Government affair data dynamic authorization management method based on secure multi-party computing
By using secure multi-party computation and hardware secure enclave technology, quantum-resistant dynamic property-based encryption key fragmentation is generated, which solves the problem of insufficient real-time adaptability in dynamic environments in government data authorization management, and realizes real-time dynamic adjustment of government data authorization and privacy protection.
Patent Information
- Application Number
- CN202511241825.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-02
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-09-02
AI Technical Summary
Existing government data authorization management solutions lack real-time dynamic adaptability in dynamic environments, making it difficult to cope with access permission adjustments in the event of emergencies, and also pose risks of centralized dependence and privacy leakage.
Employing secure multi-party computation technology, the system generates asymmetric key pairs using the national cryptographic SM2 algorithm, generates identity credential packages using consortium blockchain smart contracts, collaboratively generates quantum-resistant dynamic attribute-based encryption key fragments, and executes a multi-party secure computation protocol within a hardware security enclave to generate permission tokens and configure access control policies, dynamically adjusting attribute weight parameters.
It enables real-time dynamic adaptability in the government data authorization process, reduces the risk of centralized dependence, and improves the system's security and privacy protection capabilities.
Smart Images

Figure CN121077653A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of government data security authorization management, and particularly relates to a government data dynamic authorization management method based on secure multi-party computation. BACKGROUND
[0002] In the field of government data security authorization management, attribute-based encryption access control technology has been widely used. By matching the attribute information of data users with access strategies, fine-grained access control is achieved. The core is to use smart contracts to automatically execute predefined authorization strategies, and to record authorization operations through a distributed ledger to ensure audit tracking. Such solutions have achieved certain results in static strategy execution and operation transparency, and can meet the basic security needs of regular government data sharing scenarios. With the surge in the amount of business carried by government cloud platforms and the increase in data sensitivity, especially in dynamic scenarios such as emergency management and cross-regional collaboration, the traditional technical architecture gradually shows the problem of inadequate adaptability.
[0003] Although the existing solutions have been optimized in terms of strategy execution efficiency and audit tracking, their core authorization mechanism still relies on predefined static strategy models, which makes it difficult to cope with the frequent changes in access requirements and security situation in the government environment. Existing technologies usually use fixed attribute encryption key generation methods, which lack the ability to perceive and respond to dynamic environmental factors. In the process of handling public emergencies, government data of different security levels needs to be dynamically adjusted according to real-time risk indicators. However, the traditional ABE scheme cannot automatically adapt the key parameters. Government data sharing involves multiple mutually untrusted functional departments. Most existing solutions rely on trusted third parties for key management, which poses a single point of failure and privacy leakage risk. SUMMARY
[0004] In view of the above existing problems, the present application is proposed.
[0005] Therefore, the present application provides a government data dynamic authorization management method based on secure multi-party computation, which solves the problem of insufficient real-time dynamic adaptability caused by static strategies and centralized dependence in the government data authorization process.
[0006] To solve the above technical problems, the present application provides the following technical solutions:
[0007] In the first aspect, the present application provides a government data dynamic authorization management method based on secure multi-party computation, which includes assigning a unique identity to each participant, generating an asymmetric key pair using the SM2 algorithm, registering the public key and institutional attribute information to the alliance chain smart contract, and generating an identity credential package.
[0008] The participants generate anti-quantum dynamic attribute-based encryption key fragments based on attribute information in the identity credential package through a secure multi-party computation protocol, and distribute the key fragments to each participant by using threshold secret sharing technology;
[0009] The FPGA acceleration card receives the anti-quantum dynamic attribute-based encryption key fragments, executes the multi-party secure computation protocol in the hardware secure enclave, and obtains the decision result and the permission token ciphertext segment;
[0010] The verification smart contract on the alliance chain receives the decision result and the permission token ciphertext segment, restores the complete permission token by threshold decryption, verifies the validity, and generates an authorization record;
[0011] According to the authorization record, the access control policy of the edge computing node is configured, and the encrypted query of the data requester is responded by using the oblivious transfer protocol;
[0012] The audit node monitors the access log of the data requester, dynamically adjusts the attribute weight parameter through the secure multi-party computation protocol, and synchronizes to the anti-quantum dynamic attribute-based encryption key fragments.
[0013] As a preferred scheme of the government data dynamic authorization management method based on secure multi-party computation, wherein: a unique identity is allocated to each participant, a non-symmetric key pair is generated by using the national SM2 algorithm, the public key and the institutional attribute information are registered to the alliance chain smart contract, and an identity credential package is generated, including the following steps,
[0014] The government data management unit generates a unique identity for each participant by using a hash algorithm, generates a non-symmetric key pair on an elliptic curve by using the national SM2 algorithm, and obtains a private key and a public key;
[0015] The private key is written into a hardware security module, a two-factor access control policy is configured, a physically protected private key storage handle is obtained, a standardized institutional attribute JSON object is constructed according to the administrative responsibilities of the participants,
[0016] The unique identity, the public key and the standardized institutional attribute JSON object are combined into a registration transaction data structure;
[0017] Based on the registration transaction data structure, the registration contract deployed on the alliance chain is used to obtain the call result of the block height and the transaction hash, the CA agency verifies the call result of the block height and the transaction hash, the root certificate is signed by using the SM2 algorithm, and a digital certificate is obtained;
[0018] The unique identity, the public key, the standardized institutional attribute JSON object and the digital certificate are integrated to generate an identity credential package.
[0019] As a preferred scheme of the government affair data dynamic authorization management method based on secure multi-party computation, wherein: participating parties generate anti-quantum dynamic attribute-based encryption key fragments through a secure multi-party computation protocol based on attribute information in the identity credential package, including the following steps,
[0020] The government affair data management unit parses the agency attribute information in the identity credential package and converts it into a standardized binary attribute vector, and each participating party generates a cryptographic public matrix and an attribute association matrix through a secure multi-party protocol based on the standardized binary attribute vector;
[0021] The real-time weight value is obtained according to the current timestamp and the initial weight;
[0022] The attribute association matrix and the real-time weight value are used to calculate the master key through MPC secure computation, and the anti-quantum dynamic attribute-based encryption key fragments are generated.
[0023] As a preferred scheme of the government affair data dynamic authorization management method based on secure multi-party computation, wherein: threshold secret sharing technology is used to distribute to each participating party, including the following steps,
[0024] Discrete Gaussian noise is added to the anti-quantum dynamic attribute-based encryption key fragments to obtain a noise key;
[0025] A polynomial is constructed based on the noise key to obtain a polynomial coefficient vector;
[0026] The Shamir threshold secret sharing method is used to obtain the key fragments of each participating party, and the key fragments are encrypted using an additive homomorphic encryption scheme to obtain an encrypted fragment set;
[0027] Each participating party decrypts the encrypted fragment set and performs verification, and the verified key fragments are written into a hardware security module.
[0028] As a preferred scheme of the government affair data dynamic authorization management method based on secure multi-party computation, wherein: FPGA acceleration cards are used to receive anti-quantum dynamic attribute-based encryption key fragments, and multi-party secure computation protocols are executed in a hardware security enclave to obtain decision results and permission token ciphertext fragments, including the following steps,
[0029] The FPGA loads a physically isolated TrustZone security enclave firmware to generate a chip unique key, and the received encrypted fragment set is processed using Paillier homomorphic decryption to obtain plaintext key fragments;
[0030] The noise key is reconstructed on a finite field through Lagrange interpolation to obtain a verified fragment set, and a built-in true random number generator of the FPGA generates a three-tuple pool in parallel;
[0031] The encrypted matching result of the request attribute and the dynamic weight is calculated based on the GMW protocol, the encrypted matching result is decrypted by the Shamir algorithm, and a decision result and a permission token ciphertext segment are obtained.
[0032] As a preferred scheme of the government data dynamic authorization management method based on secure multi-party computation, wherein: the decision result and the permission token ciphertext segment are received by a verification smart contract on the alliance chain, the complete permission token is recovered by threshold decryption and the validity is verified, an authorization record is generated, including the following steps,
[0033] The encrypted decision result and the token segment transaction request are obtained by listening to the blockchain event log through the verification smart contract, the original data packet to be processed is obtained, the digital signature of the token segment transaction request is verified using the public key, and a data packet with a passed signature verification is obtained.
[0034] The smart contract collects encrypted permission token segments from participant nodes, obtains a segment set meeting the threshold requirement, reconstructs the noise key by the Shamir secret sharing algorithm, decrypts to obtain the plaintext permission token, verifies the plaintext permission token using a multi-dimensional joint verification method, and obtains the content of the verified plaintext permission token.
[0035] According to the verified token content, an authorization record is generated.
[0036] As a preferred scheme of the government data dynamic authorization management method based on secure multi-party computation, wherein: according to the authorization record, an access control strategy of an edge computing node is configured, and an oblivious transfer protocol is used to respond to encrypted query of a data requester, including the following steps,
[0037] The edge node obtains the authorization record from the blockchain, extracts the allowed operation list, the forbidden operation list and the effective condition in the permission declaration field, and obtains a structured policy object;
[0038] The structured policy object is converted into a policy language file of a Linux security enhancement module, a binary policy file of type forced rule and access vector is generated, a policy module is obtained, a security loading interface loads the policy module into a Linux security module, a policy activation state code is obtained, a symmetric decryption is performed on the encrypted query data submitted by the requester by using a voice key, a plaintext query statement is obtained, the operation field in the query statement is compared with the allowed operation list in the policy object, a security filtered query syntax tree is obtained, and a target data index value is extracted from the security filtered query syntax tree.
[0039] The requester calculates a blind request parameter by an elliptic curve blinding algorithm according to the target data index value, an elliptic curve generator and a random number, and obtains an oblivious transfer protocol request packet.
[0040] The edge node uses its own private key to hash and confuse all data items, generates a corresponding response data set, and the requester uses the pre-shared elliptic curve parameters and its own selected bit information to extract and decrypt the target data item from the response packet to obtain the plaintext query result.
[0041] As a preferred scheme of the government data dynamic authorization management method based on secure multi-party computation, wherein: the audit node monitors the access log of the data requester, dynamically adjusts the attribute weight parameter through the secure multi-party computation protocol, and synchronizes to the anti-quantum dynamic attribute-based encryption key fragment, including the following steps,
[0042] The audit node receives the encrypted access log stream of the edge computing node through the TLS1.3 protocol, obtains the encrypted log block with timestamp, hashes the Merkle tree root of the encrypted log block, and compares it with the blockchain storage, and outputs the standardized log data verified;
[0043] Each audit node aggregates the log feature values through the secure multi-party protocol to obtain the encrypted statistical result;
[0044] Based on the statistical result, the abnormal access behavior exceeding the 3σ range is identified to obtain a risk event report, and the weight adjustment gradient is obtained through the MPC protocol according to the risk report;
[0045] The weight adjustment gradient is used to dynamically adjust the attribute correlation matrix to obtain an adjusted matrix parameter set, and a new key fragment is generated through threshold secret sharing based on the adjusted matrix parameter set, the Merkle root hash of the new key fragment is written into the smart contract, and a strategy update transaction receipt is obtained.
[0046] In a second aspect, the present application provides a computer device comprising a memory and a processor, the memory storing a computer program, wherein: the computer program is executed by the processor to realize any step of the government data dynamic authorization management method based on secure multi-party computation according to the first aspect of the present application.
[0047] In a third aspect, the present application provides a computer readable storage medium having a computer program stored thereon, wherein: the computer program is executed by the processor to realize any step of the government data dynamic authorization management method based on secure multi-party computation according to the first aspect of the present application.
[0048] The application has the beneficial effects that: by allocating a unique identity by each participant and generating an asymmetric key pair by using the national secret SM2 algorithm, the public key and the agency attribute information are registered to the identity credential package generated by the alliance chain smart contract; based on the attribute information in the identity credential package, the anti-quantum dynamic attribute-based encryption key fragments are generated by the secure multi-party computation protocol and are distributed by using the threshold secret sharing technology, the multi-party secure computation protocol is executed in the hardware security enclave by using the FPGA acceleration card, and the decision result and the permission token ciphertext segment are obtained; the threshold decryption and the token verification are realized by the alliance chain verification smart contract, the authorization record is generated, the access control policy of the edge computing node is configured according to the authorization record, the data query is responded by using the careless transmission protocol, the access log is monitored by the audit node, the attribute weight parameter is dynamically adjusted and is synchronized to the key fragment. BRIEF DESCRIPTION OF DRAWINGS
[0049] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings needed to be used in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0050] Fig. 1 The flowchart of the government data dynamic authorization management method based on secure multi-party computation.
[0051] Fig. 2 The flowchart of the government data participant identity credential package generation.
[0052] Fig. 3 The flowchart of the anti-quantum dynamic attribute-based encryption key fragment collaborative generation.
[0053] Fig. 4 The flowchart of the dynamic authorization verification based on the hardware security enclave. DETAILED DESCRIPTION
[0054] In order to make the above-mentioned purposes, features and advantages of the application more obvious and easy to understand, the specific embodiments of the application will be described in detail in combination with the drawings of the specification.
[0055] In the following description, many specific details are set forth in order to provide a thorough understanding of the application, but the application can also be implemented in other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of the application, therefore the application is not limited by the specific embodiments disclosed below.
[0056] Second, the "one embodiment" or "an embodiment" referred to herein can include a particular feature, structure, or characteristic. The various embodiments appearing at different places in this specification are not necessarily all cumulative or mutually exclusive of each other.
[0057] Referring to Figs. 1-4 For one embodiment of the present application, the embodiment provides a government affair data dynamic authorization management method based on secure multi-party computation, comprising the following steps:
[0058] S1, assign a unique identity to each participant, generate an asymmetric key pair using the national SM2 algorithm, register the public key and institution attribute information to the alliance chain smart contract, and generate an identity credential package.
[0059] S1.1, the government data management unit generates a unique identity for each participant using a hash algorithm, generates an asymmetric key pair on an elliptic curve using the national SM2 algorithm, and obtains a private key and a public key.
[0060] Specifically, the expression is,
[0061] ID=SM3(O||D||N);
[0062] Wherein, ID is a unique identity, O is an institution code, D is an administrative division code, and N is a random number.
[0063] S1.2, write the private key into the hardware security module, configure a two-factor access control policy, obtain a physically protected private key storage handle, and construct a standardized institution attribute JSON object according to the administrative responsibilities of the participants.
[0064] Further, the private key generated by the national SM2 algorithm is stored in the tamper-proof storage area of the hardware security module in an encrypted form by calling the key import function provided by the hardware security module; then a two-factor access control policy is configured, which requires the verification of both a physical smart card and a biological feature to access the private key, and a physically protected private key storage handle is generated, and at the same time, according to the administrative responsibilities of the participants in the government system, the permission attribute field is extracted, and a standardized institution attribute JSON object is constructed.
[0065] S1.3, combine the unique identity, the public key and the standardized institution attribute JSON object into a registration transaction data structure.
[0066] Further, the specific process of combining the unique identity, public key and standardized agency attribute JSON object into the registration transaction data structure is: first, extract the unique identity complete string generated by the hash algorithm, obtain the compressed format public key binary data generated by the national SM2 algorithm, and the serialized byte stream of the standardized agency attribute JSON object containing the department level, data classification and operation permission field, then according to the transaction data format defined by the alliance chain smart contract, place the unique identity as the index field in the head of the structure, the public key data as the identity verification field in the middle of the structure, and the standardized agency attribute JSON object as the permission declaration field in the tail of the structure, and finally add the version number field and the data length field to form the complete registration transaction data structure,
[0067] S1.4, based on the registration transaction data structure, use the registration contract deployed on the alliance chain to obtain the block height and transaction hash calling result, use the CA agency to verify the block height and transaction hash calling result, use the root certificate to perform SM2 signature, and obtain the digital certificate.
[0068] Further, based on the registration transaction data structure, the registration contract function deployed on the alliance chain is called, and the registration transaction data structure is transmitted as an input parameter into the registration method of the registration contract. After executing the smart contract code, a calling result containing the block height and transaction hash is generated in the blockchain network. The certificate authority node listens to the blockchain network to obtain the calling result, verifies whether the block height is within the current chain height range and whether the transaction hash is valid, and after verification, the certificate authority uses its root certificate private key to perform national SM2 algorithm signature on the public key field and the agency attribute field in the registration transaction data structure to obtain the digital certificate.
[0069] S1.5, integrate the unique identity, public key, standardized agency attribute JSON object and digital certificate to generate an identity credential package.
[0070] Further, the specific process of integrating the unique identity, public key, standardized agency attribute JSON object and digital certificate to generate an identity credential package is: the unique identity generated by the hash algorithm is taken as the credential index field, the public key generated by the national SM2 algorithm is taken as the identity verification field, the standardized agency attribute JSON object containing the department level and data classification is taken as the permission declaration field, and the digital certificate issued by the CA agency is taken as the trust anchor field; the four fields are assembled into a structured data block in order according to the ASN.1 encoding rule, the SM3 hash value of the data block is calculated as the integrity check code, and finally the identity credential package is generated.
[0071] S2, the participants generate anti-quantum dynamic attribute-based encryption key fragments through secure multi-party computation protocol based on the attribute information in the identity credential package.
[0072] S2.1, the government data management unit parses the agency attribute information in the identity credential package, converts it into a standardized binary attribute vector, and each participant generates a cryptographic public matrix and an attribute association matrix based on the standardized binary attribute vector through a secure multi-party protocol.
[0073] Further, the government data management unit parses the agency attribute information in the identity credential package, extracts the department level and data classification field in the standardized agency attribute JSON object; converts each attribute field into a fixed-length binary attribute vector through a SHA3 hash function; each participant generates a cryptographic public matrix by calculating the matrix product through the additive homomorphism encryption feature of the secure multi-party computation protocol based on the binary attribute vector they hold; and continues to calculate the attribute association matrix through the multiplication sub-protocol of the secure multi-party computation protocol, and finally obtains the complete combination of the cryptographic public matrix and the attribute association matrix.
[0074] S2.2, according to the current timestamp and the initial weight, the real-time weight value is obtained.
[0075] Further, the process of calculating the real-time weight value according to the current timestamp and the initial weight is: obtaining the accurate time difference value from the authorization start time to the current time, and substituting the time difference value into the exponential decay function for calculation; the exponential decay function takes the initial weight as the reference value and a fixed decay coefficient as the proportion constant, and obtains the real-time weight value through the negative exponential operation of the natural constant; the real-time weight value presents continuous decay characteristics as time goes on, and finally outputs the real-time weight value.
[0076] S2.3, using the attribute association matrix and the real-time weight value, the MPC secure computation master key is used to generate an anti-quantum dynamic attribute-based encryption key fragment.
[0077] Specifically, the expression is,
[0078] sk=[A|B0+∑w·x i B i ] -1 ·G;
[0079] Where, sk is an anti-quantum dynamic attribute-based encryption key fragment, A is a public parameter matrix, B0 is an attribute association matrix, w is a dynamic weight function, x i is the binary encoding value of the i-th attribute, B i is the association matrix corresponding to the i-th attribute, and G is a fixed trapdoor matrix in lattice cryptography.
[0080] S3, using threshold secret sharing technology to distribute to each participant.
[0081] S3.1, add discrete Gaussian noise to the quantum-resistant dynamic attribute-based encryption key fragment to obtain a noisy key.
[0082] Further, a random noise value is obtained from a cryptographically secure discrete Gaussian distribution sampler, the random noise value has a zero mean and a preset standard deviation parameter, and the quantum-resistant dynamic attribute-based encryption key fragment and the discrete Gaussian noise value are added in a finite field to obtain a noisy key.
[0083] S3.2, construct a polynomial based on the noisy key to obtain a polynomial coefficient vector.
[0084] Specifically, the expression is,
[0085] f(z)=sk″+a1z+...+a t-1 z m-1 ;
[0086] Wherein, f(z) is a polynomial coefficient vector, z is an input variable, sk″ is a noisy key, a1 is a random coefficient vector, a t-1 is the t-1th coefficient of the random coefficient vector, z k-1 is the m-1th power of the input variable, t is a threshold value, and m is the highest degree.
[0087] S3.3, use Shamir threshold secret sharing method to obtain the key fragment of each participant, and use additive homomorphic encryption scheme to encrypt the key fragment to obtain an encrypted fragment set.
[0088] Further, the specific process of using Shamir threshold secret sharing method to obtain the key fragment of each participant is: based on the noisy key, a t-1th degree polynomial is constructed, and the unique number of each participant is substituted into the polynomial to calculate the corresponding key fragment value; then, using Paillier additive homomorphic encryption scheme, the public key of the receiver is used to encrypt each key fragment value to generate an encrypted fragment set.
[0089] S3.4, each participant decrypts the encrypted fragment set and verifies it, and writes the verified key fragment into a hardware security module.
[0090] s j =f·(j);
[0091] Wherein, s j is the key fragment of the jth participant, j is the unique number of the participant, f is the polynomial
[0092] S4, use FPGA acceleration card to receive quantum-resistant dynamic attribute-based encryption key fragment, execute multi-party secure computation protocol in hardware security enclave to obtain decision result and permission token ciphertext segment.
[0093] S4.1, using FPGA to load physically isolated TrustZone secure enclave firmware, generating chip unique key, using Paillier homomorphic decryption processing to receive encrypted fragment set, getting plaintext key fragment.
[0094] Further, the process of using FPGA to load physically isolated TrustZone secure enclave firmware is: through the FPGA configuration interface, write the digitally signed TrustZone secure enclave firmware image into the physically isolated secure area, trigger the physically unclonable function to generate the chip unique key based on the chip physical characteristics; then call the hardware implementation module of the Paillier homomorphic decryption algorithm in the secure enclave, use the chip unique key to decrypt the encrypted fragments in the secret fragment set, restore the plaintext key fragments through modular exponentiation and modular inverse; get the plaintext key fragments.
[0095] S4.2, reconstruct the noise key on the finite field through Lagrange interpolation, get the verified fragment set, and the FPGA built-in true random number generator generates a three tuple pool in parallel.
[0096] Further, the process of reconstructing the noise key on the finite field through Lagrange interpolation is: collect a set of plaintext key fragments that reach at least the threshold value, use the Lagrange interpolation formula to calculate the function value of the zero point with each plaintext key fragment corresponding to the participant number as the interpolation point abscissa and the fragment value as the ordinate, reconstruct the complete noise key, and verify whether each interpolation point satisfies the polynomial constraint relationship, form a verified fragment set through the verified plaintext key fragments, and the FPGA built-in true random number generator generates multiple groups of Beaver three tuples based on quantum noise source in parallel.
[0097] S4.3, based on GMW protocol to calculate the encrypted matching result of request attribute and dynamic weight, decrypt the encrypted matching result through Shamir algorithm, get the decision result and the permission token ciphertext segment.
[0098] Specifically, the expression is,
[0099]
[0100] Wherein, E(Match) is the encrypted matching result, E(x i ) is the encrypted value of the i-th attribute, E(w i ) is the encrypted value of the dynamic weight of the i-th attribute, E(r) is the encrypted vector, n is the total number of attributes, and i is the attribute index.
[0101] Specifically, the expression is,
[0102]
[0103] wherein Match is the decrypted matching result, q is a modulus, and k is a node index in the Lagrange interpolation.
[0104] S5. Receiving the decision result and the encrypted token fragment through the verification smart contract on the alliance chain, restoring the complete token through threshold decryption and verifying the validity, and generating an authorization record.
[0105] S5.1. Listening to the blockchain event log through the verification smart contract, obtaining the transaction request of the encrypted decision result and the token fragment, obtaining the original data packet to be processed, verifying the digital signature of the transaction request of the token fragment using the public key, and obtaining the data packet with a passed signature verification.
[0106] Further, the verification smart contract continuously scans the newly generated blocks in the blockchain network, identifies the transaction request event containing the encrypted decision result and the token fragment, extracts the complete encrypted data payload from the blockchain transaction data, assembles it into the original data packet to be processed, verifies the digital signature in the transaction request using the pre-stored public key of the supervision node, checks the matching of the signature and the transaction hash using the SM2 signature verification algorithm, and the transaction request data that passes the verification is marked as a data packet with a passed signature verification.
[0107] S5.2. The smart contract collects encrypted token fragments from participant nodes, obtains a fragment set that meets the threshold requirement, reconstructs the noise key through the Shamir secret sharing algorithm, decrypts to obtain the plaintext token, verifies the plaintext token using a multi-dimensional joint verification method, and obtains the content of the plaintext token that passes the verification.
[0108] Further, the smart contract collects encrypted token fragments from participant nodes, and when the number of collected encrypted token fragments reaches a preset threshold value, a fragment set that meets the threshold requirement is formed. The encrypted token fragments in the fragment set that meets the threshold requirement are reconstructed using the Shamir secret sharing algorithm to restore the noise key. The encrypted token fragments are decrypted using the noise key to obtain the plaintext token, and the plaintext token is verified using a multi-dimensional joint verification method. The multi-dimensional joint verification method includes consistency checking and validity verification of identity information, timestamps, access policies, and digital signatures in the plaintext token. Only when all dimensions pass the verification, the plaintext token is determined to be valid, and the content of the plaintext token that passes the verification is obtained.
[0109] S5.3. Generating an authorization record according to the token content that passes the verification.
[0110] Further, the permission declaration field and the data identification field in the token content verified by the analysis are parsed to extract the access permission list and the valid period information; the extracted permission information and the data resource identification are combined into a structured record, and the current timestamp and the blockchain block height are added as audit information; the permission entries are calculated by hash using the Merkle tree structure to generate a root hash value, and finally a complete authorization record containing data hash, permission policy and audit trail is formed.
[0111] S6. According to the authorization record, the access control policy of the edge computing node is configured, and the encryption query of the data request party is responded by using the oblivious transfer protocol.
[0112] S6.1, the edge node obtains the authorization record from the blockchain, extracts the allowed operation list, the prohibited operation list and the effective condition in the permission declaration field, and obtains a structured policy object.
[0113] Further, the latest block data containing the authorization record is queried through the blockchain node interface, and the permission declaration field in the authorization record is parsed; the specific operation types contained in the allowed operation list, the restricted operation types contained in the prohibited operation list, and the time constraints and attribute constraints contained in the effective condition are extracted from the permission declaration field; these extracted elements are combined into a structured policy object containing complete permission information.
[0114] S6.2, the structured policy object is converted into a policy language file of the Linux security enhancement module, a binary policy file of the type forced rule and the access vector is generated, a policy module is obtained, the policy module is loaded into the Linux security module through a security loading interface, a policy activation state code is obtained, the encryption query data submitted by the request party is symmetrically decrypted by using the key pair, a plaintext query statement is obtained, the operation field in the query statement is compared with the allowed operation list in the policy object, a security filtered query syntax tree is obtained, and a target data index value is extracted from the security filtered query syntax tree.
[0115] Further, the allowed operation list and the forbidden operation list in the structured policy object are parsed to generate corresponding type enforcement rule declaration and access vector definition, the policy compiler is used to compile the policy language file into a binary format policy module, the policy module contains machine code representation of the type enforcement rule and the access vector; the security module loading function of the Linux kernel is called through the secure loading interface to load the policy module into the Linux security module, and a policy activation status code is returned to represent the loading result; the encrypted query data submitted by the requestor is decrypted using the session key to obtain a plaintext query statement; the operation field in the plaintext query statement is compared with the allowed operation list in the structured policy object item by item to filter out unauthorized operation items and generate a security filtered query syntax tree; the specific value of the target data index value is parsed from the WHERE condition clause of the security filtered query syntax tree.
[0116] S6.3, the requestor calculates a blind request parameter using an elliptic curve blinding algorithm based on the target data index value, an elliptic curve generator and a random number, and obtains an oblivious transfer protocol request packet.
[0117] Specifically, the expression is,
[0118] c = g σ ·h r modp
[0119] Wherein, c is the blind request parameter, g is the elliptic curve base point, sigma is the target data index value, and h is the elliptic curve point of the receiver public key.
[0120] S6.4, the edge node uses its own private key to perform hash confusion on all data items to generate a corresponding response data set, and the requestor extracts and decrypts the target data item from the response packet using the pre-shared elliptic curve parameters and its own selected bit information to obtain the plaintext query result.
[0121] Further, the message authentication code of each data item is calculated using the national standard SM3 hash algorithm combined with the private key of the edge node, the original data item is XORed with the hash value to realize confusion, and a response data set containing all the confused data items is generated, which maintains the arrangement order of the original data items; the requestor uses the pre-shared elliptic curve generator and its own selected bit information to restore the blinding factor through elliptic curve point multiplication operation, extracts the confused data corresponding to the target position from the response data set, and removes the confusion effect through twice XOR operation to obtain the plaintext query result.
[0122] S7, the audit node monitors the access log of the data requestor, dynamically adjusts the attribute weight parameter through the secure multi-party computation protocol, and synchronizes to the anti-quantum dynamic attribute-based encryption key fragment.
[0123] S7.1, the audit node receives the encrypted access log stream of the edge computing node through the TLS1.3 protocol, obtains the encrypted log block with timestamp, hashes the Merkle tree root of the encrypted log block, and compares it with the blockchain storage, and outputs the standardized log data that passes the verification.
[0124] Further, a TLS1.3 security channel based on a national secret algorithm is established to receive the encrypted access log data stream transmitted in real time by the edge computing node; the received data stream is processed by block according to a fixed time window, a time stamp mark accurate to milliseconds is added to each data block, and an encrypted log block with timestamp is formed; the Merkle tree root hash value of each encrypted log block with timestamp is calculated, and the root hash value is compared and verified with the corresponding hash record stored in the blockchain in advance; only the encrypted log block that passes the consistency verification is decrypted to obtain the standardized log data that passes the verification.
[0125] S7.2, each audit node aggregates log feature values through a secure multi-party protocol to obtain encrypted statistical results.
[0126] Further, each audit node extracts key feature values from the standardized log data, including access frequency, operation type distribution, and time sequence pattern, etc. Feature indicators, and uses Paillier additive homomorphic encryption algorithm to encrypt the feature values of each node, and through the summation operation rule of the secure multi-party computing protocol, the encrypted feature values of all nodes are aggregated in the ciphertext state to generate encrypted statistical results containing global statistical features.
[0127] S7.3, based on the statistical results, identify abnormal access behaviors exceeding 3σ range, obtain risk event reports, and obtain weight adjustment gradient through MPC protocol according to risk reports.
[0128] Further, through the secure comparison protocol, identify abnormal data points deviating from the mean by more than three standard deviations, classify the identified abnormal access behaviors according to risk levels, generate risk event reports containing timestamps, risk types and impact levels; according to the risk indicators in the risk event report, obtain the weight adjustment gradient through the gradient descent algorithm of the secure multi-party protocol, and finally output the weight update vector processed by the homomorphic encryption, which maintains the privacy of the weight parameters of each participant.
[0129] S7.4, dynamically adjust the attribute association matrix using the weight adjustment gradient, obtain the adjusted matrix parameter set, generate new key fragments based on the adjusted matrix parameter set through threshold secret sharing, write the Merkle root hash of the new key fragments into the smart contract, and obtain the policy update transaction receipt.
[0130] Further, the encrypted weight update vector is decrypted and applied to the original attribute association matrix, the matrix element value is updated through matrix addition operation, and an adjusted matrix parameter set is obtained; based on the adjusted matrix parameter set, a new key fragment is generated by using a Shamir threshold secret sharing method, to ensure that the threshold reconstruction requirement is met, a Merkle tree root hash value of all new key fragments is obtained, the root hash value is taken as a parameter to call an update function of a blockchain smart contract, and a strategy update transaction receipt containing a transaction hash and a block height is returned after the smart contract is successfully executed.
[0131] The embodiment also provides a computer device suitable for the case of the government data dynamic authorization management method based on secure multi-party computation, including a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the government data dynamic authorization management method based on secure multi-party computation proposed in the above embodiment.
[0132] The computer device can be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device. In addition, the input device can be an external keyboard, touchpad or mouse, etc.
[0133] The embodiment also provides a storage medium on which a computer program is stored, the program being executed by a processor to implement the method for implementing dynamic authorization management of government affair data based on secure multi-party computation proposed in the above embodiment; and the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk.
[0134] To sum up, the application assigns a unique identity to each participant, generates an asymmetric key pair by using the national SM2 algorithm, registers the public key and the attribute information of the institution to the smart contract of the alliance chain to generate an identity credential package; based on the attribute information in the identity credential package, generates an anti-quantum dynamic attribute-based encryption key fragment by using a secure multi-party computation protocol and distributes the key fragment by using a threshold secret sharing technology, uses an FPGA acceleration card to execute the multi-party secure computation protocol in a hardware secure enclave to obtain a decision result and a permission token ciphertext fragment; implements threshold decryption and token verification by verifying the smart contract of the alliance chain, generates an authorization record, configures an access control policy of an edge computing node according to the authorization record, responds to a data query by using an inadvertent transmission protocol, monitors an access log by using an audit node, dynamically adjusts an attribute weight parameter and synchronizes the attribute weight parameter to the key fragment.
[0135] It should be noted that the above embodiments are only used to illustrate the technical solutions of the application but not limit the application, and although the application has been described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solutions of the application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the application, and all should be covered in the scope of the claims of the application.
Claims
1. A dynamic authorization management method for government data based on secure multi-party computation, characterized in that: Comprising, A unique identity is assigned to each participant, a non-symmetric key pair is generated using the national SM2 algorithm, the public key and the agency attribute information are registered to the alliance chain smart contract, and an identity credential package is generated; Participants generate quantum-resistant dynamic attribute-based encryption key fragments based on attribute information in the identity credential package through secure multi-party computation protocols, and distribute them to each participant using threshold secret sharing technology; Anti-quantum dynamic attribute-based encryption key fragments are received using FPGA acceleration cards, and multi-party secure computation protocols are executed in a hardware security enclave to obtain decision results and permission token ciphertext fragments; The decision results and permission token ciphertext fragments are received through the verification smart contract on the alliance chain, the complete permission token is recovered through threshold decryption and verified for validity, and an authorization record is generated; According to the authorization record, the access control policy of the edge computing node is configured, and the encrypted query of the data requester is responded to using the oblivious transfer protocol; The audit node monitors the access log of the data requester, dynamically adjusts the attribute weight parameter through the secure multi-party computation protocol, and synchronizes it to the quantum-resistant dynamic attribute-based encryption key fragment.
2. The government data dynamic authorization management method based on secure multi-party computation according to claim 1, characterized in that: A unique identity is assigned to each participant, a non-symmetric key pair is generated using the national SM2 algorithm, the public key and the agency attribute information are registered to the alliance chain smart contract, and an identity credential package is generated, including the following steps, The government data management unit generates a unique identity for each participant using a hash algorithm, and generates a non-symmetric key pair on an elliptic curve using the national SM2 algorithm to obtain a private key and a public key; Write the private key to the hardware security module, configure the two-factor access control policy, get the physically protected private key storage handle, and construct a standardized agency attribute JSON object according to the administrative responsibilities of the participants, Combine the unique identity, public key, and standardized agency attribute JSON object into a registration transaction data structure; Based on the registration transaction data structure, use the registration contract deployed on the alliance chain to get the block height and transaction hash call results, use the CA agency to verify the block height and transaction hash call results, use the root certificate for SM2 signature, and get the digital certificate; Integrate the unique identity, public key, standardized agency attribute JSON object, and digital certificate to generate an identity credential package.
3. The government data dynamic authorization management method based on secure multi-party computation according to claim 2, characterized in that: Participants generate quantum-resistant dynamic attribute-based encryption key fragments based on attribute information in the identity credential package through secure multi-party computation protocols, Including the following steps, The government data management unit parses the agency attribute information in the identity credential package and converts it into a standardized binary attribute vector, and each participant generates a cryptographic public matrix and an attribute association matrix based on the standardized binary attribute vector through a secure multi-party protocol; Get the real-time weight value according to the current timestamp and the initial weight; Use the attribute association matrix and the real-time weight value to generate a quantum-resistant dynamic attribute-based encryption key through MPC secure computation of the master key.
4. The government data dynamic authorization management method based on secure multi-party computation according to claim 3, characterized in that: Distributed to each participant using threshold secret sharing technology, including the following steps, Add discrete Gaussian noise to the quantum-resistant dynamic attribute-based encryption key fragment to get a noisy key; Construct a polynomial based on the noisy key to get a polynomial coefficient vector; Each participant's key shard is derived using Shamir threshold secret sharing method, and the key shard is encrypted using an additive homomorphic encryption scheme to obtain an encrypted shard set; Each participant decrypts the encrypted shard set and verifies it, and writes the verified key shard to the hardware security module.
5. The government data dynamic authorization management method based on secure multi-party computation according to claim 4, characterized in that: An FPGA acceleration card is used to receive anti-quantum dynamic attribute-based encryption key shards, and a multi-party secure computation protocol is executed in a hardware security enclave to obtain a decision result and a permission token ciphertext segment, including the following steps, An FPGA is used to load a physically isolated TrustZone security enclave firmware to generate a chip unique key, and a Paillier homomorphic decryption process is used to receive the encrypted shard set to obtain a plaintext key shard; The noise key is reconstructed on a finite field through Lagrange interpolation to obtain a verified shard set, and a built-in true random number generator of the FPGA generates a three-tuple pool in parallel; The encrypted matching result of the request attribute and the dynamic weight is calculated based on the GMW protocol, and the encrypted matching result is decrypted by Shamir algorithm to obtain a decision result and a permission token ciphertext segment.
6. The government data dynamic authorization management method based on secure multi-party computation according to claim 5, characterized in that: The decision result and the permission token ciphertext segment are received by a verification smart contract on the alliance chain, the complete permission token is restored by threshold decryption, and the validity is verified to generate an authorization record, including the following steps, The verification smart contract listens to the blockchain event log to obtain the transaction request of the encrypted decision result and the token segment, obtains the original data packet to be processed, verifies the digital signature of the transaction request of the token segment using a public key, and obtains a data packet with a verified signature; The smart contract collects encrypted permission token shards from participant nodes to obtain a shard set that meets the threshold requirement, reconstructs the noise key using Shamir secret sharing algorithm, decrypts to obtain a plaintext permission token, and verifies the plaintext permission token using a multi-dimensional joint verification method to obtain a verified plaintext permission token content; According to the verified token content, an authorization record is generated.
7. The government data dynamic authorization management method based on secure multi-party computation according to claim 6, characterized in that: According to the authorization record, the access control policy of the edge computing node is configured, and the encrypted query of the data requester is responded using the oblivious transfer protocol, including the following steps, The edge node obtains the authorization record from the blockchain, extracts the allowed operation list, the prohibited operation list and the effective condition in the permission declaration field to obtain a structured policy object; The structured policy object is converted into a policy language file of the Linux security enhancement module, a binary policy file of the type forced rule and access vector is generated, a policy module is obtained, the policy module is loaded into the Linux security module through a secure loading interface to obtain a policy activation status code, the encrypted query data submitted by the requester is decrypted using a symmetric key to obtain a plaintext query statement, the operation field in the query statement is compared with the allowed operation list in the policy object to obtain a security filtered query syntax tree, and a target data index value is extracted from the security filtered query syntax tree; The requester calculates the blind request parameter using the blind algorithm of the elliptic curve based on the target data index value, the elliptic curve generator and the random number to obtain an oblivious transfer protocol request packet; The edge node uses its own private key to hash all data items, generates a corresponding response data set, and the requester uses the pre-shared elliptic curve parameters and its own selected bit information to extract and decrypt the target data item from the response packet to obtain the plaintext query result.
8. The government data dynamic authorization management method based on secure multi-party computation according to claim 7, characterized in that: The audit node monitors the access log of the data requester, dynamically adjusts the attribute weight parameter through the secure multi-party computation protocol, and synchronizes to the anti-quantum dynamic attribute-based encryption key fragment, The method comprises the following steps, The audit node receives the encrypted access log stream of the edge computing node through the TLS1.3 protocol, obtains the encrypted log block with timestamp, hashes the Merkle tree root of the encrypted log block, and compares it with the block chain evidence, and outputs the standardized log data verified; Each audit node aggregates log feature values through a secure multi-party protocol to obtain encrypted statistical results; Based on the statistical results, identify abnormal access behaviors exceeding the 3σ range to obtain risk event reports, and obtain the weight adjustment gradient through the MPC protocol according to the risk report; Use the weight adjustment gradient to dynamically adjust the attribute correlation matrix to obtain the adjusted matrix parameter set, generate new key fragments based on the adjusted matrix parameter set through threshold secret sharing, hash the Merkle root of the new key fragments into the smart contract to obtain the strategy update transaction receipt. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is characterized in that: The processor executes the computer program to realize the steps of the government data dynamic authorization management method based on secure multi-party computation in any one of claims 1-8.
10. A computer readable storage medium having stored thereon a computer program, characterized in that: The computer program is executed by the processor to realize the steps of the government data dynamic authorization management method based on secure multi-party computation in any one of claims 1-8.
Citation Information
Patent Citations
Improved attribute-based encryption scheme system and encryption algorithm thereof
CN114117475A
Cross-domain multi-authority collaborative attribute-based encryption access control method
CN117614618A
Safety monitoring method and system for financial information service platform
CN120372642A
Privacy protection method and system based on homomorphic encryption and block chain
CN120541863A
Attribute-based encryption method and system
WO2023109056A1
Cited By
Knowledge vector library-oriented secure storage and efficient query method
CN121412361A
Edge computing collaborative terminal equipment security access and data encryption transmission system
CN122179189A
Method for extracting and parsing bitcoin transaction autonomy information
US12626253B2
Method for extracting and parsing bitcoin transaction autonomy information
US20250037124A1