Customizable Data Access Control Method, System, and Computer-Readable Storage Medium
By using the public key of the data owner in IoT applications to encrypt data and generate customized decryption keys, the problem of inflexible centralized key distribution and access control is solved, and high security and flexible access control of data are achieved.
Patent Information
- Application Number
- CN202310105161.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-13
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2043-02-13
AI Technical Summary
In IoT applications, existing encryption technologies have problems with centralized key distribution and inflexible access control, which makes it difficult to effectively guarantee data security and privacy.
Data encryption is used by the data owner's public key, and a customized decryption key is generated using the matching private key to achieve decentralized key generation and flexible access control.
Through decentralized key generation and flexible access control, data security and privacy are improved, performance bottlenecks and security risks of key generation centers are avoided, and data access flexibility and controllability are achieved.
Smart Images

Figure BDA0004074496140000031 
Figure BDA0004074496140000037 
Figure BDA0004074496140000042
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of cryptography, and particularly relates to a customizable data access control method, system, and computer-readable storage medium. Background Art
[0002] In some Internet of Things applications (such as personal health monitoring systems), there are a large number of personal sensitive data. Once these data are uploaded to the cloud server, the data owner loses the power of access control over the data, and the data faces the risk of leakage. Therefore, additional measures must be taken to ensure data security in the Internet of Things.
[0003] In related technologies, the commonly used method to protect data security is encryption, that is, first encrypt the data and then upload the ciphertext of the data to the cloud server. Since the corresponding decryption key is not mastered, neither the cloud server nor other unauthorized visitors can know the true content of the data.
[0004] Although encryption technology can effectively protect the security and privacy of Internet of Things data, there are still two deficiencies at present. One is the centralized key distribution problem. In many cryptographic systems (such as PKI, identity-based encryption, attribute-based encryption, etc.), a key generation center is required to generate keys for all users. When the number of system users is too large, the key generation center is likely to become the performance bottleneck of the system. At the same time, once the key generation center is invaded by an attacker, the keys of all users may be exposed, and the encryption measures implemented on the data will completely fail. The other is the inflexible access control. In traditional encryption methods, the data owner encrypts the data with the public key of the data user, and the data user decrypts it with the private key matching the public key. However, in the Internet of Things based on cloud computing, there is no direct connection between the data owner and the data user, but the data is exchanged through the cloud service platform. Before uploading the data to the cloud service platform, the data owner does not know which specific data users need to access the data, and thus cannot obtain the public key of the data user for encryption.
[0005] Therefore, it is necessary to provide a customizable data access control method, system, and computer-readable storage medium to solve the above problems. Summary of the Invention
[0006] The purpose of the embodiments of this application is to provide a customizable data access control method, system, and computer-readable storage medium. The data is encrypted with the public key of the data owner, and then the decryption key is customized with the matching private key. The key is generated by the data owner, realizing decentralized key generation. Moreover, the data owner can achieve access control for specified users by changing the access control policy, making the access to the data more flexible and controllable.
[0007] In order to solve the above technical problems, this application is implemented as follows:
[0008] A customizable data access control method comprises the following steps:
[0009] Initial key generation: call the initial key generation algorithm to generate matching public key PK and private key SK 0 ;
[0010] Data encryption: Set access control policy, with the public key PK and keyword set T = {t 1 , t 2 …t i …t n} as input, run the data encryption algorithm to encrypt the plaintext data M, and output the encrypted ciphertext CT;
[0011] Custom decryption key: private key SK 0 As input, cross-call the first key generation algorithm and the second key generation algorithm, and output the customized decryption key SK TS , wherein the first key generation algorithm generates a first key with the attribute set S as input, and the first key grants the user with the elements in the attribute set S the right to access the encrypted ciphertext CT; the second key generation algorithm generates a first key with the keyword set T = {t 1 , t 2 …t i …t n Any keyword t in} i Generate a second key for the input, the second key restricts the user from accessing the encrypted ciphertext CT with the keyword t i associated data;
[0012] Data decryption: using the customized key SK TS The encrypted ciphertext CT is decrypted to restore the plaintext data M.
[0013] Preferably, the execution process of the initial key generation algorithm is:
[0014] S11: Obtain system public parameters PP from the cloud service platform:
[0015] PP=(G,G T ,e,p,g,h,w,v,z,u 0 ,u 1 ,u 2 …u n )
[0016] S12: Select a random element α, k 0 ∈Z p and the random keyword t 0 ∈Zp , where Z p represents the integer domain, and calculate:
[0017]
[0018]
[0019] S13: Output the public key PK = e(g, g) α , the private key SK 0 =(SK 0,1 , SK 0,2 , SK 0,3 ).
[0020] Preferably, the access control policy is a Boolean expression composed of AND gates "AND", OR gates "OR", and attributes,
[0021] the access control policy is expressed through the access control matrix A, and is expressed as: where A is an access control matrix with l rows and c columns, the elements in the access control matrix are all integers, each row corresponds to an attribute, and ρ represents a function that maps the row index of the access control matrix A to the attributes in the access control policy.
[0022] Preferably, the process of encrypting the plaintext data M is as follows:
[0023] S51: Select the univariate polynomial f(x)=Π 1≤i≤n (x - t i ), and calculate the coefficients y 0 , y 1 , y 2 …y n ;
[0024] S52: Randomly select an element s ∈ Z p , c - 1 random numbers b 2 , b 3 ...b c ∈ Z p , and form the vector R=(s, b 2 , b 3 ,..., b c );
[0025] S53: Calculate the inner product λ of each row vector of the access control matrix A and the vector R, and the calculation process is: λ j =A j R, where A j represents the vector of the j-th row in the access control matrix A, 1 ≤ j ≤ l; λj Denote the inner product of the vector representing the j-th row in the access control matrix A and the vector R;
[0026] S54: Select a set of random elements {r 1 , r 2 … r l} ∈ Z p , and calculate:
[0027] C 0 = Me(g, g) αs ; C 1 = g s ;
[0028]
[0029] where r j represents the j-th random element in the set {r 1 , r 2 ,..., r l}; ρ(j) represents the attribute corresponding to the j-th row in the access control matrix;
[0030] S55: Output the encrypted ciphertext CT = (C 0 , C 1 , C 2 , {E j,1 , E j,2 , E j,3} 1≤j≤l ).
[0031] Preferably, during the calling process of the first key customization algorithm and the second key customization algorithm, use the private key SK 0 as the most initial input, and then use the output of the previous algorithm as the input of the next algorithm until all algorithm operation processes are completed; the first key generation algorithm is called once, and the second key generation algorithm can be called any number of times.
[0032] Preferably, the operation process of the first key customization algorithm is expressed as:
[0033] S111: Select arbitrary elements r, r 1 , r 2 … r i … r k ∈ Z p , with the user attribute set S = (A 1 , A 2 … A i … A k ) and SR 1 = (SR 1,1 , SR 1,2, SR 1,3 ) as the input, calculate:
[0034] SR’ 1,1 = SR 1,1 w r ; K 0 = g r ;
[0035] S112: Replace SR in the input SR 1,1 with SR’ 1 in SR 1,1 , and add (K 0 , {K i,1 , K i,2 )} to the input SR 1 to obtain the output of the first key customization algorithm, denoted as:
[0036]
[0037] The operation process of the second key customization algorithm is denoted as:
[0038] S211: Select 3 random elements δ, k’ 0 , k m+1 ∈Z p , and use any keyword t in the keyword set T = {t 1 , t 2 …t i …t n}, SR i , SR 2 = (SR 2,1 , SR 2,2 , SR 2,3 ) as the input, calculate:
[0039]
[0040]
[0041]
[0042]
[0043] S212: Replace SR in the input SR 2,1 , SR 2,2 , SR 2,3 with SR’ 2 in SR 2,1 , SR 2,2 , SR 2,3 respectively, and insert (SK m+1,1 , SK m+1,2 , SKm+1,3 ) to obtain the output of the second encryption customization algorithm, denoted as:
[0044] SK T = ((SR’ 2,1 , SR’ 2,2 , SR’ 2,3 ), (SK m+1,1 , SK m+1,2 , SK m+1,3 ))
[0045] Preferably, the decryption process is specifically as follows:
[0046] Select random elements z 1 , z 2 …z n ∈Z p , for i = (1, 2…m), calculate According to the linear characteristics of the access control structure, find the constant ω j ∈Z p , such that ∑ j∈J ω j A j = (1, 0,..., 0), where J = {j: ρ(j) ∈ S}, calculate:
[0047]
[0048]
[0049]
[0050]
[0051] In the formula, where τ represents the subscript of the attribute ρ(j) in the set S;
[0052] Finally, output the plaintext M = C 0 / M’
[0053] This application also provides a customizable data access control system, including:
[0054] Initial key generation module: provides an initial key generation algorithm to generate a matching public key PK and private key SK 0 ;
[0055] Data encryption module: sets an access control policy, using the public key PK and the keyword set T = {t 1 , t 2 …t i …t n} Take the input, run the data encryption algorithm to encrypt the plaintext data M, and output the encrypted ciphertext CT;
[0056] Customized decryption key module: Use the private key SK 0 as the input, cross - call the first key generation algorithm and the second key generation algorithm, and output the customized decryption key SK TS , where the first key generation algorithm takes the attribute set S as the input to generate the first key, and the first key grants users with elements in the attribute set S the permission to access the encrypted ciphertext CT; the second key generation algorithm takes any keyword t 1 , t 2 …t i …t n} in the keyword set T = {t i as the input to generate the second key, and the second key restricts users from accessing the data in the encrypted ciphertext CT associated with the keyword t i ;
[0057] Data decryption module: Use the customized key SK TS to decrypt the encrypted ciphertext CT and restore the plaintext data M.
[0058] This application also provides a computer - readable storage medium, in which one or more programs are stored, and the one or more programs can be executed by one or more processors to implement the steps of the above - mentioned customizable data access control method.
[0059] Compared with the related technology, the technical solution of this application uses the public key of the data owner to encrypt the data, and then uses the matching private key to customize the decryption key. The key is generated by the data owner, realizing decentralized key generation; moreover, the customized decryption key generated based on the attribute set S and the keyword set T limits which users can access the data and which data users can access, making the sharing of data more secure and flexible. Detailed implementation
[0060] Next, the technical solutions in the embodiments of this application will be described clearly and completely. Obviously, the described embodiments are part of the embodiments of this application, rather than all of them. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.
[0061] This application provides a customizable data access control method, including the following steps:
[0062] Initial key generation: Call the initial key generation algorithm to generate a mutually - matching public key PK and private key SK0 .
[0063] The execution process of the initial key generation algorithm is as follows:
[0064] S11: Obtain the system public parameters PP from the cloud service platform:
[0065] PP = (G, G T , e, p, g, h, w, v, z 1 , z 2 …z n , u 0 , u 1 , u 2 …u n )
[0066] S12: Select random elements α, k 0 ∈Z p and a random keyword t 0 ∈Z p , where Z p represents the integer domain, and calculate:
[0067]
[0068]
[0069] S13: Output the public key PK = e(g, g) α , the private key SK 0 = (SK 0,1 , SK 0,2 , SK 0,3 ).
[0070] The initial key is generated by the data owner by invoking the initial key generation algorithm, eliminating the key generation center in the traditional encryption method and realizing the decentralized generation of keys, which can greatly improve the security of key use.
[0071] The system public parameters PP are provided by the cloud service platform, and the elements in the system public parameters PP are all elements in the integer domain Z p , and they satisfy the following conditions:
[0072] (1) There exists a bilinear mapping e of order p (a large prime number) that maps elements in group G to group G T , that is, e: G×G → G T ; g, h, w, v, z ∈ G; u 0 , u 1 , u 2 …u n ∈G;
[0073] (2) Bilinear property: For g, h ∈ G, a, b ∈ Z P , e(g a , h b ) = e(g, h) ab ;
[0074] (3) Non-degeneracy: There is at least one element g in the G group such that e(g, g) after calculation is a generator of the G T group;
[0075] (4) Computability: There exists an effective algorithm such that for all u, v ∈ G, the value of e(u, v) can be effectively calculated.
[0076] Data encryption: Set an access control policy, using the public key PK and the keyword set T = {t 1 , t 2 …t i …t n} as input, run the data encryption algorithm to encrypt the plaintext data M, and output the encrypted ciphertext CT.
[0077] The access control policy is a Boolean expression composed of AND gates, OR gates and attributes. For example: This access control policy indicates that the decryptor must have both the attributes of "doctor" and "internal medicine", or have the attribute of "dean" to decrypt the data. Suppose the attribute set of visitor A is {"doctor", "surgery"}, and the attribute set of visitor B is {"dean", "chief physician"}, then A cannot decrypt the data, and B can decrypt the data.
[0078] The access control policy is expressed through an access control matrix A, expressed as: where A is an access control matrix with l rows and c columns, the elements in the access control matrix are all integers, each row corresponds to an attribute, and ρ represents a function that maps the row number in the access control matrix A to the attribute in the access control policy. For example, ρ(1) = "doctor" means that the first row in the access control matrix A corresponds to the attribute "doctor".
[0079] The process of encrypting the plaintext data M is as follows:
[0080] S51: Select a unary polynomial f(x) = Π 1≤i≤n (x - t i ), calculate the coefficients y 0 , y 1 , y 2 …yn ;
[0081] S52: Randomly select an element s ∈ Z p , c - 1 random numbers b 2 , b 3 ...b c ∈ Z p , and form a vector R = (s, b 2 , b 3 ,..., b c );
[0082] S53: Calculate the inner product λ of the vector of each row in the access control matrix A and the vector R. The calculation process is: λ j = A j R, where A j represents the vector of the j - th row in the access control matrix A, 1 ≤ j ≤ l; λ j represents the inner product of the vector of the j - th row in the access control matrix A and the vector R;
[0083] S54: Select a set of random elements {r 1 , r 2 …r l} ∈ Z p , and calculate:
[0084] C 0 = Me(g, g) αs ; C 1 = g s ;
[0085]
[0086] where r j represents the j - th random element in the set {r 1 , r 2 ,..., r l}; ρ(j) represents the attribute corresponding to the j - th row in the access control matrix;
[0087] S55: Output the encrypted ciphertext CT = (C 0 , C 1 , C 2 , {E j,1 , E j,2 , E j,3} 1≤j≤l ).
[0088] After encryption is completed, the data owner uploads the encrypted ciphertext CT to the cloud service platform for storage, which does not require local storage space. At the same time, using the cloud service platform as an intermediary, data can be shared more conveniently outward.
[0089] Customized decryption key: Using the private key SK 0 as the input, cross - call the first key generation algorithm and the second key generation algorithm, and output the customized decryption key SK TS , where the first key generation algorithm takes the attribute set S as the input to generate the first key, and the first key grants users with elements in the attribute set S the permission to access the encrypted ciphertext CT; the second key generation algorithm takes any keyword t 1 , t 2 …t i …t n} in the keyword set T = {t i as the input to generate the second key, and the second key restricts users from accessing the data in the encrypted ciphertext CT associated with the keyword t i .
[0090] The operation process of the first key customization algorithm is expressed as:
[0091] S111: Select any element r, r 1 , r 2 …r i …r k ∈Z p , using the user attribute set S = (A 1 , A 2 …A i …A k ) and SR 1 =(SR 1,1 , SR 1,2 , SR 1,3 ) as the input, and calculate:
[0092] SR’ 1,1 = SR 1,1 w r ; K 0 = g r ;
[0093] S112: Replace SR 1,1 in the input SR 1 with SR’ 1,1 , and add (K 0 , {K i,1 , K i,2}) to the input SR 1 to obtain the output of the first key customization algorithm, which is expressed as:
[0094]
[0095] The operation process of the second key customization algorithm is expressed as:
[0096] S211: Select three random elements δ, k’, 0 , k m+1 ∈Z p , from the keyword set T = {t 1 , t 2 …t i …t n}, and take any keyword t i , SR 2 =(SR 2,1 , SR 2,2 , SR 2,3 ) as the input to calculate:
[0097]
[0098]
[0099]
[0100]
[0101] S212: Replace SR 2,1 , SR 2,2 , SR 2,3 in the input SR 2 with SR’ 2,1 , SR’ 2,2 , SR’ 2,3 respectively, and insert (SK m+1,1 , SK m+1,2 , SK m+1,3 ), to obtain the output of the second encryption customization algorithm, denoted as:
[0102] SK T =((SR’ 2,1 , SR’ 2,2 , SR’ 2,3 ), (SK m+1,1 , SK m+1,2 , SK m+1,3 )).
[0103] During the invocation process of the first key customization algorithm and the second key customization algorithm, take the private key SK 0 as the initial input, and then take the output of the previous algorithm as the input of the next algorithm until all algorithm operations are completed.
[0104] In the process of customizing the decryption key, the first key generation algorithm and the second key generation algorithm are cross - called. That is, the first key generation algorithm can be called first, or the second key generation algorithm can be called first. Among them, the first key generation algorithm is called once, and the second key generation algorithm can be called any number of times. When the second key generation algorithm is called multiple times, the first key generation algorithm can be called first, and then the second key generation algorithm can be called multiple times; or the second key generation algorithm can be called multiple times first, and then the first key generation algorithm can be called; or the first key generation algorithm can be inserted once among multiple calls of the second key generation algorithm. It should be noted that both the first key generation algorithm and the second key generation algorithm perform an operation process. Therefore, the call order of the first key generation algorithm and the second key generation algorithm does not affect the generation of the customized decryption key SK TS The generation of, and the customized decryption key SK TS obtained under different call orders is exactly the same.
[0105] In the process of customizing the decryption key SK TS , the attribute set S can be an empty set, that is, no user is granted access permission; the keyword set T = {t 1 , t 2 …t i …t n} can also be an empty set, that is, users can access all encrypted ciphertexts.
[0106] In the technical solution of the present application, by customizing the decryption key to limit which users can access the data and which data users can access, the sharing of data can be made more secure and flexible.
[0107] Data decryption: Use the customized key SK TS to decrypt the encrypted ciphertext CT and restore the plaintext data M.
[0108] The specific decryption process is as follows:
[0109] Select random elements z 1 , z 2 …z n ∈Z p , for i=(1, 2…m), calculate According to the linear property of the access control structure, find a constant ω j ∈Z p , such that ∑ j∈J ω j A j =(1, 0,..., 0), where J = {j: ρ(j)∈S}, calculate:
[0110]
[0111]
[0112]
[0113]
[0114] where τ represents the subscript of the attribute ρ(j) in the set S;
[0115] Finally, the output plaintext M = C 0 / M'.
[0116] This application also provides a customizable data access control system, including:
[0117] Initial key generation module: provides an initial key generation algorithm to generate a matching public key PK and private key SK 0 ;
[0118] Data encryption module: sets an access control policy, takes the public key PK and the keyword set T = {t 1 , t 2 ... t i ... t n} as input, runs a data encryption algorithm to encrypt the plaintext data M, and outputs the encrypted ciphertext CT;
[0119] Customized decryption key module: takes the private key SK 0 as input, cross-calls the first key generation algorithm and the second key generation algorithm, and outputs a customized decryption key SK TS , where the first key generation algorithm takes the attribute set S as input to generate a first key, and the first key grants users with elements in the attribute set S the permission to access the encrypted ciphertext CT; the second key generation algorithm takes any keyword t 1 , t 2 ... t i ... t n} in the keyword set T = {t i as input to generate a second key, and the second key restricts users from accessing the data associated with the keyword t i in the encrypted ciphertext CT;
[0120] Data decryption module: decrypts the encrypted ciphertext CT using the customized key SK TS to restore the plaintext data M.
[0121] The present application also provides a computer-readable storage medium, in which one or more programs are stored, and the one or more programs can be executed by one or more processors to implement the steps of the above customizable data access control method.
[0122] The embodiments of the present application have been described above. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.
Claims
1. A customizable data access control method, Characterized in that, Comprising the following steps: Initial key generation: Invoke the initial key generation algorithm to generate a matching public key PK and private key SK 0 ; Data Encryption: Set an access control policy, using the public key PK and the keyword set T = {t 1 , t 2 … t i … t n} as input, run the data encryption algorithm to encrypt the plaintext data M, and output the encrypted ciphertext CT; the access control policy is a Boolean expression composed of AND gates, OR gates, and attributes. The access control policy is expressed through an access control matrix as follows: Among them, is an l-row c-column access control matrix. The elements in the access control matrix are all integers. Each row corresponds to an attribute, and ρ represents a function that maps the row number in the access control matrix to the attribute in the access control policy; Custom decryption key: Using the private key SK 0 as the input, cross - call the first key generation algorithm and the second key generation algorithm, and output the custom decryption key SK TS , where the first key generation algorithm takes the attribute set S as the input to generate a first key, and the first key grants users with elements in the attribute set S the permission to access the encrypted ciphertext CT; the second key generation algorithm takes any keyword t 1 , t 2 … t i … t n} in the keyword set T = {t i as the input to generate a second key, and the second key restricts users from accessing the data associated with the keyword t i in the encrypted ciphertext CT; Data decryption: Use the customized key SK TS Decrypt the encrypted ciphertext CT to restore the plaintext data M.
2. The customizable data access control method according to claim 1, Characterized in that, The execution process of the initial key generation algorithm is: S11: Obtain the system public parameters PP from the cloud service platform: PP=(G,G T ,e,p,g,h,w,v,z,u0,u 1 ,u 2 …u n ) Among them, all elements in the system public parameter PP are elements in the integer domain Z p ; e represents a bilinear mapping of order p (a large prime number), which is used to map elements in group G to group G T , that is, e: G×G→G T ; g, h, w, v, z ∈ G; u 0 , u 1 , u 2 …u n ∈G; S12: Select random elements α, k 0 ∈ Z p and a random keyword t 0 ∈ Z p , and calculate: S13: Output the public key PK = e(g, g) α , and the private key SK 0 = (SK 0,1 , SK 0,2 , SK 0,3 ).
3. The customizable data access control method according to claim 2, Characterized in that, The process of encrypting the plaintext data M is: S51: Select a univariate polynomial \(f(x)=\prod\) 1≤i≤n (x - t i ), and calculate the coefficients \(y\) 0 , \(y\) 1 , \(y\) 2 … \(y\) n ; S52: Randomly select an element s ∈ Z p , c - 1 random numbers b 2 , b 3 ... b c ∈ Z p , to form a vector R = (s, b 2 , b 3 ,..., b c ); S53: Calculate the access control matrix The inner product λ of the vector of each row in and the vector R is calculated as follows: In the formula, represents the vector of the j-th row in the access control matrix, where 1 ≤ j ≤ l; λ j represents the inner product of the vector of the j-th row in the access control matrix and the vector R; S54: Select a set of random elements {r 1 , r 2 … r l} ∈ Z p , and calculate: C 0 = Me(g, g) αs ; C 1 = g s ; where r j represents the j-th random element in the set {r 1 , r 2 ,..., r l}; ρ(j) represents the attribute corresponding to the j-th row in the access control matrix; S55: Output the encrypted ciphertext CT = (C 0 , C 1 , C 2 , {E j,1 , E j,2 , E j,3} 1≤j≤l ).
4. The customizable data access control method according to claim 1, Characterized in that, During the calling process of the first key generation algorithm and the second key generation algorithm, the private key SK 0 is used as the most initial input, and then the output of the previous algorithm is used as the input of the next algorithm until all the algorithm operation processes are completed; the first key generation algorithm is called once, and the second key generation algorithm can be called any number of times.
5. The customizable data access control method according to claim 3, Characterized in that, The operation process of the first key generation algorithm is expressed as: S111: Select any element r, r 1 , r 2 …r i …r k ∈Z p , with the user attribute set S = (A 1 , A 2 …A i …A k ) and SR 1 = (SR 1,1 , SR 1,2 , SR 1,3 ) as input, calculate: SR’ 1,1 = SR 1,1 w r ; K 0 = g r ; S112: Use SR' 1,1 to replace SR in the input SR 1 , and add (K 1,1 , {K 0 , K i,1 , K i,2 ) to the input SR 1 to obtain the output of the first key generation algorithm, denoted as: The operation process of the second key generation algorithm is expressed as: S211: Select three random elements δ, k', 0 , k m+1 ∈Z p , from the keyword set T = {t 1 , t 2 …t i …t n}, for any keyword t i , SR 2 = (SR 2,1 , SR 2,2 , SR 2,3 ) as the input, calculate: S212: Using SR’ 2,1 , SR’ 2,2 , SR’ 2,3 to replace SR in the input SR 2 respectively, and inserting (SK 2,1 , SK 2,2 , SK 2,3 ), to obtain the output of the second key generation algorithm, expressed as: SK m+1,1 , SK m+1,2 , SK m+1,3 ) = ((SR’ T ), (SK 2,1 , SR’ 2,2 , SR’ 2,3 ), (SK m+1,1 , SK m+1,2 , SK m+1,3 )) 6. The customizable data access control method according to claim 5, Characterized in that, The decryption process is specifically: Select a random element z 1 , z 2 … z n ∈ Z p , for i = (1, 2… m), compute According to the linear property of the access control structure, find a constant ω j ∈ Z p , such that ∑ j∈J ω j A j = (1, 0,..., 0), where J = {j: ρ(j) ∈ S}, compute: Where τ represents the subscript of the attribute ρ(j) in the set S; The final output plaintext M = C 0 / M'.
7. A customizable data access control system, Characterized in that, Comprising: Initial key generation module: provides an initial key generation algorithm to generate a matching public key PK and private key SK 0 ; Data Encryption Module: Set an access control policy. Using the public key PK and the keyword set T = {t 1 , t 2 … t i … t n} as input, run a data encryption algorithm to encrypt the plaintext data M, and output the encrypted ciphertext CT; the access control policy is a Boolean expression composed of AND gates, OR gates, and attributes. The access control policy is expressed through an access control matrix as follows: where is an l-row c-column access control matrix. The elements in the access control matrix are all integers. Each row corresponds to an attribute, and ρ represents a function that maps the row index in the access control matrix to the attributes in the access control policy; Custom decryption key module: Using the private key SK 0 as input, cross-invoke the first key generation algorithm and the second key generation algorithm, and output the custom decryption key SK TS , where the first key generation algorithm takes the attribute set S as input to generate a first key, and the first key grants users with elements in the attribute set S the permission to access the encrypted ciphertext CT; the second key generation algorithm takes any keyword t 1 , t 2 … t i … t n} in the keyword set T = {t i as input to generate a second key, and the second key restricts users from accessing the data in the encrypted ciphertext CT associated with the keyword t i . Data decryption module: Use the customized key SK TS to decrypt the encrypted ciphertext CT and restore the plaintext data M.
8. A computer-readable storage medium, in which one or more programs are stored, and the one or more programs can be executed by one or more processors to implement the steps of the customizable data access control method according to any one of claims 1-6.
Citation Information
Patent Citations
Online and offline attribute-based Boolean keyword searchable encryption method and system
CN111913981A