Data Security Sharing Method, Device and System Based on Block Encryption

By encrypting data in the data center in blocks, combining attribute-based encryption technology and zero-knowledge proof protocols, the problem of data sharing is difficult to manage security in complex environments, and high security and privacy protection of data sharing is achieved.

CN119210902BActive Publication Date: 2025-06-27CETC BIGDATA RES INST CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411707270.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-27
Publication Date
2025-06-27
Estimated Expiration
2044-11-27

AI Technical Summary

Technical Problem

The security of data sharing is difficult to effectively manage in complex multi-organization, multi-system and multi-platform environments, and faces continuous updates of security threats and technological advances, increasing the complexity of security and privacy protection.

Method used

The data security sharing method based on block encryption is adopted to encrypt the data in blocks through the data center, and the data block ciphertext is stored on the cloud server. At the same time, attribute-based encryption technology and zero-knowledge proof protocol are used to achieve fine-grained access control and legitimacy verification of data.

Benefits of technology

The confidentiality, integrity and availability of data sharing are realized, ensuring that only legal and satisfying specific attributes can decrypt and access shared data, improving the security and privacy protection capabilities of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119210902B_ABST
    Figure CN119210902B_ABST
Patent Text Reader

Abstract

The present invention provides a data security sharing method, apparatus and system based on block encryption. The method includes: the data center divides data information into blocks, encrypts each data block to obtain a ciphertext of the data block, uploads the ciphertext of the data block to the cloud server for storage, and locally stores the block information and directory information; after receiving the data requirement information published by the data user, determines the data to be shared that meets the requirements according to the locally stored block information and directory information; authenticates the data user, determines whether the private key of the data user is legal and whether the requested data is compliant; after the verification and determination are passed, sends a shared data request to the supervision center, so that the supervision center generates a data sharing token and signature using its own private key and sends them to the data user. Using the solution of the present invention, data can be shared safely and reliably.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a data security sharing method, device and system based on block encryption. Background Art

[0002] In today's era of informatization, networking and intelligence, data has become a key factor in promoting social progress and economic development. With the rapid development of technologies such as the Internet, Internet of Things, and 5G, the collection, storage, processing and analysis of data have become more convenient, which provides broad space and infinite possibilities for data sharing. However, the security issue of data sharing has also followed, becoming an important problem restricting the development of data sharing.

[0003] Data sharing security refers to the ability to ensure that data is not accessed, leaked, tampered with or damaged by unauthorized parties during the data sharing process. It involves the security protection of data in various links such as transmission, storage, processing and use. The core goal of data sharing security is to ensure the confidentiality, integrity and availability of data, that is, the CIA (Confidentiality, Integrity, Availability) model. At present, data sharing security still faces many challenges. First, the environment of data sharing is becoming more and more complex, involving multiple different organizations, systems and platforms, which brings difficulties to the management and control of data sharing security. Second, the technology of data sharing is constantly developing, and new security threats and vulnerabilities are constantly emerging, which requires the technology and methods of data sharing security to be continuously updated and improved. Finally, data sharing involves the interests and rights of multiple parties, and it is necessary to balance the requirements of security, efficiency, privacy, compliance, etc., which undoubtedly increases the complexity and difficulty of data sharing security. Summary of the Invention

[0004] The present invention provides a data security sharing method, device and system based on block encryption to ensure the security of data sharing.

[0005] For this reason, the present invention provides the following technical solutions:

[0006] The present invention provides a data security sharing method based on block encryption, and the method includes:

[0007] The data center divides the data information into blocks, encrypts each data block to obtain the data block ciphertext, uploads the data block ciphertext to the cloud server for storage, and locally saves the block information and directory information;

[0008] After receiving the data requirement information published by the data user, determine the data to be shared that meets the requirements according to the locally saved block information and directory information;

[0009] Authenticate the data user, and determine whether the private key of the data user is legal and whether the requested data is compliant;

[0010] After passing the verification and judgment, send a shared data request to the supervision center, so that the supervision center uses its own private key to generate a data sharing token and signature, and sends them to the data user.

[0011] Optionally, the encrypting each data block to obtain a data block ciphertext includes:

[0012] Generate a public key and private key pair using an attribute-based encryption algorithm, and set an access structure, where the access structure is used to determine the attribute combination that can decrypt the data;

[0013] Encrypt each data block using the public key and the access structure to obtain a data block ciphertext.

[0014] Optionally, the data requirement information includes: the identity information of the data user, the access structure verification proof, and the requested data information; the access structure verification proof is generated by the data user according to the private key, the public parameters and the zero-knowledge proof model published by the data center; the zero-knowledge proof model is generated according to the set access structure;

[0015] The determining whether the private key of the data user is legal includes:

[0016] Determine whether the access structure verification proof meets the access structure;

[0017] If so, determine that the private key of the data user is legal.

[0018] Optionally, the method further includes:

[0019] The data user receives the data sharing token and signature sent by the supervision center; the data sharing token includes the permissions and instructions for obtaining and using the data;

[0020] Send the data sharing token and signature to the cloud server, so that the cloud server sends the corresponding data block ciphertext to the data user according to the data sharing token and signature;

[0021] The data user decrypts each data block ciphertext and combines the decrypted data into complete data information.

[0022] Optionally, the cloud server has one or more servers, and there is a main server among the multiple servers. The multiple cloud servers form a distributed storage system; different data block ciphertexts are stored on the same or different cloud servers.

[0023] Optionally, the method further includes:

[0024] The primary server receives a data sharing token and a signature sent by the data user;

[0025] Verify the signature using the public key of the supervision center, and after successful verification, broadcast the data sharing token to other cloud servers, so that the other cloud servers send the ciphertexts of relevant data blocks they store to the data user according to the data sharing token.

[0026] Optionally, the data sharing token includes permissions and instructions for obtaining and using data.

[0027] The present invention also provides a data security sharing device based on block encryption, the device includes:

[0028] A data processing module, configured to divide data information into blocks, encrypt each data block to obtain a data block ciphertext, upload the data block ciphertext to a cloud server for storage, and locally save the block information and directory information;

[0029] A data checking module, configured to determine the data to be shared that meets the requirements according to the data requirement information published by the data user on the data platform;

[0030] An authentication module, configured to authenticate the data user, and determine whether the private key of the data user is legal and whether the requested data is compliant;

[0031] A data sharing module, configured to send a shared data request to the supervision center after the authentication module's verification and judgment pass, so that the supervision center generates a data sharing token and a signature using its own private key and sends them to the data user.

[0032] The present invention also provides a data security sharing system based on block encryption, the system includes: a cloud server, a data center, and a supervision center; the data center includes the data sharing device based on block encryption;

[0033] The data center is configured to divide and encrypt data information and upload it to the cloud server, authenticate the data user when there is data to be shared that meets the requirements of the data user, and determine whether the private key of the data user is legal and whether the requested data is compliant. After the verification and judgment pass, send a shared data request to the supervision center;

[0034] The cloud server is configured to store the ciphertexts of data blocks uploaded by the data center;

[0035] The regulatory center is used to receive the shared data request, generate a data sharing token and a signature using its own private key, and send them to the data user, so that the data user can request the required data from the cloud server according to the data sharing token and the signature.

[0036] Optionally, the system further includes: a data user, which is used to publish data requirement information to the data center when data is needed; receive the data sharing token and the signature sent by the regulatory center, send the data sharing token and the signature to the cloud server, and obtain shared data from the cloud server.

[0037] Optionally, the cloud server has one or more servers, and there is a main server among the multiple servers. The multiple cloud servers form a distributed storage system; the ciphertexts of different data blocks are stored on the same or different cloud servers;

[0038] The main server receives the data sharing token and the signature sent by the data user;

[0039] Verify the signature using the public key of the regulatory center, and broadcast the data sharing token to other cloud servers after the verification passes, so that the other cloud servers can send the ciphertexts of the relevant data blocks they store to the data user according to the data sharing token.

[0040] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the data security sharing method based on block encryption.

[0041] For the data security sharing method, device and system based on block encryption provided by the present invention, the data center can securely encrypt data information in blocks and store it on the cloud server. At the same time, through the attribute-based encryption technology, fine-grained access control of data can be realized, ensuring that only data users who hold the corresponding private key and meet the access structure can decrypt and access the shared data, guaranteeing the security of data sharing. Moreover, through the data sharing token and the signature, the legitimacy and traceability of data sharing can be ensured.

[0042] Furthermore, the data center can verify whether the attributes of the data user meet the access structure through the zero-knowledge proof protocol without revealing the private key of the data user, protecting the privacy of the data user. Description of the Drawings

[0043] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0044] Figure 1 It is a flowchart of a data security sharing method based on block encryption provided by an embodiment of the present invention;

[0045] Figure 2 It is a schematic structural diagram of a data security sharing device based on block encryption provided by an embodiment of the present invention;

[0046] Figure 3 It is a schematic structural diagram of a data security sharing system based on block encryption provided by an embodiment of the present invention. Specific Embodiments

[0047] The following will detail the specific embodiments of the present invention in conjunction with the accompanying drawings. It should be understood that the specific embodiments described herein are only for explaining and illustrating the present invention, and are not used to limit the present invention.

[0048] To enable those skilled in the art of this technology to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts should fall within the scope of protection of the present invention.

[0049] The core goal of data sharing security is to ensure the confidentiality, integrity, and availability of data. Among them, confidentiality refers to the ability of data not to be obtained and accessed by unauthorized third parties. During the process of data sharing, data may need to traverse multiple different network environments and come into contact with multiple different systems and users. Therefore, ensuring the confidentiality of data is the primary task of data sharing security. Integrity refers to the ability of data to maintain its authenticity, accuracy, and consistency during storage, transmission, and processing. Data may be subject to various malicious attacks or accidental damages during the sharing process. Therefore, ensuring the integrity of data is crucial for maintaining the value and credibility of data. Availability refers to the ability of data to be normally accessed and used by authorized users when needed. The purpose of data sharing is to enable those who need the data to obtain and utilize this data. Therefore, ensuring the availability of data is also an important part of data sharing security.

[0050] To achieve the security of data sharing, a series of security technologies and measures need to be taken. For example, through data encryption technology, the confidentiality of data can be protected. Even if the data is intercepted during transmission, it cannot be interpreted by unauthorized third parties. Through technologies such as digital signatures and hash functions, the integrity of data can be verified to ensure that the data has not been tampered with during transmission and storage. Through technologies such as backup, redundancy, and load balancing, the availability of data can be improved to ensure that the data can still be used normally in the face of hardware failures, network attacks, etc.

[0051] In addition to technical measures, the security of data sharing also needs to consider management factors. For example, reasonable data sharing policies need to be formulated to clarify which data can be shared, which data cannot be shared, and the conditions and scope of data sharing. It is necessary to strengthen the monitoring and auditing of the data sharing process to detect and respond to various security threats in a timely manner. At the same time, it is also necessary to improve users' security awareness and skills to prevent data leakage or damage caused by misoperations or malicious behaviors.

[0052] Therefore, in view of the security and privacy protection issues in data sharing, the present invention provides a data security sharing method, device, and system based on block encryption. By using attribute-based encryption technology (ABE), fine-grained access control of ciphertext is realized to ensure that only users meeting specific attributes can decrypt the data. By defining a flexible access structure, the access policy of the data can be described to effectively control the data sharing process. At the same time, by using the zero-knowledge proof protocol, it can be verified whether the user meets the access structure without revealing the user's private key information, thereby protecting the user's privacy.

[0053] As Figure 1 shown, it is a flowchart of a data security sharing method based on block encryption provided by an embodiment of the present invention, including the following steps:

[0054] Step 101, the data center divides the data information into blocks, encrypts each data block to obtain the ciphertext of the data block, uploads the ciphertext of the data block to the cloud server for storage, and locally saves the block information and directory information.

[0055] For example, for the data information , it is divided into data blocks , and these data blocks are independently encrypted to obtain ciphertexts of the data blocks. For the division of data blocks, the number of divided data blocks can be determined according to the size of the data information and so on. The sizes of the divided data blocks can be the same or different, and the embodiments of the present invention do not make any limitations in this regard.

[0056] To ensure the security of data sharing, the data center can define an access structure A, which is used to determine which combination of attributes can decrypt the data to be shared. Using this access structure, restrictions can be imposed on data users, ensuring that only data users with appropriate attributes can decrypt and access sensitive data, thus achieving fine-grained access control.

[0057] In addition, the data center can use an attribute-based encryption algorithm to generate a public key PublicKey and a private key pair. Among them, the public key is used to encrypt data blocks, and the private key is used to associate specific attributes and is used during subsequent decryption.

[0058] The data center uses the public key and the access structure A to encrypt each data block to form a ciphertext of the data block =Encrypt( , PublicKey, A), where Encrypt() represents the encryption function.

[0059] In some embodiments, there can be one cloud server, that is, the above ciphertexts of data blocks are stored on the same cloud server with different storage addresses.

[0060] In other embodiments, the cloud server can adopt a cluster mode, that is, it is composed of multiple two or more servers, and there is a primary server among them. The data center uploads the ciphertexts of data blocks to the primary server, and then the primary server disperses and stores the ciphertexts of data blocks to different cloud servers. For example, it can disperse and store the ciphertexts of data blocks to cloud servers, and specifically, the corresponding cloud servers can be selected according to the comprehensive performance such as the load capacity and resource occupancy of each cloud server.

[0061] In other embodiments, it can also be the data center that selects the cloud servers for storing the ciphertexts of each data block, and the embodiments of the present invention do not limit this.

[0062] To ensure that each ciphertext of the data block is stored correctly and without error, in some embodiments, the cloud server can also return a storage certificate to the data center after storing the corresponding ciphertext of the data block. The storage certificate can include the storage address of the ciphertext of the data block. Correspondingly, after receiving the storage certificate, the data center determines that the ciphertext of the data block has been stored correctly and without error.

[0063] In the embodiments of the present invention, the storage certificate can be used as a verification mechanism to prove that the data has been stored correctly and can be retrieved and decrypted correctly when needed.

[0064] By encrypting data information in chunks and storing it dispersedly, data security can be better ensured. The ciphertext of data chunks stored on the cloud server can only be accessed through authorization.

[0065] Step 102: After receiving the data requirement information published by the data user, determine the data to be shared that meets the requirement according to the locally saved chunk information and directory information.

[0066] When the data user needs to use data, it can publish data requirement information to the data center. The data requirement information may include the identity information of the data user, the access structure verification proof, and the requested data information. Among them:

[0067] The identity information may be, for example, but not limited to any one or more of the following information: ID, name, ID card number, etc.

[0068] The requested data information may include, for example, but not limited to one or more of the following information: abstract, keyword, file number, etc.

[0069] The access structure verification proof is generated by the data user inputting information such as public parameters and private keys into the zero-knowledge proof model. The public parameters and the zero-knowledge proof model can be published by the data center, and the zero-knowledge proof model can be generated based on the access structure. By using the access structure verification proof, the data center can verify whether the user's attribute private key meets the access structure without disclosing the user's private key.

[0070] Correspondingly, after receiving the data requirement information published by the data user, the data center can first determine whether there is data to be shared that meets the requirement according to the requested data information. Specifically, it can search the locally saved chunk information and directory information according to the requested data information to determine whether there is data to be shared that meets the requirement. If there is, continue to execute the subsequent step 103; if not, it can return corresponding prompt information to the data user.

[0071] Step 103: Authenticate the identity of the data user, and determine whether the private key of the data user is legal and whether the requested data is compliant.

[0072] The data center authenticates the identity of the data user to determine whether the data user is a legal user. Specifically, the data center can submit the corresponding identity information to the real-name authentication server, and the real-name authentication server calls the official database to verify the user's identity information and returns the identity authentication result to the data center. By authenticating the identity of the data user, it can be ensured that only legal users can access the data to be shared provided by the data center.

[0073] If the authentication fails, the data center can return corresponding information prompts to the data user to prompt that the authentication of the data user fails.

[0074] If the authentication passes, the data center further needs to determine whether the private key of the data user is legal and whether the requested data is compliant.

[0075] The judgment on the legality of the data user's private key can use the zero-knowledge proof protocol to determine whether the user's attribute private key satisfies the access structure. Specifically, the data center can use the public key of the data user, public parameters, zero-knowledge proof model and related algorithms to verify the legality of the access structure verification proof.

[0076] The judgment on whether the data requested by the data user is compliant can be made in accordance with corresponding regulations or specifications, etc., and the embodiments of the present invention do not make limitations on this.

[0077] It should be noted that the algorithm for generating the zero-knowledge proof model can be set arbitrarily, and the embodiments of the present invention do not make limitations on this.

[0078] Step 104, after the verification and judgment pass, send a shared data request to the supervision center, so that the supervision center uses its own private key to generate a data sharing token and signature, and send them to the data user.

[0079] The shared data request may include: data user ID, data center ID, data information to be shared Data information to be shared: data address, and may further include: data directory information, data format, data quality (including information such as data availability, integrity, standardization, consistency and timeliness, etc.).

[0080] Correspondingly, after receiving the shared data request, the supervision center uses its own private key to generate a data sharing token and signature. Send the data sharing token and signature to the data user.

[0081] The data sharing token may include but is not limited to the following information:

[0082] Permissions: Define the operations that the user holding the token can perform, such as reading, writing, or executing.

[0083] Validity information: Includes the validity period of the token, that is, when the token starts to take effect and when it expires.

[0084] Data address: Specifies the specific resource or resource collection to which the token grants access rights.

[0085] Authentication information: May contain the user's authentication data to ensure that only legitimate holders can use the token.

[0086] Accordingly, the data user sends the received data sharing token to the cloud server. If the cloud server is in a cluster form, the received data sharing token can be sent to the master server in the cluster.

[0087] Accordingly, the master server verifies the validity of the token signature through the public key of the supervision center. If it is valid, the data sharing token is broadcast to other cloud servers, instructing them to send the ciphertext of the data block corresponding to the data address to the data user. For example, each cloud server provides the data user with the download address of the ciphertext of the data block and opens the download permission, enabling the data user to download the corresponding ciphertext of the data block from different cloud servers.

[0088] After the data user downloads the ciphertexts of each data block, the private key PrivateKey related to the attribute is used to decrypt the ciphertexts of each data block to obtain the corresponding data block, that is:

[0089] =Decrypt( , PrivateKey, A),

[0090] where Decrypt() represents the decryption function.

[0091] Then, the data user combines the decrypted data blocks into complete data information, ensuring the integrity and consistency of the data.

[0092] In the above embodiment, the storage address of the data required by the data user (i.e., the data address mentioned above) is carried in the data sharing token sent by the supervision center and sent to the data user. After the data user uploads the data sharing token and its signature to the cloud server, the cloud server can determine the ciphertext of the data block that can be provided to the data user according to this storage address.

[0093] In some embodiments, the storage address of the data required by the data user can also be directly sent to the data user by the data center without being sent to the supervision center. Correspondingly, the corresponding data address is no longer carried in the data sharing token generated by the supervision center. After the data user receives the data sharing token and its signature, the data sharing token and its signature, as well as the storage address, are uploaded to the cloud server together. The cloud server can determine the ciphertext of the data block that can be provided to the data user according to this storage address.

[0094] It should be noted that in order to ensure the correspondence between the data sharing token sent by the supervision center and the data storage address when the data user requests multiple types of data, when the data center sends a shared data request to the supervision center, identification information corresponding to the data to be shared, such as a request serial number, etc., can be carried in the request, which can uniquely identify the corresponding data storage address. Correspondingly, when the data center sends the data address information to the data user, the identification information is carried; the identification information is also carried in the data sharing token sent by the monitoring center to the data user. Correspondingly, after the cloud server receives the data address information and the data sharing token sent by the data user, after verifying that the identification information in both is consistent, the corresponding data block ciphertext is sent to the data user. If the identification information in both is inconsistent, the data block ciphertext is refused to be sent to the data user.

[0095] In some embodiments, during the process of decrypting the data block ciphertext by the data user, a hash function can also be used to verify the original data block to ensure that the data has not been tampered with during transmission and storage. Of course, before the data center blocks the corresponding data information, a hash function is first used to calculate it, and then the hashed data information is block-encrypted.

[0096] It should be noted that in specific implementations, the data center and the supervision center can update the key pair regularly to further enhance the security of the data.

[0097] For the data security sharing method based on block encryption provided by the present invention, the data center can securely block-encrypt the data information and store it on the cloud server. At the same time, through the attribute-based encryption technology, fine-grained access control of the data can be realized, ensuring that only the data user who holds the corresponding private key and meets the access structure can decrypt and access the shared data, guaranteeing the security of data sharing. Moreover, through the data sharing token and signature, the legitimacy and traceability of data sharing can be ensured.

[0098] Correspondingly, an embodiment of the present invention also provides a data security sharing device based on block encryption, as Figure 2 shown, which is a schematic structural diagram of the device.

[0099] Referring to Figure 2 , an embodiment of the data sharing device based on block encryption may include the following modules:

[0100] A data processing module 201, configured to block the data information, encrypt each data block to obtain a data block ciphertext, upload the data block ciphertext to the cloud server for storage, and locally save the block information and directory information;

[0101] A data check module 202, configured to determine the to-be-shared data that meets the requirements according to the data requirement information published by the data user on the data platform;

[0102] An authentication module 203, configured to authenticate the identity of the data user, determine whether the private key of the data user is legal, and whether the requested data is compliant;

[0103] A data sharing module 204, configured to send a shared data request to the supervision center after the authentication module 203 passes the verification and judgment, so that the supervision center generates a data sharing token and signature using its own private key and sends them to the data user.

[0104] The specific implementation manners of the above modules may refer to the descriptions in the method embodiments of the present invention before, and will not be elaborated herein.

[0105] The data security sharing device 200 based on block encryption provided by the embodiments of the present invention may be used as a data provider or a data center to provide shared data to a data user. Other related descriptions about the data security sharing device 200 based on block encryption may refer to the relevant descriptions in the foregoing embodiments, and will not be elaborated herein.

[0106] Correspondingly, the embodiments of the present invention further provide a data security sharing system based on block encryption, as Figure 3 shown, which is a schematic structural diagram of the data security sharing system based on block encryption and the system.

[0107] The data security sharing system based on block encryption includes: a cloud server 30, a data center 31, a supervision center 32, and further may include a data user 40. The data center 31 includes Figure 2 the data security sharing device 200 shown. Wherein:

[0108] The data center 31 is configured to perform block encryption on data information and upload it to the cloud server, authenticate the data user when there is to-be-shared data that meets the requirements of the data user, determine whether the private key of the data user is legal and whether the requested data is compliant, and send a shared data request to the supervision center after passing the verification and judgment;

[0109] The cloud server 30 is configured to store the encrypted data blocks uploaded by the data center;

[0110] The supervision center 32 is configured to receive the shared data request, generate a data sharing token and signature using its own private key, and send them to the data user, so that the data user requests the required data from the cloud server according to the data sharing token and signature.

[0111] The data user 40 is used to publish data requirement information to the data center 31 when data is needed; receive the data sharing token and signature sent by the supervision center 32, send the data sharing token and signature to the cloud server 30, and obtain shared data from the cloud server 30.

[0112] In specific implementation, the cloud server 30 may include one or more servers, and there is a main server among the multiple servers 30. The multiple cloud servers 30 form a distributed storage system; different ciphertext data blocks are stored on the same or different cloud servers.

[0113] In the case of multiple cloud servers 30, the main server receives the data sharing token and signature sent by the data user 40; verifies the signature using the public key of the supervision center, and broadcasts the data sharing token to other cloud servers after the verification passes, so that the other cloud servers send the relevant ciphertext data blocks they store to the data user 40 according to the data sharing token.

[0114] The specific working modes of each part and the data sharing process in the above data security sharing system based on block encryption can refer to the description in the method embodiment of the present invention before, and will not be elaborated here.

[0115] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0116] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0117] In several embodiments provided by the present invention, it should be understood that the disclosed device can be implemented in other ways.

[0118] The present invention also provides a storage medium, which is a computer-readable storage medium, on which a computer program is stored. When the computer program runs, it can execute Figure 1Some or all of the steps of the method shown. The storage medium may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc. The storage medium may also include a non-volatile memory or a non-transitory memory, etc.

[0119] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data provider to another website, computer, server, or data provider in a wired or wireless manner.

[0120] The above has introduced the embodiments of the present invention in detail. Specific implementation manners are used herein to elaborate on the present invention. The description of the above embodiments is only used to help understand the method and system of the present invention. They are only some of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. The content of this specification should not be construed as a limitation of the present invention. Therefore, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A data security sharing method based on block encryption, characterized in that: The method comprises: The data center divides the data information into blocks, encrypts each data block to obtain a data block ciphertext, uploads the data block ciphertext to the cloud server for storage, and saves the block information and directory information locally; After receiving the data demand information published by the data user, determine the data to be shared that meets the demand based on the locally stored block information and directory information; Authentication of the data user and determination of whether the data user's private key is legitimate and whether the requested data is compliant; After verification and judgment, a data sharing request is sent to the supervision center, so that the supervision center uses its own private key to generate a data sharing token and signature, and sends it to the data user; The step of encrypting each data block to obtain the data block ciphertext comprises: Generate a public key and a private key pair using an attribute-based encryption algorithm and set an access structure for determining a combination of attributes that can decrypt data; Encrypting each data block using the public key and the access structure to obtain a data block ciphertext; The data demand information includes: the identity information of the data user, the access structure verification certificate, and the requested data information; the access structure verification certificate is generated by the data user according to the private key, the public parameters issued by the data center, and the zero-knowledge proof model; the zero-knowledge proof model is generated according to the set access structure; The determining whether the private key of the data user is legal includes: Determining whether the access structure verification certificate satisfies the access structure; If yes, it is determined that the private key of the data user is legitimate; The cloud server has multiple servers, among which there is a main server, and the multiple cloud servers form a distributed storage system; different data block ciphertexts are stored on the same or different cloud servers.

2. The data security sharing method based on block encryption according to claim 1 is characterized in that: The method further comprises: The data user receives the data sharing token and signature sent by the supervision center; the data sharing token includes the authority and instructions for obtaining and using data; Send the data sharing token and signature to the cloud server, so that the cloud server will send the corresponding data block ciphertext to the data user according to the data sharing token and signature; The data user decrypts the ciphertext of each data block and combines the decrypted data into complete data information.

3. The data security sharing method based on block encryption according to claim 2 is characterized in that: The method further comprises: The main server receives the data sharing token and signature sent by the data user; The signature is verified using the public key of the regulatory center, and after verification, the data sharing token is broadcast to other cloud servers, so that the other cloud servers send the ciphertext of the relevant data blocks stored in themselves to the data user according to the data sharing token.

4. The data security sharing method based on block encryption according to claim 3 is characterized in that: The data sharing token includes permissions and instructions for obtaining and using data.

5. A data security sharing system based on block encryption, characterized in that: The system includes: a cloud server, a data center, and a supervision center; the data center and a data security sharing device based on block encryption; The data center is used to encrypt the data information in blocks and upload it to the cloud server. When there is data to be shared that meets the needs of the data user, the data user is authenticated and the private key of the data user is determined to be legal and the requested data is compliant. After the verification and judgment are passed, a request for sharing data is sent to the supervision center; The cloud server is used to store the encrypted data blocks uploaded by the data center; The supervision center is used to receive the data sharing request, generate a data sharing token and a signature using its own private key, and send them to the data user, so that the data user requests the required data from the cloud server according to the data sharing token and the signature; The data security sharing device based on block encryption includes: The data processing module is used to divide the data information into blocks, encrypt each data block to obtain the data block ciphertext, upload the data block ciphertext to the cloud server for storage, and save the block information and directory information locally; The data inspection module is used to determine the data to be shared that meets the requirements based on the data demand information published by the data user on the data platform; A verification module, used to authenticate the identity of the data user and determine whether the private key of the data user is legal and whether the requested data is compliant; A data sharing module is used to send a data sharing request to the supervision center after the verification and judgment of the verification module are passed, so that the supervision center uses its own private key to generate a data sharing token and signature, and sends it to the data user; The step of encrypting each data block to obtain a ciphertext of the data block includes: Generate a public key and a private key pair using an attribute-based encryption algorithm and set an access structure for determining a combination of attributes that can decrypt data; Encrypting each data block using the public key and the access structure to obtain a data block ciphertext; The data demand information includes: the identity information of the data user, the access structure verification certificate, and the requested data information; the access structure verification certificate is generated by the data user according to the private key, the public parameters issued by the data center, and the zero-knowledge proof model; the zero-knowledge proof model is generated according to the set access structure; The determining whether the private key of the data user is legal includes: Determining whether the access structure verification certificate satisfies the access structure; If yes, it is determined that the private key of the data user is legitimate; The cloud server has multiple servers, among which there is a main server, and the multiple cloud servers form a distributed storage system; different data block ciphertexts are stored on the same or different cloud servers.

6. The data security sharing system based on block encryption according to claim 5 is characterized in that: The system further comprises: The data user is used to publish data demand information to the data center when data is needed; receive the data sharing token and signature sent by the supervision center, send the data sharing token and signature to the cloud server, and obtain shared data from the cloud server.

7. The data security sharing system based on block encryption according to claim 6 is characterized in that: The main server receives the data sharing token and signature sent by the data user; The signature is verified using the public key of the regulatory center, and after verification, the data sharing token is broadcast to other cloud servers, so that the other cloud servers send the ciphertext of the relevant data blocks stored in themselves to the data user according to the data sharing token.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the data security sharing method based on block encryption according to any one of claims 1 to 4 are executed.

Citation Information

Patent Citations

  • Distributed trusted organization identity access control system and method

    CN113641985A

  • Data processing method, data request end, data owning end and data processing device

    CN116155619A

  • Robust cloud storage access control method based on attribute encryption

    CN116707854A