Yuan Ke, Yan Yingjie, Xiao Tong, Zhang Wenchao, Zhou Sufang, Jia Chunfu
School of Computer and Information Engineering, Henan University, Kaifeng 475004, China.
Henan Key Laboratory of Big Data Analysis and Processing, Henan University, Kaifeng 475004, China.
Entropy (Basel). 2021 Dec 9;23(12):1657. doi: 10.3390/e23121657.
In response to the rapid growth of credit-investigation data, data redundancy among credit-investigation agencies, privacy leakages of credit-investigation data subjects, and data security risks have been reported. This study proposes a privacy-protection scheme for a credit-investigation system based on blockchain technology, which realizes the secure sharing of credit-investigation data among multiple entities such as credit-investigation users, credit-investigation agencies, and cloud service providers. This scheme is based on blockchain technology to solve the problem of islanding of credit-investigation data and is based on zero-knowledge-proof technology, which works by submitting a proof to the smart contract to achieve anonymous identity authentication, ensuring that the identity privacy of credit-investigation users is not disclosed; this scheme is also based on searchable-symmetric-encryption technology to realize the retrieval of the ciphertext of the credit-investigation data. A security analysis showed that this scheme guarantees the confidentiality, the availability, the tamper-proofability, and the ciphertext searchability of credit-investigation data, as well as the fairness and anonymity of identity authentication in the credit-investigation data query. An efficiency analysis showed that, compared with similar identity-authentication schemes, the proof key of this scheme is smaller, and the verification time is shorter. Compared with similar ciphertext-retrieval schemes, the time for this scheme to generate indexes and trapdoors and return search results is significantly shorter.
随着征信数据的快速增长,出现了征信机构间的数据冗余、征信数据主体的隐私泄露以及数据安全风险等问题。本研究提出了一种基于区块链技术的征信系统隐私保护方案,实现了征信用户、征信机构和云服务提供商等多个实体间征信数据的安全共享。该方案基于区块链技术解决征信数据孤岛问题,基于零知识证明技术,通过向智能合约提交证明实现匿名身份认证,确保不泄露征信用户的身份隐私;该方案还基于可搜索对称加密技术实现征信数据密文的检索。安全性分析表明,该方案保证了征信数据的保密性、可用性、防篡改能力和密文可检索性,以及征信数据查询中身份认证的公平性和匿名性。效率分析表明,与类似身份认证方案相比,该方案的证明密钥更小,验证时间更短。与类似密文检索方案相比,该方案生成索引和陷门以及返回搜索结果的时间明显更短。