in the cloud server and decrypts the transmitted data with the private key of its corresponding pseudo-identity and the public key of the corresponding pseudo-identity of the sender.
[0074] Embodiment 3
[0075] This embodiment also provides an electronic device, referring to Figure 3 , including a memory 404 and a processor 402. A computer program is stored in the memory 404, and the processor 402 is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0076] Specifically, the above-mentioned processor 402 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured as one or more integrated circuits for implementing the embodiments of the present application.
[0077] Among them, the memory 404 may include a mass storage 404 for data or instructions. By way of example and not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In appropriate cases, the memory 404 may include removable or non-removable (or fixed) media. In appropriate cases, the memory 404 may be internal or external to the data processing device. In a particular embodiment, the memory 404 is non-volatile memory. In a particular embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). In appropriate cases, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. In appropriate cases, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended data out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0078] The memory 404 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402.
[0079] The processor 402 reads and executes the computer program instructions stored in the memory 404 to implement any one of the time - efficient verifiable cloud - chain collaborative data security transmission methods in the above - mentioned embodiments.
[0080] Optionally, the above - mentioned electronic device may further include a transmission device 406 and an input / output device 408. Among them, the transmission device 406 is connected to the above - mentioned processor 402, and the input / output device 408 is connected to the above - mentioned processor 402.
[0081] The transmission device 406 can be used to receive or send data via a network. Specific examples of the above - mentioned network may include wired or wireless networks provided by the communication provider of the electronic device. In one example, the transmission device includes a Network Interface Controller (NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the transmission device 406 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0082] The input / output device 408 is used to input or output information. In this embodiment, the input information can be pseudo - identities, public - private key pairs of each pseudo - identity, etc., and the output information can be the decryption result of the transmitted data, etc.
[0083] Optionally, in this embodiment, the above - mentioned processor 402 can be set to execute the following steps through a computer program:
[0084] Generate a master key through a key generation center and generate multiple pseudo - identities for each user in the blockchain;
[0085] Generate a public - private key pair consisting of a public key and a private key for each pseudo - identity of each user based on the master key, construct a Bloom filter for each user, embed the Bloom filter into the private key of each pseudo - identity of the corresponding user, and store the public key of each pseudo - identity on the chain;
[0086] Define a sender user and a receiver user in the blockchain. Sign and encrypt the transmission data with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user, and then upload it to the cloud server. During the sign-encryption process, add the transmission data to the Bloom filter and update the status of the Bloom filter. The receiver user obtains the sign-encrypted transmission data in the cloud server, and decrypts the transmission data with the private key of its corresponding pseudo-identity and the public key of the sender's corresponding pseudo-identity.
[0087] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and alternative embodiments, and will not be elaborated here.
[0088] Generally, various embodiments can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects of the present invention can be implemented in hardware, while other aspects can be implemented by firmware or software executed by a controller, microprocessor, or other computing device, but the present invention is not limited thereto. Although various aspects of the present invention can be shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, as a non-limiting example, the blocks, devices, systems, technologies, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general hardware or a controller, or other computing devices, or some combination thereof.
[0089] Embodiments of the present invention can be implemented by computer software, which can be executed by a data processor of a mobile device, such as in a processor entity, or by hardware, or by a combination of software and hardware. A computer software or program (also referred to as a program product), including software routines, applets, and / or macros, can be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. The computer program product can include one or more computer-executable components configured to execute the embodiments when the program runs. One or more computer-executable components can be at least one software code or a part thereof. The software can be stored on physical media such as memory chips or storage blocks implemented within a processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and their data variants, CDs. The physical media is a non-transitory medium.
[0090] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0091] The above embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A cloud chain collaborative data security transmission method with verifiable timeliness, characterized in that: The following steps are involved: Generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; Generate a public key and a private key pair for each pseudo-identity of each user based on the master key, construct a Bloom filter for each user, embed the Bloom filter into the private key of each pseudo-identity of the corresponding user, and store the public key of each pseudo-identity on the chain; A sender user and a receiver user are defined in the blockchain. The transmission data is signed with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and then uploaded to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the status of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
2. According to claim 1, a method for secure transmission of cloud chain collaborative data with verifiable timeliness, characterized in that: Based on the entity attributes of each user on the blockchain, users are divided into multiple groups. The entity attributes include computing power, functions undertaken, and physical locations. Users with the same entity attributes are regarded as users in the same group. When the public key of each pseudo-identity is stored on the chain, a dynamic accumulator is used to accumulate the public keys of all pseudo-identities of users in the same group and upload them to the blockchain for storage.
3. According to claim 2, a method for secure transmission of cloud chain collaborative data with verifiable timeliness is characterized in that: The user defines the validity period, establishes a user information tag for each user based on each user's user group, user pseudo-identity information, the public key corresponding to the pseudo-identity information, and the validity period, and stores each user's user information tag on the blockchain. The blockchain does not respond to any queries about users whose validity period has expired.
4. According to a time-validated cloud chain collaborative data security transmission method according to claim 1, it is characterized in that: In the process of signing the transmission data with the private key of any pseudo identity of the sender user and the public key of any pseudo identity of the receiver user, if it is found in the Bloom filter that the private key has been signed, the sign-encryption is terminated.
5. According to a time-validated cloud chain collaborative data security transmission method according to claim 1, it is characterized in that: After the transmission data is signed and encrypted with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user and uploaded to the cloud server, some decryption parameters and the signed file certificate are stored on the blockchain.
6. A time-validated cloud chain collaborative data secure transmission method according to claim 1, characterized in that: In the step of decrypting the transmitted data using the private key corresponding to the pseudo-identity and the public key corresponding to the pseudo-identity of the sender, the validity of the signcryption of the transmitted data is verified by the public key corresponding to the pseudo-identity of the sender.
7. According to claim 1, a method for secure transmission of cloud chain collaborative data with verifiable timeliness, characterized in that: In the step of decrypting the transmission data using the private key corresponding to the pseudo-identity and the public key corresponding to the pseudo-identity of the sender, the blockchain transmits the decryption parameters to the cloud server, the cloud server partially decrypts the transmission data based on the decryption parameters, and then sends the partially decrypted transmission data to the receiving user, and the receiving user completely decrypts the partially decrypted transmission data with the private key corresponding to the pseudo-identity to obtain the original transmission data.
8. A cloud chain collaborative data security transmission device with verifiable timeliness, characterized in that: include: A generation module, used to generate a master key through a key generation center and generate multiple pseudo identities for each user in the blockchain; A construction module generates a public key and a private key for each pseudo-identity of each user based on the master key to form a public-private key pair, constructs a Bloom filter for each user, embeds the Bloom filter into the private key of each pseudo-identity of the corresponding user, and stores the public key of each pseudo-identity on the chain; The transmission module is used to define a sender user and a receiver user in the blockchain, and to sign the transmission data with the private key of any pseudo-identity of the sender user and the public key of any pseudo-identity of the receiver user, and then upload it to the cloud server. During the sign-encryption process, the transmission data is added to the Bloom filter and the state of the Bloom filter is updated. The receiver user obtains the signed transmission data in the cloud server and decrypts the transmission data with the private key of the corresponding pseudo-identity of the sender and the public key of the corresponding pseudo-identity of the sender.
9. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute a time-verifiable cloud chain collaborative data security transmission method as described in any one of claims 1-7.
10. A readable storage medium, characterized in that: A computer program is stored in the readable storage medium, and the computer program includes a program code for controlling a process to execute a process, and the process includes a time-verifiable cloud chain collaborative data security transmission method according to any one of claims 1-7.
Citation Information
Patent Citations
Encryption and signature verification method in block chain
CN110417556A
Blockchain technology-based key signature method
CN112910640A
Key management method and device
CN113691376A
Lightweight block chain security protection device and data encryption method
CN116956313A