A time-sensitive access control method and device based on CP-ABE in edge computing

By introducing time information into CP-ABE to construct an access policy tree and outsourcing the decryption task, the problems of time constraints and limited computing resources in edge computing are solved, enabling time-sensitive data sharing and authentication, and improving the security and efficiency of edge computing.

CN116527358BActive Publication Date: 2025-10-24SHANXI ELECTRIC POWER CO POWER COMM CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310477620.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-28
Publication Date
2025-10-24
Estimated Expiration
2043-04-28

AI Technical Summary

Technical Problem

The existing CP-ABE mechanism cannot effectively meet the time constraints, limited computing resources, and authentication issues in edge computing environments, which limits its application and promotion in edge computing environments.

Method used

A time-sensitive access control method based on CP-ABE is designed. By introducing time information to construct an access policy tree, outsourcing part of the decryption task to edge nodes, and using certificateless public key hash signature for authentication, time-constrained data sharing and authentication are achieved.

Benefits of technology

It meets the time constraints in edge computing environments, reduces the computational burden on terminal devices, and enables authentication and verification of encrypted integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116527358B_ABST
    Figure CN116527358B_ABST
Patent Text Reader

Abstract

The application belongs to the field of cloud computing mode security, and particularly relates to a time-sensitive access control method and device under edge computing based on CP-ABE. The method comprises the following steps: a trusted authority generates public parameters and a master key; the trusted authority generates corresponding user keys according to the attributes of different data users, wherein the user keys comprise a unique identifier, an attribute key and a signature key; a data user generates corresponding conversion keys according to different attribute keys; a data owner generates a ciphertext to a cloud server and generates time constraint information to a time server according to the signature private key of different data users and an access tree; the time server generates a verification result according to the time constraint information; an edge node generates a time token according to the verification result and a time trapdoor; a data user applies for decryption of the ciphertext to generate a partially decrypted ciphertext; and the partially decrypted ciphertext and the attribute key of the data user are inputted to output a plaintext.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the field of cloud computing mode security, and particularly relates to a time-sensitive access control method and device based on CP-ABE in edge computing. BACKGROUND

[0002] As an extension and extension of the cloud computing mode, edge computing decomposes and migrates the uplink computing task of the user terminal or the downlink computing task of the cloud to the edge node close to the data source for processing, so as to effectively relieve the network bandwidth load and better support real-time response (Culler, David E. The once and future internet of everything[J]. GetMobile: Mobile Computing and Communications, 2017). However, the "cloud-edge-end" framework of edge computing makes the security mechanism of cloud computing unable to be directly applied to the edge computing (Zhou Jun, Shen Hua-jie, Lin Zhong-ru, et al. Research progress of edge computing privacy protection[J]. Computer Research and Development, 2020). Therefore, how to design a data sharing scheme for edge computing for ensuring the confidentiality, integrity and availability of shared data is an urgent problem to be solved (Zhang Jia-le, Zhao Yan-chao, et al. Research review of edge computing data security and privacy protection[J]. Journal of Communications, 2018) (Li Hui, Li Xiu-hua, Xiong Qing-yu, et al. Edge computing helps industrial internet: Architecture, application and challenge[J]. Computer Science, 2021).

[0003] CP-ABE (BETHENCOURT J, SAHAI A, WATERS B. Ciphertext-policy attribute-based encryption[C] / / 2007 IEEE Symposium on Security and Privacy. Piscataway: IEEE Press, 2007) can provide one-to-many and fine-grained data sharing mode, but it has problems such as inability to meet time constraint requirements, large encryption and decryption calculation overhead, and lack of verification of different entity identities, which restricts its application and promotion in the edge computing environment. In view of this, domestic and foreign researchers have carried out a lot of work, trying to improve and extend CP-ABE from aspects of space-time constraints, outsourcing computing and lightweight computing, so as to meet the requirements of edge computing environment.

[0004] (1) Space-time constraints: Literature (Kan Y, Zhen L, Jia X, et al. Time-Domain Attribute-Based Access Control for Cloud-Based Video Content Sharing: A Cryptographic Approach[J]. IEEE Transactions on Multimedia, 2016) embeds time into ciphertext and key, and designs a time-sensitive multimedia data sharing scheme; Literature (Dilixiati Wupur, Han Shuyan, Guli Mihe Erken, et al. User Revocation CP-ABE Scheme Based on Time Limit[J]. Journal of Xinjiang University (Natural Science Edition), 2019) proposes a CP-ABE scheme based on time limit, which realizes the function of user timing revocation by specifying the time limit of user accessing data; For users with hierarchical structure, based on recursive data set, Literature (ZHANG J W, MA J F, LI T, et al. Efficient hierarchical and time-sensitive data sharing with user revocation in mobile crowdsensing[J]. Security and Communication Networks, 2021) designs a hierarchical and time-sensitive CP-ABE scheme; By integrating time domain information and location domain information into the attribute encryption process, Literature (Peng Hongyan, Ling Jiao, Qin Shaohua, et al. Attribute Encryption Scheme for Edge Computing[J]. Computer Engineering, 2021) designs a CP-ABE scheme that meets both time constraints and location constraints; In view of the real-time and mobility of edge computing environment, Literature (P. Prathap Nayudu; Krovi Raja Sekhar. Dynamic Time and Location Information in Ciphertext-Policy Attribute-Based Encryption with Multi-Authorization[J]. Intelligent Automation&Soft Computing, 2023) designs a CP-ABE scheme supporting time and location attributes.

[0005] (2) Outsourcing computation: Literature (Xiong H, Zhao Y, Peng L, et al. Partially policy-hidden attribute-based broadcast encryption with secure delegation in edge computing[J]. Future Generation Computer Systems, 2019) proposed a CP-ABE scheme that can realize hidden partial policy, direct revocation and verification of outsourced decryption; Literature (Yan Xixi, He Guanghui, Yu Jinxia. Verifiable ciphertext policy attribute-based encryption secure outsourcing scheme[J]. Journal of Cryptography, 2020) designed an improved secure modular exponent outsourcing algorithm, and realized the verification function of outsourced decryption; Literature (Yang Hekun, Feng Zhaosheng, Jin Yunxia, et al. CP-ABE scheme supporting verifiable encryption and decryption outsourcing[J]. Electronic Journal, 2020) adopts an improved secure modular exponent outsourcing algorithm, outsources the encryption and decryption tasks of terminal users, and designs a CP-ABE scheme supporting verifiable encryption and decryption; Literature (Wang Zheng, Sun Zhi. Micro attribute encryption scheme supporting computation outsourcing in fog computing[J]. Computer Engineering and Science, 2022) proposes a personalized micro attribute encryption scheme with fixed length of key and ciphertext, and outsources part of the encryption and decryption tasks, thereby reducing the computational overhead of terminal devices.

[0006] (3) Lightweight computation: To solve the problem of large computation overhead of bilinear pairing in CP-ABE, the literature (Odelu V, Das A K. Design of a new CP-ABE with constant-size secret keys for lightweight devices using elliptic curve cryptography[J]. Security and Communication Networks, 2016) proposes a lightweight attribute-based encryption scheme based on elliptic curve, which is used to improve the speed of encryption and decryption; The literature (Yang Y, Shi R, Li K, et al. Multiple access control scheme for EHRs combining edge computing with smart contracts[J]. Future Generation Computer Systems, 2022) introduces a block chain mechanism on the basis of the literature (Dong Jiangtao, Yan Peiwen, Du Ruzhong. Fog computing based on pairing-free CP-ABE verifiable access control scheme[J]. Journal of Communications, 2021), and designs a pairing-free CP-ABE scheme, which is used to realize the function of verifying the correctness of access transaction. In order to protect the privacy of patient electronic health records, the literature (Yang Y, Shi R, Li K, et al. Multiple access control scheme for EHRs combining edge computing with smart contracts[J]. Future Generation Computer Systems, 2022) proposes a lightweight CP-ABE scheme supporting outsourcing and user attribute revocation.

[0007] In summary, although the CP-ABE mechanism has made great progress, there is still a lack of solutions that comprehensively consider time constraint requirements, limited computing resources, and identity verification problems. SUMMARY

[0008] The purpose of the present application is to overcome the problems existing in the prior art, and provide a time-sensitive access control method and device under edge computing based on CP-ABE.

[0009] The technical scheme adopted by the present application is as follows: a time-sensitive access control method under edge computing based on CP-ABE, comprising:

[0010] S1: a trusted authority generates public parameters and a master key;

[0011] S2: the trusted authority generates a corresponding user key according to the attributes of different data users, the user key including a unique identifier, an attribute key and a signature key;

[0012] S3: the data user generates a corresponding conversion key according to different attribute keys;

[0013] S4: the data owner generates a ciphertext to a cloud server and generates time constraint information to a time server according to the signature private key of the different data users and an access tree;

[0014] S5: the time server generates a verification result according to the time constraint information;

[0015] S6: an edge node generates a time token according to the verification result and a time trapdoor;

[0016] S7: the data user applies for decryption of the ciphertext, sends the conversion key to the edge node, the edge node obtains the ciphertext from the cloud server, and the edge node completes a partial decryption task according to the ciphertext, the conversion key, the attribute of the leaf node in the access tree and the time token, and generates a partial decryption ciphertext;

[0017] S8: the data user executes, inputs the partial decryption ciphertext and the attribute key of the data user, and outputs plaintext.

[0018] In some embodiments, the step S1 comprises:

[0019] constructing a composite-order bilinear group and a prime-order linear group;

[0020] selecting a random number;

[0021] selecting four hash functions;

[0022] generating public parameters and a master key according to the composite-order bilinear group, the prime-order linear group, the random number and the hash functions.

[0023] In some embodiments, the step S2 comprises:

[0024] the data user sends a registration request to the trusted authority, and the trusted authority selects a unique identity identifier for the data user;

[0025] generating an attribute key and a signature key according to the unique identity identifier and sending them to the data user.

[0026] In some embodiments, the step S3 comprises: the user selects a random number as a decryption key, and generates a conversion key by using the decryption key and the attribute key.

[0027] In some embodiments, step S4 comprises:

[0028] S41: constructing an access tree;

[0029] a) When the node is associated with time, then the constraint time is obtained according to the standard time control system , according to calculation , to signature:

[0030] , where P is a system public parameter, SK sig is the signature private key of the user, id is the unique identification of the user, and u i is a random number selected for each user;

[0031] Send the signed time constraint information to the time server;

[0032] b) Each node x has two associated values and ;

[0033] If the node has a time constraint, add the associated value t x , set , and according to whether there is a time constraint, it is divided into two parts ; and represent the associated values of the root node, select the root node secret value , set ;

[0034] S42: randomly select a symmetric key, encrypt the plaintext using a symmetric encryption algorithm, and calculate , where K is the symmetric key, are system public parameters, is the system master key, H0 is one of the system hash functions, and id is the unique identification of the user;

[0035] S43: Hash signature of the ciphertext using the signature key; , where P is a system public parameter, is the signature key, is the encrypted plaintext after the symmetric encryption algorithm, id is the unique identification of the user, u i is a random number selected for each user, and H is one of the system hash functions;

[0036] S44: According to the access tree node attribute where the ciphertext is located , , wherein x is a node of each leaf, is an attribute of the leaf node, k x1 is an associated value corresponding to each node, is a system public parameter, and H1 is one of system hash functions;

[0037] S45: Let Y denote a node set associated with time, and for any associated node , select a random number to generate a corresponding trapdoor: , wherein is the random number, , is a system public parameter, and t y is an associated value of the time-restricted node, H1 and H2 are system hash functions, is a constraint time obtained according to a standard time control system;

[0038] S45: Generate a ciphertext: .

[0039] In some embodiments, step S5 includes:

[0040] According to the time constraint information, verify , wherein PK sig is a signature public key, S and are hash signatures generated in S41 and S43, respectively;

[0041] If yes, add the time to the time set T ; otherwise, reject the time set T ;

[0042] For the time , publish a corresponding verification result , wherein is a system public parameter.

[0043] In some embodiments, step S6 includes:

[0044] Calculate a time constraint associated value:

[0045]

[0046] Calculate a time token: .

[0047] In some embodiments, step S7 includes:

[0048] S71: The data user applies to decrypt the ciphertext and sends the conversion key to the edge node;

[0049] S72: Calculate the normal attribute value of all leaf nodes :

[0050] , wherein Q j and Q j ’ is the conversion key of the edge node, Cx and Cx ’ is the encrypted ciphertext of all leaf nodes in the access tree;

[0051] S73: Calculate the time constraint value of the leaf node with time constraint :

[0052] , wherein Q j is the conversion key of the edge node, TK y is the time token issued in the system;

[0053] S74: Merge the processing values to obtain the leaf node value:

[0054] 1) If the node does not contain time constraint:

[0055] ;

[0056] 2) If the node is associated with time:

[0057] ;

[0058] S75: According to the properties of the access tree, recursively obtain the value of the non-leaf node of the access tree, and the value of the non-leaf node is:

[0059] , wherein z is the child node of the current node, , ;

[0060] S76: Calculate the value of the root node of the access tree:

[0061] ;

[0062] S77: According to the uploaded ciphertext, generate partial decryption ciphertext:

[0063] .

[0064] In some embodiments, step S8 comprises:

[0065] Verify the signature of some decrypted ciphertexts and verify the formula Is it true? If so, it proves that the ciphertext is sent by the original data owner and has not been tampered with; if the formula is not true, stop decryption and output ;

[0066] Calculate the symmetric key based on the data consumer attribute key:

[0067] , where C1 and C2 are the encrypted partial ciphertexts, F R To access the value of the root node of the tree, is the user's decryption key, and q is the user's attribute key;

[0068] Decrypt to obtain the plaintext.

[0069] A time-sensitive access control device for edge computing based on CP-ABE, comprising:

[0070] The trusted authority is responsible for generating public parameters and master keys, and generating corresponding private keys based on the attributes of the data user;

[0071] Cloud servers provide data storage and access capabilities;

[0072] Edge nodes are responsible for generating time tokens and completing part of the decryption task;

[0073] The time server is responsible for unifying the format of time constraints and verifying the integrity of time constraints;

[0074] The data owner is responsible for setting a time-constrained access control policy, encrypting the data according to this policy, and uploading it to CS; providing certificate-less public key hash signature function;

[0075] Data users are responsible for generating conversion keys for edge nodes, verifying the integrity of ciphertexts, and decrypting ciphertexts only when their attributes satisfy the DO's access control policy.

[0076] Compared with the prior art, the present invention has the following beneficial effects:

[0077] 1. Introduce time information and build a time-constrained access policy tree to meet data sharing requirements with time constraints;

[0078] 2. Outsource some decryption tasks to edge nodes to share computing tasks with terminal devices;

[0079] 3. Sign the ciphertext with a certificateless public key hash to achieve identity authentication and integrity verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] Figure 1Model and flow of the method TS-CP-ABE of the application;

[0081] Figure 2 Time-sensitive access tree schematic diagram. DETAILED DESCRIPTION

[0082] The application will be described in detail below with specific embodiments in conjunction with the accompanying drawings, but does not constitute a limitation on the application.

[0083] The embodiment provides a "cloud-edge-end" system using the method of the application.

[0084] In the embodiment, as shown in the figure, Figure 1 the application scheme mainly includes the following six entities: a trusted authority (TA), a cloud server (CS), an edge node (EN), a time server (TS), a data owner (DO) and a data user (DU).

[0085] (1) TA trusted authority: TA is fully trusted, responsible for generating public parameters and master keys of the TS-CP-ABE system, and generating corresponding private keys according to the attributes of the DU.

[0086] (2) CS cloud server: CS is semi-honest and curious, has strong computing and storage capabilities, and provides data storage and access functions.

[0087] (3) EN edge node: EN is semi-honest and curious, responsible for generating time tokens and completing part of the decryption task.

[0088] (4) TS time server: TS is fully trusted, responsible for unifying the format of time constraints and verifying the integrity of time constraints.

[0089] (5) DO data owner: DO is honest and trusted, responsible for setting access control policies with time constraints, encrypting data according to the policy, and uploading to CS; provides a certificateless public key hash signature function.

[0090] (6) DU data user: DU is untrusted, responsible for generating a conversion key of the edge node; verifying the integrity of the ciphertext; and only when its attributes meet the access control policy of DO, can the ciphertext be decrypted.

[0091] A time-sensitive access control method based on CP-ABE edge computing, comprising:

[0092] Initialization phase:

[0093] S1: Trusted authority generates public parameters and master key.

[0094] Specifically, executed by the trusted authority, input security parameters , output public parameters PK and master key MK.

[0095] Step 1: Construct a composite order bilinear group and a prime order linear group.

[0096] Where the composite order is , where G, G T The order of each is m = ab, G a and G b are subgroups of group G, and the generator is selected ; the prime order is , where G1G2are o order, . The generator is selected . The letters in this part are defined according to the relevant concepts of groups.

[0097] Step 2: Select a random number , calculate .

[0098] Step 3: Select four hash functions, denoted as H 0, , , .

[0099] Step 4: Generate public parameters PK and master key MK:

[0100] , .

[0101] Key generation phase:

[0102] S2: The trusted authority generates corresponding user keys according to the attributes of different data users, including unique identification, attribute key, and signature key.

[0103] The data user sends a registration request to the trusted authority, and the trusted authority selects a unique identity for the data user;

[0104] Generate attribute key and signature key according to unique identity and send to data user.

[0105] Specifically, executed by the trusted authority, input master key PK and attribute set R, output user (including data owner and data user) unique identification id, attribute key , signature key , .

[0106] Step 1: Select a random number for the user as the unique identity.

[0107] Step 2: Select a random number for the user i according to the attribute ; select a corresponding random number for the attribute . .

[0108] Step 3: Calculate the attribute key of the user:

[0109] .

[0110] Step 4: Generate the signature key of the user , .

[0111] S3: The data user generates a corresponding conversion key according to different attribute keys.

[0112] Specifically, executed by the data user, input the attribute key of the data user , output the conversion key of the edge node .

[0113] Step 1: Select a random number as the decryption key.

[0114] Step 2: DU generates a conversion key using the decryption key and the attribute key

[0115] .

[0116] for decrypting part of the decrypted ciphertext from the edge node to obtain the plaintext.

[0117] Encryption phase:

[0118] S4: The data owner generates ciphertext to the cloud server and generates time constraint information to the time server according to the signature private key of different data users and the access tree.

[0119] Specifically, executed by the DO data owner, input the symmetric key K , the data owner signature private key , the access tree T, output the ciphertext CT and the time constraint information time.

[0120] Step 1: The user constructs an access tree T as shown in Figure 2 . The access policy attribute set " , the time attribute is embedded into any node in the access policy tree, and a time-sensitive access policy tree is constructed. Figure 2 In the non-leaf node N2 and the leaf node N S , the time constraints t1 and t2 are added respectively, and the corresponding time threshold (TrapDoors, TD) and , and the time token (ToKens, TD) and are generated. For data users with attributes A1, A3 and A4 , only after the access time t1 is allowed to decrypt the ciphertext.

[0121] a) When the node is associated with time, the time constraint is calculated , and the signature is obtained:

[0122]

[0123] The signed time constraint information is sent to the time server.

[0124] b) Each node has two associated values and . If the node has a time constraint, the associated value t x is added. Set , and is divided into two parts according to whether there is a time constraint. It should be noted that and represent the associated values of the root node, and the root node secret value is selected, and is set. Each node has two associated values and . For the root node of this tree, the two associated values are specially named and , and the value of is initialized at the root node, which is a random number taken from . At the same time, the generation of C1 below also uses the secret value s.

[0125] Step 2: Randomly select a symmetric key , encrypt the plaintext m using a symmetric encryption algorithm to get , and calculate , .

[0126] Step 3: Use the signature key to sign the ciphertext C * to obtain .

[0127] Step 4: Let X denote the set of all leaf nodes in the access tree T, then each leaf node , the attribute of the leaf node is denoted as . Generate , .

[0128] Step 5: Let Y denote the set of time-related nodes, for any associated node , select a random number , and generate the corresponding trapdoor: .

[0129] Step 6: Generate the ciphertext: .

[0130] S5: The time server generates a verification result according to the time constraint information.

[0131] Specifically, executed by the TS, input the time constraint information time, and output the verification result .

[0132] Step 1: Verify whether the formula is true according to the time constraint information time content. If true, add the time to the time set T ; otherwise, reject the time set T .

[0133] Step 2: Publish the corresponding verification result for the time node .

[0134] S6: The edge node generates a time token according to the verification result and the time trapdoor.

[0135] Specifically, executed by the edge node, input the time verification result and the time trapdoor , and output the time token .

[0136] Step 1: Calculate the time constraint association value:

[0137] ;

[0138] Step 2: Calculate the time token .

[0139] Decryption phase:

[0140] S7: The data user applies for decryption of the ciphertext, sends the conversion key to the edge node, the edge node obtains the ciphertext from the cloud server, and the edge node completes the partial decryption task according to the ciphertext, the conversion key, the leaf node attribute in the access tree and the time token, and generates the partial decryption ciphertext.

[0141] Specifically, performed by the data user, input the ciphertext CT, the conversion key , the leaf node attribute in the access tree , and the time token , output the partial decryption ciphertext .

[0142] S71: The data user applies for decryption of the ciphertext, and sends the conversion key to the edge node.

[0143] S72: Calculate the normal attribute value of all leaf nodes :

[0144] .

[0145] S73: Calculate the time constraint value of the leaf node with time constraint :

[0146] .

[0147] S74: Merge the processing values to obtain the leaf node value:

[0148] 1) If the node does not contain time constraint:

[0149] ;

[0150] 2) If the node is associated with time:

[0151] ;

[0152] S75: According to the properties of the access tree, recursively obtain the value of the non-leaf node of the access tree, and the value of the non-leaf node is:

[0153] , where z is the child node of the current node, , ;

[0154] S76: Calculate the value of the root node of the access tree:

[0155] ;

[0156] S77: According to the uploaded ciphertext, generate partial decryption ciphertext:

[0157] .

[0158] S8: Data user executes, inputs partial decryption ciphertext and data user attribute key, outputs plaintext.

[0159] Specifically, executed by the data user, input ciphertext and data user attribute key , output plaintext m.

[0160] Step 1: Verify the signature of the partial decryption ciphertext. Verify if the formula is true. If true, it proves that the ciphertext at this time is the original data owner sent and has not been tampered with; if the formula is not true, stop decryption and output .

[0161] Step 2: According to q in the data user attribute key and C1, C2, F R in , calculate the symmetric key

[0162] .

[0163] Step 3: Decrypt to get plaintext .

Claims

1. A time-sensitive access control method based on CP-ABE edge computing, characterized in that, The method comprises the following steps: S1: a trusted authority generates public parameters and a master key; S2: the trusted authority generates a corresponding user key according to the attributes of different data users, the user key comprising a unique identifier, an attribute key and a signature key; S3: the data user generates a corresponding conversion key according to different attribute keys; S4: the data owner generates a ciphertext to a cloud server and generates time constraint information to a time server according to the signature private key of the different data users and an access tree; Step S4 comprises: S41: constructing an access tree; a) when the node is associated with a time, then the constraint time is obtained from the standard time control system , according to calculations , to signatures , where P is a system public parameter, SK sig is a user's signing private key, id is a user unique identification, u i is a random number selected for each user; signed time constraint information to the time server; b) each node x There are two associated values and ; If the node has time constraints, add the associated value t x , set While According to whether there are time constraints, it is divided into two parts ; And The associated value of the root node is represented, and the root node secret value is selected , set ; S42: randomly select a symmetric key, encrypt the plaintext using a symmetric encryption algorithm, and calculate , wherein K is a symmetric key, are both system public parameters, is a system master key, H0 is one of system hash functions, and id is a unique identifier of the user. S43: Hash signature of the ciphertext with the signature key; , wherein P is a system public parameter, is a signature key, is the plaintext encrypted by the symmetric encryption algorithm, id is a unique identifier of the user, u i is a random number selected for each user, and H is one of system hash functions. S44: generating according to the ciphertext the access tree node attribute , , wherein x is the node of each leaf, is the attribute of the leaf node, k x1 is the corresponding associated value of each node, is a system public parameter, and H1 is one of system hash functions; S45: Let Y denote the set of nodes associated with time, for any associated node , select a random number , generate the corresponding trapdoor: , where is a random number, , is a public parameter of the system, t y is the associated value of the time-constrained node, H1 and H2 are system hash functions, is the constraint time obtained according to the standard time control system; S46: generate the ciphertext: , T is a set of times; S5: the time server generates a verification result according to the time constraint information; S6: the edge node generates a time token according to the verification result and a time trapdoor; S7: the data user applies for decryption of the ciphertext, sends the conversion key to the edge node, and the edge node obtains the ciphertext from the cloud server; the edge node completes a partial decryption task according to the ciphertext, the conversion key, the attribute of the leaf node in the access tree and the time token, and generates a partial decryption ciphertext; S8: the data user executes, inputs the partial decryption ciphertext and the attribute key of the data user, and outputs plaintext.

2. The CP-ABE based edge computing lower time-sensitive access control method according to claim 1, characterized in that, The step S1 comprises: constructing a composite-order bilinear group and a prime-order linear group; selecting a random number; selecting four hash functions; generating public parameters and a master key according to the composite-order bilinear group, the prime-order linear group, the random number and the hash functions. 3.The CP-ABE based time-sensitive access control method for edge computing of claim 1, wherein, The step S2 comprises: the data user sends a registration request to the trusted authority, and the trusted authority selects a unique identity identifier for the data user; generating an attribute key and a signature key according to the unique identity identifier and sending them to the data user. 4.The CP-ABE based time-sensitive access control method for edge computing of claim 1, wherein, The step S3 comprises: the user selects a random number as a decryption key, and generates a conversion key by using the decryption key and the attribute key. 5.The time-sensitive access control method based on CP-ABE edge computing according to claim 1, wherein, The step S5 comprises: According to the time constraint information, verifying whether the following equation is true, where PK sig is a signature public key, S and are hash signatures generated in S41 and S43, respectively. If so, add the time to the set of join times T ; otherwise, reject the set of join times T ; To time , publish the corresponding verification result , wherein is a system public parameter.

6. The CP-ABE based time-sensitive access control method for edge computing according to claim 5, characterized in that, The step S6 comprises: calculating a time constraint correlation value: Computing time token: .

7. The CP-ABE based time-sensitive access control method for edge computing according to claim 6, characterized in that, The step S7 comprises: S71: the data user applies for decryption of the ciphertext, and sends the conversion key to the edge node; S72: Calculate the normal attribute value of all leaf nodes : wherein Q j and Q j ’ is the conversion key of the edge node, Cxand Cx ’ is the ciphertext of all leaf nodes in the access tree encrypted. S73: Calculate the time constraint value of the leaf node with time constraint : , where Q j TK is the translation key of the edge node y TT is the time token issued in the system S74: merging each processing value to obtain a leaf node value: 1) if the node does not contain time constraints: ; 2) if the node is associated with time: ; S75: recursively obtaining an access tree non-leaf node value according to the properties of the access tree, the value of the non-leaf node being: where z is a child node of the current node, , ; S76: calculating the value of the root node of the access tree: ; S77: generating a partial decryption ciphertext according to the uploaded ciphertext: 。 8. The CP-ABE based time-sensitive access control method for edge computing according to claim 7, characterized in that, The step S8 comprises: The signature of the partially decrypted ciphertext is verified, and a formula is verified If the formula is correct, it is proved that the ciphertext at this time is sent by the original data owner and has not been tampered with; if the formula is not correct, the decryption is stopped, and is output calculating a symmetric key according to the attribute key of the data user: where C1 and C2 are encrypted parts of ciphertext, F R is the value of the access tree root node, is the user decryption key, and q is the user's attribute key; decrypting to obtain plaintext.

9. A device for CP-ABE based time-sensitive access control in edge computing, for implementing the method for CP-ABE based time-sensitive access control in edge computing according to claim 1, characterized in that, The method comprises the following steps: a trusted authority is responsible for generating public parameters and a master key, and generating a corresponding private key according to the attributes of data users; a cloud server provides data storage and access functions; an edge node is responsible for generating a time token and completing a partial decryption task; a time server is responsible for unifying the format of time constraints and verifying the integrity of the time constraints; a data owner is responsible for setting an access control policy with time constraints, encrypting data according to the policy and uploading the data to the CS; and providing a certificateless public key hash signature function; a data user is responsible for generating a conversion key of the edge node, verifying the integrity of the ciphertext, and decrypting the ciphertext when the attribute of the data user meets the access control policy of the data owner.