Access control encryption and decryption method and system based on content detection
By generating global parameters and a master private key through a central authoritative institution, and combining access control and content detection for purification, the problem of malicious content propagation in public key encryption technology is solved, achieving highly secure information transmission and authentication.
Patent Information
- Application Number
- CN202511418240.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-09-30
AI Technical Summary
Existing public-key cryptography cannot effectively prevent malicious users from spreading malicious content through legitimate encrypted channels, increasing the recipient's decryption and content review workload, and failing to meet the high security requirements of modern communications.
Global parameters and a master private key are generated by a central authoritative institution. Combined with access control policies and content detection, the ciphertext is purified using a purifier to ensure that only legitimate users can decrypt the plaintext and prevent the spread of malicious content.
It enables efficient monitoring and identity verification of sensitive information, prevents the spread of malicious content, and improves the security and resistance to internal threats of communication systems.
Smart Images

Figure CN120915602A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of cryptography, and more particularly relates to an access control encryption and decryption method and system based on content detection. BACKGROUND
[0002] With the rapid development of information technology and the widespread application of the Internet, information security problems have become one of the major challenges faced by today's society. Especially in network communication, how to protect the confidentiality, integrity and availability of data, prevent unauthorized access and the spread of malicious content is a core problem in information security research. As a traditional encryption method, public key encryption (PKE) effectively protects the confidentiality of data in information transmission through the pairing of public and private keys. Specifically, the sender uses the public key of the receiver to encrypt the message, and only the receiver holding the corresponding private key can decrypt and access the message content. This encryption mechanism ensures the privacy of information flow in the transmission process and avoids the theft of unauthorized external users.
[0003] However, although the public key encryption technology can effectively protect the content of information from being accessed illegally, it also has certain limitations. In the PKE system, anyone can use the public key to encrypt information, so malicious users may send messages containing harmful content, such as malicious emails or phishing links, to the target user through a legal encryption channel. This makes the receiver need additional decryption and content review work, increasing the security risk and operational burden. In the face of increasingly complex network environment, protecting the privacy of information content alone cannot meet the security needs of modern communication. In some high-security application scenarios, in addition to the protection of information content, more fine-grained control of information flow transmission and reception is needed to ensure the legality of each party in communication and the credibility of information, and the read permission control of information flow is insufficient to cope with the evolving threats, and the write permission control of information flow is also particularly important. SUMMARY
[0004] In view of the above defects or improvement needs of the prior art, the present application provides an access control encryption and decryption method and system based on content detection, which aims to solve the technical problem that sensitive information transmission and storage exist the risk of being stolen in the prior art.
[0005] To achieve the above-mentioned purpose, according to one aspect of the present application, an access control encryption and decryption method based on content detection is provided, which is applied to an access control encryption and decryption system, the access control encryption and decryption system comprising: a central authority, a sender authority, a receiver authority, a sender, a purifier and a receiver; the method comprising: S1: the center authority: according to the input security parameters and access control policy generate global parameters and master private key , and distribute the global parameters and master private key to the sender authority and the receiver authority; and generate the key pattern corresponding to the sensitive information corresponding trapdoor set, and send the trapdoor set to the purifier; S2: the sender authority: when receiving the identity information of the sender , generate the encryption key according to the identity information , the global parameters and the master private key and feedback to the sender; S3: the receiver authority: when receiving the identity information of the receiver , generate the decryption key according to the identity information , the global parameters and the master private key and feedback to the receiver; S4: the sender: use the encryption key to encrypt the plaintext message into ciphertext , and send the ciphertext to the purifier; S5: the purifier: receive the ciphertext , if the ciphertext meets the purification requirements, use the trapdoor set to purify to obtain the purified ciphertext ; S6: the receiver: use the decryption key to decrypt the purified ciphertext .
[0006] Further, the S1 includes: the center authority performs the following operations: S101: running the initialization algorithm of access control encryption technology ACE to obtain the public parameters of ACE and master private key : , access control policy , is a random number; running the initialization algorithm of the decryptable pattern matching technology D-PM to obtain the public parameters of D-PM: ; running a key generation algorithm of a decryptable pattern matching technique D-PM to obtain a corresponding public-private key pair: , finally obtaining the master key and the global parameter ; is an upper limit of the maximum length of the keyword pattern; S102: generating a keyword pattern corresponding to the sensitive information corresponding trapdoor set; S103: transmitting the master private key and the global parameter to the sender authority and the receiver authority; transmitting a trapdoor in the trapdoor set to the purifier.
[0007] Further, the S102 comprises: generating a trapdoor in the trapdoor set according to the master private key and the keyword pattern corresponding to the sensitive information : , wherein the length .
[0008] Further, the S2 comprises: the sender authority performs the following operations: S201: when receiving the identity information of the sender , running an encryption key generation algorithm of ACE according to the master private key and the identity information of the sender to obtain an encryption key of ACE: ; S202: taking as an encryption key and transmitting it to the corresponding sender.
[0009] Further, the S3 comprises the following operations performed by the receiver authority: S301: when receiving the identity information of the receiver , running a decryption key generation algorithm of ACE according to the master private key and the identity information to obtain a decryption key of ACE: ; S302: taking as a decryption key and transmitting it to the corresponding receiver.
[0010] Further, the S4 comprises the following operations performed by the sender: S401: randomly selecting an auxiliary parameter , is a prime number, is an integer field with modulus , denotes uniform random selection; S402: According to the encryption key Run the ACE encryption algorithm to obtain the corresponding ACE encryption ciphertext and ; Run the D-PM encryption algorithm to obtain the corresponding D-PM detection ciphertext ; S403: Integrate the ciphertext and transmit to the purifier.
[0011] Further, the S5 includes the purifier performing the following operations: S501: Determine whether the received ciphertext complies with all trapdoor sets to all trapdoors corresponding to the purifying requirements, if it complies, execute S502; otherwise, end; S502: Run the ACE purifying algorithm on the ciphertext to obtain the to-be-purified ciphertext and ; S503: Parse the to-be-purified ciphertext into , does not carry any information about the plaintext, and contains the effective information of the plaintext; S504: Select a randomization factor , run the D-PM randomization algorithm on and to obtain ; S505: Integrate to obtain the purifying ciphertext , and transmit it to the corresponding receiver.
[0012] Further, the S501 includes: running the D-PM detection algorithm on the trapdoors of all trapdoor sets and the ciphertext to obtain the corresponding output result set ; if is an empty set, it is considered that the ciphertext complies with the corresponding purifying requirements, and S502 is executed; otherwise, end.
[0013] Further, the S6 includes the receiver performing the following operations: S601: According to the decryption key and the purifying ciphertext , running the decryption algorithm of ACE to obtain the auxiliary parameter ; running the decryption algorithm of ACE to obtain the detection ciphertext ; S602: running the decryption algorithm of D-PM, if the receiver and the corresponding sender are both legal users in the access control policy, obtaining the decrypted plaintext .
[0014] According to another aspect of the present application, there is provided an access control encryption and decryption system based on content detection, comprising: a central authority, configured to generate global parameters and a master private key according to input security parameters and an access control policy , and distribute the global parameters and the master private key to the sender authority and the receiver authority; and generate a keyword pattern corresponding to sensitive information , a corresponding trapdoor set, and send the trapdoor set to a purifier; a sender authority, configured to, when receiving the identity information of the sender , generate an encryption key according to the identity information , the global parameters and the master private key , and feed back to the sender; a receiver authority, configured to, when receiving the identity information of the receiver , generate a decryption key according to the identity information , the global parameters and the master private key , and feed back to the receiver; a sender, configured to use the encryption key to encrypt a plaintext message into ciphertext , and send the ciphertext to the purifier; a purifier, configured to receive the ciphertext , and, if the ciphertext meets the purification requirement, purify to obtain purified ciphertext using the trapdoor set ; a receiver, configured to use the decryption key to decrypt the purified ciphertext .
[0015] In general, the above technical solutions conceived by the present application can achieve the following beneficial effects compared with the prior art: (1) The access control encryption and decryption method based on content detection provided by the present application, the access control strategy input by the central authority is combined with the security parameter initialization global parameter and the master private key, and a trapdoor is generated according to the input content detection keyword mode. Then the central authority sends the master private key to the sender authority. The sender authority generates an encryption key for the sender according to the master private key and user information. The sender encrypts the information using the encryption key, and then sends the ciphertext to the purifier. The purifier purifies the ciphertext and broadcasts the purified ciphertext to all receivers. Except for the receivers who meet the access control strategy, any other receiver cannot obtain the information sent by the sender through this method; except for the sender who meets the access control strategy, any other sender cannot generate a legal ciphertext and send it to the appropriate receiver through this method. Through the cooperation of all parties, this scheme realizes the encryption transmission and identity authentication of user information on the basis of ensuring the efficiency of sensitive information supervision, fully protects the privacy of sensitive information and identity information of users, and thus solves the technical problem that the transmission and storage of sensitive information in the prior art are at risk of being stolen.
[0016] (2) Through the content detection of the purifier on the sent ciphertext, any ciphertext that does not meet the requirements (the ciphertext is illegally generated or the ciphertext contains malicious content) cannot be decrypted by the sender. Through the above "unread rule", "unwritable rule" and ciphertext content detection to restrict the behavior of the sender and the behavior of the receiver, this method maximizes the security of the system.
[0017] (3) The purifier purifies the ciphertext, if the ciphertext sent by the sender does not meet the requirements (the ciphertext is illegally generated or the ciphertext contains malicious content), the purifier will convert it into meaningless content. Otherwise, the purifier will broadcast the purified ciphertext to all receivers. If the receiver meets the corresponding access control strategy, the receiver can decrypt the ciphertext. Thus, the spread of malicious content is effectively prevented. This extension method can improve the ability of the system to resist internal threats, prevent attackers from spreading malicious information through legal user identities, and ensure the overall security of the communication system. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 The schematic diagram of the access control encryption and decryption system based on content detection provided by the present application.
[0019] Figure 2 The flowchart of the access control encryption and decryption method based on content detection provided by the present application. DETAILED DESCRIPTION
[0020] In order to make the objects, technical solutions and advantages of the present application clearer, further detailed description will be made to the present application in combination with the accompanying drawings and examples. It should be understood that the specific examples described herein are only used to explain the present application, and are not used to limit the present application. In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as they do not conflict with each other.
[0021] Figure 1 A schematic diagram of the access control encryption and decryption system based on content detection provided by the present application. The access control encryption and decryption system based on content detection provided by the present application comprises a central authority, a sender authority, a receiver authority, a sender, a purifier and a receiver.
[0022] The central authority has the function of generating global parameters and master private keys according to input security parameters and access control policies, distributing the global parameters and master private keys to the sender authority and the receiver authority, generating corresponding trapdoors for the keyword patterns corresponding to each sensitive information, virus feature, violation behavior and other sensitive information that needs to be detected, and sending all trapdoors to the purifier. As a trusted entity, the central authority acts as a rule maker and can set global access control policies to provide a basis for key generation and access permission management in the system.
[0023] The sender authority has the function of receiving global parameters and master private keys and the identity information of the sender, and generating corresponding encryption keys. As a trusted entity, the sender authority can independently generate encryption keys according to the identity of the sender to ensure that only authorized senders can perform encryption operations.
[0024] The receiver authority has the function of receiving global parameters and master private keys and the identity information of the receiver, and generating corresponding decryption keys. As a trusted entity, the receiver authority independently generates decryption keys according to the identity of the receiver to ensure the security and accuracy of decryption operations.
[0025] The sender has the function of receiving corresponding encryption keys, using the encryption keys to encrypt plaintext messages into ciphertexts, and sending the ciphertexts to the purifier. The sender does not directly communicate with the receiver, but forwards messages through the purifier to ensure that the message flow under the control of the purifier complies with the global access control rules.
[0026] The purifier has a receiving trapdoor that purifies all received ciphertext and sends the purified ciphertext to all recipients. Specifically, it performs a series of calculations on the ciphertext according to a preset program. If the ciphertext does not meet the requirements (including illegally generated ciphertext and messages containing malicious content), the purifier will convert it into meaningless content; if the ciphertext meets the requirements, the purifier will convert it into purified ciphertext. As an honest but semi-trusted entity, the purifier strictly follows established rules and will not actively tamper with or disclose the ciphertext content. However, considering that the purifier may be curious about analyzing or interpreting the ciphertext, it is designed to be restricted from being fully trusted, unable to access the decryption key, and unable to understand the actual meaning of the ciphertext. Furthermore, the purifier cannot know the identity of the sender or receiver of the ciphertext, thus effectively avoiding potential privacy leaks.
[0027] The receiver has the ability to receive the corresponding decryption key and the cleaned ciphertext, and attempt to decrypt the ciphertext using the decryption key to recover the plaintext message. If the identities of the receiver and the ciphertext sender comply with the access control policy, the receiver will successfully decrypt; otherwise, if the identities of the communicating parties do not comply with the access control policy, or if the ciphertext has been converted into meaningless information by the cleaner, the receiver will fail to decrypt and will be unable to recover the plaintext.
[0028] Figure 2 The flowchart of the access control encryption and decryption method based on content detection provided by the present invention includes the following steps: S1: The central authority: based on the input security parameters and access control policies Generate global parameters and the master private key The master private key is used not only in encryption keys during communication. With decryption key The generation of these keywords will also participate in keyword trapping by the central authoritative institution. The generation of global parameters by the central authoritative body. and master private key It is distributed to authoritative sending and receiving institutions, and also includes keyword patterns for each sensitive information that needs to be detected, such as sensitive information, virus characteristics, and violations. Generate the corresponding trapdoor and all the trapdoors The information is sent to the purifier so that it can perform the purification operation. As a trusted entity, the central authority acts as the rule setter, capable of setting global access control policies and providing the foundation for key generation and access control management within the system.
[0029] S2: The authoritative sending organization: based on the received global parameters. and the master private key , and the sender's identity information , to generate the corresponding encryption key . As a trusted entity, the sender authority can independently generate the encryption key according to the sender's identity, ensuring that only authorized senders can perform encryption operations.
[0030] S3: the receiver authority: according to the received global parameters and the master private key , and the receiver's identity information , to generate the corresponding decryption key . As a trusted entity, the receiver authority independently generates the decryption key according to the receiver's identity, ensuring the security and accuracy of the decryption operation.
[0031] S4: the sender: according to its own identity information obtain the corresponding encryption key from the sender authority . When the sender sends a message, use the encryption key encrypt the plaintext message into ciphertext , and send the ciphertext to the purifier. The sender does not directly communicate with the receiver, but forwards the message through the purifier to ensure that the message flow under the control of the purifier complies with the global access control rules.
[0032] S5: the purifier: according to the received trapdoor purification processing for all received ciphertexts . Specifically, it will perform a series of operations on the ciphertext according to the preset program, if the ciphertext does not meet the requirements (including illegal generation of ciphertext and messages containing malicious content), the purifier will convert it into meaningless content; if the ciphertext meets the requirements, the purifier will convert it into purified ciphertext . As an honest but semi-trusted entity, the purifier strictly follows the established rules to perform its tasks and will not actively tamper with or leak the content of the ciphertext. However, considering that the purifier may be curious about analyzing or interpreting the content of the ciphertext, it is designed to be limited in trust and cannot access the decryption key, nor can it understand the actual meaning of the ciphertext. In addition, the purifier cannot know the sender's identity and the receiver's identity, thereby effectively avoiding potential privacy leaks.
[0033] S6: the receiver: according to its own identity information obtain the corresponding decryption key from the receiver authority The recipient will also receive purified encrypted text from the purifier. And try to use the decryption key For ciphertext Decrypt to recover the plaintext message If the identities of the receiver and the sender of the ciphertext match the access control policy, the receiver will successfully decrypt the message; otherwise, if the identities of both parties do not match the access control policy, or if the ciphertext... If the plaintext has been converted into meaningless information by the purifier, the receiver will fail to decrypt it and will be unable to recover the original plaintext. .
[0034] In one embodiment, S1 includes the central authority performing the following operations: S101: Utilizing safety parameters Access control policies and the maximum length limit of keyword patterns Initialization is performed. First, the initialization algorithm of the Access Control Encryption (ACE) technology is run to obtain the ACE public parameters and master private key: Then, the initialization algorithm of the decryptable pattern matching technique D-PM is run to obtain the common parameters of D-PM: Finally, the key generation algorithm of the decryptable pattern matching technique D-PM is run to obtain the corresponding public-private key pair: The system's master key is obtained through integration. and global parameters .
[0035] S102: Based on the generated master private key and keyword patterns Generate a trapdoor: ,in length .
[0036] S103: Transmit the master private key To the authoritative sending authority and the authoritative receiving authority; the transmission trapdoor. To the air purifier.
[0037] In one embodiment, S2 includes the sender authority performing the following operations: S201: The sending authority uses the received master private key... and identity information Run the ACE encryption key generation algorithm to obtain the ACE encryption key: .
[0038] S202: Integrate and obtain the user's encryption key Transmit the encryption key. to each sender.
[0039] In one embodiment, before S201, the sender performs the following operation: sends its identity information to the sender authority.
[0040] In one embodiment, S3 includes the following operation performed by the receiver authority: S301: The receiver authority runs the decryption key generation algorithm of ACE according to the received master private key and identity information to obtain the decryption key of ACE: .
[0041] S302: Integrates to obtain the decryption key of the user transmits the decryption key to each receiver.
[0042] In one embodiment, before S301, the receiver performs the following operation: sends its identity information to the receiver authority.
[0043] In one embodiment, S4 includes the following operation performed by the sender: S401: The sender randomly selects for each , and records the auxiliary parameter . Among them is the corresponding quantity in the D-PM global parameter.
[0044] S402: The sender runs the ACE encryption algorithm according to the received encryption key to obtain the corresponding ACE encryption ciphertext , and . Note that and are actually ACE ciphertexts generated for multiple elements , and their structures are similar to , and the only part that really changes is , so in actual execution, all can share the same to reduce the size of the ciphertext to save storage space and computing overhead. The sender runs the D-PM encryption algorithm to obtain the corresponding D-PM detection ciphertext .
[0045] S403: Integrates to obtain the final ciphertext . The sender transmits the final ciphertext transmitted to the purifier.
[0046] In one embodiment, S5 includes the following operations performed by the purifier: S501: The purifier determines whether the received ciphertext meets all the trapdoor sets for all the trapdoors corresponding to the purifying requirements, and if so, proceeds to S502; otherwise, ends. S502: The purifier runs the purifying algorithm of ACE to obtain the purified ciphertext , and .
[0047] S503: The purifier parses the input detection ciphertext into , where only the latter half of the algorithm is used, and for simplicity, it can be denoted as ; and parses the purified ciphertext into and .
[0048] S504: The purifier selects a randomization factor and performs calculations to obtain the final purified ciphertext . In this step of calculation, the purifier needs to perform some necessary group element type conversion.
[0049] S505: The purifier transmits the purified ciphertext to the recipient.
[0050] In one embodiment, S501: The purifier runs the detection algorithm of D-PM according to the received trapdoor corresponding to the keyword and the ciphertext to obtain the corresponding output result set . The purifier calculates the corresponding for all the received trapdoors . If all the are empty sets, the next step is performed; otherwise, if any is not an empty set, the purifier outputs , and the purifier's operation is aborted.
[0051] In one embodiment, S6 includes the following operations performed by the recipient: S601: The recipient runs the decryption algorithm of ACE according to the received decryption key and the purified ciphertext to obtain and . Denote the auxiliary parameters .
[0052] S602: The receiver runs the decryption algorithm of ACE to obtain the detection ciphertext and If the identity of the receiver and the ciphertext sender conforms to the access control policy, the receiver runs the decryption algorithm of D-PM to obtain the decrypted plaintext .
[0053] It is to be understood that the above-described embodiments are merely illustrative of the principles of the application and that numerous and various modifications can be made by those skilled in the art without departing from the spirit and scope of the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A content detection based access control encryption and decryption method, characterized by, A method applied to an access control encryption and decryption system, the access control encryption and decryption system comprising: a center authority, a sender authority, a receiver authority, a sender, a purifier and a receiver; the method comprising: S1: the central authority: generates global parameters and master private key according to input security parameters and access control policy S2: the sender authority: generates global parameters and master private key according to input security parameters and access control policy S3: the receiver authority: generates global parameters and master private key according to input security parameters and access control policy S4: the sender authority and the receiver authority: receives global parameters and master private key from the central authority, and generates a corresponding key pattern and trapdoor set for sensitive information S5: the purifier: receives the trapdoor set from the sender authority and the receiver authority, and generates a corresponding key pattern S2: The authoritative institution of the sender: upon receiving the sender's identity information. At that time, based on the aforementioned identity information The global parameters and the master private key Generate encryption key And feedback is sent back to the sender; S3: The authoritative institution of the recipient: upon receiving the identity information of the recipient. At that time, based on the identity information The global parameters and the master private key Generate decryption key And feedback is sent to the recipient; S4: the sender: uses the encryption key plaintext message encrypted into ciphertext and sends the ciphertext to the purifier; S5: the purifier: receiving the ciphertext , if the ciphertext meets the purification requirement, purifying to obtain a purified ciphertext using the trapdoor set ; S6: said recipient: utilizes said decryption key decrypts said sanitized ciphertext decrypts said sanitized ciphertext 2. The content detection based access control encryption and decryption method of claim 1, wherein, The S1 comprises that the center authority performs the following operations: S101: running an initialization algorithm of an access control encryption technology ACE to obtain public parameters of the ACE and a master private key : , an access control policy , is a random number; running an initialization algorithm of a decryptable pattern matching technology D-PM to obtain public parameters of the D-PM: ; running a key generation algorithm of the decryptable pattern matching technology D-PM to obtain a corresponding public-private key pair: , finally obtaining the master key and the global parameter ; is an upper limit of a maximum length of the keyword pattern; S102: generate the keyword pattern a corresponding trap set; S103: transmitting the master private key and the global parameter to the sender authority and the receiver authority; transmitting a trap of the set of traps to the purifier.
3. The content detection based access control encryption and decryption method of claim 2, wherein S102 comprises: According to the master private key and the keyword pattern generating a trap within the set of traps : wherein the length .
4. The content detection based access control encryption and decryption method of claim 2, wherein, The S2 comprises that the sender authority performs the following operations: S201: When receiving the identity information of the sender , run the encryption key generation algorithm of ACE according to the master private key and the identity information of the sender to obtain the encryption key of ACE: ; S202: The as an encryption key and transmitted to the corresponding sender.
5. The content detection based access control encryption and decryption method of claim 4, wherein, The S3 comprises that the receiver authority performs the following operations: S301: When receiving the identity information of the receiver , a decryption key generation algorithm of ACE is run according to the master private key and the identity information to obtain a decryption key of ACE: ; S302: encrypting the decrypted key with the corresponding receiver's public key and transmitting the encrypted key to the corresponding receiver. as the decryption key and transmitting to the corresponding receiver.
6. The content detection based access control encryption and decryption method of claim 5, wherein, The S4 comprises that the sender performs the following operations: S401: randomly select auxiliary parameters , is a prime number, is an integer field with modulus is an integer field with modulus denotes uniform random selection; S402: according to the encryption key running the ACE encryption algorithm to obtain the corresponding ACE encryption ciphertext and ; running the D-PM encryption algorithm to obtain the corresponding D-PM detection ciphertext ; S403: integrate the ciphertext And transport to the purifier.
7. The content detection based access control encryption and decryption method of claim 6, wherein, The S5 comprises that the purifier performs the following operations: S501: judging whether the received ciphertext corresponds to all the trapdoors corresponds to the corresponding purification requirement, if yes, executing S502; otherwise, ending S502: decrypting the ciphertext Running the purification algorithm of ACE obtains the ciphertext to be purified With ; S503: parse the to-be-purified ciphertext into , does not carry any information about the plaintext, while contains the effective information of the plaintext. S504: Select a randomization factor , the randomization factor is selected from a set of randomization factors , the set of randomization factors is selected from a set of randomization factors , the set of randomization factors is selected from a set of randomization factors ; S505: The purified ciphertext is integrated and transmitted to the corresponding recipient.
8. The content detection based access control encryption and decryption method of claim 7, wherein, S501 includes: trapdoors for all trapdoor sets. and the ciphertext Running the D-PM detection algorithm yields the corresponding output result set. ;like If the set is empty, it is considered as the ciphertext. If the corresponding purification requirements are met, proceed with S502; otherwise, the process ends.
9. The content detection based access control encryption and decryption method of claim 7, wherein, The S6 comprises that the receiver performs the following operations: S601: run the decryption algorithm of ACE to obtain the auxiliary parameter according to the decryption key and the purified ciphertext ; run the decryption algorithm of ACE to obtain the detection ciphertext ; run the decryption algorithm of ACE to obtain the detection ciphertext ; S602: running a decryption algorithm of the D-PM, if the receiver and the corresponding sender are both legal users in the access control policy, obtaining the decrypted plaintext .
10. A content detection based access control encryption and decryption system, characterized by Comprising: a central authority for generating global parameters and access control policies from input security parameters and a master private key and distributing the global parameters and the master private key to the sender authorities and the receiver authorities; and generating the keyword pattern a corresponding trap set, and sending the trap set to a purifier The sender's authoritative body is used to verify the sender's identity information upon receipt. At that time, based on the aforementioned identity information The global parameters and the master private key Generate encryption key And feedback is sent back to the sender; The recipient's authoritative body is used to verify the recipient's identity information upon receipt. At that time, based on the identity information The global parameters and the master private key Generate decryption key And feedback is sent to the recipient; The sender, used with the encryption key Plain text message Encrypt to ciphertext and ciphertext Send to the air purifier; A purifier for receiving the ciphertext , if the ciphertext meets the purification requirement, purifying the ciphertext by using the trapdoor set to obtain a purified ciphertext ; a recipient, for decrypting the purified ciphertext using the decryption key decrypting the purified ciphertext using the decryption key.
Citation Information
Patent Citations
Attribute-based secure communication method and system supporting ciphertext mode matching
CN111556048A
Fine-grained access control method based on block chain in cloud edge collaborative environment
CN115484095A
Attribute-based access control encryption and decryption method and system
CN116545712A
Searchable encryption scheme for resisting malicious behaviors of data publisher and cloud server
CN117763591A
Encryption method and device for preventing malicious data release and storage medium
CN118246041A