Identity data sharing method based on proxy re-encryption
By adopting a combination method of proxy re-encryption and secret sharing technology on the blockchain, the challenges of secure transmission and granular access in blockchain data sharing are solved, and efficient and secure data sharing is achieved.
Patent Information
- Application Number
- CN202510022436.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-05-16
AI Technical Summary
The existing blockchain-based data sharing technology has challenges in the secure transmission of keys and granular access, and it is difficult to support personalized and granular access to data by different users while ensuring efficiency and security.
The identity data sharing method based on proxy re-encryption is adopted, combined with secret sharing technology, and the key generation center is generated and managed through the key generation center, and the encrypted data is converted using the proxy server to ensure the user's granular access rights, and the user's identity is verified through smart contracts.
It effectively and securely supports fine-grained access to data by different users on the blockchain, reduces the risk of data leakage, and improves the security and efficiency of data sharing.
Smart Images

Figure CN120017254A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to an identity data sharing method based on proxy re-encryption, belonging to the technical field of privacy protection and identity information management. Background Art
[0002] Traditional data sharing between digital identities usually relies on centralized data management agencies or third-party intermediaries to ensure the security and credibility of identity data. Blockchain technology provides a new data sharing model through its decentralized and distributed characteristics.
[0003] Blockchain stores data in the form of blocks and links them through cryptographic algorithms, allowing the data to form an unchangeable chain. Each participant can verify and view the complete history of the data on the blockchain, thereby ensuring the authenticity and credibility of the data. Blockchain technology ensures the transparency and immutability of data. Blockchain technology achieves decentralized data management and control by storing data on multiple nodes in the network. This means that data sharing between digital identities no longer relies on a single centralized organization, but is jointly maintained and managed by multiple nodes in the network, improving the security and reliability of data. In addition, smart contracts in blockchain technology further promote the automation and programmability of data sharing. Through smart contracts, data sharing can be carried out automatically under pre-defined rules, reducing the need for human intervention and intermediaries, and improving the efficiency and credibility of data sharing.
[0004] However, existing blockchain-based data sharing technologies often share encrypted data by transmitting keys. This method has a high demand for the secure transmission of keys. Once the keys are leaked, all users who share the keys will be threatened. At the same time, since multiple parties share the same key, it is difficult to track where the key is leaked and prevent it. When a key leak occurs, the data owner still needs to re-encrypt a large amount of data and re-upload it to the platform, which adds unnecessary redundancy and reduces performance. If the key change is achieved through a one-time one-key method, it will bring a large amount of key generation burden, greatly reducing the performance of data sharing, and the keys obtained by different users are unrelated, lacking user personalization. Therefore, how to support personalized and fine-grained access to data by different users while ensuring the efficiency and security of the blockchain is an important challenge.
[0005] Proxy Re-Encryption (PRE) can bring some ideas, but its combination with blockchain still needs a lot of running-in. PRE technology is a technology that implements proxy authorization and access control in encrypted communication. It allows the owner of the data to entrust the encrypted data to the agent. The agent can decrypt and re-encrypt the data according to the authorization policy and pass the data to the authorized user. The basic principle of PRE technology is to encrypt the original data with the owner's key and then generate a proxy key pair. The proxy key pair includes a proxy private key and a proxy public key. The owner sends the proxy public key to the agent and authorizes the agent to use the public key for decryption and re-encryption operations. The agent can decrypt the encrypted data using the proxy private key, then process the data according to the authorization policy, and re-encrypt the data using the owner's public key. Finally, the agent sends the re-encrypted data to the authorized user, who can decrypt the data using his own private key. PRE technology plays an important role in data security and privacy protection, and is particularly suitable for blockchain scenarios. Summary of the invention
[0006] The purpose of this invention is to creatively propose an identity data sharing method based on proxy re-encryption in view of the lack of fine-grained access mechanism in existing data sharing technologies and the possible threat of data sharing intermediary service providers stealing plain text. In order to make it more suitable for blockchain, secret sharing technology is integrated into proxy re-encryption technology to ensure fine-grained access technology for users.
[0007] First, the concepts and contents involved in the present invention are explained and illustrated.
[0008] Key Generation Center (KGC): responsible for the generation and distribution of user keys, and the generation and management of re-encryption keys for data owners and authorized users. In addition, KGC is also responsible for the update and revocation of keys to ensure the life cycle management of keys.
[0009] Data owner: responsible for generating and managing the original data. The data owner obtains his / her own re-encryption key, public key, and private key from the key generation center. The private key is used to encrypt the original data, and the re-encryption key is used to convert the encrypted data in the proxy server. After uploading the encrypted data to the proxy server, the data owner formulates the corresponding access control policy for the encrypted data, that is, the data that can be accessed by different identities, to achieve fine-grained access.
[0010] Authorized users: need to access encrypted data shared by the data owner. Authorized users can obtain their own key pairs from the key generation center. After submitting an application for access to data to the proxy server, the proxy server will determine the authorized user's access rights to each set of data based on the authorized user's existing identity attributes. When the access policy is met, the authorized user will receive the ciphertext encrypted by his own private key and decrypt it offline.
[0011] Proxy server: a middleman that performs encrypted data conversion. The proxy server does not have the authority to obtain the original data, nor can it obtain the original data from the ciphertext. It can only convert the ciphertext through the encryption key provided by the data owner. At the same time, when an authorized user applies to access encrypted data, the proxy server uses the smart contract to determine the authorized user's authority to access the data based on the access control policy set by the data owner. Only when the access conditions are met can the proxy server provide encrypted data conversion for the authorized user and return the converted encrypted data to the authorized user;
[0012] In order to achieve the above object, the present invention adopts the following technical scheme.
[0013] A method for sharing identity data based on proxy re-encryption, comprising the following steps:
[0014] Step 1: System initialization and key generation.
[0015] The key generation center generates system parameters and assigns key pairs to data owners or authorized users when they join. The private key is kept safe by the user and is strictly not shared by any third party. At the same time, the public key is made public and used for data encryption operations and the generation of re-encryption keys.
[0016] Step 2: Data encryption and upload.
[0017] When sharing data, the data owner uses a private key to encrypt the data. This encryption process not only focuses on the confidentiality of the data, but also pays attention to the integrity of the data during transmission and storage.
[0018] The encrypted data is uploaded to the cloud storage service.
[0019] To further enhance the security of data, data owners selectively use block encryption. Each block of data is encrypted with an independent key, so even if part of the key is cracked, the security of the overall data will not be compromised.
[0020] When uploading encrypted data, the data owner needs to formulate an access control policy to ensure that only users with matching identity attributes can access the data.
[0021] Step 3: Identity information conversion.
[0022] When the data owner decides to share data with a data user, the data owner needs to give the re-encryption key to the proxy server. This re-encryption key enables the proxy server to convert the data owner's ciphertext into ciphertext that the data user can decrypt without exposing any user's private key or the plaintext of the data. The re-encryption key is transmitted to the proxy server through a secure communication channel, and the proxy server is responsible for the secure storage and use of the key.
[0023] When a data user requests access to data, the proxy server first needs to verify whether the request is authorized by the data owner. After verification, the proxy server uses the stored re-encryption key to convert the ciphertext from the data owner's encryption domain to the data user's encryption domain. During the conversion process, the proxy server cannot access the plaintext content of the ciphertext. The converted ciphertext can only be decrypted by the data user's private key.
[0024] Step 4: Re-encrypt data and decrypt data.
[0025] The data user downloads the re-encrypted ciphertext from the cloud storage service. After obtaining the ciphertext, the data user uses his own private key to decrypt the ciphertext to restore the original data. In order to provide a better user experience and enhance security, the data user's device can implement a local caching strategy. Under this strategy, the cached data should remain encrypted, and even if the data is cached on the device, the encryption status of the data must not be affected.
[0026] Beneficial Effects
[0027] Compared with the prior art, the method of the present invention has the following advantages:
[0028] 1. The present invention utilizes proxy re-encryption technology to achieve privacy protection, reduce the risk of data leakage, and improve security during the ciphertext conversion process.
[0029] 2 The present invention realizes fine-grained access to data by users with different identities through secret sharing technology, and uses smart contracts to verify access rights to user identity data without the need for intervention from centralized institutions.
[0030] 3. The present invention can make data sharing more secure, efficient and fine-grained while protecting data privacy, so as to better adapt to data sharing in the development environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 It is a schematic diagram of the process of the present invention. DETAILED DESCRIPTION
[0032] The following will be combined with the drawings in the examples of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. The described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0033] like Figure 1 As shown, a method for sharing identity data based on proxy re-encryption. This embodiment elaborates on privacy protection in a data sharing scenario enabled by blockchain. The data owner shares the encrypted data with the data user through a proxy service provider, whose service capability is reflected by the time and economic cost of executing the service.
[0034] Step 1: System initialization and key generation.
[0035] Step 1.1: The key generation center is responsible for generating the security parameters required by the system to ensure the security of subsequent key generation and data operations.
[0036] Step 1.2: The data owner or authorized user requests to join the system and is authenticated to ensure their legitimacy.
[0037] Step 1.3: Once the user joins legally, the key generation center generates a key pair for him, including a private key and a public key.
[0038] Among them, the private key is kept safely by the user without going through any third party to ensure that the user has full control over his or her private information; the public key is made public and used for data encryption and re-encryption key generation to support secure data operations.
[0039] Step 2: Data encryption and upload.
[0040] Step 2.1: The data owner selects the data to be shared and encrypts it using a private key. This process ensures the confidentiality of the data and the integrity of the data during transmission and storage.
[0041] Step 2.2: Upload the encrypted data to a cloud storage service for secure storage and transmission.
[0042] Step 2.3: The data owner chooses to encrypt the data in blocks, and each data block is encrypted with an independent key. Even if part of the key is cracked, it will not threaten the security of the overall data.
[0043] Step 2.4: When uploading encrypted data, the data owner needs to formulate an access control policy. This policy ensures that only users with specific identity attributes can obtain access to the data;
[0044] Step 3: Identity information conversion.
[0045] Step 3.1: When the data owner decides to share data with a data user, the data owner hands over the re-encryption key to the proxy server to support the subsequent ciphertext conversion process.
[0046] The re-encryption key is transmitted to the proxy server through a secure communication channel to ensure the confidentiality and integrity of the key transmission.
[0047] The proxy server is responsible for the secure storage and use of the key to prevent unauthorized access and disclosure.
[0048] Step 3.2: When a data user requests access to data, the proxy server first verifies whether the request is authorized by the data owner to ensure data security.
[0049] After verification, the proxy server uses the stored re-encryption key to convert the ciphertext from the data owner's encryption domain to the data consumer's encryption domain.
[0050] During this process, the proxy server cannot access the plaintext content of the ciphertext.
[0051] The converted ciphertext can only be decrypted by the data user's private key, ensuring the security and privacy of the data after conversion;
[0052] Step 4: Re-encrypt data and decrypt data.
[0053] Step 4.1: The data user downloads the re-encrypted ciphertext data from the cloud storage service;
[0054] Step 4.2: The data user uses his own private key to decrypt the downloaded ciphertext and restore the original data. The data user implements a local caching strategy, allowing data to be cached to improve user experience and access efficiency.
[0055] Example
[0056] The characters involved in this embodiment are shown in Table 1:
[0057] Table 1 Character Description
[0058]
[0059] Among them, the encryption method based on re-encrypted data from step 3.2 to step 3.3 is as follows:
[0060] Method 1: Proxy re-encryption and identity verification method
[0061] Input: kfrag,capsule,aux
[0062] Output: True or False
[0063] (1) If kfrag = nil
[0064] (2) return False
[0065] (3) If capsule = nil
[0066] (4) return False
[0067] (5)cfrg←new(cfrag.CFrag)
[0068] (6)cfrg.E1←capsule.E.Mul(kfrag.Rk.Int())
[0069] (7)cfrg.V1←capsule.V.Mul(kfrag.Rk.Int())
[0070] (8)cfrg.Id←kfrag.Id
[0071] (9)cfrg.XA←kfrag.XA
[0072] (10)h←curvebn.BytesHash2CurvBN(util.AppendByt(cfrg)
[0073] (11)return True
[0074] Among them, the input kfrag, capsule, aux refers to the re-encryption key, the encrypted ciphertext, and the identity information of the data user. The proxy service provider confirms whether the data owner has sent the re-encryption key and encrypted data. Based on the data access control policy provided by the data owner, the proxy service provider verifies whether the data user meets the permission requirements and has the legality to access the data. The proxy service provider selects the fragments that meet the data user's permissions from the re-encryption key fragments. The proxy service provider re-encrypts the ciphertext using the selected key fragment to ensure that only authenticated data users can successfully decrypt. This process ensures the secure conversion of data and the controllability of access rights through the verification and re-encryption operations of the proxy service provider. The proxy service provider only allows legitimate data users to decrypt and access the data based on the authorization and policies of the data owner.
Claims
1. A method for sharing identity data based on proxy re-encryption, characterized in that: The following steps are involved: Step 1: System initialization and key generation; The key generation center generates system parameters and assigns key pairs to data owners or authorized users when they join. The private key is kept safe by the user and is strictly not shared by any third party. At the same time, the public key is made public and used for data encryption operations and the generation of re-encryption keys. Step 2: Data encryption and upload; When sharing data, the data owner uses a private key to encrypt the data. This encryption process not only focuses on the confidentiality of the data, but also on the integrity of the data during transmission and storage. The encrypted data is uploaded to the cloud storage service. The data owner selectively uses block encryption, and each block of data is encrypted using an independent key. When uploading encrypted data, the data owner needs to formulate an access control policy to ensure that only users with matching identity attributes can access the data; Step 3: Identity information conversion; When the data owner decides to share data with a data user, the data owner needs to give the re-encryption key to the proxy server; this re-encryption key enables the proxy server to convert the data owner's ciphertext into ciphertext that the data user can decrypt without exposing any user's private key or the plaintext of the data; The re-encryption key is transmitted to the proxy server through a secure communication channel, and the proxy server is responsible for the secure storage and use of the key; When a data user requests to access data, the proxy server first needs to verify whether the request is authorized by the data owner. After the verification, the proxy server uses the stored re-encryption key to convert the ciphertext from the data owner's encryption domain to the data user's encryption domain. During the conversion process, the proxy server cannot access the plaintext content of the ciphertext. The converted ciphertext can only be decrypted by the data user's private key. Step 4: Re-encrypt data and decrypt data; The data user downloads the re-encrypted ciphertext from the cloud storage service; after obtaining the ciphertext, the data user uses his own private key to decrypt the ciphertext to restore the original data.
2. The identity data sharing method based on proxy re-encryption as claimed in claim 1, characterized in that: In step 4, the data user's device implements a local caching policy, under which the cached data remains encrypted.