A collaborative access control method, system, device, medium and product

By using the Chinese residual theorem to determine the secret share of access policies in the CP-ABE scheme, the problems of information leakage and inefficiency in collaborative access control are solved, and more efficient and secure access control is achieved.

CN119675991BActive Publication Date: 2025-05-23GUIZHOU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510180775.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-05-23
Estimated Expiration
2045-02-19

AI Technical Summary

Technical Problem

The existing CP-ABE schemes have problems such as information leakage, malicious user collusion and inefficiency in collaborative access control, especially in the collaborative scenarios of multiple access policies.

Method used

The Chinese residual theorem is used to determine the secret share of each node in the access strategy, and plaintext can be obtained when the access strategy is met or not, improving access efficiency.

Benefits of technology

Through this method, the security and efficiency of access control are improved, and the problems of information leakage and inefficiency in traditional solutions are solved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675991B_ABST
    Figure CN119675991B_ABST
Patent Text Reader

Abstract

The present application discloses a collaborative access control method, system, device, medium and product, which relates to the field of access control. The method comprises: determining the access policy of each data group, using a secret sharing algorithm and a Chinese remainder theorem to determine the secret share of each node; using the symmetric key of the data group to encrypt the data group to obtain the ciphertext of the data group; encrypting the symmetric key of the data group to obtain the ciphertext of the symmetric key of the data group; when the attribute of the current access user of the data group satisfies the access policy of the data group, and when the attribute of the current access user of the data group does not satisfy the access policy of the data group, and the current access user is a collaborative user, using different decryption methods to determine the secret share of the root node in the access policy; based on the secret share of the root node in the access policy, obtain the symmetric key of the data group; according to the symmetric key of each data group and the ciphertext of each data group, obtain the plaintext. The present application improves the efficiency of access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of access control, and in particular to a collaborative access control method, system, device, medium and product. Background Art

[0002] In recent years, a lot of research has been done on data access control and encryption in public cloud storage. Attribute-Based Encryption (ABE) is considered to be one of the most suitable solutions to solve the fine-grained access control of data on cloud storage servers because it can ensure the direct management of data by data owners and provide fine-grained access control. In the Ciphertext-Policy Attribute-Based Encryption (CP-ABE) scheme, each user is associated with a set of attributes, and each ciphertext is embedded with an access structure for certain selected attributes. The access structure is used to represent the specific access policy that should be satisfied when accessing the data content. The attribute set is used as the user's identity, where the user's role / responsibility can be represented by a single attribute or a set of attributes. Only when the user's attribute set satisfies the access structure can the user decrypt the ciphertext. Traditional CP-ABE sends the policy-related access structure along with the ciphertext, which makes any user who can access the ciphertext able to obtain the attribute information of other users through the displayed access structure. Therefore, some researchers have proposed ABE schemes with hidden access structures, which are divided into partial policy hiding and complete policy hiding. In order to improve the search efficiency of the ABE scheme for encrypted data, a searchable ABE scheme is proposed.

[0003] However, the related CP-ABE scheme can only assign access rights to individuals whose attribute sets satisfy the access policy. In real life, there are situations where it is necessary to collaborate with other users to obtain confidential information. For example, a hospital has patient data from different departments. The hospital is divided into different roles such as dean, director, attending physician, nurse, and patient. Different roles have different access rights according to their attribute sets. When a surgeon wants to know whether a patient has a certain medical history, he needs to obtain relevant permissions. However, such access is not granted for a long time. In addition, patient data cannot be shared between different departments. When multiple users with different roles collaborate. Secret sharing becomes a solution for such collaborative access to data. In order to set up a general access control system, users are allowed to access data under two conditions: 1) As in the related scheme, individuals who have the attribute set and satisfy the access structure can access the data individually; 2) For users whose attribute set does not have enough permissions to access individually, they can collaborate with other users with different attributes so that their integrated attribute set has enough permissions to access the data. In the traditional threshold secret sharing scheme, a secret is divided into multiple sub-secrets and shared among multiple participants, where each participant obtains a sub-secret. However, in many real-world scenarios, some participants participate in multiple secret sharing schemes with collaborative functions, so that participants obtain more permissions than ordinary participants, but this will lead to information leakage, malicious user collusion and low efficiency. In addition, when users have more secret shares to participate in multiple secret sharing schemes, it will lead to high bandwidth efficiency and low cost. Therefore, an efficient and complex mechanism is needed to provide a safe and efficient solution for collaboration between users. Summary of the invention

[0004] The purpose of this application is to provide a collaborative access control method, system, device, medium and product, which adopts the Chinese remainder theorem to determine the secret share of each node in the access policy, and can obtain plaintext when the attribute set of the accessing user meets or does not meet the access policy, thereby improving the efficiency of access.

[0005] To achieve the above objectives, this application provides the following solutions:

[0006] In a first aspect, the present application provides a collaborative access control method, comprising:

[0007] The plain text is divided into multiple data groups, and the global public parameters, the master key of each data group, the symmetric key of each data group and the private key of the user who accesses each data group are determined.

[0008] Determine the access strategy of each data group, and based on the access strategy of each data group, use the secret sharing algorithm and the Chinese remainder theorem to determine the secret share of each node in the access strategy of each data group; the access strategy is a collaborative access control tree.

[0009] For any data group, the data group is encrypted using the symmetric key of the data group to obtain the ciphertext of the data group; and based on the global public parameters and the secret share of each node in the access policy of the data group, the symmetric key of the data group is encrypted to obtain the ciphertext of the symmetric key of the data group.

[0010] When the attributes of the current access user of the data group satisfy the access policy of the data group, the secret share of the root node in the access policy is determined based on the global public parameters, the private key of the current access user and the ciphertext of the symmetric key of the data group.

[0011] When the attributes of the current access user of the data group do not satisfy the access policy of the data group, and the current access user is a collaborative user, the secret share of the root node in the access policy is determined based on the global public parameters, the private key of the current access user, the private key of the second access user, and the ciphertext of the symmetric key of the data group; the second access user is any collaborative user except the current access user; the collaborative user is a user participating in multiple access policies.

[0012] Based on the secret share of the root node in the access policy, the ciphertext of the symmetric key of the data group is decrypted to obtain the symmetric key of the data group.

[0013] The plain text is obtained according to the symmetric key of each data group and the ciphertext of each data group.

[0014] In a second aspect, the present application provides a collaborative access control system, comprising:

[0015] The public parameter and key determination module is used to divide the plain text into multiple data groups and determine the global public parameters, the master key of each data group, the symmetric key of each data group and the private key of the access user of each data group.

[0016] The access strategy and secret share determination module is connected to the public parameter and key determination module, and is used to determine the access strategy of each data group, and according to the access strategy of each data group, a secret sharing algorithm and the Chinese remainder theorem are used to determine the secret share of each node in the access strategy of each data group; the access strategy is a collaborative access control tree.

[0017] A symmetric key encryption module is connected to the public parameter and key determination module and the access strategy and secret share determination module, and is used to encrypt any data group using the symmetric key of the data group to obtain the ciphertext of the data group; and to encrypt the symmetric key of the data group based on the global public parameters and the secret share of each node in the access strategy of the data group to obtain the ciphertext of the symmetric key of the data group.

[0018] The secret share determination module of the root node is connected to the public parameter and key determination module and the symmetric key encryption module, and is used to determine the secret share of the root node in the access policy based on the global public parameters, the private key of the current access user and the ciphertext of the symmetric key of the data group when the attribute of the current access user of the data group satisfies the access policy of the data group; when the attribute of the current access user of the data group does not satisfy the access policy of the data group and the current access user is a collaborative user, determine the secret share of the root node in the access policy based on the global public parameters, the private key of the current access user, the private key of the second access user and the ciphertext of the symmetric key of the data group; the second access user is any collaborative user except the current access user; the collaborative user is a user participating in multiple access policies.

[0019] The symmetric key decryption module is connected to the secret share determination module of the root node, and is used to decrypt the ciphertext of the symmetric key of the data group based on the secret share of the root node in the access policy to obtain the symmetric key of the data group.

[0020] The plaintext determination module is connected to the symmetric key decryption module and is used to obtain the plaintext according to the symmetric key of each data group and the ciphertext of each data group.

[0021] In a third aspect, the present application provides a computer device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the collaborative access control method described above.

[0022] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the above-mentioned collaborative access control method when executed by a processor.

[0023] In a fifth aspect, the present application provides a computer program product, including a computer program, which implements the above-mentioned collaborative access control method when executed by a processor.

[0024] According to the specific embodiments provided in this application, this application has the following technical effects:

[0025] The present application provides a collaborative access control method, system, device, medium and product, which provide a basis for subsequent steps by determining global public parameters, a master key of each data group, a symmetric key of each data group and a private key of an access user of each data group, and determine the secret share of each node in the access policy of each data group by using a secret sharing algorithm and the Chinese remainder theorem, so that nodes participating in multiple access policies use the same secret share; encrypt the data group using the symmetric key of the data group, and encrypt the symmetric key of the data group based on the global public parameters and the secret share of each node in the access policy of the data group, and perform double encryption to improve the security of access control; and can obtain plain text both when the attribute set of the access user satisfies the access policy and when it does not satisfy the access policy, thereby improving the efficiency of access. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0027] Figure 1 A schematic diagram of a collaborative access control tree in a collaborative access control method in an embodiment of the present application.

[0028] Figure 2 This is a schematic diagram of an entity in a collaborative access control method in an embodiment of the present application.

[0029] Figure 3 A flowchart of a collaborative access control method provided in one embodiment of the present application.

[0030] Figure 4 A schematic diagram of functional modules of a collaborative access control system provided in another embodiment of the present application.

[0031] Figure 5 A schematic diagram of the structure of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0032] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0033] In order to make the purpose, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0034] Construct a collaborative access control tree. is a cooperative access tree representing the access structure, express The nodes in Indicates that the node is located at of Layers (in order from top to bottom). Indicates the position of the node in the layer (from left to right). Figure 1 The access structure shown is The leaf nodes Q, B, C, and D in the tree are respectively Description. Each leaf node represents an attribute, expressed as ,like , , . Non-leaf nodes are represented as a threshold ,in Respectively represent the threshold of leaf nodes and the number of child nodes, such as node , ;when When the threshold gate represents an “OR” gate and , which represents an “AND” gate. Indicates the parent node of the node , Indicates that the parent node is The unique number of the child node of . And will Defined as a node exist The shared secret share at location, The range is from 1 to , ,in Represents the secret share to be shared, that is, the secret share of the root node. Indicates that the root node is If an attribute set satisfies the subtree, let , where if the node yes A leaf node in If and only if ,if yes A non-leaf node in If and only if there is at least Child nodes return 1, where For attribute sets.

[0035] Define collaborative nodes and collaborative access structures. Collaborative nodes: A set of participants is Secret sharing scheme shared .in For a set of participants The other set of participants is Secret sharing scheme shared .in For another participant in the collection participants. and represents the threshold for two participants to recover the secret, and represents the total number of shares of the secret shared by two participants. ,in, Common to both participants Participants, .node represents a collaborative node if it satisfies the following properties: , that is, the node must belong to the intersection of the two participant sets. Less than and , that is, the number of such collaborative nodes must be less than the node threshold.

[0036] The secret shares of the cooperative nodes are the same share, that is, if , , ,in is the first coordination node, is the second collaborative node. When the collaborative node is a leaf node, . The first coordination node is The secret share of the location, For the second collaborative node The secret share of the location, when the node is a non-leaf node, and ;in, The first coordination node The threshold value, The second coordination node The threshold value, The first coordination node The number of child nodes, The second coordination node The number of child nodes.

[0037] Collaborative access structure: Figure 1 As shown, and The participant sets are and Two monotone access structures on the same access control tree, namely, cooperative access control tree, if is a collaborative node, then

[0038] .

[0039] like Figure 2 As shown, the entities included in this application include a central authority (CA), multiple data owners (DOs), multiple data users (DUs) and a cloud server.

[0040] The central authority is the administrator, who sets the parameters for the implementation of access control and distributes keys to users.

[0041] The data owner is the entity that outsources its data to the cloud server. In order to share the data owner's data with other target entities, the data owner defines a data access policy. The access policy is represented by the access structure on the attributes, and the data content is encrypted before uploading to the cloud server.

[0042] Data users are entities that want to access data. In a collaborative access control scheme, each user is assigned to a relevant project group that he is responsible for. Data users have a set of attributes and keys associated with their attributes, and can collaborate with other valid users in the group to decrypt data.

[0043] Cloud servers provide a public cloud platform for data owners to store and share encrypted data, but they may also be curious about the information in the ciphertext.

[0044] The collaborative access control decryption scheme includes the system initialization algorithm (System Setup Algorithm, Setup), the data encryption algorithm (Data Encryption Algorithm, Encrypt), the key generation algorithm (Key Generation Algorithm, KeyGen) and the data decryption algorithm (Data Decryption, Decrypt).

[0045] (1) System initialization algorithm Executed by CA. is a safety parameter, is a global public parameter. The primary key.

[0046] (2) , For the Accessing users The attribute set of Indicates Accessing users The jth attribute in the attribute set of Indicates Accessing users The number of attributes, the key generation algorithm generates a private key for the user .

[0047] (3) Let M represent the data file. In order to improve the efficiency of the algorithm, the user first randomly selects a symmetric key before encryption. Symmetrically encrypt the plaintext M to obtain the ciphertext data , and then the data owner encrypts the symmetric key k. Represents the ring of integers modulo q, consisting of the integers from 0 to q-1.

[0048] (4) The algorithm inputs ciphertext and attribute key. Users who meet the access structure can decrypt the ciphertext individually, while users who do not meet the access structure can decrypt collaboratively.

[0049] In an exemplary embodiment, Figure 4 As shown, a collaborative access control method is provided, including the following steps 101 to 107. Among them:

[0050] Step 101, divide the plain text into multiple data groups, and determine the global public parameters, the master key of each data group, the symmetric key of each data group and the private key of the user accessing each data group.

[0051] Step 102, determine the access strategy of each data group, and according to the access strategy of each data group, use the secret sharing algorithm and the Chinese remainder theorem to determine the secret share of each node in the access strategy of each data group; the access strategy is a collaborative access control tree.

[0052] Step 103, for any data group, encrypt the data group using the symmetric key of the data group to obtain the ciphertext of the data group; and encrypt the symmetric key of the data group based on the global public parameters and the secret share of each node in the access policy of the data group to obtain the ciphertext of the symmetric key of the data group.

[0053] Step 104, when the attributes of the current access user of the data group meet the access policy of the data group, determine the secret share of the root node in the access policy based on the global public parameters, the private key of the current access user and the ciphertext of the symmetric key of the data group.

[0054] Step 105, when the attributes of the current access user of the data group do not satisfy the access policy of the data group, and the current access user is a collaborative user, determine the secret share of the root node in the access policy based on the global public parameters, the private key of the current access user, the private key of the second access user and the ciphertext of the symmetric key of the data group; the second access user is any collaborative user except the current access user; the collaborative user is a user participating in multiple access policies.

[0055] Step 106: decrypt the ciphertext of the symmetric key of the data group based on the secret share of the root node in the access policy to obtain the symmetric key of the data group.

[0056] Step 107, obtaining plain text according to the symmetric key of each data group and the ciphertext of each data group.

[0057] In another exemplary embodiment of the present application, step 101 determines the global public parameters, the master key of each data group, the symmetric key of each data group and the private key of the user accessing each data group, which is specifically as follows.

[0058] The system initialization algorithm is used to determine the global public parameters and the master key of each data group. Specifically, , CA executes the algorithm to output global public parameters and the master key Given the security parameters , first CA selects a cyclic group of order q and . Second, generate bilinear pairings , For the group The generator of For a bilinear map, choose a hash function . is a set of non-zero integers modulo q, and a security parameter is selected As the master key, . Run the algorithm to get the system parameters , where different data groups have unique group keys , is the number of data groups. Master Key and global public parameters for:

[0059] .

[0060] .

[0061] in, and is a cyclic group of order q, is the group in the global public parameter The generator of is a bilinear pairing, and is the security parameter in the global public parameter, that is, the random number, is the group key, is the first intermediate parameter of the global public parameters, is a hash function.

[0062] In another exemplary embodiment of the present application, , the CA generates a key for the user. First, the CA checks which group the data comes from and determines the group key , and then the CA randomly selects and select , and then execute the key generation algorithm to get the Accessing users The private key is:

[0063] .

[0064] in, For the Accessing users The private key of For the Accessing users The first parameter of the private key, For the Accessing users The second parameter of the private key, is the global public parameter group The generator of and is the security parameter in the global public parameters, is the group key, For the Accessing users A random number, For the Accessing users The random number of the jth attribute, For the Accessing users The attribute number of For the Accessing users The number of attributes, For the Accessing users The attribute parameters of the private key, is a hash function, For the Access users The attribute set of For the Accessing users The collaborative key, is the serial number of the access user, is the number of data sets.

[0065] Based on the global public parameters and the master key of each data group, a key generation algorithm is used to determine the private key of the access user of each data group and generate a symmetric key for each data group.

[0066] In another exemplary embodiment of the present application, step 102, according to the access strategy of each data group, uses a secret sharing algorithm and the Chinese remainder theorem to determine the secret share of each node in the access strategy of each data group, specifically including:

[0067] A secret sharing algorithm is used to determine the preliminary secret share of each node in the access strategy of each data group; the nodes of the access strategy are divided into ordinary nodes and collaborative nodes; the collaborative nodes are attributes of collaborative users; the preliminary secret share of ordinary nodes is the secret share of ordinary nodes.

[0068] Based on the preliminary secret share of each cooperative node in the access strategy of each data group, the secret share of each cooperative node is determined by using the Chinese remainder theorem.

[0069] In another exemplary embodiment of the present application, the specific process of step 103 is as follows: The data owner encrypts the symmetric key k. The data owner expresses the access policy by defining a collaborative access control tree and defines collaborative nodes in the collaborative access control tree. Based on these collaborative nodes, collaborative users can perform collaborative decryption to meet the collaborative access structure. Represents an access policy. is the ciphertext of the symmetric key. Indicates a OK A matrix of columns, Indicates Each row of is mapped to a function of the corresponding attribute. Randomly select the vector ,in is the secret share of the root node, is a randomly selected number, the purpose is to hide the secret share in each different vector by means of vectors, and calculate ,in, For the Accessing users of OK Column matrix, and randomly select , is a random number The upper number. Represents the node set of the collaborative user. The ciphertext of the symmetric key of the data group is as follows:

[0070] .

[0071] Among them, CT is the ciphertext of the symmetric key of the data group, that is, is the first parameter of the ciphertext, is a symmetric key, is the secret share of the root node, is the second parameter of the ciphertext, is the third parameter of the ciphertext, is the ciphertext about Accessing users The first parameter, is the ciphertext about Accessing users The second parameter, is the fourth parameter of the ciphertext, For the Accessing users A random number, is the ciphertext about Accessing users The intermediate parameters of is the node set of collaborative users, For Node exist The secret share at the location.

[0072] In another exemplary embodiment of the present application, step 104, based on the global public parameter, the private key of the current access user and the ciphertext of the symmetric key of the data group, determines the secret share of the root node in the access policy, specifically including:

[0073] Based on the global public parameters, the private key of the current access user and the ciphertext of the symmetric key of the data group, a recursive function and Lagrange interpolation method are used to determine the secret share of the root node in the access strategy.

[0074] In another exemplary embodiment of the present application, the private key of the access user includes a common key and a collaborative key. Private key middle, For visiting users The collaborative key, except Other than visiting users The common key of .

[0075] Step 105, based on the global public parameter, the private key of the current access user, the private key of the second access user and the ciphertext of the symmetric key of the data group, determines the secret share of the root node in the access strategy, specifically including:

[0076] Based on the global public parameters, the common key of the current accessing user and the ciphertext of the symmetric key of the data group, a recursive function is used to determine the secret share of the leaf node in the access policy corresponding to the attribute of the current accessing user.

[0077] Based on the global public parameters, the collaborative key of the current accessing user, the collaborative key of the second accessing user and the secret share of the leaf node in the access policy corresponding to the attributes of the current accessing user, a bilinear mapping is used to determine the secret share of the leaf node that satisfies the access policy.

[0078] Based on the secret shares of the leaf nodes that satisfy the access strategy, the Lagrange interpolation method is used to determine the secret share of the root node in the access strategy.

[0079] In another exemplary embodiment of the present application, the algorithm actually inputs a combination attribute set , that is, all attribute sets from the current user accessing the data and partial attribute sets from collaborative users. Collaborative users only need to enter attributes related to collaboration into the set. Private key The ciphertext of the symmetric key that satisfies the data group Only when the decryption is successful can it be decrypted independently. Represents a subset of the set of all attributes ,in, is the number of attributes in the subset of the attribute set, To be the first The attribute is mapped to Accessing users The property set If , then we can calculate in polynomial time , so that .in is a vector The vector of Denotes a vector that hides the secret through random numbers during encryption. Define a recursive function as shown below, otherwise .

[0080] .

[0081] In another exemplary embodiment of the present application, if Accessing users For the current access user, when the current access user accesses other data, if the current access user is a collaborative user, he can use his own attributes to collaborate with others to decrypt data and define another recursive function. , that is, when When you are collaborating with a user, run Algorithm and store output , which means selecting another user to collaborate on decryption. Second access user Convert the output to And expressed as follows:

[0082] .

[0083] in, is the parameter for the second access user leaf node, To decrypt the parameters of the leaf nodes that satisfy the access policy, is the collaborative key of the current access user, is the collaborative key of the second access user, To decrypt the first parameter of the leaf node, For Node exist The secret share at position, is a leaf node, A random number for the current access user. A random number for the second visiting user.

[0084] Current visiting user Broadcast its own collaborative key , since the user satisfies all the attributes that can be decrypted, the user can decrypt the intermediate node. When is an intermediate node, the Lagrange interpolation method is used:

[0085] .

[0086] Among them, when the node When it is an intermediate node, To decrypt the parameters of the intermediate node, , Indicates that the parent node is Child nodes of Number, , For child nodes A collection of numbers, Representation Node of A collection of child nodes, For Node exist The secret share of the place.

[0087] The parameters of the decryption root node are obtained through a recursive algorithm: .

[0088] in, To decrypt the parameters of the root node, the output F is as follows:

[0089] .

[0090] in, is an intermediate variable. Finally, the decryption algorithm is performed as follows and the symmetric key k is calculated:

[0091] .

[0092] Then, using the symmetric key Decrypt the ciphertext of the data group , and finally get the plaintext M.

[0093] Based on the same inventive concept, the embodiment of the present application also provides a collaborative access control system. Figure 4 As shown, it includes: a public parameter and key determination module 201, which is used to divide the plain text into multiple data groups and determine the global public parameters, the master key of each data group, the symmetric key of each data group and the private key of the access user of each data group.

[0094] The access strategy and secret share determination module 202 is connected to the public parameter and key determination module 201, and is used to determine the access strategy of each data group, and based on the access strategy of each data group, adopt the secret sharing algorithm and the Chinese remainder theorem to determine the secret share of each node in the access strategy of each data group; the access strategy is a collaborative access control tree.

[0095] The symmetric key encryption module 203 is connected to the public parameter and key determination module 201 and the access strategy and secret share determination module 202, and is used to encrypt any data group using the symmetric key of the data group to obtain the ciphertext of the data group; and to encrypt the symmetric key of the data group based on the global public parameters and the secret share of each node in the access strategy of the data group to obtain the ciphertext of the symmetric key of the data group.

[0096] The root node's secret share determination module 204 is connected to the public parameter and key determination module 201 and the symmetric key encryption module 203, and is used to determine the root node's secret share in the access policy based on the global public parameters, the current access user's private key and the ciphertext of the data group's symmetric key when the attribute of the current access user of the data group satisfies the access policy of the data group; when the attribute of the current access user of the data group does not satisfy the access policy of the data group and the current access user is a collaborative user, determine the root node's secret share in the access policy based on the global public parameters, the current access user's private key, the second access user's private key and the ciphertext of the symmetric key of the data group; the second access user is any collaborative user except the current access user; the collaborative user is a user participating in multiple access policies.

[0097] The symmetric key decryption module 205 is connected to the root node secret share determination module 204, and is used to decrypt the ciphertext of the symmetric key of the data group based on the root node secret share in the access policy to obtain the symmetric key of the data group.

[0098] The plaintext determination module 206 is connected to the symmetric key decryption module 205 and is used to obtain the plaintext according to the symmetric key of each data group and the ciphertext of each data group.

[0099] In an exemplary embodiment, a computer device is provided. The computer device may be a server or a terminal. The internal structure diagram thereof may be as follows: Figure 5As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store video tag processing data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a collaborative access control method is implemented.

[0100] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components. In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.

[0101] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, which implements the above-mentioned collaborative access control method when executed by a processor.

[0102] In an exemplary embodiment, a computer program product is provided, including a computer program, which implements the above-mentioned collaborative access control method when executed by a processor.

[0103] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0104] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM may be in various forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM).

[0105] The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. The non-relational database may include a distributed database based on blockchain, etc., but is not limited thereto. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but is not limited thereto.

[0106] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0107] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, according to the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.

Claims

1. A collaborative access control method, characterized in that: The collaborative access control method comprises: Divide the plaintext into multiple data groups, and determine the global public parameters, the master key of each data group, the symmetric key of each data group, and the private key of the user accessing each data group; Determine the access strategy for each data group, and according to the access strategy for each data group, use a secret sharing algorithm and a Chinese remainder theorem to determine the secret share of each node in the access strategy for each data group; the access strategy is a collaborative access control tree; For any data group, encrypt the data group using the symmetric key of the data group to obtain the ciphertext of the data group; and encrypt the symmetric key of the data group based on the global public parameter and the secret share of each node in the access policy of the data group to obtain the ciphertext of the symmetric key of the data group; When the attribute of the current access user of the data group satisfies the access policy of the data group, determining the secret share of the root node in the access policy based on the global public parameter, the private key of the current access user and the ciphertext of the symmetric key of the data group; When the attribute of the current access user of the data group does not satisfy the access policy of the data group, and the current access user is a collaborative user, the secret share of the root node in the access policy is determined based on the global public parameter, the private key of the current access user, the private key of the second access user and the ciphertext of the symmetric key of the data group; the second access user is any collaborative user except the current access user; the collaborative user is a user participating in multiple access policies; the private key of the access user includes a common key and a collaborative key; Determining the secret share of the root node in the access strategy based on the global public parameter, the private key of the current access user, the private key of the second access user, and the ciphertext of the symmetric key of the data group specifically includes: Based on the global public parameter, the common key of the current access user and the ciphertext of the symmetric key of the data group, a recursive function is used to determine the secret share of the leaf node in the access policy corresponding to the attribute of the current access user; Based on the global public parameter, the collaborative key of the current access user, the collaborative key of the second access user and the secret share of the leaf node in the access policy corresponding to the attribute of the current access user, a bilinear mapping is used to determine the secret share of the leaf node that satisfies the access policy; Based on the secret shares of the leaf nodes that satisfy the access policy, the secret share of the root node in the access policy is determined by using the Lagrange interpolation method; Decrypting the ciphertext of the symmetric key of the data group based on the secret share of the root node in the access policy to obtain the symmetric key of the data group; The plain text is obtained according to the symmetric key of each data group and the ciphertext of each data group.

2. The collaborative access control method according to claim 1, characterized in that: Determine the global public parameters, the master key of each data group, the symmetric key of each data group, and the private key of the user accessing each data group, including: The system initialization algorithm is used to determine the global public parameters and the master key of each data group; Based on the global public parameters and the master key of each data group, a key generation algorithm is used to determine the private key of the access user of each data group and generate a symmetric key for each data group.

3. The collaborative access control method according to claim 1, characterized in that: According to the access strategy of each data group, the secret sharing algorithm and the Chinese remainder theorem are used to determine the secret share of each node in the access strategy of each data group, including: A secret sharing algorithm is used to determine the preliminary secret share of each node in the access strategy of each data group; the nodes of the access strategy are divided into ordinary nodes and cooperative nodes; the cooperative nodes are attributes of cooperative users; the preliminary secret share of ordinary nodes is the secret share of ordinary nodes; Based on the preliminary secret share of each cooperative node in the access strategy of each data group, the secret share of each cooperative node is determined by using the Chinese remainder theorem.

4. The collaborative access control method according to claim 1, characterized in that: Determining the secret share of the root node in the access strategy based on the global public parameter, the private key of the current access user and the ciphertext of the symmetric key of the data group specifically includes: Based on the global public parameters, the private key of the current access user and the ciphertext of the symmetric key of the data group, a recursive function and Lagrange interpolation method are used to determine the secret share of the root node in the access strategy.

5. The collaborative access control method according to claim 1, characterized in that: Access User The private key is: ; in, For the Access users The private key of For the Access users The first parameter of the private key, For the Access users The second parameter of the private key, is the global public parameter group The generator of and is the security parameter in the global public parameters, is the group key, For the Access users A random number, For the Access users The random number of the jth attribute, For the Access users The attribute number of For the Access users The number of attributes, For the Access users The attribute parameters of the private key, is a hash function, For the Access users The attribute set of For the Access users The collaborative key, is the serial number of the access user, is the number of data sets.

6. A collaborative access control system, applying the collaborative access control method according to any one of claims 1 to 5, characterized in that: The collaborative access control system comprises: A public parameter and key determination module, used to divide the plain text into multiple data groups, and determine the global public parameters, the master key of each data group, the symmetric key of each data group and the private key of the access user of each data group; An access strategy and secret share determination module, connected to the public parameter and key determination module, is used to determine the access strategy of each data group, and according to the access strategy of each data group, a secret sharing algorithm and a Chinese remainder theorem are used to determine the secret share of each node in the access strategy of each data group; the access strategy is a collaborative access control tree; a symmetric key encryption module, connected to the public parameter and key determination module and the access policy and secret share determination module, for encrypting any data group with the symmetric key of the data group to obtain the ciphertext of the data group; and encrypting the symmetric key of the data group based on the global public parameter and the secret share of each node in the access policy of the data group to obtain the ciphertext of the symmetric key of the data group; The secret share determination module of the root node is connected to the public parameter and key determination module and the symmetric key encryption module, and is used to determine the secret share of the root node in the access policy based on the global public parameters, the private key of the current access user and the ciphertext of the symmetric key of the data group when the attribute of the current access user of the data group satisfies the access policy of the data group; when the attribute of the current access user of the data group does not satisfy the access policy of the data group and the current access user is a collaborative user, determine the secret share of the root node in the access policy based on the global public parameters, the private key of the current access user, the private key of the second access user and the ciphertext of the symmetric key of the data group; the second access user is any collaborative user except the current access user; the collaborative user is a user participating in multiple access policies; the private key of the access user includes an ordinary key and a collaborative key; Determining the secret share of the root node in the access strategy based on the global public parameter, the private key of the current access user, the private key of the second access user, and the ciphertext of the symmetric key of the data group specifically includes: Based on the global public parameter, the common key of the current access user and the ciphertext of the symmetric key of the data group, a recursive function is used to determine the secret share of the leaf node in the access policy corresponding to the attribute of the current access user; Based on the global public parameter, the collaborative key of the current access user, the collaborative key of the second access user and the secret share of the leaf node in the access policy corresponding to the attribute of the current access user, a bilinear mapping is used to determine the secret share of the leaf node that satisfies the access policy; Based on the secret shares of the leaf nodes that satisfy the access policy, the secret share of the root node in the access policy is determined by using the Lagrange interpolation method; A symmetric key decryption module, connected to the secret share determination module of the root node, for decrypting the ciphertext of the symmetric key of the data group based on the secret share of the root node in the access policy to obtain the symmetric key of the data group; The plaintext determination module is connected to the symmetric key decryption module and is used to obtain the plaintext according to the symmetric key of each data group and the ciphertext of each data group.

7. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the collaborative access control method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the collaborative access control method described in any one of claims 1 to 5 is implemented.

9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the collaborative access control method described in any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Fine-grained access control method based on block chain in cloud edge collaborative environment

    CN115484095A

  • Ciphertext data sharing method and system based on collaborative searchable

    CN115694974A