Interactive attribute-based encryption and decryption method and system
By handing the decryption task to the service provider (CSP) and leveraging blockchain technology, the problem of high decryption computational overhead in attribute-based encryption is solved, the decryption efficiency and security of lightweight devices are improved, and fine-grained control over data access is achieved.
Patent Information
- Application Number
- CN202510260083.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-03-06
AI Technical Summary
Existing attribute-based encryption (ABE) schemes require a large number of pairing operations during decryption, resulting in significant computational overhead on lightweight devices.
By outsourcing the computational tasks in the decryption process to the service provider (CSP) and leveraging blockchain technology to ensure the integrity and immutability of key components and access structures, the computational burden on data users is reduced.
It significantly improves decryption efficiency, enhances system security, prevents unauthorized access, and enables fine-grained control over data access rights.
Smart Images

Figure CN119760754B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of encryption and decryption technology, and in particular relates to an interactive attribute-based encryption and decryption method and system. Background Art
[0002] In existing attribute-based encryption (ABE) schemes, the decryption process requires a large number of pairing operations, which leads to significant computational overhead on lightweight devices. Summary of the Invention
[0003] The embodiments of the present application provide an interactive attribute-based encryption and decryption method and system, which can solve the technical problem of existing attribute-based encryption and decryption methods, in which the decryption process requires a large number of pairing operations, which will cause significant computing overhead on lightweight devices.
[0004] In a first aspect, an embodiment of the present application provides an interactive attribute-based encryption and decryption method, including:
[0005] The attribute authority AA executes the initialization algorithm to generate the system public parameter PP, the master key MSK and the attribute-based encrypted access structure AS;
[0006] For each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components;
[0007] The data owner DO uses the system public parameter PP and the access structure AS to encrypt the data D to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components ;
[0008] The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network;
[0009] Authorizing the user USER to obtain the ciphertext CT and the access structure AS from the blockchain network;
[0010] The authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP. Interactive decryption task;
[0011] The authorized user USER receives the decryption result fed back by the target service provider CSP.
[0012] In a possible implementation of the first aspect, the authorized user USER executes the interactive attribute-based decryption algorithm, which also includes:
[0013] The authorized user USER verifies whether the attribute of the authorized user USER satisfies the data access policy defined by the access structure AS;
[0014] If the data access policy defined by the access structure AS is met, the step of authorizing the user USER to execute the interactive attribute-based decryption algorithm is executed.
[0015] In a possible implementation of the first aspect, an intermediate key is generated. The calculation formula is:
[0016] ;
[0017] in, represents the ciphertext component generated by the data owner DO; Represents the product symbol, used to represent the Each element in Perform multiplication operations; Represents an index set, which represents a collection of attributes; Representation and attributes a key component of the associated first component; a key component representing an attribute-independent first component for encryption; Representation and attributes a key component of the associated second component; a key component representing an attribute-independent second component for encryption; Representation and attributes a key component of the associated third component; Represents a bilinear mapping function; a key component representing a first component associated with the attribute for encryption; Representation and attributes a key component of the associated first component; a key component representing a first component that is independent of the attribute; a key component representing a second component associated with the attribute for encryption; Representation and attributes a key component of the associated second component; a key component representing a second component that is independent of the attribute; a key component representing a third component associated with the attribute for encryption; Representation and attributes a key component of the associated third component; A key component representing a third component that is not associated with the attribute.
[0018] In a possible implementation of the first aspect, the intermediate key is sent to the target service provider CSP. The interactive decryption task previously included:
[0019] The target service provider CSP is determined using the following formula:
[0020] ;
[0021] in, Indicates the candidate service provider CSPs; Represents the set of all candidate service providers; Indicates the The current load of each CSP; Indicates the Network latency of each CSP; Indicates the The computing power or capacity of each CSP; Represents a set of attributes; Representation attributes Importance weight in access structure AS; Representation attributes Type; represents the distance factor; Indicates task priority; Indicates the The geographical location factor of each CSP; It represents the average value of the geographic location factor of all CSPs.
[0022] In a possible implementation of the first aspect, the authorized user USER receiving the decryption result fed back by the target service provider CSP includes:
[0023] The authorized user USER receives the decryption result from the target service provider CSP through the communication channel;
[0024] Using blockchain technology to verify whether the hash value of the decryption result matches the expected value;
[0025] If they match, the decryption result is stored; if they do not match, the smart contract will trigger an error handling mechanism.
[0026] In a second aspect, an embodiment of the present application provides an interactive attribute-based encryption and decryption system, including: an attribute authority AA, a data owner DO, an authorized user USER, and a target service provider CSP;
[0027] The attribute authorization agency AA is used to execute the initialization algorithm to generate the system public parameter PP, the master key MSK and the attribute-based encrypted access structure AS; for each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components;
[0028] The data owner DO is used to encrypt the data D using the system public parameter PP and the access structure AS to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network;
[0029] The authorized user USER obtains the ciphertext CT and the access structure AS from the blockchain network; the authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP interactive decryption task; the authorized user USER receives the decryption result fed back by the target service provider CSP.
[0030] In a third aspect, an embodiment of the present application provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the interactive attribute-based encryption and decryption method described in any one of the first aspects above is implemented.
[0031] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the interactive attribute-based encryption and decryption method described in any one of the first aspects above is implemented.
[0032] In a fifth aspect, an embodiment of the present application provides a computer program product. When the computer program product is run on a computer device, the computer device executes the interactive attribute-based encryption and decryption method described in any one of the first aspects above.
[0033] In this embodiment of the application, the attribute authorization agency AA executes the initialization algorithm to generate the system public parameter PP, the master key MSK and the attribute-based encrypted access structure AS; for each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components; the data owner DO uses the system public parameter PP and the access structure AS to encrypt the data D to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network; the authorized user USER obtains the ciphertext CT and the access structure AS from the blockchain network; the authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP. The interactive decryption task is performed by the authorized user USER; the authorized user USER receives the decryption result fed back by the target service provider CSP. By exchanging the interactive decryption task with the target service provider CSP, the authorized user USER does not need to perform a large amount of calculations on the lightweight device, thereby significantly improving the decryption efficiency. In addition, the use of blockchain technology ensures the integrity and immutability of key components and access structures, thereby improving the security of the system. Intermediate key The use of increases the security of the interactive decryption process and prevents unauthorized access.
[0034] It can be understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0036] Figure 1 This is a schematic flow chart of an interactive attribute-based encryption and decryption method provided in one embodiment of the present application;
[0037] Figure 2 This is a schematic diagram of the structure of the interactive attribute-based encryption and decryption system provided in an embodiment of the present application;
[0038] Figure 3 It is a structural diagram of the computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0039] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0040] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0041] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0042] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0043] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0044] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0045] In existing attribute-based encryption (ABE) schemes, the decryption process requires a large number of pairing operations, which will lead to significant computational overhead on lightweight devices. To solve this problem, this application proposes an interactive attribute-based encryption and decryption method, which reduces the computational burden of data users during the decryption process by handing over the computational tasks in the decryption process to the service provider (CSP). Figure 1 A schematic flow chart of an interactive attribute-based encryption and decryption method provided in one embodiment of the present application is shown. Interactive attribute-based encryption and decryption is a cryptographic method that combines attribute-based encryption and interactive decryption techniques. It allows data to be encrypted and then decrypted by a third party, while also providing fine-grained control over data access rights through attribute-based encryption.
[0046] S101, the attribute authority AA executes an initialization algorithm to generate a system public parameter PP, a master key MSK and an attribute-based encrypted access structure AS.
[0047] The attribute authority AA executes the initialization algorithm Setup to generate the system public parameters PP, the master key MSK and the attribute-based encrypted access structure AS.
[0048] The system public parameters PP are a set of parameters that can be accessed by all participants in the system (including the data owner DO, authorized users USER, and service providers). The service provider can be a cloud service provider (CSP).
[0049] Among them, the parameters usually include:
[0050] Mathematical parameters: such as elliptic curve parameters, hash functions, pairing operations, etc. These parameters define the mathematical basis of the encryption algorithm.
[0051] System identifier: an identifier used to distinguish different systems or different instances.
[0052] Encryption algorithm identifier: Specifies the type of encryption algorithm used.
[0053] The master key (MSK) is the core key in the system. It is generated and kept secret by the attribute authority (AA). It is used to generate other key components, including those unrelated to attributes and those related to attributes.
[0054] The generation of the master key (MSK) typically involves a random number generator to ensure it is sufficiently random and unpredictable. After generation, the master key (MSK) is typically stored in a secure environment, such as a hardware security module.
[0055] An access structure (AS) defines which attributes or attribute combinations are capable of decrypting a specific encrypted data. This is the core mechanism for controlling data access rights in attribute-based encryption (ABE). An AS can be simple (e.g., a single attribute) or complex (e.g., logical combinations of attributes, such as AND and OR).
[0056] The generation of the access structure AS requires the definition of the attribute authority AA according to the system requirements and security policies. It can be constructed based on attributes such as user role, department, security level, etc.
[0057] The execution of the initialization algorithm generally includes the following steps:
[0058] Select mathematical parameters: Select appropriate mathematical parameters based on the requirements of the encryption algorithm.
[0059] Generate the master key MSK: Generate the master key using a secure random number generator.
[0060] Define access structure AS: Define the access structure according to system requirements.
[0061] Generate system public parameters PP: Generate system public parameters PP by combining mathematical parameters, system identifiers, etc.
[0062] Distribution parameters: The system public parameters PP are made public to all system participants, while the master key MSK is stored confidentially.
[0063] Throughout the entire process, the attribute authority AA needs to ensure the security of all operations to prevent unauthorized access and leakage.
[0064] S102, for each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components.
[0065] Among them, the key components that are not related to attributes These key components are not associated with a specific attribute and can be used in the encryption process of multiple attributes. They are common parts of the system and are crucial to achieving the flexibility and efficiency of the encryption algorithm.
[0066] The key component associated with the attribute , these key components are for specific attributes Generated, they are directly related to the attributes. They ensure that only users with the corresponding attributes can decrypt the data. This design allows for fine-grained control over data access rights, a core advantage of attribute-based encryption.
[0067] Among them, the key components that are independent of the attributes are generated , these components typically include:
[0068] One or more randomly generated key elements, such as , ,….
[0069] These key elements can be random elements from the group and are used in certain steps of the encryption process.
[0070] Generates key components associated with attributes .
[0071] For each attribute , use a hash function or other mapping function to convert attributes Mapped to a group element, such as The master key MSK and the attribute group element are used to generate the attribute-related key components. For example, for each attribute , generate key components ,in, Represents different components.
[0072] S103, the data owner DO uses the system public parameter PP and the access structure AS to encrypt the data D to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components .
[0073] Among them, the ciphertext component generated by the data owner DO , which is the part directly encrypted from data D during the encryption process, and usually contains the main body of the encrypted data.
[0074] The specific methods of generating the ciphertext CT are mostly existing technologies and will not be described in detail here.
[0075] S104: The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network.
[0076] Smart contracts are used to manage the publication, access, and verification of the ciphertext CT and access structure AS. Smart contracts automatically enforce predefined rules, ensuring that only users who meet the requirements of the access structure AS can decrypt the data. The ciphertext CT and access structure AS are converted into a format suitable for blockchain storage. These data are published to the blockchain using the blockchain platform's application programming interface (API) or software development kit (SDK). After the data is published, its integrity and correctness can be verified through the blockchain network. Leveraging the transparency of the blockchain and the automated execution capabilities of smart contracts, fine-grained control over data access is achieved.
[0077] S105, the authorized user USER obtains the ciphertext CT and the access structure AS from the blockchain network.
[0078] Among them, the authorized user USER retrieves the ciphertext CT and access structure AS published by the data owner DO from the blockchain network.
[0079] S106: The authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP. interactive decryption task.
[0080] Among them, the authorized user USER first needs to verify whether he has the attribute combination that meets the access structure AS. This is a prerequisite for decrypting data. If the attributes of the authorized user USER meet the access structure AS, an intermediate key will be generated using the interactive attribute-based decryption algorithm. This intermediate key It is a key step in the decryption process, which will be used to initiate a decryption request to the service provider CSP. The authorized user USER will contain the intermediate key The interactive decryption task is sent to the selected CSP. This task may include the ciphertext CT, the intermediate key, and other information that may be required, such as the access structure AS.
[0081] The authorized user USER first needs to select a suitable CSP to perform the decryption task. When selecting a CSP, multiple factors may be considered, as described below.
[0082] The interaction here can be understood as outsourcing, where the interactive decryption task is transmitted and outsourced to the CSP to perform the decryption task.
[0083] S107: The authorized user USER receives the decryption result fed back by the target service provider CSP.
[0084] After receiving the interactive decryption task, the target service provider CSP will use its computing resources to perform the decryption operation. The authorized user USER receives the decryption result from the CSP.
[0085] Optionally, the authorized user USER receives the decryption result from the target service provider CSP through the communication channel; uses blockchain technology to verify whether the hash value of the decryption result matches the expected value; if it matches, stores the decryption result; if it does not match, the smart contract will trigger an error handling mechanism.
[0086] The authorized user USER receives the decryption result from the CSP via a secure communication channel. This can be achieved through a TLS / SSL-encrypted HTTPS connection or a VPN tunnel, ensuring security during data transmission. Blockchain technology is used to verify whether the hash value of the decryption result matches the expected value. Specifically, the expected hash value can be stored on the blockchain. When the decryption result is received, its hash value is calculated and compared with the expected value on the blockchain. If the hash values match, it indicates that the decryption result has not been tampered with and is safe to use. If the hash value of the decryption result is verified, the smart contract will automatically trigger, distribute the decryption result to the relevant users or systems, and store the decryption result in a local secure storage system. If there is a mismatch, the smart contract will trigger an error handling mechanism.
[0087] In the embodiment of the present application, the attribute authority AA executes the initialization algorithm to generate the system public parameter PP, the master key MSK and the attribute-based encrypted access structure AS; for each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components; the data owner DO uses the system public parameter PP and the access structure AS to encrypt the data D to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network; the authorized user USER obtains the ciphertext CT and the access structure AS from the blockchain network; the authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP. The interactive decryption task is performed by the authorized user USER; the authorized user USER receives the decryption result fed back by the target service provider CSP. By exchanging the interactive decryption task with the target service provider CSP, the authorized user USER does not need to perform a large amount of calculations on the lightweight device, thereby significantly improving the decryption efficiency. In addition, the use of blockchain technology ensures the integrity and immutability of key components and access structures, thereby improving the security of the system. Intermediate key The use of increases the security of the interactive decryption process and prevents unauthorized access.
[0088] In an optional embodiment, the authorized user USER executes the interactive attribute-based decryption algorithm, which also includes:
[0089] The authorized user USER verifies whether the attributes of the authorized user USER meet the data access policy defined by the access structure AS; if the data access policy defined by the access structure AS is met, the step of the authorized user USER executing the interactive attribute-based decryption algorithm is executed.
[0090] In an embodiment of the present application, the authorized user USER first needs to verify whether he or she possesses a combination of attributes that satisfies the definition of the access structure AS. The access structure AS defines which attribute combinations can decrypt specific data. For example, AS may be defined as "the user must possess both attribute A and attribute B." If the user's attributes satisfy the data access policy defined by the access structure AS, the user can proceed to execute the steps of the interactive attribute-based decryption algorithm. Among them, by verifying whether the user's attributes satisfy the access structure, it ensures that only authorized users can access specific data, which helps prevent unauthorized access and data leakage. The access structure AS can define complex attribute combinations, thereby achieving fine-grained control over data access. By ensuring that only qualified users can decrypt data, it helps to protect the privacy of the data and prevent sensitive information from being leaked to irrelevant personnel.
[0091] In an optional embodiment, an intermediate key is generated The calculation formula is:
[0092] ;
[0093] in, represents the ciphertext component generated by the data owner DO; Represents the product symbol, used to represent the Each element in Perform multiplication operations; Represents an index set, which represents a collection of attributes; Representation and attributes a key component of the associated first component; a key component representing an attribute-independent first component for encryption; Representation and attributes a key component of the associated second component; a key component representing an attribute-independent second component for encryption; Representation and attributes a key component of the associated third component; represents a bilinear mapping function; a key component representing a first component associated with the attribute for encryption; Representation and attributes a key component of the associated first component; a key component representing a first component that is independent of the attribute; a key component representing a second component associated with the attribute for encryption; Representation and attributes a key component of the associated second component; a key component representing a second component that is independent of the attribute; a key component representing a third component associated with the attribute for encryption; Representation and attributes a key component of the associated third component; A key component representing a third component that is not associated with the attribute.
[0094] It should be noted that the first component corresponds to the "1" at the lower right corner of the character. The second component corresponds to the "2" at the lower right corner of the character. The third component corresponds to the "3" at the lower right corner of the character.
[0095] The first, second, and third components mentioned above refer to the different parts or stages used to generate keys during the encryption and decryption process. These components are often associated with specific attributes to ensure that only users with the correct attributes can decrypt data. While the first, second, and third pairs of components are used to distinguish them, in practice, this distinction may not always be necessary, especially in simple encryption scenarios. These can be set based on actual needs.
[0096] In an embodiment of the present application, by combining multiple attribute-related and unrelated key components, the combination method can ensure that only users who meet the attribute combination defined by the access structure can generate the correct intermediate key, which increases the difficulty of cracking the key and thus enhances the security of the system. Based on the above means, the system is allowed to flexibly define which attribute combinations can decrypt data according to the access structure AS, thereby achieving fine-grained access control. In addition, by using product symbols and index sets, it can be easily expanded to support more attributes and key components, thereby adapting to different security requirements and business scenarios, and this operation is very important when generating intermediate keys because it ensures that all relevant key components are correctly combined to generate a complete intermediate key.
[0097] In an optional embodiment, the intermediate key is sent to the target service provider CSP. The interactive decryption task previously included:
[0098] The target service provider CSP is determined using the following formula:
[0099] ;
[0100] in, Indicates the candidate service provider CSPs; Represents the set of all candidate service providers; Indicates the The current load of each CSP; Indicates the Network latency of each CSP; Indicates the The computing power or capacity of each CSP; Represents a set of attributes; Representation attributes Importance weight in access structure AS; Representation attributes Type; Indicates the distance factor, such as local or remote; Indicates task priority; Indicates the The geographical location factor of each CSP; It represents the average value of the geographic location factor of all CSPs.
[0101] In the embodiment of the present application, for the load and delay ratio ,This ratio measures the relationship between the current workload and network latency of the CSP and its computing power. By minimizing this ratio, the system can select CSPs with strong computing power, low load, and low latency, thereby improving the execution efficiency of decryption tasks. By weighting these factors, the most appropriate CSP can be selected based on the specific requirements of the decryption task (such as the urgency of decryption). By considering the geographic location, the system can select the CSP with the best geographic location, thereby reducing the delay and cost of data transmission. The above formula ensures that the geographic location factor does not excessively affect the selection due to the particularly favorable or unfavorable geographic location of a single CSP. By dividing it by the sum of the geographic location factors of all CSPs, a standardized geographic location factor can be obtained, thereby more fairly evaluating the impact of each CSP's geographic location on task execution.
[0102] Among them, local CSP usually refers to a service provider that is geographically close to the data source or user location. Due to the short distance, the network latency of data transmission is low, which helps to improve the response speed of decryption tasks. Short data transmission distance usually means lower data transmission cost. If a CSP is local, its distance factor will be relatively small, which helps to reduce the value of the entire formula and makes this CSP a more attractive option.
[0103] The distance factor is typically used to quantify the "distance" between the data source and the CSP. This distance can be actual geographic distance or a measure of network latency. It reflects the potential delays and costs encountered during data transmission. The distance factor is used to prioritize decryption tasks. A smaller distance factor indicates a closer distance between the CSP and the data source or user, potentially lowering network latency and data transmission costs. Selecting a CSP with a smaller distance factor can reduce data transmission time, improve decryption efficiency, and reduce costs.
[0104] The geolocation factor generally refers to the geographic location attributes of a CSP, which may include information such as the CSP's physical location and service area. This factor is used to compare multiple CSPs and select the one with the most advantageous location. The geolocation factor is used to calculate the relative location advantage of a CSP. It is compared with the average geolocation factor of all CSPs to determine the impact of each CSP's location on the decryption task.
[0105] The distance factor focuses more on the efficiency and cost of data transmission, while the location factor examines the impact of the CSP's location on service delivery. The distance factor can be based on actual network measurements or estimates, while the location factor can be based on the CSP's location data. The distance factor directly impacts the efficiency and cost of decryption tasks, while the location factor influences CSP selection and service quality. In practical applications, both factors are crucial when selecting a suitable CSP. By comprehensively considering the distance and location factors, a CSP capable of providing high-quality services can be more effectively selected.
[0106] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0107] Corresponding to the interactive attribute-based encryption and decryption method described in the above embodiment, Figure 2 A structural block diagram of the interactive attribute-based encryption and decryption system provided in an embodiment of the present application is shown. For ease of explanation, only the parts related to the embodiment of the present application are shown.
[0108] Reference Figure 2 ,The interactive attribute-based encryption and decryption system includes: attribute authority AA, data owner DO, authorized user USER and target service provider CSP;
[0109] The attribute authorization agency AA is used to execute the initialization algorithm to generate the system public parameter PP, the master key MSK and the attribute-based encrypted access structure AS; for each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components;
[0110] The data owner DO is used to encrypt the data D using the system public parameter PP and the access structure AS to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network;
[0111] The authorized user USER obtains the ciphertext CT and the access structure AS from the blockchain network; the authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP interactive decryption task; the authorized user USER receives the decryption result fed back by the target service provider CSP.
[0112] In a possible implementation, the interactive attribute-based encryption and decryption system further includes an execution module configured to:
[0113] The authorized user USER verifies whether the attribute of the authorized user USER satisfies the data access policy defined by the access structure AS;
[0114] If the data access policy defined by the access structure AS is met, the step of authorizing the user USER to execute the interactive attribute-based decryption algorithm is executed.
[0115] In one possible implementation, an intermediate key is generated The calculation formula is:
[0116] ;
[0117] in, represents the ciphertext component generated by the data owner DO; Represents the product symbol, used to represent the Each element in Perform multiplication operations; Represents an index set, which represents a collection of attributes; Representation and attributes a key component of the associated first component; a key component representing an attribute-independent first component for encryption; Representation and attributes a key component of the associated second component; a key component representing an attribute-independent second component for encryption; Representation and attributes a key component of the associated third component; represents a bilinear mapping function; a key component representing a first component associated with the attribute for encryption; Representation and attributes a key component of the associated first component; a key component representing a first component that is independent of the attribute; a key component representing a second component associated with the attribute for encryption; Representation and attributes a key component of the associated second component; a key component representing a second component that is independent of the attribute; a key component representing a third component associated with the attribute for encryption; Representation and attributes a key component of the associated third component; A key component representing a third component that is not associated with the attribute.
[0118] In a possible implementation, the interactive attribute-based encryption and decryption system further includes a determination module configured to:
[0119] The target service provider CSP is determined using the following formula:
[0120] ;
[0121] in, Indicates the candidate service provider CSPs; Represents the set of all candidate service providers; Indicates the The current load of each CSP; Indicates the Network latency of each CSP; Indicates the The computing power or capacity of each CSP; Represents a set of attributes; Representation attributes Importance weight in access structure AS; Representation attributes Type; represents the distance factor; Indicates task priority; Indicates the The geographical location factor of each CSP; It represents the average value of the geographic location factor of all CSPs.
[0122] In a possible implementation, the authorized user USER is used to:
[0123] receiving a decryption result from a target service provider (CSP) via a communication channel;
[0124] Using blockchain technology to verify whether the hash value of the decryption result matches the expected value;
[0125] If they match, the decryption result is stored; if they do not match, the smart contract will trigger an error handling mechanism.
[0126] It should be noted that the information interaction, execution process and other contents between the above modules are based on the same concept as the method embodiment of this application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0127] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0128] An embodiment of the present application also provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor implements the steps of any of the above-mentioned method embodiments when executing the computer program.
[0129] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned various method embodiments can be implemented.
[0130] An embodiment of the present application provides a computer program product. When the computer program product is run on a computer device, the computer device can implement the steps in the above-mentioned method embodiments when executing the computer program product.
[0131] Figure 3 This is a schematic diagram of the structure of a computer device provided in one embodiment of the present application. Figure 3 As shown, the computer device of this embodiment includes: at least one processor 20 ( Figure 3 Only one is shown), a memory 21 and a computer program 22 stored in the memory 21 and executable on the at least one processor 20, wherein the processor 20 implements the steps of any of the above-mentioned interactive attribute-based encryption and decryption method embodiments when executing the computer program 22.
[0132] The computer device may include, but is not limited to, a processor 20 and a memory 21. Those skilled in the art will understand that Figure 3 The computer device is merely an example and does not constitute a limitation on the computer device. The computer device may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device may also include input and output devices, network access devices, etc.
[0133] The processor 20 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.
[0134] In some embodiments, the memory 21 may be an internal storage unit of the computer device, such as a hard disk or memory of the computer device. In other embodiments, the memory 21 may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped with the computer device. Furthermore, the memory 21 may include both an internal storage unit of the computer device and an external storage device. The memory 21 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 21 may also be used to temporarily store data that has been output or is about to be output.
[0135] If the integrated unit is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process steps in the above-mentioned method embodiments by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a device / computer equipment, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunication signals, and software distribution media. Examples include USB flash drives, removable hard drives, magnetic disks, or optical disks. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.
[0136] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0137] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0138] In the embodiments provided in this application, it should be understood that the disclosed apparatus / computer equipment and methods can be implemented in other ways. For example, the apparatus / computer equipment embodiments described above are merely schematic. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of the apparatus or unit, which can be electrical, mechanical or other forms.
[0139] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0140] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. An interactive attribute-based encryption and decryption method, characterized in that: include: The attribute authority AA executes the initialization algorithm to generate the system public parameter PP, the master key MSK and the attribute-based encrypted access structure AS; For each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components; The data owner DO uses the system public parameter PP and the access structure AS to encrypt the data D to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components ; The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network; Authorizing the user USER to obtain the ciphertext CT and the access structure AS from the blockchain network; The authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP. Interactive decryption task; The authorized user USER receives the decryption result fed back by the target service provider CSP; The intermediate key is sent to the target service provider CSP. The interactive decryption task previously included: The target service provider CSP is determined using the following formula: ; in, Indicates the candidate service provider CSPs; Represents the set of all candidate service providers; Indicates the The current load of each CSP; Indicates the Network latency of each CSP; Indicates the The computing power or capacity of each CSP; Represents a set of attributes; Representation attributes Importance weight in access structure AS; Representation attributes Type; represents the distance factor; Indicates task priority; Indicates the The geographical location factor of each CSP; It represents the average value of the geographic location factor of all CSPs.
2. The interactive attribute-based encryption and decryption method according to claim 1, wherein: The authorized user USER executes the interactive attribute-based decryption algorithm, which also includes: The authorized user USER verifies whether the attribute of the authorized user USER satisfies the data access policy defined by the access structure AS; If the data access policy defined by the access structure AS is met, the step of authorizing the user USER to execute the interactive attribute-based decryption algorithm is executed.
3. The interactive attribute-based encryption and decryption method according to claim 2, wherein: Generate intermediate keys The calculation formula is: ; in, represents the ciphertext component generated by the data owner DO; Represents the product symbol, used to represent the Each element in Perform multiplication operations; Represents an index set, which represents a collection of attributes; Representation and attributes a key component of the associated first component; a key component representing an attribute-independent first component for encryption; Representation and attributes a key component of the associated second component; a key component representing an attribute-independent second component for encryption; Representation and attributes a key component of the associated third component; represents a bilinear mapping function; a key component representing a first component associated with the attribute for encryption; Representation and attributes a key component of the associated first component; a key component representing a first component that is independent of the attribute; a key component representing a second component associated with the attribute for encryption; Representation and attributes a key component of the associated second component; a key component representing a second component that is independent of the attribute; a key component representing a third component associated with the attribute for encryption; Representation and attributes a key component of the associated third component; A key component representing a third component that is not associated with the attribute.
4. The interactive attribute-based encryption and decryption method according to claim 1, wherein: The authorized user USER receives the decryption result fed back by the target service provider CSP, including: The authorized user USER receives the decryption result from the target service provider CSP through the communication channel; Using blockchain technology to verify whether the hash value of the decryption result matches the expected value; If they match, the decryption result is stored; if they do not match, the smart contract will trigger an error handling mechanism.
5. An interactive attribute-based encryption and decryption system, implementing the method according to any one of claims 1 to 4; characterized in that: The interactive attribute-based encryption and decryption system includes: attribute authority AA, data owner DO, authorized user USER and target service provider CSP; The attribute authorization agency AA is used to execute the initialization algorithm to generate the system public parameter PP, the master key MSK and the attribute-based encrypted access structure AS; for each attribute The attribute authority AA generates a key component that is independent of the attribute based on the master key MSK and the access structure AS and the key components associated with the attributes ;in, Represents different components; The data owner DO is used to encrypt the data D using the system public parameter PP and the access structure AS to generate a ciphertext CT; wherein the ciphertext CT includes the ciphertext components generated by the data owner DO and key components The data owner DO publishes the ciphertext CT and the access structure AS to the blockchain network; The authorized user USER obtains the ciphertext CT and the access structure AS from the blockchain network; the authorized user USER executes the interactive attribute-based decryption algorithm to generate an intermediate key and sends the intermediate key to the target service provider CSP interactive decryption task; the authorized user USER receives the decryption result fed back by the target service provider CSP.
6. The interactive attribute-based encryption and decryption system according to claim 5, characterized in that: Generate intermediate keys The calculation formula is: ; in, represents the ciphertext component generated by the data owner DO; Represents the product symbol, used to represent the Each element in Perform multiplication operations; Represents an index set, which represents a collection of attributes; Representation and attributes a key component of the associated first component; a key component representing an attribute-independent first component for encryption; Representation and attributes a key component of the associated second component; a key component representing an attribute-independent second component for encryption; Representation and attributes a key component of the associated third component; Represents a bilinear mapping function; a key component representing a first component associated with the attribute for encryption; Representation and attributes a key component of the associated first component; a key component representing a first component that is independent of the attribute; a key component representing a second component associated with the attribute for encryption; Representation and attributes a key component of the associated second component; a key component representing a second component that is independent of the attribute; a key component representing a third component associated with the attribute for encryption; Representation and attributes a key component of the associated third component; A key component representing a third component that is not associated with the attribute.
7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 4 is implemented.
8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.
9. A computer program product, characterized in that When the computer program product is run on a computer device, the computer device is caused to perform the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Lightweight access method and system based on block chain
CN113434875A
CP-ABE outsourcing decryption method and device with homomorphic characteristic
CN116318647A