A lattice-based hybrid revocable attribute encryption and decryption method and system
By adopting a grid-based hybrid revocable attribute encryption and decryption method in a quantum computing environment, combined with direct and indirect revocation mechanisms, the problem of insufficient security in the existing encryption technology in the quantum computing environment is solved, and flexible access control with high security is achieved.
Patent Information
- Application Number
- CN202411897292.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-12-23
AI Technical Summary
The security of existing encryption technologies cannot be effectively guaranteed in quantum computing environments, especially in scenarios where user revocation and attribute revocation have complexity and security threats.
A mixed revocable attribute encryption and decryption method based on grid is adopted to generate public parameters and master keys through the initialization algorithm, a binary tree structure is constructed, and a user private key is generated based on the user attribute set. This method combines direct revocation and indirect revocation mechanisms to achieve flexible access control by embedding revocation lists in the ciphertext and periodically updating the key.
This method provides a high-security access control solution in the quantum computing environment, which can effectively respond to the security challenges brought by quantum computing, achieve flexible user and attribute revocation, and improve system flexibility and adaptability.
Smart Images

Figure CN119358006B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cyberspace security, and particularly relates to a lattice-based hybrid revocable attribute encryption and decryption method and system. Background Art
[0002] In cloud storage applications, data encryption and access control are core technologies to ensure secure data sharing. With the wide application of cloud computing, more and more enterprises and individuals store sensitive data in the cloud. To ensure data security, traditional encryption technologies and access control mechanisms are difficult to meet the increasingly complex security requirements in many cases, especially in scenarios where user revocation and attribute revocation need to be flexibly handled. Although traditional attribute-based encryption (ABE) schemes provide flexible access control methods, they still face many challenges in practical applications. Attribute-based encryption (ABE), as a flexible encryption technology, has been widely used in cloud storage and data sharing. It allows data owners to set access permissions according to the specific attributes of users, and only users who meet specific attribute conditions can access the encrypted data. However, traditional ABE schemes have some intractable bottlenecks in dealing with user revocation and attribute revocation, especially in the combination of the two. The specific problems are as follows: (1) Complexity of user revocation and attribute revocation: Existing ABE schemes usually adopt two modes: direct revocation and indirect revocation. Direct revocation broadcasts updated keys to non-revoked users regularly by the key generation center (KGC); while indirect revocation realizes ciphertext delegation by embedding the identity of revoked users in the ciphertext. Although these two modes can achieve certain access control, they rely on different mathematical constructs and security assumptions, resulting in difficulties in technical implementation when combining these two revocation mechanisms in the same scheme. (2) Threat of quantum computing to existing encryption schemes: With the rapid development of quantum computing technology, traditional encryption schemes based on elliptic curves and bilinear pairings may face the risk of being cracked by quantum computers. Existing identity-based encryption (IBE) and attribute-based encryption (ABE) schemes usually rely on mathematical problems such as discrete logarithms and bilinear mappings that are vulnerable to quantum computing attacks, which makes their security in the quantum computing environment unable to be effectively guaranteed. Summary of the Invention
[0003] The present invention provides a lattice-based hybrid revocable attribute encryption and decryption method and system, which is used to solve the technical problem that the security of existing encryption methods cannot be effectively guaranteed in the quantum computing environment.
[0004] In the first aspect, the present invention provides a lattice-based hybrid revocable attribute encryption and decryption method, including:
[0005] Generating public parameters and a master key according to an initialization algorithm, and constructing a binary tree structure;
[0006] Allocate binary tree leaf nodes to a user based on the binary tree structure, and generate a user private key by combining the user attribute set and the master key, where the user private key contains a path node key component;
[0007] Construct a user revocation list according to an access policy, and embed a ciphertext in the user revocation list;
[0008] Verify that the attribute set satisfies the access policy and check whether the key is consistent with the ciphertext version. If they are consistent, use the updated key to complete decryption.
[0009] In a second aspect, the present invention provides a lattice-based hybrid revocable attribute encryption and decryption system, including:
[0010] A first generation module configured to generate public parameters and a master key according to an initialization algorithm, and construct a binary tree structure;
[0011] A second generation module configured to allocate binary tree leaf nodes to a user based on the binary tree structure, and generate a user private key by combining the user attribute set and the master key, where the user private key contains a path node key component;
[0012] An embedding module configured to construct a user revocation list according to an access policy, and embed a ciphertext in the user revocation list;
[0013] A decryption module configured to verify that the attribute set satisfies the access policy and check whether the key is consistent with the ciphertext version. If they are consistent, use the updated key to complete decryption.
[0014] In a third aspect, there is provided an electronic device, including: at least one processor, and a memory communicatively connected to the at least one processor, where the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the steps of the lattice-based hybrid revocable attribute encryption and decryption method according to any embodiment of the present invention.
[0015] In a fourth aspect, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program instructions are executed by a processor, the processor is enabled to execute the steps of the lattice-based hybrid revocable attribute encryption and decryption method according to any embodiment of the present invention.
[0016] The lattice-based hybrid revocable attribute encryption and decryption method and system of the present application have the following beneficial effects:
[0017] Adopt an encryption technology based on the learning with errors (LWE) problem. Since the learning with errors problem is still considered difficult in a quantum computing environment and has quantum resistance, it can effectively cope with the security challenges brought by quantum computing;
[0018] Combines two mechanisms of direct revocation and indirect revocation, providing a flexible revocation function. By embedding a revocation list in the ciphertext, it ensures that revoked users cannot access the ciphertext, thus achieving direct user revocation and instant access control. By periodically updating the key and combining the binary tree structure to update the revoked attributes, it ensures that the revoked attributes cannot decrypt the data anymore, while not affecting the access rights of other non-revoked users, achieving indirect attribute revocation;
[0019] Provides users with a flexible revocation mode selection. Users can freely choose the way of direct revocation or indirect revocation according to their needs, and manage the access rights of ciphertext at both the user level revocation and attribute level revocation, improving the flexibility and adaptability of the system. Brief Description of the Drawings
[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0021] Figure 1 It is a flowchart of a lattice-based hybrid revocable attribute encryption and decryption method provided by an embodiment of the present invention;
[0022] Figure 2 It is a structural block diagram of a lattice-based hybrid revocable attribute encryption and decryption system provided by an embodiment of the present invention;
[0023] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed Embodiments
[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0025] Please refer to Figure 1 , which shows a flowchart of a lattice-based hybrid revocable attribute encryption and decryption method of the present application.
[0026] As Figure 1 shown, the lattice-based hybrid revocable attribute encryption and decryption method specifically includes the following steps:
[0027] Step S101: Generate public parameters and a master key according to the initialization algorithm, and construct a binary tree structure.
[0028] In this step, input the security parameter , the attribute space , and the maximum number of users in the system , where is the first attribute, is the th attribute;
[0029] According to the lattice parameters , , and the original matrix , run to obtain the public matrix and the trapdoor matrix , where is the algorithm for generating the full-rank matrix and the trapdoor matrix , , is a real number;
[0030] Randomly select matrices , , and construct a full-rank difference mapping , where is an n×m matrix, is an n×m matrix composed of group elements of a group of order q, is an n×m matrix, is an n-dimensional vector composed of group elements of a group of order q;
[0031] Construct a binary tree with leaf nodes, and select an identifier for each node in the tree;
[0032] Initialize the attribute version ;
[0033] Initialize the version update polynomial , where is the incremental change of the attribute version number, represents the number of attribute updates, is an update factor randomly selected from a group of order q ;
[0034] Output the public parameters and the master key , where is the public matrix.
[0035] Step S102: Allocate a binary tree leaf node to the user, and generate a user private key by combining the user attribute set and the master key. The user private key contains path node key components.
[0036] In this step, input the public parameters , the master key , the user identity , and the user's attribute set , where , , , , is the attribute value, is the number of attributes, is the number of default attributes, is the attribute number space;
[0037] is the user identity Select an unoccupied leaf node from the binary tree , and assign the user identity to the leaf node . For each node on the user path, randomly select th-degree polynomials to construct the first vector . For , construct the second vector , where is the set of nodes on the path from the leaf to the root, is the first polynomial function, is the nth polynomial function, is the nth polynomial function when x = i, is the symbol of the column vector, is the function that maps to the group elements of the q-order group;
[0038] For each node , generate a key component according to a preset rule. The preset rule is specifically:
[0039] For the user attribute set , calculate the key component through a sampling algorithm, where is a vector whose statistical distribution is approximately a Gaussian distribution, is a Gaussian distribution vector, It is a sampling algorithm used to output a vector whose statistical distribution is approximately Gaussian. It is the i-th full-rank difference mapping;
[0040] System attribute set The key component is calculated through the sampling algorithm ;
[0041] For the user attribute set , let ;
[0042] System attribute set , let , where ;
[0043] The output user key is: , where is the private key that satisfies the user with id and attribute S, is a set.
[0044] Step S103: Construct a user revocation list according to the access policy and embed the ciphertext in the user revocation list.
[0045] In this step, the output user key is: , where is the private key that satisfies the user with id and attribute S, is a set.
[0046] Randomly select vectors and , , calculate the main ciphertext component as: , where is a group element in a distribution, is the noise distribution, is a vector, is the noise distribution vector, is the main ciphertext component, is the first vector, , is the order of the group, is one of the ciphertext components;
[0047] For , randomly generate a matrix , calculate the ciphertext component as: , where is the j-th attribute, , is an attribute, is the j-th full-rank difference mapping, is the j-th ciphertext component, For public parameters The j-th matrix in
[0048] For , randomly generate matrix , and calculate the ciphertext component as: , ;
[0049] For each revocation node , is a binary tree for revoking users, is the revocation list, randomly generate matrix , calculate , is the ciphertext component of the revocation node, is the identifier, is an algorithm for outputting the smallest node subset of the ancestors of the corresponding leaf nodes containing all non-revoked users;
[0050] Take the attribute version number in the ciphertext as part of the ciphertext;
[0051] Output the ciphertext .
[0052] Step S104, verify that the attribute set satisfies the access policy and check whether the key is consistent with the ciphertext version. If they are consistent, use the updated key to complete decryption.
[0053] In this step, the key update algorithm is specifically as follows:
[0054] Input the old version and the user key . The execution process includes:
[0055] Calculate the version number of key update: ;
[0056] Calculate the version difference: , is the modulo symbol, is the order of the group;
[0057] Update each key component: , is the updated i-th key component, is the i-th key component;
[0058] Update the key version to and output the updated key ;
[0059] The ciphertext update algorithm is specifically as follows:
[0060] Input the old version , the new version , the ciphertext . The execution process includes:
[0061] Calculate the version difference: ;
[0062] For the ciphertext component , update it to ;
[0063] Update the ciphertext version; .
[0064] Output the updated ciphertext .
[0065] Input the public parameters , the user key , the ciphertext . The set of attributes the user has is , the access policy of the ciphertext is , and it includes the attribute version number , where , is the attribute value. The decryption process is as follows:
[0066] Check whether the set of attributes the user has meets the access policy of the ciphertext :
[0067] If in the user revocation , return , indicating decryption failure;
[0068] Check the version consistency of the key and the ciphertext:
[0069] If , call the key update algorithm to update to version ;
[0070] If , call the ciphertext update algorithm to update to version ;
[0071] Construct the attribute subset for decryption:
[0072] Select an attribute subset that meets the policy from such that , .
[0073] Verify at the user's path node Whether there is a key component required for decryption corresponding to the subset of attributes for all attributes in
[0074] Calculate the intermediate result:
[0075] For each calculate the Lagrange interpolation coefficient:
[0076] where is the remainder modulo q, is the subset of attributes for all attributes other than the current attribute j, is the current attribute, is excluding the current attribute j;
[0077] For each attribute in extract the corresponding ciphertext component from the ciphertext and combine it with the user key share to calculate the partial decryption value ;
[0078] Combine the partial decryption results:
[0079] Aggregate the partial decryption values to calculate the decryption auxiliary value ;
[0080] Recover the plaintext:
[0081] Restore the message part in to the plaintext , where is modulo 2;
[0082] Verify is correct:
[0083] If the recovered meets the verification condition, return ; otherwise return indicating decryption failure.
[0084] In summary, the method of this application combines the direct user revocation and indirect attribute revocation mechanisms to implement a flexible, efficient, and quantum-resistant access control scheme. By embedding the user revocation list in the ciphertext, the access rights of specific users are revoked to achieve direct user revocation; by the key and ciphertext update algorithms, the decryption ability of specified attributes is revoked periodically to achieve indirect attribute revocation.
[0085] Figure 2 Please refer to which shows a structural block diagram of a lattice-based hybrid revocable attribute encryption and decryption system of this application.
[0086] As shown in Figure 2 Figure 4, the hybrid revocable attribute encryption and decryption system 200 includes a first generation module 210, a second generation module 220, an embedding module 230, and a decryption module 240.
[0087] Among them, the first generation module 210 is configured to generate public parameters and a master key according to an initialization algorithm and construct a binary tree structure; the second generation module 220 is configured to allocate binary tree leaf nodes to users based on the binary tree structure and generate a user private key by combining a user attribute set and the master key, where the user private key includes a path node key component; the embedding module 230 is configured to construct a user revocation list according to an access policy and embed ciphertext in the user revocation list; the decryption module 240 is configured to verify that the attribute set satisfies the access policy and check whether the key is consistent with the ciphertext version. If they are consistent, the decryption is completed using the updated key.
[0088] It should be understood that Figure 2 the modules described in Figure 1 correspond to the respective steps in the method described in the reference Figure 2 . Therefore, the operations, features, and corresponding technical effects described above for the method also apply to the modules in
[0089] and will not be elaborated here.
[0090] As an implementation, the computer-readable storage medium of the present invention stores computer-executable instructions, and the computer-executable instructions are set as follows:
[0091] Generate public parameters and a master key according to an initialization algorithm and construct a binary tree structure;
[0092] Allocate binary tree leaf nodes to users based on the binary tree structure and generate a user private key by combining a user attribute set and the master key, where the user private key includes a path node key component;
[0093] Construct a user revocation list according to an access policy and embed ciphertext in the user revocation list;
[0094] Verify that the attribute set satisfies the access policy and check whether the key is consistent with the ciphertext version. If they are consistent, the decryption is completed using the updated key.
[0095] A computer-readable storage medium may include a storage program area and a storage data area. Among them, the storage program area may store an operating system and application programs required for at least one function; the storage data area may store data created according to the use of the lattice-based hybrid revocable attribute encryption and decryption system, etc. In addition, the computer-readable storage medium may include high-speed random access memory, and may also include a memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some embodiments, the computer-readable storage medium may optionally include a memory remotely provided with respect to the processor, and these remote memories may be connected to the lattice-based hybrid revocable attribute encryption and decryption system through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0096] Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention, as Figure 3 shown, the device includes: a processor 310 and a memory 320. The electronic device may further include: an input device 330 and an output device 340. The processor 310, the memory 320, the input device 330, and the output device 340 may be connected through a bus or other means, Figure 3 taking connection through a bus as an example. The memory 320 is the above-mentioned computer-readable storage medium. The processor 310 executes various functional applications and data processing of the server by running non-volatile software programs, instructions, and modules stored in the memory 320, that is, implements the lattice-based hybrid revocable attribute encryption and decryption method in the above method embodiment. The input device 330 may receive input digital or character information, and generate key signal inputs related to user settings and function controls of the lattice-based hybrid revocable attribute encryption and decryption system. The output device 340 may include a display device such as a display screen.
[0097] The above electronic device may execute the method provided by the embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method. For technical details not described in detail in this embodiment, reference may be made to the method provided by the embodiment of the present invention.
[0098] As an implementation manner, the above electronic device is applied to a lattice-based hybrid revocable attribute encryption and decryption system and is used for a client, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can:
[0099] Generate public parameters and a master key according to an initialization algorithm, and construct a binary tree structure;
[0100] Allocate the binary tree leaf nodes to the user based on the binary tree structure, and generate the user private key by combining the user attribute set and the master key. The user private key contains the path node key component;
[0101] Construct a user revocation list according to the access policy, and embed the ciphertext in the user revocation list;
[0102] Verify that the attribute set satisfies the access policy and check whether the key is consistent with the ciphertext version. If they are consistent, use the updated key to complete decryption.
[0103] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solutions, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of each embodiment or some parts of the embodiments.
[0104] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.
Claims
1. A lattice-based hybrid revocable attribute encryption and decryption method, characterized in that: include: Generate public parameters and a master key according to an initialization algorithm, and construct a binary tree structure, wherein generating public parameters and a master key according to an initialization algorithm, and constructing a binary tree structure includes: Enter security parameters , attribute space , and the maximum number of users in the system ,in, is the first attribute, is the th attribute; According to the grid parameters , , and the original matrix ,run , and obtain the public matrix and the trapdoor matrix ,in, To generate a full rank matrix and the trapdoor matrix The algorithm, , is a real number; Random Selection Matrix , , and construct a full-rank difference mapping ,in, is a matrix with n rows and m columns, is a matrix of n rows and m columns consisting of the group elements of a group of order q, is a matrix with n rows and m columns, is an n-dimensional vector consisting of group elements of a group of order q; Build with A binary tree with leaf nodes , for each node in the tree Select Identifier ; Initialize property version ; Initialize version update polynomial ,in, is the incremental change of the attribute version number, represents the number of attribute updates, which is a group of order q The update factor randomly selected in ; Output common parameters and the master key ,in, is a public matrix; Based on the binary tree structure, a binary leaf node is allocated to the user, and a user private key is generated by combining the user attribute set and the master key, wherein the user private key includes a path node key component; Constructing a user revocation list according to the access policy, and embedding ciphertext in the user revocation list, wherein constructing the user revocation list according to the access policy, and embedding ciphertext in the user revocation list comprises: Enter common parameters , attribute collection ,parameter , Revocation List , and the plaintext ,in, is the attribute value, ; Randomly select vector and , , calculate the main ciphertext component as: ,in, is a group element in a distribution, is the noise distribution, is a vector, is the noise distribution vector, is the primary ciphertext component, is the first vector, , For the order of the group, is one of the ciphertext components; for , randomly generated matrix , the ciphertext component is calculated as: ,in, is the jth attribute, , For attributes, is the jth full-rank difference mapping, is the jth ciphertext component, For public parameters The j-th matrix in ; for , randomly generated matrix , the ciphertext component is calculated as: , ; For each revocation node , is a binary tree for revoking users, For the revocation list, randomly generate a matrix ,calculate , To revoke the ciphertext component of the node, is the identifier, An algorithm for outputting a minimum node subset that contains the ancestors of the corresponding leaf nodes of all unrevokated users; The attribute version number in the ciphertext As part of the ciphertext; Output ciphertext ; Verify that the attribute set satisfies the access policy and check whether the key and ciphertext versions are consistent. If they are consistent, use the updated key to complete the decryption.
2. A lattice-based hybrid revocable attribute encryption and decryption method according to claim 1, characterized in that: The allocating binary tree leaf nodes to the user based on the binary tree structure and generating the user private key in combination with the user attribute set and the master key comprises: Enter common parameters , Master Key ,User ID , and the user's attribute set ,in, , , , , is the attribute value, is the number of attributes, is the number of default attributes, is the number space of attributes; For user identity From a binary tree Select an unoccupied leaf node , and the user identity Assign to leaf nodes For each node on the user path , randomly selected Polynomial To construct the first vector ,for , construct the second vector ,in, For leaves The set of nodes on the path to the root, is the first polynomial function, is the nth polynomial function, is the nth polynomial function when x=i, is the symbol of the column vector, is a function that maps to group elements of a group of order q; For each node , generate key components according to preset rules, the preset rules are specifically: For user attribute sets , the key component is calculated by the sampling algorithm , among which, among which, for The statistical distribution of is approximately a Gaussian distributed vector, is a Gaussian distributed vector, is a sampling algorithm that outputs a vector whose statistical distribution is approximately Gaussian. is the i-th full-rank difference mapping; System property sets , the key component is calculated by the sampling algorithm ; For user attribute sets ,make ; System property sets ,make ,in, ; The output user key is: ,in, To satisfy the private key of user id and attribute S, For collection.
3. A lattice-based hybrid revocable attribute encryption and decryption method according to claim 1, characterized in that: The verification attribute set satisfies the access policy and checks whether the key and the ciphertext version are consistent. If they are consistent, the updated key is used to complete the decryption, including: Enter common parameters , User Key 、Ciphertext , the attribute set of the user is , the access policy of the ciphertext is , and includes the property version number ,in, , is the attribute value; Verify that the attribute set satisfies the access policy of the ciphertext , and check the revocation status; In case of inconsistency between the key version and the ciphertext version, call the key update algorithm or the ciphertext update algorithm for synchronization; Select a subset of attributes that satisfy the policy , calculate the Lagrange interpolation coefficients And combine the partial decrypted values ; According to the main ciphertext and Recover Plaintext .
4. A lattice-based hybrid revocable attribute encryption and decryption system, characterized in that: include: The first generation module is configured to generate public parameters and a master key according to an initialization algorithm, and construct a binary tree structure, wherein the generating public parameters and a master key according to the initialization algorithm, and constructing a binary tree structure includes: Enter security parameters , attribute space , and the maximum number of users in the system ,in, is the first attribute, is the th attribute; According to the grid parameters , , and the original matrix ,run , and obtain the public matrix and the trapdoor matrix ,in, To generate a full rank matrix and the trapdoor matrix The algorithm, , is a real number; Random Selection Matrix , , and construct a full-rank difference mapping ,in, is a matrix with n rows and m columns, is a matrix of n rows and m columns consisting of the group elements of a group of order q, is a matrix with n rows and m columns, is an n-dimensional vector consisting of group elements of a group of order q; Build with A binary tree with leaf nodes , for each node in the tree Select Identifier ; Initialize property version ; Initialize version update polynomial ,in, is the incremental change of the attribute version number, represents the number of attribute updates, which is a group of order q The update factor randomly selected in ; Output common parameters and the master key ,in, is a public matrix; A second generating module is configured to allocate binary tree leaf nodes to users based on the binary tree structure, and generate a user private key in combination with a user attribute set and the master key, wherein the user private key includes a path node key component; The embedding module is configured to construct a user revocation list according to the access policy and embed the ciphertext in the user revocation list, wherein the constructing the user revocation list according to the access policy and embedding the ciphertext in the user revocation list comprises: Enter common parameters , attribute collection ,parameter , Revocation List , and the plaintext ,in, is the attribute value, ; Randomly select vector and , , calculate the main ciphertext component as: ,in, is a group element in a distribution, is the noise distribution, is a vector, is the noise distribution vector, is the primary ciphertext component, is the first vector, , For the order of the group, is one of the ciphertext components; for , randomly generated matrix , the ciphertext component is calculated as: ,in, is the jth attribute, , For attributes, is the jth full-rank difference mapping, is the jth ciphertext component, For public parameters The j-th matrix in ; for , randomly generated matrix , the ciphertext component is calculated as: , ; For each revocation node , is a binary tree for revoking users, For the revocation list, randomly generate a matrix ,calculate , To revoke the ciphertext component of the node, is the identifier, An algorithm for outputting a minimum node subset that contains the ancestors of the corresponding leaf nodes of all unrevokated users; The attribute version number in the ciphertext As part of the ciphertext; Output ciphertext ; The decryption module is configured to verify that the attribute set satisfies the access policy and check whether the key is consistent with the ciphertext version. If they are consistent, the updated key is used to complete the decryption.
5. An electronic device, characterized in that: include: At least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described in any one of claims 1 to 3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.
Citation Information
Patent Citations
Internet of vehicles revocable data sharing method based on block chain and strategy hiding technology
CN117579269A