Anonymous attribute multi-keyword searchable encryption method based on block chain
By designing anonymous attribute multi-keyword searchable encryption method based on blockchain technology, the problem of insufficient access policy protection in the existing technology is solved, efficient and secure data retrieval and sharing are achieved, and data privacy protection and access security are significantly improved.
Patent Information
- Application Number
- CN202510329920.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-20
AI Technical Summary
Existing searchable encryption schemes based on attributes have shortcomings in the protection of access policies. Unauthorized users may infer sensitive information through access policies, especially in areas where privacy requirements are extremely high.
A blockchain-based anonymous attribute multi-keyword searchable encryption method is proposed. The authoritative central system initializes the distribution of attribute keys, the patient encrypts and uploads medical data to the interstellar file system and sends it to the blockchain verification and storage, and the doctor generates traps based on the attribute keys and query keywords to ensure the encryption and protection of policy information.
It significantly enhances the privacy protection and access security of data. By integrating blockchain technology and optimized hidden access policies, efficient and trustworthy data retrieval and sharing are achieved, improving the accuracy and efficiency of data retrieval.
Smart Images

Figure CN120217414A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network information security technology, and particularly relates to an anonymous attribute multi-keyword searchable encryption method based on blockchain. Background Art
[0002] The rapid development of blockchain technology has provided convenience for many users; with its decentralized, transparent, and tamper-proof characteristics, blockchain can provide efficient distributed computing services while ensuring data security and privacy; however, despite its strong security, there is still a risk of privacy leakage, especially when dealing with data containing sensitive information; therefore, in order to ensure the privacy and security of data, data owners usually encrypt the data before outsourcing it to the blockchain to ensure that even if the data is stored on the blockchain, it can still maintain privacy and security.
[0003] In traditional technologies, simply encrypting data cannot fully solve the privacy protection problem in blockchain applications. To further enhance the security and privacy of data, researchers have developed attribute-based searchable encryption schemes. These schemes combine attribute-based encryption and search encryption technologies, allowing users to perform controlled searches on encrypted data, thereby retrieving specific information without revealing the data content. This ability not only makes data retrieval more efficient but also significantly strengthens the protection of user privacy by restricting access rights.
[0004] However, most existing attribute-based searchable encryption schemes have obvious deficiencies in protecting access policies. The access policies are usually embedded in the encrypted data in plain text, which may lead to unauthorized users inferring sensitive information through the access policies. Especially in fields with extremely high privacy requirements such as healthcare, such vulnerabilities may cause serious consequences. Summary of the Invention
[0005] To solve the above technical problems, this application proposes the following technical solutions: In a first aspect, an embodiment of this application provides an anonymous attribute multi-keyword searchable encryption method based on blockchain, including: S1, after the authoritative center system is initialized, it distributes attribute keys to doctors who request registration. The authoritative center system is used to implement user registration and key distribution; S2, the patient encrypts and uploads medical data to the InterPlanetary File System, encrypts the returned hash address and symmetric key, and then sends all the generated ciphertexts together with the generated index to the blockchain for verification and storage; S3, the doctor generates a trapdoor based on the attribute key and query keywords and sends it to the blockchain for query. After the encrypted index on the blockchain side matches the trapdoor successfully, the corresponding ciphertext is returned; S4, the doctor decrypts the ciphertext to obtain the hash address and the symmetric key, then obtains the encrypted medical data according to the hash address, and finally decrypts the medical data using the symmetric key.
[0006] In a possible implementation, after the authority center system is initialized, it distributes attribute keys to doctors who request registration, including: S11, the authority center inputs security parameters to initialize the system and generates system public keys, public parameters and master keys. The system public keys and public parameters are used to publish to all users, and the master key is saved by the authority center; S12, when the doctor registers in the system, the authority center enters the user identity, system public key and master key, generates identity information and sends it to the blockchain. At the same time, the authority center updates the system public key and master key to ensure the security of the system; S13, the doctor submits a set of attribute sets to the authoritative center, and the authoritative center inputs the master key, public parameters, public key and attribute set to obtain the attribute key and sends it to the doctor.
[0007] In one possible implementation, S11 includes: the authoritative center AC will be the security parameters As input, the algorithm chooses two prime numbers of order p The multiplicative cyclic groups G1 and G T , and define a bilinear map e: G1×G1→ G T ; Let g be the generator of group G1; is less than p The set of positive integers , The following five hash functions are defined: , , , , ; In the specific calculation of the hash function H1, the input as well as After connecting the strings, a hash operation is performed; the authoritative center AC randomly selects , and calculate the common parameters ; The master key of the output system is set to ; Output public key is , the global parameters of the output system are: Para= ; S12 includes: when the authority center AC receives the doctor's registration request, selects a random number , the authoritative center AC calculates the intermediate results ; Finally, the authority center AC updates the system public key and master key to obtain the public key and the master key ; The authoritative center AC also sends the identity information as the content of the list UL to the blockchain BC; S13 includes: taking the global parameters Para, public key PK, master secret key MSK, and attribute set S of the system as inputs, where S = [S1,..., Sn]; executed by the authoritative center AC to generate the doctor's key, and the authoritative center AC calculates the intermediate result , calculates the key attribute component , and outputs the doctor's attribute secret key as SK = ..
[0008] In a possible implementation, the patient encrypts and uploads the medical data to the InterPlanetary File System, encrypts the returned hash address and the symmetric key, and then sends all the generated ciphertexts together with the generated index to the blockchain for verification and storage, including: S21, the patient encrypts the medical data using the symmetric key and uploads the encrypted data to the InterPlanetary File System to obtain the hash address of the ciphertext; S22, after selecting a set of keyword sets and access policies, hides the access policy and generates an index; S23, the patient encrypts the ciphertext hash address and the symmetric key into a ciphertext; S24, finally the patient sends the ciphertext, index, and signature to the blockchain, and the blockchain verifies the signature and stores it.
[0009] In a possible implementation, S21 includes: randomly selecting a symmetric key K and encrypting the medical data m, and the patient uploads the encrypted data to the InterPlanetary File System, and returns the hash address M of the encrypted file; S22 includes: taking the global parameters Para, public key PK, keyword set W, and access policy T of the system as inputs, assuming the access policy T = [T1,..., T n and the keyword set W = [W1,..., W n ; the algorithm uniformly selects a random number , sets , and calculates the hidden form of the access policy as ; first calculates the index vector , and outputs the index as: ; S23 includes: encrypting the hash address M and the symmetric key K into a ciphertext, and calculating the ciphertext vector through ; outputs the ciphertext ; S24 includes: selecting a random number , and calculates the results respectively ; The output ciphertext signature ; The encrypted index , the ciphertext CT, and the digital signature are transmitted to the blockchain BC; after receiving the above data, the blockchain node first performs a hash operation on the encrypted index and the ciphertext CT to obtain ; The blockchain BC performs a bilinear pairing verification: , and only when this equation holds, the blockchain node will use the encrypted index , the ciphertext CT, and the digital signature as valid data and store them in the distributed ledger. In a possible implementation, the doctor generates a trapdoor based on the attribute key and the query keyword and sends it to the blockchain for query. After the encrypted index on the blockchain side matches the trapdoor successfully, the corresponding ciphertext is returned, including: S31, the doctor selects the keywords he is interested in, inputs the keywords he is interested in and the attribute key to generate a trapdoor, and then the doctor sends the trapdoor to the blockchain for a query request; S32, after receiving the doctor's trapdoor, the blockchain checks whether the user unique identifier is in the user list. If it does not exist, it returns failure; if it exists, it restores the hidden access policy and verifies whether it matches; if the verification passes, the system restores the random elements in the encryption process and verifies the search request by matching the keywords; if the keywords match successfully, it returns the encrypted search result, otherwise it returns failure; finally, it returns the ciphertext to the doctor.
[0010] In a possible implementation, the S31 includes: using the global parameter Para, the public key PK, the doctor's key SK, and the set of keywords of interest as inputs, and setting the set of keywords as: , selecting a random number , and calculating the trapdoor vectors respectively; calculating the trapdoor keyword set component ; The output trapdoor is ; the S32 includes: when the blockchain BC receives the trapdoor sent by the doctor and the unique identifier IDu of the data user DUu, BC first checks whether IDu exists in the UL list; if it does not exist, the user is not allowed to search and the algorithm outputs ⊥; otherwise, the blockchain BC will restore the ciphertext encrypted using the hidden access policy: ; Then verify the intermediate result whether it is the same as the index vector Equal; if this equation does not hold, the algorithm immediately terminates and outputs an error identifier , indicating that the verification fails; otherwise, calculate the intermediate element ; When receiving D, the blockchain BC performs keyword matching verification to check whether the following equation holds: ; In the keyword matching verification stage, a multi-keyword indexing mechanism is adopted, where the index structure contains n keywords, and the search trapdoor contains keywords, satisfying the constraint condition of ; When the system performs keyword matching verification, the following decision rule is adopted: If any match is successful, the keyword test is considered successful; the blockchain BC returns the new ciphertext to the doctor, where ; Otherwise, it will return .
[0011] In a possible implementation, the doctor generates a trapdoor based on the attribute key and the query keyword and sends it to the blockchain for query. After the encrypted index on the blockchain side matches the trapdoor successfully, the corresponding ciphertext is returned, including: S41, the doctor inputs his own attribute key and ciphertext, decrypts to obtain the ciphertext hash address and the symmetric key, and sends the ciphertext hash address to the InterPlanetary File System; S42, after the InterPlanetary File System accepts the ciphertext hash address, it sends the encrypted ciphertext to the doctor, and the doctor decrypts the encrypted ciphertext using the symmetric key to obtain the medical data.
[0012] In a possible implementation S41 includes: taking the global parameters Para, the key SK, and the ciphertext CT' of the system as inputs, and calculating the intermediate result in order to obtain the medical data m, and then calculating the symmetric key and the ciphertext hash address .
[0013] S42 includes: the doctor sends the ciphertext hash address M to the InterPlanetary File System to obtain the ciphertext data, and decrypts it using the symmetric key K to obtain the medical data m.
[0014] In the embodiments of the present application, during the data access process, the policy information is encrypted and protected to ensure that attackers cannot obtain sensitive information through policy analysis. This design not only significantly enhances the privacy protection of data but also fundamentally improves the security of data access. At the same time, by integrating blockchain technology, the InterPlanetary File System, and optimized hidden access policies, not only the privacy and security of data access are improved, but also efficient and reliable data retrieval and sharing are achieved, providing a more user-friendly and reliable data sharing environment for users. Through the optimization of multi-keyword search, the accuracy and efficiency of data retrieval are significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 FIG. [FIG. NUMBER] is a schematic diagram of a system framework provided by an embodiment of the present application; Figure 2 FIG. [FIG. NUMBER] is a schematic flowchart of a blockchain-based anonymous attribute multi-keyword searchable encryption method provided by an embodiment of the present application; Figure 3 FIG. [FIG. NUMBER] is a schematic interaction flowchart provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] The following elaborates on this solution in combination with the accompanying drawings and specific embodiments.
[0017] See Figure 1 , the entities involved in this embodiment include: Authoritative Center (AC): A completely trusted entity responsible for generating the master key, system public key, and public parameters of the system. According to the needs of doctors, the authoritative center creates and securely distributes keys to doctors, ensuring the security and reliability of key management. Blockchain (BC): A semi-trusted entity mainly responsible for storing encrypted data and processing user requests. By leveraging the functions of smart contracts, the blockchain can automatically execute predefined rules and logic to ensure the correct implementation of the solution. The immutability and transparency of smart contracts provide a high degree of credibility and security for the system. InterPlanetary File System (IPFS): As a semi-trusted entity, the InterPlanetary File System is responsible for the distributed storage of patients' encrypted data. When receiving a doctor's data address request, IPFS will return the corresponding encrypted file. The distributed storage feature of IPFS effectively avoids the single point of failure problem and improves the availability of data and the fault tolerance of the system. Patient: A trusted entity that has full control over its own data and is the controller of the access rights to encrypted data. The patient is responsible for creating an encrypted index and uploading the encrypted medical data to IPFS to obtain a data address. Subsequently, the patient generates a digital signature to verify the integrity and authenticity of the data, and uploads the encrypted index, ciphertext, signature, and user list to the blockchain. The patient's operations ensure the privacy and security of the data. Doctor: A semi-trusted entity that obtains encrypted data by providing a trapdoor to the blockchain and obtains an encrypted file by providing an encrypted data address to IPFS. The doctor can access the medical data after decryption. However, the doctor may attempt to obtain unauthorized access rights to medical data.
[0018] Based on the above participating entities, refer to Figure 2 and Figure 3 , the blockchain-based anonymous attribute multi-keyword searchable encryption method provided in this embodiment includes: S1. After the authoritative center system is initialized, it distributes attribute keys to doctors who request registration. The authoritative center system is used to implement user registration and key distribution.
[0019] In this embodiment, S1 includes: S11. The authoritative center inputs security parameters to initialize the system and generates a system public key, public parameters, and a master key. The system public key and public parameters are used to be published to all users, and the master key is saved by the authoritative center. S12. When a doctor registers in the system, the authoritative center inputs the user identity, system public key, and master key, generates identity information and sends it to the blockchain. At the same time, the authoritative center updates the system public key and master key to ensure the security of the system. S13. The doctor submits a set of attribute sets to the authoritative center. The authoritative center inputs the master key, public parameters, public key, and attribute sets to obtain attribute keys and sends them to the doctor.
[0020] Specifically, S11 includes: The authoritative center AC takes the security parameters As input, the algorithm selects two multiplicative cyclic groups G1 and G p of prime order T , and defines a bilinear map e: G1×G1 → G T . Let g be the generator of the group G1. is the set of positive integers less than p . , Define the following five hash functions: , , , , . Among them, in the specific calculation of the hash function H1, after concatenating the input and strings, a hash operation is performed. The authority center AC randomly selects , and calculates the public parameter . The master key of the output system is set to . The output public key is , and the global parameter of the output system is: Para = ; S12 includes: when the authority center AC receives the doctor's registration request, it selects a random number , and the authority center AC calculates the intermediate result . Finally, the authority center AC updates the system public key and the master key to obtain the public key and the master key . The authority center AC also sends the identity information as the content of the list UL to the blockchain BC.
[0021] S13 includes: taking the global parameter Para, the public key PK, the master key MSK, and the attribute set S of the system as input, where S = [S1,..., Sn]. The authority center AC executes to generate the doctor's key. The authority center AC calculates the intermediate result , calculates the key attribute component , and outputs the doctor's attribute secret key as SK = .
[0022] S2. The patient encrypts the medical data and uploads it to the InterPlanetary File System, encrypts the returned hash address and the symmetric key, and then sends all the generated ciphertexts together with the generated index to the blockchain for verification and storage.
[0023] In this embodiment, S2 includes: S21, the patient encrypts the medical data using the symmetric key and uploads the encrypted data to the InterPlanetary File System to obtain the hash address of the ciphertext. S22, after selecting a set of keyword sets and access policies, the access policy is hidden and an index is generated. S23, the patient encrypts the ciphertext hash address and the symmetric key into a ciphertext. S24, finally, the patient sends the ciphertext, index, and signature to the blockchain, and the blockchain stores them after verifying the signature.
[0024] Specifically, S21 includes: randomly selecting the symmetric key K and encrypting the medical data m, and the patient uploads the encrypted data to the InterPlanetary File System, and the hash address M of the encrypted file is returned.
[0025] S22 includes: taking the global parameters Para of the system, the public key PK, the keyword set W, and the access policy T as inputs. Assume the access policy T = [T1,..., T n and the keyword set W = [W1,..., W n . The algorithm uniformly selects a random number , sets , and calculates the hidden form of the access policy as . First, calculate the index vector , and the output index is: .
[0026] S23 includes: encrypting the hash address M and the symmetric key K into a ciphertext, and calculating the ciphertext vector . The output ciphertext is .
[0027] S24 includes: selecting a random number , and respectively calculating the results . The output ciphertext signature is ; the encrypted index , the ciphertext CT, and the digital signature are transmitted to the blockchain BC. After receiving the above data, the blockchain node first performs a hash operation on the encrypted index and the ciphertext CT to obtain . The blockchain BC performs a bilinear pair verification: . When and only when this equation holds, the blockchain node stores the encrypted index , the ciphertext CT, and the digital signature as valid data in the distributed ledger.
[0028] S3, the doctor generates a trapdoor based on the attribute key and the query keyword and sends it to the blockchain for query. After the encrypted index on the blockchain side matches the trapdoor successfully, the corresponding ciphertext is returned.
[0029] In this embodiment, S3 includes: S31, where the doctor selects keywords of interest, generates a trapdoor by inputting the keywords of interest and the attribute key, and then the doctor sends the trapdoor to the blockchain for a query request. S32, after receiving the trapdoor from the doctor, the blockchain checks whether the user unique identifier exists in the user list. If it does not exist, it returns failure. If it exists, it restores the hidden access policy and verifies whether they match. If the verification passes, the system restores the random elements during the encryption process and verifies the search request by matching the keywords. If the keyword matching is successful, it returns the encrypted search result; otherwise, it returns failure. Finally, it returns the ciphertext to the doctor.
[0030] Specifically, S31 includes: taking the global parameter Para, the public key PK, the doctor's key SK, and the set of keywords of interest as inputs, and setting the set of keywords to: , selecting a random number , and respectively calculating the trapdoor vectors . Calculating the component of the trapdoor keyword set . The output trapdoor is .
[0031] S32 includes: when the blockchain BC receives the trapdoor sent by the doctor and the unique identifier IDu of the data user DUu, BC first checks whether IDu exists in the UL list. If it does not exist, the user is not allowed to search, and the algorithm outputs ⊥. Otherwise, the blockchain BC restores the ciphertext encrypted using the hidden access policy: . Then it verifies whether the intermediate result is equal to the index vector . If this equation does not hold, the algorithm immediately terminates and outputs the error identifier , indicating that the verification fails. Otherwise, it calculates the intermediate element . When receiving D, the blockchain BC performs keyword matching verification and checks whether the following equation holds: . In the keyword matching verification stage, a multi-keyword indexing mechanism is adopted, where the index structure contains n keywords, and the search trapdoor contains keywords, satisfying the constraint condition of . When the system performs keyword matching verification, the following decision rule is adopted: if any match is successful, the keyword test is considered successful. The blockchain BC returns the new ciphertext to the doctor, where . Otherwise, it will return .
[0032] S4, the doctor decrypts the ciphertext to obtain the hash address and the symmetric key, then obtains the encrypted medical data according to the hash address, and finally decrypts it with the symmetric key to obtain the medical data.
[0033] In this embodiment, S4 includes: S41, the doctor inputs his own attribute key and the ciphertext, decrypts to obtain the ciphertext hash address and the symmetric key, and sends the ciphertext hash address to the InterPlanetary File System. S42, after receiving the ciphertext hash address, the InterPlanetary File System sends the encrypted ciphertext to the doctor, and the doctor decrypts the encrypted ciphertext with the symmetric key to obtain the medical data.
[0034] Specifically, S41 includes: taking the global parameter Para of the system, the key SK and the ciphertext CT' as inputs, and calculating an intermediate result for obtaining the medical data m , and further calculating to obtain the symmetric key and the ciphertext hash address . S42 includes: the doctor sends the ciphertext hash address M to the InterPlanetary File System to obtain the ciphertext data, and decrypts it with the symmetric key K to obtain the medical data m.
[0035] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent the situation where A exists alone, A and B exist simultaneously, or B exists alone. Where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" and its similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0036] As described above, the above is only the specific implementation manner of the present application. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. The protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A blockchain-based anonymous attribute multi-keyword searchable encryption method, characterized in that: include: S1, after the authority center system is initialized, it distributes attribute keys to doctors who request registration. The authority center system is used to implement user registration and key distribution; S2, the patient uploads the encrypted medical data to the Interstellar File System, encrypts the returned hash address and symmetric key, and then sends all the generated ciphertexts together with the generated index to the blockchain for verification and storage; S3: The doctor generates a trapdoor based on the attribute key and the query keyword and sends it to the blockchain for query. After the encrypted index on the blockchain successfully matches the trapdoor, the corresponding ciphertext is returned. S4, the doctor decrypts the ciphertext to obtain the hash address and the symmetric key, then obtains the encrypted medical data according to the hash address, and finally decrypts the medical data using the symmetric key.
2. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 1 is characterized in that: After the authoritative center system is initialized, it distributes attribute keys to doctors who request registration, including: S11, the authority center inputs security parameters to initialize the system and generates system public keys, public parameters and master keys. The system public keys and public parameters are used to publish to all users, and the master key is saved by the authority center; S12, when the doctor registers in the system, the authority center enters the user identity, system public key and master key, generates identity information and sends it to the blockchain. At the same time, the authority center updates the system public key and master key to ensure the security of the system; S13, the doctor submits a set of attribute sets to the authoritative center, and the authoritative center inputs the master key, public parameters, public key and attribute set to obtain the attribute key and sends it to the doctor.
3. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 2 is characterized in that: S11 includes: the authoritative center AC will be the security parameters As input, the algorithm chooses two prime numbers of order p The multiplicative cyclic groups G1 and G T , and define a bilinear map e: G1×G1→ G T ; Let g be the generator of group G1; is less than p The set of positive integers , The following five hash functions are defined: , , , , ; In the specific calculation of the hash function H1, the input as well as After connecting the strings, a hash operation is performed; the authoritative center AC randomly selects , and calculate the common parameters ; The master key of the output system is set to ; Output public key is , the global parameters of the output system are: Para= ; S12 includes: when the authority center AC receives the doctor's registration request, selects a random number , the authoritative center AC calculates the intermediate results ; Finally, the authority center AC updates the system public key and master key to obtain the public key and the master key ; The authoritative center AC also sends the identity information Sent to blockchain BC as list UL content; S13 includes: taking the system's global parameters Para, public key PK, master key MSK and attribute set S as input, where S = [S1, ..., Sn]; executed by the authority center AC to generate the doctor's key, and the authority center AC calculates the intermediate result , calculate the key attribute component , output the doctor's attribute key as SK= .
4. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 1 is characterized in that: The patient uploads the encrypted medical data to the Interstellar File System, encrypts the returned hash address and symmetric key, and then sends all the generated ciphertexts together with the generated index to the blockchain for verification and storage, including: S21, the patient encrypts the medical data using the symmetric key and uploads the encrypted data to the InterPlanetary File System to obtain the hash address of the ciphertext; S22, after selecting a set of keyword sets and access policies, hide the access policies and generate an index; S23, the patient encrypts the ciphertext hash address and the symmetric key into ciphertext; S24, finally the patient sends the ciphertext, index, and signature to the blockchain, which verifies the signature and stores it.
5. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 4 is characterized in that: S21 includes: randomly selecting a symmetric key K and encrypting the medical data m, the patient uploading the encrypted data to the Interplanetary File System, and returning the hash address M of the encrypted file; S22 includes: taking the system's global parameter Para, public key PK, keyword set W and access policy T as input, assuming that access policy T = [T1, ..., T n ] and keyword set W = [W1, ..., W n ]; algorithm uniformly selects random numbers ,set up , the hidden form of the computational access policy is ; First calculate the index vector , the output index is: ; S23 includes: encrypting the hash address M and the symmetric key K into ciphertext, and calculating the ciphertext vector ; Output ciphertext ; S24 includes: selecting a random number , respectively calculate the results ; Output ciphertext signature ;Dense index , ciphertext CT and digital signature Transmit to blockchain BC; after receiving the above data, the blockchain node first performs encryption index Perform hash operation on the ciphertext CT to obtain ; Blockchain BC performs bilinear pairing verification: , if and only if this equation holds, the blockchain node will encrypt the index , ciphertext CT and digital signature Stored as valid data in the distributed ledger.
6. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 1 is characterized in that: The doctor generates a trapdoor based on the attribute key and the query keyword and sends it to the blockchain for query. After the encrypted index on the blockchain side successfully matches the trapdoor, the corresponding ciphertext is returned, including: S31, the doctor selects the keyword of interest, enters the keyword of interest and the attribute key to generate a trapdoor, and then the doctor sends the trapdoor to the blockchain for query request; S32, after the blockchain receives the doctor's trapdoor, it checks whether the user's unique identifier is in the user list. If not, it returns failure; if it exists, it restores the hidden access policy and verifies whether it matches; if the verification passes, the system restores the random elements in the encryption process and verifies the search request by matching keywords; if the keyword matches successfully, it returns the encrypted search results, otherwise it returns failure; finally, it returns the ciphertext to the doctor.
7. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 6 is characterized in that: The step S31 includes: combining the global parameter Para, the public key PK, the doctor's key SK and the keyword set of interest As input, the keyword set Set to: , choose a random number , respectively calculate the trapdoor vector ; Calculate the trapdoor keyword set component ; The output trapdoor is ; The S32 includes: blockchain BC receives the trapdoor sent by the doctor When the unique identifier IDu of the data user DUu is obtained, BC first checks whether IDu exists in the UL list; if it does not exist, the user is not allowed to search and the algorithm outputs ⊥; otherwise, the blockchain BC will restore the ciphertext encrypted using the hidden access strategy: ; Then verify the intermediate results Is it consistent with the index vector If the equality does not hold, the algorithm terminates immediately and outputs an error identifier , indicating that the verification failed; otherwise, the middle element is calculated ; When receiving D, blockchain BC performs keyword matching verification to check whether the following equation holds: In the keyword matching verification phase, a multi-keyword indexing mechanism is adopted, where the index structure contains n keywords and the search trap contains Keywords, meet When the system performs keyword matching verification, the following judgment rules are adopted: if any match is successful, the keyword test is considered successful; the blockchain BC will Return to the doctor, Otherwise, it will return .
8. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 1 is characterized in that: The doctor generates a trapdoor based on the attribute key and the query keyword and sends it to the blockchain for query. After the encrypted index on the blockchain side successfully matches the trapdoor, the corresponding ciphertext is returned, including: S41, the doctor inputs his own attribute key and ciphertext, decrypts to obtain the ciphertext hash address and symmetric key, and sends the ciphertext hash address to the Interplanetary File System; S42, after the Interplanetary File System receives the ciphertext hash address, it sends the encrypted ciphertext to the doctor, who uses the symmetric key to decrypt the encrypted ciphertext and obtain the medical data.
9. The anonymous attribute multi-keyword searchable encryption method based on blockchain according to claim 8 is characterized in that: The S41 includes: taking the system global parameter Para, the key SK and the ciphertext CT' as input, and calculating the intermediate result to obtain the medical data m , and then calculate the symmetric key and the ciphertext hash address ; The S42 includes: the doctor sends the ciphertext hash address M to the Interplanetary File System to obtain the ciphertext data, and uses the symmetric key K to decrypt to obtain the medical data m.
Citation Information
Patent Citations
Attribute-based searchable encrypted block chain medical data sharing method
CN112765650A
Electronic medical record sharing method, system and equipment based on block chain and storage medium
CN116469501A
Constant ciphertext length and policy hiding access control method based on block chain
CN119066704A
User usage based encryption system and method thereof
IN202041053162A
Cited By
Safe and reliable multi-satellite task collaborative matching method based on block chain
CN120934761A