Security evidence storage method and system on data cross-domain circulation information chain based on bloom filter

By using Bloom filter and anonymous signature technology in cross-domain data circulation, the problem of information storage and traceability in cross-domain data circulation is solved, and trusted records and security verification of data circulation paths are realized, and an effective traceability and violation proof mechanism is provided.

CN120217449APending Publication Date: 2025-06-27HUAZHONG UNIV OF SCI & TECH

Patent Information

Application Number
CN202510270552.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the process of cross-domain data circulation, ensuring credible records and secure evidence storage of information is an urgent issue, especially when multiple parties participate and complex circulation paths, it is difficult for the existing technology to effectively solve the evidence storage and traceability of information related to the data transmission process.

Method used

The security proof storage method of cross-domain data circulation information chain based on Bloom filter is adopted. Through the collaboration between regulators and domain administrators, an anonymous signature private key and preset element insertion and query algorithm are used to realize the security proof storage and traceability of cross-domain data circulation information.

Benefits of technology

It realizes that during the data cross-domain circulation process, the data flow path can be reliably recorded and verified, ensuring the transparency and credibility of the data transmission process, and providing an effective traceability and proof of violations when risks occur.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217449A_ABST
    Figure CN120217449A_ABST
Patent Text Reader

Abstract

The invention belongs to the related technical field of data cross-domain circulation, and particularly relates to a data cross-domain circulation information chain security evidence storage method and system based on a Bloom filter, and the method comprises the steps: enabling each domain administrator to interact with a supervisor, and obtaining a private key which is only mastered by the domain administrator; each domain administrator stores the generated current cross-domain circulation information into a bloom filter controlled by an access supervisor of the domain administrator by adopting an element insertion algorithm preset by supervisor parameters, and if insertion fails, the number of elements contained in the filter reaches an upper limit or the filter currently reaches a periodic uplink time requirement, and the current cross-domain circulation information is stored in the bloom filter. If yes, performing anonymous signature on the current Bloom filter by adopting a private key mastered by the domain administrator and recording the signature in the block chain; a supervisor can inquire whether a certain cross-domain circulation information of the specified data exists in a certain Bloom filter or not, a circulation path of the specified data is obtained, and safe evidence storage is achieved. According to the invention, a reliable data flow path can be obtained when a risk occurs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field related to cross - domain data transfer, and more specifically, relates to a method and system for securely storing information on the chain of cross - domain data transfer based on a Bloom filter. Background Art

[0002] Nowadays, data has become an important production factor, leading to the vigorous development of China's digital economy. Building a compliant and efficient cross - domain data circulation and strengthening data security guarantee are the prerequisites for data factors to play their value. Cross - domain data scenarios are not limited to data going abroad. For example, in intelligent vehicle networking, vehicles communicate across domains through multiple roadside units; in medical data, the cross - hospital sharing of electronic medical records can avoid repeated examinations of patients and promote timely treatment; in industrial Internet, a large amount of sensor data needs to be shared across domains to enable management departments to integrate multi - source information for comprehensive decision - making. When dealing with cross - domain data transfer, ensuring the trustworthy recording of information has become the cornerstone for guaranteeing the compliance verification of the transfer. Given that this process often involves many entities and departments, the complexity of the transfer path further exacerbates the management difficulty, thus giving rise to a series of novel and urgent security and privacy protection challenges, which are significantly different from the traditional centralized data transmission mode.

[0003] Chinese Patent CN114844695B discloses a method, system and related device for business data transfer based on blockchain. The invention ensures the security of data during the business data transfer process by introducing a third - party agent and using encryption technology, and does not pay attention to the specific information of the data transfer path. Chinese Patent CN118114310A discloses a data transfer method and system, which has the following steps: S1, uploading data; S2, encrypting data; S3, scheduling data; S4, writing the received encrypted data block into the blockchain; S5, using data. The invention guarantees the integrity, traceability and non - deniability of data during the transfer process. Compared with the traditional data transfer method, it solves the problems that data is easily tampered with and the data source is difficult to trace. However, the invention completely uses the blockchain to store all information of the data, which puts great pressure on the blockchain network. In addition, although it also supports tracing the data source, it does not pay attention to the information related to the data transfer process.

[0004] Therefore, data contains rich sensitive information. To ensure its secure transfer, it is crucial and urgent to implement a transfer and storage mechanism during the cross - domain process. Summary of the Invention

[0005] In view of the above - mentioned defects or improvement requirements of the prior art, the present invention provides a method and system for securely storing information on the chain of cross - domain data transfer based on a Bloom filter, aiming to propose a method for storing evidence of cross - domain data transfer so that a reliable data transfer path can be obtained in case of risks.

[0006] To achieve the above object, according to one aspect of the present invention, there is provided a method for securely storing data cross-domain transfer information on a blockchain based on a Bloom filter, configuring supervisors required for the data cross-domain transfer process and domain administrators of each cross-domain node, so that supervisors and domain administrators can achieve secure storage of data cross-domain transfer information on the blockchain in the following manner:

[0007] Each domain administrator interacts with the supervisor based on a preset anonymous signature private key generation protocol to obtain a private key held only by the domain administrator;

[0008] Each domain administrator generates the current cross-domain transfer information of each piece of data when transferring each piece of data, and inserts the generated current cross-domain transfer information into a Bloom filter whose access is controlled by the supervisor by using an element insertion algorithm preset by the supervisor. If the insertion fails, the number of elements contained in the Bloom filter reaches the upper limit, or the Bloom filter meets the periodic on-chain time requirement at present, the current Bloom filter is anonymously signed with the private key held by the domain administrator and recorded on the blockchain;

[0009] The supervisor, according to the data user's request or its own needs, uses an element query algorithm preset by the supervisor to query whether a certain cross-domain transfer information of the specified data exists in a certain Bloom filter, so as to obtain a transfer path of the specified data, and achieve secure storage of data cross-domain transfer information on the blockchain based on the Bloom filter.

[0010] Furthermore, a data user is also configured so that the data user, supervisor, and / or domain administrator respectively verify the signature based on the verification need, using the public key corresponding to each signature, through an anonymous signature verification algorithm preset by the supervisor, to verify whether the private key of the domain administrator that generated the signature is legal.

[0011] Furthermore, as a data user of a full node of the blockchain, it can also apply to the supervisor for access rights to whether its own data cross-domain transfer information exists in the Bloom filter according to its own needs, and query whether a certain cross-domain transfer information of its own data exists in a certain Bloom filter through an element query algorithm preset by the supervisor, so as to obtain a transfer path of the own data, and achieve secure storage of data cross-domain transfer information on the blockchain based on the Bloom filter.

[0012] Furthermore, when a transfer path is obtained by the supervisor, each data user as a lightweight node of the blockchain can also verify the correctness of the transfer path.

[0013] Furthermore, the element insertion algorithm is:

[0014] Obtain the current filter or create a new filter (κ,η,λ)-CBF, where κ represents the total number of hash functions required for the Bloom filter CBF, η represents the optimal number of elements inserted into the Bloom filter CBF, and λ represents the length of the non-zero binary bits in the Bloom filter CBF;

[0015] Set the element insertion flag tag to -1; Use the bilinear mapping function preset by the supervisor parameter for the known data unique identifier Λ m and the first private key d of the known i-th domain administrator i,1 and the first master public key MPK1 of the supervisor are multiplied to obtain the intermediate variable u; Take the first l1 bits of u and the binary number N of the i-th domain administrator i are concatenated to obtain the element to be inserted result, and the bit length of the number N i is l2, satisfying l2 + l1 = λ;

[0016] Loop through the κ hash functions preset by the supervisor parameter represents the integer space between 0 and the maximum value of the position index in (κ,η,λ)-CBF to calculate the κ mapping positions of u in (κ,η,λ)-CBF Save the subscript of the first empty mapping position to the insertion flag tag, and write the randomly selected number r within the specified range [0, 2 λ -1] to the other empty mapping positions v , and calculate the exclusive OR result of the values r of all mapping positions except the mapping position corresponding to the subscript stored in tag v and result, and write it to the first empty mapping position;

[0017] If the element insertion flag tag is not equal to -1, the element insertion is successful, and the updated (κ,η,λ)-CBF is returned, otherwise the element insertion fails.

[0018] Furthermore, the element verification algorithm is as follows:

[0019] Use the bilinear mapping function preset by the supervisor parameter to multiply the known data unique identifier Λ m and the first private key s1 of the known supervisor and the public key DPK of a certain domain administrator * to obtain the element to be queried u';

[0020] Loop through the κ hash functions preset by the supervisor parameter represents the integer space between 0 and the maximum value of the position index in CBF In the integer space between them, the κ mapping positions of the element u' to be queried in the (κ, η, λ)-CBF are calculated. κ values in the mapping positions are obtained, and the exclusive OR calculation is performed to obtain the calculation result result'.

[0021] Take the first l1 bits of the element u' to be queried and the binary number N of the i-th domain administrator. i The concatenation result is obtained. If the administrator number N i is legal and the concatenation result is equal to the calculation result result', the query is successful, and the domain administrator number N is returned. i Otherwise, the query fails.

[0022] According to another aspect of the present invention, a secure on-chain storage system for cross-domain data transfer information based on a Bloom filter is provided, including: a supervisor, a domain administrator, and a data user; each party implements the secure on-chain storage process of cross-domain data transfer information based on the above-mentioned secure on-chain storage method of cross-domain data transfer information based on a Bloom filter.

[0023] According to another aspect of the present invention, an electronic device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned method are implemented.

[0024] According to another aspect of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium includes a stored computer program, wherein when the computer program is run by a processor, the device where the storage medium is located is controlled to execute the steps of the above-mentioned method.

[0025] Generally speaking, compared with the prior art through the above technical solutions conceived by the present invention, the technical solutions provided by the present invention mainly have the following beneficial effects:

[0026] 1. The present invention proposes a cross-domain anonymous storage method based on a constrained Bloom filter (CBF) whose access is controlled by a supervisor, enabling the domain administrator to effectively record the in-and-out domain information of data using it. Without permission, the correct result cannot be queried in the filter. The present invention also proposes a traceable anonymous signature. The domain administrator and the supervisor jointly generate an anonymous private key, which can realize the supervisor's tracing of the identity of the signer of the anonymous signature. The domain administrator takes the filter as the content of a blockchain transaction and signs the constrained Bloom filter onto the chain using the anonymous signature. The supervisor can query the recorded information on the chain at any time, and these query results can be effectively publicly verified. The method of the present invention helps to effectively trace the data propagation path and analyze the harm in case of risks, and provides a credible proof of data subject violation.

[0027] 2. The present invention also proposes a restricted Bloom filter controlled by an access regulator, and the regulator can authorize data users to query their own data transfer records on the chain, ensuring the normal flow of the data they own. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 is a block diagram of a secure on-chain storage process for cross-domain transfer information of data based on a Bloom filter provided by an embodiment of the present invention;

[0029] Figure 2 is a schematic diagram of a secure on-chain storage process for cross-domain transfer information of data based on a Bloom filter provided by an embodiment of the present invention.

[0030] In all the drawings, the same reference numerals are used to represent the same elements or structures, where:

[0031] 1 is the regulator, 2 is the blockchain network, 3 and 4 are domain administrators respectively, and 5 and 6 are data users respectively. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0033] Embodiment 1

[0034] A method for secure on-chain storage of cross-domain transfer information of data based on a Bloom filter, configuring a regulator required for the cross-domain transfer process of data and domain administrators of each cross-domain node, so that the regulator and domain administrators can achieve secure on-chain storage of cross-domain transfer information of data in the following manner:

[0035] As Figure 1As shown, each domain administrator interacts with the regulator based on a preset anonymous signature private key generation protocol to obtain a private key that is only controlled by the domain administrator; each domain administrator generates the current cross-domain flow information of each data when transferring it, and stores the generated current cross-domain flow information in a Bloom filter whose access is controlled by the regulator using an element insertion algorithm preset by the regulator's parameters. If the insertion fails, the number of elements contained in the Bloom filter reaches the upper limit, or the Bloom filter currently reaches the periodic chain time requirement (which can be set by the regulator), the current Bloom filter (i.e., the hash value of the current Bloom filter is signed) is anonymously signed using the private key controlled by the domain administrator and recorded in the blockchain; the regulator uses an element query algorithm preset by the regulator's parameters to query whether a certain cross-domain flow information of the specified data exists in a certain Bloom filter based on the data user's request or its own needs, so as to obtain a flow path for the specified data, thereby realizing secure on-chain storage of cross-domain flow information of data based on the Bloom filter.

[0036] The method of this embodiment involves regulators (RR) and domain administrators (DA) of each cross-domain node required for the cross-domain data flow process. Among them, there is at least one regulator, a trusted institution that manages the flow of sensitive data in accordance with the requirements of the law or its own management scope, which can be the compliance management of a large-scale group or a government regulatory department. When the risk of data propagation occurs, the stored data is queried and verified across domains to find out the data propagation route to support the judgment of illegal and irregular propagation of sensitive data. The regulator also assigns numbers to domain administrators and generates anonymous signature keys interactively; there can be multiple domain administrators, semi-honest managers who control the process of data entering and leaving the domain, which can be gateways, backbone routers, etc., responsible for controlling the inflow and outflow of domain data and uploading relevant flow records to the blockchain for audit and inspection by regulators; there can be one blockchain network, which is used to store the cross-domain data flow information uploaded by the domain administrator for audit and verification by regulators, or for verification or query by some data users.

[0037] In the method, a verifiable anonymous signature private key generation protocol is used. Each domain administrator uses this protocol to interact with the regulator (verifiable but unknown) to obtain a private key (and a public key), and the private key is only in the hands of the domain administrator. The method also uses an anonymous signature algorithm. Each domain administrator uses the private key held by the domain administrator to sign the Bloom filter containing multiple cross-domain data flow information through an anonymous signature algorithm, and each signature corresponds to a public key. In the method, the regulator can directly query on the blockchain or narrow the query scope based on known information, establish a data propagation path from the sending domain to the receiving domain, and verify the identity of the signer.

[0038] As a preferred implementation, a data user is also configured such that the data user, supervisor, and / or domain administrator respectively verify the signature based on the verification requirement, using the public key corresponding to each signature and through an anonymous signature verification algorithm preset with supervisor parameters, to verify whether the private key of the domain administrator that generated the signature is legal.

[0039] Therefore, an anonymous signature verification algorithm is also used in the method. Any party in the system (supervisor, domain administrator, data user) can use the public key corresponding to each signature to verify the signature of the domain administrator through the anonymous signature verification algorithm, which can verify whether the main private key of the domain administrator is legal, that is, it can verify whether the signer has registered with the supervisor, but the specific identity of the signer cannot be known.

[0040] As a further preferred implementation, as a data user of a blockchain full node, it can also, according to its own needs, apply to the supervisor for access rights to whether its own data cross-domain transfer information exists in the Bloom filter, and query whether a certain cross-domain transfer information of its own data exists in a certain Bloom filter through an element query algorithm preset with supervisor parameters, so as to obtain a transfer path of the own data and achieve secure on-chain storage of data cross-domain transfer information based on the Bloom filter.

[0041] There are multiple data users (DU, data users). Data users will send data across domains or receive cross-domain data according to requirements, and can be content servers, data clouds, etc. When a data user is a lightweight node of the blockchain, it can verify the on-chain query results of the supervisor. When a data user actively declares the transmission of data and acts as a full node, it can obtain the ability to actively query the transmission status of the declared data on the chain. That is, if a data user wants to actively retrieve the record of its own data transfer information on the blockchain, it needs to first declare the relevant information of its data transmission to the supervisor before data transmission and maintain a complete blockchain.

[0042] As a preferred implementation, when a transfer path is obtained by the supervisor, each data user acting as a lightweight node of the blockchain can also verify the correctness of the transfer path.

[0043] The supervisor queries the on-chain information to obtain a propagation path of data m, and any party (supervisor, domain administrator, data user) maintaining the lightweight node can verify whether the propagation path exists on the blockchain.

[0044] As a preferred implementation, the element insertion algorithm of the Bloom filter is as follows:

[0045] Obtain the current filter or create a new filter (κ,η,λ)-CBF, where κ represents the total number of hash functions required for the Bloom filter CBF, η represents the optimal number of elements inserted into the Bloom filter CBF, and λ represents the length of the non-zero binary bits in the Bloom filter CBF;

[0046] Set the element insertion flag tag to -1; use the bilinear mapping function preset by the supervisor parameter for the known unique identifier Λ of the data m and the first private key d of the known i-th domain administrator i,1 and the first master public key MPK1 of the supervisor are multiplied to obtain the intermediate variable u; take the first l1 bits of u and the binary number N of the i-th domain administrator i are concatenated to obtain the element to be inserted result, and the bit length of the number N i is l2, satisfying l2 + l1 = λ;

[0047] Loop through the κ hash functions preset by the supervisor parameter represents the integer space between 0 and the maximum value of the position index in (κ,η,λ)-CBF to calculate the κ mapping positions of u in (κ,η,λ)-CBF Save the subscript of the first empty mapping position to the insertion flag tag, and write the selected random number r within the specified range [0, 2 λ -1] to the other empty mapping positions v , calculate the exclusive OR result of the values r of all other mapping positions except the mapping position corresponding to the subscript stored in tag v and result, and write it to the first empty mapping position;

[0048] If the element insertion flag tag is not equal to -1, the element insertion is successful, and the updated (κ,η,λ)-CBF is returned; otherwise, the element insertion fails.

[0049] This algorithm involves (κ,η,λ)-CBF with the number of inserted elements not exceeding η; the following parameters are used: the unique identifier Λ of the data m ; the private key of the domain administrator; the master public key MPK1 of the supervisor; the number N of the domain administrator i ; the hash function preset by the supervisor parameter is the maximum value of the position index in CBF. After the insertion is completed, the updated (κ,η,λ)-CBF will be obtained.

[0050] The method of this embodiment relates to a Bloom filter element insertion algorithm designed based on cryptography, specifically a method for inserting elements into a controlled Bloom filter (()-CBF) by a supervisor. The core of this algorithm is to ensure access control of the Bloom filter through cryptographic means, and at the same time use the characteristics of the garbled Bloom filter (GBF) to achieve privacy protection for inserted elements.

[0051] The core steps of the algorithm are as follows:

[0052] Intermediate variable calculation: Calculate the intermediate variable u through the bilinear mapping function e, which carries the information of the data unique identifier, the domain administrator's private key, and the supervisor's master public key. The properties of the bilinear mapping function ensure that the information contained in u can be verified, but the specific data unique identifier or private key cannot be deduced inversely. This design ensures that only the supervisor and authorized data users can calculate the correct u, thus achieving strict control over access to the Bloom filter.

[0053] Element generation and compression: Concatenate the first specified bits of u with the domain administrator number to generate the element result to be inserted. This step not only inherits the information of u but also reduces the space consumption of the Bloom filter by compressing the length of u, optimizing the storage efficiency.

[0054] Mapping position calculation and insertion: Use the preset hash function to calculate k mapping positions of result in the Bloom filter, and ensure that the exclusive OR result of the values at these positions is equal to result itself through random number generation and exclusive OR operation. The exclusive OR operation ensures that all query results are "not present" without knowing the correct u, thus avoiding information leakage.

[0055] Generally speaking, this algorithm realizes access control and privacy protection. The core innovation of the algorithm is to combine the cryptographic algorithm with the Bloom filter to achieve strict supervision of access to the Bloom filter. The supervisor can calculate all u in the system by holding the master private key and authorize other participants to make queries. In addition, the design of GBF further enhances privacy protection and avoids directly exposing the hash information of elements through the garbling technology.

[0056] Further as a preferred embodiment, the above element verification algorithm is:

[0057] Adopt the bilinear mapping function preset by the supervisor's parameters Multiply the known data unique identifier Λ m and the known first private key s1 of the supervisor and a certain domain administrator public key DPK * to calculate the element u' to be queried;

[0058] Loop through κ hash functions preset by the supervisor's parameters Represents the integer space between 0 and the maximum value of the position index in the CBF, and calculates the κ mapping positions of the element u' to be queried in the (κ, η, λ)-CBF Obtain κ values at the mapping positions and perform an XOR calculation to get the calculation result result';

[0059] Take the first λ - l DA bits of the element u' to be queried and the i-th domain administrator number N i Concatenate to get the concatenation result. If the administrator number N i is legal and the concatenation result is equal to the calculation result result', the query is successful and the domain administrator number N is returned i Otherwise, the query fails.

[0060] The inputs of this algorithm include: (κ, η, λ)-CBF, the public key DPK of the domain administrator * the unique identifier Λ of the data m and the private key s1 of the supervisor; the outputs of the algorithm include: which CBF it exists in; and the domain administrator number.

[0061] This embodiment also relates to a Bloom filter query algorithm based on cryptographic design, which is used to verify the existence of data in the Bloom filter (κ, η, λ)-CBF controlled by the supervisor and return the relevant domain administrator number. This algorithm complements the aforementioned insertion algorithm and jointly realizes the tracking and verification of the data propagation path.

[0062] The core steps of the algorithm are as follows:

[0063] Generation of the element to be queried: Through the bilinear mapping function e, calculate the data unique identifier, the supervisor's private key, and the domain administrator's public key to generate the element u' to be queried. This element has the same mathematical properties as u in the insertion algorithm, that is, it contains the information of the data unique identifier, the supervisor's private key, and the domain administrator's public key, but the specific content cannot be deduced reversely. This design ensures the security of the query process.

[0064] Calculation of mapping positions and XOR operation: Use the preset hash function to calculate the k mapping positions of u' in the Bloom filter, and obtain the values at these positions for XOR operation to get the calculation result result'. This process is the inverse process of the operation in the insertion algorithm, and the XOR operation is used to verify whether the values at the mapping positions are consistent with the expectation.

[0065] ​Verification of the splicing result: Take the first specified number of bits of u' and splice them with the domain administrator number Ni to generate a splicing result. If the splicing result is equal to result' and the domain administrator number is legal, the query is successful and the domain administrator number N is returned. i ; Otherwise, the query fails. This design enables the query result to not only verify the existence of data but also trace the propagation path of the data.

[0066] Cross-domain propagation tracing: By querying twice to return the domain administrator numbers N1 and N2 of the sending domain and the receiving domain respectively, it can be determined that data has undergone cross-domain propagation between these two domains. This feature makes this algorithm have important application value in data tracing and path verification.

[0067] In the specific implementation, to achieve the on-chain secure deposit of cross-domain transfer information of data based on the Bloom filter proposed in this embodiment, generally speaking, the method involves: S1, system initialization; S2, domain administrator signature verification; S3, cross-domain transfer deposit of data (propagation information with signature); S4, on-chain transfer deposit query; S5, on-chain transfer deposit verification.

[0068] First, the following explanations are given for technical terms.

[0069] Blockchain and SPV: Blockchain is an important data storage method, with characteristics such as decentralization, immutability, and transparency. Each block consists of two parts: a block header and a block body. The block header contains the hash value of the previous block and the root hash value of the Merkle tree formed by all transactions in the block body. The block body records all transaction information and occupies a large storage space. Nodes that only save the block header are called light nodes. Light nodes can use SPV (simplified payment verification) to verify whether a certain transaction exists and is correct. When it is necessary to verify whether a certain transaction exists in the blockchain, the prover does not need to provide the complete block body, but only needs to provide the relevant hash value and auxiliary information.

[0070] Asymmetric bilinear group: There exists a mapping relationship among three different cyclic groups If the following properties are satisfied, it is called an asymmetric bilinear group, and the mapping is called a bilinear mapping. Let the order of the group be a large prime number q, and

[0071] Bilinearity: For any a, b ∈ Z q and it holds that

[0072] Non-degeneracy: There exists such that

[0073] Computability: Any can be effectively computed.

[0074] Bloom Filter: A Bloom filter (BF) is a data structure used to efficiently verify whether an element is in a set and has a wide range of applications. A classic Bloom filter can be regarded as a one-dimensional array A, where the value corresponding to each index position is 0 or 1. Initially, all values in the array are set to 0. For the elements in the set through a set of preset hash functions are mapped into the filter, that is, the value of the corresponding index position is set to 1. For an element, if querying the BF finds that all its mapped positions are 1, then the element is considered to belong to the set, otherwise it is determined not to be in the set.

[0075] Paillier Homomorphic Encryption Algorithm (as a tool for various algorithms involved): The Paillier encryption algorithm is a classic additive homomorphic public-key encryption scheme. Encryption is performed using the public key, and the resulting ciphertext can only be decrypted with the corresponding private key. Let <m> denote the ciphertext obtained by encrypting the plaintext m using the Paillier encryption algorithm. Suppose <m1> and <m2> are both ciphertexts encrypted with the same public key, and c is a constant. Then the homomorphic properties of the ciphertext are expressed as follows.

[0076] Additive Homomorphism: <m1 + m2> = <m1> · <m2>

[0077] Scalar Multiplication: <m1> c = <c · m1>.

[0078] S1, System Initialization

[0079] RR generates the basic common parameters used in the entire evidence-preserving method. System initialization involves the following S101 - S105:

[0080] S101: RR selects a group with a bilinear mapping The order of the group is a large prime number q. A set of secure cryptographic hash functions sets the relevant parameters λ, η of the filter CBF and a secure hash function λ represents the length of the binary bits of the non-zero values in the filter; η represents the optimal number of elements inserted into the filter, that is, the maximum number of insertions within the tolerable false positive rate; κ represents the number of hash functions.

[0081] S102: RR randomly selects As the master private key MSK, calculate the corresponding master public key respectively and The public information is:

[0082]

[0083] S103: Suppose there are n DAs, and RR assigns a binary number string to each DA For the set of assigned binary numbers. The operations of each DA are the same in the initialization phase. Without loss of generality, taking DA i as an example, the initialization process is as follows:

[0084] S104: DA i randomly generates as the private key, and the corresponding public key is Initializes the parameters and public key of the Paillier encryption algorithm. The result of signing with the key (d i,1 , d i,1 Q) is denoted as σ i . DA i and the public key DPK i , the number N i , and the management domain D i 's corresponding relationship is public information.

[0085] Protocol 1 Verifiable Anonymous Signature Private Key Generation Protocol

[0086] Input: The public key of the Paillier encryption algorithm of DA i , the master private key MSK of RR, the public parameters P, Q, q.

[0087] Output: RR records (a i τ i b i P, a i P, DA i ), DA i obtains the anonymous master private key d i,2 = s1s2 + s2b i τ i (mod q).

[0088] 1) DA i randomly selects and encrypts it using the Paillier encryption algorithm to obtain the ciphertext <b i >, and only DA i can decrypt it. DA i randomly selects calculates a i b i P and a i P. The ciphertext <bi > and the calculation result a i b i P, a i P is sent to RR.

[0089] 2) RR randomly selects a number and assigns it to DA i . Using the public key and ciphertext homomorphism of the Paillier encryption algorithm of DA i to perform calculations:

[0090]

[0091] The ciphertext result <s2b i τ i + s1s2> is sent to DA i .

[0092] 3) DA i decrypts <s2b i τ i + s1s2> to obtain the plaintext: d i,2 = s1s2 + s2b i τ i (mod q), calculates a i d i,2 Q and sends it to RR.

[0093] 4) RR verifies the equation

[0094]

[0095] If it holds, then calculates A = H2(s2 · a i b i P) · τ i Q and sends it to DA i , otherwise aborts the protocol. RR records (a i τ i b i P, a i P, DA i ).

[0096] 5) DAi calculates B = H2(a i b i · MPK2) -1 · b i · A, and verifies whether the following equation holds

[0097]

[0098] If it holds, then τ i b i Q = B, ends the protocol, otherwise re-executes the protocol.

[0099] S105: DA i After authenticating its identity to the RR, it interacts with the RR through Protocol 1 to obtain an anonymous private key The generation method of Protocol 1 will not have the problem of key escrow. After the protocol ends, the RR cannot obtain the generated d i,2 Use the anonymous private key d i,2 and Algorithm 1, DA i can continuously generate anonymous signatures The public key corresponding to each signature is used only once.

[0100] S2. Domain Administrator Signature Verification

[0101] Domain administrator signature verification is optional. Any party can verify the domain administrator's signature at any step after initialization.

[0102] Algorithm 1 Anonymous Signature Algorithm

[0103] Input: DA i Anonymous master private key d i,2 , message m to be signed;

[0104] Output: Anonymous signature

[0105] 1) Generate a fresh random number

[0106] 2) Calculate dSK i,j = r j d i,2 , dPK i,j = r j d i,2 Q

[0107] 3) Select a secure signature algorithm (uniform throughout the system), and use dSK i,j to sign to obtain the signature σ i,j

[0108] 4) Calculate r j s2P, r j Q, r j τ i b i Q

[0109] 5) Output the anonymous signature

[0110]

[0111] Using the anonymous master private key d i,2 and Algorithm 1, DA i can continuously generate anonymous signatures The public key corresponding to each signature is used only once. Anyone can verify the anonymous signature generated by the domain administrator through Algorithm 2 to confirm that the signer is registered at RR, but the specific identity of the signer is unknown.

[0112] Algorithm 2 Anonymous Signature Verification Algorithm

[0113] Input: Public parameters (Q, MPK1, MPK2) and anonymous signature ζ

[0114] Output: {True, False}

[0115] 1) Parse

[0116] 2) Use dPK * Verify the signature σ, and return False if it fails

[0117] 3) Verify the following two equations:

[0118]

[0119] If both are equal, return True; otherwise, return False.

[0120] / * If the equation holds, it is certain that the verification public key dPK * contains the information of the master public keys MPK1 and MPK2, that is, it is generated by a certain domain administrator. * /

[0121] S3. Data Cross-Domain Transfer and Archiving

[0122] When a data user transports data information across domains, the data transmission information will be captured by the relevant domain administrator and form an archived chain, which at least involves the following S301 - S303:

[0123] S301: Data User DU se Send data m to a data user DU in another domain re . The data m and the attached transmission information info will be captured by the domain administrators of the two users.

[0124] S302: DA se Obtain the identifier And sign σ se (Λ m ||info||N re ) and send it to DA re . At the same time, DA se Insert the identifier into the restricted Bloom filter using Algorithm 3 and sign the relevant information and upload it to the chain.

[0125] (κ, η, λ)-CBF Filter Element Insertion Algorithm 3

[0126] Input: A (κ, η, λ)-CBF with the number of inserted elements not exceeding η, and the unique identifier Λ of the data m , the private key d of the domain administrator i,1 , the master public key MPK1 of the RR, and the domain administrator number N of the sending or receiving domain i .

[0127] is the maximum value of the position index in the CBF.

[0128] Output: (κ, η, λ)-CBF

[0129] 1) tag = -1

[0130] 2)

[0131] 3) / * Define as the lowest λ - l bits of the binary form of u DA bits * /

[0132] 4) For i = 1,..., κ do

[0133] 5) If CBF then

[0134] 6) If tag == -1 then

[0135] 7)

[0136] 8) Else

[0137] 9)

[0138] 10)

[0139] 11) Else

[0140] 12)

[0141] 13) End for

[0142] 14) CBF[tag] = 1 || result

[0143] 15) Output (κ, η, λ)-CBF

[0144] When all positions collide during the insertion of an element, that is, tag = -1 after the loop ends, it means the insertion fails. The element is inserted into the new filter. Within the specified time or when the number of insertions reaches η, DAi Use the anonymous private key and anonymous signature algorithm to sign (κ,η,λ)-CBF and upload it to the chain. Generate a new filter (κ,η,λ)-CBF′ to continue recording data information.

[0145] S303: For the domain administrator DA of the receiving domain re , the transmitted data will also be captured and the signature σ se . Signature σ se After verification, calculate the signature σ re (Λ m ||info||N se )Send to DA se Acknowledge its receipt. Admin DA re Use CBF filter to record information and upload it to the blockchain. Domain administrator signature σ * (Λ m ||info||N * ) and transmission related information info will be retained to support tracking of data flow.

[0146] S4. On-chain circulation and storage query

[0147] When data transmission risks occur, the stored cross-domain data transportation information is queried and verified to find out the data transmission route to support the judgment of illegal and irregular transmission of sensitive data. RR can query directly on the blockchain or narrow the query scope based on known information. The query results recorded by the on-chain CBF filter are used to judge the credibility of the circulation information stored by DA. Step S4 at least includes steps S401 to S403.

[0148] S401: For data m, according to the public key DPK of the domain administrator se ,calculate Take u′ as the input of the on-chain CBF for query. See Algorithm 4 for CBF query.

[0149] Algorithm 4 (κ,η,λ)-CBF filter element query

[0150] Input: (κ,η,λ)-CBF, domain administrator's public key DPK * , the unique identifier of the data m , RR’s private key s1.

[0151] Output: Sending domain or receiving domain administrator number N i

[0152] 1)

[0153] 2) result = 0

[0154] 3) For i = 1, ..., κ do

[0155] 4) If CBF then

[0156] 5) Break

[0157] 6) Else

[0158] 7)

[0159] 8) End for

[0160] 9) If and then

[0161] 10) Output N i

[0162] 11) Else

[0163] 12) Break

[0164] S402: After querying the result N re Verify that the signer of the transaction where the CBF is located is DA se , if it fails, continue the query. When the verification is successful, calculate Continue the query.

[0165] S403: After querying the result N se Verify that the signer of the transaction where the CBF is located is DA re , when the verification is successful, trust the correctness of the information stored by DA, if it fails, continue.

[0166] RR establishes a propagation path of data m from the sending domain to the receiving domain. Under normal circumstances, the supervisor only verifies the identity of the signer and does not traverse the entire (a i τ i b i P, a i P, DA i ), i ∈ [1, n] for identity tracking.

[0167] S5. Verification of on-chain transfer and deposit certificates

[0168] RR queries the on-chain information and obtains that a propagation path of data m can be verified by any party maintaining a light node, such as the sender DU of m se . According to whether DU se joins the system as a light node or a full node, DU se has different permissions and steps when performing on-chain transfer and deposit certificate verification. DU seWhen joining the system as a light node, at least the following S501 to S504 are involved:

[0169] S501: RR randomly generates Calculate γΛ m . Send γΛ m to two administrators DA re and DA se on the propagation path, and request them to calculate d se,1 γΛ m , d re,1 γΛ m and return.

[0170] S502: RR calculates γ -1 ·d se,1 γΛ m and γ -1 ·d re,1 γΛ m , and sends d se,1 Λ m , d re,1 Λ m and the hash values of the blockchain transactions where the CBF filter hit during the corresponding query process and other transactions required by SPV to DU se .

[0171] S503: DU se First, reconstruct the Merkle tree based on the sent transactions and auxiliary hash values, and verify whether the root hash is consistent with that in the local saved light node. If they are consistent, it is believed that the sent transactions are indeed recorded on the chain.

[0172] S504: DU se Next, calculate

[0173]

[0174] Query in the corresponding CBF filter. According to a pair of query results (N se , N re ), find the public keys of the corresponding two domain administrators (DPK se , DPK re ). If the following two formulas

[0175]

[0176] are all equal, then DU se can determine the correctness of this propagation path.

[0177] DU seWhen joining the system as a full node, it can actively retrieve the records of its own data transfer information on the blockchain. Step S5 includes at least steps S505 to S508.

[0178] S505: DU se Before data transmission, first declare the relevant information of the data it transmits to the supervisor RR and maintain a complete blockchain.

[0179] S506: After RR's approval, send s1Λ m to the data user DU se .

[0180] S507: DU se can verify the formula and are equal to ensure that the received result is correct. If it learns that the transfer of its own data m is abnormal, the user DU se can independently calculate the element according to the public information and query it on the chain.

[0181] It should be noted that anonymous signature verification, transfer path verification, etc. are all optional operations in the deposit evidence. For example Figure 2 shows a deposit evidence scheme. 1 is the supervisor, 2 is the blockchain network, 3 and 4 are domain administrators respectively, 5 and 6 are data users respectively. In the figure, the dotted box represents the domain scope managed by the domain administrator. The data users 5 and 6 are respectively in the areas managed by two different domain administrators. S1 in the figure is the aforementioned system initialization, S2 is the aforementioned domain administrator signature verification, S3 is the aforementioned cross-domain data transfer deposit evidence (signature propagation information), S4 is the aforementioned on-chain transfer deposit evidence query, and S5 is the aforementioned on-chain transfer deposit evidence verification.

[0182] Example Two

[0183] A blockchain-based secure deposit evidence system for cross-domain data transfer information based on a Bloom filter, including: a supervisor, a domain administrator, and a data user; each party realizes the blockchain-based secure deposit evidence process for cross-domain data transfer information based on the method described in Example One above.

[0184] The relevant technical solutions are the same as those in Example One and will not be elaborated here.

[0185] Example Three

[0186] This application also relates to an electronic device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of the above method.

[0187] The electronic device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The so-called processor can be a Central Processing Unit (CPU), or can also be other general-purpose processors, Digital Signal Processors (DSPs), Application-Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The memory can be used to store computer programs and / or modules. The processor realizes various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory, and by calling the data stored in the memory.

[0188] The related technical solutions are the same as above and will not be elaborated here.

[0189] Embodiment 4

[0190] This application also relates to a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are realized.

[0191] Specifically, the memory can include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0192] The related technical solutions are the same as above and will not be elaborated here.

[0193] Those skilled in the art can easily understand that the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for securely storing cross-domain data flow information on a chain based on a Bloom filter, characterized in that: Configure the regulators and domain administrators of each cross-domain node required for the cross-domain data transfer process, so that regulators and domain administrators can achieve secure on-chain storage of cross-domain data transfer information in the following ways: Each domain administrator interacts with the regulator based on a preset anonymous signature private key generation protocol to obtain a private key held only by the domain administrator; Each domain administrator generates the current cross-domain flow information of each piece of data when transferring it, and stores the generated current cross-domain flow information in the Bloom filter of the domain administrator whose access is controlled by the regulator using the element insertion algorithm preset by the regulator parameters. If the insertion fails, the number of elements contained in the Bloom filter reaches the upper limit, or the Bloom filter reaches the periodic on-chain time requirement, the current Bloom filter is anonymously signed using the private key held by the domain administrator and recorded in the blockchain; Based on data user requests or their own needs, regulators use element query algorithms preset by regulator parameters to query whether a certain cross-domain flow information of specified data exists in a Bloom filter, so as to obtain a flow path for the specified data and realize secure on-chain storage of cross-domain data flow information based on Bloom filters.

2. The method for securely storing cross-domain data transfer information on a chain as claimed in claim 1, characterized in that: Data users are also configured so that data users, regulators and / or domain administrators, based on verification needs, use the public key corresponding to each signature to verify the signature through an anonymous signature verification algorithm preset by the regulator's parameters to verify whether the private key of the domain administrator who generated the signature is legal.

3. The method for securely storing cross-domain data transfer information on a chain as claimed in claim 2 is characterized in that: As a data user of the blockchain full node, you can also apply to the regulator for access rights to check whether your own data cross-domain flow information exists in the Bloom filter according to your own needs. Through the element query algorithm preset by the regulator's parameters, you can query whether a certain cross-domain flow information of your own data exists in a certain Bloom filter, so as to obtain a flow path for your own data and realize the secure on-chain storage of cross-domain data flow information based on Bloom filters.

4. The method for securely storing cross-domain data transfer information on a chain as claimed in claim 2 is characterized in that: When a circulation path is obtained by the regulator, each data user who is a blockchain light node can also verify the correctness of the circulation path.

5. The method for securely storing cross-domain data transfer information on a chain according to any one of claims 1 to 4, characterized in that: The element insertion algorithm is: Get the current filter or create a new filter (κ,η,λ)-CBF, where κ represents the total number of hash functions required by the Bloom filter CBF, η represents the optimal number of elements inserted into the Bloom filter CBF, and λ represents the binary bit length of non-zero values ​​in the Bloom filter CBF; Set the element insertion tag to -1; use the bilinear mapping function preset by the supervisor parameter Uniquely identify known data m And the first private key d of the known domain administrator i i,1 The product of the first master public key MPK1 of the regulator is calculated to obtain the intermediate variable u; the first l1 bits of u are taken and the binary number N of the i-th domain administrator i Perform splicing to obtain the element to be inserted result, numbered N i The bit length is l2, satisfying l2+l1=λ; Cycle through the κ hash functions preset by the supervisor parameters Indicates the maximum value of the position index from 0 to (κ,η,λ)-CBF The integer space between them is used to calculate the κ mapping positions of u in the (κ,η,λ)-CBF. Save the index of the first empty mapping position to the insertion mark tag, and write the specified range [0,2 λ -1] The random number r selected v , calculate the value r of all mapping positions except the mapping position corresponding to the index stored in tag v The XOR result of result is written into the first empty mapping position; If the element insertion mark tag is not equal to -1, the element is inserted successfully and the updated (κ,η,λ)-CBF is returned, otherwise the element insertion fails.

6. The method for securely storing cross-domain data transfer information on a chain as claimed in claim 5, characterized in that: The element verification algorithm is: Uses a bilinear mapping function with supervisor parameters preset Uniquely identify the known data m As well as the first private key s1 of the known regulator and a domain administrator public key DPK * The product of is calculated to obtain the element u′ to be queried; Cycle through the κ hash functions preset by the supervisor parameters Indicates the maximum value of the position index from 0 to CBF The integer space between them is used to calculate the κ mapping positions of the query element u′ in the (κ,η,λ)-CBF. Get the κ values ​​in the mapping position, perform XOR calculation to get the calculation result result′; Take the first l1 bits of the element u′ to be queried and the binary number N of the i-th domain administrator i Splice to get the splicing result. If the administrator number is N i If it is legal and the concatenation result is equal to the calculation result, the query is successful and the domain administrator number N is returned. i , otherwise, the query fails.

7. A data cross-domain flow information chain security evidence storage system based on Bloom filter, characterized in that: include: Regulators, domain administrators, and data users; all parties implement the process of secure storage of data cross-domain information on chain based on a Bloom filter-based method for secure storage of data cross-domain information on chain as described in any one of claims 1 to 6.

8. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed by a processor, the device where the storage medium is located is controlled to execute the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Business data circulation method, system and related equipment based on blockchain

    CN114844695B

  • Data circulation method and system

    CN118114310A

Cited By

  • Path verification method and system based on bloom filter storage link proof

    CN120811665A