An outsourcing decryption method for protecting revocable user attributes based on cloud environment data

By utilizing cloud servers in a cloud environment to handle user revocation management and improve attribute unrestricted KP-ABE scheme, the problems of high encryption and decryption overhead and low efficiency in the revocation stage in existing technologies are solved, achieving efficient user attribute management and improved decryption performance.

CN119484076BActive Publication Date: 2026-04-24GANNAN NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GANNAN NORMAL UNIV
Filing Date
2024-11-08
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In existing technologies, encryption and decryption of encrypted data in the authorization center are costly, communication and computation efficiency during the user revocation phase is low, and decryption of common parameters is complex, especially when there are large user sets or user updates, the complexity of encryption and decryption increases.

Method used

A cloud-based outsourced decryption method for data protection of revocable user attributes is adopted. Through initialization algorithm, encryption algorithm, key generation algorithm and outsourced decryption algorithm, the cloud server is used to handle user revocation management, reduce the size of public parameters, reduce the decryption workload, and improve the KP-ABE scheme with unrestricted attributes. The outsourced decryption function is handled by the proxy server.

Benefits of technology

It enables flexible management of user attributes without updating user keys and public keys, improves encryption and decryption efficiency, reduces the size of preset values ​​for public parameters, and enhances the user decryption experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484076B_ABST
    Figure CN119484076B_ABST
Patent Text Reader

Abstract

The application discloses an outsourcing decryption method for revoking user attributes based on cloud environment data protection and belongs to the technical field of cloud computing security. The application comprises an initialization algorithm, an encryption algorithm, a key generation algorithm, an outsourcing decryption algorithm and an attribute revocation algorithm. The method of the application is based on a cloud environment, public parameters are composed of a fixed number of group elements, there is no limitation on an attribute set used for encryption, user revocation can be performed at each attribute level instead of at a system level, and more fine-grained user access control is realized. Moreover, user information is not leaked in judgment of whether a user is revoked and outsourcing decryption. The scheme is proved to be safe under the complexity assumption of a composite order group. Through comparative analysis on the performance of similar schemes, the result shows that the scheme is more efficient and more flexible in the scene of user management in a cloud environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to security technologies in cloud environments, specifically to revocable user attribute outsourcing decryption technology. Background Technology

[0002] Cloud servers are an internet-based model where businesses and government departments upload data to cloud service platforms to achieve data sharing between departments. While people enjoy the advantages of these new technologies and services, concerns about data security and access control also arise. Semi-trusted cloud servers may harbor curiosity about the data they store, and unauthorized access by external users could pose a potential threat. People generally prefer that their shared data be accessible only to authorized personnel with designated credentials. To prevent these potential threats in cloud environments, cryptographic techniques are typically used to store data in encrypted form on cloud servers.

[0003] In recent years, the efficiency and flexibility of attribute-based encryption and decryption have attracted much attention from scholars. Research results on outsourced decryption and revocable users have emerged as follows: Green et al. proposed an outsourced ABE scheme, outsourcing most of the decryption overhead to a trusted third-party server; Lai et al. proposed a verifiable outsourced ABE, which, while preventing data loss, requires significant decryption costs. Belguith et al. proposed a multi-authorization-based outsourced decryption scheme, which requires each authorization center to add its own master key to the key, thus increasing the encryption and decryption overhead. Deng et al. proposed an efficient attribute-based revocable signature encryption scheme with outsourced decryption in cloud environments, which not only allows for outsourced decryption but also provides user revocation functionality; however, the communication and computation design during the revocation phase is not efficient enough. Research on revocable ABE schemes can be divided into two types: indirect revocable ABE and direct revocable ABE; Wang et al. proposed an attribute-based direct revocable encryption scheme and its application in cloud storage environments, realizing outsourced user revocation in cloud environments, but its decryption computation overhead is high.

[0004] In the above schemes, most of the common parameters are composed of attribute-related components. When designing some user cancellation schemes, the common parameters related to the user set are also preset and fixed in advance. When a large attribute set or user set is added to the system, the selection of common parameters will become particularly large, thereby increasing the complexity of encryption and decryption. Moreover, when user-related parameters are designed into common parameters, the common parameters will inevitably need to be updated as users are updated. Summary of the Invention

[0005] The technical problems to be solved by this invention are: high overhead of encryption and decryption in the authorization center; inefficient communication and computation involved in the revocation phase of revocable outsourced users; and complex decryption of public parameters. In view of the shortcomings of the prior art, this invention aims to provide an outsourced decryption method for revocable user attributes based on cloud environment data protection.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0007] An outsourced decryption method for revocable user attributes based on cloud environment data protection includes: an initialization algorithm Setup(λ), an encryption algorithm Encrypt(PP,M,S1), a key generation algorithm KeyGen(MSK,PP,(A,ρ)), and an outsourced decryption algorithm Decrypt. out (CT,SK out ), attribute cancellation algorithm

[0008] Preferably, in the outsourced decryption method for revocable user attributes based on cloud environment data protection, the initialization algorithm Setup(λ) is as follows:

[0009] Input the security parameter λ, and select a composite group G of order N = p1p2p3, where p1, p2, and p3 are three distinct prime numbers, randomly selected. H1:G→Z N Let U be the set of users and S be the set of attributes, where the attributes are defined by the attribute name at. i and attribute value s i The system is configured by selecting MSK = α as the system master key, and then outputting common parameters.

[0010] The key generation center generates a random number u for each registered user. ε ,for Assumption It has att i User set of attributes It has att i Number of users for the attribute

[0011] The key generation center sends the attribute user set to the cloud server, and the cloud server calculates for each attribute user set. The specific algorithm is as follows:

[0012] The cloud server calculates a polynomial function based on the set of attribute users. Finally, the coefficients were calculated. Composition and attributes att i Related in They are respectively equal to

[0013] Preferably, in the outsourced decryption method for revocable user attributes based on cloud environment data protection, the encryption algorithm Encrypt(PP,M,S1) is:

[0014] The data owner (DO) executes the encryption algorithm, taking plaintext M as input and a set of attributes S1 for encryption, where the attribute set S1 = {s1, s2, ..., s...} l}, Randomly select s, t1, ..., t l ∈Z N Calculate C = Me(g,g) αs C0=g s , The data owner will encrypt the text Uploaded to the cloud server.

[0015] The cloud server binds each attribute in the newly uploaded encrypted CT file. in

[0016]

[0017] Preferably, in the outsourced decryption method for revocable user attributes based on cloud environment data protection, the key generation algorithm KeyGen(MSK,PP,(A,ρ)) is:

[0018] The key generation center executes the algorithm to distribute keys to data accessors, taking into account the public parameters PP, the linear secret sharing scheme LSSS matrix (A,ρ), and the master key MSK = α. Let S2 be the set of attributes associated with the private key SK, and A be the set of attributes belonging to Z. N Let A be an n×m matrix composed of the elements of A, where ρ represents the mapping function from a certain attribute to a certain row of matrix A. Let i∈{1,…n}, and let A... i Let A represent the i-th row. Let ρ(i) represent the attributes associated with this row through mapping ρ, and randomly select ω, r1, ..., r. n ,y1…y n ∈Z N and random vectors make i∈{1,…,n},α i It is A i The secret value of the corresponding attribute in the row is calculated as follows:

[0019]

[0020] The key generation center transmits the private key SK={(A,ρ),u} through a secure channel. ε ,k0,ki,1 ,k i,2 ,k i,3 ,k i,4} i∈{1,…,n} Send to the data accessor.

[0021] Preferably, in the outsourced decryption method for revocable user attributes based on cloud environment data protection, the outsourced decryption algorithm Decrypt... out (CT,SK out ): When the proxy server receives partial keys from the user accessing the data. When retrieving attributes related to ciphertext, the proxy server will perform the following operations:

[0022] After the proxy server retrieves the requested encrypted CT, it will... ε and attribute att in S2 i corresponding Substitution

[0023]

[0024] If any of the calculation results are not equal to 1, it means that the user's attribute has been revoked, and the calculation is terminated directly; otherwise, the following algorithm continues:

[0025] 1) If the attribute set S1 of the ciphertext satisfies the access structure (A, ρ), then for partial decryption of the ciphertext, let ξ = (1, 0, ..., 0). It is the attribute-to-attribute matrix in set S2, calculated. It is a vector The values ​​corresponding to the attributes, where s i ∈S2

[0026]

[0027] Where s i =ρ(i);

[0028] 2) The proxy server sends D to the data access user.

[0029] Decrypt(C,D,SK): The data access user executes the decryption algorithm, substituting k0 into D to calculate...

[0030]

[0031] Preferably, in the outsourced decryption method for revocable user attributes based on cloud environment data protection, the attribute revocation algorithm... When a user in the attribute user set needs to be updated, the key authorization center will update the attribute user set. To the cloud server, the cloud server according to Recalculation of polynomial functions

[0032]

[0033] Based on the coefficients calculated above Construct a property-related Subsequently, without cancelling user accounts, the cloud servers will all use the newly calculated [data / method / mechanism]. Re-encrypt the relevant ciphertext.

[0034] The beneficial effects of this invention are:

[0035] 1. This invention delegates user revocation management to the cloud server, enabling the revocation of user attribute keys without updating user keys and public keys. User attribute-related keys that have not been revoked can still complete normal decryption if the access policy is satisfied. Therefore, the revocation method of this solution makes user management more flexible.

[0036] 2. By adopting the improved KP-ABE scheme with unrestricted attributes, the technology of this invention can reduce the size of the preset value of common parameters, thereby indirectly improving the efficiency of encryption and decryption;

[0037] 3. The improved solution enables outsourced decryption, allowing a large amount of decryption work to be handled by a proxy server, thus improving the user's decryption efficiency. Applying this solution to practical applications will greatly enhance the user's encryption and decryption experience. Attached Figure Description

[0038] Figure 1 Basic flowchart of this invention;

[0039] Figure 2 Comparison of the encryption algorithm operation time of this invention;

[0040] Figure 3 Comparison of the running time of the decryption algorithm of this invention. Detailed Implementation

[0041] The following is in conjunction with the appendix Figure 1-3 The technical method of the present invention will be further described in detail below:

[0042] Step 1: Build a security system. Input the security parameter λ, and select a composite group G of order N = p1p2p3, where p1, p2, and p3 are three completely different prime numbers, randomly selected. H1:G→Z N Let U be the set of users and S be the set of attributes, where the attributes are defined by the attribute name at. i and attribute value s i The system is configured by selecting MSK = α as the system master key, and then outputting common parameters.

[0043] Step 2: The key generation center generates a random number u for each registered user. ε ,for Assumption It has att i User set of attributes It has att i Number of users for the attribute

[0044] Step 3: The key generation center sends the attribute user set to the cloud server, and the cloud server calculates the key for each attribute user set.

[0045] Step 3-1: The cloud server calculates the polynomial function based on the set of attribute users.

[0046] Step 3-2: Calculate coefficients on the cloud server Composition and attributes att i Related in They are respectively equal to

[0047] Step 4: The data owner (DO) executes the encryption algorithm, inputting plaintext M and the set of attributes S1 used for encryption, where the attribute set S1 = {s1, s2, ..., s...} l}, i∈[1,l], randomly selects s,t1,…,t l ∈Z N Calculate C = Me(g,g) αs C0=g s , ciphertext Uploaded to the cloud server.

[0048] Step 5: The cloud server binds each attribute in the newly uploaded encrypted CT. in

[0049] Step 6: The key generation center distributes keys to data accessors, inputting public parameters PP, the linear secret sharing scheme LSSS matrix (A,ρ), and the master key MSK = α. Let S2 be the set of attributes related to the private key SK, and A be the set of attributes belonging to Z. N Let A be an n×m matrix composed of the elements of A, where ρ represents the mapping function from a certain attribute to a certain row of matrix A. Let i∈{1,…n}, and let A... i Let A represent the i-th row. Let ρ(i) represent the attributes associated with this row through mapping ρ, and randomly select ω, r1, ..., r. n,y1…y n ∈Z N and random vectors make i∈{1,…,n},α i It is A i The secret value of the corresponding attribute in the row is calculated as follows:

[0050]

[0051] Step 7: The key generation center transmits the private key SK = {(A,ρ),u} through a secure channel. ε ,k0,k i,1 ,k i,2 ,k i,3 ,k i,4} i∈{1,…,n} Send to the data accessor.

[0052] Step 8: The proxy server receives part of the data access user's key. When retrieving attributes related to ciphertext, use u ε and attribute att in S2 i corresponding Substitution

[0053]

[0054] Step 8-1: If the calculation result is not equal to 1, it means that the user's attributes have been revoked, and the proxy server will directly terminate the calculation.

[0055] Step 8-2: If the result is 1, and the attribute set S1 of the ciphertext satisfies the access structure (A, ρ), then the proxy server performs partial decryption of the ciphertext, letting ξ = (1, 0, ..., 0). It is the attribute-to-attribute matrix in set S2, calculated. It is a vector The values ​​corresponding to the attributes, where s i ∈S2

[0056]

[0057] Where s i =ρ(i).

[0058] Step 9: The proxy server sends D to the data access user.

[0059] Step 10: The data access user executes the decryption algorithm, substituting k0 into D to calculate...

[0060]

[0061] Step 11: When a user in the attribute user set needs to be updated, the key authorization center will update the attribute user set. To the cloud server, the cloud server according to Recalculation of polynomial functions

[0062]

[0063] Based on the coefficients calculated above Construct a property-related

[0064] Simulation experiment:

[0065] The simulation experiment uses the Java programming language, jpbc2.0 encryption library, and an i5 2.5GHz CPU, 8GB RAM, and Windows 10 operating system. The development tool is IntelliJ IDEA, JDK version 1.8. The experiment uses an A-curve with a 160-bit group-order symmetric elliptic curve and 512-bit basic elements. Based on these settings, the experimental results for encryption and decryption using different numbers of attributes (10-50) are as follows: Figure 2 , Figure 3 As shown, according to Figure 2 , Figure 3 This directly reflects that the encryption and decryption operation time of this scheme is superior to that of schemes (Wang H, Zheng Z, Wu L, et al. New directly revocable attribute-based encryption scheme and its application in cloudstorage environment), scheme (Han D, Pan N, Li K CA traceable and revocable ciphertext-policy attribute-based encryption scheme based on privacyprotection), and scheme (Li Q, Zhu H, Ying Z, et al. Traceable ciphertext-policy attribute-based encryption with verifiable outsourced decryption in ehealthcloud).

[0066] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention is limited to these examples; under the concept of the invention, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of the different aspects of the invention as described above, which are not provided in detail for the sake of brevity.

[0067] This invention is intended to cover all such substitutions, modifications, and variations falling within its broad scope. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. An outsourced decryption method for revocable user attributes based on cloud environment data protection, characterized in that, Includes cryptographic algorithms, wherein the cryptographic algorithms include: initialization algorithms Encryption algorithms Key generation algorithm Outsourced decryption algorithm Attribute cancellation algorithm ; The initialization algorithm : Input security parameters Select order as composite order group ,in They are three completely different prime numbers, randomly selected. ,make For user collection, It is a collection of attributes, where the attributes are defined by attribute names. and attribute values Composition, selection Use the system master key, and then output the common parameters. ; The key generation center generates a random number for each registered user. ,for Assuming It has User set of attributes It has Number of users for the attribute , The key generation center sends the attribute user set to the cloud server, and the cloud server calculates for each attribute user set. The specific algorithm is as follows: The cloud server calculates a polynomial function based on the set of attribute users. Finally, through the calculated coefficients Composition and attributes Related ,in They are respectively equal to ; The encryption algorithm : The encryption algorithm is executed by the data owner (DO), with plaintext input. and for encryption property sets Attribute set Random selection ,calculate The data owner will encrypt the text Uploaded to the cloud server. The cloud server is for newly uploaded encrypted text Each property is bound ,in , ; The key generation algorithm : The key generation center executes the algorithm to distribute keys to data accessors, inputting common parameters. Linear secret sharing scheme matrix and master key ,make It is with the private key A collection of related attributes It belongs to Composed of elements matrix, This indicates that a certain attribute is mapped to a matrix. Let the mapping function for a certain row be... ,use express The Okay, let's go. Through mapping To represent the attributes associated with this row, and randomly select and random vectors ,make , , yes The secret value of the corresponding attribute in the row is calculated as follows: , The key generation center transmits the private key through a secure channel. Send to the data accessor; The outsourced decryption algorithm When the proxy server receives partial keys from the user accessing the data. When retrieving attributes related to ciphertext, the proxy server will perform the following operations: The proxy server retrieved the ciphertext of the request. Afterwards, and Medium attributes corresponding Substitution , If any of the calculation results are not equal to 1, it means that the user's attribute has been revoked, and the calculation is terminated directly; otherwise, the following algorithm continues: 1) If the set of attributes of the ciphertext Satisfying access structure Then, partially decrypt the ciphertext, making , yes The matrix corresponding to the attributes in the set is calculated. , It is a vector The values ​​corresponding to the attributes, among which , , in ; 2) The proxy server will Send to the data access user. The data access user executes the decryption algorithm to... Substitute ,calculate ; The attribute cancellation algorithm When a user in the attribute user set needs to be updated, the key authorization center will update the attribute user set. To the cloud server, the cloud server according to Recalculation of polynomial functions , The coefficients are calculated above. Construct a property-related Subsequently, without cancelling user accounts, the cloud servers will all use the newly calculated [data / method / mechanism]. Re-encrypt the relevant ciphertext.