A Data Access Control Method Supporting Content Review in a Cloud Environment

By introducing a tag broadcast matching encryption (FBME) solution into the cloud data sharing platform, using tag signatures and zero-knowledge proofs, the lack of content review and privacy protection capabilities in the existing technology is solved, and efficient bilateral access control and verifiable reporting functions are realized, ensuring the anonymity of the recipient and the security of the data.

CN119966709BActive Publication Date: 2025-06-27BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510116265.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-06-27
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

The existing multi-receiver matching encryption technology lacks content censorship mechanism in cloud data sharing platforms, and lacks privacy protection capabilities, making it difficult to effectively prevent the distribution of malicious content and maintain the anonymity of the recipient.

Method used

A tag broadcast matching encryption (FBME) scheme is proposed. By introducing tag signatures and zero-knowledge proofs in the data encryption process, the receiver can verify the authenticity of the sender under anonymity and report malicious content while maintaining anonymity.

Benefits of technology

It realizes efficient bilateral access control and verifiable reporting functions in cloud data sharing scenarios, balances the anonymity of the receiver, sender authentication and content review capabilities, and effectively prevents the distribution of malicious content.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966709B_ABST
    Figure CN119966709B_ABST
Patent Text Reader

Abstract

The present invention discloses a data access control method for content review in a cloud environment, belonging to the technical field of cloud data security. The method of the present invention includes: the service provider acts as an examiner at the same time, and each party generates its own public and private key pairs according to the public parameters; the sender only generates a tag signature for the plaintext, encrypts the plaintext and the tag signature to generate a ciphertext containing the tag signature and uploads it; the receiver first verifies the authenticity of the sender for the obtained ciphertext and then decrypts the data. If it is found that the data contains malicious content, when the zero-knowledge proof in the ciphertext passes the verification, a report proof is generated and submitted to the examiner; the examiner verifies the legality of the tag signature to confirm the data source. The method of the present invention provides an efficient bilateral access control and verifiable reporting function for the encrypted data sharing of multiple receivers, allowing the receivers to obtain data from the real sender while maintaining anonymity and being able to report malicious content in a verifiable manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud data security, and particularly to a data access control method supporting content review in a cloud environment, which is applicable to cloud data sharing scenarios such as data marketplaces. Background Art

[0002] The popularization of cloud computing is profoundly changing the way organizations and users manage data storage and sharing, providing highly scalable services at low maintenance costs. Against this backdrop, data sharing platforms such as Snowflake and Datarade DataMarketplace have developed rapidly, becoming important bridges between data consumers and data providers. These platforms are typically hosted on cloud infrastructures such as AWS, Microsoft Azure, Google Cloud, etc., aiming to meet the efficient access needs of enterprise users for external data sources, thereby supporting data-based business decisions. However, this data flow and sharing also pose higher requirements for data privacy and security.

[0003] Current regulations on data quality and privacy protection such as GDPR (General Data Protection Regulation) require clearly identifying data sources in data sharing to ensure data reliability. However, traditional encryption techniques such as public key encryption and broadcast encryption mainly focus on the access rights of the recipient and lack authentication of the data sender. Matching Encryption (ME), as a key technology for implementing bilateral access control, allows the sender and the recipient to respectively specify access policies, and the data can be successfully decrypted only when both parties meet each other's policies, thus ensuring data privacy and data source authenticity.

[0004] Multi-recipient ME, while providing multi-recipient bilateral access control and anonymity, involves entities including a trusted authorization authority, a cloud server, a sender, and recipients, and its implementation process includes the following steps:

[0005] (1) System initialization. The trusted authorization authority generates a system master public key mpk and a system master secret key msk.

[0006] (2) Encryption key generation. The trusted authorization authority generates an encryption key ek σ based on the system master secret key msk and the sender's identity σ, and securely distributes it to the sender.

[0007] (3) Decryption key generation. The trusted authorization authority generates a decryption key dk ρ based on the system master secret key msk and the recipient's identity ρ, and securely distributes it to the recipient.

[0008] (4) Data encryption. The sender, according to the encryption key ek σ , the set of target recipients Given the plaintext m, obtain the ciphertext c and upload it to the cloud.

[0009] (5) Data decryption. After the receiver obtains the ciphertext c from the cloud server, use the decryption key dk ρ and the identity snd of the target sender to perform the decryption operation. If the condition is satisfied, the plaintext m can be recovered.

[0010] However, the existing multi-receiver ME in the cloud data sharing platform still faces the following problems and challenges:

[0011] 1) Lack of content review mechanism: Existing technical solutions are insufficient in dealing with the risk of receivers being exposed to malicious or harmful content. There is no effective design of a content review mechanism to prevent the distribution of malicious content, which has become an urgent but not fully studied issue in cloud data sharing.

[0012] 2) Limited privacy protection ability: An improved idea is to combine multi-receiver ME with asymmetric group marking signature (AGMF) technology to achieve content review, but this method will weaken the receiver anonymity. AGMF only provides weak receiver anonymity because its marking signature contains the encapsulation keys of all target receivers, enabling receivers to identify others in the same group, violating the requirement of multi-receiver ME for receiver anonymity. Even legitimate receivers cannot infer the authorized receiver set from the ciphertext. Summary of the Invention

[0013] To address the above problems in the cloud data sharing scenario, the present invention proposes a data access control method supporting content review in a cloud environment, designs a novel multi-receiver ME scheme, namely Franking Broadcast Matchmaking Encryption (FBME), which provides efficient bilateral access control and verifiable reporting functions for the encrypted data sharing of multiple receivers, allows receivers to obtain data from real senders while maintaining anonymity, and can report malicious content in a verifiable manner, while authorizing the service provider to hold malicious senders accountable, effectively balancing receiver anonymity, sender authentication, and content review capabilities.

[0014] A data access control method supporting content review in a cloud environment according to the present invention includes the following steps:

[0015] Step 1: The service provider generates public parameters and sends them to the data sender and receivers. Each party generates its own public-private key pair; among them, the service provider also acts as a reviewer and generates the public-private key pair of the reviewer based on the public parameters; the sender and each receiver generate their own public-private key pairs based on the public parameters.

[0016] Step 2: The sender encrypts the data according to its own private key and the set of public keys of the target recipients, generates a ciphertext containing a tagged signature, and uploads the ciphertext to the cloud data sharing platform. The service provider is responsible for storing the ciphertext on the cloud server.

[0017] Step 3: The recipient retrieves the ciphertext from the cloud server, first verifies the authenticity of the sender for the obtained ciphertext, and then restores the original data through decryption operations.

[0018] Step 4: After the recipient obtains and decrypts the ciphertext from the cloud server, if it is found that the data contains malicious content, then verify the zero-knowledge proof in the ciphertext. A successful verification indicates that the ciphertext can be reported, and a report proof with an attached tagged signature is generated and submitted to the service provider.

[0019] Step 5: As an examiner, the service provider runs a review algorithm after receiving the report proof from the recipient, verifies the legality of the tagged signature, confirms the data source, and holds the malicious sender accountable, while effectively preventing false reports.

[0020] In the above Step 1, the generated common parameters The public key and private key of the examiner generated are pk J , sk J .

[0021] In the above Step 2, based on the common parameters, a tagged signature σ=(π, c, k J ) is generated for the plaintext data m. The generation method is: select a random number Calculate the intermediate parameter Let the encapsulated ciphertext component c=(u1, u2); calculate the encapsulation key For the relation Let the statement The evidence Generate a zero-knowledge proof ⊥ represents empty.

[0022] In the above Step 2, the encryption of m and σ includes: obtaining the tagged data m frank =m||σ, and then calculating the tagged ciphertext The calculation method is: use the key generation algorithm KG in the signature scheme DS in the common parameters to generate a signature key pair (ak, vk)←DS.KG(λ), ak is the private key, vk is the public key; then select a random number And calculate the common part of the ciphertext At the same time, calculate the parameter α = H1(V1, V2, vk); the public key of the recipient φ i in the target recipient set Calculate the parameter Then generate the ciphertext Let τ: {1,..., l} → {1,..., l} be a random permutation, where l is the number of recipients in the set ; Set the parameter C = (V1, V2, {A τ(i)} i∈[1,l] ), and use the signature generation algorithm Sig in the signature scheme DS in the public parameters to generate a signature Finally, set the tagged ciphertext as

[0023] The advantages and positive effects of the present invention are as follows: The method of the present invention innovatively adopts the tagged broadcast matching encryption FBME scheme, which is an innovative multi-recipient matching encryption scheme that supports recipient anonymity and verifiable reporting functions. The FBME scheme used in the method of the present invention only generates tagged signatures for data, does not include the encapsulation key of the target recipient set, and encrypts the data and tagged signatures while embedding the sender's key. This design enables authorized recipients to access data from the real sender without disclosing any information about the privileged recipient set, and at the same time allows them to report harmful content to the examiner and hold malicious senders accountable. Therefore, the method of the present invention realizes anonymous multi-recipient bilateral access control, and at the same time meets the ideal attributes of content review, namely accountability and deniability, and meets the requirements of access control and content review for privacy protection in the cloud data sharing scenario. Brief Description of the Drawings

[0024] Figure 1 It is a schematic diagram of the data sharing process of the data access control method of the present invention;

[0025] Figure 2 It is an architecture diagram of the FBME technical solution of the present invention. Detailed Embodiment

[0026] The present invention will be further described in detail below with reference to the drawings and embodiments.

[0027] As Figure 1 shown, the entities involved in the data access control method for content review supported in the cloud environment of the present invention include a service provider, a cloud server, a data sender, and a data recipient. The functions implemented by each entity are as follows:

[0028] (1) Service provider. The service provider operates as a data sharing platform, such as a data market, to facilitate the interaction between data senders and recipients. The service provider in the embodiment of the present invention acts as an examiner when outsourcing the storage of encrypted data to the cloud server, and is responsible for verifying the authenticity of harmful content reports and holding the sender accountable.

[0029] (2) Cloud server. The cloud server is a remote storage facility used to store the encrypted data uploaded by the service provider. The cloud server provides a wide range of storage capacities for processing a large amount of encrypted data uploaded from the data sender through the service provider platform.

[0030] (3) Sender. The data sender uses its private key and the public key of the target recipient to perform tag signing and encryption on the data; then, the sender outsources the signed and encrypted ciphertext to the service provider.

[0031] (4) Recipient. The data recipient decrypts the tagged ciphertext. If the recipient suspects that the content is malicious, it can verify whether it meets the reporting criteria, such as whether the reviewer can verify the content and submit a report to the service provider for review.

[0032] The core of the method of the present invention is to implement a tagged broadcast matching encryption FBME. FBME is based on the "sign-then-encrypt" design mechanism, which can generate authenticated ciphertexts in an anonymous multi-recipient environment, realize the authenticity verification of the sender, and at the same time support the recipient to make verifiable reports on malicious content. Specifically, the design of FBME is carried out from two aspects:

[0033] 1) Content review. FBME generates an asymmetric tag signature through a non-interactive zero-knowledge proof (NIZKP) system, which only signs the data itself, rather than including the encapsulation keys of all target recipients, thus avoiding leaking the recipient set information and protecting the recipient anonymity. This signature constructs a proof of relationship related to the sender's key through the NIZKP system combined with the Fiat-Shamir transformation and the Sigma protocol, enabling the target recipient to verify the validity of the zero-knowledge proof. In addition, the tag signature encapsulates the ciphertext and the key for the reviewer, and at the same time, the tag signature also encapsulates the ciphertext and the verification key for the reviewer, ensuring that only the service provider uses its secret key to verify the tag signature, thus achieving a balance between holding malicious senders accountable and sender non-repudiation.

[0034] 2) Bilateral access control. FBME is based on the anonymous broadcast encryption (ANOBE) framework and combines a public-key encryption scheme with chosen-ciphertext indistinguishability and a strongly unforgeable one-time signature scheme. Although ANOBE provides the ability to encapsulate the message key into each recipient's ciphertext component, it does not inherently support sender authentication. To solve this problem, FBME introduces an additional message key, which is jointly derived from the sender's private key and the recipient's public key. These two keys jointly participate in the encryption process of the data and the tag signature, forming an authentication component for each recipient, thus ensuring that the recipient can verify the data source and decrypt the data securely.

[0035] This structured design ensures that the data recipients in FBME can securely identify the data source. Meanwhile, through the message tagging mechanism, any malicious content can be effectively reported and verified.

[0036] A specific implementation of the multi-recipient bilateral access control method for content review support in data sharing in the cloud environment of the present invention is as follows:

[0037] First, to implement bilateral access control, FBME defines the following six algorithms.

[0038] 1) System initialization algorithm Setup(1 λ ,n) → pp, which takes the security parameter λ and the number of recipients n in the system as inputs and outputs the system public parameters pp.

[0039] 2) Sender key generation algorithm SKGen(pp) → (spk, ssk), which takes the public parameters pp as input and outputs a public-private key pair (spk, ssk) for the data sender. spk is the public key and ssk is the private key.

[0040] 3) Recipient key generation algorithm RKGen(pp) → (rpk j , rsk j ), which takes the public parameters pp as input and outputs a public-private key pair (rpk j , rsk j ) for the data recipient. rpk j , rsk j are respectively the public key and private key of recipient j, where j is the number of the data recipient.

[0041] 4) Censor key generation algorithm JKGen(pp) → (pk J , sk J ), which takes the public parameters pp as input and outputs a public-private key pair (pk J , sk J ) for the censor. pk J , sk J are respectively the public key and private key of the censor.

[0042] 5) Encryption algorithm When taking the public key pk J of the censor, the public key spk and private key ssk of the sender, the set of target recipients and the message m as inputs, the encryption algorithm outputs the ciphertext ct.

[0043] 6) Decryption algorithm Decrypt(pp, pk J , spk, rsk j , ct) → (m, σ) / ⊥, which takes the public key pk J, the public key spk of the sender, the private key rsk of the receiver, and the ciphertext ct. The algorithm outputs the plaintext and the tag signature pair (m, σ) or ⊥.

[0044] Then, to implement content censorship, FBME defines the following three algorithms.

[0045] 7) Reporting algorithm Report(pp, pk J , spk, m, σ) → (1, report) / 0, which takes as input the public key pk of the reviewer J , the public key spk of the sender, the message m, and the tag signature σ. If π in σ is invalid, the algorithm outputs 0, indicating verification failure; otherwise, it outputs 1, indicating verification success and generating a reporting proof report, which can be sent to the reviewer for accountability.

[0046] 8) Review algorithm Judge(pp, sk J , spk, report) → 1 / 0, which takes as input the private key sk of the reviewer J , the public key spk of the sender, and the reporting proof report. The algorithm outputs 1 or 0, where 1 represents verification passed and 0 represents verification failed.

[0047] 9) Forgery algorithm Forge(pp, pk J , spk, m) → σ, which takes as input the public key pk of the reviewer J , the public key spk of the sender, and the message m. The algorithm outputs a "forged" signature σ.

[0048] Then, a specific implementation process of the method of the present invention includes the following four steps.

[0049] Step 1: System initialization, perform key generation. Initialize the system parameters, and each participant generates its own public and private keys. Among them, the sender and the receiver need to register their public keys with the service provider.

[0050] Step 1.1) System initialization, the service provider executes the system initialization algorithm Setup(1 λ , n):

[0051] Let be a group of prime order p with a generator a bilinear pairing e: Select 2 collusion-resistant hash functions: H1: H2: where represents a non-zero integer. Select two collusion-resistant key derivation functions: H: H: where the parameter η ∈ poly(λ), and a strongly unforgeable one-time signature scheme: DS = (KG, Sig, Vrf), which includes three algorithms: key generation KG, signature generation Sig, and signature verification Vrf. Set the public parameters poly(λ) is a polynomial in the security parameter λ, which is usually used in cryptography to describe the growth law of some parameters in the system (such as key length or output length) relative to the security parameter.

[0052] Step 1.2) Key generation.

[0053] (1) Generate the data sender's key using SKGen(pp): Select a random value Calculate the intermediate parameter Set the public key spk = (E1, E2), and the private key ssk = (s, θ1, θ2).

[0054] (2) Generate the data receiver's key using RKGen(pp): Select a random value And calculate the parameter Set the public key rpk of data receiver j j =(D 1,j , D 2,j , D 3,j ), and the private key

[0055] (3) Generate the examiner's key using the algorithm JKGen(pp): Select two random values Set the public key The private key

[0056] Step 2: Data publishing. The sender encrypts the data using its private key and the set of public keys of the target receivers, generates a ciphertext containing the marked signature, and uploads the ciphertext to the cloud data sharing platform. The service provider is responsible for storing the ciphertext on the cloud server.

[0057] For the data plaintext m, the sender uses the encryption algorithm for the set of public keys of the target receivers Generate the marked ciphertext and upload it to the service provider, and the service provider outsources the storage of the ciphertext to the cloud server.

[0058] The sender executes the algorithm Including: Obtain its own private key ssk = (s, θ1, θ2) and public key spk, the public key pk of the examiner J , the set of public keys of the target receivers Set For each receiver φ i in the set, the public key is denoted as is the set The number of recipients; and is executed in two steps:

[0059] Step 2.1) Generate a tag signature σ for m. Select a random number Calculate the intermediate parameter Let the encapsulated ciphertext component c = (u1, u2). Calculate the encapsulation key For the relation Let the statement and the evidence ⊥ represents empty. Use the proof algorithm Prove of NIZKP of the zero-knowledge proof system to generate a zero-knowledge proof and set the tag signature σ = (π, c, k J ). Specifically, the relation consists of 3 sub-relations:

[0060]

[0061] The relation proves the validity of the sender's public-private key pair. The relation proves that (c, k J ) is generated by the same random value r. The relation proves that c is an illegal ciphertext component generated by the parameter r * = (r, r′), where r′ represents a random number different from r. By combining these sub-relations, the complete relation is defined as follows:

[0062]

[0063] where ∧ represents the AND operation and ∨ represents the OR operation.

[0064] Above The first part of the expression contains two sub-parts: (i) guarantees the sender's authentication of the examiner; (ii) guarantees that the ciphertext component c and the corresponding examiner encapsulation key k J are in good format and further convinces the recipient that c and k J can be successfully verified by the examiner. The second part of the expression aims to guarantee deniability. In other words, it allows a forger to construct a valid zero-knowledge proof π without knowing the sender's private key while preventing the formation of a valid tag signature σ. The relation combines these two parts with the "or" operation. Therefore, either the sender or the forger can generate a valid Generate a valid zero - knowledge proof. The first part can be used by the legitimate sender to generate a legitimate proof π, and the second part can be used by the forger to generate a legitimate proof π with two random numbers it holds. However, only the legitimate sender can generate σ for the verifier to verify.

[0065] Step 2.2) Encrypt m and σ. Let the marked data m frank = m||σ, and calculate the marked ciphertext ct according to the following steps.

[0066] First, generate a signature key pair (ak, vk) ← DS.KG(λ), where ak is the private key and vk is the public key, and DS.KG is the key generation algorithm in the signature scheme. Then select a random number and calculate the public part of the ciphertext At the same time, calculate the parameter α = H1(V1, V2, vk). For each First calculate Then generate the ciphertext Both are intermediate parameters. Let τ: {1,..., l} → {1,..., l} be a random permutation, set C = (V1, V2, {A τ(i)} i∈[1,l] ), and calculate the signature DS.Sig is the signature generation algorithm in the signature scheme. Finally, set the marked ciphertext as

[0067] Step Three: Data reception. After the receiver obtains the ciphertext from the cloud server, it first verifies the authenticity of the sender, and then restores the original data through decryption operations.

[0068] The receiver designates a target sender and retrieves the matching data from the cloud server. For each ciphertext, the receiver uses the decryption algorithm Decrypt(pp, pk J , spk, rsk j , ct) to decrypt it.

[0069] Based on spk = (E1, E2), the receiver j , the public key of the verifier pk J , decrypts the received ciphertext ct and executes the following process to restore the plaintext. Verify ct, if then return ⊥. Otherwise, calculate α = H1(V1, V2, vk), and then calculate the parameters and DS.Vrf is the signature verification algorithm in the signature scheme. Generate and judge If m frank is not empty, then parse m frank = m||σ, return the plaintext m, otherwise output ⊥.

[0070] Step 4. Content review. If the recipient discovers malicious content in the data, then verify the zero-knowledge proof in the ciphertext to ensure that the ciphertext can be reported, and generate a report proof with a marked signature and submit it to the service provider. As the reviewer, the service provider runs a review algorithm after receiving the report from the recipient, verifies the legality of the marked signature, confirms the data source, and holds the malicious sender accountable, while effectively preventing false reports.

[0071] In the content review stage, if the recipient suspects that the data is malicious, they can use the reporting algorithm to check whether the malicious message can be successfully verified by the reviewer and generate a report proof to send to the service provider for accountability.

[0072] Step 4.1) The data recipient executes the Report(pp,pk J ,spk,m,σ) algorithm. If m is considered malicious, the recipient performs the following verification:

[0073] Parse σ=(π,c,k J ), set the statement Use the verification algorithm Verify of NIZKP to verify the legality of π. If then it means that π is illegal or invalid, return 0, the verification fails, indicating that the malicious message cannot be verified by the reviewer; otherwise output 1, indicating that π is legal, the verification is successful, and the reviewer can verify the malicious message. If the verification is successful, generate a report proof report=(m,σ).

[0074] Step 4.2) When the reviewer receives a report from the data recipient, the reviewer runs a review algorithm to determine whether the message was sent by the corresponding sender, aiming to avoid false reports and ensure accountability. First, call NIZKP.Verify to check the validity of the zero-knowledge proof, and then use the reviewer's private key to verify whether the encapsulated key and the corresponding decapsulated key are the same.

[0075] The execution of the review algorithm Judge(pp,sk J ,spk,report) includes: Parse spk=(E1,E2), report=(m,σ) and σ=(π,c,k J ). Let the statement If then return 0, otherwise calculate the parameter If k J ′≠k J, return 0, otherwise return 1. When the review algorithm returns 0, it represents that the verification fails, marking that the signature verification fails. The reviewer cannot determine that the malicious message was sent by the sender claimed by the recipient, indicating that there is a situation where the recipient abuses the report. When the review algorithm returns 1, it represents that the verification is successful, marking that the signature verification passes. This time, the recipient's report is successful, and the malicious message was indeed sent by the corresponding sender. In this way, the recipient can identify the malicious sender who sent the malicious information and seek appropriate compensation from the sender.

[0076] Step Five: The method of the present invention is also equipped with a forgery algorithm to forge signatures that look convincing and indistinguishable from legitimate signatures. Note that the forgery algorithm is not intended to be executed by legitimate users. Instead, its existence ensures that in the scenario where specific sensitive data is leaked from the service provider, the sender can deny it to the public to avoid reputation and other impacts.

[0077] The specific execution of the forgery algorithm Forge(pp, pk J , spk, m) includes: parsing spk = (E1, E2), first selecting Calculating And setting the encapsulated ciphertext component c * = (u1, u2). Then calculating the encapsulation key For the relationship Let the statement And the evidence Using the zero-knowledge proof system NIZKP to generate a zero-knowledge proof And setting the "forged" marked signature σ = (π, c, k J ).

[0078] The purpose of designing the forgery algorithm in the present invention is to solve a special scenario requirement existing in the real data sharing platform, that is, if the sensitive data of the platform is leaked, in order to protect the rights and interests of the data owners and protect their privacy, the data sharing platform wants to protect them. The existence of the forgery algorithm enables only the platform reviewer to verify and hold accountable for malicious messages. When sensitive data is accidentally leaked to the public, since both legitimate senders and illegal adversaries can generate the proof π, the public cannot attribute the message to the sender and cannot determine who generated the message, thus protecting the sender from economic or reputation impacts and protecting the sender's privacy to a certain extent.

[0079] In general, the various example embodiments of the present disclosure may be implemented in hardware or dedicated circuits, software, firmware, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device. When aspects of the embodiments of the present disclosure are illustrated or described as block diagrams, flowcharts, or using some other graphical representation, it will be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented as non-limiting examples in hardware, software, firmware, dedicated circuits or logic, general hardware or controllers or other computing devices, or some combination thereof.

[0080] Except for the technical features described in the specification, all are well-known technologies to those skilled in the art. The present invention omits the description of well-known components and well-known technologies to avoid redundancy and unnecessarily limit the present invention. The implementation manners described in the above embodiments do not represent all the implementation manners consistent with the present application. Based on the technical solution of the present invention, various modifications or deformations that can be made by those skilled in the art without creative efforts are still within the protection scope of the present invention.

Claims

1. A data access control method supporting content review in a cloud environment, characterized in that: include: Step 1: The service provider generates public parameters and sends them to the sender and receiver of the data. Each party generates its own public-private key pair. The service provider also acts as an examiner and generates the examiner's public-private key pair based on the public parameters. The sender and each receiver generates their own public-private key pair based on the public parameters. Step 2: The sender encrypts the data based on its own private key and the target recipient's public key set to generate a ciphertext containing a signature, and uploads the ciphertext to the cloud data sharing platform, where the service provider stores the ciphertext on the cloud server; Step 3: The receiver retrieves the ciphertext from the cloud server, verifies the authenticity of the sender, and then restores the original data through decryption. Step 4: After the receiver obtains the ciphertext from the cloud server and decrypts it, if it finds that the data contains malicious content, it verifies the zero-knowledge proof in the ciphertext. If the verification is successful, it means that the ciphertext can be reported, and generates a report certificate with a marked signature and submits it to the service provider; Step 5: The service provider acts as a reviewer and runs a review algorithm after receiving the report certificate from the recipient to verify the legitimacy of the marked signature and confirm the source of the data.

2. The method according to claim 1, characterized in that In step 1, the service provider generates public parameters in: is a group of prime order p, select two data Generate a bilinear pairing Two Collusion-Resistant Hash Functions Two Collusion-Resistant Key Derivation Functions Parameter η∈poly(λ), λ is a security parameter, and poly(λ) is a polynomial about the security parameter λ; DS is a strongly unforgeable one-time signature scheme.

3. The method according to claim 1 or 2, characterized in that: In step 1, the service provider generates the public and private key pair of the auditor, including: selecting two random values Setting the public key Private Key in represents a non-zero integer, g1, g2 are obtained from the public parameter pp; The method for the sender to generate a public-private key pair includes: selecting a random value Calculation parameters Set public key spk = (E1, E2), private key ssk = (s, θ1, θ2); The method for the receiver j to generate a public-private key pair includes: selecting a random value x 1,j ,x 2,j ,y 1,j ,y 2,j , Calculate intermediate parameters Set the public key rpk of the receiver j j =(D 1,j ,D 2,j ,D 3,j ), private key 4. The method according to claim 1 or 2, characterized in that: In step 2, the sender obtains its own public key spk = (E1, E2) and private key ssk = (s, θ1, θ2), and the auditor's public key pk J , and the target recipient's public key set Generate a signature for plaintext m based on public parameters, including: Select a random number Calculate intermediate parameters Let the encapsulated ciphertext component c = (u1, u2); calculate the encapsulation key Targeting relationships Order statement evidence ⊥ means empty, and the zero-knowledge proof is generated by the proof algorithm Prove of the non-interactive zero-knowledge proof NIZKP Set the tag signature σ = (π, c, k J ); Among them, the relationship It consists of 3 sub-relations: relation Prove the validity of the sender's public and private key pair. Prove that (c,k J ) are generated by the same random value r, the relationship Prove that c is formed by r * = (r, r′) generates an illegal ciphertext component, where r′ represents a random number different from r; the relationship is obtained by combining the three sub-relations as follows: Among them, ∧ represents the AND operation, and ∨ represents the OR operation; The first part of the expression For the legitimate sender to generate a legitimate proof π, which consists of two sub-parts: Ensure that the sender authenticates the identity of the reviewer; (ii) Ensure that the ciphertext component c and the corresponding auditor wrapping key k J is well-formed and further convinces the receivers c and k J Can be successfully verified by the examiner; The second part of the expression The forger uses the two random numbers he holds to generate a legitimate proof π.

5. The method according to claim 4, characterized in that In the step 2, after the sender generates a signature σ for the plaintext m, it encrypts m and σ, including: obtaining the signature data m frank =m||σ, then calculate the marked ciphertext ct; Let the sender set The receiver φ i The public key is represented as i=1,2,...l, l is a set The number of recipients; First, use the key generation algorithm KG in the signature scheme DS in the public parameters to generate a signature key pair (ak, vk)←DS.KG(λ), where ak is the private key and vk is the public key; then select the random number And calculate the public part of the ciphertext At the same time, calculate the parameter α = H1 (V1, V2, vk); set Each receiver φ i The public key is represented as Calculation parameters Then generate the ciphertext Let τ:{1,...,l}→{1,...,l} be a random permutation, and set the parameter C=(V1,V2,{A τ(i) } i∈[1,l] ) and use the signature generation algorithm Sig in the signature scheme DS in the public parameters to generate a signature Finally, set the ciphertext to 6. The method according to claim 1 or 2, characterized in that: In step 3, after the receiver j retrieves and receives the ciphertext ct from the cloud server, it decrypts ct, including: the receiver j obtains the sender's public key spk = (E1, E2), its own private key First, use the verification signature algorithm Vrf in the signature scheme DS in the public parameters to To verify, if Return ⊥; otherwise calculate the parameter α=H1(V1,V2,vk), calculate the parameter and Generate labeled data If m frank ≠⊥, parsing m frank =m||σ, returns the plaintext m, otherwise returns ⊥.

7. The method according to claim 1 or 2, characterized in that: The fourth step includes: the receiver parses the signature σ=(π,c,k J ), set the statement Then use the NIZKP verification algorithm to verify the legitimacy of the zero-knowledge proof π obtained by parsing. Indicates that π is illegal, returns 0, verification fails, and the auditor cannot verify the data suspected by the receiver to contain malicious content; otherwise, outputs 1, indicating that π is legal, verification succeeds, and generates a report certificate report = (m, σ).

8. The method according to claim 1 or 2, characterized in that: The step 5 includes: the examiner parses the sender's public key spk = (E1, E2), the report certificate report = (m, σ) and the marking signature σ = (π, c, k J ), order statement where pk J is the auditor's public key and the auditor's private key Then use NIZKP's verification algorithm to check the validity of the zero-knowledge proof. Returns 0, otherwise the wrapped key is calculated Verify k J ′ is the same as the decapsulated key k J If they are the same, return 0, otherwise return 1; 0 means verification failed, the tag signature is illegal, and the receiver has abused the report; 1 means verification is successful, the tag signature is legal, the receiver reported successfully, and the data containing malicious content was sent by the sender reported by the receiver.

9. The method according to claim 1 or 2, characterized in that: The method described above configures a forgery algorithm, which is provided to illegal users and not used by legal users. The implementation of the forgery algorithm includes: inputting the sender's public key spk = (E1, E2), selecting two different random numbers r and r', r * =(r,r′); then calculate the encapsulated ciphertext component c * =(u1,u2), where Calculate the wrapping key Targeting relationships Order statement evidence Generate zero-knowledge proof using NIZKP's proof algorithm Set the forged tag signature σ=(π,c,k J ).

Citation Information

Patent Citations

  • Privacy protection identity authentication system and method for Internet of Vehicles

    CN113395167A

  • Public key encryption method supporting bidirectional access control and capable of realizing responsibility investigation

    CN117254906A