Revocable attribute encrypted data sharing scheme based on block chain and proxy re-encryption
By adopting a comprehensive solution of technologies such as proxy recryption, revoking trees and dynamic grouping in a decentralized environment, the problem of large overhead of attribute revocation and communication is solved, and efficient and secure sharing of data is achieved.
Patent Information
- Application Number
- CN202311459452.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-03
- Publication Date
- 2025-05-06
AI Technical Summary
In a decentralized environment, it is difficult for the existing technology to effectively reduce the computing and communication overhead of attribute revocation, while ensuring data privacy and security, and meeting the needs of data sharing.
A comprehensive solution of technologies such as proxy re-encryption, revocation tree, and dynamic grouping is adopted to reduce the local computing overhead of attribute authorization agencies and users through proxy re-encryption servers, and to manage revocation trees and dynamic groupings using blockchain and smart contracts to achieve efficient attribute revocation and data decryption.
It significantly reduces the computing and communication overhead of attribute revocation, ensures data privacy and security, and provides an efficient and secure solution for data sharing in a decentralized environment.
Smart Images

Figure CN119945695A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of attribute encryption and provides a revocable attribute encryption data sharing scheme based on blockchain and proxy re-encryption. Background Art
[0002] With the rapid development of information technology, data has become the new oil of the 21st century. In this digital age, the value of data is not only reflected in the information it contains, but more importantly, through the analysis and mining of data, it can bring huge economic and social value to enterprises, governments and individuals. However, the value of data often does not exist in isolation, but is amplified in the process of sharing, exchange and cooperation among multiple parties. Therefore, how to achieve data sharing safely and efficiently has become an important research direction in the current field of information technology.
[0003] Blockchain technology provides a new perspective for solving the problem of data privacy and security protection. This technology was first known to the public as the underlying architecture of Bitcoin, showing how a decentralized currency system can achieve transaction security and immutability. As a unique distributed ledger technology, blockchain not only provides decentralized storage for data, but also ensures its integrity, authenticity and transparency. The core characteristics of blockchain, "decentralization", "immutability" and "transparency", make it an ideal tool for ensuring data privacy and security. In 2014, the birth of Ethereum marked an important milestone in blockchain technology. The introduction of the concept of "smart contracts" greatly expanded the application scenarios of blockchain technology, allowing developers to write and deploy customized applications on the blockchain. This innovation has expanded the potential application of blockchain technology from simple currency transactions to various complex industry applications, such as supply chain management, digital identity authentication, copyright protection, etc. As a distributed ledger technology, blockchain allows multiple participants to conduct transactions without a centralized authority. The technology is based on a series of cryptographic principles and distributed system concepts, providing transparency, security and immutability for data. The name of blockchain comes from its structure, which consists of two parts: blocks and chains. Each block contains a set of transaction records. At the same time, each block also contains the hash value of the previous block. In this way, blocks are linked together to form a continuous and indivisible "blockchain". This method also ensures that once a block is added to the chain, its content cannot be modified, which is the source of the "immutable" feature of the blockchain. The hash pointer is one of the core components of the blockchain, which provides protection for the integrity and security of the data structure. Simply put, a hash pointer is a pointer to a certain data and also contains the hash value of the data. Functionally, the hash pointer can not only tell the user the location of the data, but also allow the user to verify the integrity of the data and whether it has been tampered with. Inside the block, the Merkle tree structure is used to organize transaction information. The Merkle tree is a binary tree, which is mainly used to verify the content between data blocks. Its core principle is to convert the data block into a hash value of a fixed size through a hash function, and then obtain the root hash value of the Merkle tree through layers of hashing. Specifically, the leaf nodes of a Merkle tree are usually hash values of data blocks (such as transactions). Starting from the leaf nodes, they are combined in pairs and hashed again, gradually progressing upward to finally obtain the root node of the Merkle tree. By comparing the root nodes of two trees, it is possible to quickly determine whether the contents of the two trees are the same. The consensus mechanism is the core content of the blockchain. As a distributed ledger, each node in the blockchain maintains a local ledger, so how to ensure the consistency of this data is crucial.Currently common consensus algorithms include Proof of Work (PoW), Proof of Stake (PoS), and Delegated Proof of Stake (DPoS).
[0004] The emergence of smart contracts is a milestone in the history of blockchain technology development, providing a framework for automatically executed contracts. In principle, a smart contract is a piece of code deployed on the blockchain that automatically executes when certain conditions are met to complete the preset operations. Smart contracts have been further developed and improved on the Ethereum platform, which provides developers with a more flexible and powerful tool to write and deploy complex smart contracts. The decentralized and automated nature of smart contracts provides greater transparency and security for a variety of business models and transactions, with a wide range of applications from financial services, supply chain management to copyright protection.
[0005] Hyperledger Fabric is an open source blockchain framework released by the Linux Foundation. It provides a secure, modular and scalable open source blockchain framework for enterprise applications. Unlike other blockchain platforms, it was designed with the needs of enterprises in mind, so it supports a highly modular and pluggable architecture, allowing enterprises to customize and optimize for their specific application scenarios and needs. A notable feature of Hyperledger Fabric is that it supports multiple consensus mechanisms and allows fine-grained permission control between different network participants. In addition, Hyperledger Fabric provides data isolation through the concept of channels, ensuring that only authorized participants can access specific data and transactions. Hyperledger Fabric also natively supports smart contracts, which are called "chain codes" and can be written in a variety of programming languages, providing developers with greater flexibility. In summary, Hyperledger Fabric is a blockchain solution designed for modern enterprises, providing a high degree of security, scalability and customizability.
[0006] Identity-based encryption is the original prototype of attribute-based encryption (ABE). In this method, identity information that can uniquely identify an individual is usually selected as the public key for encryption. Natural biometrics, such as fingerprints or irises, are considered ideal identity authentication tools because of their natural, durable and portable characteristics. However, errors may occur when identifying these biometrics. To address this challenge, researchers introduced the concept of fuzzy identity encryption (Fuzzy-IBE). This method takes into account the slight differences between identity characteristics and decryption criteria, converts user identities into attribute sets, and only requires the intersection of two sets of attributes to reach a certain threshold to successfully decrypt the ciphertext. Further, this idea was extended to a more general attribute encryption system, marking the birth of attribute cryptography. ABE is mainly divided into two categories: ciphertext policy-based ABE (CPABE) and key policy-based ABE (KPABE).
[0007] Attribute-based encryption (ABE) is a solution that fits the characteristics of blockchain very well. The characteristic of ABE is that it is not only encrypted based on the identity of the user, but also based on the attributes of the user, such as age, gender, position or any other identifier. This allows data owners to flexibly define complex access policies. For example, in a medical management system, only users with both the attributes of "doctor" and "surgeon" are allowed to access certain data. This solution provides higher flexibility and fine-grained control for data access. Summary of the invention
[0008] The purpose of the present invention is to propose a comprehensive solution, aiming to provide a data access control method that is safe, efficient and has practical application value. The solution of the present invention combines technologies such as proxy re-encryption, revocation tree, and dynamic grouping, hoping to minimize the computational and communication overhead of attribute revocation while ensuring data privacy and security, thereby providing a new and feasible solution for data sharing in a decentralized environment to meet the urgent needs for data privacy and security in the current digital era.
[0009] The data sharing solution proposed in this invention includes five modules: attribute authorization agency, blockchain-smart contract, proxy re-encryption server, data owner, and user. The overall model of the solution is as follows: Figure 1 shown.
[0010] Attribute Authority (AA): The AA is mainly responsible for services related to user attributes. It is responsible for completing user registration, managing user attributes, distributing attributes and keys matching attributes to users, and is also responsible for completing a series of operations related to attribute revocation. The calculation and interaction between the AA and the blockchain jointly completes part of the core content of this invention: management of revocation trees, management of dynamic groups, etc.
[0011] Blockchain-Smart Contract: The smart contract deployed on the blockchain is the core of this solution. It is responsible for managing and updating the core technology revocation tree, dynamic grouping, and re-encryption key of the present invention, and accepting decryption applications from data owners and users. At the same time, it is also the core of the interaction between various components in the system.
[0012] Proxy re-encryption server: When an attribute is revoked or updated, the proxy re-encryption server receives the proxy re-encryption key from the smart contract and is responsible for re-encrypting and updating the ciphertext to generate a new version of the ciphertext. During this process, the plaintext is not exposed to the proxy server. The introduction of the proxy re-encryption server is to reduce the computing overhead of the attribute authorization agency or the user's local computing, which can greatly improve the smoothness of the overall operation of the system.
[0013] Data Owner: The data owner is the entity in the system that provides data, encrypts the data, and defines the access structure.
[0014] User: Here, user refers to the entity that wants to access and decrypt data, and is also the largest and most active part of the system. A large number of users will therefore also bring about the need for frequent attribute revocation and update, which puts high computing and communication requirements on the operation of the system, which is also the part that the present invention aims to achieve and improve.
[0015] The solution includes seven main algorithms, as follows:
[0016] 1. System initialization:
[0017] It contains two sub-algorithms, namely the global parameter generation algorithm and the system master public key and master private key generation algorithm.
[0018] (1) Global parameter generation algorithm
[0019] GlobalParamsSetUp(λ)→(GP): Randomly select bilinear groups G1 and G of prime order r T , there is a bilinear mapping e: G1×G1→G T , randomly select the generator g of the bilinear group G1. In addition, a random cryptographically secure hash function H needs to be selected. Its function is to convert a string of random numbers into an element on the cyclic group G1. Finally, the output public parameter GP can be obtained. <e,g,G1,G T , Z r , H>.
[0020] (2) Algorithm for generating the system master public key and master private key
[0021] MasterKeySetUp(GP)→(MPK, MSK): Select a random number α∈Z r , and calculate S = g α and Y1 = e(g, g) α . Select a random number β∈Z r , calculate Y2 = g β . Get the system master key MSK = <s>, system master public key MPK = <g,Y1,Y2)。
[0022] 2. User registration:
[0023] It contains two sub-algorithms, namely the dynamic grouping algorithm and the user registration and attribute authorization algorithm.
[0024] (1) Dynamic grouping algorithm
[0025] DynamicGroup(UID, Attributes)→(Group): Sum and hash the user ID UID and the user attribute string Attributes to obtain HashValue=Hash(UID+Attributes), and perform a modulo operation on the maximum number of groups N to obtain the target group ID targetGroupID=hashValue mod N. Determine whether the target group exists. If not, create a corresponding group, add the user UID and the user's attribute Attributes to the target group, and finally consider whether to split or merge the group dynamically based on the number of users UserNum and the number of attributes AttNum.
[0026] (2) User registration and attribute authorization algorithm
[0027] Register(UID, Attributes)→(User): Creates a user entity, including his UID and Attributes, and executes the DynamicGroup algorithm for dynamic grouping.
[0028] 3. User private key generation:
[0029] KeyGen(GP, MSK, MPK, User) → (USK): First randomly select t∈Z r , calculate SK1 = g α g βt , SK2=g t Then calculate SK for each attribute i in the user's Attributes list i =H(i) t Generate the corresponding version number Version = GroupVersion for the user's private key. If it is generated for the first time, set the version number Version = 1.0. Finally, calculate SK V =Hash(Version) gets the user's private key USK= <SK1,SK2,{SK i } i∈attList , S.K. V >.
[0030] 4. Ciphertext encryption:
[0031] It contains two sub-algorithms, namely the secret sharing algorithm and the ciphertext generation algorithm.
[0032] (1) Secret Sharing Algorithm
[0033] NodeShare(Secret, AccessTree, GP)→(AccessTree): For the node node on the access control tree (starting from the root node root), perform the following operations: First, determine whether the node is a leaf node. If it is a leaf node, set node.secretShare = Secret. Otherwise, obtain the threshold value node.Threshold of the node, set t = node.Threshold and randomly generate a t-1 degree polynomial, whose coefficients are stored in the node.Coefficient[] array. In particular, set node.Coefficient[0] = node.secretShare = Secret. For each child node of the node, use the t-1 degree polynomial for secret sharing, and then perform recursive operations.
[0034] (2) Ciphertext generation algorithm
[0035] Encrypt(GP, MPK, Msg, AccessTree) → (CT): Select a random number s∈Z r , for the plaintext message Msg∈G T , calculate C1 = Msge(g, g) αs and C2 = g s . Take s as a secret and share it down the access control tree AccessTree. For each node, execute NodeShare(s, AccessTree, GP). For each leaf node corresponding to attribute i, its secret shard is λ i , and then calculate the attributes of each leaf node After that, for the attribute revocation algorithm in this article, the version number of the ciphertext Version = GroupVersion is also obtained, and the hash operation is performed on it to obtain C V =Hash(Version). Finally, the ciphertext is obtained
[0036] 5. Ciphertext decryption:
[0037] It contains two sub-algorithms, namely the node secret recovery algorithm and the ciphertext decryption algorithm.
[0038] (1) Node Secret Recovery Algorithm
[0039] NodeRecover(AccessTree, Attributes[], GP)→(RootSecret): For leaf nodes LeafNode, determine whether there are attributes in Attributes[] that can satisfy node.attribute. If so, set node.valid=true. For non-leaf nodes, the algorithm maintains a child node index list validChildren[], traverses the nodes in it, and if the number of nodes with valid=true in the child nodes meets the requirement of node.threshold, the Lagrange interpolation method can be used to recover the secret value secretshare of the node, and recursive operations are performed. If the user's attribute Atrributes satisfies the access control tree AccessTree, the secret value of the root node can be finally recovered for decryption.
[0040] (2) Ciphertext decryption algorithm
[0041] Decrypt(GP, MPK, CT, USK, RevocationTree) → (Msg): First, determine whether the user attribute satisfies the access control tree AccessTree. If not, decryption fails. If so, further determine whether the version numbers USK.Version and CT.Version are equal. If not, query the revocation tree RevocationTree. If the user attribute has been revoked, decryption fails. Otherwise, execute the proxy re-encryption algorithm to update the ciphertext and key, and then decrypt. For attribute i that satisfies the access control tree AccessTree, calculate Then calculate Call the NodeRecover algorithm to recover the access control tree AccessTree root node secret value RootSecret = e(g, g) βts . Calculate DK1 = e(C2, SK1), then calculate DK2 = DK1 / RootSecret = e(g, g) αs Finally, the plain text Msg = C1 / DK2 can be calculated.
[0042] 6. Attribute revocation:
[0043] It contains two sub-algorithms, namely the undo tree algorithm and the attribute undo algorithm.
[0044] (1) Undo Tree Algorithm
[0045] Insert(UID, GroupID, Attributes)→(RevocationTree): This mainly introduces the construction method of the revocation tree, which is also the insertion method of each user attribute node. First, record the user's UID, GroupID, Attributes, Color, and create a new node newNode, then perform the insertion operation. If RevocationTree.isEmpty() == true, directly create a new RevocationTree. Otherwise, perform the insertion operation, judge newNode.UID and curNode.UID, and gradually find a suitable insertion position. At the same time, initialize newnode.Attributes[] = false, that is, the attribute is not revoked. After the insertion is completed, execute fixViolations to readjust the red-black tree to keep it balanced.
[0046] (2) Attribute revocation algorithm
[0047] RevokeAttribute(RevocationTree, UID, Attribute) → (PRK): For the specified user UID and the attribute Attribute to be revoked, first search for the corresponding node in the revocation tree RevocationTree. If there is no node corresponding to the user, the Insert method should be called first to insert it into the revocation tree. After finding the corresponding node, the algorithm will first update the node status and mark the corresponding attribute att as revoked. At the same time, the version number GroupVersion of the group to which the user belongs is updated and the re-encryption key PRK is generated.
[0048] 7. Proxy re-encryption:
[0049] ProxyReEncrypt(CT,PRK)→(CT new ): The proxy re-encryption server receives the re-encryption key PRK and first determines whether the version number Version is consistent with GroupVerion. If consistent, the ciphertext is updated using PRK. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 The figure shows the overall model of the scheme.
[0051] Figure 2 The figure shows the overall system architecture. DETAILED DESCRIPTION
[0052] According to the above scheme, the application layer and service layer of the present invention are developed based on the local machine, using the Windows 10 operating system, the processor is AMD R5600 CPU, and the memory is 16GB. The front end uses the Vue framework and the back end uses the Gin framework. The Node.js version is v16.16.0, and the npm version is 8.11.0. The Vue CLI version is 5.0.8, the Axios version is 1.12.1, the Element UI version is 2.15.9, and the front-end page is accessed through the Firefox browser. In terms of back-end development, the Gin framework is selected, and the version is v1.8.3. The back-end service is bound to listen on port 8080, and the MySQL 5.7 database service is started. The back-end application connects to the MySQL database, stores the business data in the database, and connects to the blockchain service at the same time. The contract layer and storage layer build the Hyperledger Fabric blockchain, and according to the recommendations and best practices of the official documentation of Hyperledger Fabric, build the Hyperledger Fabric blockchain on the latest long-term support version Ubuntu 18.06. The Fabric version used is v1.4.0, and Docker Compose is used to start various components in the Fabric network, including 4 peer nodes and 1 orderer node. To ensure performance and stability, the system is configured with 4GB of memory. Kafka is used for communication to achieve message transmission between nodes. Alibaba Cloud is used as the cloud server provider, and the OSS (Object Storage Service) and Elastic Compute Service (ECS) it provides are used to store encrypted files and perform intermediate calculations. During the construction process, Docker 24.0.2 and Docker Compose v2.18.1 are used to manage containers. The overall system architecture is as follows: Figure 2 shown.
[0053] The application layer implements user registration and login, attribute authorization and key generation, file management and other functions on the front end, and sends the user's operation request to the back end, and finally completes the business logic through the back end response. This system uses the Vue framework, the development language is based on JavaScript, the installation relies on Axios to complete the interface interaction, and uses Element UI to enrich the PC-side components.
[0054] The service layer is mainly responsible for functional links such as the application layer and the smart contract layer. By calling smart contracts, the application functions of the front-end and back-end of the system are completed. At the same time, the service layer is also responsible for the management of nodes and blocks. This solution uses the back-end framework Gin based on the Golang language. At the same time, this article implements the separation of the front-end and back-end, and uses Vue and Gin frameworks together to realize the data interaction between the front-end and back-end through API interface calls. The front-end sends an HTTP request to the Gin back-end. After receiving the request, the Gin framework processes the business logic to read or write data, and returns the result to the front-end, and calls Fabric-Go-SDK to complete the interaction with the contract layer.
[0055] The smart contract layer is mainly responsible for executing specific smart contracts and completing specific business functions of the system, such as the maintenance of the revocation tree and the dynamic grouping maintenance of system users. In Fabric, smart contracts can be called and interacted through rich chaincode interfaces, including GetState, DelState, and InvokeChaincode, etc. Different interface methods provide operations such as querying, deleting, and interacting with the ledger status. Smart contracts can call interface methods according to business logic to perform ledger operations and state transitions.
[0056] The data storage layer is mainly responsible for the storage of the entire system data, including the MySQL database and the blockchain service provided by Hyperledger Fabric. In this layer, the consensus mechanism of distributed nodes ensures the immutability and transparent effectiveness of the data in the system during storage and transmission.
[0057] The data sharing system of this solution includes six key modules, namely registration / login, attribute management, file upload, file download, file management and attribute revocation, as shown below.
[0058] Register / Login. In this module, users need to enter basic information to register. After successful registration, the system will automatically add the user's information to the attribute revocation tree in the background, and randomly assign a user group to the user. After successful registration, the user can log in using the registered username and password.
[0059] Attribute management. In this module, you can see the user's registration information, as well as the user's existing attributes and attribute keys. For attributes that have been authorized but have not yet generated keys, users can choose to generate corresponding attribute keys. In this process, users need to enter the password again to further ensure the security of the system. Similarly, users can also apply for new attribute authorization. After the application is successful, a new attribute certificate will be returned to the user. This new attribute certificate can then be used to generate keys and decrypt more files.
[0060] Upload files. Users can select local files to upload. Here, users can customize any access control tree to achieve complex and flexible access control. It is worth mentioning that this solution implements a graphical display function for the access control tree. When users define their access control tree, the structure of the access control tree will be displayed in real time on the right side of the page. This greatly improves the user experience and fluency of the operation.
[0061] Download files. In this module, users can see the files uploaded and shared by other users, including file type, file size, upload time, etc. At the same time, each file comes with corresponding access control requirements. At the same time, the page also displays the attribute keys owned by the user. Only when the attribute keys owned by the user meet the access control requirements of the file can the download be successful, otherwise it will prompt "Attributes do not meet, cannot download!"
[0062] File management. In the file management module, users can view the files they uploaded and downloaded. For these files, users can view their names, sizes, upload and download times, and can also click to view or delete files.
[0063] Property revocation. Only administrators have the authority to enter the property revocation management page. If the correct administrator key is not entered, the page will not be opened. After entering the correct administrator key, you can enter the property revocation management interface. Administrators can search for a single user ID or directly select a user group to view the users in it. Administrators can view the user's properties and revoke them.
[0064] First, the algorithm efficiency of each major stage of the system was simulated, and the results are shown in the following table:
[0065]
[0066]
[0067] We will focus on testing the revocation algorithm, which is a key algorithm module.
[0068] The efficiency of the revocation algorithm is simulated under different numbers of attributes, and the results are shown in the following table:
[0069] Number of attributes Time cost 10 0.8ms 20 1.3ms 30 1.8ms 40 2.3ms 50 2.7ms
[0070] As the number of attributes increases, the time overhead of the revocation algorithm grows in accordance with the logarithmic growth of theoretical calculations, and the overall time is short. In application scenarios where the number of users and attributes is large enough, the logarithmic overhead advantage of this scheme is obvious, which shows that the algorithm of the present invention is very practical.< / s>
Claims
1. A revocable attribute encrypted data sharing scheme based on blockchain and proxy re-encryption, characterized in that: There are five main entities: attribute authorization agency, blockchain-smart contract, proxy re-encryption server, data owner, and user, among which: The attribute authorization agency is mainly responsible for services related to user attributes, completing user registration, managing user attributes, and distributing attributes and keys matching attributes to users. It is also responsible for completing a series of operations related to attribute revocation; The smart contract deployed on the blockchain is responsible for managing and updating the core technology revocation tree, dynamic grouping, and re-encryption key of the present invention, and accepting decryption applications from data owners and users; The proxy re-encryption server receives the proxy re-encryption key from the smart contract and is responsible for re-encrypting and updating the ciphertext to generate a new version of the ciphertext. During this process, the plaintext is not exposed to the proxy server. The data owner is the entity that provides data in the system and is responsible for encrypting the data and defining the access structure; The user is the entity that wants to access and decrypt the data and is responsible for completing the decryption and downloading of the data; The secret data sharing scheme includes 7 algorithms: (1) System initialization algorithm to generate global public parameters and the system master public key and master private key; (2) User registration algorithm, which completes dynamic user grouping, user basic information registration, and attribute authorization; (3) User private key generation algorithm, which generates the user's private key. The user can use the private key to decrypt the corresponding ciphertext; (4) Ciphertext encryption algorithm: Generate ciphertext through secret sharing algorithm and ciphertext encryption algorithm, upload it to the blockchain, and qualified users can decrypt it to complete the secure sharing of data; (5) Ciphertext decryption algorithm, which uses the node secret recovery algorithm and the ciphertext decryption algorithm to decrypt the ciphertext that meets the requirements; (6) Attribute revocation algorithm: maintains the revocation tree and completes the revocation of user attributes by querying and updating the revocation tree, while generating a proxy re-encryption key; (7) Proxy re-encryption algorithm, the proxy re-encryption server receives the re-encryption key and updates the ciphertext.
2. The confidential data sharing solution includes 6 working modules: 1) Registration / Login: In this module, users need to enter basic information to register. After successful registration, the system will automatically add the user's information to the attribute revocation tree in the background. At the same time, a user group will be randomly assigned to the user. After successful registration, the user can log in using the registered user name and password; 2) Attribute management: In this module, you can see the user's registration information, as well as the user's existing attributes and attribute keys. For attributes that have been authorized but have not yet generated keys, users can choose to generate corresponding attribute keys. During this process, users need to enter their passwords again to further ensure the security of the system. Similarly, users can also apply for new attribute authorizations. After successful application, new attribute credentials will be returned to the user. 3) Upload files: Users can select local files to upload. Here, users can customize any access control tree to achieve complex and flexible access control; 4) Download files: In this module, users can see the files uploaded and shared by other users, including file type, file size, upload time, etc. At the same time, each file is accompanied by corresponding access control requirements. At the same time, the page also displays the attribute key owned by the user. Only when the attribute key owned by the user meets the access control requirements of the file can the download be successful. Otherwise, it will prompt "Attributes do not match, cannot download!"; 5) File management: In the file management module, users can view the files they uploaded and downloaded. For these files, users can view their names, sizes, upload and download times, and can also click to view or delete files; 6) Attribute revocation: Only administrators have the authority to enter the attribute revocation management page. If the correct administrator key is not entered, the page will not be opened. After entering the correct administrator key, you can enter the attribute revocation management interface. The administrator can search for the ID of a single user, or directly select a user group to view the users in it. The administrator can view the user's attributes and revoke them.
Citation Information
Cited By
Cloud chain collaborative medical data security sharing method based on PRE
CN121907492A
Electronic document encryption and decryption system and method based on block chain, medium and equipment
CN122001561A