A Verifiable Encrypted Data Bilateral Access Control Method in Mobile Edge Cloud
By performing ciphertext matching and decryption operations at edge nodes, combined with the accumulation tree and digital signature mechanism, the problems of DP-ABE computing burden and data source authentication in mobile edge cloud are solved, and efficient and verifiable bilateral access control is achieved.
Patent Information
- Application Number
- CN202210888023.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-25
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-07-25
AI Technical Summary
In a mobile edge cloud environment, DP-ABE technology causes mobile users to have too much computing burden when decrypting, and cannot effectively authenticate the data source, which poses waste of resources and security risks.
By performing ciphertext matching and decryption operations at edge nodes, and using the accumulation tree and digital signature mechanism, fine-grained access control for data owners and mobile users is realized, supporting mobile users to verify ciphertext matching results, ensuring the correctness of data source authentication and receiver policy matching.
Reduces the computing overhead of resource-constrained mobile devices, ensures the effectiveness of policy designation of data owners and mobile users, prevents false data senders and edge nodes from mismatching, and achieves efficient and verifiable bilateral access control.
Smart Images

Figure CN115278665B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security, and particularly relates to a verifiable encrypted data bilateral access control method in a mobile edge cloud. Background Art
[0002] Mobile edge cloud is a new architecture that extends cloud computing services to the network edge and reaches the mobile base stations near mobile users. Since edge nodes have data computing and caching capabilities, intelligent computing tasks can be deployed on edge nodes, thereby reducing the bandwidth occupation during data transmission and providing high-quality data services for nearby mobile users. Therefore, mobile edge cloud is gradually widely applied to various cloud service scenarios with strict requirements for mobility and real-time response.
[0003] Although mobile edge cloud improves the efficiency and quality of cloud services, it also brings some security and privacy problems, which will greatly limit the practical application of mobile edge cloud. Therefore, how to perform access control on sensitive data in mobile edge cloud has attracted wide attention. Existing methods are to encrypt data and perform fine-grained access control, such as using attribute-based encryption (ABE) technology;
[0004] In ciphertext-policy attribute-based encryption (CP-ABE), the data owner specifies an access policy when encrypting data, and the user can correctly decrypt the plaintext only when the policy is satisfied; while in key-policy attribute-based encryption (KP-ABE), a set of attributes are embedded by the data owner when encrypting data, and the user's key is associated with an access policy, and the ciphertext that meets the user's policy can be correctly decrypted. Therefore, ABE can achieve data access control in cloud computing and edge computing.
[0005] The dual-policy attribute-based encryption (DP-ABE) technology, which combines the access control characteristics of CP-ABE and KP-ABE, has its ciphertext and key described by a set of attributes and a specified access policy. In DP-ABE, the data owner defines a fine-grained sender policy, so that qualified users must meet the sender policy; at the same time, the user also specifies a fine-grained receiver policy for the data. Therefore, the ciphertext generated by the DP-ABE scheme can be correctly decrypted only when both the sender policy and the receiver policy are satisfied, thereby realizing bilateral access control of encrypted data.
[0006] The entities involved in DP-ABE include a trusted authorization agency, a cloud server, an edge node, a data owner, and a mobile user, as Figure 1 shown; the implementation process of DP-ABE includes the following steps:
[0007] 1) System initialization: The trusted authorization agency generates system public parameters pp and system master key mk.
[0008] 2) Key Generation: The trusted authorization agency generates a private key sk based on the system master key mk, the attribute set ρ of the mobile user, and the recipient policy, and securely distributes it to the mobile user. and securely distributes it to the mobile user.
[0009] 3) Data Encryption: The data owner defines a sender policy and an attribute set σ for the message m, encrypts to obtain the ciphertext ct, and uploads the ciphertext to the cloud server.
[0010] 4) Data Decryption: After the mobile user obtains the ciphertext ct in the cloud server through the edge node, if the attribute ρ in the key satisfies the sender policy in the ciphertext and the attribute σ in the ciphertext satisfies the recipient policy in the key then the private key sk can be used to recover the message plaintext m.
[0011] However, in the mobile edge cloud environment, there are the following problems with implementing bilateral access control of data using DP-ABE:
[0012] 1) When decrypting, the mobile user needs to simultaneously determine whether the attribute ρ in the key satisfies the sender policy in the ciphertext and whether the attribute σ in the ciphertext satisfies the recipient policy in the key Compared with traditional unilateral access control, DP-ABE brings a relatively large computational burden to resource-constrained mobile devices.
[0013] 2) The attribute set σ embedded in the ciphertext can be arbitrarily set by the data owner as long as it satisfies the recipient policy specified by the mobile user That is; therefore, DP-ABE cannot authenticate the data source, enabling only the data owner with the corresponding attributes to generate ciphertexts that satisfy the recipient policy. Summary of the Invention
[0014] To solve the above problems, the present invention proposes a method for verifiable encrypted data bilateral access control in a mobile edge cloud. The edge node is used as a caching and computing node to perform ciphertext matching and decryption operations, and also supports verification by the mobile user of the ciphertext matching result; it realizes fine-grained access control for both the data owner and the mobile user, and provides data source authentication and verifiable recipient policy matching in the edge node. The mobile user performs matching verification on the obtained target ciphertext, thereby realizing efficient and verifiable encrypted data bilateral access control in the mobile edge cloud.
[0015] The method for verifiable encrypted data bilateral access control in the mobile edge cloud is specifically as follows:
[0016] Step 1. Set up a communication scenario including a trusted authorization agency, a cloud server, edge nodes, data owners, and mobile users;
[0017] The trusted authorization agency connects the data owner and the mobile user, and respectively gives the corresponding encryption key to the data owner and the decryption key to the mobile user;
[0018] The data owner defines a sender policy for each plaintext and encrypts it using the encryption key. The data owner administrator creates an index for the set of ciphertexts sent by multiple data owners, and uploads the set of ciphertexts and the index to an edge node near the data owner administrator. The nearby edge node distributes the frequently used hot ciphertexts to the surrounding edge nodes, and uploads the infrequently used ciphertexts to the cloud server for storage;
[0019] The cloud server is a remote storage server that transmits data to and from all edge nodes through a public channel.
[0020] The edge node near the mobile user converts the ciphertexts that match the mobile user's receiving policy and sends them to the mobile user; The mobile user uses the matching decryption key, receives the matching result, and verifies to obtain the plaintext.
[0021] Step 2. The trusted authorization agency initializes the system parameters, and respectively uses the encryption and decryption key generation algorithms to output the corresponding encryption key sk σ to the data owner and the decryption key rk ρ to the mobile user;
[0022] The system parameters include: the input security parameter κ, the universal set of attributes Output the system public parameters pp and the master key mk, and output the authentication key ask for the owner administrator.
[0023] Using the master key mk and the set of attributes σ of the message sent by the data owner, the trusted authorization agency runs the SKGen algorithm to generate the encryption key sk σ .
[0024] Using the master key mk and the set of attributes ρ of the mobile user, the trusted authorization agency runs the SKGen algorithm to generate the decryption key rk ρ .
[0025] Step 3. The data owner defines a sender policy for each plaintext and encrypts each plaintext using the encryption key sk σ to obtain a set of ciphertexts
[0026] The set of ciphertexts Each ciphertext in is: ct = (c S , c A , cT , a T );
[0027] c S represents the symmetric encryption ciphertext of the plaintext m; c A is the hash value of c S ; c T represents the ciphertext related to the sender's policy for access control; a T represents the ciphertext related to the attribute set σ for data source authentication; a T = (at0, at1, at2, {at x,3} x∈σ )
[0028] Step 4. The administrator of the data owner inputs the authentication key ask for the ciphertext set to create an index and upload the index to the cloud server and the edge node near the administrator;
[0029] The index includes an inverted list an accumulation tree and a signature
[0030] Specifically, given the ciphertext set the administrator of the data owner runs the IndexGen algorithm to obtain the index ε;
[0031] where serves as the identifier of the nth ciphertext ct;
[0032] Then, use the inverted list to construct an accumulation tree;
[0033] is the set of identifiers of the ciphertexts containing the attribute a j , and t is the number of attributes in the ciphertext set;
[0034] The construction process is as follows: for each calculate the accumulation value γ is a randomly diversified secret value, which is part of the data owner administrator's key, and g is a random number of the system public parameters;
[0035] At the same time, calculate the digest d(υ) of each node υ, and determine whether the node υ is a leaf node. If so, the digest Otherwise,
[0036] N(υ) is the set of child nodes of the node υ, and φ is an injective function; d(u) is the digest of the child node u;
[0037] Finally, an accumulation tree is obtained. where R is the root node of the accumulation tree, and the root node digest is calculated. for the signature
[0038] Finally, the administrator of the data owner outsources the ciphertext set to the cloud server and outsources the index to the edge node.
[0039] Step 5: The mobile client inputs the decryption key rk ρ and the customized recipient policy runs the MKGen algorithm to output the matching key ak ρ and the recovery key vk, and uploads the matching key ak ρ to the edge node near the mobile user.
[0040] The matching key
[0041] Step 6: The edge node near the mobile user inputs the matching key ak ρ , the ciphertext set the inverted list and the accumulation tree Performs a matching operation on the ciphertexts in the ciphertext set that satisfy the recipient policy submitted by the mobile user, and converts the matching ciphertexts, and outputs the matching result and the corresponding proof to the mobile user.
[0042] is a subset of the identifier set obtained by performing a set operation corresponding to the policy on the inverted list ;
[0043] The edge node near the mobile user finds all the matching ciphertext sets from the cloud server or its cache according to the identifiers in the subset
[0044] For each Verify as follows:
[0045] First, if the attribute set σ in the ciphertext satisfies the recipient policy map each row in the matrix to an attribute; and there exists a constant {ω i} i∈L satisfies
[0046] where is a matrix of \(l_2\) rows and \(n_2\) columns, is a mapping function,
[0047] Then, according to the ciphertext \(a\) T and the matching key \(ak\) ρ , it is determined whether it satisfies If so, return \(\perp\);
[0048] \(H_1\) is a one-way hash function;
[0049] Otherwise, when the attribute set \(\rho\) in the matching key satisfies the policy in the ciphertext Map each row in the matrix into an attribute, then there exists a constant \(\{\chi\) i \} i∈I satisfying
[0050] where is a matrix of \(l_1\) rows and \(n_1\) columns, \(\psi\) is a mapping function, \(I = \{i|i\in [l_1],\psi(i)\in\rho\}\);
[0051] Then, according to the ciphertext \(c\) T and the matching key \(ak\) ρ , it is determined whether \(A_0 = e(sk'_0,c_1) / A\) is satisfied. If then set \(A_0=\perp\), otherwise, obtain the retrieval result \(v_t=(c S ,c A ,c_0,A_0)\) and append it to
[0052]
[0053] Finally, the edge node returns the matching result and the proof
[0054] Step 7: The mobile user inputs the recovery key \(vk\), accumulates the root node digest of the tree and its signature the matching result and its proof Output the set of plaintext messages or
[0055] The mobile user first checks the proof to verify the correctness of the matching result: The mobile user inputs the root node digest of the accumulative tree and its signature the matching result and its proof Verify the correctness of the matching results and output the set of matching ciphertexts
[0056] Then input the recovery key vk to decrypt and obtain the plaintext. For each If the attribute set ρ of the mobile user vk satisfies the policy in vt The mobile user can recover the corresponding plaintext m.
[0057] Finally, the mobile user outputs the set of plaintext messages Or
[0058] The beneficial effects of the present invention are as follows:
[0059] 1) A verifiable encrypted data bilateral access control method in a mobile edge cloud, which supports efficient bilateral access control. Both the data owner and the mobile user can mutually specify policies, and allows the recipient to outsource the sender authentication and data decryption operations to the edge node. The edge node realizes efficient ciphertext matching and ciphertext conversion for each recipient policy, greatly reducing the computational overhead of resource-constrained mobile devices.
[0060] 2) A verifiable encrypted data bilateral access control method in a mobile edge cloud, which allows the mobile user to verify the authenticity of the data owner and prevent attackers from impersonating legitimate data senders to generate corresponding ciphertexts using unauthorized attributes.
[0061] 3) A verifiable encrypted data bilateral access control method in a mobile edge cloud, which allows the recipient to verify the correctness of the edge node's matching results of its access policy, effectively preventing semi-trusted edge nodes from returning mismatched or incomplete matching results.
[0062] 4) A verifiable encrypted data bilateral access control method in a mobile edge cloud. The edge node completes the sender authentication and performs the main time-consuming calculations of the data decryption algorithm. Therefore, the mobile user only needs to specify its access policy and use the decryption key to generate the corresponding matching key and send it to the edge node. When receiving the matching results, only a small amount of calculation is required to decrypt the plaintext that meets the bilateral access control, thus greatly reducing the computational overhead of resource-constrained mobile users.
[0063] 5) A verifiable encrypted data bilateral access control method in a mobile edge cloud. The trusted authorization agency issues the corresponding encryption key for the data owner based on its attribute set, ensuring that only the data owner with the authorized encryption key can generate valid ciphertexts, thereby realizing sender authentication.
[0064] 6) A verifiable encrypted data bilateral access control method in mobile edge cloud, based on an accumulative tree and a digital signature mechanism, realizes the verifiability of the data matching results of edge nodes. When uploading ciphertext, the data owner establishes an accumulative tree of the ciphertext. When matching the ciphertext based on the receiver's policy, the edge node generates its corresponding proof, and the mobile user only needs to perform a small amount of calculation to verify the correctness of the matching result, thus preventing the edge node from returning incorrect matching results. Description of the Drawings
[0065] Figure 1 It is a data bilateral access control diagram based on DP-ABE in the prior art;
[0066] Figure 2 It is a flowchart of a verifiable encrypted data bilateral access control method in mobile edge cloud according to the present invention;
[0067] Figure 3 It is the communication scenario built according to the present invention;
[0068] Figure 4 It is a method flowchart of an example of the present invention. Detailed Embodiment
[0069] The present invention will be further described in detail below with reference to the embodiments and the drawings.
[0070] The present invention proposes a verifiable encrypted data bilateral access control method in mobile edge cloud, as Figure 2 shown, and the specific steps are as follows:
[0071] Step 1: Build a communication scenario including a trusted authorization agency, a cloud server, edge nodes, data owners, and mobile users;
[0072] As Figure 3 shown, 1) Trusted authorization agency. The trusted authorization agency initializes the system parameters and distributes authentication keys to the owner administrators. In addition, the trusted authorization agency provides necessary encryption keys for each data owner associated with an attribute set, and provides decryption keys for each mobile user associated with an attribute set.
[0073] 2) Cloud server. The cloud server is a semi-trusted remote storage server with a large amount of storage space to store data, and transmits data with edge nodes through a public channel.
[0074] 3) Edge nodes. The edge nodes cache frequently used hot data, perform matching operations by checking whether the ciphertext meets the receiving policy, and perform the main decryption operation on the matched ciphertext; at the same time, in order to verify whether the edge nodes have correctly performed the matching operation, an additional proof needs to be returned.
[0075] 4) Data Owner. The data owner encrypts each data using an encryption key and a specified sender policy. The owner administrator creates an index for the ciphertext set on behalf of multiple data owners, and outsources the ciphertext set and the index to the cloud server and the edge node respectively.
[0076] 5) Mobile User. The mobile user can submit a matching key with a receiver policy to the edge node and retrieve data from it. When the mobile user receives the matching result and the corresponding proof, it can verify the correctness of the matching result. Finally, if the verification passes, the mobile user can obtain the matching plaintext through a small amount of computation.
[0077] Step 2: The trusted authorization agency initializes the system parameters, and respectively uses the encryption and decryption key generation algorithms to output the supporting encryption key sk σ for the data owner and the decryption key rk ρ for the mobile user;
[0078] The system parameters include: the input security parameter κ, the full set of attributes Select a key extractor H0 ∈ Η, three hash functions H1, H2: H3: {0, 1} * → {0, 1} * . Select a random number g, α, and for each attribute select a random number u x , Output the system public parameters and the master key mk = (g α , β), and output the authentication key ask for the owner administrator.
[0079] Using the master key mk and the attribute set σ of the message sent by the data owner, the trusted authorization agency runs the SKGen algorithm to generate the encryption key sk σ .
[0080] Specifically, for each data owner with the attribute set σ, the trusted authorization agency selects a random number and calculates ek0 = g α g βδ and ek1 = g δ . For each attribute x ∈ σ, calculate Then, the trusted authorization agency returns the encryption key sk σ = (ek0, ek1, {ek x,2} x∈σ ) through a secure channel.
[0081] Using the master key mk and the set of attributes ρ of the mobile user, the trusted authorization agency runs the SKGen algorithm to generate the decryption key rk ρ .
[0082] Specifically, for each mobile user with the set of attributes ρ, the trusted authorization agency randomly selects Calculate sk0 = g α g βr , sk1 = g r ; For each attribute x ∈ ρ, calculate Then, the trusted authorization agency returns the decryption key rk ρ =(sk0, sk1, {sk x,2}} x∈ρ ) to the mobile user.
[0083] Step 3: The data owner defines a sender policy for each plaintext And uses the encryption key sk σ To encrypt each plaintext separately, obtaining a set of ciphertexts
[0084] Specifically:[[]]
[0085] First, the data owner selects a random key And calculates k H = H0(K), c Α = H3(H2(K) || c S ), c S = SE.Enc(k H , m),
[0086] Then selects random numbers Calculates c0 = K · e(g, g) αs , c1 = g s .
[0087] Assume the sender policy Has l1 rows and n1 columns; Select random numbers ξ1,... Select For each i ∈ [l1], calculate Calculate Generate
[0088] Then, select a random number θ, Calculate at0 = ek0 · (g β ) θ = g α g β(δ+θ) , at1 = ek1 · g θ = g δ+θ , at2 = g μFor each attribute \(x\in\sigma\), compute Generate \(a\) T \(=(a_{t0},a_{t1},a_{t2},\{a_{t}\}\) x,3 \}\) x∈σ ).
[0089] Finally, the data owner outputs the ciphertext set where each ciphertext \(ct=(c\) S , \(c\) A , \(c\) T , \(a\) T ).
[0090] \(c\) S represents the symmetric encryption ciphertext of the plaintext \(m\); \(c\) A is the hash value of \(c\) S ; \(c\) T represents the ciphertext related to the sender's policy for access control; \(a\) T represents the ciphertext related to the attribute set \(\sigma\) for data source authentication;
[0091] Step 4. The administrator of the data owner inputs the authentication key \(ask\) for the ciphertext set Create an index and upload the index to the cloud server and the edge node near the administrator;
[0092] The index includes an inverted list an accumulation tree and a signature
[0093] The index \(\varepsilon\) can effectively retrieve data from the ciphertext set and verify the correctness and integrity of the matching result, which is the key innovative part of the invention; the inverted list facilitates the cloud server to quickly and efficiently retrieve data from the ciphertext set and obtain the matching result; the accumulation tree constructed based on an extractable collision-resistant hash function is used for the cloud server to provide a proof of the correctness of the matching result and is the key to achieving verifiability. Among them, the accumulation tree root node digest can guarantee the integrity of all hash values and thus further guarantee the integrity of the ciphertexts in the set; the signature is used for the mobile user to verify the validity of the root node digest
[0094] Specifically, given the ciphertext set the administrator of the data owner runs the IndexGen algorithm to obtain the index \(\varepsilon\);
[0095] where As the identifier of the nth ciphertext ct;
[0096] Then, use the inverted list to construct the accumulative tree;
[0097] For the set of identifiers of ciphertexts containing attribute a j , where t is the number of attributes in the ciphertext set;
[0098] The construction process is as follows: For each calculate the accumulative value γ is a randomly diversified secret value and is part of the data owner's administrator key.
[0099] Meanwhile, calculate the digest d(υ) of each node υ, and determine whether node υ is a leaf node. If so, the digest Otherwise,
[0100] N(υ) is the set of child nodes of node υ, and φ is an injective function; d(u) is the digest of child node u;
[0101] Finally, obtain the accumulative tree where R is the root node of the accumulative tree, and calculate the root node digest of the signature
[0102] Finally, the administrator of the data owner outsources the ciphertext set to the cloud server and outsources the index to the edge node.
[0103] Step Five: The mobile user inputs the decryption key rk ρ and the custom receiver policy and runs the MKGen algorithm to output the matching key ak ρ and the recovery key vk, and uploads the matching key ak ρ to the edge node near the mobile user.
[0104] Specifically, for each receiver policy the mobile user runs the MKGen algorithm to obtain the matching key and the recovery key. Assume has l2 rows and n2 columns. Select a random number τ, y2,..., Let Calculate Generate the recovery key and the matching key ak ρ :
[0105]
[0106]
[0107] Among them, \(sk'_0, sk'_1, \{sk'\) x,2}\) x∈ρ are obtained by using random numbers to randomize the decryption key \(rk\) ρ =(sk0, sk1, \{sk x,2}\) x∈ρ );
[0108] \(ck_0\) and \(ck_1\) are tags for convenient identification. Essentially, they perform exponentiation operations using the system parameters \(g\), \(h\), and the random number \(\tau\) selected at this stage. Perform exponentiation operations.
[0109] Step 6: The edge node near the mobile user inputs the matching key \(ak\) ρ , the ciphertext set inverted list and the accumulative tree perform matching operations on the ciphertexts in the ciphertext set that meet the receiving policy submitted by the mobile user, and transform the matching ciphertexts, and output the matching result and the corresponding proof to the mobile user.
[0110] To respond to the matching policy the edge node runs the IndexMatch algorithm to obtain the matching result and its proof.
[0111] Specifically, perform the corresponding set operation on the inverted list to obtain the result which is a subset of the identifier set .
[0112] Subsequently, initialize the proof Generate the proof as follows:
[0113] 1) For a j ∈Φ, run the QueryTree algorithm to generate Specifically, first initialize the node set hash table For each Let I j ={υ0, υ1,..., υ b} be the path from the leaf node υ0 associated with X j to the root node υ b =R, and put I jAppend to Γ. Then, for each non-leaf node υ in Γ z , compute and append (d(υ z-1 ), ν z ) to
[0114] 2) For each internal node Z υ is the set corresponding to the children nodes of node υ, is the set of hash values of the elements in set Z υ . Perform the set operation corresponding to node υ on set Z υ to obtain the result O υ , and compute its hash value Append to Then compute as follows:
[0115] If υ corresponds to the intersection operation, obtain and append to Specifically, for j = 1,..., ι, the ProveIntersection algorithm computes and computes the polynomial q j (γ) such that it satisfies Finally, output
[0116] If υ corresponds to the union operation, obtain and append to Specifically, initialize For each U j,k , k = 1,..., Δ - 1 is the number of layers of the binary tree . Represent the two sets corresponding to its children nodes as A j,k-1 , B j,k-1 . The ProveUnion algorithm first computes U j,k = A j,k-1 ∪B j,k-1 , I j,k = A j,k-1 ∩B j,k-1 and the hash value Then append to Π U ; then run and append to Π U . Finally, output Π υ = Π U .
[0117] 3) For the result compute the polynomial and append the coefficients of to
[0118] Then, the edge nodes near the mobile user find all the matching ciphertext sets from the cloud server or its cache according to the identifiers in the subset and
[0119] For each Verify as follows: If the attribute set σ in the ciphertext satisfies the receiving policy then there exists a constant {ω i} i∈L that satisfies where Then calculate
[0120]
[0121] The receiving policy is a matrix of l1 rows and n1 columns, is a mapping function that maps each row in the matrix to an attribute;
[0122] According to the ciphertext a T and the matching key ak ρ , if it satisfies return ⊥;
[0123] H1 is a one-way hash function;
[0124] Otherwise, perform the following transformation on the ciphertext ct:
[0125] If the attribute set ρ in the matching key satisfies the policy in the ciphertext then there exists a constant {χ i} i∈I that satisfies where I = {i|i ∈ [l2], ψ(i) ∈ ρ}, and then calculate
[0126]
[0127] is a matrix of l2 rows and n2 columns, and ψ is a mapping function that maps each row in the matrix to an attribute when the attribute set ρ in the matching key satisfies the policy in the ciphertext;
[0128] And according to the ciphertext c T and the matching key ak ρ , calculate If then set A0 = ⊥, otherwise, obtain the retrieval result vt = (c S , c A , c0, A0) and append it to
[0129] Finally, the edge node returns the matching result and proof
[0130] Step 7: The mobile user inputs the recovery key vk and accumulates the root node summary of the tree and its signature Matching results And its proof Output plaintext message set or
[0131] The mobile user first checks the proof to verify the correctness of the matching result. The mobile user enters the root node summary of the cumulative tree and its signature Matching results And its proof Verify the correctness of the matching results and output the matching ciphertext set
[0132] Then input the recovery key vk to decrypt and get the plaintext. If the attribute set ρ of mobile user vk satisfies the policy in vt The mobile user can recover the corresponding plaintext m.
[0133] Finally, the mobile user outputs a set of plaintext messages or
[0134] (1) The verification matching results are as follows.
[0135] ①By signature verify Whether the cumulative tree root node summary is fresh and correct.
[0136] ②Run VerifyTree Verify all accumulated values The effectiveness of each Indeed corresponds to the cumulative tree The j-th leaf node of .
[0137] Specifically, for each from Recover the proof π j ={(d(υ0),ν1),(d(υ1),ν2),...,(d(υ b-1 ),ν b )}, and then verify by checking the following equation
[0138] (i)
[0139] (ii)
[0140] (iii)
[0141] If the above equations all hold, output 1.
[0142] ③ For each internal node First, check the equation Then calculate as follows:
[0143] If υ corresponds to the intersection operation, run VerifyIntersection Specifically, check the following equations:
[0144] (i)
[0145] (ii)
[0146] If all hold, output 1.
[0147] If υ corresponds to the union operation, run VerifyUnion Specifically, calculate as follows:
[0148] (i) For each Check the equation
[0149] (ii) For each Check the equation
[0150] (iii) For each proof of intersection Run VerifyIntersection
[0151] (iv) For each node of the binary tree Check the equation
[0152] If any of the above does not hold, output 0; otherwise, output 1.
[0153] ④ Check the equation If it holds, output 1; otherwise, output 0.
[0154] If at least one of the above fails, return ⊥.
[0155] Otherwise, verify whether each identifier in can be found in find the unique vt that satisfies in If there is none, return ⊥. Otherwise, perform the decryption operation.
[0156] (2) For each If the attribute set ρ of the mobile user satisfies the policy in vt The mobile user can recover the corresponding plaintext m. Specifically, for each vt = (c S , c A , c0, A0), first calculate and check whether the equation H3(H2(K) || c S ) = c A holds. If it holds, calculate k H = H0(K), then return m = SE.Dec(k H , c S ), otherwise return ⊥.
[0157] The mobile user only needs to perform simple calculations to recover the plaintext because the time-consuming decryption task has been outsourced to the edge node for execution, that is, the ciphertext matching is only semi-decryption, which will not reveal secrets and will not affect security.
[0158] Example:
[0159] Let be the set of plaintexts, be the corresponding set of ciphertexts and ε be the index of the set of ciphertexts. The algorithm of the overall technical solution is defined as follows:
[0160] 1) System initialization algorithm Setup Input the security parameter κ, the full set of attributes Output the system public key pp and the master key mk, and output the authentication key ask for the owner administrator. All other algorithms implicitly specify pp as the input.
[0161] 2) Encryption key generation algorithm SKGen(mk, σ). Input the system master key MK and the attribute set σ, output the encryption key sk σ .
[0162] 3) Decryption key generation algorithm RKGen(mk, ρ). Input the system master key mk and the attribute set ρ, output the decryption key rk ρ .
[0163] 4) Encryption algorithm Encrypt Input the encryption key sk σ , the message and the sender's policy Output the encrypted ciphertext ct.
[0164] 5) Index Generation Algorithm IndexGen Input the authentication key ask and the ciphertext set Output the index Including the inverted list Accumulation tree And signature
[0165] 6) Matching Key Generation Algorithm MKGen Input the decryption key rk ρ And the recipient's policy Output the matching key ak ρ And the recovery key vk.
[0166] 7) Index Matching Algorithm IndexMatch Input the matching key ak ρ , the ciphertext set Inverted list And the accumulation tree Output the matching result And the corresponding proof
[0167] 8) Verification and Decryption Algorithm VerifyDec Input the recovery key vk, the root node digest of the accumulation tree And its signature Matching result And its proof Output the set of plaintext messages Or
[0168] As Figure 4 Shown, the implementation process of the overall technical solution is as follows:
[0169] 1) System initialization
[0170] The trusted authorization agency selects the security parameter κ and the entire set of attributes Run the Setup algorithm. Specifically, select the key extractor H0 ∈ Η, three hash functions H1, H2: H3: {0,1} * → {0,1} * . Select a random number g, α, And for each attribute Select a random number u x , Generate the key msk = (g α , β) and
[0171] Subsequently, the trusted authorization agency instantiates an extractable collision-resistant hash function Selects random numbers γ, a Outputs sk H =(γ, a). Runs a digital signature algorithm to generate a signature key ssk and a verification key svk, and selects an injective function φ: Generates apk = (pk H , svk, φ), ask = (sk H , ssk).
[0172] Finally, the trusted authorization agency outputs the system public parameters pp = (mpk, apk), generates the system master key mk = msk and secretly stores it, and sends ask to the owner administrator through a secure channel.
[0173] 2) Key Generation
[0174] (1) Encryption key generation. For a data owner with an attribute set σ, the trusted authorization agency runs the SKGen algorithm to select a random number And calculates ek0 = g α g βδ And ek1 = g δ . For each attribute x ∈ σ, calculates Then, the trusted authorization agency returns the encryption key sk σ =(ek0, ek1, {ek x,2} x∈σ ) through a secure channel.
[0175] (2) Decryption key generation. For each mobile user with an attribute set ρ, the trusted authorization agency runs the RKGen algorithm to randomly select Calculates sk0 = g α g βr , sk1 = g r . For each attribute x ∈ ρ, calculates Then, the trusted authorization agency returns the decryption key rk ρ =(sk0, sk1, {sk x,2} x∈ρ ) to the mobile user.
[0176] 3) Data Storage
[0177] Given a set of plaintexts The data owner first encrypts each plaintext Then the owner administrator indexes the set of ciphertexts using an inverted list and generates an accumulation tree for it
[0178] (1) For each message m, the data owner flexibly specifies the sender policy Run the Encrypt algorithm to obtain the ciphertext ct. Specifically, the data owner selects a random key and computes k H = H0(K), c Α = H3(H2(K) || c S ), c S = SE.Enc(k H , m), selects a random number and computes c0 = K · e(g, g) αs , c1 = g s . Assume the sender policy has l1 rows and n1 columns. Select random numbers ξ1,..., Select For each i ∈ [l1], compute Compute Generate
[0179] Then, select a random number θ, compute at0 = ek0 · (g β ) θ = g α g β(δ+θ) , at1 = ek1 · g θ = g δ+θ , at2 = g μ . For each attribute x ∈ σ, compute Generate a T = (at0, at1, at2, {at x,3} x∈σ ). Finally, the data owner outputs the ciphertext ct = (c S , c A , c T , a T ). In the following text, let be the identifier of each ciphertext ct.
[0180] (2) Given the ciphertext set The owner administrator runs the IndexGen algorithm to obtain the index ε. Specifically, it includes: Let be the set of identifiers of the ciphertexts containing the attribute a j , t be the number of attributes in the ciphertext set, and let be the inverted list, and then construct an accumulative tree for . The construction process is as follows: For each Compute the accumulative value And calculate the digest d(υ) for each node υ. Specifically, if υ is a leaf node, Otherwise, Therefore, the accumulative tree is obtained where R is the root node of the accumulative tree, and calculate the root node digest of the signature
[0181] Finally, the owner administrator will outsource to the cloud server, and outsource the index to the edge node.
[0182] 4) Data retrieval
[0183] Let be a monotone Boolean normal form defined on the attribute set , and is of the tree structure.
[0184] (1) For each recipient policy The mobile user runs the MKGen algorithm to obtain the matching key and the recovery key. Assume has l2 rows and n2 columns. Select a random number τ, y2,..., Let Calculate Generate the recovery key and the matching key ak ρ .
[0185]
[0186]
[0187] (2) To answer the matching policy The edge node runs the IndexMatch algorithm to obtain the matching result and its proof. Specifically, perform the corresponding set operation on the inverted list to obtain the result which is subset. Subsequently, initialize the proof Generate the proof as follows:
[0188] ① For a j ∈Φ, run the QueryTree algorithm to generate Specifically, the algorithm first initializes the node set hash table For each Let I j={υ0,υ1,...,υ b} is the path from the leaf node υ0 associated with X j to the root node υ b =R, and append I j to Γ. Then, for each non-leaf node υ z in Γ, calculate and append (d(υ z-1 ),ν z ) to
[0189] ② For each internal node Z υ is the set corresponding to the child nodes of υ, is the set of hash values of the elements in Z υ . Perform the set operation corresponding to υ on Z υ to obtain the result O υ and calculate its hash value Append to Then calculate as follows:
[0190] If υ corresponds to the intersection operation, obtain and append it to Specifically, for j = 1,..., ι, the ProveIntersection algorithm calculates and calculates the polynomial q j (γ) such that it satisfies Finally, output
[0191] If υ corresponds to the union operation, obtain and append it to Specifically, initialize For each U j,k , k = 1,..., Δ - 1 is the number of layers of the binary tree . Represent the two sets corresponding to its child nodes as A j,k-1 , B j,k-1 . The ProveUnion algorithm first calculates U j,k =A j,k-1 ∪B j,k-1 , I j,k =A j,k-1 ∩B j,k-1 and the hash value Then append to Π U ; then run and append it to Π U . Finally, output Π υ =Π U .
[0192] ③For the result Calculate the polynomial and append the coefficients of to
[0193] Then, the edge node finds all the matching ciphertext sets from the cloud server or its cache according to the identifier in For each Verify as follows: If the attribute set σ in the ciphertext satisfies the policy then there exists a constant {ω } i} i∈L satisfying Here Then calculate
[0194]
[0195] If return ⊥; otherwise, perform the following transformation on the ciphertext ct. If the attribute set ρ in the matching key satisfies the policy in the ciphertext then there exists a constant {χ i} i∈I satisfying where I = {i|i ∈ [l1], ψ(i) ∈ ρ}, then calculate
[0196]
[0197] and calculate If then set A0 = ⊥, otherwise, obtain the retrieval result vt = (c S , c A , c0, A0) and append it to
[0198] Finally, the edge node returns the matching result and the proof
[0199] 5) Data decryption
[0200] Once receiving and the mobile user first checks the proof to verify the correctness of the matching result, and then decrypts to obtain the plaintext.
[0201] (1) Verify the matching result as follows.
[0202] ①Verify through the signature whether is the fresh and correct accumulator tree root node digest.
[0203] ②Run VerifyTree Verify all accumulated values The effectiveness of each Indeed corresponds to the cumulative tree Specifically, for each from Recover the proof π j ={(d(υ0),ν1),(d(υ1),ν2),...,(d(υ b-1 ),ν b )}, and then verify by checking the following equation
[0204] (i)
[0205] (ii)
[0206] (iii)
[0207] If all the above equations are true, output 1.
[0208] ③For each internal node First check the equation Then the calculation is as follows:
[0209] If υ corresponds to an intersection operation, run VerifyIntersection Specifically, examine the following equation:
[0210] (i)
[0211] (ii)
[0212] If all are true, output 1.
[0213] If υ corresponds to a union operation, run VerifyUnion Specifically, the calculation is as follows:
[0214] (i) For each Check the equation
[0215] (ii) For each Check the equation
[0216] (iii) Proof for each intersection Run VerifyIntersection
[0217] (iv) For each node of the binary tree , check the equation
[0218] If any of the above does not hold, output 0; otherwise, output 1.
[0219] ④ Check the equation If it holds, output 1; otherwise, output 0.
[0220] If at least one of the above fails, return ⊥. Otherwise, verify whether each identifier in can find a unique vt in such that If there is one that does not, return ⊥. Otherwise, perform the decryption operation.
[0221] (2) For each If the attribute set ρ of the mobile user satisfies the policy in vt the mobile user can recover the corresponding plaintext m. Specifically, for each vt = (c S , c A , c0, A0), first calculate and check whether the equation H3(H2(K) || c S ) = c A holds. If it holds, calculate k H = H0(K), and then return m = SE.Dec(k H , c S ); otherwise, return ⊥.
Claims
1. A verifiable encrypted data bilateral access control method in mobile edge cloud, the specific steps are as follows: Step 1: Build a communication scenario including a trusted authorization agency, a cloud server, edge nodes, data owners, and mobile users; Step 2: The trusted authorization agency initializes the system parameters, and respectively uses the encryption and decryption key generation algorithms to output the matching encryption key sk σ to the data owner and the decryption key rk ρ to the mobile user; Step 3: The data owner defines a sender policy for each plaintext and encrypts each plaintext using the encryption key sk σ to obtain a set of ciphertexts Ciphertext set Each ciphertext in S is: ct = (c A , c T , a T ); c S represents the symmetric encryption ciphertext of the plaintext m; c A is the hash value with respect to c S ; c T represents the ciphertext related to the sender's policy for access control; a T represents the ciphertext related to the attribute set σ for data source authentication; a T =(at0, at1, at2, {at x,3} x∈σ ); Step 4. The administrator of the data owner inputs the authentication key ask as a ciphertext set Create an index And upload the index to the cloud server and the edge node near the administrator; Step 5. The mobile client inputs the decryption key rk ρ and the customized recipient policy Run the MKGen algorithm to output the matching key ak ρ and the recovery key vk, and upload the matching key ak ρ to the edge node near the mobile user; Matching key Among them, H1 is a hash function; e(g,g) α is an element outputting the system public parameters; τ is a random number; ck0 and ck1 are marks for convenient identification, and essentially use the system parameters g, h and the random numbers selected in this stage to perform exponentiation; sk′0, sk′1, {sk′ x,2} x∈ρ is to randomize the decryption key rk with the random number ρ ; for each attribute x ∈ ρ; random number l2 is the number of rows; Step 6: The edge node near the mobile user inputs the matching key ak ρ , the ciphertext set inverted list and the accumulative tree Perform a matching operation on the ciphertexts in the ciphertext set that meet the receiving policy submitted by the mobile user, and transform the matching ciphertexts, and output the matching results and the corresponding proofs to the mobile user; is a subset of the set of identifiers, obtained by performing set operations on the inverted list executing the corresponding strategy obtained; Edge nodes near the mobile user find all matching ciphertext sets from the cloud server or its cache according to the identifiers in the subset For each Verify as follows: First, if the attribute set σ in the ciphertext satisfies the receiving policy then there exists a constant {ω i} i∈L that satisfies where is a matrix of l2 rows and n2 columns, is a mapping function, Then, according to the ciphertext a T and the matching key ak ρ , determine whether it satisfies If so, return ⊥; H1 is a one-way hash function; Otherwise, when the set of attributes ρ in the matching key satisfies the policy in the ciphertext There exists a constant {χ i} i∈I that satisfies Among them is a matrix of l1 rows and n1 columns, ψ is a mapping function, I = {i|i ∈ [l1], ψ(i) ∈ ρ}; Then, according to the ciphertext c T and the matching key ak ρ , determine whether it satisfies A0 = e(sk′0, c1) / A. If so, set A0 = ⊥. Otherwise, obtain the retrieval result vt = (c S , c A , c0, A0) and append it to Finally, the edge node returns the matching result and the proof Step 7: Move the user input recovery key vk and accumulate the root node digest of the tree and its signature matching result and its proof After checking that the proof verifies the correctness of the matching result, decrypt the ciphertext and output the plaintext message set or 2. The verifiable encrypted data bilateral access control method in a mobile edge cloud according to claim 1, characterized in that The trusted authorization agency connects the data owner and the mobile user, and respectively gives the supporting encryption key to the data owner and the decryption key to the mobile user; The data owner defines a sender policy for each plaintext and encrypts it using the encryption key. The data owner administrator creates an index for the ciphertext set sent by multiple data owners, and uploads the ciphertext set and the index to the edge node near the data owner administrator. The nearby edge node distributes the frequently used hot ciphertexts to the surrounding edge nodes, and uploads the infrequently used ciphertexts to the cloud server for storage; The cloud server is a remote storage server and transmits data with all edge nodes through a public channel; The edge node near the mobile user converts the ciphertext that matches the mobile user's receiving policy and sends it to the mobile user; the mobile user uses the matching decryption key to receive the matching result and obtains the plaintext after verification.
3. The verifiable encrypted data bilateral access control method in a mobile edge cloud according to claim 1, characterized in that, The system parameters include: an input security parameter κ, and a complete set of attributes Output the system public parameters pp and the master key mk, and output the authentication key ask for the owner administrator; Using the master key mk and the set of attributes σ of the message sent by the data owner, the trusted authorization agency runs the SKGen algorithm to generate the encryption key sk σ ; Using the master key mk and the set of attributes ρ of the mobile user, the trusted authorization agency runs the SKGen algorithm to generate the decryption key rk ρ .
4. The verifiable encrypted data bilateral access control method in a mobile edge cloud according to claim 1, characterized in that, The index includes an inverted list accumulation tree and signature Specifically, given a set of ciphertexts The administrator of the data owner runs the IndexGen algorithm to obtain the index ε; wherein serves as an identifier for the nth ciphertext ct; Then, use the inverted list to construct the cumulative tree; is a set of identifiers for ciphertexts containing attribute a j , where t is the number of attributes in the ciphertext set; The construction process is as follows: For each calculate the cumulative value γ is a randomly sampled secret value, which is part of the data owner's administrator key, and g is a random number of the system public parameters; Meanwhile, calculate the digest d(υ) of each node υ, and determine whether the node υ is a leaf node. If so, the digest Otherwise, N(υ) is the set of child nodes of node υ, φ is an injective function; d(u) is the digest of child node u; Finally, an accumulation tree is obtained where R is the root node of the accumulation tree, and the root node digest is calculated for the signature Finally, the administrator of the data owner outsources the ciphertext set to the cloud server and outsources the index to the edge node.
5. The verifiable encrypted data bilateral access control method in a mobile edge cloud according to claim 1, characterized in that, In the seventh step, the mobile user first checks the proof to verify the correctness of the matching result: the mobile user inputs the root node digest of the accumulation tree and its signature matching result and its proof verifies the correctness of the matching result and outputs the set of matching ciphertexts Then, the recovery key vk is input to decrypt and obtain the plaintext. For each If the attribute set ρ of the mobile user vk satisfies the policy in vt The mobile user can recover the corresponding plaintext m; Finally, the mobile user outputs a set of plaintext messages Or