Single sign-on access control method based on attribute encryption in cloud storage

By introducing a combination of attribute encryption and single sign-on in cloud storage, the problems of unauthorized access and privacy leakage in cloud storage are solved, efficient and secure access control and flexible data sharing are achieved, and the system's computing and communication overhead is reduced.

CN120301660APending Publication Date: 2025-07-11UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510525460.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In a cloud storage environment, it is difficult for the existing technology to effectively combine attribute encryption and single sign-on, resulting in unauthorized data access and privacy leakage. In addition, traditional ABE solutions have problems such as large computing and communication overhead and insufficient security in terms of dynamic access control.

Method used

The cloud storage-based attribute encryption method is adopted to generate the system public parameters and user private keys through the authentication server, and the public and private keys are generated in combination with the attribute authority. After the user registers, the data owner formulates access policies for encryption, the storage server verifies user attributes, and the attribute authority for key updates, realizing fine-grained access control and user revocation.

Benefits of technology

It realizes the confidentiality and privacy protection of user data, supports dynamic access control, reduces communication overhead, improves the efficiency and security of access control, and supports flexible cloud storage data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301660A_ABST
    Figure CN120301660A_ABST
Patent Text Reader

Abstract

The invention discloses a single sign-on access control method based on attribute encryption in cloud storage, and relates to the technical field of information security, and the method comprises the steps: S1, generating a system public parameter and a master key, and enabling an attribute authority to generate own public and private keys; s2, the user registers to an authentication server, and the authentication server issues a token to the user; s3, the authentication server generates a corresponding decryption key for each user; s4, the data owner formulates an access strategy, encrypts the message according to the access strategy and the system public parameters, calculates and uploads a ciphertext to the storage server; s5, the user sends a decryption request to the storage server, and a plaintext is obtained through decryption; s6, the attribute authority updates the ciphertext and the decryption key; the authentication server maintains a user revocation list. According to the method, dynamic fine-grained access control is realized on the premise that information such as user attributes is not leaked, the problem of privacy leakage caused by multiple times of registration of the user is relieved through a single sign-on method, and the method has high efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a single sign-on access control method based on attribute encryption in cloud storage. Background Art

[0002] With the wide application of cloud storage, how to achieve efficient and flexible access control while ensuring data security has become a key issue. Traditional access control mechanisms usually rely on identity-based authentication methods, which require maintaining a large number of user credentials, not only increasing the management cost but also bringing greater security risks. Attribute-Based Encryption (ABE), as a fine-grained encryption access control technology, allows data owners to define access policies based on user attributes without explicitly identifying users, thus improving the security and flexibility of data sharing. At the same time, the Single Sign-On (SSO) mechanism allows users to access multiple cloud services using a single identity authentication, simplifying the authentication process and enhancing the user experience. Combining ABE with SSO can not only enhance the security in the cloud environment but also improve the scalability and management efficiency of access control.

[0003] However, deploying a similar solution in a cloud storage environment still faces many challenges. First, the cloud environment is usually regarded as semi-trusted, and cloud service providers (CSPs) have full access to the stored data, which may lead to unauthorized data access and privacy leakage. Without an effective encryption mechanism, malicious insiders or external attackers may steal or abuse sensitive information in cloud storage. Second, traditional ABE schemes have limitations in dynamic access control. Especially when attributes are revoked and policies are updated, it often requires re-encrypting data or frequently updating keys, resulting in large computational and communication overheads and affecting system performance. In addition, combining SSO authentication with ABE also brings new security challenges. For example, when SSO credentials are leaked or stolen, attackers may bypass the access control mechanism of attribute encryption and illegally access protected data. Therefore, how to effectively combine multi-factor authentication (MFA), token verification and other mechanisms to prevent the abuse of SSO authentication credentials remains an urgent problem to be solved.

[0004] To address these challenges, there is an urgent need to design a secure, efficient single sign-on solution that supports dynamic access control, realizes efficient attribute revocation and policy update on the premise of ensuring data confidentiality, and can be seamlessly integrated with the SSO authentication mechanism to prevent unauthorized access problems caused by credential leakage. Summary of the Invention

[0005] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a single sign-on access control method based on attribute encryption in cloud storage.

[0006] The purpose of the present invention is achieved through the following technical solutions:

[0007] The present invention discloses a single sign-on access control method based on attribute encryption in cloud storage. The method is applied to a cloud storage system, which includes an authentication server, an attribute authority, a data owner, a user, a storage server, and a proxy server. The method specifically includes the following steps:

[0008] S1. The authentication server generates system public parameters and a master key according to security parameters, and the attribute authority generates its own public and private keys;

[0009] S2. The user registers with the authentication server, and the authentication server issues a token to the user to record user attributes and other user information;

[0010] S3. The authentication server generates a corresponding decryption key for each user according to the master key and the attributes in the user token;

[0011] S4. The data owner formulates an access policy, encrypts the message according to the access policy and the system public parameters, calculates and uploads the ciphertext to the storage server;

[0012] S5. The user sends a decryption request to the storage server. The storage server verifies the legitimacy of the user token with the authentication server, and determines whether the user can decrypt according to the user attributes in the token. If the access policy in the ciphertext is satisfied, the user decrypts to obtain the plaintext;

[0013] S6. The attribute authority updates the ciphertext and the decryption key according to its own public and private keys and the attributes to be revoked; the authentication server maintains a user revocation list, and when a user is revoked, the table entries are added and deleted.

[0014] Further, step S1 specifically includes the following steps:

[0015] S11. The authentication server generates a system master key MSK and system public parameters GP = (p, g, g a , G, G T , e, H, VK AS ) according to the security parameter λ; where G and G T are two multiplicative cyclic groups of prime order p; g is a generator of the group G; a is a random number selected from ; e is a bilinear mapping e: G × G → G T ; H is a hash function, H: {0,1} * → G; VKAS is a verification key;

[0016] S12. After verifying the user's legitimacy, the authentication server assigns a unique identifier u to the user; the authentication server selects two random numbers and calculates the first public key of user u and the first private key SK u = z u ; the authentication server generates a digital certificate The key pair used is (SK AS , VK AS ); where Enc( ) is an asymmetric encryption algorithm;

[0017] S13. The attribute authority AA k generates a second private key SK k = (α k , β k , γ k ); for each attribute x in the attribute set k managed by the attribute authority AA , the attribute authority AA k selects a version key k and generates the corresponding attribute public key Finally, the second public key of the attribute authority AA k is calculated where k is the index of the attribute authority, and the version key is a random number;

[0018] S14. User u writes the attribute set AttrSet u to be assigned into the digital certificate and submits the certificate Cert(u) to the attribute authority AA k ; the attribute authority AA k uses the verification key VK AS to verify the identity of user u; if the identity of user u is legal, the attribute authority AA k grants user u the corresponding attribute set AttrSet u , otherwise it will refuse to provide services for it.

[0019] Preferably, step S2 specifically includes: User u sends its certificate Cert(u), the attribute set AttrSet u and other information to the authentication server for registration; the authentication server returns to user u a token Token(u) = (H, P, σ) and a public-private key pair (PK u , SK u); where the header H and the payload part P of the token Token(u) contain information such as user attributes and are encoded using Base64; the signature part σ uses the ECC elliptic curve algorithm.

[0020] Preferably, step S3 specifically includes the following steps:

[0021] S31. The user u sends the token Token(u) to the attribute authority AA k , and the authentication server verifies whether the identity of the user u is legal;

[0022] S32. If the identity of the user u is legal, the attribute authority AA k uses the obtained attribute set AttrSet u , the third private key SK a , the public key set and the public parameters GP to generate the first key

[0023] All the first keys are combined to obtain the decryption key SK u,a , and it is returned to the user and the trusted proxy server; where, is a random number selected by the attribute authority, j ∈ S U , k ∈ S A , S U and S A represent the user set and the attribute authority set.

[0024] Preferably, step S4 specifically includes the following steps:

[0025] S41. The data owner divides the message m into multiple segments {m1,..., m n}, and encrypts these segments using different keys {ck1,..., ck n} through the symmetric encryption algorithm; the data owner formulates the corresponding access policy A i for the key ck i ; where the access policy A i is a tree structure, the leaf nodes are attributes, and the root node is the key ck i ;

[0026] S42. The data owner selects a random exponent s and a vector For an l×n matrix M, calculate the set where l is the number of attributes included in the access policy; y2,..., y n are used to share the exponent s; M i represents the i-th row of the matrix M;

[0027] S43. The data owner selects a random number in the group in and calculate the ciphertext

[0028] Then upload it to the cloud server and send the ciphertext to the proxy server at the same time; where, I A is the set of attribute authorities involved in the access policy; ρ(i) is the attribute represented by the i-th row of the matrix M; k ∈ I A ; i ∈ {1,..., l}.

[0029] Preferably, step S5 specifically includes the following steps:

[0030] S51. There are multiple cloud servers in the system. The user selects the cloud server where the ciphertext is located and sends a decryption request, with the token Token(u) attached. The authentication server verifies whether the user's identity is legal and whether the user's attributes meet the access structure in the ciphertext;

[0031] S52. The proxy server selects a set of constants If and only if the set {λ i} is a legal sharing of the exponent s, the proxy server recovers the exponent s = ∑ i∈I ω i λ i ; After obtaining the exponent, the proxy server calculates the decryption password

[0032] Then send the decryption password to the non-revoked user u j ; where, is the set of attributes in the ciphertext; is the set of attribute indices; N A = |I A | is the number of attribute authorities involved in the ciphertext;

[0033] S53. The user uses its decryption private key SK u to calculate the content key Next, use the content key ck to decrypt and recover the message m = Dec ck (Enc ck (m)).

[0034] Preferably, step S6 specifically includes the following steps:

[0035] S61. After a certain user attribute is revoked, the attribute authority AA k managing the attribute generates a new version key attribute update key the private key update key of the non-revoked user u j and the ciphertext update key and the ciphertext update key

[0036] The revoked attribute The attribute key of is updated to Attribute Authority AA k Sends the third key To the non-revoked user u j And sends the fourth key To the cloud server; where D 2,i Is the ciphertext component; Is the initial version key before revocation; Is a random number selected by the attribute authority;

[0037] S62. After receiving the updated key sent by the attribute authority, the non-revoked user u j Updates its private key to

[0038] Where x k Represents the non-revoked attributes in the set S j,k And

[0039] S63. The cloud server stores the updated key sent by the attribute authority; when the server receives a decryption request from a user, the server checks whether the ciphertext contains the revoked attribute If it contains, that is Then the cloud server updates the ciphertext to

[0040] If it does not contain, it sends the decryption password TK to the user;

[0041] S64. The authentication server maintains a global user revocation list RevList, the entries of which are composed of N boolean values flag N Where N = |u| is the number of registered users in the system; when a registered user u i Registers, the authentication server adds a new entry flag to the list i And sets its value to 1; when the revoked user u j Is revoked, the value of the corresponding entry flag in the list j Is set to 0; before the attribute authority and the cloud server provide corresponding services to users, they need to check the corresponding entries in the revocation list, and only when the corresponding entry is 1 will the attribute authority and the cloud server provide corresponding services to it.

[0042] The beneficial effects of the present invention are:

[0043] 1) In the system of the present invention, there is only one completely trusted authentication server, which realizes the confidentiality of user data to the cloud server and guarantees the privacy of the data owner and users.

[0044] 2) The present invention includes fine-grained attribute revocation and user revocation, ensuring the forward and backward security of the method, enabling the system to manage user permissions in real time, and realizing more practical and flexible cloud storage data sharing.

[0045] 3) The present invention adopts a single sign-on mechanism. After a user registers with the authentication server, the user obtains a token containing information such as attributes. The user can log in to all cloud servers in the system through this token without re-registering, greatly improving efficiency and reducing communication overhead. Brief Description of the Drawings

[0046] Figure 1 It is a schematic diagram of the steps of the single sign-on access control method based on attribute encryption in cloud storage according to an embodiment of the present invention. Detailed Embodiment

[0047] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0048] The present invention discloses a single sign-on access control method based on attribute encryption in cloud storage, and its schematic diagram of steps is as Figure 1 shown. The method is applied to a cloud storage system, and the cloud storage system includes an authentication server, an attribute authority, a data owner, a user, a storage server, and a proxy server. The method specifically includes the following steps:

[0049] S1. The authentication server generates system public parameters and a master key according to security parameters, and the attribute authority generates its own public and private keys;

[0050] S2. The user registers with the authentication server, and the authentication server issues a token to the user for recording user attributes and other user information;

[0051] S3. The authentication server generates a corresponding decryption key for each user according to the master key and the attributes in the user token;

[0052] S4. The data owner formulates an access policy, encrypts the message according to the access policy and the system public parameters, calculates and uploads the ciphertext to the storage server;

[0053] S5. The user sends a decryption request to the storage server. The storage server verifies the legitimacy of the user token with the authentication server, and determines whether the user can decrypt according to the user attributes in the token. If the access policy in the ciphertext is satisfied, the user decrypts to obtain the plaintext.

[0054] S6. The attribute authority updates the ciphertext and the decryption key according to its own public and private keys and the attributes to be revoked; the authentication server maintains a user revocation list, and when a user is revoked, the table entries are added and deleted.

[0055] Specifically, step S1 specifically includes the following steps:

[0056] S11. The authentication server generates the system master key MSK and the system public parameters GP = {p, g, g a , G, G T , e, H, VK AS ) according to the security parameter λ; where G and G T are two multiplicative cyclic groups of prime order p; g is the generator of the group G; a is a random number selected from ; e is a bilinear map e: G×G→G T ; H is a hash function, H: {0,1} * →G; VK AS is a verification key; it is written into the broadcast module of the authentication server as the public key;

[0057] S12. After verifying the user's legitimacy, the authentication server assigns a unique identifier u to the user; the authentication server selects two random numbers and calculates the user u's first public key and the first private key SK u = z u ; the authentication server generates a digital certificate using the key pair (SK AS , VK AS ); where Enc() is an asymmetric encryption algorithm;

[0058] S13. The attribute authority AA k generates the second private key SK k = (α k , β k , γ k ); for each attribute x k in the attribute set managed by the attribute authority AA k , the attribute authority AA k selects a version key and generates the corresponding attribute public key Finally, it calculates to obtain the attribute authority AAk the second public key where k is the index of the attribute authority, and the version key is a random number;

[0059] S14. The user u writes the attribute set AttrSet to be allocated u into the digital certificate and submits the certificate Cert(u) to the attribute authority AA k . The attribute authority AA k uses the verification key VK AS to verify the identity of the user u; if the identity of the user u is legal, the attribute authority AA k assigns the corresponding attribute set AttrSet to the user u u , otherwise, it will refuse to provide services for it.

[0060] Specifically, step S2 specifically includes: The user u sends its certificate Cert(u), the attribute set AttrSet u and other information to the authentication server for registration; the authentication server returns a JWT-formatted token Token(u) = (H, P, σ) and a public-private key pair (PK u , SK u ) to the user u; where the header H and the payload part P of the token Token(u) contain information such as user attributes and are encoded using Base64; the signature part σ uses the ECC elliptic curve algorithm.

[0061] Specifically, step S3 specifically includes the following steps:

[0062] S31. The user u sends the token Token(u) to the attribute authority AA k , and the authentication server verifies whether the identity of the user u is legal;

[0063] S32. If the identity of the user u is legal, the attribute authority AA k uses the verified attribute set AttrSet u , the third private key SK a , the public key set and the public parameters GP to generate the first key

[0064] All the first keys are combined to obtain the decryption key SK u,a , and it is returned to the user and the trusted proxy server; where, is a random number selected by the attribute authority, j ∈ S U , k ∈ S A , S U and S ARepresents the user set and the attribute authority set.

[0065] Specifically, step S4 specifically includes the following steps:

[0066] S41. The data owner divides the message m into multiple segments {m1,..., m n}, and encrypts these segments using different keys {ck1,..., ck n} through a symmetric encryption algorithm; the data owner formulates a corresponding access policy A i for the key ck i ; among them, the access policy A i is a tree structure, the leaf nodes are attributes, and the root node is the key ck i ;

[0067] S42. The data owner selects a random exponent s and a vector For an l×n matrix M, calculate the set where l is the number of attributes included in the access policy; y2,..., y n are used to share the exponent s; M i represents the i-th row of the matrix M;

[0068] S43. The data owner selects a random number in the group and calculates the ciphertext

[0069] Then upload it to the cloud server and send the ciphertext to the proxy server at the same time; among them, I A is the set of attribute authorities involved in the access policy; ρ(i) is the attribute represented by the i-th row of the matrix M; k∈I A ; i∈{1,..., l}.

[0070] Specifically, step S5 specifically includes the following steps:

[0071] S51. There are multiple cloud servers in the system. The user selects the cloud server where the ciphertext is located and sends a decryption request, which is accompanied by the token Token(u). The authentication server verifies whether the user's identity is legal and whether the user's attributes meet the access structure in the ciphertext;

[0072] S52. The proxy server selects a set of constants If and only if the set {λ i} is a legal sharing of the exponent s, the proxy server recovers the exponent s = ∑ i∈I ω i λ i ; after obtaining the exponent, the proxy server calculates the decryption password

[0073] Then, the decryption password is sent to the non-revoked user u j ; where is the set of attributes in the ciphertext; is the set of attribute indexes; N A = |I A | is the number of attribute authorities involved in the ciphertext;

[0074] S53. The user uses its decryption private key SK u to calculate the content key Next, the content key ck is used to decrypt and recover the message m = Dec ck (Enc ck (m)).

[0075] Specifically, step S6 specifically includes the following steps:

[0076] S61. After a certain user attribute is revoked, the attribute authority AA k managing the attribute generates a new version key attribute update key The private key update key j for the non-revoked user u and the ciphertext update key

[0077] The attribute key of the revoked attribute is updated to The attribute authority AA k sends the third key to the non-revoked user u j , and sends the fourth key to the cloud server; where D 2,i is the ciphertext component; is the initial version key before revocation; is a random number selected by the attribute authority;

[0078] S62. After receiving the update key sent by the attribute authority, the non-revoked user u j updates its private key to

[0079] where x k represents the non-revoked attributes in the set S j,k , and

[0080] S63. The cloud server stores the update key sent by the attribute authority; when the server receives a decryption request from a user, the server checks whether the ciphertext contains the revoked attribute If it contains, that is Then the cloud server updates the ciphertext to

[0081] If it does not contain, the decryption password TK is sent to the user;

[0082] S64. The authentication server maintains a global user revocation list RevList, and its entries consist of N boolean values flag N constitute; where N = |u| is the number of registered users in the system; when a registered user u i registers, the authentication server adds a new entry flag i to the list and sets its value to 1; when the revoked user u j is revoked, the corresponding entry flag j in the list is set to 0; before the attribute authority and the cloud server provide corresponding services to the user, they need to check the corresponding entry in the revocation list. Only when the corresponding entry is 1, the attribute authority and the cloud server will provide corresponding services to it.

[0083] The present invention includes fine-grained attribute revocation and user revocation, which ensures the forward and backward security of the scheme, enables the system to manage user permissions in real time, and realizes more practical and flexible cloud storage data sharing. There is only one fully trusted authentication server in the system, which realizes the confidentiality of user data to the cloud server and guarantees the privacy of data owners and users.

[0084] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. And the changes and alterations made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.

Claims

1. A single sign-on access control method based on attribute encryption in cloud storage, characterized in that: The method is applied to a cloud storage system, which includes an authentication server, an attribute authority, a data owner, a user, a storage server, and a proxy server. The method specifically includes the following steps: S1. The authentication server generates system public parameters and master keys based on security parameters, and the attribute authority generates its own public and private keys; S2. The user registers with the authentication server, and the authentication server issues a token to the user to record user attributes and other user information; S3. The authentication server generates a corresponding decryption key for each user based on the master key and the attributes in the user token; S4. The data owner formulates an access policy, encrypts the message according to the access policy and system public parameters, and calculates and uploads the ciphertext to the storage server; S5. The user sends a decryption request to the storage server. The storage server verifies the legitimacy of the user token with the authentication server and determines whether the user can decrypt based on the user attributes in the token. If the access policy in the ciphertext is met, the user decrypts and obtains the plaintext. S6. The attribute authority updates the ciphertext and decryption key based on its own public and private keys and the attributes that need to be revoked; the authentication server maintains a user revocation list and adds and deletes entries when revoking a user.

2. The single sign-on access control method based on attribute encryption in cloud storage according to claim 1, characterized in that Step S1 specifically includes the following steps: S11. The authentication server generates the system master key MSK and the system public parameters GP = (p, g, g a , G, G T , e, H, VK AS ); where G and G T are two multiplicative cyclic groups of prime order p; g is a generator of group G; a is a random number selected from ; e is a bilinear map e: G×G → G T ; H is a hash function, H: {0, 1} * → G; VK AS is a verification key; After verifying the user's legitimacy, the authentication server assigns a unique identifier u to the user; the authentication server selects two random numbers u u , and calculates the first public key and the first private key SK u = z u ; the authentication server generates a digital certificate using the key pair (SK AS , VK AS ); where Enc( ) is an asymmetric encryption algorithm; S13. Attribute Authority AA k Generate the second private key SK k =(α k , β k , γ k ); For the attribute authority AA k For each attribute x in the set of attributes managed by it k , the attribute authority AA k selects a version key and generates the corresponding attribute public key Finally, calculate the second public key of the attribute authority AA k as where k is the index of the attribute authority, and the version key α k , β k , γ k , are random numbers; S14. User u writes the set of attributes AttrSet to be assigned u into the digital certificate and submits the certificate Cert(u) to the attribute authority AA k . The attribute authority AA k uses the verification key VK AS to verify the identity of user u. If the identity of user u is legal, the attribute authority AA k assigns the corresponding set of attributes AttrSet to user u u , otherwise, it will refuse to provide services for him / her.

3. The single sign-on access control method based on attribute encryption in cloud storage according to claim 2, wherein, Step S2 specifically includes: User u sends their certificate Cert(u), attribute set AttrSet u and other information to the authentication server for registration; the authentication server returns to user u a token Token(u) = (H, P, σ) and a public-private key pair (PK u , SK u ); where the file header H and the payload part P of the token Token(u) contain information such as user attributes, encoded using Base64; the signature part σ uses the ECC elliptic curve algorithm.

4. The single sign-on access control method based on attribute encryption in cloud storage according to claim 3, wherein Step S3 specifically includes the following steps: S31. User u sends the token Token(u) to the attribute authority AA k , and the authentication server verifies whether the identity of user u is legal; S32. If the identity of user u is legal, the attribute authority AA k uses the obtained attribute set AttrSet u , the third private key SK a , the public key set and the public parameters GP to generate the first key All the first key combinations are combined to obtain the decryption key SK u,a , and it is returned to the user and the trusted proxy server; where h j,k , is a random number selected by the attribute authority, j ∈ S U , k ∈ S A , S U and S A represent the user set and the attribute authority set respectively.

5. The single sign-on access control method based on attribute encryption in cloud storage according to claim 4, characterized in that: Step S4 The specific steps include: S41. The data owner divides the message m into multiple segments {m1, …, m n}, and encrypts these segments using different keys {ck1, …, ck n} through a symmetric encryption algorithm; the data owner formulates a corresponding access policy A i for the key ck i ; among them, the access policy A i is a tree structure, the leaf nodes are attributes, and the root node is the key ck i ; S42. The data owner selects a random exponent s and vector For an l×n matrix M, compute the set where l is the number of attributes included in the access policy; y2, …, y n for sharing the exponent s; M i represents the i-th row of the matrix M; S43. The data owner selects a random number in the group and calculates the ciphertext ​ Then upload it to the cloud server and send the ciphertext to the proxy server at the same time; where, I A is the set of attribute authorities involved in the access policy; ρ(i) is the attribute represented by the i-th row of matrix M; k ∈ I A ; i ∈ {1, …, l}.

6. The single sign-on access control method based on attribute encryption in cloud storage according to claim 5, wherein Step S5 specifically includes the following steps: S51. There are multiple cloud servers in the system. The user selects the cloud server where the ciphertext is located and sends a decryption request, which is accompanied by a token Token(u). The authentication server verifies whether the user's identity is legitimate and whether the user's attributes meet the access structure in the ciphertext. S52. The proxy server selects a set of constants If and only if the set {λ i} is a legal share of the exponent S, the proxy server recovers the exponent s = ∑ i∈I ω i λ i ; After obtaining the exponent, the proxy server calculates the decryption password Then the decryption password is sent to the non-revoked user u j ; where is the set of attributes in the ciphertext; is the set of attribute indexes; N A = |I A | is the number of attribute authorities involved in the ciphertext; The user uses their decryption private key SK u to calculate the content key Next, use the content key cj to decrypt the message m = Dec ck (Enc ck (m)) for decryption and recovery.

7. The single sign-on access control method based on attribute encryption in cloud storage according to claim 6, wherein Step S6 specifically includes the following steps: S61. A certain user attribute After being revoked, the attribute authority AA k Generates a new version key Attribute update key Non-revoked user u j 's private key update key And ciphertext update key The revoked attribute 's attribute key is updated to Attribute authority AA k Sends the third key To non-revoked user u j And sends the fourth key To the cloud server; where D 2,i Is the ciphertext component; Is the initial version key before revocation; Is a random number selected by the attribute authority After receiving the updated key sent by the attribute authority, the non-revoked user u j updates its private key to where x k represents the attributes in the set S j,k that are not revoked, and The cloud server stores the updated key sent by the attribute authority; when the server receives a decryption request from a user, the server checks whether the ciphertext contains the revoked attribute If it contains, that is then the cloud server updates the ciphertext to If it does not contain, then the decryption password TK is sent to the user; The authentication server maintains a global user revocation list RevList, and its entries are composed of N boolean values flag N ; where N = |u| is the number of registered users in the system; when a registered user u i registers, the authentication server adds a new entry flag i to the list and sets its value to 1; when the revoked user u j is revoked, the corresponding entry flag j in the list is set to 0; before the attribute authority and the cloud server provide corresponding services to the user, they need to check the corresponding entry in the revocation list. Only when the corresponding entry is 1 will the attribute authority and the cloud server provide corresponding services to it.