Encryption method and system for policy hiding and puncturing based on attributes
By employing attribute-based policy hiding and puncture encryption methods in the Internet of Things, the problems of access policy leakage and insufficient forward security are solved, achieving privacy protection and forward security of access policies and ensuring data security.
Patent Information
- Application Number
- CN202511154246.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-18
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-08-18
AI Technical Summary
Existing attribute-based encryption methods suffer from insufficient forward security and access policy leakage in the Internet of Things, failing to effectively protect user privacy and data security.
An attribute-based policy hiding and puncture encryption method is adopted. By hiding the user policy in the encrypted access policy, and allowing the user to actively puncture the key after successful verification to lose the decryption ability, the security and forward security of the access policy are ensured by combining blockchain technology.
It implements privacy protection for access policies, prevents policy leakage, and proactively revokes the decryption function when the key is leaked, ensuring the long-term confidentiality and security of data.
Smart Images

Figure CN120856441A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data encryption technology, and in particular to an attribute-based strategy hiding and penetration encryption method and system. Background Technology
[0002] The rise of the Internet of Things (IoT) has significantly improved quality of life, particularly in areas such as smart homes, healthcare, and smart city traffic management. While the IoT demonstrates enormous potential in intelligence and connectivity, its technological characteristics and application scenarios also present significant drawbacks. Due to limited storage and processing capabilities, IoT systems face challenges in managing large-scale data workloads. Furthermore, constrained resources make large amounts of data vulnerable to security risks. To address these issues and enhance data protection, researchers are increasingly integrating attribute encryption with IoT technologies.
[0003] Since Sahai and Waters pioneered attribute-based encryption in 2005, research on attribute encryption has expanded rapidly. Subsequently, Goyal et al. proposed an attribute encryption scheme that embeds attributes into the ciphertext, while Bethencourt et al. proposed a scheme that embeds attributes into the decryption key. Because ciphertext-policy attribute encryption schemes delegate access control to data owners, allowing them to define access policies for ciphertext and specify which data users are allowed to access it, ciphertext-policy attribute encryption schemes are more suitable for secure data sharing systems than key-policy attribute encryption schemes. However, due to its fine-grained access control mechanism, attribute encryption achieves privacy protection and data sharing, and therefore has also been widely used in the Internet of Things (IoT).
[0004] Hiding access policies is extremely important. For example, in a healthcare application, if the access policy is (User ID: 11256) AND (Department: Mental Health), an attacker could easily infer that the associated ciphertext is related to a mental illness patient because the policy is published in plaintext. To address such privacy issues, some researchers have begun designing attribute-based encryption schemes that support hiding access policies.
[0005] The concept of puncture encryption involves a user using a selected tag to puncture the decryption key after reading the plaintext. Once punctured, the key permanently loses its decryption capability. The combination of puncture encryption and attribute encryption allows puncture encryption schemes to possess the fine-grained access control of attribute encryption. Existing public encryption methods generally suffer from two key flaws that limit their application in scenarios with high security and privacy protection requirements. First, these methods typically fail to guarantee forward security. If a user's private key is leaked at some point, an attacker could use that key to decrypt historical ciphertext, thus exposing the user's past private data to the risk of leakage. The lack of forward security means that the system cannot effectively prevent unauthorized access to old data in the face of key leakage events, seriously threatening the long-term confidentiality of the data. Second, in most public encryption schemes, access policies are usually embedded directly in the ciphertext in plaintext form. This not only easily reveals the data owner's access control intent but may also expose sensitive information related to the policy (such as identity, occupation, health status, etc.). Even if an attacker cannot decrypt the ciphertext, they may be able to deduce the general content of the data by analyzing the access policy, resulting in indirect information leakage. Therefore, existing solutions still have significant shortcomings in terms of privacy protection and security robustness, and there is an urgent need to introduce access policy hiding and encryption mechanisms that support flexible forward security to improve them. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to overcome the shortcomings of the prior art and provide an encryption method and system for policy hiding and penetration based on attributes. The access policy exists in the ciphertext in an encrypted form. After the user successfully verifies the access policy, he / she can decrypt it. He / she can choose to penetrate the key with decryption function to make it lose its decryption ability.
[0007] To solve the above-mentioned technical problems, the present invention adopts the following technical solution:
[0008] An attribute-based policy hiding and penetration encryption method proposed according to the present invention includes:
[0009] Step A: Set the system public parameter PK and master private key MSK;
[0010] Step B: Apply access policies based on PK and MSK Encryption is performed to obtain the encrypted access policy. in, Let ρ be the access matrix, and ρ be the value of the access matrix. A function that maps a line to a property. Let ρ' be the matrix in the access policy after policy hiding, and let ρ' be the mapping function in the access policy after policy hiding.
[0011] Step C: Based on PK and tag set t1,...,t dEncrypt message M to obtain ciphertext CT, where t d′ The d′-th tag is embedded in the ciphertext, 1≤d′≤d, where d is the maximum number of tags;
[0012] Step D: Based on PK and MSK, generate the user's private key SK and piercing key KP0 from the attribute set ω;
[0013] Step E: Generate the post-puncture key KP based on PK and the puncture key KP0;
[0014] Step F: Verify the encrypted access policy based on ω and SK. Ensure policy encryption It has not been maliciously altered;
[0015] Step G: Based on SK,KP,CT,t1,...,t d Restore message.
[0016] As a further optimization of the attribute-based policy hiding and penetration encryption method described in this invention, step A includes:
[0017] Step A1: Select a group G of order p;
[0018] Step A2: Select a safety parameter 1 with length k. k Choose a bilinear mapping e: G×G→G T Where → indicates output, G T It is a multiplicative cyclic group of order p, which is a prime number.
[0019] Step A3: In the modulo p integer group that does not contain zero elements Randomly select exponents α and a from G, and then randomly select element h from G. j,d′ Where j∈[1,n] max ] and d'∈1,...,d,h j,d′ For the element in column j with label d′, n max For matrix The maximum number of columns, where all attribute authority centers AA are blockchain nodes; set the attribute authority center set U. θ ={AA1,AA2,...,AA b ,...,AA θ}, AA b Let μ be the b-th attribute authority center, and each attribute authority center will be randomly assigned an integer μ. b Then calculate the MSK components. Where b∈[1,θ], θ is the total number of attribute authority centers;
[0020] System Public Parameters The master private key is MSK=(g α Define a d-order polynomial q(x) and set V(x) = g. q(x) , where g is a generator of group G, and e(g,g) α Let e(g,g) be raised to the power of α, where e(g,g) represents the pairing operation of g and g. Let F be the hash function that maps attributes to G: U→G, where U is the set of attributes, t0 is the selected initial label that does not participate in the puncture, V(x) is the value calculated in the exponent field by Lagrange interpolation, and x is the interpolation point for reconstructing the polynomial value.
[0021] As a further optimization of the attribute-based policy hiding and penetration encryption method described in this invention, step B includes:
[0022] Attribute authority center calculation (1+μ) b ·p), and set policy encryption components B, B′ and B”, where
[0023] For each attribute attr in the access policy, in A hidden factor γ is randomly selected from the data. x And calculate the policy concealment coefficient. Then through calculation Will Each line in the map is mapped to a hidden strategy. Where I represents the result of the process of... The value of B after bilinear mapping, F(*) is the hash value obtained by mapping the attribute to G, and attr σ For the σ-th attribute, F(attr) σ ) is to obtain the σ-th attribute attr σ The hash value obtained by mapping to G, Yes The value obtained by performing bilinear operations on B is... Pairing operation for B.
[0024] As a further optimization of the attribute-based policy hiding and penetration encryption method described in this invention, step C includes:
[0025] exist Selected from Set vector s and z ε All are in The elements in the set, 2≤ε≤n max Select a row with number l and a column with number n. max matrix Then the ciphertext is obtained through calculation.
[0026]
[0027] Where s is the shared value, C0, C1, C 2,i,j C 3,d All are encrypted components. Let i be the element in the i-th row and j-th column. Let j be the vector in column j. For the element in the j-th row and ρ(l′)-th column, which is the power of -s, V(F(t) d′ )) is calculated by F(t) d′ The value obtained, F(t) d′ ) is the value obtained by calculating the d'th tag using the hash function F.
[0028] As a further optimization of the attribute-based policy hiding and penetration encryption method described in this invention, step D includes:
[0029] Select r,r a , r ξ All The elements in the set, 1≤ξ≤n max Output the user's private key and stab key, for
[0030] Among them, D, D 1,i 、D 2,σ 、D 3,σ All are attribute private key components, KP 01 KP 02 KP 03 KP 04 All are private key piercing components. r is the value of the j-th column and the σ-th element. ξ The power of F, where F(*) is the hash value calculated using the hash function F, r i It is the randomization factor of the i-th row share, and V(F(t0)) is the value obtained by calculating F(t0).
[0031] As a further optimization of the attribute-based policy hiding and penetration encryption method described in this invention, step E includes:
[0032] Choose λ′ and By inputting the existing key {KP0,KP1,...,KP} after τ-1 punctures... τ′ ,...,KP τ-1}; where KP τ′ Let KP be the key obtained after the τ′th puncture, 0≤τ′≤τ-1; and calculate the latest puncture key KP=(KP 01 ′,KPτ1 KP 02 ',KP τ2 KP 03 ',KP τ3 KP 04 ',KP 04 ),in All are in The selected elements, KP 01 ′,KP 02 ′,KP 03 ′, all are key components after puncture, KP τ1 KP τ2 KP τ3 KP is the key component obtained through computation. 04 ' is a tag indicating that no garment insertion is performed, KP 04 Let t be a single target label used to identify the object to which the key is pierced, and V(F(t)) be the value obtained by calculating F(t).
[0033] As a further optimization of the attribute-based policy hiding and penetration encryption method described in this invention, step F includes:
[0034] Data User Computing And compare it with I to verify whether the access policy is correct; among which, All are in The element in, I′ is obtained by applying D σ D 3,σ The value after bilinear mapping, D σ Let G be the policy hiding coefficient, e(*) be the bilinear pairing operation, F(*) be the hash value obtained by mapping the attribute to G, and ρ(l') be the hash value obtained by mapping the attribute to G. The function that maps the l'th row to the attribute, where 1≤l'≤l, γ x It is a hidden factor.
[0035] As a further optimization of the attribute-based policy hiding and penetration encryption method described in this invention, step G includes:
[0036] By inputting the ciphertext CT, private key SK, puncture key KP, and tag set (t1,...,t), the following information is provided: d To recover the message; first calculate and Here, T and A are both values obtained through bilinear mapping, Γ is a set of row indices and Γ = {i|ρ(i)∈ω}, and the message is finally recovered. Multiple exponential weights ω d′ Weighted product, ωd′ It is a set of weights used to reconstruct shared values, ω * The decryption weight set for recovering messages during the decryption process. v for ciphertext component i The power of ρ(i) is the power of The i-th row is the function that maps to the attribute, and τ is the number of times the key is pierced.
[0037] An attribute-based policy hiding and penetration encryption system includes a system parameter setting module, a policy hiding module, an encryption module, a private key generation module, a key penetration module, a policy verification module, and a decryption module; wherein,
[0038] The system parameter setting module is used to set the system public parameter PK and master private key MSK; among them, PK is output to the policy hiding module, encryption module, private key generation module, and key penetration module, and MSK is output to the policy hiding module and private key generation module;
[0039] The policy hiding module is used to set access policies based on PK and MSK. Encryption is performed to obtain the encrypted access policy. in, Let ρ be the access matrix, and ρ be the value of the access matrix. A function that maps a line to a property. Let ρ' be the matrix in the access policy after policy hiding, and let ρ' be the mapping function in the access policy after policy hiding.
[0040] The encryption module is used to determine the encryption based on the PK and tag set t1,...,t. d Encrypt message M to obtain ciphertext CT, where t d′ The d′-th tag is embedded in the ciphertext, 1≤d′≤d, where d is the maximum number of tags;
[0041] The private key generation module is used to generate the user's private key SK and piercing key KP0 based on PK, MSK, and attribute set ω.
[0042] The key puncture module is used to generate the punctured key KP based on PK and the puncture key KP0.
[0043] The policy verification module is used to verify the encrypted access policy based on ω and SK. Ensure that the encrypted part of the policy has not been maliciously tampered with;
[0044] The decryption module is used to decrypt SK,KP,CT,t1,...,t d Restore message.
[0045] A computer device includes a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that, when the processor executes the computer program, it implements the steps of the attribute-based policy hiding and piercing encryption method as described above.
[0046] Compared with the prior art, the present invention, employing the above technical solution, has the following technical effects:
[0047] (1) The policy hiding was achieved by using blockchain technology, which solved the possibility of access policy leakage;
[0048] (2) The puncture function is implemented, which makes the encryption scheme have forward security and allows users to actively revoke the key decryption function. Attached Figure Description
[0049] Figure 1 This is a schematic diagram of the operation of the encryption system of the present invention.
[0050] Figure 2 This is a system flowchart of the present invention. Detailed Implementation
[0051] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0052] Theoretical explanation used in this invention:
[0053] 1. Bilinear mapping
[0054] G,G T It is a cyclic group of order p, where g is a generator of G. If the mapping e: G×G→G... T A mapping is considered a bilinear mapping if it satisfies the following three properties:
[0055] Bilinear:
[0056] Non-degeneracy: e(h,f)≠1
[0057] Computability: e is highly computable.
[0058] 2. DBDH Difficulty Assumption
[0059] Given a tuple (g, g a ,g b ,g c )∈G 4 and an element Z∈G T As input, if adversary A has |Pr[A(g,g]] a ,g b ,g c ,e(g,g)abc )=0]-Pr[A(g,g a ,g b ,g c If [,Z)=0]|≤ε(k), then the DBDH difficulty assumption holds on G.
[0060] like Figure 2 As shown, the specific execution flow of the encryption method provided by this invention is as follows:
[0061] Step A, System Parameter Generation:
[0062] Choose a group G of order p; choose a security parameter 1 of length k. k Choose a bilinear mapping e: G×G→G T Where → indicates output, G T Let U be a multiplicative cyclic group of order p prime numbers, and U be a set of attributes; let U be a group of integers modulo p that does not contain zero elements. Randomly select exponents α and a from G, and then randomly select element h from G. j,d′ , where j∈[1,n max And labels d'∈1,...,d. All attribute authority centers AA are blockchain nodes. Set the attribute authority center set Uθ={AA1,AA2,...,AA...} θ}, and each attribute authority will randomly select an integer μ. b Then calculate the MSK components. The number of attribute authority centers is b∈[1,θ].
[0063] System Public Parameters The master private key is MSK=(g α Define a d-order polynomial q(x) and set V(x) = g. q(x) Where g is a generator of group G, e denotes a bilinear mapping, and e(g,g) α Let e(g,g) be raised to the power of α, where e(g,g) represents the pairing operation of g and g. Let F be the hash function that maps attributes to G: U→G. Let t0 be the selected initial label that does not participate in the puncture. Let V(x) be the value calculated in the exponent field by Lagrange interpolation, where x is the interpolation point of the reconstructed polynomial value.
[0064] Step B, Strategy Hiding:
[0065] Attribute authority center calculation (1+μ) b ·p), and set policy encryption components B, B′ and B”, where
[0066] For each attribute attr in the access policy, in A hidden factor γ is randomly selected from the data. x And calculate the policy concealment coefficient. Then through calculation Will Each line in the map is mapped to a hidden strategy. Let ρ' be the matrix in the access policy after policy hiding, and ρ' be the mapping function in the access policy after policy hiding, where I is the mapping function after policy hiding. The value of B after bilinear mapping;
[0067] Step C, encrypt the plaintext:
[0068] exist Selected from Set vector s and z ε All are in The elements in the array are selected from rows l and columns n. max matrix Then the ciphertext is obtained through calculation.
[0069]
[0070] Wherein, C0, C1, C 2,i,j C 3,j All are encrypted components. For the element in row i and column j, The vector in the j-th column, For the element in row j and column ρ(i) raised to the power of -s, V(F(t) d′ )) is calculated by F(t) d′ The value obtained, F(t) d′ ) represents the value obtained by calculating the d'th tag using a hash function.
[0071] Step D, Generate Key:
[0072] Select r,r a , r ζ All The elements in the output list will generate the user's private key and the piercing key. , Where, D, D 1,i D 2,σ D 3,σ All are attribute private key components, KP 01 KP 02 KP 03 KP 04 All are private key piercing components. r is the value of the element in the j-th row and the σ-th row. j Power of 1.
[0073] Step E, Key Puncture:
[0074] Choose λ′ and By inputting the existing key {KP0,KP1,...,KP} after τ-1 punctures... τ-1 The subscript represents the key obtained after the τth puncture. The latest puncture key, KP = KP, is calculated. 01 ',KP τ1 KP 02 ′,KP τ2 KP 03 ′,KP τ3 KP 04 ',KP 04 ,in KP 04 ′=t0,KP 04 =t, λ′, r0, r are all in The selected elements, KP 01 ′,KP τ1 KP 02 ′,KP τ2 KP 03 ',KP τ3 KP 04 ',KP 04 All of these are puncture keys obtained through calculation.
[0075] Step F, verify the access policy:
[0076] Then the data user calculates And compare it with I to verify whether the access policy is correct; I' is obtained by accessing D. σ D 3,σ The value after bilinear mapping.
[0077] Step G, decrypt the ciphertext:
[0078] By inputting the ciphertext CT, private key SK, puncture key KP, and tag set (t1,...,t), the following information is provided: d To recover the message. First calculate... and Where T and A are both values obtained through bilinear mapping, ultimately recovering the message.
[0079] The specific calculations are as follows:
[0080]
[0081] The following section will explain the specific applications of the encryption scheme described above in the Internet of Things.
[0082] Assume the sender is an authorized organization intending to send security messages to all SM series engine control boards within a specific area. The receivers are various vehicles. Receiver 1 is a Jeep equipped with an SM1 engine control board; receiver 2 is an SUV equipped with an SM2 engine control board; and receiver N is an unknown vehicle with an SMX engine control board. The key distribution center is only responsible for creating and distributing the initial key.
[0083] In each message sent to a specific IoT device, the sender includes a linear access structure (e.g., corresponding to the SM series engine control board in this example) and a tag (such as a message identifier or time identifier). From the initial key generation, the IoT device's secret key is the decryption key embedded with its attribute ω. The purpose of this system is to allow IoT devices with attributes satisfying the access structure to decrypt messages, and further, it allows the corresponding IoT device to selectively revoke the decryption capability of messages with specific tags. This is achieved by piercing the key at time point t. The receiver updates its existing key, generating a new piercing key with tag t. Thus, even if the new key used for communication is leaked, an attacker cannot use it to decrypt other important information embedded with t. Furthermore, generating the piercing key does not require communication with a key distribution center, nor does it require deleting components from the existing key to generate the new key.
[0084] like Figure 1 An attribute-based policy hiding and key penetration encryption system includes a system parameter setting module, a policy hiding module, an encryption module, a private key generation module, a key penetration module, a policy verification module, and a decryption module; wherein,
[0085] The system parameter setting module is used to set the system public parameter PK and master private key MSK; among them, PK is output to the policy hiding module, encryption module, private key generation module, and key penetration module, and MSK is output to the policy hiding module and private key generation module;
[0086] The policy hiding module is used to set access policies based on PK and MSK. Encryption is performed to obtain the encrypted access policy. in, Let ρ be the access matrix, and ρ be the value of the access matrix. A function that maps a line to a property. Let ρ' be the matrix in the access policy after policy hiding, and let ρ' be the mapping function in the access policy after policy hiding.
[0087] The encryption module is used to determine the encryption based on the PK and tag set t1,...,t.d Encrypt message M to obtain ciphertext CT, where t d′ The d′-th tag is embedded in the ciphertext, 1≤d′≤d, where d is the maximum number of tags;
[0088] The private key generation module is used to generate the user's private key SK and piercing key KP0 based on PK, MSK, and attribute set ω.
[0089] The key puncture module is used to generate the punctured key KP based on PK and the puncture key KP0.
[0090] The policy verification module is used to verify the encrypted access policy based on ω and SK. Ensure that the encrypted part of the policy has not been maliciously tampered with;
[0091] The decryption module is used to decrypt SK,KP,CT,t1,...,t d Restore message.
[0092] This invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor, wherein the processor executes the computer program to implement the steps of the attribute-based policy hiding and penetration encryption method as described above.
[0093] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the attribute-based policy hiding and piercing encryption method described above.
[0094] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention can be implemented using various computer languages, such as the object-oriented programming language Java and the interpreted scripting language JavaScript.
[0095] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0096] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0097] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0098] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0099] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. An attribute-based strategy for hiding and penetrating encryption, characterized in that, include: Step A: Set the system public parameter PK and master private key MSK; Step B: Apply access policies based on PK and MSK Encryption is performed to obtain the encrypted access policy. in, Let ρ be the access matrix, and ρ be the value of the access matrix. A function that maps a line to a property. Let ρ' be the matrix in the access strategy after policy hiding, and let ρ' be the mapping function in the access strategy after policy hiding. Step C: Based on PK and tag set t1,...,t d Encrypt message M to obtain ciphertext CT, where t d' The d'th tag is embedded in the ciphertext, 1≤d'≤d, where d is the maximum number of tags; Step D: Based on PK and MSK, generate the user's private key SK and piercing key KP0 from the attribute set ω; Step E: Generate the post-puncture key KP based on PK and the puncture key KP0; Step F: Verify the encrypted access policy based on ω and SK. Ensure policy encryption It has not been maliciously altered; Step G: Based on SK,KP,CT,t1,...,t d Restore message.
2. The encryption method based on attribute-based strategy hiding and penetration according to claim 1, characterized in that, Step A includes: Step A1: Select a group G of order p; Step A2: Select a safety parameter 1 with length k. k Choose a bilinear mapping e: G×G→G T Where → indicates output, G T It is a multiplicative cyclic group of order p, which is a prime number. Step A3: In the modulo p integer group that does not contain zero elements Randomly select exponents α and a from G, and then randomly select element h from G. j,d' Where j∈[1,n] max ] and d'∈1,...,d,h j,d' For the element in column j with label d′, n max For matrix The maximum number of columns, where all attribute authority centers AA are blockchain nodes; set the attribute authority center set U. θ ={AA1,AA2,...,AA b ,...,AA θ }, AA b Let μ be the b-th attribute authority center, and each attribute authority center will be randomly assigned an integer μ. b Then calculate the MSK components. Where b∈[1,θ], θ is the total number of attribute authority centers; System Public Parameters The master private key is MSK=(g α Define a d-order polynomial q(x) and set V(x) = g. q(x) , where g is a generator of group G, and e(g,g) α Let e(g,g) be raised to the power of α, where e(g,g) represents the pairing operation of g and g. Let F be the hash function that maps attributes to G: U→G, where U is the set of attributes, t0 is the selected initial label that does not participate in the puncture, V(x) is the value calculated in the exponent field by Lagrange interpolation, and x is the interpolation point for reconstructing the polynomial value.
3. The encryption method based on attribute-based strategy hiding and penetration according to claim 1, characterized in that, Step B includes: Attribute authority center calculation (1+μ) b ·p), and set policy encryption components B, B′ and B”, where For each attribute attr in the access policy, in A hidden factor γ is randomly selected from the data. x And calculate the policy concealment coefficient. Then through calculation Will Each line in the map is mapped to a hidden strategy. Where I represents the result of the process of... The value of B after bilinear mapping, F(*) is the hash value obtained by mapping the attribute to G, and attr σ For the σ-th attribute, F(attr) σ ) is to obtain the σ-th attribute attr σ The hash value obtained by mapping to G, Yes The value obtained by performing bilinear operations on B is... Pairing operation for B.
4. The encryption method based on attribute-based strategy hiding and penetration according to claim 1, characterized in that, Step C includes: exist Select s from the middle. Set vector s and z ε All are in The elements in the set, 2≤ε≤n max Select a row with number l and a column with number n. max matrix Then the ciphertext is obtained through calculation. Where s is the shared value, C0, C1, C 2,i,j C 3,d All are encrypted components. Let i be the element in the i-th row and j-th column. Let j be the vector in column j. For the element in row j and column ρ(l') raised to the power of -s, V(F(t) d' )) is calculated by F(t) d' The value obtained, F(t) d' ) is the value obtained by calculating the d'th tag using the hash function F.
5. The encryption method for attribute-based strategy hiding and penetration according to claim 1, characterized in that, Step D includes: Select r,r a , r ξ All The elements in the set, 1≤ξ≤n max Output the user's private key and stab key, for Among them, D, D 1,i D 2,σ D 3,σ All are attribute private key components, KP 01 KP 02 KP 03 KP 04 All are private key piercing components. r is the value of the j-th column and the σ-th element. ξ The power of F, where F(*) is the hash value calculated using the hash function F, r i It is the randomization factor of the i-th row share, and V(F(t0)) is the value obtained by calculating F(t0).
6. The encryption method for attribute-based strategy hiding and penetration according to claim 1, characterized in that, Step E includes: Choose λ' and By inputting the existing key {KP0,KP1,...,KP} after τ-1 punctures... τ' ,...,KP τ-1 }; where KP τ' Let KP be the key obtained after the τ'th puncture, 0≤τ'≤τ-1; and calculate the latest puncture key KP = (KP 01 ',KP τ1 KP 02 ',KP τ2 KP 03 ',KP τ3 KP 04 ',KP 04 ),in KP 04 =t0,KP 04 =t, λ', r0, r1 are all in The selected elements, KP 01 ′,KP 02 ′,KP 03 ′, all are key components after puncture, KP τ1 KP τ2 KP τ3 KP is the key component obtained after computation. 04 ' is a tag indicating that no garment insertion is performed, KP 04 Let t be a single target label used to identify the object to which the key is pierced, and V(F(t)) be the value obtained by calculating F(t).
7. The encryption method based on attribute-based strategy hiding and penetration according to claim 1, characterized in that, Step F includes: Data User Computing And compare it with I to verify whether the access policy is correct; among which, All are in The element in, I′ is obtained by applying D σ D 3,σ The value after bilinear mapping, D σ Let G be the policy hiding coefficient, e(*) be the bilinear pairing operation, F(*) be the hash value obtained by mapping the attribute to G, and ρ(l′) be the hash value obtained by mapping the attribute to G. The function that maps the l'th row to the attribute, where 1≤l′≤l, γ x It is a hidden factor.
8. The encryption method for attribute-based strategy hiding and penetration according to claim 1, characterized in that, Step G includes: By inputting the ciphertext CT, private key SK, puncture key KP, and tag set (t1,...,t), the following information is provided: d To recover the message; first calculate and Here, T and A are both values obtained through bilinear mapping, Γ is a set of row indices and Γ = {i|ρ(i)∈ω}, and the message is finally recovered. Multiple exponential weights ω d′ Weighted product, ω d′ It is a set of weights used to reconstruct shared values, where ω* is the decryption weight set during the message recovery process. v for ciphertext component i The power of ρ(i) is the power of The i-th row is the function that maps to the attribute, and τ is the number of times the key is pierced.
9. An attribute-based policy hiding and penetration encryption system, characterized in that, It includes a system parameter setting module, a policy hiding module, an encryption module, a private key generation module, a key penetration module, a policy verification module, and a decryption module; among which, The system parameter setting module is used to set the system public parameter PK and master private key MSK; among them, PK is output to the policy hiding module, encryption module, private key generation module, and key penetration module, and MSK is output to the policy hiding module and private key generation module; The policy hiding module is used to set access policies based on PK and MSK. Encryption is performed to obtain the encrypted access policy. in, Let ρ be the access matrix, and ρ be the value of the access matrix. A function that maps a line to a property. Let ρ' be the matrix in the access policy after policy hiding, and let ρ' be the mapping function in the access policy after policy hiding. The encryption module is used to determine the encryption based on the PK and tag set t1,...,t. d Encrypt message M to obtain ciphertext CT, where t d′ The d′-th tag is embedded in the ciphertext, 1≤d′≤d, where d is the maximum number of tags; The private key generation module is used to generate the user's private key SK and piercing key KP0 based on PK, MSK, and attribute set ω. The key puncture module is used to generate the punctured key KP based on PK and the puncture key KP0. The policy verification module is used to verify the encrypted access policy based on ω and SK. Ensure that the encrypted part of the policy has not been maliciously tampered with; The decryption module is used to decrypt SK,KP,CT,t1,...,t d Restore message.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the attribute-based policy hiding and piercing encryption method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Anti-leakage CP-ABE method under strategy hiding and outsourcing decryption
CN107181590A
Ciphertext policy attribute encryption method supporting policy hiding and attribute updating
CN113055168A
Security attribute-based encryption method supporting flexible management and control of attributes and users
CN116346354A
Revocable attribute-based encryption method with strategy hiding
CN120342749A
Blockchain privacy data access control method and system
WO2023226641A1