A Set Intersection Method for Implementing Two-Way Authentication on the Cloud

By introducing a ensemble intersection method of two-way authentication on the cloud in cloud computing, the limitations and high cost of authorization management in the existing technology are solved, and two-way authorization authentication and low-cost data intersection calculation are realized, which improves data privacy security and cloud computing efficiency.

CN116346333BActive Publication Date: 2025-05-30XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310239198.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-13
Publication Date
2025-05-30
Estimated Expiration
2043-03-13

AI Technical Summary

Technical Problem

The existing cloud computing protocols have limitations in the authorization management between data users and data owners, resulting in frequent data abuse, and high cloud computing costs and communication complexity.

Method used

A collection intersection method is proposed to realize two-way authentication on the cloud. The master key and the main public key are generated through a third-party trusted device, and the participant terminal generates a private key and a user public key, and the data is encrypted using the master key and the main public key. After performing two-way identity authentication, the cloud server calculates the intersection of the ciphertext data sets and encrypts the distribution to the participating terminals.

Benefits of technology

Two-way authorization and authentication are realized to ensure the initiative of both parties, reduce computing costs, and improve data privacy security and cloud computing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346333B_ABST
    Figure CN116346333B_ABST
Patent Text Reader

Abstract

In view of the deficiencies of the prior art, the present invention proposes a method for set intersection to achieve two-way authentication on the cloud. The cloud server can effectively verify whether each of the participating parties in the set intersection is two-way specified. When two-way authorization is satisfied, each participating party receives encrypted intersection information, so that the final intersection result can be obtained after decryption. Each participating party generates a key and encrypts its own data set and uploads it to the cloud server, and the cloud server can use the encrypted data set for two-way identity authentication. The present invention takes into account two-way identity authorization. Only when the two participating parties mutually specify each other as the access policy can the authentication be successful and the authorization management ability be possessed. Both participating parties are in an active position in the intersection operation, and the participating parties only need simple mathematical calculations for encryption processing without bilinear mapping, effectively reducing the calculation cost. No one, including the cloud server of the present invention, can obtain any information about the input set.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a set intersection method for implementing two-way authentication on the cloud. Background Art

[0002] With the rapid development of cloud computing, its powerful computing power and huge storage space provide strong support for the computing and processing of big data. Cloud-assisted private set intersection protocols allow participants to simplify their input sets after encryption or other processing and outsource them to a cloud server, and hand over the storage and computing tasks of a large amount of encrypted data to the cloud server to greatly reduce the storage and computing overhead of the participants. In this context, it is of great significance to carry out research on performance improvement and function expansion by optimizing the security requirements of the protocol around data value and data privacy. However, the development and use of cloud computing have brought about the phenomenon of abuse of access to data. Therefore, given an efficient authorization management method to ensure that data users meet the requirements is an urgent problem to ensure security.

[0003] The cloud server performs an intersection operation on two outsourced encrypted data sets of the data owner. However, in existing protocols, the data owner cannot decide whether to use all or part of its encrypted data to calculate the intersection, nor can it specify with whom to compare. In 2021, Wang et al. proposed an authorized private set intersection protocol that supports flexible authorization and cross-type authorization calculation of data sets. The concept he proposed proves security based on a simple number theory hypothesis problem. The final experimental results show that the performance of this protocol is comparable to that of existing outsourced PSI protocols.

[0004] In the same year, Qiu et al. proposed an identity-based equality test encryption algorithm that supports flexible authorization, which supports testing whether two ciphertexts encrypted with different keys encapsulate the same message, and at the same time supports fine-grained authorization for testing. Based on the equivalence test of ciphertexts, there is a direct way to support authorized users to search for ciphertexts of different users, accelerating the sharing of secret data among user groups. In addition, this scheme does not have the complex key management problems in traditional public key infrastructures. A specific construction is proposed and its security is proven by a simple mathematical proof. Finally, the correctness of the experimental test scheme is verified. Mohammad et al. first proposed an attribute-based private set intersection scheme on the cloud, which allows the data owner to control the intersection operation on its outsourced data set by defining an access control policy, gives the security definition of this scheme, and proves the security of the scheme under the standard model.

[0005] Most of the currently proposed privacy-preserving set intersection protocols with fine-grained authorization satisfy the authorization management at a specific user level. The designated users passively receive data and transmit data as required, resulting in limitations in the authorization level. In addition, the existing solutions that separately define access control policies to control the outsourced data set make it impossible to distinguish between data users and data owners to achieve the effect of the cloud computing intersection being returned to all users. Moreover, the cloud computing cost and communication complexity are extremely high, which increases the cost and goes against the original intention of cloud computing. Summary of the Invention

[0006] To solve the above problems existing in the prior art, the present invention provides a method for set intersection implementing two-way authentication on the cloud. The technical problems to be solved by the present invention are realized through the following technical solutions:

[0007] The present invention provides a method for set intersection implementing two-way authentication on the cloud, which is applied to a set intersection system for implementing two-way authentication on the cloud. The system includes a third-party trusted device, multiple participating party terminals, and a cloud server. The method for set intersection implementing two-way authentication on the cloud includes:

[0008] Step 1, the third-party trusted device generates a master key and a master public key, and publishes the master public key;

[0009] Step 2, each participating party terminal generates its own private key and user public key, and publishes its own user public key;

[0010] Step 3, each participating party terminal generates its own identity key by using the master key, the master public key, and its own identity, and encrypts the data to be uploaded by using the identity key to generate ciphertext data, and uploads the ciphertext data set formed by the ciphertext data;

[0011] Step 4, the cloud server performs two-way identity authentication on the ciphertext data sets uploaded by each participating party terminal, calculates the intersection of the ciphertext data sets, and encrypts the intersection and then distributes it;

[0012] Step 5, each participating party terminal receives the encrypted intersection information, and decrypts the encrypted intersection information to obtain the intersection result.

[0013] Advantages of the present invention:

[0014] 1. The model algorithm of the present invention is applicable to various privacy set intersection fields, and proposes a method for set intersection implementing two-way authentication on the cloud suitable for preventing data abuse. When one party designates to perform set intersection with another party, the other party can directly perform calculations without obtaining authorization authentication. The one-way designated permission has limitations in multi-party PSI. Therefore, we propose a privacy-preserving set intersection protocol with two-way authorization authentication to ensure the initiative of both participating parties.

[0015] 2. The set intersection method for realizing two-way authentication on the cloud in the present invention is a method for encrypting data sets at low cost. In order for the cloud server to effectively implement two-way identity authentication, the dual orthogonal vector space algorithm is introduced to generate parameters. Part of the ciphertext is composed of this information, and the encryption of the data set elements for the rest directly uses exponential operations, reducing the computational cost brought by bilinear mapping and ensuring security and the correctness of cloud computing.

[0016] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Description of the Drawings

[0017] Figure 1 It is a schematic flowchart of a set intersection method for realizing two-way authentication on the cloud provided by the present invention. Detailed Embodiments

[0018] The present invention will be further described in detail below with reference to specific embodiments, but the implementation manners of the present invention are not limited thereto.

[0019] Before introducing the present invention, a brief introduction to the concept of the set intersection method for realizing two-way authentication on the cloud in the present invention is first made.

[0020] In today's big data era, people's lives are transformed into various data existing in the network, not only limited to making friends, shopping, transportation, etc., but also in important fields such as national military and politics. The network data covers a huge amount of user information, which also means huge commercial value and economic prospects. However, the direct utilization of data often comes with the problem of privacy leakage. If the privacy of data can be fully protected, people will have a stronger willingness to participate in the collaborative computing of data and conduct scientific research, commercial utilization, social construction, etc. in a win-win cooperation manner, so that the data can play its due value. How to better balance the relationship between data value and data privacy has become an urgent issue to be solved.

[0021] As society pays more and more attention to network data, legal regulations such as the "Network Security Law of the People's Republic of China" and the "Cryptography Law of the People's Republic of China" have been successively made public and implemented. In relevant laws, the protection of personal information and the legal conditions for transmitting data to a third party are similar. After user authorization and security risk assessment, the data service provider can transmit relevant data to a third party. However, in actual situations, when user data is entrusted to an institution, these institutions indirectly obtain the sovereignty of user data, resulting in frequent occurrences of institutions abusing customer data. And the massive data means that the data platform has potentially huge value, which poses a higher challenge to the security of the system.

[0022] In order to protect data privacy in the actual network environment and realize the effective use of data value, the cryptography community and the industry are committed to the development of privacy protection in the actual application market. In this context, secure multi-party computing technology has gradually emerged in the field of scientific research. Privacy-preserving set intersection calculation belongs to a specific application problem in the field of secure multi-party computing. It not only has important theoretical significance but also has strong application value. It can improve the security of the system and tap the huge value behind massive data. Under the condition that the data is held by different managers, this protocol achieves a win-win situation of protecting privacy and sharing information. It usually consists of two participants, the sender and the receiver. Each party has a privacy set as the input of the protocol. The two parties need to collaboratively calculate the intersection of the two input sets while ensuring the privacy of their respective set elements. In life, people can use sets to represent data with certain specific attributes, so the computational problem of data intersection can be solved by operations between sets. Therefore, this protocol also has a wide range of application scenarios, such as private contact discovery, sample alignment of vertical federated learning, and measuring advertising effectiveness.

[0023] In addition, the privacy-preserving set intersection protocol is also widely used in the cloud computing industry, such as mobile social networks, network clustering, relationship path discovery, and genetic paternity testing. In order to more perfectly solve the security problem of data transmission between data service providers and third parties, we propose a cloud authorization management method. For example, in genetic paternity testing, since most health information such as personal genome information is shared electronically, the possibility of abuse increases, which requires the protection of more sensitive personal data. Data desensitization can no longer be achieved by identifying or aggregating genome data, because genome data is already the final identifier. An effective way is authorization management. Only by mutually specifying permission to access data and perform calculations on data can the institution be unable to obtain the sovereignty of user data. The designation of data control rights is still generated by the user himself. With the popularization of the importance of privacy security by the state, it has become a consensus that sensitive data on public networks are protected, stored, and transmitted in ciphertext. Therefore, how to effectively solve the problem of data abuse has become an increasingly urgent social need. Our invention provides a way of authorization management for data use, which greatly improves privacy security, expands the application scope of privacy computing, and improves the practicality of the algorithm. The present invention can be applied to any other privacy protection scenarios that require control and management of data use.

[0024] like Figure 1 As shown, the present invention provides a set intersection method for realizing two-way authentication on the cloud, which is applied to a set intersection system for realizing two-way authentication on the cloud, the system comprising a third-party trusted device, multiple participant terminals, and a cloud server; the set intersection method for realizing two-way authentication on the cloud comprises:

[0025] Step 1: The third-party trusted device generates a master key and a master public key, and publishes the master public key.

[0026] The present invention can generate the master key and the master public key in the following manner:

[0027] The third-party trusted device PG executes the Setup algorithm to generate the master key and the public key. The generation process is as follows:

[0028] Step 1.1: Introduce a security parameter 1 λ , and generate a bilinear mapping pair of a large prime number q

[0029] where G, G 1 , G 2 , G T represent cyclic groups, q represents the order of the cyclic groups G, G 1 , G 2 , g, g 1 , g 2 respectively represent the generators of the cyclic groups G, G 1 , G 2 , and e represents the bilinear mapping G 1 ×G 2 →G T ;

[0030] Step 1.2: Sample the random dual standard orthogonal basis to obtain such that d 1 , …, d 8 represent elements in D, represents D * in, and let

[0031] Step 1.3: Select retain the master key msk, and publish the master public key mpk;

[0032] where, represents random selection, and Z q represents the prime number group.

[0033] Step 2: Each participating party terminal generates its own private key and user public key, and publishes its own user public key;

[0034] In the present invention, the participating party terminal Alice randomly selects as the private key and generates its own user public key pk a and publishes it; the participating party terminal Bob randomly selects as the private key and generates its own user public key pk band disclose; wherein, sk a = β a , sk b = β b ,

[0035] Step 3. Each participating party terminal generates its own identity key by using the master key, the master public key and its own identity, and encrypts the data to be uploaded by using the identity key to generate ciphertext data, and uploads the ciphertext data set formed by the ciphertext data;

[0036] The present invention can generate a ciphertext data set in the following manner:

[0037] Step 3.1. The participating party terminal Alice selects a random number r, and executes the SKGen algorithm with the master key msk, the master public key mpk and the participating party identity as inputs to generate the identity key ek σ ;

[0038] SKGen(mpk, msk, σ) → ek σ ;

[0039]

[0040] Step 3.2. For 1 ≤ i ≤ n, the participating party terminal Alice randomly selects r q in Z i , and encrypts the data set D a it owns by using the identity key ek σ to obtain the ciphertext data set C a , and the specific calculation is as follows:

[0041] C a = (C t , C 0 , C i );

[0042] wherein, C t is the first part of the ciphertext of the ciphertext C a , and is expressed as: C 0 is the second part of the ciphertext of the ciphertext C a , and is expressed as: rcv represents the access policy specified by this participating party; C i is the third part of the ciphertext of the ciphertext C a , and is expressed as: d i ∈ D a .

[0043] Step 3.3, the participating party terminal Bob selects a random number s, s 1 , s 2 , and uses the master secret key msk, the master public key mpk, and the identity of the participating party as inputs to execute the RKGen algorithm to generate the identity key dk ρ ;

[0044] RKGen(mpk, msk, ρ) → dk ρ ;

[0045]

[0046] Step 3.4, for the participating party terminal Bob, for 1 ≤ j ≤ n, randomly selects r q in Z j , and encrypts its own dataset D b to obtain the ciphertext dataset C b :

[0047] C b = (C′ t , C′ 0 , C k , C j );

[0048] wherein, C′ t is the first part of the ciphertext of ciphertext C b , expressed as: C′ 0 is the second part of the ciphertext of ciphertext C b , expressed as: snd represents the access policy of the target participating party; C k is the third part of the ciphertext of ciphertext C b , expressed as: C k = k 3 ; C j is the fourth part of the ciphertext of ciphertext C b , expressed as: d j ∈ D b .

[0049] Step 4, the cloud server performs two-way identity authentication on the ciphertext datasets uploaded by each participating party terminal, calculates the intersection between the ciphertext datasets, encrypts the intersection, and then distributes it;

[0050] The present invention can calculate the intersection between the ciphertext datasets in the following manner:

[0051] Step 4.1, the cloud server calculates the authentication parameters t 1 , t 2 respectively selected from the ciphertext datasets uploaded by two participating party terminals:

[0052]

[0053] Among them, t 1 is the authentication parameter of the participant terminal Alice; t 2 represents the authentication parameter of the participant terminal Bob;

[0054] Step 4.2, the cloud server uses the authentication parameters t 1 , t 2 and the ciphertext data set uploaded by the participant to try to calculate the intersection between the ciphertext data sets:

[0055]

[0056] Step 4.3, if the intersection e(C t , C′ t ) is equal to it means that the element d i (d j ) is in the intersection, which also means that the cloud server has successfully authenticated the two-way identities of the participant terminals, adds the ciphertext data C i to T a ={C i}; adds the ciphertext data C j to T b ={C j}; and sends T a to the participant terminal Alice and sends T b to the participant terminal Bob.

[0057] Step 5, each participant terminal receives the encrypted intersection information and decrypts the encrypted intersection information to obtain the intersection result.

[0058] Each participant terminal of the present invention can obtain the intersection result in the following manner:

[0059] Step 5.1, the participant terminal Alice receives the encrypted intersection information from the cloud server and directly decrypts the encrypted intersection information using its own private key β a to obtain the element d i in the intersection: C i3 represents the third part of C i , and the third part is C i2 represents the second part of C i , and the second part is

[0060] Step 5.2, the participant terminal Bob receives the encrypted intersection information from the cloud server and uses its own private key β b to directly decrypt the encrypted intersection information to obtain d j : C j3 represents the third part of C j and the third part is C j2 represents the second part of C j and the second part is

[0061] In view of the deficiencies of the prior art, the present invention proposes an efficient privacy - protected intersection method for implementing two - way authentication on the cloud. The cloud server can effectively verify whether each of the participating parties in the set intersection operation is two - way specified. When two - way authorization is satisfied, each participating party receives the encrypted intersection information, so that the final intersection result can be obtained by decryption. Each participating party generates a key and encrypts its own data set and uploads it to the cloud server, and the cloud server can use the encrypted data set for two - way identity authentication. The present invention takes into account two - way identity authorization. Only when the two participating parties mutually specify each other as the access policy can the authentication succeed and have the authorization management ability. Both participating parties are in an active position in the intersection operation, and the participating party's encryption process only requires simple mathematical calculations instead of bilinear mapping, effectively reducing the calculation cost. No one, including the cloud server, can obtain any information about the input set.

[0062] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality" means two or more unless otherwise specifically defined.

[0063] Although the present application has been described in conjunction with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and achieve other variations of the disclosed embodiments by viewing the accompanying drawings, the disclosure content, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality of cases.

[0064] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A method for set intersection to achieve two-way authentication on the cloud, characterized in that, it is applied to a set intersection system for achieving two-way authentication on the cloud, and the system includes a third-party trusted device, multiple participating party terminals, and a cloud server; The method for set intersection to achieve two-way authentication on the cloud includes: Step 1, the third-party trusted device generates a master key and a master public key, and publishes the master public key; Step 2, each participating party terminal generates its own private key and user public key, and publishes its own user public key; Step 3, each participating party terminal generates its own identity key by using the master key, the master public key, and its own identity, and encrypts the data to be uploaded by using the identity key to generate ciphertext data, and uploads the ciphertext data set formed by the ciphertext data; Step 4, the cloud server performs two-way identity authentication on the ciphertext data sets uploaded by each participating party terminal, calculates the intersection between the ciphertext data sets, and issues the encrypted intersection after encryption; Step 5, each participating party terminal receives the encrypted intersection information, and decrypts the encrypted intersection information to obtain the intersection result; Step 1 includes: The third-party trusted device PG executes the Setup algorithm to generate a master key and a public key, and the generation process is as follows: Step 1.1, introduce a security parameter 1 λ , generate a bilinear mapping pair G of a large prime number q: = (q, G 1 , G 2 , G, G T , g, g 1 , g 2 , e); Among them, \(G, G\) 1 , \(G\) 2 , \(G\) T denote cyclic groups, \(q\) denotes the order of the cyclic groups \(G, G\) 1 , \(G\) 2 , \(g, g\) 1 , \(g\) 2 respectively denote the generators of the cyclic groups \(G, G\) 1 , \(G\) 2 , and \(e\) denotes the bilinear map \(G\) 1 \(\times G\) 2 \(\to G\) T ; Step 1.2, for the random dual orthonormal basis sample to obtain such that d 1 , …, d 8 represent the elements in D, represent D * the elements in, let Step 1.3, select Keep the master secret key msk and publish the master public key mpk; Among them, denotes random selection, Z q denotes a prime cyclic group; Step 2 includes: The participating party terminal Alice randomly selects as the private key, generates its own user public key pk a and makes it public; The participating party terminal Bob randomly selects as the private key and generates its own user public key pk b and makes it public; Among them, sk a = β a , sk b = β b , Step 3 includes: Step 3.1, the participating party terminal Alice selects a random number r, and executes the SKGen algorithm with the master secret key msk, the master public key mpk, and the participating party's identity as inputs to generate an identity key ek σ ; SKGen(mpk, msk, σ) → ek σ ; Step 3.2, for the participating party terminal Alice, for 1 ≤ i ≤ n, randomly select r q in Z i , and use the identity key ek a to encrypt its own dataset D σ to obtain the ciphertext dataset C a , and the specific calculation is as follows: C a =(C t , C 0 , C i ); Among them, C t is the first part of the ciphertext C a , expressed as: C 0 is the second part of the ciphertext C a , expressed as: rcv represents the access policy specified by this participating party; C i is the third part of the ciphertext C a , expressed as: d i ∈ D a ; Step 3.3, the participant terminal Bob selects a random number s, s 1 , s 2 , and takes the master secret key msk, the master public key mpk and the participant identity as inputs to execute the RKGen algorithm to generate the identity key dk ρ ; RKGen(mpk, msk, ρ) → dk ρ ; Step 3.4, for the participating party terminal Bob where 1 ≤ j ≤ n, randomly select r q in Z j , and encrypt its own dataset D b to obtain the ciphertext dataset C b : C b =(C t t, C′ 0 , C k , C j ); Among them, C t t is the first part of the ciphertext C b , expressed as: C′ 0 is the second part of the ciphertext C b , expressed as: snd represents the access policy of the target participant; C k is the third part of the ciphertext C b , expressed as: C k = k 3 ; C j is the fourth part of the ciphertext C b , expressed as: d j ∈ D b ; Step 4 includes: Step 4.1, the cloud server calculates the authentication parameters t respectively selected from the ciphertext datasets uploaded by the two participating party terminals 1 , t 2 : Among them, t 1 is the authentication parameter of the participant terminal Alice; t 2 represents the authentication parameter of the participant terminal Bob; Step 4.2, the cloud server uses the authentication parameters t 1 , t 2 's calculation result and the ciphertext data sets uploaded by the participants to attempt to calculate the intersection between the ciphertext data sets: Step 4.3, if the intersection e(C t , C t ′) is equal to , it means that the element d i or d j is in the intersection. Then the cloud server successfully authenticates the two-way identities of the participating party terminals, adds the ciphertext data C i to T a = {C i}, adds the ciphertext data C j to T b = {C j}, and sends T a to the participating party terminal Alice and sends T b to the participating party terminal Bob.

2. The method for set intersection to achieve two-way authentication on the cloud according to claim 1, characterized in that, Step 5 includes: Step 5.1, the participant terminal Alice receives the encrypted intersection information from the cloud server and directly decrypts the encrypted intersection information using its own private key β a to obtain the element d in the intersection i : C i3 represents the third part of C i and the third part is C i2 represents the second part of C i and the second part is Step 5.2, the participating party terminal Bob receives the encrypted intersection information from the cloud server and uses its own private key β b to directly decrypt the encrypted intersection information to obtain d j : C j3 represents the third part of C, and the third part is j C j2 represents the second part of C, and the second part is j ​​

Citation Information

Patent Citations

  • User anonymous identity authentication protocol based on k-pseudonym set in wireless network

    CN104283899A

  • Ciphertext data set intersection calculation method, device, system, client, server and medium

    CN110474764A