Cross-chain cargo transportation method based on NTRU grid signcryption

By adopting a cross-chain cargo transportation method based on NTRU signature in cargo transportation, the loss of cargo transportation data in the face of denial of service attacks and the blockchain storage pressure when the Internet of Things data increases is solved, and efficient and secure data transmission and storage are achieved.

CN120181706APending Publication Date: 2025-06-20XIAN UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510347697.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing safe storage methods for cargo transportation data will lead to the loss of all user data when facing a denial of service attack, and will not effectively solve the problem of blockchain storage pressure when the Internet of Things data is sharply increasing. There is a lack of cross-chain cargo transportation methods based on NTRU grid signing for intelligent transportation.

Method used

A cross-chain cargo transportation method based on NTRU grid signature is adopted. Through the steps of system initialization, membership joining, selection of cargo transporters, transportation process, etc., the hash function and discrete Gaussian distribution are used to generate public and private keys to achieve secure storage and transmission of data, and data is transmitted across the chain through alliance chains and cloud storage systems.

Benefits of technology

This method can withstand quantum computing attacks, improve the security and efficiency of data transmission, reduce the storage pressure of blockchain, and ensure fairness of cargo transportation. It is suitable for transportation fields such as food, machinery, and military products.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120181706A_ABST
    Figure CN120181706A_ABST
Patent Text Reader

Abstract

A cross-chain cargo transportation method based on NTRU lattice signcryption comprises the steps of system initialization, member addition, cargo transporter selection, transportation process and cargo confirmation. According to the invention, the authenticity of the block chain data in the cross-chain process can be ensured through the relay chain technology, and the quantum computing attack of the cross-chain cargo transportation data can be resisted through the NTRU grid signcryption technology. Through the attribute implicit access control technology, a cargo transporter can fairly compete for a proper transportation task according to own attribute characteristics, and the behavior that an attacker obtains identity information characteristics of the cargo transporter can be avoided. The method has the advantages of quantum computing attack resistance, high signcryption efficiency, reduction of block chain storage pressure, guarantee of cargo transportation fairness and the like, and is suitable for intelligent transportation fields of food, machinery, military products and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network information security, and particularly relates to cargo transportation. Background Art

[0002] In order to solve problems such as imperfect user information protection mechanism, asymmetric logistics information, and lack of effective supervision mechanism in the process of cargo transportation, the data generated in logistics can be stored on the consortium blockchain, and attribute signcryption can be used to ensure the security of the data. The explicit attribute access control policy will expose the user's identity information, and all data stored on a single consortium blockchain will undoubtedly increase the storage burden of the blockchain. In the existing data security storage method for transporting goods, the data generated during the cargo transportation process is stored on a cloud server, and the blockchain network consensus mechanism is used to securely audit the storage records. Although this method reduces the storage pressure on the blockchain, when facing a denial-of-service attack, all the user's data will be lost. In the existing two-way option privacy transportation protection method, although access control of data and integrity detection of data are achieved, however, the problem of blockchain storage pressure when the Internet of Things data increases sharply has not been solved. So far, there is no cross-chain cargo transportation method based on NTRU lattice signcryption for intelligent transportation. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to overcome the above-mentioned technical problems and provide a highly efficient cross-chain cargo transportation method based on NTRU lattice signcryption.

[0004] The technical solution adopted to solve the above technical problems consists of the following steps:

[0005] (1) System initialization

[0006] Set a security parameter N ∈ [2 7 , 2 9 bits, select a large prime number Q ≥ 5 with 2 k bits, where Q satisfies gcd(p, q) = 1, where k ∈ [7, 9], p takes the value of 2 or 3, and the Gaussian parameter σ is determined according to Equation (1).

[0007]

[0008] Among them, A and B are coefficients, A and B are positive numbers at least equal to 1, and A is different from B.

[0009] 1) The system management center sets the global attribute set U:

[0010] U ← {u1, u2, …, u n},

[0011] Among them, n represents the number of global attributes, where n is a finite positive integer. U is sent to the task allocation center through a secure channel for storage.

[0012] 2) The System Management Center (SMC) uses a trapdoor generation method to obtain the system master public key h and the master private key D.

[0013] 3) The System Management Center (SMC) selects three hash functions H1, H2, and H3 that are resistant to quantum computing attacks:

[0014]

[0015] Among them, l1 represents the length of the user identity; l2 represents an arbitrary length; t represents the length of the message plaintext m, where t is a finite positive integer; represents the identity information of length l1 composed of 0 and 1; {0, 1} N represents the set of strings of length N composed of 0 and 1; represents the set of strings of arbitrary length composed of 0 and 1.

[0016] 4) The System Management Center determines the hash value V s :

[0017] V s = H1(ID s ),

[0018] Among them, ID s represents the identity information of the System Management Center (SMC); the private key (α s , β s ) is obtained by the preimage sampling method, α s , β s ∈ R N,q , α s + β s h = V s , ||α s || represents the norm of α s ||β s || represents the norm of β s ||.

[0019] 5) The System Management Center publishes the system parameters

[0020]

[0021] (2) Member Joining

[0022] 1) When the task allocation center joins the system, it sends the identity information ID to the System Management Center (SMC); after the System Management Center (SMC) approves the audit, it calculates the hash value V TDC ; TDC:

[0023] V TDC = H1(ID TDC ),

[0024] wherein, ID TDC represents the identity information of the task allocation center; the system management center SMC generates a partial private key (α TDC , β TDC ) of the task allocation center through the preimage sampling method, and satisfies:

[0025] α TDC + β TDC h = V TDC

[0026] wherein, ||α TDC || represents the norm of α TDC ||β TDC || represents the norm of β TDC The system management center SMC sends its private key (α TDC , β TDC ) to the task allocation center; the task allocation center receives the private key (α TDC , β TDC ) and verifies:

[0027] α TDC + β TDC h = V TDC

[0028] If the equation holds, accept (α TDC , β TDC ) as the partial private key; if the verification fails, reject it and require the system management center SMC to resend. Other users in the system, the cargo owner CO, the cargo transporter CT, and the cargo receiver CR use the same method to extract the partial key.

[0029] 2) The task allocation center randomly selects as its own secret value, wherein, is a discrete Gaussian distribution; determine the public key P K,TDC of the task allocation center according to the following formula:

[0030] P K,TDC = V TDC + η TDC × ζ TDC

[0031] ζ TDC = γ TDC + h × δ TDC

[0032] η TDC= H2(ID TDC , V TDC , h)

[0033] The private key S of the task assignment center K,TDC ← {α TDC , β TDC , γ TDC , δ TDC}, and the public key is P K,TDC ; Other users in the system obtain the public key and private key using the same method.

[0034] 3) The system management center selects the attribute set E CT for the transporter according to the identity information ID CT uploaded by the transporter. The system management center performs the following operations:

[0035]

[0036] where, U i represents the i-th attribute in U; represents the i-th bit in the transporter attribute vector , i ∈ [1, n].[[]]

[0037] The transporter determines the attribute vector according to the following formula

[0038]

[0039] (3) Select the transporter

[0040] 1) The task assignment center selects a suitable transporter and sets the access policy attribute set E A , E A ∈ U. The task assignment center performs the following operations:

[0041]

[0042] The access policy vector

[0043] 2) The task assignment center publishes the transport label and the access policy vector The transporter sends the task label identity information ID CT , attribute vector to participate in the campaign.

[0044] 3) The alliance chain smart contract searches for the access policy vector corresponding to the task label Perform attribute matching to verify whether the following equation holds:

[0045]

[0046] If the equation holds, send the identity information ID CT to the task allocation center and stop the attribute matching for the corresponding task label; otherwise, continue to accept attribute matching until it is successful.

[0047] (4) Transportation process

[0048] 1) The task allocation center receives the identity information ID CT , and selects the optimal transportation route W and estimates the transportation time T based on the cargo information m G and the vehicle information of the identity information ID CT .

[0049] 2) The task allocation center sends to the cargo owner sends to the cargo transporter sends to the cargo receiver

[0050] 3) The task allocation center summarizes all the information of this transportation process in the first plaintext m1:

[0051]

[0052] Sign and encrypt the first plaintext m1 as follows:

[0053] ① The task allocation center calculates:

[0054] ρ1 = v1 × (h × r 0,1 + e 0,1 )

[0055]

[0056] where v1, is an element selected from the discrete Gaussian distribution , r 0,1 , r 1,1 , r 2,1 is an element selected from the secret polynomial ξ A , r 0,1 , r 1,1 , r 2,1 ∈ ξ A , e 0,1 , e 1,1 , e 2,1 , e 3,1 , e 4,1 is an element selected from the noise polynomial ξ B ​0,1 , e 1,1 , e 2,1 , e 3,1 , e 4,1 ∈ ξ B , μ1 is a set of strings of any positive - integer length consisting of 0 and 1. P K,CR is the public key of the goods receiver, V CR is the hash value calculated according to the identity ID CR of the goods receiver, η CR is the hash value calculated according to (ID CR , V CR , h); ρ1, c 1,1 , c 2,1 , c 3,1 , c 4,1 , c 5,1 are partial ciphertexts in the calculation process.

[0057] ② The task - assignment center determines the first - part signature z 1,1 :

[0058] z 1,1 = θ1+(ω1 × r 3,1 + e 5,1 ),

[0059] where ω1, θ1 are elements selected from the discrete Gaussian distribution , r 3,1 is an element selected from the secret polynomial ξ A , r 3,1 ∈ ξ A , e 5,1 is an element selected from the noise polynomial ξ B , e 5,1 ∈ ξ B . Determine the hash value κ1 according to the following formula:

[0060] κ1 = H3(z 1,1 , m1);

[0061] With probability output the second - part signature z 2,1 :

[0062] z 2,1 = θ1 + κ1×(α TDC + γ TDC ),

[0063] With probability output the third - part signature z 3,1 :

[0064] z3,1 = θ1 - κ1 × h × (β TDC + δ TDC ).

[0065] ③ The task allocation center uploads part of the ciphertext information C 1,1 to the cloud storage system for storage through the smart contract on the side chain:

[0066] C 1,1 ← (ρ1, c 1,1 , c 2,1 , c 3,1 , c 4,1 , c 5,1 ),

[0067] The task label and the participating user information (ID CO , ID CT , ID CR ) and the storage address ad1 returned by the cloud storage system are uploaded to the side chain of the task allocation center for storage. The task label and part of the ciphertext information C 2,1 are uploaded to the consortium chain.

[0068] C 2,1 ← (z 1,1 , z 2,1 , z 3,1 ),

[0069] 4) The goods owner verifies the identity of the goods transporter. The goods transporter undertakes the transportation task. The goods owner summarizes the goods proof information m GP , the time T b when the goods transporter starts transportation, and other information in this transportation process in the second plaintext m2:

[0070] m2 ← {m G , m GP , ID CT , ID CR , T b},

[0071] The goods owner selects calculation parameters in the same way as the task allocation center and performs signcryption on the second plaintext m2 using the same steps to obtain the first part of the ciphertext information C 1,2 :

[0072] C 1,2 ← (ρ2, c 1,2 , c 2,2 , c 3,2 , c 4,2 , c 5,2 ),

[0073] and the second part of the ciphertext information C 2,2 :

[0074] C 2,2 ←(z 1,2 ,z 2,2 ,z 3,2 ),

[0075] The goods owner uploads the first part of the ciphertext information C to the cloud storage system for storage through the smart contract on the side chain; uploads the task label 1,2 and the participating user information (ID , ID CO , ID CT , ID CR ) and the storage address ad2 returned by the cloud storage system to the side chain of the goods owner for storage; uploads the task label and the partial ciphertext information C 2,2 to the consortium chain.

[0076] 5) The goods transporter starts transporting according to the route specified by the task distribution center. The IoT device on the transport vehicle starts recording the driving route and transport time. After the goods arrive, the smart contract on the side chain of the goods transporter aggregates the driving route W′, transport time T′ and other information during the transport in the third plaintext m3:

[0077] m3←{m G , ID CT , ID CR , W′, T′}

[0078] The goods transporter selects calculation parameters in the same way as the task distribution center and performs signcryption on the third plaintext m3 in the same steps to obtain the first part of the ciphertext information C 1,3 :

[0079] C 1,3 ←(ρ3, c 1,3 , c 2,3 , c 3,3 , c 4,3 , c 5,3 ),

[0080] and the second part of the ciphertext information C 2,3 :

[0081] C 2,3 ←(z 1,3 , z 2,3 , z 3,3 );

[0082] The goods transporter uploads the first part of the ciphertext information C to the cloud storage system for storage through the smart contract on the side chain; uploads the task label 1,3 ​ and the information of participating users (ID CO , ID CT , ID CR ) and the storage address ad3 returned by the cloud storage system are uploaded to the side chain of the goods transporter for storage; the task label and part of the ciphertext information C 2,3 are uploaded to the alliance chain; the goods transporter performs signcryption on the task label and the storage address ad3 returned by the cloud storage system to obtain the ciphertext and send the ciphertext to the recipient of the goods through the relay chain.

[0083] (5) Goods confirmation

[0084] The recipient of the goods performs the following decryption operation on the received ciphertext :

[0085] 1) The recipient of the goods uses the storage address ad3 to obtain part of the ciphertext information C 1,3 from the cloud storage system and performs the calculation:

[0086] μ′3 = c 2,3 + c 3,3 - β CR × c 4,3 - ζ CR × c 5,3 ,

[0087]

[0088] where μ′ 3,j represents the j-th bit of μ′3, j ∈ [1, t], and the recipient of the goods calculates:

[0089]

[0090] 2) The recipient of the goods uses the task label to obtain part of the ciphertext information C 2,3 sent by the task assignment center from the alliance chain and verifies whether the following equation holds:

[0091] z 2,3 × η CT - z 3,3 × η CT - H3(m′3, z 1,3 ) × PK ,CT = H3(m′3, z 1,3 ) × V CT × (η CT-1) If it holds, the goods receiver accepts the plaintext m′3, and obtains the driving route W′ and transportation time T′ of the Internet of Things device from m′3; otherwise, refuses to accept.

[0092] 3) The goods receiver summarizes the transportation task information m′1:

[0093]

[0094] The goods transporter verifies whether the following equation holds:

[0095] z 1,1 η× TDC -z 1,3 ×η TDC -H3(m′3,z 1,1 )×P K,TDC

[0096] =H3(m′3,z 1,1 )×V TDC ×(η TDC -1)

[0097] If the equation holds, the goods receiver accepts the goods; otherwise, refuses to accept.

[0098] In step (1) system initialization of the present invention, a security parameter N∈[2 7 ,2 9 bits, a large prime number q≥5 of 2 k bits is set, q satisfies gcd(p,q)=1, k takes the value of 8, and p takes the value of 3; in formula (1), the value range of A is (1,10], the value range of B is (1,10], and A is different from B.

[0099] In formula (1) of step (1) system initialization of the present invention, the preferred value range of A is (2,10], and the preferred value range of B is (2,10].

[0100] In formula (1) of step (1) system initialization of the present invention, the best value of A is 1.3, and the best value of B is 1.2.

[0101] In 1) of step (1) of the present invention, in the system management center setting the global attribute set U, the U:

[0102] U←{u1,u2,…,u n}

[0103] Wherein, n is the number of global attributes, the value range of n is 50 to 150, and U is sent to the task distribution center for storage through a secure channel.

[0104] In the system management center of step (1) of the present invention, in the global attribute set U, U is as follows:

[0105] U ← {u1, u2, …, u n}

[0106] where n is the number of global attributes, and the optimal value of n is 100. Send U to the task distribution center TDC for storage through a secure channel.

[0107] In the hash functions H1, H2, and H3 of step (1) of the present invention, t represents the length of the message plaintext m, and t takes a value of 256 bits.

[0108] Since the present invention ensures the authenticity of blockchain data during the cross-chain process, can resist quantum computing attacks on goods transportation data during the cross-chain process, and goods transporters can fairly compete for suitable transportation tasks according to their own attribute characteristics, avoiding the behavior of malicious attackers obtaining the identity information characteristics of goods transporters. The present invention has the advantages of anti-quantum computing attack, high signcryption efficiency, reducing the storage pressure of the blockchain, and ensuring the fairness of goods transportation, and is applicable to technical fields such as food, machinery, and military product transportation. BRIEF DESCRIPTION OF THE DRAWINGS

[0109] Figure 1 is the flowchart of Embodiment 1 of the present invention.

[0110] Figure 2 is the result graph of Embodiment 1 of the present invention and the comparative experiment. DETAILED DESCRIPTION OF THE INVENTION

[0111] The present invention will be further described in detail below with reference to the drawings and embodiments, but the present invention is not limited to the following embodiments.

[0112] Embodiment 1

[0113] The cross-chain goods transportation method based on NTRU lattice signcryption in this embodiment consists of the following steps (see Figure 1 ):

[0114] (1) System initialization

[0115] Set a security parameter N ∈ [2 7 , 2 9 bits. In this embodiment, N takes a value of 2 8 . Select a large prime number q ≥ 5 with 2 k bits, and q satisfies gcd(p, q) = 1, where k ∈ [7, 9]. In this embodiment, k takes a value of 8, p takes a value of 2 or 3, and in this embodiment, p takes a value of 3. Determine the Gaussian parameter σ according to Equation (1):

[0116]

[0117] Among them, A and B are coefficients. The value range of A is (1, 10], and the value range of B is (1, 10]. The preferred value range of A is (2, 10], and the preferred value range of B is (2, 10], and A and B are not the same. The optimal value of A in this embodiment is 1.3, and the optimal value of B is 1.2.

[0118] 1) The system management center sets the global attribute set U:

[0119] U ← {u1, u2, …, u n},

[0120] where n represents the number of global attributes, the value range of n is 50 to 150, and the value of n in this embodiment is 100. U is sent to the task distribution center TDC through a secure channel for storage.

[0121] 2) The system management center SMC obtains the system master public key h and the master private key D by using the trapdoor generation method.

[0122] 3) The system management center SMC selects three hash functions H1, H2, and H3 that resist quantum computing attacks:

[0123]

[0124] Among them, l1 represents the length of the user's identity; l2 represents an arbitrary length; t represents the length of the message plaintext m, t is a finite positive integer, t represents the length of the message plaintext m, and the value of t in this embodiment is 256 bits. represents the identity information of length l1 composed of 0 and 1; {0, 1} N represents the set of strings of length N composed of 0 and 1; represents the set of strings of arbitrary length composed of 0 and 1.

[0125] 4) The system management center determines the hash value V s :

[0126] V s = H1(ID s ),

[0127] where ID s represents the identity information of the system management center SMC; the private key (α s , β s ) is obtained by using the preimage sampling method, α s , β s ∈ R N,q , and α s + β s h = V s , || αs || represents α s 's normal form, ||β s || represents β s 's normal form.

[0128] 5) The system management center announces system parameters

[0129]

[0130] (2) Member joining

[0131] 1) When the task distribution center joins the system, it sends its identity information ID to the system management center SMC TDC ; After the system management center SMC approves the verification, it calculates the hash value V TDC :

[0132] V TDC = H1(ID TDC ),

[0133] where ID TDC represents the identity information of the task distribution center; The system management center SMC generates the partial private key (α TDC , β TDC ) of the task distribution center through the preimage sampling method, and satisfies:

[0134] α TDC + β TDC h = V TDC

[0135] where, ||α TDC || represents α TDC 's normal form, ||β TDC || represents β TDC 's normal form, and the system management center SMC sends its private key (α TDC , β TDC ) to the task distribution center; The task distribution center receives the private key (α TDC , β TDC ) and verifies:

[0136] α TDC + β TDC h = V TDC

[0137] If the equation holds, accept (α TDC , β TDC ) as the partial private key; If the verification fails, reject it and require the system management center SMC to resend. Other users in the system, the cargo owner CO, the cargo transporter CT, and the cargo receiver CR, extract the partial key using the same method;

[0138] 2) The task assignment center randomly selects as its own secret value, where is a discrete Gaussian distribution; the public key P of the task assignment center is determined by the following formula K,TDC :

[0139] P K,TDC = V TDC + η TDC × ζ TDC

[0140] ζ TDC = γ TDC + h × η TDC

[0141] η TDC = H2(ID TDC , V TDC , h)

[0142] The private key S of the task assignment center K,TDC ← {α TDC , β TDC , γ TDC , δ TDC}, and the public key is P K,TDC .

[0143] Other users in the system obtain public keys and private keys using the same method.

[0144] 3) The system management center selects an attribute set E CT for the goods transporter according to the identity information ID CT uploaded by the goods transporter, and the system management center performs the following operations:

[0145]

[0146] where U i represents the i-th attribute in U; represents the i-th bit in the transporter attribute vector , i ∈ [1, n], and n in this embodiment takes the value of 100.

[0147] The goods transporter determines the attribute vector according to the following formula

[0148]

[0149] (3) Select the goods transporter

[0150] 1) The task assignment center selects a suitable goods transporter and sets the access policy attribute set F A , E A ∈ U, and the task assignment center performs the following operations:

[0151]

[0152] Access policy vector

[0153] 2) The task assignment center publishes the transportation label on the consortium blockchain and the access policy vector The goods transporter sends the task label to the consortium blockchain smart contract Identity information ID CT , the attribute vector to run for election

[0154] 3) The consortium blockchain smart contract searches for the access policy vector corresponding to the task label on the consortium blockchain according to the election information sent by the goods transporter for attribute matching, and verifies whether the following equation holds:

[0155]

[0156] If the equation holds, send the identity information ID CT to the task assignment center and stop the attribute matching for the corresponding task label; otherwise, continue to accept the attribute matching until the matching is successful

[0157] (4) Transportation process

[0158] 1) The task assignment center receives the identity information ID CT , selects the optimal transportation route W and estimates the transportation time T according to the goods information m G and the vehicle information of the identity information ID CT

[0159] 2) The task assignment center sends to the goods owner sends to the goods transporter sends to the goods receiver

[0160] 3) The task assignment center summarizes all the information of this transportation process in the first plaintext m1:

[0161]

[0162] Sign and encrypt the first plaintext m1 as follows:

[0163] ① The task assignment center calculates:

[0164] ρ1 = v1(h × r 0,1 + e 0,1 )

[0165]

[0166]

[0167] Among them, v1, is an element selected from a discrete Gaussian distribution , r 0,1 , r 1,1 , r 2,1 is an element selected from the secret polynomial ξ A , r 0,1 , r 1,1 , r 2,1 ∈ ξ A , e 0,1 , e 1,1 , e 2,1 , e 3,1 , e 4,1 is an element selected from the noise polynomial ξ B , e 0,1 , e 1,1 , e 2,1 , e 3,1 , e 4,1 ∈ ξ B , μ1 is a set of strings of 0s and 1s of any positive integer length, P K,CR is the public key of the goods receiver, V CR is the hash value calculated according to the identity ID CR of the goods receiver, η CR is the hash value calculated according to (ID CR , V CR , h); ρ1, c 1,1 , c 2,1 , c 3,1 , c 4,1 , c 5,1 are partial ciphertexts in the calculation process

[0168] ② The task assignment center determines the first part of the signature z 1,1 as follows:

[0169] z 1,1 = θ1 + (ω1 × r 3,1 + e 5,1 ),

[0170] Among them, ω1, θ1 are elements selected from the discrete Gaussian distribution , r 3,1 is an element selected from the secret polynomial ξ A , r 3,1 ∈ ξ A , e5,1 is an element selected from the noise polynomial ξ B , e 5,1 ∈ξ B , and the hash value κ1 is determined according to the following formula:

[0171] κ1 = H3(z 1,1 , m1);

[0172] Output the second part of the signature z with probability 2,1 :

[0173] z 2,1 = θ1 + κ1 × (α TDC + γ TDC ),

[0174] Output the third part of the signature z with probability 3,1 :

[0175] z 3,1 = θ1 - κ1 × h × (β TDC + δ TDC )

[0176] ③ The task allocation center uploads part of the ciphertext information C 1,1 to the cloud storage system for storage through the smart contract on the side chain:

[0177] C 1,1 ← (ρ1, c 1,1 , c 2,1 , c 3,1 , c 4,1 , c 5,1 )

[0178] Upload the task label and the participating user information (ID CO , ID CT , ID CR ) and the storage address ad1 returned by the cloud storage system to the side chain of the task allocation center for storage, and upload the task label and part of the ciphertext information C 2,1 to the consortium chain:

[0179] C 2,1 ← (z 1,1 , z 2,1 , z 3,1 )

[0180] 4) The goods owner verifies the identity of the goods transporter, the goods transporter transports, and the goods owner provides the goods proof information m GP , the time T b, Other information of this transportation process is summarized in the second plaintext m2:

[0181] m2 ← {m G , m GP , ID CT , ID CR , T b}}

[0182] The goods owner selects calculation parameters in the same way as the task allocation center and performs signcryption on the second plaintext m2 using the same steps to obtain the first part of the ciphertext information C 1,2 :

[0183] C 1,2 ← (ρ2, c 1,2 , c 2,2 , c 3,2 , c 4,2 , c 5,2 ),

[0184] and the second part of the ciphertext information C 2,2 :

[0185] C 2,2 ← (z 1,2 , z 2,2 , z 3,2 ),

[0186] The goods owner uploads the first part of the ciphertext information C 1,2 to the cloud storage system for storage through the smart contract on the side chain; uploads the task label and the participating user information (ID CO , ID CT , ID CR ) and the storage address ad2 returned by the cloud storage system to the side chain of the goods owner for storage; uploads the task label and the partial ciphertext information C 2,2 to the consortium chain.

[0187] 5) The goods transporter starts transportation according to the route specified by the task allocation center. The IoT device on the transportation vehicle starts to record the driving route and transportation time. After the goods arrive, the smart contract on the side chain of the goods transporter summarizes the driving route W′, transportation time T′ and other information during the transportation process in the third plaintext m3:

[0188] m3 ← {m G , ID CT , ID CR , W′, T′},

[0189] The goods transporter selects calculation parameters in the same way as the task allocation center, and performs signcryption on the third plaintext m3 in the same steps to obtain the first part of ciphertext information C 1,3 :

[0190] C 1,3 ←(ρ3,c 1,3 ,c 2,3 ,c 3,3 ,c 4,3 ,c 5,3 ),

[0191] and the second part of ciphertext information C 2,3 :

[0192] C 2,3 ←(z 1,3 ,z 2,3 ,z 3,3 ).

[0193] The goods transporter uploads the first part of ciphertext information C 1,3 to the cloud storage system for storage through the smart contract on the side chain; uploads the task label and the participating user information (ID CO ,ID CT ,ID CR ) and the storage address ad3 returned by the cloud storage system to the side chain of the goods transporter for storage; uploads the task label and the partial ciphertext information C 2,3 to the consortium chain; the goods transporter signs and encrypts the task label and the storage address ad3 returned by the cloud storage system to obtain the ciphertext and sends the ciphertext information to the goods receiver through the relay chain.

[0194] (5) Goods confirmation

[0195] The goods receiver decrypts the received ciphertext as follows:

[0196] 1) The goods receiver uses the storage address ad3 to obtain the partial ciphertext information C 1,3 from the cloud storage system and performs the calculation:

[0197] μ′3 = c 2,3 + c 3,3 - β CR × c 4,3 - ζ CR × c 5,3

[0198]

[0199] Among them, μ′ 3,j represents the j-th bit of μ′3, where j ∈ [1, t], and the goods receiver calculates:

[0200]

[0201] 2) The goods receiver uses the task label to obtain the partial ciphertext information C sent by the task distribution center from the consortium chain 2,3 , and verifies whether the following equation holds:

[0202] z 2,3 × η CT - z 3,3 × η CT - H3(m′3, z 1,3 ) × P K,CT = H3(m′3, z 1,3 ) × V CT × (η CT - 1). If it holds, the goods receiver accepts the plaintext m′3, and obtains the driving route W′ and transportation time T′ recorded by the Internet of Things device from m′3; otherwise, rejects it;

[0203] 3) The goods receiver summarizes the transportation task information m′1:

[0204]

[0205] The goods transporter verifies whether the following equation holds:

[0206] z 1,1 η × TDC - z 1,3 × η TDC - H3(m′3, z 1,1 ) × P K,TDC

[0207] = H3(m′3, z 1,1 ) × V TDC × (η TDC - 1)

[0208] If the equation holds, the goods receiver accepts the goods; otherwise, rejects them.

[0209] The cross-chain goods transportation method based on NTRU lattice signcryption is completed.

[0210] Example 2

[0211] The cross-chain goods transportation method based on NTRU lattice signcryption in this example consists of the following steps:

[0212] (1) System initialization

[0213] Set a security parameter \(N\in[2 7 ,2 9 bits. In this embodiment, \(N\) takes the value of 2 7 . Select a large prime number \(q\geq5\) with 2 k bits, where \(q\) satisfies \(\gcd(p,q)=1\), where \(k\in[7,9]\). In this embodiment, \(k\) takes the value of 7, and \(p\) takes the value of 2 or 3. In this embodiment, \(p\) takes the value of 2. Determine the Gaussian parameter \(\sigma\) according to Equation (1):

[0214]

[0215] where \(A\) and \(B\) are coefficients. The value range of \(A\) is \((1,10]\), the value range of \(B\) is \((1,10]\), and \(A\) and \(B\) are different. In this embodiment, \(A\) takes the value of 5 and \(B\) takes the value of 10.

[0216] 1) The system management center sets the global attribute set \(U\):

[0217] \(U\leftarrow\{u_1,u_2,\cdots,u n \}\),

[0218] where \(n\) represents the number of global attributes, and the value range of \(n\) is 50 - 150. In this embodiment, \(n\) takes the value of 50. Send \(U\) to the task distribution center TDC for storage through a secure channel.

[0219] Other steps of this step are the same as those in Embodiment 1.

[0220] (2) Member joining

[0221] Steps 1) and 2) are the same as those in Embodiment 1.

[0222] 3) The system management center selects an attribute set \(E\) for the transporter according to the identity information ID CT uploaded by the goods transporter CT \(\in U\). The system management center performs the following operations:

[0223]

[0224] where \(U i represents the \(i\)-th attribute in \(U\); represents the \(i\)-th bit in the transporter attribute vector , \(i\in[1,n]\). In this embodiment, \(n\) takes the value of 50.

[0225] Other steps of this step are the same as those in Embodiment 1.

[0226] Other steps are the same as those in Embodiment 1. Complete the cross-chain goods transportation method based on NTRU lattice signcryption.

[0227] Embodiment 3

[0228] The cross-chain cargo transportation method based on NTRU lattice signcryption in this embodiment consists of the following steps:

[0229] (1) System initialization

[0230] Set a security parameter N ∈ [2 7 , 2 9 , and in this embodiment, N is taken as 2 9 , select a large prime number q ≥ 5 with 2 k bits, where q satisfies gcd(p, q) = 1, where k ∈ [7, 9], in this embodiment, k is taken as 9, p is taken as 2 or 3, and in this embodiment, p is taken as 3. Determine the Gaussian parameter σ according to Equation (1):

[0231]

[0232] where A and B are coefficients, the value range of A is (1, 10], the value range of B is (1, 10], and A and B are different. In this embodiment, A is taken as 10 and B is taken as 5.

[0233] 1) The system management center sets the global attribute set U:

[0234] U ← {u1, u2, …, u n},

[0235] where n represents the number of global attributes, and the value range is 50 to 150. In this embodiment, n is taken as 150, and U is sent to the task distribution center TDC for storage through a secure channel.

[0236] (2) Member joining

[0237] Steps 1) and 2) are the same as those in Embodiment 1.

[0238] 3) The system management center selects an attribute set E CT ∈ U for the transporter according to the identity information ID CT uploaded by the cargo transporter, and the system management center performs the following operations:

[0239]

[0240] where U i represents the i-th attribute in U; represents the i-th bit in the transporter attribute vector , i ∈ [1, n], and in this embodiment, n is taken as 150.

[0241] The other steps of this step are the same as those in Embodiment 1.

[0242] The other steps are the same as those in Embodiment 1. The cross-chain cargo transportation method based on NTRU lattice signcryption is completed.

[0243] To verify the beneficial effects of the present invention, the inventors conducted a comparative experiment on the calculation time using the cross-chain cargo transportation method based on NTRU lattice signcryption in Embodiment 1 of the present invention (hereinafter referred to as Embodiment 1) and Secure cloud-based data storage scheme using postquantum integer lattices based signcryption for IoT applications (hereinafter referred to as Comparative Experiment 1), Identity-based searchable attribute signcryption in lattice for a blockchain-based medical system (hereinafter referred to as Comparative Experiment 2), Lattices-Inspired CP ABE from LWE Scheme for Data Access and Sharing Based on Blockchain (hereinafter referred to as Comparative Experiment 3). The experimental results are shown in Table 1 and Figure 2 .

[0244] Table 1 Results of the calculation time of Embodiment 1 and the comparative experiments

[0245]

[0246] As can be seen from Table 1 and Figure 2 it can be seen that the signcryption operation time of Embodiment 1 is slightly higher than that of Comparative Experiments 1 and 2. This is because the rejection sampling algorithm is used in the signcryption operation of Embodiment 1, resulting in a higher time. However, the unsigncryption operation time and the overall operation time of Embodiment 1 are much lower than those of the comparative experimental methods.

Claims

1. A cross-chain cargo transportation method based on NTRU lattice signcryption, characterized in that It consists of the following steps: (1) System initialization Assume a security parameter N∈[2 7 ,2 9 ] bits, select 2 k The large prime number of bits q≥5, q satisfies gcd(p,q)=1, where k∈[7,9], p is 2 or 3, and the Gaussian parameter σ is determined according to formula (1): Among them, A and B are coefficients, A, B are positive numbers at least 1, and A and B are different; 1) The system management center sets the global attribute set U: U←{u1,u2,…,u n }, Where n represents the number of global attributes, n is a finite positive integer, and U is sent to the task allocation center through a secure channel for storage; 2) The system management center SMC uses the trapdoor generation method to obtain the system master public key h and master private key D; 3) The system management center SMC selects three hash functions H1, H2, and H3 that are resistant to quantum computing attacks: Where l1 represents the length of the user identity; l2 represents an arbitrary length; t represents the length of the message plaintext m, and t is a finite positive integer; Represents identity information consisting of 0 and 1 with a length of l1; {0,1} N Represents a string of length N consisting of 0 and 1; Represents a set of strings of any length consisting of 0s and 1s; 4) The system management center determines the hash value V s : In s =H1(ID s ), Among them, ID s Represents the identity information of the system management center SMC; the original image sampling method is used to obtain the private key (α s ,β s ), α s ,β s ∈R N,q , α s +β s h=V s , ‖α s ‖, ||α s || represents α s The paradigm of ||β s || means β s paradigm; 5) System Management Center announces system parameters (2) Membership 1) When the task distribution center joins the system, it sends the identity information ID to the system management center SMC TDC ; The system management center SMC has passed the review and calculated the hash value V TDC : In TDC =H1(ID TDC ), Among them, ID TDC Represents the identity information of the task distribution center; the system management center SMC generates part of the private key of the task distribution center through the original image sampling method (α TDC ,β TDC ), and satisfy: a TDC +b TDC h=V TDC Among them, ||α TDC ||, ||α TDC || represents α TDC The paradigm of ||β TDC || means β TDC The system management center SMC sends its private key (α TDC ,β TDC ); the task distribution center receives the private key (α TDC ,β TDC ),verify: a TDC +b TDC h=V TDC If the equality holds, accept (α TDC ,β TDC ) as a partial private key; if the verification fails, it is rejected and the system management center SMC is requested to resend it. Other users in the system, cargo owner CO, cargo transporter CT, and cargo receiver CR, use the same method to extract partial keys; 2) Random selection of task allocation centers As its secret value, is a discrete Gaussian distribution; the public key P of the task distribution center is determined by the following formula K,TDC : P K,TDC =V TDC +n TDC ×ζ TDC g TDC =c TDC +h×d TDC η TDC =H2(ID TDC ,V TDC ,h) The private key S of the task distribution center K,TDC ←{α TDC ,β TDC ,γ TDC ,δ TDC }, the public key is P K,TDC ; Other users in the system use the same method to obtain public and private keys; 3) The system management center will collect the ID information uploaded by the cargo transporter. CT , select attribute set E for it CT ∈U, the system management center performs the following operations: Among them, U i represents the i-th attribute in U; Represents the transporter attribute vector The i-th position in , i∈[1,n]; The cargo transporter determines the attribute vector as follows: (3) Select the freight forwarder 1) The task allocation center selects a suitable cargo transporter and sets the access policy attribute set E A ,E A ∈U, the task allocation center performs the following operations: Access Policy Vector 2) The task distribution center publishes the transport number on the alliance chain and access policy vector The cargo transporter sends the task number to the consortium chain smart contract Identity information ID CT , attribute vector Conduct election campaigns; 3) The alliance chain smart contract searches for the task number on the alliance chain based on the campaign information sent by the cargo transporter The corresponding access policy vector Perform attribute matching to verify whether the following equation holds: If the equation holds, send the ID CT For the task allocation center, stop the attribute matching of the corresponding task number; otherwise, continue to accept attribute matching until the matching is successful; (4) Transportation process 1) The task distribution center receives the identity information ID CT , according to the cargo information m G and identity information ID CT Based on the vehicle information, select the optimal transportation route W and estimate the transportation time T; 2) The task distribution center sends the goods owner Send to freight forwarder Send to the consignee 3) The task distribution center summarizes all the information of the transportation process in the first plaintext m1: The first plaintext m1 is signed as follows: ①Task allocation center calculation: ρ1=v1×(h×r 0,1 +e 0,1 ) c 3,1 =θ1×(V CR ×(r 2,1 -r 1,1 )+e 2,1 ) c 4,1 =θ1×(h×r 2,1 +e 3,1 ) c 5,1 =θ1×(η CR ×r 1,1 +e 4,1 ) Among them, v1,θ1 are from discrete Gaussian distribution The selected element, v1, r 0,1 ,r 1,1 ,r 2,1 is the secret polynomial ξ A The elements selected from 0,1 ,r 1,1 ,r 2,1 ∈ξ A , e 0,1 ,e 1,1 ,e 2,1 ,e 3,1 ,e 4,1 is the noise polynomial ξ B The selected element, e 0,1 ,e 1,1 ,e 2,1 ,e 3,1 ,e 4,1 ∈ξ B , μ1 is a set of strings of any positive integer length consisting of 0 and 1, P K,CR is the public key of the recipient of the goods, V CR Based on the ID of the recipient of the goods CR The calculated hash value, η CR According to (ID CR ,V CR ,h) calculated hash value; ρ1, c 1,1 、c 2,1 、c 3,1 、c 4,1 、c 5,1 It is part of the ciphertext in the calculation process; ②The task allocation center determines the first part of the signature z according to the formula 1,1 : z 1,1 =θ1+(ω1×r 3,1 +e 5,1 ), Among them, ω1, θ1 are from discrete Gaussian distribution The selected elements in ω1, r 3,1 is the secret polynomial ξ A The elements selected from 3,1 ∈ξ A , e 5,1 is the noise polynomial ξ B The selected element, e 5,1 ∈ξ B ; Determine the hash value κ1 as follows: κ1=H3(z 1,1 ,m1); By probability Output the second part of the signature z 2,1 : z 2,1 =θ1+κ1×(α TDC +g TDC ), By probability Output the third part of the signature z 3,1 : z 3,1 =θ1-κ1×h×(β TDC +d TDC ); ③The task distribution center sends part of the encrypted information C through the smart contract on the side chain. 1,1 Upload to cloud storage system for storage: C 1,1 ←(ρ1,c 1,1 ,c 2,1 ,c 3,1 ,c 4,1 ,c 5,1 ) Label the task and participating user information (ID CO ,ID CT ,ID CR ) and the storage address ad1 returned by the cloud storage system are uploaded to the task allocation center side chain for storage, and the task number and part of the ciphertext information C 2,1 Upload to the consortium chain: C 2,1 ←(from 1,1 ,With 2,1 ,With 3,1 ) 4) The cargo owner verifies the identity of the cargo transporter, the cargo transporter undertakes the transportation task, and the cargo owner submits the cargo certification information to GP , the time when the freight transporter starts transporting T b , other information of this transportation process is summarized in the second plaintext m2: m2←{m G ,m GP ,ID CT ,ID CR ,T b } The cargo owner selects the calculation parameters in the same way as the task distribution center, and uses the same steps to signcrypt the second plaintext m2 to obtain the first part of the ciphertext information C 1,2 : C 1,2 ←(ρ2,c 1,2 ,c 2,2 ,c 3,2 ,c 4,2 ,c 5,2 ), and the second part of the ciphertext information C 2,2 : C 2,2 ←(from 1,2 ,With 2,2 ,With 3,2 ), The owner of the goods sends the first part of the encrypted information C through the smart contract on the side chain. 1,2 Upload to the cloud storage system for storage; label the task and participating user information (ID CO ,ID CT ,ID CR ) and the storage address ad2 returned by the cloud storage system are uploaded to the side chain of the goods owner for storage; the task number and part of the ciphertext information C 2,2 Upload to the consortium chain; 5) The freight transporter starts transporting goods according to the route specified by the task allocation center, and the IoT device on the transport tool starts recording the route and transportation time. After the goods arrive, the smart contract on the freight transporter's side chain summarizes the route W', transportation time T' and other information recorded by the IoT device during the transportation process in the third plaintext m3: m3←{m G ,ID CT ,ID CR ,W′,T′}, The cargo transporter selects the calculation parameters in the same way as the task allocation center, and uses the same steps to signcrypt the third plaintext m3 to obtain the first part of the ciphertext information C 1,3 : C 1,3 ←(ρ3,c 1,3 ,c 2,3 ,c 3,3 ,c 4,3 ,c 5,3 ), and the second part of the ciphertext information C 2,3 : C 2,3 ←(from 1,3 ,With 2,3 ,With 3,3 ); The cargo transporter sends the first part of the encrypted information C through the smart contract on the side chain. 1,3 Upload to the cloud storage system for storage; label the task and participating user information (ID CO ,ID CT ,ID CR ) and the storage address ad3 returned by the cloud storage system are uploaded to the side chain of the cargo transporter for storage; the task number and part of the ciphertext information C 2,3 Upload to the alliance chain; cargo transporters label the tasks Sign and encrypt the storage address ad3 returned by the cloud storage system to obtain the ciphertext Pass the ciphertext through the relay chain sent to the recipient of the goods; (5) Goods confirmation The recipient of the goods receives the ciphertext Perform the following decryption operations: 1) The recipient of the goods uses the storage address ad3 to obtain part of the ciphertext information C from the cloud storage system 1,3 , and calculate: μ′3=c 2,3 +c 3,3 -b CR ×c 4,3 -g CR ×c 5,3 , Among them, μ′ 3,j Denote the jth bit of μ′3, j∈[1,t], the receiver of the goods calculates: 2) The cargo receiver uses the task number Get part of the ciphertext information C sent by the task distribution center from the alliance chain 2,3 , verify whether the following equation holds: With 2,3 ×η CT -With 3,3 ×η CT -H3(m′3,z 1,3 )×P K,CT =H3(m′3,z 1,3 )×V CT ×(η CT -1) If so, the cargo receiver accepts the plaintext m′3 and obtains the driving route W′ and transportation time T′ recorded by the IoT device from m′3; otherwise, it refuses to accept it; 3) The cargo recipient summarizes the transportation task information m′1: The freight transporter verifies that the following equation holds true: With 1,1 η× TDC -With 1,3 ×η TDC -H3(m′3,z 1,1 )×P K,TDC =H3(m′3,z 1,1 )×V TDC ×(η TDC -1) If the equation holds true, the receiver of the goods accepts the goods, otherwise refuses to accept them.

2. The cross-chain cargo transportation method based on NTRU lattice signcryption according to claim 1 is characterized in that: In step (1) system initialization, a security parameter N∈[2 7 ,2 9 ] bits, 2 k The large prime number of bits q≥5, q satisfies gcd(p,q)=1, k is 8, and p is 3; in formula (1), the value range of A is (1,10], the value range of B is (1,10], and A and B are different.

3. The cross-chain cargo transportation method based on NTRU lattice signcryption according to claim 1 or 2, characterized in that: In the formula (1) of the system initialization in step (1), the value range of A is (2, 10], and the value range of B is (2, 10].

4. The cross-chain cargo transportation method based on NTRU lattice signcryption according to claim 1 or 2, characterized in that: In the formula (1) of the system initialization in step (1), the value range of A is 1.3, and the value range of B is 1.

2.

5. The cross-chain cargo transportation method based on NTRU lattice signcryption according to claim 3 is characterized in that: In the formula (1) of the system initialization in step (1), the value range of A is 1.3, and the value range of B is 1.

2.

6. The cross-chain cargo transportation method based on NTRU lattice signcryption according to claim 1 is characterized in that: In step (1) 1) the system management center sets a global attribute set U, wherein U: U←{u1,u2,…,u n } Wherein, n is the number of global attributes, and the value range of n is 50 to 150. U is sent to the task allocation center through a secure channel for storage.

7. The cross-chain cargo transportation method based on NTRU lattice signcryption according to claim 1 or 6, characterized in that: In step (1) 1) the system management center sets a global attribute set U, wherein U: U←{u1,u2,…,u n } Wherein, n is the number of global attributes, and the value of n is 100. U is sent to the task distribution center TDC through a secure channel for storage.

8. The cross-chain cargo transportation method based on NTRU lattice signcryption according to claim 1 is characterized in that: In the hash functions H1, H2, and H3 of step (1) 3), the t represents the length of the message plaintext m, and the value of t is 256 bits.