An Attribute-Based Access Control Encryption Method and Device
The property-based access control encryption method addresses the limitations of identity-based systems by using attributes and policies to securely manage information flow, ensuring only authorized entities can access encrypted data, thus enhancing security and compliance.
Patent Information
- Application Number
- CN202310385354.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-12
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2043-04-12
AI Technical Summary
The existing access control encryption scheme builds access control policies based on identity, and cannot intuitively and conveniently express the system's access control policies, and has security and expression limitations.
The attribute-based access control encryption method is adopted. By assigning attributes and policies to each user, and using authoritative institutions to generate public parameters and master keys, the sender uses the encryption key to encrypt the information, the purifier purifies and broadcasts the purified ciphertext, and the receiver decrypts according to the attribute set to ensure that only users who meet the policy can decrypt the information.
It realizes higher security and fine-grained information flow control, can efficiently manage user behavior, ensure that all users in the system comply with preset access control policies, and ensure system security to the greatest extent.
Smart Images

Figure CN116389006B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of access control encryption, and more specifically, relates to an attribute-based access control encryption method and device. Background Art
[0002] Traditional cryptography was born to study how to securely transmit information in an insecure channel. Its purpose is to protect an honest party from external attacks, that is, only the party with the decryption key can access the content of the data stream. With the advent of the cloud computing era and the development of privacy protection technologies, it is required that the cryptographic system can support any fine-grained access control mechanism. Therefore, the cryptographic community has successively proposed identity encryption, searchable encryption, functional encryption, etc. However, with the complication of communication scenarios, people hope that the control of the data stream is no longer limited to controlling the reading of information, but also controlling the sending of information. This is the concept of access control.
[0003] However, traditional access control that relies on a trusted central processor, where the central processor can decide the communication between users. But if it is attacked, it is easy for an attacker to tamper with the access control policy or even obtain all the content of the communication. Thus, cryptography has proposed the concept of access control encryption, which defines the permissions of the sender and the receiver in a fine-grained manner through a predefined policy, and uses a semi-trusted purifier to implement policy decision-making, which can make a blind decision on the policy without knowing the sender, the receiver, and the content of the transmission. Even if the purifier is attacked, the attacker cannot tamper with the access control policy or obtain any useful information from the encrypted information flow.
[0004] Currently proposed access control encryption schemes are basically based on identities to construct access control policies. Although this method is easy to complete the construction of policies, there are still limitations in expression. Identity-based access control policies cannot intuitively and conveniently express the access control policies of the system. Summary of the Invention
[0005] In view of the above-mentioned deficiencies or improvement requirements of the prior art, the present invention provides an attribute-based access control encryption method and device. The purpose is that each user is assigned a set of attributes and policies. The attributes determine which information to receive, and the policies determine which users to send information to. Attribute-based access control encryption can intuitively manage the information flow. Except for the authoritative institution and the sender, other parties cannot obtain information about the policy. Therefore, the present invention has higher security; thereby solving the technical problems that the existing access control encryption methods cannot control the information flow and cannot efficiently manage the behaviors of users.
[0006] To achieve the above object, according to one aspect of the present invention, there is provided an attribute-based access control encryption method, including:
[0007] S1: Authority: Generate public parameters pp and master secret key msk according to the input access control list; the access policy list includes: the access policy A that determines the range of recipients corresponding to the sender and the attribute set L that determines the range of information received by the recipient; the public parameters pp and master secret key msk are respectively expressed as:
[0008]
[0009]
[0010] Y is a public parameter, and are public parameters corresponding to attributes, vk is the verification key, crs is the common reference string; sk is the signature key; among them, {p, G1, G2, G T , g1, g2, e} is a TypeIII group, G1, G2, G T are all multiplicative groups of order p, g1 is the generator of group G1, g2 is the generator of group G2, e: G1×G2→G T is a bilinear mapping, n is the total number of attributes in the attribute set L, n i is the number of attribute values included in each attribute; use the bilinear mapping function e to calculate Y = e(g1, g2) w , w is a random number, represents the set of integers in the range (0, p); is a random number;
[0011] S2: Generate the encryption key ek according to the input public parameters pp, master secret key msk and the sender's access policy A A , and send the encryption key ek A ;
[0012] S3: Sender: Receive the encryption key ek A sent by the authority, and use the encryption key ek A to encrypt the message m to generate the ciphertext C.
[0013] In one embodiment, S2 includes:
[0014] Input the public parameters pp, master secret key msk and the sender's access policy A = [A1, A2,..., A n ;
[0015] Select a random number Use r to encrypt Y in the public parameters pp to obtain a random key Use r to encrypt the generator g1 of group G1 to obtain the key K0;
[0016] Random selection If the attribute value v i,q ∈A i Then the secret key If Then the secret key [K i,q,1 ,K i,q,2 is a random value;
[0017] Use the signature key sk to Perform encryption to obtain the signature σ; Output the encryption key
[0018] In one of the embodiments, S3 includes:
[0019] S31: Select a random number Use u1 to re-randomize Y to obtain Re-randomize g1 to obtain K0′, re-randomize And To obtain K′ i,q,1 And K′ i,q,2 ; Use the random number u1 to re-randomize the signature σ to obtain σ′;
[0020] S32: Use the random numbers u1, K0, Encrypt m respectively to obtain
[0021] S33: Based on And w = (u1) to generate a zero-knowledge proof π;
[0022] S34: Output the ciphertext as
[0023] According to another aspect of the present invention, there is provided an attribute-based access control encryption device, including a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps of the above access control encryption method are implemented.
[0024] According to another aspect of the present invention, there is provided an attribute-based access control encryption and decryption method, including:
[0025] S1 - S3: Execute the attribute-based access control encryption method described in the attribute-based access control encryption method; and after S1, there is also S4: The authority generates a decryption key dk according to the public parameters pp, the master secret key msk, and the attribute set L of the receiver L ;
[0026] S5: Purifier: Receive the ciphertext C sent by the sender, verify the legality of the ciphertext C. If it is legal, purify the ciphertext C to obtain the purified ciphertext C', and broadcast the purified ciphertext C'.
[0027] S6: Receiver: Receive the decryption key dk sent by the authority L and the purified ciphertext C' broadcast by the purifier. If the attribute set L of the receiver satisfies the access policy A of the sender carried by the purified ciphertext C', then use the decryption key dk L to decrypt the purified ciphertext C' to obtain the message m.
[0028] In one embodiment, S4 includes:
[0029] Input the public parameters pp, the master secret key msk, and the attribute set L of the receiver, where
[0030] Select a random number Calculate and D0 = g2 w-s ;
[0031] Calculate t i is the i-th value in the q-th attribute;
[0032] Output the decryption key dk L = (D0, {[D i,0 , D i,1 , D i,2}) 1≤i≤n .
[0033] In one embodiment, the ciphertext C is:
[0034]
[0035] S5 includes: The purifier performs the following operations: Purify the ciphertext.
[0036] S51: After receiving the ciphertext C, verify whether the re-randomized signature σ' is correct through the signature verification key vk pre-sent by the authority, and then verify whether the zero-knowledge proof π is correct using the common reference string crs pre-sent by the authority. If it is incorrect, directly discard the ciphertext;
[0037] S52: If it is correct, purify the ciphertext, and the purified ciphertext
[0038] where, Both r and r' are random values.
[0039] In one embodiment, S6 includes:
[0040] If the attribute set L of the receiver cannot satisfy the policy of the ciphertext, the receiver cannot decrypt the ciphertext;
[0041] If it can be satisfied, the receiver can calculate to decrypt the message; where 1 ≤ i ≤ n, where the attribute set
[0042] According to another aspect of the present invention, there is provided an attribute-based access control encryption and decryption device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the attribute-based access control encryption and decryption method are implemented.
[0043] According to another aspect of the present invention, there is provided an attribute-based access control encryption and decryption system, including:
[0044] An authority for generating public parameters pp and a master secret key msk according to the input access control list; the access policy list includes: an access policy A for determining the range of the sender corresponding to the receiver and an attribute set L for determining the range of information received by the receiver; the public parameters pp and the master secret key msk are respectively expressed as:
[0045]
[0046]
[0047] Y is a public parameter, and are both public parameters related to attributes, vk is a verification key, crs is a public reference string; sk is a signature key; where {p, G1, G2, G T , g1, g2, e} is a TypeIII group, G1, G2, G T are both multiplicative groups of order p, g1 is a generator of the G1 group, g2 is a generator of the G2 group, e: G1×G2→G T is a bilinear mapping, n is the total number of attributes in the attribute set L, n i is the number of attribute values included in each attribute; using the bilinear mapping function e to calculate Y = e(g1, g2) w , w is a random number, represents the set of integers in the range (0, p); is a random number;
[0048] A sender for receiving the encryption key ek sent by the authority A , and using the encryption key ekA Encrypt the message m to generate the ciphertext C and send it;
[0049] A purifier, which is used to receive the ciphertext C sent by the sender, verify the legality of the ciphertext C. If it is legal, purify the ciphertext C to obtain the purified ciphertext C' and broadcast the purified ciphertext C';
[0050] A receiver, which is used to receive the decryption key dk sent by the authority L and the purified ciphertext C' broadcast by the purifier. If the attribute set L of the receiver satisfies the access policy A of the sender carried by the purified ciphertext C', use the decryption key dk L to decrypt the purified ciphertext C' to obtain the message m.
[0051] Generally speaking, compared with the prior art through the above technical solutions conceived by the present invention, the following beneficial effects can be achieved:
[0052] (1) The present invention provides an attribute-based access control encryption method, which involves 2 participating parties: the authority and the sender. Among them, the authority initializes the public parameters and the master key according to the input access control list, and generates the encryption key for the sender according to the policy of the user in the access control list. The sender uses the encryption key to encrypt the information and then sends the ciphertext. Compared with the current access control encryption scheme designed based on identity, its security and expressiveness are limited. The access control encryption designed by the present invention is based on attributes, and it can control the information flow in a more fine-grained manner, can efficiently manage the behavior of users, and realizes the control of the information flow in the system through cryptography to ensure that all users in the system must abide by the preset access control policy.
[0053] (2) The present invention provides an attribute-based access control encryption and decryption method, which involves the following 4 participating parties: the authority, the sender, the receiver, and the purifier. Among them, the authority calculates the public parameters and the master key according to the input access control list, and generates the encryption key and the decryption key for the sender and the receiver respectively according to the policy of the user in the access control list. The sender uses the encryption key to encrypt the information and then sends the ciphertext to the purifier. The purifier purifies the ciphertext and broadcasts the purified ciphertext to all receivers. The receiver can decrypt the ciphertext if it meets the corresponding policy. Except for the key generation center and the sender, no one else can obtain information about the policy, including the receiver. Since the receiver cannot know any information about the policy, the security of the system can be guaranteed to the greatest extent. Description of the Drawings
[0054] Figure 1 It is a flowchart of the attribute-based access control encryption and decryption method provided by Embodiment 1 of the present invention.
[0055] Figure 2 This is the flowchart of the attribute - based access control encryption and decryption method provided in Embodiment 5 of the present invention.
[0056] Figure 3 This is the structural schematic diagram of the attribute - based access control encryption and decryption system provided in Embodiment 10 of the present invention. Detailed implementation manners
[0057] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0058] Embodiment 1
[0059] As Figure 1 shown, this embodiment provides an attribute - based access control encryption method. As Figure 1 shown, the application involves the following two participating parties: the authority and the sender.
[0060] S1: Authority: Generate public parameters pp and master secret key msk according to the input access control list. The access policy list includes: the access policy A that determines the range of recipients corresponding to the sender and the attribute set L that determines the range of information received by the recipient; the public parameters pp and master secret key msk are respectively expressed as:
[0061]
[0062]
[0063] Y is a public parameter, and are both public parameters related to attributes, vk is a verification key, crs is a common reference string; sk is a signature key; among them, {p, G1, G2, G T , g1, g2, e} is a TypeIII group, G1, G2, G T are all multiplicative groups of order p, g1 is a generator of the G1 group, g2 is a generator of the G2 group, e: G1×G2→G T is a bilinear mapping, n is the total number of attributes in the attribute set L, n i is the number of attribute values included in each attribute; use the bilinear mapping function e to calculate Y = e(g1, g2) w , W is a random number, represents the set of integers in the range (0, p); is a random number.
[0064] S2: Authority: Generate an encryption key ek according to the input public parameters pp, the master secret key msk, and the access policy A of the sender A , and send the encryption key ek A .
[0065] S3: Sender: Receive the encryption key ek sent by the authority A , and use the encryption key ek A to encrypt the message m to generate the ciphertext C.
[0066] Among them, S1 includes the following:
[0067] S11: The input access control list, which contains the access control information of all users in the system. Each line contains different users, and each user contains two pieces of information: the access policy and the attributes.
[0068] S12: Select a TypeIII group {p, G1, G2, G T , g1, g2, e}, where p is a prime number, G1, G2, G T are three multiplicative groups of order p, g1 is the generator of the G1 group, g2 is the generator of the G2 group, and e: G1×G2→G T is a bilinear map.
[0069] S13: Assume that there are n attributes in the attribute set, and each attribute has ni possible attribute values. For 1 ≤ i ≤ n, select a random number and calculate
[0070] S14: Select a random number Calculate Y = e(g1, g2) w .
[0071] S15: Initialize the signature system and generate the verification key vk and the signature key sk of the signature system. Initialize the zero-knowledge proof system and generate the common reference string crs of the zero-knowledge proof scheme.
[0072] S16: Output the public parameters The master secret key
[0073] Example 2
[0074] In this example, S2 includes:
[0075] S21: Input the public parameters pp, the master secret key msk, and the access policy A of the sender = [A1, A2,..., An .
[0076] S22: Randomly select and calculate K0 = g1 r .
[0077] S23: For 1 ≤ i ≤ n, randomly select and calculate by the following method If If is a random value.
[0078] S24: Generate a signature σ for using the signature key sk.
[0079] S25: Output the encryption key
[0080] Embodiment 3
[0081] In this embodiment Step S3 includes the following sub - steps:
[0082] S31: Select a random number Calculate and re - randomize the signature using the random number u1 to get σ'.
[0083] S32: Use the random number to calculate
[0084] S33: Generate a zero - knowledge proof π through and w = (u1).
[0085] S34: Output the ciphertext as
[0086] Embodiment 4
[0087] In this embodiment, an attribute - based access control encryption device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above - mentioned access control encryption method are implemented.
[0088] Embodiment 5
[0089] As Figure 2 shown, this embodiment provides an attribute - based access control encryption and decryption method, including:
[0090] S1: The authoritative institution runs system initialization according to the preset access control policy, generating public parameters pp and the master secret key msk.
[0091] S2: The authoritative institution generates the sender's encryption key ek according to the input sender's policy A, public parameters pp, and the master secret key msk A , for transmission to the sender.
[0092] S4: The authoritative institution inputs the recipient's attribute set L, and then generates the recipient's decryption key dk according to the public parameters pp and the master secret key msk L , for transmission to the recipient.
[0093] S3: The sender uses the encryption key ek A to encrypt the message m, obtaining the ciphertext C. The sender sends the ciphertext C to the purifier.
[0094] S5: The purifier performs a legality verification on the ciphertext C. If it is illegal, the ciphertext C is directly discarded. If it is legal, the purifier performs calculations on the ciphertext C to obtain the purified ciphertext C'. The purifier broadcasts the purified ciphertext C' to all recipients.
[0095] S6: After obtaining the purified ciphertext C', the recipient will use its own decryption key dk L to decrypt it. If the attribute set L does not satisfy the policy A in the ciphertext, decryption fails. If it satisfies, the message m can be successfully decrypted.
[0096] Example 6
[0097] In this example, S4 includes:
[0098] S41: Input the public parameters pp, the master secret key msk, and the recipient's attribute set L, where
[0099] S42: Select a random number Calculate D0 = g2 w-s .
[0100] S43: For 1 ≤ i ≤ n, calculate
[0101] S44: Output the decryption key dk L = (D0, {{D i,j} 0≤j≤2} 1≤i≤n ).
[0102] Example 7
[0103] In this example, when the ciphertext C is:
[0104]
[0105] S5 includes: The purifier performs the following operations:
[0106] S51: After receiving the ciphertext, the purifier first verifies whether the re-randomized signature σ′ is correct through the signature verification key vk, and then verifies whether the zero-knowledge proof π is correct using the common reference string crs. If it is incorrect, the ciphertext is directly discarded.
[0107] S52: If it is correct, the ciphertext is purified, and the purified ciphertext is calculated in the following manner:
[0108]
[0109]
[0110]
[0111]
[0112] Example 8
[0113] In this example, dk L =(D0, {{D i,j}} 0≤j≤2}} 1≤i≤n ), and step S6 includes the following sub-steps:
[0114] S61: For 1 ≤ i ≤ n, where
[0115] S62: If the attribute set L of the receiver cannot satisfy the policy of the ciphertext, the receiver cannot decrypt the ciphertext. If it can satisfy, the receiver can decrypt the message by calculating
[0116] Example 9
[0117] This example provides an attribute-based access control encryption and decryption device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the attribute-based access control encryption and decryption method are implemented.
[0118] Example 10
[0119] This example provides an attribute-based access control encryption and decryption system, as Figure 3 shown, which is applied to an access control encryption and decryption device involving the following 4 parties: an authority, a sender, a receiver, and a purifier.
[0120] S1: The authority runs system initialization according to the preset access control policy to generate public parameters pp and the master secret key msk. The public parameters pp and the master secret key msk are respectively expressed as:
[0121]
[0122]
[0123] Y is a public parameter, and are both public parameters related to attributes, vk is the verification key, crs is the public reference string; sk is the signature key; among them, {p, G1, G2, G T , g1, g2, e} is a TypeIII group, G1, G2, G T are both multiplicative groups of order p, g1 is the generator of the G1 group, g2 is the generator of the G2 group, e: G1×G2→G T is a bilinear map, n is the total number of attributes in the attribute set L, n i is the number of attribute values included in each attribute; use the bilinear map function e to calculate Y = e(g1, g2) w , W is a random number, represents the set of integers in the range (0, p); is a random number.
[0124] S4: The authority inputs the attribute set L of the receiver, and then generates the decryption key dk L of this receiver according to the public parameters pp and the master secret key msk for transmission to the receiver.
[0125] S3: The sender uses the encryption key ek A to encrypt the message m to obtain the ciphertext C. The sender sends the ciphertext C to the purifier.
[0126] S4: The authority generates the encryption key ek A of this sender according to the input policy A of the sender, the public parameters pp and the master secret key msk for transmission to the sender.
[0127] S5: The purifier verifies the legality of the ciphertext C. If it is illegal, the ciphertext C is directly discarded. If it is legal, the purifier calculates the ciphertext C to obtain the purified ciphertext C'. The purifier broadcasts the purified ciphertext C' to all receivers.
[0128] S6: After the receiver obtains the purified ciphertext C', it will use its own decryption key dk LDecrypt it. If the attribute set L does not satisfy the policy A in the ciphertext, decryption fails; otherwise, the message m can be successfully decrypted.
[0129] Example 11
[0130] According to another aspect of the present invention, there is provided a computer-readable storage medium having stored thereon a computer program, which, when executed by a processor, implements the steps of the above access control encryption method.
[0131] Example 12
[0132] According to another aspect of the present invention, there is provided a computer-readable storage medium having stored thereon a computer program, which, when executed by a processor, implements the steps of the above access control encryption and decryption method.
[0133] Those skilled in the art can easily understand that the above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An attribute-based access control encryption method, characterized in that, Including: S1: Authority: Generate public parameters pp and master secret key msk according to the input access control list; The access policy list includes: access policy A that determines the range of recipients corresponding to the sender and attribute set L that determines the range of information received by the recipient; The public parameters pp and master secret key msk are respectively expressed as: Y is a public parameter, and are public parameters corresponding to attributes, vk is a verification key, crs is a common reference string; sk is a signature key; where, {p, G1, G2, G T , g1, g2, e} is a Type III group, G1, G2, G T are all multiplicative groups of order p, g1 is a generator of the G1 group, g2 is a generator of the G2 group, e: G1×G2→G T is a bilinear map, n is the total number of attributes in the attribute set L, n i is the number of attribute values included in each attribute; using the bilinear map function e to calculate Y = e(g1, g2) w , w is a random number, represents the set of integers in the range (0, p); is a random number; S2: Authoritative agency: Generate an encryption key ek according to the input public parameter pp, the master secret key msk, and the sender's access policy A A , and send the encryption key ek A ; S3: Sender: Receive the encrypted key ek sent by the receiving authority A , and use the encrypted key ek A to encrypt the message m to generate the ciphertext C.
2. The attribute-based access control encryption method according to claim 1, characterized in that S2 Including: Input public parameter pp, master secret key msk, and the sender's access policy A = [A1, A2,..., A n ; Select a random number Use r to encrypt Y in the public parameter pp to obtain a random key Use r to encrypt the generator g1 of the G1 group to obtain the key K0 = g1 r ; Random selection If the attribute value v i,q ∈A i Then the key If Then the key [K i,q,1 , K i,q,2 is a random value; Encrypt using the signature key sk to obtain the signature σ; to obtain the signature σ; Output encryption key 3. The attribute-based access control encryption method according to claim 2, wherein S3 Including: S31: Select a random number Re-randomize Y using u1 to obtain Re-randomize g1 to obtain K0′, re-randomize and to obtain K′ i,q,1 and K′ i,q,2 ; Use the random number u1 to re-randomize the signature σ to obtain σ′; S32: Use the random number u1 to encrypt m to obtain S33: Based on and w = (u1), generate a zero-knowledge proof π; S34: The output ciphertext is 4. An attribute-based access control encryption device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 3.
5. An attribute-based access control encryption and decryption method, characterized in that, Including: S1 - S3: Execute the attribute - based access control encryption method described in any one of claims 1 - 3; And after S1, it further includes: S4: The authoritative agency generates the decryption key dk according to the public parameter pp, the master secret key msk, and the attribute set L of the receiver L ; S5: Purifier: Receive the ciphertext C sent by the sender, verify the legality of the ciphertext C, if legal, purify the ciphertext C to obtain the purified ciphertext C', and broadcast the purified ciphertext C'; S6: Receiver: Receive the decryption key dk sent by the authority L and the purified ciphertext C' broadcast by the purifier. If the attribute set L of the receiver satisfies the access policy A of the sender carried by the purified ciphertext C', use the decryption key dk L to decrypt the purified ciphertext C' to obtain the message m.
6. The attribute-based access control encryption and decryption method according to claim 5, characterized in that S4 Including: Input the public parameters pp, the master secret key msk, and the set of attributes L of the receiver, where Select a random number Calculate and D0 = g2 w-s ; Calculation t i is the value of the i-th attribute; Output decryption key dk L =(D0, {[D i,0 , D i,1 , D i,2}) 1≤i≤n )。 7. The attribute-based access control encryption and decryption method according to claim 6, characterized in that, S5 includes: When the ciphertext C is generated by the method described in claim 3, the purifier performs the following operations: S51: After receiving the ciphertext C, verify whether the re - randomized signature σ′ is correct through the signature verification key vk pre - sent by the authority, and then verify whether the zero - knowledge proof π is correct through the public reference string crs pre - sent by the authority. If incorrect, directly discard the ciphertext; S52: If it is correct, purify the ciphertext, and purify the ciphertext wherein both r and r' are random values.
8. The attribute-based access control encryption and decryption method according to claim 7, characterized in that S6 Including: If the attribute set L of the recipient cannot satisfy the policy of the ciphertext, the recipient cannot decrypt the ciphertext; If it can be satisfied, the receiver can calculate to decrypt the message; where 1 ≤ i ≤ n, where the attribute set 9. An attribute-based access control encryption and decryption device, comprising a memory and a processor, where the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 5 to 8.
10. An attribute-based access control encryption and decryption system, characterized in that, Including: Authority, used for the authority to generate public parameters pp and master secret key msk according to the input access control list; The access policy list includes: access policy A that determines the range of recipients corresponding to the sender and attribute set L that determines the range of information received by the recipient; The public parameters pp and master secret key msk are respectively expressed as: Y is a public parameter, and are public parameters corresponding to attributes, vk is a verification key, crs is a common reference string; sk is a signature key; where, {p, G1, G2, G T , g1, g2, e} is a Type III group, G1, G2, G T are all multiplicative groups of order p, g1 is a generator of the G1 group, g2 is a generator of the G2 group, e: G1 × G2 → G T is a bilinear map, n is the total number of attributes in the attribute set L, n i is the number of attribute values included in each attribute; use the bilinear map function e to calculate Y = e(g1, g2) w , w is a random number, represents the set of integers in the range (0, p); is a random number; Sender, which is used to receive the encrypted key ek sent by the authoritative institution A , and uses the encrypted key ek A to encrypt the message m, generate the ciphertext C and send it; Purifier, used for receiving the ciphertext C sent by the sender, verifying the legality of the ciphertext C, if legal, purifying the ciphertext C to obtain the purified ciphertext C', and broadcasting the purified ciphertext C'; A receiver, which is configured to receive a decryption key dk sent by an authority L and a sanitized ciphertext C' broadcast by a sanitizer. If the attribute set L of the receiver satisfies the access policy A of the sender carried by the sanitized ciphertext C', the decryption key dk L is used to decrypt the sanitized ciphertext C' to obtain the message m.
Citation Information
Patent Citations
Unlimited revocable attribute-based encryption method
CN114095160A
Data circulation control method based on cleanable attribute encryption in cloud environment
CN115277171A