Controllable Access Control in Permissioned Blockchains via Controllable Threshold Proxy Re-Encryption

Wenzhong Li, Zhaoyang Xie, Shengli Liu, Yunxiao Zhou, Haibin Zhang · IEEE Transactions on Information Forensics and Security · 2025

Conventional blockchains can provide data availability and integrity only. Tons of applications additionally need confidentiality with flexible access control such that data providers can decide how their data are shared through blockchains. This paper aims at enhancing Byzantine Fault Tolerance (BFT)-based permissioned blockchains with controllable access control. To this goal, we extend the concept of Proxy Re-Encryption (PRE) to a new variant called Controllable Threshold PRE (CT-PRE). The traditional PRE enables a proxy, using a re-encryption key, to convert a ciphertext meant for delegator A into another ciphertext meant for delegatee B, all without exposing the original message. CT-PRE extends PRE into the setting with multiple proxies (corresponding to blockchain servers and avoiding a single point of failure) and enables the delegator to fully take control of its ciphertext. We formally define CT-PRE and construct a provably secure CTPRE scheme. We further extend the CTPRE scheme to a verifiable one VCTPRE. We implement the Verifiable CT-PRE scheme with stronger security, integrate it in our BFT-based blockchain system, and deploy our system in a WAN on Amazon EC2 with 22 nodes across four continents. We show that our system is highly efficient, achieving a throughput of 5.15 ktx/sec (for access control operations) and 10.83 ktx/sec (for write operations, only slightly slower than our BFT write operations), respectively.

Read the paper · More papers on PaperTik