节点文献

基于区块链的分布式系统隐私保护方法研究

Research on Privacy Protection Methods in Blockchain-enabled Distributed System

【作者】 李朝阳;

【导师】 李剑;

【作者基本信息】 北京邮电大学 , 智能科学与技术, 2021, 博士

【摘要】 随着区块链技术的发展,传统中心化的系统正在经历着革命性的变化与升级,其在金融、物联网、医疗健康、政务、知识产权等领域的应用落地在不断地加快。但是,近年来关于区块链的安全事件也在不断地增长,基于区块链的分布式系统隐私安全问题尤为突出。此外,随着量子计算机的研制与量子计算的发展,传统基于计算复杂性的密码算法面对量子攻击的脆弱性日益凸显。因此,本文研究基于区块链的分布式系统隐私保护方法,并重点研究能够抵抗量子计算攻击的密码算法,这对于提高分布式系统用户隐私的安全性,具有十分重要的研究价值和实际意义。本文针对传统中心化系统中存在的问题,尤其是医疗服务系统中的用户隐私与数据安全问题,以及基于区块链的分布式系统中用户隐私安全问题,开展抗量子计算攻击的隐私保护方法研究。本文的研究内容主要围绕以下四个方面展开:(1)基于联盟链的医疗大数据安全共享针对传统中心化医疗服务系统中存在的数据孤岛、信息丢失等问题,提出一个基于联盟链的医疗大数据安全共享方案。利用联盟链技术建立医疗大数据分布式存储管理的健康链模型,打破传统医疗服务系统中不同医疗机构数据分散化的壁垒,解决人为或自然因素导致的信息丢失问题。同时,设计斯坦尔博格数据资源定价博弈模型,促进不同医疗机构之间的数据资源共享,提高医疗大数据的效益值。性能分析表明,所提出的方案相比于固定平均定价策略,在资源消费者效益值降低15%的情况下,可以使得资源提供者的收益值提高80%,且系统的最大化效益提高103%。因此,该方案不仅能保护用户隐私信息的安全性,还可提高医疗大数据资源的利用价值。(2)基于格密码的用户签名认证针对当前基于区块链的分布式系统中存在的认证协议不能有效抵抗量子计算攻击,且协议功能单一、实用性不强等问题,提出基于格密码的用户签名认证方案。利用格密码理论,设计两种分别适用不同环境的抗量子盲签名方案和代理盲签名方案。所提出的两类方案可以有效增强基于区块链的分布式系统交易认证的抗量子计算攻击安全性,并针对不同业务功能需求建立不同的安全签名认证机制,提高了系统用户认证与交易验证的安全性。同时,效率比较分析表明所设计方案的签名尺寸相比于类似方案均降低50%以上,不仅降低签名存储所需空间,还降低交易签名过程的计算复杂度,并提高交易执行的效率。(3)基于盆栽树的交易隐私保护针对基于区块链的分布式系统中存在的交易隐私泄露问题,提出一种基于盆栽树的交易隐私保护方案。利用盆栽树算法构造一个轻量级的区块链钱包模型,由根密钥对生成叶子密钥对,用于交易的签名与验证。用户仅需保存根密钥对,大大降低了分布式系统的密钥管理难度。并设计基于格困难假设的交易签名验证算法,以提高分布式系统的抗量子计算攻击安全性。安全性证明表明该方案可以抵抗适应性选择消息攻击下的强不可伪造性。另外,该方案生成N笔交易需要的密钥对所占用的存储空间仅为传统方法的1/N,且随着交易笔数N的不断增加,该方案将更加节省钱包空间。(4)基于可搜索加密的数据安全管理针对基于区块链的医疗服务系统中账本臃肿、数据可搜索性差、量子攻击威胁等问题,提出基于可搜索加密的数据安全管理方案。设计一种链上帐本-链下存储的轻量级医疗大数据安全管理模型,其只需将电子医疗记录的索引上传到区块链账本上,并将真实电子医疗记录数据存储在本地服务器上。该模型通过索引查找数据,有效避免直接接触数据带来的安全问题,且大大减轻公共账本的臃肿问题。同时,提出一种基于格密码的关键词可搜索属性基加密方案,建立基于属性的灵活访问策略,实现数据的细粒度访问控制。采用关键词机制,保证电子医疗记录数据的可搜索安全性,并利用后量子格密码来提高系统的抗量子计算攻击安全性。

【Abstract】 With the development of blockchain technology,the traditional centralized system is undergoing revolutionary changes and upgrades,and its applications in finance,Internet of Things,medical and health care,government affairs,intellectual property,and other fields are also accelerating.However,blockchain-related security incidents are also on the rise in recent years,and the user privacy security of blockchain-based distributed systems is particularly prominent.Besides,with the development of quantum computers and quantum computing,the vulnerability of traditional cryptographic algorithms based on computational complexity to quantum attacks has become increasingly prominent.Therefore,it is of great research value and significance to study the privacy protection methods for the blockchain-enabled distributed system,especially the anti-quantum attack cryptographic algorithms,to improve user privacy security.In view of the problems existing in the traditional centralized system,especially the user privacy and data security in the medical service system,and the user privacy security in the blockchain-enabled distributed system,this thesis studies the privacy protection methods against quantum attacks.The research content of this thesis mainly revolves around the following four aspects:(1)Secure medical big data sharing based on consortium blockchainAiming at data island problems and information loss existing in the traditional centralized medical service system,a blockchain-based distributed storage and sharing scheme for big medical data is proposed.By utilizing the consortium blockchain technology,a secure storage and management mode called Healthchain has been established,which can break the barrier of data decentralization of various medical institutions in the traditional healthcare service system,and solve the problem of information loss caused by human or natural factors.Simultaneously,A Steinberg data resource pricing game is proposed to promote data resource sharing among different medical institutions and improve the medical big data’s benefit value.The performance analysis shows that:compared with the fixed average pricing strategy,the proposed scheme can increase the profit value of resource consumers by 80%,and the maximum benefit of the system by 103%,while the benefit value of the resource consumer is only reduced by 15%.Therefore,this scheme not only protects the security of users’ privacy information,but also improves the utilization value of medical big data resources.(2)User signature authentication based on lattice cryptographyAiming at the problem that the authentication protocol in the current blockchain-enabled distributed system cannot effectively resist the attack from quantum computing,single protocol function,and lack of practicality,a blockchain-enabled distributed anti-quantum security signature authentication scheme has been proposed.By lattice cryptography theory,two kinds of anti-quantum blind signature schemes and proxy blind signature schemes suitable for different environments are designed.The proposed two schemes can effectively enhance the anti-quantum attack security of transaction authentication in the blockchain-enabled distributed system,and establish different secure signature authentication mechanisms according to various business function requirements,thus improving the security of user and transaction verification in the system.The comparative analysis of efficiency shows that the schemes’ signature size is reduced by more than 50%compared with similar schemes,which reduces the storage space required for a signature,reduces the computational complexity of the transaction signature process,and improves the efficiency of transaction execution.(3)Bonsai trees empowered transaction privacy protectionAiming at the transaction privacy leakage problem existing in the current blockchain-enabled distributed system,a Bonsai trees empowered transaction privacy protection scheme is proposed.A lightweight blockchain wallet model is constructed using the Bonsai trees algorithm.The root key pair generates the leaf key pair,which is used for transaction signature and verification.Users only need to save the root key pair,which greatly reduces the difficulty of key management in distributed system.In order to improve the security of distributed system against quantum computing attacks,a transaction signature verification algorithm based on the lattice difficulty hypothesis is designed.The security proof shows that the scheme can resist the strong unforgability under adaptive selection message attack.The storage space required to generate N transactions of this scheme is only 1/N of that of the traditional method,and with the increase of the number N of transactions,this scheme will save more wallet space.(4)Searchable encryption empowered data security managementAiming at the problems of significant redundancy of ledger,poor searchability of data,and quantum attack threat in the blockchain-based medical service system,a searchable encryption empowered data security management scheme is proposed.A lightweight medical big data security management model called On-chain and Off-chain storage is designed,which only requires the electronic medical record index to be uploaded to the blockchain ledger and the real electronic medical record data to be stored on the local server.This model can find the data by index,effectively avoid the security problem caused by direct contact with the data,and significantly reduce public accounts’ bloated phenomenon.Simultaneously,a keyword-searchable attribute-based encryption scheme based on lattice assumption is proposed,and a flexible attribute-based access policy is established to achieve fine-grained access control of data.The keyword mechanism is used to ensure the searchable security of the electronic medical record data,and the post-quantum lattice cryptography is used to improve the security of the system against quantum computing attacks.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络