Revocable attribute-based encryption method with strategy hiding

Through the combination of cuckoo filter and hash obfuscation technology, the AGK tree and attribute group key are established, which solves the problem of user privacy leakage and permission revocation in the CP-ABE solution, and realizes efficient policy hiding and fine-grained user attribute revocation, enhancing data security and query efficiency.

CN120342749APending Publication Date: 2025-07-18HUAIYIN INSTITUTE OF TECHNOLOGY
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510658279.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing ciphertext policy attribute encryption (CP-ABE) scheme has problems such as user privacy information leakage and permission revocation insecure, and cannot prove complete security in real-world attack scenarios, and there are security risks when user permissions are changed.

Method used

The cuckoo filter is used to combine hash obfuscation technology to hide the mapping function. By establishing AGK tree and attribute group keys, a fine-grained attribute revocation function is realized, improving privacy and insert query efficiency.

Benefits of technology

It realizes efficient policy hiding and fine-grained user attribute revocation, enhances data security, reduces confidentiality costs, and improves user privacy protection and query efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342749A_ABST
    Figure CN120342749A_ABST
Patent Text Reader

Abstract

The invention discloses a revocable attribute-based encryption method with strategy hiding, which is based on ciphertext strategy attribute encryption, solves the problem that user privacy is leaked due to disclosure of an access strategy, realizes revocation of fine-grained user attribute access authority, and is proved to be completely safe. In a system establishment stage, system parameters are disclosed, a public key and a master key are generated, an authoritative authority authorizes a data user, distributes a private key and generates an AGK tree and an attribute group key, a data owner generates a ciphertext according to the public key, an access structure set by the data owner and a selected secret value, and the ciphertext is transmitted to the data owner. And then hiding the mapping function by using a cuckoo filter, positioning the attribute by a data user through the cuckoo filter, updating a private key by using an attribute group key, and finally decrypting the ciphertext to obtain the wanted information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security, and in particular to a revocable attribute-based encryption method with policy hiding. Background Art

[0002] With the booming development of network technology, data sharing has become very common. In order to prevent data leakage, data owners need to encrypt the data before sharing it. Access control is crucial as the first line of defense against unauthorized access to shared data.

[0003] Attribute-based encryption (ABE) has received increasing attention because it can protect data privacy and achieve fine-grained, one-to-many, and non-interactive access control. Existing ABE schemes have two complementary forms, namely the key-policy attribute-based encryption (KP-ABE) scheme and the ciphertext-policy attribute-based encryption (CP-ABE) scheme. In the KP-ABE scheme, the access policy is associated with the key, and the data is annotated with attributes. In the CP-ABE scheme, the access policy is associated with the data, and the attributes are associated with the key. Only those keys whose associated attributes satisfy the policy associated with the data can decrypt it.

[0004] Therefore, in the prior art, the CP-ABE scheme is more in line with the conventional access control model. However, the traditional CP-ABE scheme has some problems. The existing construction can only be proven to be selectively secure and cannot be proven to be fully secure, which is more suitable for real-world attack scenarios. Moreover, when users upload ciphertexts, they also upload their access policies, and the access policies usually contain some attribute information of the users. If not hidden, it will lead to the leakage of user information. In addition, in the encryption system, user permissions change from time to time, and the conventional implementation of user permission revocation also brings security risks. Therefore, there is an urgent need for a new attribute encryption method with high efficiency, hidden policy, and high-security permission revocation to improve user data security. Summary of the Invention

[0005] Object of the Invention: To solve the problems mentioned in the background art, the present invention discloses a revocable attribute-based encryption method with policy hiding. The mapping function is hidden by combining the cuckoo filter with the hash obfuscation technology. Data users locate the attributes through the cuckoo filter and update the private key using the attribute group key, improving the privacy and the efficiency of insertion and query of the method. By establishing the AGK tree and the attribute group key, an efficient fine-grained attribute revocation function is realized.

[0006] Technical Solution:

[0007] The present invention discloses a revocable attribute-based encryption method with policy hiding, and the method includes the following steps:

[0008] S1 System Initialization: The authorization agency constructs a bilinear group structure of three-prime order, generating a public key PK containing bilinear mapping parameters and a master private key MK;

[0009] S2 Attribute Key Generation: Based on the user attribute set S u Generate a private key component containing a random mask to generate a user private key, and dynamically obtain an attribute group key through the path key PK t ;

[0010] S3 Encryption and Policy Hiding: Calculate the shared value λ based on the access policy (M, ρ) i , encrypt the data and perform re-encryption to generate a new attribute group key

[0011] S3.1 Combine the cuckoo filter with the hash obfuscation technique, insert the unique key value v i and the fingerprint hash f ρ(i) to perform policy hiding;

[0012] S4 Decryption Phase: Through the user attribute set S u and the cuckoo filter, restore the row number mapping function corresponding to the attribute λ i , the user decrypts the attribute group key through the path key PK t and updates the private key; Use the bilinear pairing calculation to eliminate the random mask and restore e(g, g) , and finally restore the plaintext msg; αs

[0013] S5 When a user attribute is revoked, only the attribute group key involving the revoked attribute is updated, and the attribute key distribution is dynamically managed through the AGK tree.

[0014] Furthermore, the system initialization steps are as follows:

[0015] The authorization agency selects a bilinear additive group G of order N = p1p2p3, defines as a subgroup of order p in G i , i ∈ {1, 2, 3}, where a bilinear mapping e: G × G → G T ; The authorization agency selects random numbers α, a ∈ Z N , where Z N represents the set of integers modulo N, i.e., {0, 1, 2, 3..., N - 1}, g is the generator of the group X3 is the generator of the group , input an attribute set S, for each attribute λ j , where 1 ≤ j ≤ |S|, |S| represents the number of attributes in the attribute set S, select a random value s j ∈ Z N, calculate the public key PK and the master private key MK respectively:

[0016] The public key PK contains the order N of the bilinear group G, the generator g of the group the a-th power of the generator g, and the result e(g, g) of the bilinear mapping α for subsequent encryption and decryption, and for each attribute λ j , generate the corresponding public key parameter T j , that is where s j is a randomly selected number;

[0017] The master private key MK contains the core parameter random number α for generating the user private key and the generator X3 of

[0018] Furthermore, the user private key described in S2 is generated as follows:

[0019] The authorization agency first selects a random number t ∈ Z N and a random element According to PK, MK, and the user's attributes S u calculate the user's key SK u ; The key SK u contains K, L, K i in three parts: K is composed of the product of the α-th power of the generator g of the group the at-th power of g, and the random element R0, that is, K = g α g at R0, the random number t ∈ Z N ; L represents the commitment of t as the product of g t and the random element R′0, that is, expressed as L = g t R′0; For each attribute λ in the user attribute set S u , i ∈ S i , K u is composed of the generated corresponding private key component i and the random number R and the random number R i product, that is where comes from the public key.

[0020] Furthermore, the attribute group key described in S2 is generated as follows:

[0021] The authorization structure generates an attribute group E for each attribute i , E i represents the set of users who own this attribute. The cloud server generates an AGK tree for all users U and distributes the attribute group key to the users in U; In the tree, each node v jAll hold an AGK, denoted as AGK j , the set of all AGKs on the path from the leaf node to the root node is called the path key. Each member in U is assigned to a leaf node of the tree, random keys are generated and assigned for each leaf node and internal node, and for each member u t ∈U, the set of all AGKs of all nodes on the path from the leaf node to the root node, i.e., the path key PK, is established t .

[0022] Furthermore, the specific processes of S3 data encryption and re-encryption are as follows:

[0023] The data owner sets up an access policy (M, ρ) for the encrypted data. M is an l×n matrix, and ρ is the mapping from each row M i to the attribute ρ(i). The data owner selects a random vector z = (s, z2, …, z n ), T , for each row of M, a random number r i ∈Z N is selected, and λ i = M i ·z is calculated. For the encrypted data msg, the ciphertext CT is calculated. Random numbers K ρ(i) ∈Z N are selected for all ρ(i), and the re-encrypted ciphertext CT′ is obtained:

[0024] The re-encrypted ciphertext CT′ includes the encrypted message C, the master key commitment D, the attribute-related ciphertext component C i and the commitment D i of the random number. C is the same as in the original encryption stage, and the bilinear pair e(g, g) αs is used as a mask to protect the plaintext msg. This component is retained during re-encryption to ensure that the underlying security parameter of the encrypted message remains unchanged, i.e., C = msg·e(g, g) αs ; D = g s provides a public commitment to the master secret s for calculating the bilinear pairing during subsequent decryption, which is the same as in the original encryption stage; the ciphertext component C i is the same as in the original encryption stage and is expressed as During re-encryption, D i is modified to , i.e., the new attribute group key. The random number r i is bound to the new attribute group key . Only the user with the latest K λi can solve g ri to achieve attribute revocation; if a user is revoked, the system can generate a new attribute group key for this attribute and update D i, the revoked user cannot complete decryption because they cannot obtain a new key; in the AGK tree, select the minimum covering set of the attribute group users, namely AGK(E i ), for each attribute y ∈ Y in the access policy, use the minimum covering set AGK(E y ) of the attribute group E y ) to encrypt the key K ρ(y) in K , generate the header information Hdr expressed as K (K ρ(y) ) is the symmetric encryption of K ρ(y) with the key K

[0025] Further, the specific steps of S3.1 are as follows:

[0026] Define the parameters (m, b, f, H1, H2) of the attribute cuckoo filter τ, where m represents the number of buckets of the filter, n represents the size of each bucket, f represents the fingerprint length, and H1 and H2 are hash functions used to calculate the initial position and alternative bucket position of the bucket;

[0027] Add the attribute ρ(i) to the filter and insert a unique value v i = ξ i l + i, where ξ i is a random number;

[0028] Use the fingerprint generation function to generate the fingerprint f ρ(i) of ρ(i), and calculate the position inserted into the bucket through H1 and H2, where h1 and h2 are the positions where the data calculated by the hash function is stored in the bucket. If there is an empty insertable position in the bucket, randomly insert the key-value pair into one of them. If both buckets are full, randomly remove one element for insertion, and the removed element recalculates the alternative bucket position for insertion. Repeat until insertion is successful. If no empty position is found after 500 repeated operations, expand the size of the filter and increase the number of buckets.

[0029] Further, the decryption process of the attribute group key in the S4 decryption stage is as follows;

[0030] User u t has a valid attribute i, that is, u t ∈E i , use the common AGK in AGK(G i ) and PK t to decrypt the attribute group key from Hdr E i = {u1, u2, u5, u6, u7, u8}, then u5 can use the path key AGK3 ∈ PK5 to decrypt Kλi The user updates their private key SK using the attribute group key u Update the K in the original user's private key i to The other private key components remain unchanged, that is

[0031] Furthermore, the user attribute revocation process described in S5 is as follows:

[0032] When a user attribute is revoked, the AGK updates the user attribute group involving the revoked attribute, and the server randomly selects the vector z′ = (s′, z′2, …, z′ n ) T and the attribute group key Update the ciphertext CT′ to ciphertext CT”:

[0033] Mask the message msg using the superposition value s + s′ of the old and new master secrets for the encrypted message C, that is msg·e(g,g) α(s+s′) ; After the original D in the ciphertext is updated, it needs to be bound to the new parameter s′, that is, D is g (s+s′) for subsequent pairing calculations; C i Keep the original encryption structure, that is D i Bind the random number r i to the new attribute group key The revoked user cannot solve due to the lack of resulting in decryption failure. The non-revoked users obtain and can correctly calculate the pairing terms through the AGK tree; For each attribute y ∈ Y in the access policy, generate a new attribute group key for subsequent re-encryption operations. According to the attribute group E corresponding to the attribute y y , extract its minimum covering set AGK(E y ) from the AGK tree. For each newly generated Use all the keys K in AGK(E y ) to encrypt them respectively, aggregate the encryption results of all attributes, and generate a ciphertext set to form the final header information Hdr

[0034] Beneficial effects:

[0035] 1. The present invention combines attribute-based encryption with cuckoo filter technology, making up for the shortcomings of existing methods in the prior art in implementing the policy hiding function, which cannot delete attributes and expand policies. It realizes a more efficient attribute positioning mechanism through key-value pair comparison, improving the privacy and the efficiency of insertion and query of the scheme

[0036] 2. The present invention realizes a more efficient and finer-grained user attribute revocation function by establishing an AGK tree and an attribute group key in an attribute-based encryption method with policy hiding, improves the problem that the existing attribute-based encryption method with policy hiding usually uses a user list to implement user revocation, often requires a large amount of modification of user keys and ciphertexts, and has a large computational overhead, enhances data security while reducing the confidentiality cost. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 It is a flowchart of the method of the present invention;

[0038] Figure 2 It is a schematic diagram of the application of the AGK tree of the present invention;

[0039] Figure 3 It is a schematic diagram of the insertion value of the cuckoo filter in the embodiment of the present invention;

[0040] Figure 4 It is a graph of the comparison experiment results in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0042] As Figure 1 shown, this embodiment discloses a revocable attribute-based encryption method with policy hiding:

[0043] S1 System initialization: The authorization agency constructs a three-prime-order bilinear group structure and generates a public key PK and a master private key MK containing bilinear mapping parameters.

[0044] First, the authorization agency selects a bilinear additive group G of order n = p1p2p3 (3 different prime numbers), defines as a subgroup of order p i in G, i ∈ {1, 2, 3}, where a bilinear mapping e: G × G → G T . Then the authorization agency selects a random number a, a ∈ Z N , where Z N represents the set of integers modulo N, i.e., {0, 1, 2, 3..., N - 1}, g is the generator of the group , X3 is the generator of the group , and an attribute set S is input. For each attribute λ j, where \(1\leq j\leq|S|\), and \(|S|\) represents the number of attributes in the attribute set \(S\). Select a random value \(s\) j \(\in\mathbb{Z}\) N . Calculate the public key \(PK\) and the master private key \(MK\) respectively:

[0045]

[0046] \(MK=(a, X_3)\)

[0047] The public key \(PK\) contains the order \(N\) of the bilinear group \(G\), the generator \(g\) of the group the \(a\)-th power of the generator \(g\), and the result \(e(g, g)\) of the bilinear mapping α for subsequent encryption and decryption, and for each attribute \(\lambda\) j , generate the corresponding public key parameter \(T\) j , that is where \(s\) j is a randomly selected number.

[0048] The master private key \(MK\) contains the core parameter random number \(\alpha\) for generating the user's private key and the generator \(X_3\) of, which is used to introduce randomness into the private key.

[0049] S2 Attribute Key Generation: The user's private key generation generates private key components containing random masks based on the user's attribute set, and uses subgroup random elements \((R_0, R_0', R_i)\) to enhance the anti-leakage ability of the private key; Attribute Group Key Tree (AGK tree) Construction: Generate a binary tree structure for all users, assign attribute group keys to each node, and users dynamically obtain attribute group keys through the path key \((PK\) t ) to support efficient key distribution and update.

[0050] User Private Key Generation:

[0051] The authorization agency first selects a random number \(t\in\mathbb{Z}\) N and a random element Then, according to \(PK\), \(MK\), and the user's attributes \(S\) u calculate the user's key \(SK\) u :

[0052]

[0053] The key \(SK\) u contains \(K\), \(L\), \(K\) i which consists of three parts. \(K\) is composed of the product of the \(\alpha\)-th power of the generator \(g\) of the group the \(at\)-th power of \(g\), and the random element \(R_0\), that is \(K = g\) α g at \(R_0\), where the random number \(t\in\mathbb{Z}\) N ; \(L\) represents the commitment of \(t\) as \(g\)t and the product of the random element R′0, which is denoted as L = g t R′0; for each attribute λ u in the user attribute set S i , i ∈ S u , K i consists of the corresponding private key component generated and the random number R i , that is where comes from the public key.

[0054] Attribute group key generation:

[0055] The authorization structure generates an attribute group E for each attribute i , E i represents the set of users who possess the attribute. In this embodiment, the attributes of users u1, u2, u3 are {λ1, λ2, λ3}, {λ2, λ3}, {λ1, λ3}, then the generated attribute groups are E1 = {u1, u3}, E2 = {u1, u2}, E3 = {u1, u2, u3}. Next, the cloud server generates a binary tree, the AGK tree, for all users U, as Figure 2 shown, and this tree will be used to distribute the attribute group keys to the users in U. In the tree, each node v j holds an AGK, denoted as AGK j , and the set of all AGKs on the path from the leaf node to the root node is called the path key. The AGK tree is generated as follows:

[0056] Assign each member in U to the leaf nodes of the tree, generate and assign random keys for each leaf node and internal node.

[0057] For each member u t ∈ U, establish the set of AGKs of all nodes on the path from the leaf node to the root node, that is, the path key PK t , and the path key PK2 of user u2 is {AGK9, AGK4, AGK2, AGK1}.

[0058] S3 Encryption and policy hiding: Data encryption is based on the access policy (M, ρ), select a random vector and a random number, calculate the shared value λ i , generate the ciphertext CT; Data re-encryption: Generate a new key for the attribute group Update the ciphertext random number commitment D i , and only legitimate users can obtain the new key through the AGK tree to complete decryption.

[0059] Data encryption:

[0060] The data owner sets up an access policy (M, ρ) for the encrypted data. M is an l×n matrix, and ρ is the mapping from each row M i of the matrix M to the attribute ρ(i). The data owner selects a random vector z = (s, z2, …, z n ) T . For each row of M, a random number r i ∈Z N is selected, and λ i = M i ·z is calculated. For the encrypted data msg, the ciphertext CT is calculated as follows:

[0061]

[0062] The ciphertext CT contains the encrypted message C, the master key commitment D, the attribute-related ciphertext component C i and the commitment D i of the random number. The encrypted message C is the result of randomizing the plaintext msg by the bilinear pair e(g, g) αs , that is, C = msg·e(g, g) αs , and only the user with the legal private key can decrypt it. The master key commitment D provides g s as a public parameter, D = g s for subsequent decryption to calculate the bilinear pairing. The attribute-related ciphertext component C i is the product of and , that is, encoding the row calculation result λ i of the access policy matrix into the ciphertext, using the attribute public key T ρ(i) and the random number r i to introduce randomness. The commitment D i of the random number provides g ri to verify the legality of C i , that is, where i ∈ [1, l].

[0063] Data re-encryption:

[0064] First, for all ρ(i), random numbers K ρ(i) ∈Z N are selected, and then the ciphertext CT' is re-encrypted as:

[0065]

[0066] The re-encrypted ciphertext CT′ contains the encrypted message C, the master key commitment D, the attribute-related ciphertext component C i and the commitment D i, C is consistent with the original encryption phase and uses the bilinear pairing e(g, g) αs as a mask to protect the plaintext msg. This component is retained during re - encryption to ensure that the underlying security parameters of the encrypted message remain unchanged, i.e., C = msg·e(g, g) αs ; D = g s provides a public commitment to the master secret s for calculating the bilinear pairing during subsequent decryption, which is consistent with the original encryption phase; similarly, the ciphertext component C i is expressed as being consistent with the original encryption phase During re - encryption, D i is modified to where is the newly generated attribute - group key. The random number r i is bound to the attribute - group key Only users with the latest can solve out to achieve attribute revocation. If a user is revoked, the system can generate a new attribute - group key for this attribute and update D i , and the revoked user cannot complete decryption because they cannot obtain the new key

[0067] Then, in the AGK tree, select the minimum cover set of the attribute - group users, i.e., AGK(E i ), E j = {u1, u2, u5, u6, u7, u8}, AGK(E i ) = {AGK3, AGK4}. Finally, for each attribute y ∈ Y in the access policy, use the key K in the minimum cover set AGK(E y ) of the attribute - group E y to encrypt K ρ(y) , and generate the header information Hdr, which is expressed as where Y is a set of attributes included in the access policy, and E K (K ρ(y) ) is the symmetric encryption of K ρ(y) with the key K

[0068] Policy hiding: By combining the cuckoo filter and hash - obfuscation techniques, hide the mapping relationship between the attributes in the access policy and the ciphertext line numbers, and insert the unique key value v i and the fingerprint hash f ρ(i) to achieve the privacy protection of the access policy

[0069] First, define the parameters (m, b, f, H1, H2) of the attribute cuckoo filter τ, where m represents the number of buckets in the filter, n represents the size of each bucket, f represents the fingerprint length, and H1 and H2 are hash functions used to calculate the initial position of the bucket and the position of the alternative bucket. To add the attribute ρ(i) to the filter, a unique value v bound to the line number i will be inserted i = ξ i l + i, where ξ i is a random number. Generate the fingerprint f of ρ(i) using the fingerprint generation function ρ(i) , and calculate the position to be inserted into the bucket through H1 and H2:

[0070] h1 = H1(f ρ(i) ) mod m

[0071]

[0072] where h1 and h2 are the positions in the bucket calculated by the hash function. If there is an empty insertable position in the bucket, randomly insert the key-value pair into one of them. If both buckets are full, randomly remove one element and then insert it. The removed element is recalculated for the alternative bucket position and inserted. Repeat until the insertion is successful. If no empty position is found after 500 repeated operations, expand the size of the filter and increase the number of buckets. The insertion value of the cuckoo filter is as Figure 3 shown

[0073] S4 Decryption phase: Through the user attribute set S u and the cuckoo filter, restore the line number mapping function corresponding to the attribute λ i ; The user decrypts the attribute group key t using the path key PK to update the private key; If the user attributes satisfy the access policy, use bilinear pairing calculation to eliminate the random mask and restore e(g, g) αs , and finally restore the plaintext msg

[0074] Attribute line number query

[0075] This function takes the user attribute set S u and the cuckoo filter τ as inputs. For each attribute λ i ∈ S u , first generate the fingerprint f ρ(i) and calculate the position of the bucket into which it is inserted, and obtain v by comparing the key-value pairs i . Then calculate the line number corresponding to the attribute λ i , that is, rownum i = v i mod l, and generate a mapping function θ: S u from the attribute set Su → J.

[0076] Recovery of the decryptable attribute mapping function:

[0077] This function takes θ as input and generates a set of attribute mapping functions P by selecting an attribute for each row in J, where each is a single mapping function that maps J to the attribute basis First, generate the attributes associated with each row in J and calculate the cardinality of the mapping functions in P. Then, for each it selects an attribute for each row in J to form an attribute set The selection condition is Then all are added to the set P.

[0078] Attribute group key decryption:

[0079] If user u t has a valid attribute i, i.e., u t ∈ E i , then he can use the AGK (G i ) and the PK t common in to decrypt the attribute group key from the Hdr. i If E Next, the user updates his private key SK using the attribute group key u Update the K in the original user's private key i to while keeping the other private key components unchanged, i.e.,

[0080] Plaintext recovery:

[0081] If the user's attributes satisfy the access policy, there exists a constant ω i ∈ Z N , Then calculate:

[0082] Perform a bilinear mapping pairing on the main key commitment D = g s (the power of the generator of the public random number s) and the core K = g α g at R0 of the user key to obtain an intermediate value. For each attribute of the user Calculate two pairings: e(C i , L) to verify the legality of the attribute parameters, Verify the update status of the attribute group key, multiply after weighting, aiming to eliminate the interference term e(g, g)ats Construct the quotient by operating on the result of multiplying the intermediate value by the weight, and calculate the final result as e(g, g). αs The core secret value for decryption, generated from the master key and the temporary random number:

[0083]

[0084] C / e(g, g) αs = msg

[0085] Finally, the plaintext message msg is recovered through the ratio of the ciphertext C to the pairing result e(g, g). If it cannot be decrypted, the decryption algorithm outputs ⊥, indicating that the user's attributes do not satisfy the access policy. αs When a user's attribute is revoked, only the attribute group key involving the revoked attribute is updated. The server generates new parameters, updates the ciphertext, and generates new header information. It dynamically manages the attribute key distribution through the AGK tree to achieve efficient revocation with the minimum covering set and reduce the key update complexity.

[0086] User attribute revocation: When a user's attribute is revoked, first the AGK updates the user's attribute group involving the revoked attribute without updating the user key. Then the server randomly selects the vector z′ = (s′, z′2, …, z′

[0087] and the attribute group key n )T and the attribute group key Then, update the ciphertext to:

[0088]

[0089] The updated ciphertext CT” includes masking the encrypted message C with the sum of the old and new master secrets s + s′ for the message msg, i.e., msg · e(g, g) α(s+s′) ; D in the original ciphertext needs to be bound to the new parameter s′ after update, i.e., D is g (s+s′) for subsequent pairing calculations; C i retains the original encryption structure, i.e., D i binds the random number r i to the new attribute group key The revoked user cannot solve due to lack of resulting in decryption failure. The non-revoked users can obtain and correctly calculate the pairing terms through the AGK tree.

[0090] Finally, for each attribute y ∈ Y in the access policy, generate a new attribute group key for subsequent re-encryption operations. According to the attribute group E corresponding to the attribute y y , extract its minimum covering set AGK(E from the AGK treey )。 These keys belong to the user paths of the currently unrevoked users with the attribute y. For each newly generated Encrypt each key K in AGK(E y ) separately, aggregate the encryption results of all attributes, and generate a set of ciphertexts Form the final header information Hdr:

[0091]

[0092] As Figure 4 shown, in this embodiment, the Java language, the JPBC 2.0 library, and JDK 15 are used to conduct simulation experiments. The computer configuration for the simulation experiment is as follows: (1) CPU: Intel Core i5-12400; (2) RAM: 16GB; (3) Operating system: Windows 11. The curve used for the bilinear pairing in the experiment is y 2 = x 3 + x. The number of attributes is set as a variable in the experiment. The relationship between the number of attributes and the encryption time and decryption time is measured respectively, and the encryption and decryption efficiencies of the two schemes and this embodiment (Our) under different attribute scales are compared. The encryption times of all three schemes increase approximately linearly with the number of attributes, which conforms to the time complexity characteristics of the attribute-based encryption (ABE) scheme. When the number of attributes increases from 10 to 50, the increase in the encryption and decryption times of the Our scheme is significantly lower than that of the comparison schemes. Under the same attribute scale, through the optimization of the attribute group key tree (AGK-Tree) in this embodiment, while ensuring data security, it also has the effects of accelerating the response and saving computing resources.

[0093] The above description of the embodiments enables those skilled in the art to implement or use the present invention. Various modifications to the embodiments will be obvious to those skilled in the art. The general principles of the present invention can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention should not be limited to the embodiments shown herein, but should cover the widest scope that conforms to the principles and novel features disclosed in the present invention.

Claims

1. A revocable attribute-based encryption method with policy hiding, characterized in that, The method includes the following steps: S1 System initialization: The authorizing agency constructs a bilinear group structure of three-prime order, generating a public key PK containing bilinear mapping parameters and a master private key MK; S2 Attribute Key Generation: Based on the user attribute set S u Generate a private key component containing a random mask to generate the user's private key through the path key PK t Dynamically obtain the attribute group key; S3 Encryption and Policy Hiding: Calculate the Shared Value λ Based on the Access Policy (M, ρ) i , encrypt the data and re-encrypt it to generate a new attribute group key S3.1 Combine the cuckoo filter with the hash obfuscation technique to insert the unique key value v i and the fingerprint hash f ρ(i) for policy hiding; S4 Decryption Phase: Through the user attribute set S u and the cuckoo filter, restore the attribute λ i corresponding line number mapping function. The user decrypts the attribute group key t through the path key PK Update the private key; Use bilinear pairing calculation to restore e(g, g) after eliminating the random mask αs , and finally restore the plaintext msg; S5 When a user attribute is revoked, only the attribute group key involving the revoked attribute is updated, and the attribute key distribution is dynamically managed through the AGK tree.

2. The revocable attribute-based encryption method with policy hiding according to claim 1, wherein, The system initialization step is as follows: The authorizing agency selects a bilinear additive group \(G\) of order \(N = p_1p_2p_3\), and defines as a subgroup of \(G\) of order \(p\) i , where \(i\in\{1,2,3\}\). A bilinear map \(e:G\times G\rightarrow G\) T ; the authorizing agency selects random numbers \(\alpha,a\in\mathbb{Z}\) N , where \(\mathbb{Z}\) N represents the set of integers modulo \(N\), i.e., \(\{0,1,2,3,\cdots,N - 1\}\), \(g\) is the generator of the group , \(X_3\) is the generator of the group . Given an attribute set \(S\), for each attribute \(\lambda\) j , where \(1\leq j\leq|S|\) and \(|S|\) represents the number of attributes in the attribute set \(S\), a random value \(s\) j \(\in\mathbb{Z}\) N is selected, and the public key \(PK\) and the master private key \(MK\) are calculated respectively: The public key PK contains the order N of the bilinear group G, the group generator g, the a-th power of the generator g, and the result e(g, g) of the bilinear mapping α for subsequent encryption and decryption, and for each attribute λ j to generate the corresponding public key parameter T j , that is where s j is a randomly selected number; The master private key MK contains the core parameter random number α for generating the user private key and the generator X3 for introducing randomness into the private key.

3. The revocable attribute-based encryption method with policy hiding according to claim 2, wherein S2 The user private key is generated as follows: The authorization agency first selects a random number \(t\in\mathbb{Z}\). N and random elements \(R_0, R'_0\). Based on the public key \(PK\), the master key \(MK\), and the user's attributes \(S\). u Calculate the user's secret key \(SK\). u The secret key \(SK\). u Contains three parts: \(K\), \(L\), \(K\). i Part \(K\) consists of the product of the \(\alpha\)-th power of the generator \(g\) of the group, the \(a^t\)-th power of \(g\), and the random element \(R_0\), i.e., \(K = g^{\alpha}g^{a^t}R_0\), where the random number \(t\in\mathbb{Z}\). Part \(L\) represents the commitment of \(t\) as the product of \(g^t\) and the random element \(R'_0\), i.e., \(L = g^tR'_0\). For each attribute \(\lambda\) in the user attribute set \(S\), \(i\in S\), \(K_i\) is composed of the product of the generated corresponding private key component \(d_i\) and the random number \(R\). α \(g^{\alpha}\). at \(g^{a^t}R_0\), where the random number \(t\in\mathbb{Z}\). N Part \(L\) represents the commitment of \(t\) as the product of \(g^t\) and the random element \(R'_0\), i.e., \(L = g^tR'_0\). t That is, \(L = g^tR'_0\). For each attribute \(\lambda\) in the user attribute set \(S\), t \(i\in S\), u each attribute \(\lambda\). i \(i\in S\), u \(K_i\). i Is composed of the generated corresponding private key component \(d_i\) and the random number \(R\). i That is, where \(d_i\) comes from the public key.

4. The revocable attribute-based encryption method with policy hiding according to claim 3, wherein S2 The attribute group key is generated as follows: The authorization structure generates an attribute group E for each attribute i , E i represents the set of users who have this attribute. The cloud server generates an AGK tree for all users U and distributes the attribute group key to the users in U; in the tree, each node v j holds an AGK, denoted as AGK j . The set of all AGKs on the path from the leaf node to the root node is called the path key. Each member in U is assigned to a leaf node of the tree, and random keys are generated and assigned for each leaf node and internal node. For each member u t ∈U, the set of all AGKs of the nodes on the path from the leaf node to the root node, that is, the path key PK t is established.

5. The revocable attribute-based encryption method with policy hiding according to claim 4, characterized in that, S3 The specific processes of data encryption and re-encryption are as follows: The data owner sets an access policy (M, ρ) for the encrypted data. M is an l×n matrix, and ρ is the mapping from each row M i of the matrix M to the attribute ρ(i). The data owner selects a random vector z = (s, z2, …, z n ) T . For each row of M, a random number r i ∈Z N is selected, and λ i = M i ·z is calculated. For the encrypted data msg, the ciphertext CT is calculated. Random numbers K ρ(i) ∈Z N are selected for all ρ(i), and the re-encrypted ciphertext CT′ is obtained: The re-encrypted ciphertext CT′ contains the encrypted message C, the master key commitment D, and the attribute-related ciphertext component C i and the commitment D of the random number i , C is consistent with the original encryption phase and uses the bilinear pair e(g,g) αs as a mask to protect the plaintext msg. This component is retained during re-encryption to ensure that the underlying security parameters of the encrypted message remain unchanged, i.e., C = msg·e(g,g) αs ; D = g s provides a public commitment to the master secret s for calculating the bilinear pairing during subsequent decryption, which is consistent with the original encryption phase; Ciphertext component C i Is represented as being consistent with the original encryption phase When re-encrypting, D i Is modified to That is, the new attribute group key, combines the random number r i With the new attribute group key Is bound, and only users with the latest Can decrypt To achieve attribute revocation; if a user is revoked, the system can generate a new attribute group key for the attribute and update D i , and the revoked user cannot complete decryption because they cannot obtain the new key; in the AGK tree, select the minimum covering set of the attribute group users, that is, AGK(E i ), for each attribute y ∈ Y in the access policy, use the minimum covering set AGK(E y ) of the attribute group E y ) to encrypt the key K ρ(y) , generating the header information Hdr represented as Where Y is a set of attributes included in the access policy, and E K (K ρ(y) ) is the symmetric encryption of K ρ(y) With the key K 6. The revocable attribute-based encryption method with policy hiding according to claim 5, characterized in that, S3.1 The specific steps are as follows: Define the parameters (m, b, f, H1, H2) of the attribute cuckoo filter τ, where m represents the number of buckets of the filter, n represents the size of each bucket, f represents the fingerprint length, and H1 and H2 are hash functions used to calculate the initial position of the bucket and the position of the alternative bucket; Add the attribute ρ(i) to the filter and insert a unique value v bound to the line number i i = ξ i l + i, where ξ i is a random number; Generate the fingerprint f of ρ(i) using the fingerprint generation function ρ(i) , calculate the position inserted into the bucket through H1 and H2, h1 = H1(f ρ(i) ) mod m, where h1 and h2 are the positions where the data calculated by the hash function is stored in the bucket. If there is an empty insertable position in the bucket, randomly insert the key-value pair into one of them. If both buckets are full, randomly remove one element for insertion. The removed element is recalculated for the spare bucket position for insertion, and repeat until insertion is successful. If no empty position is found after 500 repeated operations, expand the size of the filter and increase the number of buckets.

7. The revocable attribute-based encryption method with policy hiding according to claim 6, wherein S4 The decryption process of the attribute group key in the decryption phase is as follows; User u t has a valid attribute i, i.e., u t ∈E i , uses AGK(G i ) and PK t to decrypt the attribute group key from Hdr using the common AGK E i ={u1,u2,u5,u6,u7,u8}, then u5 can decrypt using the path key AGK3 ∈ PK5 The user updates its private key SK using the attribute group key u Updates the K in the original user's private key i to The other private key components remain unchanged, i.e., 8. The revocable attribute-based encryption method with policy hiding according to claim 7, characterized in that, S5 The user attribute revocation process is as follows: When the user attribute is revoked, AGK updates the user attribute group involving the revoked attribute, and the server randomly selects the vector z′ = (s′, z′2, …, z′ n ) T and the attribute group key to update the ciphertext CT′ to the ciphertext CT″: The encrypted message C masks the message msg using the superimposed value s + s′ of the old and new master secrets, i.e., msg·e(g,g) α(s+s′) ; After the update in the original ciphertext, D needs to be bound to the new parameter s′, i.e., D is g (s+s′) For subsequent pairing calculations; C i Retains the original encryption structure, i.e., D i Binds the random number r i to the new attribute group key The revoked user cannot solve it because there is no which leads to decryption failure. The non-revoked user obtains it through the AGK tree and can correctly calculate the pairing item; for each attribute y ∈ Y in the access policy, a new attribute group key is generated for subsequent re-encryption operations. According to the attribute group E corresponding to the attribute y , extract its minimum covering set AGK(E y ) from the AGK tree. For each newly generated y , encrypt it separately using all the keys K in AGK(E ). Aggregate the encrypted results of all attributes to generate a set of ciphertexts y to form the final header information Hdr. ​

Citation Information

Cited By

  • Efficient non-contact access control policy modification method and system

    CN120639510A

  • An efficient non-contact access control policy modification method and system

    CN120639510B

  • Encryption method and system for policy hiding and puncturing based on attributes

    CN120856441A

  • An attribute-based policy hiding and puncturing encryption method and system

    CN120856441B

  • Policy hidden access control method and system based on distributed Cuckou filter

    CN121567488A