A data encryption and ciphertext retrieval method for distributed multi-center institutions

Through the key policy attribute encryption method of distributed multi-center institutions, the problem that traditional encryption methods cannot be efficiently retrieved in cloud storage environments is solved, efficient and secure data encryption and ciphertext retrieval in multi-center environments are realized, and the security and fault tolerance of the system are enhanced.

CN119652524BActive Publication Date: 2025-05-16WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510167805.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-16
Estimated Expiration
2045-02-17

AI Technical Summary

Technical Problem

In cloud storage environments, traditional data encryption methods cannot perform efficient keyword search in an encrypted state, especially when large-scale distributed data processing, resulting in inefficient retrieval. At the same time, the single-center key management model has single point of failure and trust problems in a multi-center environment.

Method used

The key policy attribute encryption method of distributed multi-center institutions is adopted to generate, distribute and manage keys through multiple independent key centers to achieve efficient ciphertext retrieval. In the stages of system initialization, key generation, encryption, decryption and ciphertext retrieval, this method uses technical means such as public parameters, public keys, master keys, private keys and trapped gates to ensure data security and retrieval efficiency.

Benefits of technology

It realizes efficient and secure data encryption and ciphertext retrieval in a multi-center environment, avoids single point of failure, enhances the system's fault tolerance and security, and optimizes the computing overhead of key authorization process and trap gate generation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652524B_ABST
    Figure CN119652524B_ABST
Patent Text Reader

Abstract

The present invention discloses a distributed multi-center data encryption and ciphertext retrieval method, which comprises two parts: a multi-center key policy attribute encryption method and a distributed multi-center key policy ciphertext retrieval method. The multi-center key policy attribute encryption method realizes efficient key policy attribute encryption under multiple authorization centers, solves the privacy security risks such as easy system crash and single point failure in a single-center scenario, and enhances system security. The distributed multi-center key policy ciphertext retrieval method solves the risk of keyword privacy leakage in traditional searchable encryption schemes. The invention effectively protects keyword privacy by hiding policies, designs a multi-center architecture to generate trapdoors, effectively prevents single point crashes and other problems, and at the same time improves trapdoor generation efficiency and enhances system practicality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of searchable encryption in applied cryptography, and relates to a data encryption and ciphertext retrieval method, and specifically to a distributed multi-center data encryption and ciphertext retrieval method. Background Art

[0002] With the development of cloud computing and distributed systems, more and more individuals and enterprises are storing data in the cloud. However, how to achieve efficient retrieval operations while ensuring data privacy and security has become a key challenge in cloud storage environments. Although traditional data encryption methods can effectively protect the confidentiality of data, they are usually unable to perform keyword searches in an encrypted state, resulting in low retrieval efficiency, especially when dealing with large-scale distributed data.

[0003] To solve this problem, searchable encryption technology was proposed, which allows users to quickly search by keywords while keeping data encrypted. However, with the complexity of application scenarios, the single-center key management model faces bottlenecks in practical applications. Especially in large-scale distributed systems, single point failures and trust issues have become important factors limiting system performance and security. For this reason, multi-center key management and distributed searchable encryption technology have become new research directions.

[0004] Multi-center key policy attribute encryption technology combines the advantages of attribute encryption and searchable encryption. It not only allows encrypted data to be access-controlled based on user attributes, but also supports keyword retrieval in an encrypted state. By introducing multiple independent key centers, the system can avoid single point failures and enhance the system's fault tolerance and security. Under this architecture, key generation, distribution, and management are jointly completed by multiple centers, greatly improving the security and flexibility of the system.

[0005] However, the introduction of multi-center key policy attribute encryption also brings a series of new technical challenges. For example, how to efficiently manage keys in a distributed environment, ensure the independence and collaboration of each key center, and how to ensure the forward security, backward security and query privacy of encrypted data in a multi-user, multi-key center environment are all problems that need to be solved urgently. In addition, in practical applications, how to design a secure and efficient distributed key policy ciphertext retrieval system to support large-scale concurrent retrieval requests is also a research focus in this field. Therefore, for distributed multi-center environments, combining key policy attribute encryption and searchable encryption technology to design an efficient and secure ciphertext retrieval system is of great significance to improving the level of data privacy protection and retrieval efficiency in cloud storage. Summary of the invention

[0006] In view of the above requirements for searchable encryption, privacy security, distributed security, etc. and the drawbacks of the above traditional solutions, the present invention provides a data encryption and ciphertext retrieval method of a distributed multi-center organization.

[0007] The technical solution adopted by the data confidentiality method of the present invention is: a data encryption method of a distributed multi-center mechanism, applied to a data encryption and retrieval system; the data encryption and retrieval system participating entities include data users, distributed multi-center mechanisms and cloud servers; and includes the following stages:

[0008] During the system initialization phase, the security parameter λ and the number of central agencies K are input, and the initialization process generates the system public parameters par , No. k The public key PK of a central institution k and the master key MK k , and expose the parameters par Provided to system participating entities;

[0009] Key generation phase, central agency k Enter system public parameters par , master key MK k , the data user's identifier , and access structures , and finally output the private key of the data user ;

[0010] During the encryption phase, the cloud server performs encryption operations and first enters the system public parameters par , Central Institution k The public key PK k , a large set of attributes , and the plaintext message msg, and finally output the encrypted ciphertext CT;

[0011] In the decryption phase, the data user inputs the encrypted ciphertext CT associated with the large attribute set S, as well as the user's private key , and finally output the decrypted plaintext message msg or the termination symbol of decryption failure .

[0012] As a preference, during the system initialization phase, a large attribute set is first defined. ,in , m is the total number of elements in the attribute set, each attribute Contains the attribute name n i and attribute values v i ; Define access structure , where M is a l ×n Shared matrix, M i The corresponding matrix i row, π is a matrix i Line M i Mapped into a mapping function of attribute π(i), each attribute Also include the attribute name and attribute values ; Property value v i and The ciphertext and key will not be exposed; definition and are two hash functions, To map a string of arbitrary length into a positive integer group of order p In; define G1, G2 and G T is a prime number of order three p The multiplicative cyclic group of are the corresponding generators of groups G1 and G2 respectively, For bilinear pairing operation; input security parameter , number of central institutions , choose a random number , For the stage p The positive integer group; for each central institution k ∈[K] calculates the generated value , set the system public parameters to , open central agency k The public key , save the private key .

[0013] Preferably, during the key generation phase, when the data user Request and Access Structure The associated private key, where , Indicates attribute related l ×n shared matrix, Represents a matrix δ Rows are mapped to an attribute The mapping function of each attribute Include attribute name and attribute values ,in u An identifier representing the user, k The label of the central organization; enter the public parameters , private key , the central agency generates the data user private key ,in , , ; Indicates a n -1 dimensional vector, where all vector elements belong to the integer group, || represents the cascade connection operation symbol; k∈[N].

[0014] Preferably, during the encryption phase, the public parameters are input , public key , attribute set , where i∈[m], m The total number of elements in the attribute set and the input message msg, which will eventually generate the ciphertext ;in , are the random values ​​selected respectively; , is a continuous multiplication function.

[0015] Preferably, in the decryption stage, the input and attribute set Related ciphertext , and the user's private key , first determine whether there is an attribute set , we can find the constant Make , and finally decrypted to get ,in Indicated by k Central institutions for users u The generated private key, CT is the ciphertext stored by the cloud server, u i corresponds to the i-th attribute.

[0016] The technical solution adopted by the ciphertext retrieval method of the present invention is: a distributed multi-center mechanism ciphertext retrieval method, applied to a data encryption and retrieval system; the data encryption and retrieval system participating entities include data users, distributed multi-center mechanisms and cloud servers; and includes the following stages:

[0017] During the system initialization phase, the security parameter λ and the number of central agencies K are input, and the initialization process generates the system public parameters par , No. k The public key PK of a central institution k and the master key MK k , and expose the parameters par Provided to system participating entities;

[0018] Key generation phase, central agency k Enter system public parameters par , master key MK k , the data user's identifier , and access structures , and finally output the trapdoor of the data user ;

[0019] In the encryption phase, the cloud server performs encryption operations and first inputs the system public parameters par , Central Institution k The public key PK k , keyword set T, and plaintext message msg, and finally output encrypted ciphertext CT;

[0020] In the search and matching phase, the data user inputs the encrypted ciphertext CT related to the keyword set T, as well as the data user’s trapdoor , and finally output the search results, where 1 is output if the match is successful, otherwise 0 is output.

[0021] As a preferred embodiment, during the system initialization phase, a keyword set is first defined. ,in , m is the total number of elements in the keyword set, each keyword Contains keyword name n i and keyword values v i ; Define keyword structure A=(M,π,{π( i )}), where M is a l × n Shared matrix, M i The corresponding matrix i row, π is a matrix M i Mapped into a keyword π( i ) mapping function; each keyword Include keyword names and keyword values ;Keyword value v i and The ciphertext and key will not be exposed; definition and are two hash functions, To map a string of arbitrary length into a positive integer group of order p In; define G1, G2 and G T is a prime number of order three p The multiplicative cyclic group of are the corresponding generators of groups G1 and G2 respectively, is the bilinear pairing operation;

[0022] Enter security parameters , number of central institutions , choose a random number , For the stage p The positive integer group; for each central institution k ∈[K] calculates the generated value , set the system public parameters to , open central agency k The public key , save the private key .

[0023] Preferably, during the key generation phase, when the data user Request and Access Structure Related keywords: trapdoor, among which , Indicates keyword related l ×n shared matrix, Represents a matrix Rows are mapped to a keyword The mapping function of each keyword Include keyword names and keyword values ,in u An identifier representing the user, k The label of the central organization; enter the public parameters , private key , the central agency executes the algorithm to generate data user keyword trap ,in k ∈[N], , , ; Indicates a n -1-dimensional vectors, where all vector elements belong to the integer group, Represents the cascade connection operation symbol.

[0024] Preferably, during the encryption phase, the public parameters are input , public key , and keyword sets ,in , m is the total number of elements in the keyword set; finally, an encrypted index is generated ;in , , are the random values ​​selected respectively; , is a continuous multiplication function.

[0025] Preferably, in the search and matching stage, the input and the keyword set Related Encryption Indexes , and user trapdoors , first determine whether there is an attribute set , we can find the constant Make , and finally decrypted to get ,if , then it indicates that the match is successful and outputs 1, otherwise it outputs 0. Indicated by k Central institutions for users u The generated trapdoor, CT is the encrypted index stored in the cloud server, u i For the corresponding attribute keywords.

[0026] Compared with the prior art, the advantages and positive effects of the present invention are mainly reflected in the following aspects:

[0027] (1) The present invention proposes a key policy attribute encryption method for multiple centers. The invention realizes efficient key policy attribute encryption under multiple authorization centers, solves the privacy and security risks such as system crash and single point failure in a single center scenario, and enhances system security.

[0028] (2) The present invention provides a distributed multi-center key policy ciphertext retrieval method, which solves the risk of keyword privacy leakage in traditional searchable encryption schemes. The invention effectively protects keyword privacy by hiding policies, designs a multi-institution center architecture to generate trapdoors, effectively prevents single point collapse and other problems, and at the same time improves the efficiency of trapdoor generation and enhances the practicality of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The technical solution of this article is further described using embodiments and specific implementation methods. In addition, some drawings are also used in the process of describing the technical solution. For those skilled in the art, other drawings and the intention of the present invention can also be obtained based on these drawings without paying creative work.

[0030] Figure 1 It is a framework diagram of a key policy attribute encryption method of a multi-center institution in an embodiment of the present invention;

[0031] Figure 2 It is a structural diagram of the key policy ciphertext retrieval method of a distributed multi-center organization in an embodiment of the present invention. DETAILED DESCRIPTION

[0032] In order to facilitate the understanding and implementation of the present invention by those skilled in the art, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the implementation examples described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.

[0033] The present invention provides a distributed multi-center data encryption and ciphertext retrieval method, which is applied to a data encryption and retrieval system, wherein the system participating entities include data users, distributed multi-center organizations and cloud servers.

[0034] Please see Figure 1 , this embodiment provides a distributed multi-center data encryption method, including the following stages:

[0035] During the system initialization phase, the security parameter λ and the number of central agencies K are input, and the initialization process generates the system public parameters par , No. k The public key PK of a central institution k and the master key MK k , and expose the parameters par Provided to system participating entities;

[0036] In one embodiment, during the system initialization phase, a large attribute set is first defined. ,in , m is the total number of elements in the attribute set, each attribute Contains the attribute name n i and attribute values v i ; Define access structure , where M is a l × n Shared matrix, M i The corresponding matrix i row, π is a matrix i Line M i Mapped into a mapping function of attribute π(i), each attribute Also include the attribute name and attribute values ; Property value v i and The ciphertext and key will not be exposed; definition and are two hash functions, To map a string of arbitrary length into a positive integer group of order p In; define G1, G2 and G T is a prime number of order three pThe multiplicative cyclic group of are the corresponding generators of groups G1 and G2 respectively, For bilinear pairing operation; input security parameter , number of central institutions , choose a random number , For the stage p The positive integer group; for each central institution k ∈[K] calculates the generated value , set the system public parameters to , open central agency k The public key , save the private key .

[0037] Key generation phase, central agency k Enter system public parameters par , master key MK k , the data user's identifier , and access structures , and finally output the private key of the data user ;

[0038] In one embodiment, during the key generation phase, when the data user Request and Access Structure The associated private key, where , Indicates attribute related l ×n shared matrix, Represents a matrix δ Rows are mapped to an attribute The mapping function of each attribute Include attribute name and attribute values ,in u An identifier representing the user, k The label of the central organization; enter the public parameters , private key , the central agency generates the data user private key ,in , , ; Indicates a n -1 dimensional vector, where all vector elements belong to the integer group, || represents the cascade connection operation symbol; k∈[N].

[0039] During the encryption phase, the cloud server performs encryption operations and first enters the system public parameters par , Central Institution kThe public key PK k , a large set of attributes , and the plaintext message msg, and finally output the encrypted ciphertext CT;

[0040] In one embodiment, during the encryption phase, the public parameters are input , public key , attribute set , where i∈[m], m The total number of elements in the attribute set and the input message msg, which will eventually generate the ciphertext ;in , are the random values ​​selected respectively; , is a continuous multiplication function.

[0041] In the decryption phase, the data user inputs the encrypted ciphertext CT associated with the large attribute set S, as well as the user's private key , and finally output the decrypted plaintext message msg or the termination symbol of decryption failure .

[0042] In one embodiment, during the decryption phase, the input and attribute set Related ciphertext , and the user's private key , first determine whether there is an attribute set , we can find the constant Make , and finally decrypted to get ,in Indicated by k Central institutions for users u The generated private key, CT is the ciphertext stored by the cloud server, u i For the corresponding i attributes.

[0043] Please see Figure 2 This embodiment provides a distributed multi-center ciphertext retrieval method, which specifically includes the following stages:

[0044] During the system initialization phase, the security parameter λ and the number of central agencies K are input, and the initialization process generates the system public parameters par , No. k The public key PK of a central institution k and the master key MK k , and expose the parameters par Provided to system participating entities;

[0045] In one embodiment, during the system initialization phase, a keyword set is first defined. ,in , m is the total number of elements in the keyword set, each keyword Contains keyword name n i and keyword values v i ; Define keyword structure A=(M,π,{π( i )}), where M is a l × n Shared matrix, M i The corresponding matrix i row, π is a matrix M i Mapped into a keyword π( i ) mapping function; each keyword Include keyword names and keyword values ;Keyword value v i and The ciphertext and key will not be exposed; definition and are two hash functions, To map a string of arbitrary length into a positive integer group of order p In; define G1, G2 and G T is a prime number of order three p The multiplicative cyclic group of are the corresponding generators of groups G1 and G2 respectively, is the bilinear pairing operation;

[0046] Enter security parameters , number of central institutions , choose a random number , For the stage p The positive integer group; for each central institution k ∈[K] calculates the generated value , set the system public parameters to , open central agency k The public key , save the private key .

[0047] Key generation phase, central agency k Enter system public parameters par , master key MK k , the data user's identifier , and access structures , and finally output the trapdoor of the data user ;

[0048] In one embodiment, during the key generation phase, when the data user Request and Access Structure Related keywords: trapdoor, among which , Indicates keyword related l ×n shared matrix, Represents a matrix Rows are mapped to a keyword The mapping function of each keyword Include keyword names and keyword values ,in u An identifier representing the user, k The label of the central organization; enter the public parameters , private key , the central agency executes the algorithm to generate data user keyword trap ,in k ∈[N], , , ; Indicates a n -1-dimensional vectors, where all vector elements belong to the integer group, Represents the cascade connection operation symbol.

[0049] In the encryption phase, the cloud server performs encryption operations and first inputs the system public parameters par , Central Institution k The public key PK k , keyword set T, and plaintext message msg, and finally output encrypted ciphertext CT;

[0050] In one embodiment, during the encryption phase, the public parameters are input , public key , and keyword sets ,in , m is the total number of elements in the keyword set; finally, an encrypted index is generated ;in , , are the random values ​​selected respectively; , is a continuous multiplication function.

[0051] In the search and matching phase, the data user inputs the encrypted ciphertext CT related to the keyword set T, as well as the data user’s trapdoor , and finally output the search results, where 1 is output if the match is successful, otherwise 0 is output.

[0052] In one embodiment, during the search and matching phase, the input and the keyword set Related Encryption Indexes , and user trapdoors , first determine whether there is an attribute set , we can find the constant Make , and finally decrypted to get ,if , then it indicates that the match is successful and outputs 1, otherwise it outputs 0. Indicated by k Central institutions for users u The generated trapdoor, CT is the encrypted index stored in the cloud server, u i For the corresponding attribute keywords.

[0053] This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the data encryption method of the distributed multi-center mechanism when executing the program.

[0054] This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the ciphertext retrieval method of the distributed multi-center mechanism when executing the program.

[0055] This embodiment also provides a software product, including a computer program, which implements the data encryption method of the distributed multi-center mechanism when executed by a processor.

[0056] This embodiment also provides a software product, including a computer program, which implements the distributed multi-center mechanism ciphertext retrieval method when executed by a processor.

[0057] The present invention is further described below through specific experiments.

[0058] This embodiment conducts extensive experimental analysis and randomly extracts relevant Wikipedia data sets into sub-data sets of different data sizes to evaluate the key generation phase, encryption index generation overhead, and search and matching phase computational overhead in the distributed multi-center data encryption and ciphertext retrieval system. The specific analysis is as follows:

[0059] The experiment was conducted under a 64-bit Ubuntu system, using a 1.70 GHz Intel Core i5-3337 processor and 2.00GB of memory, and using Stanford's pairing-based PBC cryptographic library. The experiment showed that the time to run an intra-group exponential operation E was 0.000836 seconds, and a bilinear pairing operation P and multiplication operation M took 0.005530 seconds and 0.000007 seconds respectively.

[0060] (1) All experiments in the experiment are tested based on the Wikipedia dataset, which includes 438,191 keywords, 26,922 documents, and a total of 16,127,503 keyword-document pairs. Based on this dataset, the experiment first extracts sub-datasets of different sizes according to the number of keywords and documents, to measure the impact of different dataset sizes on the computational overhead of related steps. The specific results are shown in Table 1:

[0061] Table 1: Sub-dataset extraction table

[0062]

[0063] (2) For the different data sets extracted above, the computational overhead of the trapdoor generation stage is further analyzed in the experiment. It can be seen that a total of intra-group exponential operations E and multiplication operations M need to be performed, among which a small number of hash operations are lightweight and the computational overhead is very small and can be ignored. From the experimental steps, it can be seen that when the number of central agencies is fixed, the computational overhead of the trapdoor generation stage is positively correlated with the number of keywords. The experiment was tested based on different sub-data sets. The test results are shown in Table 2. It can be seen that when the number of search keywords is 1000, the time to generate the trapdoor is only 0.838s. It is obvious that this stage is very efficient.

[0064] Table 2: Computational overhead of trapdoor generation phase

[0065]

[0066] (3) For the different data sets extracted above, the computational overhead of the encrypted index generation stage is further analyzed in the experiment. The core computational overhead involved includes the intra-group exponential operation E, the multiplication operation M and the bilinear pairing operation P. The computational overhead of the same lightweight hash operation is negligible. It can be seen from the experimental process that the number of central agencies is also fixed, and the computational overhead of the encrypted index generation stage also increases with the increase of the number of keywords. In the experiment, different sub-data sets extracted from the Wikipedia data set were tested respectively, and the number of central agencies was also fixed. The test results show that when the number of keywords increases from 1000 to 100000, the number of keyword-document pairs changes from 3511776 to 15367040, and the time consumed in the encrypted index generation stage changes from about 0.842s to 83.606s. It can be seen that the encrypted index generation process of the present invention is efficient.

[0067] Table 3: Computational overhead of encryption index generation phase

[0068]

[0069] (4) Finally, the experiment analyzed the impact of different data sets on the computational overhead of the search and matching phase. The experiment was also tested based on a sub-data set extracted from the Wikipedia data set. In the search and matching phase, multiplication operations, bilinear pairing operations, and exponential operations are involved. The operation time for a single execution is

[0070] 0.005530 seconds, 0.000007 seconds and 0.000836 seconds. The specific test results can be seen from Table 4 that the larger the matching keyword set, the greater the time overhead consumed in the search and matching process. When the number of keyword sets increases from 1000 to 100000, the time overhead of the search phase increases from 19.119s to 108.341s. It can be seen that the search overhead of the present invention is efficient.

[0071] Table 4: Computational overhead of the search and matching phase

[0072]

[0073] The present invention solves the security bottleneck and computing bottleneck existing in the single authorization center architecture in the traditional public key searchable encryption scheme, designs a key policy encryption method for distributed multi-center institutions, realizes the privacy security protection of key distribution by multiple authorization centers and optimizes the computing overhead of the key authorization process; the application of this method in the field of ciphertext retrieval can realize key policy ciphertext retrieval of distributed multi-center institutions, solves the privacy security risks of traditional single-center institutions, protects the privacy security of keywords, and optimizes the computing overhead of the trapdoor generation process, thereby further improving the system performance.

[0074] The present invention can provide users with a reliable and secure ciphertext retrieval method in cloud storage, data security, blockchain, industrial Internet and other fields.

[0075] It should be understood that the embodiments described above are part of the embodiments of the present invention, rather than all of the embodiments. In addition, the technical features in the various embodiments or single embodiments provided by the present invention can be combined with each other arbitrarily to form a feasible technical solution. Such combination is not restricted by the sequence of steps and / or the structural composition mode, but must be based on the ability of ordinary technicians in the field to implement. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such combination of technical solutions does not exist and is not within the protection scope required by the present invention.

[0076] It should be understood that the above description of the preferred embodiment is relatively detailed and cannot be regarded as limiting the scope of patent protection of the present invention. Under the enlightenment of the present invention, ordinary technicians in this field can also make substitutions or modifications without departing from the scope of protection of the claims of the present invention, which all fall within the scope of protection of the present invention. The scope of protection requested for the present invention shall be based on the attached claims.

Claims

1. A data encryption method for a distributed multi-center organization, applied to a data encryption and retrieval system, wherein the data encryption and retrieval system participating entities include data users, distributed multi-center organizations and cloud servers; characterized in that: The following phases are included: During the system initialization phase, the security parameter λ and the number of central agencies K are input, and the initialization process generates the system public parameters par , No. k The public key PK of a central institution k and the master key MK k , and expose system parameters par Provided to system participating entities; The system exposes parameters ,in and are two hash functions, To map a string of arbitrary length into a positive integer group of order p Medium; G1, G2 and G T is a prime number of order three p The multiplicative cyclic group of are the corresponding generators of groups G1 and G2 respectively, For bilinear pairing operation; select random numbers , For the stage p The group of positive integers of ; Key generation phase, central agency k Enter system public parameters par , master key MK k , the data user's identifier , and access structures , and finally output the private key of the data user ; In the key generation phase, when the data user Request and Access Structure The associated private key, where , Indicates attribute related l ×n shared matrix, Represents a matrix δ Rows are mapped to an attribute The mapping function of each attribute Include attribute name and attribute values ,in u An identifier representing the user, k The label of the central organization; enter the public parameters , private key , the central agency generates the data user private key ,in , , ; Indicates a n -1 dimensional vector, where all vector elements belong to the integer group, || represents the cascade connection operation symbol; k∈[N]; During the encryption phase, the cloud server performs encryption operations and first enters the system public parameters par , Central Institution k The public key PK k , a large set of attributes , and the plaintext message msg, and finally output the encrypted ciphertext CT; In the decryption phase, the data user inputs the encrypted ciphertext CT associated with the large attribute set S, as well as the data user's private key , and finally output the decrypted plaintext message msg or the termination symbol of decryption failure .

2. The data encryption method of a distributed multi-center mechanism according to claim 1, characterized in that: In the system initialization phase, a large attribute set is first defined. ,in , m is the total number of elements in the attribute set, each attribute Contains the attribute name n i and attribute values v i ; Define access structure , where M is a l × n Shared matrix, M i The corresponding matrix i row, π is a matrix i Line M i Mapped into a mapping function of attribute π(i), each attribute Also include the attribute name and attribute values ; Property value v i and No exposure to ciphertext and keys; input security parameters , number of central institutions For each central institution k ∈[K] calculates the generated value ; Public Central Institutions k The public key , save the private key .

3. The data encryption method of a distributed multi-center mechanism according to claim 2, characterized in that: In the encryption phase, public parameters are input , public key , attribute set , where i∈[m], m The total number of elements in the attribute set and the input message msg, which will eventually generate the ciphertext ;in , are the random values ​​selected respectively; , is a continuous multiplication function.

4. The data encryption method of a distributed multi-center mechanism according to claim 3 is characterized in that: In the decryption phase, the input and attribute set Related ciphertext , and the user's private key , first determine whether there is an attribute set , we can find the constant Make , and finally decrypted to get ,in Indicated by k Central institutions for users u The generated private key, CT is the ciphertext stored by the cloud server, u i For the corresponding i attributes.

5. A distributed multi-center ciphertext retrieval method, applied to a data encryption and retrieval system, wherein the data encryption and retrieval system participants include data users, distributed multi-center organizations and cloud servers; characterized in that: The following phases are included: During the system initialization phase, the security parameter λ and the number of central agencies K are input, and the initialization process generates the system public parameters par , No. k The public key PK of a central institution k and the master key MK k , and expose system parameters par Provided to system participating entities; The system exposes parameters ,in and are two hash functions, To map a string of arbitrary length into a positive integer group of order p Medium; G1, G2 and G T is a prime number of order three p The multiplicative cyclic group of are the corresponding generators of groups G1 and G2 respectively, For bilinear pairing operation; select random numbers , For the stage p The group of positive integers of ; Key generation phase, central agency k Enter system public parameters par , master key MK k , the data user's identifier , and access structures , and finally output the trapdoor of the data user ; In the key generation phase, when the data user Request and Access Structure Related keywords: trapdoor, among which , Indicates keyword related l ×n shared matrix, Represents a matrix Rows are mapped to a keyword The mapping function of each keyword Include keyword names and keyword values ,in u An identifier representing the user, k The label of the central organization; enter the public parameters , private key , the central agency executes the algorithm to generate data user keyword trap ,in k ∈[N], , , ; Indicates a n -1-dimensional vectors, where all vector elements belong to the integer group, Represents the cascade connection operation symbol; In the encryption phase, the cloud server performs encryption operations and first inputs the system public parameters par , Central Institution k The public key PK k , keyword set T, and plaintext message msg, and finally output encrypted ciphertext CT; In the search and matching phase, the data user inputs the encrypted ciphertext CT related to the keyword set T, as well as the data user’s trapdoor , and finally output the search results, where 1 is output if the match is successful, otherwise 0 is output.

6. The distributed multi-center ciphertext retrieval method according to claim 5, characterized in that: In the system initialization phase, we first define a large attribute set. ,in , m is the total number of elements in the attribute set, each attribute Contains the attribute name n i and attribute values v i ; Define access structure , where M is a l × n Shared matrix, M i The corresponding matrix i row, π is a matrix i Line M i Mapped into a mapping function of attribute π(i), each attribute Also include the attribute name and attribute values ; Property value v i and No exposure to ciphertext and keys; input security parameters , number of central institutions For each central institution k ∈[K] calculates the generated value ; Public Central Institutions k The public key , save the private key .

7. The distributed multi-center ciphertext retrieval method according to claim 6, characterized in that: In the encryption phase, public parameters are input , public key , and keyword sets ,in , m is the total number of elements in the keyword set; finally, an encrypted index is generated ;in , , are the random values ​​selected respectively; , is a continuous multiplication function.

8. The distributed multi-center ciphertext retrieval method according to claim 7, characterized in that: In the search matching stage, input and keyword set Related Encryption Indexes , and user trapdoors , first determine whether there is an attribute set , we can find the constant Make , and finally decrypted to get ,if , then it indicates that the match is successful and outputs 1, otherwise it outputs 0. Indicated by k Central institutions for users u The generated trapdoor, CT is the encrypted index stored in the cloud server, u i For the corresponding attribute keywords.

Citation Information

Patent Citations

  • Attribute-based encryption method for multiple authority centers

    CN103618728A

  • Multi-mechanism encryption method used in lattices for supporting strategy hiding

    CN108512662A