Flexible authorization ciphertext equivalence test public key authentication encryption methods, systems and media

CN117040808BActive Publication Date: 2026-08-14SOUTH CHINA AGRICULTURAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-20
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

据了解,这种方案无法实现等值密文测试且加密,陷门和测试算法效率低下,且支持灵活授权的前向安全密文等值测试公钥认证加密方案暂未被提出

Benefits of technology

[0109]1、本发明引入了一种用户级别的多类型授权的等值测试方案,多类型授权可以让云服务器的匹配范围更广,用户也可以根据自己的需求去提交不同的授权,具有更高的自由度。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117040808B_ABST
    Figure CN117040808B_ABST
Patent Text Reader

Abstract

This invention discloses a flexible authorization ciphertext equivalence test public key authentication encryption method, system, and medium. The method includes: obtaining public parameters and user public-private key pairs, wherein the user's public-private key pairs include the sender's public-private key pair and the receiver's public-private key pair; inputting the message to be encrypted and the current first system time, calculating the ciphertext based on the sender's private key, the receiver's public key, and the public parameters, and uploading the ciphertext to a server; inputting the current second system time, calculating the authorization trapdoor based on the receiver's private key, the sender's public key, the other receiver's and / or the sender's public key, and the public parameters, and uploading the authorization trapdoor to the server; inputting the ciphertexts of the two users and the corresponding authorization trapdoors to the server, so that the server performs an equivalence test on the ciphertexts of the two users and returns the test result. This invention can support flexible authorization, achieve forward security, and effectively resist offline message recovery attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a flexible authorized ciphertext equivalence test public key authentication encryption method, apparatus, system, and storage medium, belonging to the field of information security. Background Technology

[0002] With the massive growth of data, cloud storage services have become increasingly popular. More and more companies and individuals are storing their private data on cloud servers to reduce their own data storage and management burdens and to enable data sharing. While cloud servers offer significant benefits to users, they also present potential vulnerabilities and cannot guarantee data confidentiality. In recent years, data breaches involving user data stored on cloud servers have become increasingly common, posing a significant risk of personal information leakage. Therefore, to protect sensitive data from leakage, data is often encrypted before being uploaded to cloud servers, leading to the widespread research and application of encryption technology in practical scenarios. However, storing data in encrypted form on cloud servers makes data retrieval and sharing difficult. When a user wants to query certain data, they must download and decrypt all the encrypted data stored on the cloud server before searching locally, which undoubtedly increases the user's computational and communication costs significantly, making it impractical. Another method involves the user sending their key to the cloud server for decryption and retrieval, but this allows the cloud server to access the user's plaintext information, posing a security risk. Therefore, effectively retrieving encrypted data from cloud servers is the future direction of development.

[0003] The basic idea of ​​equivalence ciphertext testing is to determine whether a ciphertext matches specific information based solely on its equivalence comparison, without revealing the information inherent in the encrypted data itself, and then output the matching result. Equivalence ciphertext testing is primarily used in scenarios requiring both data security and rapid data retrieval. Here are some application scenarios for equivalence ciphertext testing: Cloud Computing: In cloud services, users store data in the cloud, but cloud service providers cannot see the plaintext information. Equivalence ciphertext testing can be used to ensure data privacy when data retrieval is required. Big Data Analytics: For big data analytics, massive amounts of data need to be stored and searched. Equivalence ciphertext testing can simplify search operations and protect data privacy. Medical Data Management: Medical institutions need to protect patient privacy while simultaneously retrieving and processing medical records and other data. Equivalence ciphertext testing can simultaneously protect data privacy and improve data retrieval efficiency. For receiver-level authorization, the user needs to specify the user being compared. For sender-level authorization, the user needs to specify the sender being compared. For receiver-sender-level authorization, the user needs to specify both the user being compared and the sender.

[0004] However, among existing equivalence ciphertext testing schemes, none have achieved a public-key encryption scheme that offers flexible authorization, forward security, and resistance to offline message recovery attacks. Flexible authorization refers to the existence of multiple different types of authorization, making it more widely applicable. Forward security involves embedding time parameters into the ciphertext and authorization; during equivalence testing, it is necessary to verify the correctness of the time in the ciphertext and authorization to ensure that old authorizations cannot be used in new ciphertext authorizations. Resistance to offline message recovery attacks refers to curious servers repeatedly matching other ciphertexts and guessing the relationships between them. The paper "Forward Secure Public-key Authenticated Encryption with Conjunctive Keyword Search" by Zhe Jiang et al. (In: The Computer Journal (2022)) discloses a forward-secure public-key authenticated searchable encryption method. This method uses 0-encoding and 1-encoding to process time in the Millionaires Problem and binds the ciphertext and trapdoor to their respective generation times to achieve forward security. It is understood that this scheme cannot achieve equivalent ciphertext testing and encryption, the trapdoor and testing algorithms are inefficient, and a forward-secure ciphertext equivalent testing public key authentication encryption scheme that supports flexible authorization has not yet been proposed. Summary of the Invention

[0005] In view of this, the present invention provides a flexible authorization ciphertext equivalent test public key authentication encryption method, device, system and storage medium, which can support flexible authorization, achieve forward security and effectively resist offline message recovery attacks, with better security performance and higher efficiency compared with other solutions.

[0006] The first objective of this invention is to provide a flexible authorized ciphertext equivalence test public key authentication encryption method.

[0007] The second objective of this invention is to provide a flexible authorized ciphertext equivalence test public key authentication encryption device.

[0008] The third objective of this invention is to provide a flexible authorized ciphertext equivalence test public key authentication encryption system.

[0009] A fourth objective of this invention is to provide a computer-readable storage medium.

[0010] The first objective of this invention is achieved by adopting the following technical solution:

[0011] A flexible authorized ciphertext equivalence test public key authentication encryption method, the method comprising:

[0012] Obtain public parameters and the user's public / private key pair, wherein the user's public / private key pair includes the sender's public / private key pair and the receiver's public / private key pair;

[0013] Input the message to be encrypted and the current first system time. Calculate the ciphertext based on the sender's private key, the receiver's public key, and common parameters, and upload the ciphertext to the server.

[0014] Input the current second system time, calculate the authorization trapdoor based on the recipient's private key, the sender's public key, the other party's public key and / or sender's public key, and public parameters, and upload the authorization trapdoor to the server;

[0015] The ciphertexts of the two users and the corresponding authorization traps are input into the server, so that the server can perform an equivalence test on the ciphertexts of the two users and return the test result.

[0016] Furthermore, the process for generating the common parameters is as follows:

[0017] Given a security parameter λ and a bilinear group in, It is a multiplicative cyclic group of prime number p, and two random numbers are randomly selected. As a generator, It is to satisfy The bilinear mapping relationship;

[0018] Choose five hash functions as follows:

[0019]

[0020] Among them, ι m Indicates the maximum message length, l p and l g express and Maximum length of elements Represents {0,1,2,...,p-1}; outputs common parameters based on random parameters and a hash function.

[0021] Furthermore, the process of generating the sender's public-private key pair is as follows:

[0022] Input common parameters and randomly select two numbers. Generate public key pairs and private key pair

[0023] The process of generating the receiver's public-private key pair is as follows:

[0024] Input common parameters and randomly select two numbers. Generate public key pairs and private key pair

[0025] Furthermore, the input message to be encrypted and the current first system time are used to calculate the ciphertext based on the sender's private key, the receiver's public key, and common parameters, and then the ciphertext is uploaded to the server. Specifically, this includes:

[0026] Generate three random numbers And calculate the shared key

[0027] The first system time t is processed as follows And calculate And 0≤i≤n, where the third hash function is one of the H3 common parameters;

[0028] calculate And calculate

[0029] Calculate the first ciphertext

[0030] M is the message to be encrypted, where H1, H4, and H5 are the first, fourth, and fifth hash functions in the common parameters;

[0031] Calculate the second, third, and fourth ciphertext segments. C4 = g δ ;

[0032] The fifth, sixth, and seventh ciphertext segments are calculated as C5 = {R}. i} 1≤i≤n ,

[0033] The eighth ciphertext segment is calculated as follows:

[0034]

[0035] H2 is the second hash function in the public parameters, and the T set is also part of the ciphertext.

[0036] Furthermore, by inputting the current second system time, and based on the recipient's private key, the sender's public key, the other recipient's public key, and common parameters, an authorization trapdoor is calculated and uploaded to the server. Specifically, this includes:

[0037] Generate a random number And calculate the shared key The second system time t' is processed as follows And calculate π y =H3(y i ,κ), and

[0038] The three authorizations are calculated as follows:

[0039]

[0040]

[0041]

[0042] in, Collections are also part of the authorization;

[0043] The process of performing an equivalence test on the ciphertexts of two users and returning the test result specifically includes:

[0044] like and The test continues;

[0045] Choose π y y comes from Calculate the following results:

[0046]

[0047] Choose π′ y y comes from Calculate the following results:

[0048]

[0049] Calculate D1 and D′1 respectively:

[0050]

[0051] Calculate Δ and Δ′ respectively:

[0052]

[0053]

[0054] If Δ = Δ′, then M = M′, and return 1 to indicate that the ciphertexts of the two users correspond to the same message; otherwise, output 0 to indicate that the ciphertexts of the two users correspond to different messages.

[0055] Furthermore, by inputting the current second system time, and based on the receiver's private key, the sender's public key, the other sender's public key, and common parameters, the authorized trapdoor is calculated, specifically including:

[0056] Generate a random number And calculate the shared key

[0057] The second system time t' is processed as follows And calculate π y =H3(y i ,χ), and

[0058] The three authorizations are calculated as follows:

[0059]

[0060]

[0061]

[0062] in, Collections are also part of the authorization;

[0063] The process of performing an equivalence test on the ciphertexts of two users and returning the test result specifically includes:

[0064] like and The test continues;

[0065] Choose π y y comes from Calculate the following results:

[0066]

[0067] Choose π′ y y comes from Calculate the following results:

[0068]

[0069] Calculate D1 and D′ respectively. i for:

[0070]

[0071] Calculate Δ and Δ′ respectively:

[0072]

[0073]

[0074] If Δ = Δ′, then M = M′, and returning 1 indicates that the ciphertexts of the two senders correspond to equal messages; otherwise, outputting 0 indicates that the ciphertexts of the two senders correspond to unequal messages.

[0075] Furthermore, by inputting the current second system time, and based on the receiver's private key, the sender's public key, the other receiver's public key, the other sender's public key, and common parameters, the authorized trapdoor is calculated, specifically including:

[0076] Generate a random number And calculate the shared key

[0077] The second system time t' is processed as follows And calculate π y =H3(y i ,k), and

[0078] The three authorizations are calculated as follows:

[0079]

[0080]

[0081]

[0082] in, Collections are also part of the authorization;

[0083] The process of performing an equivalence test on the ciphertexts of two users and returning the test result specifically includes:

[0084] like and The test continues;

[0085] Choose π y y comes from Calculate the following results:

[0086]

[0087] Choose π′ y y comes from Calculate the following results:

[0088]

[0089] Calculate D1 and D′1 respectively:

[0090]

[0091] Calculate Δ and Δ′ respectively:

[0092]

[0093]

[0094] If Δ = Δ′, then M = M′, and returning 1 indicates that the ciphertexts of the two senders correspond to equal messages; otherwise, outputting 0 indicates that the ciphertexts of the two senders correspond to unequal messages.

[0095] The second objective of this invention is achieved by adopting the following technical solution:

[0096] A flexible authorized ciphertext equivalence test public key authentication encryption device, the device comprising:

[0097] The acquisition module is used to acquire public parameters and the user's public-private key pair, wherein the user's public-private key pair includes the sender's public-private key pair and the receiver's public-private key pair;

[0098] The ciphertext generation module is used to take the message to be encrypted and the current first system time as input, calculate the ciphertext based on the sender's private key, the receiver's public key and public parameters, and upload the ciphertext to the server;

[0099] The authorization trapdoor generation module is used to take the current second system time as input, calculate the authorization trapdoor based on the receiver's private key, the sender's public key, the other receiver's and / or sender's public key, and public parameters, and upload the authorization trapdoor to the server;

[0100] The testing module is used to input the ciphertext of two users and the corresponding authorization trapdoor into the server, so that the server can perform an equivalence test on the ciphertext of the two users and return the test result.

[0101] The third objective of this invention is achieved by adopting the following technical solution:

[0102] A flexible authorized ciphertext equivalence test public key authentication encryption system, the system includes a user terminal, a key generation center and a server, the user terminal being connected to the key generation center and the server respectively;

[0103] The user terminal is used to obtain public parameters and the user's public-private key pair; input the message to be encrypted and the current first system time, calculate the ciphertext based on the sender's private key, the receiver's public key, and the public parameters, and upload the ciphertext to the server; input the current second system time, calculate the authorization trapdoor based on the receiver's private key, the sender's public key, the other receiver's and / or the sender's public key, and the public parameters, and upload the authorization trapdoor to the server; and input the user's ciphertext to decrypt it.

[0104] The key generation center is used to generate public parameters and public / private key pairs for users:

[0105] The server is used to perform an equivalence test on the ciphertexts of two users and the corresponding authorization trapdoors, and then return the test result.

[0106] The fourth objective of this invention is achieved by adopting the following technical solution:

[0107] A computer-readable storage medium storing a program that, when executed by a processor, implements the above-described flexible authorization ciphertext equivalence test public key authentication encryption method.

[0108] The present invention has the following advantages over the prior art:

[0109] 1. This invention introduces a user-level multi-type authorization equivalence test scheme. Multi-type authorization allows for a wider matching range for cloud servers, and users can submit different authorizations according to their own needs, providing greater freedom.

[0110] 2. This invention can use a shared key, requiring both the sender and receiver to authenticate each other, and the receiver to authenticate the other party's receiver or sender. This design can resist offline message recovery attacks and ensure that the user's ciphertext cannot be repeatedly matched by a curious cloud server to find a pattern.

[0111] 3. This invention incorporates a time parameter into the ciphertext and the authorization, ensuring that the old authorization cannot be applied to the new ciphertext. That is, it ensures that the ciphertext generated later requires a new authorization cloud server to perform equivalence testing. This design can be applied to marketing, similar to a paid service with an expiration date.

[0112] 4. Compared with existing forward-secure searchable encryption methods, this invention is suitable for scenarios involving ciphertext equivalence testing and can also achieve keyword search; finally, the computational efficiency of encryption, authorization trapdoor generation, and testing is improved by 42%, 65%, and 65%, respectively, greatly reducing the burden on users. Attached Figure Description

[0113] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the structures shown in these drawings without creative effort.

[0114] Figure 1 This is a structural block diagram of the flexible authorized ciphertext equivalence test public key authentication encryption system of Embodiment 1 of the present invention.

[0115] Figure 2 This is a flowchart illustrating the implementation of the flexible authorized ciphertext equivalence test public key authentication encryption system of Embodiment 1 of the present invention.

[0116] Figure 3This is a flowchart of the flexible authorization ciphertext equivalence test public key authentication encryption method of Embodiment 1 of the present invention.

[0117] Figure 4 This is a structural block diagram of the flexible authorized ciphertext equivalence test public key authentication encryption device according to Embodiment 2 of the present invention. Detailed Implementation

[0118] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0119] Example 1:

[0120] like Figure 1 As shown, this embodiment provides a flexible authorized ciphertext equivalence test public key authentication encryption system. The system includes a user terminal, a key generation center, and a server. The user terminal is connected to the key generation center and the server, respectively.

[0121] like Figure 2 As shown, the specific implementation process of the flexible authorization ciphertext equivalence test public key authentication encryption system in this embodiment is as follows:

[0122] (1) System initialization

[0123] System initialization is completed through the key generation center, specifically including:

[0124] Given a security parameter λ and a bilinear group in, It is a multiplicative cyclic group of prime number p, and two random numbers are randomly selected. As a generator, It is to satisfy The bilinear mapping relationship.

[0125] Choose five hash functions as follows:

[0126]

[0127] Among them, l m Indicates the maximum message length, l p and l g express and Maximum length of elements Represents {0,1,2,...,p-1};

[0128] Output common parameters based on random parameters and hash function.

[0129] (2) User Key Generation

[0130] A user's public-private key pair includes the sender's public-private key pair and the receiver's public-private key pair. The user's key generation process is completed through a key generation center, specifically including:

[0131] The process of generating the sender's public-private key pair is as follows:

[0132] Input the common parameter PP, and randomly select two numbers. Generate public key pairs and private key pair

[0133] The process of generating the receiver's public-private key pair is as follows:

[0134] Input common parameters and randomly select two numbers. Generate public key pairs and private key pair

[0135] (3) Ciphertext generation

[0136] The ciphertext generation process is completed through the user client and includes the following:

[0137] Input the message to be encrypted and the current first system time. Based on the sender's private key, the receiver's public key, and common parameters, perform the following operations to calculate the ciphertext:

[0138] Step 1: Generate three random numbers And calculate the shared key

[0139] The second step is to process the first system time t as T = {m} ι m ι-1 …m i |m i =1, 1≤i≤ι}, and calculate x. i =H3(y i ,κ),y i ∈T and 0≤i≤n, where the third hash function is one of the H3 common parameters;

[0140] Step 3: Calculation And calculate

[0141] Calculate the first ciphertext

[0142] M is the message to be encrypted, where H1, H4, and H5 are the first, fourth, and fifth hash functions in the common parameters;

[0143] Calculate the second, third, and fourth ciphertext segments. C4 = g δ ;

[0144] The fifth, sixth, and seventh ciphertext segments are calculated as C5 = {R}. i} 1≤i≤n ,

[0145] The eighth ciphertext segment is calculated as follows:

[0146]

[0147] H2 is the second hash function in the public parameters, and the T set is also part of the ciphertext.

[0148] (4) Ciphertext Decryption

[0149] The ciphertext decryption process is completed through the user client and includes the following:

[0150] Based on the user's private key sk and public parameter pp, the following formula is calculated from the input ciphertext C:

[0151]

[0152] C1, C2, C3, C4, C5, C6, C7, and C8 are the eight ciphertext segments of ciphertext C, where H2 is the second hash function in the public parameters, M is the decrypted message, and sk is the receiver's private key.

[0153] verify as well as Check if the condition is met. If it is met, return the decrypted message M.

[0154] (5) Authorization trapdoor generation

[0155] The generation of the authorized trapdoor is completed through the user client, specifically including:

[0156] Input the current second system time, and calculate the authorized trapdoor based on the recipient's private key, the sender's public key, the other recipient's and / or sender's public keys, and common parameters.

[0157] As can be seen, there are three types of authorization trapdoors. The first type of authorization trapdoor is calculated based on the receiver's private key, the sender's public key, the other receiver's public key, and common parameters. The second type of authorization trapdoor is calculated based on the receiver's private key, the sender's public key, the other sender's public key, and common parameters. The third type of authorization trapdoor is calculated based on the receiver's private key, the sender's public key, the other receiver, the other sender's public key, and common parameters.

[0158] A. The generation process of the first type of authorization trapdoor is as follows:

[0159] Step 1: Generate a random number And calculate the shared key

[0160] The second step is to process the second system time t' as follows: And calculate π y =H3(y i ,K), and

[0161] Step 3: Calculate the three authorization segments as follows:

[0162]

[0163]

[0164]

[0165] in, Collections are also part of the authorization.

[0166] B. The generation process of the second type of authorization trapdoor is as follows:

[0167] Step 1: Generate a random number And calculate the shared key

[0168] The second step is to process the second system time t' as follows: And calculate π y =H3(y i ,K ) , and

[0169] Step 3: Calculate the three authorization segments as follows:

[0170]

[0171]

[0172]

[0173] in, Collections are also part of the authorization.

[0174] C. The generation process of the third type of authorization trapdoor is as follows:

[0175] Step 1: Generate a random number And calculate the shared key

[0176] The second step is to process the second system time t' as follows: And calculate π y =H3(y i ,κ), and

[0177] Step 3: Calculate the three authorization segments as follows:

[0178]

[0179]

[0180]

[0181] in, Collections are also part of the authorization.

[0182] (6) Ciphertext Equivalence Test

[0183] The ciphertext equivalence test is performed on the server and includes the following:

[0184] Input the ciphertext of two users and the corresponding authorization trapdoor, perform an equivalence test on the ciphertext of the two users, and return the test result.

[0185] Since there are three types of authorization traps, there are also three types of ciphertext equivalence tests. The ciphertext equivalence test corresponding to the first type of authorization trap is called the first type of ciphertext equivalence test, the ciphertext equivalence test corresponding to the second type of authorization trap is called the second type of ciphertext equivalence test, and the ciphertext equivalence test corresponding to the third type of authorization trap is called the third type of ciphertext equivalence test.

[0186] A. The process of the first type of ciphertext equivalence test is as follows:

[0187] Step 1, if and The test continues; otherwise, the first type of ciphertext equivalence test is terminated.

[0188] Step 2: Select π y y comes from Calculate the following results:

[0189]

[0190] Choose π′ y y comes from Calculate the following results:

[0191]

[0192] Step 3: Calculate D1 and D′1 respectively:

[0193]

[0194]

[0195] Step 4: Calculate Δ and Δ′ respectively:

[0196]

[0197]

[0198] If Δ = Δ′, then M = M′, and return 1 to indicate that the ciphertexts of the two users correspond to the same message; otherwise, output 0 to indicate that the ciphertexts of the two users correspond to different messages.

[0199] B. The process of the second type of ciphertext equivalence test is as follows:

[0200] Step 1, if and The test continues; otherwise, the second type of ciphertext equivalence test is terminated.

[0201] Step 2: Select π y y comes from Calculate the following results:

[0202]

[0203] Choose π′ y y comes from Calculate the following results:

[0204]

[0205] Step 3: Calculate D1 and D′1 respectively:

[0206]

[0207]

[0208] Step 4: Calculate Δ and Δ′ respectively:

[0209]

[0210]

[0211] If Δ = Δ′, then M = M′, and returning 1 indicates that the ciphertexts of the two senders correspond to equal messages; otherwise, outputting 0 indicates that the ciphertexts of the two senders correspond to unequal messages.

[0212] C. The process of the third type of ciphertext equivalence test is as follows:

[0213] Step 1, if and The test continues; otherwise, the second type of ciphertext equivalence test is terminated.

[0214] Step 2: Select π y y comes from Calculate the following results:

[0215]

[0216] Choose π′ y y comes from Calculate the following results:

[0217]

[0218] Step 3: Calculate D1 and D′1 respectively:

[0219]

[0220]

[0221] Step 4: Calculate Δ and Δ′ respectively:

[0222]

[0223]

[0224] If Δ = Δ′, then M = M′, and returning 1 indicates that the ciphertexts of the two senders correspond to equal messages; otherwise, outputting 0 indicates that the ciphertexts of the two senders correspond to unequal messages.

[0225] like Figure 3 As shown, this embodiment provides a flexible authorized ciphertext equivalent test public key authentication encryption method, which is mainly implemented through the above steps (2), (3), (5) and (6), and is explained in detail below:

[0226] S301. Obtain public parameters and the user's public / private key pair.

[0227] S302. Input the message to be encrypted and the current first system time. Calculate the ciphertext based on the sender's private key, the receiver's public key, and public parameters, and upload the ciphertext to the server.

[0228] S303. Input the current second system time, calculate the authorization trapdoor based on the receiver's private key, the sender's public key, the other receiver's and / or sender's public key, and public parameters, and upload the authorization trapdoor to the server.

[0229] This step S303 is divided into three cases:

[0230] 1) Input the current second system time, calculate the first type of authorization trapdoor based on the receiver's private key, the sender's public key, the other receiver's public key and public parameters, and upload the first type of authorization trapdoor to the server.

[0231] 2) Input the current second system time, calculate the second type of authorization trapdoor based on the receiver's private key, the sender's public key, the other sender's public key and public parameters, and upload the second type of authorization trapdoor to the server.

[0232] 3) Input the current second system time, calculate the third type of authorization trapdoor based on the receiver's private key, the sender's public key, the other sender's public key, the other receiver's public key, and public parameters, and upload the third type of authorization trapdoor to the server.

[0233] S304. Input the ciphertexts of the two users and the corresponding authorization traps into the server so that the server can perform an equivalence test on the ciphertexts of the two users and return the test results.

[0234] This step S304 is divided into three cases:

[0235] 1) Input the ciphertexts of the two users and the corresponding first-type authorization trapdoors into the server so that the server can perform a first-type equivalence test on the ciphertexts of the two users and return the test results.

[0236] 2) Input the ciphertexts of the two users and the corresponding second-type authorization trapdoors into the server so that the server can perform a second-type equivalence test on the ciphertexts of the two users and return the test results.

[0237] 3) Input the ciphertexts of the two users and the corresponding third-type authorization traps into the server so that the server can perform a third-type equivalence test on the ciphertexts of the two users and return the test results.

[0238] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by a program instructing related hardware, and the corresponding program can be stored in a computer-readable storage medium.

[0239] It should be noted that although the method operations of the above embodiments are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the order of execution of the described steps may be changed. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0240] Example 2:

[0241] like Figure 4 As shown, this embodiment provides a flexible authorized ciphertext equivalence test public key authentication encryption device. The device includes an acquisition module 401, a ciphertext generation module 402, an authorization trapdoor generation module 403, and a testing module 404. The specific descriptions of each module are as follows:

[0242] The acquisition module 401 is used to acquire public parameters and the user's public-private key pair, wherein the user's public-private key pair includes the sender's public-private key pair and the receiver's public-private key pair.

[0243] The ciphertext generation module 402 is used to input the message to be encrypted and the current first system time, calculate the ciphertext based on the sender's private key, the receiver's public key and public parameters, and upload the ciphertext to the server.

[0244] The authorization trapdoor generation module 403 is used to input the current second system time, calculate the authorization trapdoor based on the receiver's private key, the sender's public key, the other party's public key and / or sender's public key, and common parameters, and upload the authorization trapdoor to the server.

[0245] Test module 404 is used to input the ciphertexts of two users and the corresponding authorization trapdoors into the server, so that the server can perform an equivalence test on the ciphertexts of the two users and return the test results.

[0246] It should be noted that the device provided in the above embodiments is only an example of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure can be divided into different functional modules to complete all or part of the functions described above.

[0247] Example 3:

[0248] This embodiment provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the flexible authorized ciphertext equality test public key authentication encryption method of Embodiment 1 above, as follows:

[0249] Obtain public parameters and the user's public / private key pair, wherein the user's public / private key pair includes the sender's public / private key pair and the receiver's public / private key pair;

[0250] Input the message to be encrypted and the current first system time. Calculate the ciphertext based on the sender's private key, the receiver's public key, and common parameters, and upload the ciphertext to the server.

[0251] Input the current second system time, calculate the authorization trapdoor based on the recipient's private key, the sender's public key, the other party's public key and / or sender's public key, and public parameters, and upload the authorization trapdoor to the server;

[0252] The ciphertexts of the two users and the corresponding authorization traps are input into the server, so that the server can perform an equivalence test on the ciphertexts of the two users and return the test result.

[0253] The computer-readable storage medium of this embodiment may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.

[0254] In summary, this invention introduces a user-level multi-type authorization equivalence testing scheme. Multi-type authorization allows for a wider matching range for cloud servers, and users can submit different authorizations according to their needs, providing greater freedom. Furthermore, through the use of shared keys, both the sender and receiver need to authenticate each other, and the receiver needs to authenticate the other party's receiver or sender. This design can resist offline message recovery attacks, ensuring that users' ciphertext cannot be repeatedly matched by curious cloud servers to find patterns.

[0255] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope disclosed in the present invention, based on the technical solution and inventive concept of the present invention, shall fall within the scope of protection of the present invention.

Claims

1. A flexible authorized ciphertext equivalence test public key authentication encryption method, characterized in that, The method includes: Obtain public parameters and the user's public / private key pair, wherein the user's public / private key pair includes the sender's public / private key pair and the receiver's public / private key pair; Input the message to be encrypted and the current first system time. Calculate the ciphertext based on the sender's private key, the receiver's public key, and common parameters, and upload the ciphertext to the server. Input the current second system time. Based on the recipient's private key, the sender's public key, the other recipient's and / or sender's public keys, and common parameters, calculate the authorization trapdoor and upload it to the server. A random number is generated after inputting the current second system time. And calculate the shared key. The second system time t' is processed as follows and calculate , ,and ; The ciphertexts of the two users and the corresponding authorization traps are input into the server so that the server can perform an equivalence test on the ciphertexts of the two users and return the test result. The input message to be encrypted and the current first system time are used to calculate the ciphertext based on the sender's private key, the receiver's public key, and common parameters. Specifically, this includes: Generate three random numbers And calculate the shared key. ; The first system time t is processed as T and calculate , and ,in The third hash function in the public parameters; calculate and calculate , ; Calculate the first ciphertext = M represents the message to be encrypted, where 、 、 These are the first, fourth, and fifth hash functions in the common parameters; Calculate the second, third, and fourth ciphertext segments. ; Calculate the ciphertext in segments five, six, and seven as follows: ; The eighth ciphertext segment is calculated as follows: ; H2 is the second hash function in the public parameters, and the T set is also part of the ciphertext.

2. The flexible authorized ciphertext equivalence test public key authentication encryption method according to claim 1, characterized in that, The process of generating the common parameters is as follows: Given a security parameter λ and a bilinear group ,in, It is a multiplicative cyclic group of prime number p, and two random numbers are randomly selected. As a generator, It is to satisfy The bilinear mapping relationship; Choose five hash functions as follows: ; in, Indicates the maximum message length. and express and Maximum length of elements Represents {0,1,2,...,p-1}; Output common parameters based on random parameters and hash function. .

3. The flexible authorized ciphertext equivalence test public key authentication encryption method according to claim 1, characterized in that, The process of generating the sender's public-private key pair is as follows: Input common parameters and randomly select two numbers. Generate public key pair and the private key pair are ; The process of generating the receiver's public-private key pair is as follows: Input common parameters and randomly select two numbers. Generate public key pair and the private key pair are .

4. The flexible authorization ciphertext equivalence test public key authentication encryption method according to any one of claims 1-3, characterized in that, The authorized trapdoor is calculated based on the recipient's private key, the sender's public key, the other recipient's public key, and common parameters. Specifically, it includes: The three authorizations are calculated as follows: ; in, Collections are also part of the authorization; The process of performing an equivalence test on the ciphertexts of two users and returning the test result specifically includes: like and The test continues; choose y comes from Calculate the following results: ; choose y comes from Calculate the following results: ; Calculate D1 and D2 respectively for: ; Calculate △ and △ respectively for: ; like ,but If the output is 1, it means that the ciphertext messages of the two users are equal; otherwise, it means that the ciphertext messages of the two users are not equal.

5. The flexible authorization ciphertext equivalence test public key authentication encryption method according to any one of claims 1-3, characterized in that, The authorized trapdoor is calculated based on the recipient's private key, the sender's public key, the other sender's public key, and common parameters. Specifically, it includes: The three authorizations are calculated as follows: ; in, Collections are also part of the authorization; The process of performing an equivalence test on the ciphertexts of two users and returning the test result specifically includes: like and The test continues; choose y comes from Calculate the following results: ; choose y comes from Calculate the following results: ; Calculate D1 and D2 respectively for: ; Calculate △ and △ respectively for: ; like ,but If the output is 1, it means that the ciphertexts of the two senders correspond to the same message; otherwise, it outputs 0, meaning that the ciphertexts of the two senders correspond to different messages.

6. The flexible authorization ciphertext equivalence test public key authentication encryption method according to any one of claims 1-3, characterized in that, Based on the recipient's private key, the sender's public key, the other recipient's public key, the other sender's public key, and common parameters, an authorized trapdoor is calculated, specifically including: The three authorizations are calculated as follows: ; in, Collections are also part of the authorization; The process of performing an equivalence test on the ciphertexts of two users and returning the test result specifically includes: like and The test continues; choose y comes from Calculate the following results: ; choose y comes from Calculate the following results: ; Calculate D1 and D2 respectively for: ; Calculate △ and △ respectively for: ; like ,but If the output is 1, it means that the ciphertexts of the two senders correspond to the same message; otherwise, it outputs 0, meaning that the ciphertexts of the two senders correspond to different messages.

7. A flexible authorized ciphertext equivalence test public key authentication encryption device, characterized in that, The device includes: The acquisition module is used to acquire public parameters and the user's public-private key pair, wherein the user's public-private key pair includes the sender's public-private key pair and the receiver's public-private key pair; The ciphertext generation module is used to take the message to be encrypted and the current first system time as input, calculate the ciphertext based on the sender's private key, the receiver's public key and public parameters, and upload the ciphertext to the server; The authorization trapdoor generation module is used to calculate the authorization trapdoor based on the recipient's private key, the sender's public key, the other recipient's and / or sender's public keys, and common parameters, after inputting the current second system time. The authorization trapdoor is then uploaded to the server. Specifically, after inputting the current second system time, a random number is generated. And calculate the shared key. The second system time t' is processed as follows and calculate , ,and ; The testing module is used to input the ciphertext of two users and the corresponding authorization traps into the server, so that the server can perform an equivalence test on the ciphertext of the two users and return the test results. The input message to be encrypted and the current first system time are used to calculate the ciphertext based on the sender's private key, the receiver's public key, and common parameters. Specifically, this includes: Generate three random numbers And calculate the shared key. ; The first system time t is processed as T and calculate , and ,in The third hash function in the public parameters; calculate and calculate , ; Calculate the first ciphertext = M represents the message to be encrypted, where 、 、 These are the first, fourth, and fifth hash functions in the common parameters; Calculate the second, third, and fourth ciphertext segments. ; Calculate the ciphertext in segments five, six, and seven as follows: ; The eighth ciphertext segment is calculated as follows: ; H2 is the second hash function in the public parameters, and the T set is also part of the ciphertext.

8. A flexible authorized ciphertext equivalence test public key authentication encryption system, characterized in that, The system includes a user terminal, a key generation center, and a server, with the user terminal connected to the key generation center and the server respectively. The user terminal is used to obtain public parameters and the user's public-private key pair; input the message to be encrypted and the current first system time, calculate the ciphertext based on the sender's private key, the receiver's public key, and the public parameters, and upload the ciphertext to the server; input the current second system time, calculate the authorization trapdoor based on the receiver's private key, the sender's public key, the other party's public key and / or the sender's public key, and the public parameters, and upload the authorization trapdoor to the server; and input the user's ciphertext to decrypt it, wherein, after inputting the current second system time, a random number is generated. And calculate the shared key. The second system time t' is processed as follows and calculate , ,and ; The key generation center is used to generate public parameters and public / private key pairs for users: The server is used to perform an equivalence test on the ciphertexts of two users and the corresponding authorization traps after inputting the ciphertexts of the two users and return the test results. The input message to be encrypted and the current first system time are used to calculate the ciphertext based on the sender's private key, the receiver's public key, and common parameters. Specifically, this includes: Generate three random numbers And calculate the shared key. ; The first system time t is processed as T and calculate , and ,in The third hash function in the public parameters; calculate and calculate , ; Calculate the first ciphertext = M represents the message to be encrypted, where 、 、 These are the first, fourth, and fifth hash functions in the common parameters; Calculate the second, third, and fourth ciphertext segments. ; Calculate the ciphertext in segments five, six, and seven as follows: ; The eighth ciphertext segment is calculated as follows: ; H2 is the second hash function in the public parameters, and the T set is also part of the ciphertext.

9. A computer-readable storage medium storing a program, characterized in that, When the program is executed by the processor, it implements the flexible authorization ciphertext equivalence test public key authentication encryption method as described in any one of claims 1-7.