Attribute-based encryption method, system, device and storage medium

By designing an attribute-based encryption method in a cloud server, using a phased outsourcing decryption mechanism and conversion key, the problem of data users whose access permissions cannot be prevented from being decrypted by revoked is solved in the prior art, and the controllability of data user rights and high data security is achieved.

CN119675984BActive Publication Date: 2025-05-06ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510174925.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-06
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

The existing access control scheme cannot effectively prevent data users whose access permissions are revoked from decrypting past ciphertexts, and requires other data users to regularly update their private keys, making it difficult to control data user rights safely and conveniently.

Method used

By designing an attribute-based encryption method in a cloud server, it receives data access requests from data users, obtains user lists, determines the conversion key based on the user ID, decrypts the ciphertext once, cancels the access control layer information, and sends the user ID and decryption instructions to the trusted execution environment, performs secondary decryption, verifys access permissions and ciphertext legality, and finally, the data user decrypts three times to obtain the target data.

Benefits of technology

Effectively reduce the cost of decryption, realize the controllability of data user permissions, prevent users with revoked permissions from decrypting historical ciphertexts, enhance data security, and resist malicious attacks and side channel attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675984B_ABST
    Figure CN119675984B_ABST
Patent Text Reader

Abstract

The present application relates to an attribute-based encryption method, system, device and storage medium. The method includes: receiving a data access request from a data user, the data access request includes a user ID of the data user and a requested ciphertext, the ciphertext includes access control layer information and encrypted data layer information; obtaining a user list, determining a conversion key corresponding to the data user from the user list according to the user ID, and decrypting the ciphertext once according to the conversion key to obtain a primary conversion ciphertext; sending the user ID and the primary conversion ciphertext to a trusted execution environment, so that the trusted execution environment decrypts the primary conversion ciphertext twice to obtain a secondary conversion ciphertext, and sending a decryption instruction carrying the secondary conversion ciphertext to the data user; wherein the decryption instruction is used to instruct the data user to decrypt the secondary conversion ciphertext three times to obtain the target data. The use of this method can more safely and conveniently realize controllable data user permissions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of access control technology, and in particular to an attribute-based encryption method, system, device and storage medium. Background Art

[0002] Cloud storage service providers provide efficient and convenient remote data hosting services for end users with limited resources, effectively reducing the storage burden and maintenance costs of terminal devices. However, in data sharing scenarios, when other data users access these hosted data, they must use appropriate access control policies to prevent unauthorized access and ensure the security of private data.

[0003] However, in existing access control schemes, access rights are controlled by preventing data users whose access rights have been revoked from decrypting future ciphertexts through timestamps and private key updates.

[0004] However, based on existing technologies, it is impossible to prevent data users whose access rights have been revoked from decrypting past ciphertexts, and other data users are also required to update their private keys regularly. Therefore, how to more securely and conveniently achieve controllable data user permissions remains a key and challenging issue. Summary of the invention

[0005] Based on this, it is necessary to provide an attribute-based encryption method, system, device and storage medium that can more safely and conveniently implement controllable data user permissions in response to the above technical problems.

[0006] In a first aspect, the present application provides an attribute-based encryption method for use in a cloud server, comprising:

[0007] Receiving a data access request from a data user, the data access request including a user ID of the data user and a ciphertext of the request, the ciphertext including access control layer information and encrypted data layer information;

[0008] Obtain a user list, determine the conversion key corresponding to the data user from the user list according to the user identifier, and decrypt the ciphertext once according to the conversion key to obtain a converted ciphertext. The decryption is used to cancel the access control layer information in the ciphertext.

[0009] Sending the user identifier and the first conversion ciphertext to the trusted execution environment, so that the trusted execution environment performs a second decryption on the first conversion ciphertext to obtain a second conversion ciphertext, and sends a decryption instruction carrying the second conversion ciphertext to the data user;

[0010] The secondary decryption is used to verify the access rights of the data user and the legitimacy of the primary conversion ciphertext, and the decryption instruction is used to instruct the data user to decrypt the secondary conversion ciphertext three times to obtain the target data.

[0011] In one embodiment, the user list is a collection of legitimate data users, the user list includes user identifiers of legitimate data users, attribute sets corresponding to the legitimate data users, and conversion keys, and obtaining the user list and determining the conversion key corresponding to the data user from the user list according to the user identifier includes:

[0012] Obtaining user list status information, and obtaining a user list from the user list status information when the user list status information is verified to be reliable;

[0013] If the user identification is in the user list, it is determined that the data user has the data access right, and the conversion key corresponding to the data user is determined from the user list according to the user identification.

[0014] In one embodiment, decrypting the ciphertext once according to the conversion key to obtain a converted ciphertext includes:

[0015] The conversion key and ciphertext are input into a one-stage conversion algorithm, the access control layer in the ciphertext is cancelled, and a converted ciphertext is obtained. The one-stage conversion algorithm is used to match the attribute set of the data user with the access control layer of the ciphertext, and a converted ciphertext is obtained when the sharing conditions of the preset linear secret sharing scheme are met.

[0016] In one embodiment, the user list also includes a revocation key based on symmetric encryption encapsulation corresponding to the legitimate data user, and the user identifier and the primary conversion ciphertext are sent to the trusted execution environment so that the trusted execution environment performs secondary decryption on the primary conversion ciphertext to obtain the secondary conversion ciphertext, including:

[0017] The user ID and the first conversion ciphertext are sent to the trusted execution environment so that the trusted execution environment determines the data user's data access rights based on the user ID and the user list status information; if the data user has data access rights, the revocation key based on symmetric encryption encapsulation corresponding to the data user is determined from the user list according to the user ID; the revocation key and the first conversion ciphertext are input into the two-stage conversion algorithm to verify the legitimacy of the first conversion ciphertext, and the second conversion ciphertext is output if the first conversion ciphertext is legal.

[0018] In a second aspect, the present application also provides an attribute-based encryption system, including:

[0019] The system includes a key generation center, a cloud service provider, a data owner and a data user. The cloud service provider includes a storage module, a state module, a cloud server and a trusted execution environment.

[0020] The key generation center is used to execute the initialization algorithm to generate public and private keys and manage the user list;

[0021] The data owner is used to encrypt the target data according to the public key and the linear secret sharing scheme type access control policy to obtain the ciphertext, and store the ciphertext in the storage module of the cloud service provider. The ciphertext includes the access control layer information and the encrypted data layer information;

[0022] A cloud server is used to receive a data access request from a data user, wherein the data access request includes a user ID of the data user and a requested ciphertext; obtain a conversion key corresponding to the data user from a user list according to the user ID, and decrypt the ciphertext once according to the conversion key to obtain a first conversion ciphertext, wherein the first decryption is used to cancel the access control layer information in the ciphertext; send the user ID and the first conversion ciphertext to a trusted execution environment, so that the trusted execution environment performs a second decryption on the first conversion ciphertext to obtain a second conversion ciphertext, and send a decryption instruction carrying the second conversion ciphertext to the data user; wherein the second decryption is used to verify the access rights of the data user and the legitimacy of the first conversion ciphertext, and the decryption instruction is used to instruct the data user to perform a third decryption on the second conversion ciphertext to obtain the target data;

[0023] A trusted execution environment, for receiving the primary conversion ciphertext, performing secondary decryption on the primary conversion ciphertext to obtain secondary conversion ciphertext, and sending a decryption instruction carrying the secondary conversion ciphertext to a data user;

[0024] A data user is associated with a set of attribute sets. The data user is used to receive a decryption instruction and decrypt the secondary conversion ciphertext three times according to the decryption instruction to obtain target data.

[0025] In one of the embodiments, the key generation center is also used to determine a conversion key, a revocation key, and a decryption key based on the private key and the attribute set of the data user, send the conversion key and the revocation key to the cloud server to be stored in the state module, and send the decryption key to the data user, so that the data user decrypts the secondary conversion ciphertext three times based on the decryption key to obtain the target data.

[0026] In one of the embodiments, the key generation center is specifically used to update the user list when a new data user is added or a data user is revoked, and associate the user list with the current timestamp to generate user list status information, and store the user list status information in a status module of the cloud service provider.

[0027] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, any of the methods described in the first aspect is implemented.

[0028] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any of the methods described in the first aspect above.

[0029] In a fifth aspect, the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements any of the methods described in the first aspect above.

[0030] In the above-mentioned attribute-based encryption method, system, device and storage medium, the cloud server receives a data access request from a data user, the data access request includes the user identification of the data user and the requested ciphertext, the ciphertext includes access control layer information and encrypted data layer information; and obtains a user list, determines the conversion key corresponding to the data user from the user list according to the user identification, and decrypts the ciphertext once according to the conversion key to obtain a primary conversion ciphertext, and the primary decryption is used to cancel the access control layer information in the ciphertext; then the user identification and the primary conversion ciphertext are sent to a trusted execution environment, so that the trusted execution environment decrypts the primary conversion ciphertext twice to obtain a secondary conversion ciphertext, and sends a decryption instruction carrying the secondary conversion ciphertext to the data user; wherein the secondary decryption is used to verify the access rights of the data user and the legitimacy of the primary conversion ciphertext, and the decryption instruction is used to instruct the data user to decrypt the secondary conversion ciphertext three times to obtain the target data. In this way, by designing a phased outsourcing decryption mechanism, the most time-consuming attribute-based access control layer matching task in attribute-based encryption and decryption is delegated to a cloud server with abundant computing resources, and the high overhead of mapping in the ciphertext access control layer is eliminated based on the conversion key. The trusted execution environment is responsible for lightweight conversion operations, and the data user is responsible for performing three decryption operations. This can effectively solve the problem of high computational overhead in traditional access control schemes when acquiring target data. At the same time, by maintaining the user list, only data users in the user list can perform decryption operations, and data users whose permissions have been revoked cannot decrypt based on historical keys, which can more safely and conveniently achieve controllable data user permissions. Furthermore, the above method overcomes the dilemma of balancing high efficiency and high security in access control, and can resist collusion attacks between revoked users and malicious storage servers and side-channel attacks against trusted execution environments. The private key is divided into three parts, and the revocation key is used to ensure the security of user permission checks, while the decryption key ensures the security of complete data decryption. Even if the attribute set meets the access policy, the corresponding conversion key is stolen, and one of the revocation key or the decryption key is destroyed, the ciphertext cannot be completely decrypted, thereby ensuring the security of the target data. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0032] Figure 1 A diagram of an application environment of an attribute-based encryption method in an embodiment;

[0033] Figure 2 A schematic diagram of a flow chart of an attribute-based encryption method in one embodiment;

[0034] Figure 3 A schematic diagram of a flow chart of a step of determining a conversion key corresponding to a data user from a user list according to a user identifier in an embodiment;

[0035] Figure 4 It is a flowchart of an attribute-based encryption method in another embodiment;

[0036] Figure 5 A schematic diagram of the steps of determining the LSSS matrix in one embodiment;

[0037] Figure 6 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0038] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0039] Cloud storage service providers provide efficient and convenient remote data hosting services for end users with limited resources, effectively reducing the storage burden and maintenance costs of terminal devices. However, in data sharing scenarios, when other users access these hosted data, they must use appropriate access control policies to prevent unauthorized access and ensure the security of private data.

[0040] Attribute-Based Encryption (ABE), as a one-to-many public key encryption system, is widely used on public cloud storage servers and is a cutting-edge technology for implementing flexible and fine-grained access control over encrypted data. ABE is mainly divided into two types: Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and Key-Policy Attribute-Based Encryption (KP-ABE). CP-ABE allows the access policy formulated by the data owner to be bound to the ciphertext, and the attribute set of the data user to its decryption key. The ciphertext can only be decrypted if and only if the attribute set of the data user satisfies the access policy in the ciphertext, which is suitable for data sharing scenarios. KP-ABE operates in a way that the access policy and the attribute position are interchanged, that is, the access policy is bound to the key, and the attribute set is hidden in the ciphertext, which is more suitable for broadcast encryption scenarios.

[0041] However, the decryption cost is high in existing access control schemes, so how to achieve controllable data user permissions without relying on expensive decryption mechanisms remains a critical and challenging issue.

[0042] In view of this, the embodiment of the present application provides an attribute-based encryption method that can reduce the decryption cost. The attribute-based encryption method provided by the embodiment of the present application can be applied to Figure 1In the attribute-based encryption system 10 shown in the figure, the system includes a key generation center (Key Generation Center, KGC) 100, a cloud service provider (Cloud Service Provider, CSP) 110, a data owner (Data Owner, DO) 120 and a data user (Data User, DU) 130. The cloud service provider 110 includes a storage module (Storage) 111, a state module (State) 112, a cloud server (Server) 113 and a trusted execution environment (Trusted Execution Environment) The cloud service provider 110 includes a storage module 111 for storing the ciphertext of the target data in a storage module 111 of the cloud service provider 110, wherein the ciphertext includes access control layer information and encrypted data layer information; a cloud server 113 is used to receive a data access request from a data user 130, wherein the data access request includes a user ID of the data user 130 and the requested ciphertext; a conversion key corresponding to the data user is obtained from the user list according to the user ID, and the ciphertext is decrypted once according to the conversion key to obtain a converted ciphertext, wherein the decryption is used to cancel the access control layer information in the ciphertext; and the user ID and the conversion key are converted into a converted ciphertext. The ciphertext is sent to the trusted execution environment 114, so that the trusted execution environment 114 performs a second decryption on the first-converted ciphertext to obtain a second-converted ciphertext, and sends a decryption instruction carrying the second-converted ciphertext to the data user 130; wherein the second decryption is used to verify the access rights of the data user 130 and the legitimacy of the first-converted ciphertext, and the decryption instruction is used to instruct the data user 130 to perform a third decryption on the second-converted ciphertext to obtain the target data; the trusted execution environment 114 is used to receive the first-converted ciphertext, perform a second decryption on the first-converted ciphertext to obtain a second-converted ciphertext, and send a decryption instruction carrying the second-converted ciphertext to the data user; the data user 130 is associated with a set of attribute sets, and the data user 130 is used to receive the decryption instruction, and perform a third decryption on the second-converted ciphertext according to the decryption instruction to obtain the target data.

[0043] In an exemplary embodiment, Figure 2 As shown, an attribute-based encryption method is provided, which is applied to Figure 1 The cloud server in the example is used to illustrate, including the following steps 201 to 203. Among them:

[0044] Step 201: Receive a data access request from a data user.

[0045] The data access request includes the user identification of the data user and the ciphertext of the request, and the ciphertext includes access control layer information and encrypted data layer information.

[0046] Optionally, a data user may send a data access request to a cloud service provider. After receiving the data access request, the cloud service provider processes the data access request of the data user by means of a cloud server, including parsing the data user's user identification (UID) and the requested ciphertext C from the data access request, and saving the user identification record. At the same time, the ciphertext C is retrieved from the storage module. Thus, if the ciphertext is retrieved from the storage module, a subsequent decryption process is performed. It can be understood that if the ciphertext does not exist in the storage module, there is no need to perform subsequent decryption.

[0047] Optionally, the encryption process of encrypting the target data to obtain the ciphertext C is introduced below:

[0048] Optionally, encryption of the target data is performed by the data owner, and optionally, the data owner defines an access policy associated with the target user. ,in represents the matrix strategy generated by the linear secret sharing scheme (LSSS), where It is a global access policy space. Then, the public key (Master Public Key, mpk) is used to execute the encryption algorithm to encrypt the target data, generate ciphertext, and store the ciphertext in the storage module.

[0049] Optionally, the target user may be any data user.

[0050] Optionally, the public key may be a global public key (Master Public Key, mpk), which may be generated by a key generation center during the initialization phase of the attribute-based encryption system, and a private key may be generated at the same time. The key generation center may broadcast public parameters such as the public key to other entities of the attribute-based encryption system.

[0051] Optionally, the key generation center can be fully trusted.

[0052] In a possible implementation, the key generation center may generate a public key by: using a security parameter and an attribute space As input, through the preset initialization algorithm, a global public key mpk and a global master private key (Master Private Key, msk) are output.

[0053] Optionally, the initialization algorithm can be implemented based on a bilinear map, which can set a multiplication cyclic group on a prime P-order elliptic curve , with generator g, there exists a bilinear map ,in It is another multiplicative cyclic group of prime order P based on elliptic curves. The initialization algorithm first selects two random parameters from the system attribute domain ,in, For the system attribute domain, select three hash functions , and , calculate and output the public key and private key .

[0054] Optionally, the above hash function is a mapping relationship, and the embodiment of the present application does not limit the form of the specific hash function.

[0055] Optional, g is a multiplicative cyclic group A generator of the multiplicative cyclic group All elements of are powers of g, if the mapping Satisfy the following properties:

[0056] 1) Bilinear: For any and ,have .

[0057] 2) Non-degenerate: .

[0058] 3) Computability: For any , which can effectively calculate .

[0059] The mapping e can be called an admissible bilinear map.

[0060] Optionally, when the data owner uses the public key to execute the encryption algorithm to encrypt the target data, the public key, the target data, and the LSSS access control policy can be used to encrypt the target data. As input, the target data M is a random 01 binary string of length k, that is, ,matrix , the dimension of the matrix is , is a mapping function that maps each row of the matrix to the attribute space In , where the definition .

[0061] Optionally, a random element is selected in the encryption algorithm and a random vector , where s is the secret value, , then calculate ,Then, generate the ciphertext according to the above parameters.

[0062] Optionally, the ciphertext may include data ciphertext layer information (used to encrypt data) and access control layer information (used to restrict access), where the ciphertext layer includes , and , represents a bit-by-bit XOR operation, the access control layer can include two The ciphertext Used to hide the secret s, where a random Random numbers , and finally get the ciphertext .

[0063] in,

[0064]

[0065] Optionally, the linear secret sharing scheme LSSS has the ability to hide the plaintext string access policy and can flexibly transform the traditional threshold access tree into a matrix-type monotone access structure, thereby achieving more flexible access control in the highly expressive CP-ABE. Optionally, for an attribute space Secret sharing scheme on , if there exists a binary , where rows and columns are The matrix and a mapping function , so that for any random vector (where s stands for secret, are other random integers), the matrix With vector The product of can hide the secret s in the attribute label of each row, and The attribute label belonging to the i-th row of the matrix (i.e. ). Let a tuple The scheme denoted as LSSS, for any set of authorization attributes , if there exists a set of valid shares ,in , and there exists an efficient algorithm for computing a set of vectors ,satisfy Then, when the vector Exists, then the formula From the effective share Recover the secret.

[0066] Step 202, obtain a user list, determine a conversion key corresponding to the data user from the user list according to the user identifier, and decrypt the ciphertext once according to the conversion key to obtain a converted ciphertext.

[0067] Among them, one decryption is used to cancel the access control layer information in the ciphertext.

[0068] Optionally, the user list may include user identifications of registered data users and conversion keys corresponding to the data users, which may be stored in the storage module.

[0069] Optionally, the user list may be created and maintained by the key generation center, and the user list may be updated when a new data user is registered or the authority of an old data user is revoked, so as to ensure the reliability of the user list.

[0070] Optionally, the user list may include at least one column. When the user list is multiple columns, one column is the user identification of the data user, and the other column is the transition key (Transition Key, TK) corresponding to the data user. When the user list is one column, the user identification information and the corresponding transition key can be combined. The embodiment of the present application does not limit the form of the user list.

[0071] Optionally, the conversion key may be a key generated for each data user by a key generation center according to a preset key generation algorithm and associated with an attribute set of the data user.

[0072] Optionally, a preset key generation algorithm can take the private key and the attribute set of the data user as input, output the conversion key, select the random number , convert the key ,in, They can be calculated by the following formulas:

[0073]

[0074]

[0075] Optionally, the ciphertext may be decrypted once according to the conversion key to obtain a converted ciphertext.

[0076] Step 203: Send the user identifier and the first conversion ciphertext to the trusted execution environment, so that the trusted execution environment performs a second decryption on the first conversion ciphertext to obtain a second conversion ciphertext, and sends a decryption instruction carrying the second conversion ciphertext to the data user.

[0077] The secondary decryption is used to verify the access rights of the data user and the legitimacy of the primary conversion ciphertext, and the decryption instruction is used to instruct the data user to decrypt the secondary conversion ciphertext three times to obtain the target data.

[0078] Optionally, the trusted execution environment can be a computing environment that provides isolation and protection for sensitive data in hardware, can be an isolated area demarcated in the processor of a cloud server, or can be other computing devices, which is not limited in the embodiments of the present application.

[0079] Alternatively, the trusted execution environment can be considered as a white-box model, that is, the trusted execution environment only guarantees the integrity of the internal state (code and data), but does not protect the confidentiality (other states except for proofs, signatures, and keys), thereby avoiding the potential secret leakage problem of the trusted execution environment.

[0080] Optionally, in the above step 202, when the key generation center executes the preset key generation algorithm to generate the conversion key, it also generates a revocation key (Revocation Key, RK) and a decryption key (DecryptionKey, DK) corresponding to the data user, wherein the revocation key can be , the decryption key can be .

[0081] Optionally, the cloud server can send the user identification and the first conversion ciphertext to the trusted execution environment. After the trusted execution environment receives the user identification and the first conversion ciphertext, it can determine the revocation key based on the user identification, and then perform a second decryption based on the revocation key and the first conversion ciphertext to obtain the second conversion ciphertext.

[0082] Optionally, before performing secondary decryption, the trusted execution environment needs to determine whether the data user's permissions have been updated based on the user identifier. If the data user's permissions are revoked before secondary decryption, there is no need for secondary decryption and the current data access request can be rejected.

[0083] In one possible implementation, when determining whether the data user's permissions have been updated, a comparison can be made between the current system time and the update time of the user list. If the time difference between the update time of the user list and the current system time is less than a preset threshold, it can be considered that the user list has been updated. Then, based on the user identifier and the updated user list, it is determined whether the permissions of the current data user have been revoked. If the time difference between the update time of the user list and the current system time is greater than or equal to the preset threshold, it can be considered that the user list has not been updated. At this time, the permissions of the current data user have not been updated.

[0084] In another possible implementation, it is possible to directly determine whether the current data user's permissions are revoked based on the user ID and the user list. That is, if the user ID exists in the user list, the current data user's permissions are not updated; if the user ID does not exist in the user list, the current data user's permissions are revoked.

[0085] Optionally, after verifying the access rights of the data user, it is necessary to verify the legitimacy of the first conversion ciphertext according to the preset ciphertext legitimacy verification method to check whether the first conversion ciphertext generated by the cloud server is legal. Only after determining that the first conversion ciphertext is legal, will a second decryption be performed to obtain the secondary conversion key.

[0086] Optionally, the trusted execution environment decrypts the primary ciphertext twice to obtain a secondary converted ciphertext, and generates a decryption instruction based on the secondary converted ciphertext and the user identifier, and sends the decryption instruction to the data user. After receiving the decryption instruction, the data user can decrypt the secondary converted ciphertext three times according to the three-way decryption algorithm and the decryption key held by the data user, thereby obtaining the target data.

[0087] In the above attribute-based encryption method, the cloud server receives a data access request from a data user, the data access request includes a user ID of the data user and a ciphertext of the request, the ciphertext includes access control layer information and encrypted data layer information; and obtains a user list, determines a conversion key corresponding to the data user from the user list according to the user ID, and decrypts the ciphertext once according to the conversion key to obtain a primary conversion ciphertext, and the primary decryption is used to cancel the access control layer information in the ciphertext; then the user ID and the primary conversion ciphertext are sent to a trusted execution environment, so that the trusted execution environment performs a secondary decryption on the primary conversion ciphertext to obtain a secondary conversion ciphertext, and sends a decryption instruction carrying the secondary conversion ciphertext to the data user; wherein the secondary decryption is used to verify the access rights of the data user and the legitimacy of the primary conversion ciphertext, and the decryption instruction is used to instruct the data user to decrypt the secondary conversion ciphertext three times to obtain the target data. In this way, by designing a phased outsourcing decryption mechanism, the private key is divided into three parts, corresponding to three decryption processes. The most time-consuming attribute-based access control layer matching task in attribute-based encryption and decryption is delegated to a cloud server with abundant computing resources. The high overhead of mapping in the ciphertext access control layer is eliminated based on the conversion key. The trusted execution environment is responsible for lightweight conversion operations, and the revocation key is used to ensure the security of user permission checks. The data user is responsible for performing three decryption operations. In this way, when acquiring target data, the problem of high computational overhead in traditional access control schemes can be effectively solved. At the same time, by maintaining the user list, only data users in the user list can perform decryption operations. Data users whose permissions have been revoked cannot decrypt based on historical keys, which can more safely and conveniently realize controllable data user permissions. Furthermore, the above method overcomes the dilemma of balancing high efficiency and high security in access control, and can resist collusion attacks between revoked users and malicious storage servers and side-channel attacks against trusted execution environments. The private key is divided into three parts, and the revocation key is used to ensure the security of user permission checks, while the decryption key ensures the security of complete data decryption. Even if the attribute set meets the access policy, the corresponding conversion key is stolen, and one of the revocation key or the decryption key is destroyed, the ciphertext cannot be completely decrypted, thereby ensuring the security of the target data.

[0088] In an exemplary embodiment, Figure 3 As shown, optionally, the user list is a collection of legitimate data users, the user list includes user identifiers of legitimate data users, attribute sets corresponding to legitimate data users, and conversion keys, obtaining the user list, and determining the conversion keys corresponding to the data users from the user list according to the user identifiers, including the following steps 301 to 302. Among them:

[0089] Step 301, obtaining user list status information, and obtaining a user list from the user list status information when the user list status information is verified to be reliable.

[0090] Optionally, the legal data user may be a registered data user and a data user authorized to have access rights.

[0091] Optionally, the user list status information may be stored in a status module, and the user list status information is created and maintained by a key generation center.

[0092] Optionally, the key generation center can generate user list status information ,in, is the user list generated at time i, is the key generation center at time i A signature of a user list, wherein a user list status information can be generated at each time interval (such as hour, day, etc.), or a user list status information can be generated when there is a new registered data user or the old user's authority is revoked.

[0093] Optionally, there may be multiple user list status information in the status module, and previous user list status information may be deleted when storing new user list status information so that there is only one user list status information in the status module, which is not limited in the present application.

[0094] Optionally, if there are multiple user list status information, that is, multiple candidate user list status information, the latest user list status information can be retrieved from the status module, and then whether the user list status information is reliable can be determined based on the signature.

[0095] Optionally, retrieving the user list status information at the latest moment from the status module can be by sorting each candidate user list status information according to time i to determine the user list status information at the latest moment; or it can be by calculating the difference between time i in each candidate user list status information and the current system time, and taking the user list status information with the smallest difference as the user list status information at the latest moment.

[0096] Optionally, the status module can forward the latest user list status information to the cloud server and the trusted execution environment. It can be forwarded when a request is received, or it can be actively forwarded when the user list status information is updated. This is not limited in the embodiments of the present application.

[0097] Optionally, after determining the user list status information, determine the user list from the user list status information .

[0098] Step 302: If the user identifier is in the user list, it is determined that the data user has data access rights, and a conversion key corresponding to the data user is determined from the user list according to the user identifier.

[0099] Optionally, the user list may include a user ID, a set of attributes corresponding to the data user, and a conversion key:

[0100]

[0101] Where UID is the user ID of each registered data user. It represents the set of legal data users. represents the attribute set of the data user, Represents the conversion key of the data user.

[0102] Optionally, when it is determined that the data user has the data access right, the conversion key corresponding to the data user may be determined from the user list according to the user identifier of the data user.

[0103] The above-mentioned acquisition of user list status information, when verifying that the user list status information is reliable, obtains the user list from the user list status information; if the user identifier is in the user list, it is determined that the data user has the data access right, and determines the conversion key corresponding to the data user from the user list according to the user identifier; by introducing a trusted third-party key generation center, the third-party key generation center generates and maintains the user list status information associated with the data user, and when acquiring the user list, verifies the reliability of the user list through the signature; there is no need to rely on the delegation work of introducing timestamps to update all ciphertexts through the storage server, nor is there any need to update the keys of other users when the data user is revoked; the user list can be updated when a new data user is registered or the old user's authority is revoked, which can more safely and conveniently realize the controllable data user authority.

[0104] In an exemplary embodiment, optionally, decrypting the ciphertext once according to the conversion key to obtain a converted ciphertext includes:

[0105] The conversion key and the ciphertext are input into the one-stage conversion algorithm, the access control layer in the ciphertext is cancelled, and a conversion ciphertext is obtained.

[0106] Among them, the one-stage conversion algorithm is used to match the attribute set of the data user with the access control layer of the ciphertext, and when the sharing conditions of the preset linear secret sharing scheme are met, a converted ciphertext is obtained.

[0107] Optionally, the one-stage conversion algorithm can be implemented based on a linear secret sharing scheme LSSS, where the sharing condition of the preset linear secret sharing scheme can be that there is a set of vectors ,satisfy , you can set the collection For each attribute label in attribute set A in the matrix The distribution of ,satisfy , otherwise the attribute set A does not satisfy the access strategy ( ), it will prompt failure.

[0108] Optionally, after determining that the vector exists When , you can output a conversion ciphertext ,in, is the information of the ciphertext layer, and It can be determined by the ciphertext layer information, access control layer information and conversion key TK according to the following formula:

[0109]

[0110]

[0111] In an exemplary embodiment, optionally, the user list also includes a revocation key based on symmetric encryption encapsulation corresponding to the legitimate data user, and the user identifier and the primary conversion ciphertext are sent to the trusted execution environment so that the trusted execution environment performs secondary decryption on the primary conversion ciphertext to obtain the secondary conversion ciphertext, including:

[0112] The user ID and the first conversion ciphertext are sent to the trusted execution environment so that the trusted execution environment determines the data user's data access rights based on the user ID and the user list status information; if the data user has data access rights, the revocation key based on symmetric encryption encapsulation corresponding to the data user is determined from the user list according to the user ID; the revocation key and the first conversion ciphertext are input into the two-stage conversion algorithm to verify the legitimacy of the first conversion ciphertext, and the second conversion ciphertext is output if the first conversion ciphertext is legal.

[0113] Optionally, the user list also includes a revocation key based on symmetric encryption encapsulation, i.e.

[0114]

[0115] in, It is a symmetric authentication encryption key shared by the remote attestation mechanism between the key generation center and the trusted execution environment. This indicates the revocation key encapsulated using symmetric encryption.

[0116] Optionally, the cloud server sends the user identification and the one-time conversion ciphertext to the trusted execution environment, so that the trusted execution environment determines the access rights of the data user according to the user identification and the user list status information.

[0117] Optionally, the trusted execution environment may obtain user list status information from the storage module, and obtain a user list from the user list status information after verifying that the user list status information is reliable. If the user identifier is in the user list, it is determined that the data user has data access rights.

[0118] Optionally, when the data user has data access rights, the revocation key based on symmetric encryption encapsulation can be determined from the user list according to the user identification, and then decrypted based on the symmetric authentication encryption key to obtain the revocation key.

[0119] Optionally, after the data user authority verification is passed, a two-stage conversion algorithm is used to verify the legitimacy of the first conversion ciphertext, and a second conversion ciphertext is output. When the data user authority verification fails, the trusted execution environment no longer performs subsequent decryption operations.

[0120] Optionally, the two-stage conversion algorithm can use the revocation key to check whether the converted ciphertext is legal without fully decrypting it. middle Calculation and Related, Calculation and Related, while revoking the key , so we can calculate and , and verify the condition Is the relationship established? , it indicates that the ciphertext conversion is legal.

[0121] Optionally, after verifying the legality of the first conversion ciphertext, the second conversion ciphertext can be output .

[0122] Optionally, after determining the secondary conversion ciphertext in the trusted execution environment, the data user may decrypt the secondary conversion ciphertext three times according to the decryption instruction sent by the trusted execution environment, using the decryption key and the secondary conversion ciphertext as input, where the decryption key is , output target data and ,in .

[0123] Optional, if and , the target data can be determined, otherwise the decryption fails.

[0124] Based on the same inventive concept, the embodiment of the present application also provides an attribute-based encryption system for implementing the attribute-based encryption method described above. The implementation scheme for solving the problem provided by the system is similar to the implementation scheme described in the above method. Therefore, the specific limitations in one or more system embodiments provided below can refer to the limitations of the attribute-based encryption method above, and will not be repeated here. The structure of the system can be referred to Figure 1 , including a key generation center 100, a cloud service provider 110, a data owner 120 and a data user 130, the cloud service provider 110 includes a storage module 111, a state module 112, a cloud server 113 and a trusted execution environment 114; wherein:

[0125] The key generation center 100 is used to execute an initialization algorithm to generate a public key and a private key, and manage a user list.

[0126] The data owner 120 is used to encrypt the target data according to the public key and linear secret sharing scheme type access control policy to obtain a ciphertext, and store the ciphertext in the storage module 111 of the cloud service provider 110. The ciphertext includes access control layer information and encrypted data layer information.

[0127] The cloud server 113 is used to receive a data access request from a data user 130, where the data access request includes a user identifier of the data user 130 and a requested ciphertext; obtain a conversion key corresponding to the data user from a user list according to the user identifier, and decrypt the ciphertext once according to the conversion key to obtain a first-conversion ciphertext, where the first decryption is used to cancel the access control layer information in the ciphertext; send the user identifier and the first-conversion ciphertext to the trusted execution environment 114, so that the trusted execution environment 114 performs a second decryption on the first-conversion ciphertext to obtain a second-conversion ciphertext, and sends a decryption instruction carrying the second-conversion ciphertext to the data user 130; wherein the second decryption is used to verify the access rights of the data user 130 and the legitimacy of the first-conversion ciphertext, and the decryption instruction is used to instruct the data user 130 to decrypt the second-conversion ciphertext three times to obtain the target data.

[0128] The trusted execution environment 114 is used to receive the primary conversion ciphertext, perform secondary decryption on the primary conversion ciphertext to obtain secondary conversion ciphertext, and send a decryption instruction carrying the secondary conversion ciphertext to the data user.

[0129] The data user 130 is associated with a set of attribute sets. The data user 130 is used to receive a decryption instruction and perform three decryptions on the secondary conversion ciphertext according to the decryption instruction to obtain target data.

[0130] In an exemplary embodiment, the key generation center is also used to determine the conversion key, revocation key and decryption key based on the private key and the attribute set of the data user, send the conversion key and revocation key to the cloud server to store in the status module, and send the decryption key to the data user, so that the data user can decrypt the secondary conversion ciphertext three times based on the decryption key to obtain the target data.

[0131] In an exemplary embodiment, the key generation center is specifically used to update the user list when a new data user is added or a data user is revoked, and associate the user list with the current timestamp to generate user list status information, and store the user list status information in a status module of the cloud service provider.

[0132] As an optional implementation, Figure 4 As shown, the attribute-based encryption method provided in the embodiment of the present application may include the following specific steps:

[0133] Step 401: The key generation center initializes the system, defines a global access policy space and a global attribute space, and generates a public key and a private key.

[0134] In step 402, the data owner encrypts the target data according to the public key and the linear secret sharing scheme type access control policy to obtain a ciphertext.

[0135] The ciphertext is stored in the storage module, and the ciphertext includes access control layer information and encrypted data layer information.

[0136] Step 403: The key generation center determines a conversion key, a revocation key, and a decryption key according to the private key and the attribute set of the data user.

[0137] In step 404, the key generation center performs remote authentication with the trusted execution environment, and symmetrically encrypts and encapsulates the revocation key according to the symmetric authentication encryption key shared by the remote attestation mechanism.

[0138] Step 405: The key generation center manages the user list status information according to the user identification of the data user, the attribute set of the data user, the conversion key and the symmetrically encrypted encapsulated revocation key.

[0139] When a new user is registered or the authority of an old user is revoked, a user list status information is generated and the user list information is updated.

[0140] Step 406: The cloud server receives a data access request from a data user.

[0141] The data access request includes the user ID of the data user and the ciphertext of the request.

[0142] Step 407: The cloud server obtains the user list status information, and when the user list status information is verified to be reliable, obtains the user list from the user list status information.

[0143] Step 408: If the user identifier is in the user list, the cloud server determines that the data user has data access rights, and determines the conversion key corresponding to the data user from the user list according to the user identifier.

[0144] In step 409, the cloud server inputs the conversion key and the ciphertext into a one-stage conversion algorithm, cancels the access control layer in the ciphertext, and obtains a converted ciphertext.

[0145] Among them, the one-stage conversion algorithm is used to match the attribute set of the data user with the access control layer of the ciphertext, and when the sharing conditions of the preset linear secret sharing scheme are met, a converted ciphertext is obtained.

[0146] In step 410, the cloud server sends the user identification and the one-time conversion ciphertext to the trusted execution environment.

[0147] Step 411: The trusted execution environment determines the data access permission of the data user according to the user identification and the user list status information.

[0148] Step 412: If the data user has data access rights, the trusted execution environment determines the revocation key based on symmetric encryption encapsulation corresponding to the data user from the user list according to the user identifier.

[0149] Step 413: The trusted execution environment inputs the revocation key and the first conversion ciphertext into the two-stage conversion algorithm, verifies the legitimacy of the first conversion ciphertext, and outputs the second conversion ciphertext if the first conversion ciphertext is legal.

[0150] In step 414, the trusted execution environment sends a decryption instruction carrying the secondary conversion ciphertext to the data user.

[0151] Step 415: After receiving the decryption instruction, the data user decrypts the secondary conversion ciphertext three times according to the decryption key to obtain the target data.

[0152] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0153] Exemplarily, the method comprises the following stages:

[0154] First, the system initialization phase: The key generation center creates and maintains the data user list UserList, which represents the authorized permissions. The list UserList is associated with a timestamp and recorded as the state st. Whenever it is updated, the key generation center uses a signature to prove the reliability of the list and stores it in the state module of the cloud service provider. Then, the key generation center executes the initialization algorithm to initialize the ElGamal encryption system and defines the global access policy space and the global attribute space For the convenience of calculation, in the examples of this application, the multiplication cyclic group and the bilinear mapping on the elliptic curve are generated based on the A-type elliptic curve (r: 20 bits, q: 64 bits). The specific values ​​of the parameters of the elliptic curve are as follows:

[0155]

[0156] Then, choose the generator , and randomly select a=231, b=567 as the pairing index of hidden information, and calculate:

[0157]

[0158]

[0159]

[0160] Declare three hash functions to indicate the mapping relationship. , and Finally, get the public key and private key and broadcast the public key to the cloud service provider, data owner, and data user DU.

[0161] Second, data encryption outsourcing stage: In order to effectively control the access rights of data users to target data, the data owner needs to define an LSSS access policy , which describes in detail the rules and conditions for access rights, ensuring that only users who meet specific conditions can access encrypted data. In this application example, the length of the plaintext space bit string k=256, and the data owner's encrypted message M is:

[0162]

[0163] In addition, the threshold access policy is a set of nested policies ((A,B,2),(C,D,E,3),(F,(G,H,2),1),2). The rightmost number 2 means that at least two conditions must be met in the following three sub-policies to meet the requirements of the overall access policy:

[0164] Strategy (A,B,2): requires that the data user's attribute set contains at least two attributes in the set {A,B}.

[0165] Strategy (C,D,E,3): requires that the data user's attribute set contains at least three attributes in the set {C,D,E}.

[0166] Strategy (F, (G, H, 2), 1): requires that the data user's attribute set contains at least one attribute from the set {F}, or satisfies the nested strategy (G, H, 2), that is, contains at least two attributes from the set {G, H}.

[0167] Then, if Figure 5 As shown in the figure, the threshold access strategy is used to generate an access control tree, and then transformed by the linear secret sharing scheme LSSS to form a new matrix access strategy. The specific expressions are as follows:

[0168]

[0169] Optionally, the access control tree can be converted into an LSSS matrix according to the Lewko-Waters algorithm , the access control tree can also be converted into an LSSS matrix according to the Liu-Cao-Wong algorithm , the embodiments of the present application do not limit this.

[0170] matrix of rows , column n = 6. Subsequently, the data owner uses the public key mpk to execute the encryption algorithm to encrypt the target data M.

[0171] Assuming that The element R=[5287446842473432484,1533198477521699665] is selected and hashed to get:

[0172]

[0173] Then, the secret value is calculated For ease of explanation, other random numbers are also selected in a simple way, for example, , , so we get Next, to hide the secret value s in the access policy In the calculation , , the final ciphertext C contains the information of the ElGamal data ciphertext layer (used to encrypt data) and the access control layer (used to restrict access). Among them, the ElGamal data ciphertext layer information is calculated:

[0174]

[0175] Calculate access control layer information:

[0176]

[0177]

[0178] Finally, the ciphertext The outsourced storage is stored in the storage module of the cloud service provider so that data users can access it according to the access policy requirements.

[0179] Third, key generation stage: In order to facilitate permission checking and realize the decryption of the outsourced part of the data user, the key generation center executes the key generation algorithm to generate a key for each data user with its attribute set. There are three types of keys associated with it: conversion key, revocation key and decryption key. For example, in the embodiment of the present application, the attribute set of the data user is A=(A, B, C, D, F), which has five attributes. Next, select , convert the key ,in,

[0180]

[0181]

[0182] Revoking a key and the decryption key Finally, the key generation center sends the decryption key to the data user through a secure channel, and stores the conversion key and the encapsulated revocation key in the user list state information st.

[0183] Fourth, data request access stage: Each data user is associated with a user ID to check whether the user has registered access control information with the key generation center, and to facilitate the retrieval of the user's record in the state module State. In the embodiment of the present application, on the basis that the data user has been registered (that is, the key generation center has generated three keys for it), a data access request is sent to the cloud service provider. The cloud service provider records the user ID of the data user, the storage module retrieves the requested ciphertext, and then forwards the user ID and ciphertext to the cloud server.

[0184] Fifth, the first stage of outsourced decryption: the cloud server receives the user ID and ciphertext, and retrieves the user list status information at the latest moment from the status module S. If the data user exists in the user list of this state, the cloud server extracts the conversion key from the user list. And because the attribute set A=(A,B,C,D,F) of the data user in this embodiment obviously satisfies the sub-strategy (A,B,2) and sub-strategy (F,(G,H,2),1) in ((A,B,2),(C,D,E,3),(F,(G,H,2),1),2), it also means that the overall access strategy is satisfied, and I={1,2,3,4,6}.

[0185] Optionally, the cloud server performs a one-stage conversion algorithm, first solving the matrix equation and calculating the condition of ,at this time

[0186]

[0187]

[0188]

[0189]

[0190]

[0191] Then, we get a converted ciphertext Finally, the decryption instruction carrying the user ID and the first conversion ciphertext is sent to the trusted execution environment.

[0192] Sixth, the second stage of outsourcing decryption: After receiving the decryption instruction, the trusted execution environment retrieves the latest user list status information st from the status module and verifies the integrity and freshness of st. Assuming that in the present application example, the user identifier exists in the user list of this state, the trusted execution environment extracts the revocation key from the user list. Subsequently, the trusted execution environment executes the two-stage conversion algorithm, using the revocation key RK, to check whether the converted ciphertext is legal without full decryption, that is, to calculate:

[0193] =[5499749376306853863,9444736379000478718]

[0194] =[5499749376306853863,9444736379000478718]

[0195] because , which means that the cloud server has executed the fifth step according to the rules, the first conversion ciphertext is legal, and the trusted execution environment will allow the subsequent steps to be executed. Output the second conversion ciphertext:

[0196]

[0197] Then, the secondary transformed ciphertext is sent to the data user.

[0198] Seventh, three-stage decryption: The data user receives the secondary conversion ciphertext and uses the decryption key to perform the three-stage decryption algorithm. Calculation:

[0199]

[0200]

[0201]

[0202]

[0203]

[0204]

[0205] The above calculation results meet the conditions: and , which means M is correct, and the target data can be obtained:

[0206]

[0207] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 6 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an attribute-based encryption method is implemented.

[0208] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0209] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps described in any of the above method embodiments when executing the computer program.

[0210] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps described in any of the above method embodiments are implemented.

[0211] In one embodiment, a computer program product is provided, including a computer program, which implements the steps described in any of the above method embodiments when executed by a processor.

[0212] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.

[0213] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0214] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. An attribute-based encryption method, characterized in that: Used in a cloud server, the method comprises: Receiving a data access request from a data user, wherein the data access request includes a user identifier of the data user and a ciphertext of the request, wherein the ciphertext includes access control layer information and encrypted data layer information; Obtaining a user list, determining a conversion key corresponding to the data user from the user list according to the user identifier, and decrypting the ciphertext once according to the conversion key to obtain a converted ciphertext, wherein the decryption once is used to cancel the access control layer information in the ciphertext; Sending the user identifier and the first conversion ciphertext to a trusted execution environment, so that the trusted execution environment performs a second decryption on the first conversion ciphertext to obtain a second conversion ciphertext, and sends a decryption instruction carrying the second conversion ciphertext to the data user; The secondary decryption is used to verify the access rights of the data user and the legitimacy of the primary conversion ciphertext, and the decryption instruction is used to instruct the data user to decrypt the secondary conversion ciphertext three times to obtain the target data; The decrypting the ciphertext once according to the conversion key to obtain a converted ciphertext comprises: Inputting the conversion key and the ciphertext into a one-stage conversion algorithm, canceling the access control layer in the ciphertext, and obtaining a first-stage conversion ciphertext, wherein the one-stage conversion algorithm is used to match the attribute set of the data user with the access control layer of the ciphertext, and obtaining the first-stage conversion ciphertext when a sharing condition of a preset linear secret sharing scheme is met; The user list also includes a revocation key based on symmetric encryption encapsulation corresponding to a legitimate data user, and the sending of the user identifier and the primary conversion ciphertext to a trusted execution environment so that the trusted execution environment performs secondary decryption on the primary conversion ciphertext to obtain a secondary conversion ciphertext includes: The user identifier and the first conversion ciphertext are sent to a trusted execution environment, so that the trusted execution environment determines the data access rights of the data user according to the user identifier and the user list status information; if the data user has the data access rights, the revocation key based on symmetric encryption encapsulation corresponding to the data user is determined from the user list according to the user identifier; the revocation key and the first conversion ciphertext are input into a two-stage conversion algorithm to verify the legitimacy of the first conversion ciphertext, and the second conversion ciphertext is output if the first conversion ciphertext is legal.

2. The method according to claim 1, characterized in that The user list is a collection of legal data users, and the user list includes user identifiers of the legal data users, attribute sets corresponding to the legal data users, and conversion keys. The acquiring of the user list, and determining the conversion key corresponding to the data user from the user list according to the user identifier, includes: Acquire user list status information, and when verifying that the user list status information is reliable, acquire a user list from the user list status information; If the user identification is in the user list, it is determined that the data user has data access rights, and a conversion key corresponding to the data user is determined from the user list according to the user identification.

3. An attribute-based encryption system, characterized in that: The system includes a key generation center, a cloud service provider, a data owner and a data user, wherein the cloud service provider includes a storage module, a state module, a cloud server and a trusted execution environment; The key generation center is used to execute the initialization algorithm to generate public keys and private keys, and manage the user list; The data owner is used to encrypt the target data according to the public key and the linear secret sharing scheme type access control policy to obtain a ciphertext, and store the ciphertext in a storage module of the cloud service provider, wherein the ciphertext includes access control layer information and encrypted data layer information; The cloud server is used to perform the steps of the attribute-based encryption method according to claim 1 or 2; The trusted execution environment is used to receive the first conversion ciphertext, perform a second decryption on the first conversion ciphertext to obtain a second conversion ciphertext, and send a decryption instruction carrying the second conversion ciphertext to the data user; The data user is associated with a set of attribute sets, and is used to receive a decryption instruction and decrypt the secondary conversion ciphertext three times according to the decryption instruction to obtain target data.

4. The system according to claim 3, characterized in that The key generation center is also used to determine a conversion key, a revocation key and a decryption key based on the private key and the attribute set of the data user, send the conversion key and the revocation key to the cloud server to be stored in the state module, and send the decryption key to the data user, so that the data user decrypts the secondary conversion ciphertext three times based on the decryption key to obtain the target data.

5. The system according to claim 3, characterized in that The key generation center is specifically used to update the user list when a new data user is added or a data user is revoked, and associate the user list with the current timestamp to generate user list status information, and store the user list status information in the status module of the cloud service provider.

6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to claim 1 or 2 are implemented.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to claim 1 or 2 are implemented.

8. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to claim 1 or 2 are implemented.

Citation Information

Patent Citations

  • Multi-authorization center access control method supporting strategy hiding and cloud storage system

    CN110099043A

  • System and method for providing an authorised third party with overt ledger secured key escrow access to a secret

    CN112673591A