Cloud data sharing system and method for supply chain
By encrypting and distributing shared data ciphertexts in the proxy server, the problem of shared data leakage risk in the supply chain system is solved, and data sharing with high security and fault tolerance is achieved.
Patent Information
- Application Number
- CN202510434902.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-06-20
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the existing supply chain system, shared data is stored in plain text in cloud servers, and there is a risk of leaking trade secrets.
By generating public and private key pairs in the proxy server, encrypting the shared data, generating a shared data ciphertext, and secretly sharing the ciphertext based on the threshold value t, N secret shares are obtained and stored in N supply chain terminals respectively.
It avoids the risk of cloud servers obtaining shared data, improves data security, and improves fault tolerance through distributed threshold secret sharing solutions, ensuring reliable data recovery.
Smart Images

Figure CN120185907A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a cloud data sharing system and method for a supply chain. Background Art
[0002] A supply chain refers to the entire process from producing parts, manufacturing intermediate products and final products, and finally delivering them to consumers. In this process, the suppliers, manufacturers, distributors, and consumers involved form a network chain structure through the connection of upstream and downstream members. In order for the supply chain process to operate healthily, orderly, and efficiently, supply chain management is required, so that the overall system cost of the supply chain is minimized, and suppliers, manufacturers, warehouses, distribution centers, and channel merchants are effectively organized to carry out product manufacturing, transportation, distribution, and sales, which is also called supply chain management.
[0003] Supply chain management involves multiple supply chain terminals, and each link in the supply chain may involve at least one supply chain terminal. These supply chain terminals usually need to share some data, such as real-time data or other data in the production, transportation, storage and other links. The data that needs to be shared is called shared data. Currently, a supply chain terminal can upload the shared data to a cloud server and let the cloud server store the shared data. Then, other supply chain terminals in the supply chain system can obtain the shared data from the cloud server, thus realizing data sharing.
[0004] However, these shared data are usually stored in the cloud server in plain text. Generally, the cloud server is provided by a third-party cloud service provider, so the cloud service provider can obtain these shared data, posing a risk of commercial secret leakage. Summary of the Invention
[0005] Embodiments of this application provide a cloud data sharing system and method for a supply chain to ensure the security of shared data of supply chain terminals.
[0006] The first aspect of this application provides a cloud data sharing system for a supply chain, including: A proxy server, configured to generate a public-private key pair, where the public-private key pair includes a corresponding public key and a private key; the public key is used to encrypt the plain text to obtain a cipher text; the private key is used to decrypt the cipher text to obtain the plain text; A first supply chain terminal, configured to send shared data to the proxy server; The proxy server is further configured to use the public key to encrypt the shared data to obtain a shared data cipher text; The proxy server is further configured to perform secret sharing on the shared data cipher text based on a threshold value t to obtain N secret shares, where both N and t are positive integers, and N is greater than t; The proxy server is further configured to send a corresponding one of the N secret shares to each of the N supply chain terminals, where the N supply chain terminals and the N secret shares are in one-to-one correspondence, so that each of the N supply chain terminals stores the corresponding secret share; The second supply chain terminal is configured to send a first data request to the proxy server, and the first data request is used to request the shared data; The proxy server is further configured to request the stored secret shares from at least t of the N supply chain terminals; If the proxy server successfully obtains the at least t secret shares, the proxy server generates the encrypted shared data based on the at least t secret shares; The proxy server is further configured to decrypt the encrypted shared data based on the private key to obtain the shared data; The proxy server is further configured to send the shared data to the second supply chain terminal.
[0007] In this application, since the encrypted shared data is converted into N secret shares and stored in N supply chain terminals respectively, instead of being stored in the cloud server, the cloud server cannot obtain the shared data, that is, the risk of disclosing business secrets is avoided, and the data security of the shared data is guaranteed. In addition, due to the use of the secret sharing scheme based on "distributed threshold", when there are disconnections or lost secret shares among the N supply chain terminals, as long as at least t secret shares are obtained, the encrypted shared data can be restored, improving the fault tolerance rate and further guaranteeing the security of the shared data. Moreover, since the proxy server encrypts the shared data based on the public key to obtain the encrypted shared data, and then further performs secret sharing on the encrypted shared data, double encryption is achieved, and the data security of the shared data is further protected.
[0008] A second aspect of this application provides a proxy server for cloud data sharing in a supply chain, including: A processing module, configured to generate a public-private key pair, where the public-private key pair includes a corresponding public key and a private key; the public key is used to encrypt the plaintext to obtain the ciphertext; the private key is used to decrypt the ciphertext to obtain the plaintext; A transceiver module, configured to receive the shared data sent by the first supply chain terminal; The processing module is further configured to encrypt the shared data using the public key to obtain the encrypted shared data; The processing module is further configured to perform secret sharing on the encrypted shared data based on the threshold value t to obtain N secret shares, where both N and t are positive integers, and N is greater than t; The transceiver module is further configured to separately send a corresponding one of the N secret shares to each of the N supply chain terminals, where the N supply chain terminals and the N secret shares are in one-to-one correspondence, so that each of the N supply chain terminals stores the corresponding secret share; The transceiver module is further configured to receive a first data request sent by a second supply chain terminal, where the first data request is used to request the shared data; The transceiver module is further configured to request the stored secret shares from at least t of the N supply chain terminals; The processing module is further configured to, if successfully obtaining the at least t secret shares, generate a ciphertext of the shared data based on the at least t secret shares; The processing module is further configured to decrypt the ciphertext of the shared data based on the private key to obtain the shared data; The transceiver module is further configured to send the shared data to the second supply chain terminal.
[0009] In this application, since the ciphertext of the shared data is converted into N secret shares and stored separately in N supply chain terminals instead of in the cloud server, the cloud server cannot obtain the shared data, that is, the risk of disclosing business secrets is avoided, and the data security of the shared data is guaranteed. In addition, due to the use of a secret sharing scheme based on "distributed threshold", when there are dropouts or lost secret shares among the N supply chain terminals, as long as at least t secret shares are obtained, the ciphertext of the shared data can be restored, improving the fault tolerance rate and further guaranteeing the security of the shared data. Moreover, since the proxy server encrypts the shared data based on the public key to obtain the ciphertext of the shared data and then further performs secret sharing on the ciphertext of the shared data, double encryption is achieved, further protecting the data security of the shared data.
[0010] A third aspect of this application provides a cloud data sharing method for a supply chain, including: A proxy server generates a public-private key pair, where the public-private key pair includes a corresponding public key and a private key; the public key is used to encrypt a plaintext to obtain a ciphertext; the private key is used to decrypt the ciphertext to obtain the plaintext; A first supply chain terminal sends shared data to the proxy server; The proxy server uses the public key to encrypt the shared data to obtain a ciphertext of the shared data; The proxy server performs secret sharing on the ciphertext of the shared data based on a threshold value t to obtain N secret shares, where both N and t are positive integers and N is greater than t; The proxy server sends a corresponding one of the N secret shares to each of the N supply chain terminals, where the N supply chain terminals and the N secret shares are in one-to-one correspondence, so that each of the N supply chain terminals stores the corresponding secret share; The second supply chain terminal sends a first data request to the proxy server, and the first data request is used to request the shared data; The proxy server requests the stored secret shares from at least t of the N supply chain terminals; The proxy server generates the encrypted text of the shared data based on the at least t secret shares; The proxy server decrypts the encrypted text of the shared data based on the private key to obtain the shared data; The proxy server sends the shared data to the second supply chain terminal.
[0011] In this application, since the encrypted text of the shared data is converted into N secret shares and stored in N supply chain terminals respectively, instead of being stored in the cloud server, the cloud server cannot obtain the shared data, that is, the risk of disclosing business secrets is avoided, and the data security of the shared data is guaranteed. In addition, due to the use of the secret sharing scheme based on "distributed threshold", when there are disconnections or lost secret shares among the N supply chain terminals, as long as at least t secret shares are obtained, the encrypted text of the shared data can be restored, improving the fault tolerance rate and further guaranteeing the security of the shared data. Moreover, since the proxy server encrypts the shared data based on the public key to obtain the encrypted text of the shared data, and then further performs secret sharing on the encrypted text of the shared data, double encryption is realized, and the data security of the shared data is further protected.
[0012] In some possible implementation manners, the proxy server performs secret sharing on the encrypted text of the shared data based on the threshold value t to obtain N secret shares, including: the proxy server runs the sharing generation algorithm SS.Split(es, t) of the distributed threshold homomorphic encryption system to obtain the N secret shares, where t is the threshold value, es is the encrypted text of the shared data, and the SS.Split() is the Shamir secret sharing algorithm.
[0013] In some possible implementation manners, after the proxy server performs secret sharing on the encrypted text of the shared data based on the threshold value t to obtain N secret shares, the method further includes: the proxy server stores the N secret shares locally.
[0014] In some possible implementation manners, after the second supply chain terminal sends a first data request to the proxy server, the method further includes: The proxy server obtains the N secret shares from local based on the first data request; If the proxy server successfully obtains the N secret shares locally, the proxy server performs the step of generating the ciphertext of the shared data based on at least t of the secret shares; If the proxy server fails to successfully obtain the N secret shares locally, the proxy server performs the step of requesting the stored secret shares from at least t of the N supply chain terminals.
[0015] As described above, the ciphertext of the shared data is generated into N secret shares by the proxy server and stored in N supply chain terminals, thus avoiding the risk of disclosing business secrets and ensuring the data security of the shared data. It can be seen that the proxy server also has a certain storage function. Failure to utilize this storage function causes a certain amount of performance waste. In order to make full use of the storage function of the proxy server, reduce the communication between the proxy server and the N supply chain terminals, and reduce the latency, the shared data that requires real-time response can be shared more quickly and timely on each supply chain terminal.
[0016] A fourth aspect of the present application provides a cloud data sharing method for a supply chain, including: The proxy server generates a public-private key pair, which includes a corresponding public key and a private key; the public key is used to encrypt the plaintext to obtain a ciphertext; the private key is used to decrypt the ciphertext to obtain the plaintext; The proxy server receives the shared data sent by the first supply chain terminal; The proxy server encrypts the shared data using the public key to obtain a ciphertext of the shared data; The proxy server performs secret sharing on the ciphertext of the shared data based on a threshold value t to obtain N secret shares, where both N and t are positive integers, and N is greater than t; The proxy server sends a corresponding one of the N secret shares to each of the N supply chain terminals, where the N supply chain terminals and the N secret shares are in one-to-one correspondence, so that each of the N supply chain terminals stores the corresponding secret share; The proxy server receives a first data request sent by the second supply chain terminal, and the first data request is used to request the shared data; The proxy server requests the stored secret shares from at least t of the N supply chain terminals; If the proxy server successfully obtains the at least t secret shares, the proxy server generates the ciphertext of the shared data based on the at least t secret shares; The proxy server decrypts the ciphertext of the shared data based on the private key to obtain the shared data; The proxy server sends the shared data to the second supply chain terminal.
[0017] In this application, since the shared data ciphertext is converted into N secret shares and stored in N supply chain terminals respectively, instead of being stored in the cloud server, the cloud server cannot obtain the shared data, which avoids the risk of disclosing business secrets and ensures the data security of the shared data. In addition, due to the use of the secret sharing scheme based on "distributed threshold", when there are disconnections or lost secret shares among the N supply chain terminals, as long as at least t secret shares are obtained, the shared data ciphertext can be restored, improving the fault tolerance rate and further ensuring the security of the shared data. Moreover, since the proxy server encrypts the shared data based on the public key to obtain the shared data ciphertext and then further performs secret sharing on the shared data ciphertext, double encryption is achieved, further protecting the data security of the shared data.
[0018] In some possible implementation manners, the proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares, including: The proxy server runs the sharing generation algorithm SS.Split(es, t) of the distributed threshold homomorphic encryption system to obtain the N secret shares, where t is the threshold value, es is the shared data ciphertext, and the SS.Split() is the Shamir secret sharing algorithm.
[0019] In some possible implementation manners, after the proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares, the method further includes: The proxy server stores the N secret shares locally.
[0020] In some possible implementation manners, after the second supply chain terminal sends a first data request to the proxy server, the method further includes: The proxy server obtains the N secret shares from local based on the first data request; If the proxy server successfully obtains the N secret shares from local, the proxy server executes the step of generating the shared data ciphertext based on the at least t secret shares; If the proxy server fails to successfully obtain the N secret shares from local, the proxy server executes the step of requesting the stored secret shares from at least t supply chain terminals among the N supply chain terminals.
[0021] As described above, the ciphertext of the shared data is generated into N secret shares and stored in N supply chain terminals through a proxy server, thus avoiding the risk of disclosing business secrets and ensuring the data security of the shared data. It can be seen that the proxy server also has a certain storage function. If this storage function is not utilized, it will cause a certain waste of performance. In order to make full use of the storage function of the proxy server, reduce the communication between the proxy server and the N supply chain terminals, and reduce the latency, the shared data that requires real-time response can be shared more quickly and timely on each supply chain terminal.
[0022] In a fifth aspect of the present application, a computer-readable storage medium is provided. Instructions are stored in the computer-readable storage medium. When it runs on a computer, it causes the computer to execute the method provided by any possible implementation manner of the third aspect or the fourth aspect described above.
[0023] In a sixth aspect of the present application, a computer program product is provided. The computer program product includes computer-executable instructions, and the computer-executable instructions are stored in a computer-readable storage medium; at least one processor of the device can read the computer-executable instructions from the computer-readable storage medium, and at least one processor executes the computer-executable instructions to cause the device to implement the method provided by any possible implementation manner of the third aspect or the fourth aspect described above.
[0024] In a seventh aspect of the present application, a communication device is provided. The communication device may include at least one processor, a memory, and a communication interface. At least one processor is coupled to the memory and the communication interface. The memory is used to store instructions, at least one processor is used to execute the instructions, and the communication interface is used to communicate with other communication devices under the control of at least one processor. When the instructions are executed by at least one processor, at least one processor executes the method in any possible implementation manner of the third aspect or the fourth aspect.
[0025] In an eighth aspect of the present application, a chip system is provided. The chip system includes a processor for supporting the implementation of the functions involved in any possible implementation manner of the third aspect or the fourth aspect described above.
[0026] In a possible design, the chip system may further include a memory for storing necessary program instructions and data. The chip system may be composed of chips or may include chips and other discrete devices.
[0027] Among them, the technical effects brought by the fifth to eighth aspects or any possible implementation manner thereof can be referred to the technical effects brought by different possible implementation manners of the third aspect or the fourth aspect, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 Schematic diagram of the composition structure of a cloud data sharing system provided by an embodiment of the present application; Figure 2 Schematic diagram of the process of a cloud data sharing method for a supply chain provided by an embodiment of the present application; Figure 3 Schematic diagram of the process of a cloud data sharing method for a supply chain provided by an embodiment of the present application; Figure 4 Schematic diagram of the structure of a proxy server for cloud data sharing for a supply chain provided by an embodiment of the present application; Figure 5 Schematic diagram of the structure of a communication device provided by an embodiment of the present application. Detailed implementation manners
[0029] An embodiment of the present application provides a cloud data sharing system and method for a supply chain, which is used to ensure the security of shared data at the supply chain terminal.
[0030] The embodiments of the present application will be described below with reference to the accompanying drawings.
[0031] Terms such as "first" and "second" in the specification, claims and above-mentioned drawings of the present application are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing the embodiments of the present application. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.
[0032] Supply chain management involves multiple supply chain terminals, and each link in the supply chain may involve at least one supply chain terminal. These supply chain terminals usually need to share some data, such as real-time data or other data in the production, transportation, storage and other links. The data to be shared is called shared data. Currently, a supply chain terminal can upload the shared data to a cloud server and let the cloud server store the shared data. Then, other supply chain terminals in the supply chain system can obtain the shared data from the cloud server, thereby realizing data sharing.
[0033] However, these shared data are usually stored in the cloud server in plain text, and the cloud server is generally provided by a third-party cloud service provider. Then, the cloud service provider can obtain these shared data, and there is a risk of leakage of business secrets.
[0034] To this end, an embodiment of the present application provides a cloud data sharing system for a supply chain. The cloud data sharing system includes a cloud server, a proxy server, and multiple supply chain terminals. Among them, the proxy server belongs to the user.
[0035] In the present application, the proxy server pre-generates a public-private key pair, which includes a corresponding public key and a private key. Among them, the public key is used to encrypt the plaintext to obtain a ciphertext; the private key is used to decrypt the ciphertext to obtain the plaintext. Then, when the proxy server receives the shared data sent by the first supply chain terminal, the proxy server can use the public key to encrypt the shared data to obtain a shared data ciphertext. Next, the proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares. Both N and t are positive integers, where N is greater than t. The proxy server can send a corresponding secret share among the N secret shares to each of the N supply chain terminals, where the N supply chain terminals and the N secret shares are in one-to-one correspondence, so that each supply chain terminal among the N supply chain terminals stores the corresponding secret share, thereby realizing the secure storage of the shared data ciphertext.
[0036] Then, when the second supply chain terminal sends a first data request for requesting the shared data to the proxy server, the proxy server can request the stored secret shares from at least t supply chain terminals among the N supply chain terminals. If the proxy server successfully obtains the at least t secret shares, the proxy server generates the shared data ciphertext based on the at least t secret shares, decrypts the shared data ciphertext based on the private key to obtain the shared data, and sends the shared data to the second supply chain terminal, thereby realizing the sharing of the shared data between the first supply chain terminal and the second supply chain terminal.
[0037] Compared with directly storing the plaintext of the shared data in the cloud server, the solution of the present application encrypts the shared data into a shared data ciphertext and generates corresponding N secret shares, which are respectively stored in N supply chain terminals, avoiding the participation of the cloud server and avoiding the leakage of the shared data. Moreover, due to double confidentiality, the confidentiality effect is greatly increased, and the security of the shared data is greatly improved.
[0038] Exemplarily, please refer to Figure 1 As shown, an embodiment of the present application provides a cloud data sharing system 100, including a proxy server 110, a cloud server 120, a first supply chain terminal 130, and a second supply chain terminal 140.
[0039] In an embodiment of the present invention, the proxy server 110 may be a device such as a gateway acting as a pipeline, a firewall device, a content delivery network, etc., which is not limited herein. Exemplarily, the proxy server 110 may be a Gateway GPRS Support Node (GGSN) or a Public Data Network Gateway (PGW). Its internal structure may be similar to that of a server. On this basis, the proxy server 110 has a service processing module for performing the functions of the proxy server 110 in the embodiments of the present application.
[0040] In an embodiment of the present invention, the cloud server 120 is used to store shared data, such as various media contents such as text, images, audio, and video. The internal structure of the cloud server 120 may include one or more central processing units (CPUs) (for example, one or more processors) and a memory, and one or more storage media for storing applications or data (for example, one or more mass storage devices). Among them, the memory and the storage media may be transient storage or persistent storage. The program stored in the storage media may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the cloud server 120. Further, the central processor may be configured to communicate with the storage media and execute a series of instruction operations in the storage media on the cloud server 120.
[0041] In an embodiment of the present application, the supply chain terminal is used to record and upload supply chain information, thereby forming a supply chain system, which provides the possibility of supply chain management for the healthy, orderly, and efficient operation of the supply chain process, so that the system cost of the entire supply chain is minimized, and suppliers, manufacturers, warehouses, distribution centers, and channel merchants, etc., are effectively organized together for product manufacturing, transportation, distribution, and sales, which is also called supply chain management.
[0042] The supply chain terminals involved in the embodiments of the present invention (such as the first supply chain terminal 130 and the second supply chain terminal 140) can be devices that provide voice and / or data connectivity to users, handheld devices with wireless connection functions, or other processing devices connected to a wireless modem. The wireless terminal can communicate with one or more core networks via a radio access network (RAN). The wireless terminal can be a mobile terminal, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal. For example, it can be a portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted mobile device that exchanges voice and / or data with the radio access network. For example, devices such as personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), etc. The wireless terminal can also be referred to as a system, subscriber unit, subscriber station, mobile station, mobile, remote station, access point, remote terminal, access terminal, user terminal, terminal device, user agent, user device, or user equipment, which is not limited herein.
[0043] It should be noted that the internal structure of the supply chain terminal can include components such as a radio frequency (RF) circuit, a memory, an input unit, a display unit, sensors, an audio circuit, a wireless fidelity (WiFi) module, a processor, and a power supply. Those skilled in the art can understand that the structure of the terminal described above does not limit the terminal, and it can include more or fewer components than shown in the figure, or combine certain components, or arrange different components.
[0044] Exemplarily, in the cloud data sharing system 100, there can be multiple supply chain terminals. In this application, the first supply chain terminal 130 and the second supply chain terminal 140 are taken as examples for illustration.
[0045] In the embodiments of the present application, the proxy server 110, the first supply chain terminal 130, and the second supply chain terminal 140 all belong to users and do not belong to a third party. In the present application, since the shared data is not stored in the cloud server 120, the risk of disclosing business secrets is avoided. When the data sharing between the first supply chain terminal 130 and the second supply chain terminal 140 is realized, the security of the shared data is guaranteed.
[0046] The foregoing embodiments introduced the cloud data sharing system for the supply chain provided by the present application. Next, a cloud data sharing method for the supply chain executed based on the cloud data sharing system for the supply chain will be introduced.
[0047] Please refer to Figure 2 As shown, a cloud data sharing method for the supply chain provided in Embodiment 1 of the present application mainly includes the following steps: 201. The proxy server generates a public-private key pair, and the public-private key pair includes a corresponding public key and a private key.
[0048] It should be noted that for the corresponding public key and private key, the public key is used to encrypt the plaintext to obtain the ciphertext; the private key is used to decrypt the ciphertext to obtain the plaintext.
[0049] Exemplarily, the public-private key pair can be expressed as (pk, sk), where pk represents the public key and sk represents the private key. pk is used to encrypt the shared data to obtain the shared data ciphertext; sk is used to decrypt the shared data ciphertext to obtain the shared data.
[0050] Exemplarily, the following describes two methods for the proxy server to generate a public-private key pair.
[0051] Method 1: First, the proxy server sets R3 according to a preset R, where R is a set of polynomials with a degree not greater than 2048, and R3 is a set of polynomials obtained by taking the coefficients of the elements (polynomials) in R modulo 3, that is, the elements of R3 are polynomials with a degree of 2048 and coefficients being values in {-1, 0, 1}. In some possible implementation manners, the proxy server can also set R5 or R7, etc. according to R, which is not limited herein. Here, R3 is taken as an example for illustration. Then, the proxy server selects a polynomial s from R3 according to a preset uniform distribution μ, that is, the polynomial s is an element in R3, that is, s is a polynomial with a degree of 2048 and coefficients being values in {-1, 0, 1}, and the proxy server can determine the private key sk = s, thereby obtaining the private key sk.
[0052] Next, the proxy server determines the random noise e according to the preset chi-square distribution, and calculates the public key pk = [-(a•s + e)]h, obtaining the public key as pk. It should be noted that [-(a•s + e)]h means that the polynomial coefficients of -(a•s + e) within the brackets are modulo h, where h is a preset value, that is, the public key is generated based on the private key.
[0053] It should be noted that since the private key sk is a polynomial of degree 2048 with coefficients being values in {-1, 0, 1}, then the public key pk is also a polynomial of degree 2048, and each coefficient in the public key pk does not exceed h (exemplarily, h is a 54-bit integer).
[0054] Through the above method one, the public-private key pair (pk, sk) can be obtained.
[0055] Method two: The proxy server runs the preset HPKE.Gen(lλ), where l is the preset modulus of the polynomial and λ is the preset security parameter, to obtain the public-private key pair (pk, sk).
[0056] It should be noted that HPKE.Gen() is the encryption system of the standard integrated encryption scheme (elliptic curve integrate encrypt scheme, ECIES). The curve used is the secp256k1 curve, that is, the public key pk is an elliptic curve point, and the non-compressed representation requires 512 bits. Exemplarily, the public key pk is a polynomial of degree 2048, and each coefficient in this polynomial is a value within 54 bits.
[0057] Through the above method two, the public-private key pair (pk, sk) can be obtained.
[0058] It should be noted that the proxy server can obtain the public-private key pair through the above method one or method two, or can obtain the public-private key pair through other methods, which is not limited here.
[0059] 202. The first supply chain terminal sends the shared data to the proxy server.
[0060] In the embodiment of the present application, the shared data can be real-time data or other data in links such as production, transportation, and storage, which is not limited here. The shared data is used to realize the sharing among multiple supply chain terminals. For example, the first supply chain terminal and the second supply chain terminal share the shared data.
[0061] In some possible implementation manners, the first supply chain terminal may send the shared data to the proxy server via the public network or via the local area network, which is not limited herein. The first supply chain terminal and the proxy server may negotiate a communication key to implement communication. The communication key may be an asymmetric key or a symmetric key, which is not limited herein.
[0062] In some possible implementation manners, after the first supply chain terminal is input with the shared data, the first supply chain terminal immediately sends the shared data to the proxy server.
[0063] In some possible implementation manners, when the shared data in the first supply chain terminal is updated to obtain the updated shared data, the first supply chain terminal immediately sends the updated shared data to the proxy server.
[0064] In some possible implementation manners, the first supply chain terminal periodically sends the shared data to the proxy server.
[0065] In some possible implementation manners, the proxy server sends a request for obtaining the shared data to the first supply chain terminal. After receiving the obtaining request, the first supply chain terminal sends the shared data to the proxy server.
[0066] In some possible implementation manners, the first supply chain terminal may send a storage request for the shared data to the proxy server. The storage request includes metadata and the shared data, and the metadata corresponds to the shared data, which is not limited herein.
[0067] 203. The proxy server uses the public key to encrypt the shared data to obtain the encrypted shared data ciphertext.
[0068] In some possible implementation manners, the proxy server may use the public key to encrypt the shared data by multiple methods to obtain the encrypted shared data ciphertext. The following takes 2 methods as examples for illustration.
[0069] Method 1 If the public-private key pair is generated by Method 1 in step 201, then the encryption algorithm includes the following steps: (1) The proxy server selects a polynomial u from R3 according to the preset uniform distribution μ. Wherein, in the system parameters, R is a set of polynomials with a degree not greater than 2048. Then, R3 is a set of polynomials obtained by taking the coefficients of the elements (polynomials) in R modulo 3, that is, the elements of R3 are polynomials with a degree of 2048 and coefficients being values in {-1, 0, 1}, and u is an element in R3.
[0070] (2) The proxy server selects two noises e0 and e1 according to the preset chi-square distribution; (3) The proxy server calculates c0 = [a • u + e0], c1 = [pk • u + e1 + ceiling(h / l) • x]h, where x is the shared data, ceiling(h / l) is the smallest integer not less than h / l, and h is the preset polynomial coefficient modulus h, so as to obtain c1 as the ciphertext of the shared data.
[0071] Through the above steps, the encryption of the shared data x by the public key pk is realized, and the ciphertext c1 of the shared data is obtained, denoted as es = c1.
[0072] Method 2: If the public-private key pair is generated by Method 2 in Step 201 and the obtained ciphertext of the shared data is denoted as es, then the encryption algorithm is HPKE.Enc(), and HPKE.Enc() is the encryption method in the standard ECIES, which will not be elaborated here.
[0073] It should be noted that the above are only 2 of the methods, and there are many methods for encrypting shared data with a public key, which are not limited here.
[0074] 204. The proxy server performs secret sharing on the ciphertext of the shared data based on the threshold value t to obtain N secret shares.
[0075] It should be noted that the data is secretly shared and handed over to multiple different devices for storage, so it is called distributed. t is called the threshold value, and such a scheme is called a distributed threshold secret sharing scheme. In the distributed threshold secret sharing scheme, assuming that (N - t) devices are offline, or these (N - t) devices lose the secret shares, as long as t secret shares can be obtained, the original data can be restored. Both N and t are positive integers, where N is greater than t.
[0076] It should be noted that the secret sharing based on the threshold value can be realized based on a data according to a preset algorithm, so as to obtain N secret shares. Among them, any t secret shares among the N secret shares can restore the data based on the preset algorithm. In the embodiments of the present application, the proxy server can perform secret sharing on the ciphertext of the shared data based on the threshold value t to obtain N secret shares. Among them, when any t secret shares among the N secret shares are obtained, the ciphertext of the shared data can be restored based on the preset algorithm and these t secret shares.
[0077] In the embodiment of the present application, the proxy server needs to first check the number of supply chain terminals. If the number of supply chain terminals is greater than the threshold value t, the proxy server continues to execute the subsequent steps; otherwise, it ends. When the number of supply chain terminals is greater than or equal to the threshold value t, the proxy server can run the sharing generation algorithm SS.Split(es,t) of the distributed threshold homomorphic encryption system to generate N secret shares of the shared data ciphertext.
[0078] Exemplarily, in SS.Split(), a polynomial f(x) of degree (t - 1) is preset, where f(0) is the secret to be shared. Let f(x1), f(x2), ……, f(xN) be the N secret shares respectively. Then, as long as t secret shares out of the N secret shares are obtained, the secret to be shared can be restored. Exemplarily, the method for restoring the secret to be shared can be to substitute the t secret shares into a polynomial of degree (t - 1) with unknown coefficients respectively to obtain a system of equations, which is a system of t linear equations with t variables. By solving this system of equations, the coefficients of each term of the polynomial of degree (t - 1) are obtained, so as to restore f(x), and then calculate f(0) to obtain the shared secret. In some possible implementation manners, the Lagrange interpolation algorithm can also be used to calculate the values of the coefficients of each term in the polynomial f(x), so as to restore the polynomial f(x).
[0079] For example, if es = 1, then the proxy server executes the secret sharing algorithm SS.Split(es,t) on es to obtain N secret shares of es. For example, when N = 5, after the secret sharing of es, 5 secret shares {1, 2, 3, 4, 5} of es can be obtained. Assuming t = 3, then the value of es can be restored by obtaining 3 of {1, 2, 3, 4, 5}.
[0080] 205. The proxy server sends a corresponding one of the N secret shares to each of the N supply chain terminals.
[0081] In an embodiment of the present application, the proxy server may distribute the N secret shares to N supply chain terminals respectively, where one supply chain terminal stores one secret share, and the N secret shares correspond to the N supply chain terminals one by one. For example, 10 secret shares are generated for the ciphertext A of the shared data (i.e., N = 10), and the 10 secret shares are distributed to 10 different supply chain terminals for storage respectively. Each of the 10 supply chain terminals stores one secret share, and the secret shares stored by each supply chain terminal are different. When it is necessary to recover the ciphertext of the shared data, the proxy server only needs to obtain t shares (t < N) of the N secret shares to recover the ciphertext of the shared data. For example, if t = 5, then only need to obtain the secret shares stored by any 5 of the 10 supply chain terminals, and the ciphertext of the shared data can be recovered through calculation.
[0082] Exemplarily, N = 5. After the secret sharing of es, 5 secret shares {1, 2, 3, 4, 5} can be obtained. The proxy server may send each value in {1, 2, 3, 4, 5} to 5 supply chain terminals respectively, and let each of the 5 supply chain terminals store one secret share.
[0083] In some possible implementation manners, the proxy server may establish a table, use the metadata of the shared data as an index, and use the identifiers of the N supply chain terminals as mapping results, so that the identifiers of the N supply chain terminals can be found based on the metadata. Exemplarily, the identifiers of the N supply chain terminals may be the Internet protocol (IP) addresses of the respective supply chain terminals among the N supply chain terminals, or other identifiers, which are not limited herein.
[0084] In the embodiment of the present application, through the above steps 201-205, the confidentiality and storage of the shared data of the first supply chain terminal are completed. Next, through steps 206-210, the second supply chain terminal obtains the shared data, thereby realizing the data sharing of the shared data.
[0085] 206. The second supply chain terminal sends a first data request to the proxy server, and the first data request is used to request the shared data.
[0086] In some possible implementation manners, the second supply chain terminal is another supply chain terminal different from the first supply chain terminal, and the second supply chain terminal and the first supply chain terminal may also be the same supply chain terminal, which is not limited herein.
[0087] In some possible implementation manners, the first data request carries the metadata of the shared data, and the metadata is used to request to obtain the shared data.
[0088] 207. The proxy server requests at least t supply chain terminals among the N supply chain terminals to obtain the stored secret shares, and obtains at least t secret shares.
[0089] In the embodiment of the present application, the proxy server may be based on the metadata of the shared data in the first data request. Exemplarily, the metadata of the shared data is carried in the first data request, then the proxy server may determine the identities of the corresponding N supply chain terminals based on the metadata, so as to determine the N supply chain terminals. Then, the proxy server may request at least t supply chain terminals among the N supply chain terminals to obtain the stored secret shares, and obtain at least t secret shares.
[0090] Exemplarily, N = 5, t = 3, and the 5 secret shares of the shared data ciphertext are {1, 2, 3, 4, 5}. The proxy server may obtain at least 3 secret shares from the 5 secret shares. For example, the at least 3 secret shares are {1, 2, 3}, {1, 2, 5}, {2, 3, 4, 5}, which are not limited herein.
[0091] 208. The proxy server generates the shared data ciphertext based on the at least t secret shares.
[0092] In some possible implementation manners, if fewer than N - t supply chain terminals among the N supply chain terminals are offline or lose the secret shares, then the proxy server may successfully obtain at least t secret shares from the N supply chain terminals, and the proxy server may generate the shared data ciphertext based on the at least t secret shares.
[0093] In some possible implementation manners, the proxy server may use a preset decryption algorithm to perform decryption calculations on t secret shares to obtain the shared data ciphertext. Exemplarily, continuing the above example, when the proxy client performs secret sharing, it uses SS.Split() (i.e., the Shamir secret sharing algorithm), then the preset decryption algorithm may be regarded as the inverse operation of SS.Split().
[0094] Exemplarily, continuing with the above example, the method for restoring the ciphertext of the shared data to be shared can be to substitute t secret shares into a polynomial f(x) of degree (t - 1) with unknown coefficients (i.e., the polynomial f(x) used for secret sharing), obtaining a system of equations, which is a system of t linear equations with t variables. By solving this system of equations, the coefficients of each term of the polynomial f(x) are obtained, thereby restoring f(x). Then, f(0) is calculated to obtain the shared secret, i.e., the ciphertext of the shared data. In some possible implementation manners, the coefficients of each term in the polynomial f(x) can be calculated directly by solving this system of equations, solving a matrix equation, or using the Lagrange interpolation algorithm, so as to obtain the polynomial f(x), and then the value of f(0) is calculated as the weighted average of the ciphertext of the shared data, which is not limited herein.
[0095] 209. The proxy server decrypts the ciphertext of the shared data based on the private key to obtain the shared data.
[0096] In the embodiment of the present application, when the proxy server receives the ciphertext of the shared data, it can use the private key to decrypt the ciphertext of the shared data to obtain the shared data. In the embodiment of the present application, since the ciphertext of the shared data is generated by the public key of the proxy server, only the private key of the proxy server can decrypt the ciphertext of the shared data, thus avoiding the risk of disclosing business secrets and ensuring the data security of the shared data.
[0097] Exemplarily, continuing with the above example, HPKE = (HPKE.Gen(), HPKE.Enc(), HPKE.Dec()), where HPKE.Gen() is a key generation algorithm, HPKE.Enc() is an encryption algorithm, and HPKE.Dec() is a decryption algorithm. Among them, HPKE.Gen() is used to generate a public-private key pair; HPKE.Enc() is used to encrypt the shared data based on the public key to obtain the ciphertext of the shared data; HPKE.Dec() is used to decrypt the ciphertext of the shared data based on the private key to obtain the plaintext of the shared data.
[0098] 210. The proxy server sends the shared data to the second supply chain terminal.
[0099] In some possible implementation manners, after the proxy server decrypts the ciphertext of the shared data to obtain the shared data, it can send the shared data to the second supply chain terminal, thereby realizing the sharing of the shared data between the first supply chain terminal and the second supply chain terminal.
[0100] In the embodiments of the present application, since the shared data ciphertext is converted into N secret shares and stored in N supply chain terminals respectively, rather than in the cloud server, the cloud server cannot obtain the shared data, thus avoiding the risk of disclosing trade secrets and ensuring the data security of the shared data. In addition, due to the use of the secret sharing scheme based on distributed threshold, when there are disconnections or lost secret shares among the N supply chain terminals, as long as at least t secret shares are obtained, the shared data ciphertext can be restored, improving the fault tolerance rate and further ensuring the security of the shared data. Moreover, since the proxy server encrypts the shared data based on the public key to obtain the shared data ciphertext and then further performs secret sharing on the shared data ciphertext, double encryption is achieved, further protecting the data security of the shared data.
[0101] The foregoing Embodiment 1 realizes storing N secret shares of the shared data ciphertext through N supply chain terminals, thus avoiding the risk of disclosing trade secrets and ensuring the data security of the shared data. However, since communication is still required between the proxy server and the N supply chain terminals, the latency is increased. Moreover, the proxy server also has a certain storage function, and this storage function is not utilized, resulting in a certain waste of performance.
[0102] Therefore, Embodiment 2 of the present application provides a cloud data sharing method for the supply chain, which is used to make full use of the storage function of the proxy server, reduce the communication between the proxy server and the N supply chain terminals, reduce the latency, and enable faster and more timely data sharing on each supply chain terminal for shared data that requires real-time response.
[0103] Please refer to Figure 3 As shown, a cloud data sharing method for the supply chain provided by Embodiment 2 of the present application mainly includes the following steps: 301. The proxy server generates a public-private key pair, which includes the corresponding public key and private key.
[0104] 302. The first supply chain terminal sends the shared data to the proxy server.
[0105] 303. The proxy server encrypts the shared data using the public key to obtain the shared data ciphertext.
[0106] 304. The proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares.
[0107] Steps 301-304 are the same as steps 201-204 and will not be elaborated here.
[0108] 305. The proxy server stores the N secret shares locally.
[0109] As described above, the proxy server generates N secret shares of the shared data ciphertext and stores them in N supply chain terminals, thus avoiding the risk of disclosing business secrets and ensuring the data security of the shared data. It can be seen that the proxy server also has a certain storage function. If this storage function is not utilized, it will cause a certain waste of performance. In order to make full use of the storage function of the proxy server, reduce the communication between the proxy server and the N supply chain terminals, and reduce the latency, the shared data that requires real-time response can be shared more quickly and timely on each supply chain terminal.
[0110] In some possible implementation manners, the proxy server can determine whether the shared data is hot data. If so, the proxy server stores the N secret shares locally. Exemplarily, when the proxy server receives a request for the shared data, it determines that the shared data is hot data. Another example is that when the proxy server receives a preset number of requests for the shared data within a certain period of time, it determines that the shared data is hot data. There is no limitation here.
[0111] It should be noted that since the proxy server belongs to the user and does not belong to a third-party cloud service provider, the shared data ciphertext can be stored locally, avoiding the risk of disclosing business secrets and ensuring data security.
[0112] In some possible implementation manners, the proxy server can establish a table, use the metadata of the shared data as an index, and use the identifiers of the N supply chain terminals as mapping results, so that the identifiers of the N supply chain terminals can be found based on the metadata. Exemplarily, the identifiers of the N supply chain terminals can be the Internet protocol (IP) addresses of each supply chain terminal in the N supply chain terminals, or other identifiers. There is no limitation here.
[0113] In the embodiments of the present application, through the above steps 301-305, the confidentiality and storage of the shared data of the first supply chain terminal are completed. Next, through steps 306-310, the second supply chain terminal obtains the shared data, thereby realizing the data sharing of the shared data.
[0114] 306. The second supply chain terminal sends a first data request to the proxy server, and the first data request is used to request the shared data.
[0115] Step 306 is the same as step 206 and will not be elaborated here.
[0116] 307. The proxy server obtains the N secret shares locally based on the first data request.
[0117] In an embodiment of the present application, when the proxy server receives the first data request, it first attempts to obtain the N secret shares from the local based on the first data request. If the proxy server successfully obtains the N secret shares from the local, the proxy server does not need to request the N secret shares of the shared data ciphertext from N supply chain terminals, reducing the communication between the proxy server and the N supply chain terminals and reducing the latency. For shared data that requires real-time response, faster and more timely data sharing can be achieved on each supply chain terminal.
[0118] 308. The proxy server generates the shared data ciphertext based on the at least t secret shares.
[0119] 309. The proxy server decrypts the shared data ciphertext based on the private key to obtain the shared data.
[0120] 310. The proxy server sends the shared data to the second supply chain terminal.
[0121] Steps 308 - 310 are the same as steps 208 - 210 and will not be elaborated here.
[0122] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0123] To facilitate better implementation of the above solutions of the embodiments of the present application, the following also provides related devices for implementing the above solutions.
[0124] Please refer to Figure 4 As shown, a proxy server 110 for cloud data sharing in a supply chain provided by an embodiment of the present application includes: A processing module 401, configured to generate a public-private key pair, where the public-private key pair includes a corresponding public key and a private key; the public key is used to encrypt the plaintext to obtain the ciphertext; the private key is used to decrypt the ciphertext to obtain the plaintext; A transceiver module 402, configured to receive the shared data sent by the first supply chain terminal; The processing module 401 is further configured to encrypt the shared data using the public key to obtain a shared data ciphertext; The processing module 401 is further configured to perform secret sharing on the shared data ciphertext based on a threshold value t to obtain N secret shares, where both N and t are positive integers, and N is greater than t; The transceiver module 402 is further configured to separately send a corresponding one of the N secret shares to each of the N supply chain terminals, where the N supply chain terminals and the N secret shares are in one-to-one correspondence, so that each of the N supply chain terminals stores the corresponding secret share; The transceiver module 402 is further configured to receive a first data request sent by a second supply chain terminal, where the first data request is used to request the shared data; The transceiver module 402 is further configured to request the stored secret shares from at least t of the N supply chain terminals; The processing module 401 is further configured to, if the acquisition of the at least t secret shares is successful, generate the shared data ciphertext based on the at least t secret shares; The processing module 401 is further configured to decrypt the shared data ciphertext based on the private key to obtain the shared data; The transceiver module 402 is further configured to send the shared data to the second supply chain terminal.
[0125] In some possible implementation manners, the processing module 401 is specifically configured to: run the sharing generation algorithm SS.Split(es, t) of the distributed threshold homomorphic encryption system to obtain the N secret shares, where t is the threshold value, es is the shared data ciphertext, and the SS.Split() is the Shamir secret sharing algorithm.
[0126] In some possible implementation manners, the processing module 401 is further configured to: locally store the N secret shares.
[0127] In some possible implementation manners, the processing module 401 is further configured to: Obtain the N secret shares from the local based on the first data request; If the N secret shares are successfully obtained from the local, then execute the step of generating the shared data ciphertext based on the at least t secret shares; If the N secret shares are not successfully obtained from the local, then execute the step of requesting the stored secret shares from at least t of the N supply chain terminals.
[0128] It should be noted that, for the information interaction, execution process, etc. among the above-mentioned device modules / units, since they are based on the same concept as the method embodiment of the present application, the technical effects brought by them are the same as those of the method embodiment of the present application. For the specific content, reference may be made to the description in the foregoing method embodiment of the present application, and details are not described herein again.
[0129] The embodiments of the present application further provide a computer storage medium. The computer storage medium stores a program, and the program executes some or all of the steps recorded in the above method embodiments.
[0130] Next, another communication device provided by the embodiments of the present application will be introduced. Please refer to Figure 5 As shown, the communication device 500 includes: A receiver 501, a transmitter 502, a processor 503, and a memory 504. In some embodiments of the present application, the receiver 501, the transmitter 502, the processor 503, and the memory 504 can be connected through a bus or other means. Among them, Figure 5 taking the connection through the bus as an example.
[0131] The memory 504 may include a read-only memory and a random access memory, and provide instructions and data to the processor 503. A part of the memory 504 may also include a non-volatile random access memory (NVRAM). The memory 504 stores an operating system and operating instructions, executable modules, or data structures, or subsets thereof, or extended sets thereof. Among them, the operating instructions may include various operating instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and processing hardware-based tasks.
[0132] The processor 503 controls the operation of the communication device 500. The processor 503 may also be referred to as a central processing unit (CPU). In a specific application, the various components of the communication device 500 are coupled together through a bus system. The bus system may include a power bus, a control bus, a status signal bus, etc. in addition to the data bus. However, for the sake of clear illustration, all kinds of buses are referred to as the bus system in the figure.
[0133] The method disclosed in the embodiments of the present application can be applied to or implemented by the processor 503. The processor 503 can be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above method can be completed by the integrated logic circuit in hardware or instructions in software form in the processor 503. The above-mentioned processor 503 can be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 504, and the processor 503 reads the information in the memory 504 and combines its hardware to complete the steps of the above method.
[0134] The receiver 501 can be used to receive input digital or character information and generate signal inputs related to relevant settings and function controls. The transmitter 502 can include a display device such as a display screen, and the transmitter 502 can be used to output digital or character information through an external interface.
[0135] In the embodiments of the present application, the processor 503 is used to execute the foregoing cloud data sharing method for a supply chain.
[0136] In another possible design, when the proxy server 110 or the communication device 500 is a chip, it includes a processing unit and a communication unit. The processing unit can be, for example, a processor, and the communication unit can be, for example, an input / output interface, a pin, or a circuit. The processing unit can execute the computer-executable instructions stored in the storage unit to enable the chip in the terminal to execute the method for sending wireless report information according to any one of the above first aspects. Optionally, the storage unit is the storage unit inside the chip, such as a register, a cache, etc. The storage unit can also be the storage unit outside the chip in the terminal, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.
[0137] Among them, the processor mentioned anywhere above can be a general-purpose central processing unit, a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the above methods.
[0138] In addition, it should be noted that the device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the drawings of the device embodiments provided in this application, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.
[0139] Through the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general hardware, and of course, it can also be implemented by dedicated hardware including application-specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, functions completed by computer programs can be easily implemented by corresponding hardware, and the specific hardware structures for implementing the same function can also be diverse, such as analog circuits, digital circuits, or dedicated circuits. However, for this application, in more cases, software program implementation is a better implementation method. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a floppy disk, a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disc of a computer, and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments of this application.
[0140] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product.
[0141] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
Claims
1. A cloud data sharing system for supply chain, characterized in that: include: The proxy server is used to generate a public-private key pair, wherein the public-private key pair includes a corresponding public key and a private key; The public key is used to encrypt the plaintext to obtain the ciphertext; The private key is used to decrypt the ciphertext to obtain the plaintext; A first supply chain terminal, used for sending shared data to the proxy server; The proxy server is further used to encrypt the shared data using the public key to obtain a ciphertext of the shared data; The proxy server is further used to perform secret sharing on the shared data ciphertext based on a threshold value t to obtain N secret shares, where N and t are both positive integers, and N is greater than t; The proxy server is further configured to send a corresponding secret share of the N secret shares to each supply chain terminal among the N supply chain terminals, wherein the N supply chain terminals and the N secret shares correspond one to one, so that each supply chain terminal among the N supply chain terminals stores the corresponding secret share; A second supply chain terminal is used to send a first data request to the proxy server, where the first data request is used to request the shared data; The proxy server is further used to request at least t supply chain terminals among the N supply chain terminals to obtain the stored secret shares; If the proxy server successfully obtains the at least t secret shares, the proxy server generates the shared data ciphertext based on the at least t secret shares; The proxy server is further configured to decrypt the shared data ciphertext based on the private key to obtain the shared data; The proxy server is further used to send the shared data to the second supply chain terminal.
2. A proxy server for cloud data sharing in supply chain, characterized in that: include: A processing module, configured to generate a public-private key pair, wherein the public-private key pair includes a corresponding public key and a private key; The public key is used to encrypt the plaintext to obtain the ciphertext; The private key is used to decrypt the ciphertext to obtain the plaintext; A transceiver module, used for receiving shared data sent by the first supply chain terminal; The processing module is further used to encrypt the shared data using the public key to obtain a shared data ciphertext; The processing module is further used to perform secret sharing on the shared data ciphertext based on a threshold value t to obtain N secret shares, where N and t are both positive integers, and N is greater than t; The transceiver module is further used to send a corresponding secret share of the N secret shares to each supply chain terminal among the N supply chain terminals, wherein the N supply chain terminals and the N secret shares correspond one to one, so that each supply chain terminal among the N supply chain terminals stores the corresponding secret share; The transceiver module is further used to receive a first data request sent by a second supply chain terminal, where the first data request is used to request the shared data; The transceiver module is further used to request at least t supply chain terminals among the N supply chain terminals to obtain the stored secret share; The processing module is further configured to generate the shared data ciphertext based on the at least t secret shares if the at least t secret shares are successfully obtained; The processing module is further used to decrypt the shared data ciphertext based on the private key to obtain the shared data; The transceiver module is also used to send the shared data to the second supply chain terminal.
3. A cloud data sharing method for supply chain, characterized in that: include: The proxy server generates a public-private key pair, wherein the public-private key pair includes a corresponding public key and a private key; The public key is used to encrypt the plaintext to obtain the ciphertext; The private key is used to decrypt the ciphertext to obtain the plaintext; The first supply chain terminal sends the shared data to the proxy server; The proxy server encrypts the shared data using the public key to obtain a ciphertext of the shared data; The proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares, where N and t are both positive integers, and N is greater than t; The proxy server sends a corresponding secret share of the N secret shares to each supply chain terminal among the N supply chain terminals, wherein the N supply chain terminals and the N secret shares correspond one to one, so that each supply chain terminal among the N supply chain terminals stores the corresponding secret share; The second supply chain terminal sends a first data request to the proxy server, where the first data request is used to request the shared data; The proxy server requests at least t supply chain terminals among the N supply chain terminals to obtain the stored secret share; The proxy server generates the shared data ciphertext based on the at least t secret shares; The proxy server decrypts the shared data ciphertext based on the private key to obtain the shared data; The proxy server sends the shared data to the second supply chain terminal.
4. The method according to claim 3, characterized in that: The proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares, including: The proxy server runs the sharing generation algorithm SS.Split(es,t) of the distributed threshold homomorphic encryption system to obtain the N secret shares, wherein t is the threshold value, es is the shared data ciphertext, and the SS.Split() is the Shamir secret sharing algorithm.
5. The method according to claim 3 or 4, characterized in that: After the proxy server performs secret sharing on the shared data ciphertext based on the threshold value t and obtains N secret shares, the method further includes: The proxy server stores the N secret shares locally.
6. The method according to claim 5, characterized in that: After the second supply chain terminal sends the first data request to the proxy server, the method further includes: The proxy server obtains the N secret shares locally based on the first data request; If the proxy server successfully obtains the N secret shares locally, the proxy server executes the step of generating the shared data ciphertext based on the at least t secret shares; If the proxy server fails to successfully obtain the N secret shares locally, the proxy server executes the step of requesting at least t supply chain terminals among the N supply chain terminals to obtain the stored secret shares.
7. A cloud data sharing method for supply chain, characterized in that: include: The proxy server generates a public-private key pair, wherein the public-private key pair includes a corresponding public key and a private key; The public key is used to encrypt the plaintext to obtain the ciphertext; The private key is used to decrypt the ciphertext to obtain the plaintext; The proxy server receives the shared data sent by the first supply chain terminal; The proxy server encrypts the shared data using the public key to obtain a ciphertext of the shared data; The proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares, where N and t are both positive integers, and N is greater than t; The proxy server sends a corresponding secret share of the N secret shares to each of the N supply chain terminals, wherein the N supply chain terminals and the N secret shares correspond one to one, so that each of the N supply chain terminals stores the corresponding secret share; The proxy server receives a first data request sent by a second supply chain terminal, where the first data request is used to request the shared data; The proxy server requests at least t supply chain terminals among the N supply chain terminals to obtain the stored secret share; If the proxy server successfully obtains the at least t secret shares, the proxy server generates the shared data ciphertext based on the at least t secret shares; The proxy server decrypts the shared data ciphertext based on the private key to obtain the shared data; The proxy server sends the shared data to the second supply chain terminal.
8. The method according to claim 7, characterized in that: The proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares, including: The proxy server runs the sharing generation algorithm SS.Split(es,t) of the distributed threshold homomorphic encryption system to obtain the N secret shares, wherein t is the threshold value, es is the shared data ciphertext, and the SS.Split() is the Shamir secret sharing algorithm.
9. The method according to claim 7 or 8, characterized in that: After the proxy server performs secret sharing on the shared data ciphertext based on the threshold value t to obtain N secret shares, the method further includes: The proxy server stores the N secret shares locally.
10. The method according to claim 9, characterized in that: After the second supply chain terminal sends the first data request to the proxy server, the method further includes: The proxy server obtains the N secret shares locally based on the first data request; If the proxy server successfully obtains the N secret shares locally, the proxy server executes the step of generating the shared data ciphertext based on the at least t secret shares; If the proxy server fails to successfully obtain the N secret shares locally, the proxy server executes the step of requesting at least t supply chain terminals among the N supply chain terminals to obtain the stored secret shares.