PAEMKS-based Data Management and Search Method, Device, and System

By introducing the private key and tag information of the data owner on the cloud server side, the efficiency and security problems of multi-keyword search and multi-receive user scenarios in the prior art are solved, and efficient and secure data retrieval is achieved, which is suitable for data management of smart grids.

CN116389080BActive Publication Date: 2025-07-11XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310267679.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-17
Publication Date
2025-07-11
Estimated Expiration
2043-03-17

AI Technical Summary

Technical Problem

The existing public key searchable encryption method is not efficient and accurate in multi-keyword search and multiple receiving user scenarios, and cannot effectively resist keyword guessing attacks from internal malicious cloud servers, resulting in information leakage.

Method used

Using a PAEMKS-based data management method, the data owner's private key is introduced, and by generating the first private key and the first public key, combining the tag information to perform the matching test of the ciphertext data, only the designated testers are allowed to perform the matching test to prevent the malicious server from generating the test ciphertext.

Benefits of technology

Effectively resist external and internal keyword guessing attacks, support multi-keyword search, improve retrieval efficiency and accuracy, is suitable for multiple recipient scenarios, and enhances system security and practicality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389080B_ABST
    Figure CN116389080B_ABST
Patent Text Reader

Abstract

The present invention discloses a data management and search method based on PAEMKS, including: system initialization, generating system public parameters according to the input security parameters; each participant generating a public-private key pair based on the public parameters, publicly disclosing the public key, and privately hiding the private key; the data owner encrypting the data to be shared based on the public parameters and its own private key to obtain ciphertext data; the data user generating trapdoors for a number of keywords to be queried based on the public parameters and its own private key, and uploading them to the cloud server; the cloud server performing a matching test on the ciphertext data and the trapdoors, and returning the ciphertext data with successful pairing as the search result to the data user. This method can resist external online / offline keyword guessing attacks and keyword guessing attacks initiated by internal malicious servers simultaneously, with high security; and supports the function of multiple keyword retrievals, improving the retrieval efficiency and accuracy, and is applicable to scenarios with multiple receivers, with high practicality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data encryption security, and particularly relates to a data management and search method, device, and system based on PAEMKS. Background Art

[0002] With the development of computer technology, cloud computing is also becoming a strategic focus of the development of the information technology industry, and global information technology enterprises are all transforming towards cloud computing. For example, in the field of electric power energy, with the increasing energy demand and the deepening of the electricity marketization process, users' requirements for the reliability and quality of electric energy are also continuously improving. Therefore, the intelligence of the power grid is the trend of the power grid development. In the smart grid environment, energy and data management are the main considerations, but traditional energy management systems have limited memory and storage, and cannot meet the growing storage needs of numerous customers. Therefore, using cloud computing with powerful computing power has become the only choice at present.

[0003] In a cloud-based smart grid, the data center outsources data to a cloud server for storage, which greatly reduces local storage resources. Although cloud computing provides many conveniences for the smart grid, there are still huge problems and challenges. When the data center of the smart grid outsources customers' sensitive data to cloud storage, the transmitted data is easily invaded by illegal entities. At the same time, the data center also loses the ability to effectively control the data. Through data access, the cloud server and illegal users can try to obtain the information contained in the data, and the privacy security of grid users is also difficult to guarantee. To protect the security of sensitive data, the most effective method is to use an encryption algorithm to encrypt the plaintext before outsourcing the user data to the cloud.

[0004] In practical applications, due to the language habits of users, the space of common keywords for retrieval is very small. An attacker may use the public key of the data receiver to generate ciphertext. If the attacker can call the matching test algorithm, he / she can generate ciphertext for all possible keywords and perform a matching test using the intercepted trapdoor until a match is successful. This kind of attack is called keyword guessing attacks (KGA).

[0005] One way to resist KGA is to control the permission to call the matching test algorithm. For example, Rhee et al. proposed a public-key encryption with a designated tester (dPEKS) scheme. In dPEKS, only the designated tester can execute the matching test algorithm to determine whether the trapdoor matches the keyword ciphertext. Rhee et al. also proposed the concept of trapdoor indistinguishability security and proved that providing trapdoor indistinguishability security in the dPEKS scheme is a sufficient condition for resisting KGA.

[0006] However, existing public-key searchable encryption methods do not consider the multi-keyword search function and the scenario of multiple receiving users. There are relatively few methods that can simultaneously implement the multi-keyword search function and the scenario of multiple receiving users. As a result, their efficiency and accuracy are not high, leading to redundant search results and the user not being able to obtain the target entries, thus reducing the practicality of the scheme. In addition, most existing public-key searchable encryption schemes assume that the cloud server is honest but curious and consider malicious cloud servers less. An internal malicious cloud server may cause the system to be vulnerable to keyword guessing attacks, resulting in the leakage of the receiving user's information and low security. Summary of the Invention

[0007] To solve the above problems existing in the prior art, the present invention provides a data management and search method, device, and system based on PAEMKS. The technical problems to be solved by the present invention are achieved through the following technical solutions:

[0008] In the first aspect, the present invention provides a data management and search method based on PAEMKS, which is applied to the cloud server side and includes:

[0009] Generate a first private key and a first public key according to the system public parameters, retain the first private key, and publish the first public key;

[0010] Obtain ciphertext data and the marking information of the data user; wherein, the ciphertext data is encrypted by the data owner for the data to be shared based on the system public parameters and its own second private key; the marking information is separately allocated by the trusted center for each data user;

[0011] In response to receiving the trapdoor sent by the data user, perform a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information, and return the ciphertext data with a successful pairing as the search result to the data user.

[0012] In the second aspect, the present invention provides a data management and search device based on PAEMKS, which is applied to the cloud server side and includes:

[0013] The first key generation module is used to generate a first private key and a first public key based on the system public parameters, retain the first private key, and disclose the first public key.

[0014] The first data acquisition module is used to acquire ciphertext data and the marking information of the data user; wherein, the ciphertext data is obtained by the data owner encrypting the data to be shared based on the system public parameters and its own second private key; the marking information is separately assigned by the trusted center for each data user.

[0015] The matching test module is used to, in response to receiving the trapdoor sent by the data user, perform a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information, and return the ciphertext data with successful pairing as the search result to the data user.

[0016] Thirdly, the present invention provides a data management and search method based on PAEMKS, which is applied to the data user side and includes:

[0017] Acquire the data user marking information and generate a third private key and a third public key accordingly, while retaining the third private key and disclosing the third public key.

[0018] Select several keywords for the data to be queried, and generate a trapdoor for the keywords by using the third private key, and send the trapdoor to the cloud server side to obtain the corresponding ciphertext data.

[0019] Fourthly, the present invention provides a data management and search device based on PAEMKS, which is applied to the data user side and includes:

[0020] The third key generation module is used to acquire the data user marking information and generate a third private key and a third public key accordingly, while retaining the third private key and disclosing the third public key.

[0021] The trapdoor generation module is used to select several keywords for the data to be queried, and generate a trapdoor for the keywords by using the second private key, and send the trapdoor to the cloud server side to obtain the corresponding ciphertext data.

[0022] Fifthly, the present invention provides a data management and search system based on PAEMKS, including the data management and search device based on PAEMKS applied to the server side and the data management and search device based on PAEMKS applied to the data user side in the above embodiments.

[0023] The beneficial effects of the present invention:

[0024] The data management and search method based on PAEMKS provided by the present invention introduces the private key of the data owner in the encryption stage, so that a malicious server cannot use the public key of the receiver to generate test ciphertexts for guessed candidate keywords, and thus cannot perform keyword guessing attacks. Therefore, the system can not only resist external online / offline keyword guessing attacks, but also resist keyword guessing attacks initiated by internal malicious servers, with high security; and this solution supports the function of retrieving multiple keywords, improving the retrieval efficiency and accuracy, and is applicable to scenarios with multiple receivers, with high practicability.

[0025] The following will further describe the present invention in detail with reference to the accompanying drawings and embodiments. Brief Description of the Drawings

[0026] Figure 1 is a schematic flowchart of a data management and search method based on PAEMKS provided by an embodiment of the present invention on the cloud server side;

[0027] Figure 2 is a schematic flowchart of a data management and search method based on PAEMKS provided by an embodiment of the present invention on the data user side;

[0028] Figure 3 is a schematic structural diagram of a data management and search device based on PAEMKS applied to the cloud server side provided by an embodiment of the present invention;

[0029] Figure 4 is a schematic structural diagram of a data management and search device based on PAEMKS applied to the data user side provided by an embodiment of the present invention;

[0030] Figure 5 is a schematic structural diagram of a data management and search system based on PAEMKS provided by an embodiment of the present invention;

[0031] Figure 6 is a schematic flowchart of the working process of a data management and search system based on PAEMKS provided by an embodiment of the present invention. Detailed Embodiments

[0032] In view of the deficiencies of the prior art, the present invention proposes a public key authentication scheme (public key authorilicate encryption with multi-keyword search, PAEMKS) applicable to scenarios with multiple receivers and capable of supporting the function of searching for multiple keywords. The method proposed by the present invention will be introduced in detail below from the perspectives of the cloud server side and the data user side.

[0033] Embodiment 1

[0034] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a data management and search method based on PAEMKS on the cloud server side provided by an embodiment of the present invention, and includes:

[0035] Step 1: Generate a first private key and a first public key according to system public parameters, retain the first private key, and make the first public key public.

[0036] First, obtain the system public parameter gp.

[0037] In this embodiment, the system public parameter gp is generated by a trusted center. The trusted center generates the system public parameter wherein, represents a multiplicative cyclic group of order p, g represents a generator of the cyclic group, e: represents a bilinear mapping, and H represents a hash function. After the trusted center generates the public parameter gp, it discloses it to all participants across the network, and the cloud server side can then obtain this parameter.

[0038] Then, the cloud server generates its own public and private key pair based on the obtained public parameter, that is, the first private key and the first public key.

[0039] Specifically, randomly select an integer β in , and let the first private key sk cs = β, and let the first public key pk cs = g β ; wherein, represents a finite field modulo p.

[0040] Finally, retain the first private key and make the first public key public across the network.

[0041] Step 2: Obtain the ciphertext data and the marking information of the data user.

[0042] In this embodiment, the ciphertext data is encrypted by the data owner (i.e., the resource sharing party) for the data to be shared based on the system public parameter and its own second private key.

[0043] Specifically, the steps for the data owner to encrypt the data to be shared based on the system public parameter and its own second private key to obtain the ciphertext data are as follows:

[0044] First, obtain the public parameter gp publicly generated by the trusted center.

[0045] Then, the data owner generates its own public and private key pair based on the obtained public parameter, that is, the second private key and the second public key. Specifically, randomly select an integer α in , and let the second private key sk s= α, let the second public key pk s = g α , while retaining the second private key and making the second public key public.

[0046] Next, select keywords for the data to be shared, denoted as where l1 represents the number of keywords of the data to be shared.

[0047] Finally, use the second private key to generate ciphertext for the keyword w to obtain the ciphertext data CT.

[0048] Optionally, as an implementation, this embodiment can calculate the first part of the ciphertext A = PS r , the second part of the ciphertext B = pk CS r and the third part of the ciphertext where j = 1, 2,..., l1, and finally form the ciphertext CT = (A, B, C j ).

[0049] It can be understood that this embodiment can also randomly select other encryption algorithms to encrypt the keywords, and this embodiment does not make specific limitations on this.

[0050] After the data owner generates the ciphertext data, upload it to the cloud server for query.

[0051] Furthermore, in this embodiment, the marking information is separately assigned by the trusted center for each data user.

[0052] Specifically, the trusted center randomly selects t numbers s, a1, a2,..., a t-1 in and constructs a polynomial f(x) of degree t - 1 = s + a1x + a2x +... + a t-1 x t-1 , then selects t points (x i , y i ), where y i = f(x i ), x i as the marking information of different users, distributes the t points (x i , y i ) to t different data users, and sends x i to the cloud server. Then retain s as the master key and send PS = g s to the data owner.

[0053] Step 3: In response to receiving the trapdoor sent by the data user, perform a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information, and return the ciphertext data with successful pairing as the search result to the data user.

[0054] Specifically, when the cloud server receives a query request and a keyword trapdoor from a resource user (i.e., data user) R i , it performs the following steps to calculate the matching with the keyword ciphertext CT = (A, B, C ): j )

[0055] First, calculate the Lagrange coefficient polynomial ψ(x) according to the marking information of different users. The calculation formula is as follows:

[0056]

[0057] where x i , x j represent the marking information of different users, i and j represent different users, and t represents the number of users;

[0058] Then, use the Shamir key recovery principle to calculate the following formula:

[0059]

[0060] where represents the public key of the data user R i , which is also called the third public key in this embodiment and is generated by the data user side according to the system public parameters and user marking information; y i = f(x i ), f(x) = s + a1x + a2x + … + a t-1 x t-1 , s is the constant term of the polynomial f(x), and a1, a2, a t-1 are the coefficients of the polynomial respectively.

[0061] Finally, use the first private key to match the trapdoor i sent by the data user R with the ciphertext data CT and verify the following equation:

[0062]

[0063] If the equation holds, the output result is 1, indicating that the keyword ciphertext and the plaintext keyword corresponding to the trapdoor are equal, and the trapdoor and the ciphertext data CT are successfully paired;

[0064] Otherwise, the output result is 0, indicating that the keyword ciphertext and the plaintext keyword corresponding to the trapdoor are not equal, the pairing fails, and the search task stops.

[0065] where C j , B, and A are all ciphertexts in the ciphertext data CT Denote the data user R i The corresponding third public key and are both trapdoors data in, sk CS Denote the first private key corresponding to the cloud server, and g is a public parameter of the system

[0066] The data management and search method based on PAEMKS provided by the present invention introduces the private key of the data owner in the encryption stage, so that a malicious server cannot use the public key of the receiver to generate test ciphertext for the guessed candidate keywords, and thus cannot perform keyword guessing attacks. Therefore, the system can not only resist external online / offline keyword guessing attacks, but also resist keyword guessing attacks initiated by internal malicious servers, and has high security; and compared with single-keyword search and the PAEKS scheme applicable to single users, the present invention supports the function of retrieving multiple keywords, improves the retrieval efficiency and accuracy, and is more beneficial in practical applications for scenarios applicable to multiple receivers

[0067] Embodiment 2

[0068] Please refer to Figure 2 , Figure 2 which is a schematic flow diagram of a data management and search method based on PAEMKS provided by an embodiment of the present invention at the data user side, and includes

[0069] Step 1: Obtain data user marking information and generate a third private key and a third public key accordingly, and retain the third private key while making the third public key public

[0070] First, obtain the user marking information (x i , y i ) generated by the trusted center and the public parameter gp; where i = 1, 2,..., t represents the number of data users

[0071] Then, generate the public and private key pair of the data user itself, that is, the third private key and the third public key, based on the marking information (x i , y i ). Specifically, let the current data user R i The third private key of The third public key

[0072] Finally, retain the third private key and make the third public key public to the whole network

[0073] Step 2: Select several keywords for the data to be queried, and generate a trapdoor for the keywords using the third private key, and send the trapdoor to the cloud server side to obtain the corresponding ciphertext data

[0074] For example, when the data user Ri To query the power consumption or balance, request data from the cloud server according to your own needs.

[0075] First, select several current data users R i Keywords to be queried, denoted as where l2 represents the number of keywords to be queried.

[0076] Then, use its own third private key and the second public key pk of the data owner S Calculate the trapdoor of the keyword w' The calculation formula is as follows:

[0077]

[0078] where

[0079]

[0080] Send the generated trapdoor To the cloud server for search query to obtain the required query file.

[0081] Since the method provided by the present invention introduces the private key of the data owner in the encryption stage, a malicious server cannot use the public key of the receiver to generate test ciphertext for guessed candidate keywords, so it cannot perform keyword guessing attacks; and compared with single-keyword search and the PAEKS scheme applicable to single users, the present invention supports the function of retrieving multiple keywords, improves the efficiency and accuracy of retrieval, and is more beneficial in practical applications for scenarios applicable to multiple receivers.

[0082] Embodiment III

[0083] Based on the above Embodiment I, this embodiment provides a data management and search device based on PAEMKS applied to the cloud server side. Please refer to Figure 3 , Figure 3 is a schematic structural diagram of a data management and search device based on PAEMKS applied to the cloud server side provided by an embodiment of the present invention, which includes:

[0084] The first key generation module is used to generate a first private key and a first public key according to the system public parameters, retain the first private key, and publish the first public key;

[0085] The first data acquisition module is used to acquire ciphertext data and the marking information of the data user; wherein, the ciphertext data is encrypted by the data owner for the data to be shared based on the system public parameters and its own second private key; the marking information is separately assigned by the trusted center for each data user;

[0086] A matching test module, which is configured to perform a matching test on ciphertext data and a trapdoor based on a first private key and tag information in response to receiving the trapdoor sent by a data user, and return the ciphertext data with successful pairing as a search result to the data user.

[0087] The device provided in this embodiment can be used to implement the method provided in the first embodiment above. For the detailed process, please refer to the first embodiment above.

[0088] Embodiment Four

[0089] Based on the second embodiment above, this embodiment provides a data management and search device based on PAEMKS applied to a data user side. Please refer to Figure 4 , Figure 4 FIG. is a schematic structural diagram of a data management and search device based on PAEMKS applied to a data user side provided by an embodiment of the present invention, and it includes:

[0090] A third key generation module, which is configured to obtain data user tag information and generate a third private key and a third public key accordingly, and at the same time retain the third private key and make the third public key public;

[0091] A trapdoor generation module, which is configured to select several keywords for the data to be queried, generate a trapdoor for the keywords by using a second private key, and send the trapdoor to the cloud server side to obtain corresponding ciphertext data.

[0092] The device provided in this embodiment can be used to implement the method provided in the first embodiment above. For the detailed process, please refer to the second embodiment above.

[0093] Embodiment Five

[0094] Based on the first to fourth embodiments above, this embodiment provides a data management and search system based on PAEMKS. Please refer to Figure 5 , Figure 5 FIG. is a schematic structural diagram of a data management and search system based on PAEMKS provided by an embodiment of the present invention, and it includes the data management and search device based on PAEMKS applied to the cloud server side provided in the third embodiment above and the data management and search device based on PAEMKS applied to the data user side provided in the fourth embodiment above.

[0095] It can be understood that the system further includes a second key generation module and a data encryption module applied to the data owner side, that is, the resource sharing party; wherein,

[0096] The second key generation module is configured to generate a public-private key pair of the data owner itself, that is, a second private key and a second public key;

[0097] The data encryption module is used to encrypt the data to be shared according to the system public parameters and the second private key to obtain ciphertext data.

[0098] Please refer to Figure 6 , Figure 6 which is a schematic diagram of the working process of a data management and search system based on PAEMKS provided by an embodiment of the present invention, specifically including:

[0099] S1: System initialization, generating system public parameters according to the input security parameters;

[0100] S2: Each participating party generates a public-private key pair based on the public parameters, discloses the public key, and hides the private key;

[0101] S3: The data owner encrypts the data to be shared based on the public parameters and its own private key to obtain ciphertext data;

[0102] S4: The data user generates trapdoors for a number of keywords to be queried based on the public parameters and its own private key, and uploads them to the cloud server;

[0103] S5: The cloud server performs a matching test on the ciphertext data and the trapdoors, and returns the ciphertext data with successful pairing as the search result to the data user.

[0104] For the detailed implementation process of the data management and search system based on PAEMKS provided in this embodiment, reference can be made to the above-mentioned Embodiment 1 to Embodiment 4, which will not be elaborated here.

[0105] Compared with the existing public key searchable encryption technology, the public key authenticated encryption method proposed by the present invention, which is applicable to multiple users and supports multi-keyword search, has a more challenging security model, that is, it is assumed that the server is malicious; this method can resist keyword guessing attacks initiated by internal malicious servers because the private key of the data owner is introduced in the encryption stage, making it impossible for malicious servers to generate test ciphertexts for the guessed candidate keywords using the receiver's public key, so keyword guessing attacks cannot be executed, thus ensuring the confidentiality of ciphertexts and the privacy of trapdoors, while ensuring the legitimacy of data owners; compared with single-keyword search and public key authenticated searchable encryption schemes applicable to single users, the present invention supports the function of retrieving multiple keywords, improving the efficiency and accuracy of retrieval, and is also applicable to scenarios with multiple receivers, making it more practical.

[0106] In addition, the present invention embeds the private key of the data owner in the encryption stage, preventing malicious servers from generating candidate keyword ciphertexts, fundamentally solving this problem, making it possible for public key searchable cryptography technology to have practicality. At the same time, it solves the problem of redundant search results caused by the single keyword search function.

[0107] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A data management and search method based on PAEMKS, which is applied to the cloud server side, characterized in that Including: Generate a first private key and a first public key according to the system public parameters, retain the first private key, and make the first public key public; Obtain the ciphertext data and the marking information of the data user; wherein, the ciphertext data is encrypted by the data owner for the data to be shared based on the system public parameters and its own second private key; the marking information is separately assigned by the trusted center to each data user; In response to receiving the trapdoor sent by the data user, perform a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information, and return the ciphertext data with successful pairing as the search result to the data user; Wherein, the performing a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information includes: Calculate the Lagrange coefficient polynomial ψ(x) according to the marking information of different users, and the calculation formula is: Among them, x i and x j represent the marking information of different users, i and j represent different users, and t represents the number of users; Calculate the following formula using the Shamir key recovery principle: Among them, represents the third public key of data user R i , y i = f(x i ), f(x) = s + a1x + a2x + … + a t-1 x t-1 , s is the constant term of the polynomial f(x), and a1, a2, a t-1 are the coefficients of the polynomial respectively; g is a public parameter of the system; Use the first private key to match the trapdoor i sent by data user R and the ciphertext data CT, and verify the following equation: If the equation holds, the trapdoor and the ciphertext data CT are successfully paired. Otherwise, the pairing fails and the search task stops; Among them, C j , B, and A are all ciphertexts in the ciphertext data CT, represents the third public key corresponding to the data user R i , and are both trapdoor data in, and sk CS represents the first private key corresponding to the cloud server.

2. The data management and search method based on PAEMKS according to claim 1, characterized in that, The generating a first private key and a first public key according to the system public parameters includes: Obtain the system public parameters gp generated by the trusted center; wherein, denotes a multiplicative cyclic group of order p, and g denotes a generator of the cyclic group, denotes a bilinear mapping, and H denotes a hash function; Select an integer β randomly in , and let the first private key sk cs = β, and let the first public key pk cs = g β ; where represents the finite field of modulo p.

3. The data management and search method based on PAEMKS according to claim 2, wherein, The steps for the data owner to encrypt the data to be shared based on the system public parameters and its own second private key to obtain the ciphertext data are as follows: Obtain the public parameters gp; Select an integer α randomly in , and let the second private key sk s = α. Let the second public key pk s = g α . At the same time, keep the second private key and publish the second public key; Select keywords for the data to be shared, denoted as w = {w1, …, w l1}; where l1 represents the number of keywords of the data to be shared; Generate a ciphertext for the keyword w using the second private key to obtain the ciphertext data CT.

4. A data management and search device based on PAEMKS, which is applied to the cloud server side, is characterized in that Including: A first key generation module, configured to generate a first private key and a first public key according to the system public parameters, retain the first private key, and make the first public key public; A first data acquisition module, configured to obtain the ciphertext data and the marking information of the data user; wherein, the ciphertext data is encrypted by the data owner for the data to be shared based on the system public parameters and its own second private key; the marking information is separately assigned by the trusted center to each data user; A matching test module, configured to, in response to receiving the trapdoor sent by the data user, perform a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information, and return the ciphertext data with successful pairing as the search result to the data user; Wherein, the performing a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information includes: Calculate the Lagrange coefficient polynomial ψ(x) according to the marking information of different users, and the calculation formula is: where x i and x j represent the marking information of different users, i and j represent different users, and t represents the number of users; Calculate the following formula using the Shamir key recovery principle: Among them, represents the third public key of data user R i , y i = f(x i ), f(x) = s + a1x + a2x + … + a t-1 x t-1 , s is the constant term of polynomial f(x), a1, a2, a t-1 are the coefficients of the polynomial respectively; g is a public parameter of the system; Use the first private key to match the trapdoor TD i sent by the data user R Ri and the ciphertext data CT, and verify the following equation: If the equation holds, the trapdoor and the ciphertext data CT are successfully paired. Otherwise, the pairing fails and the search task stops; Among them, C j , B, and A are all ciphertexts in the ciphertext data CT, represents the third public key corresponding to the data user R i , and are both trapdoor data in, sk CS represents the first private key corresponding to the cloud server.

5. A data management and search method based on PAEMKS, applied to the data user side, characterized in that, Including: Obtain the marking information of the data user and generate a third private key and a third public key accordingly, retain the third private key, and make the third public key public; Select several keywords for the data to be queried, generate a trapdoor for the keywords using the third private key, and send the trapdoor to the cloud server to obtain the corresponding ciphertext data; the corresponding ciphertext data is the ciphertext data with successful pairing obtained by the cloud server performing a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information; The cloud server performing a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information includes: Calculate the Lagrange coefficient polynomial ψ(x) according to the marking information of different users, and the calculation formula is: where x i and x j represent the marker information of different users, i and j represent different users, and t represents the number of users; Calculate the following formula using the Shamir secret key recovery principle: Among them, represents the third public key of data user R i , y i = f(x i ), f(x) = s + a1x + a2x + … + a t-1 x t-1 , s is the constant term of the polynomial f(x), and a1, a2, a t-1 are the coefficients of the polynomial respectively; g is a public parameter of the system; Use the first private key to match the trapdoor i sent by data user R and the ciphertext data CT, and verify the following equation: If the equation holds, the trapdoor and the ciphertext data CT are successfully paired. Otherwise, the pairing fails and the search task stops; Among them, C j , B, and A are all ciphertexts in the ciphertext data CT, represents the third public key corresponding to the data user R i , and are all trapdoor data, and sk CS represents the first private key corresponding to the cloud server.

6. The data management and search method based on PAEMKS according to claim 5, characterized in that, The obtaining of the data user's marking information and generating the third private key and the third public key based thereon includes: Obtain the user tag information (x i , y i ) generated by the trusted center; where i = 1, 2, …, t represents the number of data users; Based on the marked information (x i , y i ), let the third private key of the current data user R i be and the third public key 7. The data management and search method based on PAEMKS according to claim 6, characterized in that, Select several keywords for the data to be queried, and generate a trapdoor for the keywords using the third private key, including: Select several current data users R i Keywords to be queried, denoted as w' = {w1', …, w l2 '}; where l2 represents the number of keywords to be queried; Using its own third private key and the second public key pk of the data owner S Calculate the trapdoor of the keyword w' The calculation formula is as follows: Wherein, Wherein, g is a public parameter of the system, and H represents a hash function.

8. A data management and search device based on PAEMKS, which is applied to a data client, is characterized in that Includes: A third key generation module, configured to obtain the data user's marking information and generate a third private key and a third public key based thereon, and at the same time retain the third private key and disclose the third public key; A trapdoor generation module, configured to select several keywords for the data to be queried, generate a trapdoor for the keywords using the third private key, and send the trapdoor to the cloud server side to obtain corresponding ciphertext data; the corresponding ciphertext data is the ciphertext data that the cloud server side obtains after performing a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information; The cloud server side performs a matching test on the ciphertext data and the trapdoor based on the first private key and the marking information, including: Calculate the Lagrange coefficient polynomial ψ(x) according to the marking information of different users, and the calculation formula is: Among them, x i and x j represent the marking information of different users, i and j represent different users, and t represents the number of users; Calculate the following formula using the Shamir secret key recovery principle: Among them, represents the third public key of data user R i , y i = f(x i ), f(x) = s + a1x + a2x + … + a t-1 x t-1 , s is the constant term of the polynomial f(x), a1, a2, a t-1 are the coefficients of the polynomial respectively; g is a public parameter of the system; Use the first private key to match the trapdoor i sent by data user R and the ciphertext data CT, and verify the following equation: If the equation holds, the trapdoor and the ciphertext data CT are successfully paired. Otherwise, the pairing fails and the search task is stopped; Among them, C j , B, and A are all ciphertexts in the ciphertext data CT, represents the third public key corresponding to the data user R i , and are both trapdoor data in, and sk CS represents the first private key corresponding to the cloud server.

9. A data management and search system based on PAEMKS, characterized in that, It includes the data management and search device based on PAEMKS applied to the cloud server side described in claim 4 and the data management and search device based on PAEMKS applied to the data user side described in claim 8.