A flexible data sharing method and system based on public key and attribute-based encryption

By generating the conversion key RK, the normal public key encrypted ciphertext is converted into attribute-based encrypted ciphertext, which solves the security and efficiency of data sharing between the public key encryption system users and the attribute-based encryption system users, and realizes secure sharing and private key protection.

CN119483920BActive Publication Date: 2025-06-06CHANGSHA UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411107084.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-13
Publication Date
2025-06-06
Estimated Expiration
2044-08-13

AI Technical Summary

Technical Problem

The prior art is difficult to achieve secure data sharing between users of public key encryption system and users of attribute-based encryption system. Usually, it is necessary to share the private key or decrypt it first and then encrypt it, resulting in security and efficiency problems.

Method used

By generating the conversion key RK, the normal public key encrypted ciphertext is converted into attribute-based encrypted ciphertext, and data sharing between the public key encryption system users and attribute-based encryption system users is realized without decrypting the data.

Benefits of technology

It realizes secure sharing between users of public key encryption system and users of attribute-based encryption system, protects user private keys, realizes fine-grained data security sharing, and is suitable for "posterior" data sharing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119483920B_ABST
    Figure CN119483920B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for flexible data sharing based on public key and attribute-based encryption, belonging to the field of data encryption technology. In the solution of the present invention, a trusted third party generates system public parameters PP and a master private key MSK; an ordinary public key encryption user generates an ordinary public key PK and an ordinary private key SK; the trusted third party generates a user attribute-based private key SK based on the user attribute set S ABE ; the ordinary public key encryption user encrypts the data plaintext M to obtain an ordinary public key encrypted ciphertext CT; the ordinary public key encryption user generates a conversion key RK, and at the same time sets an access control policy to limit the usage right of the conversion key RK; the cloud service provider uses the conversion key RK to convert the ordinary public key encrypted ciphertext CT into an attribute-based encrypted ciphertext CT'; the attribute-based encryption user uses the user attribute-based private key SK ABE to decrypt the attribute-based encrypted ciphertext CT' and output the data plaintext M. The present invention can directly convert the ordinary public key encrypted ciphertext specified by the user into an attribute-based encrypted ciphertext.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data encryption, and in particular relates to a method and system for flexible data sharing based on public key and attribute-based encryption. Background Art

[0002] In the information world, data needs to be encrypted to protect information security. Currently, the most widely used data encryption method on the Internet is public key encryption. In a public key encryption system, users can use their own public keys to encrypt data so that the data can only be accessed by themselves to protect data security. At the same time, with the development of information security theory and technology, other encryption technologies have emerged in an endless stream. Among them, in the field of cloud computing, attribute-based encryption has become the most promising encryption technology suitable for cloud computing. Attribute-based encryption allows users to encrypt data without specifying the identity of the specific recipient when encrypting, but use attribute-based access control policies to encrypt data. As long as the recipient's attributes meet the access control policy, it can be decrypted.

[0003] Public key encryption and attribute-based encryption each have their own application scenarios and users. The two systems are independent of each other. There is still no solution for how to achieve secure data sharing between users of the public key encryption system and the attribute-based encryption system. For example, a user who uses a public key to encrypt personal photos wants to upload the photos to cloud storage and specify an access control policy to achieve secure data sharing. In this case, the existing methods either require users to share their private keys or let users decrypt the data first and then use attribute-based encryption. These methods will bring security and efficiency issues.

[0004] Therefore, it is necessary to provide a flexible data sharing method and system based on public key and attribute-based encryption to solve the above problems. Summary of the invention

[0005] The present invention provides a flexible data sharing method and system based on public key and attribute-based encryption, which can directly convert the ordinary public key encrypted ciphertext specified by the user into the attribute-based encrypted ciphertext, realize the secure sharing of data between the users of the ordinary public key encryption system and the users of the attribute set encryption system, and effectively solve the defects in the background technology.

[0006] In order to solve the above-mentioned technical problems, the present invention is achieved as follows:

[0007] A flexible data sharing method based on public key and attribute-based encryption includes the following steps:

[0008] System initialization: A trusted third party generates system public parameters PP and master private key MSK;

[0009] Ordinary public and private key generation: Ordinary public key encryption users obtain system public parameters PP, and generate matching ordinary public keys PK and ordinary private keys SK based on the system public parameters PP;

[0010] Attribute-based private key generation: A trusted third party sets a user attribute set S and generates a user attribute-based private key SK based on the system public parameter PP, the master private key MSK, and the user attribute set S. ABE ;

[0011] Ordinary public key encryption: Ordinary public key encryption users set keyword set T, encrypt data plaintext M with ordinary public key PK and keyword set T, obtain ordinary public key encrypted ciphertext CT, and upload ordinary public key encrypted ciphertext CT to the cloud service provider;

[0012] Conversion key generation: Ordinary public key encryption users generate conversion keys RK based on system public parameters PP, ordinary private keys SK and keyword set T, and set access control policies to limit the use rights of conversion keys RK. The access control policies are expressed by linear secret partitioning scheme LSSS(A, ρ), where A is a matrix with l rows and c columns, each row corresponds to an attribute in the user attribute set S, and ρ represents a function that maps each row in matrix A to the corresponding attribute.

[0013] Ciphertext conversion: The cloud service provider uses the conversion key RK to convert the common public key encrypted ciphertext CT whose keyword set is consistent with the keyword set in the conversion key RK into the attribute-based encrypted ciphertext CT′;

[0014] Attribute-based encrypted ciphertext decryption: determine the user attribute-based private key SK ABE Does the associated user attribute set satisfy the access control policy? If so, use the user attribute base private key SK ABE Decrypt the attribute-based encrypted ciphertext CT′ and output the data plaintext M; otherwise, the decryption is terminated.

[0015] As a preferred improvement, the system initialization process specifically includes the following steps:

[0016] Select a bilinear map e with order p: G×G→G T , maps the elements in group G to group G T , select any element g,u,h,v,w,∈G,q 1 ,q 2 , ..., q n ∈G,α∈Z p , and the hash function H:G T →G, where Z p represents the field of integers of order p;

[0017] Run the bilinear group generation algorithm to calculate:

[0018] PP=(G,G T ,e,p,g,u,h,v,w,q 1 ,q 2 ,…,q n , H, e(g, g) α );

[0019] MSK=g α ;

[0020] Output system public parameters PP and master private key MSK.

[0021] As a preferred improvement, the process of generating common public and private keys specifically includes the following steps:

[0022] Choose a random element β∈Z p ,calculate:

[0023] PK=e(g,g) β ;

[0024] SK=g β ;

[0025] Output the public key PK and the private key SK.

[0026] As a preferred improvement, the process of generating the attribute-based private key specifically includes the following steps:

[0027] Set user attribute collection

[0028] Choose a random element r∈Z p , select m random elements r 1 , r 2 , ..., r m ∈Z p ,calculate:

[0029] K 0 =g α w r ;

[0030] K 1 =g r ;

[0031]

[0032] Where j = 1, 2, ..., m;

[0033] Output user attribute base private key SK ABE =(K 0 , K 1 , {D 1,j, D 2,j} j=1,2...,m ).

[0034] As a preferred improvement, the process of ordinary public key encryption specifically includes the following steps:

[0035] Set keyword set

[0036] Choose a random element s∈Z p ,calculate:

[0037] C 0 =Me(g, g) βs ;

[0038] C 1 =g s ;

[0039]

[0040] Output common public key encrypted ciphertext CT = (C 0 , C 1 , C 2 ).

[0041] As a preferred improvement, the method further comprises the following steps:

[0042] Ordinary public key encryption ciphertext decryption: Use the ordinary private key SK to decrypt the ordinary ciphertext CT and output the data plaintext M. The decryption process is expressed as:

[0043] M=C 0 / e(C 1 , SK) = Me(g, g) βs / e(g s , g β ).

[0044] As a preferred improvement, the process of converting key generation specifically includes the following steps:

[0045] Choose a random element δ, k∈Z p , and select a random element k for all i=1,2…l i ∈Z p ; Select a random vector with c elements And let its first element be k;

[0046] Calculate the inner product λ i =yA i , where A i is the i-th row of matrix A, then calculate:

[0047] d 1 =g δH(e(g,g) αk );

[0048] d 2 =g k ;

[0049]

[0050] Output conversion key RK = (d 1 , d 2 ,{d 3,i , d 4,i , d 5,i} i=1,...,l , d 6 ).

[0051] As a preferred improvement, the ciphertext conversion process specifically includes the following steps:

[0052] calculate:

[0053] c 1 =d 1 ;

[0054] c 2 =d 2 ;

[0055] c 3,i =d 3,i ;

[0056] c 4,i =d 4,i ;

[0057] c 5,i =d 5,i ;

[0058]

[0059]

[0060] Output attribute-based encrypted ciphertext CT′=(c 1 , c 2 ,{c 3,i , c 4,i , c 5,i} i=1,...,l , c 6 , c 7 ).

[0061] As a preferred improvement, the process of attribute-based encrypted ciphertext decryption specifically includes the following steps:

[0062] Determine the user attribute base private key SK ABEWhether the associated attribute satisfies the access control policy, if so, execute the following steps; otherwise, terminate the decryption;

[0063] Find the constant {ω in polynomial time i ∈Z p} i∈I make Established, where I={i:ρ(i)∈S}, ρ(i)=a j ∈S, calculate:

[0064]

[0065] c 1 / H(e(g α , g k )) = g δ H(e(g,g) αk ) / H(e(g α , g k )) = g δ ;

[0066] Output data plain text

[0067]

[0068] A system for executing the above-mentioned data flexible sharing method based on public key and attribute-based encryption, comprising:

[0069] System initialization module: deployed on a trusted third party to generate system public parameters PP and master private key MSK;

[0070] Ordinary public and private key generation module: deployed on the ordinary public key encryption client, used to obtain the system public parameter PP, and generate the matching ordinary public key PK and ordinary private key SK based on the system public parameter PP;

[0071] Attribute-based private key generation module: deployed on a trusted third party, used to set the user attribute set S, and generate the user attribute-based private key SK based on the system public parameter PP, the master private key MSK and the user attribute set S ABE ;

[0072] Ordinary public key encryption module: deployed on the ordinary public key encryption client, used to set the keyword set T, encrypt the data plaintext M with the ordinary public key PK and the keyword set T, obtain the ordinary public key encrypted ciphertext CT, and upload the ordinary public key encrypted ciphertext CT to the cloud service provider;

[0073] Conversion key generation module: deployed on the common public key encryption client, used to generate the conversion key RK based on the system public parameter PP, the common private key SK and the keyword set T, and set the access control policy to limit the use rights of the conversion key RK. The access control policy is expressed by the linear secret partitioning scheme LSSS(A, ρ), where A is a matrix with l rows and c columns, each row corresponds to an attribute in the user attribute set S, and ρ represents a function that maps each row in the matrix A to the corresponding attribute;

[0074] Ciphertext conversion module: deployed on the cloud service provider side, used to use the conversion key RK to convert the common public key encrypted ciphertext CT whose keyword set is consistent with the keyword set in the conversion key RK into the attribute-based encrypted ciphertext CT′;

[0075] Attribute-based encryption ciphertext decryption module: deployed on the attribute-based encryption client to determine the user's attribute-based private key SK ABE Does the associated user attribute set satisfy the access control policy? If so, use the user attribute base private key SK ABE Decrypt the attribute-based encrypted ciphertext CT′ and output the data plaintext M; otherwise, the decryption is terminated.

[0076] The beneficial effects of the present invention are:

[0077] (1) The present invention aims to solve the problem of securely sharing data between users of a public key encryption system and users of an attribute-based encryption system, and proposes a flexible data sharing method and system based on public key and attribute-based encryption. The method allows users of a public key encryption system to convert their public key encrypted ciphertext into attribute-based encrypted ciphertext by specifying an access control policy without decrypting the data, so that users in the attribute-based encryption system who meet the access control policy can access the data. Compared with the method of decrypting first and then encrypting or directly sharing the private key, the method protects the user's private key and realizes fine-grained data security sharing.

[0078] (2) Compared with traditional public key encryption, the flexible data sharing method based on public key and attribute-based encryption proposed in the present invention allows users to encrypt data using a tag set (keyword combined with T), that is, a public key encrypted ciphertext can be associated with multiple different tags. In this way, when users need to share data, they can accurately locate the public key encrypted ciphertext that needs to be converted by specifying a tag set;

[0079] (3) Compared with the traditional ciphertext conversion method, the flexible data sharing method based on public key and attribute-based encryption proposed in the present invention can be used by users of both public key encryption and attribute-based encryption systems respectively, and the users of the public key encryption system have the ability to convert ciphertext. When they need to share data, they can convert their public key encrypted ciphertext into attribute-based encrypted ciphertext to achieve flexible data sharing based on access control policies. Due to this feature, the method proposed in the present invention is suitable for "post-hoc" data sharing scenarios. For example, in IoT data collection, users do not know who needs to access their data at the beginning, so they can use their own public key to encrypt data to achieve data security storage; after a period of time, when the user decides to share data (such as uploading data to the cloud) but still does not know the specific identity of the visitor, the user can specify the access control policy to generate a conversion key and send it to the cloud server. The cloud server uses the conversion key to replace the public key in the ciphertext with the access control policy newly specified by the user, thereby completing a "post-hoc" data sharing, making data sharing more flexible. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] Figure 1 A flow chart showing a method for flexible data sharing based on public key and attribute-based encryption provided by the present invention. DETAILED DESCRIPTION

[0081] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0082] Please refer to Figure 1 The present invention provides a flexible data sharing method based on public key and attribute-based encryption, comprising the following steps:

[0083] System initialization: A trusted third party generates system public parameters PP and master private key MSK.

[0084] The system initialization process specifically includes the following steps:

[0085] Select a bilinear map e with order p: G×G→G T , maps the elements in group G to group G T , select any element g,u,h,v,w,∈G,q 1 ,q 2 , ..., q n ∈G,α∈Z p , and the hash function H:G T →G, where Zp represents the field of integers of order p;

[0086] Run the bilinear group generation algorithm to calculate:

[0087] PP=(G,G T ,e,p,g,u,h,v,w,q 1 ,q 2 ,…,q n , H, e(g, g) α );

[0088] MSK=g α ;

[0089] Output system public parameters PP and master private key MSK. System public parameters PP are open to the public, and master private key MSK is kept secret by a trusted third party.

[0090] Ordinary public and private key generation: Ordinary public key encryption users obtain the system public parameters PP, and generate matching ordinary public keys PK and ordinary private keys SK based on the system public parameters PP.

[0091] The process of generating common public and private keys specifically includes the following steps:

[0092] Choose a random element β∈Z p ,calculate:

[0093] PK=e(g,g) β ;

[0094] SK=g β ;

[0095] Output the public key PK and private key SK. The ordinary public key PK is open to the public, and the ordinary private key SK is kept secret by the ordinary public key encryption user.

[0096] Attribute-based private key generation: A trusted third party sets a user attribute set S and generates a user attribute-based private key SK based on the system public parameter PP, the master private key MSK, and the user attribute set S. ABE .

[0097] The process of generating an attribute-based private key specifically includes the following steps:

[0098] Set user attribute collection

[0099] Choose a random element r∈Z p , select m random elements r 1 , r 2 , ..., r m ∈Z p ,calculate:

[0100] K 0 =g α w r ;

[0101] K 1 =g r ;

[0102]

[0103] Where j = 1, 2, ..., m;

[0104] Output user attribute base private key SK ABE =(K 0 , K 1 , {D 1,j , D 2,j} j=1,2...,m ).

[0105] Ordinary public key encryption: For ordinary public key encryption, the user sets a keyword set T, encrypts the data plaintext M with the ordinary public key PK and the keyword set T, obtains the ordinary public key encrypted ciphertext CT, and uploads the ordinary public key encrypted ciphertext CT to the cloud service provider.

[0106] The process of ordinary public key encryption specifically includes the following steps:

[0107] Set keyword set

[0108] Choose a random element s∈Z p ,calculate:

[0109] C 0 =Me(g, g) βs ;

[0110] C 1 =g s ;

[0111]

[0112] Output common public key encrypted ciphertext CT = (C 0 , C 1 , C 2 ).

[0113] Ordinary public key encryption users have the authority to encrypt data plaintext M. The encrypted ordinary public key encryption ciphertext CT is uploaded to the cloud service provider and released to the public by the cloud service provider. Attribute-based encryption users can obtain ordinary public key encryption ciphertext CT directly from the cloud service provider without direct contact with ordinary public key encryption users, which improves the privacy of the data sharing process; and the contact between cloud service providers and attribute-based encryption users is a "one-to-many" method. Compared with the "one-to-one" contact between ordinary public key encryption users and attribute-based encryption users in traditional technologies, it can greatly increase the number of data sharing objects and is conducive to data dissemination; furthermore, after the ordinary public key encryption ciphertext CT is uploaded to the cloud service provider, it is stored by the cloud service provider. Ordinary public key encryption users no longer need to store the data plaintext M locally, but only need to store the ordinary private key SK. When the data plaintext M is needed, the ordinary public key encryption ciphertext CT is downloaded from the cloud service provider, and the ordinary private key SK is used to decrypt and restore the data plaintext M.

[0114] Conversion key generation: Ordinary public key encryption users generate conversion keys RK based on system public parameters PP, ordinary private keys SK and keyword set T, and set access control policies to limit the use rights of conversion keys RK. The access control policies are expressed by linear secret partitioning scheme LSSS(A, ρ), where A is a matrix with l rows and c columns, each row corresponding to an attribute in the user attribute set S, and ρ represents a function that maps each row in matrix A to the corresponding attribute.

[0115] The access control policy is a Boolean expression composed of AND gates, OR gates, and attributes, which represents the relationship between access rights and user attributes. For example, when sharing data in an online forum, the access control structure set is OR("Attribute 2: Ordinary user" AND "Attribute 3: Forum level 3 and above"), this access control policy This indicates that only users with the attribute of "administrator" or users with both the attributes of "ordinary user" and "forum level 3 and above" can obtain access to the conversion key RK.

[0116] Access Control Policy It is expressed by the linear secret partitioning scheme LSSS(A, ρ), for example, ρ(1) = "tourist user" means that the first row in the matrix A corresponds to the attribute "tourist user".

[0117] The process of converting key generation specifically includes the following steps:

[0118] Choose a random element δ, k∈Z p , and select a random element k for all i=1,2…l i ∈Z p; Select a random vector with c elements And let its first element be k;

[0119] Calculate the inner product λ i =yA i , where A i is the i-th row of matrix A, then calculate:

[0120] d 1 =g δ H(e(g,g) αk );

[0121] d 2 =g k ;

[0122]

[0123] Output conversion key RK = (d 1 , d 2 , {d 3,i , d 4,i , d 5,i} i=1,...,l , d 6 ).

[0124] Ciphertext conversion: The cloud service provider uses the conversion key RK to convert the ordinary public key encrypted ciphertext CT whose keyword set is consistent with the keyword set in the conversion key RK into the attribute-based encrypted ciphertext CT′.

[0125] In the process of generating ordinary public key encryption ciphertext CT, the keyword set T is introduced. In the process of generating conversion key RK, the keyword set T is also introduced. Therefore, there is a unique corresponding relationship between ordinary public key encryption ciphertext CT and conversion key RK. Only ordinary public key encryption ciphertext with the same keyword set as the keyword set in the conversion key RK can be converted into attribute-based encryption ciphertext CT′ by the conversion key RK. The attribute-based encryption ciphertext CT′ is provided to the outside by the cloud service provider, and attribute-based encryption users can download it from the cloud service provider.

[0126] At the same time, the conversion key RK is generated based on the ordinary private key SK, and the ciphertext conversion process no longer needs to use the ordinary private key SK, that is, the data owner does not need to provide the ordinary private key SK to the cloud service provider, which can ensure the security of the ordinary private key SK.

[0127] The ciphertext conversion process specifically includes the following steps:

[0128] calculate:

[0129] c 1 =d 1 ;

[0130] c 2 =d 2 ;

[0131] c 3,i =d 3,i ;

[0132] c 4,i =d 4,i ;

[0133] c 5,i =d 5,i ;

[0134]

[0135] Output attribute-based encrypted ciphertext CT′=(c 1 , c 2 ,{c 3,i , c 4,i , c 5,i} i=1,...,l , c 6 , c 7 ).

[0136] From the above steps, it can be seen that the data plaintext M is encrypted twice to obtain the ordinary public key encryption ciphertext CT and the attribute-based encryption ciphertext CT′ respectively. The encryption strength of the attribute-based encryption ciphertext CT′ is better than that of the ordinary public key encryption ciphertext CT. Both ciphertexts can decrypt the data plaintext M; and the ordinary public key encryption ciphertext CT and the attribute-based encryption ciphertext CT′ are generated by different objects, and the generation processes of the two are independent of each other and will not interfere with each other.

[0137] Ordinary public key encryption ciphertext decryption: Use the ordinary private key SK to decrypt the ordinary ciphertext CT and output the data plaintext M. The decryption process is expressed as:

[0138] M=C 0 / e(C 1 , SK) = Me(g, g) βs / e(g s , g β ).

[0139] Attribute-based encrypted ciphertext decryption: determine the user attribute-based private key SK ABE Does the associated user attribute set satisfy the access control policy? If so, use the user attribute base private key SK ABE Decrypt the attribute-based encrypted ciphertext CT′ and output the data plaintext M; otherwise, the decryption is terminated.

[0140] The process of attribute-based encryption ciphertext decryption specifically includes the following steps:

[0141] Determine the user attribute base private key SK ABEWhether the associated attribute satisfies the access control policy, if so, execute the following steps; otherwise, terminate the decryption;

[0142] Find the constant {ω in polynomial time i ∈Z p} i∈I make Established, where I={i:ρ(i)∈S}, ρ(i)=a j ∈S, calculate:

[0143]

[0144] c 1 / H(e(g α , g k )) = g δ H(e(g,g) αk ) / H(e(g α , g k )) = g δ ;

[0145] Output data plain text

[0146]

[0147] The present invention also provides a system for executing the above-mentioned data flexible sharing method based on public key and attribute-based encryption, comprising:

[0148] System initialization module: deployed on a trusted third party to generate system public parameters PP and master private key MSK;

[0149] Ordinary public and private key generation module: deployed on the ordinary public key encryption client, used to obtain the system public parameter PP, and generate the matching ordinary public key PK and ordinary private key SK based on the system public parameter PP;

[0150] Attribute-based private key generation module: deployed on a trusted third party, used to set the user attribute set S, and generate the user attribute-based private key SK based on the system public parameter PP, the master private key MSK and the user attribute set S ABE ;

[0151] Ordinary public key encryption module: deployed on the ordinary public key encryption client, used to set the keyword set T, encrypt the data plaintext M with the ordinary public key PK and the keyword set T, obtain the ordinary public key encrypted ciphertext CT, and upload the ordinary public key encrypted ciphertext CT to the cloud service provider;

[0152] Conversion key generation module: deployed on the common public key encryption client, used to generate the conversion key RK based on the system public parameter PP, the common private key SK and the keyword set T, and set the access control policy to limit the use rights of the conversion key RK. The access control policy is expressed by the linear secret partitioning scheme LSSS(A, ρ), where A is a matrix with l rows and c columns, each row corresponds to an attribute in the user attribute set S, and ρ represents a function that maps each row in the matrix A to the corresponding attribute;

[0153] Ciphertext conversion module: deployed on the cloud service provider side, used to use the conversion key RK to convert the common public key encrypted ciphertext CT whose keyword set is consistent with the keyword set in the conversion key RK into the attribute-based encrypted ciphertext CT′;

[0154] Attribute-based encryption ciphertext decryption module: deployed on the attribute-based encryption client to determine the user's attribute-based private key SK ABE Does the associated user attribute set satisfy the access control policy? If so, use the user attribute base private key SK ABE Decrypt the attribute-based encrypted ciphertext CT′ and output the data plaintext M; otherwise, the decryption is terminated.

[0155] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation modes, which are merely illustrative rather than restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are within the protection of the present invention.

Claims

1. A flexible data sharing method based on public key and attribute-based encryption, characterized in that: The steps include: System initialization: A trusted third party generates system public parameters PP and master private key MSK; Ordinary public and private key generation: Ordinary public key encryption users obtain system public parameters PP, and generate matching ordinary public keys PK and ordinary private keys SK based on the system public parameters PP; Attribute-based private key generation: A trusted third party sets a user attribute set S and generates a user attribute-based private key SK based on the system public parameter PP, the master private key MSK, and the user attribute set S. ABE ; Ordinary public key encryption: Ordinary public key encryption users set keyword set T, encrypt data plaintext M with ordinary public key PK and keyword set T, obtain ordinary public key encrypted ciphertext CT, and upload ordinary public key encrypted ciphertext CT to the cloud service provider; Conversion key generation: Ordinary public key encryption users generate conversion keys RK based on system public parameters PP, ordinary private keys SK and keyword set T, and set access control policies to limit the use rights of conversion keys RK. The access control policies are expressed by linear secret partitioning scheme LSSS(A,ρ), where A is a matrix with l rows and c columns, each row corresponds to an attribute in the user attribute set S, and ρ represents a function that maps each row in matrix A to the corresponding attribute; Ciphertext conversion: The cloud service provider uses the conversion key RK to convert the common public key encrypted ciphertext CT whose keyword set is consistent with the keyword set in the conversion key RK into the attribute-based encrypted ciphertext CT′; Attribute-based encrypted ciphertext decryption: determine the user attribute-based private key SK ABE Does the associated user attribute set satisfy the access control policy? If so, use the user attribute base private key SK ABE Decrypt the attribute-based encrypted ciphertext CT′ and output the data plaintext M; otherwise, the decryption is terminated; The process of ordinary public key encryption specifically includes the following steps: Set keyword set In the formula, Z p represents the field of integers of order p; Choose a random element s∈Z p ,calculate: C0=Me(g,g) βs , where e is a bilinear mapping of order p, expressed as e:G×G→G T , used to map elements in group G to group G T ; g represents any element in the group G; β represents the integer field Z p Random elements in C1=g s ; Where u represents any element in the group G; q1,q2,...,q n ∈G; Output common public key encrypted ciphertext CT = (C0, C1, C2).

2. The flexible data sharing method based on public key and attribute-based encryption according to claim 1 is characterized in that: The system initialization process specifically includes the following steps: Select a bilinear map e:G×G→G with order p as a large prime number T , maps the elements in group G to group G T , select any element g,u,h,v,w,∈G,q1,q2,...,q n ∈G,α∈Z p , and the hash function H:G T →G; Run the bilinear group generation algorithm to calculate: PP=(G,G T ,e,p,g,u,h,v,w,q1,q2,...,q n ,H,e(g,g) α ); MSK=g α ; Output system public parameters PP and master private key MSK.

3. The flexible data sharing method based on public key and attribute-based encryption according to claim 2 is characterized in that: The process of generating common public and private keys specifically includes the following steps: calculate: PK=e(g,g) β ; SK=g β ; Output the public key PK and the private key SK.

4. The flexible data sharing method based on public key and attribute-based encryption according to claim 3 is characterized in that: The process of generating an attribute-based private key specifically includes the following steps: Set user attribute collection Choose a random element r∈Z p , select m random elements r1,r2,...,r m ∈Z p ,calculate: K0=g α w r ; K1=g r ; Where j = 1, 2, ..., m; Output user attribute base private key SK ABE =(K0,K1,{D 1,j ,D 2,j } j=1,2...,m ).

5. The flexible data sharing method based on public key and attribute-based encryption according to claim 4 is characterized in that: The following steps are also included: Ordinary public key encryption ciphertext decryption: Use the ordinary private key SK to decrypt the ordinary ciphertext CT and output the data plaintext M. The decryption process is expressed as: M=C0 / e(C1,SK)=Me(g,g) βs / e(g s ,g β )。 6. The flexible data sharing method based on public key and attribute-based encryption according to claim 5 is characterized in that: The process of converting key generation specifically includes the following steps: Choose a random element δ,k∈Z p , and select a random element k for all i=1,2···l i ∈Z p ; Select a random vector with c elements And let its first element be k; Calculate the inner product λ i =yA i , where A i is the i-th row of matrix A, then calculate: d1=g δ H(e(g,g) αk ); d2=g k ; Output conversion key RK = (d1, d2, {d 3,i ,d 4,i ,d 5,i } i=1,...,l ,d6).

7. The flexible data sharing method based on public key and attribute-based encryption according to claim 6 is characterized in that: The ciphertext conversion process specifically includes the following steps: calculate: c1=d1; c2=d2; c 3,i =d 3,i ; c 4,i =d 4,i ; c 5,i =d 5,i ; Output attribute-based encrypted ciphertext CT′=(c1,c2,{c 3,i ,c 4,i ,c 5,i } i=1,...,l ,c6,c7).

8. The flexible data sharing method based on public key and attribute-based encryption according to claim 7 is characterized in that: The process of attribute-based encryption ciphertext decryption specifically includes the following steps: Determine the user attribute base private key SK ABE Whether the associated attribute satisfies the access control policy, if so, execute the following steps; Otherwise, decryption is terminated; Find the constant {ω in polynomial time i ∈Z p } i∈I make Established, where I={i:ρ(i)∈S}, ρ(i)=a j ∈S, calculate: c1 / H(e(g α ,g k ))=g δ H(e(g,g) αk ) / H(e(g α ,g k ))=g δ ; Output data plain text 9. A system for executing the flexible data sharing method based on public key and attribute-based encryption according to any one of claims 1 to 8, characterized in that: include: System initialization module: deployed on a trusted third party to generate system public parameters PP and master private key MSK; Ordinary public and private key generation module: deployed on the ordinary public key encryption client, used to obtain the system public parameter PP, and generate the matching ordinary public key PK and ordinary private key SK based on the system public parameter PP; Attribute-based private key generation module: deployed on a trusted third party, used to set the user attribute set S, and generate the user attribute-based private key SK based on the system public parameter PP, the master private key MSK and the user attribute set S ABE ; Ordinary public key encryption module: deployed on the ordinary public key encryption client, used to set the keyword set T, encrypt the data plaintext M with the ordinary public key PK and the keyword set T, obtain the ordinary public key encrypted ciphertext CT, and upload the ordinary public key encrypted ciphertext CT to the cloud service provider; Conversion key generation module: deployed on the common public key encryption client, used to generate the conversion key RK based on the system public parameter PP, the common private key SK and the keyword set T, and set the access control policy to limit the use rights of the conversion key RK. The access control policy is expressed by the linear secret partitioning scheme LSSS(A,ρ), where A is a matrix with l rows and c columns, each row corresponds to an attribute in the user attribute set S, and ρ represents a function that maps each row in the matrix A to the corresponding attribute; Ciphertext conversion module: deployed on the cloud service provider side, used to use the conversion key RK to convert the common public key encrypted ciphertext CT whose keyword set is consistent with the keyword set in the conversion key RK into the attribute-based encrypted ciphertext CT′; Attribute-based encryption ciphertext decryption module: deployed on the attribute-based encryption client to determine the user's attribute-based private key SK ABE Does the associated user attribute set satisfy the access control policy? If so, use the user attribute base private key SK ABE Decrypt the attribute-based encrypted ciphertext CT′ and output the data plaintext M; otherwise, the decryption is terminated.

Citation Information

Patent Citations

  • Outsourcing attribute encryption method supporting attribute cancellation

    CN106452735A

  • Attribute-based online / offline keyword search method in mobile cloud environment and cloud computing application system thereof

    CN107547530A