Blockchain and privacy protection-based data security sharing method and system for ship internet of things

By employing blockchain and privacy-preserving data security sharing methods, and utilizing hybrid encryption and proxy re-encryption technologies, the problems of user privacy information leakage and data integrity in ship Internet of Things (SIL) have been solved, achieving efficient data sharing and storage security, and improving system stability and service quality.

CN120602924BActive Publication Date: 2026-02-17ANHUI NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510824930.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2026-02-17
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

In existing ship Internet of Things (SIoT) solutions, waterway information stored on edge servers or cloud servers is vulnerable to attacks, leading to the leakage of user privacy information. Furthermore, the communication environment is unstable, affecting data integrity and security.

Method used

It adopts a data security sharing method based on blockchain and privacy protection, initializes data through a key management center, uses hybrid encryption and proxy re-encryption technology, combined with a blockchain storage model, to ensure the integrity and reliability of data transmission and storage, and uses identity signature technology to verify and track malicious behavior.

Benefits of technology

It improves the security and stability of data sharing, prevents attackers from speculating on user privacy information, ensures information integrity and reliability, reduces blockchain overhead, and achieves efficient message encryption and decryption and quality of service.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602924B_ABST
    Figure CN120602924B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on blockchain and privacy protection's ship internet of things data security sharing method and system, wherein the method comprises: key management center initialization data, prestore symmetric key k and pseudonym material x1 for each offshore equipment, and send private key to offshore equipment, send shared private key and identity key to channel base station, send private key to cloud server;Offshore equipment generates pseudonym using its own pseudonym material x1, uses hybrid encryption means to mix encrypt shared information into ciphertext, then signs the ciphertext, and finally sends the data report of ciphertext digital signature to channel base station.The method is used, can prevent attacker from using data report to speculate user's travel path and other private information, can guarantee the integrity and reliability of shared information in transmission and storage process, while establishing a perfect sharing feedback mechanism, greatly improve the stability of entire sharing system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent transportation systems technology, and more specifically, to a method and system for secure data sharing in the Internet of Ships based on blockchain and privacy protection. Background Technology

[0002] With the increasing prevalence of intelligent transportation systems, the Internet of Ships (IoS), as an important component of these systems, has also experienced rapid development in recent years, playing a crucial role in improving traffic efficiency and safety. One of the main functions of IoS is an information-sharing mechanism among nearshore equipment. This mechanism relies on the intelligent detection devices of nearshore equipment to monitor waterway conditions in real time and quickly disseminate the collected data to other nearshore equipment in the network, thereby supporting dynamic route planning and optimizing traffic flow management.

[0003] In existing ship-to-ship (STS) solutions, waterway information is typically stored on edge servers or cloud servers, which are often considered semi-trusted, potentially compromising the integrity of the information. Furthermore, the unstable communication environment in STS may expose user privacy information (coastal equipment location, routes, and schedules) to attackers. If attackers obtain this sensitive information, it could severely damage their interests and hinder the future development of STS.

[0004] Therefore, providing a blockchain-based and privacy-protected method and system for secure data sharing in ship networks that can effectively solve the above-mentioned technical problems during use is a problem that this invention urgently needs to solve. Summary of the Invention

[0005] The purpose of this invention is to provide a method and system for secure data sharing in the Internet of Ships based on blockchain and privacy protection. This method and system can prevent attackers from using data reports to infer users' travel routes and other private information, while ensuring the integrity and reliability of shared information during transmission and storage. At the same time, a sound sharing feedback mechanism is established, which greatly improves the stability of the entire sharing system.

[0006] To achieve the above objectives, the present invention provides a method for secure data sharing in a ship network based on blockchain and privacy protection, the method comprising:

[0007] Step S101: The key management center initializes the data, pre-stores the symmetric key k and pseudonym material x1 for each offshore device, and sets the private key... Send to offshore equipment to share private key and identity key Send the private key SSK to the airway base station. CS Send to the cloud server;

[0008] Step S102, the offshore equipment generates a pseudonym using its own pseudonym material x1. The shared information m is encrypted into ciphertext using a hybrid encryption method. Then the ciphertext The data is signed and then sent to the airway base station with the encrypted digital signature.

[0009] Step S103: After receiving the data report sent by the near-shore equipment, the waterway base station performs signature verification on the data report; wherein,

[0010] If the signature verification passes, proceed to step S104; otherwise, discard the data report.

[0011] In step S104, the airway base station decrypts the data report for the first time to obtain a randomly selected symmetric encryption key d. i,1 After the first step of decryption is completed, the airway base station performs proxy re-encryption on the original ciphertext ED to form a new data report and signature, and sends it to the cloud server.

[0012] Step S105: After receiving the new data report sent by the airway base station, the cloud server performs signature verification on the new data report; wherein,

[0013] If the signature verification passes, proceed to step S106; otherwise, discard the data report.

[0014] In step S106, the cloud server uses its shared private key to decrypt the original ciphertext ED, stores the encrypted original data, and returns the stored index value to the airway base station.

[0015] In step S107, the airway base station publishes the index value and shared data information to the blockchain.

[0016] Preferably, when offshore equipment wants to obtain shared information, the method further includes:

[0017] In step S108, the offshore equipment seeking to obtain shared information first sends a data request to the waterway base station and digitally signs the data request; the waterway base station then verifies the signature.

[0018] If the signature verification passes, the airway base station retrieves the data from the blockchain based on RoudID and TS4; otherwise, the data request is discarded.

[0019] In step S109, after the airway base station retrieves the data, it requests data from the cloud server based on the index. If no response is received, it reports malicious behavior by the cloud server to a trusted third-party organization. If a response is received, h′ is calculated. ED =H0(ED), by judging the equation h′ ED=h ED The check determines whether the original ciphertext ED has been tampered with. If there are no issues, then ED is encrypted into ciphertext. Send to offshore equipment.

[0020] Step S110, the offshore equipment receives the encrypted message. First, the original ciphertext ED is decrypted using the shared private key. Then, the message m is decrypted using the key k from the tamper-proof device. If the offshore equipment detects falsified information, it reports to a trusted organization and provides a pseudonym for the shared information. The trusted organization then calculates... To obtain real identities and hold those responsible for malicious acts accountable, among other things... This is the true identity of the offshore equipment. and Together, they form the pseudonym for the offshore equipment, and x2 is one of the system's master keys.

[0021] Preferably, step S108 includes the following steps:

[0022] In step S1081, when offshore equipment wants to obtain shared information, it first sends a data request to the waterway base station and digitally signs the data request. in RoudID is a alias for the target region. j,1 It is a random number, and x1 is the system master key. TS4 is the full pseudonym for offshore equipment; TS4 is the current timestamp.

[0023] Step S1082, the airway base station according to Verify the signature, where eSigPIDODj,P is a bilinear pairing operation, PK2 is one of the system public keys, and P,Q are generators of group G.

[0024] Preferably, in step S103, bilinear pairing authentication is performed on the data report using the following formula:

[0025]

[0026]

[0027] Where P is the generator of □, TS is the current timestamp, PK2 is the public key issued by the key management center, e() is the bilinear pairing function, H0 is the hash function, and G is a cyclic multiplicative group. It is a mixed encrypted ciphertext sent by offshore equipment, and Type is the type of data sent.

[0028] Preferably, step S104 includes the following steps:

[0029] Step S1041, the airway base station uses the shared private key of the airway base station. The encrypted shared data is decrypted for the first time to obtain a randomly selected symmetric encryption key d. i,1 and the original ciphertext ED

[0030] Step S1042: After the first step of decryption is completed, the airway base station performs proxy re-encryption on the original ciphertext ED to form ciphertext.

[0031] Step S1043, select a random number r z,1 Perform digital signature calculation on the aggregated ciphertext:

[0032] and

[0033] in, The private key for the airway base station (BS). in, It is a hybrid encrypted ciphertext for airway base stations. This is the true identity of the airway base station. TS2 is a pseudonym for offshore equipment. and Together, they form the digital signature of the airway base station. z,1 It is a random number selected by the airway base station. The ciphertext and digital signature are packaged into a data report. Then, it is sent to the cloud server.

[0034] Preferably, step S105 uses the following formula to verify the signature of the new data report:

[0035]

[0036] Wherein, ω is a pre-calculated bilinear pairing calculation. It is a partial digital signature of the airway base station, and PK1 is a partial system public key.

[0037] This invention also provides a ship network data security sharing system based on blockchain and privacy protection, the system comprising:

[0038] The key management center control module is used to initialize the key management center data, pre-store the symmetric key k and pseudonym material x1 for each offshore device, and store the private key. Send to offshore equipment to share private key and identity key Send the private key SSK to the airway base station. CS Send to the cloud server;

[0039] The offshore equipment encryption module is used to generate pseudonyms using pseudonym material x1 from offshore equipment. The shared information m is encrypted into ciphertext using a hybrid encryption method. Then the ciphertext The data is signed and then sent as a digitally signed encrypted report to the airway base station.

[0040] The waterway base station verification module is used to verify the signature of data reports received from near-shore equipment; among other things...

[0041] If the signature verification is successful, the cloud server uses its shared private key to decrypt the original ciphertext ED, stores the encrypted original data, and returns the stored index value to the airway base station; otherwise, the data report is discarded.

[0042] The information publishing module is used to publish index values ​​and shared data information to the blockchain using airway base stations.

[0043] Preferably, the system further includes:

[0044] The shared information acquisition module is used to send data requests to the airway base station and digitally sign the data requests, which are then verified by the airway base station; among them,

[0045] If the signature verification passes, the airway base station retrieves the data from the blockchain based on RoudID and TS4; otherwise, the data request is discarded.

[0046] The malicious operation tracking module, after retrieving data from the airway base station, requests data from the cloud server based on the index. If no response is received, it reports malicious behavior by the cloud server to a trusted third-party organization. If data is received, it calculates h′. ED =H0(ED), by judging the equation h′ ED =h ED Whether the original ciphertext ED has been tampered with is determined by whether the ciphertext has been found. If not, the airway base station reports to a trusted agency for punishment.

[0047] According to the above technical solution, the ship network data security sharing method based on blockchain and privacy protection provided by this invention adopts hybrid encryption and blockchain technology to protect the secure sharing of information of near-shore equipment. At the same time, it achieves efficient encryption of shared information, which not only improves the efficiency of message encryption and decryption in the sharing process, but also improves service quality. In addition, it uses blockchain technology to realize a new storage mode, storing the original ciphertext in the cloud server and storing the ciphertext data certificate on the blockchain. This not only reduces the overhead of the blockchain, but also ensures the integrity and reliability of data in the storage process. Furthermore, the method uses identity signature technology with batch verification to realize data integrity and identity authentication in the communication process, preventing attackers from impersonating legitimate users to send false data reports or tampering with correct data reports during data report transmission.

[0048] Other features and advantages of the present invention will be described in detail in the following detailed description section; and all parts not covered in the present invention are the same as or can be implemented using the prior art. Attached Figure Description

[0049] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the following detailed description to explain the invention, but do not constitute a limitation thereof. In the drawings:

[0050] Figure 1 This is a flowchart illustrating a preferred embodiment of the present invention for a secure data sharing method for ship-to-ship networks based on blockchain and privacy protection.

[0051] Figure 2 This is a flowchart of a preferred embodiment of the present invention for a secure data sharing method for ship-to-ship networks based on blockchain and privacy protection.

[0052] Figure 3 This is a flowchart of data messages in a preferred embodiment of the ship network data security sharing method based on blockchain and privacy protection provided by the present invention;

[0053] Figure 4 This is a block diagram of a modular structure of a ship network data security sharing system based on blockchain and privacy protection, provided in a preferred embodiment of the present invention.

[0054] Figure 5 This is a system framework diagram of secure data sharing for ship-to-ship networking based on blockchain and privacy protection, provided in a preferred embodiment of the present invention. Detailed Implementation

[0055] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0056] like Figure 1-3 As shown, this invention provides a method for secure data sharing in a ship network based on blockchain and privacy protection, the method comprising:

[0057] Step S101: The key management center initializes the data, pre-stores the symmetric key k and pseudonym material x1 for each offshore device, and sets the private key... Send to offshore equipment to share private key and identity key Send the private key SSK to the airway base station. CS Send to the cloud server;

[0058] Step S102, the offshore equipment generates a pseudonym using its own pseudonym material x1. The shared information m is encrypted into ciphertext using a hybrid encryption method. Then the ciphertext The data is signed and then sent to the airway base station with the encrypted digital signature.

[0059] Step S103: After receiving the data report sent by the near-shore equipment, the waterway base station performs signature verification on the data report; wherein,

[0060] If the signature verification passes, proceed to step S104; otherwise, discard the data report.

[0061] In step S104, the airway base station decrypts the data report for the first time to obtain a randomly selected symmetric encryption key d. i,1 After the first step of decryption is completed, the airway base station performs proxy re-encryption on the original ciphertext ED to form a new data report and signature, and sends it to the cloud server.

[0062] Step S105: After receiving the new data report sent by the airway base station, the cloud server performs signature verification on the new data report; wherein,

[0063] If the signature verification passes, proceed to step S106; otherwise, discard the data report.

[0064] In step S106, the cloud server uses its shared private key to decrypt the original ciphertext ED, stores the encrypted original data, and returns the stored index value to the airway base station.

[0065] In step S107, the airway base station publishes the index value and shared data information to the blockchain.

[0066] Preferably, when offshore equipment wants to obtain shared information, the method further includes:

[0067] In step S108, the offshore equipment seeking to obtain shared information first sends a data request to the waterway base station and digitally signs the data request; the waterway base station then verifies the signature.

[0068] If the signature verification passes, the airway base station retrieves the data from the blockchain based on RoudID and TS4; otherwise, the data request is discarded.

[0069] In step S109, after the airway base station retrieves the data, it requests data from the cloud server based on the index. If no response is received, it reports malicious behavior by the cloud server to a trusted third-party organization. If a response is received, h′ is calculated. ED =H0(ED), by judging the equation h′ ED =h ED The check determines whether the original ciphertext ED has been tampered with. If there are no issues, then ED is encrypted into ciphertext. Send to offshore equipment.

[0070] Step S110, the offshore equipment receives the encrypted message. First, the original ciphertext ED is decrypted using the shared private key. Then, the message m is decrypted using the key k from the tamper-proof device. If the offshore equipment detects falsified information, it reports to a trusted organization and provides a pseudonym for the shared information. The trusted organization then calculates... To obtain real identities and hold those responsible for malicious acts accountable, among other things... This is the true identity of the offshore equipment. and Together, they form the pseudonym for the offshore equipment, and x2 is one of the system's master keys.

[0071] Preferably, step S108 includes the following steps:

[0072] In step S1081, when offshore equipment wants to obtain shared information, it first sends a data request to the waterway base station and digitally signs the data request. in RoudID is a alias for the target region. j,1 It is a random number, and x1 is the system master key. TS4 is the full pseudonym for offshore equipment; TS4 is the current timestamp.

[0073] Step S1082, the airway base station according to Verify the signature, where eSigPIDODj,P is a bilinear pairing operation, PK2 is one of the system public keys, and P,Q are generators of group G.

[0074] Preferably, in step S103, bilinear pairing authentication is performed on the data report using the following formula:

[0075]

[0076] Where P is The generator is TS, which is the current timestamp; PK2 is the public key issued by the key management center; e() is the bilinear pairing function; H0 is the hash function; and G is a cyclic multiplicative group. It is a mixed encrypted ciphertext sent by offshore equipment, and Type is the type of data sent.

[0077] Preferably, step S104 includes the following steps:

[0078] Step S1041, the airway base station uses the shared private key of the airway base station. The encrypted shared data is decrypted for the first time to obtain a randomly selected symmetric encryption key d. i,1 and the original ciphertext ED

[0079] Step S1042: After the first step of decryption is completed, the airway base station performs proxy re-encryption on the original ciphertext ED to form ciphertext.

[0080] Step S1043, select a random number r z,1 Perform digital signature calculation on the aggregated ciphertext:

[0081] and

[0082] in, The private key for the airway base station (BS). in, It is a hybrid encrypted ciphertext for airway base stations. This is the true identity of the airway base station. TS2 is a pseudonym for offshore equipment. and Sig BSz,2 Together, they form the digital signature of the airway base station. z,1 It is a random number selected by the airway base station. The ciphertext and digital signature are packaged into a data report. Then, it is sent to the cloud server.

[0083] Preferably, step S105 uses the following formula to verify the signature of the new data report:

[0084]

[0085] Wherein, ω is a pre-calculated bilinear pairing calculation. It is a partial digital signature of the airway base station, and PK1 is a partial system public key.

[0086] In the above scheme, the following specific implementation method is provided to illustrate the present invention:

[0087] 1. Scheme initialization:

[0088] TEC, as a trusted registration entity, is responsible for the initialization of the entire system. First, TEC executes the security function based on the input security parameter λ. Generate (P,Q,G1,G) T Secondly, TEC selects three cryptographic hash functions H, H0, H1, where, At the same time, TEC selects two security parameters x1 and x2 as the system master key, then the system public key is PK1 = x1·P, PK2 = x2·P, and calculates the bilinear pairing function ω = e(P,P).

[0089] During the user registration phase, TEC selects a safe, large prime number. As a symmetric encryption key, it is stored in the tamper-proof device (TPD) of all offshore equipment. Furthermore, TEC will also monitor the identity of offshore equipment. The identity password (PWD) and master key x2 are pre-stored in the TPD. Finally, TEC calculates the identity password for each user. SSK CS , Forward it to the respective entities.

[0090] 2. Data upload stage:

[0091] Offshore equipment regularly generates data reports and uploads them to the waterway base station for auxiliary sharing. The specific data report generation steps are as follows:

[0092] 2.1: When offshore equipment shares data, in order to protect its privacy, it uses random numbers r i,1 Generate your own kana, as follows:

[0093]

[0094] 2.2: Based on the hybrid encryption algorithm, the offshore equipment first uses symmetric encryption to encrypt the original message m, i.e., ED = AES. k (m), where AES is a symmetric encryption algorithm. Then, a random number d is selected. i,1 Encrypt the key k to generate ciphertext:

[0095]

[0096] Enc is the RSA encryption algorithm; and it calculates...

[0097] 2.3: Select the current timestamp and calculate the signature data. and

[0098] 2.4: Finally, the offshore equipment sends a data report. Give the airway base station BS z .

[0099] 3. Data storage:

[0100] The waterway base station receives data packets sent by near-shore equipment. At this time, data integrity checks and proxy re-encryption are performed before storage. The specific steps are as follows:

[0101] 3.1: The airway base station uses the system's master key pair to perform bilinear pairing verification on data packets:

[0102]

[0103] 3.2: After verification, the airway base station processes the encrypted message. Decrypt the message and calculate the ciphertext digest:

[0104]

[0105] Dec and DES are the RSA decryption algorithm and the symmetric decryption algorithm, respectively.

[0106] 3.3: After parsing the ciphertext, the airway base station selects a random number r. z,1 and d z,1 The proxy performs re-encryption and signing before transmitting the data to the cloud server. Details are as follows:

[0107]

[0108] After completing the above operations, send the data packet. Give it to the cloud server.

[0109] 3.4: After receiving the data packet, the cloud server first verifies it by calculating... The signature data is obtained, and then bilinear pairing verification is performed. After successful verification, the cloud server uses its own private key SSK. CS calculate Subsequently, through calculation Obtain the original ciphertext. Finally, use... Store the data in the form of a 5-tuple and return the index to the airway base station.

[0110] 4. Data Sharing Phase

[0111] After the airway base station receives the index transmitted by the CS, it calculates a signature for blockchain consensus, and then uploads the shared data information to the blockchain. The specific steps are as follows:

[0112] 4.1: The airway base station selects a random number r. z,2 Calculate signature data

[0113]

[0114] Then sign It is published to the blockchain for other nodes to verify its integrity.

[0115] 4.2: Other blockchain nodes verify the uploaded data. First, they calculate... Then, bilinear pairing calculations were performed for verification. Upload is allowed after verification.

[0116] 4.3: Once the airway base station receives the consensus result, it will send the data packet... Write it on the blockchain, where

[0117] 5. Data Request Phase

[0118] When other offshore equipment wants to access shared information, it first sends a request to a nearby navigation channel base station, which then assists the vehicle in completing the information sharing. The specific steps are as follows:

[0119] 5.1: Offshore equipment makes requests based on the target region and data type, and then performs signature calculation on the requests. in Finally, a request data packet is sent to the airway base station.

[0120] 5.2: The airway base station received the data packet. First calculate Bilinear paired verification was then performed. If the verification is successful, retrieve the data from the blockchain using RoudID and TS4.

[0121] 5.3: After retrieving data from the blockchain, the airway base station requests data ED from the cloud server based on the index. Calculate h′. ED=H0(ED) to determine if ED has been tampered with. Then, choose a random number d. y,1 Perform hybrid encryption, and then encrypt the data. Send to the requesting offshore device. The specific encryption process is as follows:

[0122]

[0123] 5.4: Offshore equipment received Afterwards, decryption calculations are performed to obtain the original encrypted data ED, which is then decrypted using the key k stored in the tamper-proof device. The specific process is as follows:

[0124]

[0125] 6. Malicious Operation Tracking Phase

[0126] 6.1: By judging h ED =h′ ED Whether the equation holds true is used to determine if there is malicious activity when the cloud server stores data. If it does not hold true, the airway base station reports to a trusted agency for punishment.

[0127] 6.2: If the requesting offshore equipment discovers an error in the shared information, it will provide the trusted authority with the pseudonym of the information provider. The trusted authority will then calculate... according to Those responsible will be held accountable.

[0128] like Figure 4-5 As shown, the present invention also provides a system corresponding to the above method, namely a ship network data security sharing system based on blockchain and privacy protection, the system comprising:

[0129] Key Management Center Control Module 1 is used to initialize data for the Key Management Center, pre-store symmetric key k and pseudonym material x1 for each offshore device (OD), and store the private key. Send to offshore equipment to share private key and identity key Send the private key SSK to the airway base station (BS). CS Send to the cloud server (CS);

[0130] Offshore Equipment Encryption Module 2 is used to generate pseudonyms using pseudonym material x1 from offshore equipment (OD). The shared information m is encrypted into ciphertext using a hybrid encryption method. Then the ciphertext The data is signed and then sent as a digitally signed encrypted report to the airway base station.

[0131] Channel base station verification module 3 is used to receive OD from near-shore equipment.i After sending the data report, a signature verification is performed on the data report; among which,

[0132] If the signature verification is successful, the cloud server uses its shared private key to decrypt the original ciphertext ED, stores the encrypted original data, and returns the stored index value to the airway base station; otherwise, the data report is discarded.

[0133] Information publishing module 4 is used to publish index values ​​and shared data information to the blockchain using airway base stations.

[0134] In a preferred embodiment of the present invention, the system further includes:

[0135] The shared information acquisition module 5 is used to send data requests to the airway base station, digitally sign the data requests, and have the airway base station verify the signatures; wherein,

[0136] If the signature verification passes, the airway base station retrieves the data from the blockchain based on RoudID and TS4; otherwise, the data request is discarded.

[0137] The malicious operation tracking module 6, after retrieving data from the airway base station, requests data from the cloud server based on the index. If no response is received, it reports malicious behavior by the cloud server to a trusted third-party organization. If a response is received, it calculates h′. ED =H0(ED), by judging the equation h′ ED =h ED Whether the original ciphertext ED has been tampered with is determined by whether the ciphertext has been found. If not, the airway base station reports to a trusted agency for punishment.

[0138] In summary, the system provided by this invention employs hybrid encryption and blockchain technology to protect the secure sharing of information from offshore equipment. It achieves efficient encryption of shared information, improving both message encryption / decryption efficiency and service quality. Furthermore, it utilizes blockchain technology to implement a novel storage model, storing the original ciphertext on a cloud server and the ciphertext data credentials on the blockchain. This reduces blockchain overhead and ensures efficient data integrity and reliability during storage. In addition, the method employs batch-verified identity signature technology to achieve data integrity and authentication during communication, preventing attackers from impersonating legitimate users to send false data reports or tampering with correct data reports during data report transmission.

[0139] The preferred embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the specific details of the above embodiments. Within the scope of the technical concept of the present invention, various simple modifications can be made to the technical solution of the present invention, and these simple modifications all fall within the protection scope of the present invention.

[0140] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, the present invention will not describe the various possible combinations separately.

[0141] Furthermore, various different embodiments of the present invention can be combined in any way, as long as they do not violate the spirit of the present invention, they should also be regarded as the content disclosed by the present invention.

Claims

1. A blockchain and privacy protection based ship internet of things data security sharing method, characterized in that, The method comprises: Step S101, the key management center initializes data, pre-stores symmetric key k and pseudonym material x1 for each offshore device, and sends the private key to the offshore device, sends the shared private key and the identity key to the channel base station, and sends the private key SSK CS to the cloud server; Step S102, the offshore device generates a pseudonym by using its own pseudonym material x1 The shared information m is hybrid-encrypted into ciphertext using hybrid encryption means The ciphertext is then signed and finally the digitally signed data of the ciphertext is reported to the channel base station; Step S103, after the channel base station receives the data report sent by the offshore equipment, the data report is verified by signature; wherein, If the signature verification is passed, step S104 is executed, otherwise the data report is discarded; Step S104, the channel base station first decrypts the data report to obtain the randomly selected symmetric encryption key d i,1 and the original ciphertext ED. After the first decryption is completed, the channel base station proxy re-encrypts the original ciphertext ED to form a new data report and signature, and sends to the cloud server; Step S105, after the cloud server receives the new data report sent by the channel base station, the new data report is verified by signature; wherein, If the signature verification is passed, step S106 is executed, otherwise the data report is discarded; Step S106, the cloud server decrypts the original ciphertext ED by using its own shared private key, stores the encrypted original data, and returns the stored index value to the channel base station; Step S107, the channel base station publishes the index value and shared data information to the block chain.

2. The blockchain and privacy protection based ship internet of things data security sharing method according to claim 1, characterized in that, When the offshore equipment wants to obtain shared information, the method further comprises: Step S108, the offshore equipment that wants to obtain shared information first sends a data request to the channel base station, and the data request is digitally signed, and the channel base station performs signature verification; wherein, If the signature verification is passed, the channel base station retrieves data in the block chain according to RoudID and TS4; otherwise, the data request is discarded; RoudID is a channel network number, and TS4 is a time stamp, used to record the time of publishing information; Step S109, after the channel base station retrieves the data, it will request data from the cloud server according to the index, if no reply, report to the third party trusted agency that the cloud server has malicious behavior, if reply data, calculate h ′ ED =H0(ED), by judging the equation h ′ ED =H0(ED), by judging the equation h ED whether the original ciphertext ED is tampered, if all is no problem, then encrypt ED into ciphertext send to offshore equipment; index is the value data stored in the index of the cloud server, find data according to the index, improve data retrieval efficiency; H0 is a hash function; Step S110, the offshore device receives the ciphertext First, using its own shared private key to decrypt the original ciphertext ED, and at this time using the key k in the tamper-proof device to decrypt the message m, if the offshore device finds that the information is false, it reports the trusted agency and provides the pseudonym of the shared information, the trusted agency calculates to obtain the real identity, and conducts the accountability of malicious behavior, wherein is the real identity of the offshore device, and together constitute the pseudonym of the offshore device, and x2 is one of the system master keys; represents the exclusive or operation in the computer, and H represents a hash function.

3. The blockchain and privacy protection based ship internet of things data security sharing method according to claim 2, characterized in that, The step S108 comprises the following steps: Step S1081, when the offshore device wants to acquire the shared information, it will first send a data request to the channel base station and digitally sign the data request wherein RoudID is the alias of the target area, r j,1 is a random number, h1 is the system master key, is the pseudonym full name of the offshore device, TS4 is the current timestamp; The symbol || is a connector in a computer, representing character splicing; Step S1082, the channel base station according to verifying the signature, wherein, is a bilinear pairing operation, PK2 is one of the system public keys, and P, Q are generators of the group G.

4. The blockchain and privacy protection based ship internet of things data security sharing method according to claim 3, characterized in that, The data report is verified by signature in the step S103 by the following formula: Wherein, P is the generator of G, TS1 is the time stamp of current time, PK2 is the public key issued by the key management center, e() is a bilinear pairing function, H0 is a hash function, G is a cyclic multiplicative group, Is the hybrid encryption ciphertext sent by the offshore device, Type is the type of the sent data.

5. The blockchain and privacy protection based ship internet of things data security sharing method according to claim 1, characterized in that, The step S104 comprises the following steps: Step S1041, the channel base station uses the shared private key of the channel base station to encrypt the random symmetric encryption key d and the original ciphertext ED Firstly decrypt the encrypted shared data to obtain the randomly selected symmetric encryption key d i,1 and the original ciphertext ED; Step S1042, after the first decryption is completed, the channel base station proxy re-encrypts the original ciphertext ED to form ciphertext is the first part is the second part Step S1043, selecting a random number r z,1 A digital signature is calculated for the aggregated ciphertext: and wherein, is a private key of the channel base station BS, is a bilinear pairing symbol in cryptography, representing a base bilinear operation, wherein, is a channel base station hybrid encryption ciphertext, is a real identity of the channel base station, is a pseudonym of the offshore device, and TS2 is a transmission time stamp, and together constitute a digital signature of the channel base station; r z,1 is a random number selected by the channel base station; and the ciphertext and the digital signature are packaged into a data report and then sent to the cloud server.

6. The blockchain and privacy protection based ship internet of things data security sharing method according to claim 1, characterized in that, The new data report is verified by signature in the step S105 by the following formula: Where ω is a bilinear pairing calculation calculated by the system, is a partial digital signature of the channel base station, PK1 is a partial system public key; ω represents a basic bilinear operation, that is, ω = e(P, Q), P and Q are elements of an elliptic curve, is a partial digital signature of the channel base station, The first digital signature, e is a bilinear pairing operation operator, PK1 is a system public key, The ID of the channel base station, is a partial digital signature of the channel base station, The second digital signature, is the encrypted ciphertext of the channel base station, TS2 is the time stamp, representing the time when the ciphertext is generated, Represents the pseudonym code of the ship, H1 is the code of the hash function.

7. A blockchain and privacy protection based ship internet of things data security sharing system for performing the method of any one of claims 1-6, characterized in that, The system comprises: A key management center control module is configured to initialize data of the key management center, pre-store a symmetric key k and pseudonym material x1 for each offshore device, and send the private key to the offshore device, send the shared private key and the identity key to the channel base station, and send the private key SSK CS to the cloud server. An offshore equipment encryption module for generating a pseudonym using pseudonym material x1 of the offshore equipment The shared information m is hybrid-encrypted into ciphertext using hybrid encryption means The ciphertext is then signed and the digitally signed data report is finally sent to the route base station; A channel base station verification module, configured to, after receiving the data report sent by the offshore equipment, verify the data report by signature; wherein, If the signature verification is passed, control the cloud server to decrypt the original ciphertext ED by using its own shared private key, store the encrypted original data, and return the stored index value to the channel base station, otherwise discard the data report; An information publishing module, configured to publish the index value and shared data information to the block chain by using the channel base station. 8.The blockchain and privacy protection based ship internet of things data security sharing system according to claim 7, characterized in that, The system further comprises: A shared information acquisition module, configured to send a data request to the channel base station, and digitally sign the data request, and the channel base station performs signature verification; wherein, If the signature verification is passed, the channel base station retrieves data in the block chain according to RoudID and TS4; otherwise, the data request is discarded; Malicious operation tracking module, after the channel base station retrieves the data, it will request data from the cloud server according to the index, if no reply, report to the third party trusted agency that the cloud server has malicious behavior, if reply data, calculate h ′ ED =H0(ED), by judging the equation h ′ ED =H0(ED), by judging the equation h ED Whether it is established determines whether the original ciphertext ED is tampered with, if not, the channel base station reports to the trusted agency for punishment.

Citation Information

Patent Citations

  • Private data security sharing method based on block chain

    CN117692227A

  • Security data sharing method with conditional privacy protection in Internet of Vehicles

    CN118233882A