Personal health data sharing system and method based on zero knowledge proof
Through a personal health data sharing system based on zero-knowledge proof, the synergy between trusted centers and cloud servers is used to realize the secure sharing of health data, solve the security and privacy issues in the existing technology, and improve data access efficiency.
Patent Information
- Application Number
- CN202510577921.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-07-25
AI Technical Summary
The existing health data sharing system has serious security and privacy problems, and is inefficient when facing multi-user requests, making it difficult to achieve safe and efficient personal health data sharing.
A personal health data sharing system based on zero-knowledge proof is adopted, and the secure sharing of health data is achieved through trusted center registration, cloud server storage and encryption, data provider identity authentication and broadcast re-encryption, combined with data requester decryption, and can realize the secure sharing of health data.
It realizes the sharing of personal health data safely and efficiently without leaking sensitive information, protects data privacy and improves the efficiency of data access.
Smart Images

Figure CN120378098A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data sharing, and more particularly to a personal health data sharing system and a data sharing method based on zero-knowledge proof. Background Art
[0002] Currently, a large number of health data requesters have emerged in the market, who hope to obtain personal health data and apply it to clinical research, disease prevention, etc. Therefore, the sharing of personal health data is necessary to a certain extent. However, there are still relatively serious security and privacy problems in the existing sharing research related to health data, as well as efficiency problems faced when dealing with multiple users' requests for health data. Therefore, how to design a lightweight personal health data security sharing scheme urgently needs to be solved. Summary of the Invention
[0003] The purpose of the embodiments of the present invention is to provide a personal health data sharing system and method based on zero-knowledge proof. The personal health data sharing system and method based on zero-knowledge proof solve the security problems and privacy leakage problems in the process of health data sharing, and realize the secure sharing of health data.
[0004] To achieve the above purpose, the embodiments of the present invention provide a personal health data sharing system based on zero-knowledge proof, and the personal health data sharing system based on zero-knowledge proof includes:
[0005] A trusted center, which is responsible for the registration of a group of data requesters, a cloud server, and a group of data providers; responsible for generating and distributing public keys / private keys for data requesters and a group of data providers, and performing pre-computation;
[0006] The data provider, after passing the identity authentication on the cloud server side, encrypts the original health data to obtain a one-time ciphertext of the health data, and uploads the one-time ciphertext of the health data to the cloud server side; after the data provider receives a data request from the cloud server, it verifies the legitimacy of the identity of the data requester set. After successful verification, the data provider sends a broadcast re-encryption key to the cloud server, allowing the cloud server to perform broadcast proxy re-encryption operations.
[0007] The cloud server, when a data requester requests a certain type of health data from it, the cloud server searches through keywords, retrieves the set of data providers that have this type of data; under the explicit authorization of each member of the data provider set, the cloud server uses the broadcast re-encryption keys generated by each member of the data provider set respectively to perform broadcast re-encryption operations on the respective original ciphertexts, and sends the broadcast re-encrypted ciphertexts to each member of the data requester set respectively.
[0008] The set of data requesters, which sends data requests to the cloud server and indicates the type of health data it requests; each data requester receives the re-encrypted ciphertext sent from the cloud server side; each member of the set of data requesters decrypts the re-encrypted ciphertext to obtain the original health data.
[0009] The present invention also provides a personal health data sharing method based on zero-knowledge proof. The personal health data sharing method based on zero-knowledge proof uses the above-mentioned personal health data sharing system based on zero-knowledge proof, and the personal health data sharing method based on zero-knowledge proof includes:
[0010] The identity authentication sub-protocol and data security sharing sub-protocol of the data provider, wherein,
[0011] In the identity authentication sub-protocol of the data provider, first register the personal health data sharing system based on zero-knowledge proof; the set of data providers proves their identities to the cloud server, and each data provider has its own identity certificate;
[0012] In the data security sharing sub-protocol, first initialize the personal health data sharing system based on zero-knowledge proof to generate the system public key, the private key of the data provider, and the private keys of each member of the set of data requesters; the data provider encrypts its health data and stores it in the cloud server; the set of data requesters sends a request for a certain type of health data they need to the cloud server, and the cloud server performs a keyword search according to the data request to find out which data providers have the same keyword, and broadcasts the identity certificates of the data providers and the data request to the data providers; the data providers compare their respective identity certificates with the identity certificates provided by the cloud server, and if they are equal to one of the values, they verify the identity legality of each member of the set of data requesters; after successful verification, these data providers with the same identity certificates respectively generate their own broadcast re-encryption keys and send them to the cloud server, allowing the cloud server to provide proxy broadcast re-encryption operations for them; the cloud server acts as an agent, uses the broadcast re-encryption keys of the data providers to perform re-encryption operations on their encrypted data, and sends each re-encrypted ciphertext to the set of data requesters; the set of data requesters receives the re-encrypted ciphertext sent by the cloud server and decrypts it to obtain the required health data plaintext.
[0013] Preferably, registering the personal health data sharing system based on zero-knowledge proof includes:
[0014] The trusted center sends the secret value and its commitment to each of the data providers respectively; in the identity authentication sub - protocol of the data providers, let \(n\) be an integer that cannot be factored within a finite time under the existing computing power conditions; \(g_1\), \(g_2\) are high - order elements in \(\mathbb{Z}\) n ; \(h_1\), \(h_2\) are elements in the group generated by \(g_1\); \(H\) is an ideal collision - resistant hash function; in addition, the trusted center selects some secret parameters \(\{b,t,l,s\}\). The data providers and the cloud server obtain the secret parameters through a secure channel;
[0015] The following secret parameters are randomly selected by the trusted center, that is:
[0016] \(r_1\in[-2 s n + 1,2 s n-1]\), \(r_2\in[-2 s n + 1,2 s n-1]\), \(x\in[0,b]\);
[0017] The trusted center calculates the commitment \(\{E,F\}\) of the secret value \(x\):
[0018]
[0019] The trusted center publishes \(\{E,F\}\) to the cloud server and can ensure that \(\{r_1,r_2,x\}\) is not leaked at the same time;
[0020] The data providers send their respective identities \(id\) i and registration requests to the trusted center and enter the registration phase; the trusted center sends \(\{r_1,r_2,x\}\) to each registered data provider respectively;
[0021] Once the data providers receive \(\{r_1,r_2,x\}\), they randomly select \(\omega\in[1,2 t+lb -1]\), For efficiency considerations, the data providers can perform the following calculations before starting the authentication:
[0022]
[0023] \(W_1\) and \(W_2\) are used to generate the identity proof of the data providers in the authentication phase.
[0024] Preferably, the set of data providers proves their identities to the cloud server, and each data provider has its own identity proof including:
[0025] The cloud server verifies the identity of the \(i\) - th data provider by checking the identity proof \(\pi\) i ;
[0026] The \(i\)-th data provider generates a proof of identity \(\pi\). i =\(\{C, D, D1, D2\}\) is calculated according to the following formula:
[0027]
[0028] \(D = \omega + Cx\)
[0029] \(D1 = q1 + Cr1\)
[0030] \(D2 = q2 + Cr2\)
[0031] Based on the results of the above equations, the \(i\)-th data provider obtains the proof of identity \(\pi\). i =\(\{C, D, D1, D2\}\);
[0032] The \(i\)-th data provider sends the proof of identity \(\pi\). i to the cloud server;
[0033] According to the FO commitment protocol, the cloud server verifies whether the following equations hold:
[0034]
[0035] If the above three equations hold, the identity of this data provider is legal.
[0036] Preferably, initialize the personal health data sharing system based on zero-knowledge proof, and generate the system public key, the private key of the data provider, and the private keys of the members in the data requester set, including:
[0037] Given a secret parameter \(\varPsi\in N\) and the total number \(M\) of members in the data requester set, construct a bilinear map \(e: G\times G\rightarrow G\). T ; \(G\) and \(G\). T are two multiplicative groups of prime order \(P\), where \(|P|=\varPsi\); randomly select 3 generators \((g, h, u)\in G\). 3 and a secret \(\alpha\in Z\). P * ; Select two hash functions, \(H1:\{0, 1\}\rightarrow Z\). P * and \(H2: G\). T \(\rightarrow G\); obtain the system public key \(SPK = \{G, G\). T , e, v, h, h α u, u α , H1, H2\}, where \(v = e(g, h)\);
[0038] Generate the private key of the data provider \(DP\). i :
[0039] Generate the private key of the data requester DR j :
[0040] Preferably, after the cloud server successfully verifies the legal identity of the data provider, the data provider uses zero-knowledge proof and the system public key to encrypt its health data, and the obtained health data ciphertext includes:
[0041] After the cloud server successfully verifies the legal identity of the data provider DP i the data provider DP i uses zero-knowledge proof π i and the system public key SPK to encrypt its health data m, and obtains the ciphertext CT. The specific content is as follows:
[0042]
[0043] where k1 is a random value, k1 ∈ Z P * ;
[0044] The data provider DP i stores its health data in the form of the initial health data ciphertext CT, this health data type keyword, and the identity proof π of the i-th data provider i in the cloud server.
[0045] Preferably, the data requester set sends a certain type of health data request to the cloud server; after the cloud server receives the health data request from the data requester set, it discovers which data providers have the same keyword through keyword search; the cloud server broadcasts the identity proofs of all the data providers and the data request to all the data providers; the data providers compare their respective identity proofs with the identity proofs provided by the cloud server. If they are equal to one of the values, they verify the identity legality of each member of the data requester set; after successful verification, these data providers with the same identity proof respectively generate their own broadcast re-encryption keys and send them to the cloud server, allowing the cloud server to provide proxy broadcast re-encryption operations for them, including:
[0046] The data requester set sends a certain type of health data request token to the cloud server: this health data type keyword, and the identity set S of q data requesters in the set = {id1, id2,..., id q};
[0047] After receiving the health data request token from the set of data requesters, the cloud server discovers which data providers have the same keywords through keyword search, and then broadcasts the identity proofs π of all these data providers i along with the data request token to all the data providers. The data providers that receive the data request token compare their respective identity proofs with these π i . If it is equal to one of the π i values, then the data provider DP i verifies the identity legality of each member of the set of data requesters. After successful verification, the data provider agrees to contribute the corresponding type of health data;
[0048] The data provider takes the system public key SPK, the zero - knowledge proof π i , the private key sk i and {a0, a1,..., a q} generated by the Lagrange interpolation polynomial by the set of data requesters S = {id1, id2,..., id n} as inputs to generate a re - encryption key
[0049] where, for each id j ∈S, calculate x i = H1(id j ), where k2 is a random value k2 ∈ Z P * ;
[0050]
[0051]
[0052] Then the re - encryption key generation algorithm is as follows:
[0053]
[0054] where k3 is a random value, k3 ∈ Z P * .
[0055] Preferably, the cloud server acts as an agent, uses the broadcast re - encryption key of the data provider to perform re - encryption operations on its encrypted data, and sends each re - encrypted ciphertext to the set of data requesters, including:
[0056] The cloud server receives the identity proof π i of the data provider DP i and its re - encryption key After that, first, according to the identity proof π i find the corresponding initial ciphertext CT i , then, using the system public key SPK, the re-encryption key sent by the data provider DP i and the identity proof π as well as the initial ciphertext CT corresponding to the identity proof π i as inputs, re-encrypt the initial ciphertext CT i to obtain the re-encrypted ciphertext CT i ', and the specific algorithm is as follows: i Specifically, the re-encryption algorithm is as follows:
[0057]
[0058] Preferably, the set of data requesters receives the re-encrypted ciphertext sent by the cloud server and decrypts it to obtain the required plaintext of the health data, including:
[0059] After each member of the set of data requesters receives the re-encrypted ciphertext CT i ', use their respective identity id j and their private key sk j to decrypt it to obtain the plaintext of the health data m, and the decryption process is as follows:
[0060]
[0061] If id j ∈S, then the plaintext of the health data m is successfully obtained.
[0062] In addition, the present invention also provides a machine-readable storage medium, on which instructions are stored, and these instructions are used to cause the machine to execute the above-mentioned personal health data sharing method based on zero-knowledge proof.
[0063] Through the above technical solutions, the personal health data sharing system based on zero-knowledge proof of the present invention realizes the setting and registration of the system through the trusted center, realizes the storage of the health data in ciphertext once through the cloud server. In addition, the data requester provides identity authentication to the cloud server by using zero-knowledge proof, the cloud service performs broadcast proxy re-encryption on the health data in ciphertext once, and each member of the set of data requesters decrypts the re-encrypted ciphertext respectively to obtain the original health data. The present invention realizes the secure sharing of personal health data by combining zero-knowledge proof with identity-based broadcast proxy re-encryption.
[0064] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent specific implementation part. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following specific embodiments, they are used to explain the embodiments of the present invention, but do not constitute a limitation to the embodiments of the present invention. In the accompanying drawings:
[0066] Figure 1 is a system module block diagram of the personal health data sharing system based on zero-knowledge proof of the present invention;
[0067] Figure 2 is a simulation flowchart of personal health data sharing based on zero-knowledge proof of the present invention; and
[0068] Figure 3 is a flowchart of an implementation manner of the personal health data sharing method based on zero-knowledge proof of the present invention. Specific Embodiments
[0069] The following will detail the specific embodiments of the embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to illustrate and explain the embodiments of the present invention, and do not limit the embodiments of the present invention.
[0070] Zero-knowledge proof is a cryptographic tool with privacy protection and security. It can verify the authenticity of information without revealing any specific content. And since no specific data is transmitted, there is almost no risk of leaking sensitive information. Therefore, if zero-knowledge proof technology is used, the above security and privacy problems can be well solved.
[0071] In summary, how to design a lightweight personal health data security sharing protocol based on the health data sharing scenario is an urgent problem to be solved.
[0072] Figure 1 is a system module block diagram of a personal health data sharing system based on zero-knowledge proof of the present invention, as Figure 1As shown in the figure, the personal health data sharing system based on zero-knowledge proof includes: a trusted center (i.e., the trusted center): registering data providers (i.e., a group of data providers), a cloud server (i.e., the cloud server), and a set of data requesters (i.e., a group of data requesters); being responsible for generating and distributing public keys / private keys for the set of data requesters and data providers; and performing pre-computation; data providers: sending an authentication request to the cloud server; encrypting the original health data to obtain a one-time ciphertext of the health data and uploading it to the cloud server; and authenticating the identity of the set of data providers; sending a broadcast re-encryption key to the cloud server side to allow the cloud server side to provide broadcast proxy re-encryption operations; the cloud server: performing keyword search; respectively using the broadcast re-encryption keys generated by each data provider to perform re-encryption operations on the respective original ciphertexts; and sending the broadcast re-encrypted ciphertexts to the set of data requesters; the set of data requesters: decrypting their respective re-encrypted ciphertexts to obtain the original health data.
[0073] Figure 2 is a simulation flowchart of personal health data sharing based on zero-knowledge proof of the present invention. As Figure 2 shown, 1. Forward the commitment {E,F} of the secret value x; 2. Provide the identity id of the data provider i ; 3. Send the secret values {r1,r2,x}; 4. Send (CT, keyword, π i ); 5. Forward the data request token = (keyword, S); 6. Forward (token, π i ); 7. Broadcast re-encryption key 8. Re-encrypted ciphertext CT' = {CT1', CT2', CT3', CT4'}; The whole process realizes the secure sharing of personal health data.
[0074] Figure 3It is a flowchart of an implementation manner of a personal health data sharing method based on zero-knowledge proof. The present invention also provides a personal health data sharing method based on zero-knowledge proof, which uses the above-mentioned personal health data sharing system based on zero-knowledge proof, and the personal health data sharing method based on zero-knowledge proof includes: an identity authentication sub-protocol and a data security sharing sub-protocol of a data provider: In the identity authentication sub-protocol of the data provider, in step 1, register the personal health data sharing system based on zero-knowledge proof, and then the data provider set proves its identity to the cloud server, and each data provider has its own identity certificate; In the data security sharing sub-protocol, in step 2, initialize the personal health data sharing system based on zero-knowledge proof, generate a system public key, a private key of the data provider, and private keys of each member in the data requester set; In step 3, the data provider encrypts its health data and stores it in the cloud server; In step 4, the data requester set sends a request for a certain type of health data they need to the cloud server, and the cloud server performs a keyword search according to the data request to find out which data providers have the same keyword, and broadcasts the identity certificate of the data provider together with the data request to the data provider; After the data provider compares its zero-knowledge proof with all the identity certificates sent by the cloud one by one, as long as there is a same situation, it verifies the identity legality of each member in the data requester set in the data request; After successful verification, these data providers with the same identity certificate respectively generate their own broadcast re-encryption keys and send them to the cloud server, allowing the cloud server to perform proxy broadcast re-encryption operations for them; In step 5, the cloud server acts as an agent, uses the broadcast re-encryption key of the data provider to perform a re-encryption operation on its encrypted data, and sends each re-encrypted ciphertext to the data requester set; In step 6, the data requester set receives the re-encrypted ciphertext sent by the cloud server and decrypts it to obtain the required health data plaintext.
[0075] In the step 1, registering the personal health data sharing system based on zero-knowledge proof, and then the data provider set proves its identity to the cloud server, and each data provider has its own identity certificate includes:
[0076] In step 7, the trusted center sends the secret value and its commitment to each of the data providers respectively; in the identity authentication sub-protocol of the data provider, let n be an integer that cannot be factored in a finite time under the existing computing power conditions; g1, g2 are high-order elements in Z n ; h1, h2 are elements in the group generated by g1; H is an ideal collision-resistant hash function; in addition, the trusted center selects some secret parameters {b, t, l, s}. The data provider and the cloud server obtain the secret parameters through a secure channel;
[0077] The following secret parameters are randomly selected by the trusted center, namely:
[0078] r1 ∈ [-2 s n + 1, 2 s n - 1], r2 ∈ [-2 s n + 1, 2 s n - 1], x ∈ [0, b];
[0079] The trusted center calculates the commitment {E, F} of the secret value x:
[0080]
[0081] The trusted center publishes {E, F} to the cloud server and can ensure that {r1, r2, x} is not leaked at the same time;
[0082] The data provider sends its respective identity id i and the registration request to enter the registration stage; the trusted center sends {r1, r2, x} to each successfully registered data provider respectively;
[0083] Once the data provider receives {r1, r2, x}, it randomly selects ω ∈ [1, 2 t+lb - 1], For efficiency considerations, the data provider can perform the following calculations before starting the authentication:
[0084]
[0085] W1 and W2 are used to generate the identity proof of the data provider during the authentication stage.
[0086] Step 8, in order to protect the identity of the data provider during the authentication process, the identity authentication sub - protocol of the data provider designs an anonymous authentication protocol based on the FO commitment protocol; the cloud server can verify the identity of the i - th data provider by checking the identity proof π i ;
[0087] The i - th data provider generates the proof of identity π i = {C, D, D1, D2} calculated according to the following formula:
[0088]
[0089] D = ω + Cx
[0090] D1 = q1 + Cr1
[0091] D2 = q2 + Cr2
[0092] According to the above equation results, the i - th data provider obtains the identity proof π i={C, D, D1, D2};
[0093] The i-th data provider sends the identity proof π i to the cloud server;
[0094] According to the FO commitment protocol, the cloud server verifies whether the following equations hold:
[0095]
[0096] If the above three equations hold, the identity of this data provider is legal.
[0097] In step 2, the personal health data sharing system based on zero-knowledge proof is initialized to generate the system public key, the private key of the data provider, and the private keys of the members in the data requester set, including:
[0098] Step 9, given a secret parameter Ψ ∈ N and the total number M of possible members in the data requester set, construct a bilinear map e: G × G → G T ; G and G T are two multiplicative groups of prime order P, where |P| = Ψ; randomly select 3 generators (g, h, u) ∈ G 3 and a secret α ∈ Z P * ; select two hash functions, H1: {0, 1} → Z P * and H2: G T → G; obtain the system public key SPK = {G, G T , e, v, h, h α u, u α , H1, H2}, where v = e(g, h);
[0099] Generate the private key of the data provider DP i :
[0100] Generate the private key of the data requester DR j :
[0101] In step 3, the data provider encrypts its health data and stores it in the cloud server, including:
[0102] Step 10, after the cloud server successfully verifies the legal identity of the data provider DP i , the data provider DP i uses the zero-knowledge proof π i and the system public key SPK to encrypt its health data m to obtain the ciphertext CT, and the specific content is as follows:
[0103]
[0104] Among them, k1 is a random value, and k1 ∈ Z P * ;
[0105] Data Provider DP i stores its health data in the cloud server in the form of (encrypted initial health data CT, this health data type keyword, the identity proof π of the i-th data provider i ).
[0106] In step 4, the data requester set sends a request for a certain type of health data they need to the cloud server. The cloud server performs a keyword search based on the data request, finds out which data providers have the same keyword, and broadcasts the identity proofs of the data providers together with the data request to the data providers. After the data providers compare their zero-knowledge proofs with all the identity proofs sent by the cloud one by one, as long as there is a match, they verify the identity legality of each member of the data requester set in the data request. After successful verification, these data providers with the same identity proofs respectively generate their own broadcast re-encryption keys and send them to the cloud server, allowing the cloud server to provide proxy broadcast re-encryption operations for them, including:
[0107] Step 11, the data requester set sends a token for a certain type of health data request to the cloud server: (this health data type keyword, the identity set S of q data requesters = {id1, id2,..., id q};
[0108] After receiving the health data request token from the data requester set, the cloud server discovers which data providers have the same keyword through keyword search, and then broadcasts the identity proofs π of all these data providers i together with the data request token to all data providers. The data providers that receive the data request token compare their respective identity proofs with these π i If it is equal to one of the π i values, then the data provider DP i verifies the identity legality of each member of the data requester set. After successful verification, the data provider agrees to contribute the corresponding type of health data;
[0109] The data provider provides the system public key SPK, the zero-knowledge proof π i , the private key sk i and the set S of data requesters = {id1, id2,..., id q}{Generated by Lagrange interpolation polynomial {a0, a1,..., a n} is used as input to generate the re-encryption key
[0110] Among them, for each id j ∈S, calculate x i = H1(id j ), where k2 is a random value, k2 ∈ Z P * ;
[0111]
[0112] Then the re-encryption key The generation algorithm is as follows:
[0113]
[0114] where k3 is a random value, k3 ∈ Z P * .
[0115] In step 5, the cloud server acts as an agent, uses the broadcast re-encryption key of the data provider to perform re-encryption operations on its encrypted data, and sends each re-encrypted ciphertext to the set of data requesters, including:
[0116] Step 12, the cloud server receives the identity proof π i of the data provider DP i and its re-encryption key After that, first, according to the identity proof π i find the corresponding initial ciphertext CT i , and then use the system public key SPK, the re-encryption key i sent by the data provider DP and the identity proof π i corresponding initial ciphertext CT i as input, re-encrypt the initial ciphertext CT i to obtain the re-encrypted ciphertext CT i ', and the specific algorithm is as follows:
[0117]
[0118] In step 6, the set of data requesters receives the re-encrypted ciphertext sent by the cloud server and decrypts it to obtain the required health data plaintext, including:
[0119] Step 13, after each member of the set of data requesters receives the re-encrypted ciphertext CT i ', use their respective identities id jand its private key sk j Decrypt it to obtain the plaintext m of the health data. The decryption process is as follows:
[0120]
[0121] If id j ∈S, then the plaintext m of the health data is successfully obtained.
[0122] An embodiment of the present invention provides a storage medium, on which a program is stored, and when the program is executed by a processor, a personal health data sharing method based on zero-knowledge proof is implemented.
[0123] An embodiment of the present invention provides a processor, and the processor is used to run a program, wherein when the program runs, the personal health data sharing method based on zero-knowledge proof is executed.
[0124] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0125] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0126] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0127] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 steps of the functions specified in one block or multiple blocks.
[0128] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.
[0129] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0130] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can be implemented by any method or technology for information storage. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0131] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, commodity or device comprising the element.
[0132] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0133] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A personal health data sharing system based on zero-knowledge proof, characterized in that, The personal health data sharing system based on zero - knowledge proof includes: A trusted center, which is responsible for the registration of a group of data requesters, a cloud server, and a group of data providers; it is responsible for generating and distributing public keys / private keys for data requesters and a group of data providers, and performing pre - calculations; The data provider, after passing the authentication on the cloud server side, encrypts the original health data to obtain the one - time ciphertext of the health data, and uploads the one - time ciphertext of the health data to the cloud server side; after the data provider receives a data request from the cloud server, it verifies the legality of the identity of the data requester set. After successful verification, the data provider sends a broadcast re - encryption key to the cloud server, allowing the cloud server to perform broadcast proxy re - encryption operations; The cloud server, when a data requester requests a certain type of health data from it, the cloud server searches through keywords, retrieves the set of data providers that have this type of data; under the explicit authorization of each member of the data provider set, the cloud server uses the broadcast re - encryption keys generated by each member of the data provider set respectively to perform broadcast re - encryption operations on the corresponding original ciphertexts respectively, and sends the broadcast re - encrypted ciphertexts to each member of the data requester set respectively; The data requester set, the data requester set sends a data request to the cloud server and indicates the type of health data it requests; each data requester receives the re - encrypted ciphertext sent from the cloud server side; each member in the data requester set decrypts the re - encrypted ciphertext to obtain the original health data.
2. A personal health data sharing method based on zero-knowledge proof, characterized in that, The personal health data sharing method based on zero - knowledge proof uses the personal health data sharing system based on zero - knowledge proof described in claim 1. The personal health data sharing method based on zero - knowledge proof includes: The identity authentication sub - protocol and data security sharing sub - protocol of the data provider, where, In the identity authentication sub - protocol of the data provider, first, the personal health data sharing system based on zero - knowledge proof is registered; the data provider set proves its identity to the cloud server, and each data provider has its own identity certificate; In the data security sharing sub - protocol, first, initialize the zero - knowledge - proof - based personal health data sharing system to generate a system public key, the private key of the data provider, and the private keys of each member in the data requester set; the data provider encrypts its health data and stores it in the cloud server; the data requester set sends a request for a certain type of health data they need to the cloud server, the cloud server conducts a keyword search based on the data request, searches for which data providers have the same keyword, and broadcasts the identity proofs of the data providers together with the data request to the data providers; the data providers compare their respective identity proofs with the identity proofs provided by the cloud server, if it is equal to one of the values, then verify the identity legality of each member of the data requester set; after successful verification, these data providers with the same identity proofs respectively generate their own broadcast re - encryption keys and send them to the cloud server, allowing the cloud server to perform proxy broadcast re - encryption operations for them; the cloud server, as an agent, uses the broadcast re - encryption keys of the data providers to re - encrypt the encrypted data and sends each re - encrypted ciphertext to the data requester set; the data requester set receives the re - encrypted ciphertext sent by the cloud server and decrypts it to obtain the required plaintext of the health data.
3. The personal health data sharing method based on zero-knowledge proof according to claim 2, wherein Registering the zero - knowledge - proof - based personal health data sharing system includes: The trusted center sends the secret value and its commitment to each of the data providers respectively; in the identity authentication sub-protocol of the data provider, let n be an integer that cannot be factored within a finite time under the existing computing power conditions; g1, g2 are high-order elements in Z n ; h1, h2 are elements in the group generated by g1; H is an ideal collision-resistant hash function; in addition, the trusted center selects some secret parameters {b, t, l, s}. The data provider and the cloud server obtain the secret parameters through a secure channel; The following secret parameters are randomly selected by the trusted center, namely: r1 ∈ [-2 s n + 1, 2 s n - 1], r2 ∈ [-2 s n + 1, 2 s n - 1], x ∈ [0, b]; The trusted center calculates the commitments {E, F} of the secret value x: The trusted center publishes {E, F} to the cloud server and can ensure that {r1, r2, x} is not leaked at the same time; The data providers send their respective identity IDs to the trusted center i and registration requests, entering the registration phase; the trusted center sends {r1, r2, x} to each of the successfully registered data providers; Once the data provider receives {r1, r2, x}, it randomly selects ω ∈ [1, 2 t+lb - 1], For efficiency considerations, the data provider can perform the following calculations before starting the authentication: W1 and W2 are used to generate the identity proof of the data provider in the authentication phase.
4. The personal health data sharing method based on zero-knowledge proof according to claim 3, wherein The data provider set proves its identity to the cloud server. Each data provider has its own identity proof, including: The cloud server verifies the identity of the i-th data provider by checking the identity proof π i ; The \(i\)-th said data provider generates a proof of identity \(\pi\) i =\(\{C, D, D1, D2\}\) is calculated according to the following formula: D = ω + Cx D1 = q1 + Cr1 D2 = q2 + Cr2 Based on the above equation result, the i-th said data provider obtains the identity proof π i ={C, D, D1, D2}; The i-th data provider sends the identity proof π i to the cloud server; According to the FO commitment protocol, the cloud server verifies whether the following equations hold: If the above three equations hold, then the identity of this data provider is legal.
5. The method for sharing personal health data based on zero-knowledge proof according to claim 4, wherein, Initializing the zero - knowledge - proof - based personal health data sharing system to generate a system public key, the private key of the data provider, and the private keys of each member in the data requester set includes: Given a secret parameter Ψ ∈ N and a total number M of members in the set of all data requesters, construct a bilinear map e: G × G → G T ; G and G T are two multiplicative groups of prime order P, where |P| = Ψ; randomly select three generators (g, h, u) ∈ G 3 and a secret α ∈ Z P * ; select two hash functions, H1: {0, 1} → Z P * and H2: G T → G; obtain the system public key SPK = {G, G T , e, v, h, h α u, u α , H1, H2}, where v = e(g, h); Generate the private key of the data provider DP i : Generate the private key of the data requester DR j :
6. The method for sharing personal health data based on zero-knowledge proof according to claim 5, wherein After the cloud server successfully verifies the legal identity of the data provider, the data provider uses zero - knowledge proof and the system public key to encrypt its health data to obtain the health data ciphertext, including: After the cloud server successfully verifies the legal identity of the data provider DP i , the data provider DP i uses zero - knowledge proof π i and the system public key SPK to encrypt its health data m, obtaining the ciphertext CT. The specific content is as follows: where k1 is a random value, k1 ∈ Z P * ; The data provider DP i stores its health data in the form of the initial health data ciphertext CT, the keyword of this health data type, and the identity proof π of the i-th data provider i in the cloud server.
7. The personal health data sharing method based on zero - knowledge proof according to claim 6, wherein The set of data requesters sends a certain type of health data request to the cloud server; after the cloud server receives the health data request from the set of data requesters, it discovers which data providers have the same keywords through keyword search; the cloud server broadcasts the identity certificates of all the data providers and the data request to all the data providers; the data providers compare their respective identity certificates with the identity certificates provided by the cloud server, and if they are equal to one of the values, they verify the identity legality of each member of the set of data requesters; After successful verification, these data providers with the same identity certificates respectively generate their own broadcast re-encryption keys and send them to the cloud server. The operations allowed for the cloud server to provide proxy broadcast re-encryption for them include: The set of data requesters sends a certain type of health data request token to the cloud server: the keyword of this health data type, and the identity set S of q data requesters in the set of data requesters is {id1, id2,..., id q}; After receiving the health data request token from the set of data requesters, the cloud server discovers which data providers have the same keywords through keyword search, and then broadcasts the identity proofs π of all these data providers i along with the data request token to all the data providers. The data providers that receive the data request token will compare their respective identity proofs with these π i If it is equal to one of the π i values, then the data provider DP i verifies the identity legality of each member of the set of data requesters. After successful verification, the data provider agrees to contribute the corresponding type of health data; The data provider takes the system public key SPK, the zero-knowledge proof π i , the private key sk i and {a0, a1,..., a q} generated by the Lagrange interpolation polynomial by the set of data requesters S = {id1, id2,..., id n} as inputs to generate the re-encryption key rkπ i→S ; where, for each id j ∈S, calculate x i = H1(id j ), where k2 is a random value, k2 ∈ Z P * ; Then the re-encryption key The generation algorithm is as follows: where k3 is a random value, k3 ∈ Z P * .
8. The data security sharing sub - protocol in the personal health data sharing method based on zero - knowledge proof according to claim 7, characterized in that, The cloud server, as an agent, uses the broadcast re-encryption keys of the data providers to perform re-encryption operations on the encrypted data for them, and sends each re-encrypted ciphertext to the set of data requesters, including: The cloud server receives the identity proof π i from the data provider DP i and its re-encryption key . First, based on the identity proof π i , the corresponding initial ciphertext CT i is found. Then, using the system public key SPK, the re-encryption key i sent by the data provider DP , the identity proof π i , and the corresponding initial ciphertext CT i as inputs, the initial ciphertext CT i is re-encrypted to obtain the re-encrypted ciphertext CT i '. The specific algorithm is as follows:
9. The data security sharing sub - protocol in the personal health data sharing method based on zero - knowledge proof according to claim 7, characterized in that, The set of data requesters receives the re-encrypted ciphertext sent by the cloud server and decrypts it to obtain the required health data plaintext, including: Each member of the set of data requesters receives the re-encrypted ciphertext CT i ', and then uses their respective identity id j and its private key sk j to decrypt it to obtain the plaintext m of the health data. The decryption process is as follows: If the id j ∈ S, then the plaintext m of the health data is successfully obtained.
10. A machine-readable storage medium having instructions stored thereon, characterized in that, This instruction is used to cause a machine to execute the personal health data sharing method based on zero-knowledge proof described in any one of claims 2-9.