This invention discloses a time-constrained, secure, and controllable data flow method in a cloud-edge environment, belonging to the field of mobile edge
cloud computing. Specifically, it involves: First, establishing a communication
scenario including an authorizing agency for both the sender and
receiver, the sender, edge nodes, a
cloud server, and the
receiver. Given security parameters, the authorized agency for the
receiver runs a global initialization
algorithm, outputting public parameters and domain public / private keys. Then, the authorized agency for the sender inputs the public parameters and domain public key, outputting its own domain public / private key. For each sender, an
access structure and a
valid time interval are assigned, and an
encryption key is generated. For each receiver, an attribute set is assigned, and a decryption key is generated. Finally, the sender runs the
encryption algorithm and outputs the original
ciphertext; the
edge node verifies the sender's sending authority and outputs the cleaned
ciphertext; and the legitimate receiver decrypts and outputs the
plaintext. This invention meets the requirements for secure and controllable data flow in a cloud-edge environment.