Dynamic hierarchical data access control method based on resumable puncture encryption

By recording the secret value during the key puncture process based on a method of recoverable puncture encryption, efficient dynamic hierarchical access control is achieved, solving the time-consuming problem of senior users restoring the permissions of subordinate users, supporting coarse-grained revocation operations, and ensuring the forward security of data and the rapid recovery of user permissions.

CN119728282BActive Publication Date: 2025-10-03ANHUI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411980552.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-10-03
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

Existing technologies make it difficult to efficiently and dynamically implement access control of hierarchical user permissions in the Industrial Internet of Things. In particular, it is time-consuming and inefficient for senior users to restore permissions for subordinate users, and it is impossible to effectively restore restricted access rights.

Method used

A method based on resumable puncture encryption is adopted to achieve efficient dynamic hierarchical access control by recording the secret value during the key puncture process, supporting coarse-grained user revocation operations and restoring the permissions of subordinate users through key delegation and key update mechanisms.

Benefits of technology

It implements efficient and dynamic hierarchical access control, supports senior users to quickly restore the permissions of subordinate users, reduces the time overhead of permission recovery, and reduces the user burden through edge node-assisted decryption, ensuring the forward security of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728282B_ABST
    Figure CN119728282B_ABST
Patent Text Reader

Abstract

The present invention discloses a dynamic hierarchical data access control method based on recoverable puncture encryption, wherein the user key consists of an attribute key and a puncture key; the hierarchical user revokes the access rights of some of its subordinate data according to needs; the hierarchical user restores the previously revoked data access rights of some of its subordinate data when necessary; the edge node updates the attribute conversion key stored therein using key update material; the data owner encrypts the data using puncture attribute-based encryption according to the defined access structure and data tag set; after the malicious user is revoked, the third-party cloud server is responsible for publicly updating the ciphertext; the edge node of the Internet of Things uses the conversion key to partially decrypt the ciphertext; the user can only access the ciphertext whose attributes meet the ciphertext access structure and does not contain the punctured key tag; the malicious user is revoked in the user revocation stage, and the key of the non-revoked user is updated; the present invention can realize fine-grained hierarchical dynamic access control, and provides a feasible method for dynamic permission control between hierarchical organizational levels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the Internet of Things and puncture encryption technology, and in particular to a dynamic hierarchical data access control method based on recoverable puncture encryption. Background Art

[0002] Cloud computing has attracted increasing attention due to its ability to provide on-demand computing and storage, as well as services for resource-constrained users. Many Internet-connected IoT devices and businesses are turning to cloud services for data storage, freeing them from the burden of maintaining local data. However, because the cloud is semi-trusted, outsourced data must be encrypted before being uploaded. Outsourced data uploaded to cloud servers is not physically controlled by the user. Therefore, access control and security of outsourced data remain major challenges to the widespread adoption of cloud computing.

[0003] Attribute-based encryption (ABE) is commonly used for sharing outsourced data in the cloud. This is because it can provide one-to-many data encryption and fine-grained access control for outsourced data uploaded to semi-trusted cloud servers. However, in the Industrial Internet of Things, there are many hierarchical organizations and enterprises, such as hospitals, smart device factories, and medical data organizations. Within this hierarchy, users are divided into different levels by position, with different access rights, and their permissions to outsourced data are dynamically controlled by their managers. Using ABE alone makes it difficult to stratify user permission requirements.

[0004] Pierceable encryption (PE) is a technique that supports selective key puncturing. In PE, data is encrypted using descriptive labels of the data (e.g., collection time, file size, and data type). A user punctures his key using a set of labels, thereby limiting the key's decryption capabilities to a portion of the data. Subsequently, the user can only access data whose label set does not contain the punctured labels. Existing literature uses PE to implement data sharing in a hierarchical structure. However, it cannot effectively restore the privileges of users with limited access. A high-level user can limit the access rights of low-level users under their management. However, if many restricted privileges need to be restored, a high-level user should puncture the key with unrevoked labels. This is time-consuming if the number of unrevoked labels is large. Therefore, we have a solution that allows high-level users to efficiently restore the corresponding restricted privileges of their subordinates using a secret value saved during the key puncturing process. Summary of the Invention

[0005] Purpose of the invention: The purpose of the present invention is to address the deficiencies in the prior art and to provide a dynamic hierarchical data access control method based on recoverable puncture encryption. The present invention optimizes puncture encryption to achieve efficient, dynamic, and hierarchical access control. By recording the secret value of the puncture tag corresponding to the key puncture process, the present invention helps users to efficiently restore some of their subordinates' previously revoked data access rights. The present invention also supports coarse-grained user revocation operations. The security of the cryptographic protocol is evaluated through formal security analysis and can resist various types of attacks. Compared with other related schemes, it has stronger security.

[0006] Technical solution: A dynamic hierarchical data access control method based on recoverable puncture encryption of the present invention comprises the following steps:

[0007] Step (1): The key distribution center KGC runs the group generator Gen to initialize the system and obtain the system master public key MPK and the system master private key MSK; and initializes the key distribution center KGC, cloud service provider CSP, data owner DO, data user DU, and edge node ENs respectively;

[0008] Among them, the public key of the data user DU is pk id , the private key is sk id ;The cloud service provider CSP, data owner DO and edge nodes ENs all store the system master public key MPK and the system master private key MSK;

[0009] Step (2): In the key generation phase, the key distribution center KGC and its administrator generate user keys for data users; that is, when a data user initiates an access request to the system, the key distribution center KGC generates an attribute conversion key tk based on the user attribute R. id and pierceable keys And send it to the highest-level data users and edge nodes ENs through secure channels;

[0010] Step (3): In the permission revocation phase, the data users of each hierarchical user revoke the access rights of their subordinate data according to their needs. The specific method is as follows:

[0011] High-level users first use their own puncture key and the ids of its subordinates k+1 Distribute puncturable keys to its subordinates and revoke permissions, then k+1 Perform key delegation, then the high-level user punctures the key according to the tag set, and merges the puncture keys of the high-level user's subordinates Subordinates who possess this key cannot access the ciphertext containing the labels of the corresponding label set;

[0012] Step (4), in the permission restoration phase, the hierarchical user, when necessary, restores the previously revoked data access rights of its subordinates. The specific method is as follows:

[0013] Data user DU according to identity vector Request its manager to restore the included tag t i After receiving the ciphertext, the manager first restores part of the data rights of the data owner DO; the data user DU re-randomizes part of the puncturable key; the final user deletes the tag t i The relevant key;

[0014] Step (5): In the key update phase, the edge node ENs uses the key update material to update the attribute conversion key stored therein. The specific method is as follows:

[0015] The key distribution center KGC parses the current time period t into For all nodes, record the indices where all bits in the timestamp are 0 to calculate the key update material ku θ , and calculate the key update material ku at period t t And broadcast it to the edge nodes ENs. After receiving it, the edge nodes ENs update their own stored attribute conversion keys;

[0016] Step (6), ciphertext generation phase, the data owner DO runs the encryption algorithm to encrypt the corresponding plaintext information m and obtains the ciphertext CT;

[0017] Step (7), ciphertext update phase, after the data user revokes the permission, the cloud service provider CSP updates the ciphertext within the new time period t and obtains the updated ciphertext CT t ;

[0018] When the system reaches a new time period t, CSP calculates the index set V where all bits of the timestamp t are 0; then it updates the ciphertext CT stored in it according to the index set V and calculates Get the ciphertext under time period t

[0019] Step (8), ciphertext outsourcing decryption phase, edge nodes ENs use the conversion key of the attribute key to decrypt part of the ciphertext and obtain the converted ciphertext

[0020] Step (9), during the ciphertext decryption phase, the data user DU that meets the access policy initiates an access request to the edge node ENs through the system public key MPK and obtains the ciphertext CT t2 After that, when the ciphertext does not contain the tag that the data user DU key is punctured, the data user DU runs the decryption algorithm to obtain the plaintext m

[0021] Step (10), user revocation phase, KGC adds the malicious user's ID to the revocation list rl, and the edge node ENs updates the key of the unrevoked user and obtains the updated revocation list as follows:

[0022] rl←rl∪(id,t).

[0023] Furthermore, the detailed process of step (1) is as follows:

[0024] The key distribution center KGC runs the group generator Gen(1 λ )Get parameters parms=(p,G,G T ,e,g), where g is the generator of the group G, and e is a bilinear map e:G×G→G T ;

[0025] Then KGC selects the bounded time T of the system and calculates l1=log2T, random values ​​w,w0,w1,…,w n ,u0,u1,…,u l ,h1,…,h U ,v0,v1,…,v l1 ∈G and a,α,β,t0∈Z p ; Where t0 is a distinguishing mark that will not be used in encryption;

[0026] Then KGC chooses the hash function H1: {0,1} * →G, H2: {0,1} * →Z p ; Label space and identity space And a binary tree BT with at least N leaf nodes, finally generating the system master public key MPK={parms,e(g,g) α ,g β ,g a ,w,w0,w1,…,w n ,u0,u1,…,u l ,h1,…,h U ,v0,v1,…,v l1 ,H1,H2} and system master private key MSK={β,α};

[0027] Data user DU uses random value γ id ∈Z p Calculate the key: sk id =γ id .

[0028] Furthermore, the process of generating the key in step (2) is as follows:

[0029] Step (2.1), after the data user initiates an access request to the system, KGC generates an attribute key based on the user attribute R;

[0030] First, input the user attribute set R and calculate the attribute key components for each attribute in R;

[0031] Then for each attribute in R, KGC selects a leaf node of an undefined BT and stores the id in the node;

[0032] Then, according to the id selected in step (3-1-2), the path Path(id) from the root node of the tree BT to id is calculated. For each node θ on the path Path(id), if g in node θ θ Has been defined for direct use (where g θ is the corresponding value stored in node θ), otherwise a random value g is selected θ ∈G, and update st to st∪(θ,g θ ) to update the value of node θ (st is the key-value pair of the node and the node storage value in the tree);

[0033] Choose t′∈Z p and calculate Calculation: tk1 = g θ 'g at′ ,tk2=g t′ , tk θ =(tk1,tk2,{tk 3,τ} τ∈[k] );

[0034] where tk1, tk2, tk 3,τ All are intermediate variables; finally the conversion key tk is obtained id ={(id,R),{tk θ} θ∈Path(id)};

[0035] Step (2.2), KGC selects a random value r, r id ∈Z p , then calculate the puncturable key

[0036]

[0037] Output conversion key tk id and pierceable keys And sent to the highest-level users and edge nodes ENs through secure channels.

[0038] Furthermore, the specific method of revoking the authority in step (3) is:

[0039] Step (3.1) The high-level user uses his own puncture key and the ids of its subordinates k+1 Distribute puncturable keys and revoke permissions for its subordinates, where k represents the depth of the hierarchical organization where the top level is located;

[0040] Step (3.2), select a random number r′ id ∈Z p , and according to id k+1 To delegate the key:

[0041]

[0042] Step (3.3), high-level users puncture the key according to the tag set, for the newly added (t i ,...,t j ) selects a random value r for each label in i ′,λ i , r i ∈Z p , and calculate:

[0043]

[0044] Step (3.4), the high-level user saves the corresponding secret value λ for each tag i , such as: ({t i :λ i},…,{t k :λ k}) and merge to get the puncture key of the subordinates of the high-level user Subordinates with this key cannot access the tag set Tag∪t i ...∪t j The ciphertext of the label.

[0045] Furthermore, the specific process of restoring permissions in step (4) is as follows:

[0046] The data user DU first Request its manager to restore the included tag t i The ciphertext of t i Find the {t saved during puncture i :λ i} to restore some data permissions of the data owner DO;

[0047] Then, the data user manager receives the sk from the data user DU. 0,1 , choose a random value r i′∈Z p ,calculate And sk′ 0,1 Sent to data user DU;

[0048] The data user DU receives the processed sk 0,1 Then, use the random value r i 'Complete (sk 0,2 ,sk 0,3 ) re-randomization;

[0049]

[0050] Then the user deletes the tag t i The relevant key (sk i,1 ,sk i ,sk i,3 ), that is, the puncture label is completed i revocation.

[0051] Furthermore, the specific method for updating the key in step (5) is:

[0052] The key distribution center KGC parses the current time period t into Let t[i] be the i-th bit of timestamp t;

[0053] For all nodes θ∈KUNodes(st,rl,t), randomly select And define a set V∈[l] to record the indices of all bits 0 in the timestamp to calculate the key update material ku θ =(ku1,ku2):

[0054]

[0055] Calculate the key update material ku at period t t =(t,{ku θ} θ∈KUNodes(st,rl,t) ) and broadcast it to edge nodes ENs;

[0056] The edge nodes ENs receive the ku t Update the attribute conversion key stored in itself. If Path(id)∩KUNodes(st,rl,t)=(), then terminate. Otherwise, there exists a θ∈Path(id)∩KUNodes(st,rl,t);

[0057] Let V be the index set of all 0 bits of timestamp t, and the edge node ENs updates its own stored attribute conversion key utk id,t =((id,R,t),utk1,utk2,{utk3,τ} τ∈[k] ,utk4);

[0058] utk1=tk1;

[0059]

[0060] utk2=tk2=g t′ ,

[0061] Furthermore, the specific process of generating the ciphertext in step (6) is as follows:

[0062] Data owner DO input (MPK,m,S,id k ,AS,t), m is the encrypted plaintext, and identity vector id k =(I1,…,I k ), AS=(M,ρ);

[0063] Then use a univariate polynomial Define a constant vector z=(z0,z1,...,z n ), for each i∈[1,k], calculate id i =H(I i );

[0064] Next, the data owner DO selects a random vector and calculate For i∈[1,l], randomly select t i ∈Z p , calculate the ciphertext C = me(g β ,w),C1=g s ,

[0065] Then, assuming Timestamp The set of indices of all 0 bits of is the output of the algorithm TEncode(t,T), and then calculates the time ciphertext component Final ciphertext

[0066] Furthermore, the specific process of outsourcing the decryption of the ciphertext in step (8) is as follows:

[0067] First, the edge nodes ENs parse the information in the ciphertext: the attribute set R is parsed into (R1,...,R k), the access structure AS is (M,ρ),;

[0068] in is a matrix, ρ is a mapping ρ: [l]→Z p ;

[0069] Then, assume I = {i:ρ(i)∈S} and a constant set {ω i ∈Z p} i∈I , when there is a set of attributes full of I that satisfies the access structure, there is ∑ i∈I ω i λ i =s, ENs uses the attribute conversion key to partially decrypt the ciphertext. The decryption process is:

[0070]

[0071] The edge node ENs finally obtains the converted ciphertext as And store waiting DU request.

[0072] Furthermore, the specific process of decrypting the ciphertext in step (9) is as follows:

[0073] First obtain the system public key MPK and update the ciphertext Private Key and DU's sk id ;

[0074] in

[0075] The data user then chooses a random number z=sk id ∈Z p To blind the key And send the blinded decryption key to ENs that help it outsource decryption;

[0076] The edge nodes ENs calculate the constant vector z=(z0,z1,...,z n ), calculate the following ciphertext components:

[0077]

[0078]

[0079] Calculate the partial decrypted ciphertext Afterwards Send to DU;

[0080] The data user DU decrypts the received partial ciphertext Decrypt and get the plaintext

[0081] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0082] (1) The present invention uses identity-based layered encryption to delegate the keys of senior users to subordinates. In the key delegation process, puncturable keys are introduced to restrict access rights, and revoking punctured tags enables effective restoration of restricted privileges to previous tags.

[0083] (2) The present invention takes into account the need to directly restrict all user access rights and server-assisted user revocation. Through trusted institutions and edge nodes, as well as efficient public ciphertext updates, the present invention ensures forward-secure revocation of outsourced data after user use. In addition, edge nodes can assist data users in partially decrypting ciphertext to reduce the user's decryption burden. BRIEF DESCRIPTION OF THE DRAWINGS

[0084] Figure 1 It is a system model diagram of the present invention;

[0085] Figure 2 This is a comparison chart of permission revocation costs in the embodiment;

[0086] Figure 3 This is a comparison chart of permission recovery overhead in the embodiment. DETAILED DESCRIPTION

[0087] The technical solution of the present invention is described in detail below, but the protection scope of the present invention is not limited to the embodiments.

[0088] The present invention realizes coarse-grained user revocation while supporting hierarchical organization of dynamic hierarchical access control. The data owner (DO) formulates access policies and a set of descriptive tags for the data. The data user (DU) can correctly decrypt the ciphertext only when the attribute set of the data user (DU) satisfies the access structure of the ciphertext and the ciphertext does not contain a tag whose key is pierced. The puncture key of the data user is distributed by its manager, and the attribute key is uniformly distributed by the KGC. The system supports two types of access control operations. For dynamic access control between fine-grained levels, it supports fine-grained revocation and restoration of user access rights to partial data. For coarse-grained access control, it supports server-assisted user revocation. After the KGC revokes the user, the ENs updates the user attribute conversion key stored therein by generating key update materials by the KGC to realize user revocation. At the same time, the CSP will publicly update the ciphertext according to the time period to ensure the forward security of user revocation.

[0089] In order to facilitate understanding of the technical solution of this embodiment, the meanings of the relevant variables are first explained, and the specific contents are shown in Table 1.

[0090] Table 1

[0091]

[0092] like Figure 1 As shown, the present invention mainly involves the following entities, namely, a key distribution center (KGC), edge nodes (ENs), data owners (DO), data users (DU), and cloud service providers (CSP), and specifically includes the following steps:

[0093] Step (1): The key distribution center KGC runs the group generator Gen to initialize the system and obtain the system master public key MPK and the system master private key MSK; and initializes the key distribution center KGC, cloud service provider CSP, data owner DO, data user DU, and edge node ENs respectively;

[0094] Among them, the public key of the data user DU is pk id , the private key is sk id ;The cloud service provider CSP, data owner DO and edge nodes ENs all store the system master public key MPK and the system master private key MSK;

[0095] Step (2): In the key generation phase, the key distribution center KGC and its administrator generate user keys for data users; that is, when a data user initiates an access request to the system, the key distribution center KGC generates an attribute conversion key tk based on the user attribute R. id and pierceable keys And send it to the highest-level data users and edge nodes ENs through secure channels;

[0096] Step (3): In the permission revocation phase, each layer of data user revokes the access rights of its subordinate data according to its needs. The specific method is as follows:

[0097] High-level users first use their own puncture key and the ids of its subordinates k+1 Distribute puncturable keys to its subordinates and revoke permissions, then k+1 Perform key delegation, then the high-level user punctures the key according to the tag set, and merges the puncture keys of the high-level user's subordinates Subordinates who possess this key cannot access the ciphertext containing the labels of the corresponding label set;

[0098] Step (4), in the permission restoration phase, the hierarchical user, when necessary, restores the previously revoked data access rights of its subordinates. The specific method is as follows:

[0099] Data user DU according to identity vector Request its manager to restore the included tag t iAfter receiving the ciphertext, the manager first restores part of the data rights of the data owner DO; the data user DU re-randomizes part of the puncturable key; the final user deletes the tag t i The relevant key;

[0100] Step (5): In the key update phase, the edge node ENs uses the key update material to update the attribute conversion key stored therein. The specific method is as follows:

[0101] The key distribution center KGC parses the current time period t into For all nodes, record the indices where all bits in the timestamp are 0 to calculate the key update material ku θ , and calculate the key update material ku at period t t And broadcast it to the edge nodes ENs. After receiving it, the edge nodes ENs update their own stored attribute conversion keys;

[0102] Step (6), ciphertext generation phase, the data owner DO runs the encryption algorithm to encrypt the corresponding plaintext information m and obtains the ciphertext CT;

[0103] Step (7), ciphertext update phase, after the data user revokes the permission, the cloud service provider CSP updates the ciphertext within the new time period t and obtains the updated ciphertext CT t ;

[0104] When the system reaches a new time period t, CSP calculates the index set V where all bits of the timestamp t are 0; then it updates the ciphertext CT stored in it according to the index set V and calculates Get the ciphertext under time period t

[0105] Step (8), ciphertext outsourcing decryption phase, edge nodes ENs use the conversion key of the attribute key to decrypt part of the ciphertext and obtain the converted ciphertext

[0106] Step (9), during the ciphertext decryption phase, the data user DU that meets the access policy initiates an access request to the edge node ENs through the system public key MPK and obtains the ciphertext CT t2 After that, when the ciphertext does not contain the tag that the data user DU key is punctured, the data user DU runs the decryption algorithm to obtain the plaintext m

[0107] Step (10), user revocation phase, KGC adds the malicious user's ID to the revocation list rl, and the edge node ENs updates the key of the unrevoked user and obtains the updated revocation list as follows:

[0108] rl←rl∪(id,t).

[0109] The detailed process of step (1) is:

[0110] The key distribution center KGC runs the group generator Gen(1 λ )Get parameters parms=(p,G,G T ,e,g), where g is the generator of the group G, and e is a bilinear map e:G×G→G T ;

[0111] Then KGC selects the bounded time T of the system and calculates l1=log2T, random values ​​w,w0,w1,…,w n ,u0,u1,…,u l ,h1,…,h U ,v0,v1,…,v l1 ∈G and a,α,β,t0∈Z p ; Where t0 is a distinguishing mark that will not be used in encryption;

[0112] Then KGC chooses the hash function H1: {0,1} * →G, H2: {0,1} * →Z p ; Label space and identity space And a binary tree BT with at least N leaf nodes, finally generating the system master public key MPK={parms,e(g,g) α ,g β ,g a ,w,w0,w1,…,w n ,u0,u1,…,u l ,h1,…,h U ,v0,v1,…,v l1 ,H1,H2} and system master private key MSK={β,α};

[0113] Data user DU uses random value γ id ∈Z p Calculate the key: sk id =γ id .

[0114] Furthermore, the process of generating the key in step (2) is as follows:

[0115] Step (2.1), after the data user initiates an access request to the system, KGC generates an attribute key based on the user attribute R;

[0116] First, input the user attribute set R and calculate the attribute key components for each attribute in R;

[0117] Then for each attribute in R, KGC selects a leaf node of an undefined BT and stores the id in the node;

[0118] Then, according to the id selected in step (3-1-2), the path Path(id) from the root node of the tree BT to id is calculated. For each node θ on the path Path(id), if g in node θ θ Has been defined for direct use (where g θ is the corresponding value stored in node θ), otherwise a random value g is selected θ ∈G, and update st to st∪(θ,g θ ) to update the value of node θ (st is the key-value pair of the node and the node storage value in the tree);

[0119] Choose t′∈Z p and calculate Calculation: tk1 = g θ 'g at′ ,tk2=g t′ , tk θ =(tk1,tk2,{tk 3,τ} τ∈[k] );

[0120] where tk1, tk2, tk 3,τ All are intermediate variables; finally the conversion key tk is obtained id ={(id,R),{tk θ} θ∈Path(id)};

[0121] Step (2.2), KGC selects a random value r, r id ∈Z p , then calculate the puncturable key

[0122]

[0123] Output conversion key tk id and pierceable keys And sent to the highest-level users and edge nodes ENs through secure channels.

[0124] The specific method for revoking permissions in step (3) is:

[0125] Step (3.1) The high-level user uses his own puncture key and the ids of its subordinates k+1Distribute puncturable keys and revoke permissions for its subordinates, where k represents the depth of the hierarchical organization where the top level is located;

[0126] Step (3.2), select a random number r′ id ∈Z p , and according to id k+1 To delegate the key:

[0127]

[0128] Step (3.3), high-level users puncture the key according to the tag set, for the newly added (t i ,...,t j ) selects a random value r for each label in i ′,λ i , r i ∈Z p , and calculate:

[0129]

[0130]

[0131] Step (3.4), the high-level user saves the corresponding secret value λ for each tag i , such as: ({t i :λ i},…,{t k :λ k}) and merge to get the puncture key of the subordinates of the high-level user Subordinates with this key cannot access the tag set Tag∪t i ...∪t j The ciphertext of the label.

[0132] Step (4) Specific process of restoring permissions:

[0133] The data user DU first Request its manager to restore the included tag t i The ciphertext of t i Find the {t saved during puncture i :λ i} to restore some data permissions of the data owner DO;

[0134] Then, the data user manager receives the sk from the data user DU. 0,1 , choose a random value r i ′∈Z p ,calculate And sk′ 0,1 Sent to data user DU;

[0135] The data user DU receives the processed sk 0,1 Then, use the random value r i 'Complete (sk 0,2 ,sk 0,3 ) re-randomization;

[0136]

[0137] Then the user deletes the tag t i The relevant key (sk i,1 ,sk i ,sk i,3 ), then the puncture label is completed i revocation.

[0138] The specific method for key update in step (5) is:

[0139] The key distribution center KGC parses the current time period t into (l1 is log2T), let t[i] be the i-th bit of timestamp t;

[0140] For all nodes θ∈KUNodes(st,rl,t), randomly select And define a set V∈[l] to record the indices of all bits 0 in the timestamp to calculate the key update material ku θ =(ku1,ku2):

[0141]

[0142] Calculate the key update material ku at period t t =(t,{ku θ} θ∈KUNodes(st,rl,t) ) and broadcast it to edge nodes ENs;

[0143] The edge nodes ENs receive the ku t Update the attribute conversion key stored in itself. If Path(id)∩KUNodes(st,rl,t)=(), then terminate. Otherwise, there exists a θ∈Path(id)∩KUNodes(st,rl,t);

[0144] Let V be the index set of all 0 bits of timestamp t, and the edge node ENs updates its own stored attribute conversion key utk id,t =((id,R,t),utk1,utk2,{utk 3,τ} τ∈[k] ,utk4);

[0145] utk1=tk1;

[0146]

[0147] utk2=tk2=g t′ ,

[0148] The specific process of generating ciphertext in step (6) is as follows:

[0149] Data owner DO input (MPK,m,S,id k ,AS,t), m is the encrypted plaintext, and identity vector id k =(I1,…,I k ), AS=(M,ρ);

[0150] Then use a univariate polynomial Define a constant vector z=(z0,z1,...,z n ), for each i∈[1,k], calculate id i =H(I i );

[0151] Next, the data owner DO selects a random vector and calculate For i∈[1,l], randomly select t i ∈Z p , calculate the ciphertext C =

[0152] me(g β ,w),C1=g s ,

[0153] Then, assuming Timestamp The set of indices of all 0 bits of is the output of the algorithm TEncode(t,T), and then calculates the time ciphertext component Final ciphertext

[0154] The specific process of step (8) ciphertext outsourcing decryption is as follows:

[0155] First, the edge nodes ENs parse the information in the ciphertext: the attribute set R is parsed into (R1,...,R k ), the access structure AS is (M,ρ),;

[0156] in is a matrix, ρ is a mapping ρ: [l]→Z p ;

[0157] Then, assume I = {i:ρ(i)∈S} and a constant set {ω i ∈Z p} i∈I , when there is a set of attributes full of I that satisfies the access structure, there is ∑ i∈I ω i λ i =s, ENs uses the attribute conversion key to partially decrypt the ciphertext. The decryption process is:

[0158]

[0159]

[0160] The edge node ENs finally obtains the converted ciphertext as And store waiting DU request.

[0161] The specific process of decrypting the ciphertext in step (9) is as follows:

[0162] First obtain the system public key MPK and update the ciphertext Private Key and DU's sk id ;

[0163] in

[0164] The data user then chooses a random number z=sk id ∈Z p To blind the key And send the blinded decryption key to ENs that help it outsource decryption;

[0165] The edge nodes ENs calculate the constant vector z=(z0,z1,...,z n ), calculate the following ciphertext components:

[0166]

[0167] Calculate the partial decrypted ciphertext Afterwards Send to data user DU; data user DU decrypts the received ciphertext Decrypt and get the plaintext

[0168] To further verify the effect of the present invention, this embodiment is run on a virtual machine with Ubuntu 20.04.4 LTS operating system and 4GB RAM, and the host machine's CPU is 11th generation Core TM i7-11700@3.40GHz.

[0169] The functional implementation of the technical solution of the present invention is compared, and the results are shown in Table 2. The technical solution of the present invention supports more suitable hierarchical authority control functions.

[0170] Table 2

[0171]

[0172] Comparing the revocation and restoration of the rights of the technical solution of the present invention, the results are as follows: Figure 2 and Figure 3 As shown, under general circumstances, the technical solution of the present invention still has high dynamic permission control efficiency under relatively secure privacy protection.

Claims

1. A dynamic hierarchical data access control method based on recoverable puncture encryption, characterized in that: The following steps are involved: Step (1): The key distribution center KGC runs the group generator Gen to initialize the system and obtain the system master public key MPK and the system master private key MSK; and initializes the key distribution center KGC, cloud service provider CSP, data owner DO, data user DU, and edge node ENs respectively; Among them, the public key of the data user DU is pk id , the private key is sk id ;The cloud service provider CSP, data owner DO and edge nodes ENs all store the system master public key MPK and the system master private key MSK; Step (2): In the key generation phase, the key distribution center KGC and its administrator generate user keys for data users; that is, when a data user initiates an access request to the system, the key distribution center KGC generates an attribute conversion key tk based on the user attribute R. id and pierceable keys And send it to the highest-level data users and edge nodes ENs through secure channels; Step (3): In the permission revocation phase, the data users of each hierarchical user revoke the access rights of their subordinate data according to their needs. The specific method is as follows: High-level users first use their own puncture key and the ids of its subordinates k+1 Distribute puncturable keys to its subordinates and revoke permissions, then k+1 Perform key delegation, then the high-level user punctures the key according to the tag set, and merges the puncture keys of the high-level user's subordinates Subordinates who possess this key cannot access the ciphertext containing the labels of the corresponding label set; Step (4), in the permission restoration phase, the hierarchical user, when necessary, restores the previously revoked data access rights of its subordinates. The specific method is as follows: The data user DU first Request its manager to restore the included tag t i The ciphertext of t i Find the {t saved during puncture i :λ i } to restore some data permissions of the data owner DO; Then, the data user manager receives the sk from the data user DU. 0,1 , choose a random value r′ i ∈Z p ,calculate And sk′ 0,1 Sent to data user DU; The data user DU receives the processed sk 0,1 Then, use the random value r′ i Complete (sk 0,2 ,sk 0,3 ) re-randomization; Then the user deletes the tag t i The relevant key (sk i,1 ,sk i ,sk i,3 ), then the puncture label is completed i revocation; Step (5): In the key update phase, the edge node ENs uses the key update material to update the attribute conversion key stored therein. The specific method is as follows: The key distribution center KGC parses the current time period t into For all nodes, record the indices where all bits in the timestamp are 0 to calculate the key update material ku θ , and calculate the key update material ku at period t t , and broadcast it to the edge nodes ENs. After receiving it, the edge nodes ENs update their own stored attribute conversion keys; Step (6), ciphertext generation phase, the data owner DO runs the encryption algorithm to encrypt the corresponding plaintext information m and obtains the ciphertext CT; Step (7), ciphertext update phase, after the data user revokes the permission, the cloud service provider CSP updates the ciphertext within the new time period t and obtains the updated ciphertext CT t ; When the system reaches a new time period t, CSP calculates the current timestamp The index set V with all bits 0 is then updated according to the index set V, and the ciphertext CT stored therein is calculated. ∏ i∈v C 6,i =(v0∏ i∈V v i ) s , get the ciphertext under time period t Step (8), ciphertext outsourcing decryption phase, edge nodes ENs use the conversion key of the attribute key to decrypt part of the ciphertext and obtain the converted ciphertext Step (9), during the ciphertext decryption phase, the data user DU that meets the access policy initiates an access request to the edge node ENs through the system public key MPK and obtains the ciphertext CT t2 Afterwards, when the ciphertext does not contain the tag indicating that the data user DU's key has been compromised, the data user DU runs the decryption algorithm to obtain the plaintext m. The specific process is as follows: First obtain the system public key MPK and update the ciphertext Private Key and DU's sk id ; in The data user then chooses a random number z=sk id ∈Z p To blind the key And send the blinded decryption key to ENs that help it outsource decryption; The edge nodes ENs calculate the constant vector z=(z0,z1,...,z n ), calculate the following ciphertext components: Calculate the partial decrypted ciphertext Afterwards Send to DU; The data user DU decrypts the received partial ciphertext Decrypt and get the plaintext Step (10), user revocation phase, KGC adds the malicious user's ID to the revocation list rl, and the edge node ENs updates the key of the unrevoked user and obtains the updated revocation list as follows: rl←rl∪(id,t).

2. The dynamic hierarchical data access control method based on recoverable puncture encryption according to claim 1 is characterized in that: The detailed process of step (1) is as follows: The key distribution center KGC runs the group generator Gen(1 λ )Get parameters parms=(p,G,G T ,e,g), where g is the generator of the group G, and e is a bilinear map e:G×G→G T ; Then KGC selects the system bounded time T, and then calculates l1=log2T, the random value and a,α,β,t0∈Z p ; Where t0 is a distinguishing mark that will not be used in encryption; Then KGC chooses the hash function H1: {0,1} * →G, H2: {0,1} * →Z p ; Label space and identity space And a binary tree BT with at least N leaf nodes, which ultimately generates the system master public key and system master private key MSK = {β,α}; Data user DU uses random value γ id ∈Z p Calculate the key: sk id =γ id .

3. The dynamic hierarchical data access control method based on recoverable puncture encryption according to claim 1 is characterized in that: The process of generating the key in step (2) is as follows: Step (2.1), after the data user initiates an access request to the system, KGC generates an attribute key based on the user attribute R; First, input the user attribute set R and calculate the attribute key components for each attribute in R; Then for each attribute in R, KGC selects a leaf node of an undefined BT and stores the id in the node; Then, based on the selected id, the path Path(id) from the root node of the tree BT to the id is calculated. For each node θ on the path Path(id), if g in the node θ θ If it has been defined, use it directly, otherwise choose a random value g θ ∈G, and update st to st∪(θ,g θ ) to update the value of node θ; Choose t′∈Z p and calculate Calculation: tk1 = g θ 'g at′ ,tk2=g t′ , tk θ =(tk1,tk2,{tk 3,τ } τ∈[k] ); where tk1, tk2, tk 3,τ All are intermediate variables; finally the conversion key tk is obtained id ={(id,R),{tk θ } θ∈Path(id) }; Step (2.2), KGC selects a random value r, r id ∈Z p , then calculate the puncturable key sk 0,2 =g r ; Output conversion key tk id and pierceable keys And sent to the highest-level users and edge nodes ENs through secure channels.

4. The dynamic hierarchical data access control method based on recoverable puncture encryption according to claim 1 is characterized in that: The specific method of revoking the authority in step (3) is: Step (3.1) The high-level user uses his own puncture key and the ids of its subordinates k+1 Distribute puncturable keys and revoke permissions for its subordinates, where k represents the depth of the hierarchical organization where the top level is located; Step (3.2), select a random number r′ id ∈ p , and according to id k+1 To delegate the key: Step (3.3), high-level users puncture the key according to the tag set, for the newly added (t i ,...,t j ) selects a random value r′ for each label in i ,λ i , r i ∈Z p , and calculate: Step (3.4), the high-level user saves the corresponding secret value λ for each tag i ,({t i :λ i },…,{t k :λ k }) and merge to get the puncture key of the subordinates of the high-level user Subordinates with this key cannot access the tag set Tag∪t i ...∪t j The ciphertext of the label.

5. The dynamic hierarchical data access control method based on recoverable puncture encryption according to claim 1 is characterized in that: The specific method for key update in step (5) is: The key distribution center KGC parses the current time period t into Let t[i] be the i-th bit of timestamp t; For all nodes θ∈KUNodes(st,rl,t), randomly select And define a set V∈[l] to record the indices of all bits 0 in the timestamp to calculate the key update material ku θ =(ku1,ku2): Calculate the key update material ku at period t t =(t,{ku θ } θ∈KUNodes(st,rl,t) ) and broadcast it to edge nodes ENs; The edge nodes ENs receive the ku t Update the attribute conversion key stored in itself. If Path(id)∩KUNodes(st,rl,t)=(), then terminate. Otherwise, there exists a θ∈Path(id)∩KUNodes(st,rl,t); Let V be the index set of all 0 bits of timestamp t, and the edge node ENs updates its own stored attribute conversion key utk id,t =((id,R,t),utk1,utk2,{utk 3,τ } τ∈[k] ,utk4); utk1=tk1; utk2=tk2=g t′ , 6. The dynamic hierarchical data access control method based on recoverable puncture encryption according to claim 1 is characterized in that: The specific process of generating the ciphertext in step (6) is as follows: Data owner DO input (MPK,m,S,id k ,AS,t); m is the encrypted plaintext, d≤n,id k =(I1,…,I k ) is the identity vector, AS = (M, ρ); Then use a univariate polynomial Define a constant vector z=(z0,z1,...,z n ), for each i∈[1,k], calculate id i =H(I i ); Next, the data owner DO selects a random vector and calculate For i∈[1,l], randomly select t i ∈Z p , calculate the ciphertext C = me(g β ,w),C1=g s , Then, assuming Current timestamp The set of indices of all 0 bits of is the output of the algorithm TEncode(t,T), and then calculates the time ciphertext component Final ciphertext 7. The dynamic hierarchical data access control method based on recoverable puncture encryption according to claim 1 is characterized in that: The specific process of outsourcing the decryption of the ciphertext in step (8) is as follows: First, the edge nodes ENs parse the information in the ciphertext: the attribute set R is parsed into (R1,...,R k ), the access structure AS is (M,ρ),; in is a matrix, ρ is a mapping, ρ: [l] → Z p ; Then, assume I = {i:ρ(i)∈S} and a constant set {ω i ∈Z p } i∈I , when there exists an attribute set I that satisfies the access structure, there is ∑ i∈I ω i λ i =s, ENs uses the attribute conversion key to partially decrypt the ciphertext. The decryption process is: The edge node ENs finally obtains the converted ciphertext as And store waiting DU request.

Citation Information

Patent Citations

  • Fine-grained extensible identity-based broadcast encryption method and system

    CN116318951A

  • Forward security encrypted data controllable editing method in cloud environment

    CN119210813A