A Method for Secure Data Flow Based on Access Control Encryption in a Cloud-Edge Environment

By adopting cross-domain internal component access control encryption technology and threshold maintenance structure in the cloud computing environment, the problems of cross-domain data circulation control and data writing control in the cloud computing environment are solved, and the secure circulation of private data and effective data control are realized.

CN119622700BActive Publication Date: 2025-06-20BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411678082.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2025-06-20
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

The prior art is difficult to achieve cross-domain data circulation control and data writing control in a cloud computing environment, resulting in malicious senders who may disclose sensitive data.

Method used

Cross-domain internal access control encryption technology is adopted, and the threshold-keeping structure and distributed key generation protocol are used to ensure that only authorized senders and receivers can generate legal encrypted cryptographic texts, and use edge nodes to clean up and realize the secure circulation of data.

Benefits of technology

It realizes cross-domain secure circulation of private data in cloud-edge environments, ensures data read and write control, and prevents malicious senders from leaking sensitive data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119622700B_ABST
    Figure CN119622700B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for secure data flow based on access control encryption in a cloud-edge environment, belonging to the field of secure data circulation; specifically: First, a cloud-edge environment simulation scenario is built; the receiving domain authorization agency outputs the receiving domain public key and private key. Then, n sending domain authorization agencies jointly execute an algorithm to obtain the sending domain public key and their respective authorization keys. Each sending domain authorization agency independently runs a partial encryption key generation algorithm to obtain its respective partial encryption key, and the sender runs an encryption key aggregation algorithm to obtain the aggregated encryption key. Next, the receiving domain authorization agency obtains the decryption key and returns it to the receiver. The sender uses the aggregated encryption key to encrypt the plaintext data m and uploads it to the edge node, and a purification algorithm generates a purified ciphertext and uploads it to the cloud server. Finally, after the user retrieves the purified ciphertext, it is decrypted with the decryption key to obtain the message m. The present invention meets the requirements for secure circulation of private data in a cloud-edge environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data security circulation, and particularly relates to a data security flow method based on access control encryption in a cloud-edge environment. Background Art

[0002] With the development of information technology, the amount of enterprise data is increasing continuously. How to effectively manage and utilize this data has become an important issue faced by enterprise managers. To reduce the cost of maintaining data centers and improve the efficiency of data sharing at the same time, enterprises usually adopt cloud platforms such as Alibaba Cloud or Huawei Cloud to store and manage data, so that users can share data efficiently through the cloud.

[0003] However, on the one hand, the data may contain users' privacy information, and according to relevant laws and regulations, they cannot be shared arbitrarily; on the other hand, the cloud platform is semi-trusted and may disclose the stored data.

[0004] Therefore, privacy data cannot be directly shared on the cloud, and an efficient and secure sharing mechanism is needed to realize the sharing of privacy data in a cloud-edge environment.

[0005] Currently, in the prior art, technologies such as attribute-based encryption (ABE) and inner product encryption (IPE) are used to protect data privacy while realizing efficient data sharing.

[0006] Specifically, in an IPE-based data sharing system, the sender embeds an attribute vector describing the access policy into the ciphertext and publishes the encrypted data to the cloud server, so that only users who meet the specified access policy can decrypt it, and it is ensured that the cloud server and external adversaries cannot obtain any information about the data and the access policy.

[0007] Inner product encryption (IPE) technology can realize the encryption protection of privacy data in a cloud-edge environment. The entities involved include a trusted authorization agency, a cloud server, a sender, and a receiver. As Figure 1 shown, the implementation process of IPE includes the following steps:

[0008] 1) System initialization: The trusted authorization agency generates a system public key PK and a system master key MK.

[0009] 2) Key generation: The trusted authorization agency generates a decryption key DK according to the system master key MK and the predicate vector and securely distributes it to the receiver.

[0010] 3) Data encryption: The sender inputs the system public key PK, the plaintext m, and the attribute vector to generate the ciphertext ct.

[0011] 4) Data decryption: The receiver inputs the decryption key DK and the ciphertext ct, and decrypts the plaintext m or ⊥.

[0012] In the cloud computing environment, although the IPE technology can protect the privacy of data and receivers, there are still the following problems for the secure circulation of data:

[0013] 1) IPE does not support cross-domain data circulation control, that is, one authorization agency is responsible for authorizing both the sender and the receiver at the same time. In practical applications, in order to better explore the data value, data often needs to be circulated between different agencies, and the senders and receivers in different agencies are often authorized by their respective agencies.

[0014] 2) IPE can only achieve read control of data, that is, only authorized receivers can access the data through their decryption keys, but it cannot achieve write control of data. That is, any sender can execute the encryption algorithm to upload the ciphertext to the cloud server, resulting in malicious senders encrypting and leaking sensitive data to some receivers, thus causing the failure of data circulation control.

[0015] The existing references are as follows:

[0016] [1] Wang Guohuan. Principle and Application of Inner Product Encryption Technology [J]. Network Security Technology & Application, 2021, (01): 27-30.

[0017] [2] Chen Lixuan. Research on Access Control Encryption Scheme for Edge Cloud Computing [D]. Beijing University of Posts and Telecommunications, 2023.

[0018] [3] Wang Zheng, Wang Jingwei, Yin Xinchun. Attribute-Based Purifiable and Collaborative Data Sharing Scheme in Medical Scenarios [J / OL]. Computer Science, 1-12 [2024-09-28]. Summary of the Invention

[0019] Aiming at the problems existing in the prior art, the present invention proposes a method for secure data flow based on access control encryption in a cloud-edge environment, which uses cross-domain inner product access control encryption to achieve encryption protection and circulation control of private data, and meets the requirements for secure circulation of private data in the cloud-edge environment.

[0020] The method for secure data flow based on access control encryption in a cloud-edge environment is specifically as follows:

[0021] Step 1: Build a cloud-edge environment simulation scenario including a sender and a cloud server;

[0022] The simulation scenario includes: a receiving domain authorization agency (RA), a sending domain authorization agency (SAs), a sender, an edge node, a cloud server, and a receiver;

[0023] The receiving domain authority is responsible for generating decryption keys for each receiver within its domain.

[0024] A single sending domain authority cannot generate a valid encryption key. At least a threshold number t of authorities jointly generate a valid encryption key for the senders within their domain.

[0025] The sender obtains the encryption key corresponding to its attribute vector from multiple sending domain authorities, uses this key to encrypt the shared data, and passes the original ciphertext to the edge node.

[0026] The edge node checks the original ciphertext and converts it into a sanitized ciphertext. First, the edge node verifies whether the sender's ciphertext is generated by an authorized attribute vector. If the verification is correct, the edge node sanitizes the ciphertext using a random message key and uploads the sanitized ciphertext to the cloud server.

[0027] The cloud server provides a large amount of storage space for the sanitized ciphertexts from the edge nodes, and sends the frequently accessed ciphertexts to the edge nodes for caching for quick access.

[0028] The receiver obtains the corresponding decryption key from the receiving domain authority, obtains the sanitized ciphertext from the edge node, and uses the decryption key to decrypt the sanitized ciphertext to recover the plaintext.

[0029] Step 2: Input the security parameter λ of the initial input algorithm Setup(λ), and output the public parameter pp.

[0030] Step 3: The receiving domain authority inputs the public parameter pp into the algorithm RASetup(pp), and outputs the receiving domain public key mpk ra and the receiving domain private key msk ra .

[0031] Step 4: n sending domain authorities jointly execute the operation of sending the public parameter pp and the receiving domain public key mpk ra to the algorithm SASetup(pp, mpk ra , n, t), and obtain the public key mpk sa of the sending domain and their respective authorization keys.

[0032] n is the number of sending domain authorities, t is the threshold of the number n of sending domain authorities. The authorization key of the i-th sending domain authority is

[0033] Step 5: For each sending domain authority within the threshold, use the public key mpk sa of the sending domain and their respective authorization keys to run the partial encryption key generation algorithm to obtain their respective partial encryption keys, and return them to the sender; after the sender receives t partial encryption keys, run the aggregated encryption key algorithm to obtain the aggregated encryption key

[0034] Partial encryption key generation algorithm is: Input the public key mpk of the sending domain sa , the authorized private key of the i-th sending domain authorization agency , the unique identifier id and attribute vector of the sender Output the partial encryption key ek generated by the i-th sending domain authorization agency for this sender i .

[0035] Aggregate encryption key algorithm EKReconst(mpk sa ,{ek i} i∈T ): Input the public key mpk of the sending domain sa and t partial encryption keys {ek i}, where T represents the set [1,2,...,i,...t]; Output the aggregate encryption key i∈T

[0036] Step 6: The receiver requests the decryption key from the receiving domain authorization agency, and the receiving domain authorization agency runs the decryption key generation algorithm to obtain the decryption key and returns it to the receiver.

[0037] Decryption key generation algorithm Input the private key msk of the receiving domain ra and the predicate vector Output the decryption key

[0038] Step 7: The sender uses the aggregate encryption key to run the encryption algorithm Encrypt to encrypt the given plaintext data m, obtain the original encrypted ciphertext ct, and upload it to the edge node.

[0039] Input the public key mpk of the receiving domain ra , the public key mpk of the sending domain sa , the encryption key and the given plaintext data m to the encryption algorithm Encrypt, output the original encrypted ciphertext: ct = (c,π), where c is the ciphertext of the plaintext data m, and π is the zero-knowledge proof;

[0040] Among them:

[0041]

[0042] s,τ are randomly selected numbers; Y, g, g0, g j , y j are all the public key mpk of the receiving domain​ra group elements; l represents the length of the attribute vector; C, C0, E, E0, C j , E j represent the parameters of the original ciphertext ct.

[0043] The zero-knowledge proof π is obtained by the sender running the proof algorithm of the Schnorr scheme. The specific formula is as follows:

[0044]

[0045] pok represents the proof of knowledge, W is the witness, e(·,·) is the pairing operation, μ, η are the parameters of the encryption key parameters.

[0046] vk 00 , vk 0j is a group element from the public key mpk of the sending domain sa group elements.

[0047] Step 8. After receiving the original ciphertext ct from the sender, the edge node runs the sanitization algorithm to generate the sanitized ciphertext and uploads it to the cloud server.

[0048] The sanitization algorithm Sanitize(mpk ra , mpk sa , ct) takes as input the public key mpk of the receiving domain ra , the public key mpk of the sending domain sa and the original ciphertext ct, and determines whether ct is legal. If so, it outputs the sanitized ciphertext ct′; otherwise, it outputs ⊥.

[0049] Select a random number Calculate:

[0050]

[0051] Step 9. When the user, as the receiver, wants to access the sanitized ciphertext in the cloud server, it requests the ciphertext from the nearest edge node. The edge node determines whether it stores the ciphertext. If so, it directly returns it to the user; otherwise, the edge node requests it from the cloud server, saves it after obtaining the ciphertext, and returns it to the user.

[0052] Step 10. After the user retrieves the sanitized ciphertext ct′, it runs the decryption algorithm Decrypt with the decryption key to decrypt and obtain the plaintext m.

[0053] The decryption algorithm takes as input the decryption key and the sanitized ciphertext ct′. If the predicate vector in the decryption key and the attribute vector in the purification ciphertext Satisfy Output the plaintext m, otherwise output ⊥.

[0054] The advantages of the present invention are as follows:

[0055] 1) A method for secure data flow based on access control encryption in a cloud-edge environment improves the security of private data circulation in the cloud-edge environment, realizes cross-domain data sharing, the sending domain authorization agency controls who the sender can send data to, and the receiving domain authorization agency controls who the receiver can receive data from. At the same time, it ensures that a single sending domain authorization agency cannot arbitrarily generate encryption keys to produce legal ciphertexts.

[0056] 2) A method for secure data flow based on access control encryption in a cloud-edge environment can not only achieve read control of data but also achieve write control of data, ensuring that only authorized senders can use their encryption keys to generate valid ciphertexts, while ciphertexts generated by unauthorized senders will be discarded by the edge nodes, preventing malicious senders from leaking sensitive data to unauthorized receivers. Description of the Drawings

[0057] Figure 1 It is a schematic diagram of IPE-based data protection in the prior art;

[0058] Figure 2 It is a flowchart of a method for secure data flow based on access control encryption in a cloud-edge environment according to the present invention;

[0059] Figure 3 It is a simulation scenario diagram of a cloud-edge environment including a sender and a cloud server built according to the present invention. Detailed Embodiments

[0060] The present invention will be further described in detail below with reference to the drawings and examples.

[0061] The present invention proposes a method for secure data flow based on access control encryption in a cloud-edge environment, which uses cross-domain inner product access control encryption to achieve encryption protection and circulation control of private data. First, through the threshold-preserving structural signature and the distributed key generation protocol, decentralized encryption key generation is realized, ensuring that a single sending domain authorization agency cannot arbitrarily generate encryption keys to produce legal ciphertexts to bypass purification. Then, the zero-knowledge proof mechanism is used to prove that only authorized encryption keys can produce legal ciphertexts, and the edge nodes are used to purify the legal original ciphertexts while discarding the illegal ciphertexts, ensuring that only authorized senders and receivers can successfully send and receive ciphertexts, and unauthorized receivers cannot recover the message from the ciphertext even if they collude with the sender; meeting the requirements for secure circulation of private data in the cloud-edge environment. Specifically:

[0062] 1) Divide the authorization agencies into the sending - domain authorization agency (SA) and the receiving - domain authorization agency (RA), and generate corresponding keys for the senders and receivers within their respective domains to support cross - domain data - flow control. At the same time, use the distributed key - generation protocol and the threshold - structure signature scheme to achieve decentralized encryption - key generation. Let all SAs jointly select and distribute the domain keys for generating encryption keys, and share them among all SAs, so that a legitimate encryption key can be generated only when a certain threshold number of SAs are working, in order to reduce the trust and dependence on a single SA.

[0063] 2) Design a sanitizable inner - product encryption and sanitization algorithm. In the encryption phase, use the encryption key associated with the attribute vector to encrypt the message and use the zero - knowledge proof mechanism to generate the corresponding proof. In the sanitization phase, the sanitizer verifies the proof and sanitizes the legitimate ciphertext (i.e., the ciphertext generated using the authorized attribute vector ), and then uploads the sanitized ciphertext to the cloud server while discarding the illegitimate ciphertext, so as to achieve data write - control. Only the receiver holding the valid private key can correctly decrypt the sanitized ciphertext, and an unauthorized receiver cannot decrypt the sanitized ciphertext even if colluding with a malicious sender.

[0064] As Figure 2 shown, the method for secure data flow based on access - control encryption in a cloud - edge environment is as follows:

[0065] Step 1: Build a cloud - edge environment simulation scenario including senders and cloud servers;

[0066] All network communications between the sender and the cloud server are controlled by the sanitizer, and the read - control of data is determined by the predicate vector of the receiver. The entities involved are Figure 3 as shown, including: the receiving - domain authorization agency (RA), the sending - domain authorization agencies (SAs), the sender, the edge node, the cloud server, and the receiver.

[0067] The receiving - domain authorization agency acts as the administrator of the receiving domain, which is a completely honest entity and is responsible for generating decryption keys for each receiver within its domain.

[0068] The sending - domain authorization agency acts as the information - security committee in the sending domain. The secret key of the sending domain is distributed among n committee members. Therefore, a single sending - domain authorization agency cannot generate a valid encryption key, and at least a threshold number t of authorization agencies are required to jointly generate a valid encryption key for the senders within its domain.

[0069] The sender obtains the encryption key corresponding to its attribute vector from multiple sending - domain authorization agencies, encrypts the shared data using this key, and passes the original ciphertext to the edge node.

[0070] For each data, the sender first processes it using a random message key, then encapsulates the message key using an encryption key, and finally sends the encrypted result to the edge node.

[0071] The edge node checks the original ciphertext and converts it into a sanitized ciphertext. First, the edge node verifies whether the sender's ciphertext is generated by an authorized attribute vector. If the verification is correct, the edge node sanitizes the ciphertext using a random message key and uploads the sanitized ciphertext to the cloud server.

[0072] The cloud server provides a large amount of storage space for the sanitized ciphertexts from the edge nodes and sends the frequently accessed ciphertexts to the edge nodes for caching for quick access.

[0073] The receiver obtains the corresponding decryption key from the receiving domain authority, retrieves the sanitized ciphertext from the edge node, and decrypts the sanitized ciphertext using the decryption key to recover the plaintext.

[0074] Step 2: Input the security parameter λ of the initial input algorithm Setup(λ) and output the public parameters pp.

[0075] Step 3: The receiving domain authority inputs the public parameters pp into the algorithm RASetup(pp) and outputs the receiving domain public key mpk ra and the receiving domain private key msk ra .

[0076] Step 4: n sending domain authorities jointly execute to send the public parameters pp and the receiving domain public key mpk ra to the algorithm SASetup(pp, mpk ra , n, t), and obtain the public key mpk sa of the sending domain and their respective authorization keys.

[0077] n is the number of sending domain authorities, t is the threshold of the number n of sending domain authorities, and the authorization key of the i-th sending domain authority is

[0078] Step 5: For each sending domain authority within the threshold, use the public key mpk sa of the sending domain and their respective authorization keys to run the partial encryption key generation algorithm to obtain their respective partial encryption keys and return them to the sender; after the sender receives t partial encryption keys, run the aggregate encryption key algorithm to obtain the aggregate encryption key

[0079] The partial encryption key generation algorithm is: Input the public key mpk sa of the sending domain, the authorization private key of the i-th sending domain authority, the unique identifier id of the sender, and the attribute vector Output the partial encryption key ek generated by the i-th sending domain authorization agency for the sender i .

[0080] Aggregate encryption key algorithm EKReconst(mpk sa , {ek i}) i∈T : Input the public key mpk of the sending domain sa and t partial encryption keys {ek i}, where T represents the set [1, 2,..., i,... t]; output the aggregate encryption key i∈T

[0081] Step 6: The receiver requests the decryption key from the receiving domain authorization agency, and the receiving domain authorization agency runs the decryption key generation algorithm to obtain the decryption key and returns it to the receiver.

[0082] Decryption key generation algorithm Input the private key msk of the receiving domain ra and the predicate vector Output the decryption key

[0083] Step 7: The sender uses the aggregate encryption key to run the encryption algorithm Encrypt to encrypt the given plaintext data m, obtain the original encrypted ciphertext ct, and upload it to the edge node.

[0084] Input the public key mpk of the receiving domain ra , the public key mpk of the sending domain sa , the encryption key and the given plaintext data m to the encryption algorithm Output the original encrypted ciphertext: ct = (c, π), where c is the ciphertext of the plaintext data m and π is the zero-knowledge proof;

[0085] Among them:

[0086]

[0087] s, τ are randomly selected numbers; Y, g, g0, g j , y j are all group elements of the public key mpk of the receiving domain ra ; l represents the length of the attribute vector; C, C0, E, E0, C j , E j represent the parameters of the original encrypted ciphertext ct.

[0088] ​The zero-knowledge proof π is obtained by the sender running the proof algorithm of the Schnorr scheme. The specific formula is as follows:

[0089]

[0090] pok represents the proof of knowledge, W is the evidence, e(·,·) is the pairing operation, and μ, η are the parameters of the encryption key of. vk 00 , vk 0j is a group element from the public key mpk of the sending domain sa .

[0091] Step Eight: After receiving the original ciphertext ct from the sender, the edge node runs the sanitization algorithm to generate the sanitized ciphertext and uploads it to the cloud server.

[0092] The sanitization algorithm Sanitize(mpk ra , mpk sa , ct) takes as input the public key mpk of the receiving domain ra , the public key mpk of the sending domain sa and the original ciphertext ct, and determines whether ct is legal. If so, it outputs the sanitized ciphertext ct′; otherwise, it outputs ⊥.

[0093] Select a random number Calculate:

[0094]

[0095] where C, E,

[0096] C0, E0, C j , E j are parameters from the original ciphertext ct.

[0097] Step Nine: When the user, as the receiver, wants to access the sanitized ciphertext in the cloud server, it requests the ciphertext from the nearest edge node. The edge node determines whether it has the ciphertext. If so, it directly returns it to the user; otherwise, the edge node requests it from the cloud server, saves the ciphertext after obtaining it, and returns it to the user.

[0098] Step Ten: After the user retrieves the sanitized ciphertext ct′, it runs the decryption algorithm Decrypt with the decryption key to decrypt and obtain the plaintext m.

[0099] The decryption algorithm takes as input the decryption key and the sanitized ciphertext ct′. If the predicate vector in the decryption key and the attribute vector in the sanitized ciphertext satisfy Output the plaintext m, otherwise output ⊥.

[0100] Example:

[0101] 1) System initialization

[0102] First, select the security parameter λ, and RA runs the Setup algorithm.

[0103] Specifically: construct a bilinear group of prime order p and The corresponding bilinear map is e: Select a random number is the length of the attribute / predicate vector owned by the user.

[0104] Finally, output the public parameters

[0105] Secondly, RA runs the RASetup algorithm to create the receiving domain private key;;

[0106] Specifically: select a random number Calculate:

[0107]

[0108] where g, h are selected from the public parameters pp.

[0109] Then, RA publishes the receiving domain public key mpk ra and retains the domain key msk ra .

[0110] Finally, n SAs jointly run the SASetup algorithm to create the sending domain authorization agency key, specifically as follows:

[0111] Let SA1,…,SA n want to select l + 1 secrets and distribute these secrets among them; SA i calculates the share according to the Pedersen distributed key generation protocol and retains its signature key: sk i =(sk i0 , sk i1 ,…, sk il )=(v i , z 1i ,…z i ). Specifically, taking the distribution of v as an example, assume that each party SA i can sign, and SA i executes the following protocol:

[0112] · Randomly select and publish vi0 Commitment E0, where

[0113] · Randomly select Let F(x) = s i0 + d1x + … + d t-1 x t-1 and calculate v ij = F(j), j = 1, …, n.

[0114] · Randomly select and use b k to commit to d k , k = 1, …, t - 1, and finally broadcast:

[0115] E ik = E(d k , b k ), k = 1, …, t - 1.

[0116] · First, let G(x) = r i0 + b1x + … + b t-1 x t-1 , r ij = G(j), j = 1, …, n, and finally sign (v ij , r ij ) and send the signature and the share to SA j .

[0117] · Verify the shares (v j , r ji , r ji ) received from other parties SA and check that if there is an index j for which the check fails, then publish the share and its signature and terminate the protocol.

[0118] · Calculate the secret v = v 10 + … + v n0 of the share

[0119] Publish its verification key

[0120] The global verification key can be calculated according to Lagrange polynomial interpolation.

[0121] Finally, each SA initializes a list and retains the authorization agency key and generates a common reference string crs based on the Schnorr non-interactive zero-knowledge proof scheme, and publishes the domain public key:

[0122] mpk sa=(vk,{vk i} i∈N ,crs).

[0123] 2) Encryption key generation

[0124] Each sender requests an attribute vector from t SAs respectively for the corresponding partial encryption key. The i-th SA independently runs the EKParGen algorithm to create the partial encryption key ek i . Specifically, for the attribute vector with identifier id the SA first checks If not, let η = H(id) and calculate and

[0125] Then generate a signature Finally, send to the sender through a secure channel and put id into

[0126] After obtaining t partial encryption keys, the sender runs the EKReconst algorithm to integrate them into the final encryption key Specifically as follows: Calculate where is the Lagrange coefficient of participant i. Finally, use as his / her encryption key.

[0127] 3) Decryption key generation

[0128] For each receiver, first assign a predicate vector to it Then run the DKGen algorithm to generate the decryption key Specifically, given the predicate vector select a random number Calculate

[0129]

[0130] Finally, the receiving domain authority sends the decryption key to the receiver through a secure channel.

[0131] 4) Data encryption

[0132] Given the plaintext data m, the sender uses the encryption key to run the Encrypt algorithm to encrypt the data.

[0133] First, select a random number Calculate

[0134] Obtain

[0135] Secondly, the sender runs the proof algorithm of the Schnorr scheme to calculate the zero - knowledge proof π to prove to the purifier that it has the correct Specifically, the sender obtains π through the proof of the following equation.

[0136]

[0137] Finally, the sender securely sends the ciphertext ct=(c, π) to the edge node.

[0138] 5) Ciphertext purification

[0139] For each uploaded ciphertext ct=(c, π), the edge node runs the Sanitize algorithm for purification. First, the edge node verifies the zero - knowledge proof π to verify that the sender has the corresponding encryption key and uses this encryption key to generate the ciphertext. If the verification fails, the ciphertext is discarded.

[0140] If all checks pass, calculate the purified ciphertext as follows. Select a random number Then calculate:

[0141]

[0142] Finally, the edge node uploads the purified ciphertext to the cloud server.

[0143] 6) Data decryption

[0144] The receiver receives data from the edge node or the cloud server. For the purified ciphertext c′, the receiver uses the decryption key to run the Decrypt algorithm to decrypt the plaintext m. Specifically, if then calculate

[0145]

[0146] Finally, the receiver can recover the plaintext m = C′ / A.

Claims

1. A data security flow method based on access control encryption in a cloud-edge environment, characterized in that: The specific steps are as follows: Step 1: Build a cloud-edge environment simulation scenario including the sender and the cloud server; The simulation scenario includes: receiving domain authority, sending domain authority, sender, edge node, cloud server and receiver; Step 2: Initially input the security parameter λ of the algorithm Setup(λ) and output the public parameter pp; Step 3: The receiving domain authority inputs the public parameter pp into the algorithm RASetup(pp) and outputs the receiving domain public key mpk ra and receiving domain private key msk ra ; Step 4: n sending domain authorities jointly execute the public parameter pp and the receiving domain public key mpk ra Send to algorithm SASetup(pp,mpk ra ,n,t), obtain the public key mpk of the sending domain sa and respective authorization keys; n is the number of sending domain authorities, t is the threshold of the number of sending domain authorities n, and the authorization key of the i-th sending domain authority is Step 5: For each sending domain authority within the threshold, use the sending domain's public key mpk sa and their respective authorization keys, run the partial encryption key generation algorithm to obtain their respective partial encryption keys, and return them to the sender; after the sender receives t partial encryption keys, it runs the aggregate encryption key algorithm to obtain the aggregate encryption key Step 6: The receiver requests the decryption key from the receiving domain authority, and the receiving domain authority runs the decryption key generation algorithm to obtain the decryption key. and returns it to the recipient; Step 7: The sender uses the aggregate encryption key Run the encryption algorithm Encrypt to encrypt the given plaintext data m, obtain the encrypted original ciphertext ct, and upload it to the edge node; Enter the receiving domain public key mpk ra , send domain public key mpk sa , encryption key And the given plaintext data m to the encryption algorithm Encrypt, output the encrypted original ciphertext: ct = (c, π), c is the ciphertext of the plaintext data m, π is the zero-knowledge proof; Step 8: After receiving the original ciphertext ct from the sender, the edge node runs the purification algorithm to generate the purified ciphertext and uploads it to the cloud server; Step 9: When the user as a receiver wants to access the purified ciphertext in the cloud server, the user requests the ciphertext from the nearest edge node. The edge node determines whether the ciphertext exists. If so, it returns it directly to the user. Otherwise, the edge node requests the cloud server, obtains the ciphertext, saves it, and returns it to the user. Step 10: After the user retrieves the purified ciphertext ct′, use the decryption key Run the decryption algorithm Decrypt to decrypt and get the plaintext m.

2. A data security flow method based on access control encryption in a cloud-edge environment as claimed in claim 1, characterized in that: In the simulation scenario of step 1, the receiving domain authority is responsible for generating a decryption key for each receiver in its domain; A single sending domain authority cannot generate a valid encryption key, and at least a threshold number t of authorities jointly generate valid encryption keys for senders in their domains; The sender obtains the encryption key corresponding to its attribute vector from multiple sending domain authorities, and uses the key to encrypt the shared data, and transmits the original ciphertext to the edge node; in the original ciphertext ct: s,τ are selected random numbers; Y, g, g0, g j ,y j All are receiving domain public key mpk ra The group element; l represents the length of the attribute vector; C, C0, E, E0, C j , E j Represents the parameters of the original ciphertext ct; The zero-knowledge proof π is obtained by the sender running the proof algorithm of the Schnorr scheme. The specific formula is as follows: pok represents proof of knowledge, W is evidence, e(·,·) is the pairing operation, μ, η are encryption keys Parameters; vk 00 , vk 0j It comes from the sending domain public key mpk sa The group elements of The edge node checks the original ciphertext and converts it into a purified ciphertext. First, the edge node verifies whether the sender ciphertext is generated by the authorized attribute vector. If the verification is correct, the edge node purifies the ciphertext using a random message key and uploads the purified ciphertext to the cloud server. Sanitize(mpk ra ,mpk sa ,ct) Input the receiving domain public key mpk ra , send domain public key mpk sa and the original ciphertext ct, determine whether ct is legal, if so, output the purified ciphertext ct′, otherwise output ⊥; Select random number calculate: The cloud server provides a large amount of storage space for the purified ciphertext from the edge nodes and sends the frequently accessed ciphertext to the edge nodes for caching for fast access; The receiver obtains the corresponding decryption key from the receiving domain authority, obtains the purified ciphertext from the edge node, and uses the decryption key to decrypt the purified ciphertext to restore the plaintext.

3. A data security flow method based on access control encryption in a cloud-edge environment as described in claim 2, characterized in that: In step 5, the partial encryption key generation algorithm For: Enter the sending domain public key mpk sa , the authorized private key of the i-th sending domain authority The sender's unique identifier id and attribute vector Output the partial encryption key ek generated by the i-th sending domain authority for the sender i ; Aggregate encryption key algorithm EKReconst(mpk sa ,{ek i } i∈T ): Enter the sending domain public key mpk sa and t partial encryption keys {ek i } i∈T , T represents the set [1,2,...,i,...t]; output aggregate encryption key 4. A data security flow method based on access control encryption in a cloud-edge environment as claimed in claim 1, characterized in that: In step 6, the decryption key generation algorithm Enter the receiving domain private key msk ra and predicate vector Output decryption key 5. A data security flow method based on access control encryption in a cloud-edge environment as claimed in claim 1, characterized in that: In step 10, the decryption algorithm Enter the decryption key and the purified ciphertext ct′, if the predicate vector in the decryption key and the attribute vector in the purified ciphertext satisfy Output plaintext m, otherwise output ⊥.

Citation Information

Patent Citations

  • User privacy protection method based on attribute and homomorphism mixed encryption under cloud environment

    CN104079574A

  • Bidirectional access control method and system applied to cloud side data sharing

    CN112187798A