A method for encrypting fine-grained predicate functions with convertible property in access structure

By designing a fine-grained predicate function encryption method with convertible access structure, the problem that existing encryption schemes cannot achieve fine-grained controllability and flexible secure data access is solved, and flexible secure data access control in multiple scenarios is realized.

CN117278206BActive Publication Date: 2026-08-25GUIZHOU UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202311203603.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-18
Publication Date
2026-08-25
Estimated Expiration
2043-09-18

AI Technical Summary

Technical Problem

Existing encryption schemes cannot achieve fine-grained, controllable, flexible, and secure data access control, and traditional public-key encryption systems cannot meet the needs of on-demand data applications in multiple scenarios.

Method used

A fine-grained predicate function encryption method with convertible access structure is designed. The access structure is defined by set theory, the predicate access control function is designed, and a permissioned fine-grained access control predicate function encryption model is constructed, including system settings, policy control, key generation, encryption and decryption modules. A bilinear generator is used to generate keys and perform encryption and decryption operations.

Benefits of technology

It enables fine-grained data querying and control based on the access structure, supports flexible and secure data access in multiple scenarios, and meets the needs of open data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117278206B_ABST
    Figure CN117278206B_ABST
Patent Text Reader

Abstract

The application discloses a fine-grained predicate function encryption method with convertible property on access structure, and is characterized in that the steps include giving the definition of general access structure based on set theory, defining the matching operation of access structure vector and attribute set vector, designing predicate access control function, constructing a fine-grained access control predicate function encryption model with authority based on the proposed predicate access control function, and constructing a fine-grained predicate function encryption model with convertible property on access structure. The application can complete the conversion and unification between ciphertext policy predicate encryption and key policy predicate encryption according to actual application scenes, and can hide the attribute values of participants by using predicate coding, so that the privacy of users is protected, and the application can be more safely applied to complex and changeable cloud environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption technology, specifically to a fine-grained predicate function encryption method with convertible access structure. Background Technology

[0002] In the current context of the booming digital economy, data has become a new factor of production. How to balance usability and security in the process of data sharing and application has become a hot research topic in industry and academia. Using cryptographic techniques to encrypt data before uploading it to the cloud can ensure data security to a certain extent. However, traditional public-key encryption systems use an "all-or-nothing" approach to encrypt and decrypt ciphertext data, failing to enable on-demand data application. Furthermore, existing encryption schemes are typically only applicable to a specific type of application scenario, lacking scalability. Therefore, researching more granular, controllable, flexible, and secure encryption schemes is of significant research value.

[0003] Patent application CN202210703263.3 discloses a searchable public-key encryption method that simultaneously supports semantic queries. This invention, while ensuring data security, semantically expands user query information, solving the accuracy problem in the field of ciphertext retrieval. However, this invention cannot perform fine-grained query searches on ciphertext data based on access structures. Patent application CN202210500855 proposes a delegated inner product function encryption method. This method has the following characteristics: 1. The user's key is bound to their identity and a vector; 2. The user can directly delegate their decryption rights to a delegate and set a validity period for the delegation; 3. The delegate can only decrypt the ciphertext within the delegation period; 4. No agency is required to re-encrypt the data. However, this invention does not consider the access control needs of the data owner and has a limited applicable scenarios.

[0004] Predicate function encryption evolved from attribute encryption and possesses strong expressive power, enabling partial encryption and decryption of ciphertext data. However, existing research has not addressed the issue from the perspective of fine-grained general access structures, and its construction of access control strategies is relatively limited. Therefore, in environments with imperfect trust, it is of great significance to design predicate strategies related to access structures, fully considering the requirements of data confidentiality and open sharing, and to implement a fine-grained predicate function encryption method with convertible properties. Summary of the Invention

[0005] A fine-grained predicate function encryption method with convertible access structure, comprising:

[0006] S1 gives the definition of the general access structure Σ based on set theory;

[0007] S2 defines the matching operation for accessing the structure vector and the attribute set vector;

[0008] S3 designs predicate access control functions;

[0009] S4 constructs a predicate function cryptographic model with permissioned fine-grained access control;

[0010] S5 constructs a fine-grained predicate function encryption model with convertible properties on the access structure.

[0011] S1, in set theory, defines a general access structure ∑, which includes: fusion participant A user Power set of attribute set Power set of logical operation set 2 Θ Given a hierarchical permission set R, define the Cartesian product: This allows us to construct an access tree structure with hierarchical permissions:

[0012]

[0013] Will subset of Defined as a general access structure with hierarchical permissions.

[0014] S2 defines the matching operation between the access structure vector and the attribute set vector, which includes: defining the access structure vector based on the proposed general access structure. and attribute set vector Matching operation

[0015]

[0016] in For the set of authorized attributes, r ∑ ,r∈R; based on this, a predicate strategy is proposed.

[0017] S3's predicate access control functions include: based on the predicate strategy. Design a predicate access control function. in, For function space, For key space, For plaintext space:

[0018]

[0019] like Then the participant has the right to operate on the function f being calculated.

[0020] The S4 constructs a permissioned fine-grained access control predicate function encryption model, which includes: constructing a permissioned fine-grained access control predicate function encryption model based on the proposed predicate access control function. This model includes a system setup module (1). λ → (pub, msk), Encryption module Key generation module Strategy control module Decryption module Dec(c, sk f The five modules are f(m) → f(m).

[0021] The system settings module requires inputting security parameter 1. λ Then, a public parameter `pub` and a master private key `msk` are generated. The public parameter `pub` is sent to the encryption module, and the master private key `msk` is sent to the key generation module. Next, the policy control module determines the key based on the predicate vectors of the participants. and Generative predicate strategy P ∑ It then sends the master private key msk and the predicate policy P to the key generation module and the encryption module; the key generation module receives the master private key msk and the predicate policy P. ∑ Then, based on the user authorization vector Generate user private key sk with predicate access control function f f , will the user's private key sk f Send to the decryption module; the encryption module in the predicate strategy P ∑ The following uses the common parameter pub to modify the predicate vector. Encrypt message m to obtain ciphertext c; finally, in Under the premise that the decryption module uses the user's private key sk f Decrypt the ciphertext c to obtain the relevant function value of message m.

[0022] Based on the constructed predicate function encryption model, a fine-grained predicate function encryption model with convertible access structure is constructed. This model includes a system setting module, a policy control module, a key generation module, an encryption module, and a decryption module.

[0023] System settings module: Enter security parameter 1 λ On a composite-order bilinear generator, we obtain (p1, p2, p3, G, G). T (e,g,G4), where p1p2p3 are distinct large prime numbers, and G and G4 are... T It is a cyclic group of order N (N = p1o2p3). G subgroups The generator, e, is a bilinear mapping e: G×G→G T g is a generator of G4; the system property set is A, A∈∑; randomly selected Output common parameters Master private key

[0024] Strategy control module: Input participant predicate vectors and Based on practical application requirements, the access structure vector is monotonically stretched into a predicate encoding. The access structure predicate vector of data owner V is: Define an access policy (M, π), where M ∈ ∑ is an m × n access control matrix, and M a Let M be the a-th row, and π be the row mapping function, where π:M a →π(a); will access the structure predicate vector Encode to obtain π(v) i Output predicate strategy P ∑ With π(v) i );

[0025] Key generation module: Input public parameter pub, master private key msk, computed function f, and attribute predicate vector of user W. Random selection calculate Output skx = (k, k i ,k i ′);

[0026] Encryption module: Input public parameter pub, message m, and predicate encoding π(v) i Random selection Calculate c0 = mY β ; Output ciphertext c = (c0, c1, c2) i ,c i Decryption module: Input ciphertext c, user function private key sk f If predicate strategy That is, it exists Then calculate Output the message-related function value f(m). When f is set as an identity function, the message m can be obtained. Attached Figure Description

[0027] Figure 1 A predicate function encryption model for fine-grained access control with permissions;

[0028] Figure 2 This is a fine-grained predicate function encryption model with convertible properties in its access structure. Detailed Implementation

[0029] Example 1:

[0030] like Figure 1 , Figure 2 As shown, the fine-grained predicate function encryption method with convertible access structure according to the present invention includes the following steps:

[0031] Step 1: Based on set theory, define the general access structure ∑. Specifically:

[0032] Integration Participant A user Power set of attribute set Power set of logical operation set 2 Θ Given a hierarchical permission set R, define the Cartesian product:

[0033]

[0034] This allows us to construct an access tree structure with hierarchical permissions:

[0035]

[0036] Will subset of Defined as a general access structure with hierarchical permissions.

[0037] Step 2: Based on the proposed general access structure, define the access structure vector. and attribute set vector Matching operation

[0038]

[0039] in For the set of authorized attributes, r ∑ ,r∈R. Based on this, a predicate strategy is proposed. Implement matching and discrimination between participant attribute sets and access permission structures.

[0040] Step 3: Based on predicate strategy Design a predicate access control function. in, For function space, For key space, For plaintext space:

[0041]

[0042] The above formula shows that if Then the participant has the right to operate on the function f being calculated.

[0043] Step 4: Construct the following based on the proposed predicate access control function: Figure 1 The illustrated fine-grained access control predicate function encryption model with permissions implements access control through predicate policies and predicate functions. This model consists of five modules: Setup, Spc, KeyGen, Enc, and Dec.

[0044]

[0045] First, the system settings module inputs security parameter 1. λ Then, a public parameter `pub` and a master private key `msk` are generated. The public parameter `pub` is sent to the encryption module, and the master private key `msk` is sent to the key generation module. Next, the policy control module determines the key based on the predicate vectors of the participants. and Generative predicate strategy P ∑ It then sends the master private key msk and the predicate policy P to the key generation module and the encryption module; the key generation module receives the master private key msk and the predicate policy P. ∑ Then, based on the user authorization vector Generate user private key sk with predicate access control function f f , will the user's private key sk f Send to the decryption module; the encryption module in the predicate strategy P ∑ The following uses the common parameter pub to modify the predicate vector. Encrypt message m to obtain ciphertext c; finally, in Under the premise that the decryption module uses the user's private key sk f Decrypt the ciphertext c to obtain the relevant function value of message m.

[0046] Step 5: Based on the constructed predicate function encryption model, construct a fine-grained predicate function encryption model with convertible access structures, such as... Figure 2 As shown.

[0047] The model consists of a system settings module, a policy control module, a key generation module, an encryption module, and a decryption module.

[0048] System settings module: Enter security parameter 1 λ On a composite-order bilinear generator, we obtain (p1, p2, p3, G, G). T (e,g,G4), where p1p2p3 are distinct large prime numbers, and G and G4 are... T It is a cyclic group of order N (N = p1p2p3). G subgroups The generator, e, is a bilinear mapping e: G×G→G Tg is a generator of G4; the system property set is A, A∈∑; randomly selected Output common parameters Master private key

[0049] Strategy control module: Input participant predicate vectors and Based on practical application requirements, the access structure vector is monotonically stretched into a predicate encoding. Here, the application scenario is set as a cloud data sharing application scenario, and the access structure predicate vector of data owner V is: Define an access policy (M, π), where M ∈ ∑ is an m × n access control matrix, and M a Let M be the a-th row, and π be the row mapping function, where π:M a →π(a); will access the structure predicate vector Encode to obtain π(v) i Output predicate strategy P ∑ With π(v) i );

[0050] Key generation module: Input public parameter pub, master private key msk, computed function f, and attribute predicate vector of user W. Random selection calculate Output sk f =(k,k i ,k i ′); Encryption module: Input public parameter pub, message m and predicate encoding π(v i Random selection Calculate c0 = mY β ; Output ciphertext c = (c0, c1, c2) i ,c i ′);

[0051] Decryption module: Input ciphertext c, user function private key sk f If predicate strategy That is, it exists Then calculate Output the message-related function value f(m). When f is set as an identity function, the message m can be obtained.

Claims

1. A fine-grained predicate function encryption method with convertible access structure, characterized in that... include: S1 provides a general access structure based on set theory. Definition; S2 defines the matching operation for accessing structure vectors and attribute set vectors; S3 Design predicate access control functions; S4 constructs a predicate function cryptographic model with permissioned fine-grained access control; S5 constructs a fine-grained predicate function encryption model with convertible access structures; S1 includes: Integration Participants Power set of attribute set The power set of logical operation sets and hierarchical permission sets Define the Cartesian product: This allows us to construct an access tree structure with hierarchical permissions: ; Will subset of Defined as a general access structure with hierarchical permissions; S2 includes: defining an access structure vector based on the proposed general access structure. and attribute set vector Matching operation : in For the set of authorized attributes, Based on this, a predicate strategy is proposed. S3 includes: based on predicate strategy Design predicate access control functions , , , ,in, For function space, For key space, For plaintext space: like Then the participants' evaluation of the computed function You have the necessary permissions.

2. The fine-grained predicate function encryption method with convertible properties on the access structure according to claim 1, characterized in that... S4 includes: constructing a permissioned, fine-grained access control predicate function encryption model based on the proposed predicate access control function, which includes a system settings module. Strategy control module Key generation module Encryption module Decryption module Five modules; the system settings module is for inputting security parameters. Common parameters are generated later. With the master private key , will common parameters Send the master private key to the encryption module. The key is sent to the key generation module; secondly, the policy control module processes the predicate vectors of the participants. and Generative predicate strategy The key is then sent to the key generation module and the encryption module; the key generation module receives the master private key. and predicate strategy Then, based on the user authorization vector With predicate access control functions Generate user private key , user private key Send to the decryption module; the encryption module in the predicate strategy Use common parameters below For predicate vectors and messages Encrypt to obtain ciphertext Finally, in Under the premise that the decryption module uses the user's private key For ciphertext Perform decryption to obtain the message. The relevant function values.

3. The fine-grained predicate function encryption method with convertible properties on the access structure according to claim 2, characterized in that... S5 builds upon the predicate function encryption model constructed by S4, and constructs a fine-grained predicate function encryption model with convertible access structures.

4. The fine-grained predicate function encryption method with convertible properties on the access structure according to claim 3, characterized in that... System setup module for the S5 fine-grained predicate function encryption model: Input security parameters On a composite-order bilinear generator, we obtain ,in, They are large prime numbers that are not equal to each other. and for Cyclic group of order 1 , They are respectively subgroup generator, For bilinear mapping , for The generator; the complete set of system properties is , Random selection , , , Output common parameters Master private key .

5. The fine-grained predicate function encryption method with convertible properties on the access structure according to claim 4, characterized in that... The policy control module of the fine-grained predicate function encryption model in S5: input participant predicate vectors and Based on actual application requirements, the access structure vectors are monotonically stretched into predicate encodings, and the data owner... The access structure predicate vector is Define access policies ,in, for Access control matrix, for The a-th row, For row mapping functions, ; will access the structure predicate vector Encode to obtain Output predicate strategy and .

6. The fine-grained predicate function encryption method with convertible properties on the access structure according to claim 5, characterized in that... Key generation module for the fine-grained predicate function encryption model in S5: Input common parameters Master private key The function being computed and users Attribute predicate vector Random selection , , , ;calculate ; , ; , Output .

7. The fine-grained predicate function encryption method with convertible properties on the access structure according to claim 5, characterized in that... The encryption module of the fine-grained predicate function encryption model in S5: input common parameters ,information and predicate encoding Random selection , ;calculate ; ; , ; , Output ciphertext .

8. The fine-grained predicate function encryption method with convertible properties on the access structure according to claim 7, characterized in that... The decryption module of the fine-grained predicate function encryption model in S5: Input ciphertext User function private key If predicate strategy That is, it exists Then calculate Output message related function values ,when When set as an identity function, a message can be obtained. .

Citation Information

Patent Citations

  • A Delegable Inner Product Function Encryption Method

    CN114785500B

  • A searchable public key encryption method supporting semantic query simultaneously

    CN114969795B

  • Encryption system based on attribute sets and relational predicates and access control method

    CN105635135A

  • Keyword security query method based on fine-grained authorization of attribute-based encryption

    CN111027084A