A collaborative decryption attribute encryption method suitable for a file sharing scenario

CN122839401APending Publication Date: 2026-09-29XINGTANG TELECOMM TECH CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510381284.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0003]然而,现有属性密码算法和方案仍然面临着海量属性规模下的效率不足、用户动态加入管理不灵活等典型应用问题,尚不足以满足数据安全共享场景下的应用需求和安全需求

Benefits of technology

[0051]与现有技术相比,本发明至少可实现如下有益效果之一:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122839401A_ABST
    Figure CN122839401A_ABST
Patent Text Reader

Abstract

The application relates to a collaborative decryption attribute encryption method and system suitable for a file sharing scene and relates to the technical field of information security, and solves the technical problem of how to design an attribute encryption scheme suitable for a one-to-many file publishing and sharing scene. The method comprises the following steps: an attribute authorization agency generates system parameters and generates a user private key according to the system parameters and multiple attributes of a user; a data owner performs monotone span program encoding on an access strategy and generates attribute ciphertext encapsulating a symmetric key according to an encoding result and the master public key; a data user performs monotone span program decoding on the encoding result of the data owner and generates collaborative request data according to a decoding result and the attribute ciphertext; an attribute collaborative manager generates collaborative decryption data according to the collaborative request data; and the data user recovers the symmetric key according to the collaborative decryption data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a collaborative decryption attribute encryption method suitable for file sharing scenarios. Background Technology

[0002] Attribute-based access control (ABE) is a method for implementing fine-grained access control of data in information systems. Due to its efficiency, dynamism, flexibility, and privacy, it has demonstrated broad application potential in database and cloud storage applications. This technology uses attribute cryptography to encrypt data, and by embedding access control policies into the ciphertext or key, it can effectively achieve flexible access control of specified data by a designated subject. Sahai and Waters first proposed a fuzzy identity-based encryption scheme in 2005, a milestone in attribute cryptography. This scheme, by introducing the concept of attributes, formed an attribute-based encryption system (ABE). Subsequently, Sahai and Waters et al. extended ABE, proposing key-policy ABE (KP-ABE) and ciphertext-policy ABE (CP-ABE), respectively.

[0003] However, existing attribute cryptography algorithms and schemes still face typical application problems such as insufficient efficiency under massive attribute scale and inflexible management of dynamic user addition, and are not yet sufficient to meet the application and security requirements in data security sharing scenarios.

[0004] In one-to-many file publishing and sharing scenarios (similar to NAS), the file publishing process has low performance requirements; however, the file decryption stage may involve multiple users concurrently requesting decryption, requiring a certain response time for users to the decrypted data. Under high concurrency, the performance requirements for collaborative administrators are high. Designing an attribute-based password scheme suitable for one-to-many file publishing and sharing scenarios is a pressing technical problem that needs to be solved. Summary of the Invention

[0005] Based on the above analysis, the embodiments of the present invention aim to provide a collaborative decryption attribute encryption method suitable for file sharing scenarios, in order to solve the technical problem of how to design an attribute password scheme that is suitable for one-to-many file publishing and sharing scenarios.

[0006] In a first aspect, embodiments of the present invention provide a collaborative decryption attribute encryption method suitable for file sharing scenarios, comprising the following steps:

[0007] The attribute authorization authority generates system parameters and generates a user private key based on the system parameters and multiple user attributes. The system parameters include a master public key, a master private key, and a collaboration key. The master public key contains parameters that encapsulate the collaboration key.

[0008] The data owner performs monotonically stretched programming to encode the access policy and generates attribute ciphertext encapsulating the symmetric key based on the encoding result and the master public key;

[0009] The data user performs a monotonic tensor program to decode the data owner's encoding result, and generates collaborative request data based on the decoding result and the attribute ciphertext.

[0010] The attribute collaboration manager generates collaboration decryption data based on the collaboration request data;

[0011] The data user recovers the symmetric key based on the collaboratively decrypted data.

[0012] Based on a further improvement of the above method, the attribute authorization agency generates system parameters including:

[0013] The attribute authorization authority generates a plurality of first random numbers in the prime number domain, wherein the plurality of first random numbers includes the collaborative key;

[0014] The attribute authorization agency generates multiple first parameters based on the generator of the bilinear pair and the multiple first random numbers, wherein the multiple first parameters include a first parameter that encapsulates the collaborative key and is generated through bilinear pair mapping;

[0015] The attribute authorization authority generates the master public key and the master private key based on the plurality of first random numbers and the plurality of first parameters.

[0016] A further improvement to the above method involves the attribute authorization authority generating a user private key based on the system parameters and multiple user attributes, including:

[0017] The attribute authorization agency generates multiple second random numbers within the prime number domain;

[0018] The attribute authorization authority uses a hash-to-curve algorithm to generate a first component of the user's private key based on the master private key and the plurality of second random numbers;

[0019] The attribute authorization authority uses a hash-to-curve algorithm to generate a second component of the user's private key corresponding to the user's attributes based on the plurality of second random numbers and the user's plurality of attributes;

[0020] The attribute authorization authority concatenates the first component and the second component of the user's private key to form the user's private key.

[0021] Based on a further improvement of the above method, the data owner generates attribute ciphertext encapsulating the symmetric key according to the encoding result and the master public key, including:

[0022] The data owner generates multiple third random numbers within the prime number domain;

[0023] The data owner generates the first component of the attribute ciphertext based on the master public key and the plurality of third random numbers;

[0024] The data owner generates ciphertext for the corresponding row of the tensor matrix based on the multiple third random numbers, the encoded tensor matrix, and the corresponding attribute set. The ciphertext for the corresponding row of the tensor matrix is ​​the second component of the attribute ciphertext. The first and second components of the attribute ciphertext together encapsulate the symmetric key.

[0025] Based on further improvements to the above method, data users can generate collaborative request data according to the decoding results, including:

[0026] Data users generate target parameters for collaborative request data based on the decoding results and the second component of the attribute ciphertext.

[0027] Based on a further improvement of the above method, the attribute collaboration manager generates collaboration decryption data according to the collaboration request data, including:

[0028] The attribute collaboration manager generates collaborative decryption data based on the target parameters of the collaboration request data and the collaboration key.

[0029] Based on a further improvement of the above method, the data user recovers the symmetric key from the collaborative decryption data, including:

[0030] The data user generates a second parameter based on the decoding result and its attribute set;

[0031] The data user calculates the target symmetric key based on the second parameter, the user's private key, the first component of the attribute ciphertext, and the collaborative decryption data.

[0032] Based on a further improvement to the above method, the data user calculates the target symmetric key according to the second parameter, the user's private key, the first component of the attribute ciphertext, and the collaborative decryption data, including:

[0033] The data user calculates the target symmetric key K' using the following formula:

[0034]

[0035] Where e() is a bilinear mapping, t1, t2, t3 are the second parameters, COr1, COr2, COr3 are the collaborative decryption data, x1, x2, x3 are the parameters in the first component of the user's private key, and z1, z2, z3 are the first component of the attribute ciphertext.

[0036] Secondly, embodiments of the present invention also provide a collaborative decryption attribute encryption system suitable for file sharing scenarios, including an attribute authorization authority, a data owner, a data user, and an attribute collaboration manager, wherein...

[0037] The attribute authorization authority is configured to execute:

[0038] Generate system parameters and generate a user private key based on the system parameters and multiple user attributes, wherein the system parameters include a master public key, a master private key, and a collaboration key, and the master public key contains parameters encapsulating the collaboration key;

[0039] The data owner is configured to execute:

[0040] The access policy is monotonically stretched and encoded, and attribute ciphertext encapsulating the symmetric key is generated based on the encoding result and the master public key.

[0041] The data user is configured to execute:

[0042] The data user performs a monotonic tensor program to decode the data owner's encoding result, and generates collaborative request data based on the decoding result and the attribute ciphertext.

[0043] The attribute collaboration manager is configured to execute:

[0044] Generate collaborative decryption data based on the collaborative request data.

[0045] The data user is also configured to perform:

[0046] The data user recovers the symmetric key based on the collaboratively decrypted data.

[0047] Based on further improvements to the above system, the attribute authorization authority is configured to perform:

[0048] Generate a plurality of first random numbers in the prime number field, wherein the plurality of first random numbers includes the cooperative key;

[0049] Multiple first parameters are generated based on the generator of the bilinear pair and the multiple first random numbers, wherein the multiple first parameters include a first parameter that encapsulates the collaborative key and is generated by mapping the bilinear pair;

[0050] The master public key and the master private key are generated based on the plurality of first random numbers and the plurality of first parameters.

[0051] Compared with the prior art, the present invention can achieve at least one of the following beneficial effects:

[0052] 1. This invention designs a collaborative attribute encryption scheme based on collaborative manager control. It uses cryptographic means to ensure that the user's decryption process must rely on the collaborative data issued by the attribute collaborative manager, thus ensuring that collaborative management cannot be bypassed.

[0053] 2. In the solution of this invention, during the decryption stage, the collaborative manager does not need complex calculations such as large number modular inverse. The computational load of the collaborative manager is small, which reduces the computational burden of the collaborative manager under high concurrency in the one-to-many file publishing and sharing scenario, thereby improving the decryption efficiency under massive attribute scale.

[0054] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description

[0055] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts.

[0056] Figure 1 A flowchart illustrating a collaborative decryption attribute encryption method suitable for file-sharing scenarios according to an embodiment of the present invention is shown. Detailed Implementation

[0057] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.

[0058] Figure 1 A flowchart illustrating a collaborative decryption attribute encryption method suitable for file-sharing scenarios according to an embodiment of the present invention is shown.

[0059] The following is combined with Figure 1 An embodiment of the present invention will be described.

[0060] like Figure 1 As shown, this collaborative decryption attribute encryption method suitable for file-sharing scenarios includes:

[0061] Step 101: The attribute authorization authority generates system parameters and generates a user private key based on the system parameters and multiple user attributes.

[0062] In this embodiment, the attribute authorization authority can be a trusted center, which can output system parameters according to the initialization algorithm. The system parameters include a collaboration key, a master public key, and a master private key. The attribute authorization authority can send the collaboration key and the master public key to the collaboration administrator and the data owner, respectively, to perform relevant encryption operations.

[0063] In some embodiments, the initialization algorithm includes performing the following steps:

[0064] Step S100: Generate multiple first random numbers in the prime number field, wherein the multiple first random numbers include the collaborative key.

[0065] Step S200: Generate multiple first parameters based on the generator of the bilinear pair and multiple first random numbers, wherein the multiple first parameters include the first parameter that encapsulates the collaborative key and is generated through the bilinear pair mapping.

[0066] Step S300: Generate the master public key and master private key based on multiple first random numbers and multiple first parameters.

[0067] Steps S100-S300 will be described below with reference to a specific implementation method.

[0068] In step S100, the following random numbers can be randomly generated in the prime number field p:

[0069] r, a1, a2, b1, b2, d1, d2, d3, Co

[0070] Where co is the collaboration key.

[0071] In step S200, g1 and g2 can be selected as two generators of a bilinear pair, and the following calculation can be performed:

[0072]

[0073] Where e() is a bilinear mapping. The parameters g, H1, H2, C1, C2, C3, T1, T2, T3, and T4 obtained through the above calculations are the first parameters in this embodiment, where T3 and T4 encapsulate the collaborative key co. As can be seen from the above calculation formula, the first parameter C3 used to calculate T3 and T4 contains information about the collaborative key co; therefore, T3 and T4 encapsulate the collaborative key co.

[0074] In step S300, the master public key and master private key can be obtained in the following way:

[0075] Master public key: mpk = (H1, H2, C1, C2, C3, T1, T2, T3, T4)

[0076] Master private key: msk = (g, a1, a2, b1, b2, d1, d2, d3)

[0077] For example, the master public key can be formed by concatenating the parameters H1, H2, C1, C2, C3, T1, T2, T3, T4; the master private key can be formed by concatenating the parameters g, a1, a2, b1, b2, d1, d2, d3.

[0078] After obtaining the collaboration key and master public key through steps S100-S300, the attribute authorization agency can send the collaboration key to the collaboration administrator and the master public key to the data owner.

[0079] In this embodiment, the attribute authorization authority can generate a private key for each user using a user private key generation algorithm. This algorithm can take system parameters and multiple user attributes as input to generate a private key for each user.

[0080] In some embodiments, the key generation algorithm includes the following steps:

[0081] Step S101: Generate multiple second random numbers within the prime number field.

[0082] Step S102: Use the hash-to-curve algorithm to generate the first component of the user's private key based on the master private key and multiple second random numbers.

[0083] Step S103: Using the hash-to-curve algorithm, generate a second component of the user's private key corresponding to the user's attributes based on multiple second random numbers and multiple user attributes.

[0084] Step S104: Concatenate the first component of the user's private key and the second component of the user's private key to form the user's private key.

[0085] Steps S101-S104 will be described below with reference to a specific implementation method.

[0086] In step S101, the following random numbers can be randomly generated in the prime number field p:

[0087] r1, r2, σ

[0088] Where r1, r2, and σ are the second random numbers in this embodiment.

[0089] In step S102, the master private key and a second random number can be used as inputs, and the following parameters can be calculated using a hash-to-curve algorithm:

[0090]

[0091] In this context, a1, a2, b1, b2, and d3 are parameters in the primary private key. It is a function that hashes data m to points on an elliptic curve, i.e., a hash-to-curve algorithm, where different values ​​of l and k represent different paddings for data m. The parameters x1, x2, x3, y1, y2, and y3 obtained through the above calculations can be used as the first component of the user's private key.

[0092] In step S103, the second component of the user's private key can be calculated using the master private key and multiple user attributes as input, in the following manner:

[0093] Suppose a user has t attributes, each attribute s i ∈U, i∈[1,t],

[0094] 1. The attribute authorization agency generates multiple random numbers σ within the prime number domain. i .

[0095] 2. Attribute authorization agency calculation:

[0096]

[0097] Where a1, a2, b1, and b2 are parameters in the primary private key. It is a function that hashes data m to points on an elliptic curve, i.e., a hash-to-curve algorithm, where different values ​​of l and k represent different fills for data m.

[0098] 3. SK i =(sk i,1 ,sk i,2 ,sk i,3 ) represents the corresponding attribute s i The user key component, which is the second component of the user private key in this embodiment.

[0099] In step S104, the user's private key sk can be obtained in the following way:

[0100] sk=(x1,x2,x3,y1,y2,y3,sk1,…,sk t )

[0101] Step 102: The data owner performs monotonically stretched programming on the access policy and generates attribute ciphertext encapsulating the symmetric key based on the encoding result and the master public key.

[0102] An access policy is a set of rules or regulations used to define which users can access specific resources under what conditions. It is usually based on a user's identity, role, permissions, or other attributes to determine access permissions, hence it is also called an attribute policy.

[0103] A monotone span program (MSP) is a mathematical tool for computing monotone Boolean functions, with important applications in cryptography and access control. Proposed by Karchmer and Wigderson, it was used to construct linear secret sharing schemes (LSSS). A monotone span program represents a monotone Boolean function through a series of linear combinations and spanning operations; that is, a Boolean function consisting only of AND and OR logic gates, excluding NOT gates. In access control, monotone span programs can be used to describe the access structure, i.e., which user sets are authorized and which are unauthorized. By converting the access structure into a monotone span program, the corresponding linear secret sharing scheme can be further constructed, enabling the secure sharing and recovery of secret information.

[0104] The spanning matrix is ​​a matrix whose row vectors correspond to linear combinations in a monotonically spanning procedure, and whose columns correspond to input variables. In a monotonically spanning procedure, each authorized user set can span the target vector by linearly combining these row vectors, thereby recovering the secret. The construction of the spanning matrix must satisfy certain conditions to ensure that only the authorized user set can successfully recover the secret.

[0105] In this embodiment, the data owner can generate attribute ciphertext encapsulating the symmetric key using an attribute encryption algorithm. This attribute encryption algorithm can take the master public key and access policy as input to generate attribute ciphertext encapsulating the symmetric key.

[0106] In some embodiments, the attribute encryption algorithm includes the following steps:

[0107] Step S201: Generate multiple third random numbers within the prime number field.

[0108] Step S202: Generate the first component of the attribute ciphertext based on the master public key and multiple third random numbers.

[0109] Step S203: Based on multiple third random numbers, the encoded tensor matrix, and the corresponding attribute set, generate the ciphertext of the corresponding row of the tensor matrix, where the ciphertext of the corresponding row of the tensor matrix is ​​the second component of the attribute ciphertext, and the first and second components of the attribute ciphertext jointly encapsulate the symmetric key.

[0110] Steps S201-S203 will be described below with reference to a specific implementation method.

[0111] In step S201, the following random numbers can be randomly generated in the prime number field p:

[0112] u1, u2

[0113] Where u1 and u2 are the third random numbers in this embodiment.

[0114] In step S202, the first component of the attribute ciphertext can be calculated using the master public key and a third random number as inputs in the following manner:

[0115] f = hash(file_id)

[0116]

[0117] Here, hash() is the hash function, file_id is the identifier of the file to be encrypted, and z1, z2, and z3 are the first components of the attribute ciphertext.

[0118] In step S203, the second component of the attribute ciphertext can be calculated using the third random number, the encoded tensor matrix, and the corresponding attribute set as inputs, in the following manner:

[0119] Suppose that the access strategy is coded using a monotonically tensing program, and the resulting tensing matrix and corresponding attribute set are M respectively. p And label. Let the spanning matrix M be... p There are n rows and m columns, and each attribute in the attribute set label is label[i]. Perform the following calculation for row i∈[1,n]:

[0120]

[0121] The ciphertext c of the corresponding line i =(c i,1 c i,2 c i,3 ), which is the second component of the attribute ciphertext.

[0122] In this embodiment, the first component and the second component of the attribute ciphertext can be concatenated together to form the attribute ciphertext:

[0123] C p =(z1,z2,z3,c1,...,c n )

[0124] In this embodiment, the data owner can transmit the generated attribute ciphertext c p Send to data users.

[0125] In this embodiment, the data owner can calculate the symmetric key K in the following way:

[0126]

[0127] As can be seen from the above calculation process, the parameters used to calculate the symmetric key K are u1, u2, and f, and these parameter information has been encapsulated in the attribute ciphertext.

[0128] Step 103: The data user performs monotonic tensor decoding on the data owner's encoding result and generates collaborative request data based on the decoding result and the attribute ciphertext.

[0129] In this embodiment, the data user can use a monotonic tensing procedure to tense the matrix M. p The corresponding attribute set label and user attribute set s i Decoding ∈U, i∈[1,t] yields the set I,d I Where set I is M p The set of bank numbers represents the rows that conform to the access strategy; set d I These are the integer coefficients corresponding to set I, used for polynomial calculations.

[0130] Next, data users can use sets I, d I The parameters of the collaborative request data are calculated using the second component of the attribute ciphertext in the following manner:

[0131]

[0132] Where v1, v2, and v3 are the target parameters for collaborative request data.

[0133] Afterwards, data users can submit collaborative request data C. q =(user id file id (v1, v2, v3) are sent to the attribute collaboration manager. In this collaboration request data, user... id For the identity information of data users, file id An identifier for the data requested by the data user.

[0134] Step 104: The attribute collaboration manager generates collaboration decryption data based on the collaboration request data.

[0135] In this embodiment, the attribute collaboration manager can generate collaborative decryption data through the attribute collaboration decryption algorithm.

[0136] In some embodiments, the attribute-based collaborative decryption algorithm may generate collaborative decryption data based on the target parameters and collaborative key of the collaborative request data.

[0137] The attribute collaborative decryption algorithm will be explained below with reference to a specific implementation method.

[0138] Attribute collaboration manager based on user id file id After verifying the user's identity and permissions, the collaboratively decrypted data can be calculated in the following ways:

[0139] f = hash(file) id )

[0140]

[0141] Afterwards, the attribute collaboration manager can collaboratively decrypt data C rsp =(Cor1, COr2, COr3) is sent to the data user. In this embodiment, the collaboration manager only needs to perform simple exponentiation operations without performing complex operations such as modular inversion, resulting in a relatively small computational load. For one-to-many file sharing scenarios, the collaboration manager needs to handle a large number of collaborative decryption requests simultaneously, thus resulting in a large computational load. However, in this solution, the computational load of a single decryption operation by the collaboration manager is relatively small, so even with a large number of collaborative decryption requests, it can still meet business needs.

[0142] Step 105: The data user recovers the symmetric key based on the collaboratively decrypted data.

[0143] In some embodiments, step 105 may include the following steps:

[0144] Step S501: The data user generates the second parameter based on the decoding result and its attribute set.

[0145] Step S502: The data user calculates the target symmetric key based on the second parameter, the user private key, the first component of the attribute ciphertext, and the collaborative decryption data.

[0146] Steps S501-S502 will be described below with reference to a specific implementation method.

[0147] In step S501, the data user obtains set I, d I Then, the following calculations can be performed:

[0148]

[0149] Wherein, t1, t2, and t3 are the second parameters in this embodiment.

[0150] In step S502, the data user can calculate the target symmetric key K' as follows:

[0151]

[0152] Calculations show that the target symmetric key K' obtained by the data user is equal to the symmetric key K of the data owner. The data user can use the target symmetric key K' to decrypt the data encrypted by the data owner using the symmetric key K.

[0153] This invention also provides a collaborative decryption attribute encryption system suitable for file-sharing scenarios, including an attribute authorization agency, a data owner, a data user, and an attribute collaboration manager. The attribute authorization agency is configured to: generate system parameters and generate a user private key based on the system parameters and multiple user attributes. The system parameters include a master public key, a master private key, and a collaboration key, with the master public key containing parameters encapsulating the collaboration key. The data owner is configured to: perform monotonically tensor encoding on an access policy and generate attribute ciphertext encapsulating a symmetric key based on the encoding result and the master public key. The data user is configured to: perform monotonically tensor decoding on the data owner's encoding result and generate collaboration request data based on the decoding result and the attribute ciphertext. The attribute collaboration manager is configured to: generate collaborative decryption data based on the collaboration request data. The data user is further configured to: recover the symmetric key based on the collaborative decryption data.

[0154] Since the various units of the collaborative decryption attribute encryption system in the embodiments of the present invention have been described above in conjunction with the method embodiments, they will not be repeated here.

[0155] Compared with the prior art, the embodiments of the present invention can achieve at least one of the following beneficial effects:

[0156] 1. This invention designs a collaborative attribute encryption scheme based on collaborative manager control. It uses cryptographic means to ensure that the user's decryption process must rely on the collaborative data issued by the attribute collaborative manager, thus ensuring that collaborative management cannot be bypassed.

[0157] 2. In the solution of this invention, during the decryption stage, the collaborative manager does not need complex calculations such as large number modular inverse. The computational load of the collaborative manager is small, which reduces the computational burden of the collaborative manager under high concurrency in the one-to-many file publishing and sharing scenario, thereby improving the decryption efficiency under massive attribute scale.

[0158] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.

Claims

1. A collaborative decryption attribute encryption method suitable for file sharing scenarios, characterized in that, Includes the following steps: The attribute authorization authority generates system parameters and generates a user private key based on the system parameters and multiple user attributes. The system parameters include a master public key, a master private key, and a collaboration key. The master public key contains parameters that encapsulate the collaboration key. The data owner performs monotonically stretched programming to encode the access policy and generates attribute ciphertext encapsulating the symmetric key based on the encoding result and the master public key; The data user performs a monotonic tensor program to decode the data owner's encoding result, and generates collaborative request data based on the decoding result and the attribute ciphertext. The attribute collaboration manager generates collaboration decryption data based on the collaboration request data; The data user recovers the symmetric key based on the collaboratively decrypted data.

2. The method according to claim 1, characterized in that, The attribute authorization agency generates system parameters including: The attribute authorization authority generates a plurality of first random numbers in the prime number domain, wherein the plurality of first random numbers includes the collaborative key; The attribute authorization agency generates multiple first parameters based on the generator of the bilinear pair and the multiple first random numbers, wherein the multiple first parameters include a first parameter that encapsulates the collaborative key and is generated through bilinear pair mapping; The attribute authorization authority generates the master public key and the master private key based on the plurality of first random numbers and the plurality of first parameters.

3. The method according to claim 1, characterized in that, The attribute authorization authority generates a user private key based on the system parameters and multiple user attributes, including: The attribute authorization agency generates multiple second random numbers within the prime number domain; The attribute authorization authority uses a hash-to-curve algorithm to generate a first component of the user's private key based on the master private key and the plurality of second random numbers; The attribute authorization authority uses a hash-to-curve algorithm to generate a second component of the user's private key corresponding to the user's attributes based on the plurality of second random numbers and the user's plurality of attributes; The attribute authorization authority concatenates the first component and the second component of the user's private key to form the user's private key.

4. The method according to claim 1, characterized in that, The data owner generates attribute ciphertext encapsulating the symmetric key based on the encoding result and the master public key, including: The data owner generates multiple third random numbers within the prime number domain; The data owner generates the first component of the attribute ciphertext based on the master public key and the plurality of third random numbers; The data owner generates ciphertext for the corresponding row of the tensor matrix based on the plurality of third random numbers, the tensor matrix generated by encoding, and the corresponding attribute set. The ciphertext for the corresponding row of the tensor matrix is ​​the second component of the attribute ciphertext. The first and second components of the attribute ciphertext together encapsulate the symmetric key.

5. The method according to claim 4, characterized in that, Data users generate collaborative request data based on the decoding results, including: Data users generate target parameters for collaborative request data based on the decoding results and the second component of the attribute ciphertext.

6. The method according to claim 1, characterized in that, The attribute collaboration manager generates collaborative decryption data based on the collaboration request data, including: The attribute collaboration manager generates collaborative decryption data based on the target parameters of the collaboration request data and the collaboration key.

7. The method according to claim 1, characterized in that, Data users recover the symmetric key based on the collaboratively decrypted data, including: The data user generates a second parameter based on the decoding result and its attribute set; The data user calculates the target symmetric key based on the second parameter, the user's private key, the first component of the attribute ciphertext, and the collaborative decryption data.

8. The method according to claim 7, characterized in that, The data user calculates the target symmetric key based on the second parameter, the user's private key, the first component of the attribute ciphertext, and the collaborative decryption data, including: The data user calculates the target symmetric key K' using the following formula: Where e() is a bilinear mapping, t1, t2, and t3 are the second parameters, COr1, COr2, and COr3 are the collaborative decryption data, x1, x2, and x3 are the parameters in the first component of the user's private key, and z1, z2, and z3 are the first components of the attribute ciphertext.

9. A collaborative decryption attribute encryption system suitable for file sharing scenarios, characterized in that, This includes attribute authorization agencies, data owners, data users, and attribute collaboration managers, among whom... The attribute authorization authority is configured to execute: Generate system parameters and generate a user private key based on the system parameters and multiple user attributes, wherein the system parameters include a master public key, a master private key, and a collaboration key, and the master public key contains parameters encapsulating the collaboration key; The data owner is configured to execute: The access policy is monotonically stretched and encoded, and attribute ciphertext encapsulating the symmetric key is generated based on the encoding result and the master public key. The data user is configured to execute: The data user performs a monotonic tensor program to decode the data owner's encoding result, and generates collaborative request data based on the decoding result and the attribute ciphertext. The attribute collaboration manager is configured to execute: Generate collaborative decryption data based on the collaborative request data. The data user is also configured to perform: The data user recovers the symmetric key based on the collaboratively decrypted data.

10. The system according to claim 9, characterized in that, The attribute authorization authority is configured to execute: Generate a plurality of first random numbers in the prime number field, wherein the plurality of first random numbers includes the cooperative key; Multiple first parameters are generated based on the generator of the bilinear pair and the multiple first random numbers, wherein the multiple first parameters include a first parameter that encapsulates the collaborative key and is generated by mapping the bilinear pair; The master public key and the master private key are generated based on the plurality of first random numbers and the plurality of first parameters.