Zhan Yonghua, Yuan Feng, Shi Rui, Shi Guozhen, Dong Chen
College of Computer and Data Science, Fuzhou University, Fuzhou 350108, China.
Institute 706, Second Academy of CASIC, Beijing 100854, China.
Sensors (Basel). 2024 Jan 13;24(2):496. doi: 10.3390/s24020496.
Electronic tickets (e-tickets) are gradually being adopted as a substitute for paper-based tickets to bring convenience to customers, corporations, and governments. However, their adoption faces a number of practical challenges, such as flexibility, privacy, secure storage, and inability to deploy on IoT devices such as smartphones. These concerns motivate the current research on e-ticket systems, which seeks to ensure the unforgeability and authenticity of e-tickets while simultaneously protecting user privacy. Many existing schemes cannot fully satisfy all these requirements. To improve on the current state-of-the-art solutions, this paper constructs a blockchain-enhanced privacy-preserving e-ticket system for IoT devices, dubbed PriTKT, which is based on blockchain, structure-preserving signatures (SPS), unlinkable redactable signatures (URS), and zero-knowledge proofs (ZKP). It supports flexible policy-based ticket purchasing and ensures user unlinkability. According to the data minimization and revealing principle of GDPR, PriTKT empowers users to selectively disclose subsets of (necessary) attributes to sellers as long as the disclosed attributes satisfy ticket purchasing policies. In addition, benefiting from the decentralization and immutability of blockchain, effective detection and efficient tracing of double spending of e-tickets are supported in PriTKT. Considering the impracticality of existing e-tickets schemes with burdensome ZKPs, we replace them with URS/SPS or efficient ZKP to significantly improve the efficiency of ticket issuing and make it suitable for use on smartphones.
电子票(e票)正逐渐被采用以替代纸质票,为客户、企业和政府带来便利。然而,其采用面临一些实际挑战,如灵活性、隐私、安全存储以及无法部署在智能手机等物联网设备上。这些问题推动了当前对电子票务系统的研究,该研究旨在确保电子票的不可伪造性和真实性,同时保护用户隐私。许多现有方案无法完全满足所有这些要求。为了改进当前的先进解决方案,本文构建了一种用于物联网设备的区块链增强型隐私保护电子票务系统,称为PriTKT,它基于区块链、结构保留签名(SPS)、不可链接可编辑签名(URS)和零知识证明(ZKP)。它支持基于灵活策略的购票,并确保用户不可链接性。根据通用数据保护条例(GDPR)的数据最小化和披露原则,PriTKT赋予用户选择性地向卖家披露(必要)属性子集的权力,只要披露的属性满足购票政策。此外,受益于区块链的去中心化和不可变性,PriTKT支持对电子票重复消费的有效检测和高效追踪。考虑到现有带有繁重零知识证明的电子票方案不切实际,我们用URS/SPS或高效的零知识证明取代它们,以显著提高票务发行效率并使其适合在智能手机上使用。