Stream data sharing method and system based on bidirectional hash chain symmetric encryption and signcryption

Through the generation of symmetric encryption keys on the bidirectional hash chain and the decentralized management model using the interstellar file system, problems such as large time and computing power overhead and single point failure in the flow data sharing process in the existing technology are solved, and efficient and secure flow data sharing is achieved.

CN120150997AActive Publication Date: 2025-06-13ZHEJIANG UNIV +1

Patent Information

Application Number
CN202510240466.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-13
Estimated Expiration
2045-03-03

AI Technical Summary

Technical Problem

The existing IoT communication technology faces the problems of large time and computing overhead in terms of streaming data sharing, slow public key encryption process, complex symmetric encryption key management, and the centralized storage architecture is prone to single point failure.

Method used

The two-way hash chain is used to generate symmetric encryption keys, combining the advantages of symmetric encryption and public key encryption, and only the first and last two encryption sub-keys of the encryption key are sent to reduce communication overhead; the decentralized management model of the interstellar file system is used to improve the robustness of the system; and the data transmission volume is compressed through the Chinese residual theorem.

Benefits of technology

It significantly improves encryption efficiency, reduces the complexity of key management, reduces communication overhead, ensures the efficiency and security of data sharing, and avoids single point of failure and trust problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150997A_ABST
    Figure CN120150997A_ABST
Patent Text Reader

Abstract

The invention relates to a stream data sharing method and system based on bidirectional Hash chain symmetric encryption and signcryption in the technical field of data sharing. The method comprises the following steps: calculating an original beginning left key corresponding to a first encryption time unit and an original ending right key corresponding to a last encryption time unit in a maximum time interval; on the basis of the original beginning left key and the original ending right key, original encryption sub-keys corresponding to other encryption time units are calculated to generate an encryption key; performing symmetric encryption on the stream data by using the encryption key, obtaining response data of a request time period based on the application request, and performing signcryption processing on the response data to obtain signcryption data; and sending the signcryption data to the data application user, so that the data application user performs de-signcryption on the signcryption data to obtain the response data, and performs decryption processing on the response data to obtain the target data, thereby solving the problems of relatively high resource consumption and relatively low confidentiality during point-to-point data transmission of the existing stream data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data sharing, and particularly to a streaming data sharing system based on two-way hash chain symmetric encryption and signcryption. Background Art

[0002] With the rapid development of Internet of Things technology, the phenomenon of device interconnection and using the network for information and data has become more and more common. In the type of data transmission, streaming data (sequential data continuously generated and transmitted, such as video streams, audio streams, and sensor data streams, etc.) organized by time clues occupies an increasingly important position. They often need to be encrypted and uploaded to the cloud after being collected by various Internet of Things sensors, and then accessed in units of time periods. The continuity of streaming data is crucial for the use of application scenarios. However, the existing Internet of Things communication technologies face many challenges in streaming data sharing.

[0003] First, the time and computing power overheads of traditional algorithms are relatively large. In the process of encrypted sharing of streaming data, if a public key encryption algorithm is used, although the security is relatively high, the encryption and decryption processes are relatively slow, which is not suitable for large-scale streaming data transmission. Moreover, many times it is impossible to know in advance who will receive the data and obtain the public key of the other party, so it is difficult to carry out public key encryption. If a traditional symmetric encryption algorithm is used, to ensure data security, a symmetric key needs to be specially generated for each piece of data. When the user requests a large amount of data, the key transmission will generate a large amount of communication overhead.

[0004] Second, the centralized storage architecture has limitations. Most of the existing Internet of Things systems rely on centralized servers to store data. However, doing so is prone to single point of failure problems, thus affecting the data transmission of the entire system. For streaming data, failures will cause the data sharing process to be interrupted, affecting the reliability of the system. At the same time, centralized servers require users to fully trust the operators of the servers to ensure that their transaction data will not be leaked or tampered with, but in reality, it is very difficult to guarantee this. Summary of the Invention

[0005] A streaming data sharing system based on two-way hash chain symmetric encryption and signcryption is provided. Compared with the prior art, it has the following beneficial effects:

[0006] Using a two-way hash chain to generate symmetric encryption keys significantly improves the encryption efficiency and reduces the complexity of key management. Combining the advantages of symmetric encryption and public key encryption, calculating the symmetric key using a two-way hash chain, only the first and last two encrypted sub-keys in the encryption key need to be sent during transmission, reducing the communication overhead, providing an efficient key generation and management mechanism, and only sending the first and last two encrypted sub-keys. The encryption keys outside the time period of the first and last two encrypted sub-keys cannot be calculated, ensuring that the access of data requesting users will not exceed the boundary and ensuring the efficiency and security of data sharing;

[0007] Use the decentralized management mode of the InterPlanetary File System (IPFS). IPFS is a decentralized file storage and sharing protocol that realizes an efficient and secure file transfer network through distributed hash tables, content addressing, and peer-to-peer communication technologies. Using IPFS can improve the robustness of the system, avoid single-point failures and trust issues, and ensure the real-time and continuous transmission of streaming data;

[0008] Use the Chinese Remainder Theorem to reduce communication overhead. The present invention uses the Chinese Remainder Theorem to compress the CID set of the requested data, thereby reducing the amount of data transmission.

[0009] Solve the problems that existing streaming data consumes a large amount of resources and has low confidentiality during peer-to-peer data transmission.

[0010] To solve the above technical problems, the present invention is solved by the following technical solutions:

[0011] A method for sharing streaming data based on two-way hash chain symmetric encryption and signcryption, comprising the following steps:

[0012] Set the maximum time interval of the date and the encryption time unit, calculate the original starting left key corresponding to the first encryption time unit within the maximum time interval, and the original ending right key corresponding to the last encryption time unit;

[0013] Based on the original starting left key and the original ending right key, use the fourth hash function to calculate the original encryption sub-keys corresponding to the remaining encryption time units;

[0014] Collect all the original encryption sub-keys, the original starting left key, and the original ending right key into a list to obtain the encryption key;

[0015] Use the encryption key to perform symmetric encryption on the streaming data, and obtain the response data for the requested time period based on the application request of the data application user, and perform signcryption processing on the response data to obtain the signcrypted data;

[0016] Send the signcrypted data to the data application user, so that the data application user can perform unsigncryption on the signcrypted data to obtain the response data, and perform decryption processing on the response data to obtain the target data.

[0017] Among them, the data application user performs decryption processing on the response data to obtain the target data, including the following steps:

[0018] Obtain the set of large prime numbers uploaded by the data uploading user to the blockchain network, and decompress the compressed data in the response data based on the set of large prime numbers to obtain the index data;

[0019] Download the first ciphertext corresponding to the index data in the InterPlanetary File System based on the index data, and obtain the left starting key and the right ending key of the request segment in the response data;

[0020] Calculate the encrypted sub-keys of the request segments corresponding to the remaining encrypted time units within the request time period based on the left starting key and the right ending key of the request segment;

[0021] Decrypt the first ciphertext using the left starting key of the request segment, the right ending key of the request segment, and all the encrypted sub-keys of the request segments to obtain the target data.

[0022] Among them, the calculation formulas for the original left starting key, the original right ending key, and the original encrypted sub-keys are:

[0023]

[0024] Among them, α and β are two long-term secret keys of the data upload user, DT represents the date, n is the maximum time interval, H 4 (·) is the fourth hash function, i represents the i-th encrypted time unit, is the original left starting key, is the original right ending key, and together constitute the original encrypted sub-keys, and is calculated based on the original left starting key, is calculated based on the original right ending key.

[0025] Among them, the calculation formula for the encrypted sub-keys of the request segments corresponding to the remaining encrypted time units within the request time period is:

[0026]

[0027] Among them, are all the encrypted sub-keys of the request segments, H 4 (·) is the fourth hash function, i represents the i-th encrypted time unit, is the encrypted sub-key of the request segment calculated based on the left starting key of the request segment, is the encrypted sub-key of the request segment calculated based on the right ending key of the request segment.

[0028] Among them, obtaining the response data of the request time period based on the application request of the data application user includes the following steps:

[0029] Upload the first ciphertext obtained by symmetric encryption to the InterPlanetary File System, and receive the index set returned by the InterPlanetary File System according to the first ciphertext;

[0030] Based on the requested time period in the application request, compress the index data of the requested time period in the index set, and package the compressed index data, the left key at the beginning of the request segment corresponding to the index data, and the right key at the end of the request segment to generate response data.

[0031] Among them, performing signcryption processing on the response data includes the following steps:

[0032] Obtain the encryption parameters publicly disclosed by the key generation center, randomly select a random number as the user's partial private key 1, and generate the user's partial public key 1 based on the encryption parameters, and send the user's partial public key 1 to the key generation center;

[0033] Receive the central public key 1 and the central private key 1 generated by the key generation center based on the user's partial public key 1 and the encryption parameters;

[0034] Obtain the user's partial public key 2 of the data application user and the central public key 2 of the key generation center, calculate the signcryption parameters, and encrypt the response data based on the user's partial public key 2, the central public key 2, the application user information, the signcryption parameters, and the system public key to generate the second ciphertext;

[0035] Sign the second ciphertext based on the upload user information, the user's partial public key 1, the central public key 1, the random number, the time stamp, the user's partial private key 1, and the central private key 1 to obtain the signcryption data.

[0036] Among them, encrypting the response data based on the user's partial public key 2, the central public key 2, the application user information, the signcryption parameters, and the system public key to generate the second ciphertext includes the following steps:

[0037] Based on the application user information, the user's partial public key 2, the central public key 2, and the system public key, calculate the first application user hash value through the first hash function. Among them, the calculation formula of the first application user hash value is: Among them, RID DU is the application user information, X DU is the user's partial public key 2, A DU is the central public key 2, and SPK is the system public key of the key generation center;

[0038] Based on the random number, the user's partial public key 2, the central public key 2, the first application user hash value, the system public key, and the signcryption parameters, calculate the encryption mask through the second hash function. Among them, the encryption mask calculation formula is: B = H 2 (RIDDU , U, W), u represents a random number, which is a value within the positive integer group of the key generation center; the signcryption parameter U = u * P, where P is the generator of the additive group of the key generation center; W is an intermediate calculation parameter;

[0039] Encrypt the response data through an encryption mask to obtain the second ciphertext, where the calculation formula of the second ciphertext is: where M represents the response data.

[0040] Among them, encrypt the response data based on the user partial public key II, the central public key II, the application user information, the signcryption parameter, and the system public key to generate the second ciphertext, including the following steps:

[0041] Based on the application user information, the user partial public key II, the central public key II, and the system public key, calculate the first application user hash value through the first hash function, where the calculation formula of the first application user hash value is: where RID DU is the application user information, X DU is the user partial public key II, A DU is the central public key II, and SPK is the system public key of the key generation center;

[0042] Based on the random number, the user partial public key II, the central public key II, the first application user hash value, the system public key, and the signcryption parameter, calculate the encryption mask through the second hash function, where the encryption mask calculation formula is: B = H 2 (RID DU , U, W), u represents a random number, which is a value within the positive integer group of the key generation center; the signcryption parameter U = u * P, where P is the generator of the additive group of the key generation center; W is an intermediate calculation parameter;

[0043] Encrypt the response data through the encryption mask to obtain the second ciphertext, where the calculation formula of the second ciphertext is: where M represents the response data.

[0044] Among them, the data application user decrypts the signcrypted data, including the following steps:

[0045] Receive the signcrypted data sent by the data uploading user, and perform timeliness verification on the signcrypted data. After the verification passes, obtain the user partial private key II and the central private key II;

[0046] Based on the user partial private key II, the central private key II, the application user information in the signcrypted data, and the signcryption parameter in the signcrypted data, decrypt the second ciphertext in the signcrypted data to obtain the response data.

[0047] A streaming data sharing system based on two-way hash chain symmetric encryption and signcryption, the streaming data sharing system executing the above-mentioned streaming data sharing method based on two-way hash chain symmetric encryption and signcryption, including a data uploading user, a data requesting user, a key generation center, and the InterPlanetary File System (IPFS);

[0048] The data uploading user is used to perform the following steps:

[0049] Set the maximum time interval of the date and the encryption time unit, calculate the original starting left key corresponding to the first encryption time unit within the maximum time interval, and the original ending right key corresponding to the last encryption time unit; based on the original starting left key and the original ending right key, use the fourth hash function to calculate the original encryption sub-keys corresponding to the remaining encryption time units; collect all the original encryption sub-keys, the original starting left key, and the original ending right key into a list to obtain the encryption key; use the encryption key to perform symmetric encryption on the streaming data, and obtain the response data for the requested time period based on the application request of the data requesting user, and perform signcryption processing on the response data to obtain the signcrypted data;

[0050] The data requesting user is used to perform the following steps:

[0051] Unsigncrypt the signcrypted data to obtain the response data, and obtain the set of large prime numbers uploaded by the data uploading user to the blockchain network, and decompress the compressed data in the response data based on the set of large prime numbers to obtain the index data; download the first ciphertext corresponding to the index data in the InterPlanetary File System based on the index data, and obtain the requested segment left starting key and the requested segment ending right key in the response data; based on the requested segment left starting key and the requested segment ending right key, calculate the requested segment encryption sub-keys corresponding to the remaining encryption time units within the requested time period; use the requested segment left starting key, the requested segment ending right key, and all the requested segment encryption sub-keys to decrypt the first ciphertext to obtain the target data;

[0052] The key generation center is used to receive the user partial public key one and the user partial public key two, and respectively generate the center public key one and the center private key one based on the user partial public key one, and respectively generate the center public key two and the center private key two based on the user partial public key two;

[0053] The InterPlanetary File System is used to receive the first ciphertext of the data uploading user and return the index set corresponding to the first ciphertext. Brief Description of the Drawings

[0054] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0055] Figure 1 This is the architecture diagram of a streaming data sharing system based on bidirectional hash chain symmetric encryption and signcryption proposed in the second embodiment. Detailed implementation manners

[0056] The following will further elaborate on the present invention in combination with embodiments. The following embodiments are explanations of the present invention, and the present invention is not limited to the following embodiments.

[0057] Embodiment 1

[0058] Before elaborating on the method for sharing streaming data based on bidirectional hash chain symmetric encryption and signcryption of the present invention, the following briefly describes the uses of the Key Generation Center (KGC) and the simple process of setting it up.

[0059] The Key Generation Center is used to generate public parameters, as well as complete public keys and private keys for participating users. When setting up the Key Generation Center, a security parameter λ needs to be given, and then two large prime numbers p and q are selected, with their lengths approximately λ bits. Then, let E(F p ) be an elliptic curve defined over the finite field F p , and its equation is:

[0060] y 2 ≡x 3 +ax + b (mod p), where a ∈ F p , b ∈ F p , and it satisfies the condition: 4a 3 + 27b 2 ≠ 0 mod p. When the Key Generation Center performs signcryption, it will select an additive group G, whose order is q, and is defined on the elliptic curve E(F p ), and also includes the point at infinity. Let P be the generator of the additive group.

[0061] On the other hand, the Key Generation Center also defines four hash functions, as follows:

[0062] The first hash function H 1 :

[0063] The second hash function H 2 : {0, 1} id × G × G → {0, 1}l ;

[0064] The third hash function H 3 :

[0065] The fourth hash function H 4 : {0, 1} * →{0, 1} k ,

[0066] where id represents the identity length, l represents the information length, k represents the encryption key length, T represents a timestamp, represents the multiplicative group of positive integers modulo q.

[0067] The first hash function is used to calculate the combination of the user's identity, public key, and the system public key, combines the identity information (a binary bit string of length id) with elements in three additive groups G, and outputs an element in the multiplicative group ; The second hash function is used to generate a mask or encryption key for the message, combines the identity information with elements in two additive groups G, and outputs a bit string of a fixed length; The third hash function is used to calculate the signature part during the signcryption process, combines the identity information, elements in two additive groups G, a bit string (the encrypted version of the message), an element in an additive group G, and a timestamp, and outputs an element in the multiplicative group ; The fourth hash function is used to generate an encryption key, takes a bit string of any length as input, and outputs a bit string of a fixed length.

[0068] On the other hand, for the streaming data sharing method based on two-way hash chain symmetric encryption and signcryption of the present invention to execute properly, a system composed of a data uploading user, a data requesting user, a key generation center, and the InterPlanetary File System needs to be built to support data transmission during the encryption and decryption of time-series data. During the building process, both the data uploading user and the data requesting user need to register with the key generation center to establish a trust relationship with the key generation center. Therefore, after the data uploading user completes registration, it can directly obtain the encryption parameters publicly disclosed by the key generation center for the data uploading user to generate user partial public key one and user partial private key one, where the encryption parameters include the multiplicative group and the generator P of the additive group, and the generator P of the additive group is the base point on the elliptic curve, and the encryption parameter is the data brought by the key generation center, which is the parameter available when the key generation center is built. In addition, when the data uploading user registers with the key generation center, two long-term secret keys α and β of the data uploading user will be automatically generated. After completing the above basic preparations, the stream data sharing method based on two-way hash chain symmetric encryption and signcryption can be carried out. It should be noted that in the stream data sharing process of this application, it is mainly divided into two processes: symmetric encryption based on two-way hash chain and signcryption. Among them, the symmetric encryption based on two-way hash chain is the symmetric encryption of the stream data collected by the data uploading user; the signcryption is the encryption of the data generated when the data application user applies for data and the data uploading user responds to the application.

[0069] First, the stream data collected by the data uploading user is symmetrically encrypted, that is, the stream data collected by the data uploading user is symmetrically encrypted using the encryption key generated by the two-way hash chain to obtain the first ciphertext, and the first ciphertext is uploaded to the InterPlanetary File System (IPFS).

[0070] Specifically, a maximum time interval of a date and an encrypted time unit are set; a fourth hash function is used to calculate an original beginning left key corresponding to the first encrypted time unit within the maximum time interval, and an original ending right key corresponding to the last encrypted time unit; based on the original beginning left key and the original ending right key, the fourth hash function is used to calculate the original encrypted subkeys corresponding to the remaining encrypted time units, and all the original encrypted subkeys, the original beginning left key and the original ending right key are combined into a list to obtain an encryption key; the encryption key is used to symmetrically encrypt the stream data to obtain a first ciphertext.

[0071] More specifically, assuming that the maximum time interval on date DT is n, the data upload user needs to calculate The user who uploads the data first calculates The required related content is first calculated when i=1 (that is, when the first calculation is the first one), also known as the original starting left key, and the calculation formula is: Then according to the calculation result of i=1, Recursive calculation Next, the encryption subkey when i=n (i.e., the first calculation is the nth one) is calculated, also known as the original ending right key, and the calculation formula is: Then according to the calculation of i=n, ​​for Recursive calculation It should be noted that α and β are two long-term secret keys of the data uploading user, which are randomly selected by the data uploading user during the system initialization phase. The secret key space is {0, 1}k, where k is the key length.

[0072] Further, according to the previous calculations, it can be obtained that for Calculating the encryption key Then represent it as a data set Kset DT , and

[0073] When the data uploading user starts to collect data on date DT, the data uploading user looks up the corresponding time period in KSet DT for the time period to be encrypted according to the need Then use the found corresponding time period to encrypt the streaming data Thereby generating the first ciphertext And upload the first ciphertext through IPFS for outsourced data storage. Correspondingly, the data uploading user will receive the index set sent by IPFS Then the data uploading user deletes where represents the data collected by the data uploading user in the time interval t i collected.

[0074] After completing the upload of the first ciphertext and the data uploading user receives the index set returned by the InterPlanetary File System, since the data uploading user will only trigger the signcryption process for the response data corresponding to the data requested to be viewed in the application request when receiving the application request from the data request user, therefore, this embodiment further describes the signcryption process executed after the data uploading user receives the application request from the data request user.

[0075] For the data signcryption process for the data generated by the data uploading user when responding to the application request of the data request user: Based on the application request of the data request user and the index set returned by the InterPlanetary File System according to the first ciphertext, generate the response data for the requested time period.

[0076] Specifically, based on the requested time period in the application request of the data request user, compress the index data of the requested time period in the index set, and package the compressed index data and the left key at the beginning of the request segment and the right key at the end of the request segment corresponding to the index data to generate the response data.

[0077] In this embodiment, the request time of the data request user is within the time range [t s , t eTaking the [data] as an example, after receiving the request, the data uploading user will first randomly generate a set of large prime numbers, and the length of the generated set of large prime numbers is equal to the length of the index data. The set of large prime numbers will be uploaded to the blockchain network for public disclosure, and then the index data will be compressed using the Chinese Remainder Theorem technology with the set of large prime numbers to generate compressed data. Thus, through compression processing, the communication overhead is reduced, and then the left key at the beginning of the request segment for the request time period corresponding to the index data The right key at the end of the request segment (i.e.: ) and the compressed data are packaged to obtain the response data for the request time period.

[0078] When obtaining the response data, the data uploading user can also execute: obtaining the encryption parameters publicly disclosed by the key generation center; randomly selecting a random number as the user's partial private key one, and generating the user's partial public key one based on the encryption parameters, and sending the user's partial public key one to the key generation center; receiving the central public key one and the central private key one generated at the key generation center based on the user's partial public key one.

[0079] Specifically, when the data uploading user obtains the encryption parameters, a random integer x DO is generated as the user's partial private key one, and x DO satisfies Then calculate the user's partial public key one X DO , and the calculation formula is: X DO =x DO ·P. After obtaining the user's partial private key one and the user's partial public key one, the data uploading user packs the uploading user information, timestamp, and the user's partial public key one, and sends them to the key generation center through the SSL / TLS protocol. Among them, the form of the uploaded data after packing can be expressed as {RID DO , X DO , T}, where RID DO represents the uploading user information, which is carried by the data uploading user itself, and T represents the timestamp.

[0080] Next, receive the central public key one and the central private key one generated at the key generation center based on the user's partial public key one and the encryption parameters.

[0081] Among them, the key generation center generates the central public key one and the central private key one, including the following steps: selecting a random value one a DO , and the random value one satisfies Calculate the central public key one of the key generation center according to the random value one, and the calculation formula is: A DO =a DOP; will upload user information RID DO 、User's partial public key - X DO 、Center public key A DO and the system public key SPK of the key generation center, using the first hash function to calculate the first uploading user hash value Based on the system master private key msk and random value a of the key generation center DO and the first uploaded user hash Computing center private key y DO Among them, the system master private key and system public key are parameters provided by the key generation center.

[0082] Specifically, the first upload user hash value The calculation formula is: The central private key of the key generation center is y DO The calculation formula is:

[0083] It should be noted that after the key generation center generates the central public key 1 and the central private key 1, it sends the central public key 1 and the central private key 1 to the data upload user through the SSL / TSL protocol. The data upload user can also send part of the user's public key 1 to the X DO A DO Summarize into a set to form a complete public key - PK DO ={X DO , A DO}; Change the user's partial private key to x DO With the central private key DO Summarize into a set to form a complete private key sk DO ={x DO ,y DO}.

[0084] On the other hand, after the complete public key one is generated, the complete public key one will also be uploaded to the blockchain network for public disclosure; and after receiving the central private key one and the central public key one, the data uploading user will also verify the correctness of the central private key one and the central public key one. Only if the verification is successful can it be finally used by the data uploading user.

[0085] The data uploader verifies the correctness of the central private key 1 and central public key 1 of the key generation center, which specifically includes the following steps: upload the user information RID DO 、User's partial public key - X DO 、Center public key A DO and the system public key SPK of the key generation center, and calculates the first hash verification value through the first hash function Based on the central private key 1, the central public key 1, the first hash verification value, and the system public key, set the correctness verification condition; determine whether the correctness verification condition holds. If it holds, store the received central public key 1 and central private key 1. If it does not hold, the key generation center regenerates the central public key 1 and central private key 1.

[0086] Specifically, the correctness verification condition is:

[0087]

[0088] where P is a base point on the elliptic curve, used to generate other points on the elliptic curve; y DO ·P represents adding point P to itself y DO times, which is a scalar multiplication operation in elliptic curve cryptography; this equation is used to verify whether the central private key 1 of the key generation center matches the central public key 1. If the equation holds, it means that the central private key 1 of the key generation center is correctly generated, and the data uploading user can receive this central private key 1 and combine it with the user's partial private key 1 to generate a complete private key pair. If the equation does not hold, it means that the central private key 1 of the key generation center may be tampered with or calculated incorrectly, and the data uploading user needs to re-obtain the central private key 1 of the correct key generation center.

[0089] Through the setting of the correctness verification condition in this application, it is ensured that the central public key 1 and central private key 1 obtained by the data uploading user are correct and can be used for signcryption, thereby determining that the key generation center has not leaked or tampered with the central private key 1, and further ensuring the security of the system.

[0090] After verifying the correctness of the central private key 1 and central public key 1 of the key generation center, the data uploading user can upload {RID DO , PK DO} to the consortium blockchain.

[0091] Then obtain the user's partial public key 2 of the data application user and the central public key 2 of the key generation center, and calculate the signcryption parameters. Encrypt the response data based on the user's partial public key 2, the central public key 2, the application user information, the signcryption parameters, and the system public key to generate the second ciphertext.

[0092] Among them, obtaining the user's partial public key 2 of the data application user includes the following steps:

[0093] The data application user obtains the encryption parameters publicly disclosed by the key generation center, which are used for the data application user to generate the user's partial public key 2 and the user's partial private key 2.

[0094] When the data application user obtains the encryption parameters, generate a random integer x DU as the user's partial private key 2, and xDU Meet Then calculate the user's partial public key two X DU , and the calculation formula is: X DU = x DU ·P. After obtaining the user's partial private key two and the user's partial public key two, the data application user packs the application user information, timestamp, and the user's partial public key two, and sends them to the key generation center through the SSL / TLS protocol. Among them, the data form after packing and uploading can be expressed as {RID DU , X DU , T}, where RID DU represents the application user information, which is carried by the data application user itself, and T represents the timestamp.

[0095] After the key generation center obtains the user's partial public key two, it generates the center public key two based on the user's partial public key two. First, select a random value two a DU , and the random value two meets Then calculate the center public key two of the key generation center according to the random value two, and the calculation formula is: A DU = a DU ·P. After generating the center public key two, the key generation center sends the center public key two to the data application user through the SSL / TSL protocol, and at the same time, the center public key two will also be uploaded to the blockchain network for public disclosure.

[0096] On the other hand, after the data application user receives the center public key two, it can also aggregate the user's partial public key two X DU and the center public key two A DU into a set to form the complete public key two PK DU ={X DU , A DU}, and then upload the complete public key two to the blockchain network for public disclosure. Therefore, the data upload user can obtain the user's partial public key two and the center public key two in the complete public key two through the blockchain network.

[0097] After obtaining the user's partial public key two and the center public key two, the signcryption parameters can be calculated, which specifically include the following steps: Select a random number u, and u meets Calculate the signcryption parameter U based on the random number, and the calculation formula is: U = u * P.

[0098] After obtaining the user's partial public key two, the center public key two, and the signcryption parameter, the step of generating the second ciphertext can be executed, which is specifically as follows:

[0099] Based on the application user information RID DU , the user's partial public key two X DU , the center public key two A DUand the system public key SPK, calculate the first applicant user hash value through the first hash function Its calculation formula is

[0100] Based on the random number, user partial public key II, central public key II, first applicant user hash value, system public key and signcryption parameter, calculate the encryption mask B through the second hash function, and its calculation formula is: B = H 2 (RID DU , U, W), where

[0101] After obtaining the encryption mask B, encrypt the response data through the encryption mask to obtain the second ciphertext c. Among them, the calculation formula of the second ciphertext c is: Among them, M represents the response data.

[0102] After obtaining the second ciphertext, sign the second ciphertext based on the uploaded user information, user partial public key I, central public key I, random number, timestamp, user partial private key I and central private key I to obtain the signcryption data. Specifically, first calculate the third uploaded user hash value through the third hash function, and calculate the signature through the third uploaded user hash value, random number, user partial private key I and central private key I to obtain the signcryption data.

[0103] Among them, the calculation formula of the third uploaded user hash value is: The calculation formula of the signcryption data is:

[0104] So far, the data uploading user has completed the encryption process. This application generates an encryption key by using a two-way hash chain, uses the encryption key to perform the first layer of encryption on the streaming data, and then uses an efficient encryption algorithm to perform the second layer of signcryption on the response data, solving the confidentiality problem of large-scale streaming data stored in the cloud, and can also greatly save the key management overhead; on the other hand, using the IPFS distributed storage system to store data can well avoid the single point of failure problem of the system and improve the system robustness.

[0105] It should be noted that the response data in this embodiment will be regenerated according to each application request of the data application user, while the user partial public key 1, user partial private key 1 generated by the data uploading user; the central public key 1, central private key 1, central public key 2 and central private key 2 generated by the key generation center; the user partial public key 2, user partial private key 2 generated by the data application user only need to be generated once and are held for a long time, and will not change no matter how many times the response data is regenerated. On the other hand, the streaming data sharing method based on two-way hash chain symmetric encryption and signcryption of the present invention also decrypts data at the data application user for decrypting the signcrypted data generated by the data uploading user, including the following steps:

[0106] Send a data application request to the data uploading user.

[0107] Receive the signcrypted data returned by the data uploading user, and the set of large prime numbers uploaded by the data uploading user to the blockchain network, where the signcrypted data includes the uploading user information RID DO , signature σ, second ciphertext c, signcryption parameter U and timestamp T, and the signcrypted data are all calculated during the signcryption process and can be directly used during the unsigncryption process.

[0108] Verify the timeliness of the signcrypted data, and obtain the user partial private key 2 and central private key 2 after the verification passes, where the timeliness verification is performed according to the sending time of the application request and the returning time of the signcrypted data. If the returning time of the signcrypted data is after the sending time of the application request and satisfies the set time difference threshold with the sending time of the application request, the timeliness verification is satisfied, otherwise the timeliness verification fails.

[0109] Decrypt the second ciphertext in the signcrypted data based on the user partial private key 2, central private key 2, the application user information in the signcrypted data, and the signcryption parameter in the signcrypted data to obtain the response data.

[0110] Specifically, the calculation formula of the response data is as follows:

[0111]

[0112] Among them, B’ = H 2 (RID DU , U, W’);

[0113] W’ = U·(x DU + y DU ).

[0114] Thus, the response data is finally obtained

[0115] On the other hand, this embodiment further includes a step of verifying the correctness of the signature, and the condition for verifying the correctness of the signature is: satisfying the equation holds. If the equation holds, the verification is successful, and the response data M' is calculated; otherwise, the verification fails.

[0116] where h DO′ = H 3 (RID DO , X DO , A DO , c, U, T);

[0117]

[0118] After completing the verification step, download the set of large prime numbers from the blockchain network, and decompress the compressed data in the response data based on the set of large prime numbers to obtain index data.

[0119] After obtaining the index data, download the first ciphertext corresponding to the requested time period in the InterPlanetary File System according to the index data and obtain the left start key and right end key of the request segment in the response data.

[0120] Next, the data request user calculates the encrypted sub-keys of the request segments corresponding to the remaining encrypted time units within the requested time period based on the left start key and right end key of the request segment. The calculation formula is:

[0121]

[0122] where are all the encrypted sub-keys of the request segments, H 4 (·) is the fourth hash function, i represents the i-th encrypted time unit, is the encrypted sub-key of the request segment calculated according to the left start key of the request segment, is the encrypted sub-key of the request segment calculated according to the right end key of the request segment. The left start key and right end key of the request segment are known.

[0123] Thus, the left start key of the request segment, the right end key of the request segment, and all the encrypted sub-keys of the request segments are aggregated into a set to obtain The representation of the set is: the encrypted key set

[0124] Then use the encrypted key set to decrypt the first ciphertext, and finally obtain the target data

[0125] It should be noted that since the encryption of the streaming data in the present invention is implemented based on the symmetric encryption of the bidirectional hash chain, the encryption key for the streaming data is also used as the decryption key during the decryption process of the response data. On the other hand, by way of example, the streaming data in the present invention includes, but is not limited to, videos taken by data uploading users through surveillance cameras at various time periods.

[0126] Embodiment 2

[0127] As Figure 1 shown, a streaming data sharing system based on symmetric encryption and signcryption of bidirectional hash chains includes a data uploading user, a data requesting user, a key generation center, and an InterPlanetary File System (IPFS);

[0128] The data uploading user is used to perform the following steps:

[0129] Set the maximum time interval of the date and the encryption time unit, calculate the original start left key corresponding to the first encryption time unit within the maximum time interval, and the original end right key corresponding to the last encryption time unit; based on the original start left key and the original end right key, use the fourth hash function to calculate the original encryption sub-keys corresponding to the remaining encryption time units; aggregate all the original encryption sub-keys, the original start left key, and the original end right key into a list to obtain the encryption key; use the encryption key to perform symmetric encryption on the streaming data, and based on the application request of the data requesting user, obtain the response data for the requested time period, and perform signcryption processing on the response data to obtain the signcrypted data;

[0130] The data requesting user is used to perform the following steps:

[0131] Perform unsigncryption on the signcrypted data to obtain the response data, and obtain the set of large prime numbers uploaded by the data uploading user to the blockchain network. Based on the set of large prime numbers, decompress the compressed data in the response data to obtain the index data; based on the index data, download the first ciphertext corresponding to the index data in the InterPlanetary File System, and obtain the request segment start left key and the request segment end right key in the response data; based on the request segment start left key and the request segment end right key, calculate the request segment encryption sub-keys corresponding to the remaining encryption time units within the requested time period; use the request segment start left key, the request segment end right key, and all the request segment encryption sub-keys to decrypt the first ciphertext to obtain the target data;

[0132] The key generation center is used to receive the user partial public key 1 and the user partial public key 2, and respectively generate the center public key 1 and the center private key 1 based on the user partial public key 1, and respectively generate the center public key 2 and the center private key 2 based on the user partial public key 2;

[0133] The InterPlanetary File System is used to receive the first ciphertext from the data uploading user and return the index set corresponding to the first ciphertext.

[0134] It should be noted that since the stream data sharing system executes the stream data sharing method based on two-way hash chain symmetric encryption and signcryption as described in Embodiment 1, it will not be repeated in this embodiment.

[0135] As mentioned above, the above are only the preferred embodiments of the present invention, and do not impose any formal or substantial limitations on the present invention. It should be pointed out that for those of ordinary skill in the art of this technology, without departing from the method of the present invention, several improvements and supplements can still be made, and these improvements and supplements should also be regarded as the protection scope of the present invention. Any equivalent changes made by those skilled in the art by making some changes, modifications and evolutions using the technical content disclosed above without departing from the spirit and scope of the present invention are equivalent embodiments of the present invention; at the same time, any equivalent changes made to the above embodiments based on the essential technology of the present invention, including changes, modifications and evolutions, still fall within the scope of the technical solution of the present invention.

Claims

1. A stream data sharing method based on two-way hash chain symmetric encryption and signcryption, characterized in that: The following steps are involved: Set the maximum time interval and encryption time unit of the date, calculate the original beginning left key corresponding to the first encryption time unit in the maximum time interval, and the original ending right key corresponding to the last encryption time unit; Based on the original beginning left key and the original ending right key, using a fourth hash function to calculate the original encryption subkeys corresponding to the remaining encryption time units; Collect all the original encryption subkeys, the original beginning left key and the original ending right key into a list to obtain the encryption key; Symmetrically encrypt the stream data using an encryption key, obtain response data for a request time period based on an application request from a data application user, and signcrypt the response data to obtain signcrypted data; The signcrypted data is sent to the data applying user, so that the data applying user decrypts the signcrypted data to obtain response data, and decrypts the response data to obtain target data.

2. A stream data sharing method based on bidirectional hash chain symmetric encryption and signcryption according to claim 1, characterized in that: The data application user decrypts the response data to obtain the target data, including the following steps: Obtain a large prime number set uploaded by the data uploading user to the blockchain network, and decompress the compressed data in the response data based on the large prime number set to obtain index data; Downloading a first ciphertext corresponding to the index data in the InterPlanetary File System based on the index data, and obtaining a request segment left start key and a request segment end right key in the response data; Based on the request segment left start key and the request segment end right key, calculate the request segment encryption subkey corresponding to the remaining encryption time units in the request time period; The first ciphertext is decrypted using the left beginning key of the request segment, the right ending key of the request segment, and all the encryption subkeys of the request segment to obtain the target data.

3. A stream data sharing method based on bidirectional hash chain symmetric encryption and signcryption according to claim 1, characterized in that: The calculation formula of the original beginning left key, the original ending right key and the original encryption subkey is: Among them, α and β are two long-term secret keys of the data uploading user, DT represents the date, n is the maximum time interval, H4(·) is the fourth hash function, and i represents the i-th encrypted time unit. is the original starting left key, is the original ending right key, and together constitute the original encryption subkey, and Calculated based on the original starting left key, Calculated based on the original ending right key.

4. A stream data sharing method based on bidirectional hash chain symmetric encryption and signcryption according to claim 2, characterized in that: The calculation formula for the request segment encryption subkey corresponding to the remaining encryption time units within the request time period is: in, Encrypt the subkey for all request segments, H4(·) is the fourth hash function, i represents the i-th encryption time unit, The key for the request segment is left at the beginning The calculated encryption subkey for the requested segment, Right key for the request segment end The calculated encryption subkey for the requested segment.

5. A stream data sharing method based on bidirectional hash chain symmetric encryption and signcryption according to any one of claims 1 to 4, characterized in that: Obtaining response data for a requested time period based on an application request from a data application user includes the following steps: Upload the first ciphertext obtained by symmetric encryption to the InterPlanetary File System, and receive the index set returned by the InterPlanetary File System according to the first ciphertext; Based on the request time period in the application request, the index data of the request time period in the index set is compressed, and the compressed index data, the left key at the beginning of the request segment of the request time period corresponding to the index data, and the right key at the end of the request segment are packaged to generate response data.

6. A stream data sharing method based on two-way hash chain symmetric encryption and signcryption according to claim 5, characterized in that: Performing signcryption processing on the response data includes the following steps: Obtain the encryption parameters disclosed by the key generation center, randomly select a random number as the user's partial private key one, generate the user's partial public key one based on the encryption parameters, and send the user's partial public key one to the key generation center; Receiving a central public key 1 and a central private key 1 generated by a key generation center based on a user partial public key 1 and encryption parameters; Obtain the user partial public key 2 of the data applying user and the central public key 2 of the key generation center, calculate the signcryption parameter, encrypt the response data based on the user partial public key 2, the central public key 2, the applying user information, the signcryption parameter, and the system public key to generate a second ciphertext; The second ciphertext is signed based on the uploading user information, the user's partial public key 1, the center's public key 1, the random number, the timestamp, the user's partial private key 1 and the center's private key 1 to obtain the signed encrypted data.

7. A stream data sharing method based on two-way hash chain symmetric encryption and signcryption according to claim 6, characterized in that: The response data is encrypted based on the user partial public key 2, the center public key 2, the application user information, the signcryption parameter, and the system public key to generate a second ciphertext, including the following steps: Based on the applicant user information, the user's partial public key 2, the center public key 2 and the system public key, the first applicant user hash value is calculated by the first hash function, wherein the calculation formula of the first applicant user hash value is: Among them, RID DU To apply for user information, X DU A is the user's partial public key 2 DU is the center public key 2, SPK is the system public key of the key generation center; Based on the random number, the user's partial public key 2, the center's public key 2, the first applicant's hash value, the system's public key, and the signcryption parameter, the encryption mask is calculated by the second hash function, where the encryption mask calculation formula is: B = H2 (RID DU , U, W), u represents a random number, which is a value in the positive integer group of the key generation center; the signcryption parameter U=u*P, where P is the generator of the additive group of the key generation center; W is an intermediate calculation parameter; The response data is encrypted by the encryption mask to obtain a second ciphertext, wherein the calculation formula of the second ciphertext is: Wherein, M represents the response data.

8. A stream data sharing method based on bidirectional hash chain symmetric encryption and signcryption according to claim 7, characterized in that: Signing the second ciphertext includes the following steps: Calculate the third uploading user hash value by using the third hash function, and calculate the signature by using the third uploading user hash value, the random number, the user partial private key one and the center private key one to obtain the signcrypted data; The calculation formula of the third uploading user hash value is: RID DO To upload user information, X DO A is the user's partial public key DO is the central public key 1, T is the timestamp; The calculation formula of the signcryption data is: x DO Partial private key of the user, y DO The central private key is one.

9. A stream data sharing method based on bidirectional hash chain symmetric encryption and signcryption according to any one of claims 1 to 4, characterized in that: The data application user decrypts the signed data, which includes the following steps: Receive the signed data sent by the data upload user, and verify the timeliness of the signed data. After the verification is passed, obtain the user's partial private key 2 and the center private key 2; Based on the user partial private key 2, the central private key 2, the applicant user information in the signcrypted data, and the signcryption parameters in the signcrypted data, the second ciphertext in the signcrypted data is decrypted to obtain response data.

10. A stream data sharing system based on two-way hash chain symmetric encryption and signcryption, characterized in that: The stream data sharing system executes the stream data sharing method based on bidirectional hash chain symmetric encryption and signcryption as described in any one of claims 1 to 9, including a data uploading user, a data applying user, a key generation center and an interplanetary file system; The data upload user is used to perform the following steps: Set the maximum time interval and encryption time unit of the date, calculate the original beginning left key corresponding to the first encryption time unit in the maximum time interval, and the original ending right key corresponding to the last encryption time unit; Based on the original beginning left key and the original ending right key, use the fourth hash function to calculate the original encryption subkeys corresponding to the remaining encryption time units; collect all the original encryption subkeys, the original beginning left key and the original ending right key into a list to obtain an encryption key; Symmetrically encrypt the stream data using an encryption key, obtain response data for a request time period based on an application request from a data application user, and signcrypt the response data to obtain signcrypted data; The data application user is used to perform the following steps: Decrypt the signcrypted data to obtain response data, obtain a large prime number set uploaded to the blockchain network by the data upload user, and decompress the compressed data in the response data based on the large prime number set to obtain index data; Based on the index data, a first ciphertext corresponding to the index data is downloaded from the Interstellar File System, and a request segment left start key and a request segment end right key in the response data are obtained; based on the request segment left start key and the request segment end right key, a request segment encryption subkey corresponding to the remaining encryption time units in the request time period is calculated; the first ciphertext is decrypted using the request segment left start key, the request segment end right key and all request segment encryption subkeys to obtain target data; The key generation center is used to receive a user partial public key 1 and a user partial public key 2, and generate a central public key 1 and a central private key 1 based on the user partial public key 1, and generate a central public key 2 and a central private key 2 based on the user partial public key 2; The interplanetary file system is used to receive a first ciphertext from a data uploading user and return an index set corresponding to the first ciphertext.

Citation Information

Patent Citations

  • Asymmetric bilinear pair-based secret signcryption method

    CN109462481A

  • Certificateless signcryption system and method based on trap door hash function

    CN111262709A

  • Certificateless threshold signcryption method under secret sharing mechanism

    CN112260830A

  • Semi-homomorphic encryption Internet of Things privacy protection scheme based on block chain

    CN118473635A

Cited By

  • Encryption communication method and system

    CN120881214A

  • Public key legality verification method and device based on asymmetric encryption algorithm, equipment and medium

    CN121486081A