Traceable encryption system, method and related devices

By introducing zero-knowledge proof signature σZKP and CA's global private key GSK into the cloud storage system, the problem of being unable to trace the file provider in cloud storage is solved, realizing privacy protection and traceability of abnormal CT and improving data security.

CN114329502BActive Publication Date: 2025-10-24HUAWEI TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011052486.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-29
Publication Date
2025-10-24
Estimated Expiration
2040-09-29

AI Technical Summary

Technical Problem

Existing attribute-based encryption cloud storage systems cannot effectively track file providers, allowing malicious users to upload forged or illegal files undetected, and potentially exposing user privacy during the tracing process.

Method used

The system introduces zero-knowledge proof signature σZKP and uses the CA's global private key GSK for traceability, which protects user privacy while enabling the traceability of the source of abnormal CTs. The computing power of the cloud server is used to improve decryption speed and security.

Benefits of technology

While protecting user privacy, it enables the tracing of the source of abnormal CT scans, improves data security and decryption speed, and ensures the privacy protection of user identities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329502B_ABST
    Figure CN114329502B_ABST
Patent Text Reader

Abstract

The present application discloses a traceable encryption system that can be applied to the field of cloud storage. The system includes: a first terminal, a cloud server and an authorization center CA; the first terminal is used to encrypt a target plaintext using the CA's global public key GPK, the cloud server's public key CPK and the attribute center's public key APK to obtain a target ciphertext CT, and the first user attribute secret key USK is used to encrypt the target plaintext CT. pid,S1 And CT get the zero-knowledge proof signature σ ZKP , send CT and σ to the cloud server ZKP ; The cloud server is used to receive the CT and σ sent by the first terminal ZKP If CT is abnormal, send CT and σ to CA ZKP ; CA is used to receive CT and σ sent by the cloud server ZKP , using σ ZKP Tracing the source of CT. This application introduces a third party to protect user privacy while tracing the source of abnormal CT.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of cloud storage, and in particular to a traceable encryption system, method and related device. BACKGROUND

[0002] Cloud storage is an online storage mode that stores data on a virtual server hosted by a third party. In order to protect the data stored by users in the cloud, attribute-based encryption (ABE) is usually used to encrypt the data.

[0003] Since cloud storage is usually for many users, different users can upload encrypted files to the cloud platform, and it is difficult to track the file provider. In the attribute-based encryption with keyword search (ABKS) encryption algorithm, a file provider only needs to specify the access structure of the plaintext, and the identity of the file provider does not need to be included in the ciphertext. A malicious file provider can use this feature to upload fake files to mislead users, or upload some illegal files. Therefore, the ABKS system using ABKS cannot effectively track the file provider, and a malicious file provider may inject fake files or illegal files without worrying about being discovered. A simple processing method is to include the identity of the user during encryption, so that the file provider can be publicly traced, which can well solve the problem of tracing the file provider.

[0004] However, this method will disclose the privacy of the user, for example, an encrypted file with a doctor label of infectious disease leaks the type of ciphertext, which may be maliciously downloaded and spread. SUMMARY

[0005] The present application provides a traceable encryption system, method and related device, which can trace the source of abnormal CT on the basis of protecting the privacy of users.

[0006] The first aspect of the present application provides a traceable encryption system.

[0007] The system comprises a first terminal, a cloud server and an authorization center;

[0008] The first terminal is configured to encrypt a target plaintext using a global public key GPK of a CA, a cloud server public key CPK and an attribute center public key APK to obtain a target ciphertext CT, and obtain a zero-knowledge proof signature σ according to a first user attribute secret key USK pid,S1 and CTZKP , the cloud server sends CT and the sigma to the CA ZKP The first user can be an account logged in on the first terminal, or the first terminal itself. When the first user is the first terminal itself, the first user can be a MAC address or an IP address of the first terminal, etc.

[0009] The cloud server is configured to receive CT and the sigma sent by the first terminal ZKP If CT is abnormal, the cloud server sends CT and the sigma to the CA ZKP CT abnormality includes that the content carried by CT is false, or violates laws and regulations, etc.

[0010] The CA is configured to receive CT and the sigma sent by the cloud server ZKP The CA uses the sigma to trace the source of CT. ZKP

[0011] In the present application, the sigma ZKP is a signature related to the identity of the first user, and the signature is related to the global private key GSK of the CA, so the CA can use GSK and the sigma ZKP to obtain the identity of the first user, that is, to trace the source of CT. The cloud server cannot obtain the identity of the first user without GSK, thereby protecting the privacy of the user. Therefore, by introducing a third party, the source of abnormal CT can be traced on the basis of protecting the privacy of the user, and the CA belongs to the third party of the first user and the cloud server.

[0012] In an optional mode of the first aspect, the system further comprises a second terminal; the first terminal is further configured to obtain a verification key VK from a C f and a random number of CT, and send the VK to the cloud server; the cloud server is further configured to receive the VK sent by the first terminal, and perform partial decryption on CT according to a second proxy key UDK pid,S2 of the second terminal to obtain a partially decrypted target ciphertext CT out , and send CT out and the VK to the second terminal; the second terminal is configured to decrypt CT pid,S2 according to the VK and a second decryption token tk out to obtain a target plaintext. The cloud server assists the second terminal in decryption, so as to improve the decryption speed of the second terminal. Moreover, the cloud server generally has strong computing capability, so as to improve the overall decryption time. The overall decryption time includes the decryption time of the second terminal and the decryption time of the cloud server.

[0013] In an optional mode of the first aspect, the first terminal is further configured to generate an additional ciphertext CT' according to CT and a second user identity uid2, and send the CT' to the cloud server; the cloud server is further configured to determine the CT', the VK, and the UDK​pid,S2 Whether the first condition is met, if the first condition is met, then it is determined that the second terminal meets the conditions for obtaining the CT. Among them, in the ciphertext policy ABE and key policy ABE of attribute-based encryption (ABE), the key policy ABE cannot determine who can access the CT. The ciphertext policy ABE can only determine which users with which attributes can access the CT, but there may be multiple users with the same attribute. Therefore, through CT′, this application enables a specified user to access the CT, thereby improving data security.

[0014] In an optional manner of the first aspect, the CA is also used to pid,S1 Perform a legality check. If USK pid,S1 If it is legal, then according to CA's global private key GSK and USK pid,S1 Get the first user identity uid1. Among them, in the attribute encryption ABKS (CP-ABKS) system of ciphertext access policy, the privileges of file search and decryption are shared among a group of users, rather than associated with a single user. Therefore, in this case, it is difficult to track down malicious users who deliberately leak passwords. For example, a user named Jack has the attribute set "Huawei Corp. Engineer", and another user named Tom has the same attribute set. Both users have search and decryption access policies for documents (Huawei Corp. AND Engineer). If one of the engineers leaks his attribute key through the black market, it is difficult to trace back to which engineer leaked the key. This application will use USK pid,S1 Associated to a single user, thus in USK pid,S1 In case of leakage, you can use USK pid,S1 Find the corresponding user.

[0015] In an optional manner of the first aspect, the first terminal is further configured to obtain an encrypted index (EI) based on a keyword subset KW of the target plaintext and send the EI to the cloud server; the second terminal is further configured to obtain a keyword subset QE and send the EI to the cloud server based on the QE and the second user key USK. pid,S2 A trapdoor TW is constructed and sent to the cloud server. The cloud server is further configured to determine whether CT, TW, EI, and the cloud server's private key CSK satisfy a second condition. If so, QE is determined to belong to KW. This application implements keyword search for target plaintext without decrypting CT, facilitating data retrieval in cloud storage.

[0016] A second aspect of the present application provides a traceable encryption method.

[0017] The method includes: the first terminal uses the global public key GPK of the authorization center CA, the cloud server public key CPK and the attribute center public key APK to encrypt the target plaintext to obtain the target ciphertext CT; the first terminal uses the first user attribute secret key USK to encrypt the target plaintext CT; pid,S1 And CT get the zero-knowledge proof signature σ ZKP ; The first terminal sends CT and σ to the cloud server ZKP ,σ ZKP and CT for CA using σ ZKP Trace the source of CT.

[0018] In an optional manner of the second aspect, the first terminal f and a random number to obtain the verification key VK; the first terminal sends VK to the cloud server, and VK is used by the second terminal to decrypt the token tk according to VK and the second pid,S2 CT out Decrypt and get the target plaintext, CT out The server uses the second user agent key UDK of the second terminal pid,S2 Obtained by partially decrypting CT.

[0019] In an optional manner of the second aspect, the first terminal generates an additional ciphertext CT' based on CT and the second user identity uid2; the first terminal sends CT' to the cloud server, and CT' is used by the cloud server to determine CT', VK, UDK pid,S2 Whether the first condition is met. If the first condition is met, it means that the second terminal meets the condition for obtaining the CT.

[0020] In an optional manner of the second aspect, the first terminal obtains an encryption index EI based on a keyword subset KW of the target plaintext; the first terminal sends EI to the cloud server, and EI is used by the cloud server to determine whether CT, the trapdoor TW, EI, and the cloud server's private key CSK meet a second condition. If the second condition is met, it means that the keyword subset QE belongs to KW, and TW is the second terminal based on QE and the second user attribute key USK pid,S2 Constructed.

[0021] The third aspect of this application provides a traceable encryption method.

[0022] The method includes: a cloud server receives a target ciphertext CT and a zero-knowledge proof signature σ sent by a first terminal; ZKP , wherein the CT is obtained by the first terminal using the global public key GPK of the authorization center CA, the cloud server public key CPK and the attribute center public key APK to encrypt the target plaintext, the σ ZKP The first terminal uses the first user attribute key USK pid,S1and the CT, and the cloud server sends the CT and the σ to the CA if the CT is abnormal ZKP , the σ ZKP and the CT are used by the CA to trace the source of the CT using the σ ZKP .

[0023] In an optional manner of the third aspect, the cloud server receives a verification key VK sent by the first terminal;

[0024] The cloud server partially decrypts the CT according to a second proxy key UDK of the second terminal pid,S2 to obtain a partially decrypted target ciphertext CT out .

[0025] The cloud server sends the CT out and the VK to the second terminal, the VK being obtained by the first terminal according to a C f of the CT and a random number, the VK being used by the second terminal to decrypt the CT pid,S2 according to the VK and a second decryption token tk out to obtain the target plaintext.

[0026] In an optional manner of the third aspect, the cloud server determines whether an additional ciphertext CT', the VK, the UDK pid,S2 satisfy a first condition, the CT' being generated by the first terminal according to the CT and a second user identity uid2; if the first condition is satisfied, the cloud server determines that the second terminal satisfies a condition of obtaining the CT.

[0027] In an optional manner of the third aspect, the cloud server determines whether the CT, a trapdoor TW, an encryption index EI, and a private key CSK of the cloud server satisfy a second condition; if the second condition is satisfied, the cloud server determines that a keyword subset QE belongs to a keyword subset KW, the EI being obtained by the first terminal according to the KW of the target plaintext, the TW being constructed by the second terminal according to the QE and a second user attribute key USK pid,S2 .

[0028] The fourth aspect of the present application provides an encryption device with traceability.

[0029] The device comprises:

[0030] An encryption module is configured to encrypt a target plaintext using a global public key GPK of an authorization center CA, a cloud server public key CPK, and an attribute center public key APK to obtain a target ciphertext CT.

[0031] A processing module is configured to process a first user attribute key USK pid,S1 And the CT obtains the zero-knowledge proof signature σ ZKP ;

[0032] A sending module is used to send the CT and the σ to the cloud server. ZKP , the σ ZKP and the CT for the CA utilizing the σ ZKP The source of the CT is traced.

[0033] In an optional manner of the fourth aspect, the processing module is further configured to: f and a random number to obtain the verification key VK;

[0034] The sending module is further used to send the VK to the cloud server, and the VK is used by the second terminal to decrypt the token tk according to the VK and the second decryption token tk pid,S2 CT out Decrypt to obtain the target plaintext, the CT out The server is based on the second user agent key UDK of the second terminal pid,S2 Obtained by partially decrypting the CT.

[0035] In an optional manner of the fourth aspect, the processing module is further configured to generate an additional ciphertext CT′ based on the CT and the second user identity uid2;

[0036] The sending module is further used to send the CT′ to the cloud server, and the CT′ is used by the cloud server to determine the CT′, the VK, and the UDK pid,S2 Whether the first condition is met. If the first condition is met, it means that the second terminal meets the condition for obtaining the CT.

[0037] In an optional manner of the fourth aspect, the processing module is further configured to obtain an encryption index EI according to the keyword subset KW of the target plaintext;

[0038] The sending module is further configured to send the EI to the cloud server, wherein the EI is used by the cloud server to determine whether the CT, the trapdoor TW, the EI, and the private key CSK of the cloud server meet a second condition. If the second condition is met, it indicates that the keyword subset QE belongs to the KW, and the TW is the second terminal according to the QE and the second user attribute key USK. pid,S2 Constructed.

[0039] A fifth aspect of the present application provides a traceable encryption device.

[0040] The device includes: a receiving module for receiving a target ciphertext CT and a zero-knowledge proof signature σ sent by a first terminal ZKP , wherein the CT is obtained by the first terminal using the global public key GPK of the authorization center CA, the cloud server public key CPK and the attribute center public key APK to encrypt the target plaintext, the σ ZKP The first terminal uses the first user attribute key USK pid,S1 and the CT obtained;

[0041] A sending module, configured to send the CT and the σ to the CA if the CT is abnormal ZKP , the σ ZKP and the CT for the CA utilizing the σ ZKP The source of the CT is traced.

[0042] In an optional manner of the fifth aspect, the receiving module is further configured to receive a verification key VK sent by the first terminal;

[0043] The device further comprises:

[0044] A decryption module for decrypting a second agent key UDK of the second terminal pid,S2 Partially decrypt the CT to obtain the partially decrypted target ciphertext CT out ;

[0045] The sending module is further configured to send the CT to the second terminal. out and the VK, the VK is the C of the first terminal according to the CT f and a random number thereof, the VK is used by the second terminal according to the VK and the second decryption token tk pid,S2 For the CT out Decryption is performed to obtain the target plaintext.

[0046] In an optional manner of the fifth aspect, the device further includes:

[0047] Determination module, used to determine the additional ciphertext CT', the VK, the UDK pid,S2 whether the first condition is met, the CT′ is generated by the first terminal according to the CT and the second user identity uid2;

[0048] The determining module is further configured to determine that the second terminal meets a condition for acquiring the CT if the first condition is met.

[0049] In an optional manner of the fifth aspect, the device further includes:

[0050] a determination module, configured to determine whether the CT, the trapdoor TW, the encryption index EI, and the private key CSK of the cloud server satisfy a second condition;

[0051] The determining module is further configured to determine that the keyword subset QE belongs to the keyword subset KW if the second condition is met, the EI is obtained by the first terminal according to the KW of the target plaintext, and the TW is obtained by the second terminal according to the QE and the second user attribute key USK. pid,S2 Constructed.

[0052] The sixth aspect of the present application provides a traceable encryption device.

[0053] The device includes a processor and a transceiver;

[0054] The processor is used to encrypt the target plaintext using the global public key GPK of the authorization center CA, the cloud server public key CPK and the attribute center public key APK to obtain the target ciphertext CT, and the first user attribute secret key USK is used to encrypt the target plaintext pid,S1 And the CT obtains the zero-knowledge proof signature σ ZKP ;

[0055] The transceiver is used to send the CT and the σ to the cloud server ZKP , the σ ZKP and the CT for the CA utilizing the σ ZKP The source of the CT is traced.

[0056] The seventh aspect of the present application provides a traceable encryption device.

[0057] The device includes a processor and a transceiver;

[0058] The transceiver is used to receive the target ciphertext CT and the zero-knowledge proof signature σ sent by the first terminal ZKP , wherein the CT is obtained by the first terminal using the global public key GPK of the authorization center CA, the cloud server public key CPK and the attribute center public key APK to encrypt the target plaintext, the σ ZKP The first terminal uses the first user attribute key USK pid,S1 and the CT obtained;

[0059] The processor is used to determine whether the CT is abnormal;

[0060] The transceiver is further configured to send the CT and the σ to the CA if the CT is abnormal. ZKP , the σ ZKP and the CT for the CA utilizing the σ ZKP The source of the CT is traced.

[0061] The eighth aspect of the present application provides a computer storage medium, characterized in that the computer storage medium stores instructions, and the instructions cause a computer to perform the method according to the first aspect or any one of the implementation manners of the first aspect when the computer executes the instructions.

[0062] The ninth aspect of the present application provides a computer program product, characterized in that the computer program product causes a computer to perform the method according to the first aspect or any one of the implementation manners of the first aspect when the computer executes the computer program product. BRIEF DESCRIPTION OF DRAWINGS

[0063] Figure 1 A network framework diagram of a traceable encryption system in an embodiment of the present application;

[0064] Figure 2 A flowchart of system initialization and user registration in an embodiment of the present application;

[0065] Figure 3 A flowchart of obtaining a CT by a second terminal without keyword subset search in an embodiment of the present application;

[0066] Figure 4 A flowchart of obtaining a CT by a second terminal with keyword subset search in an embodiment of the present application;

[0067] Figure 5 A flowchart of tracing a source of a CT in an embodiment of the present application;

[0068] Figure 6 A flowchart of tracing a user identity by a user attribute private key in an embodiment of the present application;

[0069] Figure 7 A structural schematic diagram of a traceable encryption device in an embodiment of the present application;

[0070] Figure 8 Another structural schematic diagram of a traceable encryption device in an embodiment of the present application;

[0071] Figure 9 A structural schematic diagram of a traceable encryption device in an embodiment of the present application;

[0072] Figure 10 Another structural schematic diagram of a traceable encryption device in an embodiment of the present application. DETAILED DESCRIPTION

[0073] The embodiments of the present application provide a traceable encryption system, method and related device, which are applied to the field of cloud storage, and can trace a source of an abnormal CT on the basis of protecting user privacy.

[0074] The advent of cloud computing brings the features of on-demand application of computing and storage resources, unified storage of data, and large-scale reduction of equipment purchase and maintenance costs. These advantages lead companies and individuals to adopt this new IT architecture to put data and services on the cloud. However, for sensitive data stored on the cloud, privacy is a problem. In order to reduce the risk of privacy leakage, data owners use encryption to protect data stored on the cloud. ABE not only protects the privacy of user data, but also provides users with fine-grained access control of data.

[0075] ABE is an attribute-based encryption, and the biggest difference between it and RSA, IBE (Identity-Based Encryption) and other encryption methods is that it implements one-to-many encryption and decryption. That is, ABE does not need to know the identity information of the recipient each time, as other encryption methods do. When the user's attributes meet the encryption described by the policy, the user can decrypt. ABE was first proposed by Ostrovsky in 2007, and since then, many research works have been carried out in this field, including ABE algorithms based on hierarchical structure and decentralized structure, supporting users of systems using hierarchical structure.

[0076] Since cloud storage is usually for many users, different users can upload encrypted files to the cloud platform, and it is difficult to track the file provider. In the encryption algorithm of ABE with keyword search (ABKS), a file provider only needs to specify the access structure of the plaintext, and the identity of the file provider does not need to be included in the ciphertext. A malicious file provider can use this feature to upload fake files to mislead users, or upload some illegal files. Therefore, the ABKS system using ABKS cannot effectively track the file provider, and a malicious file provider may inject fake files or illegal files without worrying about being found. A simple processing method is to include the identity of the user during encryption, so that the file provider can be publicly traced. This method can well solve the problem of tracing the file provider. However, this method will expose the privacy of the user, for example, an encrypted file with a doctor's label of infectious disease leaks the type of ciphertext, which may therefore be maliciously downloaded and spread.

[0077] To this end, the embodiment of the present application provides a traceable encryption system. In this system, the first user encrypts the target plaintext through the terminal to obtain the target ciphertext CT, and uploads CT to the cloud server, so that users with common attributes can download and decrypt the data from the server. In this system, in order to ensure the accountability of CT, the first user needs to upload the zero-knowledge proof signature σ associated with CT. ZKP , the σ ZKP and σ ZKP is a signature related to the identity of the first user, and the signature is related to the CA's global private key GSK, so the CA can use GSK and σ ZKP Obtaining the identity of the first user allows tracing the source of the CT. Because the cloud server lacks GSK, it cannot determine the identity of the first user, thus protecting user privacy. By involving a third party, the source of abnormal CT can be traced while protecting user privacy.

[0078] In order to facilitate understanding of the traceable encryption system provided in the embodiment of the present application, the composition of the system is described below. Figure 1 , Figure 1 This is a network framework diagram of a traceable encryption system in an embodiment of the present application. The system includes: an authorization center CA101, an attribute center AA102, a cloud server 103, a first terminal 104, and a second terminal 105. CA101, AA102, and cloud server 103 are computer devices with storage and computing capabilities, such as servers. CA101 is a global trust party, the core of the system, and is responsible for the creation of the system. At the same time, CA also accepts registrations from the attribute center 102 and terminals, which include the first terminal 104 and the second terminal 105. Each AA is an independent attribute center that can issue attributes and corresponding attribute keys to users. In the example of the present application, AA102 issues attributes and corresponding user keys to the first terminal 104 and the second terminal 105. The cloud server 103 provides storage and access services for the first terminal 104 and the second terminal 105, and processes the search requests of the terminals. When the search results are not empty, the search results are returned to the terminals. In the embodiment of the present application, the cloud server 103 provides storage services for the first terminal 104, storing the CT sent by the first terminal 104. The cloud server 103 provides access services for the second terminal 104, sending the CT to the second terminal 105. CA101 assigns an anonymous identity to each user, and the terminal can use this identity to send a search request to the cloud server 103. When the search keyword matches the keyword contained in the ciphertext index and the user meets the access policy embedded in the ciphertext, the cloud server 103 will return the corresponding result and perform the outsourced decryption work in the cloud to obtain the partially decrypted target ciphertext CT. outHowever, the target plaintext cannot be obtained. Then, the terminal can further decrypt the ciphertext returned by the cloud server using its own attribute key.

[0079] The first terminal 104 and the second terminal 105 can generally refer to a device having a communication capability with a network device, such as an access terminal device, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, a remote terminal device, a mobile device, a user terminal device, a wireless terminal device, a user agent, or a user equipment, etc. It can also be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device, other processing devices connected to a wireless modem, a vehicle-mounted device, a wearable device (smart watch, smart bracelet, etc.), a smart home (or home appliance), a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), or a vehicle device in vehicle to everything (V2X), customer premise equipment (CPE), etc. The specific implementation form of the terminal is not limited in the present application.

[0080] The traceable encryption system provided by the embodiments of the present application is applied to the field of cryptography, and therefore many algorithm concepts are involved, which are uniformly described below.

[0081] Given a positive integer n, let [n] represent the set of all positive integers less than or equal to n, [n] = {1, 2, …, n}. Let [n] represent the set of all positive integers less than or equal to n, [n] = {1, 2, …, n}.

[0082] Bilinear Paring: and are two prime groups of order p, g is the generator of the group . An efficiently computable mapping e: becomes a bilinear mapping, which satisfies the following properties:

[0083] 1. Bilinearity: for all a, e(g a , g b ) = e(g, g) ab .

[0084] 2. Non-degenerate: e(g, g) ≠ 1, 1 is the identity of the group.

[0085] 3. e is efficiently computable.

[0086] Assumption 1 (q-SDH assumption). is a bilinear prime group of order p, g is a generator of the group The q-Strong Diffie-Hellman (q-SDH) problem in the group is defined as follows: Given a (q+1) -dimensional vector as input, the output is An algorithm has advantage ∈ in computing q-SDH in the group if for any x in and any parameters input in the above inequality holds. If the (q, t, ∈)-SDH assumption holds in the group G, then there is no t-time algorithm that always has an advantage of at least ∈ in solving the q-SDH problem in the group

[0087] Assumption 2 (decisional bilinear Diffie-Hellman assumption). is a bilinear prime group of order p, g is a generator of the group

[0088] Select any a, b, If the adversary obtains It is difficult for the attacker to distinguish from the element R, where R is an arbitrary element in If the adversary has an advantage of ∈ in solving the above assumption, then the following inequality always holds:

[0089]

[0090]

[0091] Definition 1 (access structure). {P1,..., Pn} represents a multi-party set. The set is monotonic if for C: when B ∈ A and then ​​​​A monotone access mechanism is a monotone set A that is a non-empty subset of the set {P1, ..., Pn}, i.e. The set in A is called the authorized set, and the set that does not belong to A is called the unauthorized set.

[0092] Definition 2. (Linear Secret Sharing Schemes (LSSS)). M is an l×n matrix. ρ: {1, …, l} → P is a function that maps a row of the matrix M to some entity Pi. A secret sharing method π on P is a linear secret sharing method on Zp if the following conditions are met:

[0093] 1. The secret component of each party forms a vector on Zp.

[0094] 2. For a given π, there exists a lxn matrix M, called the shared secret generator matrix. For x=1,…,l, use ρ(i) to denote the xth row of the matrix M, where ρ:{1,…,l}→P is a function that maps the rows of the matrix M to some entity P. A column vector where μ∈Z p is a shared secret, r2,…,rn∈Zp are randomly selected.

[0095] So It is a vector of l components based on π containing the secret μ, the components belongs to the entity P indexed by ρ(i).

[0096] Every LSSS structure has the property of linear reconstruction. Let Π be an LSSS of access structure A. Let A represent an authorization set, and define And I = {i|ρ(i)∈A}. The vector (1, 0, ..., 0) can be synthesized from the row vectors of the matrix M whose index is the set I, and there exists a constant {wi∈Zp}i∈I, for any legal component {v i}, we can get ∑ i∈I w i v i =μ. These constants {w i can be found in polynomial time in a variable size of the component generator matrix M.

[0097] For a non-authorized set A', the constant set {w i} does not exist. In this case, if I'={i|ρ(i)∈A'}, then for the vector The first element w1 of this vector is a non-zero element in Zp, and for any i∈I', Here Mi is the i-th row of the matrix M.

[0098] A zero-knowledge proof protocol involves a prover (P) and a verifier (V): P convinces V that P knows w such that a certain type of relation holds for a known string x As If P can convince V in some way while ensuring that V does not gain any information about the statement being verified, then the protocol is called a zero-knowledge proof of knowledge (ZKP). The formal definition of ZKP signature transforms an interactive proof into a non-interactive form. For a given relation A zero-knowledge proof signature (ZKP signature) can be denoted by ∑ = (Setup, Sign, Verify), where the language used by the zero-knowledge proof is The system setup algorithm Setup takes a security parameter λ as input and outputs public parameters pp. The signature algorithm Sign takes (m, w, x) as input and outputs a zero-knowledge proof signature (ZKP signature) σ, where m is the message to be signed, The system verification algorithm Verify takes (m, x, σ) as input and outputs a bit b ∈ {0, 1}. The formal security definition of zero-knowledge proof signature is named SimExt-Secure, which contains the following properties:

[0099] Correctness, for any relation that satisfies and an arbitrary given message m, there exists a negligible function v that satisfies the following inequality:

[0100] Pr[Verify(m, x, σ) = 1: pp ← Setup(1 λ ), σ ← Sign(m, w, x)] ≥ 1 - v(λ).

[0101] Simulatability, there exists a polynomial-time simulator and a negligible function v, such that for any PPT adversary cannot distinguish between the record Sim = (Simsetup, Simsign) obtained through simulation and the record obtained through the actual protocol:

[0102]

[0103] Here tp represents a trapdoor, which contains a simulator that can simulate the signature and its evidence w.

[0104] Extraction, there is a polynomial-time extractor, denoted as Ext, which can extract the witness w given the trapdoor tp and the simulated record number, and for a negligible function v, the following result can be obtained:

[0105]

[0106] (pp, tp) <- Simsetup(l λ ),

[0107] w <- (Ext (pp, tp, m, x, σ))] < v (l)

[0108] Here, Q S is the Simsign oracle list that lists all the successful queries of the attacker .

[0109] The algorithmic concepts in the embodiments of the present application are described above. In order to make the traceable encryption system provided by the embodiments of the present application operate normally, a system initialization process needs to be performed first. The process includes a global setup (CA setup) performed by a CA, a cloud setup, and an attribute authority setup, which are performed by the CA.

[0110] Please refer to Figure 2 , Figure 2 for a flowchart of the system initialization and user registration in the embodiments of the present application.

[0111] The CA performs the global setup:

[0112] In step 201, the CA generates a global parameter GP and a global secret key GSK according to a group G p .

[0113] The CA obtains a security strength parameter . According to the security strength parameter, the algorithm calls a group generator G p to generate a bilinear group of order p and generator g. A hash function H is determined. A symmetric encryption and decryption algorithm SEnc / SDec (with a key space of ) is determined, and a signature and signature verification algorithm (Sig / Ver) is determined. The above algorithms must be cryptographically secure algorithms.

[0114] The CA generates symmetric encryption keys k1 and k2, and the signature / verification key pair sk CA / vk CA ,in CA initializes an empty user traceability list Then, CA selects random numbers α, a, λ, And calculate: f=g τ , B=f a , Φ1=e(g, g) α , Φ2=e(g, g), and After the above calculations are completed, CA obtains the global parameters and the global private key GS = (α, a, λ, τ, k1, k2, k3, sk CA The global parameter GP can also be called the CA's global public key GPK. To simplify the description, GP is ignored as the default input in the formula in the following description. A detailed explanation is provided only when necessary.

[0115] In step 202, the CA sends the GP to the AA, the cloud server, and the terminal.

[0116] It should be noted that the CA does not need to send GP to the AA, cloud server, and terminal at the same time. For example, the CA can wait until the AA or cloud server sends a registration request to the CA before sending GP to the AA and cloud server. For the terminal, the AA can wait until the terminal sends a registration request to the AA before sending GP to the terminal.

[0117] CA performs cloud server key initialization:

[0118] In step 203, the CA generates a cloud server public key CPK and a private key CSK based on the GP.

[0119] CA selects random number Calculate X = g x The public key of the cloud server is CPK=X, and the private key of the cloud server is CSK=x.

[0120] In step 204, the CA sends the CPK and CSK to the cloud server.

[0121] CA performs attribute center initialization:

[0122] In step 205, the CA generates the attribute center's public key APK and private key ASK based on the GSK.

[0123] The algorithm requires the use of a global private key GSK = (α, a, λ, τ, k1, k2, sk CA) as input. For the i-th attribute center AA i , i , and computes Y i ′ = Y i a , and The public key APK and the private key ASK of the attribute center AA i are APK = (Y i , Y i , Z i , Z i ) and ASK = (β i , y i , τ) respectively.

[0124] In step 206, the CA sends APK and ASK to the AA.

[0125] The flow of user registration is described as follows.

[0126] User registration is divided into three steps. First, when a user joins the system, the user first registers with the CA (using the UserReg algorithm), obtains a global anonymous ID, a partial decryption key, and a user certificate. Then the attribute center AA verifies the user's certificate and generates an attribute key for the user. Finally, the user uses the obtained key to generate a proxy key (UserDKGen algorithm), which functions to help the cloud server to help the user to outsource decryption of data. The MSG message in the certificate issued by the CA to the user contains key association information.

[0127] In step 207, the terminal initiates a registration request to the CA.

[0128] In step 208, the CA generates a user anonymous identity pid, a global partial secret key USKp, and a user certificate UCert according to the GSK.

[0129] When a new user initiates registration with the CA, the CA allocates a globally unique user identity to the user and generates an anonymous identity for the user to help the user to achieve anonymity. Among them, is a random number, and the symbol "||" represents concatenation between elements. The CA selects random numbers r, r', θ2, and computes, D2' = H1(pid) r , D1" = g r′CA sets MSG = (msg1 = H1 (pid), msg2 = g r ). The user's global partial key is USK p =(D1, D1′, D1″, D2, D2′), the user’s certificate is CA in the retrospective list Add γ pid .

[0130] In step 209, CA sends pid, USK to AA. p and UCert.

[0131] In step 210, AA calculates the number of USKs according to pid. p Generate user key USK with UCert pid,S .

[0132] Assume that the attribute set of user (pid) is S=(attr1, ..., attr δ ). {AA1,…,AA δ Each attribute center in} first uses the CA's verification key vk CA Verify the user's certificate UCert to authenticate the user. If UCert fails the verification, the algorithm terminates. Otherwise, AA will generate attribute keys {usk1, ..., usk δ}. For example, the attribute center AA i Generate the i-th attribute key usk for the user i =(D 3,i , D 4,i ),in In this way, the user's complete key is USK pid , S =(USK p ,usk1,…,usk δ )=(D1, D1′, D1″, D2, D2′, {D 3,i , D 4,i} i∈{1,…,δ} ).

[0133] In step 211, the AA sends the USK to the terminal. pid,S and.

[0134] In step 212, the terminal pid,S Generate UDK agent key pid,S and decrypted token tk pid,S .

[0135] The terminal selects a random number and claims a proxy key UDK pid,S = (dk1, dk2, dk 2′ 3,i , dk 4,i} i∈{1,…,δ} , where dk2= D2, and the proxy key UDK pid,S will be sent to the cloud server for outsourcing decryption. The token tk pid,S = D5.

[0136] In step 213, the terminal sends the UDK pid,S to the cloud server.

[0137] The system initialization and user registration are described above, and the encryption method provided by the embodiments of the present application will be described below.

[0138] For the convenience of understanding, according to the above system initialization and user registration, some data corresponding to different devices are integrated below.

[0139] The authorization center CA: global parameter GP, global private key GSK.

[0140] The cloud server Cloud: public key CPK, private key CSK.

[0141] The attribute center AA: public key APK, private key ASK.

[0142] The first terminal: the account logged in by the first user, the first certificate UCert1 corresponding to the account of the first user, the first anonymous identity pid1, the first user identity uid1, the first user attribute secret key USK pid,S1 , and the first proxy key UDK pid,S1 .

[0143] The second terminal: the account logged in by the second user, the second certificate UCert2 corresponding to the account of the second user, the second anonymous identity pid2, the second user identity uid2, the first user attribute secret key USK pid,S2 , and the second proxy key UDK pid,S2 .

[0144] The registration process of the first user and the second user can refer to the user registration process in the foregoing Figure 2 , for example, UCert1 and UCert2 refer to UCert in the foregoing Figure 2 , uid1 and uid2 refer to uid in the foregoing Figure 2 . ​

[0145] After the first terminal uploads the CT to the cloud server, the CT can be normal or abnormal. In both cases, the second terminal can obtain the CT. The second terminal can obtain the CT through keyword subset query or without keyword subset query, which will be described below.

[0146] Please refer to Figure 3 , Figure 3 The flow chart of the second terminal not searching for the CT through the keyword subset in the embodiment of the present application.

[0147] Before uploading the file CT to the cloud server, the first terminal first extracts a search keyword subset from the file A keyword index is constructed for the CT. In order to realize fine-grained access control, the file owner needs to determine an access structure to encrypt the target plaintext M and its keyword subset KW. The output of the encryption algorithm is the ciphertext CT, the encrypted keyword index EI and a verifiable key VK, wherein the verification key VK is used to verify the correctness of the cloud part of the target ciphertext output by the Decryption out algorithm.

[0148] In step 301, the first terminal encrypts the target plaintext using the global public key GPK of the CA, the public key CPK of the cloud server and the attribute public key APK, and obtains the target ciphertext CT.

[0149] M is a file containing the target plaintext, is the keyword subset provided by the first terminal according to the file M. is the access structure of the file M, wherein is an l×n access matrix. ρ is a function that maps the column vector in to the attribute. A random number and a random vector Calculate and wherein is the xth row of the matrix .

[0150] Then, a random number is selected and the following is calculated:

[0151]

[0152] C1=g μ , C3=g s

[0153]

[0154]

[0155]

[0156] The target ciphertext CT of file M is obtained as follows:

[0157] CT=(C0,C1,C2,C3,{C 4,x , C 5,x , C 6,x} x∈[1,…,l] , C f )

[0158] In step 302, the first terminal f And a random number to obtain the verification key VK.

[0159] Choose a random number Γ∈ R G and calculate k f =H2(Γ), The verification key can be obtained by the following formula VK=H2(Γ||C f ).

[0160] In step 303, the first terminal obtains an encryption index EI according to the keyword subset KW of the target plaintext.

[0161] Construct a φ-degree polynomial (φ>n1):

[0162]

[0163] And satisfy is the n1 root of the equation Φ(x) = 1. Select a random number And calculate:

[0164]

[0165] The encryption index of KW is EI=({I 1,j} j∈{0,…,φ} , I2).

[0166] In step 304, the first terminal receives the information based on CT, EI, and USK. pid,S1 , st gets the zero-knowledge proof signature σ ZKP .

[0167] After encrypting the target plaintext M and obtaining the target ciphertext CT, the first terminal signs the ciphertext. To trace the creation and modification time of CT, the first terminal embeds a timestamp st in the signature.

[0168] In the signature algorithm, the first terminal (assuming its anonymous ID is pid1) generates a zero-knowledge proof signature σ ZKP As follows:

[0169]

[0170] Assuming the timestamp is st, and the ciphertext is CT. The first terminal uses the following calculation to construct a zero-knowledge signature σ ZKP Select random numbers u1, u1', u2, And make the following calculations:

[0171]

[0172]

[0173]

[0174] ψ = H2(γ1, γ2, γ3, Φ4, Ψ1, Ψ2, Ψ3, CT, st)

[0175] χ1 = u1' - ψ·u1, χ2 = u2 - ψ·H2(γ pid )

[0176] Where "||" represents concatenation between elements. The signature algorithm Sign outputs σ ZKP = (γ1, γ2, γ3, Φ4, χ1, χ2, ψ, st).

[0177] In step 305, the first terminal sends CT, EI, VK and σ ZKP to the cloud server.

[0178] In step 306, the cloud server verifies whether σ ZKP is legal, if it is legal, then stores CT, VK and σ ZKP ; otherwise, it is rejected.

[0179] After the cloud server receives the signature σ ZKP , CT and st sent by the first terminal, it performs the following calculations:

[0180]

[0181]

[0182] If ψ = H2(γ1, γ2, γ3, Φ4, Ψ1', Ψ2', Ψ3', CT, st) holds, then σ ZKP is legal, and the cloud server stores CT, VK, σ ZKPOtherwise, CT, VK and σ ZKP will be rejected by the cloud server, i.e. the cloud server will not help the first terminal to store CT. In the following, we will take the case that σ ZKP is legal as an example to describe the related contents.

[0183] In step 307, the second terminal requests CT from the cloud server.

[0184] In step 308, the cloud server uses UDK pid,S2 to decrypt CT, and gets CT out .

[0185] The cloud server uses UDK pid,S2 to decrypt CT, and gets the partially decrypted target ciphertext CT out . In order to realize lightweight data decryption on the second terminal, the cloud server uses the proxy key UDK pid,S2 of the second user, and uses the Decrypt out algorithm to generate the completed partially decrypted target ciphertext CT out . Then, the second terminal uses the verification key VK to confirm the correctness of the partially decrypted ciphertext CT out , and uses the Decrypt U algorithm to obtain the plaintext.

[0186] For a given ciphertext CT and the proxy key UDK pid,S2 of the second user, the cloud server selects a constant set satisfying and performs the following decryption operation:

[0187]

[0188]

[0189] The partially decrypted target ciphertext is CT out = (C0, ct1, ct2, ct3, C f ).

[0190] In step 309, the cloud server sends CT out and VK to the second terminal.

[0191] In step 310, the second terminal uses VK to verify whether CT out is correct, and if so, uses tk pid,S2 to decrypt CT out and obtains the target plaintext M.

[0192] Given a partially decrypted target ciphertext CT out, the verification key VK and the user's decryption token tk pid,S2 = D5. The second terminal computes and verifies whether the equation H2(Γ' || C f ) = VK holds. If not, it outputs "⊥" indicating that CT out is incorrect. Otherwise, the second terminal decrypts CT to obtain the target plaintext where k f = H2(Γ').

[0193] The above describes the process of the second terminal obtaining CT by keyword subset search. The process of the second terminal obtaining CT by keyword subset search is described as follows. Figure 4 , Figure 4 is a flowchart of the process of the second terminal obtaining CT by keyword subset search in the embodiment of the present application.

[0194] In step 306, the cloud server verifies whether σ ZKP is legal, and if so, stores CT, VK and σ ZKP ; otherwise, it is rejected.

[0195] The above describes steps 301-306 in the above Figure 3 .

[0196] In step 401, the second terminal constructs a trapdoor TW according to the keyword subset QE and the second user attribute key USK pid,S2 .

[0197] Suppose that the user key associated with the attribute set is USK pid,S , S = (attr1,..., attr δ ). The user gives a search keyword subset and constructs a trapdoor TW = (T0, {T 1,j} j={0,…,φ} , {T 2,i , T 3,i} i∈{1,…,δ} , Φ0) as follows:

[0198]

[0199]

[0200]

[0201] where φ is the degree of the polynomial lΦ(x) (constructed in the encryption algorithm Encryption).

[0202] In step 402, the second terminal sends TW to the cloud server.

[0203] In step 403, the cloud server determines whether CT, TW, EI, the private key CSK of the cloud server satisfy the second condition.

[0204] Given a ciphertext CT, an encryption index EI, a trapdoor TW and a cloud server private key CSK, the cloud server tests whether the following equation holds:

[0205]

[0206] If it holds, the cloud server outputs 1, indicating that and S (an access policy associated with TW) satisfies the access control policy (the access control policy of CT, EI). Otherwise, it outputs 0. When the cloud server outputs 1, it indicates that CT, TW, EI, the private key CSK of the cloud server satisfy the second condition, the target plaintext M meets the search condition of the second terminal, and the second terminal also has the permission to obtain CT.

[0207] In step 307, the second terminal requests CT from the cloud server.

[0208] Continuing the description of steps 307-310 in the above Figure 3 .

[0209] The above describes the process of the second terminal obtaining CT in the embodiment of the application. The process of the CA tracing the source of CT when CT is abnormal is described below.

[0210] Please refer to Figure 5 , Figure 5 for the flowchart of tracing the source of CT in the embodiment of the application.

[0211] In step 306, the cloud server verifies whether σ ZKP is legal. If it is legal, it stores CT, VK and σ ZKP ; otherwise, it rejects.

[0212] Continuing the description of steps 301-306 in the above Figure 3 .

[0213] In step 501, the second terminal determines whether CT is abnormal.

[0214] The cloud server can receive a report from a terminal that has obtained CT, and determine whether CT is abnormal according to the report of the terminal on CT. The terminal may, for example, be the second terminal in the above Figure 3 .

[0215] In step 502, the second terminal sends CT and σZKP .

[0216] If the cloud server determines that CT is abnormal, the cloud server sends CT and σ to the CA ZKP .

[0217] In step 503, the CA uses CT, GSK, σ ZKP to trace the source of CT to obtain the first user identity uid1.

[0218] After the cloud server receives CT and σ ZKP , the CA traces the identity of the first user through the data source tracing algorithm SourceTrace. It is mentioned above that the signature σ ZKP contains elements and In the user registration UserReg algorithm, the CA stores γ in the file pid . The CA queries γ that satisfies the following condition in pid :

[0219]

[0220] Then, the first user identity uid1 is obtained through and .

[0221] The above describes the process of tracing the source of CT. In actual application, the user attribute private key of a certain user may be leaked. In the attribute-based key encryption ABKS (CP-ABKS) system of the ciphertext access policy, the privilege of file searching and decryption is shared among a group of users, rather than being associated with a single user. Therefore, in this case, it is difficult to trace the malicious user who intentionally leaks the password. For example, a user named Jack has an attribute set "Huawe Corp. engineer", and another user named Tom has the same attribute set. Both users have the privilege of searching and decrypting a document with an access policy of (Huawe Corp. AND engineer). If one of the engineers leaks his user attribute key through the black market, it is difficult to trace which engineer leaked the key in the existing system. CP-ABKS is designed for the scenario of single user encryption and multiple user decryption. The file owner (for example, the first terminal in the embodiments of the present application) does not know which users can decrypt when encrypting. This feature increases the difficulty encountered by CP-ABKS in tracing malicious users. Therefore, the traceable encryption system provided in the present application can trace the identity of the user who leaks the user attribute private key.

[0222] Please refer to Figure 6 , Figure 6Flow chart of tracing user identity by user attribute private key in the embodiments of the present application.

[0223] If a user attribute private key is compromised, the DABE algorithm of the present application can trace to which user the attribute private key is compromised. The tracing of the attribute private key compromise includes two algorithms, one is the key sanity check algorithm KeySanityCheck, i.e. whether the user attribute private key is legal. If the user attribute private key is legal, the CA can obtain the information of the key compromise by using the TraitorTrace algorithm. The above algorithms are lightweight and do not need complex repeated encryption operations.

[0224] In step 601, the CA obtains the compromised USK pid,S .

[0225] In step 602, the CA verifies whether the USK pid,S is legal.

[0226] Key sanity check Suppose the attribute private key of a user is USK pid,S , and the attribute set associated with the attribute private key is S=(attr1,..., attr δ ). The key sanity check includes two steps. First, the CA checks whether the form of USK pid,S is consistent with the following form USK pid,S =(D1, D1', D1", D2, D2', {D 3,i , D 4,i} i∈{1,…,δ} ), wherein D1, D1', D1", D2', D 3,i , and Then, the CA checks whether the following equation is correct:

[0227]

[0228]

[0229] If the USK pid,S passes the key sanity check, output 1. Otherwise, output 0.

[0230] In step 603, if the USK pid,S is legal, the CA obtains the uid by using the USK pid,S and the GSK.

[0231] Traitor trace: if the key sanity check does not pass (output is 0), the algorithm terminates. Otherwise, the CA calculates and Thus, the identity of the attribute private key leaker is found.

[0232] After knowing the identity of the attribute private key leaker, an important issue is how to recover the search and decryption privilege related to the attribute private key. The user attribute private key contains an element which contains the identity of the user. This element, as part of the proxy key dk2=D2, must be uploaded to the cloud server. The CA will put it into the attribute private key recovery list, which is signed by the CA and stored on the cloud server, to realize the attribute private key revocation.

[0233] As can be seen from the above description, the traceable encryption system in the present application can effectively trace the data owner (for example, the first terminal) and the data user (for example, the second terminal), wherein the data owner or the data user adopts a distributed attribute encryption and decryption algorithm to encrypt and decrypt data. The system supports fine-grained anonymous access control and double traceability. The technology provided in the present application can be applied in the fields of cloud computing, identity management, Internet of Things, etc., and the keyword subset search algorithm can help users search encrypted data stored on the cloud or remote service in ciphertext.

[0234] Although traceable ABE algorithms already exist, the existing algorithms are all based on a single attribute center. It is not a simple work to extend the traceability algorithm of the malicious attribute key leaker from a single attribute center to multiple attribute centers, and the main reasons are as follows. In a distributed ABE (DABE) system, the attribute private key of a user is generated by multiple attribute centers (AAs) rather than a single AA. These attribute centers (AAs) are independent of each other, so the attribute private keys of the user (generated by different AAs) are not associated with each other. The traceability of the malicious attribute key leaker requires a trusted party to reveal the identity of the malicious user according to the leaked attribute private key. Since the functions of these distributed attribute centers are the same, it is unreasonable to require one of the attribute centers to act as a trusted third party. Therefore, the present application sets up a separate CA as a trusted third party. However, this method is also difficult. For the existing DABE algorithm, the CA is responsible for establishing the entire system and generating a public-private key pair for each attribute center AA, and the CA does not participate in the generation of the attribute private key of the user. However, the traceability of the malicious attribute key leaker requires the trusted third party to participate in the generation process of the attribute private key and implant a backdoor in the attribute private key of the user. Therefore, the present application redesigns the structure of DABE to add traceability: the CA participates in the generation process of the attribute private key of the user, but an attribute center AA generates the attribute private key for the user. Another challenge is to establish the association between the attribute private keys generated by different AAs, so that they can cooperate in the process of data decryption.

[0235] Regarding the keyword subset search, the traceable system in the present application divides the user's attribute key generation algorithm into two algorithms: user registration and attribute key generation. In the user registration process, the CA generates a part of the key for a registered user, a user certificate, which contains a link element that establishes a necessary association between the user's attribute key and the CA-generated part. The backdoor of the user's identity (used to trace the user) is hidden in the CA-generated part of the key. In the subsequent algorithm, each attribute center confirms the legitimacy of the link element by verifying the user's certificate, and then generates an attribute key for the user. The algorithm for malicious key leakage user tracing is a lightweight algorithm. At the same time, the key recovery algorithm does not participate in the key calculation.

[0236] In the traceable system in the present application, before the ciphertext is uploaded to the cloud server, a data provider needs to generate a signature based on zero-knowledge proof (Zero Knowledge Proof (ZKP)) for the encrypted file as unforgeable and undeniable evidence of the creation or modification of the uploaded file. The attribute of the zero-knowledge proof is used to protect the identity privacy of the data uploading user. The cloud server only accepts the data after the ZKP signature of the encrypted data is verified. Under normal circumstances, the identity of the user is guaranteed to be anonymous. However, when the file is problematic, the CA can trace which user uploaded the malicious file.

[0237] In some cases, the data provider may want to further control access to encrypted data, for example, only allow a specific user to access an encrypted file. Therefore, only the specified user can decrypt the data. An example is that the data owner places a secret contract on the identity management platform, allowing only a specified device or user to access the contract. This is a kind of one-to-one access control. To solve the above-mentioned needs, in the embodiments of the present application, the initialization and user registration process of the system described above Figure 3 , and part of the encryption and decryption content can be modified to realize one-to-one access control. Since the content of this part and the content of the foregoing Figures 2-6 may have a lot of repetition, for the convenience of description, the content not described below can refer to the related description in the foregoing Figures 2-6 .

[0238] System initialization includes authorization center initialization, cloud server key initialization and attribute center initialization.

[0239] Authorization center initialization:

[0240] The CA obtains a security strength parameter The initialization algorithm calls the group generator G p to generate a bilinear group of order p The generator is g. Determine the hash function CA determines symmetric encryption and decryption algorithm SEnc / SDec (key space is , determine the signature and signature verification algorithm (Sig / Ver), the above algorithm must be a secure algorithm in the sense of cryptography.

[0241] CA generates three keys k1, k2, for symmetric encryption and decryption algorithm. CA generates a pair of signature / verification key pair sk CA / vk CA , wherein CA initializes a user tracking list Then, generate a random number a, a, l, And calculate g1=g α , f=g τ , B=f a , Phi1=e(g, g) α , Phi2=e(g, g), The global parameter is defined as The global private key is defined as GSK=(a, a, l, t, k1, k2, k3, sk CA ).

[0242] Cloud server key initialization and attribute center initialization are similar to the description in the foregoing Figure 2 .

[0243] The content of user registration is described below. The steps of user registration are similar to the description in the foregoing

[0244] CA generates a user anonymous identity pid, a global partial secret key USKp and a user certificate Ucert according to GSK.

[0245] When a user initiates registration, CA generates a globally unique user identity for the user and generates an anonymous identity for the user, wherein is a random number, and “||” indicates element concatenation. CA selects random numbers r, r′, θ2, θ3, And calculate D2′=H1(pid) r , D1″=g r′ CA obtains MSG by calculation = (msg1 = H1 (pid), msg2 = g r ). CA generates a partial private key USK for the user p =(r uid , D0, D1, D1′, D1″, D2, D2′) and certificates Afterwards, CA Add γ pid .

[0246] AA according to pid, USK p Generate user key USK with UCert pid,S .

[0247] Assume that the attribute set of user (pid) is S=(attr1, ..., attr δ ). {AA1,…,AA δ Each attribute center in} first uses the CA's verification key vk CA Verify the user's certificate UCert to authenticate the user. If UCert fails the verification, the algorithm terminates. Otherwise, these attribute centers will generate attribute keys {usk1, ..., usk δ}. For example, the attribute center AA i Generate the i-th attribute key usk for the user i =(D 3,i , D 4,i ),in In this way, the user's complete key USK pid,S =(USK p ,usk1,…,usk δ )=(r uid ,D0,D1,D′1,D″1,D2,D′2,{D 3,i ,D 4,i} i∈{1,…,δ} ).

[0248] User agent secret key, decrypted token tk pid , SThe generation is similar to the description in the foregoing Figure 2 .

[0249] The above describes the system initialization and user registration, and the following describes the content of data encryption.

[0250] Before uploading the target ciphertext CT to the cloud server, the first terminal first extracts a search keyword subset KW from the target plaintext M A keyword index is constructed for the target plaintext M. In order to realize fine-grained access control, the first terminal needs to determine an access structure to encrypt the target plaintext M and the keyword subset KW. The output of the encryption algorithm is the ciphertext CT, the encrypted keyword index EI and a verifiable key VK, wherein the verification key VK is used to verify the correctness of the cloud server part of the target ciphertext output by the Decryption out algorithm.

[0251] M is a file containing a target plaintext, KW is a keyword subset provided by the file owner according to the file M. is an access structure of the file M, wherein is an l*n access matrix, and p is a function that maps the column vector in to an attribute. A random number and a random vector are selected. and wherein is the xth row of the matrix . A random number R G is selected and k f = H2(Γ) is calculated, The verification key can be obtained by the formula VK = H2(Γ||C f ).

[0252] Then, a random number is selected and the following is calculated:

[0253]

[0254] C1 = g μ , C3 = g s

[0255]

[0256]

[0257]

[0258] For a user with identity uid2, select a random number and compute:

[0259] C2' = e(g, g) s′

[0260] The ciphertext of file M is:

[0261] CT = (C0, C1, C2, C3, {C 4,x , C 5,x , C 6,x ) x∈[1,…,l] , C f )

[0262] CT' = (C0', C1', C2', C3, C f ).

[0263] Next, the second terminal constructs an encrypted index EI according to the search keyword subset corresponding to the target ciphertext .

[0264] Construct a Cφ-degree polynomial (φ > n1)

[0265]

[0266] and satisfy are n1 roots of the equation Φ(x) = 1.

[0267] Next, select a random number and compute:

[0268]

[0269] The encrypted index of KW is EI = ({I 1,j} j∈{0,…,φ} , I2).

[0270] The above describes data encryption, and the following describes data decryption.

[0271] In order to achieve lightweight data decryption on the second terminal, the cloud server uses the proxy key UDK of the second user pid,S2 , uses the Decrypt out algorithm to generate a partially decrypted target ciphertext CT out . Then, the second terminal uses the verification key VK to confirm the correctness of the partially decrypted target ciphertext CT out , and uses the Decrypt U algorithm to obtain the target plaintext.

[0272] Proxy decryption algorithm: Given a ciphertext CT and a user's proxy key UDK pid,S , the cloud server picks a constant set satisfying and performs the following decryption operation:

[0273]

[0274]

[0275] The partially decrypted ciphertext is CT out = (ct1, ct2, ct3, C f )

[0276] User decryption algorithm: Given a partially decrypted target ciphertext CT out , the verification key VK and the second user's decryption token tk pid,S = D5, the second terminal computes and verifies whether the equation H2(Γ' || C f ) = VK holds. If not, it outputs "⊥", indicating that CT out is incorrect. Otherwise, the second terminal decrypts the ciphertext to obtain the plaintext where k f = H2(Γ').

[0277] To support single user decryption, the present application designs the following algorithm:

[0278] SpecificDecrypt U (CT', VK, UDK pid,S2 ) → M / ⊥: Given a ciphertext CT', the verification key VK and the user's proxy key UDK pid,S2 , the cloud server computes and verifies whether the equation H2(Γ' || C f ) = VK holds. If not, it outputs "⊥", indicating that the second terminal has no access to CT. Otherwise, the second terminal decrypts CT out and obtains where k f = H2(Γ').

[0279] The above describes the traceable encryption system and method in the embodiments of the present application. The traceable encryption device in the embodiments of the present application is described below.

[0280] Please refer to Figure 7 , Figure 7 for a structural schematic diagram of the traceable encryption device in the embodiments of the present application.

[0281] The apparatus comprises:

[0282] The encryption module 701 is configured to encrypt the target plaintext by using a global public key GPK of an authorization center CA, a cloud server public key CPK and an attribute public key APK, to obtain target ciphertext CT.

[0283] The processing module 702 is configured to obtain zero-knowledge proof signature σ pid,S1 and CT according to the first user attribute secret key USK ZKP .

[0284] The sending module 703 is configured to send CT and σ ZKP to the cloud server, wherein σ ZKP and CT are used for the CA to trace the source of CT by using σ ZKP .

[0285] The modules in the apparatus can perform the following partial or complete operations in addition to the operations.

[0286] In an optional manner, the processing module 702 is further configured to obtain verification key VK according to C f of CT and a random number;

[0287] The sending module 703 is further configured to send VK to the cloud server, wherein VK is used for the second terminal to decrypt CT pid,S2 according to VK and a second decryption token tk out , to obtain the target plaintext, wherein CT out is obtained by the server partially decrypting CT according to a second user agent secret key UDK pid,S2 of the second terminal.

[0288] In an optional manner, the processing module 702 is further configured to generate additional ciphertext CT' according to the target plaintext and a second user identity uid2;

[0289] The sending module 703 is further configured to send CT' to the cloud server, wherein CT' is used for the cloud server to determine whether CT', VK and UDK pid,S2 satisfy a first condition, and if the first condition is satisfied, it indicates that the second terminal satisfies a condition for obtaining CT.

[0290] In an optional manner, the processing module 702 is further configured to obtain encryption index EI according to a keyword subset KW of the target plaintext;

[0291] The sending module 703 is further configured to send EI to the cloud server, wherein EI is used for the cloud server to determine whether CT, a trapdoor TW, EI and a private key CSK of the cloud server satisfy a second condition, and if the second condition is satisfied, it indicates that the keyword subset QE belongs to KW, and the trapdoor TW is obtained by the second terminal according to QE and a second user attribute secret key USKpid,S2 Constructed.

[0292] See also Figure 8 , Figure 8 This is another structural diagram of the traceable encryption device in the embodiment of the present application.

[0293] The device includes:

[0294] Receiving module 801, configured to receive the target ciphertext CT and the zero-knowledge proof signature σ sent by the first terminal ZKP , where CT is obtained by the first terminal using the global public key GPK of the authorization center CA, the cloud server public key CPK and the public key APK in the attribute to encrypt the target plaintext, σ ZKP The first terminal uses the first user attribute key USK pid,S1 and CT obtained;

[0295] The sending module 802 is used to send CT and σ to CA if CT is abnormal. ZKP , σ ZKP and CT for CA using σ ZKP Trace the source of CT.

[0296] In an optional manner of the fifth aspect, the receiving module is further configured to receive a verification key VK sent by the first terminal;

[0297] The device also includes:

[0298] Decryption module, used for decrypting the second agent key UDK of the second terminal pid,S2 Partially decrypt CT to obtain the partially decrypted target ciphertext CT out ,

[0299] The sending module is also used to send CT to the second terminal out and VK, VK is the first terminal according to CT's C f And a random number is obtained, VK is used for the second terminal according to VK and the second decryption token tk pid,S2 CT out Decrypt and obtain the target plaintext.

[0300] In addition to executing the operations, the modules in the device may also execute some or all of the following operations.

[0301] In an optional manner, the device further includes:

[0302] Determination module, used to determine the additional ciphertext CT′, VK, UDK pid,S2 Whether the first condition is met, CT′ is generated by the first terminal based on CT and the second user identity uid2;

[0303] The determining module is further configured to determine that the second terminal satisfies the condition of obtaining the CT if the first condition is satisfied.

[0304] In an optional manner, the apparatus further includes:

[0305] The determining module is configured to determine whether the CT, the trapdoor TW, the encryption index EI, and the private key CSK of the cloud server satisfy a second condition.

[0306] The determining module is further configured to determine that the keyword subset QE belongs to the keyword subset KW and the TW is obtained by the second terminal according to the keyword subset QE and the second user attribute secret key USK if the second condition is satisfied. pid,S2 The trapdoor TW is constructed.

[0307] The traceable encryption apparatus in the embodiments of the present application is described above, and the traceable encryption device in the embodiments of the present application is described below.

[0308] Please refer to Figure 9 , Figure 9 for a structural schematic diagram of the traceable encryption device in the embodiments of the present application.

[0309] As Figure 9 shown, for ease of illustration, only parts related to the embodiments of the present application are shown, and specific technical details not disclosed are referred to the method or system part of the embodiments of the present application. The traceable encryption device can be any terminal device including a mobile phone, a tablet computer, a PDA (Personal Digital Assistant), a POS (Point of Sales), a vehicle-mounted computer, etc. Take the mobile phone as an example of the traceable encryption device:

[0310] Figure 9 A block diagram of part of the structure of the mobile phone related to the terminal provided by the embodiments of the present application is shown. As Figure 9 shown, the mobile phone includes: RF (Radio Frequency) circuit 910, memory 920, input unit 930, display unit 940, sensor 950, audio circuit 960, wireless fidelity module 970, processor 980, and power supply 990, etc. Those skilled in the art can understand Figure 9 that the structure of the mobile phone shown in the embodiments of the present application does not constitute a limitation on the mobile phone, and can include more or fewer components than shown, or combine certain components, or different arrangement of components.

[0311] The various constituent components of the mobile phone are specifically introduced below: Figure 9

[0312] ​The RF circuit 910 can be used for receiving and sending signals in the process of information or communication, in particular, receiving the downlink information from the base station and processing by the processor 980; in addition, sending the uplink data to the base station. Generally, the RF circuit 910 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF circuit 910 can also communicate with the network and other devices through wireless communication. The above-mentioned wireless communication can use any communication standard or protocol, including but not limited to global system for mobile communication (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), email, short message service (SMS), etc.

[0313] The memory 920 can be used to store software programs and modules, and the processor 980 can execute various function applications and data processing of the mobile phone by running the software programs and modules stored in the memory 920. The memory 920 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), etc.; the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory 920 can include a high-speed random access memory, and can also include a non-volatile memory, for example, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device.

[0314] The input unit 930 can be used to receive input digital or character information, and to generate key signal inputs used for user settings and function controls of the mobile phone. Specifically, the input unit 930 can include a touch panel 931 and other input devices 932. The touch panel 931, also called a touch screen, can collect touch operations (such as operations of a user using a finger, a stylus, or any suitable object or accessory on or near the touch panel 931) of the user on or near it, and drive the corresponding connection device according to the pre-set program. Optionally, the touch panel 931 can include two parts, a touch detection device and a touch controller. The touch detection device detects the touch position of the user and detects the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into touch coordinates, and sends it to the processor 980, and can also receive commands from the processor 980 and execute them. In addition, the touch panel 931 can be implemented in various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 931, the input unit 930 can also include other input devices 932. Specifically, the other input devices 932 can include one or more of a physical keyboard, function keys (such as volume control keys, on / off keys, etc.), trackballs, mice, joysticks, etc.

[0315] The display unit 940 can be used to display information input by the user or information provided to the user, as well as various menus of the mobile phone. The display unit 940 can include a display panel 941, which can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel 931 can cover the display panel 941, and when the touch panel 931 detects a touch operation on or near it, it transmits to the processor 980 to determine the type of touch event, and then the processor 980 provides corresponding visual output on the display panel 941 according to the type of touch event. Although in the Figure 9 , the touch panel 931 and the display panel 941 are implemented as two independent components to realize the input and output functions of the mobile phone, in some embodiments, the touch panel 931 and the display panel 941 can be integrated to realize the input and output functions of the mobile phone.

[0316] The phone can also include at least one sensor 950, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor can include an ambient light sensor to adjust the brightness of the display panel 941 according to the brightness of ambient light, and a proximity sensor to turn off the display panel 941 and / or the backlight when the phone is moved to the ear. As one of the motion sensors, the accelerometer sensor can detect the magnitude and direction of the acceleration in each direction (generally three axes), and when at rest, the magnitude and direction of the gravity, which can be used for identifying the phone posture application (such as switching between landscape and portrait screens, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), and the like. As for other sensors that can also be configured on the phone, such as a gyroscope, a barometer, a hygrometer, a thermometer, an infrared sensor, and the like, will not be described here.

[0317] The audio circuit 960, the speaker 961, and the microphone 962 can provide an audio interface between the user and the phone. The audio circuit 960 can convert the received audio data into an electrical signal, which is transmitted to the speaker 961 to be converted into a sound signal for output. On the other hand, the microphone 962 converts the collected sound signal into an electrical signal, which is received by the audio circuit 960 and converted into audio data. The audio data is output to the processor 980 for processing, and then transmitted to another phone via the RF circuit 910, or output to the memory 920 for further processing.

[0318] Wireless fidelity is a short-range wireless transmission technology. The phone can help users send and receive e-mails, browse web pages, and access streaming media through the wireless fidelity module 970, which provides users with wireless broadband Internet access. Although Figure 9 The wireless fidelity module 970 is shown, but it is understood that it is not a necessary component of the phone.

[0319] The processor 980 is the control center of the phone, which connects all parts of the phone through various interfaces and lines, and performs various functions and processes data of the phone by running or executing software programs and / or modules stored in the memory 920, and calling data stored in the memory 920, thereby monitoring the phone as a whole. Optionally, the processor 980 can include one or more processing units; preferably, the processor 980 can integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, and application programs, and the modem processor mainly processes wireless communication. It is understood that the above-mentioned modem processor can also not be integrated into the processor 980.

[0320] The mobile phone further includes a power supply 990 (such as a battery) for supplying power to various components, and preferably, the power supply is logically connected to the processor 980 through a power management system, so that the power management system can realize functions such as charge management, discharge management, and power consumption management.

[0321] Although not shown, the mobile phone can further include a camera, a Bluetooth module, and the like.

[0322] In the embodiment of the present application, the processor 980 of the mobile phone is specifically configured to encrypt a target plaintext using a global public key GPK of a certificate authority CA, a cloud server public key CPK, and an attribute public key APK to obtain a target ciphertext CT, and obtain a zero-knowledge proof signature σ pid,S1 and CT according to a first user attribute secret key USK ZKP ;

[0323] The RF circuit 910 is specifically configured to send the CT and σ ZKP to the cloud server, and σ ZKP and CT are used for the CA to trace the source of CT using σ ZKP .

[0324] In an optional manner, the processor 980 is further configured to obtain a verification key VK according to C f of the CT and a random number;

[0325] The RF circuit 910 is further configured to send the VK to the cloud server, and the VK is used for a second terminal to decrypt CT pid,S2 according to the VK and a second decryption token tk out , to obtain the target plaintext, wherein the CT out is obtained by the server according to partial decryption of a second user agent secret key UDK pid,S2 of the second terminal.

[0326] In an optional manner, the processor 980 is further configured to generate an additional ciphertext CT' according to the CT and a second user identity uid2;

[0327] The RF circuit 910 is further configured to send the CT' to the cloud server, and the CT' is used for the cloud server to determine whether the CT', the VK, and the UDK pid,S2 satisfy a first condition, and if the first condition is satisfied, it indicates that the second terminal satisfies a condition for obtaining the CT.

[0328] In an optional manner, the processor 980 is further configured to obtain an encryption index EI according to a keyword subset KW of the target plaintext;

[0329] The RF circuit 910 is further configured to send the EI to the cloud server, where the EI is used by the cloud server to determine the CT, the trapdoor TW, the EI, and a private key CSK of the cloud server whether to satisfy a second condition, and if the second condition is satisfied, it indicates that the keyword subset QE belongs to the KW, and the TW is determined by the second terminal according to the QE and a second user attribute secret key USK pid,S2 The construction is completed.

[0330] In the embodiments of the present application, the processor 980 included in the mobile phone can perform the functions in the above-mentioned embodiments, and details are not repeated here. Figure 2 Or Figure 3 The functions in the embodiments shown in the above-mentioned embodiments, and details are not repeated here.

[0331] Please refer to Figure 10 , Figure 10 Another structural diagram of the traceable encryption device in the embodiments of the present application.

[0332] As Figure 10 shown, the traceable encryption device 1000 includes a processor 1010 and a transceiver 1020 coupled to the processor 1010. The processor 1010 can be a central processing unit (CPU), a network processor (NP), or a combination of CPU and NP. The processor can also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above-mentioned PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 1010 can refer to one processor, or can include multiple processors.

[0333] The transceiver 1020 is configured to receive the target ciphertext CT and the zero-knowledge proof signature σ ZKP sent by the first terminal, where the CT is obtained by encrypting the target plaintext using the global public key GPK of the authorization center CA, the cloud server public key CPK and the attribute public key APK, and σ ZKP is obtained by the first terminal according to the first user attribute secret key USK pid,S1 and CT;

[0334] The processor 1010 is configured to determine whether the CT is abnormal;

[0335] The transceiver 1020 is further configured to send CT and σ to the CA if CT is abnormal. ZKP ,σ ZKP and CT for CA using σ ZKP Trace the source of CT.

[0336] The processor 1010 is further configured to execute the computer-readable instructions in the memory 1020 and, in accordance with the instructions of the computer-readable instructions, perform all or part of the operations that the cloud server can perform, such as the cloud server performing the following operations in conjunction with the computer-readable instructions: Figures 2-5 The operations performed in the corresponding embodiment.

[0337] In other embodiments, the traceable encryption device 1000 further includes a memory, which may include a volatile memory (volatile memory), such as a random-access memory (RAM); the memory 1020 may also include a non-volatile memory (non-volatile memory), such as a read-only memory (ROM), a FRAM memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); the memory may also include a combination of the above types of memory.

[0338] The following is a security proof of the traceable encryption system.

[0339] Theorem 1. If the bilinear Diffie-Hellman assumption holds, then the proposed traceable encryption system is secure.

[0340] Proof. Assume there is a PPT opponent To destroy the security of the system, we can construct a PPT algorithm C to destroy the decision bilinear Diffie-Hellman (DBDH) assumption. Obtain the given term from the decision bilinear Diffie-Hellman assumption in

[0341] Setting. Challenger To give Provide the system's global parameters GP and the cloud server's public key CPK. To implicitly set α = α′ + ab, where a and b are set in the DBDH assumption, is a randomly selected element. Then, Calculate Φ1 = e(g, g)α = e(g a , g b )e(g, g) α′ and generates a pair of signature / verification keys sk CA / vk CA . Randomly select λ, τ, k1, k2, Compute h = g λ , f = g τ , B = (g a ) τ = f a , Φ2 = e(g, g), Φ3 = e(g, h) / e(B, f), X = g x . Send global parameters GP = (g, h, f, B, Φ1, Φ2, Φ3, vk CA ) and public key CPK = X to

[0342] First stage. Adaptively issue the following queries.

[0343] (1) Receive an attribute authority attribute AA i key generation query. Challenger selects a random number y i , Computes Then, Send APK i = (Y i , Y i ', Z i , Z i ')a and private key ASK i = (β i , y i , τ) of AA i to

[0344] (2) Receive a user registration query (carrying user uid), Computes to be the user pseudonym, where Selects a random number θ2, Computes D'2 = H1(pid) τ , Selects v,​ Implicitly set r = v + b, r' = v' - bτ -1 H2(γ pid ). Then, Construction:

[0345]

[0346] g r = g v+b = g ν • (g b )

[0347]

[0348]

[0349] Set the certificate message to MSG = (msg1 = H1(pid), msg2 = g r ). The user's partial key USK p = (D1, D'1, D'1, D2, D'2) and the certificate are sent to

[0350] (3) On the premise that (pid, USK p , Ucert) are generated by , make a user key generation query for the attribute set S = (attr1,..., attr δ ). Upon receiving the query, use the CA's verification key keyvk CA to check the validity of Ucert. If it passes the test, construct usk i = (D 3,i , D 4,i ) for each attribute:

[0351]

[0352]

[0353] Then, return USK pid,S = (D1, D'1, D"1, D2, D'2, {D 3,i , D 4,i} i∈{1,…,δ} ) to

[0354] (4) A user delegates a key query on an attribute set S, Searches for an entry (S, USK pid,S , DK pid,S ) in a table T containing S without specifying pid. If such an entry exists, Return the delegation key DK pid,S to Otherwise, Generate a random global user identity uid and run the user registration oracle to obtain Also run the user key generation oracle to obtain Use USK pid,S and the UserDKGen algorithm to construct UDK pid,S . Then, insert the entry (S, USK pid,S , DK pid,S ) into T. Return UDK pid,S to Set D = D U S.

[0355] (5) Receive a trapdoor generation query on a set of keys for a user with identity uid, First run and to generate the user's key USK pid,S . Then, Select and construct:

[0356]

[0357]

[0358] Then, Return the trapdoor to

[0359] TW = (T0, {T 1,j} j={0,…,φ} , {T 2,i , T 3,i} i∈{1,…,δ} , Φ0).

[0360] Challenge. When decides to end phase 1, output an access policy Two sets of keys and two messages in, The restriction is that no query satisfies in phase 1 The key of the attribute set S.

[0361] Pick a random vector calculate in yes The xth row of choose choose represents i∈{1,…,l}. Then, Randomly select Γ0, Select random numbers ξ1, ξ2∈{0, 1}, and The ciphertext structure is:

[0362]

[0363]

[0364] Calculating the encryption key Ciphertext and verification key

[0365] Next, Need to generate keyword set Construct a φ-degree polynomial (φ>n1):

[0366]

[0367] Make is the equation Φ * (x) = 1. Then, select the n1 roots at random And calculate:

[0368]

[0369] Then, Towards Send challenge ciphertext Encrypted Index and verification key VK * .

[0370] Phase 2. Same as Phase 1. The restrictions are and S does not satisfy

[0371] Guess. ξ′1, ξ′2∈{0,1}. Output a guess. If ξ′1=ξ1, ξ′2=ξ2, then Output 1 means T = e(g, g) abs Otherwise, the output is 0, indicating that T is Random elements in .

[0372] Probability Analysis. Hypothesis It has an advantage in attacking the decision-making bilinear Diffie-Hellman assumption, while has an advantage ε′ in winning this game. Then, it is easy to know that ε′ = ε.

[0373] Theorem 2: When ∈′=∈, and Assumption) Under the above system For the traitor to be traceable, where q represents the total number of key queries, Indicates that in the group The running time of the power operation on , |S| is the number of attributes in S.

[0374] Proof. Assume there is a PPT opponent To break the traceability of the above system, we can construct a PPT algorithm To break the q-SDH assumption. Here is an example of a q-SDH problem: set up i∈{0, 1,…, q}.

[0375] set up. choose set up Expand f(x) to in are the coefficients of f(x). Then, the algorithm set up:

[0376]

[0377]

[0378] Randomly select α,a, Calculate f=g τ , B=f a , Φ1=e(g, g) αΦ2 = e(g, g), Φ3 = e(g, h) / e(B, f). A pair of symmetric keys k1, k2, k3 e K1, a pair of signature / verification keys sk CA / vk CA , and output global parameters GP = (g, h, f, B, Φ1, Φ2, Φ3, vk CA ).

[0379] Key query. To submit a tuple (uid i , S i = {attr i,1 ,..., attr i,δ}) for the i-th key query, where i < q. Set f i (x) = f(x) / (x + ζ i ). Set f i (x) = f(x) / (x + ζ i ), expand f i (x) as where are the coefficients of f i (x). Then, the algorithm C sets: Choose r, r', θ1, θ2, θ3, τ, Compute:

[0380]

[0381] D2 = ζ i , D'2 = H1(pid) τ

[0382] D"1 = g r′

[0383]

[0384] Output the key

[0385] Fake key. Output a challenge key Let ∈ A denote the event that the USK * passes the key check, while if ∈ A does not occur, Select a random tuple As a solution to the q-SDH problem. If ∈ A An event occurs, Will solve the q-SDH problem using USK * Because of the form of USK * It can be expressed as:

[0386]

[0387]

[0388]

[0389] Express f(x) as some Using long division Because And Cannot divide f(x) completely, so Will be expanded as Where Is the coefficient of

[0390] Calculate Also can be expressed as

[0391]

[0392] Set And calculate:

[0393]

[0394] Then, (c * , w * ) is a well-constructed solution to the q-SDH problem.

[0395] Probability analysis.

[0396] Let ∈ SDH Represent the event that (c * , w * ) is a solution to the q-SDH problem.

[0397]

[0398] Time analysis.​​

[0399] The execution time of the simulation is determined by the exponent and bilinear mapping operations of the query phase. Then The running time of is constrained by , where q represents the number of key queries, represents the running time of the power operation on the group , |S| is the number of attributes in the set S.

[0400] Theorem 3. σ ZKP in the algorithm symbol pid is the zero-knowledge secure proof of (γ pid,S , D'1, D"1), which proves the following statement:

[0401]

[0402] The completeness of ZKP is obvious, and we focus on the soundness, zero-knowledge, anonymity and traceability of the data source.

[0403] Correctness. When the equality is verified, the honest prover will generate an accepted signature:

[0404]

[0405]

[0406]

[0407] Then we have:

[0408]

[0409] The above equation verifies the correctness and integrity of the symbol and verification algorithm.

[0410] Simulation. Given GP, USK pid,S , CT, EI, st as input, use random oracle The signature σ ZKP can be simulated as follows.

[0411] Simulate random selection γ1, γ2, χ1, Calculate ψ_5=e(υ_2,g) / e(υ_3,b),Ψ5=e(γ2,g) / e(γ3,B),

[0412] Then set The resulting signatures are distributed identically to real ZKP signatures, assuming that the decision-making Diffie-Hellman problem is hard in G. The tuple (γ1, γ2, γ3) is indistinguishable from the real signature on (CT||EI).

[0413] Extraction. Suppose there exist two zero-knowledge proofs of knowledge signatures with the same (γ1, γ2, γ3, Φ4) ​​but different challenges (ψ′, ψ) and different responses (χ1, χ2) and (χ′1, χ′2).

[0414] Extract calculation:

[0415]

[0416]

[0417] Then (D′1, D″1) can be extracted by computing:

[0418]

[0419]

[0420] Anonymous. Due to the zero-knowledge nature of ZKP, the signature σ ZKP No information about the user key USK is disclosed pid,S The elements in (γ pid , D′1, D″1). In addition, u1, u 1′ , u2 is random, with γ pid Therefore, ZKP does not concatenate different signatures generated by the same user (with the identity uid and the pseudonym pid).

[0421] Traceability of data source. This can be easily derived from the SourceTrace algorithm. For a specific ZKP signature σ ZKP , CA directly tracks which users pass the checklist Is there an element γ in pid to generate it so that The user's uid can then be obtained from the gamma pid Recovery.

[0422] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely illustrative. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0423] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments.

[0424] In addition, each functional unit in the embodiments of the present application can be integrated in one processing unit, or each unit can exist physically as a separate unit, or two or more units can be integrated in one unit. The integrated unit can be implemented in the form of hardware, or in the form of software functional units.

[0425] When the integrated unit is implemented in the form of software functional units and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such an understanding, the technical solutions of the present application essentially, or the part that contributes to the prior art, or all or a part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: a flash disk, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk, and various other media that can store program codes.

Claims

1. A traceable encryption system, characterized by, Comprising: a first terminal, a cloud server, a plurality of attribute centers AA and an authorization center CA; The first terminal is configured to encrypt a target plaintext using a global public key GPK of CA, a cloud server public key CPK and an attribute center public key APK to obtain a target ciphertext CT, and to obtain a first user attribute secret key and the CT to obtain a zero-knowledge proof signature The first terminal is configured to encrypt a target plaintext using a global public key GPK of CA, a cloud server public key CPK and an attribute center public key APK to obtain a target ciphertext CT, and to obtain a first user attribute secret key , the cloud server sends the CT and the generated by at least one AA of the plurality of AAs according to a user anonymous identity pid; The cloud server is configured to receive the CT and the first terminal identifier sent by the first terminal, and send the CT and the first terminal identifier to the CA if the CT is normal. , and send the CT and the first terminal identifier to the CA if the CT is abnormal. ; The CA is configured to receive the CT and the , trace the origin of the CT using the .

2. The system of claim 1, wherein, The system further comprises a second terminal; The first terminal is further configured to receive a C signal from the CT. f and a random number to obtain a verification key VK, and send the VK to the cloud server; The cloud server is further configured to receive the VK sent by the first terminal, and send the VK and the second proxy key of the second terminal to the second terminal according to the second proxy key of the second terminal Partially decrypt the CT to obtain a partially decrypted target ciphertext , and send the partially decrypted target ciphertext to the second terminal and the VK to the second terminal. The second terminal is used to decrypt the token according to the VK and the second Regarding the Decryption is performed to obtain the target plaintext.

3. The system of claim 2, wherein, The first terminal is further configured to generate additional cryptographic data based on the CT and a second user identity uid2 , and send the to the cloud server. The cloud server is also used to determine the , the VK, the Whether a first condition is met, if the first condition is met, determining that the second terminal meets a condition for obtaining the CT.

4. The system of any one of claims 1 to 3, wherein, The CA is also used to check the legality of the If the legality is checked, the first user identity uid1 is obtained according to the global private key GSK of the CA and the first user identity uid1.​ 5. The system of any one of claims 2 to 3, wherein, The first terminal is further configured to obtain an encryption index EI according to a keyword subset KW of the target plaintext, and send the EI to the cloud server. The second terminal is also configured to acquire a keyword subset QE, and construct a trap TW according to the QE and a second user attribute secret key The second terminal is also configured to acquire a keyword subset QE, and construct a trap TW according to the QE and a second user attribute secret key The cloud server is further configured to determine whether the CT, the TW, the EI and a private key CSK of the cloud server satisfy a second condition, and if the second condition is satisfied, determine that the QE belongs to the KW.

6. A traceable encryption method characterized by, Comprising: The first terminal encrypts a target plaintext using a global public key GPK of an authorization center CA, a cloud server public key CPK and an attribute center public key APK to obtain a target ciphertext CT; The first terminal generates a zero-knowledge proof signature according to the first user attribute key and the CT , the generated by at least one of a plurality of attribute centers AA according to the user anonymous identity pid The first terminal sends the CT and the , the and the CT are used by the CA to trace the origin of the CT.

7. The method of claim 6, wherein, The first terminal derives a verification key VK from the C f and a random number. The first terminal sends the VK to the cloud server, the VK being used by a second terminal to decrypt the CT according to the VK and a second decryption token to obtain the target plaintext, the CT being partially decrypted by the server according to a second user agent secret key of the second terminal ​​​ 8. The method of claim 7, wherein, The first terminal generates additional cryptographic text according to the CT and a second user identity uid2 ; The first terminal sends the cloud server the , the for the cloud server to determine the , the VK, the whether a first condition is met, and if the first condition is met, it indicates that the second terminal meets the condition for obtaining the CT.

9. The method of any one of claims 7 to 8, wherein, The first terminal obtains an encryption index EI according to a keyword subset KW of the target plaintext. The first terminal sends the EI to the cloud server, the EI is used for the cloud server to determine the CT, the TW, the EI, and whether the private key CSK of the cloud server satisfies a second condition, if the second condition is satisfied, it indicates that the keyword subset QE belongs to the KW, and the TW is generated by the second terminal according to the QE and a second user attribute key constructed.

10. A traceable encryption device, characterized by Comprising: An encryption module configured to encrypt a target plaintext using a global public key GPK of an authorization center CA, a cloud server public key CPK and an attribute center public key APK to obtain a target ciphertext CT; The processing module is configured to generate a first user attribute key according to the first user attribute key and the CT obtains a zero-knowledge proof signature , the generated by at least one of a plurality of attribute centers AA according to the user anonymous identity pid; The sending module is configured to send the CT and the CA to a cloud server. The cloud server is configured to trace the source of the CT. The cloud server is configured to trace the source of the CT. The cloud server is configured to trace the source of the CT.

11. The apparatus of claim 10, wherein, The processing module is further configured to obtain a verification key VK according to the CT and a random number. f and a random number. The sending module is further used to send the VK to the cloud server, and the VK is used by the second terminal to decrypt the VK according to the VK and the second decryption token. right Decrypt to obtain the target plaintext, the The server is based on the second user agent key of the second terminal Obtained by partially decrypting the CT.

12. The apparatus of claim 11, wherein, The processing module is further configured to generate an additional cryptogram based on the CT and a second user identity uid2 ; The sending module is further configured to send the cloud server with the , the for the cloud server to determine whether the , the VK, the satisfy a first condition, and if the first condition is satisfied, it indicates that the second terminal satisfies the condition of obtaining the CT.

13. The apparatus of any one of claims 11 to 12, wherein, The processing module is further configured to obtain an encryption index EI according to a keyword subset KW of the target plaintext. The sending module is further configured to send the EI to the cloud server, where the EI is used by the cloud server to determine whether the CT, the TW, the EI, and a private key CSK of the cloud server satisfy a second condition, and if the second condition is satisfied, it indicates that the keyword subset QE belongs to the KW, and the TW is calculated by the second terminal according to the QE and a second user attribute key constructed.

14. A traceable cryptographic device, characterized in that Comprising a processor and a transceiver, The processor is configured to encrypt a target plaintext using a global public key GPK of a certification authority CA, a cloud server public key CPK and an attribute center public key APK to obtain a target ciphertext CT, and to obtain a zero-knowledge proof signature based on a first user attribute secret key and the CT The zero-knowledge proof signature is generated by at least one attribute center AA in a plurality of attribute centers AA according to a user anonymous identity pid. The transceiver is configured to transmit the CT and the , the and the CT are configured to trace the origin of the CT by the CA using the .

15. A computer storage medium, comprising, The computer storage medium has stored therein instructions, which, when executed on a computer, cause the computer to perform the method of any one of claims 6 to 9.

16. A computer program product, characterised in that, The computer program product, when executed on a computer, causes the computer to perform the method of any one of claims 6 to 9.

Citation Information

Patent Citations

  • Key escrow-free secure multi-keyword sorting and searching system

    CN108632032A

  • Data security traceability and access control system under cloud computing framework

    CN111327620A