Certificateless puncturable signcryption method for resisting long-range attack of block chain

By introducing authoritative node collection and punctureable technology on the blockchain, long-range attacks caused by key leakage are solved, decentralization of the blockchain network and confidentiality of transaction information are achieved, historical transaction tampering, and computing and communication costs are reduced.

CN120415833APending Publication Date: 2025-08-01HANGZHOU INTERNATIONAL INNOVATION INSTITUTE OF BEIHANG UNIVERSITY +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510592881.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

Existing blockchain technology faces the threat of long-term attacks caused by key leakage, resulting in the modification of historical transactions and the confidentiality of transaction information. The existing certificate-free confidentiality solution has failed to effectively solve the centralization problem of blockchain network.

Method used

The authoritative blockchain node set is used to replace traditional KGC, and combined with Bloom filter and punctureable technology, a decentralized certificate-free encryption method is realized. Through the user's private key, the signature user judges the message correlation and generates the signature text. The signature user verifies the signature text legality and supports the signature capability of revoking specific messages.

Benefits of technology

It realizes decentralization of blockchain networks, reduces computing and communication costs, prevents long-term attacks caused by key leakage, ensures the confidentiality and integrity of transaction information, and solves the problems of key custody and centralization.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention belongs to the field of computer and information security, and discloses a blockchain anti-long-range attack certificateless puncturable signcryption method, which comprises seven steps of system initialization and parameter establishment, user part private key extraction, puncture key updating, secret value extraction, public key generation, signcryption and de-signcryption. An authoritative node set in the block chain is adopted to initialize the system and generate a user part private key and a puncture key, so that the defect of key distribution based on a centralized entity is overcome; a puncturable technology is embedded, and the private key of the user is associated with the message, so that the capability of operating specific messages is realized, and long-range attacks caused by key leakage in the block chain are resisted; in addition, the signcryption and de-signcryption operation not only saves the calculation and communication cost, but also ensures the confidentiality and integrity of the block chain message. According to the method, the problems that long-range attacks exist in centralized entities and block chain rights and interests in the prior art, and confidentiality and integrity of messages on a chain cannot be provided at the same time in the prior art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computers and information security, and particularly relates to a certificateless puncturable signcryption method for blockchain against long-range attacks. Background Art

[0002] With the characteristics of decentralization, immutability and transparency, blockchain technology has gradually become the focus of attention in the academic and industrial fields. As a core consensus mechanism of blockchain technology, proof of stake participates in the network verification and block creation process by holding and locking cryptocurrencies, rather than relying on computing power, which improves energy efficiency and enhances the security and decentralization characteristics of the network, thus receiving extensive attention. Despite its potential advantages, it faces the threat of long-range attacks caused by key leakage. Such attacks can enable attackers to rewrite or delete the transaction history that has occurred on the blockchain, thus violating the basic immutability characteristic of the blockchain. In 2020, Li et al. proposed an identity-based puncturable signature scheme, which updates the private key with selected messages to revoke the signature ability for specific messages, thus solving the long-range attack problem caused by key leakage. Subsequently, some identity-based puncturable signature schemes and lattice-based puncturable signature schemes under the standard model were also proposed correspondingly to provide security under the standard model or quantum security.

[0003] However, long-range attacks caused by key leakage can not only modify historical transactions on the blockchain, but also some sensitive information will be stolen, thus bringing inestimable losses to traders. In order to ensure both the immutability of historical transactions on the blockchain and the confidentiality of transaction information, some people adopt the signcryption technology of "signing first and then encrypting" to solve the corresponding problems. However, the existing related work is either signcryption based on traditional public key infrastructure or signcryption based on identity or attributes. The former requires expensive certificate management costs, and the latter has the problem of key escrow. Therefore, a certificateless signcryption scheme based on blockchain has been proposed to ensure the information security of vehicle networks or edge computing networks. However, the current work only uses the decentralization feature of blockchain to solve the problems of other networks, and does not solve the long-range attack problem of the blockchain network itself, especially the immutability problem of historical transactions and the confidentiality problem of transaction information caused by key leakage on the blockchain. Summary of the Invention

[0004] Aiming at the disadvantages of the above-mentioned existing technologies, the present invention aims to provide a certificateless puncturable signcryption method for blockchain against long-range attacks, which simultaneously solves the threat of historical transactions being modified caused by long-range attacks in the blockchain network and the confidentiality problem of transaction information, and provides double protection for the confidential information and integrity of certain transactions of the blockchain protocol.

[0005] To achieve the above invention objectives, the detailed technical solution of the present invention is as follows:

[0006] A certificateless puncturable signcryption method for blockchain against long-range attacks. In this method, the traditional third-party entity-based KGC is converted into a set of authoritative nodes in the blockchain to implement a decentralized certificateless cryptosystem. At the same time, the prefix of the message is selected to puncture and update the user's private key, so that part of the user's private key is associated with the message. Before a signcryption user signcrypts a certain message, the user first determines whether the message is associated with the punctured private key. If it is associated with the puncture key of the signcryption user, the signcryption user discards this message and returns an error. Otherwise, the signcryption user uses its own public and private keys and the public key of the unsigncryption user to signcrypt the plaintext message to generate a signcrypted text. And after receiving the signcrypted text, the unsigncryption user first verifies its legality, and then uses its own private key to recover the message. The present invention replaces the traditional third-party entity-based KGC with a set of authoritative nodes in the blockchain, realizing a decentralized certificateless cryptosystem suitable for blockchain networks, thereby designing a decentralized certificateless signcryption method and introducing the puncturable technology into it, which not only saves computational and communication costs, but also meets confidentiality and non-repudiation, and supports the ability to revoke the signcryption of specific messages, providing double protection for the confidential information and integrity of certain transactions in the blockchain protocol. The method specifically includes the following steps:

[0007] (1) Initialize a certificateless puncturable signcryption cryptosystem based on the blockchain and a Bloom filter. Input the security parameter, and the set of authoritative nodes in the blockchain generates the master key and public parameters of this cryptosystem;

[0008] After completing the system initialization, input the user identity to be traded. The set of authoritative nodes first encodes the user identity into an array associated with the Bloom filter, and then generates a partial private key of the user through the master key and public parameters, and sends it to the user;

[0009] (3) In order to reduce the harm caused by key leakage and remove the ability to unsigncrypt specific messages, the set of authoritative nodes punctures and updates the partial private key of the user by using the master key, public parameters, message elements, and the array associated with the user identity to generate a puncture key, and sends it to the user;

[0010] (4) The user can generate a secret value that is unknown to the set of authoritative nodes and external nodes by using its own array information of the identity and public parameters;

[0011] (5) After the user selects its own secret value, the user generates its own public key by using the public parameters and the secret value;

[0012] (6) When the signcryption user needs to conduct a transaction on a sensitive plaintext message, the signcryption user signcrypts the message by using the public parameters, their own identity information, public and private keys, and the identity and public key of the unsigncryption user. Before generating the signcrypted text, it first checks whether the selected plaintext message has been punctured. If so, it does not perform signcryption and returns an error symbol; otherwise, it generates the signcrypted text. to the blockchain network;

[0013] (7) When the unsigncryption user receives the signcrypted text, the unsigncryption user uses the public parameters, the signcrypted text, the identity information and public key of the signcryption user to verify the authenticity of the signcryption. Once the verification passes, it uses its own identity information and public and private keys to perform unsigncryption.

[0014] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0015] (1) The certificateless puncturable signcryption method based on blockchain provided by the present invention replaces the trusted third party - the key generation center KGC in the traditional certificateless cryptosystem with the authoritative node set of the blockchain. This method not only solves the certificate management problem in the traditional public key infrastructure and the key escrow problem in identity - or attribute - based cryptography, but also solves the centralization problem brought by the KGC in the existing blockchain - based certificateless cryptosystem. The adopted authoritative node set of the blockchain can convert the centralized KGC into a distributed key generation mode, providing key generation and management services without violating the decentralized characteristics of the blockchain.

[0016] (2) The certificateless puncturable signcryption method based on blockchain provided by the present invention adopts the puncturable technology, which can finely revoke or disable the unsigncryption ability of transaction users for specific transactions on the chain. For example, it can prevent processed transactions from being re - signcrypted or reused. In this way, even if the transaction user's key is leaked, it does not affect the signcryption of other unprocessed transactions.

[0017] (3) The certificateless puncturable signcryption method based on blockchain provided by the present invention adopts the puncturable signcryption technology to prevent the long - range attack caused by key leakage on the proof - of - stake blockchain. If a transaction user does not want a certain transaction to be made public, it can puncture the private key related to the transaction. Even if the punctured key is leaked, the attacker who obtains the key cannot re - sign the transaction, nor can it decrypt the transaction, thereby improving the integrity of on - chain transactions and the confidentiality of transaction information. Specific implementation manners

[0018] The specific implementation manners of the present invention will be described clearly and completely below, so as to facilitate those skilled in the art of this technology to understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific implementation manners. For those ordinary skilled in the art of this technology, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions created using the concept of the present invention are within the scope of protection.

[0019] The method of the present invention consists of seven algorithms, and the specific implementation process is as follows:

[0020] Step 1: System initialization and parameter establishment: In the system initialization stage, the authoritative node set in the blockchain needs to set the security parameters of the system and establish the public parameters required for the entire system and the master secret key ; specifically including: selecting a security parameter , two additive cyclic groups of prime order q and , and a multiplicative cyclic group of prime order q , defining an asymmetric bilinear mapping , setting the generators of the additive cyclic groups and to be and respectively, and having ; randomly selecting five collision-resistant cryptographic hash functions , , , , , where represents a natural number, represents the set of prime numbers, represents a string composed of 0s and 1s of any length, represents the security parameter a combination string of 0s and 1s within the length; randomly selecting an element from as the master secret key of the system, and calculating the master public key of the system; initializing a Bloom filter, selecting two natural numbers , randomly selecting hash functions , and generating a uniform distribution on the array . Initializing an array with a length of , setting the function set ; the authoritative node set secretly stores and , and publicly discloses the public parameters ;

[0021] Step 2: User partial private key extraction: By using the master key , the public parameters and the array associated with the user's identity , the authoritative node set calculates and sends to the user through a secure channel;

[0022] Step 3: Piercing key update: By using the master key , the public parameters , the element , the array associated with the user's identity and the partial private key , the authoritative node set performs piercing update on the user's partial private key to generate the piercing key ; Specifically, it includes: adding the element to the set of the Bloom filter, calculating , for all , setting , while the other positions in the array remain 0, and returning the updated array ; For the partial private key , for each , when , define , when , define , where represents the -th subscript in the array , and represents the error symbol; the authoritative node set calculates the user's piercing key and sends to the user through a secure channel;

[0023] Step 4: Secret value extraction: By using the array and the public parameters , the user randomly selects an element from and calculates as its own secret value;

[0024] Step 5: Public key generation: By using the public parameters and the secret value , the user calculates as its own public key;

[0025] Step 6, Signcryption: By using its own private key and the public key of the unsigncrypting user, the signcryption user signcrypts the message to generate a signcrypted text ; Specifically, assume the signcryption user is Alice and the unsigncrypting user is Bob. Then, the public key of Alice is , and the public key of Bob is ; If for all there is , it is considered that the message already exists. The Bloom filter returns 1, and Alice cannot signcrypt this message , and an error symbol is returned; Otherwise, the Bloom filter returns 0, which means that Alice has at least one subscript that can make its partial private key , where , is a natural number; Alice randomly selects a subscript from the set , and its partial private key ; Randomly select two elements and from , calculate , , , , , where is the identity information of Bob, represents the exclusive OR operation; Alice sends the signcrypted text to Bob;

[0026] Step 7, Unsigncryption: After receiving the signcrypted text , Bob calculates the hash value and judges it against the value ; If , Bob refuses to perform unsigncryption; If , Bob calculates using its own partial private key , and calculates , then the plaintext message .

Claims

1. A certificateless puncturable signcryption method against long-range attacks in blockchain, characterized in that, It includes the following steps: Step 1, System Initialization and Parameter Establishment: In the system initialization phase, the set of authoritative nodes in the blockchain needs to set the security parameters of the system and establish the public parameters required for the entire system and the master key ; Specifically include: select a security parameter , two additive cyclic groups of prime order q and , and a multiplicative cyclic group of prime order q , define an asymmetric bilinear mapping , let the generators of the additive cyclic groups and be and respectively, and there is ; randomly select five collision-resistant cryptographic hash functions , , , , , where represents natural numbers, represents the set of prime numbers, represents a string composed of 0s and 1s of arbitrary length, represents the security parameter within the length of the 0 and 1 combination string; randomly select an element from as the master key of the system, and calculate the master public key of the system; initialize a Bloom filter, select two natural numbers , randomly select hash functions , and generate a uniform distribution on the array . Initialize an array with a length of , and set the function set ; the set of authoritative nodes secretly stores and , and publicly disclose the public parameters ; Step 2, User partial private key extraction: By using the master key , the public parameters and the array associated with the user identity , the authoritative node set calculates , and sends to the user through a secure channel; Step 3, punctured key update: By using the master key , public parameters , elements , an array associated with the user identity and partial private key , the set of authoritative nodes performs punctured update on the user's partial private key to generate a punctured key ; specifically including: adding the element to the set of Bloom filters, calculating , for all , setting , while other positions in the array remain 0, and returning the updated array ; for the partial private key , for each , when , defining , when , defining , where represents the -th subscript in the array , represents the error symbol; the set of authoritative nodes calculates the user's punctured key , and sends to the user through a secure channel; Step 4, Secret value extraction: By using the array and the public parameter , the user randomly selects an element from , and calculates as his own secret value; Step 5, Public key generation: By using the public parameters and the secret value , the user calculates as its own public key; Step 6, Signcryption: The signcryption user signcrypts the message by using its own private key and the public key of the unsigncryption user to generate a signcrypted text ; Specifically, assume the signcryption user is Alice and the unsigncryption user is Bob. Then, the public key of Alice is , and the public key of Bob is ; If for all there is , it is considered that the message already exists. The Bloom filter returns 1, and Alice cannot signcrypt this message , and an error symbol is returned; Otherwise, the Bloom filter returns 0, meaning that Alice has at least one subscript that can make its partial private key , where , is a natural number; Alice randomly selects a subscript from the set , and its partial private key ; Randomly select two elements and from , calculate , , , , , where is the identity information of Bob, represents the XOR operation; Alice sends the signcrypted text to Bob; Step 7, Decrypt and verify the signature: After Bob receives the signed ciphertext , calculate the hash value, and compare its hash value with the value for judgment; if , Bob refuses to decrypt and verify the signature; if , Bob calculates through his own partial private key , and calculates , then the plaintext message is .

Citation Information

Cited By

  • Attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations

    CN120956419A