Privacy-preserving data sharing method and device supporting efficient query and access control
By storing access control indexes and security keyword indexes on the blockchain, combined with attribute encryption and searchable encryption, the single point failure and privacy leakage problems in data sharing transactions are solved, efficient query and access control are achieved, and a variety of complex queries are supported, ensuring the reliability and privacy protection of the transaction process.
Patent Information
- Application Number
- CN202510934290.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-07-08
AI Technical Summary
In existing technologies, data sharing transactions rely on trusted third-party platforms, which pose a single point of failure risk, a high risk of privacy leakage, a lack of tamper-proof evidence in the transaction process, low query efficiency and easy leakage of intermediate information, and difficulty in supporting complex queries and access control.
Through attribute encryption and searchable encryption methods, access control indexes and security keyword indexes are stored on the blockchain. Authorized users can query on the service platform and blockchain through query trapdoors. The data owner provides encrypted data locally to ensure that the data does not leave the user's control and record the entire transaction process.
It realizes decentralized data sharing, supports multiple complex queries, reduces blockchain storage overhead, ensures data privacy protection, records the authenticity and reliability of the transaction process, and reduces privacy leaks.
Smart Images

Figure CN120429895B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security and data sharing, and in particular to a privacy-preserving data sharing method based on blockchain that supports efficient query and access control. Background Art
[0002] The development of new technologies such as the Internet of Things and cloud computing has accelerated the application of data. Mining and analyzing massive amounts of data will bring enormous value, a feat already proven in many fields, such as education and healthcare. To extract value from distributed data collected by various internet-connected devices, data sharing transactions are essential, enabling the ability to connect and share data between smart devices at any time. Traditional data trading models typically rely on data trading markets operated by trusted third parties. While these platforms provide an online environment for data commodity transactions, they suffer from significant shortcomings in terms of tracing the entire data flow, quickly resolving transaction disputes, and protecting data privacy. The traditional data trading process involves the data owner storing their encrypted data on a third-party data platform. The data buyer then sends a request to the data owner through the platform and pays the third party for the data. After the platform confirms payment, it sends the data to the data buyer. After the data buyer confirms the data is correct, the platform remits the payment to the data owner. This transaction process has at least the following flaws that limit the application of data sharing:
[0003] (1) The traditional data trading market is controlled by a single entity, prone to single points of failure, and lacks an authoritative and unified data trustworthy circulation infrastructure. Centralized institutions take on too much computing and storage work, and the data owner's data is out of the user's physical control, posing the risk of privacy leakage.
[0004] (2) There is a lack of irreversible transaction evidence at each stage of the transaction process. Due to the lack of such irreversible evidence, there is not enough evidence to hold parties accountable when disputes arise.
[0005] Due to the blockchain's excellent tamper-resistant properties, building a data sharing platform based on it is a promising solution. However, due to the inherent performance limitations of blockchain, balancing privacy protection, query functionality, and blockchain overhead presents challenges. Because secure query mechanisms rely heavily on specific encrypted index structures and complex computations, current methods can only support simple queries, such as single-keyword searches, which severely limits the application scenarios of data sharing. Furthermore, current methods use access control to allow users to access data that meets access policies based on their attributes. However, this often requires querying followed by verification, which is inefficient and prone to leaking intermediate information during interactions.
[0006] Therefore, how to provide a privacy-preserving data sharing method that can support efficient query and access control without the need for a trusted third party and retain traceability-friendly evidence for subsequent accountability is an urgent problem that needs to be solved.
[0007] In view of this, the present invention is proposed. Summary of the Invention
[0008] The purpose of the present invention is to provide a privacy-protected data sharing method and device that supports efficient query and access control, can support multiple query types and access control to reduce privacy leakage, and can truly and accurately record the entire process of data circulation, ensure the authenticity and reliability of information throughout the transaction process, and thus solve the above-mentioned technical problems existing in the prior art.
[0009] The purpose of the present invention is achieved through the following technical solutions:
[0010] A privacy-preserving data sharing method supporting efficient query and access control is used in a data sharing transaction system in which several data owners and several authorized users communicate with a service platform and a blockchain, comprising:
[0011] Step 1: The data owner extracts keywords and file index identifiers from the local data file to be shared, encrypts the file index identifier using attribute encryption to generate an access control index, and uploads it to the blockchain;
[0012] Step 2: The data owner encrypts the keywords using a searchable encryption method to generate a secure keyword index, and uploads and stores the transaction address of the secure keyword index and the corresponding access control index on the blockchain to the service platform;
[0013] Step 3: The data owner generates a corresponding query trap based on the query request sent by the authorized user and returns it to the authorized user;
[0014] Step 4: The authorized user searches the service platform using a query trapdoor to obtain the transaction address of the corresponding access control index on the blockchain returned by the service platform;
[0015] Step 5: The authorized user uses the transaction address to find the corresponding access control index on the blockchain, decrypts the access control index to obtain the file index identifier of the data owner's local data file, and then sends it to the data owner;
[0016] In step 6, the data owner uses the received file index identifier to obtain the corresponding data file from the local computer, encrypts it and sends it to the authorized user, so that the authorized user can obtain the target data after decryption.
[0017] A processing device comprising:
[0018] at least one memory for storing one or more programs;
[0019] At least one processor is capable of executing one or more programs stored in the memory. When the one or more programs are executed by the processor, the processor is enabled to implement the method described in the present invention.
[0020] Compared with the existing technology, the privacy-preserving data sharing method and device provided by the present invention that supports efficient query and access control have the following beneficial effects:
[0021] (1) This method can achieve decentralized data sharing transactions, using blockchain technology to record relevant information during the data circulation process and only storing attribute-encrypted index information on the blockchain, ensuring that the original data of the data owner does not leave the domain. It solves the single point of failure problem of traditional centralized platforms and is a fair and reliable privacy-preserving data sharing solution.
[0022] (2) This method can realize privacy-preserving data search and support many complex queries such as Boolean queries and fuzzy queries. It can meet the diverse query requirements in different application scenarios while ensuring security and efficiency.
[0023] (3) This method considers two important forms of privacy protection in data sharing scenarios, namely, searchable encryption and attribute-based access control, and designs a new data structure Prime Filter to unify the two, thus realizing personalized encrypted search and access control.
[0024] The present invention establishes a mapping relationship between the blockchain and the off-chain, so that only the attribute-encrypted file index needs to be stored on the chain, while complex searches are performed off-chain, which greatly reduces the storage overhead of the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0026] Figure 1 A flowchart of a privacy-preserving data sharing method that supports efficient query and access control provided by an embodiment of the present invention.
[0027] Figure 2 A schematic diagram of a data sharing transaction system used in the method provided in an embodiment of the present invention.
[0028] Figure 3 This is a specific flow chart of the privacy protection data sharing method provided by an embodiment of the present invention.
[0029] Figure 4 This is an example diagram of constructing keyword vectors provided by an embodiment of the present invention.
[0030] Figure 5 An example diagram of a vector representation of an index and trapdoor embedded in a keyword search strategy and access strategy for constructing a privacy-preserving data sharing method provided by an embodiment of the present invention.
[0031] Figure 6 Flowchart of the blockchain search phase of the privacy-preserving data sharing method provided in an embodiment of the present invention.
[0032] Figure 7 A schematic diagram illustrating the time consumption of generating a security keyword index for the privacy-preserving data sharing method provided in an embodiment of the present invention.
[0033] Figure 8 A schematic diagram illustrating the time consumption of query trapdoor generation in the privacy-preserving data sharing method provided in an embodiment of the present invention.
[0034] Figure 9 A schematic diagram illustrating the relationship between the number of data files and the search speed and time consumption of the privacy-preserving data sharing method provided by an embodiment of the present invention.
[0035] Figure 10 A schematic diagram illustrating the relationship between the number of keywords in a query and the search speed and time consumption in the privacy-preserving data sharing method provided by an embodiment of the present invention.
[0036] Figure 11 A schematic diagram illustrating the precise search accuracy of the privacy-preserving data sharing method provided in an embodiment of the present invention.
[0037] Figure 12 A schematic diagram illustrating the fuzzy search accuracy of the privacy-preserving data sharing method provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0038] The following is a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the specific content of the present invention. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments, and do not constitute a limitation of the present invention. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0039] First, the following terms may be used in this article:
[0040] The term “and / or” means that either or both of them can be realized at the same time. For example, X and / or Y includes both “X” or “Y” and “X and Y”.
[0041] The terms "include," "comprises," "contains," "has," or other similar expressions should be interpreted as non-exclusive. For example, "including certain technical features (such as raw materials, components, ingredients, carriers, dosage forms, materials, dimensions, parts, components, mechanisms, devices, steps, procedures, methods, reaction conditions, processing conditions, parameters, algorithms, signals, data, products, or manufactured articles)" should be interpreted as including not only the technical features explicitly listed, but also other technical features known in the art that are not explicitly listed.
[0042] The term "consisting of" excludes any technical features not explicitly listed. If used in a claim, this term renders the claim closed, excluding any technical features other than those explicitly listed, except for conventional impurities associated with them. If this term appears only in a clause of a claim, it limits only the elements explicitly listed in that clause; elements listed in other clauses are not excluded from the claim as a whole.
[0043] Unless otherwise specified or limited, the terms "mounted," "connected," "connect," and "fixed" should be interpreted broadly. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediary; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in this document based on specific circumstances.
[0044] When concentration, temperature, pressure, size or other parameters are expressed in the form of a numerical range, the numerical range should be understood to specifically disclose all ranges formed by the pairing of any upper limit, lower limit, or preferred value within the numerical range, regardless of whether the range is explicitly stated. For example, if a numerical range of "2 to 8" is stated, the numerical range should be interpreted as including ranges of "2 to 7," "2 to 6," "5 to 7," "3 to 4 and 6 to 7," "3 to 5 and 7," "2 and 5 to 7," etc. Unless otherwise specified, the numerical ranges stated herein include both their endpoints and all integers and fractions within the numerical range.
[0045] The terms "center", "longitudinal", "lateral", "length", "width", "thickness", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", "clockwise", "counterclockwise", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings and are only for the convenience and simplification of description, and do not explicitly or implicitly indicate that the device or element referred to must have a specific orientation, be constructed and operate in a specific orientation, and therefore should not be understood as a limitation to this document.
[0046] The scheme provided by the present invention is described in detail below. The contents not described in detail in the examples of the present invention belong to the prior art known to professionals in this field. If specific conditions are not specified in the examples of the present invention, they are carried out according to conventional conditions in the field or conditions recommended by the manufacturer. If the manufacturer of the reagents or instruments used in the examples of the present invention is not specified, they are all conventional products that can be purchased commercially.
[0047] like Figure 1 、 Figure 2 As shown, an embodiment of the present invention provides a privacy-preserving data sharing method that supports efficient query and access control, which is used in a data sharing transaction system in which several data owners and several authorized users are respectively connected to a service platform and a blockchain for communication, including:
[0048] Step 1: The data owner extracts keywords and file index identifiers from the local data file to be shared, encrypts the file index identifier using attribute encryption to generate an access control index, and uploads it to the blockchain;
[0049] Step 2: The data owner encrypts the keywords using a searchable encryption method to generate a secure keyword index, and uploads and stores the transaction address of the secure keyword index and the corresponding access control index on the blockchain to the service platform;
[0050] Step 3: The data owner generates a corresponding query trap based on the query request sent by the authorized user and returns it to the authorized user;
[0051] Step 4: The authorized user searches the service platform using a query trapdoor to obtain the transaction address of the corresponding access control index on the blockchain returned by the service platform;
[0052] Step 5: The authorized user uses the transaction address to find the corresponding access control index on the blockchain, decrypts the access control index to obtain the file index identifier of the data owner's local data file, and then sends it to the data owner;
[0053] In step 6, the data owner uses the received file index identifier to obtain the corresponding data file from the local computer, encrypts it and sends it to the authorized user, so that the authorized user can obtain the target data after decryption.
[0054] Preferably, in step 1 of the above method, encrypting the file index identifier using the attribute encryption method to generate the access control index comprises: encrypting the file index identifier using the attribute encryption method to generate the access control index embedded with the access control policy;
[0055] In step 4, the service platform calculates and compares the query trapdoor with the stored security keyword index, and obtains the transaction address of the access control index on the blockchain that meets the query request and satisfies the user's access control policy and search policy, and returns it to the data owner;
[0056] In step 5, the authorized user decrypts the access control index using his own attribute key to obtain the file index identifier of the data file locally owned by the data owner;
[0057] In step 6, the data owner obtains the corresponding data file from the local computer and encrypts it before sending it to the authorized user in the following manner, including:
[0058] Encrypt the acquired data file, then encrypt the key using the attribute encryption method, and send the encrypted ciphertext data file and the encrypted ciphertext key to the authorized user;
[0059] In step 6, the authorized user obtains the target data after decryption in the following manner, including:
[0060] Decrypt the received ciphertext key according to its own attribute key, and use the decrypted key to decrypt the ciphertext data file to obtain the target data.
[0061] Preferably, in step 1 of the above method, the data owner extracts keywords and file index identifiers from the local data file to be shared in the following manner, encrypts the file index identifier using an attribute encryption method to generate an access control index, and uploads it to the blockchain, including:
[0062] Step 11, initialize system parameters:
[0063] The data owner randomly selects two numbers As the master private key, where is a modulo prime number The reversible element multiplication group under the master private key is Calculate the first element separately With the second element ,in, is a modulo prime number Factorial cyclic group The generator of is a collision-resistant hash function. express The first value in the attribute value set of attribute values, Indicates the attribute space authorized by the data owner The attributes , attribute space , is the bilinear pairing operator on the elliptic curve group; calculated using and Composing the master public key and publish it to all authorized users;
[0064] Step 12: Generate attribute keys:
[0065] The data owner randomly selects a secret value from the set of attributes owned by each authorized user. , through the secret value and computed property keys Bind each attribute of the authorized user to its corresponding attribute value. The attribute key calculation formula is: ,in, is the aggregate secret value and the first Attributes and attribute keys corresponding to attribute values, Both are collision-resistant hash functions. The data owner sends the attribute key to the authorized user who meets the corresponding attribute set; the user attribute set is the attribute space A subset of
[0066] Step 13: Encrypt the file index identifier and upload it to the blockchain:
[0067] Access policy for each data file owned by the data owner The attributes contained in and the attribute values corresponding to the attributes are calculated by continuously aggregating the values of all attributes and corresponding attribute values. , let the index identifier of the data file stored locally on the data owner be , randomly pick another secret value , with a secret value File index identifier Encrypted as access control index ,in, , the data owner will index the access control Upload to the blockchain and store it in the form of key-value pairs in the smart contract. The hash value of the original data used to verify data integrity and correctness is also uploaded to the blockchain along with the access control index, and the transaction address of the access control index on the blockchain is recorded. .
[0068] Preferably, in step 2 of the above method, the data owner encrypts the keywords using a searchable encryption method to generate a secure keyword index, and uploads and stores the transaction address of the secure keyword index and the corresponding access control index on the blockchain to the service platform, including:
[0069] Step 21: Use vectors to represent keywords:
[0070] The data owner converts the keywords of each data file extracted in step 1 into a corresponding bigram set using the 2-gram method. Each bigram set contains all the consecutive two letters that appear in the corresponding keyword.
[0071] For each bigram set, a 26×26-bit keyword vector is used to uniquely represent the corresponding keyword. Each position in the keyword vector represents a possible bigram combination. If the bigram combination exists in the bigram set of a given keyword, the corresponding position in the keyword vector is set to 1, and the remaining positions are set to 0.
[0072] like Figure 4 As shown, for example, if the keyword is "science", its bigram set is .
[0073] Step 22: Build a secure keyword index that supports fuzzy Boolean queries and access control:
[0074] Step 221: Build a keyword index:
[0075] The keyword vectors representing the keywords of each data file obtained in step 21 are mapped into a Prime Filter index vector embedded with keyword search strategy and access strategy through a local sensitive hash function according to a predetermined mapping rule. , the Prime Filter index vector The value at each position is initially 1. For this Prime Filter index vector of any data file The dimensions are constant dimension;
[0076] The predetermined mapping rule is: given two sets of non-intersecting prime number sequences and , map the mapped keyword vector to a prime number sequence through a hash function Insert a prime number in into the Prime Filter index vector In , the access strategy is mapped to another prime number sequence Insert the reciprocal of a prime number in into the Prime Filter index vector middle;
[0077] Step 222, encryption processing:
[0078] The data owner's Prime Filter index vector synthesized in step 221 The encryption process is performed in the following manner: a random string is selected , and randomly select two dimensional reversible matrix ,Will As the key, the Prime Filter index vector is decomposed according to the following rules Decompose into : For any Prime Filter index vector Elements in ], ,if S [j]= 1, then set γ ' [j]= γ '' [j]=γ[j] Otherwise, let γ ' [j] = 1 2 γ [j ] + r , γ '' [j] = 1 2 γ [j ] - r ,in is a random number; then use the reversible matrix encryption Get the encrypted result , the encryption result of data in all directions Add transaction address Get the encrypted result containing the transaction address , upload the encrypted result containing the transaction address to the service platform as the file index identifier of the data file of the data owner Security keyword index.
[0079] Preferably, in step 3 of the above method, the data owner generates a corresponding query trapdoor according to the query request sent by the authorized user and returns it to the authorized user in the following manner, including:
[0080] Step 31: Receive the query expression:
[0081] The data owner receives a Boolean expression consisting of query keywords corresponding to the query content sent by the authorized user;
[0082] Step 32: Build a query trapdoor:
[0083] The data owner constructs a The invention relates to a Prime Filter index vector for embedding keyword search strategy and access strategy of a dimension, specifically: query keywords in Boolean expression are converted into several bigram sets by 2-gram method, several keyword vectors are obtained according to the several bigram sets, and then all keyword vectors are mapped into a Prime Filter index vector for embedding keyword search strategy and access strategy by local sensitive hash function according to predetermined mapping rule; the predetermined mapping rule is: given two sets of non-intersecting prime number sequences and , map the mapped keyword vector to a prime number sequence through a hash function Insert the reciprocal of a prime number in into the Prime Filter index vector to map the access strategy to another prime number sequence Insert a prime number in into the Prime Filter index vector;
[0084] When the query's Boolean expression is a conjunction, the query trapdoor is constructed as follows:
[0085] Let the Prime Filter index vector be , the data owner uses his own key Decompose the Prime Filter index vector according to the following decomposition rules Decompose into : Prime Filter index vector Elements in ], ,if S [j]= 0 settings β ' [j]= β '' [j]= β[j] Otherwise, let β ' [j] = 1 2 β[j] + r ' , β '' [j] = 1 2 β[j] - r ' ,in is a random number; then encryption for , the data owner will Submitting a query request as the authorized user and sending a query trapdoor based on the authorized user's attributes to the authorized user;
[0086] When the Boolean expression of the query is not a conjunction, the Boolean expression of the query is split into several conjunctions. After constructing the query sub-trapgates according to the query trapgate construction method of the conjunction, all the query sub-trapgates are constructed as The vector matrix of dimension is used as the final query trapdoor, where is the number of conjunctions in the disjunctive normal form, is the dimension of the index, 2 means that the conjunctions under the operator and non-operator semantics will be judged separately.
[0087] Preferably, in step 4 of the above method, the authorized user searches the service platform using a query trapdoor in the following manner to obtain the transaction address of the corresponding access control index on the blockchain returned by the service platform, including:
[0088] Step 41, calculate the similarity:
[0089] Allows authorized users to use received query trapdoors Search on the service platform, and the service platform will index all the security keywords stored locally and query trapdoor Do the following inner product calculation: , get the inner product result;
[0090] Step 42, result comparison:
[0091] When the Boolean expression of the query is a conjunction, if the inner product result calculated in step 41 is an integer, it is confirmed that a result that meets the query requirements has been found, and the service platform will set the transaction address of the corresponding result. Return to the authorized user;
[0092] The conditions for successful matching of the Boolean expression of any query are: the inner product result is a matrix with at least one row, the first element of each row is an integer, and the second element is not an integer. If a result that meets the query requirements is found, the service platform will set the transaction address of the corresponding result. Returned to the authorized user.
[0093] Preferably, in step 5 of the above method, the authorized user uses the transaction address to find the corresponding access control index on the blockchain, decrypts the access control index to obtain the file index identifier of the data owner's local data file, and then sends it to the data owner, including:
[0094] Query on the blockchain: Authorized users can query the result set based on the access control index returned by the service platform. Get the corresponding access control index on the blockchain , authorized users calculate based on their own attribute keys , according to the obtained Calculate the file index identifier of the local data file of the data owner , calculate the file index identifiers of all data files Then get the file index identifier set , set the file index identifier Sent to the data owner.
[0095] Preferably, in step 6 of the above method, the data owner uses the received file index identifier to obtain the corresponding data file from the local computer, encrypts it, and sends it to the authorized user in the following manner, including:
[0096] Shared ciphertext data: The data owner sends a set of file index identifiers based on the authorized user. , find the corresponding data file in the locally stored data file, and use the randomly selected key to find the data file Encrypt using symmetric encryption and encrypt the key using general attribute encryption based on the attributes of the authorized user The encrypted ciphertext data file and the encrypted ciphertext key are sent to the authorized user.
[0097] Preferably, in step 6 of the above method, the authorized user is enabled to obtain the target data after decryption in the following manner, including:
[0098] User decryption: After the authorized user receives the encrypted ciphertext data file and the encrypted ciphertext key, he first uses his own attribute key to decrypt the ciphertext key to obtain the plaintext key Then use the key The ciphertext data file is decrypted to obtain the plaintext data file. The hash value of the original data of the plaintext data file is calculated and compared with the hash value on the blockchain. If the comparison results are consistent, it is confirmed that the data file sent by the data owner is correct and the transaction is completed; otherwise, it is confirmed that the data file sent by the data owner is incorrect and the transaction is invalid.
[0099] An embodiment of the present invention further provides a processing device, comprising:
[0100] at least one memory for storing one or more programs;
[0101] At least one processor can execute one or more programs stored in the memory, and when the one or more programs are executed by the processor, the processor can implement the above method.
[0102] An embodiment of the present invention further provides a readable storage medium storing a computer program, which can implement the method of the present invention when executed by a processor.
[0103] In summary, the method of the embodiment of the present invention is a privacy-preserving data sharing method based on blockchain that supports efficient query and access control. It can expand data sharing capabilities and support a variety of complex query types, such as Boolean queries, fuzzy queries, etc.; it supports powerful access control to reduce privacy leakage; and it can truly and accurately record the entire process of data circulation, ensuring the authenticity and reliability of information throughout the entire transaction process.
[0104] In order to more clearly demonstrate the technical solution and technical effects provided by the present invention, the solution provided by the embodiment of the present invention is described in detail with reference to specific embodiments below.
[0105] Example 1
[0106] This embodiment provides a privacy-preserving data sharing method that supports efficient query and access control. The data transaction sharing system of the method is applicable to the following scenarios: Figure 2 As shown, it includes: several data owners, several authorized users, a service platform and blockchain.
[0107] The shared transaction process of this method is as follows Figure 1 、 Figure 3 Shown, including:
[0108] Step 1: The data owner extracts a keyword index from the data to be shared and stores the encrypted keyword index embedded with the access control policy on the blockchain using attribute encryption.
[0109] Step 2: The data owner stores the access control keyword index embedded with the search strategy and access control strategy, encrypted using a searchable encryption method, and the transaction address corresponding to the access control keyword index on the blockchain on the service platform;
[0110] Step 3: The authorized user requests a query trapdoor from the data owner based on their query needs. The data owner generates a corresponding query trapdoor for the authorized user based on the authorized user's request content.
[0111] Step 4: The authorized user submits the query trapdoor to the service platform. The service platform searches for the transaction address of the access control keyword index on the blockchain that meets the user's access control policy and search policy, and returns it to the authorized user.
[0112] Step 5: The authorized user uses these transaction addresses to find the attribute-encrypted access control keyword index on the blockchain, decrypts the access control keyword index using their own attribute key, obtains the file index of the data owner's local data file, and sends the file index to the data owner.
[0113] In step 6, the data owner obtains the corresponding data file from the local data file according to the file index, encrypts the data file, and encrypts the key using the attribute encryption method, and sends the encrypted data file and the encrypted key to the authorized user; the authorized user decrypts the encryption key according to his or her own attribute key, and uses the decrypted key to decrypt the encrypted data file to obtain the target data.
[0114] Throughout the entire process, authorized users can flexibly submit their own query types, such as Boolean queries, fuzzy queries, etc., while data owners can regularly update access control policies. Specifically, the privacy-preserving data sharing method follows the following steps:
[0115] Step 1: Set up an access control keyword index based on attribute encryption and upload it to the blockchain:
[0116] This step is completed by the data owner.
[0117] Step 11: Initialize system parameters:
[0118] The data owner randomly selects two numbers As the master private key, calculate the first element With the second element ,in, Indicates the attribute space authorized by the data owner The attributes , attribute space , Indicates the attributes The first value in the attribute value set of attribute values, is the bilinear pairing operator on the elliptic curve group, is a collision-resistant hash function; set the master public key to And published to authorized users.
[0119] Step 12: Key Generation:
[0120] For each attribute set owned by an authorized user, the data owner randomly selects a secret value , through the secret value And the following calculation binds each attribute of the user to its corresponding attribute value, that is, calculates the attribute key ,in ,in, For collision-resistant hash functions, the data owner sends the attribute key to authorized users who meet the corresponding attribute set.
[0121] Step 13: On-chain index encryption:
[0122] Access policy for each file owned by the data owner The attributes contained in and their corresponding attribute value calculations Let the index identifier of the data stored locally by the data owner be , randomly selected ,encryption Indexing access control keywords ,in , the data owner indexes this access control keyword The data is stored on the chain in the form of key-value pairs in the smart contract. At the same time, the hash value of the original data is also stored on the chain along with this index to provide data integrity and correctness verification, and record the transaction address. .
[0123] The above settings are based on attribute encryption, access control keyword indexing and uploading to the blockchain. The entire process module is implemented based on the cryptographic library of bilinear mapping, and can be implemented by directly calling Python's Pypbc cryptographic library.
[0124] Step 2: Set up a secure keyword index off-chain that supports multiple query types and store it on the service platform:
[0125] This step is completed by the data owner.
[0126] Step 21: Vector representation of keywords (such as Figure 4 shown):
[0127] The data owner converts the keywords of each file extracted in step 1 into a bigram set using the 2-gram method. The bigram set contains all the consecutive two letters that appear in the keyword. For example, the bigram set of the keyword "science" is The keyword is uniquely represented by a 26×26-bit vector. Each position in the vector represents a possible bigram combination. If the bigram combination exists in the bigram set of the given keyword, the position in the vector is set to 1, and the remaining positions are set to 0.
[0128] Step 22: Representation of an index that supports fuzzy Boolean queries and access control (e.g. Figure 5 shown):
[0129] Step 221: Index building:
[0130] The vector representation of the keywords contained in each file obtained in the previous step is mapped into a prime filter using a special type of hash function—locality-sensitive hashing (LSH). A prime filter is a vector whose values at each position are either 1 or a specific prime number or the reciprocal of a prime number. Locality-sensitive hashing is key to implementing fuzzy search. It can hash inputs with similarity within a certain threshold to the same output with a high probability. For example, the misspelled keyword "sciencf" and the correctly spelled keyword "science" are likely to be mapped to the same index vector, prime filter, after locality-sensitive hashing. The prime filter is initially set to 1. Keywords and attribute values are mapped to two mutually exclusive sets of prime numbers using a hash function. During the index construction phase, each keyword is mapped to a prime number from the corresponding set and inserted into the prime filter. Access policies are mapped to the reciprocal of the prime numbers from the corresponding set and inserted into the index vector. The insertion method is to multiply the value at the corresponding position by the value to be inserted.
[0131] This results in a vector representation of the index that embeds the keyword search strategy and access strategy. For any file, the dimension of this vector representation is constant and can be set to dimension.
[0132] Step 222: Encryption processing:
[0133] The vector synthesized by the above steps For encryption, the data owner randomly selects a string , randomly select two dimensional reversible matrix ,Will Keep it as a key. Decompose it according to the following rules Decompose into : For any Prime Filter index vector Elements in ], ,if S [j]= 1, then set γ ' [j]= γ '' [j]=γ[j] Otherwise, let γ ' [j] = 1 2 γ [j ] + r , γ '' [j] = 1 2 γ [j ] - r ,in is a random number; then encryption for , the encryption result of data in all directions Add transaction address Get the encrypted result containing the transaction address , the data owner will encrypt the transaction address The file index identifier representing the data owner uploaded and stored on the service platform Security keyword index.
[0134] Step 3: Query trapdoor construction:
[0135] Authorized users can form a Boolean expression based on the content they want to search for. For example, if an authorized user wants to search for files containing the keywords "apple" and "banana" or "orange" but not "milk", the Boolean expression can be written as The authorized user sends this Boolean expression to the data owner. The present invention allows the authorized user to make a certain degree of spelling errors. For example, if the user spells "apple" as "appld", it will not have a significant impact on the final search results.
[0136] Step 32: Query trapdoor construction (such as Figure 5 shown):
[0137] Take conjunction as an example, After receiving the query expression requested by the authorized user, the data owner constructs a query expression based on the query expression and the user's own attributes using the opposite method of steps 21 and 221. The vector representation of the index of the embedded keyword search strategy and access strategy of the dimension is used to map each keyword in the query to the reciprocal of a prime number in the corresponding set and insert it into the Prime Filter. The access strategy is mapped to a prime number in the corresponding set and inserted into the Prime Filter. Let the Prime Filter be The data owner uses his own key According to the following decomposition rules Decompose into : Prime Filter index vector Elements in ], ,if S [j]= 0 settings β ' [j]= β '' [j]= β[j] Otherwise, let β ' [j] = 1 2 β[j] + r ' , β '' [j] = 1 2 β[j] - r ' ,in is a random number; then encryption for , the data owner will The query request submitted by the user and the query trapdoor based on the user's attributes are sent to the authorized user.
[0138] Note that any Boolean expression can be expressed as a disjunctive normal form consisting of "AND, OR, NOT". When extended to any Boolean expression, it can be split into several conjunctions, and constructed separately according to the trapdoor construction method of the conjunction. The corresponding trapdoors can be constructed as indivual dimensional vector matrix, where is the number of conjunctions in the disjunctive normal form, is the dimension of the index, 2 means judging the conjunctions under the semantics of "AND" and "NOT" separately.
[0139] Step 4: Off-chain platform calculation:
[0140] Step 41: Similarity calculation:
[0141] Authorized users get Then use it to search on the service platform, and the service platform will store all the encrypted indexes previously stored in its database. and Do the following inner product calculation: .
[0142] Step 42: Comparison of results:
[0143] For the conjunction query expression, if the inner product result calculated in step 41 is an integer, it means that a result that meets the query requirements has been found, and the service platform will collect the transaction address of the corresponding result. Return to the authorized user; For any Boolean query expression, the condition for a successful match is that there is at least one row in the calculation result matrix where the first number is an integer and the second number is not an integer. The mathematical principle that can find the correct result through the above calculation method is , that is, the result obtained by the above calculation of the encrypted index and trapdoor is the same as the result of the direct inner product of the unencrypted index and trapdoor. The complete process of off-chain search is as follows Figure 6 shown.
[0144] Step 5: Query the results on the chain:
[0145] Authorized users use the transaction address set returned by the service platform in step 4.2 Get the encrypted file on the chain , that is, in step 13 , authorized users calculate based on their own attribute keys , and finally calculate the file index identifier . Calculate all file index identifiers Then get the file index identifier set , set the file index identifier Sent to the data owner.
[0146] Step 6: Ciphertext data sharing:
[0147] The data owner receives the file index identifier set sent by the authorized user Then, according to the file index identifier set Find the original data file in the local database, and use the randomly selected key Encrypt using the symmetric encryption method AES, and encrypt the key based on the user's attributes using the attribute encryption method in step 13 and sends the encrypted ciphertext data file and the ciphertext key together to the authorized user;
[0148] User decryption:
[0149] The authorized user receives the encrypted ciphertext data file and the encrypted ciphertext key, and first decrypts the ciphertext key with his own attribute key to obtain the plaintext key. Then use the key Decrypt the ciphertext data file to obtain the plaintext data file, calculate the hash value of the data file and compare it with the hash value on the chain. If the results are consistent, it means that the data file sent by the data owner is correct and the transaction is completed; otherwise, it means that the data file sent by the data owner is wrong and the regulatory agency can be requested for arbitration. The transaction is invalid and the authorized user does not need to pay the query fee.
[0150] In specific implementation, Figures 7 to 10 As shown in the figure, the time cost of the method of the present invention was tested. The effect of different file numbers on the time cost of index generation was tested ( Figure 7 ), we can see that as the number of files increases, the time it takes to generate an index increases linearly. When the number of files is 10,000, the time it takes to generate an index is about 20,000ms. We tested the effect of different numbers of keywords in the query on the time it takes to generate a trapdoor ( Figure 8 ), it can be seen that as the number of keywords increases, the trapdoor generation time is basically stable. This is because the trapdoor length designed by the present invention is constant. Figure 9 and Figure 10 The effect of the number of files and keywords on search time is shown. It can be seen that our method has a very fast search speed. An encrypted search of 10,000 files only takes about 400ms. As the number of files and keywords increases, the search time increases approximately linearly. Finally, the accuracy of exact search and fuzzy search is tested. Figure 11 and Figure 12 As can be seen from the above, as the number of keywords increases, both precise search (see Figure 11 ) or fuzzy search (see Figure 12 ), the method of the present invention can always maintain a high accuracy.
[0151] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a program. The program can be stored in a computer-readable storage medium. When executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0152] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by any person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims. The information disclosed in the background technology section of this article is only intended to deepen the understanding of the overall background technology of the present invention, and should not be regarded as an admission or any form of implication that the information constitutes prior art already known to those skilled in the art.
Claims
1. A privacy-preserving data sharing method that supports efficient query and access control, characterized in that: A data sharing transaction system for multiple data owners and multiple authorized users to communicate with a service platform and blockchain, including: Step 1: The data owner extracts keywords and file index identifiers from the local data file to be shared, encrypts the file index identifier using attribute encryption to generate an access control index, and uploads it to the blockchain; Step 2: The data owner encrypts the keywords using a searchable encryption method to generate a secure keyword index, and uploads the transaction address of the secure keyword index and the corresponding access control index on the blockchain to the service platform; including: Step 21: Use vectors to represent keywords: The data owner converts the keywords of each data file extracted in step 1 into a corresponding bigram set using the 2-gram method. Each bigram set contains all the consecutive two letters that appear in the corresponding keyword. For each bigram set, a 26×26-bit keyword vector is used to uniquely represent the corresponding keyword. Each position in the keyword vector represents a possible bigram combination. If the bigram combination exists in the bigram set of a given keyword, the corresponding position in the keyword vector is set to 1, and the remaining positions are set to 0. Step 22: Build a secure keyword index that supports fuzzy Boolean queries and access control: Step 221: Build a keyword index: The keyword vectors representing the keywords of each data file obtained in step 21 are mapped into a Prime Filter index vector embedded with keyword search strategy and access strategy through a local sensitive hash function according to a predetermined mapping rule. , the Prime Filter index vector The value at each position is initially 1. For this PrimeFilter index vector of any data file The dimensions are constant dimension; The predetermined mapping rule is: given two sets of non-intersecting prime number sequences and , map the mapped keyword vector to a prime number sequence through a hash function Insert a prime number in into the Prime Filter index vector In , the access strategy is mapped to another prime number sequence Insert the reciprocal of a prime number in into the Prime Filter index vector middle; Step 222, encryption processing: The data owner's Prime Filter index vector synthesized in step 221 The encryption process is performed in the following manner: a random string is selected , and randomly select two dimensional reversible matrix ,Will As the key, the Prime Filter index vector is decomposed according to the following rules Decompose into : For any Prime Filter index vector Elements in ], ,if 1, then set Otherwise, let , ,in is a random number; then use the reversible matrix encryption Get the encrypted result ; The encryption result of data in all directions Add transaction address Get the encrypted result containing the transaction address , upload the encrypted result containing the transaction address to the service platform as the file index identifier of the data file of the data owner Security keyword index; Step 3: The data owner generates a corresponding query trap based on the query request sent by the authorized user and returns it to the authorized user; Step 4: The authorized user searches the service platform using a query trapdoor to obtain the transaction address of the corresponding access control index on the blockchain returned by the service platform; Step 5: The authorized user uses the transaction address to find the corresponding access control index on the blockchain, decrypts the access control index to obtain the file index identifier of the data owner's local data file, and then sends it to the data owner; In step 6, the data owner uses the received file index identifier to obtain the corresponding data file from the local computer, encrypts it and sends it to the authorized user, so that the authorized user can obtain the target data after decryption.
2. The privacy-preserving data sharing method supporting efficient query and access control according to claim 1, characterized in that: In the step 1, encrypting the file index identifier using the attribute encryption method to generate the access control index is as follows: encrypting the file index identifier using the attribute encryption method to generate the access control index embedded with the access control policy; In step 4, the service platform calculates and compares the query trapdoor with the stored security keyword index, and obtains the transaction address of the access control index on the blockchain that meets the query request and satisfies the user's access control policy and search policy, and returns it to the data owner; In step 5, the authorized user decrypts the access control index using his own attribute key to obtain the file index identifier of the data file locally owned by the data owner; In step 6, the data owner obtains the corresponding data file from the local computer and encrypts it before sending it to the authorized user in the following manner, including: Encrypt the acquired data file, then encrypt the key using the attribute encryption method, and send the encrypted ciphertext data file and the encrypted ciphertext key to the authorized user; In step 6, the authorized user obtains the target data after decryption in the following manner, including: Decrypt the received ciphertext key according to its own attribute key, and use the decrypted key to decrypt the ciphertext data file to obtain the target data.
3. The privacy-preserving data sharing method supporting efficient query and access control according to claim 1 or 2, characterized in that: In step 1, the data owner extracts keywords and file index identifiers from the local data file to be shared in the following manner, encrypts the file index identifier using an attribute encryption method to generate an access control index, and uploads it to the blockchain, including: Step 11, initialize system parameters: The data owner randomly selects two numbers As the master private key, where is a modulo prime number The reversible element multiplication group under the master private key is Calculate the first element separately With the second element ,in, is a modulo prime number Factorial cyclic group The generator of is a collision-resistant hash function. Indicates the attribute space authorized by the data owner The attributes , attribute space , Indicates the attributes The first value in the attribute value set of attribute values, is the bilinear pairing operator on the elliptic curve group; calculated using and Composing the master public key and publish it to all authorized users; Step 12: Generate attribute keys: The data owner randomly selects a secret value from the set of attributes owned by each authorized user. , through the secret value and computed property keys Bind each attribute of the authorized user to its corresponding attribute value. The attribute key calculation formula is: ,in, is the aggregate secret value and the first Attributes and attribute keys corresponding to attribute values, For collision-resistant hash functions, the data owner sends the attribute key to the authorized user who meets the corresponding attribute set; Step 13: Encrypt the file index identifier and upload it to the blockchain: Access policy for each data file owned by the data owner The attributes contained in and the attribute values corresponding to the attributes are calculated by continuously aggregating the values of all attributes and corresponding attribute values. , let the index identifier of the data file stored locally on the data owner be , randomly pick another secret value , with a secret value File index identifier Encrypted as access control index ,in, , the data owner will index the access control Upload to the blockchain and store it in the form of key-value pairs in the smart contract. The hash value of the original data used to verify data integrity and correctness is also uploaded to the blockchain along with the access control index, and the transaction address of the access control index on the blockchain is recorded. .
4. The privacy-preserving data sharing method supporting efficient query and access control according to claim 1, characterized in that: In step 3, the data owner generates a corresponding query trapdoor based on the query request sent by the authorized user and returns it to the authorized user in the following manner, including: Step 31: Receive the query expression: The data owner receives a Boolean expression consisting of query keywords corresponding to the query content sent by the authorized user; Step 32: Build a query trapdoor: The data owner constructs a The invention relates to a Prime Filter index vector for embedding keyword search strategy and access strategy of a dimension, specifically: query keywords in Boolean expression are converted into several bigram sets by 2-gram method, several keyword vectors are obtained according to the several bigram sets, and then all keyword vectors are mapped into a Prime Filter index vector for embedding keyword search strategy and access strategy by local sensitive hash function according to predetermined mapping rule; the predetermined mapping rule is: given two sets of non-intersecting prime number sequences and , map the mapped keyword vector to a prime number sequence through a hash function Insert the reciprocal of a prime number in into the Prime Filter index vector to map the access strategy to another prime number sequence Insert a prime number in into the Prime Filter index vector; When the query's Boolean expression is a conjunction, the query trapdoor is constructed as follows: Let the Prime Filter index vector be , the data owner uses his own key Decompose the Prime Filter index vector according to the following decomposition rules Decompose into :vector Elements in ], ,if 0 settings Otherwise, let , ,in is a random number; then encryption for , the data owner will Submitting a query request as the authorized user and sending a query trapdoor based on the authorized user's attributes to the authorized user; When the Boolean expression of the query is not a conjunction, the Boolean expression of the query is split into several conjunctions. After constructing the query sub-trapgates according to the query trapgate construction method of the conjunction, all the query sub-trapgates are constructed as The vector matrix of dimension is used as the final query trapdoor, where is the number of conjunctions in the disjunctive normal form, is the dimension of the index, 2 means that the conjunctions under the operator and non-operator semantics will be judged separately.
5. The privacy-preserving data sharing method supporting efficient query and access control according to claim 4, characterized in that: In step 4, the authorized user searches the service platform using a query trapdoor in the following manner to obtain the transaction address of the corresponding access control index on the blockchain returned by the service platform, including: Step 41, calculate the similarity: Allows authorized users to use received query trapdoors Search on the service platform, and the service platform will index all the security keywords stored locally and query trapdoor Do the following inner product calculation: , get the inner product result; Step 42, result comparison: When the Boolean expression of the query is a conjunction, if the inner product result calculated in step 41 is an integer, it is confirmed that a result that meets the query requirements has been found, and the service platform will set the transaction address of the corresponding result. Return to the authorized user; The conditions for successful matching of the Boolean expression of any query are: the inner product result is a matrix with at least one row, the first element of a row is an integer, and the second element is not an integer, then it is confirmed that a result that meets the query requirements is found, and the service platform will set the transaction address of the corresponding result. Returned to the authorized user.
6. The privacy-preserving data sharing method supporting efficient query and access control according to claim 5, characterized in that: In step 5, the authorized user uses the transaction address to find the corresponding access control index on the blockchain, decrypts the access control index to obtain the file index identifier of the data owner's local data file, and then sends it to the data owner, including: Query on the blockchain: Authorized users can query the result set based on the access control index returned by the service platform. Get the corresponding access control index on the blockchain , authorized users calculate based on their own attribute keys , according to the obtained Calculate the file index identifier of the local data file of the data owner , calculate the file index identifiers of all data files Then get the file index identifier set , set the file index identifier Sent to the data owner.
7. The privacy-preserving data sharing method supporting efficient query and access control according to claim 6, characterized in that: In step 6, the data owner uses the received file index identifier to obtain the corresponding data file from the local computer, encrypts the data file, and sends it to the authorized user in the following manner, including: Shared ciphertext data: The data owner sends a set of file index identifiers based on the authorized user. , find the corresponding data file in the locally stored data file, and use the randomly selected key to find the data file Encrypt using symmetric encryption and encrypt the key using general attribute encryption based on the attributes of the authorized user The encrypted ciphertext data file and the encrypted ciphertext key are sent to the authorized user.
8. The privacy-preserving data sharing method supporting efficient query and access control according to claim 7, characterized in that: In step 6, the authorized user obtains the target data after decryption in the following manner, including: User decryption: After the authorized user receives the encrypted ciphertext data file and the encrypted ciphertext key, he first uses his own attribute key to decrypt the ciphertext key to obtain the plaintext key Then use the key The ciphertext data file is decrypted to obtain the plaintext data file. The hash value of the original data of the plaintext data file is calculated and compared with the hash value on the blockchain. If the comparison results are consistent, it is confirmed that the data file sent by the data owner is correct and the transaction is completed; otherwise, it is confirmed that the data file sent by the data owner is incorrect and the transaction is invalid.
9. A processing device, characterized in that include: at least one memory for storing one or more programs; At least one processor is capable of executing one or more programs stored in the memory, and when the one or more programs are executed by the processor, the processor is capable of implementing the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Private data sharing and retrieval method, system and equipment based on block chain
CN116663046A
Key privacy data security evidence storage sharing method and device
CN118826998A