An Encryption and Decryption Method, Device, Equipment, Medium and Product for Access Control Inner Product Function
By building an access control internal product function encryption model and embedding dual internal product predicates and function vectors, the problem of one-way access control in the existing technology is solved, and bidirectional computing permission control and stronger privacy protection are realized.
Patent Information
- Application Number
- CN202510361080.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-26
AI Technical Summary
The prior art can only implement one-way receiver access control, and it is difficult to adapt to more complex computing permission control needs.
By building an access control internal product function encryption model, using the system settings module, key generation module, encryption module and decryption module, the dual internal product predicates and function vectors are embedded to realize two-way access control.
Two-way control of the calculation permissions of the inner product function value is realized, improving the adaptability to the needs of more complex calculation permissions, and strengthening the privacy protection of the recipient.
Smart Images

Figure CN119892501B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of inner product function calculation, and in particular to an access control inner product function encryption and decryption method, device, equipment, medium and product. Background Art
[0002] In the fields of Internet of Things, cloud computing, etc., it is necessary to perform secure calculations on the increasing amount of private data to mine the value of data, that is, to calculate it without leaking the plaintext and obtain the correct calculation results. To address this problem, inner product functional encryption (IPFE) is an effective solution in the field of inner product function calculation. The decryption private key of IPFE is related to a vector. After encrypting the plaintext vector, the ciphertext is obtained, and after decryption, an inner product function value about the plaintext vector is obtained. In addition, no other information about the plaintext vector and the vector contained in the decryption private key will be leaked. However, when the number of keys used for decryption is equal to the dimension of the plaintext vector, the attacker can completely restore the plaintext vector through the combination of multiple private keys, thereby leaking more information, which exceeds the original design goal of only calculating the inner product. Therefore, the existing technology avoids this information leakage problem by introducing an access control mechanism to ensure the confidentiality of the inner product function value.
[0003] Among the existing access control methods, attribute encryption has been widely studied for data access control in cloud environments. Existing technologies mainly focus on how to combine attribute encryption, identity encryption, proxy re-encryption and other technologies with IPFE. However, these methods can only achieve one-way access control for the recipient and cannot protect attribute privacy, making it difficult to adapt to more complex computing permission management requirements. Summary of the invention
[0004] The purpose of this application is to provide an access control inner product function encryption and decryption method, device, equipment, medium and product, which can solve the problem that the existing technology can only implement one-way recipient access control, and thus it is difficult to adapt to more complex computing authority management requirements.
[0005] To achieve the above objectives, this application provides the following solutions:
[0006] In the first aspect, the present application provides an access control inner product function encryption and decryption method, the access control inner product function encryption and decryption method is to encrypt and decrypt by constructing an access control inner product function encryption model, the access control inner product function encryption model is based on a system setting module, a key generation module, an encryption module and a decryption module. The access control inner product function encryption and decryption method includes: converting the security parameter Enter the system settings module and determine the common parameters and the master private key ; The security parameter is used to characterize the security level of a cryptographic primitive; define a vector and a vector as the structure of a double inner product predicate; where represents a pair of vectors associated with the sender, represents a pair of vectors associated with the receiver; represents the sender's predicate vector; t represents the sender's attribute vector; represents the receiver's attribute vector; represents the receiver's predicate vector; input the public parameter , the master private key and three vectors into the key generation module to generate the decryption private key ; where the decryption private key contains three vectors ; represents the function vector related to the decryption private key ; the decryption private key includes the sender's predicate vector , the receiver's attribute vector and the vector related to the decryption private key ; input the public parameter , the master private key and three vectors into the encryption module, and encrypt the sender's data according to the public parameter , the master private key and three vectors to generate a ciphertext; the ciphertext is the encrypted sender's data, and the ciphertext contains three vectors ; represents the vector related to the ciphertext; when the receiver receives the ciphertext, input the ciphertext, the decryption private key and the public parameter into the decryption module for permission matching to determine the first result; based on the first result and the decryption module, obtain the second result; according to the first result and the second result, determine the inner product function value of the vector and the vector ; determine the decrypted ciphertext through the inner product function value of the vector and the vector ; the decrypted ciphertext is the sender's data.
[0007] In a second aspect, the present application provides an access control inner product function encryption and decryption device, including: a system setting module, configured to input the security parameter into the system setting module to determine the public parameter and the master private key ; The security parameter is used to characterize the security level of a cryptographic primitive; a key generation module for defining vectors and vectors as the structure of a double inner product predicate; where represents a pair of vectors associated with the sender, represents a pair of vectors associated with the receiver; represents the sender predicate vector; t represents the sender attribute vector; represents the receiver attribute vector; represents the receiver predicate vector; input the public parameter , the master private key and three vectors into the key generation module to generate the decryption private key ; where the decryption private key contains three vectors ; represents the function vector related to the decryption private key ; the decryption private key includes the sender predicate vector , the receiver attribute vector and the vector related to the decryption private key ; an encryption module for inputting the public parameter , the master private key and three vectors into the encryption module, and encrypting the sender's data according to the public parameter , the master private key and three vectors to generate a ciphertext; the ciphertext is the encrypted sender's data, and the ciphertext contains three vectors ; represents the vector related to the ciphertext; a decryption module for, when the receiver receives the ciphertext, inputting the ciphertext, the decryption private key and the public parameter into the decryption module for permission matching to determine a first result; obtaining a second result based on the first result and the decryption module; determining the inner product function value of the vector and the vector according to the first result and the second result ; determining the decrypted ciphertext through the inner product function value of the vector and the vector ; the decrypted ciphertext is the sender's data.
[0008] In a third aspect, the present application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the computer program to implement the access control inner product function encryption and decryption method described above.
[0009] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the access control inner product function encryption and decryption method described above.
[0010] In a fifth aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the access control inner product function encryption and decryption method described in any one of the above.
[0011] According to the specific embodiments provided by the present application, the following technical effects are disclosed in the present application:
[0012] The present application provides an access control inner product function encryption and decryption method, device, equipment, medium, and product. First, the security parameter is input into the system setup module to determine the public parameter and the recipient's master private key. The vectors and the vector are used as the double inner product predicate. Then, the public parameter , the master private key , and the three vectors are input into the key generation module to generate the decryption private key , and the public parameter , the master private key , and the three vectors are input into the encryption module to generate the ciphertext. In this way, by embedding a part of the vectors related to the recipient and the sender (i.e., the double inner product predicate) and the corresponding function vectors (i.e., the function vector related to the decryption private key and the function vector related to the ciphertext) into the decryption private key and the ciphertext respectively for encryption, two-way access control for the recipient and the sender is achieved in the subsequent permission matching and decryption operations of the inner product function value. Among them, due to the strong attribute hiding property of the structure of the double inner product predicate, the privacy of the recipient is effectively protected, realizing that the data can be calculated but not visible, and being able to more accurately describe the security objective of the access control inner product function encryption and decryption method, that is, only the legitimate recipient who passes the permission matching can obtain the first result, and after obtaining the first result, determine the correct inner product function value , and then obtain the decrypted ciphertext. That is, two-way control over the calculation permission of the inner product function value is realized, and the adaptability to the control requirements of more complex calculation permissions is improved. Description of the Drawings
[0013] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0014] Figure 1 It is a schematic flowchart of an access control inner product function encryption and decryption method provided in an embodiment of the present application.
[0015] Figure 2 It is a schematic diagram of an access control function encryption and decryption model supporting double inner product predicates provided in an embodiment of the present application.
[0016] Figure 3 It is a structural block diagram of an access control inner product function encryption and decryption device provided in an embodiment of the present application. Specific Embodiments
[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0018] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0019] Embodiment 1: As Figure 1 shown, the present application provides an access control inner product function encryption and decryption method supporting double inner product predicates. The access control inner product function encryption and decryption method performs encryption and decryption by constructing an access control inner product function encryption model. The access control inner product function encryption model is constructed based on a system setup module, a key generation module, an encryption module, and a decryption module. The access control inner product function encryption and decryption method includes Step 101 - Step 108.
[0020] Step 101: Input the security parameter into the system setup module to determine the public parameter and the master private key ; the security parameter is used to represent the security level of the cryptographic primitive.
[0021] In some embodiments, Step 101 specifically includes: Based on the random matrix 、random matrix 、random matrix sequence and random matrix , select a random vector and a random vector , and determine the master private key and the public parameters ; wherein, represents the -th element of the random matrix sequence ; the public parameter includes a bilinear group; the bilinear group is ; represents the order of the group , and ; , represents the generator of the group ; , is the generator of the group ; represents a bilinear mapping ; represents the exponential operation with as the base in the group ; represents the transpose; represents the dimension of the vector associated with the receiver; represents randomly selecting an element in the integer ring with a prime order of ; represents random selection; represents an integer; , and all represent different dimension sizes; represents a random matrix with a dimension of 1 for the vector associated with the receiver; represents a random matrix with a dimension of for the vector associated with the receiver.
[0022] Step 102: Define the vectors and as the structure of the bilinear inner product predicate; wherein, represents a pair of vectors associated with the sender, represents a pair of vectors associated with the receiver; represents the sender predicate vector; t represents the sender attribute vector; represents the receiver attribute vector; represents the receiver predicate vector.
[0023] Step 103: Use the public parameters , the master private key and three vectors Input the key generation module to generate the decryption private key ; wherein, the decryption private key contains three vectors ; represents the function vector related to the decryption private key ; the decryption private key includes the sender predicate vector , the receiver attribute vector and the vector related to the decryption private key .
[0024] In some embodiments, step 103 specifically includes: inputting the public parameters , the master private key and three vectors into the key generation module, calculating the decryption private key , and selecting a random vector .
[0025] Wherein, , represents the key component related to the sender predicate vector and the receiver attribute vector, represents the key component related to the receiver attribute vector, and represent the key components related to the vector ; , , respectively represent the th element in the vector , the vector ; ; represents the dimension of the vector associated with the receiver; represents the dimension of the vector associated with the sender.
[0026] Step 104: Input the public parameters , the master private key and three vectors into the encryption module, and encrypt the sender's data according to the public parameters , the master private key and three vectors to generate the ciphertext; the ciphertext is the encrypted sender's data, and the ciphertext contains three vectors ; represents the vector related to the ciphertext.
[0027] In some embodiments, step 104 specifically includes: selecting a random vector , input the public parameter , the master private key , and three vectors into the encryption module, and output the ciphertext . Among them, respectively represent the intermediate ciphertext components for decryption, the ciphertext components related to the sender attribute vector and the receiver predicate vector, and the ciphertext components related to the vector ; ; among them, , and respectively represent the vector , the vector and the vector the th element.
[0028] Step 105: When the receiver receives the ciphertext, input the ciphertext, the decryption private key, and the public parameter into the decryption module for permission matching to determine the first result.
[0029] In some embodiments, step 105 specifically includes: making the inner product function value of the vector and the vector equal to zero, and making the inner product function value of the vector and the vector also equal to zero as the condition for permission matching; based on the condition for permission matching, determine the first result according to the formula of the preset operation; the formula of the preset operation is:
[0030]
[0031] Step 106: Based on the first result and the decryption module, obtain the second result.
[0032] In some embodiments, step 106 specifically includes the following.
[0033] According to , determine the second result .
[0034] Step 107: According to the first result and the second result, determine the inner product function value of the vector and the vector .
[0035] Step 108: Through the inner product function value of the vector and the vector , determine the decrypted ciphertext; the decrypted ciphertext is the data of the sender.
[0036] Refer to Figure 2 , an encryption and decryption device for an access control inner product function, comprising: a system setup module 1 for inputting security parameters into the system setup module to determine public parameters and the master private key ; the security parameters are used to characterize the security level of cryptographic primitives; a key generation module 2 for defining vectors and vector as the structure of the double inner product predicate; wherein, represents a pair of vectors associated with the sender, represents a pair of vectors associated with the receiver; represents the sender predicate vector; t represents the sender attribute vector; represents the receiver attribute vector; represents the receiver predicate vector; input the public parameters , the master private key and three vectors into the key generation module to generate the decryption private key ; wherein, the decryption private key contains three vectors ; represents the function vector related to the decryption private key ; the decryption private key includes the sender predicate vector , the receiver attribute vector and the vector related to the decryption private key ; an encryption module 3 for inputting the public parameters , the master private key and three vectors into the encryption module, and encrypting the data of the sender according to the public parameters , the master private key and three vectors to generate a ciphertext; the ciphertext is the encrypted data of the sender, and the ciphertext contains three vectors ; represents the vector related to the ciphertext; a decryption module 4 for, when the receiver receives the ciphertext, inputting the ciphertext, the decryption private key and the public parameters into the decryption module for permission matching to determine the first result; obtaining the second result based on the first result and the decryption module; determining the inner product function value of vector and vector according to the first result and the second result; passing through vector Sum vector Inner product function value , determine the decrypted ciphertext; the decrypted ciphertext is the data of the sender.
[0037] This application focuses on the security requirements of data availability without visibility and controllable on-demand computing. Combining the idea of two-way access control and the encryption and decryption scheme of inner product functions, it proposes an encryption and decryption method for access control functions supporting double inner product predicates to solve the problem of flexible and controllable permissions for on-demand secure computing.
[0038] In an exemplary embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the above method is implemented.
[0039] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by a processor, the above method is implemented.
[0040] In an exemplary embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the above method is implemented.
[0041] Embodiment 2: Refer to Figure 3 , first, input security parameters, and the system setting module generates a master private key and public parameters and sends them to the key generation module. Then, the key generation module uses the master private key to generate a decryption private key, and at the same time embeds a part of the double inner product predicate related to the receiver and the sender, and a function vector related to the decryption private key in the key generation module; secondly, the sender encrypts its own data using the public key, and all the ciphertexts generated in the encryption module contain a part of the double inner product predicate related to the sender and the receiver, and a function vector related to the ciphertext. Then, after receiving the ciphertext, the receiver uses this decryption private key to decrypt the ciphertext. The decryption module includes two parts: permission matching and decryption operation execution. Only the receiver who passes the permission matching can continue to execute the decryption operation to calculate the correct inner product function value. In this way, by simultaneously embedding the double inner product predicate and the corresponding function vector in the decryption key and the ciphertext, two-way control of the computing permission is realized. At the same time, the contained double inner product predicate has strong attribute hiding properties, which effectively protects the privacy of the receiver, realizes data computable without visibility, and meets the requirements of secure data fine-grained control.
[0042] The formal definitions of encryption and decryption for the access control function based on the support for the double inner product predicate are shown in Table 1, which is the encryption and decryption definition table for the access control function supporting the double inner product predicate. Among them, Setup is the algorithm corresponding to the system setup module (abbreviated as the system setup algorithm), KeyGen is the algorithm of the key generation module (Key Generation, abbreviated as the key generation algorithm), Enc is the algorithm of the encryption module (Encryption, abbreviated as the encryption algorithm), and Dec is the algorithm of the decryption module (Decryption, abbreviated as the decryption algorithm).
[0043] Table 1 Encryption and Decryption Definition Table for the Access Control Function Supporting the Double Inner Product Predicate
[0044]
[0045] Specifically, the use of double inner product predicate encryption in this application can achieve fine-grained access control and conditional decryption without exposing the plaintext. Among them, the four algorithms of Setup, KeyGen, Enc, and Dec correspond to the following four steps respectively.
[0046] Step 1: System Setup Algorithm , specifically including: inputting the security parameter , where the security parameter is also an implicit input of the other several algorithms, the bilinear group , where is the order of the group, is the generator of the group , is the generator of the group . The bilinear mapping , where represents performing an exponentiation operation in the group , represents performing an exponentiation operation in the group , represents performing a bilinear mapping operation in the group . Select random matrices , random matrix , random matrix sequence and random matrix , select random vectors and random vector ; among them, the symbol represents randomly selecting an element in the integer ring with a prime order of , is an integer, 's superscript represents different dimension sizes. Output the public parameter and the master private key as follows.
[0047] 。
[0048] 。
[0049] Among them, represents the transpose of the matrix , represents belongs to the set , where represents the exponentiation operation in the group . The content in the square brackets represents the value participating in the operation. represents that the exponentiation operation is executed within the loop .
[0050] Step 2: Key Generation Algorithm , specifically including: The key generation algorithm is mainly executed by the authority center. This algorithm takes the public parameters , the master private key and three vectors as inputs. Among them, represents the sender's predicate vector, represents the receiver's attribute vector, represents the function vector related to the decryption private key . Among them, and are used to support the permission matching process. A random vector is selected, and the receiver's private key is calculated. Among them, is randomly selected from the elements in the integer ring with a prime order of and a dimension of .
[0051] Among them, . represents the key component related to the sender's predicate vector and the receiver's attribute vector, represents the key component related to the receiver's attribute vector, and represent the key components related to the vector .
[0052] Step 3: Encryption Algorithm , specifically including: Input the public parameters , the master private key and three vectors . Among them represents the sender's attribute vector, represents the receiver's predicate vector, represents the one related to the ciphertext The relevant function vectors, select random vectors , and output the ciphertext .
[0053] Among them, ; , , respectively represent the th element in the vector , the vector in the th element.
[0054] Step 4: Decryption algorithm , indicates that the inner product function value is incorrect. The correct or incorrect inner product function value is obtained through the decryption module. Incorrect indicates that the recipient does not have legal permission. Specifically include: input public parameters , recipient's private key and ciphertext . First, perform the operations corresponding to permission matching as follows.
[0055]
[0056] When the inner product value of the vectors and is equal to zero, and the inner product value of the vectors and is also equal to zero, can be obtained. Then perform the decryption operation as follows.
[0057]
[0058] Since the inner product function value to be finally calculated is on the exponent with the generator of the group as the base, this is equivalent to solving the discrete logarithm, and the inner product function value can be calculated using the Baby-Step Giant-Step (BSGS) algorithm under certain conditions.
[0059] It is worth noting that the proposed double inner product predicate structure in this application contains two pairs of vectors and , where is associated with the sender, is associated with the recipient.
[0060] The present application has the following advantages: (1) It supports a more flexible two-way calculation permission control function. Based on the designed double inner product predicate structure, which is embedded in the key generation algorithm and the encryption algorithm, the double inner product predicate structure includes a pair of vectors related to the sender and a pair of vectors associated with the receiver. It realizes the two-way control of the calculation permission of the inner product function. Effectively solves the problem that the existing technologies based on identity encryption and attribute encryption can only achieve one-way access control for the receiver. Improves the adaptability to the more complex calculation permission control requirements. (2) Only the legitimate receiver with permission in the present application can obtain the correct inner product function value. However, most of the existing technologies can only achieve indistinguishability security, making it difficult to cope with stronger adversary attacks. Therefore, the present application can support semi-adaptive simulation security. The simulation security performance can more accurately describe the security goal of the access control function encryption method. (3) It has more efficient calculation and storage overheads. Specifically, in practical applications, when the dimension of the predicate (attribute) vector is in the interval [1000, 10000], the calculation and storage overheads of the three algorithms KeyGen, Enc, and Dec increase at a faster rate, but the overall calculation and storage overheads are still lower than those of the existing technologies. Compared with the existing technologies, the calculation time and storage overheads of the present application show a more stable linear growth trend with the dimension of the predicate (attribute) vector.
[0061] Generally speaking, the ingenious design of embedding the double inner product predicate structure into the key and ciphertext structures, especially in the encryption method, effectively reduces the complexity brought by the double inner product predicate by using the addition operation characteristics of random matrices and exponents in the group (that is, the multiplication of any elements in the same group is equal to the addition of exponents. That is, it follows the power operation rule: when multiplying powers with the same base, the base remains unchanged and the exponents are added). At the same time, it ensures the two-way calculation permission control function and stronger simulation security.
[0062] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of the relevant data need to comply with the relevant regulations.
[0063] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0064] The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0065] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0066] Specific examples are used in this article to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. An access control inner product function encryption and decryption method, characterized in that: The access control inner product function encryption and decryption method is to encrypt and decrypt by constructing an access control inner product function encryption model, wherein the access control inner product function encryption model is constructed based on a system setting module, a key generation module, an encryption module and a decryption module, and the access control inner product function encryption and decryption method includes: The security parameters Enter the system settings module and determine the common parameters and the master private key ; The security parameter is used to characterize the security level of the cryptographic primitive; Defining vectors and vector is the structure of a double inner product predicate; represents a pair of vectors associated with the sender, represents a pair of vectors associated with the receiver; represents the sender predicate vector; t represents the sender attribute vector; represents the receiver attribute vector; represents the receiver predicate vector; The public parameters , Master Private Key and three vectors Enter the key generation module to generate a decryption private key ; Among them, the decryption private key contains three vectors ; Representing and decrypting private keys Related function vector; the decryption private key Include sender predicate vector , receiver attribute vector and the decryption private key Related vectors ; The public parameters , Master Private Key and three vectors Input encryption module and according to public parameters , Master Private Key and three vectors The sender's data is encrypted to generate ciphertext; the ciphertext is the encrypted sender's data, and the ciphertext contains three vectors ; represents the vector associated with the ciphertext; After receiving the ciphertext, the receiver inputs the ciphertext, the decryption private key and the public parameters into a decryption module for authority matching to determine a first result; Based on the first result and the decryption module, obtain a second result; According to the first result and the second result, determine the vector and vector The inner product function value of ; By vector and vector The inner product function value of , determine the decrypted ciphertext; the decrypted ciphertext is the data of the sender.
2. The access control inner product function encryption and decryption method according to claim 1 is characterized in that: The security parameters Enter the system settings module and determine the common parameters and the master private key , specifically including: Based on random matrix , random matrix , random matrix sequence and a random matrix , choose a random vector and a random vector , determine the master private key and public parameters ;in, Represents a random matrix sequence No. elements; the common parameters Including a bilinear group; the bilinear group is ; Representation Group , and The order, , Representation Group The generator of , It's a group The generator of represents a bilinear map, ; Indicates in group China-Israel Exponential operation with base; represents transpose; represents the dimension of the vector associated with the receiver; Indicates that in prime order The integer ring Randomly select elements from Indicates random selection; Represents an integer; , and Both said Different dimensional sizes; A random matrix of dimension 1 representing the vector associated with the receiver; The dimension of the vector associated with the receiver is A random matrix.
3. The access control inner product function encryption and decryption method according to claim 2 is characterized in that: The public parameters , Master Private Key and three vectors And the key generation module to generate the decryption private key , specifically including: The public parameters , Master Private Key and three vectors Enter the key generation module to calculate the decryption private key , and choose a random vector ;in, , represents the key component associated with the sender predicate vector and the receiver attribute vector, represents the key component associated with the receiver attribute vector, and Representation and vector the relevant key components; , , Represents vectors ,vector ,vector Middle elements; represents the dimension of the vector associated with the receiver; represents the dimension of the vector associated with the sender; Indicates in group China-Israel Exponential operation with base.
4. The access control inner product function encryption and decryption method according to claim 3 is characterized in that: The public parameters , Master Private Key , three vectors Input encryption module and according to public parameters , Master Private Key and three vectors Encrypt the sender's data to generate ciphertext, including: Choose a random vector , the public parameters , Master Private Key , three vectors Input encryption module, output ciphertext ;in, They represent the intermediate ciphertext components used for decryption, the ciphertext components related to the sender attribute vector and the receiver predicate vector, and the ciphertext components related to the vector Related ciphertext components; ; in, , and Represents vectors ,vector and vector Middle elements.
5. The access control inner product function encryption and decryption method according to claim 4 is characterized in that: After receiving the ciphertext, the receiver inputs the ciphertext, the decryption private key and the public parameters into the decryption module for authority matching to determine the first result, which specifically includes: Vector and vector The inner product function value of is equal to zero, and the vector and vector The inner product function value of It is also equal to zero, as a condition for permission matching; Based on the permission matching condition, the first result is determined according to the preset calculation formula ; The formula for the preset operation is: ; in, Indicates in group Perform a bilinear map operation in .
6. The access control inner product function encryption and decryption method according to claim 5, characterized in that: Based on the first result and the decryption module, a second result is obtained, which specifically includes: according to , determine the second result .
7. An access control inner product function encryption and decryption device, characterized in that: include: System settings module, used to set security parameters Enter the system settings module and determine the common parameters and the master private key ; The security parameter is used to characterize the security level of the cryptographic primitive; Key generation module, used to define vector and vector is the structure of a double inner product predicate; represents a pair of vectors associated with the sender, represents a pair of vectors associated with the receiver; represents the sender predicate vector; t represents the sender attribute vector; represents the receiver attribute vector; Represents the receiver predicate vector; the public parameters , Master Private Key and three vectors Enter the key generation module to generate a decryption private key ; Among them, the decryption private key contains three vectors ; Representing and decrypting private keys Related function vector; the decryption private key Include sender predicate vector , receiver attribute vector and the decryption private key Related vectors ; Encryption module, used to convert public parameters , Master Private Key and three vectors Input encryption module and according to public parameters , Master Private Key and three vectors The sender's data is encrypted to generate ciphertext; the ciphertext is the encrypted sender's data, and the ciphertext contains three vectors ; represents the vector associated with the ciphertext; a decryption module, configured to input the ciphertext, the decryption private key and the public parameter into the decryption module for authority matching after the receiving party receives the ciphertext, and determine a first result; obtain a second result based on the first result and the decryption module; and determine a vector according to the first result and the second result. and vector The inner product function value of ; through vector and vector The inner product function value of , determine the decrypted ciphertext; the decrypted ciphertext is the data of the sender.
8. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the access control inner product function encryption and decryption method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the access control inner product function encryption and decryption method described in any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the access control inner product function encryption and decryption method described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Cryptographic system, cryptographic communication method, encryption apparatus, key generation apparatus, decryption apparatus, content server, program, and storage medium
CN102369687A
Information transmission method and device and related equipment
CN116506162A