A mandatory access control method based on attributes

By presetting conversion nodes and level nodes in the access tree, the problem that existing CP-ABE solutions cannot encrypt multiple different secret files is solved, and the function of encrypting multiple different secret files in one access tree is realized, ensuring the security of cloud encrypted ciphertexts.

CN114357469BActive Publication Date: 2025-06-06SICHUAN NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110466549.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-04-28
Publication Date
2025-06-06
Estimated Expiration
2041-04-28

AI Technical Summary

Technical Problem

The existing CP-ABE scheme can only encrypt one file in one access tree, and cannot implement the function of encrypting multiple different secret files.

Method used

The authorized organization calculates the system public key and master key, obtains the data consumer private key, and presets the conversion node and level node in the access tree to realize the encryption of multiple different secret files.

Benefits of technology

Encryption of multiple different encryption files is implemented in an access tree, suitable for sharing and storage of cloud-encrypted ciphertexts, ensuring the security of data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114357469B_ABST
    Figure CN114357469B_ABST
Patent Text Reader

Abstract

The present invention discloses a mandatory access control method based on attributes, in which a data consumer device defines an access tree according to the number of files to be encrypted, information of the files to be encrypted and the confidentiality level of each file to be encrypted, and pre-sets conversion nodes in the access tree to realize the conversion of different data consumer attribute sets, and completes the encryption of multiple files to be encrypted with different confidentiality levels on the same access tree by pre-setting level nodes, which is suitable for sharing and storing encrypted ciphertexts of various clouds; after the data consumer device downloads the encrypted ciphertext, when the attributes of the data consumer meet the structure of the access tree and the security level of the data consumer is greater than or equal to the confidentiality level of the encrypted ciphertext, the downloaded encrypted ciphertext is decrypted by the data consumer private key obtained from the authorization agency, thereby ensuring the access security of the cloud encrypted ciphertext, and by introducing the data consumer attribute set, the data consumer private key obtained by the data consumer device has a hierarchical structure and is more universal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data access, and in particular to an attribute-based mandatory access control method. Background Art

[0002] The development of cloud computing has brought convenience to people. People do not need to buy hardware resources, but rent remote resources to achieve the purpose of storing a large amount of data consumer data. However, in order to protect the privacy of data, data consumers need to encrypt data before uploading it to the public cloud. In order to securely store and share encrypted ciphertext, access control of data in the public cloud has been fully studied in recent years. Attribute-based encryption (ABE) is considered to be an effective solution, which can achieve fine-grained access control of data and flexible data sharing. ABE can be divided into key policy-based attribute encryption (KP-ABE) and encrypted ciphertext policy-based attribute encryption (CP-ABE), and its access structure is hidden in the key and encrypted ciphertext respectively. The KP-ABE solution is suitable for applications in pay TV, video on demand and other systems. The CP-ABE solution is suitable for access control services, such as electronic medical health record access, social networking site access and other systems, that is, CP-ABE is more suitable for use in the encrypted ciphertext storage and sharing environment of the public cloud.

[0003] However, in many scenarios, some files may have different confidentiality levels, and data consumers are also divided into different security levels. Only data consumers with matching levels can decrypt the files, and when access control is performed on a certain file, its corresponding access tree may be a subtree of another file, or its subtree may be an access tree of another file. For example, in an enterprise or organization, some important files / documents are encrypted by attributes and shared by multiple data consumers, but these files stipulate that some data consumers can decrypt while some data consumers cannot. In other words, data consumers with the same attributes may have different security levels. High-security-level data consumers can decrypt low-security-level files, and vice versa. The current CP-ABE scheme can only encrypt one file in one access tree, but cannot encrypt multiple files of different confidentiality levels. Summary of the invention

[0004] The technical problem to be solved by the present invention is that the current CP-ABE scheme can only realize the function of encrypting one file in one access tree, but cannot realize the function of encrypting multiple files of different confidentiality levels. Therefore, the present invention provides an attribute-based mandatory access control method to realize the function of encrypting multiple files of different confidentiality levels in one access tree.

[0005] The present invention is achieved through the following technical solutions:

[0006] A mandatory access control method based on attributes, comprising:

[0007] The authorization agency obtains the system public key and the system master key by calculating the system initialization parameters, and obtains the data consumer identity information and the data consumer attribute set from the data consumer device; calculates the data consumer private key corresponding to each data consumer identity information based on the system public key, the system master key and the data consumer attribute set; sends the system public key to the data owner device, and sends the corresponding data consumer private key to the corresponding data consumer device according to the data consumer identity information;

[0008] The data owner device obtains the system public key from the authorization agency, and defines an access tree according to the number of files to be encrypted, information of the files to be encrypted, and the confidentiality level of each file to be encrypted; based on the access tree, the files to be encrypted are encrypted using the system public key to obtain encrypted ciphertext and send it to the cloud service provider for storage;

[0009] The data consumer device downloads the encrypted ciphertext from the cloud service provider and obtains the data consumer security level from the data consumer identity information. When the data consumer security level is greater than or equal to the level of the encrypted ciphertext in the access tree and the attributes of the data consumer device meet the structure of the access tree, the encrypted ciphertext is decrypted by using the obtained data consumer private key to obtain the decrypted plaintext, otherwise it cannot be decrypted.

[0010] Furthermore, the system initialization parameters include a hash function H, a bilinear map e, a group G 0 and the group G 0 Generator g, p-order prime field Z p ;

[0011] The calculation process of the system public key is specifically as follows: based on the system initialization parameters, from Z p Choose a random number α from β i and θ i , where β i where i=[1,…,n], θ i where i = [1, ..., n-1], n represents the maximum security level of the data consumer or the level of the encrypted file; based on the random number α, β i and θ i ,pass e(g,g) α Calculate the system public key sub-item, and obtain the system public key according to the system initialization parameters and the calculated system public key sub-item. The system public key PK is

[0012] The system master key calculation process is specifically as follows: based on the system initialization parameters, the system master key sub-item g is calculated. α , and according to Z p The random number selected in β i and θ i , get the system master key, the system master key MSK is

[0013] Furthermore, the data consumer identity information includes a data consumer identifier and a data consumer security level; the data consumer attribute set S includes multiple sub-attribute sets, each of which includes an external sub-attribute set S 0 and multiple internal sub-attribute sets S i , where i = [1,…,m], m represents the number of internal sub-attribute sets;

[0014] The calculating the data consumer private key corresponding to each data consumer identity information based on the system public key, the system master key and the data consumer attribute set includes:

[0015] According to the data consumer security level j and data consumer identification, from Z p Randomly select j random numbers as the data consumer security level identifier group r <t>< / t> =(r <1> ,…,r <j>< / j> ), where Z p represents the prime field of order p;

[0016] Get the system public key sub-item group from the system public key PK Get the system master key sub-item g from the system master key MSK α , and based on the system public key PK, the system master key MSK and the data consumer security level identifier group r <t>< / t> Calculate the non-attribute key sub-term D t , where t = [1,…,j];

[0017] For each sub-attribute set in the data consumer attribute set S, if i≠0, the data consumer security level is the internal sub-attribute set S of level j i Identifier Z p A random number in; if i = 0, the data consumer security level is the external sub-attribute set S of level j 0 The identifier is For r <j>< / j> ; Where i = [0,…,m];

[0018] For the internal sub-attribute set S i The kth attribute a in i,k , where k = [1,…,n i ],n i Represents the internal sub-attribute set S i The number of attributes in the data consumer security level is j, and the internal sub-attribute set S i The identifier of the kth attribute in Z p A random number in

[0019] Calculate each attribute a i,k The hash value H(a i,k ), based on the group G in the system public key PK 0 The generator g of the data consumer attribute set S, the i-th internal sub-attribute set S i Identifier and S i Each attribute identifier in Calculate the attribute key sub-item D i,k and D′ i,k ;

[0020] Based on the system public key sub-item p in the system public key PK, the external sub-attribute set S 0 The identifier r <j>< / j> and the internal sub-attribute set S i Identifier Calculate the set conversion key sub-item L i , where i = [1,…,m];

[0021] Based on the system public key sub-item group k in the system public key PK i , the data consumer security level identifier group (r <1> ,…,r <j>< / j> ) Calculate the security level conversion key sub-item U i , where i = [1, ..., j-1];

[0022] The non-attribute key sub-item D t , the attribute key sub-item D i,k and D′ i,k , the set conversion key sub-item L i And the security level conversion key sub-item U i As the data consumer private key SK.

[0023] Further, calculate the non-attribute key sub-item D t The specific formula is: Where t = [1,…, j], r <t>< / t> Indicates the data consumer level identifier group, gα It is the system master key sub-item in the system master key MSK. It is the system public key sub-item group in the system public key PK;

[0024] Calculate the attribute key sub-item D i,k and D′ i,k The specific formula is: Among them, g is the group G in the system public key PK 0 The generator of The internal sub-attribute set S represents the data consumer security level j i The identifier of a i,k Represents the internal sub-attribute set S i The kth attribute in H(a i,k ) for each attribute a i,k The hash value of is the internal sub-attribute set S of data consumer security level j i The identifier of the kth attribute in , where i = [0, ..., m], k = [1, ..., n i ], m represents the number of internal sub-attribute sets, n i Represents the sub-attribute set S i The number of attributes in the

[0025] Calculate the set conversion key sub-item L i The specific formula is in, is the system public key sub-item p in the system public key PK, The internal sub-attribute set S represents the data consumer security level j i The identifier, r <j>< / j> Represents the external sub-attribute set S 0 Identifier of , where i = [1, ..., m], m represents the number of internal sub-attribute sets;

[0026] Calculate the security level conversion key sub-item U i The specific formula is in, is the system public key sub-item group k in the system public key PK i , r represents a group of data consumer security level identifiers, where i = [1,…, j-1], r <j>< / j> It represents both the jth element of the data consumer security level identifier group and the external sub-attribute set S 0 Identifier of .

[0027] Furthermore, the encrypting the file to be encrypted by using the system public key based on the access tree to obtain an encrypted ciphertext includes:

[0028] From Z p Randomly select a root secret value s from the access tree The root node R starts to distribute the secret value s in a top-down manner so that the access tree Each node in has a corresponding secret value;

[0029] Get the file M to be encrypted corresponding to the level node x' in the access tree x′ , file M to be encrypted x′ The confidentiality level rank (M x′ ), where x′∈X, X represents the set of level nodes;

[0030] Based on the file information to be encrypted, access the tree The secret value q allocated to all level nodes x′ in x′ (0) and the system public key PK calculation level node ciphertext sub-item

[0031] Get the access tree The secret value q assigned to the leaf node y y (0), where y∈Y, Y represents the visit tree The leaf node set in the system is combined with the system public key PK to calculate the leaf node ciphertext sub-item C y , C′ y ;

[0032] Get the access tree The secret value q obtained by the conversion node v v (0), where v∈V, V represents the visit tree The conversion node set is converted, and the conversion node ciphertext sub-item is calculated in combination with the system public key PK

[0033] Further, the calculation level node ciphertext sub-item The specific formula is Among them, M x′ Indicates the file to be encrypted corresponding to level node x′, e(g, g) α is the system public key sub-item in the system public key PK, q x′ (0) represents the secret value allocated to level node x′;

[0034] Compute-level node ciphertext sub-item The specific formula is Among them, p is the system public key sub-item in the system public key PK, q x′ (0) represents the secret value allocated to level node x′;

[0035] Compute-level node ciphertext sub-item The specific formula is in, is the system public key sub-item in the system public key PK, rank(M x′ ) is M x′ The level of confidentiality, rank(M x′ )∈[1,n];q x′ (0) represents the secret value allocated to level node x′;

[0036] Compute-level node ciphertext sub-item The specific formula is in is the system public key sub-item in the system public key PK, rank(M x′ ) is M x′ The level of confidentiality, rank(M x′ )∈[1,n];q x′ (0) represents the secret value allocated to level node x′;

[0037] Calculate the leaf node ciphertext sub-item C y The specific formula is Among them, g is the system public key sub-item in the system public key PK, q y (0) represents the secret value assigned to the leaf node y;

[0038] Calculate the leaf node ciphertext sub-item C′ y The specific formula is att(y) represents the attribute associated with the leaf node y, H(att(y)) represents the hash value corresponding to att(y), and q y (0) represents the secret value assigned to the leaf node y;

[0039] Calculate the conversion node ciphertext sub-item The specific formula is Among them, p is the system public key sub-item in the system public key PK, q v (0) represents the secret value obtained by converting node v.

[0040] Furthermore, the decrypting the encrypted ciphertext by using the acquired data consumer private key to obtain the decrypted plaintext includes:

[0041] Visit tree and data consumer attribute set The execution tree satisfies the function The tree satisfies the function The specific execution process is:

[0042] I. Visit the tree Each node x in the tree executes the corresponding visit to satisfy the function Get the label set Lab of all nodes x ,in, Represents a sub-access tree with x node as the root node;

[0043] II. If the access tree corresponding to node x satisfies the function Return to label set Lab x , then from the label set Lab x Select a label i from the data consumer and execute the node decryption function based on the data consumer private key. Get the decrypted plaintext.

[0044] Furthermore, the access tree Each node x in the tree executes the corresponding visit to satisfy the function Get the label set Lab of each node x ,include:

[0045] If node x is a leaf node, then determine whether att(x) is attribute a in the consumer attribute set S. i,k , if att(x) is attribute a in the consumer attribute set S i,k ,but Return label i∈Lab x , among which, Lab x is the set of all labels i that meet the conditions, and att(x) represents the attribute associated with the leaf node x;

[0046] If node x is a non-leaf node, then at least k x Child nodes of non-leaf node x The visit tree satisfies the function Return Contains the tag i or is a transition node and but Return label i∈Lab x .

[0047] Furthermore, if the access tree corresponding to the node x satisfies the function Return to label set Lab x , then from the label set Lab x Select a label i from the data consumer and execute the node decryption function based on the data consumer private key. include:

[0048] If x is a leaf node, the attribute associated with the leaf node x is att(x) = a i,k ∈S i ,but:

[0049]

[0050] Among them, D i,k and D′ i,k is the attribute key sub-item in the data consumer's private key SK, C x and C′ x Represents the leaf node ciphertext sub-item in the encrypted ciphertext CT;

[0051] If the attribute att(x) associated with the leaf node x ≠ a i,k ∈S i , then the decryption is terminated;

[0052] If x is a non-leaf node, let B x Any k of non-leaf nodes x x The set of child nodes z, for each z∈B x ,

[0053] a. If i∈Lab z , then execute:

[0054] i. If i≠0, the node decryption function is executed as follows:

[0055]

[0056] ii. If i=0, the node decryption function is executed as follows:

[0057]

[0058] Where l = index(z), B z ′={index(z):z∈B x }, B x Any k for x x The set of child nodes z;

[0059] b. If some i′≠i,i′∈Lab z , and z is a transition node, then execute:

[0060] i. If i′≠0, convert arrive as follows:

[0061]

[0062] ii. If i′=0, then convert arrive as follows:

[0063]

[0064] in, To change the node ciphertext sub-item in the encrypted ciphertext CT, L i and L i′ The key sub-items in the data consumer's private key SK are converted into a collection;

[0065] If conditions a and b are not met, the decryption is terminated.

[0066] Further, execute the node decryption function It also includes the associated hour,

[0067] If i = 0, then otherwise

[0068] If j = rank (M x′ ), that is, the security level of the data consumer is the same as the confidentiality level of the encrypted file; then

[0069] a. If i≠0, calculate M x′ as follows:

[0070]

[0071] b. Otherwise,

[0072]

[0073] If j>rank(M x′ ), that is, the data consumer security level is greater than the encryption file level, then let rank(M x′ ) = t, calculate

[0074] a. If i≠0,

[0075] b. If i = 0,

[0076] The final calculation M x′ :

[0077]

[0078] When <rank(M x′ ), that is, the data consumer security level is less than the encrypted file level, and the decryption is terminated.

[0079] The present invention provides an attribute-based mandatory access control method. A data consumer device defines an access tree according to the number of files to be encrypted, information of the files to be encrypted and the confidentiality level of each file to be encrypted, and pre-sets conversion nodes in the access tree to realize the conversion of different data consumer attribute sets. By pre-setting level nodes, encryption of multiple files to be encrypted with different confidentiality levels on the same access tree is completed, which is suitable for sharing and storing encrypted ciphertexts of various clouds. After the data consumer device downloads the encrypted ciphertext, when the attributes of the data consumer meet the structure of the access tree and the security level of the data consumer is greater than or equal to the confidentiality level of the encrypted ciphertext, the downloaded encrypted ciphertext is decrypted by the data consumer private key obtained from the authorization agency, thereby ensuring the access security of the cloud encrypted ciphertext. By introducing the data consumer attribute set, the data consumer private key obtained by the data consumer device has a hierarchical structure and is more universal. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] The drawings described herein are used to provide a further understanding of the embodiments of the present invention, constitute a part of this application, and do not constitute a limitation of the embodiments of the present invention. In the drawings:

[0081] Figure 1 The present invention is a principle block diagram of an attribute-based mandatory access control method.

[0082] Figure 2 The figure is a flow chart of calculating the system public key and the system master key in one embodiment of the present invention.

[0083] Figure 3 The figure is a flow chart of calculating the private key of a data consumer in one embodiment of the present invention.

[0084] Figure 4 The figure is a flow chart of encryption processing of a file to be encrypted in one embodiment of the present invention.

[0085] Figure 5 for Figure 4 Flowchart of secret value distribution in .

[0086] Figure 6 The figure is a decryption calculation flow chart in one embodiment of the present invention.

[0087] Figure 7 for Figure 6 The tree satisfies the function The construction flow chart of .

[0088] Figure 8 for Figure 6 Decryption module 1 calculation flow chart.

[0089] Fig. 9 for Figure 6 Decryption module 2 calculation flow chart. DETAILED DESCRIPTION

[0090] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with embodiments and drawings. The exemplary embodiments of the present invention and their description are only used to explain the present invention and are not intended to limit the present invention.

[0091] Example

[0092] like Figure 1 As shown, the present invention provides an attribute-based mandatory access control method, comprising:

[0093] The authority (Authority) obtains the system public key PK and the system master key MSK by calculating the system initialization parameters, and obtains the data consumer identity information and the data consumer attribute set S from the data consumer device (User); calculates the data consumer private key SK corresponding to each data consumer identity information based on the system public key PK, the system master key MSK and the data consumer attribute set S; sends the system public key PK to the data owner device (Owner), and sends the corresponding data consumer private key to the corresponding data consumer device (User) according to the data consumer identity information.

[0094] The data consumer attribute set S refers to a set of attributes of the data consumer. In this embodiment, the attributes of the data consumer include but are not limited to the project identifier, project time and project address in which the user participates.

[0095] By combining the data consumer attribute set to calculate the data consumer private key, the key can support the attribute structure with hierarchical attributes, which is more flexible and universal than the previous CP-ABE.

[0096] The data owner device (Owner) obtains the system public key PK from the authority (Authority) and uses the encrypted file M x′ The number of files to be encrypted M x′ Information and each file to be encrypted M x′ The security level definition access tree Based on visit tree The file to be encrypted is encrypted using the system public key PK to obtain an encrypted ciphertext CT and sent to the cloud service provider (CSP) for storage. x′ The information refers to the specific content of the file to be encrypted.

[0097] The data consumer device (User) downloads the encrypted ciphertext CT from the cloud service provider (CSP) and obtains the data consumer security level from the data consumer identity information. When the data consumer security level is greater than or equal to the level of the encrypted ciphertext in the access tree, the encrypted ciphertext CT is decrypted using the obtained data consumer private key SK to obtain the decrypted plaintext M x′ , otherwise it cannot be decrypted.

[0098] Furthermore, if Figure 2 As shown, the system initialization parameters include hash function H, bilinear map e, group G 0 and Group G 0 Generator g, p-order prime field Z p .

[0099] The calculation process of the system public key is as follows: Based on the system initialization parameters, from Z p Choose a random number α from β i and θ i , where β i where i=[1,…,n], θ i where i = [1,…,n-1], n represents the maximum security level of the data consumer or the level of the encrypted file. Based on the random number α, β i and θ i ,pass e(g,g) α Calculate the system public key sub-item, and obtain the system public key based on the system initialization parameters and the calculated system public key sub-item. The system public key PK is

[0100] The specific process of calculating the system master key is as follows: Based on the system initialization parameters, calculate the system master key sub-item g α , and according to Z p The random number selected in β i and θ i , get the system master key, the system master key MSK is

[0101] Furthermore, the data consumer identity information includes the data consumer identifier and the data consumer security level. The data consumer attribute set S includes multiple sub-attribute sets, each of which includes an external sub-attribute set S 0 and multiple internal sub-attribute sets S i , where i = [1,…,m], and m represents the number of internal sub-attribute sets.

[0102] like Figure 3 As shown, the data consumer private key corresponding to each data consumer identity information is calculated based on the system public key, the system master key and the data consumer attribute set, including:

[0103] According to the data consumer security level j and data consumer identification, from Z p Randomly select j random numbers as the data consumer security level identifier group r <t>< / t> =(r <1> ,…,r <j>< / j> ). Among them, Z p represents the field of prime numbers of order p.

[0104] Get the system public key sub-item group from the system public key PK Get the system master key sub-item g from the system master key MSK α , and based on the system public key PK, the system master key MSK and the data consumer security level identifier group r <t>< / t> Calculate the non-attribute key sub-term D t , where t = [1,…,j].

[0105] Specifically, calculate the non-attribute key sub-item D t The specific formula is: Where t = [1,…,j], r <t>< / t> Indicates the data consumer level identifier group, g α It is the system master key sub-item in the system master key MSK. It is the system public key sub-item group in the system public key PK.

[0106] For each sub-attribute set in the data consumer attribute set S, if i≠0, the data consumer security level is the internal sub-attribute set S of level j i Identifier Z p A random number in; if i = 0, the data consumer security level is the external sub-attribute set S of level j 0 The identifier is For r <j>< / j> . Where i = [0,…,m].

[0107] For the internal sub-attribute set S i The kth attribute a in i,k , where k = [1,…,n i ],n i Represents the internal sub-attribute set S i The number of attributes in the data consumer security level is j, and the internal sub-attribute set S i The identifier of the kth attribute in Z p A random number in .

[0108] Calculate each attribute a i,k The hash value H(a i,k ), based on the group G in the system public key PK 0 The generator g of the data consumer attribute set S, the i-th internal sub-attribute set S i Identifier and S i Each attribute identifier in Calculate the attribute key sub-item D i,k and D′ i,k .

[0109] Specifically, calculate the attribute key sub-item D i,k and D′ i,k The specific formula is: Among them, g is the group G in the system public key PK 0 The generator of The internal sub-attribute set S represents the data consumer security level j i The identifier of a i,k Represents the internal sub-attribute set S i The kth attribute in H(a i,k ) for each attribute a i,k The hash value of is the internal sub-attribute set S of data consumer security level j i The identifier of the kth attribute in , where i = [0, ..., m], k = [1, ..., n i ], m represents the number of internal sub-attribute sets, n i Represents the sub-attribute set S i The number of attributes in the table.

[0110] Based on the system public key sub-item p in the system public key PK, the external sub-attribute set S 0 The identifier r <j>< / j> and the internal sub-attribute set S i Identifier Calculate the set conversion key sub-item L i , where i = [1,…,m].

[0111] Specifically, calculate the set conversion key sub-item L i The specific formula is in, is the system public key sub-item p in the system public key PK, The internal sub-attribute set S represents the data consumer security level j i The identifier, r <j>< / j> Represents the external sub-attribute set S 0 Identifier of , where i = [1,…,m], m represents the number of internal sub-attribute sets.

[0112] Based on the system public key sub-item group k in the system public key PK i , data consumer security level identifier group (r <1> ,…,r <j>< / j> ) Calculate the security level conversion key sub-item U i , where i = [1,…,j-1].

[0113] Specifically, calculate the security level conversion key sub-item U i The specific formula is in, is the system public key sub-item group k in the system public key PK i , r represents a group of data consumer security level identifiers, where i = [1,…,j-1], r <j>< / j> It represents both the jth element of the data consumer security level identifier group and the external sub-attribute set S 0 Identifier of .

[0114] Set the non-attribute key subkey D t , Attribute key sub-item D i,k and D′ i,k , Set conversion key sub-item L i And the security level conversion key sub-item U i As the data consumer private key SK, that is Where D t where t=[1,…,j], D i,k ,D′ i,k where i=[0,…,m], k=[1,…,n i ], L i where i=[1,…,m], U i where i=[1,…,j-1].

[0115] Furthermore, this embodiment makes To access the tree, x represents a node in the tree. If x is a leaf node, it represents an attribute; if x is a non-leaf node, it represents a threshold ("AND" gate and "OR" gate). Let num x Indicates the number of children of node x in the tree, k x Indicates the threshold value of x (0≤k x ≤num x ). When k x = 1 and x is a non-leaf node, then x is an "OR" gate; when k x =num x When x is a leaf node, k x = 1. Let parent(x) represent the access tree The parent node of the x node, att(x) represents the access tree The attributes associated with the leaf node x in the example. Each child node of a non-leaf node is marked with a serial number, which is marked as 1, ..., num x . Let index(x) represent the index of x in its sibling nodes. represents a tree with root node R, then Represents the visited subtree with its root at x.

[0116] This example accesses the tree There are also two types of special nodes, namely level nodes and conversion nodes. Among them, level nodes are non-leaf nodes, which are used to mark files of different levels; conversion nodes are used to convert the identifier of one sub-attribute set into another sub-attribute set identifier when a certain attribute in different sub-attribute sets in the attribute set is allowed to be combined. For example, if a user participates in two projects at the same time, the attribute sets of the user in each project are {project number: 300, time: {year: 2019, month: March}, location: Beijing}, {project number: 301, time: {year: 2018, month: May} location: Shanghai}, and the year attribute 2019 in the sub-attribute set time of the first attribute set and the year attribute 2018 in the sub-attribute set time of the second attribute set are allowed to be combined, and the year attribute 2019 in the sub-attribute set time of the first attribute set is converted to the year attribute 2018 in the sub-attribute set time of the second attribute set, so as to realize the conversion of attribute sets of different data consumers and integrate different access trees with overlapping parts into a single access tree to realize the encryption of multiple files.

[0117] Furthermore, if Figure 4 As shown, the file to be encrypted is encrypted using the system public key based on the access tree to obtain the encrypted ciphertext, including:

[0118] like Figure 5 As shown, from Z p Randomly select a root secret value s from the access tree The root node R starts to distribute the secret value s in a top-down manner so that the access tree Each node in has a corresponding secret value.

[0119] Get the file M to be encrypted corresponding to the level node x' in the access tree x′ , file M to be encrypted x′ The confidentiality level rank (M x′ ), where x′∈X, X represents the set of level nodes.

[0120] Based on the information of the file to be encrypted, access the tree The secret value q allocated to all level nodes x′ in x′ (0) and the system public key PK calculation level node ciphertext sub-item

[0121] in, Represents the first ciphertext sub-item of the level node, Represents the second ciphertext sub-item of the level node, Represents the third ciphertext sub-item of the level node, Represents the fourth ciphertext subitem of a level node.

[0122] Specifically, the calculation level node ciphertext sub-item The specific formula is Among them, M x′ Indicates the file to be encrypted corresponding to level node x′, e(g,g) α is the system public key sub-item in the system public key PK, q x′ (0) represents the secret value allocated to level node x′.

[0123] Compute-level node ciphertext sub-item The specific formula is Among them, p is the system public key sub-item in the system public key PK, q x′ (0) represents the secret value allocated to level node x′.

[0124] Compute-level node ciphertext sub-item The specific formula is in, is the system public key sub-item in the system public key PK, rank(M x′ ) is M x′ The level of confidentiality, rank(M x′ )∈[1,n].q x′ (0) represents the secret value allocated to level node x′.

[0125] Compute-level node ciphertext sub-item The specific formula is in is the system public key sub-item in the system public key PK, rank(M x′ ) is M x′ The level of confidentiality, rank(M x′ )∈[1,n].q x′ (0) represents the secret value allocated to level node x′.

[0126] Get the access tree The secret value q assigned to the leaf node y y (0), where y∈Y, Y represents the visit tree The leaf node set is combined with the system public key PK to calculate the leaf node ciphertext sub-item C y ,C′ y .

[0127] Among them, C y , represents the first ciphertext sub-item of leaf node y, C′ y Represents the second ciphertext sub-item of leaf node y.

[0128] Specifically, calculate the leaf node ciphertext sub-item C y The specific formula is Among them, g is the system public key sub-item in the system public key PK, q y (0) represents the secret value allocated to the leaf node y.

[0129] Calculate the leaf node ciphertext sub-item C′ y The specific formula is att(y) represents the attribute associated with the leaf node y, H(att(y)) represents the hash value corresponding to att(y), and qy(0) represents the secret value allocated to the leaf node y.

[0130] Get the access tree The secret value q obtained by the conversion node v v (0), where v∈V, V represents the visit tree The node set is converted and the ciphertext sub-item of the conversion node is calculated in combination with the system public key PK

[0131] Specifically, calculate the conversion node ciphertext sub-item The specific formula is Among them, p is the system public key sub-item in the system public key PK, q v (0) represents the secret value obtained by converting node v.

[0132] Furthermore, if Figure 6 As shown, the encrypted ciphertext is decrypted by the acquired data consumer private key to obtain the decrypted plaintext, including:

[0133] Visit tree And the data consumer attribute set S execution tree satisfies the function The tree satisfies the function The specific execution process is as follows:

[0134] I. Visit the tree Each node x in the tree executes the corresponding visit to satisfy the function Get the label set Lab of all nodes x ,in, Represents a sub-access tree with x node as the root node.

[0135] II. If the access tree corresponding to node x satisfies the function Return to label set Lab x , then from the label set Lab x Select a label i and execute the node decryption function based on the data consumer private key Get the decrypted plaintext.

[0136] Furthermore, if Figure 7 As shown, the access tree Each node x in the tree executes the corresponding visit to satisfy the function Get the label set Lab of each node x ,include:

[0137] If node x is a leaf node, then determine whether att(x) is attribute a in the consumer attribute set S. i,k , if att(x) is attribute a in the consumer attribute set S i,k ,but Return label i∈Lab x , among which, Lab x is the set of all labels i that meet the conditions, and att(x) represents the attribute associated with the leaf node x.

[0138] If node x is a non-leaf node, then at least k x Child nodes of non-leaf node x The visit tree satisfies the function Return Contains the tag i or is a transition node and but Return label i∈Lab x .

[0139] Furthermore, this embodiment includes two decryption modules, namely, decryption module 1 and decryption module 2. Among them, decryption module 1 is as follows: Figure 8 As shown, if the access tree corresponding to node x satisfies the function Return to label set Lab x , then from the label set Lab x Select a label i and execute the node decryption function based on the data consumer private key include:

[0140] If x is a leaf node, the attribute associated with the leaf node x is att(x) = a i,k ∈S i ,but:

[0141]

[0142] Among them, D i,k and D′ i,k is the attribute key sub-item in the data consumer's private key SK, C x and C′ x Represents the leaf node ciphertext sub-item in the encrypted ciphertext CT.

[0143] If the attribute att(x) associated with the leaf node x ≠ a i,k ∈S i , the decryption terminates.

[0144] If x is a non-leaf node, let B x Any k of non-leaf nodes x x The set of child nodes z, for each z∈B x ,

[0145] a. If i∈Lab z , then execute:

[0146] i. If i≠0, the node decryption function is executed as follows:

[0147]

[0148] ii. If i=0, the node decryption function is executed as follows:

[0149]

[0150] Where l = index(z), B z ′={index(z):z∈B x }, B x Any k for x x The set of child nodes z.

[0151] b. If some i′≠i,i′∈Lab z , and z is a transition node, then execute:

[0152] i. If i′≠0, convert arrive as follows:

[0153]

[0154] ii. If i′=0, then convert arrive as follows:

[0155]

[0156] in, To change the node ciphertext sub-item in the encrypted ciphertext CT, L i and L i′ The key sub-items in the data consumer's private key SK are converted into a collection.

[0157] If conditions a and b are not met, the decryption is terminated.

[0158] Decryption module 2 Fig. 9 As shown, execute the node decryption function It also includes the associated hour,

[0159] If i = 0, then otherwise

[0160] If j = rank (M x′ ), that is, the security level of the data consumer is the same as the confidentiality level of the encrypted file.

[0161] a. If i≠0, calculate M x′ as follows:

[0162]

[0163] b. Otherwise,

[0164]

[0165] If j>rank(M x′ ), that is, the data consumer security level is greater than the encryption file level, then let rank(M x′ ) = t, calculate

[0166] a. If i≠0,

[0167] b. If i = 0,

[0168] The final calculation M x′ :

[0169]

[0170] When <rank(M x′ ), that is, the data consumer security level is less than the encrypted file level, and the decryption is terminated.

[0171] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0172] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A mandatory access control method based on attributes, It is characterized in that include: The authorization agency obtains the system public key and the system master key by calculating the system initialization parameters, and obtains the data consumer identity information and the data consumer attribute set from the data consumer device; calculates the data consumer private key corresponding to each data consumer identity information based on the system public key, the system master key and the data consumer attribute set; Send the system public key to the data owner device, and send the corresponding data consumer private key to the corresponding data consumer device according to the data consumer identity information; The data owner device obtains the system public key from the authorization agency and defines an access tree according to the number of files to be encrypted, information of the files to be encrypted and the confidentiality level of each file to be encrypted; Encrypting the file to be encrypted using the system public key based on the access tree to obtain an encrypted ciphertext and sending it to a cloud service provider for storage; The data consumer device downloads the encrypted ciphertext from the cloud service provider and obtains the data consumer security level from the data consumer identity information. When the data consumer security level is greater than or equal to the level of the encrypted ciphertext in the access tree and the attribute of the data consumer device satisfies the structure of the access tree, the encrypted ciphertext is decrypted by using the obtained data consumer private key to obtain the decrypted plaintext, otherwise the decryption cannot be performed; The encrypting the file to be encrypted by using the system public key based on the access tree to obtain an encrypted ciphertext includes: From Z p Randomly select a root secret value s from the access tree The root node R starts to distribute the secret value s in a top-down manner so that the access tree Each node in has a corresponding secret value; Get the file M to be encrypted corresponding to the level node x' in the access tree x′ , file M to be encrypted x′ The confidentiality level rank (M x′ ), where x′∈X, X represents the set of level nodes; Based on the file information to be encrypted, access the tree The secret value q allocated to all level nodes x′ in x′ (0) and the system public key PK calculation level node ciphertext sub-item Get the access tree The secret value q assigned to the leaf node y y (0), where y∈Y, Y represents the visit tree The leaf node set in the system is combined with the system public key PK to calculate the leaf node ciphertext sub-item C y ,C′ y ; Get the access tree The secret value q obtained by the conversion node v v (0), where v∈V, V represents the visit tree The conversion node set is converted, and the conversion node ciphertext sub-item is calculated in combination with the system public key PK 2. The attribute-based mandatory access control method according to claim 1, It is characterized in that The system initialization parameters include hash function H, bilinear map e, group G 0 and the group G 0 Generator g, p-order prime field Z p ; The calculation process of the system public key is specifically as follows: based on the system initialization parameters, from Z p Choose a random number α from β i and θ i , where β i where i=[1,…,n], θ i where i = [1, ..., n-1], n represents the maximum security level of the data consumer or the level of the encrypted file; based on the random number α, β i and θ i ,pass e(g,g) α Calculate the system public key sub-item, and obtain the system public key according to the system initialization parameters and the calculated system public key sub-item. The system public key PK is The system master key calculation process is specifically as follows: based on the system initialization parameters, the system master key sub-item g is calculated. α , and according to Z p The random number selected in β i and θ i , get the system master key, the system master key MSK is 3. The attribute-based mandatory access control method according to claim 1, It is characterized in that The data consumer identity information includes the data consumer identifier and the data consumer security level; the data consumer attribute set S includes multiple sub-attribute sets, each of which includes an external sub-attribute set S 0 and multiple internal sub-attribute sets S i , where i = [1,…,m], m represents the number of internal sub-attribute sets; The calculating the data consumer private key corresponding to each data consumer identity information based on the system public key, the system master key and the data consumer attribute set includes: According to the data consumer security level j and data consumer identification, from Z p Randomly select j random numbers as the data consumer security level identifier group r <t>< / t> =(r <1> ,…,r <j>< / j> ), where Z p represents the prime field of order p; Get the system public key sub-item group from the system public key PK Get the system master key sub-item g from the system master key MSK α , and based on the system public key PK, the system master key MSK and the data consumer security level identifier group r <t>< / t> Calculate the non-attribute key sub-term D t , where t = [1,…,j]; For each sub-attribute set in the data consumer attribute set S, if i≠0, the data consumer security level is the internal sub-attribute set S of level j i The identifier r i <j>< / j> Z p A random number in; if i = 0, the data consumer security level is the external sub-attribute set S of level j 0 The identifier is For r <j>< / j> ; Where i = [0,…,m]; For the internal sub-attribute set S i The kth attribute a in i,k , where k = [1,…,n i ],n i Represents the internal sub-attribute set S i The number of attributes in the data consumer security level is j, and the internal sub-attribute set S i The identifier of the kth attribute in Z p A random number in Calculate each attribute a i,k The hash value H(a i,k ), based on the group G in the system public key PK 0 The generator g of the data consumer attribute set S, the i-th internal sub-attribute set S i The identifier r i <j>< / j> and S i Each attribute identifier in Calculate the attribute key sub-item D i,k and D′ i,k ; Based on the system public key sub-item p in the system public key PK, the external sub-attribute set S 0 The identifier r <j>< / j> and the internal sub-attribute set S i The identifier r i <j>< / j> , calculate the set conversion key sub-item L i , where i = [1,…,m]; Based on the system public key sub-item group k in the system public key PK i , the data consumer security level identifier group (r <1> ,…,r <j>< / j> ) Calculate the security level conversion key sub-item U i , where i = [1,…,j-1]; The non-attribute key sub-item D t , the attribute key sub-item D i,k and D′ i,k , the set conversion key sub-item L i And the security level conversion key sub-item U i As the data consumer private key SK.

4. The attribute-based mandatory access control method according to claim 3, It is characterized in that Calculate the non-attribute key sub-term D t The specific formula is: Where t = [1,…,j], r <t>< / t> Indicates the data consumer level identifier group, g α It is the system master key sub-item in the system master key MSK. It is the system public key sub-item group in the system public key PK; Calculate the attribute key sub-item D i,k and D′ i,k The specific formula is: Among them, g is the group G in the system public key PK 0 The generator of r i <j>< / j> The internal sub-attribute set S represents the data consumer security level j i The identifier of a i,k Represents the internal sub-attribute set S i The kth attribute in H(a i,k ) for each attribute a i,k The hash value of is the internal sub-attribute set S of data consumer security level j i The identifier of the kth attribute in , where i = [0, ..., m], k = [1, ..., n i ], m represents the number of internal sub-attribute sets, n i Represents the sub-attribute set S i The number of attributes in the Calculate the set conversion key sub-item L i The specific formula is in, is the system public key sub-item p in the system public key PK, r i <j>< / j> The internal sub-attribute set S represents the data consumer security level j i The identifier, r <j>< / j> Represents the external sub-attribute set S 0 Identifier of , where i = [1,…,m], m represents the number of internal sub-attribute sets; Calculate the security level conversion key sub-item U i The specific formula is in, is the system public key sub-item group k in the system public key PK i , r represents a group of data consumer security level identifiers, where i = [1,…,j-1], r <j>< / j> It represents both the jth element of the data consumer security level identifier group and the external sub-attribute set S 0 Identifier of .

5. The attribute-based mandatory access control method according to claim 1, Features: Compute-level node ciphertext sub-item The specific formula is Among them, M x′ Indicates the file to be encrypted corresponding to level node x′, e(g,g) α is the system public key sub-item in the system public key PK, q x′ (0) represents the secret value allocated to level node x′; Compute-level node ciphertext sub-item The specific formula is Among them, p is the system public key sub-item in the system public key PK, q x′ (0) represents the secret value allocated to level node x′; Compute-level node ciphertext sub-item The specific formula is in, is the system public key sub-item in the system public key PK, rank(M x′ ) is M x′ The level of confidentiality, rank(M x′ )∈[1,n];q x′ (0) represents the secret value allocated to level node x′; Compute-level node ciphertext sub-item The specific formula is in is the system public key sub-item in the system public key PK, rank(M x′ ) is M x′ The level of confidentiality, rank(M x′ )∈[1,n];q x′ (0) represents the secret value allocated to level node x′; Calculate the leaf node ciphertext sub-item C y The specific formula is Among them, g is the system public key sub-item in the system public key PK, q y (0) represents the secret value assigned to the leaf node y; Calculate the leaf node ciphertext sub-item C′ y The specific formula is att(y) represents the attribute associated with the leaf node y, H(att(y)) represents the hash value corresponding to att(y), and q y (0) represents the secret value assigned to the leaf node y; Calculate the conversion node ciphertext sub-item The specific formula is Among them, p is the system public key sub-item in the system public key PK, q v (0) represents the secret value obtained by converting node v.

6. The attribute-based mandatory access control method according to claim 1, It is characterized in that The decrypting of the encrypted ciphertext by using the acquired data consumer private key to obtain the decrypted plaintext includes: Visit tree And the data consumer attribute set S execution tree satisfies the function The tree satisfies the function The specific execution process is: I. Visit the tree Each node x in the tree executes the corresponding visit to satisfy the function Get the label set Lab of all nodes x ,in, Represents a sub-access tree with x node as the root node; II. If the access tree corresponding to node x satisfies the function Return to label set Lab x , then from the label set Lab x Select a label i from the data consumer and execute the node decryption function based on the data consumer private key. Get the decrypted plaintext.

7. The attribute-based mandatory access control method according to claim 6, It is characterized in that The pair visits the tree Each node x in the tree executes the corresponding visit to satisfy the function Get the label set Lab of each node x ,include: If node x is a leaf node, then determine whether att(x) is attribute a in the consumer attribute set S. i,k , if att(x) is attribute a in the consumer attribute set S i,k ,but Return label i∈Lab x , among which, Lab x is the set of all labels i that meet the conditions, and att(x) represents the attribute associated with the leaf node x; If node x is a non-leaf node, then at least k x Child nodes of non-leaf node x The visit tree satisfies the function Return Contains the tag i or is a transition node and but Return label i∈Lab x .

8. The attribute-based mandatory access control method according to claim 6, It is characterized in that If the access tree corresponding to the node x satisfies the function Return to label set Lab x , then from the label set Lab x Select a label i from the data consumer and execute the node decryption function based on the data consumer private key. include: If x is a leaf node, the attribute associated with the leaf node x is att(x) = a i,k ∈S i ,but: Among them, D i,k and D′ i,k is the attribute key sub-item in the data consumer's private key SK, C x and C′ x Represents the leaf node ciphertext sub-item in the encrypted ciphertext CT; If the attribute att(x) associated with the leaf node x ≠ a i,k ∈S i , then the decryption is terminated; If x is a non-leaf node, let B x Any k of non-leaf nodes x x The set of child nodes z, for each z∈B x , a. If i∈Lab z , then execute: i. If i≠0, the node decryption function is executed as follows: ii. If i=0, the node decryption function is executed as follows: in, B x Any k for x x The set of child nodes z; b. If some i′≠i,i′∈Lab z , and z is a transition node, then execute: i. If i′≠0, convert arrive as follows: ii. If i′=0, then convert arrive as follows: in, To change the node ciphertext sub-item in the encrypted ciphertext CT, L i and L i′ The key sub-items in the data consumer's private key SK are converted into a collection; If conditions a and b are not met, the decryption is terminated.

9. The attribute-based mandatory access control method according to claim 6, It is characterized in that Execute node decryption function It also includes the associated hour, If i = 0, then otherwise If j = rank (M x′ ), that is, the security level of the data consumer is the same as the confidentiality level of the encrypted file; then a. If i≠0, calculate M x′ as follows: b. Otherwise, If j>rank(M x′ ), that is, the data consumer security level is greater than the encryption file level, then let rank(M x′ ) = t, calculate a. If i≠0, b. If i = 0, The final calculation M x′ : When <rank(M x′ ), that is, the data consumer security level is less than the encrypted file level, and the decryption is terminated.

Citation Information

Patent Citations

  • Multi-mechanism hierarchical attribute-based encryption method applied to cloud storage

    CN103618729A

  • Ciphertext sharing method in public cloud environment

    CN106506155A