Model file distribution method and device, storage medium and processor

Through the close cooperation of key generation, encryption, proxy re-encryption and decryption links, the problem of low encryption and decryption efficiency in model file distribution is solved, and the efficient and secure distribution of model files is achieved.

CN120185906APending Publication Date: 2025-06-20太保科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510421183.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

While ensuring the security in the distribution process of model files, the prior art has the problem of low encryption and decryption efficiency.

Method used

The key generation center generates corresponding key data for the model owner and user through the key generation center. The model owner encrypts the original model file and generates a re-encrypted key. The key agent center performs the proxy re-encrypted operation to generate a re-encrypted ciphertext specific to the specified model user. The model user decrypts after receiving the re-encrypted ciphertext.

Benefits of technology

It realizes the improvement of encryption and decryption efficiency during the distribution of model files, ensures accurate control of model files and access rights, and enhances data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185906A_ABST
    Figure CN120185906A_ABST
Patent Text Reader

Abstract

The invention discloses a model file distribution method and device, a storage medium and a processor. In the scheme, a key generation center generates key data of a model owner based on an identifier of the model owner, and generates key data of a model user based on an identifier of the model user; the model owner encrypts the original model file based on the encryption element and the main public key, generates a re-encryption key, and sends the encryption element, the re-encryption key and the encrypted model file to the key agent center; the key agent center generates a re-encryption ciphertext based on the encryption element and the re-encryption key, and sends the re-encryption ciphertext and the encrypted model file to a model user; and the model user decrypts the encrypted model file based on the key data of the model user, the re-encrypted ciphertext and the main public key to obtain an original model file. Compared with the problems of poor security and low encryption and decryption efficiency in the model file distribution process, the method has obvious advantages.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data transmission, and particularly to a method, device, storage medium and processor for distributing model files. Background Art

[0002] Currently, with the development of large model technology, the cost of training large models is constantly rising. Especially for those ultra-large models with more than 100B parameters, such models not only require huge computing resources and a large amount of data sets for pre-training, but also need to fine-tune the pre-trained large model in specific business scenarios to effectively meet the different business needs of the company. After the large model undergoes pre-training and fine-tuning, the network structure and weight files of the large model are saved as binary files respectively, and these binary files are simply referred to as model files. Therefore, the security of model files is extremely important during the distribution process.

[0003] However, the model files themselves have a large amount of data, and there is a problem of low encryption and decryption efficiency during the distribution process of model files.

[0004] Therefore, how to improve the encryption and decryption efficiency while ensuring the security of model files during the distribution process is a technical problem to be solved urgently. Summary of the Invention

[0005] Based on the above problems, the present application provides a method, device, storage medium and processor for distributing model files, aiming to improve the encryption and decryption efficiency while ensuring the security of model files during the distribution process.

[0006] The embodiments of the present application disclose the following technical solutions:

[0007] The first aspect of the present application provides a method for distributing model files, and the method includes:

[0008] The key generation center generates the key data of the model owner based on the identifier of the model owner, and generates the key data of the model user based on the identifier of the model user;

[0009] The model owner encrypts the original model file based on the encryption element and the public master key to obtain the encrypted model file, generates a re-encryption key based on the key data of the model owner and the public key of the model user, and sends the encryption element, the re-encryption key and the encrypted model file to the key proxy center;

[0010] The key proxy center generates a re-encrypted ciphertext based on the encryption element and the re-encryption key, and sends the re-encrypted ciphertext and the encrypted model file to the model user;

[0011] The model user decrypts the encrypted model file based on the model user's key data, the re-encrypted ciphertext, and the public master key to obtain the original model file.

[0012] Optionally, the model owner encrypts the original model file based on the encryption element and the public master key to obtain the encrypted model file, generates a re-encryption key based on the model owner's key data and the public key of the model user, and sends the encryption element, the re-encryption key, and the encrypted model file to the key proxy center, including:

[0013] The model owner determines the encryption element based on a random number and the public key of the model user;

[0014] The model owner calculates the encryption key based on the encryption element and the public master key;

[0015] Encrypt the original model file using the encryption key to obtain the encrypted model file;

[0016] Generate a re-encryption key based on the model owner's key data and the public key of the model user;

[0017] Send the encryption element, the re-encryption key, and the encrypted model file to the key proxy center.

[0018] Optionally, the model owner calculates the encryption key based on the encryption element and the public master key, including:

[0019] The model owner calculates the encryption key using bilinear pairing based on the encryption element and the public master key; the public master key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0020] Optionally, the key generation center generates the model owner's key data based on the model owner's identifier and generates the model user's key data based on the model user's identifier, including:

[0021] The key generation center maps the model owner's identifier and the model user's identifier to the BLS12-381 elliptic curve respectively using a public hash function based on the model owner's identifier and the model user's identifier to obtain the public key of the model owner and the public key of the model user;

[0022] Generate the model owner's private key based on the master private key and the public key of the model owner;

[0023] Generate the model user's private key based on the master private key and the public key of the model user;

[0024] The key data of the model owner includes the public key of the model owner and the private key of the model owner; the key data of the model user includes the public key of the model user and the private key of the model user; the master private key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0025] Optionally, the model user decrypts the encrypted model file based on the key data of the model user, the re-encrypted ciphertext, and the master public key to obtain the original model file, including:

[0026] The model user calculates an encryption key based on the key data of the model user, the re-encrypted ciphertext, and the master public key, and decrypts the encrypted model file based on the encryption key to obtain the original model file.

[0027] The second aspect of this application provides a model file distribution device, which includes:

[0028] A key generation module, configured to generate the key data of the model owner by the key generation center based on the identifier of the model owner, and generate the key data of the model user based on the identifier of the model user;

[0029] An encryption module, configured to encrypt the original model file by the model owner based on the encryption element and the master public key to obtain the encrypted model file, generate a re-encryption key based on the key data of the model owner and the public key of the model user, and send the encryption element, the re-encryption key, and the encrypted model file to the key proxy center;

[0030] A proxy re-encryption module, configured to generate a re-encrypted ciphertext by the key proxy center based on the encryption element and the re-encryption key, and send the re-encrypted ciphertext and the encrypted model file to the model user;

[0031] A decryption module, configured to decrypt the encrypted model file by the model user based on the key data of the model user, the re-encrypted ciphertext, and the master public key to obtain the original model file.

[0032] Optionally, the encryption module is specifically configured to:

[0033] The model owner determines the encryption element based on a random number and the public key of the model user;

[0034] The model owner calculates an encryption key based on the encryption element and the master public key;

[0035] Encrypt the original model file using the encryption key to obtain the encrypted model file;

[0036] Generate a re-encryption key based on the key data of the model owner and the public key of the model user;

[0037] Send the encrypted element, the re-encryption key, and the encrypted model file to the key proxy center.

[0038] Optionally, the encryption module is specifically configured to:

[0039] The model owner calculates an encryption key using bilinear pairing based on the encrypted element and the master public key; the master public key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0040] A third aspect of the present application provides a computer-readable storage medium storing a computer program that, when run by a processor, implements the model file distribution method provided in any implementation manner of the first aspect.

[0041] A fourth aspect of the present application provides a processor for running a computer program that, when the program runs, executes the model file distribution method provided in any implementation manner of the first aspect.

[0042] Compared with the prior art, the present application has the following beneficial effects:

[0043] In the model file distribution method provided by the present application, the key generation center generates corresponding key data for different users, laying the foundation for the whole process. The model owner encrypts the original model file and generates a re-encryption key, which not only ensures the confidentiality of the model file but also realizes precise control over the access rights of model users. The key proxy center performs proxy re-encryption operations to generate re-encrypted ciphertext specific to a designated model user. This mechanism ensures that even the key proxy center cannot decrypt the data content alone, thus further enhancing data security. After receiving the re-encrypted ciphertext, the model user decrypts the re-encrypted ciphertext to recover the encrypted model file. This way, only authorized model users can access the content of the model file, while other unauthorized users cannot decrypt or access the data.

[0044] In summary, the model file distribution method provided by the present application, through the close cooperation of key generation, data encryption, proxy re-encryption, and data decryption links, not only ensures the security of the model file during distribution but also can flexibly manage the decryption rights of users. In addition, this method simplifies the key management and distribution process and greatly improves the efficiency of the encryption and decryption process. Description of the Drawings

[0045] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0046] Figure 1 It is a flowchart of a model file distribution method provided by an embodiment of the present application;

[0047] Figure 2 It is a flowchart of another model file distribution method provided by an embodiment of the present application;

[0048] Figure 3 It is an interface display diagram of a key generation center provided by an embodiment of the present application;

[0049] Figure 4 It is an interface display diagram of a user's encrypted data provided by an embodiment of the present application;

[0050] Figure 5 It is an interface display diagram of generating a user's encryption result provided by an embodiment of the present application;

[0051] Figure 6 It is an interface display diagram of a key proxy center provided by an embodiment of the present application;

[0052] Figure 7 It is an interface display diagram of a key proxy center generating a re-encrypted ciphertext provided by an embodiment of the present application;

[0053] Figure 8 It is an interface display diagram of a user decryption center provided by an embodiment of the present application;

[0054] Figure 9 It is a schematic structural diagram of a model file distribution device provided by an embodiment of the present application. Detailed implementation manners

[0055] As described above, as the core output, the security of the model file is extremely important during the distribution process. However, the model file itself has a large data volume, and there is a problem of low encryption and decryption efficiency during the distribution process of the model file.

[0056] In view of the above problems, through research, the inventors have proposed a model file distribution method, apparatus, storage medium, and processor. The key generation center generates the key data of the model owner based on the identifier of the model owner, and generates the key data of the model user based on the identifier of the model user; the model owner encrypts the original model file based on the encryption element and the master public key to obtain the encrypted model file, generates a re-encryption key based on the key data of the model owner and the public key of the model user, and sends the encryption element, the re-encryption key, and the encrypted model file to the key proxy center; the key proxy center generates a re-encrypted ciphertext based on the encryption element and the re-encryption key, and sends the re-encrypted ciphertext and the encrypted model file to the model user; the model user decrypts the encrypted model file based on the key data of the model user, the re-encrypted ciphertext, and the master public key to obtain the original model file.

[0057] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0058] See Figure 1 , which is a flowchart of a model file distribution method provided by an embodiment of this application. As Figure 1 shown, the method includes the following steps:

[0059] S101. The key generation center generates the key data of the model owner based on the identifier of the model owner, and generates the key data of the model user based on the identifier of the model user.

[0060] Among them, the key data includes a public key and a private key.

[0061] The key generation center generates key data corresponding to the identifier of the user (such as the email address) through user registration. The private key of the user is kept by the user, the public key of the user is public, and at the same time, the identifier of the publicly registered user is public. This method ensures that the system can manage keys safely and effectively.

[0062] S102. The model owner encrypts the original model file based on the encryption element and the master public key to obtain the encrypted model file, generates a re-encryption key based on the key data of the model owner and the public key of the model user, and sends the encryption element, the re-encryption key, and the encrypted model file to the key proxy center.

[0063] Among them, the encryption element is generated based on a random number and the public key of the model user; the master public key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0064] The model owner refers to the owner or generator of the original model file, who has full control over the model file, including deciding who can access the file and how to securely transmit and distribute the file. The model owner encrypts the original model file and generates a re-encryption key, which allows the key proxy center to generate a re-encrypted ciphertext based on the re-encryption key, so that only the specified model user can decrypt it.

[0065] BLS12-381 is a specially designed elliptic curve mainly used in modern cryptographic protocols, especially those scenarios that require efficient bilinear pairing operations. BLS12-381 is designed to provide a security strength of approximately 128 bits while maximizing efficiency in implementation, especially in finite field arithmetic and pairing calculations. A key feature of this curve is that it supports efficient bilinear pairing operations. Bilinear pairing is a special function e:G1×G2→G T where G1 and G2 respectively correspond to different point sets on the curve, and G1 and G2 have the same prime order, and G T is the target group, and the result of the bilinear pairing lies within this group.

[0066] The model owner encrypts the original model file to ensure that even if the encrypted model file is intercepted during transmission, unauthorized third parties cannot access its content without direct interaction with the model user. Using the re-encryption key, the transmission of the model file is indirectly completed through the key proxy center, which further enhances security and also enables flexible management of access rights. By generating a unique re-encryption key for each authorized model user, differential access right management for different users is achieved.

[0067] S103. The key proxy center generates a re-encrypted ciphertext based on the encryption element and the re-encryption key, and sends the re-encrypted ciphertext and the encrypted model file to the model user.

[0068] As an intermediary, the key proxy center is responsible for the re-encryption operation. By using re-encryption technology, the private key of the model owner does not need to be directly exposed to other parties, including the key proxy center, which reduces the risk of key leakage and improves the security of the model file during distribution. Moreover, the key proxy center cannot decrypt, which can promote the effective sharing of sensitive data such as model files while ensuring data security. Different model users can utilize these resources under authorization, which is conducive to collaboration across organizations or departments.

[0069] S104. The model user decrypts the encrypted model file based on the key data of the model user, the re-encrypted ciphertext, and the public master key to obtain the original model file.

[0070] The model user refers to an individual or system that hopes to obtain the model file and use the model file. The model user is the final recipient, but needs to go through the authorization and decryption processes to access the original model file. The model owner can only decrypt the content for which they are authorized and cannot access unauthorized files. That is to say, from the moment the model owner encrypts the model file until the model user decrypts it, the model file remains encrypted throughout the entire distribution process, ensuring the security of the data during transmission and storage.

[0071] In an implementable embodiment, the model owner can also be converted into a model user.

[0072] In the model file distribution method provided by the embodiments of the present application, the key generation center generates corresponding key data for different users, laying the foundation for the entire process. The model owner encrypts the original model file and generates a re-encryption key, which not only ensures the confidentiality of the model file but also realizes precise control over the access rights of the model user. The key proxy center performs the proxy re-encryption operation to generate a re-encrypted ciphertext specific to the designated model user. This mechanism ensures that even the key proxy center cannot decrypt the data content alone, thereby further enhancing data security. After receiving the re-encrypted ciphertext, the model user decrypts the re-encrypted ciphertext and then recovers the encrypted model file. In this way, only the authorized model user can access the content of the model file, while other unauthorized users cannot decrypt or access the data.

[0073] In summary, the model file distribution method provided by the embodiments of the present application, through the close cooperation of the key generation, data encryption, proxy re-encryption, and data decryption links, not only ensures the security of the model file during the distribution process but also can flexibly manage the decryption permissions of users. In addition, this method simplifies the key management and distribution processes and greatly improves the efficiency of the encryption and decryption processes.

[0074] Based on the above embodiments, in order to further improve the model file distribution method, a step is added in which the key generation center generates a public master key and a private master key based on the BLS12-381 elliptic curve. Taking the model owner as user A and the model user as user B, and assuming that user B has obtained the authorization of user A as an example for illustration.

[0075] See Figure 2 , which is a flowchart of another model file distribution method provided by the embodiments of the present application. As Figure 2As shown, the method includes the following steps:

[0076] S201. The key generation center generates a master public key and a master private key based on the BLS12-381 elliptic curve.

[0077] In an implementable embodiment, the BLS12-381 elliptic curve supports efficient bilinear pairing, i.e., e: G1×G2→G T , where G1 and G2 are elliptic curve groups, and G1 and G2 have the same prime order, and G T is the target group. Assume g1 and g2 are arbitrary solutions of the elliptic curve, then the bilinear property is satisfied: e(g1 a , g2 b ) = e(g1, g2) ab .

[0078] The key generation center is responsible for generating the master public key (MPK) and the master private key (MSK) of the system, and uses the MSK to generate a unique private key (SK) for each registered user. Among them, the master private key is retained by the key generation center.

[0079] S202. The key generation center generates the key data of user A based on the identifier of user A, and generates the key data of user B based on the identifier of user B.

[0080] In an implementable embodiment:

[0081] The key generation center maps the identifier of the model owner and the identifier of the model user to the BLS12-381 elliptic curve respectively using a public hash function based on the identifier of the model owner and the identifier of the model user, and obtains the public key of the model owner and the public key of the model user;

[0082] Generates the private key of the model owner based on the master private key and the public key of the model owner;

[0083] Generates the private key of the model user based on the master private key and the public key of the model user;

[0084] The key data of the model owner includes the public key of the model owner and the private key of the model owner; the key data of the model user includes the public key of the model user and the private key of the model user; the master private key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0085] When a user registers, the key generation center generates key data corresponding to the user's identifier (such as an email address). The user's private key is not publicly disclosed. At the same time, the publicly registered user identifier is mapped to the BLS12-381 elliptic curve through a publicly available hash function to calculate hash(userID). As Figure 3 shown Figure 3As an example, the interface of the key generation center is shown. This interface includes an input box for the user identifier (such as an email address), the already generated master public key (MPK), and public and private keys generated based on different user identifiers. The input box for the user identifier is used to prompt the user to enter the user identifier. Clicking the button generates the public and private keys corresponding to the user identifier. The already generated master public key (MPK) is: 1380691592326724594186135960003899382815651270322861796564223736022537818583 3738690941731901751466743117623235748761242938734920612499869064 0171607831011735349601200344259272762851318018659457840264368706 2933147068669610832139956982426041576255374550870270534456610541 1379513697297856815135739392728231442497838893142769609933949672 53460580639524582652822668114901647824109618695779619493790825352950224579353080395541641911023612676124063389561842845401889091. The public key corresponding to the user identifier testme@1.2 is: 21058861401728980663985884447021035405838484814814859811059094034177309945326. The private key corresponding to the user identifier testme@1.2 is: 39491687549403370741353463161408421438259309576462671149757004186696432381700. The public key corresponding to the user identifier testme@3.4 is: 10468031010640112368260533098881573021287039179538204331633349877094358648507. The private key corresponding to testme@3.4 is: 46732394198382223760902488200050195240791549827563437233593297174859079749569.

[0086] Exemplarily, assume that the private key of user A and hash(A) are skA and hA, and the private key of user B and hash(B) are skB and hB, where skA = MSK ^ hash(A) and skB = MSK ^ hash(B).

[0087] In this design based on the BLS12-381 elliptic curve and bilinear pairing, the user private keys skA and skB are generated by combining the master private key MSK with the user-specific hash values hA and hB. Due to the difficulty of the elliptic curve discrete logarithm problem, an attacker cannot reverse-engineer the master private key MSK from the known private keys and hash values. In addition, the private keys of different users are independent of each other, and the master private key MSK is only known to the key generation center and is not exposed to any user. Even if the private key of a certain user is leaked, it will not affect the security of the private keys or the master private key of other users, further enhancing the security of the system. Therefore, this design effectively protects the security of the master private key MSK, enabling the system to securely support encryption and decryption operations in a multi-user environment.

[0088] S203. User A encrypts the original model file based on the encryption element and the public master key to obtain the encrypted model file, generates a re-encryption key based on the key data of user A and the public key of user B, and sends the encryption element, the re-encryption key, and the encrypted model file to the key proxy center.

[0089] In an implementable embodiment:[[]]

[0090] The model owner determines the encryption element based on a random number and the public key of the model user;

[0091] The model owner calculates the encryption key based on the encryption element and the public master key;

[0092] Encrypt the original model file using the encryption key to obtain the encrypted model file;

[0093] Generate a re-encryption key based on the key data of the model owner and the public key of the model user;

[0094] Send the encryption element, the re-encryption key, and the encrypted model file to the key proxy center.

[0095] Among them, the model owner calculates the encryption key based on the encryption element and the public master key, including:[[]]

[0096] The model owner calculates the encryption key using bilinear pairing based on the encryption element and the public master key; the public master key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0097] Such asFigure 4 As shown Figure 4 displays the interface for the user to encrypt data. Based on the data provided in Figure 3 , in this interface, the Encryption Key (SK) is the private key, specifically: 39491687549403370741353463161408421438259309576462671149757004186696432381700, the Master Public Key (MPK) is the public key, specifically: 13806915923267245941861359600038993828156512703228617965642237360225378185833738690941731901751466743117623235748761242938734920612…, My Email is the email address entered by the model owner, taking testme@1.2 as an example, Recipient Email is the email address of the model user that the model owner needs to enter, taking testme@3.4 as an example, the model owner needs to enter the data to be encrypted in Text to Encrypt, and there is a button Generate Encrypted Text. After clicking, the encrypted data is generated according to the input information.

[0098] As Figure 5 shown Figure 5 displays the interface diagram of the user's encryption result generated taking the content entered in Figure 4 as an example. Figure 5In the encrypted result shown, C1 is the encryption element, specifically: 131284680358210663716928307803393070795420238784131897976002513571576972 3601042299595600138866159306413963657165088521250500842040997557 52465336334998530123977197024743383206009265265377466726610001393434120701802281550922187759199, Nonce is a random number, specifically: 58de7a8995ba760617e626a1ebda6833, Ciphertext shows the encrypted data, specifically: 1c21330ef6f8f080af0fee387abc0c226e426e3a3c2b3f979b8a90b9a763386e3beedd23637bb5c, Tag is the encryption key, specifically: 6eea838bb082fda79f36b8fc223fade5, Rekey is the re-encryption key, specifically: 2315571171843757050511905276204492601569001381853636169930738396465256028458, which is used for subsequent re-encryption operations.

[0099] Exemplarily, when user A encrypts the original model file, by introducing a random number random, the encryption element g1 is obtained, specifically: g1 = G1^(random * hB), g2 = MPK = G2^MSK.

[0100] Among them, G1 and G2 are elliptic curve groups, hB is a point on G1 mapped by the hash value of user B, random is a random number belonging to the finite field Fr of prime order, MPK is the master public key, and MSK is the master private key.

[0101] The encryption key is calculated using the bilinear pairing e, specifically:

[0102] AES(KEY) = G T = e(g 1, g2) = e(G1, G2)^(random * hB * MSK).

[0103] The above mechanism can ensure that the keys generated by each encryption are different by introducing a random number and using bilinear pairing for encryption, preventing replay attacks.

[0104] Based on the key data of the model owner and the public key of the model user, the re-encryption key rekeyA->B is obtained. The specific formula is as follows:

[0105] rekeyA->B = sk_A^(hB * hB * ~hA) = MSK^(hA * hB * hB * ~hA) = MSK^(hB * hB) = sk_B^hB.

[0106] Where ~hA is the inverse term of hA, i.e., hA · ~hA = 1, and MSK is the master secret key.

[0107] The role of the re-encryption key is to convert the data that could originally only be decrypted by the model owner into a form that can only be decrypted by a specific model user without exposing the decryption key of the model owner.

[0108] S204. The key proxy center generates a re-encrypted ciphertext based on the encryption element and the re-encryption key, and sends the re-encrypted ciphertext and the encrypted model file to user B.

[0109] As Figure 6 shown in the key proxy center interface, C1 is the received encryption element, specifically: 1312846803582106637169283078033930707954202387841318979760025135 715769723601042299595600138866159306413963657165088521250500842049, and RK_AB is the re-encryption key, specifically: 23155711718437570505119052765204492601569001381853636169930738396465256028458. Click the button: Generate C1 Prime (C’), and the generated result is the re-encrypted ciphertext as Figure 7 shown. Figure 7The re-encrypted ciphertext C1 Prime generated is specifically: 1545059287865236060747234654599979534126045148996391461596117997904637558709127496561198255140807 0948186974593661621832886922637401265134249694118212896320154992 87720706877297520902945685405181430825890289467946722000450280142447005.

[0110] The key proxy center performs proxy re-encryption through the encryption element g1 and the re-encryption key rekeyA->B to generate the re-encrypted ciphertext C1_prime. The specific formula is as follows:

[0111] Where C1_prime = g1^rekeyA->B, that is: C1_prime′ = g1^(sk_B*hB).

[0112] The key proxy center executes the proxy re-encryption operation to generate a re-encrypted ciphertext specific to the specified model user. This mechanism ensures that even the key proxy center cannot decrypt the data content alone, thereby further enhancing the security of the model file distribution process. By using the key proxy center for re-encryption, the private key of the model owner does not need to be directly exposed to any other party, reducing the risk of key leakage and making key management more centralized and efficient. Since the re-encryption process can be automated, the efficiency of model file distribution is improved, and at the same time, the security of each distribution is ensured. In summary, the method of using the key proxy center for re-encryption greatly enhances the security and flexibility of data transmission while simplifying the key management process.

[0113] S205. User B decrypts the encrypted model file based on User B's key data, the re-encrypted ciphertext, and the public master key to obtain the original model file.

[0114] In an implementable embodiment:

[0115] The model user calculates the encryption key based on the model user's key data, the re-encrypted ciphertext, and the public master key, and decrypts the encrypted model file based on the encryption key to obtain the original model file.

[0116] Such as Figure 8The user decryption data interface diagram shown, where MPK is the public key, specifically: 13806915923267245941861359600038993828156512703228617965642237360225378185833738690941731901751466743117623235748761242938734920612…, sk_B is the private key of the model user, specifically 46732394198382223760902488200050195240791549827563437233593297174859079749569, C' is the re-encrypted ciphertext, specifically: 1545059787652360607473465459997953412604514899639146159611799790463755870912749656119825514080709481869745936616218328869226374012, ID_B is the identifier of the model user, specifically: testme@3.4, nonce(hex) is the random number, specifically: 58de7a8995ba760617e626a1ebda6833, ciphertext(hex) is the encrypted data, specifically: 1c21330ef6f8f080af0fee387abc0c226e426e3a3c2b3f979b8a90b9a763386e3beedd23637bb5c. Click the decryption button to obtain the encrypted key tag(hex), specifically: 6eea838bb082fda79f36b8fc223fade5.

[0117] Exemplarily, when user B calculates the encryption key AES(KEY), user B knows the re-encrypted ciphertext C1_prime and the public key MPK of the master. Using the properties of bilinear pairing,

[0118] then e(C1_prime, MPK) = e(G1^(random*hB*MSK*hB*hB), G2^MSK)

[0119] = e(G1, G2)^(random*hB*MSK)(hB*hB*MSK).

[0120] Since e(G1, G2)^(random*hB*MSK) = GT = AES(KEY),

[0121] Let \(ss = sk\_B * hB\), then \(e(C1\_prime, MPK)^{(\sim ss)} = e(G1, G2) = AES(KEY)\).

[0122] To recover the encryption key \(AES(KEY)\), user B needs to eliminate the influence of \(ss\). Assume that \(\sim ss\) is the inverse of \(ss\), and through this inverse, the redundant terms are eliminated to obtain the encryption key. The encrypted model file is decrypted using the encryption key to obtain the original model file.

[0123] Another model file distribution method provided by the embodiments of this application is that the key center generates the master public key, the master private key, and the key data of different users, laying the foundation for the whole process. The model owner encrypts the original model file and generates the re-encryption key, which not only ensures the confidentiality of the model file but also realizes the precise control of the access rights of model users. The key proxy center performs the proxy re-encryption operation to generate the re-encrypted ciphertext specific to the designated model user. This mechanism ensures that even the key proxy center cannot decrypt the data content alone, thus further enhancing the data security. After receiving the re-encrypted ciphertext, the model user decrypts the re-encrypted ciphertext, and then recovers the encrypted model file. In this way, only the authorized model users can access the content of the model file, while other unauthorized users cannot decrypt or access the data.

[0124] Based on the model file distribution method introduced in the previous embodiments, correspondingly, this application also provides a model file distribution device. Figure 9 The structural schematic diagram of the device. As Figure 9 shown, the model file distribution device includes:

[0125] A key generation module 901, configured to generate the key data of the model owner by the key generation center based on the identifier of the model owner, and generate the key data of the model user based on the identifier of the model user.

[0126] An encryption module 902, configured to encrypt the original model file by the model owner based on the encryption element and the master public key to obtain the encrypted model file, generate the re-encryption key based on the key data of the model owner and the public key of the model user, and send the encryption element, the re-encryption key, and the encrypted model file to the key proxy center.

[0127] A proxy re-encryption module 903, configured to generate the re-encrypted ciphertext by the key proxy center based on the encryption element and the re-encryption key, and send the re-encrypted ciphertext and the encrypted model file to the model user.

[0128] The decryption module 904 is used for the model user to decrypt the encrypted model file based on the key data of the model user, the re-encrypted ciphertext, and the master public key to obtain the original model file.

[0129] Optionally, the encryption module is specifically configured to:

[0130] The model owner determines an encryption element based on a random number and the public key of the model user;

[0131] The model owner calculates an encryption key based on the encryption element and the master public key;

[0132] Use the encryption key to encrypt the original model file to obtain the encrypted model file;

[0133] Generate a re-encryption key based on the key data of the model owner and the public key of the model user;

[0134] Send the encryption element, the re-encryption key, and the encrypted model file to the key proxy center.

[0135] Optionally, the encryption module is specifically configured to:

[0136] The model owner uses bilinear pairing to calculate an encryption key based on the encryption element and the master public key; the master public key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0137] Optionally, the key generation module is specifically configured to:

[0138] The key generation center maps the identifier of the model owner and the identifier of the model user to the BLS12-381 elliptic curve respectively using a public hash function to obtain the public key of the model owner and the public key of the model user;

[0139] Generate the private key of the model owner based on the master private key and the public key of the model owner;

[0140] Generate the private key of the model user based on the master private key and the public key of the model user;

[0141] The key data of the model owner includes the public key of the model owner and the private key of the model owner; the key data of the model user includes the public key of the model user and the private key of the model user; the master private key is generated by the key generation center based on the BLS12-381 elliptic curve.

[0142] Optionally, the decryption module is specifically configured to:

[0143] Based on the key data of the model user, the re-encrypted ciphertext, and the public master key, the model user calculates an encryption key, and decrypts the encrypted model file based on the encryption key to obtain the original model file.

[0144] In addition, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the program is run by a processor, the model file distribution method introduced in any manner of the method embodiment is implemented.

[0145] In addition, an embodiment of the present application further provides a processor, which is used to run a computer program. When the program runs, it executes the model file distribution method introduced in any implementation manner of the foregoing method embodiment.

[0146] It should be noted that the various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. The device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components described as unit tips may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative work.

[0147] The above is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A model file distribution method, characterized in that: include: The key generation center generates key data of the model owner based on the identifier of the model owner, and generates key data of the model user based on the identifier of the model user; The model owner encrypts the original model file based on the encryption element and the master public key to obtain the encrypted model file, generates a re-encryption key based on the key data of the model owner and the public key of the model user, and sends the encryption element, the re-encryption key and the encrypted model file to the key agency center; The key agency center generates a re-encrypted ciphertext based on the encryption element and the re-encryption key, and sends the re-encrypted ciphertext and the encrypted model file to the model user; The model user decrypts the encrypted model file based on the model user's key data, the re-encrypted ciphertext and the master public key to obtain the original model file.

2. The method according to claim 1, characterized in that The model owner encrypts the original model file based on the encryption element and the master public key to obtain the encrypted model file, generates a re-encryption key based on the key data of the model owner and the public key of the model user, and sends the encryption element, the re-encryption key and the encrypted model file to the key agency center, including: The model owner determines the encryption element based on the random number and the public key of the model user; The model owner calculates the encryption key based on the encryption element and the master public key; Encrypting the original model file using the encryption key to obtain an encrypted model file; Generate a re-encryption key based on the key data of the model owner and the public key of the model user; The encryption element, the re-encryption key and the encrypted model file are sent to a key agency center.

3. The method according to claim 2, characterized in that The model owner calculates the encryption key based on the encryption element and the master public key, including: The model owner obtains the encryption key based on the encryption element and the master public key using bilinear pairing calculation; the master public key is generated by the key generation center based on the BLS12-381 elliptic curve.

4. The method according to claim 1, characterized in that: The key generation center generates key data of the model owner based on the identifier of the model owner, and generates key data of the model user based on the identifier of the model user, including: The key generation center uses a public hash function to map the model owner's identifier and the model user's identifier to the BLS12-381 elliptic curve based on the model owner's identifier and the model user's identifier, and obtains the model owner's public key and the model user's public key; Generate the model owner's private key based on the master private key and the model owner's public key; Generate the model user's private key based on the master private key and the model user's public key; The key data of the model owner includes the public key and the private key of the model owner; the key data of the model user includes the public key and the private key of the model user; the master private key is generated by the key generation center based on the BLS12-381 elliptic curve.

5. The method according to claim 1, characterized in that: The model user decrypts the encrypted model file based on the key data of the model user, the re-encrypted ciphertext and the master public key to obtain the original model file, including: The model user calculates an encryption key based on the model user's key data, the re-encrypted ciphertext and the master public key, and decrypts the encrypted model file based on the encryption key to obtain the original model file.

6. A model file distribution device, characterized in that: include: A key generation module, used for the key generation center to generate key data of the model owner based on the identifier of the model owner, and to generate key data of the model user based on the identifier of the model user; The encryption module is used for the model owner to encrypt the original model file based on the encryption element and the master public key to obtain the encrypted model file, generate a re-encryption key based on the key data of the model owner and the public key of the model user, and send the encryption element, the re-encryption key and the encrypted model file to the key agency center; An agent re-encryption module is used for the key agent center to generate a re-encrypted ciphertext based on the encryption element and the re-encryption key, and send the re-encrypted ciphertext and the encrypted model file to the model user; The decryption module is used for the model user to decrypt the encrypted model file based on the model user's key data, the re-encrypted ciphertext and the master public key to obtain the original model file.

7. The device according to claim 6, characterized in that The encryption module is specifically used for: The model owner determines the encryption element based on the random number and the public key of the model user; The model owner calculates the encryption key based on the encryption element and the master public key; Encrypting the original model file using the encryption key to obtain an encrypted model file; Generate a re-encryption key based on the key data of the model owner and the public key of the model user; The encryption element, the re-encryption key and the encrypted model file are sent to a key agency center.

8. The device according to claim 7, characterized in that The encryption module is specifically used for: The model owner obtains the encryption key based on the encryption element and the master public key using bilinear pairing calculation; the master public key is generated by the key generation center based on the BLS12-381 elliptic curve.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the program is executed by a processor, the model file distribution method according to any one of claims 1 to 5 is implemented.

10. A processor, characterized in that: Used to run a computer program, which, when running, executes the model file distribution method according to any one of claims 1 to 5.