Electronic license security protection method and system based on block chain, and storage medium
By employing a blockchain-based electronic certificate security protection method, which utilizes key generation, data encryption, and robust watermarking algorithms, the problems of certificate falsification and information barriers in electronic certificate management platforms are solved. This achieves privacy protection and trusted verification of certificates, ensuring the secure transfer and data sharing of certificates.
Patent Information
- Application Number
- CN202510852061.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-11-14
AI Technical Summary
Existing electronic certificate management platforms suffer from problems such as massive amounts of certificate data, difficulty in verifying the authenticity of certificates, and inability to effectively resolve information barriers and interoperability issues between different certificates, making it difficult to determine the authenticity and integrity of electronic certificates.
A blockchain-based electronic certificate security protection method is adopted, which realizes privacy protection and trusted verification of electronic certificates through key generation, data encryption, index encryption, smart contracts and robust watermarking algorithms. The index is stored using blockchain technology, and version permission changes and user revocation are supported.
It achieves privacy and security protection for electronic certificates, prevents the leakage of certificate privacy and unauthorized use, ensures the immutability and reliable circulation of certificates, and enhances trust and security in data sharing.
Smart Images

Figure CN120956441A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of electronic certificate security, specifically relating to a blockchain-based electronic certificate security protection method, system, and storage medium. Background Technology
[0002] Currently, domestic electronic certificate management platforms mainly rely on third-party certification authorities to establish a central database to store data. They use a centralized database to complete the production, storage, information retrieval, and exchange and sharing of certificates. Data access and update permissions belong to state organs and are shared by various departments, but this cannot effectively solve the information barriers and information interoperability problems between different certificates.
[0003] For example, with the growth in electricity demand, the requirements for the skills and professional qualities of power operators are also constantly increasing. Building a complete training, assessment, and certification management tool has become a core foundation for ensuring the development of the power grid's talent pool. However, during training, due to the large number of trainees and the numerous assessments and certifications, it is difficult to verify the authenticity and integrity of electronic certificates. Although an audit and management process has been established, the sheer volume of certificate data still presents a problem of difficulty in verifying their authenticity.
[0004] Blockchain's decentralized approach can solve security and trust issues in data storage and sharing. It establishes data ownership during data sharing, achieving immutability in storage, traceability in the circulation process, and auditability in data management. This ensures data security in storage, sharing, and auditing, promotes data sharing and utilization, enhances trust in data circulation, eliminates single points of failure, and defends against cyberattacks. Summary of the Invention
[0005] Purpose of the Invention: In order to overcome the above-mentioned technical problems, the first objective of this invention is to provide a blockchain-based electronic certificate security protection method, which can effectively guarantee the privacy and security of electronic certificates and verification, and prevent the leakage of certificate privacy and the unauthorized use of certificates. Based on the implementation of this method, the second objective of this invention is to provide a blockchain-based electronic certificate security protection system.
[0006] Technical Solution: A blockchain-based method for securing electronic certificates, the encryption process of which includes:
[0007] (11) Key generation
[0008] First, based on the electronic certificate, the key generation department uses FaceNet to extract a 128-dimensional real-valued feature vector. The eigenvectors are then normalized, and noise interference is eliminated through histogram equalization or adaptive filtering to ensure their stability. Finally, the mean of the eigenvector F is calculated using the following formula.
[0009]
[0010] F i Let F represent the i-th element of the eigenvector. Let each eigenvalue F... i By comparing with the mean, a binary feature vector B∈{0,1} is generated. 128 Among them, B i The value is
[0011] Then, the key management department randomly generates a version number for the user. Get version information V = (i, v i The version information is converted into a binary representation. The feature vector B and the converted binary information are then segmented into fixed-length groups of 4 bits and concatenated alternately. The concatenated data is then hashed to generate a fixed-length key K. 11 To reduce key inconsistencies caused by feature extraction errors, the error-correcting coding function BCH code is used for encoding, as shown in the following formula:
[0012] K'1=E(K 11 )
[0013] Here, E is the error correction coding function, which adds redundant information to tolerate small errors.
[0014] Finally, define multiplicative cyclic groups G1 and G2 for a large prime number P, where g1 and g2 are two generators of G1. Let e: G1 × G1 = G2 be an admissible bilinear mapping, and randomly select two values α. Represents the remaining classes modulo P, based on version information V = (i, v i ) and randomly selected values calculate The key sk is defined as the concatenation of K'1 and A:
[0015] sk=K'1||A
[0016] The key management department sends the key sk to the user, and the version information V is kept by the key management department.
[0017] (12) Data encryption
[0018] Encryption of electronic certificates: After the certificate holder possesses the certificate, the issuing party generates a parameter value ω for them and randomly generates a search key. Combine parameter value ω and search key SK s Transmitted to the certificate holder via a secure channel; the certificate holder selects keywords kw = {kw1, kw2, ... kw} from the original certificate text D. m}, using the electronic certificate-related data of the certificate holder ki The SHA256 hash is used as the ciphertext encryption key K = SHA256(k1,k2,…k). n Then, using key K, the original document D is encrypted using an encryption algorithm to obtain the ciphertext C = Enc. K (D), Enc is a symmetric cryptographic encryption algorithm that uploads the generated ciphertext of the certificate to the storage system and records the returned file address h. location ;
[0019] Index encryption: The ciphertext C of the certificate is encrypted using the first m bytes of its hash value as the index of the key, i.e., CT. k =H[0:m], randomly select the encryption key For file address h location Encryption is performed to obtain the address ciphertext. Enc is a symmetric cryptographic encryption algorithm; CT k CT scan l Embedded within an Ethereum transaction and broadcast to the Ethereum blockchain, the transaction ID is recorded upon confirmation, with the blockchain ensuring data security. Then, the issuer uses the holder's real identity (RID), parameter value ω, and search key SK. s The identity PID is calculated using the pseudo-random function F = F(RID||ω,SK). s ), DDenck = SHA256(K1), the issuing party sends the pseudo-identity PID, transaction ID, and the SHA256 value enck of K1 to the smart contract in the blockchain via the transaction, and calls the smart contract's index function to store a secure index. The smart contract defines a lookup table I containing key-value pairs.<address,value> , where address = PID, value = (ID, enck).
[0020] Furthermore, the method includes the following steps in the data decryption process:
[0021] (21) Data Search
[0022] First, a search token is generated, based on the pseudo-identity PID and the keyword set kw = {kw1, kw2, ... kw} to be searched. zm (zm≤m), randomly select calculate Let T = (J, {L i |i∈{0,1,2,…zm}}), use PID and T as search tokens;
[0023] If a user needs to query the certificate holder's certificate data, the certificate holder sends the generated PID to the user. The user then generates a token based on their own keyword set and broadcasts the token on the blockchain. A data search is then performed. Upon receiving the broadcast, the searcher calls a smart contract to match the PID in the search token. Based on the matched pseudo-identity PID, the corresponding Ethereum transaction ID is found, and the keyword index CT stored in the ID is read. k It calculates the key K1 through the smart contract interface, matches the calculated K1 with enck in the smart contract, and if the match is successful, it finds the search result result = (S) based on the key-value pair. id ,S enck ) Returned to the certificate holder or user, where S id S represents the set of ID search results that satisfy the search token. enck This represents the set of search results that satisfy the search token; then the searcher downloads the key index through the blockchain block ID, if the keyword set kw = {kw1, kw2, ... kw} zm} (zm≤m) is the keyword set kw={kw1,kw2,…kw m If the subset of} is obtained, then the decryption key K1 can be obtained. The result of the calculation is compared with the corresponding S enck Perform verification to check if SHA256(K1) is equal to SHA256(S). enck If they are equal, return K1 and ID;
[0024] (22) Data Decryption
[0025] The data decryption includes decryption by the certificate holder and decryption by the user. For decryption by the certificate holder, after receiving the ID and K1 returned by the searcher, the certificate holder downloads CT from the Ethereum blockchain based on the ID. k CT scan l CT can be decrypted based on the returned K1. l get Then according to h location The encrypted data C can be downloaded. Because the certificate holder possesses their own certificate-related data, the encryption key K can be obtained, and D = Dec can be directly decrypted. K (C); If the user is decrypting, after obtaining the ciphertext C, since the encryption key K is missing, it needs to be calculated to recover the encryption key. The calculation formula is as follows:
[0026]
[0027] Once the encryption key K is obtained, the user can use K to calculate D = Dec K (C) to recover the original data;
[0028] Furthermore, when the user's attributes change, the key management department will regenerate a new version of the information V'=(i',v'). i At this point, the old version information V = (i, v) i Since decryption is impossible, the encryption key K cannot be recovered. Only when the key management department regenerates the attribute key sk' for the user can the user decrypt the certificate. This ensures that users whose access has been revoked cannot continue to obtain electronic certificates, thereby achieving certificate privacy and security.
[0029] Furthermore, this method includes the following for the trusted verification process of electronic certificates:
[0030] (31) First, generate verification information for the issuer, holder, and custodian.
[0031] The issuer, holder, and depositor all generate their own public-private key pairs based on the SM2 digital signature algorithm, and each holds the private key SK. a SK b SK c PK and expose public key to blockchain a PK b PK c Each of these processes generates its own SM2 signature information, thereby enabling the verification of the certificate after embedding the signature information.
[0032] Each of the three parties uses its own public key and identity information as input, and takes the 256-bit hash value of the SM3 hash algorithm as its unique identification code sγ1, sγ2, sγ3 to complete the consistency binding of electronic certificates with the identity information of each participating party.
[0033] This step includes generating a global robust watermark embedding extraction key K based on the robust watermarking algorithm RW. w This is so that each participating party can embed its unique identification code into the certificate carrier;
[0034] (32) Issuance of electronic certificates
[0035] To realize the identity information of the issuing party and the certificate channel tα r The embedded binding is achieved by the certificate issuer embedding sγ1 into tα using the robust watermarking algorithm RW. r In the process, the red channel tβ, which contains the identity information of the issuing party, is used to obtain certificates. r ;
[0036] To ensure the unforgeability of the access certificate, the issuing party uses the SM2 signature algorithm with tβ. r Generate its signature information μ as the original text to be signed. r And use the robust watermarking algorithm RW to transfer μ rEmbedded into tβ r In the process, the original certificate containing the issuing authority's certification information will be sent to the certificate holder, along with the relevant verification information {sγ1,PK}. a ,tβ r ,μ r The information is published on the blockchain, thereby enabling the verifiable issuance of authoritative certificates.
[0037] (33) Submit credible certificates again
[0038] The certificate holder obtains the original signature tβ from the certificate issuer using the robust watermarking algorithm RW. r and signature information μ r The authenticity of the certificate source is verified using the SM2 signature algorithm. To ensure consistency between the certificate holder's identity information and the submitted certificate, the certificate holder embeds sγ2 into tα using the robust watermarking algorithm RW. g This allows for a green channel for obtaining certificates containing the certificate holder's identity information. g The certificate copy containing information from both parties will be sent to the certificate holder, along with the relevant verification information {sγ2,PK}. b ,tβ r The electronic certificate is published on the blockchain, thus completing the trusted submission of the electronic certificate.
[0039] (34) Authorization Return
[0040] The evidence custodian obtains the original signature tβ of the issuing party using the robust watermarking algorithm RW. r and signature information μ r The authenticity of the certificate source is verified using the SM2 signature algorithm. To ensure consistency between the identity information of the certificate holder and the submitted certificate, the certificate holder embeds sγ3 into tβ using the robust watermarking algorithm RW. b In this process, the blue channel tβ containing the identity information of the certificate holder is obtained. b , and then with tβ r ,tβ g ,tβ b Generate corresponding signature information μ as the original text to be signed. b And use the robust watermarking algorithm RW to transfer μ b Embedded into tβ b In the process, a copy of the certificate containing information from all three parties will be returned to the corresponding certificate holder, along with relevant verification information {sγ3,PK}. c ,tβ r ||tβ g ||tβ b ,μ b The evidence is published on the blockchain to ensure its verifiability to the certifying party.
[0041] (35) Submit authorization certificates
[0042] The certificate holder uses the robust watermarking algorithm RW to confirm that the certificate holder has embedded their own identity information. To ensure the verifiability of the certificate's authentic authorization, the certificate holder uses tβ. r , tβ b β, as the original text to be signed, is used to generate the corresponding signature information μ using the SM2 signature algorithm. g And use the robust watermarking algorithm RW to transfer μ g Embedded into tβ g In the process, a copy of the certificate containing third-party authentication information will be sent to the certificate holder, along with the relevant verification information {sγ2,PK}. b ,tβ r ||tβ g ,μ g The electronic certificate is published on the blockchain, thus completing the verifiable storage of the certificate. After obtaining a copy of the certificate, the custodian can obtain the original signature tβ of the certificate holder through the robust watermarking algorithm RW. g and signature information μ g And verify whether the certificate has been genuinely authorized by the certificate holder through the SM2 signature algorithm.
[0043] Furthermore, the method includes defining several participants to complete blockchain-based electronic certificate security protection:
[0044] The key management department is responsible for generating attribute keys for users and managing the storage permissions of the issuers of electronic certificates;
[0045] The issuing authority is the authoritative body that issues the license or permit.
[0046] The certificate holder is the owner of the electronic certificate data;
[0047] The evidence storage agency refers to the agency that handles government affairs and needs to verify the authenticity of the source of the certificates and licenses;
[0048] The user refers to a third-party user or organization that needs to use the certificate holder's certificate data;
[0049] The storage system is responsible for storing and retrieving data. The blockchain stores verification information during the certificate transfer process. Data stored on the blockchain cannot be arbitrarily modified and serves as evidence for verification.
[0050] Based on the implementation of a blockchain-based electronic certificate security protection method, the present invention also provides a blockchain-based electronic certificate security protection system, which executes the aforementioned electronic certificate security protection method.
[0051] Furthermore, the implementation of this system includes:
[0052] Electronic certificate privacy protection: Data encryption and decryption of electronic certificates are carried out by the participating parties, and access control of the electronic certificate database is realized by the encryption method based on attributes. At the same time, blockchain technology is used to store indexes, smart contracts are used to realize data sharing and acquisition, and user revocation is supported by changing version permissions.
[0053] Trusted verification of electronic certificates: Based on the defined participants, and combining cryptographic algorithms and robust watermarking algorithms, a shared storage process for electronic certificates is constructed, and a trusted verification framework for electronic certificates is built.
[0054] The present invention also provides a computer-readable storage medium storing an electronic certificate protection program, wherein the electronic certificate protection program, when executed by a processor, implements the aforementioned electronic certificate security protection method and steps based on blockchain technology.
[0055] Beneficial effects: The electronic certificate security protection method based on blockchain technology of the present invention provides robust access control for the electronic certificate database by utilizing attribute-based encryption technology for electronic certificate privacy protection. It also utilizes blockchain technology to store indexes, employs smart contracts to achieve data sharing and retrieval, and supports user revocation through version permission changes, effectively protecting user privacy from leakage. Furthermore, the trusted verification of electronic certificates combines cryptographic algorithms and robust watermarking algorithms to design a shared evidence storage process for electronic certificates, constructing a trusted verification framework to ensure third-party trusted verification of electronic certificates. Attached Figure Description
[0056] Figure 1 This is a flowchart illustrating the implementation of the electronic certificate security protection method based on blockchain technology of the present invention. Detailed Implementation
[0057] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0058] like Figure 1 As shown, the present invention provides a method for secure protection of electronic certificates based on blockchain technology, comprising the following steps:
[0059] First, we define the participants in the privacy protection and trusted verification of electronic certificates. There are a total of seven participants: the key management department, the certificate issuer, the certificate holder, the evidence storage party, the user, the Ethereum blockchain network, and the storage system. Specifically, the key management department is responsible for generating attribute keys for users and managing the storage permissions of the certificate issuer; the certificate issuer is the authoritative body that issues the certificate; the certificate holder is the owner of the electronic certificate data; the evidence storage party refers to the evidence storage agency handling government affairs, which needs to verify the authenticity of the certificate's source; the user refers to a third-party user or organization that needs to use the certificate holder's certificate data; and the storage system is responsible for data storage and retrieval. The blockchain stores verification information during the certificate circulation process, and the data stored on the blockchain cannot be arbitrarily modified and can serve as evidence for verification.
[0060] In methods for protecting the privacy of electronic certificates, the first step is data encryption, which includes the following steps:
[0061] (11) Key generation:
[0062] First, based on the electronic certificate, the key generation department uses FaceNet to extract a 128-dimensional real-valued feature vector. The eigenvectors are then normalized, and noise interference is eliminated through histogram equalization or adaptive filtering to ensure their stability. Finally, the mean of the eigenvector F is calculated using the following formula.
[0063]
[0064] F i Let F represent the i-th element of the eigenvector. Let each eigenvalue F... i By comparing with the mean, a binary feature vector B∈{0,1} is generated. 128 Among them, B i The value is
[0065]
[0066] Then, the key management department randomly generates a version number for the user. Get version information V = (i, v i The version information is converted into a binary representation. The feature vector B and the converted binary information are then segmented into fixed-length groups of 4 bits and concatenated alternately. The concatenated data is then hashed to generate a fixed-length key K. 11 To reduce key inconsistencies caused by feature extraction errors, the error-correcting coding function BCH code is used for encoding, as shown in the following formula:
[0067] K'1=E(K 11 )
[0068] Here, E is the error correction coding function, which adds redundant information to tolerate small errors.
[0069] Finally, define multiplicative cyclic groups G1 and G2 for a large prime number P, where g1 and g2 are two generators of G1. Let e: G1 × G1 = G2 be an admissible bilinear mapping, and randomly select two values α. Represents the remaining classes modulo P, based on version information V = (i, v i ) and randomly selected values calculate The key sk is defined as the concatenation of K'1 and A:
[0070] sk=K'1||A
[0071] The key management department sends the key sk to the user, and the version information V is kept by the key management department.
[0072] (12) Data encryption: First, the electronic certificate is encrypted. After the certificate holder has the certificate, the issuing party generates a parameter value ω for him / her and randomly generates a search key. Combine parameter value ω and search key SK s The certificate is transmitted to the certificate holder via a secure channel, and then the keyword kw = {kw1, kw2, ... kw} is selected from the original certificate text D. m}, using the electronic certificate-related data of the certificate holder k i The SHA256 hash is used as the ciphertext encryption key K = SHA256(k1,k2,…k). n Then, using key K, the original document D is encrypted using an encryption algorithm to obtain the ciphertext C = Enc. K (D), Enc is a symmetric cryptographic encryption algorithm that uploads the generated ciphertext of the certificate to the storage system and records the returned file address h. location Secondly, index encryption is used. The ciphertext C of the document is encrypted using the first m bytes of its hash value as the index of the key, i.e., CT. k =H[0:m]. Randomly select an encryption key. For file address h location Encryption is performed to obtain the address ciphertext. Enc is a symmetric cryptographic encryption algorithm. (The last part, "CT," appears to be a fragment and doesn't translate directly. It's left as is.) k CT scan l The process involves embedding the transaction within an Ethereum transaction and broadcasting it to the Ethereum blockchain. Once the transaction is confirmed, the transaction ID is recorded, and the blockchain ensures data security. The issuer then uses the holder's real identity (RID), parameter value ω, and search key SK to determine the certificate holder's identity. s The identity PID is calculated using the pseudo-random function F = F(RID||ω,SK).s ), DDenck = SHA256(K1). The issuing party sends the pseudo-identity PID, transaction ID, and the SHA256 value enck of K1 to the smart contract in the blockchain via a transaction, and calls the smart contract's indexing function to store a secure index. The smart contract defines a lookup table I containing key-value pairs.<address,value> , where address = PID, value = (ID, enck).
[0073] The next step is data decryption, which includes the following steps:
[0074] (21) Data Search: First, a search token is generated based on the pseudo-identity PID and the keyword set kw = {kw1, kw2, ... kw} to be searched. zm (zm≤m), randomly select calculate Let T = (J, {L i (i∈{0,1,2,…zm}) uses PID and T as search tokens. If a user needs to query the certificate holder's certificate data, the certificate holder sends the generated PID to the user. The user then generates a token based on their keyword set and broadcasts the token on the blockchain. A data search is then performed. Upon receiving the broadcast, the searcher calls the smart contract to match based on the PID in the search token. Based on the matched pseudo-identity PID, the corresponding Ethereum transaction ID is found, and the keyword index CT stored in the ID is read. k It calculates the key K1 through the smart contract interface, matches the calculated K1 with enck in the smart contract, and if the match is successful, it finds the search result result = (S) based on the key-value pair. id ,S enck ) Returned to the certificate holder or user, where S id S represents the set of ID search results that satisfy the search token. enck This represents the set of search results that satisfy the search token (enck). The searcher then downloads the key index using the blockchain block ID within this set, if the keyword set kw = {kw1, kw2, ... kw}. zm} (zm≤m) is the keyword set kw={kw1,kw2,…kw m If the subset of} is obtained, then the decryption key K1 can be obtained. The result of the calculation is compared with the corresponding S enck Perform verification to check if SHA256(K1) is equal to SHA256(S). enck If they are equal, return K1 and ID.
[0075] (22) Data Decryption: Data decryption is divided into two cases: decryption by the certificate holder and decryption by the user. For decryption by the certificate holder, after receiving the ID and K1 returned by the searcher, the certificate holder downloads CT from the Ethereum blockchain based on the ID. k CT scan l CT can be decrypted based on the returned K1. l get Then according to h location The encrypted data C can be downloaded. Because the certificate holder possesses their own certificate-related data, the encryption key K can be obtained, and D = Dec can be directly decrypted. K (C). If the user is decrypting, after obtaining the ciphertext C, since the encryption key K is missing, it needs to be calculated to recover the encryption key. The calculation formula is as follows:
[0076]
[0077] Once the encryption key K is obtained, the user can use K to calculate D = Dec K (C) to recover the original data D.
[0078] Furthermore, when the user's attributes change, the key management department will regenerate a new version of the information V'=(i',v'). i At this point, the old version information V = (i, v) i Since decryption is impossible, the encryption key K cannot be recovered. Only when the key management department regenerates the attribute key sk' for the user can the user decrypt the certificate. This ensures that users whose access has been revoked cannot continue to obtain electronic certificates, further guaranteeing the privacy and security of the certificates.
[0079] The specific steps for verifying the credibility of electronic certificates are as follows:
[0080] (31) First, generate verification information for the issuer, holder, and custodian.
[0081] The issuer, holder, and depositor all generate their own public-private key pairs based on the SM2 digital signature algorithm, and each holds the private key SK. a SK b SK c PK and expose public key to blockchain a PK b PK cThis process generates individual SM2 signature information, enabling verifiability of the embedded signature information in the certificate. Each of the three parties uses its own public key and identity information as input, and a 256-bit hash value from the SM3 hash algorithm is used as its unique identification code sγ1, sγ2, and sγ3 to ensure consistency between the electronic certificate and the identity information of each participating party. A global robust watermark embedding and extraction key K is generated based on the robust watermarking algorithm RW. w This is so that each participating party can embed their unique identification code into the certificate carrier.
[0082] (32) Issuance of electronic certificates
[0083] To realize the identity information of the issuing party and the certificate channel tα r The embedded binding is achieved by the certificate issuer embedding sγ1 into tα using the robust watermarking algorithm RW. r In the process, the red channel tβ, which contains the identity information of the issuing party, is used to obtain certificates. r To ensure the unforgeability of the channel certificate, the issuing party uses the SM2 signature algorithm with tβ. r Generate its signature information μ as the original text to be signed. r And use the robust watermarking algorithm RW to transfer μ r Embedded into tβ r In the process, the original certificate containing the issuing authority's certification information will be sent to the certificate holder, along with the relevant verification information {sγ1,PK}. a ,tβ r ,μ r The information is published on the blockchain, thereby completing the verifiable issuance of authoritative certificates.
[0084] (33) Submit credible certificates again
[0085] The certificate holder obtains the original signature tβ from the certificate issuer using the robust watermarking algorithm RW. r and signature information μ r The authenticity of the certificate source is verified using the SM2 signature algorithm. To ensure consistency between the certificate holder's identity information and the submitted certificate, the certificate holder embeds sγ2 into tα using the robust watermarking algorithm RW. g This allows for a green channel for obtaining certificates containing the certificate holder's identity information. g The certificate copy containing information from both parties will be sent to the certificate holder, along with the relevant verification information {sγ2,PK}. b ,tβ r The electronic certificate is published on the blockchain, thus completing the trusted submission of the electronic certificate.
[0086] (34) Authorization Return
[0087] The evidence custodian obtains the original signature tβ of the issuing party using the robust watermarking algorithm RW. r and signature information μr The authenticity of the certificate source is verified using the SM2 signature algorithm. To ensure consistency between the identity information of the certificate holder and the submitted certificate, the certificate holder embeds sγ3 into tβ using the robust watermarking algorithm RW. b In this process, the blue channel tβ containing the identity information of the certificate holder is obtained. b , and then with tβ r ,tβ g ,tβ b Generate corresponding signature information μ as the original text to be signed. b And use the robust watermarking algorithm RW to transfer μ b Embedded into tβ b In the process, a copy of the certificate containing information from all three parties will be returned to the corresponding certificate holder, along with relevant verification information {sγ3,PK}. c ,tβ r ||tβ g ||tβ b ,μ b The information is published on the blockchain to ensure the verifiability of the evidence.
[0088] (35) Submit authorization certificates
[0089] The certificate holder uses the robust watermarking algorithm RW to confirm that the certificate holder has embedded their own identity information. To ensure the verifiability of the certificate's authentic authorization, the certificate holder uses tβ. r , tβ b β, as the original text to be signed, is used to generate the corresponding signature information μ using the SM2 signature algorithm. g And use the robust watermarking algorithm RW to transfer μ g Embedded into tβ g In the process, a copy of the certificate containing third-party authentication information will be sent to the certificate holder, along with the relevant verification information {sγ2,PK}. b ,tβ r ||tβ g ,μ g The electronic certificate is published on the blockchain, thus completing the verifiable storage of the certificate. After obtaining a copy of the certificate, the custodian can obtain the original signature tβ of the certificate holder through the robust watermarking algorithm RW. g and signature information μ g The SM2 signature algorithm is used to verify whether the certificate has been genuinely authorized by the certificate holder. This process ensures the security of the electronic certificate's transfer among the three parties.
[0090] Based on the above-described preferred embodiments of the present invention, and through the foregoing description, those skilled in the art can make various changes and modifications without departing from the inventive concept. The technical scope of this invention is not limited to the contents of the specification, but must be determined according to the scope of the claims.
Claims
1. A blockchain-based method for the security protection of electronic certificates, characterized in that, The encryption process of this method includes: (11) Key generation The cryptography generation department extracts a 128-dimensional real-valued feature vector F based on FaceNet, normalizes the extracted feature vector, and eliminates noise interference through histogram equalization or adaptive filtering. Then, the mean of the feature vector F is calculated using the following formula. F i This represents the i-th element of the eigenvector, where each eigenvalue F... i The binary feature vector B is generated by comparing it with the mean. Then, the key management department randomly generates a version number for the user. Get version information V = (i, v i The version information is converted into a binary representation. The feature vector B is then combined with the converted binary information, and the data is segmented into fixed-length groups of 4 bits and concatenated alternately. The concatenated data is then hashed to generate a fixed-length key K. 11 To reduce key inconsistencies caused by feature extraction errors, the error-correcting coding function BCH code is used for encoding, as shown in the following expression: K'1=E(K 11 ) Where E is the error correction coding function, which adds redundant information to tolerate small errors; Finally, define multiplicative cyclic groups G1 and G2 for a large prime number P, where g1 and g2 are two generators of G1. Let e: G1 × G1 = G2 be an admissible bilinear mapping, and randomly select two values. Represents the remaining classes modulo P, based on version information V = (i, v i ) and randomly selected values Calculate A = The key sk is defined as the concatenation of K'1 and A: sk=K'1||A The key management department sends the key sk to the user, and the version information V is kept by the key management department. (12) Data encryption Encryption of electronic certificates: After the certificate holder possesses the certificate, the issuing party generates a parameter value ω for them and randomly generates a search key. Combine parameter value ω and search key SK s Transmitted to the certificate holder via a secure channel; the certificate holder selects the keyword kw = {kw1, kw2, ... kw} from the original certificate text D. m }, using the electronic certificate-related data of the certificate holder k i After obtaining the SHA256 hash, use it as the ciphertext encryption key K = SHA256(k1,k2,…k n Then, using key K, the original document D is encrypted using an encryption algorithm to obtain the ciphertext C = Enc. K (D), Enc is a symmetric cryptographic encryption algorithm that uploads the generated ciphertext of the certificate to the storage system and records the returned file address h. location ; Index encryption: The ciphertext C of the certificate is encrypted using the first m bytes of its hash value as the index of the key, i.e., CT. k =H[0:m], randomly select the encryption key For file address h location Encryption is performed to obtain the address ciphertext. Enc is a symmetric cryptographic encryption algorithm; CT k CT scan l Embedded within an Ethereum transaction and broadcast to the Ethereum blockchain, the transaction ID is recorded upon confirmation, with the blockchain ensuring data security. Then, the issuer uses the holder's real identity (RID), parameter value ω, and search key SK. s The identity PID is calculated using the pseudo-random function F = F(RID||ω,SK). s ), DDenck = SHA256(K1), the issuing party sends the pseudo-identity PID, transaction ID, and the SHA256 value enck of K1 to the smart contract in the blockchain via the transaction, and calls the smart contract's index function to store a secure index. The smart contract defines a lookup table I containing key-value pairs.<address,value> , where address = PID, value = (ID, enck).
2. The electronic certificate security protection method according to claim 1, characterized in that, This method includes the following steps in the data decryption process: (21) Data Search First, a search token is generated, based on the pseudo-identity PID and the keyword set kw = {kw1, kw2, ... kw} to be searched. zm (zm≤m), randomly select calculate Let T = (J, {L i |i∈{0,1,2,…zm}}), use PID and T as search tokens; If a user needs to query the certificate holder's certificate data, the certificate holder sends the generated PID to the user. The user then generates a token based on their own keyword set and broadcasts the token on the blockchain. A data search is then performed. Upon receiving the broadcast, the searcher invokes a smart contract to match the PID from the search token. Based on the matched pseudo-identity PID, the corresponding Ethereum transaction ID is found, and the keyword index CT stored in the ID is retrieved. k It calculates the key K1 through the smart contract interface, matches the calculated K1 with enck in the smart contract, and if the match is successful, it finds the search result result = (S) based on the key-value pair. id ,S enck ) Returned to the certificate holder or user, where S id S represents the set of ID search results that satisfy the search token. enck This represents the set of search results that satisfy the search token; then the searcher downloads the key index through the blockchain block ID, if the keyword set kw = {kw1, kw2, ... kw} zm } (zm≤m) is the keyword set kw={kw1,kw2,…kw m If the subset of} is obtained, then the decryption key K1 can be obtained. The result of the calculation is compared with the corresponding S enck Perform verification to check if SHA256(K1) is equal to SHA256(S). enck If they are equal, return K1 and ID; (22) Data Decryption The data decryption includes decryption by the certificate holder and decryption by the user. For decryption by the certificate holder, after receiving the ID and K1 returned by the searcher, the certificate holder downloads CT from the Ethereum blockchain based on the ID. k CT scan l CT can be decrypted based on the returned K1. l get Then according to h location The encrypted data C can be downloaded. Because the certificate holder possesses their own certificate-related data, the encryption key K can be obtained, and D = Dec can be directly decrypted. K (C); If the user is decrypting, after obtaining the ciphertext C, since the encryption key K is missing, it needs to be calculated to recover the encryption key. The calculation formula is as follows: Once the encryption key K is obtained, the user can use K to calculate D = Dec K (C) to recover the original data; Furthermore, when the user's attributes change, the key management department will regenerate a new version of the information V'=(i',v'). i At this point, the old version information V = (i, v) i Since decryption is impossible, the encryption key K cannot be recovered. Only when the key management department regenerates the attribute key sk' for the user can the user decrypt the certificate. This ensures that users whose access has been revoked cannot continue to obtain electronic certificates, thereby achieving certificate privacy and security.
3. The electronic certificate security protection method according to claim 1 or 2, characterized in that, This method includes the following steps in the trusted verification process for electronic certificates: (31) First, generate verification information for the issuer, holder, and custodian. The issuer, holder, and depositor all generate their own public-private key pairs based on the SM2 digital signature algorithm, and each holds the private key SK. a SK b SK c PK and expose public key to blockchain a PK b PK c Each of these processes generates its own SM2 signature information, thereby enabling the verification of the certificate after embedding the signature information. Each of the three parties uses its own public key and identity information as input, and takes the 256-bit hash value of the SM3 hash algorithm as its unique identification code sγ1, sγ2, sγ3 to complete the consistency binding of electronic certificates with the identity information of each participating party. This step includes generating a global robust watermark embedding extraction key K based on the robust watermarking algorithm RW. w This is so that each participating party can embed its unique identification code into the certificate carrier; (32) Issuance of electronic certificates To realize the identity information of the issuing party and the certificate channel tα r The embedded binding is achieved by the certificate issuer embedding sγ1 into tα using the robust watermarking algorithm RW. r In the process, the red channel tβ, which contains the identity information of the issuing party, is used to obtain certificates. r ; To ensure the unforgeability of the access certificate, the issuing party uses the SM2 signature algorithm with tβ. r Generate its signature information μ as the original text to be signed. r And use the robust watermarking algorithm RW to transfer μ r Embedded into tβ r In the process, the original certificate containing the issuing authority's certification information will be sent to the certificate holder, along with the relevant verification information {sγ1,PK}. a ,tβ r ,μ r The information is published on the blockchain, thereby enabling the verifiable issuance of authoritative certificates. (33) Submit credible certificates again The certificate holder obtains the original signature tβ from the certificate issuer using the robust watermarking algorithm RW. r and signature information μ r The authenticity of the certificate source is verified using the SM2 signature algorithm. To ensure consistency between the certificate holder's identity information and the submitted certificate, the certificate holder embeds sγ2 into tα using the robust watermarking algorithm RW. g This allows for a green channel for obtaining certificates containing the certificate holder's identity information. g The certificate copy containing information from both parties will be sent to the certificate holder, along with the relevant verification information {sγ2,PK}. b ,tβ r The electronic certificate is published on the blockchain, thus completing the trusted submission of the electronic certificate. (34) Authorization Return The evidence custodian obtains the original signature tβ of the issuing party using the robust watermarking algorithm RW. r and signature information μ r The authenticity of the certificate source is verified using the SM2 signature algorithm. To ensure consistency between the identity information of the certificate holder and the submitted certificate, the certificate holder embeds sγ3 into tβ using the robust watermarking algorithm RW. b In this process, the blue channel tβ containing the identity information of the certificate holder is obtained. b , and then with tβ r ,tβ g ,tβ b Generate corresponding signature information μ as the original text to be signed. b And use the robust watermarking algorithm RW to transfer μ b Embedded into tβ b In the process, a copy of the certificate containing information from all three parties will be returned to the corresponding certificate holder, along with relevant verification information {sγ3,PK}. c ,tβ r ||tβ g ||tβ b ,μ b The evidence is published on the blockchain to ensure its verifiability to the certifying party. (35) Submit authorization certificates The certificate holder uses the robust watermarking algorithm RW to confirm that the certificate holder has embedded their own identity information. To ensure the verifiability of the certificate's authentic authorization, the certificate holder uses tβ. r , tβ b β, as the original text to be signed, is used to generate the corresponding signature information μ using the SM2 signature algorithm. g And use the robust watermarking algorithm RW to transfer μ g Embedded into tβ g In the process, a copy of the certificate containing third-party authentication information will be sent to the certificate holder, along with the relevant verification information {sγ2,PK}. b ,tβ r ||tβ g ,μ g The electronic certificate is published on the blockchain, thus completing the verifiable storage of the certificate. After obtaining a copy of the certificate, the custodian can obtain the original signature tβ of the certificate holder through the robust watermarking algorithm RW. g and signature information μ g And verify whether the certificate has been genuinely authorized by the certificate holder through the SM2 signature algorithm.
4. The electronic certificate security protection method according to claim 1, characterized in that, This method includes defining several participating parties to complete blockchain-based electronic certificate security protection: The key management department is responsible for generating attribute keys for users and managing the storage permissions of the issuers of electronic certificates; The issuing authority is the authoritative body that issues the license or permit. The certificate holder is the owner of the electronic certificate data; The evidence storage agency refers to the agency that handles government affairs and needs to verify the authenticity of the source of the certificates and licenses; The user refers to a third-party user or organization that needs to use the certificate holder's certificate data; The storage system is responsible for storing and retrieving data. The blockchain stores verification information during the certificate transfer process. Data stored on the blockchain cannot be arbitrarily modified and serves as evidence for verification.
5. A blockchain-based electronic certificate security protection system, characterized in that, The system implements the electronic certificate security protection method as described in any one of claims 1-4.
6. The electronic certificate security protection system according to claim 5, characterized in that, The implementation of this system includes: Electronic certificate privacy protection: Data encryption and decryption of electronic certificates are carried out by the participating parties, and access control of the electronic certificate database is realized by the encryption method based on attributes. At the same time, blockchain technology is used to store indexes, smart contracts are used to realize data sharing and acquisition, and user revocation is supported by changing version permissions. Trusted verification of electronic certificates: Based on the defined participants, and combining cryptographic algorithms and robust watermarking algorithms, a shared storage process for electronic certificates is constructed, and a trusted verification framework for electronic certificates is built.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores an electronic certificate protection program, which, when executed by a processor, implements the electronic certificate security protection method based on blockchain technology as described in any one of claims 1-4.