Intelligent traffic vehicle collaborative management method and system based on block chain

By using a blockchain-based smart transportation vehicle collaborative management method in the Internet of Vehicles, judging encryption requirements by obtaining the characteristics of data plaintext, using an access control policy tree for encryption, and achieving cross-chain encryption through aggregation signatures, it solves the problem that a single blockchain is difficult to cope with the high amount of big data and real-time performance, and significantly improves the level of data privacy protection.

CN120034857AInactive Publication Date: 2025-05-23WUHU SIMBA NETWORK TECH CO LTD

Patent Information

Application Number
CN202510187842.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-23
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The data privacy protection achieved by the prior art through blockchain in the Internet of Vehicles is limited to a single blockchain scenario, and the cross-chain encryption and decryption solutions between different blockchains are very limited, resulting in the limitation of the degree of data privacy protection.

Method used

A blockchain-based smart transportation vehicle collaborative management method and system is proposed. By obtaining the characteristics of the data plaintext, whether encryption is needed is determined, the attribute-based encryption is used to use a pre-built access control policy tree to generate message ciphertext, and the cross-chain ciphertext is generated through aggregation signatures to achieve secure information interoperability between different blockchains.

Benefits of technology

The implementation of cross-chain encryption and decryption between different blockchains in the smart transportation and vehicle network has significantly improved the level of data privacy protection and solved the problem of the difficulty of a single blockchain in dealing with the high demand for large data volume and real-time performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034857A_ABST
    Figure CN120034857A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of block chains, and discloses an intelligent traffic vehicle collaborative management method and system based on a block chain, and the method comprises the steps: obtaining a first feature based on a data plaintext, judging whether to encrypt the data plaintext or not according to the first feature, carrying out the attribute-based encryption of the data plaintext according to a pre-constructed access control strategy tree, and carrying out the attribute-based encryption of the data plaintext. The method comprises the following steps of: generating a message ciphertext according to the message information, performing aggregation signature on the message ciphertext to generate a cross-chain ciphertext, sending the cross-chain ciphertext to a cross-chain node of a target chain, finally verifying the cross-chain ciphertext, sending the cross-chain ciphertext to a receiving party when the verification is successful, and decrypting the cross-chain ciphertext by the receiving party. In the smart traffic internet of vehicles, cross-chain encryption and decryption among different block chains can be realized, so that the privacy protection level of data is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain technology, and more specifically, to a blockchain-based smart transportation vehicle collaborative management method and system. Background Art

[0002] The Internet of Vehicles achieves intelligent management through information technology and provides vehicles with real-time traffic information. However, there are security risks such as privacy leakage in the interaction between vehicles and road services. Therefore, while promoting the application of the Internet of Vehicles, the privacy security of the system must be guaranteed. Blockchain technology, due to its decentralized nature, can help realize service management and data sharing in the Internet of Vehicles. However, the Internet of Vehicles' demand for large amounts of data and high real-time performance makes it difficult for a single blockchain to cope with these challenges. The use of multiple blockchains operating in parallel can effectively share the pressure of data processing, but how to achieve secure information exchange between blockchains is still an issue that needs to be addressed.

[0003] For example, the Chinese patent application with publication number CN116760619A provides a vehicle privacy protection method based on cloud storage blockchain in the Internet of Vehicles. The invention realizes conditional vehicle privacy protection through blockchain. The decentralized identity and related information are autonomously controlled by the vehicle and protected by keys. The Chinese patent application with publication number CN110365485A provides a user privacy protection solution for car-hailing based on blockchain. The invention realizes privacy protection of car-hailing data between passengers and drivers through blockchain.

[0004] Although the above-mentioned existing technologies have achieved certain data privacy protection in the Internet of Vehicles through blockchain technology, they are all limited to the scenario of a single blockchain. In the existing technologies, cross-chain encryption and decryption schemes that can realize interactions between different blockchains are still very limited, which limits the degree of data privacy protection.

[0005] In view of this, the present invention proposes a blockchain-based smart transportation vehicle collaborative management method and system to solve the above problems. Summary of the invention

[0006] In order to overcome the above-mentioned defects of the prior art, the present invention provides a blockchain-based smart transportation vehicle collaborative management method and system.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] First, the blockchain-based intelligent transportation vehicle collaborative management method is applied to data transmission between the sender and the receiver, including:

[0009] receiving plaintext data transmitted by a sender, obtaining a first feature based on the plaintext data, and determining whether to encrypt the plaintext data according to the first feature;

[0010] When the data plaintext needs to be encrypted, attribute-based encryption is performed on the data plaintext according to the pre-built access control policy tree to generate the message ciphertext;

[0011] Aggregate signature is performed on the message ciphertext to generate cross-chain ciphertext, and the cross-chain ciphertext is sent to the cross-chain node of the target chain. The target chain is the blockchain corresponding to the recipient.

[0012] The cross-chain ciphertext is verified. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext.

[0013] Furthermore, the method for constructing the access control policy tree includes:

[0014] Create an initial strategy tree and select a random number s as the polynomial q of the root node R in the initial strategy tree R The initial value of (x), i.e., q R (x) = s, where s∈Z P ;

[0015] Among them, Z P is the set of integers modulo P, q R (x) is a polynomial of the root node R, used to represent the access control rule;

[0016] For each non-root node x, set its polynomial q x (0) = q parent(x) [index(x)], the non-root node x is a node other than the root node R in the initial strategy tree;

[0017] Among them, index(x) is the branch number of the non-root node x in its parent node, parent(x) is the parent node of the non-root node x, and q x (0) is the value of the polynomial of the non-root node x at x=0;

[0018] For each node, random polynomial coefficients are selected to define its complete polynomial form and ensure that the highest degree of each node is its access threshold k x Subtract 1;

[0019] Among them, k x is the access threshold of non-root node x;

[0020] Repeat the above steps until the entire access control policy tree is recursively constructed.

[0021] Furthermore, the method for performing attribute-based encryption on the data plaintext includes: performing attribute-based encryption on the data plaintext through a bilinear mapping function and an access control policy tree, as follows:

[0022]

[0023] In the formula, CT represents the message ciphertext, T represents the access control policy tree, is represented as the first part of the message ciphertext, C is represented as the second part of the message ciphertext, Me(g,g) is a bilinear mapping function, α is the primary key value, s is a random number in the access control policy tree, h is a system parameter, y∈Y represents the set of all leaf nodes in the access control policy tree T, y is one of the leaf nodes, g is the generator of the finite cyclic group, and C y Characterized as the third part of the message ciphertext, C' y Represented as the fourth part of the message ciphertext, q y (0) is the value of the polynomial of leaf node y at 0, H[att(y)] is the hash value of leaf node y, Represents an arbitrary quantifier.

[0024] Furthermore, the method for obtaining the first feature based on the data plaintext includes:

[0025] Obtain the sender information of the data plaintext, determine the corresponding priority level based on the sender information, use the priority level as the priority feature, obtain the sending time of the data plaintext, calculate the time difference between the sending time and the current time, use the time difference as the timeliness feature, obtain the number of sensitive words in the data plaintext, and use the number of sensitive words as the sensitivity feature.

[0026] Furthermore, the method for determining whether to encrypt the data plaintext according to the first feature includes:

[0027] The first feature is input into the pre-built encryption classification model to obtain the encryption classification result. When the encryption classification result is encrypted, the data plaintext needs to be encrypted. The encryption classification result includes encryption and non-encryption.

[0028] The construction method of the encrypted classification model includes:

[0029] Get Q groups of data, where Q is a positive integer greater than 1, and the data includes the historical first feature and the historical encrypted classification results. Take the historical first feature and the historical encrypted classification results as sample sets, divide the sample sets into training sets and test sets, build a classifier, take the historical first feature in the training set as input data, take the historical encrypted classification results in the training set as output data, train the classifier to obtain an initial classifier, test the initial classifier using the test set, and output a classifier that meets the preset accuracy as an encrypted classification model.

[0030] Furthermore, the method of performing aggregate signing on the message ciphertext includes:

[0031] The cross-chain ciphertext is generated by multiplying the private key of each member with the hash value of the encrypted message, and adding the calculation results of all members, as follows:

[0032]

[0033] In the formula, AS is the cross-chain ciphertext, H(·) is the hash algorithm, n is the number of members, K i is the private key of the i-th member.

[0034] Furthermore, the method for verifying the cross-chain ciphertext includes:

[0035] Input the cross-chain ciphertext into the preset target equation to determine whether the target equation is established. If it is established, the verification is successful; if not, the verification is unsuccessful.

[0036] The target equation is:

[0037]

[0038] Where e(·) is a bilinear mapping function, G is a cyclic group on the elliptic curve, and P i is the public key of the i-th member.

[0039] Furthermore, the method for decrypting the cross-chain ciphertext includes:

[0040] The data plaintext is restored through the bilinear mapping function, the random number in the access control policy tree, and the master key value, as follows:

[0041]

[0042] In the formula, PT is the data plaintext, It is represented as the first part of the message ciphertext, s is the random number in the access control policy tree, α is the master key value, and β is the specific parameter value of the private key.

[0043] In the second aspect, a blockchain-based intelligent transportation vehicle collaborative management system is used to implement the above-mentioned blockchain-based intelligent transportation vehicle collaborative management method, including:

[0044] A judgment module: used for receiving the plaintext data transmitted by the sender, obtaining a first feature based on the plaintext data, and judging whether to encrypt the plaintext data according to the first feature;

[0045] Encryption module: when data plaintext needs to be encrypted, attribute-based encryption is performed on the data plaintext according to the pre-built access control policy tree to generate message ciphertext;

[0046] Processing module: used to aggregate the signature of the message ciphertext to generate the cross-chain ciphertext, and send the cross-chain ciphertext to the cross-chain node of the target chain. The target chain is the blockchain corresponding to the recipient.

[0047] Decryption module: used to verify the cross-chain ciphertext. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext.

[0048] Compared with the prior art, the present invention has the following beneficial effects:

[0049] The present invention first obtains a first feature based on the data plaintext, determines whether to encrypt the data plaintext according to the first feature, performs attribute-based encryption on the data plaintext according to a pre-built access control policy tree to generate a message ciphertext, then performs an aggregate signature on the message ciphertext to generate a cross-chain ciphertext, sends the cross-chain ciphertext to the cross-chain node of the target chain, and finally verifies the cross-chain ciphertext. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext. Through the above method, in the smart transportation vehicle network, cross-chain encryption and decryption between different blockchains can be achieved, thereby significantly improving the level of data privacy protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 This is a flowchart of the blockchain-based intelligent transportation vehicle collaborative management method of the present invention;

[0051] Figure 2 This is a schematic diagram of the structure of the blockchain-based intelligent transportation vehicle collaborative management system in the present invention;

[0052] Figure 3 Schematic diagram of plaintext cross-chain data transmission in the present invention. DETAILED DESCRIPTION

[0053] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0054] Example 1

[0055] See also Figure 1 As shown, this embodiment discloses a blockchain-based intelligent transportation vehicle collaborative management method, which is applied to data transmission between a sender and a receiver, including:

[0056] S10: receiving plaintext data transmitted by the sender, obtaining a first feature based on the plaintext data, and determining whether to encrypt the plaintext data according to the first feature;

[0057] In this embodiment, the sender can be a vehicle traveling on a road network, or it can be a roadside unit (RSU), a traffic management center, or other entities with data sending functions in the Internet of Vehicles. The above-mentioned plaintext data can be the vehicle's location information, speed information, vehicle status data (such as fuel level, power level, fault conditions, etc.), traffic flow information, road condition data, etc. The first feature includes a timeliness feature, a sensitivity feature, and a priority feature. The timeliness feature represents the timeliness of the data plaintext, the sensitivity feature represents the privacy of the data plaintext, and the priority feature represents the importance or urgency of the data plaintext.

[0058] The method for obtaining the first feature based on data plaintext includes:

[0059] Obtain the sender information of the data plaintext, determine the corresponding priority level based on the sender information, use the priority level as the priority feature, obtain the sending time of the data plaintext, calculate the time difference between the sending time and the current time, use the time difference as the timeliness feature, obtain the number of sensitive words in the data plaintext, and use the number of sensitive words as the sensitivity feature.

[0060] The sender information mentioned above can be the name information of the sender. Exemplarily, the name information of the sender can be a traffic management center, a roadside unit, an ordinary vehicle, and an emergency vehicle, etc. Normally, the priority level corresponding to the emergency vehicle is greater than the priority level corresponding to the traffic management center, and the priority level corresponding to the traffic management center is greater than the priority level corresponding to the roadside unit. We will not go into too much detail on this. It can be understood that the priority level is pre-set based on expert experience. Similarly, in this embodiment, a sensitive word library is pre-constructed. When there are corresponding sensitive words in the data plaintext, or there are words with a high similarity to the sensitive words, the number of sensitive words in the data plaintext is obtained. The similarity can be obtained by calculating the Euclidean distance or cosine similarity. Calculating the Euclidean distance or cosine similarity is a prior art, and this embodiment will not go into too much detail on this.

[0061] It should be added that, this embodiment determines whether to encrypt the plaintext data based on the first feature, taking the sensitivity feature as an example, the greater the sensitivity feature, the more the plaintext data must be encrypted, so as to achieve privacy protection of the plaintext data. It is understandable that the encryption operation will increase the volume of the data and the transmission time. If all data is encrypted, it will take up a lot of communication bandwidth and computing resources, especially in scenarios such as the Internet of Vehicles that require a quick response, which may cause data transmission delays. Therefore, this embodiment can reduce unnecessary encryption operations by encrypting only sensitive or high-priority data, thereby improving the overall efficiency of the system.

[0062] The method for determining whether to encrypt the data plaintext according to the first feature includes:

[0063] The first feature is input into the pre-built encryption classification model to obtain the encryption classification result. When the encryption classification result is encrypted, the data plaintext needs to be encrypted. The encryption classification result includes encryption and non-encryption.

[0064] The construction method of the encrypted classification model includes:

[0065] Acquire Q groups of data, where Q is a positive integer greater than 1, and the data includes the historical first feature and the historical encrypted classification results. The historical first feature and the historical encrypted classification results are used as sample sets, and the sample sets are divided into training sets and test sets. A classifier is constructed, and the historical first feature in the training set is used as input data, and the historical encrypted classification results in the training set are used as output data. The classifier is trained to obtain an initial classifier, and the initial classifier is tested using the test set. The initial classifier that meets the preset accuracy is output as an encrypted classification model, and the classifier is preferably a naive Bayes model or a support vector machine model.

[0066] It is understandable that when the encryption classification result is encrypted, the plaintext data needs to be specially encrypted. When the encryption classification result is non-encrypted, the plaintext data can be uploaded directly, or simply processed in a way similar to public key and private key before uploading.

[0067] S20: When the data plaintext needs to be encrypted, attribute-based encryption is performed on the data plaintext according to the pre-built access control policy tree to generate a message ciphertext;

[0068] In this embodiment, the access control policy tree refers to a structured policy model for defining and managing data access rights. It usually describes the accessor's permission requirements and data access control rules based on attributes. The access control policy tree represents different access conditions and policies through nodes. Each node may represent a specific attribute requirement (such as role, identity, permission level, etc.). The combination of these conditions is used to control which users or entities can access the data.

[0069] The access control policy tree construction method includes:

[0070] Create an initial strategy tree and select a random number s as the polynomial q of the root node R in the initial strategy tree R The initial value of (x), i.e., q R (x) = s, where s∈Z P ;

[0071] Among them, Z P is the set of integers modulo P, qR (x) is a polynomial of the root node R, used to represent the access control rule;

[0072] For each non-root node x, set its polynomial q x (0) = q parent(x) [index(x)], the non-root node x is a node other than the root node R in the initial strategy tree;

[0073] Among them, index(x) is the branch number of the non-root node x in its parent node, parent(x) is the parent node of the non-root node x, and q x (0) is the value of the polynomial of the non-root node x at x=0;

[0074] For each node, random polynomial coefficients are selected to define its complete polynomial form and ensure that the highest degree of each node is its access threshold k x Subtract 1;

[0075] Among them, k x is the access threshold of non-root node x;

[0076] Repeat the above steps until the entire access control policy tree is recursively constructed.

[0077] It should be noted that, in this embodiment, the method for creating an initial policy tree can be to use attributes (such as user attributes, resource attributes, environmental attributes, etc.) to define access policies, and these attributes can be organized into an initial policy tree, in which each node represents an attribute condition, and is implemented using an existing ABAC framework (such as XACML). By writing ABAC policy rules, the conditions and logical relationships of each node are defined, and the initial policy tree is constructed.

[0078] It should be added that the module P represents the base of a modular operation, for example, Z P represents the set of all non-negative integers less than P, namely: {0,1,2,…,p-1}, where p is the cardinality of the modular operation, defined as a positive integer, Z P It is a finite field, usually used for modular operations in cryptography and data security to ensure that the calculation result is always a value within a finite integer range. In the construction of the access control policy tree, modulo p is used to define the coefficients and calculation results of the polynomial. Through the modulo p operation, it can be ensured that all values ​​are within a fixed range to prevent overflow or uncontrolled numerical growth.

[0079] In this embodiment, the polynomial of the root node R is initialized to provide the basis for the access control policy tree. The root node usually represents the control logic of the highest level. The polynomial of the root node R is generated as the starting point of the tree to start building the access control logic. The purpose of setting the polynomial for each non-root node x is to ensure that the polynomial of each non-root node is associated with the polynomial of its parent node to maintain the structure and logic of the entire access control policy tree. In this way, the relationship between nodes is established, making the access control policy tree a coherent whole, ensuring the consistency of data access rights at all levels.

[0080] In the above, for the root node R, a random number s is selected as the initial value of the polynomial, while for the non-root node x, the value of the polynomial is generated based on the polynomial of its parent node. Therefore, in order to determine the complete polynomial form of each node, random coefficients are selected to define the remaining polynomial terms, so that the polynomial of each node forms a unique functional relationship to meet the requirements of access control.

[0081] In the above, ensure that the highest order of each node is its access threshold k x The purpose of subtracting 1 is that when the highest degree of the polynomial of each node is its access threshold k x Subtracting 1 ensures that the polynomial has k x -1 coefficient, which means that if and only if there are at least k x The polynomial of the node can be reconstructed only when the child nodes (or attributes) meet the access condition. For example, if the threshold k x =3, the polynomial is a quadratic polynomial (the highest order is 2), which means that at least 3 correct attributes or child nodes are required to decrypt the data.

[0082] From the above content, it can be seen that this embodiment defines the polynomial by selecting a random number s and a random coefficient to ensure that the polynomial form of each node is unique and unpredictable. This method increases the difficulty for attackers to guess and reconstruct the policy tree, thereby enhancing the security of the system. At the same time, the custom-created policy tree can be customized and optimized according to specific access control requirements to better adapt to the diversity and complexity of actual application scenarios. In addition, since the polynomials and coefficients of the policy tree are randomly generated, the structure and content of the policy tree are not easily speculated and analyzed by the outside world, thereby further enhancing the privacy protection of users and data.

[0083] The method for performing attribute-based encryption on data plaintext includes: performing attribute-based encryption on data plaintext through a bilinear mapping function and an access control policy tree;

[0084] Specific methods include:

[0085]

[0086] In the formula, CT represents the message ciphertext, T represents the access control policy tree, is represented as the first part of the message ciphertext, C is represented as the second part of the message ciphertext, Me(g,g) is a bilinear mapping function, α is the primary key value, s is a random number in the access control policy tree, h is a system parameter, y∈Y represents the set of all leaf nodes in the access control policy tree T, y is one of the leaf nodes, g is the generator of the finite cyclic group, and C y Characterized as the third part of the message ciphertext, C' y Represented as the fourth part of the message ciphertext, q y (0) is the value of the polynomial of leaf node y at 0, H[att(y)] is the hash value of leaf node y, Represents an arbitrary quantifier.

[0087] It should be noted that T represents the access control policy tree, which defines the rules or policies for access control. Each node of the policy tree represents an attribute condition, and the root node defines the combination rules of the attributes, such as logical "and" and "or". These rules determine who has the right to access the data. In attribute-based encryption, the access control policy tree T is used to limit the users who can decrypt the message ciphertext. Only users who meet all the attribute conditions in the access control policy tree T can decrypt correctly.

[0088] It should be added that the message ciphertext consists of four parts: C.C y and C' y , the above Me(g,g) is a bilinear mapping function, which maps two group elements into a new group element, which is used to construct encrypted ciphertext to ensure that only users who meet the policy can decrypt. g is a generator of a cyclic group, which generates all possible elements in the group. α is part of the master key, s is a random number in the access control policy tree, which ensures the randomness and security of encryption. The exponential part of αs is added to enhance security and prevent the content of the ciphertext from being speculated and cracked. C is the second part of the ciphertext, where h is a system parameter. This item is used for part of the calculation in encryption to ensure that only users with the correct key can decrypt.

[0089] In this embodiment, for each leaf node y, the following two parts of ciphertext are calculated:

[0090] Here g is the generator of the group, q y (0) is the value of the polynomial at leaf node y at 0. This polynomial is recursively generated from the policy polynomial of the parent node, ensuring that the polynomial value of each node is associated with its parent node. In this way, the encryption policy is embedded in the polynomial generation process, ensuring that only users who meet the policy conditions can decrypt.

[0091] H[att(y)] is the hash value of attribute y. The hash function H(·) is used to map the attribute to a group element so that it can participate in encryption calculation. y (0) is the value of the polynomial at 0, which represents the constraint of the policy tree. Only users with the correct attributes can use their decryption keys to decrypt this part of the ciphertext.

[0092] This embodiment implements attribute-based encryption of data by combining policy trees, polynomial generation, random numbers and bilinear mapping, ensuring that only users who meet policy conditions can decrypt the data, thereby achieving effective access control and privacy protection of the data. This method enhances the security and confidentiality of the system through randomness, mathematical operations and the flexibility of encryption strategies.

[0093] S30: Perform aggregate signature on the message ciphertext to generate a cross-chain ciphertext, and send the cross-chain ciphertext to the cross-chain node of the target chain, where the target chain is the blockchain corresponding to the recipient;

[0094] Methods for performing aggregate signature on message ciphertext include:

[0095] The cross-chain ciphertext is generated by multiplying the private key of each member with the hash value of the encrypted message and adding the calculation results of all members together;

[0096] Specific methods include:

[0097]

[0098] In the formula, AS is the cross-chain ciphertext, H(·) is the hash algorithm, n is the number of members, K i is the private key of the i-th member.

[0099] It should be noted that if Figure 3 As shown, in this embodiment, the message ciphertext is first aggregated and signed in the source chain. The source chain is the initial storage location of the data, where the data is encrypted and protected. It can be a specific blockchain network, which is mainly responsible for the generation, storage and preliminary management of data. The source chain interacts with other chains (target chains) through cross-chain contracts or cross-chain nodes to securely transfer data from the source chain to the target chain. After the cross-chain node reads the data on the source chain, it can initiate a data sharing request to the target chain according to predefined rules and protocols. The source chain has several alliance members, which refer to different entities or organizations involved in the operation and governance of the source chain. In the blockchain of the Internet of Vehicles, alliance members can be network operators, communication service providers, and cloud service providers, etc. The private key mentioned above is the secret information unique to the member. The private key is usually used to generate a digital signature to prove that the source of the data is legal and that the data has not been tampered with.

[0100] In this embodiment, each alliance member signs the message ciphertext with its private key, generates the signature part through the hash algorithm, and merges the signatures of all members into an aggregate signature (AS). This method ensures the integrity and authenticity of the message and prevents data tampering and forgery during cross-chain transmission. Through the aggregate signature method, the signatures of multiple alliance members are merged into a single signature, which reduces the amount of calculation in the verification process and improves the efficiency of cross-chain data sharing. In this way, the target chain only needs to verify one aggregate signature instead of verifying the signature of each member one by one.

[0101] It should be added that, combined with the encryption of step S20 and the aggregate signature of step S30, the target chain only needs to verify one aggregate signature, without verifying the signature of each member one by one, thereby reducing the amount of calculation and time consumption. This method not only ensures data security, but also significantly improves the efficiency of data sharing and transmission.

[0102] S40: Verify the cross-chain ciphertext. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext.

[0103] In this embodiment, after the data plaintext is encrypted and the aggregate signature is generated, the cross-chain node of the source chain forwards the cross-chain ciphertext to the cross-chain node of the target chain. After receiving the message, the cross-chain node of the target chain verifies the aggregate signature to ensure the correctness of the signature. Then users who meet the decryption authority can decrypt the cross-chain ciphertext. In this way, data can be shared across chains between different chains and ensure corresponding authorization and verification.

[0104] Among them, the methods for verifying cross-chain ciphertext include:

[0105] Input the cross-chain ciphertext into the preset target equation to determine whether the target equation is established. If it is established, the verification is successful; if not, the verification is unsuccessful.

[0106] The target equation is:

[0107]

[0108] Where e(·) is a bilinear mapping function, G is a cyclic group on the elliptic curve, and P i is the public key of the i-th member.

[0109] It should be noted that a cyclic group is a mathematical structure, commonly used in the field of cryptography. Its elements are points on the elliptic curve. The generator of the group is a specific point g, and the bilinear mapping function is usually a pairing function, which is used to map points in two elliptic curve groups to a target group. It is used to verify certain properties in elliptic curve encryption. The bilinear mapping function has two key features. The first is that for all a, b∈Z P , that is, there exists e(g a ,g b )=e(g,g) ab , which means that if two numbers are given as powers, the bilinear map can multiply them. Secondly, if e(g,g)=1, then it is only true when g=1, which ensures that the mapping does not lose information. In the verification process of this embodiment, the target equation utilizes the characteristics of the bilinear map to convert the cross-chain ciphertext AS into a verifiable format. If the equation holds, it means that the signature is valid, that is, the signature parts of all alliance members are correctly aggregated.

[0110] In this embodiment, the difficulty of bilinear mapping and elliptic curve discrete logarithm problem ensures that attackers cannot easily crack the private key, and the use of hash function can ensure the consistency of the original message. Any change to the message will cause the hash value to change, thereby causing signature verification failure.

[0111] Methods for decrypting cross-chain ciphertext include:

[0112] Recover the data plaintext through the bilinear mapping function, the random number in the access control policy tree and the master key value;

[0113] Specific methods include:

[0114]

[0115] In the formula, PT is the data plaintext, It is represented as the first part of the message ciphertext, s is the random number in the access control policy tree, α is the master key value, and β is the specific parameter value of the private key.

[0116] It should be noted that β is a specific parameter value in the private key, which refers to a specific value of the private key of a member in the source chain. In the attribute-based encryption process, the attribute strategy and the master key value α are used to encrypt the plaintext data. In order to decrypt this data, the master key value α and the specific parameter β in the private key must be used at the same time to ensure that only users who meet the specific access policy have decryption authority.

[0117] The decryption process uses the parameters in the formula (such as the master key value α and the private key parameter β) to calculate the data plaintext. This calculation process relies on the characteristics of the bilinear mapping to ensure that decryption can only be performed correctly when the user's attributes meet the corresponding ciphertext strategy.

[0118] Specifically, the decryption process of the formula is: restore the data plaintext by offsetting the influence of the random number s and the master key value α introduced in the encryption process. When decrypting, recursively calculate from the leaf node to the root node, and gradually use the user's private key and attribute information to decrypt each part of the ciphertext. The power operation and division operation of the bilinear mapping function are combined to offset the random number s and the master key α introduced in the encryption, and finally restore the data plaintext.

[0119] In this embodiment, first, a first feature is obtained based on the data plaintext, and it is determined whether to encrypt the data plaintext according to the first feature. The data plaintext is encrypted based on the attribute according to the pre-built access control policy tree to generate a message ciphertext. Then, the message ciphertext is aggregated and signed to generate a cross-chain ciphertext. The cross-chain ciphertext is sent to the cross-chain node of the target chain. Finally, the cross-chain ciphertext is verified. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext. In the above manner, in the smart transportation vehicle network, cross-chain encryption and decryption between different blockchains can be achieved, thereby significantly improving the level of data privacy protection.

[0120] Example 2

[0121] See also Figure 2 As shown, based on the same inventive concept, this embodiment discloses a blockchain-based intelligent transportation vehicle collaborative management system. For details not provided in this embodiment, please refer to the description of the relevant parts in Embodiment 1. The system includes:

[0122] A judgment module: used for receiving the plaintext data transmitted by the sender, obtaining a first feature based on the plaintext data, and judging whether to encrypt the plaintext data according to the first feature;

[0123] In this embodiment, the sender can be a vehicle traveling on a road network, or it can be a roadside unit (RSU), a traffic management center, or other entities with data sending functions in the Internet of Vehicles. The above-mentioned plaintext data can be the vehicle's location information, speed information, vehicle status data (such as fuel level, power level, fault conditions, etc.), traffic flow information, road condition data, etc. The first feature includes a timeliness feature, a sensitivity feature, and a priority feature. The timeliness feature represents the timeliness of the data plaintext, the sensitivity feature represents the privacy of the data plaintext, and the priority feature represents the importance or urgency of the data plaintext.

[0124] The method for obtaining the first feature based on data plaintext includes:

[0125] Obtain the sender information of the data plaintext, determine the corresponding priority level based on the sender information, use the priority level as the priority feature, obtain the sending time of the data plaintext, calculate the time difference between the sending time and the current time, use the time difference as the timeliness feature, obtain the number of sensitive words in the data plaintext, and use the number of sensitive words as the sensitivity feature.

[0126] The method for determining whether to encrypt the data plaintext according to the first feature includes:

[0127] The first feature is input into the pre-built encryption classification model to obtain the encryption classification result. When the encryption classification result is encrypted, the data plaintext needs to be encrypted. The encryption classification result includes encryption and non-encryption.

[0128] The construction method of the encrypted classification model includes:

[0129] Acquire Q groups of data, where Q is a positive integer greater than 1, and the data includes the historical first feature and the historical encrypted classification results. The historical first feature and the historical encrypted classification results are used as sample sets, and the sample sets are divided into training sets and test sets. A classifier is constructed, and the historical first feature in the training set is used as input data, and the historical encrypted classification results in the training set are used as output data. The classifier is trained to obtain an initial classifier, and the initial classifier is tested using the test set. The initial classifier that meets the preset accuracy is output as an encrypted classification model, and the classifier is preferably a naive Bayes model or a support vector machine model.

[0130] It is understandable that when the encryption classification result is encrypted, the plaintext data needs to be specially encrypted. When the encryption classification result is non-encrypted, the plaintext data can be uploaded directly, or simply processed in a way similar to public key and private key before uploading.

[0131] Encryption module: when data plaintext needs to be encrypted, attribute-based encryption is performed on the data plaintext according to the pre-built access control policy tree to generate message ciphertext;

[0132] In this embodiment, the access control policy tree refers to a structured policy model for defining and managing data access rights. It usually describes the accessor's permission requirements and data access control rules based on attributes. The access control policy tree represents different access conditions and policies through nodes. Each node may represent a specific attribute requirement (such as role, identity, permission level, etc.). The combination of these conditions is used to control which users or entities can access the data.

[0133] The access control policy tree construction method includes:

[0134] Create an initial strategy tree and select a random number s as the polynomial q of the root node R in the initial strategy tree R The initial value of (x), i.e., q R (x) = s, where s∈Z P ;

[0135] Among them, Z P is the set of integers modulo P, q R (x) is a polynomial of the root node R, used to represent the access control rule;

[0136] For each non-root node x, set its polynomial q x (0) = q parent(x) [index(x)], the non-root node x is a node other than the root node R in the initial strategy tree;

[0137] Among them, index(x) is the branch number of the non-root node x in its parent node, parent(x) is the parent node of the non-root node x, and q x (0) is the value of the polynomial of the non-root node x at x=0;

[0138] For each node, random polynomial coefficients are selected to define its complete polynomial form and ensure that the highest degree of each node is its access threshold k x Subtract 1;

[0139] Among them, k x is the access threshold of non-root node x;

[0140] Repeat the above steps until the entire access control policy tree is recursively constructed.

[0141] Processing module: used to aggregate the signature of the message ciphertext to generate the cross-chain ciphertext, and send the cross-chain ciphertext to the cross-chain node of the target chain. The target chain is the blockchain corresponding to the recipient.

[0142] Decryption module: used to verify the cross-chain ciphertext. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext;

[0143] In this embodiment, after the data plaintext is encrypted and the aggregate signature is generated, the cross-chain node of the source chain forwards the cross-chain ciphertext to the cross-chain node of the target chain. After receiving the message, the cross-chain node of the target chain verifies the aggregate signature to ensure the correctness of the signature. Then users who meet the decryption authority can decrypt the cross-chain ciphertext. In this way, data can be shared across chains between different chains and ensure corresponding authorization and verification.

[0144] Among them, the methods for verifying cross-chain ciphertext include:

[0145] Input the cross-chain ciphertext into the preset target equation to determine whether the target equation is established. If it is established, the verification is successful; if not, the verification is unsuccessful.

[0146] The target equation is:

[0147]

[0148] Where e(·) is a bilinear mapping function, G is a cyclic group on the elliptic curve, and P i is the public key of the i-th member.

[0149] Methods for decrypting cross-chain ciphertext include:

[0150]

[0151] In the formula, PT is the data plaintext, It is represented as the first part of the message ciphertext, s is the random number in the access control policy tree, α is the master key value, and β is the specific parameter value of the private key.

[0152] It should be noted that β is a specific parameter value in the private key, which refers to a specific value of the private key of a member in the source chain. In the attribute-based encryption process, the attribute strategy and the master key value α are used to encrypt the plaintext data. In order to decrypt this data, the master key value α and the specific parameter β in the private key must be used at the same time to ensure that only users who meet the specific access policy have decryption authority.

[0153] The decryption process uses the parameters in the formula (such as the master key value α and the private key parameter β) to calculate the data plaintext. This calculation process relies on the characteristics of the bilinear mapping to ensure that decryption can only be performed correctly when the user's attributes meet the corresponding ciphertext strategy.

[0154] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters, weights and thresholds in the formula are set by technicians in this field according to actual conditions.

[0155] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

[0156] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A blockchain-based intelligent transportation vehicle collaborative management method is applied to data transmission between a sender and a receiver, characterized in that: include: receiving plaintext data transmitted by a sender, obtaining a first feature based on the plaintext data, and determining whether to encrypt the plaintext data according to the first feature; When the data plaintext needs to be encrypted, attribute-based encryption is performed on the data plaintext according to the pre-built access control policy tree to generate the message ciphertext; Aggregate signature is performed on the message ciphertext to generate cross-chain ciphertext, and the cross-chain ciphertext is sent to the cross-chain node of the target chain. The target chain is the blockchain corresponding to the recipient. The cross-chain ciphertext is verified. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext.

2. The blockchain-based intelligent transportation vehicle collaborative management method according to claim 1 is characterized in that: The method for constructing the access control policy tree includes: Create an initial strategy tree and select a random number s as the polynomial q of the root node R in the initial strategy tree R The initial value of (x), i.e., q R (x) = s, where s∈Z P ; Among them, Z P is the set of integers modulo P, q R (x) is a polynomial of the root node R, used to represent the access control rule; For each non-root node x, set its polynomial q x (0) = q parent(x) [index(x)], the non-root node x is a node other than the root node R in the initial strategy tree; Among them, index(x) is the branch number of the non-root node x in its parent node, parent(x) is the parent node of the non-root node x, and q x (0) is the value of the polynomial of the non-root node x at x=0; For each node, random polynomial coefficients are selected to define its complete polynomial form and ensure that the highest degree of each node is its access threshold k x Subtract 1; Among them, k x is the access threshold of non-root node x; Repeat the above steps until the entire access control policy tree is recursively constructed.

3. The blockchain-based intelligent transportation vehicle collaborative management method according to claim 2 is characterized in that: The method for performing attribute-based encryption on data plaintext includes: performing attribute-based encryption on data plaintext through a bilinear mapping function and an access control policy tree.

4. The blockchain-based intelligent transportation vehicle collaborative management method according to claim 1 is characterized in that: The method for obtaining the first feature based on data plaintext includes: Obtain the sender information of the data plaintext, determine the corresponding priority level based on the sender information, use the priority level as the priority feature, obtain the sending time of the data plaintext, calculate the time difference between the sending time and the current time, use the time difference as the timeliness feature, obtain the number of sensitive words in the data plaintext, and use the number of sensitive words as the sensitivity feature.

5. The blockchain-based intelligent transportation vehicle collaborative management method according to claim 4 is characterized in that: The method for determining whether to encrypt the data plaintext according to the first feature includes: Input the first feature into the pre-built encryption classification model to obtain the encryption classification result. When the encryption classification result is encrypted, the data plaintext needs to be encrypted. The encryption classification result includes encryption and non-encryption. The construction method of the encrypted classification model includes: Get Q groups of data, where Q is a positive integer greater than 1, and the data includes the historical first feature and the historical encrypted classification results. Take the historical first feature and the historical encrypted classification results as sample sets, divide the sample sets into training sets and test sets, build a classifier, take the historical first feature in the training set as input data, take the historical encrypted classification results in the training set as output data, train the classifier to obtain an initial classifier, test the initial classifier using the test set, and output the initial classifier that meets the preset accuracy as the encrypted classification model.

6. The blockchain-based intelligent transportation vehicle collaborative management method according to claim 3 is characterized in that: The method for performing aggregate signing on a message ciphertext comprises: The calculation result is obtained by multiplying the private key of each member with the hash value of the encrypted message, and the calculation results of all members are added together to generate the cross-chain ciphertext.

7. The blockchain-based intelligent transportation vehicle collaborative management method according to claim 6 is characterized in that: The method for verifying the cross-chain ciphertext includes: Input the cross-chain ciphertext into the preset target equation to determine whether the target equation is established. If so, the verification is successful; if not, the verification is unsuccessful. The target equation is: Where e(·) is a bilinear mapping function, G is a cyclic group on the elliptic curve, and P i is the public key of the i-th member, CT is the message ciphertext, AS is the cross-chain ciphertext, n is the number of members, and H(·) is the hash algorithm.

8. The blockchain-based intelligent transportation vehicle collaborative management method according to claim 7 is characterized in that: The method for decrypting the cross-chain ciphertext includes: The data plaintext is recovered through the bilinear mapping function, the random number in the access control policy tree and the master key value.

9. A blockchain-based intelligent transportation vehicle collaborative management system, which is used to implement the blockchain-based intelligent transportation vehicle collaborative management method described in any one of claims 1 to 8, characterized in that: include: A judgment module: used for receiving the plaintext data transmitted by the sender, obtaining a first feature based on the plaintext data, and judging whether to encrypt the plaintext data according to the first feature; Encryption module: when data plaintext needs to be encrypted, attribute-based encryption is performed on the data plaintext according to the pre-built access control policy tree to generate message ciphertext; Processing module: used to aggregate the signature of the message ciphertext to generate the cross-chain ciphertext, and send the cross-chain ciphertext to the cross-chain node of the target chain. The target chain is the blockchain corresponding to the recipient. Decryption module: used to verify the cross-chain ciphertext. When the verification is successful, the cross-chain ciphertext is sent to the recipient, and the recipient decrypts the cross-chain ciphertext.

Citation Information

Patent Citations

  • User privacy protection scheme for car hailing based on blockchain

    CN110365485A

  • Vehicle privacy protection method based on cloud storage block chain in Internet of Vehicles

    CN116760619A

  • Ciphertext revocable attribute encryption-based urban Internet of Vehicles cross-chain method and system

    CN118233861A

  • Encryption transmission method based on power distribution data

    CN118381659A

  • Access control method based on ciphertext policy attribute-based encryption on block chain

    CN119094219A

Cited By

  • Smart city sensitive data information hierarchical access control method and system

    CN122137681A