Information sharing, information provenance methods, and apparatuses
By generating anonymous private keys and signing information sharing mechanisms for shared users, as well as information traceability mechanisms, the problems of privacy security and information leakage in Internet applications are solved, and effective supervision of privacy protection and traceability accountability is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-12
- Publication Date
- 2026-04-07
AI Technical Summary
In internet application scenarios, existing technologies are insufficient to effectively protect the privacy and security of users sharing information, and the lack of effective information traceability mechanisms makes it difficult to prevent information leakage and tampering, and difficult to obtain electronic evidence.
By constructing an information sharing mechanism, anonymous user private keys are generated for sharing users, and these user private keys are used to sign the shared data. Combined with an information traceability mechanism, the sharing users can be traced, thereby achieving supervision of the shared data.
It protects the privacy and security of users who share data, facilitates electronic evidence collection and traceability and accountability, and enables effective supervision of shared data.
Smart Images

Figure CN116743774B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information processing, in particular to an information sharing method, an information tracing method, a device and a computer readable storage medium. BACKGROUND
[0002] Information sharing is a bridge and link for collaborative computing, information exchange and mutual operation among terminal devices in an Internet application scenario. The information shared among terminal devices involves secret information and private data. To protect the secure sharing of secret information and prevent information leakage and tampering, the shared data needs to be encrypted.
[0003] Secondly, in the Internet application scenario, establishing an information tracing mechanism can effectively reduce the publication of malicious information and false information, and is conducive to electronic evidence collection of rumor events by law enforcement. SUMMARY
[0004] Therefore, the purpose of the present application is to provide an information sharing method, an information tracing method, a device and a computer readable storage medium. By constructing an information sharing mechanism, an anonymous user private key is generated for the user attribute of a sharing user, and the sharing data published by the sharing user is signed using the user private key, thereby protecting the privacy security of the sharing user in the Internet application. Furthermore, by constructing an information tracing mechanism, the sharing user who publishes the sharing data is traced, which facilitates electronic evidence collection and tracing accountability, and realizes the supervision of sharing data.
[0005] In a first aspect, the embodiments of the present application provide an information sharing method, comprising the following steps:
[0006] The client obtains the user attribute corresponding to the sharing user, and inputs the user attribute to the first server. The first server generates a user private key according to the obtained user attribute and a preset system public key, and sends the user private key to the client for storage.
[0007] The client obtains the sharing data corresponding to the sharing user and the access control policy information corresponding to the sharing data, wherein the access control policy information is used to indicate the corresponding user attribute.
[0008] The client obtains the user association data corresponding to the sharing data according to the access control policy information and the user private key, and sends the sharing data, the corresponding access control policy information and the user association data to the second server.
[0009] The second server generates a preliminary signature corresponding to the sharing data according to the system public key, the access control policy information and the user association data, and sends the preliminary signature and the system public key to the client.
[0010] The client generates an intermediate signature corresponding to the shared data based on the system public key, shared data, and preliminary signature. The intermediate signature is then combined with the user's private key to construct a target signature corresponding to the shared data. Finally, the target signature is sent to a second server for storage.
[0011] Secondly, embodiments of this application provide an information tracing method, comprising the following steps:
[0012] The client obtains the shared data to be traced and sends the shared data to be traced to the first server;
[0013] The first server generates a tracing instruction based on the obtained shared data to be traced, and sends it to the second server to obtain the target signature corresponding to the shared data to be traced sent by the second server.
[0014] The first server extracts the user's private key from the target signature and obtains the user attributes corresponding to the shared data to be traced based on the user's private key.
[0015] Thirdly, embodiments of this application provide an information sharing and traceability device, including a client, a first server, and a second server. The client is connected to the first server and the second server respectively, and the first server is connected to the second server. The client is used to execute the steps of the information sharing method as described in the first aspect, and to execute the steps of the information traceability method as described in the second aspect.
[0016] The first server is configured to perform the steps of the information sharing method as described in the first aspect, and the steps of the information tracing method as described in the second aspect;
[0017] The second server is used to execute the steps of the information sharing method as described in the first aspect, and the steps of the information tracing method as described in the second aspect.
[0018] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the information sharing method as described in the first aspect.
[0019] This application provides an information sharing and information tracing method, apparatus, device, and storage medium. By constructing an information sharing mechanism, an anonymous user private key is generated for the user attributes of the sharing user, and the shared data published by the sharing user is signed using the user private key, thus protecting the privacy and security of the sharing user in Internet applications. Furthermore, by constructing an information tracing mechanism, the sharing user who published the shared data can be traced, facilitating electronic forensics and accountability, and enabling the supervision of shared data.
[0020] To better understand and implement this invention, the following detailed description is provided in conjunction with the accompanying drawings. Attached Figure Description
[0021] Figure 1 This is a schematic diagram illustrating an application scenario of the information sharing method provided in the first embodiment of this application;
[0022] Figure 2 A flowchart illustrating the information sharing method provided in the first embodiment of this application;
[0023] Figure 3 A flowchart illustrating the information sharing method provided in the second embodiment of this application;
[0024] Figure 4 A schematic diagram of step S1 in the information sharing method provided in the first embodiment of this application;
[0025] Figure 5 A schematic diagram of step S3 in the information sharing method provided in the first embodiment of this application;
[0026] Figure 6 A schematic diagram of step S4 in the information sharing method provided in the first embodiment of this application;
[0027] Figure 7 A schematic diagram of step S5 in the information sharing method provided in the first embodiment of this application;
[0028] Figure 8 A flowchart illustrating the information sharing method provided in the second embodiment of this application;
[0029] Figure 9 A flowchart illustrating the information tracing method provided in the third embodiment of this application;
[0030] Figure 10 A schematic diagram of step S12 in the information sharing method provided in the third embodiment of this application;
[0031] Figure 11 This is a schematic diagram of the information sharing and traceability device provided in the fourth embodiment of this application. Detailed Implementation
[0032] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0033] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0034] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0035] Please refer to Figure 1 , Figure 1 This is a schematic diagram of an application scenario for the information sharing method provided in the first embodiment of this application. The application scenario includes a client 1, a first server 2, and a second server 3. The first server 2 and the second server 3 can access the Internet through a network access method and establish a data communication connection with the user's client 1. A data communication connection is established between the first server 2 and the second server 3. The network can be a communication medium of various connection types that enables communication between the first server 2, the second server 3, and the user's client 1, such as a wired communication link, a wireless communication link, or an optical fiber cable, etc. This application does not impose any limitations on this.
[0036] It should be noted that there are multiple interpretations of the concept of "client" in the existing technology. For example, it can be understood as an application installed on a computer device, or it can be understood as a hardware device corresponding to a server.
[0037] In the embodiments of this application, the term "client" refers to a hardware device corresponding to a server, and more specifically, to a computer device, such as a smartphone, a smart interactive whiteboard, and a personal computer.
[0038] When the client is a mobile device such as a smartphone or smart interactive whiteboard, users can install a matching mobile application on the client or access a web application on the client.
[0039] When the client is a non-mobile device such as a personal computer (PC), the user can install the matching PC application on the client, and can also access the web application on the client.
[0040] Among them, mobile applications refer to applications that can be installed on mobile devices, PC applications refer to applications that can be installed on non-mobile devices, and web applications refer to applications that need to be accessed through a browser.
[0041] Specifically, web applications can be divided into mobile and PC versions depending on the client type, and the page layout and server support provided may differ between the two.
[0042] The server can function as a service server, responsible for further connecting to related audio data servers, video streaming servers, and other servers providing related support, thereby forming a logically interconnected service cluster to serve related terminal devices, such as… Figure 1 The user's game client, as shown, provides services.
[0043] The first server contains a key generator, which consists of attribute authorization servers from different organizations. It is mainly used to authorize and manage user attribute characteristics, initialize the entire system, and issue private keys to system users.
[0044] The second server can be a cloud server. A cloud server is a cloud service provider, which refers to an entity capable of providing cloud service functions. This can be a private cloud service provided by an individual entity or a service provided by a public cloud. The cloud service provider mainly utilizes the computing power and storage advantages of cloud services to assist users in generating preliminary signatures corresponding to shared data and to provide storage and sharing services for the shared data.
[0045] Please see Figure 2 , Figure 2 The flowchart illustrates the information sharing method provided in the first embodiment of this application, which includes the following steps:
[0046] S1: The client obtains the user attributes corresponding to the shared user and inputs the user attributes to the first server; the first server generates a user private key based on the obtained user attributes and the preset system public key, and sends it to the client for storage.
[0047] Shared users consist of professionals with specialized knowledge and ordinary users. These users can publish shared data on internet applications. This shared data can be basic scientific knowledge, product raw material information, etc., published by professionals for specific groups (e.g., the general public, upstream and downstream enterprises).
[0048] The user attributes include numeric character attributes and several text character attributes. The numeric character attributes include an identity ID attribute, and the text character attributes include an organization attribute, a major attribute, and a professional title attribute. For example, the organization attribute could be South China Normal University, the major attribute could be Computer Application, the professional title attribute could be Professor, and the identity ID attribute could be a string constructed from numeric characters, etc. This application does not impose any restrictions on these attributes.
[0049] The user private key includes user association data corresponding to the user attributes. The user association data is the component data of the user private key and is used to reflect the user attributes. The user association data includes first private key data corresponding to numeric character attributes, second private key data corresponding to text character attributes, and anonymous identity data.
[0050] In this embodiment, the user can input user attributes into the client. The client responds to the user registration instruction by inputting the user attributes into the first server. The first server generates a user private key based on the obtained user attributes and a preset system public key, and sends it to the client for storage.
[0051] The system public key is pre-generated by the first server using a key generator and stored in the storage space pre-set by both the first and second servers. Please refer to [link / reference needed]. Figure 3 , Figure 3 The flowchart of the information sharing method provided in the second embodiment of this application further includes step S6, which is performed before step S1, as follows:
[0052] S6: In response to the initialization command, the first server extracts the first parameter from the preset integer multiplication loop group, generates the system public key based on the first parameter and the key generator, and sends it to the second server for storage.
[0053] To ensure the secure sharing of classified information and prevent its leakage and tampering, in this embodiment, each time the first server starts, it responds to an initialization command. The first server extracts a random number λ (λ∈Z) from a preset integer multiplication cyclic group Z as a first parameter. Based on the first parameter and a key generator, it generates the system public key and sends it to the second server for storage to enhance security. The system public key is:
[0054] {g,g b H(.)}
[0055] In the formula, g is the generator in the integer multiplication cyclic group, b is the traceability key, and g b H(.) is a component of the system public key generated by exponentially operating the generator and the traceability key, where H(.) is a single trapdoor function.
[0056] Please see Figure 4 , Figure 4 The schematic diagram of step S1 in the information sharing method provided in the first embodiment of this application includes steps S101 to S103, as follows:
[0057] S101: For the numeric character attribute, the first server extracts the second parameter from the integer multiplication cyclic group, and calculates the first private key data according to the second parameter, the identity ID attribute, the system public key, and the preset first private key data calculation algorithm.
[0058] In this embodiment, for the numeric character attribute, the first server extracts a random number ζ, ζ∈Z, from the integer multiplication cyclic group as a second parameter to obfuscate the numeric character attribute of the shared user, thereby improving the security of the obtained user private key.
[0059] The first server calculates the first private key data based on the second parameter, the identity ID attribute, the generator in the system public key, the single trapdoor function, and a preset first private key data calculation algorithm. The first private key data is:
[0060] SK1 = g H(ID||ζ)
[0061] In the formula, SK1 is the first private key data, ID is the identity ID attribute, ζ is the second parameter, H(ID||ζ) is the single trapdoor function value corresponding to the bitwise logical OR operation result of the identity ID attribute output by the single trapdoor function and the second parameter, and g H(ID||ζ) The result is generated by performing an exponentiation operation between the generator and H(ID||ζ), where || is the bitwise OR operator.
[0062] S102: Based on the second parameter, the identity ID attribute, the system public key, and the preset anonymous identity data calculation algorithm, generate the first sub-anonymous identity data and the second sub-anonymous identity data, and combine the first sub-anonymous identity data and the second sub-anonymous identity data to construct anonymous identity data.
[0063] In this embodiment, the first server determines the parameters based on the second parameter, the identity ID attribute, the generator g in the system public key, and g. b Based on a preset anonymous identity data calculation algorithm, a first sub-anonymous identity data and a second sub-anonymous identity data are generated. The first sub-anonymous identity data and the second sub-anonymous identity data are combined to construct anonymous identity data, wherein the anonymous identity data is:
[0064]
[0065] RID2 = g ζ
[0066] PID = {RID1, RID2}
[0067] In the formula, PID is the anonymous identity data, RID1 is the first sub-anonymous identity data, and g bζ g is a component element in the system public key. b The result generated by exponential operation with the second parameter, RID2 is the second sub-anonymized data, g ζ The result generated by exponentiation of the generator and the second parameter. The XOR operator;
[0068] S103: For the text character attributes, the first server extracts the third parameter corresponding to each text character attribute from the integer multiplication loop group, and calculates the second private key data corresponding to each text character attribute based on the third parameter corresponding to each text character attribute, the first private key data, and the system public key.
[0069] In this embodiment, for the text character attributes, the first server extracts the random number t corresponding to each text character attribute from the integer multiplication loop group. i , t i ∈Z, as the third parameter, is used to obfuscate the various text character attributes of the shared user in order to improve the security of the obtained user private key.
[0070] The first server calculates the second private key data corresponding to each of the stated text character attributes based on the third parameter, the first private key data, and the single trapdoor function in the system public key. The expression for the second private key data is:
[0071]
[0072] In the formula, i represents the attribute of the i-th text character, and t i SK is the third parameter corresponding to the i-th text character attribute. 2, This is the second private key data corresponding to the i-th text character attribute. The result is generated by performing an exponential operation on the value of the single trapdoor function corresponding to the i-th text character attribute output by the single trapdoor function and the corresponding third parameter.
[0073] S104: The first server combines the first private key data, the anonymous identity data, and the second private key data corresponding to each of the text character attributes to obtain the user private key.
[0074] In this embodiment, the first server combines the first private key data, the anonymous identity data, and the second private key data corresponding to each of the text character attributes to obtain the user private key.
[0075] S2: The client obtains the shared data and the access control policy information corresponding to the shared data.
[0076] In this embodiment, the client obtains shared data input by the shared user and the access control policy information corresponding to the shared data. The access control policy information is used to indicate corresponding user attributes, including several text character attributes. By setting the access control policy information, the user groups allowed to access the information can be determined. For example, if the information is shared with professors in the field of computer applications, the access control policy can be set to: (Professor or Associate Professor) and Computer Applications.
[0077] S3: The client obtains the user association data corresponding to the shared data based on the access control policy information and the user's private key, and sends the shared data, the corresponding access control policy information, and the user association data to the second server.
[0078] In this embodiment, the client obtains the user-related data corresponding to the shared data based on the access control policy information and the user's private key, and sends the shared data, the corresponding access control policy information, and the user-related data to the second server.
[0079] Please see Figure 5 , Figure 5 A schematic diagram of step S3 in the information sharing method provided in the first embodiment of this application, including step S301, is shown below:
[0080] S301: Based on the access control policy information and the user's private key, if the text character attributes in the access control policy information match the text character attributes in the user's private key, the client extracts the second private key data corresponding to the matching text character attributes in the user's private key, combines them, and uses them as the user-associated data corresponding to the shared data.
[0081] In this embodiment, the client, based on the access control policy information and the user's private key, if the text character attributes in the access control policy information match the text character attributes in the user's private key, extracts the second private key data corresponding to the matching text character attributes in the user's private key, combines them, and uses them as the user-associated data corresponding to the shared data.
[0082] S4: The second server generates a preliminary signature corresponding to the shared data based on the system public key, access control policy information, and user association data, and sends the preliminary signature and system public key to the client.
[0083] The initial signature is used to verify the authenticity and integrity of information. It creates a unique virtual fingerprint for an individual or entity, used to identify the user and protect the corresponding information.
[0084] In this embodiment, the second server generates a preliminary signature corresponding to the shared data based on the system public key, access control policy information, and user association data, and sends the preliminary signature and system public key to the client.
[0085] Please see Figure 6 , Figure 6 The schematic diagram of step S4 in the information sharing method provided in the first embodiment of this application includes steps S401 to S403, as follows:
[0086] S401: The second server obtains the parameter set corresponding to the access control policy information. The parameter set includes the fourth parameter corresponding to the plurality of text character attributes. The second server generates a first preliminary signature corresponding to the matching text character attribute based on the access control policy information and user association data. If the text character attribute in the access control policy information matches the text character attribute corresponding to the user association data, the second server generates a first preliminary signature corresponding to the matching text character attribute based on the fourth parameter corresponding to the corresponding text character attribute in the parameter set, the user association data, and the system public key.
[0087] In this embodiment, the second server selects a random number x corresponding to each of the several text character attributes corresponding to the access control policy information. i As the fourth parameter, the parameter set is constructed to obfuscate the attributes of various text characters and construct a more secure signature.
[0088] The second server, based on the access control policy information and user association data, if the text character attributes in the access control policy information match the text character attributes corresponding to the user association data, generates a first preliminary sub-signature corresponding to the matching text character attributes based on the fourth parameter corresponding to the text character attributes in the parameter set, the user association data, and the system public key. The first preliminary sub-signature is:
[0089]
[0090] In the formula, For the first preliminary signature corresponding to the i-th text character attribute, x i The fourth parameter corresponds to the attribute of the i-th text character. The result of exponentiation between the generator and the fourth parameter corresponding to the i-th character attribute.
[0091] S402: If the text character attributes in the access control policy information do not match the text character attributes corresponding to the user-associated data, generate a first preliminary sub-signature corresponding to the mismatched text character attributes based on the fourth parameter corresponding to the text character attributes in the parameter set and the system public key.
[0092] If the text character attributes in the access control policy information do not match the text character attributes corresponding to the user-associated data, in this embodiment, the second server generates a first preliminary sub-signature corresponding to the mismatched text character attributes based on the fourth parameter corresponding to the text character attributes in the parameter set and the system public key. The first preliminary sub-signature is:
[0093]
[0094] S403: The second server generates a second preliminary signature based on the shared data and the system public key, and combines the first sub-preliminary signature and the second preliminary signature corresponding to each text character attribute to generate a preliminary signature corresponding to the shared data.
[0095] In this embodiment, the second server generates a second preliminary signature based on the shared data and the system public key. Specifically, the second server combines the shared data and uses the one-way trapdoor function in the system public key to calculate H(M), and then...
[0096] ′
[0097] The second preliminary signature σ2 is obtained by bilinear mapping H(M) based on the certificate cyclic group Z.
[0098] The second server combines the first preliminary signature and the second preliminary signature corresponding to each text character attribute to generate a preliminary signature corresponding to the shared data, wherein the preliminary signature is:
[0099] σ ′ ={σ 1,x ′ ,2 ′}
[0100] In the formula, σ ′ For the initial signature, σ2 ′ This is the second preliminary signature.
[0101] S5: The client generates an intermediate signature corresponding to the shared data based on the system public key, shared data, and preliminary signature. The intermediate signature is combined with the user's private key to construct the target signature corresponding to the shared data. The target signature is then sent to the second server for storage.
[0102] In this embodiment, the client generates an intermediate signature corresponding to the shared data based on the system public key, shared data, and preliminary signature. The target signature includes a first sub-intermediate signature, a second sub-intermediate signature, and a third sub-intermediate signature.
[0103] The intermediate signature and the user's private key are combined to construct the target signature corresponding to the shared data, and the target signature is sent to the second server for storage. By adopting a decentralized attribute-based signature scheme, an anonymous user private key is generated for the user attributes that reflect the privacy information of the sharing user. The sharing user uses the anonymous user private key to sign the published shared data, thus protecting the privacy and security of the sharing user in Internet applications.
[0104] Please see Figure 7 , Figure 7 A schematic diagram of step S5 in the information sharing method provided in the first embodiment of this application, including steps S501 to S502, is shown below:
[0105] S501: The client generates a first sub-intermediate signature, a second sub-intermediate signature, and a third sub-intermediate signature corresponding to the shared data based on the preset fuzzy identity factor, the preliminary signature, and the system public key.
[0106] The fuzzy identity factors include a first fuzzy identity factor a and a second fuzzy identity factor r. In this embodiment, the client generates the first sub-intermediate signature based on the first fuzzy identity factor, the preliminary signature, and the generator in the system public key, wherein the first sub-intermediate signature is:
[0107] σ1=g a σ′
[0108] In the formula, σ1 is the first sub-intermediate signature, a is the first fuzzy identity factor, and σ′ is the preliminary signature;
[0109] The client generates the second sub-intermediate signature based on the shared data, the first fuzzy identity factor, the second fuzzy identity factor, the preliminary signature, the generator in the system public key, and the single trapdoor function. The second sub-intermediate signature is as follows:
[0110] σ²=H(M) r g a σ′
[0111] In the formula, σ2 is the second sub-intermediate signature, M is the shared data, r is the second fuzzy identity factor, and H(M) r The result is generated by performing an exponential operation on the single trapdoor function value corresponding to the shared data output by the single trapdoor function and the second fuzzy identity factor;
[0112] The client generates the third sub-intermediate signature based on the shared data, the second fuzzy identity factor, the preliminary signature, the generator in the system public key, and the single trapdoor function, wherein the third sub-intermediate signature is:
[0113] σ3=e(g,H(M) -r σ′)
[0114] In the formula, σ3 is the third sub-intermediate signature, and H(M) -r The result is generated by performing an exponential operation on the single trapdoor function value corresponding to the shared data output by the single trapdoor function and the second fuzzy identity factor after inversion.
[0115] S502: The client combines the first sub-intermediate signature, the second sub-intermediate signature, and the third sub-intermediate signature corresponding to the shared data to obtain the intermediate signature, and combines the intermediate signature with the anonymous identity data in the user's private key to generate the target signature corresponding to the shared data.
[0116] In this embodiment, the client combines the first sub-intermediate signature, the second sub-intermediate signature, and the third sub-intermediate signature corresponding to the shared data to obtain the intermediate signature, and combines the intermediate signature with the anonymous identity data in the user's private key to generate the target signature corresponding to the shared data.
[0117] Please see Figure 8 , Figure 8 The flowchart illustrating the information sharing method provided in the second embodiment of this application further includes steps S7 to S9, as detailed below:
[0118] S7: The client obtains the user attributes and access information identifier corresponding to the accessing user, and sends the user attributes and access information identifier to the first server.
[0119] The access information identifier is used to indicate the shared data to be accessed.
[0120] In this embodiment, the client obtains the user attributes and the access information identifier corresponding to the accessing user, and sends the user attributes and the access information identifier to the first server.
[0121] S8: The first server generates an access instruction based on the obtained access information identifier and sends it to the second server. The second server responds to the access instruction and sends the access control policy, shared data, and target signature corresponding to the access information identifier to the first server.
[0122] In this embodiment, the first server generates an access instruction based on the obtained access information identifier and sends it to the second server. The second server responds to the access instruction by sending the access control policy, shared data, and target signature corresponding to the access information identifier to the first server.
[0123] S9: The first server determines the access validity based on the obtained user attributes and the access control policy corresponding to the access information identifier. If valid, it determines the information validity based on the shared data corresponding to the access information identifier and the target signature. If valid, it generates a read command and sends it to the second server. The second server responds to the read command and sends the shared data corresponding to the access information identifier to the client. The client displays the obtained shared data corresponding to the access information identifier on a preset display interface.
[0124] In this embodiment, the first server determines the access validity based on the obtained user attributes and the access control policy corresponding to the access information identifier to confirm the identity validity of the accessing user. If valid, it determines the information validity based on the shared data corresponding to the access information identifier and the target signature to verify the integrity of the information content and whether it has been tampered with. If valid, it generates a read command and sends it to the second server. The second server responds to the read command by sending the shared data corresponding to the access information identifier to the client. The client displays the obtained shared data corresponding to the access information identifier on a preset display interface.
[0125] Please see Figure 9 , Figure 9 The flowchart of the information tracing method provided in the third embodiment of this application includes steps S10 to S12, as follows:
[0126] S10: The client obtains the shared data to be traced and sends the shared data to be traced to the first server.
[0127] In this embodiment, the client can obtain the shared data to be traced by inputting the corresponding link of the shared data by the user tracing the source, and then send the shared data to be traced to the first server.
[0128] S11: The first server generates a tracing instruction based on the obtained shared data to be traced, and sends it to the second server to obtain the target signature corresponding to the shared data to be traced sent by the second server.
[0129] The target signature includes anonymous identity data, which is used to indicate the identity ID attribute of the user corresponding to the shared data to be traced.
[0130] In this embodiment, the first server generates a tracing instruction based on the obtained traceable information identifier and sends it to the second server to obtain the tracing key sent by the second server and the target signature corresponding to the traceable information identifier.
[0131] S12: The first server extracts the user's private key from the target signature and obtains the user attributes corresponding to the shared data to be traced based on the user's private key.
[0132] In this embodiment, the first server generates a tracing instruction based on the obtained shared data to be traced, and sends it to the second server to obtain the target signature corresponding to the shared data to be traced sent by the second server.
[0133] In an optional embodiment, the client can also obtain a verification key input by the tracing user, and input the verification key along with the shared data to be traced to the first server. The first server determines the validity of the tracing based on the verification key and the tracing key to confirm whether the tracing behavior is authorized. Typically, when the first server generates the tracing key through a key generator, it stores the tracing key in a preset storage space as the verification key. When the tracing user wants to trace the shared data, they need to obtain the verification key to prove that their tracing behavior is authorized.
[0134] If valid, the first server extracts the user's private key from the target signature and obtains the user attributes corresponding to the shared data to be traced based on the user's private key. This enables tracing the user who published the shared data, facilitating electronic forensics and accountability, and achieving supervision of shared data.
[0135] Please see Figure 10 , Figure 10 A schematic diagram of step S12 in the information sharing method provided in the third embodiment of this application, including steps S121 to S122, is as follows:
[0136] S121: The first server extracts anonymous identity data from the user's private key.
[0137] In this embodiment, the first server extracts anonymous identity data from the user's private key, wherein the anonymous identity data includes first sub-anonymous identity data and second sub-anonymous identity data.
[0138] S122: The first server obtains the identity ID attribute corresponding to the shared data to be traced based on the first sub-anonymous identity data, the second sub-anonymous identity data, the preset system public key, and the preset identity ID attribute calculation algorithm.
[0139] In this embodiment, the first server obtains the identity ID attribute corresponding to the shared data to be traced based on the first sub-anonymous identity data, the second sub-anonymous identity data, the preset system public key, and the preset identity ID attribute calculation algorithm. The identity ID attribute calculation algorithm is as follows:
[0140]
[0141] In the formula, ID represents the identity ID attribute, RID1 represents the first sub-anonymous identity data, RID2 represents the second sub-anonymous data, and b represents the tracing key. This is the XOR operator.
[0142] Please refer to Figure 11 , Figure 11 This is a schematic diagram of the information sharing and traceability device provided in the fourth embodiment of this application, including a client 110, a first server 111, and a second server 112. The client 110 is connected to both the first server 111 and the second server 112, and the first server 111 is connected to the second server 112.
[0143] Client 111 is used to execute the information sharing method provided in the first embodiment and the second embodiment, and to execute the information tracing method provided in the third embodiment;
[0144] The first server 112 is used to execute the information sharing method provided in the first embodiment and the second embodiment, and to execute the information tracing method provided in the third embodiment;
[0145] The second server 113 is used to execute the information sharing method provided in the first embodiment and the second embodiment, and to execute the information tracing method provided in the third embodiment.
[0146] By establishing an information-sharing mechanism, anonymous user private keys are generated for the user attributes of sharing users, and these private keys are used to sign the shared data published by the sharing users, thus protecting the privacy and security of sharing users in internet applications. Furthermore, by establishing an information traceability mechanism, the sharing users who published the shared data can be traced, facilitating electronic forensics and accountability, and enabling the supervision of shared data.
[0147] The fifth embodiment of this application also provides a storage medium that can store multiple instructions. These instructions are applicable to being loaded by a processor and executed by the method steps of the first to third embodiments described above. For details of the execution process, please refer to the specific descriptions of the first to third embodiments, which will not be repeated here.
[0148] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0149] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0150] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the algorithm. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0151] In the embodiments provided by this invention, it should be understood that the disclosed apparatus / terminal devices and methods can be implemented in other ways. For example, the apparatus / terminal device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0152] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0153] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0154] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms.
[0155] This invention is not limited to the above-described embodiments. If any modifications or variations to this invention do not depart from the spirit and scope of this invention, and if such modifications and variations fall within the scope of the claims and equivalent technologies of this invention, then this invention also intends to include such modifications and variations.
Claims
1. An information sharing method, characterized in that, Includes the following steps: The client obtains the user attributes corresponding to the shared user and inputs the user attributes into the first server; The first server generates a user private key based on the obtained user attributes and the preset system public key, and sends it to the client for storage; The client obtains the shared data corresponding to the shared user, and the access control policy information corresponding to the shared data, wherein the access control policy information is used to indicate the corresponding user attributes; The client obtains the user-related data corresponding to the shared data based on the access control policy information and the user's private key, and sends the shared data, the corresponding access control policy information, and the user-related data to the second server. The second server generates a preliminary signature corresponding to the shared data based on the system public key, access control policy information, and user association data, and sends the preliminary signature and system public key to the client. The client generates an intermediate signature corresponding to the shared data based on the system public key, shared data, and preliminary signature. It then combines the intermediate signature with the user's private key to construct a target signature corresponding to the shared data and sends the target signature to the second server for storage. The user attributes include numeric character attributes and several text character attributes. The numeric character attributes include an identity ID attribute, and the text character attributes include an organization attribute, a major attribute, and a professional title attribute. The first server generates a user private key based on the obtained user attributes and a preset system public key, including the following steps: For the numeric character attribute, the first server extracts the second parameter from the integer multiplication cyclic group, and calculates the first private key data based on the second parameter, the identity ID attribute, the system public key, and a preset first private key data calculation algorithm. The first private key data calculation algorithm is as follows: In the formula, This is the first private key data. For the identity ID attribute, For the second parameter, The single trapdoor function value is the result of a bitwise logical OR operation between the identity ID attribute output by the single trapdoor function and the second parameter. For generators and The result generated by performing exponentiation. For bitwise logical OR operator; Based on the second parameter, the identity ID attribute, the system public key, and a preset anonymous identity data calculation algorithm, a first sub-anonymous identity data and a second sub-anonymous identity data are generated. The first sub-anonymous identity data and the second sub-anonymous identity data are then combined to construct anonymous identity data. The anonymous identity data calculation algorithm is as follows: In the formula, For the anonymous identity data, For the first child's anonymous identity data, The constituent elements of the system public key The result generated by exponentiation with the second parameter. For the second sub-anonymized data, The result generated by exponentiation of the generator and the second parameter. The XOR operator; For each text character attribute, the first server extracts the third parameter corresponding to each text character attribute from the integer multiplication loop group. Based on the third parameter corresponding to each text character attribute, the first private key data, and the system public key, it calculates the second private key data corresponding to each text character attribute. The expression for the second private key data is: In the formula, i Indicates the first i Each text character attribute For the first i The third parameter corresponding to each text character attribute For the first i The second private key data corresponding to each text character attribute. The first output of the single trapdoor function i The result is generated by performing an exponential operation on the single trapdoor function value corresponding to each text character attribute and the corresponding third parameter. The first server combines the first private key data, the anonymous identity data, and the second private key data corresponding to each of the text character attributes to obtain the user's private key.
2. The information sharing method according to claim 1, characterized in that, It also includes the following steps: In response to the initialization command, the first server extracts a first parameter from a preset integer multiplication loop group, generates the system public key based on the first parameter and a key generator, and sends it to the second server for storage. The system public key is: In the formula, For the generators in the integer multiplication cyclic group, b As the key for tracing the source, The constituent elements of the system public key generated by exponentially operating the generator and the traceability key. It is a single trapdoor function.
3. The information sharing method according to claim 1, characterized in that: The access control policy information includes several text character attributes; The step of obtaining user-related data corresponding to the shared data based on the access control policy information and the user's private key includes the following steps: Based on the access control policy information and the user's private key, if the text character attributes in the access control policy information match the text character attributes in the user's private key, the client extracts the second private key data corresponding to the matching text character attributes in the user's private key, combines them, and uses them as the user-associated data corresponding to the shared data.
4. The information sharing method according to claim 3, characterized in that: The preliminary signature includes a first sub-preliminary signature and a second sub-preliminary signature; The second server generates a preliminary signature corresponding to the shared data based on the system public key, access control policy information, and user association data, including the following steps: The second server obtains the parameter set corresponding to the access control policy information, the parameter set including the fourth parameter corresponding to the plurality of text character attributes; the second server, based on the access control policy information and user association data, if the text character attributes in the access control policy information match the text character attributes corresponding to the user association data, generates a first preliminary sub-signature corresponding to the matching text character attributes based on the fourth parameter corresponding to the corresponding text character attributes in the parameter set, the user association data, and the system public key, wherein the first preliminary sub-signature is: In the formula, For the first i The first preliminary signature corresponding to each text character attribute For the first i The fourth parameter corresponding to each text character attribute; If the text character attributes in the access control policy information do not match the text character attributes corresponding to the user-associated data, a first preliminary sub-signature corresponding to the mismatched text character attributes is generated based on the fourth parameter corresponding to the text character attributes in the parameter set and the system public key. The first preliminary sub-signature is: The second server generates a second preliminary signature based on the shared data and the system public key. It then combines the first and second preliminary signatures corresponding to each text character attribute to generate a preliminary signature corresponding to the shared data.
5. The information sharing method according to claim 4, characterized in that: The target signature includes a first sub-intermediate signature, a second sub-intermediate signature, and a third sub-intermediate signature; The client generates an intermediate signature corresponding to the shared data based on the system public key, shared data, and a preliminary signature. It then combines the intermediate signature with the user's private key to construct the target signature corresponding to the shared data, including the following steps: Based on a preset fuzzy identity factor, the initial signature, and the system public key, the client generates a first sub-intermediate signature, a second sub-intermediate signature, and a third sub-intermediate signature corresponding to the shared data. The first sub-intermediate signature is: In the formula, For the first child's middle signature, As the first fuzzy identity factor, For initial signature; The second intermediate signature is: In the formula, For the second child's middle signature, For the shared data, As the second fuzzy identity factor, The result is generated by performing an exponential operation on the single trapdoor function value corresponding to the shared data output by the single trapdoor function and the second fuzzy identity factor; The third intermediate signature is: In the formula, For the third child's middle signature, The result is generated by performing an exponential operation on the single trapdoor function value corresponding to the shared data output by the single trapdoor function and the second fuzzy identity factor after inversion. The client combines the first, second, and third sub-intermediate signatures corresponding to the shared data to obtain the intermediate signature, and then combines the intermediate signature with the anonymous identity data in the user's private key to generate the target signature corresponding to the shared data.
6. The information sharing method according to claim 1, characterized in that, It also includes the following steps: The client obtains the user attributes and the access information identifier corresponding to the accessing user, and sends the user attributes and the access information identifier to the first server, wherein the access information identifier is used to indicate the shared data to be accessed; The first server generates an access instruction based on the obtained access information identifier and sends it to the second server. The second server responds to the access instruction by sending the access control policy, shared data, and target signature corresponding to the access information identifier to the first server. The first server determines the access validity based on the obtained user attributes and the access control policy corresponding to the access information identifier. If valid, it determines the information validity based on the shared data corresponding to the access information identifier and the target signature. If valid, it generates a read command and sends it to the second server. The second server responds to the read command and sends the shared data corresponding to the access information identifier to the client. The client displays the obtained shared data corresponding to the access information identifier on a preset display interface.
7. An information tracing method, characterized in that, Includes the following steps: The client obtains the shared data to be traced and sends the shared data to be traced to the first server; The first server generates a tracing instruction based on the obtained shared data to be traced, and sends it to the second server to obtain the target signature corresponding to the shared data to be traced sent by the second server. The first server extracts the user's private key from the target signature. Based on the user's private key, it obtains the user attributes corresponding to the shared data to be traced. The user's private key is generated by the first server based on the obtained user attributes and a preset system public key. The user attributes include numeric character attributes and several text character attributes. The numeric character attributes include an identity ID attribute, and the text character attributes include an organization attribute, a major attribute, and a professional title attribute. The process includes the following steps: For the numeric character attribute, the first server extracts the second parameter from the integer multiplication cyclic group, and calculates the first private key data based on the second parameter, the identity ID attribute, the system public key, and a preset first private key data calculation algorithm. The first private key data calculation algorithm is as follows: In the formula, This is the first private key data. For the identity ID attribute, For the second parameter, The single trapdoor function value is the result of a bitwise logical OR operation between the identity ID attribute output by the single trapdoor function and the second parameter. For generators and The result generated by performing exponentiation. For bitwise logical OR operator; Based on the second parameter, the identity ID attribute, the system public key, and a preset anonymous identity data calculation algorithm, a first sub-anonymous identity data and a second sub-anonymous identity data are generated. The first sub-anonymous identity data and the second sub-anonymous identity data are then combined to construct anonymous identity data. The anonymous identity data calculation algorithm is as follows: In the formula, For the anonymous identity data, For the first child's anonymous identity data, The constituent elements of the system public key The result generated by exponentiation with the second parameter. For the second sub-anonymized data, The result generated by exponentiation of the generator and the second parameter. The XOR operator; For each text character attribute, the first server extracts the third parameter corresponding to each text character attribute from the integer multiplication loop group. Based on the third parameter corresponding to each text character attribute, the first private key data, and the system public key, it calculates the second private key data corresponding to each text character attribute. The expression for the second private key data is: In the formula, i Indicates the first i Each text character attribute For the first i The third parameter corresponding to each text character attribute For the first i The second private key data corresponding to each text character attribute. The first output of the single trapdoor function i The result is generated by performing an exponential operation on the single trapdoor function value corresponding to each text character attribute and the corresponding third parameter. The first server combines the first private key data, the anonymous identity data, and the second private key data corresponding to each of the text character attributes to obtain the user's private key.
8. The information tracing method according to claim 7, characterized in that: The user private key includes anonymous identity data, and the user attributes include an identity ID attribute, wherein the anonymous identity data is used to indicate the identity ID attribute of the user corresponding to the shared information to be traced. The first server extracts the user's private key from the target signature, and obtains the user attributes corresponding to the shared data to be traced based on the user's private key, including the following steps: The first server extracts anonymous identity data from the user's private key, wherein the anonymous identity data includes a first sub-anonymous identity data and a second sub-anonymous identity data, and the expression of the anonymous identity data is: In the formula, For the anonymous identity data, For the first child's anonymous identity data, Anonymous data for the second sub-sub; The first server obtains the identity ID attribute corresponding to the shared data to be traced based on the first sub-anonymous identity data, the second sub-anonymous identity data, the preset system public key, and the preset identity ID attribute calculation algorithm. The identity ID attribute calculation algorithm is as follows: In the formula, For identity ID attribute, For the first child's anonymous identity data, For the second sub-anonymized data, b The traceability key in the system's public key. This is the XOR operator.
9. An information sharing and traceability device, characterized in that, The information sharing and traceability device includes a client, a first server, and a second server. The client is connected to both the first server and the second server, and the first server is connected to the second server. The client is used to execute the method according to any one of claims 1, 3, 5 to 7; The first server is used to execute the method described in any one of claims 1 to 2 and claims 6 to 8; The second server is used to execute the method described in any one of claims 1, 4, 6, and 7.
Citation Information
Patent Citations
Secret key negotiation method and device
CN111030814A
Distributed data security sharing method and system based on block chain, and computer readable medium
CN113595971A