A certificateless dynamic data sharing system and method based on proxy re-encryption

By combining the multi-level data sharing solution of the certificate-free public key cryptography system and the proxy re-encryption system, the problems of data confidentiality, access control and continuous management in the IoT scenario are solved, and efficient data access control and cloud data management are achieved.

CN116192433BActive Publication Date: 2025-05-27CHONGQING UNIV OF POSTS & TELECOMM
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211573319.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-08
Publication Date
2025-05-27
Estimated Expiration
2042-12-08

AI Technical Summary

Technical Problem

In the IoT cloud scenario, traditional encryption algorithms are difficult to meet the needs of data confidentiality, data access control and continuous cloud data management at the same time.

Method used

A multi-level data sharing scheme combining a certificate-free public key cryptography system and a proxy re-encryption system is adopted. Multi-level data access control for dynamic key and ciphertext evolution is realized through system initialization and key generation, ciphertext encryption and decryption, proxy re-encryption and key update and ciphertext evolution modules.

Benefits of technology

It realizes end-to-end data confidentiality, provides multi-level data access control, ensures continuous management and maintenance of cloud data, reduces computing costs and ciphertext size, and takes into account practicality and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192433B_ABST
    Figure CN116192433B_ABST
Patent Text Reader

Abstract

The present invention claims protection for a certificateless dynamic data sharing system and method based on proxy re-encryption to achieve data access control under the Internet of Things cloud architecture. The Internet of Things, as the key task bearer for the collection and transmission of raw data, provides data for cloud computing as a support, which is responsible for the distributed storage and calculation of data, so as to realize the value transformation of data. It includes: a system initialization and key generation module, a ciphertext encryption and decryption module, a proxy re-encryption module, and a key update and ciphertext evolution module; the solution combines the certificateless public key cryptosystem with the proxy re-encryption system, and adds a key update and ciphertext evolution mechanism, meeting the requirements for the continuous management and maintenance of cloud data. This solution conforms to the usage requirements of users in the Internet of Things cloud scenario, has higher efficiency in terms of computing and storage, takes into account both practicality and security, and can be used to implement an efficient Internet of Things cloud data access control system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things cloud, and in particular to a multi-level data sharing scheme that combines a certificateless public key cryptosystem and a proxy re-encryption system, and evolves dynamic keys and ciphertexts under the Internet of Things cloud. Background Art

[0002] With the development of 5G communication technology and new generation network technologies such as big data and cloud computing, the Internet of Things has gradually penetrated into various industries. In the technical operation system composed of the mutual cooperation of cloud computing, big data, the Internet of Things, mobile Internet, and artificial intelligence, as the key task bearer for the collection and transmission of original data, the Internet of Things manages and uses a large number of Internet of Things access devices on the one hand, and generates and organizes a vast amount of data regarded as assets on the other hand. Cloud computing is supported by the data provided by the Internet of Things and is responsible for the distributed storage and calculation of data, so as to realize the value transformation of data. Therefore, based on functional and economic considerations, more users choose to hand over their data to cloud service providers for storage and calculation. As a latest implementation and delivery mode of Internet of Things applications, the Internet of Things cloud (IoT Cloud) has a mature implementation architecture.

[0003] In practical applications, due to the protection of data assets and the incomplete trust in cloud service providers (CSPs), how to ensure the confidentiality, controllability, and computability of cloud data has become particularly important. The most effective method in the past was for users to encrypt the data before outsourcing. However, traditional encryption algorithms have many problems and deficiencies in the Internet of Things cloud scenario and cannot simultaneously meet the following requirements: (1) End-to-end data confidentiality: The data transmission between data producers and data consumers is confidential, and the cloud server that performs storage, forwarding, and limited computing functions cannot obtain the data and keys; (2) Data access control: Users need a suitable access control mechanism, and users manage access control rights by themselves, rather than handing over this right to the cloud server; and considering the possible future data consumers, access control policies should be formulated for data, rather than for unknown access request initiators; (3) Continuous management and maintenance of cloud data: Users need to store data for a long time, but in order to ensure data security, keys need to be updated regularly, and a storage method that can balance data security and long-term maintenance capabilities is required.

[0004] CN114338229B, a lightweight dynamic broadcast proxy re-encryption and cloud data sharing method, which is characterized by adopting a lightweight dynamic broadcast proxy re-encryption method that converts the ciphertext of the data owner into the ciphertext of the data user. The proxy can update the shared list from S to L. The principal only sets the broadcast re-encryption key for a group of trustees, and uses cloud computing to embed the proxy re-encryption into the cloud environment, which can achieve efficient sharing of outsourced encrypted data. This method mainly includes steps such as system initialization, user key generation, encryption phase, re-encryption key generation, re-encryption, and user decryption. However, in the Internet of Things cloud scenario, this method cannot fully meet the needs of Internet of Things cloud users. Compared with the prior art, the present invention proposes a data sharing scheme that combines the certificateless public key cryptosystem and the proxy re-encryption system. On the basis of secure transmission, it realizes multi-level data access control based on the conditional key mechanism. Moreover, the characteristics of key update and ciphertext evolution of this scheme enable continuous management and maintenance of cloud data. The efficiency quantification analysis results of the present invention show that the present invention not only conforms to the usage needs of users in the Internet of Things cloud scenario, but also has higher efficiency in terms of computing cost and ciphertext size, taking into account both practicality and security, and can be used to implement an efficient Internet of Things cloud data access control system. Summary of the Invention

[0005] The present invention aims to solve the above problems of the prior art. A certificateless dynamic data sharing system and method based on proxy re-encryption are proposed. The technical solution of the present invention is as follows:

[0006] A certificateless dynamic data sharing system based on proxy re-encryption involves the following entities: a registration authority and a key generation center KGC, a data owner DO, a data user DU, a storage server CSP-storage of a cloud service provider, and a proxy server CSP-proxy. The specific shared system among the entities includes: a system initialization and key generation module, a ciphertext encryption and decryption module, a proxy re-encryption module, and a key update and ciphertext evolution module; wherein,

[0007] The system initialization and key generation module is used for the initialization work of the Internet of Things cloud system and the generation of user keys;

[0008] The ciphertext encryption and decryption module is used for the encryption and upload of Internet of Things cloud privacy data and the decryption of authorized data;

[0009] The proxy re-encryption module is used for the proxy re-encryption processing of the cloud server after the authorization of Internet of Things cloud privacy data;

[0010] The key update and ciphertext evolution module is used for the periodic update of keys by Internet of Things cloud users and the evolution of cloud ciphertexts.

[0011] Furthermore, the system initialization and key generation module is used for the initialization of the Internet of Things cloud system and the generation of user keys, specifically including:

[0012] The registration authority and the key generation center KGC select a cyclic group G of prime order q 1 and G 2 , a bilinear pair e: G 1 ×G 1 →G 2 , select a generator g ∈ R G 1 , let g 1 =e(g, g) ∈ G 2 , a hash function where l 1 is the sum of the lengths of the identity identifier ID, public key PK, and group G 1 elements; l 2 is the sum of the lengths of ID and condition ω; l m is the length of the message m; KGC selects as the master secret key msk and calculates P KGC =g s as the KGC public key; the public parameters params = <G 1 , G 2 , e, g, g 1 , P KGC , H 0 , H 1 , H 2 , H 3 >;

[0013] User key generation includes that the user ID A selects a random number as its partial private key sk A,2 =x A , calculates the corresponding partial public key and sends pk A,2 to the KGC through the public channel; the KGC selects and calculates h 1,A =H 1 (ID A ||pk A,2 ||R A ), and sends (u A , R A ) to the user ID A ; after receiving (u A , R A , R A ), the user ID h 1,A = H 1 (ID A || pk A,2 || R A ), verify the equation If the equation holds, then (u A , R A ) is considered valid, and calculate the partial private key d A = t A · x A , if the equation does not hold, apply for a partial key from the KGC again; the user's private key is SK A = (sk A,1 , sk A,2 ) = (d A , x A ), the user's public key is User ID A Use its private key and the entrusted user ID B Public key to generate a re-encryption key User ID A Use its private key and the re-encryption condition ω to generate a conditional key

[0014] Furthermore, the ciphertext encryption and decryption module is used for the encrypted upload of IoT cloud privacy data and the decryption of authorized data, specifically including:

[0015] Level-1 encryption: Encrypt the message m ∈ G A under the public key PK A of the user ID. The obtained Level-1 ciphertext C 2 can be decrypted by the holder of the corresponding private key SK A,r or re-encrypted by the proxy. The user ID A selects a random number A and calculates the ciphertext Calculate the ciphertext

[0016] Level-2 encryption: Encrypt the message m ∈ G A under the public key PK A of the user ID. The obtained Level-2 ciphertext 2 or or can only be decrypted by the holder of the private key of ID A . The user ID A selects a random number and calculates the ciphertext or

[0017] Level-1 decrypt: For the Level-1 ciphertext, according to the ciphertext structure, it can be regarded as in the form of c = (α, β), and it is decrypted in the following way:

[0018] Level-2 decrypt: For the Level-2 ciphertext or the ciphertext c = (α, β) output after re-encryption by the proxy server, it is decrypted in the following way: The ciphertext encrypted with the private key x A is also decrypted in a similar way.

[0019] Furthermore, the proxy re-encryption module is used for the proxy re-encryption processing of the cloud server after the authorization of the privacy data of the Internet of Things cloud, and specifically includes:

[0020] The proxy uses the re-encryption key rk A→B and the conditional key ck A,ω to re-encrypt the Level-1 ciphertext C A,r = (α, β). First, use rk A→B to calculate Then calculate The re-encrypted ciphertext where k ′ = d A k.

[0021] Furthermore, the key update and ciphertext evolution module is used for the Internet of Things cloud users to regularly update keys and cloud ciphertexts, and specifically includes:

[0022] User ID A can, according to the key generation process, request a new key from the KGC with a new identity ID A ′ A: The key structure for updating the Level-1 ciphertext is regarded as upk A,r = (X, Y), where: H 3 (e(α, H 2 (ID′ A , ω)x A′ )) The key for updating the Level-2 ciphertext is The user sends upk to the cloud server for ciphertext update;

[0023] The cloud server uses upk from the ciphertext owner to update the ciphertext as follows: The ciphertext can be regarded as c = (α, β), and the ciphertext update algorithm corresponds to the encryption algorithm: or

[0024] A data sharing method based on the system described in any one of the above, comprising the following steps:

[0025] System initialization and key generation step; ciphertext encryption and decryption step; proxy re-encryption step; key update and ciphertext evolution step, where

[0026] System initialization and key generation step: Initialize the Internet of Things cloud system and generate user keys, including the public parameter set params = <G 1 , G 2 , e, g, g 1 , P KGC , H 0 , H 1 , H 2 , H 3 , generate a user key pair (SK ID , PK ID ), and the proxy re-encryption authorization-related key rk A→B , ck A,ω ;

[0027] Ciphertext encryption and decryption step: Encrypt and upload the Internet of Things cloud privacy data and decrypt the authorized data, including two encryption algorithms, to obtain the ciphertext C A,r and and the corresponding decryption algorithm;

[0028] Proxy re-encryption step: Perform proxy re-encryption processing on the cloud server after authorizing the Internet of Things cloud privacy data. The cloud server uses the re-encryption key rk A→B and the conditional key ck A,ω to re-encrypt the Level-1 ciphertext to obtain the Level-2 ciphertext;

[0029] Key update and ciphertext evolution step: Regularly update the keys of the Internet of Things cloud users and the cloud ciphertext. After the user updates the identity, generate the update key upk and hand it over to the cloud server for ciphertext evolution update.

[0030] The advantages and beneficial effects of the present invention are as follows:

[0031] Compared with the prior art, the beneficial effects of the present invention lie in the following four characteristics:

[0032] (1) Data confidentiality: The user data is encrypted and then uploaded to the cloud. Under unauthorized circumstances, the cloud server and any third party cannot obtain the data content;

[0033] (2) Multi-level data access control: The access control mechanism based on proxy re-encryption enables the data owner to perform ciphertext-level access authorization for different data consumers; the conditional re-encryption mechanism can perform fine-grained access permission control for different data; this solution ensures more reliable access control and further reduces the security risks of semi-trusted cloud servers;

[0034] (3) Dynamic user keys: The long-term use of the same key is insecure. In this solution, when a user's key is leaked, the user updates the identity identifier and key pair in a timely manner, or performs updates regularly, enhancing security and privacy;

[0035] (4) Ciphertext evolution: After the user updates the identity identifier and key pair, there is no need to re-encrypt and upload the previous data. Instead, the cloud server is used to perform the update calculation, making long-term data backup and maintenance feasible.

[0036] The innovation of the present invention lies in proposing a data sharing solution that combines the certificateless public key cryptosystem and the proxy re-encryption system. On the basis of secure transmission, the system initialization and key generation module and the proxy re-encryption module achieve multi-level data access control based on the conditional key mechanism and the proxy re-encryption mechanism. Moreover, the key update and ciphertext evolution module enables continuous management and maintenance of cloud data. The efficiency quantification analysis results of the present invention show that the present invention not only meets the usage requirements of users in the Internet of Things cloud scenario, but also has higher efficiency in terms of computational cost and ciphertext size, taking into account both practicality and security, and can be used to implement an efficient Internet of Things cloud data access control system. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 is the system flow chart of the preferred embodiment provided by the present invention;

[0038] Figure 2 is the definition diagram of the symbols used in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] The following will clearly and detailedly describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. The described embodiments are only a part of the embodiments of the present invention.

[0040] The technical solution for the present invention to solve the above technical problems is:

[0041] Refer to Figure 1 , the specific implementation manner of the present invention is as follows:

[0042] A certificateless dynamic data sharing system based on proxy re-encryption involves the following entities: a registration authority and a key generation center KGC, a data owner DO, a data user DU, a storage server CSP-storage and a proxy server CSP-proxy of a cloud service provider. The sharing system among the entities specifically includes: a system initialization and key generation module, a ciphertext encryption and decryption module, a proxy re-encryption module, and a key update and ciphertext evolution module. Among them,

[0043] The system initialization and key generation module is used for the initialization work of the Internet of Things cloud system and the generation of user keys;

[0044] The ciphertext encryption and decryption module is used for the encrypted upload of Internet of Things cloud privacy data and the decryption of authorized data;

[0045] The proxy re-encryption module is used for the proxy re-encryption processing of cloud servers after the authorization of Internet of Things cloud privacy data;

[0046] The key update and ciphertext evolution module is used for the periodic update of keys by Internet of Things cloud users and the ciphertexts in the cloud.

[0047] 1. The registration authority and the key generation center KGC select a cyclic group G of prime order q 1 and G 2 , a bilinear pair e: G 1 ×G 1 →G 2 , select a generator g ∈ R G 1 , let g 1 =e(g,g) ∈ G 2 , a hash function where l 1 is the sum of the lengths of the identity identifier ID, the public key PK, and the elements of the group G 1 ; l 2 is the sum of the lengths of ID and the condition ω; l m is the length of the message m; KGC selects as the master secret key msk, calculates P KGC =g s as the KGC public key; the public parameters params = <G 1 , G 2 , e, g, g 1 , P KGC , H 0 , H 1 , H 2 , H 3 >;

[0048] User key generation includes that the user ID A selects a random number As part of its private key sk A,2 = x A , calculate the corresponding part of the public key Send pk through the public channel A,2 to KGC; KGC selects Calculate h 1,A = H 1 (ID A || pk A,2 || R A ), Send (u A , R A ) to user ID A ; User ID A After receiving (u A , R A ), calculate h 1,A = H 1 (ID A || pk A,2 || R A ), verify the equation If the equation holds, then (u A , R A ) is considered valid, calculate the partial private key d A = t A · x A , if the equation does not hold, apply for a partial key from KGC again; the user's private key is SK A = (sk A,1 , sk A,2 ) = (d A , x A ), the user's public key is User ID A Use its private key and the public key of the entrusted user ID B to generate a re-encryption key User ID A Use its private key and the re-encryption condition ω to generate a conditional key

[0049] 2. Level-1 encryption: Encrypt the message m ∈ G A under the public key PK A of user ID 2 The obtained Level-1 ciphertext C A,r can be decrypted by the holder of the corresponding private key SK A or re-encrypted by an agent. User ID A Select a random number Calculate the ciphertext

[0050] Level-2 encryption: Encrypt the message m ∈ G under the user ID A public key PK A The resulting Level-2 ciphertext 2 or or can only be decrypted by the private key holder with the ID A The user ID A selects a random number to calculate the ciphertext or

[0051] Level-1 decryption: For the Level-1 ciphertext, which can be regarded as in the form of c = (α, β) according to the ciphertext structure, decrypt it in the following way:

[0052] Level-2 decryption: For the Level-2 ciphertext or the ciphertext c = (α, β) output after re-encryption by the proxy server, decrypt it in the following way: The ciphertext encrypted by the private key x A is also decrypted in a similar way.

[0053] 3. The proxy uses the re-encryption key rk A→B and the conditional key ck A,ω to re-encrypt the Level-1 ciphertext C A,r = (α, β). First, use rk A→B to calculate Then calculate The re-encrypted ciphertext where k ′ = d A k.

[0054] 4. The user ID A can request a new key: SK A ′ from the KGC with the new identity ID A′ = (sk A′,1 , sk A′,2 ) = (d A ′ , x A ′ ) according to the previous key generation process and through the same algorithm. The Level-1 ciphertext update key structure is regarded as upk A,r =(X, Y), where: X = The Level-2 ciphertext update key is The user sends upk to the cloud server for ciphertext update.

[0055] The cloud server uses upk from the ciphertext owner to update the ciphertext as follows: The ciphertext can be regarded as c = (α, β), and the ciphertext update algorithm corresponds to the encryption algorithm: Or

[0056] A data sharing method based on the system described in any one of the above, which includes the following steps:

[0057] System initialization and key generation steps; ciphertext encryption and decryption steps; proxy re-encryption steps; key update and ciphertext evolution steps, where

[0058] System initialization and key generation steps: Initialize the Internet of Things cloud system and generate user keys, including the public parameter set params = <G 1 , G 2 , e, g, g 1 , P KGC , H 0 , H 1 , H 2 , H 3 >, generate the user key pair (SK ID , PK ID ), and the keys rk A→B related to proxy re-encryption authorization, ck A,ω ;

[0059] Ciphertext encryption and decryption steps: Encrypt and upload the privacy data of the Internet of Things cloud and decrypt the authorized data, including two encryption algorithms, to obtain the ciphertext C A,r and and the corresponding decryption algorithm;

[0060] Proxy re-encryption steps: Perform proxy re-encryption processing on the cloud server after authorizing the privacy data of the Internet of Things cloud. The cloud server uses the re-encryption key rk A→B and the conditional key ck A,ω to re-encrypt the Level-1 ciphertext to obtain the Level-2 ciphertext;

[0061] Key update and ciphertext evolution steps: Regularly update the keys of the Internet of Things cloud users and the ciphertexts in the cloud. After the user updates the identity, generate the update key upk and hand it over to the cloud server for ciphertext evolution update.

[0062] The systems, devices, modules or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0063] It should also be noted that the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent in such process, method, commodity or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, commodity or device including the said element.

[0064] The above embodiments should be understood as being only for illustrative purposes of the present invention and not for limiting the protection scope of the present invention. After reading the content recorded in the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.

Claims

1. A certificateless dynamic data sharing system based on proxy re-encryption involves the following entities: a registration authority and a key generation center KGC, a data owner DO, a data user DU, a storage server CSP-storage and a proxy server CSP-proxy of a cloud service provider. Characterized in that, The sharing system among entities specifically includes: a system initialization and key generation module, a ciphertext encryption and decryption module, a proxy re-encryption module, and a key update and ciphertext evolution module; among which, The system initialization and key generation module is used for the initialization work of the Internet of Things cloud system and the generation of user keys; The ciphertext encryption and decryption module is used for the encrypted upload of Internet of Things cloud privacy data and the decryption of authorized data; The proxy re-encryption module is used for the proxy re-encryption processing of the cloud server after the authorization of Internet of Things cloud privacy data; The key update and ciphertext evolution module is used for the regular update of keys and cloud ciphertexts by Internet of Things cloud users; The system initialization and key generation module is used for the initialization work of the Internet of Things cloud system and the generation of user keys, specifically including: The registration authority and the key generation center KGC select a cyclic group G of prime order q 1 and G 2 , a bilinear pairing e: G 1 ×G 1 →G 2 , select a generator g ∈ R G 1 , let g 1 = e(g, g) ∈ G 2 , hash functions where l 1 is the sum of the lengths of the identity identifier ID, public key PK, and elements of group G 1 ; l 2 is the sum of the lengths of ID and condition ω; l m is the length of message m; KGC selects as the master secret key msk, calculates P KGC = g s as the KGC public key; the public parameters params = <G 1 , G 2 , e, g, g 1 , P KGC , H 0 , H 1 , H 2 , H 3 >; User key generation includes the user ID A Select a random number As part of its private key sk A,2 = x A , Calculate the corresponding partial public key Send pk through the public channel A,2 To the KGC; The KGC selects Calculate h 1,A = H 1 (ID A || pk A,2 || R A ), Send (u A , R A ) to the user ID A ; The user ID A After receiving (u A , R A ), Calculate h 1,A = H 1 (ID A || pk A,2 || R A ), Verify the equation If the equation holds, then (u A , R A ) is considered valid, and calculate the partial private key d A = t A · x A , If the equation does not hold, then re-apply to the KGC for the partial key; The user's private key is SK A = (sk A,1 , sk A,2 ) = (d A , x A ), The user's public key is User ID A Use its private key and the public key of the entrusted user ID B Generate a re-encryption key User ID A Use its private key and the re-encryption condition ω to generate a conditional key The ciphertext encryption and decryption module is used for the encrypted upload of Internet of Things cloud privacy data and the decryption of authorized data, specifically including: Level-1 encryption: The Level-1 ciphertext C A,r is obtained from the following calculation formula for calculating the ciphertext The encrypted message m is decrypted by the corresponding private key SK A holder or proxy for re-encryption, m ∈ G 2 , random number Level-2 Encryption: The Level-2 ciphertext or is obtained from the following calculation formula, calculating the ciphertext or The encrypted message m can only be decrypted by the holder of the private key with ID A , m ∈ G 2 , random number Level-1 decrypt: For the Level-1 ciphertext, according to the ciphertext structure, it can be regarded as in the form of c = (α, β), and it is decrypted in the following way: Level-2 decryption: For the Level-2 ciphertext or the ciphertext c = (α, β) output after re-encryption by the proxy server, decrypt it in the following way: using the private key x a The ciphertext encrypted with the private key is also decrypted in a similar way; The proxy re-encryption module is used for the proxy re-encryption processing of the cloud server after the authorization of Internet of Things cloud privacy data, specifically including: The proxy uses the re-encryption key rk it receives A→B and the conditional key ck A,ω to re-encrypt the Level-1 ciphertext C A,r =(α,β). First, use rk A→B to calculate Then calculate The re-encrypted ciphertext where j ′ =d A j; The key update and ciphertext evolution module is used for the regular update of keys and cloud ciphertexts by Internet of Things cloud users, specifically including: User ID A According to the key generation process, with a new identity ID A ′ Request a new key: SK from KGC A′ =(sk A′ , 1, sk A′ , 2)=(d′ A , x′ a ), The Level1 ciphertext update key structure is regarded as upk A,r =(X, Y), where: The Level-2 ciphertext update key is The user sends upk to the cloud server for ciphertext update; The cloud server updates the ciphertext using the upk from the ciphertext owner as follows: The ciphertext can be regarded as c = (α, β), and the ciphertext update algorithm corresponds to the encryption algorithm: upd level-1 :upk A,r =(X,Y), or 2. A data sharing method of the system according to claim 1, Characterized in that, It includes the following steps: A system initialization and key generation step; a ciphertext encryption and decryption step; a proxy re-encryption step; a key update and ciphertext evolution step, where System Initialization and Key Generation Steps: Initialize the Internet of Things cloud system and generate user keys, including the set of public parameters params = <G 1 , G 2 , e, g, g 1 , P KGC , H 0 , H 1 , H 2 , H 3 , >, generate the user key pair (SK ID , PK ID ), and the keys rk A→B , ck A,ω related to proxy re-encryption authorization; Steps for ciphertext encryption and decryption: Encrypting and uploading IoT cloud privacy data and decrypting authorized data, including two encryption algorithms, to obtain ciphertext C respectively A,r and and the corresponding decryption algorithm; Proxy re-encryption step: After the cloud server is authorized for the privacy data of the IoT cloud, it performs proxy re-encryption processing. The cloud server uses the re-encryption key rk A→B and the conditional key ck A,ω to re-encrypt the Level-1 ciphertext to obtain the Level-2 ciphertext; The key update and ciphertext evolution step: Regularly update the keys and cloud ciphertexts of Internet of Things cloud users. After the user updates the identity, an updated key upk is generated and handed over to the cloud server for ciphertext evolution update.

Citation Information

Patent Citations

  • Data sharing server device, key generation server device, communication terminal, and program

    JP2019102970A