Information security protection method based on block chain
By generating decryption keys and proxy keys, combined with access control policies and consensus mechanisms, the problem of poor data security in blockchain storage technology is solved, and the security and privacy protection of data transmission is achieved, ensuring data integrity and security.
Patent Information
- Application Number
- CN202510604969.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-07-11
AI Technical Summary
In blockchain storage technology, data storage is poor in security, and hackers and illegal users can obtain data through access records. Existing protection measures are difficult to fully protect, resulting in data security and privacy leakage problems.
The global public parameters and master key are used to generate the decryption key and the proxy key, and the access control policy is used to generate the encrypted ciphertext. The data transmission security is ensured through the consensus mechanism of multiple consensus nodes, and the user and cloud server jointly decrypt the data content.
The security and privacy protection of blockchain data transmission is realized, preventing data from being tampered with and leaked, and ensuring the integrity and security of data through the joint decryption of users and cloud servers.
Smart Images

Figure CN120301591A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security, and particularly relates to an information security protection method based on blockchain. Background Technique
[0002] Blockchain technology, also known as "distributed ledger technology", is a technical solution for decentralized and collectively maintained distributed ledgers. Its essence is a distributed database system collectively participated by multiple nodes. Blockchain is not a single technology but the result of integrating multiple technologies. Using blockchain technology to maintain a reliable and tamper-resistant ledger record can reduce the risk of trust and effectively reduce the maintenance cost of collaboration among multiple participating parties. In the actual application of blockchain, each user generates a pair of asymmetric key pairs for transaction signatures on the blockchain, and the Hash value of its corresponding public key is used as the identity identifier of its transaction account. Considering various factors such as security and efficiency, the blockchain asymmetric encryption algorithm generally selects the elliptic curve algorithm, and the security of its algorithm depends on the intractability of the elliptic curve discrete logarithm problem.
[0003] In blockchain storage technology, the security issue of data storage cannot be ignored. The current blockchain storage technologies directly store data into multiple nodes of the blockchain network. When users access data, it is easy to generate access records that can be exploited by hackers and illegal users. Hackers and illegal users can conveniently use this record to trace back to the data source of the node, and then obtain the data in the blockchain node. Moreover, hackers and illegal users only need to invade one node using the node consensus mechanism to obtain the data of the entire blockchain network, resulting in serious data security and privacy leakage problems. The existing methods only install software or physical firewalls to isolate malicious access, but often cannot protect every node properly. Summary of the Invention
[0004] To solve the above technical problems, the present invention provides an information security protection method based on blockchain, including:
[0005] Select security parameters, generate relevant mathematical structures and functions, and output global public parameters and a master key, where the data comes from physical entities.
[0006] Use the global public parameters, the master key, and information attributes to generate a decryption key and a proxy key, and hand them over to the user and the cloud server for storage respectively;
[0007] The information publisher determines an access control policy and transforms it into a matrix form, generates a random vector, and calculates and outputs an encrypted ciphertext based on the random vector;
[0008] Multiple consensus nodes enter initial information, select a master node, and the master node packages the information and sends request object information;
[0009] According to the information of the request object received by the consensus nodes, if a consensus is reached, the master node sends the encrypted ciphertext to the ordinary nodes;
[0010] Decrypt the encrypted ciphertext based on the decryption key and the proxy key to restore the information content.
[0011] Preferably, the process of outputting the global public parameters and the master key includes:
[0012] The regulatory agency selects secure parameters as input to generate two multiplicative cyclic groups and of order p, and the corresponding generators are g;
[0013] Define a bilinear mapping based on the two multiplicative cyclic groups and and the generator, and define a hash function;
[0014] The regulatory agency then selects parameters and inputs them into the bilinear mapping and the hash function respectively to output the global public parameters and the master key.
[0015] Preferably, the process of generating the decryption key and the proxy key using the global public parameters, the master key, and the information attributes includes:
[0016] Generate the corresponding decryption key using the global public parameters, the master key, and the information attributes;
[0017] The regulatory agency selects a random number and then randomly selects parameters for each piece of information to obtain the secret value of the information decryption key;
[0018] Obtain the proxy key according to the information decryption key and the secret value, hand over the information decryption key to the user for storage, and hand over the proxy key to the cloud server for storage.
[0019] Preferably, the process of calculating and outputting the encrypted ciphertext based on the random vector includes:
[0020] The information publisher determines the access control policy, transforms the access control policy into a matrix form, and generates a random vector at the same time;
[0021] Select a random number, calculate the hash value of the encrypted ciphertext based on the random vector, the random number, and the access control policy, and output each component of the ciphertext;
[0022] Output the encrypted ciphertext based on each component of the ciphertext.
[0023] Preferably, the process in which multiple consensus nodes enter the initial information, select a master node, and the master node packages the information and sends the request object information includes:
[0024] Multiple consensus nodes in the blockchain network receive and process initial information, and select a primary node based on the multiple consensus nodes;
[0025] The primary node packages the information propagated by the blockchain into a block, and at the same time, the primary node sends request object information to other consensus nodes, and the request object information is used to notify other nodes to perform consensus verification.
[0026] Preferably, according to the situation of the request object information received by the consensus node, if consensus is reached, the process of the primary node sending the encrypted ciphertext to the ordinary node includes:
[0027] Other consensus nodes receive the request object information sent by the primary node, and verify the block content according to their own verification mechanisms
[0028] Within a certain period of time, if any consensus node receives one or more Request object information, it is considered that consensus is reached, and the primary node sends block information to the ordinary node to complete the confirmation and synchronization of the block;
[0029] If any consensus node receives one or more Request object information replacement requests, it is considered that the consensus fails, the information request is incorrect, and a new round of consensus process is started.
[0030] Preferably, before the consensus node receives the Request object information, it verifies whether it conforms to the access policy according to its own attributes and the ACP stored by the blockchain primary node.
[0031] Preferably, the process of decrypting the encrypted ciphertext based on the decryption key and the proxy key to restore the information content further includes:
[0032] After decrypting the encrypted ciphertext, re-perform a hash operation on the information content and compare it with the corresponding one on the blockchain. If they are the same, the information is complete. If they are different, the information is damaged, and an error report is sent to the cloud server and the regulatory agency to prevent the information from being tampered with. After the regulatory agency receives the information damage report, it immediately destroys the smart contract corresponding to the information's own attributes, thereby revoking the information content.
[0033] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computing program stored in the memory and executable on the processor. When the processor executes the computing program, the method is implemented.
[0034] On the other hand, the present invention also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the method is implemented.
[0035] Compared with the prior art, the present invention has the following advantages and technical effects:
[0036] According to the decryption key and the secret value, the present invention obtains the proxy key PxK, and separately hands over the UGSK and PxK to the user and the cloud server for storage. During data decryption, it is divided into cloud server decryption and user decryption. The CT content is decrypted by using PxK and UGSK to restore the information content M. The keys are jointly generated by the user side and the cloud server side, which ensures the transmission security of the interaction process and effectively solves the privacy and confidentiality problems involved in blockchain transactions. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The accompanying drawings that form a part of this application are used to provide a further understanding of this application. The schematic embodiments and descriptions of this application are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0038] Figure 1 It is a flowchart of the information security protection method based on blockchain according to an embodiment of the present invention;
[0039] Figure 2 It is a flowchart of data decryption according to an embodiment of the present invention;
[0040] Figure 3 It is a block diagram of the connection structure between the regulatory agency and each unit according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The following will refer to the drawings and combine the embodiments to detail this application.
[0042] It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0043] Embodiment 1
[0044] This embodiment provides an information security protection method based on blockchain, including:
[0045] S1. Blockchain initialization: The regulatory agency selects a secure parameter λ as the input, generates two multiplicative cyclic groups G and G of order p T , and the corresponding generators are g, defines a bilinear mapping e: G×G→G T , and defines a hash function H: {0,1}*→Z p , the regulatory agency then selects parameters α R , β R ∈Zp , input the bilinear mapping and the hash function respectively, and output the global public parameter G p and the master secret key MSK; among them, the nodes of the blockchain are physical entity nodes with certain computing resources or software nodes with certain computing resources.
[0046] S2. Key Generation: Use the global public parameter G p , the master secret key MSK and the information attribute S to generate the corresponding decryption key. The regulatory agency selects a random number η ∈ Z p , and then randomly selects parameters α, β, r, γ ∈ Z for each piece of information p , to obtain the information decryption key UGSK and the secret value Obtain the proxy key PxK according to the decryption key and the secret value, and hand UGSK and PxK to the user and the cloud server for storage respectively;
[0047] S3. Data Encryption: The information publisher determines the access control policy ACP and transforms it into matrix form (A, p), and then generates a random vector v = (s, y2, y3, …, y i ), where Then calculate λ for each piece of information i = A i v and output the components of the ciphertext. Randomly select Calculate where H(p(i)) is the hash value of the encrypted ciphertext, and finally output the encrypted ciphertext CT;
[0048] S4. Update the Blockchain Consensus Mechanism: Multiple consensus nodes in the blockchain network enter the initial information, and then select the master node according to p = (h - v)n, where p is the number of the currently selected master node, h is the height of the current block, v is the number of the current information, and n is the amount of node information. The master node packs the information propagated by the blockchain into a block bl, and then sends the request Request object information to other nodes;
[0049] S5. Consensus Verification: If within a certain time, any consensus node receives 1 or more Request object information, then consensus is reached, and the master node sends the block information to the ordinary nodes. If within a certain time, any consensus node receives 1 or more Request object information replacement requests, then the consensus fails, the information request is incorrect, and a new round of consensus is started;
[0050] S6. Data Decryption: It is divided into cloud server decryption and user decryption. Use PxK and UGSK to decrypt CT to restore the information content M.
[0051] Further, before the consensus node receives the Request object information, it can verify whether it conforms to the access policy according to its own attribute S ID and the ACP stored in the blockchain main node.
[0052] Further, the information publisher finds its smart contract in the blockchain according to the information's own attribute S ID to view the specific call itinerary through the event log of the smart contract, and at the same time feedback to the regulatory agency to perform periodic traceability of the information.
[0053] Further, after receiving the user's request, the cloud server decrypts it. First, it verifies whether it has access rights through ACP. If it fails, it returns an access failure message to the user. Otherwise, the cloud server calculates the corresponding constant and executes to obtain the decrypted information PCT;
[0054] User decryption: After the user receives PCT, the user restores the information content M with the decryption key UGSK.
[0055] Further, after the user decryption, the information content is re-hashed and compared with the corresponding H(M) on the blockchain. If they are the same, the information is complete. If they are different, the information is damaged and an error is reported to the cloud server and the regulatory agency to prevent the information from being tampered with.
[0056] Further, after the regulatory agency receives the information damage report, it immediately destroys the smart contract corresponding to the information's own attribute S ID to revoke the information content.
[0057] Embodiment 2
[0058] In this embodiment, a blockchain-based information security protection method is provided, including:
[0059] In this embodiment, it includes a regulatory agency, an information publisher, a user, a cloud server, and a blockchain consortium network. Among them, the information publisher is the information holder, the regulatory agency is a trustworthy management agency, the user is the data caller, and the cloud server is the data storage machine. Each unit refers to the information publisher, the user, the cloud server, and the blockchain consortium network;
[0060] In the specific implementation process, as Figures 1 - 3 shown, the blockchain-based information security protection method provided in this embodiment includes the following steps:
[0061] S1. Blockchain initialization: The regulatory agency selects a secure parameter λ as input to generate two multiplicative cyclic groups G and G of order p T , and the corresponding generators are g, and a bilinear mapping e: G×G→G is defined T, and define the hash function \(H:\{0,1\}^*\to\mathbb{Z}\) p , the regulatory agency then selects the parameters \(\alpha\) R , \(\beta\) R \(\in\mathbb{Z}\) p , and inputs them into the bilinear mapping and the hash function respectively, and outputs the global public parameter \(G\) p and the master secret key \(MSK\):
[0062]
[0063] S2. Key Generation: Use the global public parameter \(G\) p , the master secret key \(MSK\) and the information attribute \(S\) to generate the corresponding decryption key. The regulatory agency selects a random number \(\eta\in\mathbb{Z}\) p , and then randomly selects the parameters \(\alpha,\beta,r,\gamma\in\mathbb{Z}\) for each piece of information p , to obtain the information decryption key \(UGSK\) and the secret value
[0064]
[0065] Obtain the proxy key \(PxK\) according to the decryption key and the secret value:
[0066]
[0067] Hand over \(UGSK\) and \(PxK\) to the user and the cloud server for storage respectively;
[0068] S3. Data Encryption: The information publisher determines the access control policy \(ACP\) and transforms it into matrix form \((A,p)\), then generates a random vector \(v=(s,y_2,y_3,\cdots,y\) i ), where Then calculate \(\lambda\) for each piece of information i \(=A\) i \(v\) and output each component of the ciphertext \(C' = g\) s , where \(i\in[1,l]\);
[0069] Randomly select Calculate where \(H(p(i))\) is the hash value of the encrypted ciphertext, and finally output the encrypted ciphertext \(CT\):
[0070] \(CT=\{C,C',\{C\) i ,D i \} i∈[1,l] \};
[0071] S4. Update the blockchain consensus mechanism: Multiple consensus nodes in the blockchain network enter the initial information, and then select the primary node according to p = (h - v)n, where p is the number of the currently selected primary node, h is the height of the current block, v is the number of the current information, and n is the amount of node information. The primary node packs the information propagated by the blockchain into a block bl and then sends the Request object information to other nodes.
[0072] S5. Consensus verification: If any consensus node receives 1 Request object information within a certain time, consensus is reached, and the primary node sends the block information to ordinary nodes. If any consensus node receives a Request object information replacement request within a certain time, the consensus fails, the information request is incorrect, and a new round of consensus is started.
[0073] S6. Data decryption: It is divided into cloud server decryption and user decryption.
[0074] After receiving the user's request, the cloud server first verifies whether it has access rights through ACP. If it fails, it returns an access failure message to the user. Otherwise, the cloud server calculates the corresponding constant w i ∈Z p , so that ∑w i λ i = s, i ∈ [1, l], and execute to obtain the decrypted information:
[0075]
[0076] User decryption: After the user receives the PCT, the user uses the decryption key UGSK to restore the information content M:
[0077]
[0078] Use PxK and UGSK to decrypt the PCT content to restore the information content M.
[0079] Before the consensus node receives the Request object information, it can verify whether it conforms to the access policy according to its own attribute S ID and the ACP stored in the blockchain primary node.
[0080] The information publisher finds its smart contract in the blockchain according to the information's own attribute S ID and views the specific call process through the event log of the smart contract, and at the same time feedbacks to the regulatory agency to trace the information periodically.
[0081] After the user decrypts the information, the information content is hashed again and compared with the corresponding H(M) on the blockchain. If they are the same, the information is complete; if they are different, the information is damaged, and an error report is sent to the cloud server and the regulatory agency to prevent the information from being tampered with. After the regulatory agency receives the information damage report, it immediately destroys the information's own attribute S ID The corresponding smart contract is used to revoke the information content. If forced tampering occurs, it can be immediately destroyed and recorded.
[0082] On the other hand, this embodiment also provides an electronic device, including a memory, a processor, and a computing program stored in the memory and executable on the processor. When the processor executes the computing program, the method is implemented.
[0083] On the other hand, this embodiment also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the method is implemented.
[0084] The above is only a preferred specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An information security protection method based on blockchain, characterized in that Including: Select security parameters, generate relevant mathematical structures and functions, and output global public parameters and a master key, where the data comes from physical entities; Generate a decryption key and a proxy key using the global public parameters, the master key, and information attributes, and hand them over to the user and the cloud server for storage respectively; The information publisher determines the access control policy and transforms it into matrix form, generates a random vector, and calculates and outputs the encrypted ciphertext based on the random vector; Multiple consensus nodes enter the initial information, select a master node, and the master node packages the information and sends the requested object information; According to the situation of the requested object information received by the consensus nodes, if consensus is reached, the master node sends the encrypted ciphertext to the ordinary nodes; Decrypt the encrypted ciphertext based on the decryption key and the proxy key to restore the information content.
2. The method according to claim 1, characterized in that, The process of outputting the global public parameters and the master key includes: The regulatory agency selects secure parameters as input, generates two multiplicative cyclic groups \(G_1\) and \(G_2\) of order \(p\), and the corresponding generators are \(g\); Define a bilinear mapping based on the two multiplicative cyclic groups \(G_1\) and \(G_2\) and the generator, and define a hash function; The regulatory agency then selects parameters, inputs them into the bilinear mapping and the hash function respectively, and outputs the global public parameters and the master key.
3. The method according to claim 1, wherein The process of generating the decryption key and the proxy key using the global public parameters, the master key, and information attributes includes: Generate the corresponding decryption key using the global public parameters, the master key, and information attributes; The regulatory agency selects a random number, and then randomly selects parameters for each piece of information to obtain the secret value of the information decryption key; Obtain the proxy key according to the information decryption key and the secret value, hand over the information decryption key to the user for storage, and hand over the proxy key to the cloud server for storage.
4. The method according to claim 1, wherein The process of calculating and outputting the encrypted ciphertext based on the random vector includes: The information publisher determines the access control policy and transforms the access control policy into matrix form, and at the same time generates a random vector; Select a random number, calculate the hash value of the encrypted ciphertext based on the random vector, the random number, and the access control policy, and output each component of the ciphertext; Output the encrypted ciphertext based on each component of the ciphertext.
5. The method according to claim 1, wherein The process that the multiple consensus nodes enter the initial information, select a master node, and the master node packages the information and sends the requested object information includes: Multiple consensus nodes in the blockchain network receive and process the initial information, and select a master node based on the multiple consensus nodes; The master node packages the information propagated by the blockchain into a block, and at the same time the master node sends the requested object information to other consensus nodes, and the requested object information is used to notify other nodes to perform consensus verification.
6. The method according to claim 1, wherein According to the situation of the requested object information received by the consensus nodes, if consensus is reached, the process that the master node sends the encrypted ciphertext to the ordinary nodes includes: Other consensus nodes receive the requested object information sent by the master node and verify the block content according to their own verification mechanisms Within a certain period of time, if any consensus node receives information of 1 or more Request objects, it is considered that consensus is reached, and the master node sends block information to ordinary nodes to complete the confirmation and synchronization of the block; If any consensus node receives a request for replacing information of 1 or more Request objects, it is considered that the consensus fails and the information request is incorrect, and a new round of consensus process is started.
7. The method according to claim 6, wherein Before the consensus node receives the Request object information, it verifies whether it conforms to the access policy according to its own attributes and the ACP stored in the blockchain master node.
8. The method according to claim 1, characterized in that The process of decrypting the encrypted ciphertext based on the decryption key and the proxy key to restore the information content further includes: After decrypting the encrypted ciphertext, re-hash the information content and compare it with the corresponding one on the blockchain. If they are the same, the information is complete; if they are different, the information is damaged, and an error report is sent to the cloud server and the regulatory agency to prevent the information from being tampered with. After the regulatory agency receives the information damage report, it immediately destroys the smart contract corresponding to the information's own attributes, thereby revoking the information content.
9. An electronic device, comprising a memory, a processor, and a computing program stored in the memory and executable on the processor, characterized in that, When the processor executes the computing program, it implements the method described in any one of claims 1-8.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the method described in any one of claims 1-8.