Attribute encryption-based hidden transmission method for Portuo group messages

By adopting an attribute-based encryption method on the Monero blockchain, fine-grained access control for group hidden transmission is realized, transaction redundancy and key management problems in the prior art are solved, and the concealment and efficiency of the transmission channel are improved.

CN120185803APending Publication Date: 2025-06-20BEIJING JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510009790.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing hidden transmission method based on blockchain is difficult to achieve hidden group transmission, and there are problems such as transaction redundancy, the inability to achieve fine-grained access control, and the need for prior negotiation of group keys.

Method used

The method based on attribute encryption is adopted to enable the sender to formulate an access control strategy based on the attributes of the receiver, and to issue attribute keys and share viewing keys through the on-chain channel to realize fine-grained access control of a single hidden transmission transaction, avoiding the occurrence of redundant transactions.

Benefits of technology

It effectively reduces the number of transactions, realizes access control of multiple users for a single hidden transmission transaction, avoids the occurrence of redundant transactions, and reduces the burden of key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185803A_ABST
    Figure CN120185803A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of block chains, and relates to an attribute encryption-based porule group message hidden transmission method, which is used for block chain group anonymous hidden communication. An attribute-based encryption mechanism is adopted, and the method mainly comprises a key negotiation stage and a group transmission stage. In the key negotiation stage, a sender and a plurality of receivers negotiate an attribute key on a chain and share a check key, so that the risk of key leakage under the chain is reduced; in a group transmission stage, an access control strategy is embedded when a sender encrypts a message, and a receiver identifies a hidden transaction by using a check key and decrypts and extracts a hidden message by using an attribute key. The method is suitable for a group hidden transmission scene with a plurality of message receivers, avoids the risk of key leakage in an under-chain negotiation process, and realizes management of access control of the plurality of receivers to the messages in a single transaction. According to the method, repeated messages are prevented from being sent to a plurality of receivers, the risk that an opponent successfully detects the transmission channel is reduced, and privacy security is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of blockchain, and relates to a method for covert transmission of Monero group messages based on attribute encryption. Background Art

[0002] Covert transmission is a transmission behavior in which the transmitted content is only understood by both parties and not detected by a third party. The progress of blockchain technology has avoided the problem of single-point facility failure in traditional covert transmission and provided a more covert transmission channel for covert transmission. The decentralized feature of blockchain makes covert messages tamper-proof and guarantees the integrity of the messages; flooding broadcast avoids the directional propagation of messages and improves the covertness of the transmission channel.

[0003] The Monero blockchain is a type of blockchain that has emerged in recent years and has multiple privacy protection mechanisms. The privacy protection mechanisms of the Monero blockchain provide a more secure transmission channel for covert transmission. For example, the ring signature mechanism can hide the transaction sender address, and the one-time address can hide the transaction recipient address, etc.

[0004] Group covert transmission refers to a covert transmission scenario with multiple participants. Existing blockchain-based covert transmission methods are mostly used in dual-user scenarios and cannot be directly applied to group covert transmission. For example, when a single sender sends the same message to multiple recipients, a large number of redundant transactions with the same message need to be sent repeatedly. The increase in transaction samples will increase the probability of an adversary successfully detecting the transmission channel. In addition, the sender needs to manage the corresponding keys for each recipient, which causes a high key management burden on the sender. Some covert transmission methods can be used in one-to-many scenarios, but they require prior negotiation of group keys, and finer-grained access control cannot be performed within the group.

[0005] To solve the problems of message transaction redundancy, inability to achieve fine-grained access control, and the need for prior negotiation of group keys in existing methods, this patent proposes a method for covert transmission of Monero group messages based on the attribute encryption mechanism.

[0006] This method is based on the attribute encryption mechanism, enabling the sender to formulate an access control policy according to the recipient attributes, allowing users who meet the access control policy to decrypt the ciphertext to obtain the original message, which conforms to the group covert transmission scenario. This method issues attribute keys and shared viewing keys through an on-chain channel, which can effectively reduce the number of transactions while ensuring the confidentiality of the keys, realizes access control of multiple users to a single covert transmission transaction, and avoids the generation of redundant transactions. Summary of the Invention

[0007] The object of the present invention is to creatively propose a method for stealthy transmission of Monero group messages based on attribute encryption to address the problems of transaction redundancy, inability to achieve fine-grained access control, and the need for prior negotiation of group keys in existing group stealthy transmission methods. It can avoid off-chain negotiation of group keys, achieve fine-grained access control for single stealthy transaction messages in the group by embedding access control policies in ciphertext, realize transaction multiplexing, and effectively reduce the number of transactions.

[0008] The object of the present invention is solved by the following technical solutions.

[0009] A method for stealthy transmission of Monero group messages based on attribute encryption, comprising the following steps:

[0010] Step 1, the message sender initializes the master key and public key of attribute encryption, starts two full Monero nodes and two light nodes, which serve as the message sending node and the transaction receiving node respectively; each message receiver starts one full Monero node and one light node as the message receiving node;

[0011] Step 2, based on the master key described in Step 1, the message sender extracts the attributes of each message receiver, generates attribute keys, and after authentication, distributes the attribute keys on-chain in combination with the InterPlanetary File System;

[0012] Step 3, the message sender shares the viewing key of the transaction receiving node with the message receiver through the Monero blockchain to directionally filter stealthy transactions;

[0013] Step 4, the message sender designs an access control policy, encrypts the stealthy message in combination with the public key described in Step 1 to generate ciphertext, uploads the ciphertext to the InterPlanetary File System to obtain the content identifier, and embeds the identifier into the Monero transaction and then broadcasts it to the blockchain network;

[0014] Step 5, the message receiver identifies the stealthy transaction based on the viewing key described in Step 3 and extracts the content identifier, decrypts after obtaining the message ciphertext, and whether the decryption is successful depends on the access control policy described in Step 4.

[0015] The advantages of the present invention are as follows: (1) All keys are stealthily transmitted using on-chain Monero transactions, avoiding key leakage caused by off-chain attacks by adversaries; (2) Fine-grained access control, the present invention can achieve access control for different receivers through attribute encryption, without repeatedly sending the same message to receivers with different permissions, which can effectively reduce the transaction volume; (3) There is no need to repeatedly negotiate attribute keys. When the sender needs to modify the access control policy, there is no need to renegotiate the keys with the message receiver, and only the access control policy needs to be modified. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 is a schematic diagram of the method flow of the present invention

[0017] Figure 2 It is a schematic diagram of group stealth transmission access control in the method of the present invention Detailed implementation manners

[0018] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention

[0019] Embodiment

[0020] As Figure 1 and Figure 2 shown, the present invention proposes a method for stealth transmission of Monero group messages based on attribute encryption, including the following processes

[0021] Step 1, the message sender initializes the master key and public key of attribute encryption, and starts two Monero full nodes and two wallet nodes, which are used as the message sending node and the transaction receiving node respectively; each message receiver starts a Monero full node and a light node as the message receiving node

[0022] Step 2, based on the master key described in Step 1, the message sender extracts the attributes of each message receiver, generates attribute keys, and after authentication, distributes the attribute keys on the chain in combination with the InterPlanetary File System

[0023] Step 3, the message sender shares the viewing key of the transaction receiving node with the message receiver through the Monero blockchain to directionally filter stealth transactions

[0024] Step 4, the message sender designs an access control policy, encrypts the stealth message in combination with the public key described in Step 1 to generate a ciphertext, uploads the ciphertext to the InterPlanetary File System to obtain a content identifier, embeds the identifier into the Monero transaction, and then broadcasts it to the test chain network

[0025] Step 5, the message receiver identifies the stealth transaction based on the viewing key described in Step 3 and extracts the content identifier, decrypts the message ciphertext after obtaining it, and whether the decryption is successful depends on the access control policy described in Step 4

[0026] The specific process of Step 1 is as follows

[0027] Step 11, the message sender generates a master key and a system public key; the message sender refers to the stealth message sender; the master key is private to the sender, and the system public key is publicly disclosed by the sender

[0028] Step 12: The message sender creates two different Monero light nodes and starts the corresponding Monero full nodes respectively, both of which are connected to the test chain network; the test chain network is a network used for application testing for scientific research purposes, and all nodes, accounts, and transactions are for test purposes and do not involve virtual currency transactions;

[0029] Step 13: The message sender selects the nodes described in Step 12 as the message sending node and the transaction receiving node respectively; the message sending node is the sending node of the covert message; the transaction receiving node is the receiving node of the covert transaction;

[0030] Step 14: Each message receiver starts a Monero full node and a light node and connects to the Monero test chain network; the message receiver is the covert message receiver.

[0031] The specific process of Step 2 is as follows:

[0032] Step 21: The message sender extracts the attributes of multiple message receivers;

[0033] Step 22: The message sender uses the master key described in Step 11 and the attributes described in Step 21 to generate attribute keys;

[0034] Step 23: The message sender and the message receiver start the InterPlanetary File System nodes respectively and connect to the InterPlanetary File System network;

[0035] Step 24: The message receiver authenticates the message sender;

[0036] The specific process of Step 24 is as follows:

[0037] Step 241: The message sender generates a digital signature using its own viewing private key; the viewing private key is used to filter Monero transactions pointing to the corresponding viewing public key in the Monero blockchain; the viewing public key is one of the components of the Monero account address;

[0038] Step 242: The message sender embeds the digital signature into the Monero transaction to form an authentication transaction and sends it to the blockchain network; the authentication transaction refers to a Monero transaction used to authenticate the sender's identity and can prevent an adversary from sending a transaction carrying forged information;

[0039] Step 243: After obtaining the authentication transaction, the message receiver verifies the digital signature using the message sender's viewing public key and saves the digital signature;

[0040] Step 25: After encrypting the attribute key of each message receiver, the message sender combines the InterPlanetary File System and the Monero blockchain to distribute the key;

[0041] The specific process of Step 25 is as follows:

[0042] Step 251, the message sender creates Monero transactions pointing to each message recipient and saves the shared secret during the transaction generation process; the shared secret is an intermediate variable of the Monero transaction one-time address, which can only be calculated by the transaction sender and recipient, and an attacker cannot successfully calculate this shared secret within polynomial time;

[0043] Step 252, the message sender uses the hash value of the shared secret described in Step 251 as the AES encryption key to encrypt the attribute key described in Step 22 and upload it to the InterPlanetary File System and obtain the content identifier; the content identifier is a base58-encoded hash value;

[0044] Step 253, the message sender encrypts the content identifier using the AES encryption key described in Step 252 and embeds it into the Monero transaction to form a transmission transaction. The "amount" field in the transaction is generated by combining the fixed prefix of the content identifier with the digital signature encoding described in Step 243, and is sent to the Monero test chain network; the transmission transaction refers to the Monero transaction for transmitting the covert message; the fixed prefix of the content identifier refers to the hexadecimal string "0x1220"; the "amount" field of the transaction refers to the field name in the transaction;

[0045] Step 26, the message recipient extracts the content identifier from the transmission transaction described in Step 253, downloads the ciphertext from the InterPlanetary File System and decrypts it to obtain the attribute key.

[0046] The specific process of Step 3 is as follows:

[0047] Step 31, the message sender extracts the viewing private key of the transaction recipient node described in Step 12 and embeds it into the Monero transaction for transmission to each message recipient;

[0048] The specific process of Step 31 is as follows:

[0049] Step 311, the message sender creates a Monero transaction pointing to the message recipient and saves the shared secret during the transaction generation process;

[0050] Step 312, the message sender extracts the viewing private key of the transaction recipient node and encrypts it using the hash value of the shared secret described in Step 311 as the AES encryption key;

[0051] Step 313, the message sender embeds the ciphertext of the viewing private key described in Step 312 into the Monero transaction to form a transmission transaction. The "amount" field of the transaction is generated by combining the fixed identifier with the digital signature encoding described in Step 243, and sends this transaction to the Monero test chain network; the fixed identifier refers to the hexadecimal encoding of the string "view";

[0052] Step 32, after the message recipient obtains the transmission transaction described in step 313, decrypt it to obtain the viewing private key.

[0053] The specific process of step 4 is as follows:

[0054] Step 41, the message sender generates an access control policy according to the attributes of each message recipient;

[0055] Step 42, the message sender encrypts the message using the public key described in step 11 and the access control policy described in step 41 to generate a message ciphertext;

[0056] Step 43, the message sender uploads the message ciphertext described in step 42 to the InterPlanetary File System and obtains the corresponding content identifier;

[0057] Step 44, the message sender creates a transmission transaction pointing to the transaction receiving node described in step 12, embeds the content identifier described in step 43 into the transaction, and encodes the message sequence number into the "amount" field of the transaction;

[0058] Step 45, the message sender sends the transmission transaction described in step 44 to the Monero test chain network.

[0059] The specific process of step 5 is as follows:

[0060] Step 51, the message recipient uses the viewing private key described in step 32 to identify the transmission transaction described in step 45 and obtains the content identifier;

[0061] Step 52, the message recipient uses the content identifier described in step 51 to obtain the message ciphertext from the InterPlanetary File System;

[0062] Step 53, as Figure 2 shown, the message recipient attempts to decrypt the message ciphertext. If it conforms to the policy described in step 41, the decryption is successful; otherwise, the decryption fails.

[0063] Thus, this method completes the implementation of the method for covert transmission of Monero group messages based on attribute encryption.

Claims

1. A method for concealed transmission of Monero group messages based on attribute encryption, the method comprising: Step 1: The message sender initializes the master key and public key of attribute encryption, starts two Monero full nodes and two light nodes, which serve as message sending nodes and transaction receiving nodes respectively; each message receiver starts a Monero full node and a light node as message receiving nodes; Step 2: Based on the master key in step 1, the message sender extracts the attributes of each message recipient, generates an attribute key, performs identity authentication, and distributes the attribute key on the chain in combination with the InterPlanetary File System; Step 3: The message sender shares the viewing key of the transaction receiving node with the message receiver through the Monero blockchain to filter hidden transactions in a targeted manner. Step 4: The message sender designs an access control strategy, encrypts the hidden message with the public key described in step 1 to generate ciphertext, uploads the ciphertext to the InterPlanetary File System, obtains the content identifier, embeds the identifier into the Monero transaction, and broadcasts it to the test chain network; Step 5: The message receiver identifies the concealed transaction and extracts the content identifier based on the viewing key described in step 3, obtains the message ciphertext and then decrypts it. Whether the decryption is successful depends on the access control policy described in step 4.

2. The method according to claim 1, characterized in that The specific process of step 1 is as follows: Step 11, the message sender generates a master key and a system public key; the message sender refers to the hidden message sender; Step 12: The message sender creates two different Monero light nodes and starts the corresponding Monero full nodes respectively. Step 13, the message sender selects the nodes in step 12 as the message sending node and the transaction receiving node respectively; the message sending node refers to the sending node of the concealed message; the transaction receiving node refers to the receiving node of the concealed transaction; the concealed transaction refers to the transaction embedded with concealed information; Step 14, each message recipient starts a Monero full node and a light node, and connects to the Monero test chain network; the message recipient is a hidden message recipient.

3. The method according to claim 1, characterized in that The specific process of step 2 is: Step 21, the message sender extracts attributes of multiple message receivers; Step 22, the message sender generates an attribute key using the master key described in step 11 and the attribute described in step 21; Step 23, the message sender and the message receiver respectively start the InterPlanetary File System node and connect to the InterPlanetary File System network; Step 24, the message receiver authenticates the message sender; The specific process of step 24 is as follows: Step 241, the message sender generates a digital signature using its own private key; the private key is used to filter Monero transactions pointing to the corresponding public key in the Monero blockchain; the public key is one of the components of the Monero account address; the Monero blockchain refers to the Monero test chain network; the Monero transaction refers to the test transaction in the Monero test chain network; Step 242, the message sender embeds the digital signature into the Monero transaction to form an authenticated transaction and sends it to the blockchain network; Step 243, after the message receiver obtains the authentication transaction, it uses the message sender to view the public key to verify the digital signature and save the digital signature; Step 25: The message sender encrypts the attribute key of each message recipient and distributes the key in combination with the InterPlanetary File System and the Monero blockchain; The specific process of step 25 is as follows: Step 251, the message sender creates a Monero transaction pointing to each message recipient, and saves the shared secret in the transaction generation process; the shared secret is an intermediate variable of the Monero transaction one-time address, which can only be calculated by the transaction sender and the recipient; Step 252, the message sender uses the hash value of the shared secret in step 251 as the AES encryption key, encrypts the attribute key in step 22, and uploads it to the InterPlanetary File System to obtain a content identifier; Step 253: The message sender uses the AES encryption key in step 252 to encrypt the content identifier and embeds it into the Monero transaction to form a transmission transaction. The transaction "amount" field is generated by combining the fixed prefix of the content identifier with the digital signature code in step 243 and sent to the Monero test chain network. In step 26, the message recipient extracts the content identifier from the transmission transaction described in step 253, downloads the ciphertext from the InterPlanetary File System and decrypts it to obtain the attribute key.

4. The method according to claim 1, characterized in that: The specific process of step 3 is as follows: Step 31, the message sender extracts the private key of the transaction receiving node described in step 12, embeds it into the Monero transaction and transmits it to each message recipient; The specific process of step 31 is as follows: Step 311, the message sender creates a Monero transaction pointing to each message recipient and saves the shared secret in the transaction generation process; Step 312: The message sender extracts the viewing private key of the transaction receiving node and performs encryption processing using the hash value of the shared secret in step 311 as the AES encryption key; Step 313: The message sender embeds the private key ciphertext in step 312 into the Monero transaction to form a transmission transaction. The transaction "amount" field is generated by combining the fixed identifier with the digital signature encoding in step 243, and the transaction is sent to the Monero test chain network. Step 32: After the message recipient obtains the transmission transaction described in step 313, it decrypts and obtains the viewing private key.

5. The method according to claim 1, characterized in that The specific process of step 4 is as follows: Step 41, the message sender generates an access control policy according to the attributes of each message receiver; Step 42, the message sender encrypts the message using the public key described in step 11 and the access control policy described in step 41 to generate a ciphertext of the message; Step 43, the message sender uploads the ciphertext of the message in step 42 to the InterPlanetary File System and obtains the corresponding content identifier; Step 44, the message sender creates a transmission transaction pointing to the transaction receiving node described in step 12, embeds the content identifier described in step 43 into the transaction, and encodes the message sequence number into the transaction "amount" field; In step 45, the message sender sends the transaction described in step 44 to the Monero test chain network.

6. The method according to claim 1, characterized in that The specific process of step 5 is as follows: Step 51, the message recipient uses the private key in step 32 to identify the transmission transaction in step 45 and obtains the content identifier; Step 52, the message recipient uses the content identifier in step 51 to obtain the message ciphertext from the InterPlanetary File System; Step 53, the message recipient attempts to decrypt the message ciphertext. If it complies with the policy described in step 41, the decryption is successful, otherwise it cannot be decrypted.