Information processing method, system, terminal device and storage medium
By applying attribute-based encryption technology in the information processing system, using attribute public keys and proxy private keys for information encryption and processing, the problem of user privacy data leakage and difficult to revoke attribute private keys is solved, and higher information transmission security is achieved.
Patent Information
- Application Number
- CN202111600664.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-24
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-12-24
AI Technical Summary
When protecting user privacy data, it is difficult to effectively avoid privacy data leakage caused by symmetric key leakage, and the user's attribute private key is difficult to revoke.
By introducing attribute-based encryption technology in the information processing system, the first terminal sends encryption information to the first server and uses the target attribute public key for encryption. The first server obtains the attribute proxy private key of the second terminal based on the attribute identification, processes the encryption information, and sends the processed encryption information to the target terminal.
It realizes hiding the specific attribute characteristics of the user during information transmission, preventing third-party servers from knowing user attributes, improving the security of information transmission, and avoiding the risk of information leakage after user attribute changes through the use of attribute proxy private keys.
Smart Images

Figure CN114297677B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of communication technology, and in particular, relates to an information processing method, system, terminal device and storage medium. Background Art
[0002] With the rise of cloud computing and cloud storage services, as well as the deployment of cloud servers by a large number of suppliers, the hardware costs of deploying services for enterprises or individuals have been greatly reduced. For users, centralized service providers have too much authority over user privacy data.
[0003] Currently, in order to protect user privacy data when using third-party services, one solution is to first symmetric-encrypt the original data, and then use the attribute-based encryption key to encrypt the symmetric encryption. In this way, users with specific attributes can decrypt the symmetric key through their own attribute private key. However, once the user leaks the symmetric key, it will lead to the problem of leaking user privacy data, and the user's attribute private key in this solution is difficult to revoke. Summary of the invention
[0004] The embodiments of the present application provide an information processing method, system, terminal device and storage medium, which can protect user privacy data and improve the security of information transmission.
[0005] In a first aspect, an embodiment of the present application provides an information processing method, which is applied to an information processing system, wherein the information processing system includes a first terminal, multiple second terminals, and a first server, wherein the first terminal communicates with the multiple second terminals respectively through the first server, and the method includes:
[0006] The first terminal sends first encrypted information to the first server, wherein the first encrypted information is information obtained by encrypting target information according to an attribute public key corresponding to a target attribute, and the target attribute is two-dimensional data;
[0007] After receiving the first encrypted information, the first server obtains the attribute identifier of the target attribute from the first encrypted information, obtains the attribute proxy private key of the second terminal according to the attribute identifier, processes the first encrypted information using the attribute proxy private key of the second terminal to obtain processed second encrypted information, and sends the second encrypted information to the second terminal, wherein the attribute identifier is an identifier of a dimension data in the target attribute, the second terminal is a terminal corresponding to the attribute identifier, and the attribute proxy private key of the second terminal is a key obtained by encrypting the attribute private key of the second terminal according to the user public key of the second terminal;
[0008] After the second terminal receives the second encrypted information, if the user attribute of the second terminal is the target attribute, the second encrypted information is decrypted according to the user private key of the second terminal to obtain the target information.
[0009] In a second aspect, an embodiment of the present application provides an information processing system, including a first terminal, multiple second terminals and a first server, wherein the first terminal communicates with the multiple second terminals respectively through the first server, and the information processing system is used to implement the information processing method described in any one of the first aspects above.
[0010] In a third aspect, an embodiment of the present application provides a terminal device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the information processing method described in any one of the first aspects above when executing the computer program.
[0011] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and wherein the computer program, when executed by a processor, implements the information processing method described in any one of the first aspects above.
[0012] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a terminal device, enables the terminal device to execute the information processing method described in any one of the above-mentioned first aspects.
[0013] Compared with the prior art, the first aspect of the present application has the following beneficial effects:
[0014] First, when the user of the first terminal expects to communicate with a user group having a target attribute, the first terminal sends a first encrypted message to the first server, wherein the first encrypted message is information obtained by encrypting the target information according to the attribute public key corresponding to the target attribute, and the target attribute is two-dimensional data; after receiving the first encrypted message, the first server obtains the attribute identifier of the target attribute from the first encrypted message, and the attribute identifier is an identifier of one dimensional data in the target attribute; at this time, the first server can only know the rough user attributes of the user with whom the first terminal expects to communicate based on the attribute identifier, and cannot know the specific attributes, that is, the target attributes, so that the specific attributes of the recipient corresponding to the first encrypted message cannot be known on the first server side and are hidden, thereby protecting the user's personal privacy information.
[0015] Secondly, after the first server obtains the attribute identifier of the target attribute from the first encrypted information, the first server obtains the attribute proxy private key of the second terminal according to the attribute identifier, and the second terminal is the terminal corresponding to the attribute identifier, and then uses the attribute proxy private key of the second terminal to process the first encrypted information to obtain the processed second encrypted information. In this way, since the attribute proxy private key of the second terminal is the key obtained by encrypting the attribute private key of the second terminal according to the user public key of the second terminal, and the second terminal includes a terminal whose user attribute is the target attribute, when the first server uses the attribute proxy private key of the second terminal whose user attribute is the target attribute to process the first encrypted information, the attribute encryption no longer exists in the obtained second encrypted information, but is converted into information after the target information is encrypted using the user public key. In this process, the target information is always safe and has not been exposed; and for the second terminal whose user attribute is not the target attribute, the first server cannot obtain the target information after processing the first encrypted information using the attribute proxy private key of the second terminal.
[0016] Finally, the first server sends the second encrypted information to the second terminal. After the second terminal receives the second encrypted information, if the user attribute of the second terminal is the target attribute, it can be seen from the above analysis that for the second terminal whose user attribute is the target attribute, the second encrypted information is the information after the target information is encrypted using the user public key of the second terminal. The second terminal decrypts the second encrypted information according to the user private key of the second terminal to obtain the target information. In this way, the second terminal does not need to save the attribute private key corresponding to the user attribute, and can decrypt the target information only with its own user private key. This can effectively avoid the situation where the second terminal can still decrypt the target information sent by the first terminal after its own user attribute changes, because it still saves its original attribute private key and does not revoke it, thereby improving information security.
[0017] It can be understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0019] Figure 1 is a structural diagram of an information processing system provided by an embodiment of the present application;
[0020] Figure 2It is a flowchart of an information processing method provided by an embodiment of the present application;
[0021] Figure 3 is a flowchart of an information processing method provided by another embodiment of the present application;
[0022] Figure 4 It is a structural diagram of a terminal device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0023] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0024] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0025] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0026] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0027] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0028] The information processing method provided in the embodiment of the present application can be applied to Figure 1 The application scenario shown in Figure 1. Figure 1 , is a schematic diagram of an information processing system provided in an embodiment of the present application. The information processing system includes terminal A, terminal B, terminal C, terminal D, server E1 and server E2, wherein communication between the terminals is implemented through server E1, and server B communicates with server E2 and each terminal respectively.
[0029] It should be noted that the terminal A, terminal B, terminal C and terminal D in the information processing system are merely examples, the purpose of which is to illustrate that the information processing system includes multiple terminals.
[0030] Among them, the user attributes of terminal B, the user attributes of terminal C, and the user attributes of terminal D all belong to the same attribute dimension, among which the user attributes of terminal B are the same as the user attributes of terminal C, and the user attributes of terminal D are different from the user attributes of terminal B. For example, if the attribute dimension is age, the user attribute of terminal B can be expressed as (age, 21), the user attribute of terminal C can be expressed as (age, 21), and the user attribute of terminal D can be expressed as (age, 30). Here, the user attribute of terminal A is not specifically limited.
[0031] The above attribute dimension of age is only an example and not a limitation. The attribute dimension of the user may also be occupation, region, hobbies, etc. Moreover, the attribute dimensions may be the same in more than one attribute dimension or in multiple attribute dimensions, which is not specifically limited here.
[0032] If the user of terminal A wants to communicate with a user group with specific attributes, for example, the terminals corresponding to the user group with specific attributes include terminal B and terminal C. Since the communication between the terminals is realized through server E1, in order to prevent the information sent by terminal A from being known by server E1, terminal A needs to encrypt the first information (i.e., the information to be sent by terminal A) and then send it to server E1. Since the user of terminal A wants to communicate with a user group with specific attributes rather than a single user, the attribute-based encryption technology can be used to encrypt the first information and then send it to server E1.
[0033] It should be noted that attribute-based encryption belongs to the public key encryption mechanism, and its decryption object is a group, not a single user. A group of users with the same attributes corresponds to the same public key, which is generated based on the user attributes and is referred to as the attribute public key below. Each user in the group of users with the same attributes has an attribute private key.
[0034] Continuing with the above example, if the user of terminal A wants to communicate with a user group with specific attributes (i.e., a user group including the user of terminal B and the user of terminal C), terminal A can do the following:
[0035] Terminal A uses the attribute public key of the user group to encrypt the first information, and then sends it to server E1. Server E1 sends the first information encrypted by terminal A to terminal B and terminal C. Finally, terminal B and terminal C respectively use their own attribute private keys to decrypt the received encrypted first information to obtain the first information.
[0036] From the above process, it can be seen that server E1, as a third party of the two communicating parties (the sender is terminal A, and the receivers are terminal B and terminal C), provides services for the two communicating parties. Neither the sender nor the receiver of the message wants the server as a third party to know too many user attribute characteristics, because once the server as a third party learns more user attribute characteristics, it may obtain a user portrait based on the user attribute characteristics, thereby sending a large number of spam advertisements to the user in a targeted manner, resulting in a poor user experience; in addition, the server as a third party may also actively or passively leak user attribute characteristics, which may cause criminals to obtain user portraits based on user attribute characteristics and implement precise telecommunications fraud, causing user losses.
[0037] Therefore, when a third-party server is used to provide services for communication between terminals, in order to enable the information sending terminal to send encrypted information to the receiving terminal corresponding to the specific user group with hidden attributes under the premise of hiding its own attribute characteristics, an embodiment of the present application provides an information processing method, which is applied to an information processing system, wherein the information processing system includes a first server and multiple terminals, and the multiple terminals communicate with each other through the first server. It should be noted that the multiple terminals include a first terminal and a second terminal.
[0038] It should be noted that the information processing system block diagram can be found in Figure 1 , where the first terminal may be Figure 1 The terminal A in the example, the second terminal may include a terminal B, a terminal C and a terminal D, and the first server may be a server E1.
[0039] The method of the embodiment of the present application continues to use attribute-based encryption technology to achieve communication between a terminal and multiple terminals of a user group with specific attributes. Therefore, before the two communicating parties exchange information, it is necessary to generate attribute public keys and attribute private keys for each terminal with user attributes through a server corresponding to an authorized agency that can supervise user attributes. That is, the information processing system of the embodiment of the present application also includes a second server, which communicates with multiple terminals and the first server respectively. Figure 1 , the second server may be server E2.
[0040] Here, the second server is used as a server corresponding to the authorization agency capable of supervising user attributes. The following describes in detail the process of the second server generating attribute public keys and attribute private keys for each terminal having user attributes.
[0041] 1) The second server obtains a user attribute data set, and groups the user attribute data set according to a preset attribute dimension to obtain multiple attribute sets, each of which includes multiple user attributes under the same attribute dimension.
[0042] Here, a large number of different user attributes may be collected and stored as a user attribute data set in the second server. The preset attribute dimensions may be age, occupation, region, title, department, grade, etc., which are not limited here.
[0043] Among them, multiple attribute sets can be specifically expressed as:
[0044] {(a 1,1 ,a 1,2 ,…),(a 2,1 ,a 2,2 ,…),…,(a i,j ,…)}
[0045] Among them, (a 1,1,a 1,2 ,…) represents an attribute set, (a 2,1 ,a 2,2 ,…) represents an attribute set, (a i,j ,…) represents a set of attributes. Here, a i,j Represents the attribute value, where a i,j The subscript index i is the attribute identifier representing the attribute dimension, and j is the attribute identifier of the specific attribute under the attribute dimension. That is, the attribute dimension can be determined by i, and the specific attribute value under the attribute dimension i can be determined by j.
[0046] 2) The second server generates a system public key and a master key including attribute public keys of different user attributes according to the multiple attribute sets.
[0047] First, when the system is initialized, the BDH parameter generator is run according to the security parameter k to generate two multiplication cyclic groups G with order q as prime number. 0 and G 1 , and the bilinear map: e:G 0 ×G 0 →G 1 .
[0048] Here, the bilinear map has the following properties:
[0049] i1) Bilinear: There is e(g x ,g y )=e(g,g) xy , where g is G 0 The generator of .
[0050] i2) Computability: There exists an efficient algorithm to compute e(g,g).
[0051] i3) Non-degeneracy, there exists g∈G 0 ,e(g,g)≠1.
[0052] Afterwards, in Z * P Randomly select y,(t 1,1 ,t 1,2 ,…),(t 2,1 ,t 2,2 ,…),…,(t i,j ,…) as the master key, the master key MK is {y,(t 1,1 ,t 1,2 ,…),(t 2,1 ,t 2,2 ,…),…,(t i,j ,…)}. Let Y = e(g,g) y , Output system public key PK = (e, g, Y, {T i,j})
[0053] Here, t i,j Corresponding to a i,j .
[0054] Through the above processing, the second server side generates a system public key and a master key including attribute public keys of different user attributes, so as to facilitate the subsequent generation of attribute private keys for terminals in the information processing system. Specifically, the second server generates attribute private keys for each terminal in the system, which can be implemented by the following optional implementation methods.
[0055] S101: A first terminal sends request information to a second server, wherein the request information includes a user identifier of the first terminal, a user public key of the first terminal, and user attributes of the first terminal.
[0056] Here, the first terminal generates a user key pair locally, and the user key pair includes a user public key of the first terminal and a user private key of the first terminal, wherein the user private key of the first terminal is stored locally in the first terminal.
[0057] It should be noted that the request information is used to request authorization from the second server, so that the second server generates a corresponding attribute private key for the first terminal.
[0058] Among them, the user identification U of the first terminal id It is the user's unique identifier and can be generated by encrypting "salt+ID number" with MD5.
[0059] The user attributes of the first terminal {a i,j} is a two-dimensional data, wherein the two-dimensional data is composed of two dimensional data, wherein one dimensional data represents the attribute dimension of the user attribute of the first terminal, and the other dimensional data represents the specific attribute of the user of the first terminal under the attribute dimension.
[0060] S102, the second server receives the request information, generates an attribute private key of the first terminal, encrypts the attribute private key of the first terminal according to the user public key of the first terminal, obtains the attribute proxy private key of the first terminal, and sends the attribute proxy private key of the first terminal and the user identification of the first terminal to the first server.
[0061] Here, after receiving the request information, the second server examines and approves the user of the first terminal, and after the examination and approval is passed, generates an attribute private key of the first terminal.
[0062] Here, the second server uses the master key and the user attribute {a i,j}The corresponding key t i,j, generate the attribute private key SK of the first terminal u′ Specifically, it can be expressed by the following formula:
[0063]
[0064] Wherein, i is the identifier of the attribute dimension, p is a random polynomial of (total number of attribute dimensions - 1) times, where p(0) = y.
[0065] Assuming that the user public key of the first terminal is w, the attribute proxy private key can be expressed as:
[0066]
[0067] It should be noted that the second server sends the attribute proxy private key of the first terminal and the user identification of the first terminal as user registration information to the first server. In this way, the attribute private key of the terminal does not need to be returned to the terminal, and the terminal does not need to send the corresponding user registration information to the first server. This can effectively avoid the situation where the original attribute private key is still saved after the user attribute of the terminal is changed due to not actively revoking the original attribute, thereby continuing to receive information that no longer belongs to the current attribute of the terminal, resulting in information leakage. This situation can improve information security.
[0068] Here, the process of the second server generating the corresponding attribute proxy private key for the second terminal is the same as the process of the second server generating the corresponding attribute proxy private key for the first terminal, which is not repeated here. That is, for all terminals in the information processing system, the second server generates corresponding attribute proxy private keys for them.
[0069] For the issue of revoking the original attributes of the terminal after the user attributes of the terminal mentioned above are changed, see Figure 2 In an optional implementation, the method of the embodiment of the present application may further include:
[0070] S201: A second server monitors change information of a first terminal, wherein the change information includes user attributes of the first terminal after the change.
[0071] It should be noted that the authorization agency in the embodiment of the present application is completely trustworthy, for example, the authorization agency is a government agency or public institution, and the user attributes of the terminal authorized by the authorization agency will not be disclosed to a third party. The second server, as the server corresponding to the authorization agency, can monitor changes in the user attributes of the terminal, such as changes in the user's age, changes in the user's occupation, etc.
[0072] S202: If the second server detects the change information of the first terminal, the second server regenerates the attribute private key of the first terminal according to the changed user attributes of the first terminal.
[0073] S203: The second server regenerates the attribute proxy private key of the first terminal according to the regenerated attribute private key of the first terminal and the user public key of the first terminal.
[0074] Specifically, the second server regenerates the attribute private key of the first terminal according to the changed user attribute of the first terminal using the key in the master key corresponding to the changed user attribute of the first terminal, and then encrypts the regenerated attribute private key of the first terminal using the user public key of the first terminal to obtain the regenerated attribute proxy private key of the first terminal. In this way, the original attributes of the user can be revoked quickly and conveniently to maintain the safe operation of the entire system.
[0075] It should be noted that, since the first server side stores the user identification of the first terminal and the attribute proxy private key of the first terminal, after step 203, the above method also includes: the second server sends the regenerated attribute proxy private key of the first terminal to the first server, and the first server replaces the original attribute proxy private key of the first terminal with the regenerated attribute proxy private key of the first terminal, thereby ensuring the smooth progress of communication services related to the first terminal.
[0076] Here, the second server also monitors the change information of the second terminal. After monitoring the change information of the second terminal, it will also regenerate the attribute private key for the second terminal according to the change information of the second terminal, and regenerate the attribute proxy private key for the second terminal based on the regenerated attribute private key. The specific process is the same as the above-mentioned second server's processing of the first terminal, and will not be repeated here. In other words, for all terminals in the information processing system, the second server will monitor the change information of each terminal. When the change information of the terminal is monitored, it will regenerate the attribute private key and attribute proxy private key for the corresponding terminal based on the corresponding change information.
[0077] The following describes a specific implementation process of the information processing method of the embodiment of the present application during actual information exchange between communicating parties.
[0078] Figure 3 A schematic flow chart of the information processing method provided by the present application is shown, referring to Figure 3 , the information processing method is described in detail as follows:
[0079] S301, a first terminal sends first encrypted information to a first server, wherein the first encrypted information is information obtained by encrypting target information according to an attribute public key corresponding to a target attribute, and the target attribute is two-dimensional data.
[0080] Here, based on the foregoing, the attribute public key corresponding to the target attribute belongs to the user group with the target attribute. The first terminal sends the first encrypted information to the first server. The first encrypted information is the information after the target information is encrypted according to the attribute public key corresponding to the target attribute, indicating that the user of the first terminal expects to communicate with the user group with the target attribute.
[0081] The target information is plain text information, which is information that the user of the first terminal actually wants to give to the user group with target attributes.
[0082] S302, after receiving the first encrypted information, the first server obtains the attribute identifier of the target attribute from the first encrypted information, obtains the attribute proxy private key of the second terminal according to the attribute identifier, processes the first encrypted information using the attribute proxy private key of the second terminal, obtains the processed second encrypted information, and sends the second encrypted information to the second terminal, wherein the attribute identifier is an identifier of a dimension data in the target attribute, the second terminal is the terminal corresponding to the attribute identifier, and the attribute proxy private key of the second terminal is a key obtained by encrypting the attribute private key of the second terminal according to the user public key of the second terminal.
[0083] It should be noted that the target attribute is two-dimensional data, which is composed of two dimensional data, one of which represents the attribute dimension of the target attribute, and the other represents the specific attribute of the user under the attribute dimension.
[0084] In this step, the attribute identifier is an identifier of a dimension data in the target attribute. Specifically, the attribute identifier is an attribute dimension identifier of the target attribute.
[0085] The second terminal is the terminal corresponding to the attribute identifier, indicating that all terminals corresponding to the attribute identifier are the second terminal, that is, the second terminal includes terminals whose user attributes are target attributes and terminals whose user attributes are other attributes. Here, other attributes and target attributes belong to the same attribute dimension, that is, other attributes and target attributes are different specific user attributes under the same attribute dimension. Among them, the user group corresponding to the terminal whose user attribute is the target attribute is the user group that the user of the first terminal really wants to communicate with.
[0086] Since the attribute proxy private key of the second terminal is a key obtained by encrypting the attribute private key of the second terminal according to the user public key of the second terminal, and the second terminal includes a terminal whose user attribute is a target attribute, when the first server processes the first encrypted information using the attribute proxy private key of the second terminal whose user attribute is the target attribute, the attribute encryption no longer exists in the obtained second encrypted information, but is converted into information after the target information is encrypted using the user public key. During this process, the target information is always safe and has not been exposed. For the second terminal whose user attribute is not the target attribute, the first server cannot obtain the target information after processing the first encrypted information using the attribute proxy private key of the second terminal, and the information is also safe.
[0087] It should be noted that the second terminal can choose whether to receive the information broadcast by the first server, that is, the second encrypted information, within a certain period of time. Specifically, the second terminal can send a reception activation request to the first server and set the state to receive information related to its own attributes within a certain period of time. In this way, when the first server obtains the attribute identifier of the target attribute from the first encrypted information, it first confirms the second terminal that is in the receiving state and whose attribute identifier is the same as the attribute identifier obtained by the first server, and then obtains the attribute proxy private key of these second terminals, thereby saving transmission resources.
[0088] S303: After the second terminal receives the second encrypted information, if the user attribute of the second terminal is the target attribute, the second encrypted information is decrypted according to the user private key of the second terminal to obtain the target information.
[0089] From the above analysis, it can be seen that for the second terminal whose user attributes are the target attributes, the second encrypted information is the information after the target information is encrypted using the user public key of the second terminal. The second terminal decrypts the second encrypted information according to the user private key of the second terminal to obtain the target information. In this way, after the second server processes the first encrypted information in the above step S302, the second terminal does not need to save the attribute private key corresponding to the user attribute, and can decrypt the target information only with its own user private key. This can effectively avoid the situation where the second terminal can still decrypt the target information sent by the first terminal later because it still saves its original attribute private key and does not revoke it after its user attributes change, thereby improving information security.
[0090] Since the first encrypted information is information obtained by encrypting the target information according to the attribute public key corresponding to the target attribute, and the sender of the first encrypted information to the first server is the first terminal, then during step S301, the first terminal needs to encrypt the target information according to the attribute public key corresponding to the target attribute to obtain the first encrypted information.
[0091] Optionally, the attribute public key includes a first preset operator and a first parameter, wherein the first parameter is used to characterize the target attribute.
[0092] From the description of the second server generating an attribute public key for each terminal having user attributes, it can be known that the attribute public key corresponding to the target attribute is the attribute public key corresponding to the target attribute selected by the first terminal from the system public key.
[0093] For ease of understanding, let the attribute public key corresponding to the target attribute PK1 = (e, g, Y, T i,j ), Y=e(g,g) y , The first preset operator is expressed as: Y = e(g, g) y , the first parameter is expressed as Here, the attribute public key corresponding to the target attribute selected by the first terminal from the system public key mainly selects the first parameter representing the target attribute.
[0094] In a possible implementation, before step S301, the method further includes:
[0095] S11, the first terminal encrypts a preset identifier according to a first preset operator to obtain a first ciphertext.
[0096] Here, the preset identifier R is a randomly generated identifier that complies with a preset rule. For example, the preset identifier R is a string consisting of 8 numbers or letters.
[0097] Specifically, select a random number s∈Z * P , the first ciphertext H is calculated by the following formula:
[0098] H=Y s R=e(g,g) ys R
[0099] S12, the first terminal encrypts the target information according to the first preset operator to obtain a second ciphertext.
[0100] Specifically, the second ciphertext E is calculated by the following formula:
[0101] E=Y s M=e(g,g) ys M
[0102] Among them, M represents the target information.
[0103] S13: The first terminal generates an attribute operator having an attribute identifier according to the first parameter.
[0104] Specifically, the attribute operator E with attribute identification is calculated by the following formula:f :
[0105]
[0106] Among them, E f The subscript f in is used to indicate the attribute identifier of the target attribute.
[0107] S14: The first terminal determines the first ciphertext, the second ciphertext and the attribute operator as first encrypted information.
[0108] Through the above processing, the first encrypted information can represent:
[0109]
[0110] Furthermore, in step 302, the first encrypted information is processed using the attribute proxy private key of the second terminal to obtain the processed second encrypted information, which may include:
[0111] Step 3021, if the user attribute of the second terminal corresponding to the attribute proxy private key of the second terminal is the target attribute, the first server calculates the third ciphertext according to the attribute proxy private key and the attribute operator of the second terminal, and the third ciphertext is the ciphertext encrypted by the first preset operator according to the user public key of the second terminal.
[0112] In this step, the user attribute of the second terminal corresponding to the attribute proxy private key of the second terminal is the target attribute, and the attribute proxy private key of the second terminal can be expressed as:
[0113]
[0114] Wherein m is the user public key of the second terminal, and the user private key corresponding to the user public key m of the second terminal is n.
[0115] Specifically, the first server calculates the intermediate result according to the attribute proxy private key and the attribute operator of the second terminal through the following formula:
[0116]
[0117] Then, based on the above intermediate results, Lagrange interpolation is used to find the third ciphertext Q
[0118]
[0119] Step 3022: determine the first ciphertext, the second ciphertext and the third ciphertext as the second encrypted information.
[0120] Through the above processing, the second encrypted information can represent:
[0121] (H=Y s R=e(g,g)ys R,E=Y s M=e(g,g) ys M,Q=e(g,g) sym )
[0122] It should be noted that if the user attribute of the second terminal corresponding to the attribute proxy private key of the second terminal is other attributes except the target attribute under the attribute identification, the attribute proxy private key of the second terminal can be expressed as It can be known from the above calculation that after the first server performs calculation according to the attribute proxy private key and attribute operator of the second terminal, the result obtained is not the third ciphertext Q.
[0123] Furthermore, the implementation process of step S303 may include:
[0124] Step S3031: decrypt the second encrypted information according to the user private key of the second terminal to obtain the first intermediate information.
[0125] Step S3032: If the first intermediate information includes a preset identifier, the first intermediate information is decrypted to obtain the target information.
[0126] In an optional implementation manner, the implementation process of step S3031 may include:
[0127] The third ciphertext is decrypted according to the user private key of the second terminal to obtain the first ciphertext, the second ciphertext and the first preset operator.
[0128] From the above process, it can be seen that the second encrypted information can represent:
[0129] (H=Y s R=e(g,g) ys R,E=Y s M=e(g,g) ys M,Q=e(g,g) sym )
[0130] In this step, the third ciphertext Q in the second encrypted information is decrypted according to the user private key n of the second terminal to obtain the first intermediate information, which can be expressed as:
[0131] (H=Y s R=e(g,g) ys R,E=Y s M=e(g,g) ys M,Q=e(g,g) sy )
[0132] That is, the first intermediate information includes the first ciphertext, the second ciphertext and the first preset operator.
[0133] Accordingly, the implementation process of step S3032 may include:
[0134] i) decrypting the first ciphertext according to the first preset operator to obtain decrypted information.
[0135] Specifically, the first ciphertext H is decrypted according to the first preset operator Y to obtain decrypted information.
[0136] ii) If the decrypted information is a preset identifier, it is determined that the first intermediate information includes the preset identifier.
[0137] For the second terminal whose user attribute is the target attribute, after the third ciphertext Q is decrypted by the user private key n of the second terminal, the first intermediate information obtained is:
[0138] (H=Y s R=e(g,g) ys R,E=Y s M=e(g,g) ys M,Q=e(g,g) sy )
[0139] Therefore, through the treatment of step i), R = H / Y s , the decrypted information obtained is the preset identifier R.
[0140] For the second terminal whose user attributes are other attributes except the target attribute under the attribute identifier, since the third ciphertext Q cannot be obtained by the previous processing, the preset identifier R cannot be decrypted using the user private key of the second terminal. At this point, it is sufficient to output the decryption result indicating that the decryption failed, and there is no need to decrypt the second ciphertext again, which can save computing power to a small extent.
[0141] iii) decrypting the second ciphertext according to the first preset operator to obtain the target information.
[0142] For the second terminal whose user attribute is the target attribute, after decrypting the preset identifier R through the processing of the above step i), the second ciphertext E is further decrypted using the first preset operator Y, that is, M=E / Ys.
[0143] The information processing method of the embodiment of the present application has relatively decentralized computing tasks, which are not concentrated on one party in the information processing system to which it is applied, and introduces attribute identification to hide the specific attribute characteristics of the user. Moreover, all terminals in the information processing system are equal, and there is no need to distinguish between senders and receivers. The second server performs coarse-grained matching through attribute identification, and the processed information is sent out in the form of broadcast, which realizes the hiding of user's characteristic attributes at a low cost, saving the overhead of the entire system compared to the blockchain.
[0144] The method of the embodiment of the present application can be applied to many scenarios in social life, such as:
[0145] Scene 1
[0146] In order to help single young people working in the area solve the problem of difficulty in making friends, a government department of a certain administrative district decided to entrust a third party to build a blind date and dating platform.
[0147] Here, a government department of a certain administrative region acts as an authorization agency, and the server corresponding to the authorization agency is equivalent to the second server of the embodiment of the present application, establishing a secure and reliable encryption system, that is, generating a system public key and a master key for each terminal with user attributes.
[0148] The dating and friendship platform built by a third party is equivalent to the first server in the embodiment of the present application, and provides corresponding services for single young people working in the jurisdiction to communicate with each other through the platform.
[0149] Specifically, using the method of the embodiment of the present application, first, all single young people in the jurisdiction can send a request message to the server corresponding to the authorization agency through the terminal to obtain authorization from the authorization agency. The request message includes a user identifier, user attributes and user public key.
[0150] Here, the purpose of user attributes is to provide relevant proof to the authorization agency so that the authorization agency can authorize the user to use the dating platform.
[0151] Then, the server corresponding to the authorization agency generates an attribute private key for the terminal that sends the request message based on the user attributes, encrypts the attribute private key with the user public key, and generates an attribute proxy private key for the terminal.
[0152] Finally, the attribute proxy private key and user ID are sent to the corresponding server of the dating platform as user registration information to realize user registration.
[0153] In the actual information exchange process, user x registered on the dating platform can send greeting messages to people with target attributes, such as selecting target attributes (for example, gender: female; age: 28 years old; from city: City C; occupation: primary school teacher), using the system public key to select the corresponding attribute public key to encrypt the dating information he wants to send, and attach the selected attribute group information (that is, the attribute identifier of the target attribute) to the information and send it to the platform.
[0154] Afterwards, the server corresponding to the dating platform obtains the attribute proxy private keys of all terminals under the attribute identifier through the attribute identifier of the target attribute selected by the user in the encrypted information, and processes the encrypted information with the obtained attribute proxy private key, and then broadcasts the processed encrypted information to the terminal corresponding to the attribute identifier.
[0155] Finally, if the terminal that meets the target attributes receives the encrypted information broadcast by the server corresponding to the dating platform, it uses its own user private key to decrypt the information and obtain the information sent by user x.
[0156] The method of the embodiment of the present application realizes a secure and encrypted one-to-many greeting communication scenario to help single young people establish a convenient and fast communication channel without leaking their privacy.
[0157] Scene 2
[0158] The Health Commission of a certain province or city decided to entrust an Internet company to develop a communication platform for all public hospitals within its jurisdiction, on which relevant doctors can directly communicate with anonymous patients about their conditions and treatment plans, and learn from each other to improve their skills.
[0159] Here, a provincial or municipal health commission serves as an authorization agency, and the server corresponding to the authorization agency is equivalent to the second server in the embodiment of the present application, establishing a secure and reliable encryption system, that is, generating a system public key and a master key for each terminal with user attributes.
[0160] The communication platform developed by an Internet company for all public hospitals within its jurisdiction is equivalent to the first server of the embodiment of the present application, and provides corresponding services for doctors in all public hospitals within the jurisdiction to communicate with each other through the platform.
[0161] Specifically, using the method of the embodiment of the present application, first, all doctors of public hospitals in the jurisdiction can send request information to the server corresponding to the authorization agency through the terminal to obtain authorization from the authorization agency. The request information includes user identification, user attributes and user public key.
[0162] Then, the server corresponding to the authorization agency generates an attribute private key for the terminal that sends the request message based on the user attributes, encrypts the attribute private key with the user public key, and generates an attribute proxy private key for the terminal.
[0163] Finally, the attribute proxy private key and user ID are sent to the server corresponding to the communication platform as user registration information to realize user registration.
[0164] In the actual information exchange process, if Doctor A registered on the communication platform wants to communicate with the doctor of the target attribute, he can select the target attribute (for example, hospital grade: tertiary hospital; doctor title: attending physician; department: respiratory department), use the system public key to select the corresponding attribute public key to encrypt the information he wants to discuss, and attach the selected attribute group information (that is, the attribute identifier of the target attribute) to the information.
[0165] Afterwards, the server corresponding to the communication platform obtains the attribute proxy private key of all terminals under the attribute identifier through the attribute identifier of the target attribute selected by the user in the encrypted information, and processes the encrypted information with the obtained attribute proxy private key, and then broadcasts the processed encrypted information to the terminal corresponding to the attribute identifier.
[0166] Finally, if the terminal that meets the target attributes receives the encrypted information broadcast by the server corresponding to the communication platform, it will use its own user private key to decrypt the information, obtain the information sent by Doctor A, and conduct relevant communication and learning.
[0167] The method of the embodiment of the present application realizes a temporary virtual chat room function for secure communication.
[0168] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0169] An embodiment of the present application also provides an information processing system, including a first terminal, multiple second terminals, a first server and a second server, wherein the first terminal communicates with the multiple second terminals respectively through the first server, and the second server communicates with the first terminal, the second terminal and the first server respectively, and the information processing system is used to implement the steps in any of the above-mentioned method embodiments.
[0170] The present application also provides a terminal device, see Figure 4 The terminal device 400 may include: at least one processor 410, a memory 420, and a computer program stored in the memory 420 and executable on the at least one processor 410. When the processor 410 executes the computer program, the steps in any of the above-mentioned method embodiments are implemented, for example Figure 3 Steps S301 to S303 in the illustrated embodiment.
[0171] Exemplarily, the computer program may be divided into one or more modules / units, one or more modules / units are stored in the memory 420, and executed by the processor 410 to complete the present application. The one or more modules / units may be a series of computer program segments capable of completing specific functions, and the program segments are used to describe the execution process of the computer program in the terminal device 400.
[0172] Those skilled in the art will understand that Figure 4It is only an example of a terminal device and does not constitute a limitation on the terminal device. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components, such as input and output devices, network access devices, buses, etc.
[0173] The processor 410 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0174] The memory 420 may be an internal storage unit of the terminal device, or an external storage device of the terminal device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. The memory 420 is used to store the computer program and other programs and data required by the terminal device. The memory 420 may also be used to temporarily store data that has been output or is to be output.
[0175] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application is not limited to only one bus or one type of bus.
[0176] The information processing method provided in the embodiments of the present application can be applied to terminal devices such as computers, tablet computers, laptop computers, netbooks, personal digital assistants (PDAs), etc. The embodiments of the present application do not impose any restrictions on the specific types of terminal devices.
[0177] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0178] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0179] In the embodiments provided in the present application, it should be understood that the disclosed terminal equipment, devices and methods can be implemented in other ways. For example, the terminal equipment embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0180] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0181] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0182] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by one or more processors, the steps of each of the above-mentioned method embodiments can be implemented.
[0183] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by one or more processors, the steps of each of the above-mentioned method embodiments can be implemented.
[0184] Similarly, as a computer program product, when the computer program product runs on a terminal device, the terminal device can implement the steps in the above-mentioned method embodiments when executing the computer program product.
[0185] The computer program includes computer program code, which may be in source code form, object code form, executable file or some intermediate form, etc. The computer readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer readable media do not include electric carrier signals and telecommunication signals.
[0186] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. An information processing method, It is characterized in that Applied to an information processing system, the information processing system includes a first server and a plurality of terminals, the terminals communicate with each other through the first server, the method includes: The first terminal sends first encrypted information to the first server, wherein the first encrypted information is information obtained by encrypting the target information according to the attribute public key corresponding to the target attribute, and the target attribute is two-dimensional data; the two-dimensional data is composed of two dimensional data, one of which represents the attribute dimension of the target attribute, and the other dimension represents the specific attribute of the user under the dimension; After receiving the first encrypted information, the first server obtains the attribute identifier of the target attribute from the first encrypted information, obtains the attribute proxy private key of the second terminal according to the attribute identifier, processes the first encrypted information using the attribute proxy private key of the second terminal to obtain processed second encrypted information, and sends the second encrypted information to the second terminal, wherein the attribute identifier is an identifier of a dimension data in the target attribute, the second terminal is a terminal corresponding to the attribute identifier, and the attribute proxy private key of the second terminal is a key obtained by encrypting the attribute private key of the second terminal according to the user public key of the second terminal; After the second terminal receives the second encrypted information, if the user attribute of the second terminal is the target attribute, the second encrypted information is decrypted according to the user private key of the second terminal to obtain the target information; The attribute public key includes a first preset operator and a first parameter, wherein the first parameter is used to characterize the target attribute; before the first terminal sends the first encrypted information to the first server, the method further includes: The first terminal encrypts the preset identifier according to the first preset operator to obtain a first ciphertext; The first terminal encrypts the target information according to the first preset operator to obtain a second ciphertext; The first terminal generates an attribute operator having the attribute identifier according to the first parameter; The first terminal determines the first ciphertext, the second ciphertext and the attribute operator as the first encrypted information; The using the attribute proxy private key of the second terminal to process the first encrypted information to obtain the processed second encrypted information includes: If the user attribute of the second terminal corresponding to the attribute proxy private key of the second terminal is the target attribute, the first server calculates a third ciphertext according to the attribute proxy private key of the second terminal and the attribute operator, where the third ciphertext is the ciphertext encrypted by the first preset operator according to the user public key of the second terminal; The first ciphertext, the second ciphertext and the third ciphertext are determined as the second encrypted information.
2. The information processing method according to claim 1, It is characterized in that The decrypting the second encrypted information according to the user private key of the second terminal to obtain the target information includes: decrypting the second encrypted information according to the user private key of the second terminal to obtain first intermediate information; If the first intermediate information includes a preset identifier, the first intermediate information is decrypted to obtain the target information.
3. The information processing method according to claim 2, It is characterized in that The decrypting the second encrypted information according to the user private key of the second terminal to obtain the first intermediate information includes: Decrypting the third ciphertext according to the user private key of the second terminal to obtain the first ciphertext, the second ciphertext and the first preset operator; Correspondingly, if the first intermediate information includes a preset identifier, decrypting the first intermediate information to obtain the target information includes: Decrypting the first ciphertext according to the first preset operator to obtain decrypted information; If the decrypted information is the preset identifier, determining that the first intermediate information includes the preset identifier; The second ciphertext is decrypted according to the first preset operator to obtain the target information.
4. The information processing method according to claim 1, It is characterized in that The information processing system further includes a second server, wherein the second server communicates with the plurality of terminals and the first server respectively; and the method further includes: The first terminal sends request information to the second server, wherein the request information includes a user identifier of the first terminal, a user public key of the first terminal, and a user attribute of the first terminal; The second server receives the request information, generates an attribute private key of the first terminal, encrypts the attribute private key of the first terminal according to the user public key of the first terminal, obtains the attribute proxy private key of the first terminal, and sends the attribute proxy private key of the first terminal and the user identification of the first terminal to the first server.
5. The information processing method according to claim 4, It is characterized in that The method further comprises: The second server monitors change information of the first terminal, wherein the change information includes user attributes of the first terminal after the change; If the second server monitors the change information of the first terminal, the second server regenerates the attribute private key of the first terminal according to the changed user attribute of the first terminal; The second server regenerates the attribute proxy private key of the first terminal according to the regenerated attribute private key of the first terminal and the user public key of the first terminal.
6. An information processing system, It is characterized in that It comprises a first server and a plurality of terminals, wherein the terminals communicate with each other through the first server, and the information processing system is used to implement the information processing method according to any one of claims 1 to 5.
7. A terminal device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, It is characterized in that When the processor executes the computer program, the information processing method according to any one of claims 1 to 5 is implemented.
8. A computer-readable storage medium storing a computer program. It is characterized in that When the computer program is executed by a processor, the information processing method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Electric power marketing cloud storage encryption method and system thereof
CN106487792A
Method and system for realizing secure sharing of encrypted files
CN112883399A