A data sharing method supporting policy fuzzy matching and bidirectional access control

By combining matching encryption technology, Lagrangian interpolation theorem and privacy protection set interpolation technology in cloud-edge computing services, fuzzy policy matching and two-way access control are realized, solving the data sharing problem that is difficult to achieve efficient and privacy protection in the existing technology, and improving the efficiency and security of data sharing.

CN115913667BActive Publication Date: 2025-06-13YANGTZE DEITA GRADUATE SCHOOI OF BEIJING INST OF TECH (JIAXING) +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211360060.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-02
Publication Date
2025-06-13
Estimated Expiration
2042-11-02

AI Technical Summary

Technical Problem

In cloud-edge computing services, it is difficult for the prior art to realize efficient data sharing that supports policy fuzzy matching and two-way access control, especially in many-to-many communication mode, traditional matching encryption technology cannot meet the needs of real-life applications.

Method used

The cloud-edge computing service model is used to combine matching encryption technology, Lagrangian interpolation theorem and privacy protection set interpolation technology to achieve fuzzy policy matching and two-way access control. The key is generated through the key generation center, and the edge device performs a matching process between attributes and access policies to ensure the privacy protection of both parties to the communication.

Benefits of technology

It realizes data sharing that supports fuzzy policy matching and two-way access control while protecting the privacy of both communication parties, reduces the overhead of computing and communication resources on the user side, and improves the efficiency and security of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913667B_ABST
    Figure CN115913667B_ABST
Patent Text Reader

Abstract

The present invention relates to a data sharing method that supports policy fuzzy matching and two-way access control, belonging to the technical field of cloud computing data processing. This method utilizes the cloud-edge computing service mode, matching encryption technology, Lagrange interpolation theorem, and private set intersection technology to achieve data sharing that supports a policy fuzzy matching mechanism and a two-way access control mechanism. It constructs to reduce the data sharing resource overhead through the cloud-edge computing service mode, realizes two-way access control that supports two-way privacy protection through matching encryption technology, realizes policy fuzzy matching through the Lagrange interpolation theorem, and realizes a secure matching operation proxy through private set intersection technology. This method has the functional advantage of simultaneously supporting a two-way access control mechanism and a policy fuzzy matching mechanism, and has significant advantages in terms of data privacy, data sharing efficiency, user-side resource overhead, and model security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a data sharing method supporting policy fuzzy matching and bidirectional access control, belonging to the technical field of cloud computing data processing. Background Art

[0002] In recent years, cloud computing has been widely applied in various fields, providing users with convenient and low-cost computing and storage services. However, with the explosive growth of the number of terminal devices, the communication delay between terminal devices and cloud service platforms has increased significantly, unable to meet the user's demand for low-latency service response. To solve this problem, cloud-edge computing, as an emerging computing, storage, and communication mode, has attracted great attention. Cloud-edge computing services can achieve fast service response, reduce the communication bandwidth limitation of terminal devices, and alleviate network congestion by integrating the resources of edge devices and cloud servers.

[0003] However, cloud-edge computing faces severe security and privacy issues, which limit the data sharing applications and development based on cloud-edge computing services. First, although compared with cloud computing, the data stored and processed by edge computing is closer to terminal devices, edge devices still cannot be fully trusted by users. With the rise of network attacks, edge devices are vulnerable to attacks such as eavesdropping, unauthorized modification, and unauthorized access to the system, which causes users to be afraid to share data for fear of sensitive information leakage. Second, the data transmission behavior between two users may lead to information leakage through an inference attack. Accurate sharing will expose the relationship between users and help observers clarify the social relationship between users.

[0004] Regarding the above security and privacy issues, the security requirements for data sharing applications based on cloud-edge computing service models are as follows:

[0005] (1) Data confidentiality: The data can be restored only when decryption is successful;

[0006] (2) User privacy: Even if an adversary observes the occurrence of data transmission, it cannot determine the exact sender or receiver;

[0007] (3) Resistance to collusion attacks: When the cloud server colludes with some edge devices, the cloud server cannot correctly decrypt the ciphertext.

[0008] To construct a secure data sharing scheme in the cloud-edge computing mode, attribute-based encryption method (ABE), access control technology, and access control encryption method (ACE) can be considered. However, in these traditional cryptographic primitives, the access policy is only formulated by one party, belonging to a one-to-many communication mode. To enable both the sender and the receiver to formulate access policies for each other, some technicians have proposed the matching encryption technology (ME). In addition, the data sharing method based on the matching encryption technology can achieve that during the data sharing process, information can be recovered if and only if the access policies of both communication parties are satisfied, otherwise no privacy information will be leaked.

[0009] However, the data sharing method based on the matching encryption technology requires an exact match between attributes and access policies. In data sharing based on the matching encryption technology, policy exact matching means that the received attributes and access policies must exactly match to enable data sharing. However, the policy exact matching mechanism cannot meet the requirements of the many-to-many communication mode in real-world applications. Specifically, the many-to-many communication mode means that a sender can specify access policies for multiple receivers, and vice versa. For example, in a healthcare system, assume that a hospital collaborates with other organizations to develop a new treatment method for certain diseases. The hospital only allows organizations that meet its access policy to access the corresponding case data, and the organization only accesses the case data sent by the hospital that meets its access policy. If the matching encryption technology is applied, the hospital needs to formulate corresponding access policies for each organization and generate ciphertext data, which causes huge computational and communication resource overheads.

[0010] Therefore, in cloud-edge computing services, how to implement an efficient and privacy-protected data sharing that supports a policy fuzzy matching mechanism and a two-way access control mechanism remains an unsolved technical problem. Summary of the Invention

[0011] The object of the present invention is to address the deficiencies of the existing technology. To solve the technical problems such as the security and privacy of data between communication parties, policy fuzzy matching, two-way access control, and the sharing efficiency and computational overhead of large-scale data in cloud-edge computing service data sharing, a data sharing method that supports policy fuzzy matching and two-way access control is creatively proposed. This method, based on the edge cloud computing service mode, supports realizing the data sharing function that supports the policy fuzzy matching mechanism and the two-way access control mechanism while protecting the privacy of both communication parties, and at the same time greatly reduces the overhead of the user side and improves the data sharing efficiency.

[0012] The innovation of this method lies in: using the cloud-edge computing service model, matching encryption technology, Lagrange interpolation theorem, and private set intersection technology for privacy protection to achieve data sharing that supports a policy fuzzy matching mechanism and a two-way access control mechanism. It constructs a mechanism to reduce the resource overhead of data sharing through the cloud-edge computing service model, realizes two-way access control that supports two-way privacy protection through matching encryption technology, realizes policy fuzzy matching through the Lagrange interpolation theorem, and realizes a secure matching operation proxy through the private set intersection technology for privacy protection.

[0013] To achieve the above object, the present invention adopts the following technical solutions.

[0014] First, relevant concepts are explained.

[0015] Key Generation Center (KGC): The Key Generation Center is responsible for generating key information for entities participating in data sharing. After system initialization and user registration are completed, the Key Generation Center is in an offline or dormant state and does not participate in the data sharing stage.

[0016] Cloud Server (Cloud): The Cloud Server is responsible for storing the ciphertext data uploaded by the sender.

[0017] Edge Devices: As an intermediate layer, Edge Devices are responsible for storing part of the ciphertext data uploaded by the sender, the ciphertext data of attributes and access policies uploaded by the sender and the receiver, executing the matching process of attributes and access policies, obtaining the ciphertext data sent by the sender that meets the data sharing requirements from the Cloud Server, and forwarding it to the corresponding receiver.

[0018] Sender: The Sender is responsible for generating data, sender attributes, and receiver access policies for data sharing, executing the data encryption process, and sending the data ciphertext, attribute ciphertext, and access policy ciphertext to the Edge Devices.

[0019] Receiver: The Receiver is responsible for generating receiver attributes and sender access policies, encrypting this data and sending it to the Edge Devices for the matching process. Thereafter, the Receiver executes the decryption process and decrypts the correct plaintext information from the ciphertext data returned by the Edge Devices.

[0020] In the present invention, the Key Generation Center is completely trusted, and the communication channel between key generation and any other entity is secure. The Edge Devices, Cloud Server, Sender, and Receiver are all malicious entities, and the Cloud Server can collude with the Edge Devices to obtain relevant sensitive information. The present invention can resist chosen-ciphertext attack (IND-CCA).

[0021] A data sharing method supporting policy fuzzy matching and bidirectional access control, comprising the following steps:

[0022] Step 1: Initialization. The key generation center generates a master key and public parameters, and distributes the public parameters to all legitimate users and edge devices.

[0023] Specifically, first, given the security parameter 1 λ , the key generation center generates as the bilinear mapping group applied in the method of the present invention, where λ represents a positive integer preset by the system, 1 λ represents a string of 0 / 1 with length λ; p represents a prime number with length 1 λ ; represents a multiplicative cyclic group of order p; represents a multiplicative cyclic group of order p; g represents the generator of the multiplicative cyclic group ; e represents the relationship i.e.: after performing a bilinear operation on 2 elements in it is mapped to an element in

[0024] Subsequently, the key generation center selects elements g and h from the multiplicative cyclic group , and selects elements α and β from the prime field . Calculate the public key components:

[0025] Y α = e(g, g) α

[0026] Y β = e(g, g) β

[0027] where g represents an element in the multiplicative cyclic group , is a positive integer; h represents an element in the multiplicative cyclic group , is a positive integer; represents the prime field composed of {0, 1, 2,..., p - 1} with order p; α represents an element in the prime field , is a positive integer; β represents an element in the prime field , is a positive integer; Y α is a public key component; Y β is a public key component.

[0028] After that, the key generation center selects positive integers n and d, and 2n + 2 random numbers {t 1 , t 2 , …, t n+1} and {d 1 , d 2, …, d n+1}。The key generation center calculates the public key components for the

[0029]

[0030]

[0031] where n is a positive integer; d is a positive integer; t 1 is a random number; d 1 is a random number; i is a loop sequence number; T i is a public key component; D i is a public key component.

[0032] Finally, the key generation center takes (α, β) as the master secret key msk, and takes (Y α , Y β , {T i}, i=1,2,…,n+1 , {D i} i=1,2,…,n+1 ) as the public key mpk, and distributes the public parameters to all legitimate users and edge devices.

[0033] Step 2: User registration. The sender and the receiver submit their own attributes to the key generation authority as registration information. The key generation center generates an encryption key for the sender and a decryption key for the receiver.

[0034] Specifically, it includes the following steps:

[0035] Step 2.1: Encryption key for the sender.

[0036] First, the sender sends its own attribute data σ and the specified receiver access policy data to the key generation center. σ represents the sender's attribute data, represents the receiver access policy data that the sender specifies the receiver needs to satisfy.

[0037] Subsequently, the key generation center calculates ek σ = {ek i}, i ∈ σ, where:

[0038]

[0039] where i represents the loop sequence number in the sender's attribute data σ; ek σ represents the set of encryption keys generated by the key generation center according to the sender's attribute σ; ek iDenotes the encryption key generated by the key generation center according to the $i$-th attribute in the sender attribute set $\sigma$; $g$ denotes an element in the multiplicative cyclic group, which is a positive integer; $t$ is a random number generated by the key generation center; $q$ i is a random number generated by the key generation center; $q$ 1 $(x)$ represents a polynomial of degree $d - 1$ randomly selected by the key generation center, and $q$ 1 $(x)=\alpha + a$ 1 $x+\cdots + a$ d-1 $x$ d-1 ; $\alpha$ is one of the master keys generated by the key generation center, $x$ represents the unknown variable, and $a$ i represents the coefficient of the polynomial $q$ 1 $(x)$, and $x$ d-1 represents the $(d - 1)$-th power of the polynomial variable $x$.

[0040] After that, the key generation center calculates the Lagrange coefficient set of the polynomial according to the polynomial $q$ 1 $(x)$ and the Lagrange interpolation theorem as follows: where $j$ represents the loop serial number in the attribute set, represents that the value of the $j$-th attribute of the sender is represents the Lagrange coefficient set generated for the sender. The specific calculation process is as follows:

[0041]

[0042] where, represents the $i$-th Lagrange coefficient, and this Lagrange coefficient is calculated from the point in the attribute value set ; $|\sigma|$ represents the number of attribute values in the sender attribute set.

[0043] Finally, the key generation center sends to the sender through a secure channel.

[0044] Step 2.2: The receiver decrypts the key.

[0045] First, the receiver sends its own attribute data $\rho$ and the specified sender access policy data to the key generation center, where $\rho$ represents the receiver attribute data; represents the sender access policy data that the receiver formulates and requires the sender to meet.

[0046] Subsequently, the key generation center calculates $dk$ ρ $=\{dk$ i $\}$, $i\in\rho$, where:

[0047]

[0048] Among them, i represents the loop serial number in the recipient attribute data ρ; dk ρ represents the set of decryption keys generated by the key generation center according to the recipient attribute ρ; dk i represents the decryption key generated by the key generation center according to the i-th attribute in the recipient attribute set ρ; g represents the multiplicative cyclic group element in, which is a positive integer; d 1 is a random number generated by the key generation center; q 2 q(x) represents a polynomial of degree d - 1 randomly selected by the key generation center, and q 1 q(x) = β + b 1 x + … + b d-1 x d-1 ; β is one of the master keys generated by the key generation center; x represents the unknown variable; b i represents the coefficient of the polynomial q 2 q(x); x d-1 represents the (d - 1)-th power of the polynomial variable x.

[0049] After that, the key generation center calculates the Lagrange coefficient set of the polynomial according to the polynomial q 2 q(x), combined with the Lagrange interpolation theorem as j represents the loop serial number in the attribute set. represents that the value of the j-th attribute of the sender is represents the set of Lagrange coefficients generated for the recipient. The specific calculation process is as follows:

[0050]

[0051] Among them, represents the i-th Lagrange coefficient, and this Lagrange coefficient is calculated from the point in the attribute value set ; |ρ| represents the number of attribute values in the recipient attribute set.

[0052] Finally, the key generation center sends to the sender through a secure channel.

[0053] Step 3: Data encryption.

[0054] The sender combines the data received from the key generation center with the access policy formulated by the sender for the recipient and the data m that the sender wants to share, generates ciphertext data, and sends it to the edge device. Among them, represents the data returned by the key generation center to the sender during the user registration phase, It represents the access policy data executed by the sender for the receiver, and m represents the data information that the sender wants to share.

[0055] Specifically, first, the sender selects 4 random numbers Among them, u, t, r 1 , r 2 belong to the elements in the prime number field The sender calculates to obtain U, T, R 1 , R 2 , and the calculation process is as follows:

[0056] U = g u

[0057] T = g t

[0058]

[0059]

[0060] Among them, g represents an element in the multiplicative cyclic group ; is a positive integer; U, T, R 1 , R 2 are part of the ciphertext data sent by the sender.

[0061] Subsequently, the sender calculates and as part of the ciphertext data sent by the sender, and the calculation process is as follows:

[0062]

[0063]

[0064] Among them, i is the serial number for looping through the receiver's access policy ; Di represents a part of the public key data published by the key generation center; T i represents a part of the public key data published by the key generation center; {P i} represents a part of the ciphertext data sent by the sender; {E i} represents a part of the ciphertext data sent by the sender.

[0065] After that, the sender calculates W, K 1 , K 2 as part of the ciphertext data, and the specific calculation process is as follows:

[0066]

[0067]

[0068]

[0069] Among them, i is the serial number for loop traversing to receive the access policy ; represents the sender's attribute value; represents the number of elements in the sender's attribute set, that is, the number of points in polynomial fitting; ek i represents the encryption key of the sender; represents the value when the variable is equal to 0 in the Lagrange coefficient, that is, α whose value is equal to one of the master key values generated by the key generation center; d represents the degree of the polynomial in the Lagrange polynomial, that is, the minimum number of attribute values required to recover the secret, and is also the threshold detailed in the access policy that the receiver wants to satisfy to recover the secret; e(·) represents mapping to a certain element in after bilinear operation of two α represents one of the public keys generated by the key generation center; Y β represents one of the public keys generated by the key generation center; represents the public key Y β 's r 1 th power; represents the public key Y α 's r 2 th power; The operator · represents the multiplication operation.

[0070] After that, the sender calculates and obtains V as part of the ciphertext data, and the calculation process is as follows:

[0071]

[0072] Among them, the operator represents the exclusive OR operator; m represents the data that the sender wants to share; H(·) represents the hash function.

[0073] Subsequently, the sender uses the Elgamal encryption algorithm as the basic tool, takes the sender's own attributes and the specified receiver access policy as inputs, and obtains the corresponding output ciphertext E(σ) and Among them, E(σ) represents the result after encrypting the sender's attribute data σ using the Elgamal encryption algorithm, represents the result after encrypting the access policy data specified by the sender using the Elgamal encryption algorithm.

[0074] Finally, the sender integrates the ciphertext C = (T, U, {P i}, {E i}, W, K 1 , K 2 , V). The sender then Sent to the edge device. Among them, Index represents the index that can be linked to the sender; E(σ) represents the result after encrypting the sender's attribute data σ using the Elgamal encryption algorithm; represents the result after encrypting the access policy data formulated by the sender using the Elgamal encryption algorithm; C represents the ciphertext data sent by the sender.

[0075] Step 4: Policy matching.

[0076] The edge device uses the sender's attributes, the receiver's access policy, the receiver's attributes, and the sender's access policy encrypted by the Elgamal encryption algorithm received, and performs policy matching based on the privacy-preserving set intersection technology (Privacy-preserving Set Intersection), and returns the successfully matched sender data to the corresponding receiver.

[0077] Specifically, the edge device generates a vector and calculates as the initial vector for performing the privacy-preserving set intersection technology. Among them, represents the initial vector for performing the privacy-preserving set intersection technology generated by the edge device; I i represents the initial vector The i-th element in is a random even number; represents the initial vector after encryption using the Elgamal encryption algorithm

[0078] Subsequently, the edge device near the sender combines the sender's attribute σ and the receiver's access policy calculates and and sends these two results to the other edge devices.

[0079] Taking as an example, the specific calculation rule of the privacy-preserving set intersection technology is that if an element is simultaneously in σ and it remains unchanged. Otherwise, it will be replaced by a randomly generated odd number. Among them, the operation ∩ represents the set intersection operation; σ represents the sender's attribute data; represents the access policy for the receiver formulated by the sender.

[0080] When the edge device near the receiver receives and After that, combined with the receiver's attribute data ρ and the sender's access policy formulated by the receiver Calculate to obtain and Among them, the operation ∩ represents the set intersection operation; σ represents the sender's attribute data; Represents the receiving access policy formulated by the sender; Represents the sending access policy formulated by the receiver; ρ represents the receiver attribute data.

[0081] First, compare the execution results of the comparison algorithm and Find the identical items between them, and let the number of identical items be d 1 , that is Among them, Represents the number of direct matches between the sender access policy and the sender attributes; σ represents the sender attribute data; Represents the sending access policy formulated by the receiver.

[0082] Secondly, compare the execution results of the comparison algorithm and Find the identical items between them, and let the number of identical items be d 2 , that is Among them, Represents the number of direct matches between the receiver access policy and the receiver attributes; Represents the receiving access policy formulated by the sender; ρ represents the receiver attribute data.

[0083] Finally, the edge device compares d 1 ≥d ∧ d 2 ≥d, then it is considered that the current sender and receiver match successfully, and retrieve the ciphertext of the sender according to the sender Index, and then return this ciphertext to the receiver. Among them, d 1 Represents the number of direct matches between the sender access policy and the sender attributes; d 2 Represents the number of direct matches between the receiver access policy and the receiver attributes; d represents the threshold for the sender and receiver to execute policy matching this time; Index represents the identity index of the sender.

[0084] Step 5: Data decryption.

[0085] The receiver receives the sender ciphertext data C returned from the edge device, combines the receiver's own attribute ρ and the sender access policy Execute the decryption process and obtain the data m to achieve data sharing.

[0086] Specifically, first, the receiver decrypts from the ciphertext C to obtain (T, U, {P i}, {E i}, W, K 1 , K 2 , V). Among them, (T, U, {P i}, {E i}, W, K 1 , K2 , (V) are all ciphertext data sent by the sender to the edge device.

[0087] The receiver calculates g T,1 and combines g T,2 , as part of the decryption data, the calculation process is as follows:

[0088]

[0089]

[0090] Among them, i represents the loop sequence number in the continuous multiplication operator; j represents the receiver access policy loop sequence number; dk i represents the decryption key generated by the key generation center for the receiver; represents the value of the Lagrange coefficient generated by the key generation center for the receiver when the variable is equal to 0, that is, the master key β generated by the key generation center; represents the value of the j-th attribute in the receiver access policy; represents the number of elements in the receiver access policy set; d represents the threshold for the sender and receiver to execute policy matching this time; represents the sender access policy formulated by the receiver.

[0091] Finally, the receiver recovers the data sent by the sender Among them, the operator represents the exclusive OR operator; m represents the data that the sender wants to share; H(·) represents the hash function.

[0092] Beneficial effects

[0093] This method, compared with the prior art, has the functional advantages of simultaneously supporting the two-way access control mechanism and the policy fuzzy matching mechanism, and also has significant advantages in terms of data privacy, data sharing efficiency, user-side resource overhead, and model security. Description of the drawings

[0094] Figure 1 is a schematic diagram of the implementation of the method of the present invention. Detailed implementation manners

[0095] The present invention will be further described in detail below with reference to the drawings.

[0096] As Figure 1 shown, a data sharing method that supports policy fuzzy matching and two-way access control.

[0097] (1) The Key Generation Center (KGC) executes the system initialization process, generates the system master key and public parameters, and distributes the public parameters to all legitimate entities within the system. (2) The sender and the receiver register with the KGC and obtain the corresponding keys; (3) The sender generates a series of ciphertexts based on the key generated by the key generation center and the access policy of the receiver, and uses the Elgamal encryption algorithm to generate the ciphertext of the access policy and the attribute ciphertext used in the private set intersection technology, and then sends them to the edge device; (4) The edge device retains the ciphertexts used in the matching phase, that is, the sender's attributes and the receiver's access policy, and then uploads the remaining ciphertexts to the cloud; (5) The receiver sends the ciphertext of the attributes and the ciphertext of the access policy used in the private set intersection technology to the edge device; (6) The edge device performs the matching, and when the matching is successful, the edge device sends a data request to the cloud server; (7) The cloud server returns the corresponding data to the edge device, and the edge device returns the data to the receiver; (8) The receiver performs the decryption phase to recover the message.

[0098] Combined with Figure 1 , the specific implementation details of a data sharing method supporting policy fuzzy matching and two-way access control are as follows:

[0099] Step 1: Initialization. The key generation center generates the master key and public parameters, and distributes the public parameters to all legitimate users and edge devices.

[0100] Specifically, first, given the security parameter 1 λ , the key generation center generates as the bilinear mapping group applied in the method of the present invention. Where λ represents a positive integer preset by the system; 1 λ represents a string of 0s or 1s with a length of λ; p represents a prime number with a length of 1 λ ; represents a multiplicative cyclic group of order p; represents a multiplicative cyclic group of order p; g represents the generator of the multiplicative cyclic group ; e represents the relationship that is, after performing a bilinear operation on 2 elements in it is mapped to an element in

[0101] Subsequently, the key generation center selects elements g and h from the multiplicative cyclic group , and selects elements α and β from the prime field . Calculate the public key components:

[0102] Y α = e(g,g) α

[0103] Yβ = e(g, g) β

[0104] where g represents an element of the multiplicative cyclic group, and is a positive integer; h represents an element of the multiplicative cyclic group and is a positive integer; represents the prime field consisting of {0, 1, 2, …, p - 1} with order p; α represents an element of the prime field and is a positive integer; β represents an element of the prime field and is a positive integer; Y is a component of the public key; Y α is a component of the public key. β

[0105] After that, the key generation center selects positive integers n and d, and 2n + 2 random numbers {t 1 , t 2 , …, t n+1} and {d 1 , d 2 , …, d n+1}. The key generation center calculates the public key components for :

[0106]

[0107]

[0108] where n is a positive integer; d is a positive integer; t 1 is a random number; d 1 is a random number; i is a loop sequence number; T i is a component of the public key; D i is a component of the public key.

[0109] Finally, the key generation center takes (α, β) as the master secret key msk, takes (Y α , Y β , {T i} i=1,2,…,n+1 , {D i} i=1,2,…,n+1 ) as the public key mpk, and takes as the public parameters and distributes them to all legitimate users and edge devices. Here, msk represents the master secret key; mpk represents the public key.

[0110] Step 2: User registration. The sender and the receiver submit their own attributes to the key generation authority as registration information. The key generation center generates an encryption key for the sender and a decryption key for the receiver.

[0111] ​Specifically, it can be divided into the sender's encryption key generation process and the receiver's decryption key generation process.

[0112] Step 2.1: Sender's encryption key generation process.

[0113] First, the sender sends its own attribute data σ and the formulated receiver access policy data to the key generation center. Among them, σ represents the sender's attribute data; represents the access policy data that the receiver needs to meet as formulated by the sender.

[0114] Subsequently, the key generation center calculates ek σ ={ek i}(i ∈ σ), where where i represents the loop sequence number in the sender's attribute data σ; ek σ represents the set of encryption keys generated by the key generation center according to the sender's attribute σ; ek i represents the encryption key generated by the key generation center according to the i-th attribute in the sender's attribute set σ; g represents an element in the multiplicative cyclic group and is a positive integer; t 1 is a random number generated by the key generation center; q 1 (x) represents a polynomial of degree d - 1 randomly selected by the key generation center, and q 1 (x)=α + a 1 x + … + a d-1 x d -1 ; α is one of the master keys generated by the key generation center; x represents the unknown variable; a i represents the coefficient of the polynomial q 1 (x); x d-1 represents the (d - 1)-th power of the polynomial variable x.

[0115] After that, the key generation center calculates the set of Lagrange coefficients of the polynomial according to the polynomial q 1 (x) in combination with the Lagrange interpolation theorem as where j represents the loop sequence number in the attribute set; represents the value of the j-th attribute of the sender as represents the set of Lagrange coefficients generated for the sender. The calculation process is as follows:

[0116]

[0117] where, represents the i-th Lagrange coefficient, and this Lagrange coefficient is determined by the point in the set of attribute values Computationally generated; |σ| represents the number of attribute values in the sender's attribute set.

[0118] Finally, the key generation center sends to the sender through a secure channel.

[0119] Step 2.2: Receiver decrypts the key generation process.

[0120] First, the receiver sends its own attribute data ρ and the formulated sender access policy data to the key generation center. Among them, ρ represents the receiver's attribute data; represents the access policy data that the sender needs to meet as formulated by the receiver.

[0121] Subsequently, the key generation center calculates dk ρ ={dk i}(i ∈ ρ), where where i represents the loop serial number in the receiver's attribute data ρ; dk ρ represents the set of decryption keys generated by the key generation center according to the receiver's attribute ρ; dk i represents the decryption key generated by the key generation center according to the i-th attribute in the receiver's attribute set ρ; g represents an element in the multiplicative cyclic group and is a positive integer; d 1 is a random number generated by the key generation center; q 2 (x) represents a polynomial of degree d - 1 randomly selected by the key generation center, and q 1 (x)=β + b 1 x + … + b d-1 x d -1 ; β is one of the master keys generated by the key generation center; x represents the unknown variable; b i represents the coefficient of the polynomial q 2 (x); x d-1 represents the (d - 1)-th power of the polynomial variable x.

[0122] After that, the key generation center calculates the Lagrange coefficient set of the polynomial according to the polynomial q 2 (x) in combination with the Lagrange interpolation theorem as where j represents the loop serial number in the attribute set; represents the value of the j-th attribute of the sender as represents the Lagrange coefficient set generated for the receiver. The calculation process is as follows:

[0123]

[0124] where represents the i-th Lagrangian coefficient, and the Lagrangian coefficient is the midpoint of the attribute value set Calculated and generated; |ρ| represents the number of attribute values ​​in the receiver's attribute set.

[0125] Finally, the key generation center sends Sent to the sender.

[0126] Step 3: Data encryption.

[0127] The sender receives the data from the key generation center. Combined with the access policy set by the sender for the receiver The sender wants to share the data m, generate ciphertext data, and send it to the edge device. Indicates the data returned by the sender during the user registration phase. It represents the access policy data executed by the sender for the receiver; m represents the data information that the sender wants to share.

[0128] Specifically, first, the sender selects 4 random numbers where u, t, r 1 ,r 2 Belongs to the prime field The sender calculates U, T, R 1 ,R 2 , the calculation process is as follows:

[0129] U=g u

[0130] T=g t

[0131]

[0132]

[0133] Where g represents the multiplication cyclic group The elements in the equation are positive integers; U, T, R 1 ,R 2 As part of the ciphertext data sent by the sender.

[0134] Then, the sender calculates and As part of the ciphertext data sent by the sender, the calculation process is as follows:

[0135]

[0136]

[0137] Among them, i is the serial number for traversing the receiving access policy ; D i represents a part of the public key data published by the key generation center; T i represents a part of the public key data published by the key generation center; {P i} represents a part of the ciphertext data sent by the sender; {E i} represents a part of the ciphertext data sent by the sender.

[0138] After that, the sender calculates W, K 1 , K 2 as part of the ciphertext data. The specific calculation process is as follows:

[0139]

[0140]

[0141]

[0142] Among them, i is the serial number for traversing the receiving access policy ; represents the sender's attribute value; represents the number of elements in the sender's attribute set, that is, the number of points in the polynomial fitting; ek i represents the encryption key of the sender; represents the value of the Lagrange coefficient when the variable is equal to 0, that is, α whose value is equal to one of the master key values generated by the key generation center; d represents the degree of the polynomial in the Lagrange polynomial, that is, the minimum number of attribute values required to recover the secret, and is also the threshold detailed in the access policy that the receiver wants to satisfy to recover the secret; e(·) represents mapping to a certain element in after the bilinear operation of two α represents one of the public keys generated by the key generation center; Y β represents one of the public keys generated by the key generation center; represents the public key Y β to the power of r 1 ; represents the public key Y α to the power of r 2 ; The operator · represents the multiplication operation.

[0143] After that, the sender calculates and obtains V as part of the ciphertext data. The calculation process is as follows:

[0144]

[0145] Among them, the operator represents the exclusive - or operator; m represents the data that the sender wants to share; H(·) represents the hash function.

[0146] Subsequently, the sender uses the Elgamal encryption algorithm as a basic tool, takes the sender's own attributes and the formulated receiver access policy as inputs, and obtains the corresponding output ciphertext E(σ) and where E(σ) represents the result after encrypting the sender's attribute data σ using the Elgamal encryption algorithm; represents the result after encrypting the access policy data formulated by the sender using the Elgamal encryption algorithm.

[0147] Finally, the sender integrates the ciphertext C=(T, U, {P i}, {E i}, W, K 1 , K 2 , V). The sender then sends to the edge device. Among them, Index represents the index that can link to the sender; E(σ) represents the result after encrypting the sender's attribute data σ using the Elgamal encryption algorithm; represents the result after encrypting the access policy data formulated by the sender using the Elgamal encryption algorithm; C represents the ciphertext data sent by the sender.

[0148] Step 4: Data synchronization.

[0149] The edge device retains the ciphertexts used in the matching phase, namely: the sender's attributes and the receiver access policy, and uploads the remaining ciphertexts to the cloud.

[0150] Specifically, for the sender, the edge device receives the attribute ciphertext data E(σ) sent by the sender, the receiver access policy ciphertext data the shared information ciphertext data C=(T, U, {P i}, {E i}, W, K 1 , K 2 , V). The edge device synchronously uploads the shared information ciphertext data C that has not been accessed for more than the set time to the cloud server and deletes the local storage on the edge device, thereby reducing the storage overhead of the edge device.

[0151] For the receiver, the edge device receives the attribute ciphertext data E(ρ) sent by the receiver, the receiver access policy ciphertext data This data does not need to be synchronized to the cloud server.

[0152] Step 5: Trapdoor generation.

[0153] The receiving party generates the ciphertext E(ρ) and where E(ρ) represents the ciphertext after encrypting the receiving party's attribute data using the Elgamal encryption algorithm tool; represents the ciphertext after encrypting the access policy of the sending party formulated by the receiving party using the Elgamal encryption algorithm tool.

[0154] After that, the receiving party sends the ciphertext data E(ρ) and to the edge device.

[0155] Step 6: Policy matching.

[0156] The edge device uses the sender's attributes, the receiving party's access policy, the receiving party's attributes, and the sender's access policy encrypted using the Elgamal encryption algorithm received, and performs policy matching based on the privacy-preserving set intersection technology (Privacy-preserving Set Intersection), and returns the successfully matched sender data to the corresponding receiving party.

[0157] Specifically, the edge device generates the vector and calculates as the initial vector for performing the privacy-preserving set intersection technology. Among them, represents the initial vector generated by the edge device for performing the privacy-preserving set intersection technology; I i represents the initial vector the i-th element in, is a random even number; represents the initial vector after encrypting using the Elgamal encryption algorithm

[0158] Subsequently, the edge device near the sender combines the sender's attribute σ and the receiving party's access policy and calculates and and sends these two results to the other edge devices. For the specific calculation rule of the privacy-preserving set intersection technology is that if the element is in both σ and it remains unchanged. Otherwise, it will be replaced by a randomly generated odd number. For the specific calculation rule of the privacy-preserving set intersection technology is that if the element is in both and it remains unchanged. Otherwise, it will be replaced by a randomly generated odd number. Among them, the operation symbol ∩ represents the set intersection operation; σ represents the sender's attribute data; represents the access policy of the receiving party formulated by the sender.

[0159] When the edge device near the receiving party receives and After that, combining the recipient's attribute data ρ and the sender access policy formulated by the recipient calculate to obtain and For The specific calculation rule of the privacy-preserving set intersection technology is that if an element is simultaneously in σ and then it remains unchanged. Otherwise, it will be replaced by a randomly generated odd number. For The specific calculation rule of the privacy-preserving set intersection technology is that if an element is simultaneously in ρ and then it remains unchanged. Otherwise, it will be replaced by a randomly generated odd number. Among them, the operation symbol ∩ represents the set intersection operation; σ represents the sender's attribute data; represents the recipient access policy formulated by the sender; represents the sender access policy formulated by the recipient; ρ represents the recipient's attribute data.

[0160] First, compare the same items between the execution results of the comparison algorithm and Let the number of same items be d 1 , that is Among them, represents the number of direct matches between the sender access policy and the sender's attributes; σ represents the sender's attribute data; represents the sender access policy formulated by the recipient.

[0161] Compare the same items between the execution results of the comparison algorithm and Let the number of same items be d 2 , that is Among them, represents the number of direct matches between the recipient access policy and the recipient's attributes; represents the sender access policy formulated by the recipient; ρ represents the recipient's attribute data.

[0162] Then, the edge device compares d 1 ≥d ∧ d 2 ≥d, then it is considered that the current sender and recipient match successfully, and the ciphertext of the sender is requested from the cloud server according to the sender Index. Among them, d 1 represents the number of direct matches between the sender access policy and the sender's attributes; d 2 represents the number of direct matches between the recipient access policy and the recipient's attributes; d represents the threshold for the execution policy matching between the sender and the recipient this time; Index represents the identity index of the sender.

[0163] Step 7: Data Return. After the cloud server receives the data request uploaded by the edge device, it returns the corresponding data to the edge device.

[0164] Specifically, after successful matching by the edge device, i.e., when d 1 ≥d ∧ d 2 ≥d holds, the edge device first retrieves its local database to check if it contains the data of the current Index. If the local database contains this data, it is directly returned to the recipient. Otherwise, it requests the sender's ciphertext from the cloud server based on the sender's Index. After the cloud server receives the data request from the edge device, it performs data retrieval in combination with the sender's Index uploaded by the edge device, and finds the corresponding data C = (T, U, {P i}, {E i}, W, K 1 , K 2 , V). Then, it returns the data to the edge device. Subsequently, the edge device sends the data C to the recipient.

[0165] Step 8: Data Decryption. The recipient receives the sender's ciphertext data C returned from the edge device, and combines its own attribute ρ and the sender's access policy to execute the decryption process and obtain the data m.

[0166] First, the recipient decrypts (T, U, {P i}, {E i}, W, K 1 , K 2 , V) from the ciphertext C. Among them, (T, U, {P i}, {E i}, W, K 1 , K 2 , V) are all ciphertext data sent by the sender to the edge device.

[0167] The recipient calculates g T,1 and g T,2 , as part of the decrypted data. The calculation process is as follows:

[0168]

[0169]

[0170] Among them, i represents the loop sequence number in the product operator; j represents the recipient's access policy loop sequence number; dk i represents the decryption key generated by the key generation center for the recipient; represents the value of the Lagrange coefficient generated by the key generation center for the recipient when the variable is equal to 0, that is, the master key β generated by the key generation center; Denote the value of the j-th attribute in the recipient's access policy; Denote the number of elements in the recipient's access policy set; d represents the threshold for the sender and the recipient to execute policy matching this time; Denote the access policy for sending formulated by the recipient.

[0171] Finally, the recipient recovers the data sent by the sender Among them, the operator Denote the exclusive OR operator; m represents the data that the sender wants to share; H(·) represents the hash function.

Claims

1. A data sharing method supporting policy fuzzy matching and two-way access control, characterized in that, it includes the following steps: Step 1: The key generation center generates a master key and public parameters, and distributes the public parameters to all legitimate users and edge devices; Step 2: The sender and the receiver submit their own attributes to the key generation agency as registration information; the key generation center generates an encryption key for the sender and a decryption key for the receiver; Step 2.1: The sender encrypts the key; First, the sender sends its own attribute data σ and the specified access policy data of the recipient to the key generation center; σ represents the sender's attribute data, represents the access policy data that the recipient specified by the sender needs to meet; Subsequently, the key generation center calculates ek based on the data received from the sender σ ={ek i}, i ∈ σ, where: where, i represents the cyclic serial number in the sender attribute data σ; ek σ represents the set of encryption keys generated by the key generation center according to the sender attribute σ; ek i represents the encryption key generated by the key generation center according to the i-th attribute in the sender attribute set σ; g represents an element in the multiplicative cyclic group where is a positive integer; t i is a random number generated by the key generation center; q 1 q(x) represents a polynomial of degree d - 1 randomly selected by the key generation center, and 1 q(x) = α + a 1 x + … + a d-1 x d-1 ; α is one of the master keys generated by the key generation center, x represents the unknown variable, and a i represents the coefficient of the polynomial q 1 (x), and x d-1 represents the (d - 1)-th power of the polynomial variable x; After that, the key generation center calculates the Lagrange coefficient set of the polynomial according to the polynomial q 1 (x) in combination with the Lagrange interpolation theorem as follows: where j represents the loop serial number in the attribute set, indicates that the value of the j-th attribute of the sender is represents the Lagrange coefficient set generated for the sender; the specific calculation process is as follows: Among them, represents the i-th Lagrange coefficient, and this Lagrange coefficient is calculated and generated from the points in the set of attribute values; |σ| represents the number of attribute values in the sender's attribute set; Finally, the key generation center sends to the sender through a secure channel; Step 2.2: The receiver decrypts the key; First, the recipient sends its own attribute data ρ and the formulated sender access policy data to the key generation center, where ρ represents the recipient attribute data; represents the access policy data that the sender needs to satisfy formulated by the recipient; Subsequently, the key generation center calculates dk based on the data received from the recipient ρ ={dk i}, i ∈ ρ, where: where i represents the loop sequence number in the recipient attribute data ρ; dk ρ represents the set of decryption keys generated by the key generation center according to the recipient attribute ρ; dk i represents the decryption key generated by the key generation center according to the i-th attribute in the recipient attribute set ρ; g represents the multiplicative cyclic group element, a positive integer; d 1 is a random number generated by the key generation center; q 2 (x) represents a polynomial of degree d - 1 randomly selected by the key generation center, and q 1 (x) = β + b 1 x + … + b d-1 x d-1 ; β is one of the master keys generated by the key generation center; x represents the unknown variable; b i represents the coefficient of the polynomial q 2 (x); x d-1 represents the (d - 1)-th power of the polynomial variable x; After that, the key generation center calculates the Lagrange coefficient set of the polynomial according to the polynomial q 2 (x), combined with the Lagrange interpolation theorem as j represents the loop serial number in the attribute set; It means that the value of the j-th attribute of the sender is It represents the Lagrange coefficient set generated for the receiver; the specific calculation process is as follows: Among them, represents the i-th Lagrange coefficient, and this Lagrange coefficient is calculated from the points in the set of attribute values; |ρ| represents the number of attribute values in the recipient's attribute set; Finally, the key generation center sends to the sender through a secure channel; Step 3: Data encryption; The sender generates ciphertext data based on the data received from the key generation center in combination with the access policy formulated by the sender for the receiver and the data m that the sender wants to share, and sends it to the edge device; where represents the data returned by the key generation center to the sender during the user registration phase represents the access policy data executed by the sender for the receiver, and m represents the data information that the sender wants to share; Step 4: Policy matching; The edge device uses the sender's attributes, the receiver's access policy, the receiver's attributes, and the sender's access policy encrypted by the Elgamal encryption algorithm received, and performs policy matching based on the privacy-preserving set intersection, and returns the matching sender data to the corresponding receiver; Step 5: Data decryption; The receiver receives the sender's ciphertext C returned from the edge device, combines its own attribute ρ of the receiver and the sender's access policy Execute the decryption process and obtain the data m to achieve data sharing.

2. A data sharing method supporting policy fuzzy matching and two-way access control according to claim 1, characterized in that, Step 1 includes the following steps: First, given the security parameter 1 λ , the key generation center generates as a bilinear mapping group, where λ represents a positive integer preset by the system, 1 λ represents a string of 0 / 1 with length λ; p represents a prime number with length 1 λ ; represents a multiplicative cyclic group of order p; represents a multiplicative cyclic group of order p; g represents the generator of the multiplicative cyclic group ; e represents the relationship i.e., after performing a bilinear operation on two elements in, it is mapped to a certain element in; Subsequently, the key generation center selects elements g and h from the multiplicative cyclic group , selects elements α and β from the prime field , and calculates the public key components as follows: Y α = e(g,g) α Y β = e(g,g) β Among them, \(g\) represents an element in the multiplicative cyclic group where \(q\) is a positive integer; \(h\) represents an element in the multiplicative cyclic group where \(r\) is a positive integer; \(\mathbb{Z}_p\) represents the prime field consisting of \(\{0, 1, 2, \ldots, p - 1\}\) with order \(p\); \(\alpha\) represents an element in the prime field where \(a\) is a positive integer; \(\beta\) represents an element in the prime field where \(b\) is a positive integer; \(Y\) α is a component of the public key; \(Y\) β is a component of the public key; After that, the key generation center selects positive integers n and d, as well as 2n + 2 random numbers {t 1 , t 2 , …, t n+1} and {d 1 , d 2 , …, d n+1}; the key generation center calculates the public key components for : where n is a positive integer; d is a positive integer; t 1 is a random number; d 1 is a random number; i is a loop sequence number; T i is a public key component, D i is a public key component; Finally, the key generation center takes (α,β) as the master secret key msk, and takes (Y α , Y β , {T i} i=1,2,…,n+1 , {D i} i=1,2,…,n+1 ) as the public key mpk, and distributes the common parameters to all legitimate users and edge devices.

3. A data sharing method supporting policy fuzzy matching and two-way access control according to claim 1, characterized in that, Step 3 includes the following steps: First, the sender selects four random numbers u, t, r 1 , where u, t, r 1 , r 2 are elements in the prime field ; the sender calculates U, T, R 1 , R 2 , and the calculation process is as follows: U = g u T = g t Among them, \(g\) represents a multiplicative cyclic group element in, \(n\) is a positive integer; \(U, T, R\) 1 , \(R\) 2 as part of the ciphertext data sent by the sender; Subsequently, the sender calculates and as part of the ciphertext data sent by the sender. The calculation process is as follows: where i is the serial number for traversing the received access policy ; D i represents a part of the public key data issued by the key generation center; T i represents a part of the public key data issued by the key generation center; {P i} represents a part of the ciphertext data sent by the sender; {E i} represents a part of the ciphertext data sent by the sender; Thereafter, the sender calculates W and K 1 ,K 2 As part of the ciphertext data, the specific calculation process is as follows: where i is the sequence number for traversing the received access policy ; represents the sender attribute value; represents the number of elements in the sender attribute set, i.e., the number of points in polynomial fitting; ek i represents the encryption key of the sender; represents the value when the variable is equal to 0 in the Lagrange coefficient, i.e., α whose value is equal to one of the master key values generated by the key generation center; d represents the degree of the polynomial in the Lagrange polynomial, i.e., the minimum number of attribute values required to recover the secret, and is also the threshold detailed in the access policy that the receiver needs to satisfy to recover the secret in the fuzzy matching process; e(·) represents mapping to a certain element in after performing a bilinear operation on two elements in; Y α represents one of the public keys generated by the key generation center; Y β represents one of the public keys generated by the key generation center; represents the public key Y β to the power of r 1 ; represents the public key Y α to the power of r 2 ; The operator · represents the multiplication operation; After that, the sender calculates and obtains V as part of the ciphertext data, and the calculation process is as follows: Among them, the operator represents the exclusive OR operator; m represents the data that the sender wants to share; H(·) represents the hash function; Subsequently, the sender uses the Elgamal encryption algorithm as a basic tool, takes the sender's own attributes and the formulated recipient access policy as inputs, and obtains the corresponding output ciphertext E(σ) and where E(σ) represents the result of encrypting the sender's attribute data σ using the Elgamal encryption algorithm, represents the result of encrypting the access policy data formulated by the sender using the Elgamal encryption algorithm; Finally, the sender integrates the ciphertext C = (T, U, {P i}, {E i}, W, K 1 , K 2 , V); the sender then sends to the edge device; where Index represents the index that can link to the sender; E(σ) represents the result after encrypting the sender's attribute data σ using the Elgamal encryption algorithm; represents the result after encrypting the access policy data formulated by the sender using the Elgamal encryption algorithm; C represents the ciphertext data sent by the sender. Step 5 includes the following steps: First, the recipient decrypts from the ciphertext C to obtain (T, U, {P i}, {E i}, W, K 1 , K 2 , V), where (T, U, {P i}, {E i}, W, K 1 , K 2 , V) are all ciphertext data sent by the sender to the edge device; The recipient calculates g T,1 Merge g T,2 , as part of the decrypted data, the calculation process is as follows: Among them, i represents the loop sequence number in the product operator; j represents the loop sequence number of the recipient's access policy; dk i represents the decryption key generated by the key generation center for the recipient; represents the value when the variable is equal to 0 in the Lagrange coefficients generated by the key generation center for the recipient, that is, the master key β generated by the key generation center; represents the value of the j-th attribute in the recipient's access policy; represents the number of elements in the recipient's access policy set; d represents the threshold for the sender and the recipient to execute policy matching this time; represents the sender access policy formulated by the recipient; Finally, the recipient recovers the data sent by the sender where the operator represents the exclusive-or operator; m represents the data that the sender wants to share; H(·) represents the hash function.

4. A data sharing method supporting policy fuzzy matching and two-way access control according to claim 1, characterized in that, Step 4 includes the following steps: The edge device generates a vector and calculates as the initial vector for executing the private set intersection technology; where represents the initial vector for executing the private set intersection technology generated by the edge device; I i represents the initial vector the i-th element in, is a random even number; represents the initial vector after being encrypted using the Elgamal encryption algorithm Subsequently, the edge device near the sender combines the sender attribute σ and the receiver access policy to calculate and and sends these two results to the remaining edge devices; When the edge device near the recipient receives and After that, combining the recipient's attribute data ρ and the sender access policy formulated by the recipient Calculate to obtain and Among them, the operation symbol ∩ represents the intersection operation of sets; σ represents the sender's attribute data; Represents the recipient access policy formulated by the sender; Represents the sender access policy formulated by the recipient; ρ represents the recipient's attribute data; First, compare the execution results of the comparison algorithm and for the same items. Let the number of the same items be d 1 , that is where represents the number of direct matches between the sender access policy and the sender attributes; σ represents the sender attribute data; represents the sending access policy formulated by the receiver; Secondly, compare the execution results of the comparison algorithm and for identical items. Let the number of identical items be d 2 , that is wherein represents the number of direct matches between the recipient access policy and the recipient attributes; represents the recipient access policy formulated by the sender; ρ represents the recipient attribute data; Finally, the edge device compares d 1 ≥ d ∧ d 2 ≥ d, it is considered that the current sender and receiver match successfully, and the ciphertext of the sender is retrieved according to the sender Index, and then this ciphertext is returned to the receiver; where d 1 represents the number of direct matches between the sender access policy and the sender attributes; d 2 represents the number of direct matches between the receiver access policy and the receiver attributes; d represents the threshold for the sender and receiver to execute policy matching this time; Index represents the identity index of the sender.

Citation Information

Patent Citations

  • Privacy protection method for storing shared data in mobile cloud

    CN107968780A

  • A proxy-based attribute encryption cloud storage access control method

    CN109831444A