Supply chain data security and access control method capable of revoking attribute encryption

By combining revocable attribute encryption and blockchain technology, it is possible to efficiently revoke permissions without re-encryption in a dynamic supply chain environment, and ensure the security of cross-chain revocation operations, solving the problem of difficulty in guaranteeing permission revocation and security in the existing technology.

CN120128360APending Publication Date: 2025-06-10JIANGXI UNIV OF SCI & TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510191185.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In a dynamic supply chain environment, it is difficult for the prior art to effectively realize permission revocation without re-encryption, while ensuring the anti-collective security of cross-chain revocation operations.

Method used

Combining revocable attribute encryption and blockchain technology, the dynamic management of data access rights is achieved through smart contracts, flexible permission revocation operations are supported, and distributed storage is carried out through IPFS technology to ensure data integrity and traceability.

Benefits of technology

It realizes efficient revocation of permissions without re-encryption, and ensures the security of cross-chain revocation operations, improving the efficiency of the overall system and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128360A_ABST
    Figure CN120128360A_ABST
Patent Text Reader

Abstract

The invention discloses a supply chain data security and access control method capable of revoking attribute encryption. A safe access control mechanism is established among all parties in a supply chain by utilizing a block chain technology and a revocable attribute encryption algorithm, so that the privacy and safety of key data such as product information, transaction records and inventory states are ensured. Through the combination of the smart contract and the block chain technology, the data access authority can be dynamically revoked and updated, and the security, transparency and non-tampering performance of the data are ensured. In addition, decentralized data storage is realized by using IPFS, and the overall security and data processing efficiency of the system are improved through an access control strategy, a block chain consensus mechanism and an intelligent monitoring platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data encryption and access control, and particularly relates to a data security and access control method based on revocable attribute encryption (RABE) and blockchain technology, which is applied to the security management, storage and sharing of data in the supply chain. Background Art

[0002] In the past decade, the digitization and networking of the supply chain have also raised issues regarding data security and access control, especially in terms of how to efficiently and securely share sensitive data involved in the supply chain. The supply chain management system involves multiple stakeholders, such as suppliers, producers, distributors, and end-users, etc. The supply chain system is gradually facing the need for large-scale data sharing and transmission. However, there are still significant security risks in the existing supply chain system in terms of data transmission, storage, and access control. Especially in the data storage and sharing links, issues such as data security, privacy protection, and permission management need to be urgently solved.

[0003] Traditional data management methods are prone to problems such as information leakage, data tampering, and improper supply chain management when faced with complex supply chain structures. In the application of blockchain technology, although it can provide distributed data storage and immutability, in practical applications, how to ensure fine-grained control of data access permissions and how to avoid blockchain capacity limitations while ensuring high efficiency are still challenges that need to be solved urgently. Therefore, combining attribute-based encryption technology, especially the revocable attribute-based encryption scheme, can provide more flexible access control and higher data security. When the access permission changes, how to effectively revoke its decryption ability. In revocable attribute encryption, it is allowed that the data owner can revoke or update the access permissions of some users without re-encrypting the data, ensuring that only authorized users can decrypt the data. This mechanism is particularly important for the dynamically changing supply chain environment, where the identities and permissions of users often change. Wang et al. proposed a supply chain security scheme based on revocable attribute encryption and blockchain in "Revocable Attribute-based Encryption with Blockchain for Supply Chain Security in Smart Manufacturing", Computers, Materials & Continua, 2023, 71(2), which is applied to the field of smart manufacturing. The research focus is on how to use the transparency of blockchain and revocable encryption technology to protect data security and access control in the supply chain, especially applicable to the supply chain management of bulk commodities such as steel. Zhou, L et al. proposed a privacy protection scheme combining blockchain and revocable attribute encryption in "A Blockchain-based Data Privacy Protection Scheme with Revocable Attribute-based Encryption for Industrial IoT", Journal of Industrial Information Integration, 2023, 25(10), which is used for data access control in the industrial Internet of Things (IIoT) environment. Through the immutability of blockchain and the flexible access control of revocable attribute encryption, this scheme effectively guarantees the security and privacy of sensitive data.Li, H et al. proposed an efficient data protection scheme combining revocable attribute encryption and blockchain technology in "An Efficient and Revocable Attribute-based Encryption Scheme with Blockchain for Industrial Data Protection" in *Security and Privacy in Communication Networks* 2021, 135 - 147. This scheme is specifically applied to the industrial field, especially for the security issues of the steel supply chain. The scheme uses blockchain technology to ensure data integrity and provides flexible access control and revocation functions through the RABE mechanism. In the steel supply chain, blockchain can be used to record and track the whole process of transactions, ensuring that the data in each link of the supply chain will not be tampered with. In addition, blockchain can be combined with ABE to achieve refined management of data access. Gupta, R et al. proposed a hybrid model combining blockchain and attribute encryption technology in "Blockchain and Attribute-Based Encryption: A Hybrid Model for Secure and Efficient Data Sharing in Supply Chains" in *Journal of Network and Computer Applications* 2021, which is applied to secure data sharing in the supply chain. This model solves the problems of data sharing, security, access control, etc. in the steel supply chain and adopts the RABE technology to provide higher flexibility. Summary of the Invention

[0004] The object of the present invention is to provide a data security and access control method based on revocable attribute encryption and blockchain technology in view of the problems existing in the prior art. The present invention is committed to solving the core contradiction caused by permission changes in a dynamic supply chain environment: how to achieve permission revocation without re-encryption while ensuring the anti-collusion security of cross-chain revocation operations. This method encrypts the data transmitted and stored in the supply chain by combining revocable attribute encryption and blockchain technology to ensure data security and privacy. Through blockchain smart contracts, dynamic management of data access permissions is realized, supporting flexible permission revocation operations. By using IPFS technology, encrypted data is stored in a distributed network to avoid the risks brought by traditional centralized storage. At the same time, the blockchain records the stored hash value to ensure data integrity and traceability. By introducing a pre-decryption process, the overhead of key update and re-encryption of encrypted data caused by attribute revocation is reduced, thus improving the overall efficiency of the system.

[0005] The present invention is used to process operations such as data access control, permission update, and revocation. The smart contract ensures the immutability and transparency of operations through the decentralized characteristics of the blockchain, ensuring the credibility of data and permission management. The algorithm is used to generate a public key PK and a master private key, where is the public key for use in data encryption. The private key query and generation algorithm generates a user private key based on the master key and the attribute set. The generation of the private key is based on the attribute set, and the security of the private key is ensured through a random number generation mechanism. The data encryption process uses the public key, access policy, and plaintext message to generate ciphertext. This process involves the generation of random numbers to enhance the security of encryption, and the encrypted data is uploaded to the IPFS storage system. The ciphertext is initially decrypted using the private key. If the attribute set conforms to the access policy, the decryption process will provide a basis for decrypting the final message. The final decryption process combines the first private key, the second private key, and the time token to recover the plaintext message. By using blockchain technology to store encryption keys and access tokens, the transparency, auditability, and immutability of key management are ensured. The blockchain network transfers encrypted data between each participating party in the entire supply chain, manages data access control and permission verification through smart contracts, ensuring that only eligible users can access the corresponding supply chain information. All sensitive data is distributedly stored through IPFS to reduce single points of failure and ensure efficient and secure access to data.

[0006] The present invention adopts an attribute-based access control policy, dynamically generates access keys and tokens according to user attributes, and conducts real-time verification and authorization of access requests through the blockchain to ensure the compliance and security of data access. The specific implementation is as follows:

[0007] (S01): The central authority CA performs system initialization, Setup(1 λ ) → (PK, MSK) generates the global public key PK and the master private key MSK through the initialization algorithm. This process includes setting the parameters of the encryption system and generating the key pair required for encryption. According to the attribute set S of the participating party, such as supplier identity, role, permission level, etc., the private key of the participating party is generated using the key generation algorithm KeyGen(MSK, S) → sk to control the access permission.

[0008] (S02): Data Encryption and Decryption. During the data encryption process, the public key PK and the attribute set S are used to encrypt sensitive data in the supply chain, such as order information, inventory data, etc. Encrypt(PK, (M, ρ), msg) → Ct. Input the public key PK, access policy (M, ρ), plaintext msg, and output the ciphertext Ct. This process encrypts the plaintext into ciphertext using the access policy to ensure that only eligible users can decrypt it. During the data decryption process, the participating party uses the private key sk and the attribute set S to decrypt the ciphertext. Only when the attribute set of the participating party meets the access policy can the decryption be successful. Decrypt(PK, Ct, sk) → msg, output the plaintext msg. This process decrypts the ciphertext using the attribute private key to restore the original plaintext. Only users who meet the access policy can successfully decrypt it.

[0009] (S03): Access Token Generation Algorithm, (S, sk 2 , params) → TK t , input the attribute set S, which is the attribute set of the data user, and randomly select from the multiplicative group modulo p Randomly select d from the additive group modulo p 1 , d 2 , d 3 ∈Z p . For each attribute i ∈ S, calculate the attribute index index i =H 2 (i), where H 2 is a hash function used to map the attribute i to an index value. Combine the attribute private key sk 2 , system parameters params, and output the access token TK t , and request access to the corresponding data. The process of generating the access token is as follows: Encrypt the attribute index index 2 using the private key sk i and system parameters params: where is the encryption operation, which depends on the private key sk 2 , generate the access token TK t =f(C i , e z , d 1 , d 2 , d 3 , d i and the randomly selected parameters e z , d 1 , d 2 , d 3 as well as the system parameters params to generate the access token TKt The system allows data requesters to query the required data through keywords and generate corresponding access tokens. The requester uses the token to apply for decrypting the data. The system verifies its access rights through the blockchain and retrieves the corresponding file from IPFS. Finally, the verified data is securely delivered to the requester. Such a system can utilize the decentralization and transparency of the blockchain, the efficient distributed storage of IPFS, and the flexible access control of attribute-based encryption to enhance data security, privacy protection, and access efficiency.

[0010] (S04): Pre-decryption algorithm, FirstDecrpt(Ct, sk 1 ) → firsrm, input ciphertext Ct and the user's first private key sk 1 , if the attribute set S satisfies the access policy (M, ρ), then there exists a coefficient w i ∈Z p such that where I = {i | ρ(i) ∈ S}. Calculate the pre-decryption intermediate plaintext: where, Ct 0,1 , Ct 0,2 , Ct 0,3 are three elements in the ciphertext component Ct 0 , and sk' and sk ρ(i) represent different parts of the private key.

[0011] (S05): Decryption algorithm, SecDecrypt(Ct, sk 2 ) → secm decryption intermediate plaintext calculation formula Intermediate parameter num calculation formula This process finally restores the complete plaintext by combining the pre-decryption and decryption steps.

[0012] (S06): Revocable attribute encryption mechanism. To implement the revocation function, the present invention introduces a revocable attribute encryption mechanism. Through the smart contract, when the user's attributes change, their original access rights are automatically revoked and the corresponding keys are updated. Revoke(sk, A): Revoke the private key sk corresponding to the attribute set A. Where, A is the revoked attribute set and sk is the private key of the user whose permissions need to be revoked. After tracing the identity of a malicious user, the Certificate Authority (CA) can take two measures to maintain system security and cancel the malicious user's account: one is to completely revoke all the user's permissions and prevent it from accessing any data in the system; the other is to only revoke some of the malicious user's attributes, making these attributes invalid for it, but other users can still retain and use these attributes. System initialization Setup(1 λ ) → (PK, MPK), randomly select new parameters a' 1 , a'2 , d' 1 , d' 2 , d' 3 , and generate a new public key and master private key: For each legitimate user, regenerate the attribute private key sk' user = KeyGen(MPK', S), re-encrypt the data: Ct' = Encrypt(PK', (M, ρ), msg), and update the attribute private key of the users involved in the revoked attribute: sk' user = KeyGen(MPK', S\{atr}), where atr is the revoked attribute. Re-encrypt the data using the new attribute private key: Ct' = Encrypt(PK', (M, ρ'), msg), where ρ' is the new attribute mapping excluding the revoked attribute. The CA also has the right to revoke a certain system attribute, rendering this attribute invalid in the system, and all users possessing this attribute can no longer use it: Keep the system parameters unchanged and only update the part related to the revoked attribute. Update the attribute private keys of all legitimate users. Through the above steps and formulas, the CA can effectively revoke the accounts or attributes of malicious users and ensure the secure revocation of system attributes, safeguarding the overall security of the system and the confidentiality of data.

[0013] The present invention integrates blockchain distributed ledger, smart contract, and revocable attribute encryption technologies to construct a three-tier data security system for the supply chain: Through intelligent block processing of order / inventory / logistics data, achieve unitized storage of structured data; Adopt a dynamic attribute-based encryption strategy to configure multi-dimensional access permissions, combined with a timestamp key refresh mechanism to ensure data timeliness security; Rely on the blockchain to construct a four-layer traceability architecture including operation evidence storage, contract execution, policy update, and cross-chain collaboration, improving the response efficiency of permission changes, with the unauthorized access recognition accuracy reaching 99.97%, effectively solving the problems of data rights confirmation and secure sharing in multi-party collaboration in the supply chain. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 It is the overall system framework diagram.

[0015] Figure 2 It is the system model.

[0016] Figure 3 It is the algorithm flow chart.

[0017] Figure 4 It is the time cost of the basic operations of ABE.

[0018] Figure 5 It is the comparison of key generation time.

[0019] Figure 6 It is the comparison of encryption time.

[0020] Figure 7 For decryption time comparison.

[0021] Figure 8 For public parameter communication overhead comparison.

[0022] Figure 9 For master key communication overhead comparison.

[0023] Figure 10 For user space key comparison.

[0024] Figure 11 For ciphertext communication overhead comparison.

[0025] Figure 12 For the comparison of the computational overhead between the present invention and typical DCPABE schemes.

[0026] Figure 13 For the deployment of smart contracts in the steel supply chain. Detailed implementation manners

[0027] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments.

[0028] In this embodiment, taking the steel supply chain as an example, the technical solution of the invention will be described in detail. The experimental results show that when dealing with large-scale attribute sets, both the pre-decryption and decryption times are stable at a constant level of about one hundred milliseconds, thus realizing efficient and fine-grained access control for blockchain data. As Figure 1 shown, the specific working process of the framework is as follows:

[0029] (1) Request for access: The data requester sends a request for accessing the target data to the blockchain platform.

[0030] (2) Access authorization: After the blockchain platform receives the access request initiated by the data requester, each smart contract of the access control module will be executed in sequence, retrieve the attribute information of the data requester and the access control policy information preset by the data provider from the distributed ledger, and perform attribute-based access control judgment. If the access control judgment is passed, the blockchain platform will return the encrypted data address and the access control token to the data requester.

[0031] (3) Request for access: The data requester can communicate with the data provider through other channels, explain to the data provider administrator the purpose of accessing the data resource, so as to request to obtain the private key of the data provider administrator. After obtaining the private key, the data address can be decrypted; then, using the access control token as one of the parameters, a data access request is sent to the database server of the data provider.

[0032] (4) Token authentication: After receiving the access request, the database server of the data provider will use the identity authentication module to authenticate the legitimacy of the access request. Through the distribution information of the access control token, it verifies that the access request was initiated by the data requester and that the data requester has passed the access control decision.

[0033] (5) Token authorization: After receiving the token authentication result, the data provider's database server responds to the data requester's data access request.

[0034] (6) Return data: Share the target data resources with the data demander.

[0035] like Figure 2 As shown in the figure, the present invention is composed of users, miners, smart contracts, storage nodes and trusted authorization agencies. Its main functions include ensuring data integrity through consensus mechanism, implementing dynamic access control by using attribute-based encryption, supporting time-based permission management, reducing storage pressure through decentralized storage, and providing transparent operation logs for auditing and behavior tracking. Figure 3 As shown, the present invention includes five components: system initialization, attribute private key generation, encryption, pre-decryption and decryption. Figure 4 As shown, the average results show that operations E, P, M, and H consume 1.32 milliseconds, 0.74 milliseconds, 0.0036 milliseconds, and 2.94 milliseconds, respectively. The efficiency and security of the system are evaluated by recording and analyzing the encryption and decryption time, smart contract transaction time, and IPFS access time. These simulation results will help optimize the system design, improve data storage and access performance, and ensure the actual application effect of the system in steel supply chain management.

[0036] After the simulation experiment was realized, Figure 5 Comparison of key generation time: When the number of users u = 50, the time to generate user keys in the scheme of the present invention and Han et al., Pattanayak et al., Zong et al. and Ge et al. is 1.3264 milliseconds, 74.8837 milliseconds, 86.6368 milliseconds, 149.76 milliseconds and 2.8874 milliseconds respectively. Compared with the scheme of the present invention, Han et al., Pattanayak et al., Zong et al. and Ge et al. save 98.23%, 98.47%, 99.11% and 54.06% of the key generation time respectively.

[0037] Figure 6Comparison of encryption time: When l = 50, the encryption time of the scheme of the present invention and Han et al., Pattanayak et al., Zong et al., and Ge et al. are 74.28 ms, 326.9 ms, 387.411 ms, 150.6 ms, and 73.47 ms, respectively. Compared with Han et al., the proposed scheme reduces the computational overhead by about 77.27%. This is a significant savings that can greatly improve the efficiency of the encryption process, especially in resource-constrained environments. Compared with Pattanayak et al., the proposed scheme reduces the computational overhead by about 80.83%. This further highlights the efficiency of the scheme, making it particularly attractive in applications that require high-speed encryption and have limited computing resources. Compared with Zong et al., the computational overhead is reduced by about 50.67%. However, compared with Ge et al., although the encryption time is slightly increased, this increase is equivalent to about 1.10% of the computational overhead, and the overall impact is small.

[0038] Figure 7 For decryption time comparison: When q=50, the decryption time of the scheme of the present invention and Han et al., Pattanayak et al., Zong et al. and Ge et al. are 115.68 milliseconds, 161.73 milliseconds, 204.39 milliseconds, 88.4 milliseconds and 146.28 milliseconds respectively. Compared with these schemes, the scheme of the present invention saves 28.46%, 43.43%, -23.59% and 20.92% of the decryption computation overhead respectively. In terms of decryption time, the scheme of the present invention saves time in most cases, especially compared with Pattanayak et al., the saving rate reaches 43.43%. However, compared with Ge et al., the decryption time of the scheme of the present invention increases.

[0039] Figure 8Comparison of public parameter communication overhead: The public parameter communication costs of the scheme of the present invention and those of Han et al., Pattanayak et al., Zong et al., and Ge et al. are 3072 bits, 103424 bits, 2048 bits, 4096 bits, and 5280 bits, respectively. Compared with the schemes of Han et al., Pattanayak et al., Zong et al., and Ge et al., the scheme of the present invention saves 97.02%, -50%, 25%, and 41.82% of the storage cost of public parameters, respectively. The scheme of the present invention shows significant savings in communication overhead, especially compared with Han et al., with a savings rate of up to 97.02%. However, compared with Pattanayak et al., the communication overhead of the scheme of the present invention increases slightly.

[0040] Figure 9 Comparison of master key communication overhead: The master key sizes of the scheme of the present invention and those of Han et al., Pattanayak et al., Zong et al., and Ge et al. are 1664 bits, 52224 bits, 8960 bits, 6144 bits, and 2208 bits, respectively. Compared with the schemes of Han et al., Pattanayak et al., Zong et al., and Ge et al., the scheme of the present invention saves 96.81%, 81.42%, 72.91%, and 24.64% of the encryption computation cost. In the comparison of the master key space, the performance of the scheme of the present invention is very outstanding, especially compared with Han et al., the saving rate is as high as 96.81%. Even when compared with other schemes, the saving rate is between 24.64% and 81.42%.

[0041] Figure 10 Comparison of user space keys: The user key storage costs of the scheme of the present invention and those of Han et al., Pattanayak et al., Zong et al., and Ge et al. are 2048 bits, 52224 bits, 52224 bits, 53248 bits, and 52224 bits, respectively. Compared with the schemes of Han et al., Pattanayak et al., Zong et al., and Ge et al., the scheme of the present invention reduces the user key storage cost by 96.08%, 96.08%, 96.15%, and 96.08%, respectively. In the comparison of user key storage space, the scheme of the present invention shows significant savings among all the schemes, with a saving rate of about 96%.

[0042] Figure 11Communication overhead comparison of ciphertext: For |m| = 10, the ciphertext sizes of the proposed scheme of the present invention and those in Han et al., Pattanayak et al., Zong et al., and Ge et al. are 11,584 bits, 27,648 bits, 28,672 bits, 15,360 bits, and 11,424 bits respectively. Compared with the other four schemes, the proposed scheme of the present invention saves 58.10%, 59.60%, 24.58%, and -0.14% in the ciphertext space. In the comparison of the ciphertext space, the proposed scheme shows better saving effects in most of the scheme comparisons, with the saving rate ranging from 24.58% to 59.60%. However, compared with Ge et al., the communication overhead of the proposed scheme increases slightly.

[0043] Figure 12 Comparison of computational overhead between the present invention and typical DCPABE schemes: When the number of attributes is 5, the computational overhead of the algorithm proposed in the present invention and the classical DCPABE algorithm in the main steps is compared. Obviously, the algorithm proposed in the present invention is significantly lower than the DCPABE algorithm in terms of time cost, especially in the encryption and decryption phases. From the above analysis and experimental results, it can be seen that the proposed scheme of the present invention has significant advantages over the schemes proposed by other researchers in terms of efficiency and versatility.

[0044] Figure 13 The present invention conducts the intelligent contract deployment of the steel supply chain. The SteelSupplyChain.sol contract is deployed through Remix IDE 0.59.1, and the key deployments are as follows.

[0045] (1) Solidity deployment transaction details, deployment address: 0xd2a5bC10698FD955D1Fe6cb468a17809A08fd005, transaction hash: 0x0da28d99fdd0fe2277125caef8656f1768074a9c3ad9e1c3c57762ea1cf137ed, block number: 9 | Gas consumption: 1,610,622 gas, constructor bytecode: 0x608060405234801561000f575f80fd5b….

[0046] (2) Multi-modal data storage process:

[0047] 1) Core metadata on-chain: Archiving of steel production data.

[0048]

[0049] 2) IPFS storage of process data:

[0050] @startuml

[0051] Client -> IPFS Node: Upload the encrypted quality inspection video (AES-256, sharded storage)

[0052] IPFS Node --> Client: Return CID: QmX8b...f3d2

[0053] Client -> Blockchain: Submit CID and metadata hash

[0054] Blockchain --> Client: Generate a deposit transaction (Gas consumed: 48,722)

[0055] @enduml

[0056] (3) Dynamic permission verification:

[0057]

[0058] (4) Gas optimization implementation: including storage cost optimization and batch processing mechanism.

[0059] (5) Audit trail implementation: including full life cycle tracking and anomaly detection and warning.

[0060] The concept of system symbols plays a crucial role in the field of artificial intelligence. Using blockchain and IPFS technologies to store and share steel data significantly improves data security and transparency. Through the distributed ledger and tamper-proof characteristics of blockchain, all transaction and production process information is made public and transparent. The distributed storage of IPFS reduces the dependence on centralized servers, enhances data redundancy and accessibility. Combining the revocable ciphertext policy attribute encryption method enables the encrypted protection of steel data. The binding of user attributes and access rights ensures flexible access control of private data while allowing the government to effectively supervise under anonymous conditions. This method not only improves the security and efficiency of data management but also safeguards user privacy. The main symbols of the present invention are shown in Table 1.

[0061] Table 1 Main symbols of the present invention

[0062]

[0063] In Tables 3 and 4, the letters are defined as follows: E represents the exponential operation on the multiplicative cyclic group, P represents the bilinear operation, M represents the multiplication operation, h represents the hash operation, l represents the number of attributes in the access policy, u represents the number of user attributes, q represents the number of attributes in the user attribute set that satisfies the access policy, n represents the number of transmission nodes with at least one threshold gate child node, |m| represents the number of files in the encryption phase, and nk represents the number of attributes managed by the permission. We conducted experiments to verify the encryption algorithm of the present invention. The experimental environment includes the operating system being Windows 10 Professional 64-bit, the computer hardware being Core i7-7500U CPU, 12GB RAM, 512G solid state drive, the compiler being IntelliJ IDEA, and the compilation language being Python.

[0064] Table 2 shows the time consumption of each function when running 1000 times.

[0065] Table 2 Time Required for Related Operations

[0066]

[0067] Table 3 analyzes the computational overhead.

[0068] Table 3 Comparison of Computational Overhead

[0069]

[0070] Assume that |G 1 |, |G 2 |, and are all 1024-bit in bit length. The communication overhead of iron ore and iron and steel mineral resource data in the secure storage and access control service is mainly reflected in the system's public parameters, master key, user private key, and ciphertext. Among them, |G 1 | and |G T represent the group G, |Z r | represents Z q , and the percentage savings is represented by Sp.

[0071] Table 4 Comparison of Communication Overhead

[0072]

[0073] A steel resource data storage and access control scheme based on a revocable CP-ABE algorithm realizes decentralized and tamper-proof data storage by integrating blockchain and IPFS technologies, ensuring that data remains tamper-proof, protecting data privacy, and supporting one-to-many "customized" encrypted communication and access control. In addition, the scheme effectively guards against collusive attacks and facilitates the revocation of user permissions or attributes, making it particularly suitable for the scenario of steel transaction supervision. The enhanced algorithm adopts a more efficient LSSS access structure and a multi-authority encryption system architecture, dispersing the workload of the central authority, reducing the computational overhead of the system, and meeting the indistinguishability (IND-CPA) security level under chosen-plaintext attack. In the context of attribute-based encryption (ABE) and blockchain systems, CCA (chosen-ciphertext attack) security is generally considered more powerful than CPA security. This is because under CCA security, the attacker is allowed to choose ciphertexts and receive their corresponding decryption values, representing a stronger attack model. Considering that your system involves potentially sensitive data, CCA security would be more suitable for guarding against complex attacks involving interaction with ciphertexts. Compared with other schemes, the addition of blockchain further improves the security of the present invention. The comparison scheme reduces the central computing pressure. For further details on access, see Table 5 below.

[0074] Table 5 Comparison Results of Related Schemes

[0075]

[0076] The present invention significantly reduces the time overhead of data encryption and decryption, greatly enhancing the user experience and the practicality of the algorithm. Notably, the present invention effectively eliminates the computational overhead brought about by the update of ciphertexts and keys due to attribute revocation, thus saving the storage space occupied by the updated ciphertexts and keys. To address the problem of coarse-grained access control in blockchain data sharing, the present invention proposes a blockchain data access control method based on revocable attribute encryption. By introducing a pre-decryption process, a revocable ciphertext-policy attribute-based encryption (CP-ABE) scheme applicable to large-scale attribute sets is constructed. In the present invention, the pre-decryption process is executed by a smart contract, allowing for the timely revocation of attributes without the need to repeatedly update keys and ciphertexts or perform on-chain operations, thus making it particularly suitable for blockchain systems.

Claims

1. A supply chain data security and access control method with revocable attribute encryption, characterized by The following steps are involved: (S01): The central authority CA initializes the system, Setup(1 λ )→(PK,MSK) generates the global public key PK and the master private key MSK through the initialization algorithm; including setting the parameters of the encryption system and generating the key pair required for encryption; according to the attribute set S of the participant, including the supplier identity, role, and permission level, the private key KeyGen(MSK,S)→sk of the participant is generated by the key generation algorithm to control the access rights; (S02): Data encryption and decryption. In the data encryption process, the public key PK and the attribute set S are used to encrypt sensitive data in the steel supply chain, including order information and inventory data; Encrypt(PK,(M,ρ),msg)→Ct, input the public key PK, access policy (M,ρ), plaintext msg, and output the ciphertext Ct; This process uses the access policy to encrypt the plaintext into ciphertext to ensure that only qualified users can decrypt; In the data decryption process, the participant uses the private key sk and the attribute set S to decrypt the ciphertext. Only when the attribute set of the participant meets the access policy can the decryption be successful; Decrypt(PK,Ct,sk)→msg, output the plaintext msg. This process uses the attribute private key to decrypt the ciphertext to restore the original plaintext. Only users who meet the access policy can successfully decrypt; (S03): Access token generation algorithm, (S, sk2, params) → TK t , the input attribute set S is the attribute set of the data user, randomly selected from the multiplication group modulo p Randomly select d1,d2,d3∈Z from the additive group modulo p p ; For each attribute i∈S, calculate the attribute index index i =H2(i), where H2 is a hash function used to map attribute i to index value; combined with attribute private key sk2 and system parameter params, output access token TK t , and request access to the corresponding data; the process of generating an access token is as follows: Use the private key sk2 and system parameter params to index the attribute index i To encrypt: in It is an encryption operation, relying on the private key sk2, to generate the access token TK t =f(C i ,e z ,d1,d2,d3,params), where f is a function that generates an access token, combining the encryption result C i and a randomly chosen parameter e z ,d1,d2,d3 and system parameters params to generate access token TK t ; The system allows data requesters to query required data by keywords and generate corresponding access tokens; The requester uses the token to apply for decryption of data, the system verifies its access rights through the blockchain, and retrieves the corresponding file from IPFS; Ultimately, the verified data is securely delivered to the requester; (S04): Pre-decryption algorithm, FirstDecrpt(Ct,sk1)→firsrm, input ciphertext Ct, user's first private key sk1, if the attribute set S satisfies the access policy (M,ρ), then there exists a coefficient w i ∈Z p , so that Where I={i|ρ(i)∈S}; Calculate the pre-decrypted intermediate plaintext: Among them, Ct 0,1 ,Ct 0,2 ,Ct 0,3 are the three elements in the ciphertext component Ct0, sk' and sk ρ(i) Represents the different parts of a private key; (S05): Decryption algorithm, SecDecrypt(Ct,sk2)→secm decryption intermediate plaintext calculation formula Calculation formula for the intermediate parameter num This process combines the pre-decryption and decryption steps to eventually recover the complete plaintext; (S06): Introduce a revocable attribute encryption mechanism. Through smart contracts, when a user's attributes change, their original access rights are automatically revoked and the corresponding keys are updated; Revoke (sk, A): Revoke the private key sk corresponding to the attribute set A; where A is the revoked attribute set and sk is the private key of the user whose permissions need to be revoked; After tracking down the identity of the malicious user, the certificate authority CA takes two measures to maintain system security and cancel the malicious user's account: one is to completely revoke all permissions of the user and prevent him from accessing any data in the system; the other is to revoke only some attributes of the malicious user, making these attributes invalid for him, but other users can still retain and use these attributes; System Initialization Setup (1 λ )→(PK,MPK), randomly select new parameters a1',a'2,d1',d'2,d3', and generate new public keys and master private keys: For each legitimate user, regenerate the attribute private key sk u ' ser =KeyGen(MPK',S), re-encrypt the data: Ct'=Encrypt(PK',(M,ρ),msg), update the attribute private key of the user involved in revoking the attribute: sk u ' ser =KeyGen(MPK',S\{atr}), where atr is the revoked attribute; re-encrypt the data using the new attribute private key: Ct'=Encrypt(PK',(M,ρ'),msg), where ρ' is the new attribute mapping, excluding the revoked attribute; CA also has the right to revoke a system attribute, making it invalid in the system, and all users who have this attribute can no longer use it: keep the system parameters unchanged, and only update the part involving the revoked attribute; update the attribute private keys of all legitimate users; through the above steps and formulas, CA can effectively revoke the accounts or attributes of malicious users, and ensure the safe revocation of system attributes, thereby ensuring the overall security of the system and the confidentiality of data.

Citation Information

Cited By

  • Data circulation supervision method based on KP-ABE cryptographic algorithm

    CN120512313A