Access control method based on outsourcing calculation and attribute-based searchable encryption on block chain

By implementing an access control method of outsourcing computing and attribute-based searchable encryption on the blockchain, the problems of large local computing overhead and low data sharing efficiency in attribute-based encryption are solved, and more efficient and secure data sharing is achieved.

CN119995827AActive Publication Date: 2025-05-13HUBEI UNIV

Patent Information

Application Number
CN202510178125.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-13
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

In existing attribute-based encryption, there are problems such as large local computing overhead and low data sharing efficiency.

Method used

The access control method based on blockchain is adopted for outsourcing computing and attribute-based searchable encryption, and user attributes are verified through smart contracts on the blockchain to achieve secure sharing and efficient retrieval of data.

Benefits of technology

It reduces the computing overhead of local users, improves data sharing efficiency and security, and significantly reduces the computing burden of local users' encryption and decryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995827A_ABST
    Figure CN119995827A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data sharing, and particularly discloses an access control method based on outsourcing calculation and attribute-based searchable encryption on a block chain, comprising the following steps: S1, an attribute authority initializes to generate a system public key and a master key, and generates an attribute private key of a user; s2, the data owner formulates an access control strategy to assist the outsourcing encryption service provider in partial encryption, and the data user and the outsourcing encryption service provider encrypt the keyword, the data ciphertext storage address and the symmetric key and upload the encrypted ciphertext to the block chain for storage; s3, the data user generates a search trap door and sends the search trap door to the block chain, and user attributes are verified; and S4, the data user assists the outsourcing decryption service provider in partially decrypting the ciphertext, locally decrypting to obtain the data storage address and the symmetric key, downloading the data ciphertext, and decrypting by using the symmetric key to obtain the data plaintext. According to the invention, the calculation burden of encryption and decryption of a local user is reduced, and the sharing efficiency and security of data are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cyberspace security data sharing, and in particular to an access control method based on outsourced computing and attribute-based searchable encryption on a blockchain. Background Art

[0002] With the rapid development of cloud computing, data has become the most critical resource in the Internet era. In this context, cross-domain data exchange and sharing have become increasingly important, and the role of access control mechanisms has become increasingly prominent. The main purpose of access control is to protect the security of data resources and ensure that the confidentiality, integrity and availability of resources are effectively maintained under various security requirements. By formulating appropriate access control policies, access control restricts the access rights of subjects (such as users) to resources, thereby ensuring that only legitimate users can access and operate relevant data. Existing access control mechanisms can effectively manage and control access rights within a single management domain to ensure data security. However, with the rapid growth of data sharing needs and the increase in cooperation and business transactions between enterprises and organizations, the secure exchange of cross-domain data has become particularly important.

[0003] Outsourced encryption and decryption technology refers to the technology of transferring encryption and decryption operations from traditional local systems or devices to third parties (such as cloud service providers). When processing data, it allows users to outsource computing-intensive encryption and decryption operations to cloud services, thereby reducing the consumption of local computing resources and improving the efficiency and flexibility of the system. When outsourcing encryption, users entrust encryption operations to cloud service providers or third parties. In this case, the data will be encrypted before storage or transmission to ensure that the data cannot be read or tampered with even if it is accessed externally. When outsourcing decryption, on the basis of outsourced encryption, outsourced decryption allows a third party to decrypt encrypted data if certain conditions are met. Through effective encryption and decryption control and permission management, it can be ensured that only qualified users or services can decrypt data, and decryption operations can be performed by a third party on behalf of the user.

[0004] Blockchain is a distributed ledger that connects several data blocks in chronological order. It is decentralized, tamper-proof, collectively maintained, leaves traces throughout the process, and allows transactions to be traced. It uses encryption algorithms to ensure data security, transparency, and immutability. When sharing data between multiple institutions or companies, blockchain provides a trusted neutral platform that avoids the trust issues in traditional data sharing. Through the consensus mechanism, blockchain ensures data consistency and coordination between all parties.

[0005] Attribute-based searchable encryption is a cryptographic technology that combines attribute-based encryption (ABE) and searchable encryption (SE). When data is encrypted, the data is not only bound to the access control policy (for example, the data can only be decrypted by users with certain attributes), but also enables encrypted queries based on keywords or attributes. When searching, the query request is matched with the attributes of the encrypted data. Only users who meet the access control policy can perform the search, and the actual content of the data will not be exposed when searching. It is used to perform secure queries on specific attributes in encrypted data. With the increasing demand for cloud computing, data sharing, and privacy protection, this technology has received increasing attention, especially for scenarios that require fine-grained access control and efficient data retrieval. Summary of the invention

[0006] In order to solve the problems of high local computing overhead and low data sharing efficiency in existing attribute-based encryption, the present invention provides an access control method based on outsourced computing and attribute-based searchable encryption on blockchain, which can reduce local user computing overhead while improving data sharing efficiency and security.

[0007] To achieve the above objectives, the present invention proposes an access control method based on outsourced computing and attribute-based searchable encryption on blockchain, the steps of which are as follows:

[0008] S1. The trusted authority AA initializes and generates the system public key PK and the master key MSK, and generates the user attribute private key according to the attribute set of the data user;

[0009] S2. The data owner formulates an access control strategy and assists the outsourced encryption service provider in partial encryption. The data user and the outsourced encryption service provider encrypt the keywords, data ciphertext storage address and symmetric key and upload the encrypted ciphertext to the blockchain for storage;

[0010] S3: The data user generates a search trapdoor and sends it to the blockchain. The search trapdoor contract is called to verify the user attributes. If the user attributes meet the access control policy, the relevant ciphertext corresponding to the keyword is returned to the data user.

[0011] S4. The data user first assists the outsourced decryption service provider to decrypt the ciphertext part, then decrypts it locally to obtain the data storage address and symmetric key, downloads the data ciphertext from IPFS according to the storage address, and finally uses the symmetric key to decrypt the data ciphertext to obtain the data plaintext.

[0012] Preferably, in S1, the specific steps for the trusted authority to initialize and generate the system public key PK and the master key MSK are:

[0013] The trusted authority AA executes the initialization algorithm Setup(1 λ )→(PK,MSK), input the security parameter λ, generate a multiplication cyclic group G1 and G with a prime order of p T , given a bilinear mapping pair e:G1×G1→G T , define two random anti-collision Hash functions, for each attribute i∈U, randomly select parameters t1, t2, t3, and calculate e(g, g) respectively α , g β , generate the system public key PK and master key MSK:

[0014]

[0015] MSK={t1,t2,t3,α,β};

[0016] In the formula, e(g,g) α and g β All of them are mathematical formulas about double mapping pairs in cryptography, and all of them are calculation results. They are components of the system public key PK. g is the generator of G1, and the mapping relationship H1:{0,1} * →G1, represents the finite field of 1, 2, ..., p-1, {0,1} * represents a set of bit strings of arbitrary length, U is a set of system properties, and two integers are randomly selected from the finite field

[0017] Preferably, in S1, the specific steps of the trusted authority generating the user attribute private key according to the attribute set of the data user are:

[0018] S11. The trusted authority AA executes the key generation algorithm KeyGenblind(PK,MSK,S)→(SK), inputs the system public key PK, the master key MSK and the user attribute set S, and the trusted authority AA uses the Schnorr protocol to blind each user attribute i, i∈S, calculates Q, L, and calculates the challenge σ i ,calculate Challenges i The response is calculated as:

[0019] Q = z·G;

[0020] L = m·G;

[0021] σ i =H2(G‖Q‖P‖j);

[0022]

[0023] In the formula, Q represents the blinded public key, L represents the calculated value bound to the signature and the message content, and σ i Indicates that the verifier sends a randomly generated challenge to the prover. It means that the prover generates a response based on his secret and challenge and sends it to the verifier. G is a point on the elliptic curve, and the data user DU randomly selects two integers in the finite field.

[0024] S12. Order The data user DU sends info to the smart contract. For each attribute i∈U, the trusted authority AA generates an attribute private key based on the blinded user attribute set and randomly selects an integer in the finite field. The calculated attribute private key SK is:

[0025]

[0026] In the formula, info is a defined four-tuple, and D1 and D2 are partial composition parameters of the attribute private key.

[0027] Preferably, in S2, the data user and the outsourced encryption service provider encrypt the keyword, the data ciphertext storage address and the symmetric key and upload the encrypted ciphertext to the blockchain for storage, and the specific steps include:

[0028] S21, encryption service provider ESP partially encrypts to form an intermediate ciphertext;

[0029] S22. The data owner DO first encrypts the data plaintext based on the intermediate ciphertext, then encrypts the data ciphertext storage address, and finally encrypts the keyword set and the symmetric key.

[0030] Preferably, in S21, the specific steps of partially encrypting the intermediate ciphertext by the outsourced encryption service provider are:

[0031] S211, the encryption service provider ESP executes the EncryptESP(PK,T) algorithm, inputs the access control policy set by the user and converts it into an access structure tree T;

[0032] S212, the system public key PK starts from the root node of the access structure tree T, and randomly selects a node of order d for each non-leaf node x of the access structure tree from top to bottom. x The polynomial q x , randomly select a positive integer in the finite field As the node value of the root node R of the access structure tree T, set qR(0) = s, let Y be the attribute set of the leaf nodes in the access structure tree T, calculate and output the intermediate ciphertext as: CT ESP ={D x ,D' x}, where h x =H1(att(x));

[0033] In the formula, h x represents the result of the hash function H1. The input att(x) is the attribute of the leaf node. D x is the power term of the generator of group G1, D' x is the power term result of a hash function H1, q x (0) is the polynomial q corresponding to the leaf node x At the value of 0, d x =k x -1, k x Indicates the threshold of the node. For other non-leaf nodes x, set q x (0)=qparent(x)(index(x)), x∈Y.

[0034] Preferably, in S22, the data owner DO first encrypts the data plaintext based on the intermediate ciphertext, then encrypts the data ciphertext storage address, and finally encrypts the keyword set and the symmetric key. The specific steps are:

[0035] S221. The data owner DO extracts the keyword set W from the data plaintext m, encrypts the data plaintext m with the symmetric key, generates data ciphertext = Enc(m, key) and uploads it to the IPFS interplanetary file system. The returned data ciphertext storage address is encrypted with the same symmetric key key to generate the storage address ciphertext CT addr =Enc(addr,key);

[0036] S222. The data owner DO defines a keyword set W = {ω} and a symmetric key, performs attribute-based encryption, and executes the encryption algorithm Encrypt DO (PK, CT ESP , key, W)→CT, the data owner DO randomly selects a set of user attributes Calculate and get C0 = key·e(g,g) αs , C1=g βs The output symmetric key ciphertext is CT key ={C0,C1};

[0037] In the formula, C0 and C1 both represent the symmetric key partial ciphertext, and the two together constitute the symmetric key ciphertext. C0 is related to the symmetric key key, and C1 is related to the attribute set S.

[0038] S223, Randomly select a positive integer field Calculate keyword ciphertext Storage address ciphertext CT addr =Enc(addr,key), the final ciphertext CT = (CT key ,CT ω ,CT addr ,CT ESP ) and upload it to the blockchain for storage. The blockchain uses the index generation contract to create an index for the keyword ciphertext, where C2 and C3 both represent partial ciphertexts of the keyword ciphertext.

[0039] Preferably, in S3, the specific steps for a data user to generate a search trap to call a smart contract in the blockchain to perform keyword matching to obtain ciphertext are:

[0040] S31, data user DU executes trapdoor generation algorithm Trapdoor(PK,SK,S,τ)→T τ , input the system public key PK, attribute private key SK, data user DU attribute set S and search keyword τ, data user DU randomly selects an element Calculate search gate parameters y3=D1 v , generate search gate trap T τ ={y1,y2,y3,{B i =(D i ) v ,B' i =(D' i ) v} i∈S}, and sent to the blockchain for search verification;

[0041] S32. When calling the smart contract in the blockchain, the legitimacy of the DU attribute is first verified. When the verification is successful, the ciphertext corresponding to the matching keyword is searched. The calculation formula of the smart contract is:

[0042] S33. When L′=L, the attribute verification is successful, and the relevant ciphertext set is returned and sent to DU, which then sends it to the outsourced decryption service provider. If the attribute verification fails, the entire algorithm process is terminated.

[0043] Preferably, the search trapdoor smart contract in the blockchain is used to verify whether the DU attribute set satisfies the access control policy, and the attribute legitimacy is checked by a non-interactive Schnoor protocol verification.

[0044] Preferably, in S4, the data user first assists the outsourced decryption service provider to partially decrypt the ciphertext in the following specific steps:

[0045] S411, return the decryption result to DU, using the execution algorithm Decrypt DSP (PK,CT ESP,T τ ,S)→F Δ , and divide it into two cases:

[0046] S4111, x (x∈S) is a leaf node, then the calculated value F of the leaf node x used for decryption x for:

[0047]

[0048] Among them, when When F x =⊥;

[0049] S4112, x is a non-leaf node, let ρ x is a set of child nodes of any threshold, then for each child node π of x, ρ is used for decryption x The value F obtained by weighted accumulation of each non-leaf node x in the set π for:

[0050]

[0051] S412: Determine whether the attribute set of DU satisfies the access control policy. If it does, perform partial decryption to obtain the converted ciphertext F. Δ =e(g,g) uvs Return to DU.

[0052] Preferably, in S4, after DU obtains the converted ciphertext, it decrypts it locally to obtain the symmetric key, and the specific steps of accessing IPFS to finally decrypt and obtain the data plaintext are:

[0053] S421, using Decrypt DSP (PK,CT,F Δ ,SK,S)→m executes the algorithm to decrypt DU, which is calculated by the following formula:

[0054]

[0055] In the formula, θ represents the partial decryption result of the symmetric key ciphertext, and the partial decryption result is used to decrypt the data ciphertext key;

[0056] S422, DU decrypts the data ciphertext key Decrypted data ciphertext storage address addr = Dec(key, CT addr ), access IPFS from addr to get the data ciphertext CT m , and finally decrypted to obtain the data plaintext m = Dec(key, CT m ).

[0057] Therefore, the present invention proposes an access control method based on outsourced computing and attribute-based searchable encryption on blockchain, which has the following beneficial effects:

[0058] The present invention solves the problems of high local computing overhead and low data sharing efficiency in existing attribute-based encryption. It can reduce local user computing overhead while improving data sharing efficiency and security, effectively reducing the computing burden of encryption and decryption for local users, and significantly improving data sharing efficiency and security.

[0059] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 This is an access control model diagram based on outsourced computing and attribute-based searchable encryption on the blockchain. DETAILED DESCRIPTION

[0061] In order to make the technical solutions, advantages and purposes of the present invention clearer, the technical solutions of the embodiments of the present invention are clearly and completely described below. The described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the described embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work belong to the protection scope of this application.

[0062] Unless otherwise defined, technical or scientific terms used in the present invention shall have the common meanings understood by one having ordinary skills in the field to which the present invention belongs.

[0063] like Figure 1 As shown, the present invention proposes an access control method based on outsourced computing and attribute-based searchable encryption on a blockchain, the method comprising:

[0064] S1. The trusted authority AA initializes and generates the system public key PK and the master key MSK, and generates the user attribute private key according to the attribute set of the data user;

[0065] In S1, the specific steps for the trusted authority to initialize and generate the system public key PK and the master key MSK are as follows:

[0066] The trusted authority AA executes the initialization algorithm Setup(1 λ )→(PK,MSK), input the security parameter λ, generate a multiplication cyclic group G1 and G with a prime order of p T , given a bilinear mapping pair e:G1×G1→G T , define two random anti-collision Hash functions, for each attribute i∈U, randomly select parameters t1, t2, t3, and calculate e(g, g) respectivelyα , g β , generate the system public key PK and master key MSK:

[0067]

[0068] MSK={t1,t2,t3,α,β};

[0069] In the formula, e(g,g) α and g β All of them are mathematical formulas about double mapping pairs in cryptography, and all of them are calculation results. They are components of the system public key PK. g is the generator of G1, and the mapping relationship H1:{0,1} * →G1, represents the finite field of 1, 2, ..., p-1, {0,1} * represents a set of bit strings of arbitrary length, U is a set of system properties, and two integers are randomly selected from the finite field

[0070] In S1, the specific steps for the trusted authority to generate the user attribute private key based on the attribute set of the data user are:

[0071] S11. The trusted authority AA executes the key generation algorithm KeyGenblind(PK,MSK,S)→(SK), inputs the system public key PK, the master key MSK and the user attribute set S, and the trusted authority AA uses the Schnorr protocol to blind each user attribute i, i∈S, calculates Q, L, and calculates the challenge σ i ,calculate Challenges i The response is calculated as:

[0072] Q = z·G;

[0073] L = m·G;

[0074] σ i =H2(G‖Q‖P‖j);

[0075]

[0076] In the formula, Q represents the blinded public key, L represents the calculated value bound to the signature and the message content, and σ i Indicates that the verifier sends a randomly generated challenge to the prover. It means that the prover generates a response based on his secret and challenge and sends it to the verifier. G is a point on the elliptic curve, and the data user DU randomly selects two integers in the finite field.

[0077] S12. Order The data user DU sends info to the smart contract. For each attribute i∈U, the trusted authority AA generates an attribute private key based on the blinded user attribute set and randomly selects an integer in the finite field. The calculated attribute private key SK is:

[0078]

[0079] In the formula, info is a defined four-tuple, and D1 and D2 are partial composition parameters of the attribute private key.

[0080] S2. The data owner formulates an access control strategy and assists the outsourced encryption service provider in partial encryption. The data user and the outsourced encryption service provider encrypt the keywords, data ciphertext storage address and symmetric key and upload the encrypted ciphertext to the blockchain for storage. The specific steps include:

[0081] S21, encryption service provider ESP partially encrypts to form an intermediate ciphertext;

[0082] S22. The data owner DO first encrypts the data plaintext based on the intermediate ciphertext, then encrypts the data ciphertext storage address, and finally encrypts the keyword set and the symmetric key.

[0083] In S21, the specific steps of partially encrypting the intermediate ciphertext by the outsourced encryption service provider are as follows:

[0084] S211, the encryption service provider ESP executes the EncryptESP(PK,T) algorithm, inputs the access control policy set by the user and converts it into an access structure tree T;

[0085] S212, the system public key PK starts from the root node of the access structure tree T, and randomly selects a node of order d for each non-leaf node x of the access structure tree from top to bottom. x A polynomial qx, randomly select a positive integer in the finite field As the node value of the root node R of the access structure tree T, set qR(0) = s, let Y be the attribute set of the leaf nodes in the access structure tree T, calculate and output the intermediate ciphertext as: CT ESP ={D x ,D' x}, where h x =H1(att(x));

[0086] In the formula, h x represents the result of the hash function H1. The input att(x) is the attribute of the leaf node. D x is the power term of the generator of group G1, D' x is the power term result of a hash function H1, qx (0) is the polynomial q corresponding to the leaf node x At the value of 0, d x =k x -1, k x Indicates the threshold of the node. For other non-leaf nodes x, set q x (0)=qparent(x)(index(x)), x∈Y.

[0087] In S22, the data owner DO first encrypts the data plaintext based on the intermediate ciphertext, then encrypts the data ciphertext storage address, and finally encrypts the keyword set and the symmetric key. The specific steps are:

[0088] S221. The data owner DO extracts the keyword set W from the data plaintext m, encrypts the data plaintext m with the symmetric key, generates data ciphertext = Enc(m, key) and uploads it to the IPFS interplanetary file system. The returned data ciphertext storage address is encrypted with the same symmetric key key to generate the storage address ciphertext CT addr =Enc(addr,key);

[0089] S222. The data owner DO defines a keyword set W = {ω} and a symmetric key, performs attribute-based encryption, and executes the encryption algorithm Encrypt DO (PK, CTESP, key, W) → CT, the data owner DO randomly selects a set of user attributes Calculate and get C0 = key·e(g,g) αs , C1=g βs The output symmetric key ciphertext is CT key ={C0,C1};

[0090] In the formula, C0 and C1 both represent the symmetric key partial ciphertext, and the two together constitute the symmetric key ciphertext. C0 is related to the symmetric key key, and C1 is related to the attribute set S.

[0091] S223, Randomly select a positive integer field Calculate keyword ciphertext Storage address ciphertext CT addr =Enc(addr,key), the final ciphertext CT = (CT key ,CT ω ,CT addr ,CT ESP ) and upload it to the blockchain for storage. The blockchain uses the index generation contract to create an index for the keyword ciphertext, where C2 and C3 both represent partial ciphertexts of the keyword ciphertext.

[0092] S3: The data user generates a search trapdoor and sends it to the blockchain. The search trapdoor contract is called to verify the user attributes. If the user attributes meet the access control policy, the relevant ciphertext corresponding to the keyword is returned to the data user.

[0093] In S3, the specific steps for data users to generate a search trap and call the smart contract in the blockchain to perform keyword matching and obtain ciphertext are as follows:

[0094] S31, data user DU executes trapdoor generation algorithm Trapdoor(PK,SK,S,τ)→T τ , input the system public key PK, attribute private key SK, data user DU attribute set S and search keyword τ, data user DU randomly selects an element Calculate search gate parameters y3=D1 v , generate search gate trap T τ ={y1,y2,y3,{B i =(D i ) v ,B' i =(D' i ) v} i∈S}, and sent to the blockchain for search verification;

[0095] S32. The smart contract in the blockchain is called to verify the legitimacy of the DU attribute first. The search trap smart contract in the blockchain is used to verify whether the DU attribute set meets the access control policy, and the attribute legitimacy is checked through the non-interactive Schnoor protocol. When the verification is successful, the ciphertext corresponding to the matching keyword is searched. The smart contract calculation formula is:

[0096] S33. When L′=L, the attribute verification is successful, and the relevant ciphertext set is returned and sent to DU, which then sends it to the outsourced decryption service provider. If the attribute verification fails, the entire algorithm process is terminated.

[0097] S4. The data user first assists the outsourced decryption service provider to decrypt the ciphertext part, then decrypts it locally to obtain the data storage address and symmetric key, downloads the data ciphertext from IPFS according to the storage address, and finally uses the symmetric key to decrypt the data ciphertext to obtain the data plaintext.

[0098] In S4, the data user first assists the outsourced decryption service provider to decrypt the ciphertext part. The specific steps are as follows:

[0099] S411, return the decryption result to DU, using the execution algorithm Decrypt DSP (PK,CT ESP ,T τ,S)→F Δ , and divide it into two cases:

[0100] S4111, x (x∈S) is a leaf node, then the calculated value F of the leaf node x used for decryption x for:

[0101]

[0102] Among them, when When F x =⊥;

[0103] S4112, x is a non-leaf node, let ρ x is a set of child nodes of any threshold, then for each child node π of x, ρ is used for decryption x The value F obtained by weighted accumulation of each non-leaf node x in the set π for:

[0104]

[0105] S412: Determine whether the attribute set of DU satisfies the access control policy. If it does, perform partial decryption to obtain the converted ciphertext F. Δ =e(g,g) uvs Return to DU.

[0106] In S4, DU obtains the converted ciphertext and then decrypts it locally to obtain the symmetric key. The specific steps of accessing IPFS and finally decrypting the data plaintext are as follows:

[0107] S421, using Decrypt DSP (PK,CT,F Δ ,SK,S)→m executes the algorithm to decrypt DU, which is calculated by the following formula:

[0108]

[0109] In the formula, θ represents the partial decryption result of the symmetric key ciphertext, and the partial decryption result is used to decrypt the data ciphertext key;

[0110] S422, DU decrypts the data ciphertext key Decrypted data ciphertext storage address addr = Dec(key, CT addr ), access IPFS from addr to get the data ciphertext CT m , and finally decrypted to obtain the data plaintext m = Dec(key, CT m ).

[0111] Therefore, the present invention provides an access control method based on outsourced computing and attribute-based searchable encryption on the blockchain, which solves the problems of high local computing overhead and low data sharing efficiency in existing attribute-based encryption. It can reduce the computing overhead of local users while improving data sharing efficiency and security, effectively reducing the computing burden of encryption and decryption for local users, and significantly improving data sharing efficiency and security.

[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that they can still modify or replace the technical solution of the present invention with equivalents, and these modifications or equivalent replacements cannot cause the modified technical solution to deviate from the spirit and scope of the technical solution of the present invention.

Claims

1. An access control method based on outsourced computing and attribute-based searchable encryption on blockchain, characterized in that: The steps of this method are as follows: S1. The trusted authority AA initializes and generates the system public key PK and the master key MSK, and generates the user attribute private key according to the attribute set of the data user; S2. The data owner formulates an access control strategy and assists the outsourced encryption service provider in partial encryption. The data user and the outsourced encryption service provider encrypt the keywords, data ciphertext storage address and symmetric key and upload the encrypted ciphertext to the blockchain for storage; S3: The data user generates a search trapdoor and sends it to the blockchain. The search trapdoor contract is called to verify the user attributes. If the user attributes meet the access control policy, the relevant ciphertext corresponding to the keyword is returned to the data user. S4. The data user first assists the outsourced decryption service provider to decrypt the ciphertext part, then decrypts it locally to obtain the data storage address and symmetric key, downloads the data ciphertext from IPFS according to the storage address, and finally uses the symmetric key to decrypt the data ciphertext to obtain the data plaintext.

2. According to claim 1, an access control method based on outsourced computing and attribute-based searchable encryption on blockchain is characterized in that: In S1, the specific steps for the trusted authority to initialize and generate the system public key PK and the master key MSK are as follows: The trusted authority AA executes the initialization algorithm Setup(1 λ )→(PK,MSK), input the security parameter λ, generate a multiplication cyclic group G1 and G with a prime order of p T , given a bilinear mapping pair e:G1×G1→G T , define two random anti-collision Hash functions, for each attribute i∈U, randomly select parameters t1, t2, t3, and calculate e(g, g) respectively α , g β , generate the system public key PK and master key MSK: MSK={t1,t2,t3,α,β}; In the formula, e(g,g) α and g β All of them are mathematical formulas about double mapping pairs in cryptography, and all of them are calculation results. They are components of the system public key PK. g is the generator of G1. The mapping relationship is represents the finite field of 1, 2, ..., p-1, {0,1} * represents a set of bit strings of arbitrary length, U is a set of system properties, and two integers are randomly selected from the finite field 3. According to claim 2, an access control method based on outsourced computing and attribute-based searchable encryption on blockchain is characterized in that: In S1, the specific steps for the trusted authority to generate the user attribute private key based on the attribute set of the data user are: S11. The trusted authority AA executes the key generation algorithm KeyGenblind(PK,MSK,S)→(SK), inputs the system public key PK, the master key MSK and the user attribute set S, and the trusted authority AA uses the Schnorr protocol to blind each user attribute i, i∈S, calculates Q, L, and calculates the challenge σ i ,calculate Challenges i The response is calculated as: Q = z·G; L = m·G; s i =H2(G∥Q∥P∥j); In the formula, Q represents the blinded public key, L represents the calculated value bound to the signature and the message content, and σ i Indicates that the verifier sends a randomly generated challenge to the prover. It means that the prover generates a response based on his secret and challenge and sends it to the verifier. G is a point on the elliptic curve, and the data user DU randomly selects two integers in the finite field. S12. Order The data user DU sends info to the smart contract. For each attribute i∈U, the trusted authority AA generates an attribute private key based on the blinded user attribute set and randomly selects an integer in the finite field. The calculated attribute private key SK is: In the formula, info is a defined four-tuple, and D1 and D2 are partial composition parameters of the attribute private key.

4. According to claim 1, an access control method based on outsourced computing and attribute-based searchable encryption on blockchain is characterized in that: In S2, the data user and the outsourced encryption service provider encrypt the keywords, data ciphertext storage address and symmetric key and upload the encrypted ciphertext to the blockchain for storage. The specific steps include: S21, encryption service provider ESP partially encrypts to form an intermediate ciphertext; S22. The data owner DO first encrypts the data plaintext based on the intermediate ciphertext, then encrypts the data ciphertext storage address, and finally encrypts the keyword set and the symmetric key.

5. According to claim 4, an access control method based on outsourced computing and attribute-based searchable encryption on blockchain is characterized in that: In S21, the specific steps of partially encrypting the intermediate ciphertext by the outsourced encryption service provider are as follows: S211, the encryption service provider ESP executes the EncryptESP(PK,T) algorithm, inputs the access control policy set by the user and converts it into an access structure tree T; S212, the system public key PK starts from the root node of the access structure tree T, and randomly selects a node of order d for each non-leaf node x of the access structure tree from top to bottom. x The polynomial q x , randomly select a positive integer in the finite field As the node value of the root node R of the access structure tree T, set qR(0) = s, let Y be the attribute set of the leaf nodes in the access structure tree T, calculate and output the intermediate ciphertext as: CT ESP ={D x ,D' x }, where h x =H1(att(x)); In the formula, h x represents the result of the hash function H1. The input att(x) is the attribute of the leaf node. D x is the power term of the generator of group G1, D' x is the power term result of a hash function H1, q x (0) is the polynomial q corresponding to the leaf node x At the value of 0, d x =k x -1, k x Indicates the threshold of the node. For other non-leaf nodes x, set q x (0)=qparent(x)(index(x)), x∈Y.

6. The access control method based on outsourced computing and attribute-based searchable encryption on blockchain according to claim 4 is characterized in that: In S22, the data owner DO first encrypts the data plaintext based on the intermediate ciphertext, then encrypts the data ciphertext storage address, and finally encrypts the keyword set and the symmetric key. The specific steps are: S221. The data owner DO extracts the keyword set W from the data plaintext m, encrypts the data plaintext m with the symmetric key, generates data ciphertext = Enc(m, key) and uploads it to the IPFS interplanetary file system. The returned data ciphertext storage address is encrypted with the same symmetric key key to generate the storage address ciphertext CT addr =Enc(addr,key); S222. The data owner DO defines a keyword set W = {ω} and a symmetric key, performs attribute-based encryption, and executes the encryption algorithm Encrypt DO (PK, CT ESP , key, W)→CT, the data owner DO randomly selects a set of user attributes Calculate and get C0 = key·e(g,g) αs , C1=g βs The output symmetric key ciphertext is CT key ={C0,C1}; In the formula, C0 and C1 both represent the symmetric key partial ciphertext, and the two together constitute the symmetric key ciphertext. C0 is related to the symmetric key key, and C1 is related to the attribute set S. S223, Randomly select a positive integer field Calculate keyword ciphertext Storage address ciphertext CT addr =Enc(addr,key), the final ciphertext CT = (CT key ,CT ω ,CT addr ,CT ESP ) and upload it to the blockchain for storage. The blockchain uses the index generation contract to create an index for the keyword ciphertext, where C2 and C3 both represent partial ciphertexts of the keyword ciphertext.

7. The access control method based on outsourced computing and attribute-based searchable encryption on blockchain according to claim 1 is characterized in that: In S3, the specific steps for data users to generate a search trap and call the smart contract in the blockchain to perform keyword matching and obtain ciphertext are as follows: S31, data user DU executes trapdoor generation algorithm Trapdoor(PK,SK,S,τ)→T τ , input the system public key PK, attribute private key SK, data user DU attribute set S and search keyword τ, data user DU randomly selects an element Calculate search gate parameters Generate search gate T τ ={y1,y2,y3,{B i =(D i ) v ,B' i =(D' i ) v } i∈S } and sent to the blockchain for search verification; S32. When calling the smart contract in the blockchain, the legitimacy of the DU attribute is first verified. When the verification is successful, the ciphertext corresponding to the matching keyword is searched. The calculation formula of the smart contract is: S33. When L′=L, the attribute verification is successful, and the relevant ciphertext set is returned and sent to DU, which then sends it to the outsourced decryption service provider. If the attribute verification fails, the entire algorithm process is terminated.

8. The access control method based on outsourced computing and attribute-based searchable encryption on blockchain according to claim 7 is characterized in that: The search trapdoor smart contract in the blockchain is used to verify whether the DU attribute set satisfies the access control policy, and the legitimacy of the attributes is checked through the non-interactive Schnoor protocol.

9. The access control method based on outsourced computing and attribute-based searchable encryption on blockchain according to claim 1 is characterized in that: In S4, the data user first assists the outsourced decryption service provider to decrypt the ciphertext part. The specific steps are as follows: S411, return the decryption result to DU, using the execution algorithm Decrypt DSP (PK,CT ESP ,T τ ,S)→F Δ , and divide it into two cases: S4111, x (x∈S) is a leaf node, then the calculated value F of the leaf node x used for decryption x for: Among them, when When F x =⊥; S4112, x is a non-leaf node, let ρ x is a set of child nodes of any threshold, then for each child node π of x, ρ is used for decryption x The value F obtained by weighted accumulation of each non-leaf node x in the set π for: S412: Determine whether the attribute set of DU satisfies the access control policy. If it does, perform partial decryption to obtain the converted ciphertext F. Δ =e(g,g) uvs Return to DU.

10. The access control method based on outsourced computing and attribute-based searchable encryption on blockchain according to claim 1 is characterized in that: In S4, DU obtains the converted ciphertext and then decrypts it locally to obtain the symmetric key. The specific steps of accessing IPFS and finally decrypting the data plaintext are as follows: S421, using Decrypt DSP (PK,CT,F Δ ,SK,S)→m executes the algorithm to decrypt DU, which is calculated by the following formula: In the formula, θ represents the partial decryption result of the symmetric key ciphertext, and the partial decryption result is used to decrypt the data ciphertext key; S422, DU decrypts the data ciphertext key Decrypted data ciphertext storage address addr = Dec(key, CT addr ), access IPFS from addr to get the data ciphertext CT m , and finally decrypted to obtain the data plaintext m = Dec(key, CT m ).

Citation Information

Patent Citations

  • Attribute-based searchable encrypted block chain medical data sharing method

    CN112765650A

  • Data search fine-grained access control method and system based on block chain

    CN114826703A

  • Attribute-based searchable encrypted data sharing method based on block chain

    CN115834200A

  • Data security access control method based on block chain

    CN116827616A

  • Attribute set-based searchable encryption method with forward and backward privacy

    CN117596085A

Cited By

  • Encryption state knowledge graph method based on attribute-based searchable encryption

    CN121030791A