Data sharing method, device, computer equipment and storage medium
By using the private key in a distributed storage system to generate customized keys and send them to the target user, the problem of data sharing security in a distributed storage system is solved, and data security and privacy protection are achieved.
Patent Information
- Application Number
- CN202110348542.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-31
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-03-31
AI Technical Summary
In distributed storage systems, the prior art cannot effectively ensure the security of data sharing, especially in a decentralized environment, where decryption keys cannot be distributed to users through a central organization.
By obtaining the user's sharing request, a custom key is generated based on the user's private key and sent it to the target user so that the user can access the required data. This method uses the mechanisms of public key encryption and private key decryption to ensure the security of data during transmission.
It ensures the security of data sharing in a distributed storage system, avoids data leakage and unauthorized access, and enhances data privacy protection.
Smart Images

Figure CN112883002B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cyberspace cryptography, and in particular to a data sharing method, apparatus, computer equipment and storage medium. Background Art
[0002] With the development of cyberspace cryptography, distributed storage systems (such as cloud computing) have been widely studied due to their decentralization, scalability, and high reliability. However, data in distributed storage systems is stored in plain text, so the security and privacy of the data cannot be guaranteed.
[0003] In the related art, data security and privacy are protected by encryption methods, that is, data is encrypted using a key and then the ciphertext is stored on a server. This encryption method requires a central agency to distribute decryption keys to users to achieve data sharing.
[0004] However, directly sending the decryption key to the data accessor may expose the data that the data owner does not want to share, and the decentralized distributed storage system cannot distribute keys to users through a central organization. Therefore, the security of data sharing cannot be ensured in the distributed storage system. Summary of the invention
[0005] Based on this, it is necessary to provide a data sharing method, device, computer equipment and storage medium to address the above technical issues.
[0006] A data sharing method, the method comprising:
[0007] Obtain a sharing request for first data initiated by a first user, where the first data is data in the storage data of the first user, and the storage data is ciphertext data encrypted with the public key of the first user and stored in a distributed storage system; generate a customized key corresponding to the first data according to a private key, where the private key is paired with the public key; and send the customized key to a second user to instruct the second user to access the first data according to the customized key.
[0008] In one embodiment, before obtaining the sharing request for the first data initiated by the first user, the method further includes:
[0009] Obtaining public parameters from the distributed storage system; and generating a public key and a private key corresponding to the first user according to the public parameters.
[0010] In one embodiment, generating a customized key corresponding to the first data according to the private key includes:
[0011] Obtain a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate a range of data to be shared, and the tag set is used to indicate the type of data that is not to be shared; generate a customized key corresponding to the first data according to the sharing identification vector, the tag set, the public parameters and the private key, wherein the first data is determined from the stored data according to the sharing identification vector and the tag set.
[0012] In one embodiment, generating a customized key corresponding to the first data according to the shared identification vector, the tag set, the public parameter and the private key includes:
[0013] An intermediate private key is generated according to the shared identification vector, the private key and the public parameter; and a customized key is generated according to the tag set, the intermediate private key and the public parameter.
[0014] In one embodiment, generating a customized key according to the tag set, the intermediate private key and the public parameter includes:
[0015] The intermediate private key and the public parameter are respectively used to generate corresponding label customized keys for each label. The number of times the label customized keys are generated is the same as the number of labels in the label set. Each label customized key includes a newly added label unit, and the newly added label unit includes three newly added private key units of the corresponding labels. A customized key is generated based on multiple label customized keys, and the number of the label customized keys is the same as the number of labels in the label set.
[0016] In one embodiment, after sending the customized key to the second user to instruct the second user to access the first data according to the customized key, the method further includes:
[0017] Obtain a sharing request for second data initiated by a first user, where the second data is data within the first data; generate a new customized key corresponding to the second data according to the customized private key; and send the new customized key to a third user to instruct the third user to access the second data according to the new customized key.
[0018] In one implementation, generating a new customized key corresponding to the second data according to the customized private key includes:
[0019] Obtain a newly added sharing identifier; and generate a new customized key according to the newly added sharing identifier, the customized private key, and the public parameters.
[0020] A data sharing device, comprising:
[0021] A first acquisition module is used to acquire a sharing request for first data initiated by a first user, where the first data is data in the storage data of the first user, and the storage data is ciphertext data encrypted with the public key of the first user and stored in the distributed storage system;
[0022] A first generating module, configured to generate a customized key corresponding to the first data according to a private key, the private key being paired with the public key;
[0023] The first sending module is used to send the customized key to the second user to instruct the second user to access the first data according to the customized key.
[0024] In one embodiment, the device further comprises:
[0025] A second acquisition module is used to obtain public parameters from a distributed storage system;
[0026] The second generating module generates a public key and a private key corresponding to the first user according to the public parameter.
[0027] In one embodiment, the first generating module is further used for:
[0028] Obtain a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate a range of data to be shared, and the tag set is used to indicate the type of data that is not to be shared; generate a customized key corresponding to the first data according to the sharing identification vector, the tag set, the public parameters and the private key, wherein the first data is determined from the stored data according to the sharing identification vector and the tag set.
[0029] In one embodiment, the first generating module is further used for:
[0030] An intermediate private key is generated according to the shared identification vector, the private key and the public parameter; and a customized key is generated according to the tag set, the intermediate private key and the public parameter.
[0031] In one embodiment, the first generating module is further used for:
[0032] The intermediate private key and the public parameter are respectively used to generate corresponding label customized keys for each label. The number of times the label customized keys are generated is the same as the number of labels in the label set. Each label customized key includes a newly added label unit, and the newly added label unit includes three newly added private key units of the corresponding labels. A customized key is generated based on multiple label customized keys, and the number of the label customized keys is the same as the number of labels in the label set.
[0033] In one embodiment, the device further comprises:
[0034] A third acquisition module is used to acquire a sharing request for second data initiated by the first user, where the second data is data within the first data;
[0035] A third generating module, used to generate a new customized key corresponding to the second data according to the customized private key;
[0036] The second sending module is used to send the new customized key to a third user to instruct the third user to access the second data according to the new customized key.
[0037] In one embodiment, the third generation module is used to:
[0038] Obtain a newly added sharing identifier; and generate a new customized key according to the newly added sharing identifier, the customized private key, and the public parameters.
[0039] A computer device comprises a memory and a processor, wherein the memory stores a computer program and the processor implements any of the above-mentioned data sharing methods when executing the program.
[0040] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements any of the above-mentioned data sharing methods.
[0041] The above-mentioned data sharing method, device, computer equipment and storage medium first obtain a sharing request for first data initiated by a first user, where the first data is data in the storage data of the first user, and the storage data is ciphertext data encrypted with the public key of the first user and stored in a distributed storage system; then a customized key corresponding to the first data is generated according to a private key, and the private key is paired with the public key; finally, the customized key is sent to a second user to instruct the second user to access the first data according to the customized key. Therefore, the security of data sharing can be ensured in a distributed storage system through a data sharing method. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 A schematic diagram of a data sharing method in one embodiment;
[0043] Figure 2 A schematic diagram of a process for obtaining a public key and a private key in a data sharing method in an embodiment;
[0044] Figure 3 is an application flow chart of a data sharing method in one embodiment;
[0045] Figure 4 A schematic diagram of a process for generating a customized key in one embodiment;
[0046] Figure 5 A schematic diagram of a flow chart of a step of generating a customized key in another embodiment;
[0047] Figure 6 A schematic diagram of a flow chart of a step of generating a customized key in another embodiment;
[0048] Figure 7is a flow chart of a data sharing method in another embodiment;
[0049] Figure 8 A schematic diagram of a flow chart of a step of generating a new customized key in another embodiment;
[0050] Fig. 9 is a structural block diagram of a data sharing device in one embodiment;
[0051] Fig.10 is a structural block diagram of a data sharing device in another embodiment;
[0052] Fig.11 is a structural block diagram of a data sharing device in another embodiment;
[0053] Fig.12 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0054] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0055] In one embodiment, Figure 1 As shown, a data sharing method is provided, comprising the following steps:
[0056] Step 102, obtaining a sharing request for first data initiated by a first user, where the first data is data in the storage data of the first user, and the storage data is ciphertext data encrypted with the public key of the first user and stored in a distributed storage system.
[0057] Among them, the first user is the data owner, the public key is the non-secret half of the key pair used with the private key algorithm. The public key is usually used to encrypt session keys, verify digital signatures, or encrypt data that can be decrypted by the corresponding private key. The public key and private key are a key pair obtained through the algorithm. The public key can be disclosed to the outside world, while the private key is retained by oneself.
[0058] Specifically, when a first user needs to share first data in the storage data encrypted by a public key in the distributed storage system, a sharing request for the first data initiated by the first user is obtained.
[0059] Step 104: Generate a customized key corresponding to the first data according to the private key, where the private key is paired with the public key.
[0060] The private key is the cryptographic half of a key pair used with a public key algorithm, and data encrypted with the public key can only be decrypted by the corresponding private key. The custom key is a key that can decrypt the first data.
[0061] Specifically, a customized key corresponding to the first data is generated according to a private key paired with a public key, and the public key is used to encrypt the data to obtain ciphertext data.
[0062] Step 106: Send the customized key to the second user to instruct the second user to access the first data according to the customized key.
[0063] The second user is a data user, and the second user is a user who shares the first data with the first user.
[0064] Specifically, the first user sends a customized key to the second user to instruct the second user to access the first data using the customized key and share the first data with the first user.
[0065] In the above data sharing method, firstly, a sharing request for first data initiated by a first user is obtained, where the first data is data in the storage data of the first user, and the storage data is ciphertext data encrypted with the public key of the first user and stored in the distributed storage system; then a customized key corresponding to the first data is generated according to a private key, and the private key is paired with the public key; finally, the customized key is sent to a second user to instruct the second user to access the first data according to the customized key. Therefore, the security of data sharing can be ensured in a distributed storage system through the data sharing method.
[0066] In one embodiment, Figure 2 As shown, before obtaining the sharing request for the first data initiated by the first user, the method further includes the following steps:
[0067] Step 202: Obtain public parameters from the distributed storage system.
[0068] Among them, the public parameter is shared by both parties of the data. The public parameter is a distributed storage system public parameter PP (Public Parameter) obtained by inputting the security parameter λ, the maximum number of tags n associated with the ciphertext, and the maximum depth l of the identity vector according to the initialization algorithm. This security parameter is used to measure the security strength of an algorithm. Generally speaking, the larger the data, the more secure it is. For example, the encryption algorithm strength on the elliptic curve is generally 160 bits, which means that the length of an element is 160 bits; the maximum number of tags indicates the maximum number of tags that can be associated with a ciphertext; the identity vector indicates the maximum number of elements that an identity vector can contain. In the process of obtaining the public parameters, bilinear pairings are applied. The bilinear pairing is defined as a function mapping that maps elements in group G to group G. TIt is expressed as e:G×G→G T ; For a large prime number (i.e., a large prime number) p, the bilinear pairing satisfies the following properties: bilinear property, i.e., for g, h∈G, for a, b∈Z p , there is e(g a ,h b )=e(g,h) ab Established, where Z p represents the set {0, 1, 2, ..., p-1}; non-degenerate, that is, there is at least one element g in the G group such that the calculated e(g,g) is G T A generator of the group; computability, that is, there is an effective algorithm that can effectively calculate the value of e(u,ν) for all u,ν∈G.
[0069] Specifically, a bilinear map e with an order of a large prime number p is selected: G×G→G T , and then select any element g∈G,h,h0,h1,…,h n ∈G,u0,u1,……,u l ∈G, the distributed storage system public parameter PP = (G, G T ,e,p,g,h,h0,h1,…,h n ,u0,u1,……,u l ), where g is the generator of the group G, the others are elements in G, and the labels and identities used are all integer domains Z p The elements in .
[0070] Step 204: Generate a public key and a private key corresponding to the first user according to the public parameters.
[0071] The public key is used to encrypt and generate ciphertext that is stored in the distributed storage system.
[0072] Specifically, according to the first user public-private key generation algorithm, the system public parameter PP is input to generate the public key and private key corresponding to the first user. For example, the first user selects a random element α, r, r′∈Z p and the label t0∈Z p (This tag cannot be used for encryption) and the public key PK (Public Key) is obtained through the public-private key generation algorithm. PK = (g α , t0), private key SK (Secret Key), SK = ({sk 0,1 ,sk 0,2 ,sk 0,3}, sk4, sk5, t0), where:
[0073]
[0074]
[0075]
[0076] In the private key {sk 0,1 ,sk 0,2 ,sk 0,3} is related to the label, while sk4 and sk5 are not related to the label, while sk 0,3 After the public key PK is generated, according to the encryption algorithm, by inputting the public parameter PP, the public key PK, the plain text M (indicating unencrypted data), the tag set S = {t1, ..., t n} (used to indicate the data type that you do not want to share) and the identity vector (used to indicate the data range), obtain the ciphertext CT, that is, first calculate the univariate polynomial Get the polynomial coefficients z0, z1, ..., z n , then select a random element s∈Z p And calculate: C1 = Me (g α , h) s , C2=g s , Then the ciphertext CT (Cipher Text) is obtained, and the ciphertext CT = (C1, C2, C3, C4).
[0077] In this embodiment, firstly, a public parameter is obtained from a distributed storage system, and then a public key and a private key corresponding to the first user are generated according to the public parameter. The generated public key can encrypt and store data in a decentralized distributed storage system to ensure the security of the data, and the generated private key can generate a customized private key, so that the second user can obtain the first data that the first user wants to share, thereby ensuring the security of data sharing.
[0078] In the above Figure 1 In the embodiment of the invention, the first user's request for sharing the first data is first obtained, then a customized key corresponding to the first data is generated according to the private key, and finally the customized key is sent to the second user. Figure 2 In the embodiment of the present invention, before obtaining the sharing request for the first data initiated by the first user, the public parameters of the system are first obtained, and then the public key and private key corresponding to the first user are generated according to the public parameters. Figure 1 and Figure 2 The embodiments provide Figure 3The application embodiment shown, in this embodiment, first the distributed storage system completes the initialization of the system through an initialization algorithm and generates public parameters, the first user then obtains the public parameters from the distributed storage system manager to generate a public-private key pair, and then encrypts the data through the public key and stores the ciphertext in the distributed storage system, then the first user generates a customized key based on the private key and sends it to the second user, finally the second user decrypts the ciphertext based on the customized key and accesses the data, thereby completing data sharing between the first user and the second user, and no data leakage occurs, ensuring the security of data sharing.
[0079] In one embodiment, Figure 4 As shown, generating a customized key corresponding to the first data according to the private key includes:
[0080] Step 402 : Obtain a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate a range of data to be shared, and the tag set is used to indicate data types that are not to be shared.
[0081] Among them, the sharing identification vector is the first user identity identification vector, the maximum depth of the identity vector is l, and the maximum number of tags associated with the ciphertext in the tag set is n. For example, the sharing identification vector id = ("Company A", "Marketing Department", "Region A", "Sales"), the sharing identification vector is the sales data of the marketing department of Company A in Region A, and the tag set T = {"Product B", "2020.10 to 2020.12"}, which indicates that the data of Product B in the period from October 2020 to December 2020 is not shared.
[0082] Step 404: Generate a customized key corresponding to the first data according to the shared identification vector, the tag set, the public parameter and the private key, wherein the first data is determined from the stored data according to the shared identification vector and the tag set.
[0083] Specifically, a customized key corresponding to the first data is generated based on the shared data range represented by the sharing identification vector, the tag set representing the unshared data, the public parameters of the distributed storage system and the private key. The first data is determined from the stored data based on the shared data range and the unshared data.
[0084] In this embodiment, by obtaining a sharing identification vector and a tag set, the sharing identification vector is used to indicate the data range to be shared, and the tag set is used to indicate the type of data that is not to be shared; then a customized key corresponding to the first data is generated according to the sharing identification vector, the tag set, the public parameter and the private key, wherein the first data is determined from the stored data according to the sharing identification vector and the tag set. Therefore, generating a customized key corresponding to the first data enables the first user and the second user to share the first data, and can ensure the security of data sharing.
[0085] In one embodiment, Figure 5 As shown, generating a customized key corresponding to the first data according to the shared identification vector, the tag set, the public parameter and the private key includes:
[0086] Step 502: Generate an intermediate private key according to the shared identification vector, the private key and the public parameters.
[0087] Among them, the private key is generated according to the public parameters, and the private key is paired with the public key. The private key is SK = ({sk 0,1 ,sk 0,2 ,sk 0,3}, sk4, sk5, t0).
[0088] Specifically, according to the key extraction algorithm, the intermediate private key SK is generated by inputting the public parameter PP of the distributed storage system, the first user private key SK and the user sharing identification vector id id For example, user sharing identification vector id = (id1, id2, ..., id k )(where k≤l), the algorithm selects any element r″∈Z p , obtain the intermediate private key SK through the key extraction algorithm id ,in:
[0089]
[0090]
[0091] Then the key extraction algorithm is based on sk′ 0,1 , sk′4, sk′5 replace sk in SK 0,1 , sk4, sk5, other items remain unchanged, forming the intermediate private key SK id =({sk′ 0,1 ,sk 0,2 ,sk 0,3}, sk′4, sk′5, t0).
[0092] Step 504: Generate a customized key according to the tag set, the intermediate private key and the public parameter.
[0093] Specifically, according to the key puncture algorithm, a customized key corresponding to the first data is generated by inputting the tag set, the intermediate private key and the public parameter.
[0094] In this embodiment, an intermediate private key is first generated using the shared identification vector, private key and public parameters, and then a customized key corresponding to the first data is generated using the generated intermediate private key, tag set and public parameters. The customized key enables the first user and the second user to share the first data and can ensure the security of data sharing.
[0095] In one embodiment, Figure 6 As shown, generating a customized key according to the tag set, the intermediate private key and the public parameter includes:
[0096] Step 602, the intermediate private key, the public parameter and each tag generate a corresponding tag customized key respectively. The number of times the tag customized key is generated is the same as the number of tags in the tag set. Each tag customized key includes a newly added tag unit, and the newly added tag unit includes three newly added private key units of the corresponding tags.
[0097] Among them, the tag is in the tag set, and each tag in the tag set needs to perform the key puncture algorithm to generate the tag customization key of the corresponding tag. Each tag customization key contains a new tag unit. For example, for tag t, the new tag unit is {sk t,1 ,sk t,2 ,sk t,3}, the newly added private key unit corresponds to the sk in the newly added tag unit t,1 ,sk t,2 ,sk t,3 .
[0098] Specifically, according to the key puncture algorithm, the intermediate private key and the public parameter are respectively used to generate the corresponding tag customized key for each tag, and the number of times the tag customized key is generated by the key puncture algorithm is the same as the number of tags in the tag set. For example, when being punctured by tag t, according to the key puncture algorithm, the input system public parameter PP, the intermediate private key SK id and label t, output the label custom key punctured by label t in:
[0099]
[0100]
[0101]
[0102] The key puncture algorithm is based on sk′ 0,1 , sk′0,2 , sk′ 0,3 Replace SK id sk 0,1 ,sk 0,2 ,sk 0,3 , other items remain unchanged, and insert a new label unit {sk t,1 ,sk t,2 ,sk t,3} and t, the corresponding label customization key
[0103] Step 604: Generate a customized key according to multiple tag customized keys, where the number of the tag customized keys is the same as the number of tags in the tag set.
[0104] Specifically, all tags in the tag set are given a tag customization key through a tag puncture algorithm, and a customized key is generated based on each tag customization key. The number of the tag customization keys is the same as the number of tags in the tag set. m}, then m tag customization keys are generated accordingly, and finally the customized key is obtained according to the m tag customization keys. Right now sk4, sk5, t0, T={t1,...,t m}), at this time, when the first user's sharing identification id = ("Company A", "Marketing Department", "Region A", "Sales Volume") (the sharing identification vector is the sales volume data of the marketing department of Company A in Region A) and the tag set T = {"Product B", "2020.10 to 2020.12"}), the generated custom key is used for the first data shared by the first user to the second user, and the first data is the sales volume data of the marketing department of Company A in Region A, and the sales volume data does not include the data of Product B in the period from October to December 2020. When there is only one tag in the tag set, that is, the custom key is punctured by only one tag t, the custom key is generated according to the tag punctured by tag t. After that, the tag customizes the key That is, the customized key, which is used for the first user's shared identification vector id (id1, id2, ..., id k) and does not share data of the type marked by label t. At this time, when the sharing identifier id shared by the first user = ("Company A", "Marketing Department", "Region A", "Sales") (the sharing identifier vector is the sales data of the marketing department of Company A in Region A) and label t = {"Product B"}, the generated customized key is used for the first data shared by the first user to the second user. The first data is the sales data of the marketing department of Company A in Region A, and the sales data does not contain the data of Product B.
[0105] In this embodiment, a corresponding label customized key is generated for each label based on the intermediate private key and the public parameters, and then a customized key corresponding to the first data is generated based on the multiple label customized keys. The customized key enables the first user and the second user to share the first data and can ensure the security of data sharing.
[0106] In one implementation, after a customized key is generated according to the above tag set, the intermediate private key and the public parameter, the customized key is sent to the second user to instruct the second user to access the first data according to the customized key. Obtain the plaintext M. The ciphertext CT is associated with the shared identification vector id and the tag set S, and the key Associated with the shared identification vector id and the tag set T, if and only if (empty set), key Able to decrypt ciphertext, that is, by defining the polynomial Get the polynomial coefficients z0, z1, ..., z n , then calculate: And calculate for each i=1,...,m, calculate Then calculate A and B by the following formula i :
[0107]
[0108]
[0109] Finally, according to Decryption.
[0110] In this embodiment, the first data can be shared between the first user and the second user by using a customized key corresponding to the first data, and the security of data sharing can be ensured.
[0111] In one embodiment, Figure 7 As shown, after sending the customized key to the second user to instruct the second user to access the first data according to the customized key, the method further includes:
[0112] Step 702: Obtain a sharing request for second data initiated by a first user, where the second data is data within the first data.
[0113] Specifically, when a first user needs to share first data in second data in the distributed storage system, a sharing request for the second data initiated by the first user is obtained.
[0114] Step 704: Generate a new customized key corresponding to the second data according to the customized private key.
[0115] Specifically, a new customized key corresponding to the second data is generated according to the customized private key corresponding to the first data.
[0116] Step 706: Send the new customized key to the third user to instruct the third user to access the second data according to the new customized key.
[0117] Specifically, the first user sends a new customized key to the third user to instruct the third user to use the new customized key to access the second data after downloading the ciphertext data in the distributed storage system, and share the second data with the first user.
[0118] In this embodiment, when the first user wants to share part of the data within the first data range with the second user, the first user first obtains a sharing request for the second data, where the second data is the data within the first data, and then generates a new customized key corresponding to the second data based on the customized private key corresponding to the first data. Finally, the new customized key is sent to the third user to instruct the third user to access the second data based on the new customized key, thereby realizing data analysis of the first and third users and ensuring data security. The first user realizes data sharing with the third user by generating a new customized key corresponding to the second data, thereby improving the flexibility of data sharing.
[0119] In one embodiment, Figure 8 As shown, generating a new customized key corresponding to the second data according to the customized private key includes:
[0120] Step 802, obtaining a newly added sharing identifier.
[0121] Among them, the newly added sharing identifier is used to refine the scope of data sharing.
[0122] Specifically, when the first user shares part of the data within the first data range, a new sharing identifier is obtained.
[0123] Step 804: Generate a new customized key according to the newly added sharing identifier, the customized private key and the public parameters.
[0124] Specifically, a new customized key corresponding to the second data is generated by inputting the public parameter PP, the customized private key and the newly added sharing identifier through the key proxy generation algorithm. For example, the customized private key is punctured by the tag t, that is, the customized private key is Wherein the user sharing identification vector id=(id1,id2,……,id k )(where k≤l), add a new sharing identifier id k+1 , the algorithm selects a random number r″∈Z p , the new customized key is calculated by inputting the customized key punctured by tag t, the public parameters, and the newly added sharing identifier The shared identification vector of the new customized key is id′=(id1, id2, ..., id k , id k+1 ),in:
[0125]
[0126]
[0127] The above sk′ 0,1 , sk′4, sk′5 replace the custom private key pierced by tag t sk 0,1 , sk4, sk5, and other items remain unchanged, then the new customized key corresponding to the newly added sharing identifier is At this time, when the sharing identification id shared by the first user = ("Company A", "Marketing Department", "Region A", "Sales Volume"), the newly added sharing identification id k+1 =("first community") and label t={"product B"}, the generated customized key is used for the second data shared by the first user to the third user. The second data is the sales data of the marketing department of company A in the first community in region A, and the sales data does not include the data of product B.
[0128] In this embodiment, the sharing scope of the second data is determined by first acquiring the newly added sharing identifier, and then a new customized key corresponding to the second data is generated according to the newly added sharing identifier, the customized key and the public parameter. Therefore, the third user accesses the second data according to the new customized key, thereby realizing data sharing between the first user and the third user, ensuring data security, and the first user realizes data sharing with the third user by generating a new customized key corresponding to the second data, thereby improving the flexibility of data sharing.
[0129] In order to facilitate a clearer understanding of the technical solution of the present application, a more detailed embodiment is provided below for description. The distributed storage system manager initializes the distributed storage system by running the initialization algorithm to generate the public parameters of the distributed storage system. When the first user joins the distributed storage system, the public parameters of the system are first obtained, and the public and private key pairs are generated by running the first user's public and private key generation algorithm. Then the first user obtains the ciphertext by calling the encryption algorithm and using the public key to encrypt the data, and the ciphertext, i.e., the storage data, is stored in the distributed storage system. When the first user wants to share the data in the storage data, the first user obtains the intermediate private key by calling the key extraction algorithm and using the sharing identification vector id. The first user then generates a customized key by calling the key puncture algorithm and using the intermediate private key and the label set. The customized key corresponds to the shareable first data, which is the data in the storage data. After the second user obtains the customized key, the second user downloads the data ciphertext from the distributed storage system, and finally decrypts the ciphertext and restores the original data through the customized key, so that the first user can share the first data with the second user. If the first user wants to share part of the data within the range represented by the sharing identification vector id with other users, such as a third user, the first user can further refine the range by adding a sharing identification vector id k+1 Generate a new id′(id′=(id,id k+1 )), a new customized key is generated by running a key agent generation algorithm, and then, after the third user obtains the new customized key, the data ciphertext is downloaded from the distributed storage system, and the second data is obtained through the new customized key, so that the first user can share the second data with the third user.
[0130] In this embodiment, the first user generates his own public-private key pair, and then encrypts the data with the public key and stores it in the distributed storage system. When the first user shares data, he generates a customized key and sends it to the second user to instruct the second user to decrypt the ciphertext, thereby obtaining the data shared by the first user. That is, the first user does not need to share all the stored ciphertexts to achieve data sharing with the second user, and the data is not leaked, ensuring the security of data sharing. When the first user wants to share part of the shared first data with a third user, where part of the data is the second data, the first user can generate a new customized key corresponding to the second data to instruct the third user to obtain the second data, thereby achieving data sharing with the first user, thereby improving the flexibility of data sharing.
[0131] It should be understood that although Figure 1-8The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1-8 At least part of the steps may include multiple steps or multiple stages. These steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed in turn or alternately with other steps or at least part of the steps or stages in other steps.
[0132] In one embodiment, Fig. 9 As shown, a data sharing device is provided, the device 900 includes: a first acquisition module 902, a first generation module 904 and a first sending module 906, wherein:
[0133] The first acquisition module 902 is used to obtain a sharing request for first data initiated by a first user. The first data is data in the storage data of the first user. The storage data is ciphertext data encrypted with the public key of the first user and stored in the distributed storage system.
[0134] The first generating module 904 is configured to generate a customized key corresponding to the first data according to a private key, where the private key is paired with the public key.
[0135] The first sending module 906 is configured to send the customized key to the second user to instruct the second user to access the first data according to the customized key.
[0136] In one embodiment, Fig.10 As shown, the device 900 further includes: a second acquisition module and a second generation module, wherein:
[0137] The second acquisition module 908 is used to acquire public parameters from the distributed storage system.
[0138] The second generating module 910 generates a public key and a private key corresponding to the first user according to the public parameter.
[0139] In one embodiment, the first generation module 904 is used to obtain a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate a range of data to be shared, and the tag set is used to indicate the type of data that does not want to be shared; and a customized key corresponding to the first data is generated according to the sharing identification vector, the tag set, the public parameters and the private key, wherein the first data is determined from the stored data according to the sharing identification vector and the tag set.
[0140] In one embodiment, the first generating module 904 is used to generate an intermediate private key according to the shared identification vector, the private key and the public parameter; and to generate a customized key according to the tag set, the intermediate private key and the public parameter.
[0141] In one embodiment, the first generation module 904 is used to generate corresponding label customized keys for each label with the intermediate private key and the public parameter respectively. The number of times the label customized keys are generated is the same as the number of labels in the label set. Each label customized key includes a newly added label unit, and the newly added label unit includes three newly added private key units of the corresponding labels. A customized key is generated based on multiple label customized keys, and the number of the label customized keys is the same as the number of labels in the label set.
[0142] In one embodiment, Fig.11 As shown, the device 900 further includes a third acquisition module 912, a third generation module 914, and a second sending module 916, wherein:
[0143] The third acquisition module 912 is used to acquire a sharing request for second data initiated by the first user, where the second data is data within the first data.
[0144] The third generating module 914 is configured to generate a new customized key corresponding to the second data according to the customized private key.
[0145] The second sending module 916 is configured to send the new customized key to a third user to instruct the third user to access the second data according to the new customized key.
[0146] In one embodiment, the third generating module 914 is used to obtain a newly added sharing identifier; and generate a new customized key according to the newly added sharing identifier, the customized private key and the public parameters.
[0147] For the specific definition of the data sharing device, please refer to the definition of the data sharing method above, which will not be repeated here. Each module in the above data sharing device can be implemented in whole or in part by software, hardware and a combination thereof. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0148] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Fig.12As shown. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data sharing data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a data sharing method is implemented.
[0149] Those skilled in the art will understand that Fig.12 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0150] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0151] Obtain a sharing request for first data initiated by a first user, where the first data is data in the storage data of the first user, and the storage data is ciphertext data encrypted with the public key of the first user and stored in a distributed storage system; generate a customized key corresponding to the first data according to a private key, where the private key is paired with the public key; and send the customized key to a second user to instruct the second user to access the first data according to the customized key.
[0152] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0153] Obtaining public parameters from the distributed storage system; and generating a public key and a private key corresponding to the first user according to the public parameters.
[0154] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0155] Obtain a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate a range of data to be shared, and the tag set is used to indicate the type of data that is not to be shared; generate a customized key corresponding to the first data according to the sharing identification vector, the tag set, the public parameters and the private key, wherein the first data is determined from the stored data according to the sharing identification vector and the tag set.
[0156] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0157] An intermediate private key is generated according to the shared identification vector, the private key and the public parameter; and a customized key is generated according to the tag set, the intermediate private key and the public parameter.
[0158] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0159] The intermediate private key and the public parameter are respectively used to generate corresponding label customized keys for each label. The number of times the label customized keys are generated is the same as the number of labels in the label set. Each label customized key includes a newly added label unit, and the newly added label unit includes three newly added private key units of the corresponding labels. A customized key is generated based on multiple label customized keys, and the number of the label customized keys is the same as the number of labels in the label set.
[0160] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0161] Obtain a sharing request for second data initiated by a first user, where the second data is data within the first data; generate a new customized key corresponding to the second data according to the customized private key; and send the new customized key to a third user to instruct the third user to access the second data according to the new customized key.
[0162] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0163] Obtain a newly added sharing identifier; and generate a new customized key according to the newly added sharing identifier, the customized private key, and the public parameters.
[0164] In one embodiment, a computer readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0165] Obtain a sharing request for first data initiated by a first user, where the first data is data in the storage data of the first user, and the storage data is ciphertext data encrypted with the public key of the first user and stored in a distributed storage system; generate a customized key corresponding to the first data according to a private key, where the private key is paired with the public key; and send the customized key to a second user to instruct the second user to access the first data according to the customized key.
[0166] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0167] Obtaining public parameters from the distributed storage system; and generating a public key and a private key corresponding to the first user according to the public parameters.
[0168] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0169] Obtain a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate a range of data to be shared, and the tag set is used to indicate the type of data that is not to be shared; generate a customized key corresponding to the first data according to the sharing identification vector, the tag set, the public parameters and the private key, wherein the first data is determined from the stored data according to the sharing identification vector and the tag set.
[0170] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0171] An intermediate private key is generated according to the shared identification vector, the private key and the public parameter; and a customized key is generated according to the tag set, the intermediate private key and the public parameter.
[0172] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0173] The intermediate private key and the public parameter are respectively used to generate corresponding label customized keys for each label. The number of times the label customized keys are generated is the same as the number of labels in the label set. Each label customized key includes a newly added label unit, and the newly added label unit includes three newly added private key units of the corresponding labels. A customized key is generated based on multiple label customized keys, and the number of the label customized keys is the same as the number of labels in the label set.
[0174] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0175] Obtain a sharing request for second data initiated by a first user, where the second data is data within the first data; generate a new customized key corresponding to the second data according to the customized private key; and send the new customized key to a third user to instruct the third user to access the second data according to the new customized key.
[0176] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0177] Obtain a newly added sharing identifier; and generate a new customized key according to the newly added sharing identifier, the customized private key, and the public parameters.
[0178] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0179] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0180] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.
Claims
1. A data sharing method, characterized in that: The method comprises: Acquire a sharing request for first data initiated by a first user, where the first data is data in storage data of the first user, the storage data is ciphertext data encrypted by a public key of the first user and stored in a distributed storage system, and the first user is the data owner; Obtaining a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate a range of data to be shared, and the tag set is used to indicate data types that are not to be shared; Generate an intermediate private key according to the shared identification vector, the private key and the public parameters through a key extraction algorithm; According to the key puncture algorithm, the intermediate private key and the public parameter are respectively used to generate corresponding label customized keys for each label. The number of times the label customized keys are generated is the same as the number of labels in the label set. Each label customized key includes a newly added label unit, and the newly added label unit includes three newly added private key units corresponding to the labels. generating a customized key according to a plurality of tag customized keys, the number of the tag customized keys being the same as the number of tags in the tag set, wherein the first data is determined from the stored data according to the shared identification vector and the tag set, and the private key is paired with the public key; The customized key is sent to a second user to instruct the second user to access the first data according to the customized key, and the second user is a data user who shares the first data with the first user.
2. The method according to claim 1, characterized in that Before obtaining the sharing request for the first data initiated by the first user, the method further includes: Obtain public parameters from the distributed storage system; A public key and a private key corresponding to the first user are generated according to the public parameters.
3. The method according to claim 1, characterized in that After sending the customized key to the second user to instruct the second user to access the first data according to the customized key, the method further includes: Acquire a sharing request for second data initiated by a first user, where the second data is data within the first data; generating a new customized key corresponding to the second data according to the customized private key; The new customized key is sent to a third user to instruct the third user to access the second data according to the new customized key.
4. The method according to claim 3, characterized in that The generating a new customized key corresponding to the second data according to the customized private key includes: Get the newly added sharing logo; A new customized key is generated according to the newly added sharing identifier, the customized private key and the public parameters.
5. A data sharing device, characterized in that: The device comprises: A first acquisition module is configured to acquire a sharing request for first data initiated by a first user, wherein the first data is data in storage data of the first user, the storage data is ciphertext data encrypted by a public key of the first user and stored in a distributed storage system, and the first user is the data owner; The first generation module obtains a sharing identification vector and a tag set, wherein the sharing identification vector is used to indicate the data range to be shared, and the tag set is used to indicate the data type that is not to be shared; generates an intermediate private key according to the sharing identification vector, the private key and the public parameter through a key extraction algorithm; generates a corresponding tag customized key for each tag respectively using the intermediate private key and the public parameter according to a key puncture algorithm, wherein the number of times the tag customized key is generated is the same as the number of tags in the tag set, and each tag customized key includes a newly added tag unit, and the newly added tag unit includes three newly added private key units corresponding to the tags; generates a customized key according to multiple tag customized keys, wherein the number of the tag customized keys is the same as the number of tags in the tag set, wherein the first data is determined from the stored data according to the sharing identification vector and the tag set, and the private key is paired with the public key; The first sending module sends the customized key to a second user to instruct the second user to access the first data according to the customized key. The second user is a data user who shares the first data with the first user.
6. The device according to claim 5, characterized in that The device also includes a second acquisition module and a second generation module, the second acquisition module acquires public parameters from a distributed storage system; the second generation module generates a public key and a private key corresponding to the first user according to the public parameters.
7. The device according to claim 5, characterized in that The device further includes a third acquisition module, a third generation module, and a second sending module, wherein the third acquisition module is used to acquire a sharing request for second data initiated by the first user, wherein the second data is data within the first data; The third generating module is used to generate a new customized key corresponding to the second data according to the customized private key; The second sending module is used to send the new customized key to a third user to instruct the third user to access the second data according to the new customized key.
8. The device according to claim 7, characterized in that The third generating module is used to obtain a newly added sharing identifier; and generate a new customized key according to the newly added sharing identifier, the customized private key and the public parameters.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Access response method, device and internal control safety monitoring system for monitoring system files
CN108537052A
Cloud file sharing method, apparatus and device, and storage medium
CN109327448A