Oblivious Update Management Method for Data Encryption Keys Based on Edge Devices

By using chameleon hash function and bilinear mapping on edge devices, the problems of high cost and insufficient security of public key certificate management in the prior art are solved, and efficient and secure key update management is achieved.

CN115913534BActive Publication Date: 2025-07-11NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211381917.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-04
Publication Date
2025-07-11
Estimated Expiration
2042-11-04

AI Technical Summary

Technical Problem

The existing updating key management system has security problems and the cost of public key certificate management is high when updating client ciphertexts stored in the remote storage cloud.

Method used

The data encryption key inadvertent update management method based on edge devices is adopted, and the chameleon hash function and edge devices are used as key management servers to periodically update the client key, and symmetric keys are generated and updated through bilinear mapping and AES-256 encryption algorithm to reduce certificate management interactions.

Benefits of technology

It effectively reduces the cost of public key certificate management, improves the security of key updates, and avoids security issues during the interaction between the client and the key management server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913534B_ABST
    Figure CN115913534B_ABST
Patent Text Reader

Abstract

The present invention provides a method for oblivious update management of data encryption keys based on edge devices, including: Initialization stage: When a client registers, obtain system public parameters as security parameters, generate a private key and a public key pair, and generate an initial client tag; Encryption stage: The client generates a symmetric key, encrypts the data object, and stores the ciphertext in the cloud server; Key update stage: Use an edge device as a key management server. The key management server periodically updates a token using the chameleon hash algorithm and sends the updated token to the cloud server. The cloud server runs a key update algorithm to update all ciphertexts of the client; Decryption stage: The client obtains the updated ciphertext, interacts with the key management server, calculates the symmetric key through the updated ciphertext, and obtains the data object; This method does not require certificate management, effectively reduces the cost of public key certificate management, and effectively improves the security of key updates.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for managing the oblivious update of data encryption keys based on edge devices, belonging to the technical field of information security. Background Art

[0002] With the development of cloud storage in modern computing, updatable key management can protect encrypted data, thus providing periodically updatable keys. There are three roles in an updatable key management system: a client C, a key management server (KM) for storing and managing its client keys, and a storage cloud (STC) for storing client ciphertexts.

[0003] In existing updatable key management systems, when using traditional key management schemes, when updating all client ciphertexts stored in a remote storage cloud, it is necessary for the key management server to interact with the client. In this way, there are security problems during the key update interaction process, and at the same time, the cost of public key certificate management is relatively high.

[0004] The above problems should be considered and solved during the process of oblivious update management of data encryption keys. Summary of the Invention

[0005] The purpose of the present invention is to provide a method for managing the oblivious update of data encryption keys based on edge devices to solve the problems in the prior art that the cost of public key certificate management is relatively high and the security needs to be improved.

[0006] The technical solution of the present invention is as follows:

[0007] A method for managing the oblivious update of data encryption keys based on edge devices includes the following steps:

[0008] S1. Initialization stage: When a client registers, obtain system public parameters as security parameters, generate a private key and a public key pair, and generate an initial client tag.

[0009] S2. Encryption stage: The client uses a chameleon hash function to generate a symmetric key, encrypts a data object using the symmetric key to obtain a ciphertext, and stores the ciphertext in the cloud server STC. The client calculates the hash value of the data object and uploads it to the consortium blockchain.

[0010] S3. Key update stage: Use an edge device as the key management server KM. The key management server KM periodically updates a token using the trapdoor information of the chameleon hash function and sends the updated token to the cloud server STC. The cloud server STC runs a key update algorithm to update all ciphertexts of the client.

[0011] S4. Decryption phase: The client obtains the updated ciphertext through the cloud server STC, interacts with the key management server KM, calculates the symmetric key using the updated ciphertext with the chameleon hash function, decrypts the ciphertext to obtain the data object, and then obtains the hash value of the corresponding data object from the consortium blockchain to verify whether the decrypted data object has been tampered with.

[0012] Further, in step S1, when the client registers, the system public parameters are obtained as security parameters, a private key and a public key pair are generated, and the client initial tag is generated. Specifically,

[0013] S11. Generate system public parameters: G and G T are two cyclic multiplicative groups with the same prime order q, is the multiplicative group modulo q, and g is the generator of G; the bilinear map e: G×G→G T , the bilinear map has two inputs and satisfies linearity for each of the two inputs; the AES-256 symmetric encryption scheme (Enc, Dec), where Enc is AES-256 encryption and Dec is AES-256 decryption; the key length l; the chameleon hash function H: G→{0, 1} l , the encryption hash function H0: {0, 1} * →G, and the public parameters are set as pp, pp = (e, G, G T , q, g, H, H0, Enc, Dec);

[0014] S12. When using public key-based oblivious key management, go to step S13; when using identity-based oblivious key management, go to step S14;

[0015] S13. Generate a private key and a public key pair: The key management server KM randomly selects and stores an element in the multiplicative group modulo q and takes s as the private key sk of the client C c , and the key management server KM calculates the public key pk c = g s , and then sends the public key pk c to the client C; Generate the client initial tag: The key management server KM selects and stores the tag tag of the specific client C c ←G;

[0016] S14. Generate a private key and a public key pair: The PKG randomly selects as the master private key and generates the master public key mpk = g s , and the PKG generates the private key sk of the client from the client's identity ID c sk IDc = H0(IDc ) s ; Generate the client initial tag: The key management server KM selects and stores the tag of a specific client C in the multiplicative group modulo q

[0017] Furthermore, in step S2, the client uses the chameleon hash function to generate a symmetric key, encrypts the data object using the symmetric key to obtain the ciphertext, and stores the ciphertext in the cloud server STC. The client calculates the hash value of the data object and uploads it to the consortium blockchain. Specifically,

[0018] S21. The client selects a method to generate the symmetric key. When using the symmetric key generated based on the public key, it proceeds to step S22; when using the symmetric key generated based on the identity, it proceeds to step S23;

[0019] S22. The client C uses the chameleon hash function to generate the symmetric key d based on the public key k , encrypts the data object O through the symmetric encryption algorithm, calculates the symmetric key d k Encrypted data object ciphertext to obtain the ciphertext CT = (O id , R, E), where O id is the identity of the data object O, R is the random number selected in the symmetric key generation stage, and stores the ciphertext in the cloud server STC. The client calculates the hash value h = H0(O) of the data object and uploads it to the consortium blockchain;

[0020] S23. The client C uses the chameleon hash function to generate the symmetric key d based on the identity k , encrypts the data object O through the symmetric encryption algorithm, calculates the ciphertext of the data object encrypted by the symmetric key d k Encrypted data object ciphertext to obtain the ciphertext CT = (O id , R, E), where O id is the identity of the data object O, R is the random number selected in the symmetric key generation stage, and stores the ciphertext in the cloud server STC. The client calculates the hash value h = H0(O) of the data object and uploads it to the consortium blockchain.

[0021] Furthermore, in step S22, the client uses the chameleon hash function to generate the symmetric key d based on the public key k , specifically,

[0022] S221. The client C sends a request to the key management server KM;

[0023] S222. The key management server KM selects the tag of the client C c , and calculates the output T = e(H0(tagc ), pk c ), where e is a bilinear mapping, H0 is an encryption hash function, tag c is the tag of client C, pk c is the public key, and send T to client C;

[0024] S223. After client C receives the output T of the bilinear mapping e, randomly select an element R in the group, and calculate the symmetric key d using the chameleon hash function k = H(e(R, g)·T), where e is the bilinear mapping, T is the output of the bilinear mapping e, H is the chameleon hash function, and g is the generator of the cyclic multiplicative group G.

[0025] Furthermore, in step S23, the client uses the chameleon hash function to generate the symmetric key d based on the identity k , specifically

[0026] S231. Client C sends the identity ID c to the key management server KM;

[0027] S232. The key management server KM selects the tag tag of client C c , and calculates and send it to client C, where H0 is the encryption hash function and mpk is the master public key;

[0028] S233. After client C receives T, randomly select an element R in the group, and calculate the symmetric key d using the chameleon hash function k = H(e(R, g)·T), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.

[0029] Furthermore, in step S3, the key management server KM periodically updates the token using the trapdoor information of the chameleon hash function, and sends the updated token to the cloud server STC. The cloud server STC runs the key update algorithm to update all the ciphertexts of the client, specifically

[0030] S31. The key management server KM changes the tag tag of client C c to the new tag tag c ' of client C;

[0031] S32. The key management server KM calculates the updated token Ψ using the trapdoor information of the chameleon hash function, and then sends the updated token Ψ to the cloud server STC;

[0032] S33. After the cloud server STC receives the update token Ψ, the cloud server STC calculates the current random number R′ = Ψ·R, and the updated ciphertext CT′ = (O id , R′, E), where O id is the identity of the data object O.

[0033] Furthermore, in step S32, the key management server KM calculates the update token Ψ using the trapdoor information of the chameleon hash function. Specifically,

[0034] S321. When adopting public-key-based oblivious update key management, go to step S322; when adopting identity-based oblivious update key management, go to step S323;

[0035] S322. The key management server KM calculates the update token where sk c is the private key of the client C and is the trapdoor information of the chameleon hash function, H0 is the encryption hash function, tag c is the tag of the client C, and tag c ′ is the new tag of the client C;

[0036] S323. The key management server KM calculates the update token where the identity of the client is ID c , is the private key of the client C and is the trapdoor information of the chameleon hash function, tag c is the tag of the client C, and tag c ′ is the new tag of the client C.

[0037] Furthermore, in step S4, the client interacts with the key management server KM. Through the updated ciphertext, it calculates the symmetric key using the chameleon hash function, decrypts the ciphertext to obtain the data object, and then obtains the hash value of the corresponding data object from the consortium chain to verify whether the decrypted data object has been tampered with. Specifically,

[0038] S41. When the client interacts with the key management server KM and requests to obtain the symmetric key d k generated based on the public key, go to step S42; when requesting to obtain the symmetric key d k generated based on the identity, go to step S43;

[0039] S42. After obtaining the symmetric key d k generated based on the public key, the client C restores the data object through the symmetric key d k where Dec is AES-256 decryption, and E is encrypted by the symmetric key d where Dec is AES-256 decryption, and E is encrypted by the symmetric key d kCiphertext of the encrypted data object; go to step S44;

[0040] S43. Obtain the symmetric key d generated based on the identity k , and the client C restores the data object through the symmetric key d k where Dec is AES-256 decryption, and E is the ciphertext of the data object encrypted by the symmetric key d ; go to step S44; k Ciphertext of the encrypted data object; go to step S44;

[0041] S44. The client obtains the hash value h' of the corresponding data object from the consortium blockchain, and verifies whether the encrypted hash function H0(O) is equal to the hash value h' of the data object. If they are equal, it means the data object has not been tampered with; otherwise, it means the data object has been tampered with.

[0042] Furthermore, in step S42, to obtain the symmetric key d generated based on the public key k , specifically,

[0043] S421. The client C sends a request to the key management server KM.

[0044] S422. The key management server KM selects a new tag tag c ' of the client C, and updates the output T of the bilinear map e to the new output T' = e(H0(tag c '), pk c ), where e is the bilinear map, H0 is the encrypted hash function, and pk c is the public key, and returns T' to the client C.

[0045] S423. After receiving the new output T' of the bilinear map e, the client C obtains the current random number R' from the ciphertext CT', and calculates the symmetric key d using the chameleon hash function k = H(e(R', g)·T'), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.

[0046] Furthermore, in step S43, to obtain the symmetric key d generated based on the identity k , specifically,

[0047] S431. The client C sends the identity ID c to the key management server KM.

[0048] S432. The key management server KM selects a new tag tag c ' of the client C, and calculates the new output of the bilinear map where H0 is the encrypted hash function and mpk is the master public key, and returns T' to the client C;

[0049] After receiving the new output T′ of the bilinear mapping e, C obtains the current random number R′ from the ciphertext CT′ and calculates the symmetric key d using the chameleon hash function k = H(e(R′, g)·T′), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.

[0050] The beneficial effects of the present invention are as follows: This method for managing the oblivious update of data encryption keys based on edge devices eliminates the need for certificate management, effectively reducing the cost of public key certificate management; the key management server regularly updates all client ciphertexts stored in the cloud server without interacting with the clients, and all encrypted data can only be decrypted by the current key, effectively avoiding security issues arising during the interaction between the clients and the key management server. This method can reduce the cost of public key certificate management and effectively improve the security of key updates. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 is a schematic flowchart of the method for managing the oblivious update of data encryption keys based on edge devices according to an embodiment of the present invention;

[0052] Figure 2 is a schematic flowchart of the encryption stage in the embodiment;

[0053] Figure 3 is a schematic flowchart of the key update stage in the embodiment;

[0054] Figure 4 is a schematic flowchart of the decryption stage in the embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0056] Embodiment

[0057] A method for managing the oblivious update of data encryption keys based on edge devices, as Figure 1 , includes the following steps,

[0058] S1. Initialization stage: When a client registers, obtain the system public parameters as security parameters, generate a private key and a public key pair, and generate an initial client tag.

[0059] S11. Generate system public parameters: G and G T are two cyclic multiplicative groups with the same prime order q, is the multiplicative group modulo q, g is the generator of G; the bilinear mapping e: G×G→G T, the bilinear mapping has two inputs and is linear with respect to each of these two inputs; the AES-256 symmetric encryption scheme (Enc, Dec), where Enc is AES-256 encryption and Dec is AES-256 decryption; the key length l; the chameleon hash function H: G → {0, 1} l , the encryption hash function H0: {0, 1} * → G, set the public parameters as pp, pp = (e, G, G T , q, g, H, H0, Enc, Dec);

[0060] S12. When using public-key oblivious key update management, go to step S13; when using identity-based oblivious key update management, go to step S14;

[0061] S13. Generate a private key and a public key pair: The key management server KM randomly selects and stores an element in the multiplicative group modulo q Take s as the private key sk of the client C c , and the key management server KM calculates the public key pk c = g s , and then send the public key pk c to the client C; Generate the client initial tag: The key management server KM selects and stores the tag tag of the specific client C c ← G; The tag here is unique to each client and will be updated within a certain period.

[0062] S14. Generate a private key and a public key pair: The PKG randomly selects as the master private key and generates the master public key mpk = g s , and the PKG generates the private key sk of the client from the client's identity ID c sk IDc = H0(ID c ) s ; Generate the client initial tag: The key management server KM selects and stores the tag of the specific client C in the multiplicative group modulo q The tag here is unique to each client and will be updated within a certain period.

[0063] S2. Encryption phase: The client uses the chameleon hash function to generate a symmetric key, encrypts the data object using the symmetric key to obtain the ciphertext, and stores the ciphertext in the cloud server STC. The client calculates the hash value of the data object and uploads it to the consortium blockchain. As Figure 2 , specifically:

[0064] S21. The client selects a method for generating a symmetric key. When using a symmetric key generated based on a public key, it proceeds to step S22; when using a symmetric key generated based on an identity, it proceeds to step S23;

[0065] S22. The client C uses a chameleon hash function to generate a symmetric key d based on the public key k , encrypts the data object O through a symmetric encryption algorithm, and calculates the symmetric key d k The ciphertext of the encrypted data object Obtains the ciphertext CT = (O id , R, E), where O id is the identity of the data object O, R is the random number selected in the symmetric key generation stage, and stores the ciphertext in the cloud server STC. The client calculates the hash value h = H0(O) of the data object and uploads it to the consortium blockchain.

[0066] In step S22, the client uses a chameleon hash function to generate a symmetric key d based on the public key k , specifically

[0067] S221. The client C sends a request to the key management server KM;

[0068] S222. The key management server KM selects the tag of the client C c , and calculates the output T of the bilinear mapping e as T = e(H0(tag c ), pk c ), where e is the bilinear mapping, H0 is the encryption hash function, tag c is the tag of the client C, and pk c is the public key, and sends T to the client C;

[0069] S223. After the client C receives the output T of the bilinear mapping e, it randomly selects an element R in the group and uses the chameleon hash function to calculate the symmetric key d k = H(e(R, g)·T), where e is the bilinear mapping, T is the output of the bilinear mapping e, H is the chameleon hash function, and g is the generator of the cyclic multiplicative group G.

[0070] S23. The client C uses the symmetric key d generated based on the identity k , encrypts the data object O through a symmetric encryption algorithm, and calculates the ciphertext of the data object encrypted by the symmetric key d k The ciphertext of the encrypted data object Obtains the ciphertext CT = (O id , R, E), where O idLet \(ID\) be the identity of the data object \(O\), \(R\) be the random number selected in the symmetric key generation phase, and the ciphertext be stored in the cloud server \(STC\). The client calculates the hash value \(h = H_0(O)\) of the data object and uploads it to the consortium blockchain.

[0071] In step \(S23\), the client uses the chameleon hash function to generate a symmetric key \(d\) based on the identity. k , specifically,

[0072] S231. The client \(C\) sends the identity \(ID\) c to the key management server \(KM\).

[0073] S232. The key management server \(KM\) selects the tag \(tag\) of the client \(C\) c , and calculates and sends it to the client \(C\), where \(H_0\) is the encryption hash function and \(mpk\) is the master public key.

[0074] S233. After receiving \(T\), the client \(C\) randomly selects an element \(R\) in the group and calculates the symmetric key \(d\) using the chameleon hash function k \(= H(e(R, g)\cdot T)\), where \(H\) is the chameleon hash function and \(g\) is the generator of the cyclic multiplicative group \(G\).

[0075] S3. Key update phase: Use the edge device as the key management server \(KM\). The key management server \(KM\) periodically updates the token using the trapdoor information of the chameleon hash function and sends the updated token to the cloud server \(STC\). The cloud server \(STC\) runs the key update algorithm to update all ciphertexts of the client. For example Figure 3 , specifically:

[0076] S31. The key management server \(KM\) changes the tag \(tag\) of the client \(C\) c to the new tag \(tag\) c ' of the client \(C\).

[0077] S32. The key management server \(KM\) calculates the updated token \(\varPsi\) using the trapdoor information of the chameleon hash function, and then sends the updated token \(\varPsi\) to the cloud server \(STC\).

[0078] In step \(S32\), the key management server \(KM\) calculates the updated token \(\varPsi\) using the trapdoor information of the chameleon hash function. Specifically,

[0079] S321. When using public key - based oblivious key management, go to step \(S322\); when using identity - based oblivious key management, go to step \(S323\).

[0080] S322. The key management server \(KM\) calculates the updated token where \(sk\)c is the private key of client C and the trapdoor information of the chameleon hash function, H0 is the encrypted hash function, tag c is the tag of client C, tag c ' is the new label of client C;

[0081] S323, the key management server KM calculates and updates the token Among them, the client's identity is ID c , is the private key of client C and the trapdoor information of the chameleon hash function, tag c is the tag of client C, tag c ′ is the new label of client C.

[0082] S33. After receiving the update token Ψ, the cloud server STC calculates the current random number R′=Ψ·R and the updated ciphertext CT′=(O id ,R′,E), where O id is the identity of the data object O.

[0083] S4, decryption phase: The client obtains the updated ciphertext through the cloud server STC, and interacts with the key management server KM to calculate the symmetric key through the updated ciphertext, decrypt the ciphertext, and obtain the data object. Figure 4 , specifically:

[0084] S41, the client interacts with the key management server KM and requests to obtain the symmetric key d generated based on the public key k When the process goes to step S42, a request is made to obtain a symmetric key d generated based on the identity. k When , go to step S43;

[0085] S42, obtain the symmetric key d generated based on the public key k , client C uses the symmetric key d k Recovering Data Objects Among them, Dec is AES-256 decryption, and E is the symmetric key d k Encrypted data object ciphertext; go to step S44.

[0086] In step S42, a symmetric key d generated based on the public key is obtained. k , specifically,

[0087] S421, the client C sends a request to the key management server KM;

[0088] S422, the key management server KM selects a new tag tag of the client C c', and update the output T of the bilinear mapping e to the new output T' of the bilinear mapping e = e(H0(tag c '), pk c ), where e is the bilinear mapping, H0 is the encryption hash function, and pk c is the public key, and return T' to the client C;

[0089] S423. After receiving the new output T' of the bilinear mapping e, the client C obtains the current random number R' from the ciphertext CT', and calculates d k = H(e(R', g)·T'), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.

[0090] S43. After obtaining the identity-based generated symmetric key d k , the client C restores the data object through the symmetric key d k where Dec is AES-256 decryption and E is the ciphertext of the data object encrypted by the symmetric key d ; enter step S44. k

[0091] In step S43, to obtain the identity-based generated symmetric key d k , specifically,

[0092] S431. The client C sends the identity ID c to the key management server KM;

[0093] S432. The key management server KM selects a new tag tag c ' of the client C and calculates the new output of the bilinear mapping where H0 is the encryption hash function and mpk is the master public key, and return T' to the client C;

[0094] S433. After receiving the new output T' of the bilinear mapping e, C obtains the current random number R' from the ciphertext CT' and calculates the symmetric key d k = H(e(R', g)·T'), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.

[0095] S44. The client obtains the hash value h' of the corresponding data object from the consortium blockchain, and verifies whether the encryption hash function H0(O) is equal to the hash value h' of the data object. If they are equal, it means the data object has not been tampered with; otherwise, it means the data object has been tampered with.

[0096] ​This data encryption key oblivious update management method based on edge devices eliminates the need for certificate management, effectively reducing the cost of public key certificate management. The key management server periodically updates all client ciphertexts stored in the cloud server without interacting with the clients. All encrypted data can only be decrypted by the current key, effectively avoiding security issues that may arise during the interaction between the client and the key management server. This method can reduce the cost of public key certificate management and effectively improve the security of key updates.

[0097] In the present invention, there is no need for a secure channel between the key management server KM and the cloud server STC, effectively enhancing security. It can achieve a fast update process and effectively improve the efficiency of oblivious update of encryption keys. This method can achieve more secure key management and is suitable for better promotion and use.

[0098] This data encryption key oblivious update management method based on edge devices uses the edge device as the key management server KM to save and periodically update the tags of the jurisdiction users. The cloud server STC is used to store all client ciphertexts. The update process is "oblivious" to the client. This method combines the characteristics of the chameleon hash algorithm and updatable encryption in one model, which can reduce the cost of public key certificate management and effectively improve the security of key updates.

[0099] In this data encryption key oblivious update management method based on edge devices, during encryption, the client encrypts the data object and stores the ciphertext on the cloud server, and then stores the hash value of the data object on an independent consortium chain, which is a blockchain jointly managed by multiple organizations. Each organization manages one or more nodes, and its data is only allowed to be read, written, and sent by different organizations within the system. During decryption, the symmetric key is obtained through the interaction between the key management server KM and the client to decrypt the data object. At the same time, the client ciphertext is periodically updated in combination with the chameleon hash algorithm, and this update process is "oblivious" to the client.

[0100] The data encryption key oblivious update management method based on edge devices can reduce the cost of public key certificate management and improve security. The hash algorithm is a one-way algorithm, while the chameleon hash algorithm is a trapdoor hash algorithm. In the chameleon hash algorithm, if the trapdoor information is known, the collision of any input data can be efficiently calculated, that is, the input can be changed to any value without changing the hash value output by the hash function. Using the identity-based chameleon hash algorithm to construct the UOKM scheme can effectively calculate the conflict between the encryption hash function and the trapdoor information. The encryption hash function in the chameleon hash algorithm can be used to construct the symmetric key, while the trapdoor information can be used to construct the update token. If the UOKM scheme is constructed by the chameleon hash algorithm, the public key certificate management can be eliminated. In addition, the trapdoor information can hide the update key in the token, and then the token can be transmitted on the open channel between the KM server and the STC, which enhances the security of the UOKM scheme.

[0101] In the whole process of the data encryption key oblivious update management method based on edge devices, the cloud server only stores the encrypted data ciphertext, which ensures the availability of the data in the cloud storage system, while other data such as private keys are stored in the consortium chain in exponential form, which ensures the confidentiality of the data. At the same time, the unconditional obliviousness and security of this method are based on the security of the chameleon hash function. In order to protect the data object and prevent the leakage of the label within a certain period, this method will regularly update the mark (key) of each client, so as to regularly update the ciphertext protected by the label. That is to say, the previous label cannot decrypt the updated ciphertext, and the updated label will not obtain the information of the ciphertext before the update, which ensures the forward and backward security.

[0102] The above is only the embodiment of the present invention and is not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. A method for oblivious update management of data encryption keys based on edge devices, characterized in that: It includes the following steps: S1. Initialization phase: When registering on the client side, obtain the system public parameters as security parameters, generate a private key and a public key pair, and generate an initial client tag; specifically, S11. Generate system public parameters: G and G T are two cyclic multiplicative groups with the same prime order q, is the multiplicative group modulo q, and g is the generator of G; the bilinear map e: G×G→G T , the bilinear map has two inputs and is linear with respect to each of the two inputs respectively; the AES-256 symmetric encryption scheme (Enc, Dec), where Enc is AES-256 encryption and Dec is AES-256 decryption; the key length l; the chameleon hash function H: G→{0, 1} l , the encryption hash function H0: {0, 1} * →G, set the public parameters as pp, pp = (e, G, G T , q, g, H, H0, Enc, Dec); S12. When using oblivious update key management based on public key, go to step S13; when using oblivious update key management based on identity, go to step S14; S13. Generate a private key and a public key pair: The key management server KM randomly selects and stores an element in the multiplicative group modulo q Take s as the private key sk of the client C c , and the key management server KM calculates the public key pk c = g s , and then sends the public key pk c to the client C; Generate the initial tag of the client: The key management server KM selects and stores the tag tag of the specific client C c ← G; S14. Generate a private key and a public key pair: The PKG randomly selects as the master private key and generates the master public key mpk = g s from it. The PKG generates the client's private key sk c = H0(ID IDc ) c ; Generate the client's initial tag: The key management server KM selects and stores the tag of a specific client C in the multiplicative group modulo q s ​ S2. Encryption phase: The client uses a chameleon hash function to generate a symmetric key, encrypts the data object with the symmetric key to obtain the ciphertext, and stores the ciphertext in the cloud server STC. The client calculates the hash value of the data object and uploads it to the consortium blockchain; specifically, S21. The client selects a method for generating the symmetric key. When using a symmetric key generated based on the public key, go to step S22; when using a symmetric key generated based on the identity, go to step S23; S22. The client C uses the chameleon hash function to generate a symmetric key d based on the public key k , encrypts the data object O through the symmetric encryption algorithm, and calculates the symmetric key d k The encrypted data object ciphertext Obtain the ciphertext CT = (O id , R, E), where O id is the identity of the data object O, R is the random number selected in the symmetric key generation stage, and stores the ciphertext in the cloud server STC. The client calculates the hash value h = H0(O) of the data object and uploads it to the consortium blockchain; S23. The client C generates a symmetric key d based on the identity using the chameleon hash function k , encrypts the data object O through the symmetric encryption algorithm, and calculates the ciphertext of the data object encrypted by the symmetric key d k Ciphertext of the data object to obtain the ciphertext CT = (O id , R, E), where O id is the identity of the data object O, R is the random number selected in the symmetric key generation phase, stores the ciphertext in the cloud server STC, and the client calculates the hash value h = H0(O) of the data object and uploads it to the consortium blockchain; S3. Key update phase: Use an edge device as the key management server KM. The key management server KM periodically updates the token using the trapdoor information of the chameleon hash function and sends the updated token to the cloud server STC. The cloud server STC runs the key update algorithm to update all the ciphertexts of the client; specifically, S31. The key management server KM changes the tag of the client C c to the new tag tag' of the client C c ; S32. The key management server KM calculates the updated token Ψ using the trapdoor information of the chameleon hash function, and then sends the updated token Ψ to the cloud server STC; S33. After the cloud server STC receives the update token Ψ, the cloud server STC calculates the current random number R' = Ψ·R, and the updated ciphertext CT' = (O id , R', E), where O id is the identity of the data object O; S4. Decryption phase: The client obtains the updated ciphertext through the cloud server STC. The client interacts with the key management server KM, calculates the symmetric key using the chameleon hash function through the updated ciphertext, decrypts the ciphertext to obtain the data object, and then obtains the hash value of the corresponding data object from the consortium blockchain to verify whether the decrypted data object has been tampered with; specifically, S41. The client interacts with the Key Management Server (KM) to request and obtain the symmetric key d generated based on the public key. k When requesting to obtain the symmetric key d generated based on the identity, proceed to step S42. k When requesting to obtain the symmetric key d generated based on the identity, proceed to step S43. S42. Obtain the symmetric key d generated based on the public key k , and the client C restores the data object through the symmetric key d k where Dec is AES-256 decryption, and E is the ciphertext of the data object encrypted by the symmetric key d ; enter step S44; k ​ S43. Obtain the symmetric key d generated based on the identity k , the client C restores the data object through the symmetric key d k ; where Dec is AES-256 decryption, and E is the ciphertext of the data object encrypted by the symmetric key d ; enter step S44 k ​ S44. The client obtains the corresponding hash value h' of the data object from the consortium blockchain, and verifies whether the encryption hash function H0(O) is equal to the hash value h' of the data object. If they are equal, it means the data object has not been tampered with; otherwise, it means the data object has been tampered with.

2. The method for managing the oblivious update of the data encryption key based on edge devices according to claim 1, wherein: In step S22, the client generates a symmetric key d based on the public key using the chameleon hash function k , specifically S221. The client C sends a request to the key management server KM; S222. The key management server KM selects the tag of the client C c , and calculates the output T = e(H0(tag c ), pk c ) of the bilinear mapping e, where e is the bilinear mapping, H0 is the encryption hash function, tag c is the tag of the client C, pk c is the public key, and sends T to the client C; After the client C receives the output T of the bilinear mapping e, it randomly selects an element R in the group and calculates the symmetric key d using the chameleon hash function k = H(e(R, g)·T), where e is the bilinear mapping, T is the output of the bilinear mapping e, H is the chameleon hash function, and g is the generator of the cyclic multiplicative group G.

3. The method for inadvertently updating and managing data encryption keys based on edge devices according to claim 1, wherein: In step S23, the client generates a symmetric key d based on the identity using the chameleon hash function k , specifically S231. The client C sends the identity ID c to the key management server KM; S232. The key management server KM selects the tag of the client C c , and calculates and sends it to the client C, where H0 is an encryption hash function and mpk is the public key S233. After the client C receives T, randomly select an element R in the group, and calculate the symmetric key d using the chameleon hash function k = H(e(R, g)·T), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.

4. The method for managing the oblivious update of the data encryption key based on edge devices according to claim 1, characterized in that: In step S32, the key management server KM calculates the updated token Ψ using the trapdoor information of the chameleon hash function, specifically, S321. When using oblivious update key management based on public key, go to step S322; when using oblivious update key management based on identity, go to step S323; S322. The key management server KM calculates an updated token where sk c is the private key of the client C and is the trapdoor information of the chameleon hash function, H0 is an encryption hash function, tag c is the tag of the client C, and tag c ' is the new tag of the client C; S323. The key management server KM calculates the updated token where the identity of the client is ID c , is the private key of client C and the trapdoor information of the chameleon hash function, tag c is the tag of client C, tag c ' is the new tag of client C.

5. The method for oblivious update management of data encryption keys based on edge devices according to claim 1, characterized in that: In step S42, a symmetric key d generated based on the public key is obtained k , specifically, S421. The client C sends a request to the key management server KM; S422. The key management server KM selects a new tag tag for the client C c ', and updates the output T of the bilinear map e to the new output T' of the bilinear map e = e(H0(tag c '), pk c ), where e is a bilinear map, H0 is an encryption hash function, and pk c is the public key, and returns T' to the client C; After receiving the new output T' of the bilinear mapping e, the client C obtains the current random number R' from the ciphertext CT', and calculates the symmetric key d using the chameleon hash function k = H(e(R', g) · T'), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.

6. The method for managing the oblivious update of the data encryption key based on the edge device according to claim 1, characterized in that: In step S43, obtain the symmetric key d generated based on the identity k , specifically S431. The client C sends the identity ID c to the key management server KM; S432. The key management server KM selects a new tag tag of the client C c ', and calculates a new output of the bilinear mapping e where H0 is an encryption hash function and mpk is the master public key, and returns T' to the client C; After receiving the new output T' of the bilinear mapping e, C obtains the current random number R' from the ciphertext CT' and calculates the symmetric key d using the chameleon hash function k = H(e(R', g) · T'), where H is the chameleon hash function and g is the generator of the cyclic multiplicative group G.