Archives management method and system based on cloud archives
Through the archive management methods and systems based on cloud archive library, the problem that traditional archive management methods cannot meet the needs of modern enterprises is solved, efficient, safe and convenient archive management is achieved, and management costs and risks are reduced.
Patent Information
- Application Number
- CN202410317245.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-20
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-03-20
AI Technical Summary
Traditional archive management methods cannot meet the needs of modern enterprises for archive security, efficiency and management, especially when cloud computing technology has not yet been popularized.
The archive management method and system based on the cloud archive library are adopted to generate archive ciphertexts by obtaining system public parameters, generating intermediate ciphertexts, combining access policies and revoking lists, and sending them to an external cloud server.
It realizes efficient, secure and convenient file management, improves the security of files and the flexibility of access control, and reduces management costs and risks.
Smart Images

Figure CN118410503B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of archive management, and in particular to an archive management method and system based on a cloud archive library. Background Art
[0002] With the rapid development of the information age, the management and protection of archive data has become an important issue. Due to its limitations, traditional archive management methods can no longer meet the needs of modern enterprises for archive security, efficiency and management. Therefore, cloud-based archive management methods and systems have emerged, which use the advantages of cloud computing to provide enterprises with an efficient, secure and convenient archive management solution.
[0003] The information disclosed in this background technology section is only intended to deepen the understanding of the overall background technology of the present invention, and should not be regarded as acknowledging or suggesting in any form that the information constitutes the prior art already known to those skilled in the art. Summary of the invention
[0004] In view of the problems existing in the prior art, the present invention provides an archive management method and system based on a cloud archive library.
[0005] The technical solution of the present invention provides a cloud archive management method, which is aimed at the archive management side and includes:
[0006] Get system common parameters;
[0007] Generate an intermediate ciphertext based on the system public parameters and the extracted first set of random numbers;
[0008] Based on the determined access policy and revocation list, combined with the intermediate ciphertext, generate the archive ciphertext;
[0009] The archive ciphertext is sent to an external cloud server.
[0010] The technical solution of the present invention also provides a cloud archive management method, which is aimed at the archive access side and includes:
[0011] Sending archive requests to external cloud servers;
[0012] Obtaining the ciphertext of the file sent by the external cloud server;
[0013] Sending the archive ciphertext, the conversion key and the extracted first random number to an external proxy server, wherein the conversion key is generated based on the user key and the system public parameter;
[0014] In response to the conversion ciphertext sent by the external proxy server, the conversion ciphertext is decrypted based on the first random number.
[0015] Optionally, the method further comprises:
[0016] In response to a termination character sent by the external proxy server, terminating the acquisition of the archive.
[0017] The technical solution of the present invention also provides a cloud archive management method, which is aimed at the system management side and includes:
[0018] Initialize the system, generate system public parameters, and secretly store the master key;
[0019] Based on the master key and the attribute set of the user, forming an attribute vector through a vector conversion algorithm;
[0020] A user key is generated based on the system public parameters and the attribute vector.
[0021] Optionally, the system common parameters include at least one of the following:
[0022] Two cyclic groups of prime order, order, generators, bilinear maps, hash functions, common parameter components.
[0023] Optionally, the public parameter component includes a set of powers, bases of the set of powers are all the generators, and exponents of the set of powers are a second set of random numbers drawn based on a maximum user upper limit value.
[0024] The technical solution of the present invention also provides a cloud archive management method, which is aimed at the cloud service side and includes:
[0025] Get the latest revocation list;
[0026] The stored archive ciphertext is updated based on the latest revocation list.
[0027] The technical solution of the present invention also provides a cloud archive management system, the system comprising:
[0028] Acquisition module, used to obtain system common parameters;
[0029] A first generating module, used for generating an intermediate ciphertext based on the system public parameters and a first group of extracted random numbers;
[0030] A second generating module, configured to generate archive ciphertext based on the determined access policy and revocation requirement and in combination with the intermediate ciphertext;
[0031] The sending module is used to send the archive ciphertext to an external cloud server.
[0032] The technical solution of the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the archive management method based on the cloud archive as described in any one of the above items are implemented.
[0033] The technical solution of the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the archive management method based on the cloud archive as described in any of the above items are implemented.
[0034] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0036] Figure 1 A schematic diagram of the process steps of a cloud archive management method provided by the technical solution of the present invention;
[0037] Figure 2 A system structure diagram provided for this embodiment;
[0038] Figure 3 Another schematic diagram of a process provided for this embodiment;
[0039] Figure 4 A schematic diagram of the structure of a cloud archive management system is also provided for the technical solution of the present invention;
[0040] Figure 5 A schematic diagram of the physical structure of an electronic device provided by the present invention. DETAILED DESCRIPTION
[0041] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0042] The following is a detailed description of the cloud archive management method provided by the embodiment of the present application through specific embodiments and their application scenarios in conjunction with the accompanying drawings.
[0043] Figure 1 A schematic diagram of the process steps of a cloud archive management method provided by the technical solution of the present invention is as follows: Figure 1 As shown, the technical solution of the present invention provides a cloud archive management method, which is aimed at the archive management side and includes the following steps:
[0044] S110, obtaining system common parameters;
[0045] S120, generating an intermediate ciphertext based on the system public parameters and the extracted first set of random numbers;
[0046] S130, generating archive ciphertext based on the determined access policy and revocation list and in combination with the intermediate ciphertext;
[0047] S140, sending the encrypted file to an external cloud server.
[0048] The technical solution of the present invention also provides a cloud archive management method, which is aimed at the archive access side and includes:
[0049] Sending archive requests to external cloud servers;
[0050] Get the ciphertext of the archive sent by the external cloud server;
[0051] Sending the archive ciphertext, the conversion key and the extracted first random number to an external proxy server, wherein the conversion key is generated based on the user key and the system public parameter;
[0052] In response to the conversion ciphertext sent by the external proxy server, the conversion ciphertext is decrypted based on the first random number.
[0053] Optionally, the method further comprises:
[0054] In response to a termination character sent by an external proxy server, retrieval of the archive is terminated.
[0055] The technical solution of the present invention also provides a cloud archive management method, which is aimed at the system management side and includes:
[0056] Initialize the system, generate system public parameters, and secretly store the master key;
[0057] Based on the master key and the user's attribute set, an attribute vector is formed through a vector conversion algorithm;
[0058] Generate user keys based on system public parameters and attribute vectors.
[0059] Optionally, the vector conversion algorithm can refer to the literature: Sun J, Xiong H, Liu X, et al. Lightweight and privacy-aware fine-grained access control for IoT-oriented smart health [J]. IEEE Internet of Things Journal, 2020, 7 (7): 6566-6575.
[0060] Optionally, the system common parameters include at least one of the following:
[0061] Two cyclic groups of prime order, order, generators, bilinear maps, hash functions, common parameter components.
[0062] Optionally, the public parameter component includes a group of powers, bases of the group of powers are all generators, and exponents of the group of powers are a second group of random numbers drawn based on a maximum user upper limit value.
[0063] The technical solution of the present invention also provides a cloud archive management method based on the cloud archive library. The method is aimed at the cloud service side and includes:
[0064] Get the latest revocation list;
[0065] Update the stored archive ciphertext based on the latest revocation list.
[0066] Furthermore, in one embodiment, Figure 2 A system structure diagram provided for this embodiment, Figure 3 Another flow chart provided for this embodiment is as follows: Figure 2 and 3 As shown, this embodiment provides a cloud-based archive management method and system for providing efficient and secure archive management and access control for a cloud-based archive system.
[0067] This embodiment involves five entities: system administrator, archive administrator, cloud server, proxy server, and archive visitor. The topological structure and interaction between them are as follows: Figure 2 shown.
[0068] The logical flow of this embodiment can be summarized as follows: first, the system administrator initializes the archive system and creates the public parameters and system master key required by the cloud-based archive management system; on this basis, the system administrator generates a user key for each archive visitor; the archive administrator analyzes and organizes the archives, asynchronously encrypts the archives, and uploads the ciphertext to the cloud server; the archive visitor first locates the archive to be accessed and applies to the cloud server, and after obtaining the ciphertext, generates a conversion key and sends it together with the ciphertext to the proxy server; the proxy server uses the conversion key to pre-decrypt the ciphertext, obtains the converted ciphertext and returns it to the archive visitor, but the ciphertext does not disclose any information related to the archive; on this basis, the archive visitor decrypts and accesses the archive; finally, the cloud server updates the encrypted archive to meet subsequent access requirements.
[0069] It should be noted that the system administrator and the file administrator in this embodiment can be either specific persons or implemented through automated programs.
[0070] The specific steps of this embodiment are as follows:
[0071] Step 1: Initialize the file system
[0072] The system administrator performs the following operations to initialize the system.
[0073] Step 1.1: Input security parameter λ, which represents the preset length of the key in the system. The longer the key length, the higher the security, but the lower the algorithm execution efficiency.
[0074] Step 1.2: Randomly select two prime p-order cyclic groups and g is group A generator of . Construct a bilinear map e:
[0075] Step 1.3: Define a hash function H: It means that the hash function H can map a bit string of arbitrary length to the group An element in .
[0076] Step 1.4: Draw random numbers τ1,…,τ n ,α, And calculate the common parameter components (Exponentiation), U = e(g, g) α , where i∈[1,n].
[0077] Step 1.5: Set R to the maximum user upper limit and construct a random vector ( Represents a random vector There are R ), and on this basis calculate the common parameter components
[0078] Step 1.6: Output system common parameters At the same time, the system master key MSK=(τ1,…,τ n , α).
[0079] Step 2: Key generation and distribution
[0080] The system administrator performs the following operations to generate and assign a key to a user ID.
[0081] Step 2.1: Use the system master key MSK and the user's attribute set Convert the attribute set S into an attribute vector by calling the vector conversion algorithm
[0082] Step 2.2: Randomly pick a random number And calculate As the key component. In addition, calculate another part of the user key component Where the subscript j = 2, ..., R. Finally, the user key is output
[0083] Step 3: File Security Management
[0084] The archive administrator performs this step to securely store and publish archive content.
[0085] Step 3.1: The purpose of this sub-step is to calculate and generate the intermediate ciphertext to prepare for the subsequent real-time security archive service. Input the system public parameters params, and then extract a set of random numbers t, θ, And calculate the intermediate ciphertext component c0=g t , Output intermediate ciphertext ICT = (c0, {c i} i∈[1,n] ,t,θ,η1,…,η n ).
[0086] Step 3.2: The purpose of this sub-step is to quickly generate ciphertext to provide archive services based on the intermediate ciphertext once the access policy and revocation requirements are determined. Input the intermediate ciphertext ICT, system public parameters params, access policy W, revocation list RL = (ID1, ..., ID μ ), where μ represents the number of revoked users, which must satisfy μ<R. The access policy W is converted into an access vector by calling the vector conversion algorithm. According to the revocation list RL = (ID1, ..., ID μ ) Using Lagrange interpolation theorem to construct polynomial F RL (x) = (x-ID1)…(x-ID μ )=x1+x2x+…+x μ x μ-1 Finally, the generated archive ciphertext CT = (c, c′, c″, c0, {c i , γ i} i∈[1,n] ) and upload it to the cloud server.
[0087] Step 4: Authorize access to the archive
[0088] Archive visitors request access to archives from the cloud server and complete decryption with the support of the proxy server.
[0089] Step 4.1: The archive visitor enters his / her user key SK and system public parameters params, and then draws a random number And calculate Finally, output and send the conversion key Give the proxy server and the local key DK=z.
[0090] Step 4.2: The archive visitor sends the ciphertext CT to the proxy server, and then creates two vectors X = (x1, ..., x R ), Y=(1, ID,…, ID R-1 ). The inner product between them can be expressed as<X,Y> =F RL , (ID) = x1 + x2ID + ... + x μ ID μ-1 +x μ+1 ID μ If the attribute set S of the archive visitor does not satisfy the access policy W corresponding to the archive, or ID∈RL, the algorithm directly outputs the terminator ⊥. Otherwise, the proxy server generates the conversion ciphertext according to the following formula:
[0091]
[0092] And return the converted ciphertext TC to the archive visitor.
[0093] Step 4.3: After receiving the converted ciphertext TC, the archive visitor uses his local key DK to perform the following calculation to achieve secure access to the archive: Msg = c·(TC) 1 / z .
[0094] Step 5: File update and maintenance
[0095] The cloud server updates the stored archive ciphertext according to the latest revocation list to achieve archive maintenance. When the revocation list is updated from RL to RL′=(ID′1,…,ID′ μ ). The cloud server calculates the updated ciphertext component c″ as follows: Reconstruct the polynomial F RL′ (x) = (x-ID′1)…(x-ID′ μ )=x1+x2x+…+x μ x μ-1 To obtain the polynomial coefficients x1,…,x μ , and then calculate the updated ciphertext component
[0096] This embodiment designs an access control method for archive security management, implements fine-grained flexible access control supporting wildcards and an efficient, privacy-preserving access control mechanism based on inner products, and constructs a specific archive security management method; by designing an efficient user revocation mechanism, flexible management of archive access rights is achieved; through sophisticated algorithm design, the huge computing and storage overhead in the archive encryption, archive access and other stages is avoided, and there are obvious advantages in practicality.
[0097] Attribute-based access control is an advanced access control mechanism that determines whether to grant a subject access to an object based on the attributes of the subject, object, and environment. ABAC (Attribute-Based Access Control) is an advanced access control mechanism that can control access rights more flexibly, making access control more accurate and reliable. In archive management, ABAC can set different access rights based on factors such as the type, importance, and confidentiality of the archive, thereby achieving secure management of the archive.
[0098] The cloud-based archive management method and system applies ABAC to archive management, and realizes efficient storage, secure transmission and fast query of archives through the powerful computing and storage capabilities provided by cloud service providers. The system also uses a variety of encryption algorithms and security mechanisms to ensure the security and privacy of archive data. At the same time, the system also has good scalability and cross-platform compatibility, which can meet the needs of different users and enterprise applications of different sizes.
[0099] In summary, the cloud-based archive management method and system combines the advantages of cloud computing and ABAC, providing modern enterprises with an efficient, secure and convenient archive management solution. It can not only improve the efficiency and security of archive management, but also reduce the management costs and risks of enterprises. Therefore, the cloud-based archive management method and system has important application value and broad market prospects.
[0100] The following describes the archive management system of the cloud archive library provided by the present invention, and the archive management system of the cloud archive library described below and the archive management method of the cloud archive library described above can be referred to each other. It should be noted that the device described here includes a virtual device on a program running device such as a computer or a processor.
[0101] Figure 4 A schematic diagram of the structure of a cloud archive management system is also provided for the technical solution of the present invention, as shown in FIG. Figure 4 As shown, the technical solution of the present invention also provides an archive management system based on a cloud archive library, the system comprising:
[0102] Acquisition module, used to obtain system common parameters;
[0103] A first generation module, used for generating an intermediate ciphertext based on a system public parameter and a first group of extracted random numbers;
[0104] The second generation module is used to generate archive ciphertext based on the determined access policy and revocation requirements and in combination with the intermediate ciphertext;
[0105] The sending module is used to send the archive ciphertext to an external cloud server.
[0106] This embodiment provides a management method based on a cloud archive.
[0107] Figure 5 A schematic diagram of the physical structure of an electronic device provided by the present invention, such as Figure 5 As shown, the electronic device may include: a processor 810, a communication interface 820, a memory 830 and a communication bus 840, wherein the processor 810, the communication interface 820 and the memory 830 communicate with each other through the communication bus 840. The processor 810 may call the logic instructions in the memory 830 to execute the archive management method based on the cloud archive library, and the method is for the archive management side, and the method includes:
[0108] Get system common parameters;
[0109] Generate an intermediate ciphertext based on the system public parameters and the extracted first set of random numbers;
[0110] Based on the determined access policy and revocation list, combined with the intermediate ciphertext, generate the archive ciphertext;
[0111] The archive ciphertext is sent to an external cloud server.
[0112] In addition, the logic instructions in the above-mentioned memory 830 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0113] On the other hand, the present invention further provides a computer program product, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, when the program instructions are executed by a computer, the computer can execute the cloud archive management method provided by the above methods, the method is for the archive management side, the method comprises:
[0114] Get system common parameters;
[0115] Generate an intermediate ciphertext based on the system public parameters and the extracted first set of random numbers;
[0116] Based on the determined access policy and revocation list, combined with the intermediate ciphertext, generate the archive ciphertext;
[0117] The archive ciphertext is sent to an external cloud server.
[0118] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, which is implemented when the computer program is executed by a processor to perform the above-mentioned archive management method based on a cloud archive library, the method being directed to the archive management side, and comprising:
[0119] Get system common parameters;
[0120] Generate an intermediate ciphertext based on the system public parameters and the extracted first set of random numbers;
[0121] Based on the determined access policy and revocation list, combined with the intermediate ciphertext, generate the archive ciphertext;
[0122] The archive ciphertext is sent to an external cloud server.
[0123] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0124] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0125] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A file management method based on a cloud archive library, characterized in that: The following steps are involved: System management side operations: perform system initialization, generate system public parameters and secretly save the master key, where the system public parameters include at least one of two prime order cyclic groups, order, generator, bilinear map, hash function, and public parameter components, where the public parameter components include a group of powers, the bases of a group of powers are all generators, and the exponents of a group of powers are a second group of random numbers extracted based on the maximum user upper limit value; based on the master key and the user's attribute set, an attribute vector is formed through a vector conversion algorithm; based on the system public parameters and the attribute vector, a user key is generated; Archive management side operation: Obtain system public parameters; Input system public parameters params, extract a set of random numbers t, θ, η1,... Calculate the intermediate ciphertext component c0 = g t , Output the intermediate ciphertext ICT = (c0, {c i} i∈[1,n] , t, θ, η1,... η n ); Input the intermediate ciphertext ICT, system public parameters params, access policy W, revocation list RL = (ID1,..., ID μ ), where μ represents the number of revoked users and μ < r, convert the access policy W into an access vector by calling the vector conversion algorithm According to the revocation list RL = (ID1,..., ID μ ) use the Lagrange interpolation theorem method to construct a polynomial F RL (x) = (x - ID1)...(x - ID μ ) = x1 + x2x +... + x μ x μ-1 , and finally generate the archive ciphertext CT = (c, c', c”, c0, {c i , γ i} i∈[1,n] ); Send the archive ciphertext to an external cloud server; Operations on the archive access side: send an archive request to an external cloud server; obtain the archive ciphertext sent by the external cloud server; send the archive ciphertext, the conversion key generated based on the user key and the system public parameters, and the extracted first random number to the external proxy server; the archive visitor sends the ciphertext CT to the proxy server, and then establishes two vectors X=(x1,...,x R ), Y=(1, ID, ..., ID R-1 ), if the attribute set S of the file visitor does not satisfy the access policy W corresponding to the file, or ID∈RL, the algorithm directly outputs the terminator ⊥, otherwise the proxy server generates the conversion ciphertext according to the following formula: The converted ciphertext TC is returned to the archive visitor; after receiving the converted ciphertext TC, the archive visitor uses its own local key DK to calculate Msg = c·(TC) 1 / z To achieve secure access to archives; Operation on the cloud service side: Get the latest revocation list; Update the stored archive ciphertext based on the latest revocation list.
2. The archive management method based on cloud archive library according to claim 1, characterized in that: The operation on the archive access side also includes: terminating the acquisition of the archive in response to a termination character sent by an external proxy server.
3. The archive management method based on cloud archive library according to claim 1, characterized in that: In the operation on the archive access side, before the archive ciphertext, conversion key and the first random number extracted are sent to the external proxy server, the archive visitor enters his own user key SK and system public parameters params, extracts the random number And calculate Finally output and send the conversion key Give the proxy server and the local key DK=z.
4. The archive management method based on cloud archive library according to claim 1, characterized in that: In the cloud service side operation, the step of updating the stored archive ciphertext based on the latest revocation list includes: when the revocation list is updated from RL to RL'=(ID'1, ..., ID' μ ), the cloud server reconstructs the polynomial F RL' (x) = (x-ID'1)...(x-ID' μ )=x1+x2x+...+x μ x μ-1 To obtain the polynomial coefficients x1,...,x μ , and then calculate the updated ciphertext component 5. The archive management method based on cloud archive library according to claim 1, characterized in that: In the system management side operation, the system initialization step includes: inputting the security parameter λ, which represents the preset length of the key in the system, wherein the longer the key length, the higher the security, but the lower the algorithm execution efficiency; randomly selecting two prime number p-order cyclic groups and g is group A generator of , and construct a bilinear map e: Define a hash function H: Used to map a bit string of arbitrary length to a group an element in ; extract a random number τ1,...,τx,α, And calculate the common parameter components U=e(g,g) α , where i∈[1,n]; set R as the maximum user upper limit and construct a random vector in Represents a random vector There are R The elements in , and on this basis calculate the common parameter components Output system common parameters At the same time, the system master key MSK=(τ1, ..., τ n , α).
6. A cloud archive library-based archive management system, using the cloud archive library-based archive management method as claimed in claim 1, characterized in that: include: The acquisition module is used to obtain the system common parameters generated when the system is initialized; A first generation module, used for generating an intermediate ciphertext based on a system public parameter and a set of extracted random numbers; A second generation module is used to generate archive ciphertext based on the determined access policy and revocation list in combination with the intermediate ciphertext; The sending module is used to send the archive ciphertext to an external cloud server.
Citation Information
Patent Citations
Attribute encryption-based power grid data mandatory access control method and system
CN117675265A