A data sharing method based on distributed storage
By using index matrix and coding matrix in distributed storage systems to isolate data from audit servers and outsourcing audit tasks, the problem of data integrity audit in distributed storage systems is solved, and data security sharing and flexibility are improved.
Patent Information
- Application Number
- CN202510413686.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-04-03
AI Technical Summary
In the prior art, when publishing and sharing data in distributed storage systems, it is difficult to effectively ensure the integrity of data audits, especially data holders need to keep the computer on and provide hardware facilities, which have poor flexibility.
By creating an index matrix and encoding matrix in the data server, isolate the data from the audit server, outsource audit tasks to an independent audit server, and periodically update the encoding matrix to prevent the audit server from obtaining data.
The secure sharing of data is realized, avoiding data tampering from the source, reducing the requirements for data holders' hardware facilities, and improving the flexibility of data sharing.
Smart Images

Figure CN119918094B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and in particular to a data sharing method based on distributed storage. Background Art
[0002] In a distributed storage system, the release and sharing of data can easily lead to data tampering, so data integrity audit is very important. Chinese Patent Publication No. CN114781006A discloses an outsourced data integrity audit method and system based on blockchain and SGX. The data requester queries data resources on the blockchain, and after obtaining data use authorization, the audit contract is deployed to the blockchain. The data requester forwards the time parameter to the data storage party through the blockchain, and the data storage party generates proof information and sends it to SGX, which completes the data integrity audit. This method generates a label for each encrypted data block when requesting data to complete the integrity verification of the data block to be audited. The data publisher cannot control the audit process, and the flexibility is poor.
[0003] Chinese patent publication number CN119441229A discloses a distributed storage method for audit data based on a multi-layer encryption strategy. The method generates sharding rules through a pseudo-random algorithm, and dynamically shards the encrypted audit data based on the sharding rules to generate multiple data fragments. The data fragments are distributed and stored in multiple distributed storage nodes, and the integrity of the stored data is verified through hash calculation, Merkle tree verification and verification information storage mechanism. The data holder can control the audit process, but a large number of calculations in the audit process are performed on the data holder end, which requires the data holder to keep the computer turned on and provide corresponding hardware facilities. In view of this, the prior art needs further improvement. Summary of the invention
[0004] In order to solve the defects of the above-mentioned prior art, the present invention proposes a data sharing method based on distributed storage. The first user of the present invention stores data in distributed nodes through a data server to realize data sharing, and distributes data audit verification to an independent audit server through the data server. The data server completes data storage through an index matrix and isolates the data from the audit server through a coding matrix to prevent the data from being tampered with from the source.
[0005] The technical solution of the present invention is achieved in this way:
[0006] A data sharing method based on distributed storage comprises the following steps:
[0007] Step 1: The authentication server sends public parameters to the first user and issues a second private key to the second user according to the attribute tag of the second user, and the data server sends the first public key to the first user and sends the first private key to the second user;
[0008] Step 2: The first user initializes the coding matrix, encrypts multiple groups of first plaintexts based on the first public key to generate first ciphertexts, and divides the first ciphertexts into multiple groups of first data blocks;
[0009] Step 3: The data server creates an index matrix, maps the first data block to the second data block according to the index matrix, stores the second data block to the distributed node, and feeds back the index matrix to the first user;
[0010] Step 4: The first user creates a second plaintext including a data request and an index matrix, and generates a second ciphertext after encrypting the second plaintext based on the public parameter;
[0011] Step 5: The second user decrypts the second ciphertext using the second private key to obtain the second plaintext, and sends a data request to the data server, and the data server forwards the second data block according to the index matrix;
[0012] Step 6: The second user extracts a sub-index matrix from the index matrix according to the second data block, combines the second data block according to the sub-index matrix to generate a first ciphertext, and then decrypts it with the first private key to obtain a first plaintext;
[0013] Step 7: The first user generates a third data block and a first summary of the third data according to the coding matrix and the first data block, and sends the coding matrix to the data server;
[0014] Step 8: The data server generates a second summary based on the coding matrix, and the audit server audits the first summary and the second summary. If the audit passes, proceed to step 9;
[0015] Step 9: The first user updates the encoding matrix and sends it to the data server, and returns to step 4.
[0016] In the present invention, in step 1, the authentication server creates a tag set consisting of multiple attribute tags, and then generates public parameters and a second private key. The first user generates security parameters, and the data server generates a first private key and a first public key based on the security parameters.
[0017] In the present invention, in step 2, the coding matrix is a full-rank matrix with N rows and K columns, and the coding matrix consists of multiple groups of coding elements.
[0018] In the present invention, in step 3, the index matrix is a full-rank matrix with N rows and N+M columns, and the index matrix is composed of multiple groups of index elements. The first ciphertext is divided into N groups of first data blocks of the same size, and the N groups of first data blocks are mapped to N+M groups of second data blocks through the encoding matrix, wherein the M groups of second data blocks are copy data blocks.
[0019] In the present invention, in step 5, the data request includes the sequence numbers of N groups of first data blocks to be shared first plaintext, the data server retrieves no less than N groups of second data blocks according to the index matrix, and downloads N groups of second data blocks according to the network congestion level of the distributed nodes.
[0020] In the present invention, in step 6, the index elements corresponding to the second data block in the index matrix are extracted and a sub-index matrix is constructed, multiple groups of first data blocks are calculated according to the inverse matrix of the sub-index matrix, and the multiple groups of first data blocks are merged to generate the first ciphertext.
[0021] In the present invention, in step 8, the data server retrieves the second data block and generates the first data block according to the index matrix, generates the check data block of the first data block according to the encoding matrix, and calculates the second summary of each check data block.
[0022] In the present invention, in step 8, if the audit fails, the audit server will feed back the verification data block to the first user, and the first user will disconnect the distributed node corresponding to the second data block based on the retrieval. If all the verification data blocks of a group of first data blocks fail the audit, an audit exception notification is generated and the program ends, otherwise it goes to step 9.
[0023] In the present invention, if the first digest of the third data block matches the second digest of the corresponding verification data block, the audit passes; otherwise, the audit fails.
[0024] In the present invention, in step 9, the first user modifies multiple second users to be shared, extracts attribute tags of the second users from the tag set, and updates the attribute control tree used to generate the second ciphertext based on at least one set of attribute tags.
[0025] The implementation of the distributed storage-based data sharing method of the present invention has the following beneficial effects: the present invention outsources data auditing to an independent audit server, and the audit server performs the audit of the second data block without interference, avoiding the first user from keeping the computer turned on, and reducing the requirements for the hardware facilities of the first user. The present invention maps the first data block to the third data block according to the coding matrix, and periodically updates the coding matrix to avoid an untrusted audit server obtaining the first data block after multiple audits, and thereby breaking through the first ciphertext or the first plaintext. Furthermore, the present invention adjusts the scope of the second user who can share the first plaintext through the attribute control tree, without modifying the second data block of the distributed node, and reducing the data transmission volume of the data server. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is a flow chart of the data sharing method based on distributed storage of the present invention;
[0027] Figure 2A network topology diagram for data sharing of the present invention;
[0028] Figure 3 A schematic diagram of dividing a first ciphertext into multiple groups of first data blocks according to the present invention;
[0029] Figure 4 A network topology diagram for data auditing of the present invention;
[0030] Figure 5 A schematic diagram of storing a first plaintext according to the present invention;
[0031] Figure 6 A schematic diagram of sharing the first plaintext of the present invention;
[0032] Figure 7 A schematic diagram for generating a first abstract for the present invention;
[0033] Figure 8 A schematic diagram for generating a second abstract for the present invention;
[0034] Fig. 9 A schematic diagram of the first plaintext encryption and decryption of the present invention;
[0035] Fig.10 This is a schematic diagram of the second plaintext encryption and decryption of the present invention. DETAILED DESCRIPTION
[0036] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0037] In the prior art, the data audit verification of the distributed storage system is actively completed by the data publisher. Although this method can avoid data leakage, it increases the work overhead of the data publisher. The present invention completes the distributed storage of data content through an index matrix, and the data audit verification of the distributed storage is assigned to an independent audit server. To avoid data leakage, the present invention isolates the data content from the audit server through a coding matrix. At the same time, the coding matrix is periodically updated to prevent an untrustworthy audit server from breaking through the first ciphertext or the first plaintext after multiple audits. Embodiment 1
[0038] like Figures 1 to 4 As shown, a data sharing method based on distributed storage includes the following steps.
[0039] Step 1: The authentication server sends public parameters to the first user and issues a second private key to the second user based on the attribute tag of the second user. The data server sends the first public key to the first user and sends the first private key to the second user. The authentication server creates a tag set consisting of multiple attribute tags, and then generates public parameters and a second private key. The first user generates security parameters, and the data server generates a first private key and a first public key based on the security parameters. The attribute tag is, for example, the code, signature, name, etc. of the second user. The trustworthiness of the second user is confirmed based on the attribute tag, and then it is determined whether the second user has the authority to share data. Figure 2 As shown, the first user and the second user are connected to the data server and the authentication server through the wireless network to receive or send data, the data server is connected to the network router, and the network router is connected to the distributed node. The network router is responsible for transmitting data from the data server to the distributed node to ensure efficient and reliable transmission of data in the network.
[0040] Step 2: The first user initializes the coding matrix, generates the first ciphertext after encrypting multiple groups of first plaintexts based on the first public key, and divides the first ciphertext into multiple groups of first data blocks. The coding matrix is a full-rank matrix with N rows and K columns. The coding matrix consists of multiple groups of coding elements. N can be calculated according to the capacity of the first plaintext, and the encryption parameters of the first plaintext can be set according to the network security value, and K can be calculated according to the encryption parameters. The data dimension of the first plaintext is equal to the number of rows N of the coding matrix. The network security value is a preset data confidentiality level. The encryption parameters of the first plaintext are set according to the network security value. The encryption parameters are, for example, encryption algorithms, key lengths, encryption modes, etc., and then K is calculated according to the encryption parameters. The method for the first user to generate the first ciphertext after encrypting multiple groups of first plaintexts based on the first public key is as described in Example 4. In a further embodiment, the algorithms of K, N, and M can also be preset to meet specific storage and encryption requirements.
[0041] Step 3: The data server creates an index matrix, maps the first data block to the second data block according to the index matrix, stores the second data block in the distributed node, and feeds back the index matrix to the first user. The index matrix is a full-rank matrix with N rows and N+M columns, and the index matrix consists of multiple groups of index elements. Figure 3 As shown, the first ciphertext M 2 Contains multiple characters m 2 , the first ciphertext M 2 Divide into N groups of first data blocks of the same size. In the figure, the first data block P is divided 11 , the first data block P 12 , the first data block P 13. N groups of first data blocks are mapped to N+M groups of second data blocks through the encoding matrix, wherein the M groups of second data blocks are replica data blocks, and the available capacity of the distributed nodes can be collected, and M is calculated based on the available capacity to ensure that the available capacity of the distributed nodes is greater than the capacity of the N+M groups of second data blocks. In distributed storage, the index matrix is mainly used for data redundancy and recovery to ensure that the first data block can still be recovered when some distributed nodes fail. The method for the data server to map the first data block to the second data block according to the index matrix is as described in Example 2.
[0042] Step 4: The first user creates a second plaintext including a data request and an index matrix, and generates a second ciphertext after encrypting the second plaintext based on the public parameters. The data request includes the sequence numbers of the N groups of first data blocks to be shared with the first plaintext. The first user determines the shared content of the first plaintext by creating a data request, thereby avoiding the first user being unable to control the data sharing process, reducing the risk of the data source, and increasing the traceability of data sharing. The method for the first user to generate a second ciphertext after encrypting the second plaintext is as described in Example 4.
[0043] Step 5: The second user decrypts the second ciphertext with the second private key to obtain the second plaintext, and sends a data request to the data server, and the data server forwards the second data block according to the index matrix. The data server retrieves no less than N groups of second data blocks according to the index matrix, and downloads N groups of second data blocks according to the network congestion of the distributed nodes. The data server searches for the corresponding index element in the index matrix according to the data request, and forwards the second data block to the second user according to the index element. The method for the second user to obtain the second plaintext after decrypting the second ciphertext with the second private key is as described in Example 4.
[0044] Step 6: The second user extracts a sub-index matrix from the index matrix according to the second data block, generates a first ciphertext after merging the second data block according to the sub-index matrix, and then decrypts the first plaintext using the first private key. Extract the index element corresponding to the second data block in the index matrix and construct a sub-index matrix, calculate multiple groups of first data blocks according to the inverse matrix of the sub-index matrix, and merge the multiple groups of first data blocks to generate the first ciphertext. The method for the second user to generate the first ciphertext after merging the second data block according to the sub-index matrix is as described in Example 2. The method for the second user to obtain the first plaintext after decrypting the first ciphertext using the first private key is as described in Example 4.
[0045] Step 7: The first user generates a third data block and a first summary of the third data according to the coding matrix and the first data block, and sends the coding matrix to the data server. Figure 4As shown, the first user encrypts the first data block through the coding matrix to generate the third data block, so as to prevent the first data block from being deciphered during the audit process. Further, the first summary is generated according to the third data block, and the first user sends the first summary of the third data to the audit server for data audit. At the same time, the firewall is used to ensure that the first summary is not modified during the upload process, so as to prevent the audit from failing due to an erroneous first summary. The method for the first user to generate the third data block according to the coding matrix and the first data block is as described in Example 3.
[0046] Step 8: The data server generates a second summary based on the coding matrix, and the audit server audits the first summary and the second summary. If the audit passes, go to step 9. In this implementation, the data server collects audit accumulation parameters, retrieves the second data block and generates the first data block based on the index matrix, generates the verification data block of the first data block based on the coding matrix, and uses the hash algorithm and audit accumulation parameters to calculate the second summary of each verification data block. Audit accumulation parameters are, for example, timestamps, random numbers, hash values of the previous verification data block, etc., which are used to increase the security and tamper-proof capabilities of the audit. If the first summary of the third data block matches the second summary of the corresponding verification data block, the audit passes, otherwise the audit fails.
[0047] Reference Figure 1 As shown, if the audit fails, the audit server will feed back the verification data block to the first user, and the first user will disconnect the distributed node corresponding to the second data block based on the retrieval. During each audit, the data server generates a mapping table for the second data block, the first data block, and the retrieval data block. During the audit, the audit server calls the mapping table and feeds back the mapping table to the first user. Furthermore, if all the verification data blocks of a group of first data blocks fail the audit, the data shared by the first user cannot be obtained through the distributed nodes, data sharing fails, and a notification of audit exception is generated, and the program ends, otherwise it goes to step 9. The first plaintext audit verification method is as described in Example 3.
[0048] Step 9: The first user updates the encoding matrix and sends it to the data server, and returns to step 4. The first user modifies the multiple second users to be shared, extracts the attribute tags of the second users from the tag set, and updates the attribute control tree used to generate the second ciphertext based on at least one set of attribute tags. By updating the attribute control tree used to generate the second ciphertext, the confidentiality of the data is enhanced, and the flexibility of the first user in data sharing is increased. Embodiment 2
[0049] like Figure 5 to Figure 6 As shown, this embodiment further discloses the preferred first plaintext storage and sharing method of the present invention.
[0050] In step 3, the data server maps the first data block to the second data block according to the index matrix, as described below.
[0051] After the first plaintext is encrypted to generate the first ciphertext, the first ciphertext is divided into N groups of first data blocks of the same size. The N groups of first data blocks can be represented by the matrix P 1 , P 1 =[p 11 ,p 12 ,...,p 1n ,...,p 1N ], p 1n is the nth group of first data blocks. The N groups of first data blocks are mapped to the N+M groups of second data blocks via the coding matrix. The N+M groups of second data blocks can be represented by the matrix P 2 , P 2 =P 1 A N+M , P 2 =[p 21 ,p 22 ,...,p 2N ,...,p 2(N+m) ,...,p 2(N+M) ].
[0052] Index Matrix A N+M A is a full-rank matrix with N rows and N+M columns. The index matrix consists of multiple groups of index elements. N+M =[C N |D M ], C N is the identity matrix, D M is a non-zero matrix. , .
[0053] Because the index matrix A N+M The first N columns of C N is the identity matrix, the matrix P 2 The first N columns of the matrix P 1 Correspondingly, that is, p 21 =p 11 a 11 =p 11 , p 22 =p 12 a 22 =p 12 , p 2n =p 1n a nn =p 1n , p 2N =p 1N a NN . Since the index matrix A N+M The last column D Mis a non-zero matrix, the matrix P 2 The last M columns of the matrix P 1 The linear sum of multiple column elements, i.e. p 2(N+m) =p 11 a 1(N+m) +p 12 a 1(N+m) +...+p 1n a 1(N+m) +...+p 1N a 1(N+m) The N groups of second data blocks are core data blocks, and the M groups of second data blocks are replica data blocks.
[0054] In step 6, the second user generates a first ciphertext by merging the second data block according to the sub-index matrix, as described in detail below.
[0055] The data server collects N'+M' groups of second data blocks to form a matrix P 2 '. After the second user receives N'+M' groups of second data blocks, it extracts the corresponding index elements from the index matrix to form a sub-index matrix A'. The factor index matrix is a full-rank matrix, which is composed of P 1 A'=P 2 ', the entire first data block can be obtained. Since N'<N, M'<N, the data server can collect data from some distributed nodes according to the network status of the distributed nodes, thus completing the extraction of the first data block and finally generating the first ciphertext and the first plaintext.
[0056] For example, refer to Figure 5 , the first plaintext is encrypted to generate the first ciphertext, the first ciphertext is divided into 3 groups of first data blocks, the 3 groups of first data blocks are mapped to 5 groups of second data blocks, and the 5 groups of second data blocks are stored in 5 groups of distributed nodes. The second data block p 21 、p 22 、p 23 is the core data block, index matrix A N+M is a full-rank matrix with 3 rows and 5 columns, . Reference Figure 6 , due to data loss or network congestion in the distributed nodes, the data server is not connected to distributed nodes 1 and 5. 2 '=[p 22 ,p 23 ,p 24 ], the second user needs to use the second data block p 22 、p 23 、p 24 Decode the first data block. Generate the corresponding sub-index matrix A', , P 1 A'=P 2 ', that is, p 12 =p 22, p 13 =p 23 , a 14 p 11 +a 24 p 12 =p 24 , and thus the inverse solution is p 11 . Embodiment 3
[0057] like Figures 7 and 8 As shown, this embodiment further discloses the audit verification method of the preferred first plaintext of the present invention.
[0058] The first user generates a third data block according to the coding matrix and the first data block, and the N groups of first data blocks are mapped to K groups of third data blocks through the coding matrix. The N groups of first data blocks can be represented by the matrix P 1 , P 1 =[p 11 ,p 12 ,...,p 1n ,...,p 1N ], p 1n is the first data block of the nth group. The third data block can be represented by the matrix P 3 , P 3 =[p 31 ,p 32 ,...,p 3k ,...,p 3K ].
[0059] Encoding matrix B K is a full-rank matrix with N rows and K columns. The encoding matrix consists of multiple sets of encoding elements b nk composition. .P 3 =P 1 B K , p 3k =p 11 b 1k +p 12 b 2k +...+p 1n b nk +...+p 1N b Nk , any third data block p 3k It can be expressed as a matrix P 1 The first user generates a first digest of the third data using a hash algorithm and an audit accumulation parameter.
[0060] The data server retrieves the second data block and generates the first data block according to the index matrix. In this embodiment, in order to implement the audit verification of all distributed nodes, it is necessary to retrieve all the second data blocks. 2=P 1 A N+M , N'' groups of first data blocks can be obtained from the second data block, N''≥N, and then N'' groups of verification data blocks are generated through the encoding matrix, and the second summary of each verification data block is calculated using the hash algorithm and the audit accumulation parameter.
[0061] Since the first summary is derived from the third data block generated by the first user, and the second summary is derived from the verification data block generated by the data server, if the third data block and the verification data block have the same data content, the first summary matches the corresponding second summary, and the audit passes, otherwise the audit fails.
[0062] In this embodiment, the audit server feeds back the verification data block that has not passed the audit to the first user, and the first user retrieves the second data block corresponding to the verification data block. The second data block is damaged, and the corresponding distributed node is untrustworthy. Further, the first user overwrites the index element in the index matrix corresponding to the second data block. That is, the index element is reset to 0, so that the second data block cannot calculate the first data block in the future, ensuring the accuracy of the first plaintext obtained by the second user. Or the first user applies to disconnect the distributed node corresponding to the second data block.
[0063] Furthermore, the first user retrieves the corresponding first data block according to the verification data block. If all the verification data blocks of a group of first data blocks fail the audit, an audit exception notification is generated to interrupt the data sharing task.
[0064] Reference Figure 7 , in the first user, the first data block p 11 、p 12 、p 13 The third data block p is obtained by encoding the matrix 31 、p 32 、p 33 、p 34 、p 35 And the corresponding first summary 1, first summary 2, first summary 3, first summary 4, first summary 5. Matrix P 3 =P 1 B 5 , Among them, p 31 =p 11 , p 32 =p 11 b 12 +p 12 b 22 , p 33 =p 11 b 13 +p 12 b 23 +p 13 b33 , p 34 =p 12 b 24 +p 13 b 34 , p 35 =p 12 b 25 +p 13 b 35 .
[0065] Reference Figure 8 , in the data server, the second data block p 21 、p 22 、p 23 、p 24 、p 25 After inverse solution of the index matrix, 7 groups of first data blocks are obtained, including 2 groups of first data blocks p 11 , 3 groups of first data blocks p 12 , 2 groups of first data blocks p 13 The first data block can also obtain the corresponding check data block according to the encoding matrix, and further calculate the second summary 2 of the check data block. Specifically, for the check data block p 42 , can be represented by the first data block p 11 , the first data block p 12 and encoding matrix generation, Figure 8 There are 2 groups of first data blocks p 11 , 3 groups of first data blocks p 12 , then check data block p 42 There are 6 generation methods. Generate a verification data block according to each different generation method, and then calculate the corresponding second summary according to the hash algorithm. For any verification data block that fails the audit, the corresponding second data block can be retrieved through the generation path. Embodiment 4
[0066] This embodiment further discloses a preferred encryption and decryption method of the present invention. A first user generates security parameters, and a data server generates a first private key and a first public key based on the security parameters. The data server sends the first public key to the first user and sends the first private key to the second user. Fig. 9 , the first user encrypts multiple groups of first plaintexts based on the first public key to generate the first ciphertext. The second user obtains the first plaintext after decrypting the first ciphertext using the first private key. The present invention uses an identifiable object to confirm the sharing authority of the second user. When the difference between the identifiable object (official seal image) obtained by the second user and the identifiable object defined by the first user is less than a threshold parameter, the first ciphertext can be decrypted. Details are as follows.
[0067] System configuration: The first user generates the security parameter γ and the distance parameter (r 1 ,r 2), the data server receives the security parameters and distance parameters (r 1 ,r 2 ). Distance parameter (r 1 ,r 2 ) is a calculation method to measure feature differences. The data server uses the security parameter γ and the distance parameter (r 1 ,r 2 ) Run the system configuration algorithm Setup1(γ,r 1 ,r 2 )→(MPK,MSK), output the first public key MPK and the first master key MSK. At the same time, define the distance parameter (r 1 ,r 2 The data server sends the first public key to the first user.
[0068] Sharing scope definition: The first user defines an identifiable object, such as an image, official seal, signature, or the first user's full name. The first user extracts a feature vector X of the identifiable object. 1 , the feature vector is, for example, a vector composed of data such as the diagonal pixel value, maximum pixel difference, pixel variance, ASCII code, etc. of the identifiable object. The first user sends the identifiable object and the threshold parameter to the second user with sharing authority, and the second user uses the same method to extract the feature vector X of the identifiable object 2 .
[0069] Private key generation: Any second user will generate the feature vector X 2 Sent to the data server, the data server calculates the key generation algorithm KeyGen1 (MSK, X 2 )→(SKX), and obtain the first private key SKX. The data server sends the first private key SKX to the corresponding second user.
[0070] Data encryption: The first user determines the first plaintext M to be encrypted 1 , run the encryption algorithm Enc1(MPK,X 1 ,M 1 )→M 2 . Generate the first ciphertext M 2 The first ciphertext M 2 The method described in Example 1 is used to upload to the distributed nodes.
[0071] Data decryption: The second user obtains the first ciphertext M using the method described in Example 1. 2 . Run the decryption algorithm Dec1(MPK,M 2 ,SKX,r)→M 1 If d(X 1 ,X 2 )≤r, generate the first plaintext M1 If d(X 1 ,X 2 )>r, output ⊥, and end the task.
[0072] The correctness of this algorithm requires that for any (MPK,MSK)←Setup1(γ,r 1 ,r 2 ), any decryption key (SKX)←KeyGen1(MPK,X 2 ), and any first ciphertext M 2 ←Enc1(MPK,X 1 ,M 1 ), satisfying the following conditions: .
[0073] The authentication server creates a tag set consisting of multiple attribute tags, generates public parameters, a second master key, and then generates a second private key based on the second master key and the attribute tag of any second user. The authentication server sends the public parameters to the first user and issues the second private key to the second user based on the attribute tag of the second user. Fig.10 , the first user generates a second ciphertext after encrypting the second plaintext based on the public parameter. The second user decrypts the second ciphertext using the second private key to obtain the second plaintext. The present invention constructs the second private key using the attribute encryption method, and the first user can modify the access rights of the second private key according to the attribute control tree, thereby adjusting the access to the second plaintext. Since the second plaintext data is simpler, it is convenient to reduce the hardware requirements for the first user, as described in detail below.
[0074] System configuration: The first user generates security parameters λ (such as elliptic curve parameters, bilinear mapping parameters), and the authentication server receives the security parameters. The authentication server runs the algorithm Setup2(λ)→(MK,PK) to generate the public parameters PK and the second master key MK.
[0075] Attribute re-encryption: The authentication server creates a tag set U={y i |i=1,2,...I},y i is the i-th attribute label, and I is the number of attribute label types of the second user.
[0076] Private key generation: Each second user uploads an attribute tag, and the authentication server generates a private key based on the attribute tag y of any second user. i , the public parameter PK and the second master key MK generate the second private key SK2 corresponding to the second user, KeyGen2(y i ,PK,MK)→SK2. The data server sends the second private key SK2 to the corresponding second user.
[0077] Data encryption: The first user modifies the multiple second users to be shared, and constructs the polynomial g(y) of the attribute control tree according to the threshold value of the non-leaf node of the attribute control tree. i ), and use the constant term g(0) of the polynomial as the secret value (random parameter) for encrypting the second plaintext. Encrypt the second plaintext M with this secret value 3 Get the second ciphertext M 4 The algorithm is expressed as Enc2(PK, g(y i ),M 3 )→M 4 .
[0078] Data decryption: The second user obtains the second ciphertext M using the method described in Example 1. 4 The second user knows his own attribute parameter y i , public parameter PK and the second private key SK2, according to the decryption algorithm Dec2(PK, SK2, y i ,M 4 )→M 3 The second plaintext M can be obtained 3 .
[0079] Dec2 is the decryption algorithm corresponding to Enc2. Since the correctness of this algorithm requires constructing the polynomial g(y i ), enter the attribute parameter y i The constant term (secret value) of the polynomial can be obtained, and the decryption algorithm Dec2 can obtain the second plaintext. Add or delete the attribute label in the attribute control tree, and the corresponding second user obtains or loses the decryption permission. The construction method of the attribute control tree can refer to the construction method of the expression tree, binary search tree, balanced binary tree, etc., which will not be repeated in this embodiment.
[0080] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A data sharing method based on distributed storage, characterized in that: The following steps are involved: Step 1: The authentication server sends public parameters to the first user and issues a second private key to the second user according to the attribute tag of the second user, and the data server sends the first public key to the first user and sends the first private key to the second user; Step 2: The first user initializes the coding matrix, encrypts multiple groups of first plaintexts based on the first public key to generate first ciphertexts, and divides the first ciphertexts into multiple groups of first data blocks; Step 3: The data server creates an index matrix, maps the first data block to the second data block according to the index matrix, stores the second data block to the distributed node, and feeds back the index matrix to the first user; Step 4: The first user creates a second plaintext including a data request and an index matrix, and generates a second ciphertext after encrypting the second plaintext based on the public parameter; Step 5: The second user decrypts the second ciphertext using the second private key to obtain the second plaintext, and sends a data request to the data server, and the data server forwards the second data block according to the index matrix; Step 6: The second user extracts a sub-index matrix from the index matrix according to the second data block, combines the second data block according to the sub-index matrix to generate a first ciphertext, and then decrypts it with the first private key to obtain a first plaintext; Step 7: The first user generates a third data block and a first summary of the third data according to the coding matrix and the first data block, and sends the coding matrix to the data server; Step 8: The data server generates a second summary based on the coding matrix, and the audit server audits the first summary and the second summary. If the audit passes, proceed to step 9; Step 9: The first user updates the encoding matrix and sends it to the data server, and returns to step 4.
2. The data sharing method based on distributed storage according to claim 1 is characterized in that: In step 1, the authentication server creates a tag set consisting of multiple attribute tags, and then generates public parameters and a second private key. The first user generates security parameters, and the data server generates a first private key and a first public key based on the security parameters.
3. The data sharing method based on distributed storage according to claim 1 is characterized in that: In step 2, the coding matrix is a full-rank matrix with N rows and K columns, and the coding matrix consists of multiple groups of coding elements.
4. The data sharing method based on distributed storage according to claim 1 is characterized in that: In step 3, the index matrix is a full-rank matrix with N rows and N+M columns, and the index matrix consists of multiple groups of index elements. The first ciphertext is divided into N groups of first data blocks of the same size. The N groups of first data blocks are mapped to N+M groups of second data blocks through the encoding matrix, where the M groups of second data blocks are copy data blocks.
5. The data sharing method based on distributed storage according to claim 4 is characterized in that: In step 5, the data request includes the sequence numbers of N groups of first data blocks to be shared with the first plaintext, and the data server retrieves no less than N groups of second data blocks according to the index matrix, and downloads the N groups of second data blocks according to the network congestion level of the distributed nodes.
6. The data sharing method based on distributed storage according to claim 5 is characterized in that: In step 6, the index element corresponding to the second data block in the index matrix is extracted and a sub-index matrix is constructed, multiple groups of first data blocks are calculated according to the inverse matrix of the sub-index matrix, and the multiple groups of first data blocks are merged to generate a first ciphertext.
7. The data sharing method based on distributed storage according to claim 1 is characterized in that: In step 8, the data server retrieves the second data block and generates the first data block according to the index matrix, generates a check data block of the first data block according to the encoding matrix, and calculates a second summary of each check data block.
8. The data sharing method based on distributed storage according to claim 7 is characterized in that: In step 8, if the audit fails, the audit server will feed back the verification data block to the first user. The first user will disconnect the distributed node corresponding to the second data block based on the retrieval. If all the verification data blocks of a group of first data blocks fail the audit, an audit exception notification is generated and the program ends. Otherwise, it goes to step 9.
9. The data sharing method based on distributed storage according to claim 8 is characterized in that: If the first digest of the third data block matches the second digest of the corresponding verification data block, the audit passes; otherwise, the audit fails.
10. The data sharing method based on distributed storage according to claim 1, characterized in that: In step 9, the first user modifies multiple second users to be shared, extracts attribute tags of the second users from the tag set, and updates the attribute control tree used to generate the second ciphertext based on at least one set of attribute tags.
Citation Information
Patent Citations
Outsourcing data integrity auditing method and system based on block chain and SGX
CN114781006A
Auditing data distributed storage method based on multi-layer encryption strategy and related product
CN119441229A
Ciphertext policy attribute-based encryption method supporting cloud auditing and policy hiding
CN115459948A
Archive data protection method based on block chain
CN118228312A