CP-ABE and ZKP-based retail logistics privacy information protection model and method
By adopting CP-ABE and ZKP technologies in retail logistics, the problem of insufficient privacy information protection in the existing technology is solved, and the security protection and efficient transmission of privacy information in retail logistics is achieved.
Patent Information
- Application Number
- CN202510090132.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to effectively protect private information in retail logistics, especially in the process of rapid and fragmented delivery, where there is a risk of privacy information leakage.
The privacy information protection model based on CP-ABE (attributes based on encryption) and ZKP (zero knowledge proof) is adopted, and through the combination of encryption technology and blockchain, the secure transmission and storage of private information in the retail logistics process is ensured.
It realizes effective protection of privacy information in retail logistics, avoids privacy leakage caused by database leakage, reduces the risk of single point failure of traditional centralized key distribution, and improves the efficiency of retail logistics model.
Smart Images

Figure CN120012154A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of logistics technology, and specifically relates to a retail logistics privacy information protection model and method based on CP-ABE and ZKP. Background Art
[0002] With the popularization of e-commerce, retail logistics has developed rapidly. Similar to the traditional definition of logistics, retail logistics is the entire flow process of retail goods from suppliers to retailers and then to retail users in the retail process and the logistics activities involved. The difference is that orders are fragmented, the distribution network is dense, and the distribution speed is fast. It is precisely because of its fast and fragmented distribution method that retail logistics requires a higher level of consumer user privacy security protection to avoid the leakage of privacy information. For this reason, a retail logistics privacy information protection model and method based on CP-ABE and ZKP is proposed. Summary of the invention
[0003] In view of the deficiencies in the prior art, the purpose of the present invention is to provide a retail logistics privacy information protection model and method based on CP-ABE and ZKP, which solves the problems in the prior art.
[0004] The purpose of the present invention can be achieved through the following technical solutions:
[0005] A retail logistics privacy information protection model based on CP-ABE and ZKP, including the following entities: retailers, retail users, transporters, IPFS interplanetary file system, blockchain, re-encryption nodes and consensus nodes; retailers and retail users can encrypt private data and design access strategies as data owners, and can also access private data as data users; transporters can access private data as data users;
[0006] A retail user creates a logistics order, and each node generates its own public and private key and creates a system key pair (PK, MSK); after the retail user chooses to purchase the product, the private information and the master key MSK are encrypted and saved to the IPFS interstellar file system, and the blockchain saves its address. At the same time, a zero-knowledge proof commitment prove1 is generated; the re-encryption node generates a conversion key, and uses the conversion key and zero-knowledge proof commitment prove1 to re-encrypt the data, generating the corresponding zero-knowledge proof commitment prove2 and non-interactive zero-knowledge proof π; the non-interactive zero-knowledge proof π is verified through the consensus node, and a verification result is generated. If the verification result is met, the next step can be carried out; the retail merchant sends a ciphertext data request, restores the master key MSK based on its own private key and zero-knowledge proof commitment prove2, obtains the attribute key of the retail merchant through the access policy and the master key MSK, decrypts the plaintext information based on the ciphertext and the attribute key of the retail merchant, and after confirming the order, encrypts the order-related private information and uploads it for transit confirmation; the transporter obtains part of the ciphertext information according to the attribute strategy, plans the logistics route, and confirms the transportation at each transfer station, and performs terminal delivery after arriving at the destination.
[0007] Furthermore, the privacy information includes: retail user information, retail merchant information, retail product information and logistics transportation routes.
[0008] A retail logistics privacy information protection method based on CP-ABE and ZKP, using the above-mentioned retail logistics privacy information protection model based on CP-ABE and ZKP, includes the following steps:
[0009] S1, set the necessary parameters and attribute set, calculate the hash value of any attribute in the set, and output the key pair (PK, MSK);
[0010] S2, the data owner encrypts the private data plaintext m and the key MSK respectively, and generates a zero-knowledge proof commitment prove1. The re-encryption node generates a conversion key, and generates a zero-knowledge proof commitment prove2 through the conversion key for verification;
[0011] S3, the re-encryption node generates a zero-knowledge proof π through two zero-knowledge proof commitments, and submits it to the consensus node on the blockchain for consensus verification. If the verification passes, the data access request can be made;
[0012] S4, data users use their own private key Sk DU And zero-knowledge proof commitment prove2 restores the encrypted key CT MSK , obtain the data user's attribute key SK through the access policy S and the decrypted key MSK, and request access to the ciphertext CT, and restore the private data plaintext m through the ciphertext CT and the data user's attribute key SK.
[0013] Furthermore, the key pair (PK, MSK) is expressed as:
[0014] PK=(g,e(g,g) α , g β , H1, H2…, H x};
[0015] MSK=g α ;
[0016] Where α and β are random numbers selected to create the master key pair (PK, MSK). Set G0 and G1 to a cyclic group with a prime number p. g belongs to the element group G0. Then e(g, g) is a bilinear map. Set the attribute set to U. Define the attribute set size as |U|. For each attribute x in the attribute, use H x Represents its hash value, PK is the public key generated by the system, and MSK is the system master key.
[0017] Furthermore, the encryption strategy of the private data plaintext m is:
[0018]
[0019] Where M is a l×n access matrix, ρ(i) specifies the attributes associated with each row of the matrix, s is the reconstructed secret, and λ i is the share of the key sharing key, and the components of the ciphertext CT are calculated as C, C′, C i , D i ;
[0020] The master key MSK encryption strategy is:
[0021] E=f e , V = f v ;
[0022] MSK=g α , K MSK =θ((pk D0 ) e+v );
[0023] CT MSK =E AES (MSK, K MSK );
[0024] Among them, CT MSK is the result of master key MSK encryption, e, V∈Z q , E, V are the mappings of random numbers e, v, pk D0 The public key generated for the data owner, K MSK is the symmetric key, θ is the AES symmetric encryption function, EAES For encryption, D AES To decrypt.
[0025] Furthermore, the conversion key RK RN→DU The generation process is:
[0026]
[0027]
[0028] R RN→DU =sk RN *k -1 ;
[0029] Among them, X A is a random number x A The mapping of Z q is an integer group, k is the conversion key RK RN→DU Generate necessary parameters, pk DU is the data user public key, sk RN Re-encryption node private key.
[0030] Furthermore, in S3, the consensus verification process is:
[0031] s p =v+e*H2(E,V),prove1=(E,V,s p ),prove2=(E',V',s p );
[0032]
[0033] τ∈Z q ,E”=E τ ,V”=V τ ,Q”=Q τ ;
[0034] h=H(E,E',E",V,V',V",Q,Q',Q"),σ=τ+h*RK RN→DU ;
[0035] π=(E”,V”,Q”,Q’,σ);
[0036] Among them, s p is a random commitment value used to verify e and v, h is the hash result of multiple input values, RK RN→DU To convert the key for zero-knowledge proof verification CT MSK Correctness, confirming the legitimacy of the value in π by checking whether it complies with the proof protocol without obtaining any sensitive information.
[0037] Furthermore, the data user uses his own private key sk DU And zero-knowledge proof commitment prove2 restores the encrypted key CT MSK , the calculation process is:
[0038]
[0039] K MSK =θ((E′,V′) d );
[0040] MSK=D AES (CT MSK ,K MSK );
[0041] Among them, E ′ ,V ′ are the conversion values of E and V calculated by the conversion key, pk DU is the public key of the data user, sk DU It is the private key of the data user.
[0042] Furthermore, the data user attribute key SK is calculated as follows:
[0043] t∈Z q ;
[0044]
[0045]
[0046] Among them, t is an integer group random number, S is the user's attribute set, K is the parameter calculated after obtaining the key MSK, and L and P are the parameters required to decrypt the private data plaintext m.
[0047] Furthermore, the process of restoring the private data plaintext m is as follows:
[0048]
[0049] m=C / e(g,g) αs
[0050] Among them, m is restored by the generated data user attribute key SK and the parameter information of the ciphertext CT.
[0051] Beneficial effects of the present invention:
[0052] 1. The present invention uses the CP-ABE encryption strategy to encrypt the user's private information before uploading it to ensure privacy leakage caused by database leakage;
[0053] 2. The generation and distribution of keys in the present invention rely on blockchain records and verification of non-interactive zero-knowledge proofs, avoiding the single point failure risk brought by traditional centralized key distribution;
[0054] 3. Zero-knowledge proof in the present invention is used to verify the correctness and legitimacy of key calculation, so that each node does not need to trust a third party when verifying key-related operations;
[0055] 4. The present invention improves the efficiency of the retail logistics model by moving part of the calculation (such as key operations and re-encryption process) to off-chain execution while retaining the proof and verification records on the chain. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0057] Figure 1 It is a model schematic diagram of the retail logistics privacy information protection model based on CP-ABE and ZKP of the present invention;
[0058] Figure 2 It is a flow chart of the retail logistics privacy information protection method based on CP-ABE and ZKP of the present invention. DETAILED DESCRIPTION
[0059] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0060] Example 1
[0061] like Figure 1 As shown in the figure, a retail logistics privacy information protection model based on CP-ABE and ZKP includes the following entities:
[0062] Data owner (DO): encrypts data and designs access policies. Retail merchants (senders of retail items) and retail users (recipients of purchased products) can act as data owners to encrypt private data and design access policies.
[0063] Data User (DU): Decrypts the ciphertext using the attribute private key; Retail merchants, retail users, and transport parties can access private data as data users;
[0064] IPFS Interplanetary File System: stores encrypted data and transaction details related to retail logistics and provides storage addresses;
[0065] Blockchain (BC): records relevant addresses, zero-knowledge proof information and other relevant information;
[0066] Reencryption Node (RNode): re-encrypts data using the conversion key;
[0067] Consensus Node (CNode): processes and verifies transactions through a stake model to maintain the integrity of the blockchain network.
[0068] in:
[0069] A retail user creates a logistics order, and each node generates its own public and private key and creates a system key pair (PK, MSK); after the retail user chooses to purchase the product, the private information and the master key MSK are encrypted and saved to the IPFS interstellar file system, and the blockchain saves its address. At the same time, a zero-knowledge proof commitment prove1 is generated; the re-encryption node generates a conversion key, and uses the conversion key and zero-knowledge proof commitment prove1 to re-encrypt the data, generating the corresponding zero-knowledge proof commitment prove2 and non-interactive zero-knowledge proof π; the non-interactive zero-knowledge proof π is verified through the consensus node, and a verification result is generated. If the verification result is met, the next step can be carried out; the retail merchant sends a ciphertext data request, restores the master key MSK based on its own private key and zero-knowledge proof commitment prove2, obtains the attribute key of the retail merchant through the access policy and the master key MSK, decrypts the plaintext information based on the ciphertext and the attribute key of the retail merchant, and after confirming the order, encrypts the order-related private information and uploads it for transit confirmation; the transporter obtains part of the ciphertext information according to the attribute strategy, plans the logistics route, and confirms the transportation at each transfer station, and performs terminal delivery after arriving at the destination.
[0070] The privacy information includes, but is not limited to: retail user information (name, phone number, address), retail merchant information (name, phone number, address), retail product information (product information purchased or received by retail users), and logistics transportation routes.
[0071] The operation of the entire model includes the following stages:
[0072] 1) Order initialization stage: Retail users create logistics orders and set their own public and private keys pk DO , Sk DO At this time, the system security parameter takes k as input and sets G1 and G Tis a cyclic group with a prime number p. Assume that g belongs to the element group G1 and define the bilinear map as e: G1×G1→G T ; Set the attribute set to U, define the attribute set size to |U|, and for each attribute x in the attribute, use H x Represent its hash value; create a master key pair (PK, MSK).
[0073] 2) Order purchase stage: After the retail user chooses to purchase the product, the personal privacy information m and the master key MSK are encrypted to obtain the ciphertext CT and the encrypted master key CT MSK ; Among them, personal privacy information is encrypted using the ABE algorithm, and the master key MSK is encrypted and decrypted using the AES encryption algorithm. The ciphertext is then saved to the IPFS interstellar file system, and the IPFS interstellar file system address is stored in the blockchain. Then a zero-knowledge proof commitment prove1=(E, V, s p ) and sent to the blockchain;
[0074] 3) Conversion key generation phase: The re-encryption node RNode generates a key according to its own private key sk RN and the retail merchant's public key pk DU , randomly select a random number X from the integer group A , calculate the conversion key RK RN→DU , and store it in the IPFS interstellar file system; according to the conversion key RK RN→DU And zero-knowledge proof commitment prove1 generates zero-knowledge proof commitment prove2 = (E′, V′, s p ). The consensus node CNode obtains prove1 and prove2 and generates a non-interactive zero-knowledge proof π = (E″, V″, Q″, Q′, σ), and generates a verification result in the blockchain network after consensus verification.
[0075] 4) Zero-knowledge proof verification phase: After successful verification, the retail merchant sends a request to obtain ciphertext information based on the verification result, and obtains the ciphertext of the master key CTMSK and its own private key sk RM The merchant calculates the information based on the proof2 information, restores the master key MSK through AES decryption, and requests access to the ciphertext CT according to its own access policy. The merchant can obtain the user attribute private key SK through the master key MSK and its own attribute S, and encrypt and decrypt the plaintext m through CT and SK. Then, the merchant encrypts its own privacy information in the same way and uploads it to the IPFS interstellar file system and blockchain for storage.
[0076] 5) Order transportation stage: The transporter formulates the corresponding transportation route according to the starting point and the end point. The transporter obtains the logistics route part of the encrypted information according to the attribute strategy and his own private key, and can verify whether the current logistics route is correct. When the goods arrive at the station, the retail user is notified to pick up the goods at the door.
[0077] Example 2
[0078] Based on the retail logistics privacy information protection model based on CP-ABE and ZKP mentioned in Example 1, a retail logistics privacy information protection method based on CP-ABE and ZKP is proposed, and the entities involved include:
[0079] Data Owner (DO);
[0080] Data User (DU):
[0081] Re-encryption node RNode;
[0082] Consensus node Cnode;
[0083] IPFS Interplanetary File System;
[0084] Blockchain BC.
[0085] like Figure 2 As shown, a method for protecting retail logistics privacy information based on CP-ABE and ZKP specifically includes the following steps:
[0086] (1) System initialization phase: The system security parameters take k as input, α and β are random numbers selected to create the master key pair (PK, MSK), set G0 and G1 to a cyclic group with a prime number p, assume that g belongs to the element group G0, then e(g, g) is a bilinear map, and define the bilinear map as e: G0×G0→G1; set the attribute set to U, define the attribute set size to |U|, and for each attribute x in the attribute, use H x Represents its hash value; create a master key pair (PK, MSK):
[0087] PK = {g, e(g, g) α , g β , H1, H2..., H x};
[0088] MSK=g α ;
[0089] Where θ is defined as the AES symmetric encryption function, E AES For encryption, D AES For decryption, PK is the public key generated by the system and MSK is the system master key.
[0090] Choose a random number e,v∈Z q The data owner D0 calculates CT based on the system master key MSK and the public key of RNode MSK And zero-knowledge proof commitment prove1, formulate the ciphertext CT according to the policy attributes, and the calculation process is as follows:
[0091] Choose e,v∈Z q , calculate E = f e 、V=f v 、s p =v+e*H2(E,V),K MSK =θ((pk DO ) e+v ), according to the above calculation, the master key ciphertext and zero-knowledge proof commitment can be obtained: CT MSK =E AES (MSK,K MSK )、prove1=(E,V,s p ), where CT MSK is the result of master key MSK encryption, e,v∈Z q , E, V are the mappings of random numbers e, v, s p is the random commitment value used to verify e and v, pk DO The public key generated for the data owner.
[0092] The strategy for encrypting plaintext m into ciphertext is Where M is defined as a l×n access matrix, ρ(i) specifies the attributes associated with each row of the matrix, s is the reconstructed secret, ω i is a set of coefficients that satisfy a specific linear combination relationship, λ i is the share of the key sharing key, only the attribute set S satisfies (v is a vector, M i is the i-th row of M), in order to correctly reconstruct the secret Implement access authorization.
[0093] (2) Encapsulation and encryption phase: The re-encryption node RNode uses its own private key sk RN and the public key pk of the data user DU DU Generate the corresponding conversion key, the calculation process is as follows:
[0094] Choose a random number x A ∈Z q ,calculate The conversion key is: RK RN→DU =sk RN *k -1 ;
[0095] (3) Zero-knowledge proof stage: Based on the conversion key RK RN→DUThe result of zero-knowledge proof commitment prove1 generates zero-knowledge proof commitment prove2. At this time, the consensus node performs consensus verification in the blockchain and broadcasts the verification result to the blockchain. The prove2 generation process and non-interactive zero-knowledge proof calculation process are as follows:
[0096] Pass verification Is it equal to Verify that prove1 is in a format that meets the verification requirements, and then calculate Q = f e+v , We get prove2=(E',V',s p ); select a random number τ∈Z q , calculate E" = E τ 、V”=V τ 、Q”=Q τ , h=H(E,E',E”,V,V’,V”,Q,Q’,Q”), σ=τ+h*RK RN→DU Get zero-knowledge proof π=(E”,V”,Q”,Q',σ);
[0097] By verifying that h=H(E,E ′ ,E″,V,V ′ ,V″,Q,Q ′ ,Q″),E σ Is it equal to E″*(E′)? h 、V σ Is it equal to V″*(V′) h , Q σ ? Is it equal to Q″*(Q′) h , you can prove the zero-knowledge proof verification result.
[0098] (4) CP-ABE decryption phase: Data user DU sends a data request to the blockchain based on the verification result, and the master key ciphertext and zero-knowledge proof commitment prove2 are given to data user DU for calculation to recover the master key MSK. The steps are as follows:
[0099]
[0100] K MSK =θ((E′,V′) d );
[0101] MSK=D AES (CT MSK ,K MSK );
[0102] The calculation steps of the data user's DU attribute key SK are as follows:
[0103] t∈Z q ;
[0104]
[0105]
[0106] Among them, S is the user's attribute set, K is the parameter calculated after obtaining the key MSK, and L and P are the parameters required to decrypt the private data plaintext m.
[0107] Data user DU can calculate its own attribute private key SK based on the master key MSK and its own attribute set S. The plaintext information m can be restored based on SK and the ciphertext information CT. The restoration steps are as follows:
[0108]
[0109] Among them, m is restored by the generated data user attribute key SK and the parameter information of the ciphertext CT, and the private data plaintext m is: m = C / e(g,g) αs ;
[0110] Based on similar inventive concepts, an embodiment of the present invention also provides a computer storage medium storing a readable program, which, when the program is running, can execute the above-mentioned retail logistics privacy information protection method based on CP-ABE and ZKP.
[0111] Based on similar inventive concepts, an embodiment of the present invention provides an electronic device, comprising: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other through the communication bus;
[0112] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the above-mentioned retail logistics privacy information protection method based on CP-ABE and ZKP.
[0113] Based on similar inventive concepts, an embodiment of the present invention also provides a computer program product, including computer instructions, which instruct a computing device to perform operations corresponding to the above-mentioned retail logistics privacy information protection method based on CP-ABE and ZKP.
[0114] The method of the present invention may be implemented in hardware, firmware, or as software or computer code that may be stored in a recording medium (such as a CDROM, RAM, floppy disk, hard disk, or magneto-optical disk), or as computer code that is originally stored in a remote recording medium or a non-temporary machine-readable medium downloaded over a network and will be stored in a local recording medium, so that the method described herein may be stored in such software processing on a recording medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware (such as an ASIC or FPGA). It is understood that a computer, processor, microprocessor controller, or programmable hardware includes a storage component (e.g., RAM, ROM, flash memory, etc.) that can store or receive software or computer code, and when the software or computer code is accessed and executed by a computer, processor, or hardware, the method described herein is implemented. In addition, when a general-purpose computer accesses the code for implementing the method shown herein, the execution of the code converts the general-purpose computer into a dedicated computer for executing the method shown herein.
[0115] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments, and the above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, and these changes and improvements all fall within the scope of the present invention to be protected.
Claims
1. A retail logistics privacy information protection model based on CP-ABE and ZKP, characterized by: Includes the following entities: retailers, retail users, transporters, IPFS Interplanetary File System, blockchain, re-encryption nodes, and consensus nodes; retailers and retail users can encrypt private data and design access policies as data owners, and can also access private data as data users; transporters can access private data as data users; Retail users create logistics orders, and each node generates its own public and private keys and creates a system key pair (PK, MSK); after the retail user chooses to purchase goods, the private information and the master key MSK are encrypted and saved to the IPFS interstellar file system, and the blockchain saves its address. At the same time, a zero-knowledge proof commitment prove1 is generated; the re-encryption node generates a conversion key, and uses the conversion key and zero-knowledge proof commitment prove1 to re-encrypt the data, generating the corresponding zero-knowledge proof commitment prove2 and non-interactive zero-knowledge proof π; Through the consensus node, the non-interactive zero-knowledge proof π is verified and a verification result is generated. If the verification result is met, the next step can be carried out; The retail merchant sends a ciphertext data request, restores the master key MSK based on its own private key and zero-knowledge proof commitment prove2, obtains the retail merchant's attribute key through the access policy and the master key MSK, decrypts the plaintext information based on the ciphertext and the retail merchant's attribute key, and after confirming the order, encrypts the order-related privacy information and uploads it for transit confirmation; the transporter obtains part of the ciphertext information based on the attribute strategy, plans the logistics route, and confirms the transportation at each transfer station, and performs terminal delivery after arriving at the destination.
2. According to claim 1, a retail logistics privacy information protection model based on CP-ABE and ZKP is characterized in that: The privacy information includes: retail user information, retail merchant information, retail product information and logistics transportation routes.
3. A retail logistics privacy information protection method based on CP-ABE and ZKP, using a retail logistics privacy information protection model based on CP-ABE and ZKP as claimed in claim 1 or 2, characterized in that: The following steps are involved: S1, set the necessary parameters and attribute set, calculate the hash value of any attribute in the set, and output the key pair (PK, MSK); S2, the data owner encrypts the private data plaintext m and the key MSK respectively, and generates a zero-knowledge proof commitment prove1. The re-encryption node generates a conversion key, and generates a zero-knowledge proof commitment prove2 through the conversion key for verification; S3, the re-encryption node generates a zero-knowledge proof π through two zero-knowledge proof commitments, and submits it to the consensus node on the blockchain for consensus verification. If the verification passes, the data access request can be made; S4, data users use their own private key sk DU And zero-knowledge proof commitment prove2 restores the encrypted key CT MSK , obtain the data user's attribute key SK through the access policy S and the decrypted key MSK, and request access to the ciphertext CT, and restore the private data plaintext m through the ciphertext CT and the data user's attribute key SK.
4. According to claim 3, a retail logistics privacy information protection method based on CP-ABE and ZKP is characterized in that: The key pair (PK, MSK) is expressed as: PK={g,e(g,g) α ,g β ,H1,H2…,H x }; MSK=g α ; Where α, β are random numbers selected to create the master key pair (PK, MSK). Set G0 and G1 to a cyclic group with a prime number p. g belongs to the element group G0. Then e(g, g) is a bilinear map. Set the attribute set to U. Define the attribute set size as |U|. For each attribute x in the attribute, use H x Represents its hash value, PK is the public key generated by the system, and MSK is the system master key.
5. According to claim 4, a retail logistics privacy information protection method based on CP-ABE and ZKP is characterized in that: The encryption strategy for the private data plaintext m is: Where M is a l×n access matrix, ρ(i) specifies the attributes associated with each row of the matrix, s is the reconstructed secret, and λ i is the share of the key sharing key, and the components of the ciphertext CT are calculated as C, C′, C i , D i ; The master key MSK encryption strategy is: E=f e ,V=f v ; MSK=g α ,K MSK =θ((pk DO ) e+v ); CT MSK =E AES (MSK,K MSK ); Among them, CT MSK is the result of master key MSK encryption, e,v∈Z q , E, V are the mappings of random numbers e, v, pk DO The public key generated for the data owner, K MSK is the symmetric key, θ is the AES symmetric encryption function, E AES For encryption, D AES To decrypt.
6. According to claim 5, a retail logistics privacy information protection method based on CP-ABE and ZKP is characterized in that: The conversion key RK RN→DU The generation process is: RK RN→DU =en RN *to -1 ; Among them, X A is a random number x A The mapping of Z q is an integer group, k is the conversion key RK RN→DU Generate necessary parameters, pk DU is the data user public key, sk RN Re-encryption node private key.
7. The method for protecting retail logistics privacy information based on CP-ABE and ZKP according to claim 6 is characterized in that: In S3, the consensus verification process is: s p =v+e*H2(E,V),prove1=(E,V,s p ),prove2=(E',V',s p ); τ∈Z q "E"=E τ "V"=V τ "Q"=Q τ ; h=H(E,E',E”,V,V',V”,Q,Q',Q”),σ=τ+h*RK RN→DU ; π=(E”,V”,Q”,Q’,σ); Among them, s p is a random commitment value used to verify e and v, h is the hash result of multiple input values, RK RN→DU To convert the key for zero-knowledge proof verification CT MSK Correctness, confirming the legitimacy of the value in π by checking whether it complies with the proof protocol without obtaining any sensitive information.
8. The method for protecting retail logistics privacy information based on CP-ABE and ZKP according to claim 7 is characterized in that: Data users use their own private key sk DU And zero-knowledge proof commitment prove2 restores the encrypted key CT MSK , the calculation process is: K MSK =θ((E′,V′) d ); MSK=D AES (CT MSK ,K MSK ); Among them, E′ and V′ are the converted values of E and V calculated by the conversion key, pk DU is the public key of the data user, sk DU It is the private key of the data user.
9. The method for protecting retail logistics privacy information based on CP-ABE and ZKP according to claim 8 is characterized in that: The calculation method of the data user attribute key SK is: t∈Z q ; Among them, t is an integer group random number, S is the user's attribute set, K is the parameter calculated after obtaining the key MSK, and L and P are the parameters required to decrypt the private data plaintext m.
10. A retail logistics privacy information protection model based on CP-ABE and ZKP according to claim 9, characterized in that: The process of restoring the private data plaintext m is as follows: m=C / e(g,g) αs Among them, m is restored by the generated data user attribute key SK and the parameter information of the ciphertext CT.
Citation Information
Patent Citations
Logistics privacy protection system based on ciphertext policy attribute-based key encapsulation
CN113645582A
Ciphertext data security sharing and access control method based on zero knowledge proof
CN118264398A