Updatable attribute condition proxy re-encryption method with forward security and quantum attack resistance
Through the updating attribute conditional proxy re-encryption method based on LWE problems, the problem of inflexibility of delegated control in the prior art and inability to resist quantum attacks is solved, and the fine-grained control of forward security and ciphertext conversion is realized, and the security and flexibility of the data sharing system are enhanced.
Patent Information
- Application Number
- CN202510313508.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-17
AI Technical Summary
The existing proxy recryption scheme lacks flexibility in delegated control, is unable to resist quantum attacks, and is not forward-looking, resulting in key leakage that may cause serious consequences.
The updateable attribute conditional proxy re-encryption method based on the difficult problem on the grid - LWE problem is adopted to achieve forward security through the asynchronous key update mechanism, and to achieve fine-grained control of ciphertext conversion through the control structure.
It realizes fine-grained control of building a conditional proxy re-encryption method under given conditions, enhances the security of the data sharing system, improves the flexibility and robustness of the application, and is suitable for cloud storage and distributed file systems.
Smart Images

Figure CN119995876A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cyberspace security technology, and in particular to an updateable attribute conditional proxy re-encryption method with forward security and resistance to quantum attacks. Background Art
[0002] Data security has become one of the key challenges of data sharing. Traditional data sharing models often find it difficult to strike a balance between data openness and privacy protection, thus limiting the widespread application of data sharing.
[0003] Proxy Re-Encryption (PRE) technology is considered an effective method for secure data sharing because it can achieve ciphertext conversion without decryption. Proxy re-encryption is an extension of the public key encryption system. Through a semi-honest proxy, the ciphertext encrypted by the user Alice's public key is converted into ciphertext that can be decrypted by Bob's private key. The entire conversion process does not require decryption, and the proxy cannot obtain any plaintext information, making it possible to achieve data sharing while ensuring data privacy.
[0004] However, in the existing basic proxy re-encryption scheme, a flexible delegation mechanism is still missing. For example, once the proxy obtains the re-encryption key, it can convert all the ciphertexts of the delegator into ciphertexts that the trustee can decrypt, and some of these ciphertexts are highly confidential and not suitable for sharing. This requires that the proxy must be fully trusted, and this fully trusted model becomes impractical in complex application scenarios.
[0005] In order to solve the problem of delegated control, the prior art associates ciphertext and re-encryption key with specific conditions through conditional proxy re-encryption to achieve control over the re-encryption process. The ciphertext can only be correctly converted when the ciphertext condition matches the re-encryption key condition. However, conditional proxy re-encryption also leaves an unresolved challenge: how to construct a conditional proxy re-encryption method under given conditions. To address this challenge, the prior art proposes two types of conditional proxy re-encryption schemes. The first is fuzzy conditional proxy re-encryption, which allows ciphertext conversion when the re-encryption key is not completely consistent with the conditions in the ciphertext. The second is attribute-based conditional proxy re-encryption, which provides more sophisticated access control for the entrusting party by combining attributes and conditional control mechanisms. However, the security of the above-mentioned proxy re-encryption schemes is based on traditional number theory problems, so they cannot resist the attack of quantum computers. And they do not have the forward security of the trustee. Once the key is leaked, it may cause serious consequences. Summary of the invention
[0006] In view of the shortcomings of the prior art, the present invention provides an updateable attribute conditional proxy re-encryption method with forward security and resistance to quantum attacks. The present invention instantiates the updateable attribute conditional proxy re-encryption based on the difficult problem on the lattice - the LWE problem, and obtains an updateable attribute conditional proxy re-encryption method that can resist quantum attacks and achieve fine-grained transformation of re-encrypted ciphertext. The present invention not only enhances the security of data sharing, but also improves the flexibility and robustness of applications.
[0007] The technical solution of the present invention is a forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method, comprising the following steps:
[0008] S1), authorize the manager to generate and publish public parameters;
[0009] S2), the entrusting party and the trustee generate a public and private key pair of the entrusting party and the trustee according to the public parameters;
[0010] S3), the client encrypts the plaintext according to the public parameters and the client's public key and attribute vector, generates encrypted ciphertext, and sends the encrypted ciphertext to the cloud server;
[0011] S4), the entrusting party generates an updated public key for the trustee based on the trustee's public key and a ciphertext used to update the trustee's private key;
[0012] S5), the entrusting party generates a re-encryption key associated with the control policy based on the public parameters, the entrusting party's public-private key pair, and the trustee's updated public key and the control policy;
[0013] S6), the cloud server re-encrypts the encrypted ciphertext according to the re-encryption key, generates a re-encrypted ciphertext and sends it to the trustee;
[0014] S7), the trustee generates an updated private key based on the private key and the ciphertext used to update the private key;
[0015] S8), the trustee uses the public parameters, the private key of the entrusting party, and the updated private key sk′ α Decrypts encrypted ciphertext or re-encrypted ciphertext.
[0016] Preferably, in step S1), the authorized manager inputs the security parameter n through the Setup algorithm, and then in a random matrix of n×kn dimensions, each element constituting the matrix belongs to the integer group modulo q Randomly and uniformly extract l matrices B1,…,B from the distribution l , the output is the system's public parameter pp=(B1,…,B l ,χ); where χ is the error sampling Gaussian distribution.
[0017] Preferably, in step S2), the entrusting party and the trustee generate the public and private key pairs of the entrusting party and the trustee through the KeyGen algorithm, which specifically includes the following steps:
[0018] S21), through the public parameter pp and the identity of the client α, and run the trapdoor generation algorithm TrapGen to generate the matrix A α and its trapdoor Right now:
[0019]
[0020] S22) Randomly uniformly extract a matrix from the distribution Then use the sampling algorithm SamplePre and pass the matrix A α , Trapdoor and Matrix-D α , Gaussian parameter σ generates the sampling matrix R α ; Get the public and private key pair of the client (pk α ,sk α ), where the public key pk α =(A α ,D α ); Private key
[0021] S23), repeat steps S21) and S22) to obtain the public key pk of the trustee β =(A β ,D β ); Private key
[0022] Preferably, in step S3), the client uses the Encrypt algorithm to encrypt the plaintext according to the public parameters and the client's public key and attribute vector to generate encrypted ciphertext, which specifically includes the following steps:
[0023] S31), random uniform extraction
[0024] Among them, s represents the An unknown n-dimensional secret vector randomly drawn from the distribution; $ represents random uniform extraction, e in and e out Respectively represent an n-dimensional random noise vector, each element of which is independently generated according to a Gaussian distribution, and χ represents the error sampling Gaussian distribution;
[0025] S32), calculate the encrypted ciphertext c α,x The first part of α,x The included elements cin 、c out ,Right now:
[0026] ct α,x =(c in ,c out )
[0027]
[0028] In the formula, the matrix A α With D α The public key pk of the client α The two components of ; μ represents the plaintext message; q represents the modulus of the lattice;
[0029] S33) Calculate the second part of the encrypted ciphertext cc α,x ; When the attribute vector x is empty, otherwise,
[0030] In the formula, represents the empty set; cc α,x Represents the encrypted ciphertext c α,x The second part of i Represents a matrix vector The result of the operation; x i represents the components of the l-dimensional attribute vector x; B i Represents the matrix contained in the common parameters; Represents an m×kn dimensional matrix, and the value of each position in the matrix is either 1 or -1; Represents a vector space with lm dimensions, where each component of the vector belonging to the distribution is from the finite field Each component of the vector belongs to l represents the maximum value of i; m represents the dimension of the grid; G represents the Gadget matrix; for integers q≥2, n≥1, as well as A relatively special Gadget matrix G can be constructed; the detailed structure is as follows:
[0031]
[0032] In the formula, I n represents an n-row identity matrix; g T Represents the first part of the re-encryption key; It means to perform Kronecker product operation on the two matrices connected;
[0033] S34) Get the encrypted ciphertext c α,x =(ct α,x ,ccα,x );
[0034] Preferably, in step S4), the entrusting party uses the Update-pk algorithm to generate an updated public key and a ciphertext for updating the private key of the trustee according to the public key of the trustee, which specifically includes the following steps:
[0035] S41), random uniform selection matrix
[0036] S42), the matrix R' β Each element of is converted into binary, and then the bits at each position in the matrix are encrypted using parallel computing or multi-threading methods, and then reassembled into a matrix, that is:
[0037] Encrypt(pp,pk β ,μ∈{0,1} m ,R′ β )→up;
[0038] Among them, pk β is the public key of the trustee; Encrypt represents the encryption algorithm; pp represents the public parameter; μ represents the plaintext message; m represents the rank of the lattice; up represents the ciphertext used to update the private key of the trustee;
[0039] Generate a ciphertext up for updating the trustee's private key according to the above, which is used for updating the trustee's private key;
[0040] S43) According to Calculate the trustee's updated public key
[0041] In the formula, A β Indicates the original public key of the trustee and the first part of the updated public key; D β The second part of the original public key of the trustee; The second part of the trustee's updated public key, R′ β Indicated in Distribution Random Uniform Selection Matrix.
[0042] Preferably, in step S5), the client generates a re-encryption key associated with the control strategy using the ReKeyGen algorithm, which specifically includes the following steps:
[0043] S51), according to the control strategy f and the common parameter pp = (B1, ..., B l ,χ)Calculate B f :
[0044] B f =Evalpk (f,{B i} i∈[l] );
[0045] Among them, f is the control strategy; B i is the matrix containing the common parameters; B f Represents Eval pk The output of the algorithm is:
[0046] Key Homomorphic Algorithm Given positive integers n,q,l,m=[6nlogq], Any control strategy f,x={x1,...,x l}∈{0,1} l If satisfied in, e i ←χ m , then there will be the following three deterministic algorithms; Eval ct 、Eval pk and Eval sim ;
[0047] ①Eval pk (f,{B i} i∈[l] ) → B f :Eval pk The input of the algorithm is and a control strategy f, the output matrix B f ;
[0048] ②Eval ct (f,{x i ,B i ,c i} i∈[e] )→c f :Eval ct The input of the algorithm is the control strategy f, x i ∈{0,1}, c i =(x i G+B i ) T s+e i ; Where G is the Gadget matrix; the algorithm outputs c f ; meet c f =(f(x)G+B f ) T s+e f ;in, s means from An unknown n-dimensional secret vector randomly drawn from the distribution; B represents bounded; m represents the rank of the grid; x represents the attribute vector; T represents the transposition operation;
[0049] ③ The input of the algorithm is the control strategy f, S i ∈{-1,1} m×m , and matrix A; the algorithm outputs matrix S f , and satisfies AS f -f(x)G=B f Among them, B f It's Eval pk The output of the algorithm;
[0050] S52), according to the public key pk of the client α =(A α ,D α ) and private key Calculate the matrix A α |B f Trapdoor
[0051]
[0052] In the formula, Represents the matrix A α |B f The trapdoor of ExtendRight is:
[0053] ExtendRight(A,T A ,U): Input random matrix Trapdoor of lattice Λ(A) and any matrix Output Format The corresponding trapdoor T A|U ; and meet
[0054] S53) According to Calculate the matrix (A α |B f ) α,f :
[0055]
[0056] In the formula, R α,f Represents the matrix (A α |B f ), σ is the Gaussian parameter; SamplePre represents the original image sampling algorithm, which is as follows:
[0057] The input of the original image sampling SamplePre algorithm is the matrix Trapdoor vector And Gaussian parameters From approximation Extract a vector from the discrete Gaussian distribution Satisfy Ae=u;
[0058] S54), according to the updated public key of the trustee Calculate the first part of the re-encryption key g T :
[0059]
[0060] In the formula, g T Re-encryption key rk α,f→β The first part of represents the transformed rank vector of vector r1, where Respectively represent two random m-dimensional vectors drawn from the error sampling Gaussian distribution χ; that is:
[0061] S55), calculate the re-encryption key rk α,f→β The second part of Q:
[0062]
[0063] Where Q represents the re-encryption key rk α,f→β The second part of ; E1, E2, E3 represent three 2km×n, 2km×m, 2km×m matrices randomly drawn from the error sampling Gaussian distribution, that is, 0 m×m Represents a zero matrix, that is, every position of an m×m matrix is 0; I m×m They represent the unit matrix, that is, each position of the positive diagonal of the m×m matrix is 0; P2 represents the second one of the vector decomposition functions, as follows:
[0064] Vector decomposition function: Assume that BD(v) and P2(x) represent deterministic functions that map vectors to higher dimensions; let v i ∈{0,1} n ,vector The BD(v) function takes a vector v as input and outputs a higher-dimensional vector. Similarly, the P2(x) function takes as input a vector x∈ Output higher dimensional vectors BD(v) and P2(x) satisfy
[0065] S56), obtain the re-encryption key rk associated with the control policy f α,f→β :
[0066] rk α,f→β = {g T ,Q}.
[0067] Preferably, in step S6), the cloud server uses the ReEncrypt algorithm and re-encrypts the encrypted ciphertext according to the re-encryption key, which specifically includes the following steps:
[0068] S61), when the control strategy f≠0 or When , the output terminal symbol ⊥; otherwise, ct α,x =(c in ,c out ),
[0069] S62), randomly select a small integer a∈χ, calculate c f and Right now:
[0070] c f ←Eval ct (f,{(x i ,B i ,c i )} i∈[l] )
[0071]
[0072] In the formula, c f To run Eval ct The results obtained by the algorithm, Represent the re-encrypted ciphertext c β The first part of β The transformation rank of; f is the control strategy; x i represents the component of the attribute vector x; B i is a public parameter; c i is the ciphertext c α,x The second part of cc α,x Elements of g T Re-encryption key rk α,f→β The first part of ; BD represents one of the vector decomposition functions; Represents the matrix c in and c f cascade, that is, [c in |c f ]; Q represents the re-encryption key rk α,f→β The second part of
[0073] S63), output the re-encrypted ciphertext c β ,Right now:
[0074]
[0075] In the formula, ct β ,cc β Represent the re-encrypted ciphertext c β The first and second parts.
[0076] Preferably, in step S7), the trustee uses the Update-sk algorithm to generate an updated private key according to the private key and the ciphertext used to update the private key, which specifically includes the following steps:
[0077] S71), decrypting each element of the ciphertext up used to update the trustee's private key using parallel computing or multi-threading method;
[0078] S72), convert the decrypted bit string into distribution, and recombined to obtain the matrix R′ β ;
[0079] S73), output the updated private key sk′ β ,Right now:
[0080]
[0081] In the formula, in the formula, represents the trapdoor of the trustee β; Indicates the second part of the trustee's updated public key.
[0082] The trustee uses the Decrypt algorithm and updates the private key sk′ based on the public parameters, the private key of the entrusting party, and the updated private key α Decrypting encrypted ciphertext or re-encrypted ciphertext includes the following steps:
[0083] S81), according to the public parameter pp=(B1,…,B l ,χ), the private key of the client and the public key pk of the client α The original ciphertext c α,x =(ct α,x ,cc α,x )calculate
[0084] S82), according to the public parameter pp=(B1,…,B l ,χ), updated trustee private key and in the public key pk′ β The re-encrypted ciphertext calculate
[0085] The beneficial effects of the present invention are:
[0086] 1. The present invention proposes a technical solution for proxy re-encryption with renewable attribute conditions. Based on the key asynchronous update mechanism, the present invention allows the public and private keys of the trustee to be rotated regularly to achieve forward security. At the same time, the fine-grained control of ciphertext conversion is achieved through the control structure.
[0087] 2. The present invention uses the LWE problem to design a solution that can resist quantum attacks and realizes fine-grained conversion of re-encrypted ciphertext; this enhances the security of the data sharing system and improves the flexibility and robustness of the application;
[0088] 3. The present invention has significant advantages in data privacy and security and is suitable for cloud storage and distributed file systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0089] Figure 1 It is a schematic diagram of the process of the present invention;
[0090] Figure 2 It is a framework diagram of the method of the present invention;
[0091] Figure 3 is a running time test chart of eight algorithms included in UAB-CPRE when n=16 in an embodiment of the present invention;
[0092] Figure 4 It is a running time test chart of eight algorithms included in UAB-CPRE when n=32 in an embodiment of the present invention;
[0093] Figure 5 1 is a running time test chart of eight algorithms included in UAB-CPRE when n=64 in an embodiment of the present invention;
[0094] Figure 6 It is a running time diagram of the TrapGen algorithm under different grid ranks and different parameters q in an embodiment of the present invention;
[0095] Figure 7 1 is a running time diagram of the SamplePre algorithm under different grid ranks and different parameters q in an embodiment of the present invention. DETAILED DESCRIPTION
[0096] The specific implementation of the present invention will be further described below in conjunction with the accompanying drawings:
[0097] like Figure 1 and 2As shown, this embodiment provides an updateable attribute conditional proxy re-encryption method with forward security and resistance to quantum attacks. This embodiment involves an authorized manager, a delegator, a trustee, and a cloud server.
[0098] In addition, this embodiment describes the parameters involved:
[0099] (n,q,m,χ) are the parameters of the grid, where n is the rank of the grid, q is the modulus, m is the dimension of the grid, satisfying q = poly(n), and q / 4 ≥ B·(m+1) O(d) , χ is a B-Bounded distribution, where
[0100] l is the number of attributes supported by the scheme;
[0101] σ is a Gaussian parameter, satisfying ω represents the lower bound, and its value is greater than the value in the brackets;
[0102] value
[0103] The encryption method of this embodiment specifically includes the following steps:
[0104] S1), the authorized manager generates the public parameter pp through the Setup algorithm and makes the public parameter pp public. In the initialization phase, the parameter selection is as follows:
[0105] (n,q,m,X) are the parameters of the grid, where n is the rank of the grid, q is the modulus, m is the dimension of the grid, satisfying q = poly(n), and q / 4 ≥ B·(m+1) O(d) , χ is a B-Bounded distribution, where
[0106] l is the number of attributes supported by the scheme;
[0107] σ is a Gaussian parameter, satisfying ω represents the lower bound, and its value is greater than the value in the brackets.
[0108] value
[0109] The specific steps include:
[0110] S11), the authorized manager inputs the security parameter n through the Setup algorithm;
[0111] S12), random uniform extraction
[0112] S13), calculate the common parameters of the system pp = (B1, ..., B l ,χ), where χ is the error sampling Gaussian distribution.
[0113] S2) The entrusting party and the trustee generate the public and private key pairs of the entrusting party and the trustee through the KeyGen algorithm and according to the public parameters; the specific steps include:
[0114] S21), through the public parameter pp and the identity of the client α, and run the trapdoor generation algorithm Generate Matrix A α and its trapdoor
[0115] S22) Randomly uniformly extract a matrix from the distribution Then use the sampling algorithm SamplePre and pass the matrix A α , Trapdoor and Matrix-D α , Gaussian parameter σ generates the sampling matrix R α ; Get the public and private key pair of the client (pk α ,sk α ), where the public key pk α =(A α ,D α ); Private key
[0116] Similarly, according to steps S21) and S22), the public key pk corresponding to the trustee with identity β is obtained. β =(A β ,D β ) and private key sk β =(T Aβ ,R β ).
[0117] S3) The client uses the Encrypt algorithm to encrypt the plaintext according to the public parameters, the client's public key and the attribute vector, generates encrypted ciphertext, and sends the encrypted ciphertext to the cloud server; specifically, the steps include:
[0118] S31), random uniform extraction
[0119] Among them, s represents the An unknown n-dimensional secret vector randomly drawn from the distribution; $ represents random uniform extraction, e in and e outRespectively represent an n-dimensional random noise vector, each element of which is independently generated according to a Gaussian distribution, and χ represents the error sampling Gaussian distribution;
[0120] S32), calculate the encrypted ciphertext c α,x The first part of α,x The included elements c in 、c out ,Right now:
[0121] ct α,x =(c in ,c ouy )
[0122]
[0123] In the formula, the matrix A α With D α The public key pk of the client α The two components of ; μ represents the plaintext message; q represents the modulus of the lattice;
[0124] S33) Calculate the second part of the encrypted ciphertext cc α,x ;
[0125] When the attribute vector x is empty, otherwise,
[0126] In the formula, represents the empty set; cc α,x Represents the encrypted ciphertext c α,x The second part of i Represents a matrix vector The result of the operation; x i represents the components of the l-dimensional attribute vector x; B i Represents the matrix contained in the common parameters; Represents an m×kn dimensional matrix, and the value of each position in the matrix is 1 or -1; Represents a vector space with lm dimensions, where each component of the vector belonging to the distribution is from the finite field Each component of the vector belongs to l represents the maximum value of i; m represents the dimension of the grid; G represents the Gadget matrix. For integers q≥2, n≥1, as well as A relatively special Gadget matrix G can be constructed, the detailed structure is as follows:
[0127]
[0128] Among them, I n represents an n-row identity matrix; g T Represents the first part of the re-encryption key; It means to perform Kronecker product operation on the two matrices connected;
[0129] S34) Get the encrypted ciphertext c α,x =(ct α,x ,cc α,x );
[0130] S4) The entrusting party uses the Update-pk algorithm to generate an updated public key and a ciphertext for updating the private key of the trustee according to the public key of the trustee, which specifically includes the following steps:
[0131] S41), random uniform selection matrix
[0132] S42), the matrix R' β Each element of is converted into binary, and then the bits at each position in the matrix are encrypted using parallel computing or multi-threading methods, and then reassembled into a matrix, that is:
[0133] Encrypt(pp,pk β ,μ∈{0,1} m ,R′ β )→up;
[0134] Among them, pk β The public key of the trustee;
[0135] Generate a ciphertext up for updating the trustee's private key according to the above, which is used for updating the trustee's private key;
[0136] S43) According to Calculate the trustee's updated public key
[0137] In the formula, A β Indicates the original public key of the trustee and the first part of the updated public key; D β The second part of the original public key of the trustee; The second part of the trustee's updated public key, R′ β Indicated in Distribution Random Uniform Selection Matrix.
[0138] S5), the entrusting party uses the ReKeyGen algorithm and generates a re-encryption key associated with the control policy based on the public parameters, the entrusting party's public and private key pair, and the trustee's updated public key and control policy; specifically, the steps include:
[0139] S51), according to the control strategy f and the common parameter pp = (B1, ..., B l ,χ)Calculate B f :
[0140] B f =Eval pk (f,{B i} i∈[l] );
[0141] Among them, f is the control strategy; B i is the matrix containing the common parameters; B f Represents Eval pk The output of the algorithm is as follows:
[0142] Key Homomorphic Algorithm Given positive integers n,q,l,m=[6nlogq], Any control strategy f,x={x1,...,x l}∈{0,1} l If satisfied in e i ←χ m ; Then there will be the following three deterministic algorithms; Eval ct 、Eval pk and Eval sim ;
[0143] ①Eval pk (f,{B i} i∈[l] ) → B f :Eval pk Algorithm Input and a control strategy f, the output matrix B f ;
[0144] ②Eval ct (f,{x i ,B i ,c i} i∈[l] )→c f :Eval ct The algorithm inputs f, x i ∈{0,1},c i =(x i G+B i ) T s+e i , where G is the Gadget matrix and the algorithm outputs c f , satisfying c f =(f(x)G+Bf ) T s+e f ,in,
[0145] ③ Algorithm input control strategy f, S i ∈{-1,1} m×m , and matrix A; the algorithm outputs matrix S f , and satisfies AS f -f(x)G=B d ; Among them B f It's Eval pf Output.
[0146] S52), according to the public key pk of the client α =(A α ,D α ) and private key calculate
[0147]
[0148] In the formula, Represents the matrix A α |B f The trapdoor of ExtendRight is as follows:
[0149] ExtendRight(A,T A ,U): Input random matrix Trapdoor of lattice Λ(A) and any matrix Output Format The corresponding trapdoor T A|U , and satisfies
[0150] S53) According to Calculate R α,f :
[0151]
[0152] In the formula, R α,f Represents the matrix (A α |B f ), σ is the Gaussian parameter; SamplePre represents the original image sampling algorithm, the details are as follows:
[0153] The input of the original image sampling SamplePre algorithm is the matrix Trapdoor vector And Gaussian parameters From approximation Extract a vector from the discrete Gaussian distribution Satisfy Ae=u;
[0154] S54), according to the updated public key of the trustee Calculate the first part of the re-encryption key g T :
[0155]
[0156] In the formula, g T Re-encryption key rk α,f→β The first part of represents the rank of vector r1, where Respectively represent two random m-dimensional vectors drawn from the error sampling Gaussian fraction χ, that is:
[0157] S55), calculate the re-encryption key rk α,f→β The second part of Q;
[0158]
[0159] Where Q represents the re-encryption key rk α,f→β The second part; E1, E2, E3 represent three 2km×n, 2km×m, 2km×m matrices randomly drawn from the error distribution, that is, 0 m×m Represents a zero matrix, that is, every position of an m×m matrix is 0; I m×m They represent the identity matrix, that is, each position of the positive diagonal of the m×m matrix is 0; P2 represents the second one of the vector decomposition functions, as shown below;
[0160] Vector decomposition function: Assume that BD(v) and P2(x) represent deterministic functions that map vectors to higher dimensions; let v i ∈{0,1} n ,vector The BD(v) function takes a vector v as input and outputs a higher-dimensional vector.
[0161] Similarly, the P2(x) function takes the vector Output higher dimensional vectors BD(v) and P2(x) satisfy
[0162] S56), obtain the re-encryption key rk associated with the control policy f α,f→β :
[0163] rk α,f→β = {g T ,Q}.
[0164] S6), the cloud server uses the ReEncrypt algorithm and re-encrypts the encrypted ciphertext according to the re-encryption key, generates a re-encrypted ciphertext and sends it to the trustee; specifically includes the following steps:
[0165] S61), when the control strategy f≠0 or When , the output terminal symbol ⊥; otherwise, ct α,x =(c in ,c out ),
[0166] S62), randomly select a small integer a∈χ, calculate c f and Right now:
[0167] c f ←Eval ct (f,{(x i ,B i ,c i )} i∈[l] )
[0168]
[0169] In the formula, c f To run Eval ct The results obtained by the algorithm, Represent the re-encrypted ciphertext c β The first part of β The transformation rank of; f is the control strategy; x i represents the component of the attribute vector x; B i is a public parameter; c i is the ciphertext c α,x The second part of cc α,x Elements of g T Re-encryption key rk α,f→β The first part of ; BD represents one of the vector decomposition functions; Represents the matrix c in and c f Cascade, that is, [c in |c f ]; Q represents the re-encryption key rk α,f→β The second part of
[0170] S63), output, that is:
[0171]
[0172] In the formula, ct β ,cc β Represent the re-encrypted ciphertext c β The first and second parts.
[0173] S7), the trustee uses the Update algorithm to generate an updated private key based on the private key and the ciphertext used to update the private key, specifically including the following steps:
[0174] S71), decrypting each element of the ciphertext up used to update the trustee's private key using parallel computing or multi-threading method;
[0175] S72), convert the decrypted bit string into distribution, and recombined to obtain the matrix R′ β ;
[0176] S73), output the updated private key sk′ β ,Right now:
[0177]
[0178] In the formula, in the formula, represents the trapdoor of the trustee β; Indicates the second part of the trustee's updated public key.
[0179] S8), the trustee uses the Decrypt algorithm and updates the private key sk′ according to the public parameters, the private key of the entrusting party, and the updated private key sk′ α Decrypting encrypted ciphertext or re-encrypted ciphertext includes the following steps:
[0180] S81), decrypting the encrypted ciphertext;
[0181] According to the common parameters pp=(B1,…,B l ,χ), the original private key of the client and the public key pk of the client a The original ciphertext calculate For j∈[m], when μ j =1; otherwise, μ j =0; finally output μ∈{0,1} m .
[0182] S82), decrypting the heavily encrypted ciphertext;
[0183] According to the common parameters pp=(B1,…,B l ,χ), updated trustee private key and in the public key pk′ β The re-encrypted ciphertext calculate For j∈[m], when μ j =1; otherwise, μ j =0; finally output μ∈{0,1} m .
[0184] like Figure 3 , Figure 4 and Figure 5 As shown, the main time consumption of the algorithm is concentrated on the two algorithms KeyGen and ReKeyGen. The running time of the two new algorithms in the UAB-CPRE scheme proposed in this embodiment - the public key update (Update-pk) algorithm and the private key update (Update-sk) algorithm - is very small. Therefore, from the perspective of efficiency, the UAB-CPRE scheme has high feasibility. The UAB-CPRE scheme proposed in this embodiment calls the TrapGen algorithm in the re-encryption key generation algorithm and calls the SamplePre algorithm in the re-encryption algorithm. Further analysis shows that the key generation algorithm KeyGen of the UAB-CPRE scheme calls the TrapGen algorithm and the SamplePre algorithm; and the re-encryption key generation algorithm ReKeyGen also calls the SamplePre algorithm. The TrapGen and SamplePre algorithms are implemented in code. The running times of the TrapGen algorithm and the SamplePre algorithm under different grid ranks and different parameters q are shown as follows. Figure 6 and Figure 7 As shown, it can be seen that as n increases, the running time of TrapGen and SamplePre algorithms increases.
[0185] The above embodiments and descriptions are only for illustrating the principles and best embodiments of the present invention. Without departing from the spirit and scope of the present invention, the present invention may be subject to various changes and improvements, all of which fall within the scope of the present invention to be protected.
Claims
1. A forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method, characterized in that: The following steps are involved: S1), authorize the manager to generate and publish public parameters; S2), the entrusting party and the trustee generate a public and private key pair of the entrusting party and the trustee according to the public parameters; S3), the client encrypts the plaintext according to the public parameters and the client's public key and attribute vector, generates encrypted ciphertext, and sends the encrypted ciphertext to the cloud server; S4), the entrusting party generates an updated public key for the trustee based on the trustee's public key and an updated ciphertext used to update the trustee's private key; S5), the entrusting party generates a re-encryption key associated with the control policy based on the public parameters, the entrusting party's public-private key pair, the trustee's updated public key, and the control policy; S6), the cloud server re-encrypts the encrypted ciphertext according to the re-encryption key, generates a re-encrypted ciphertext and sends it to the trustee; S7), the trustee generates an updated private key based on the private key and the update ciphertext used to update the private key; S8) The trustee decrypts the re-encrypted ciphertext according to the public parameters and the trustee's updated private key.
2. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 1, characterized in that: In step S1), the authorized manager generates a public parameter pp through a Setup algorithm; First, input the security parameter n, then in a random matrix of dimension n×kn, each element of which belongs to the integer group modulo q Randomly and uniformly extract l matrices B1,…,B from the distribution l ,in The output is the system's common parameter pp = (B1, ..., B l ,χ), where χ is the B-bounded error sampling Gaussian distribution; q represents the modulus of the grid.
3. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 2, characterized in that: In step S2), the entrusting party and the trustee generate their respective public and private key pairs through the KeyGen algorithm, which specifically includes the following steps: S21), through the public parameter pp and the identity of the client α, and run the trapdoor generation algorithm TrapGen to generate the matrix A α and its trapdoor Right now: Among them, 1 n represents the security parameter; m represents the dimension of the grid, and q represents the modulus of the grid; S22) In a random matrix of dimension n×m, each element of the matrix belongs to the integer group modulo q Randomly uniformly extract a matrix D from the distribution α , and then use the sampling algorithm SamplePre and pass the matrix A α , Trapdoor and Matrix-D α , Gaussian parameter σ generates the sampling matrix R α ; Get the public and private key pair (pk α ,sk α ), where the public key pk α =(A α ,D α ); Private key S23), repeat step S21) and step S22), and obtain the public key pk of the trustee β =(A β ,D β ); Private key 4. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 3, characterized in that: In step S3), the client uses the Encrypt algorithm to encrypt the plaintext according to the public parameters and the client's public key and attribute vector to generate encrypted ciphertext, which specifically includes the following steps: S31), random uniform extraction e in ∈χ m ,e out ∈χ m ; Among them, s represents the In other words, s represents an n-dimensional random vector, and each element of the vector belongs to the modulo q integer group; $ represents random uniform extraction, e in and e out Represents an n-dimensional random noise vector, each element of which is independently generated according to Gaussian distribution, χ m represents a set of m-dimensional vectors whose elements belong to the χ distribution; S32), calculate the encrypted ciphertext c α,x The first part of ct α,x The included elements c in 、c out ,Right now: ct α,x =(c in ,c out ); In the formula, the matrix A α With D α The public key pk of the client α The two components of ; μ represents the plaintext message; q represents the modulus of the lattice; T represents the transpose operation of the matrix; S33), calculate the second part cc of the encrypted ciphertext α,x ; When the attribute vector x is empty, otherwise, In the formula, represents the empty set; cc α,x Represents the encrypted ciphertext c α,x The second part of i Represents a matrix vector The result of the operation; x i represents the i-th component of the l-dimensional attribute vector x; B i Represents the matrix contained in the common parameters; Represents an m×kn dimensional matrix, and the value of each position in the matrix is 1 or -1; Represents a vector space with lm dimensions, where each component of the vector belonging to the distribution is from the finite field Each component of the vector belongs to l represents the maximum value of i; m represents the dimension of the grid; G represents the Gadget matrix; for integers q≥2, n≥1, as well as Construct a relatively special Gadget matrix G as follows: Among them, I n represents an n-row identity matrix; g T Represents the first part of the re-encryption key; It means to perform Kronecker product operation on the two matrices connected; S34) Get the encrypted ciphertext c α,x =(ct α,x ,cc α,x ).
5. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 4, characterized in that: In step S4), the entrusting party uses the Update-pk algorithm to generate an updated public key and a ciphertext for updating the private key of the trustee according to the public key of the trustee, which specifically includes the following steps: S41), random uniform selection matrix S42), the matrix R' β Each element of is converted into binary, and then the bits at each position in the matrix are encrypted using parallel computing or multi-threading methods, and then reassembled into a matrix, that is: Encrypt(pp,pk β ,μ∈{0,1} m ,R′ β )→up; Among them, pk β is the public key of the trustee; p represents the plaintext message; up represents the ciphertext; Generate a ciphertext up for updating the trustee's private key according to the above, which is used for updating the trustee's private key; S43) According to Calculate the trustee's updated public key In the formula, A β Indicates the original public key of the trustee and the first part of the updated public key; D β The second part representing the original public key of the trustee; The second part of the trustee's updated public key, R′ β Indicated in Distribution Random Uniform Selection Matrix.
6. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 5, characterized in that: In step S5), the client generates a re-encryption key associated with the control strategy using the ReKeyGen algorithm, which specifically includes the following steps: S51), according to the control strategy f and the common parameter pp = (B1, ..., B l ,χ)Calculate B f : B f =Eval pk (f,{B i } i∈[l] ); Among them, f is the control strategy; B i is the matrix containing the common parameters; B f Represents Eval pk The output of the algorithm; S52), according to the public key pk of the client α =(A α ,D α ) and private key Calculate the matrix A α |B f Trapdoor In the formula, Represents the matrix A α |B f Trapdoor; ExtendRight means rightward extension algorithm; S53), according to the matrix A α |B f Trapdoor Calculate the matrix (A α |B f ) α,f : In the formula, R α,f Represents the matrix (A α |B f ), σ is the Gaussian parameter; SamplePre represents the pre-image sampling algorithm; S54), according to the updated public key of the trustee Calculate the first part of the re-encryption key g T : In the formula, g T Re-encryption key rk α,f→β The first part of represents the transpose of vector r1, where Respectively represent two random m-dimensional vectors drawn from the sampled Gaussian distribution χ, namely: S55), calculate the re-encryption key rk α,f→β The second part of Q: Where Q represents the re-encryption key rk α,f→β The second part; E1, E2, E3 represent three 2km×n, 2km×m, 2km×m matrices randomly drawn from the error distribution, that is: 0 m×m Represents a zero matrix, that is, every position of an m×m matrix is 0; I m×m They represent the unit matrix, that is, each position of the positive diagonal of the m×m matrix is 0; P2 represents the second one of the vector decomposition functions; S56), obtain the re-encryption key rk associated with the control policy f α,f→β : rk α,f→β ={g T ,Q}。 7. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 6, characterized in that: In step S51), the specific steps are as follows: Key fully homomorphic algorithm given a positive integer Any control strategy f, If satisfied c i =(x i G+B i ) T s+e i ,in e i ←χ m , then there will be the following three deterministic algorithms, namely Eval ct 、Eval pk and Eval sim ; ① :Algorithm input and a control strategy f, the output matrix B f ; ② : Algorithm input f, x i ∈{0,1}, c i =(x i G+B i ) T s+e i ; Where G is the Gadget matrix, the algorithm outputs c f , satisfying c f =(f(x)G+B f ) T s+e f ,in, ③ Algorithm input control strategy f, S i ∈{-1,1} m×m , and matrix A, the algorithm output matrix S f , and satisfies AS f -f(x)G=B f , where B f It's Eval pk obtained by the algorithm.
8. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 7, characterized in that: In step S6), the cloud server uses ReEncrypt algorithm is used to re-encrypt the encrypted ciphertext according to the re-encryption key, which specifically includes the following steps: S61), when the control strategy f≠0 or When , the output terminal symbol ⊥; otherwise, ct α,x =(c in ,c out ), S62), randomly select a small integer a∈χ, calculate c f and Right now: c f ←Eval ct (f,{(x i ,B i ,c i )} i∈[l] ) In the formula, c f To run Eval ct The results obtained by the algorithm; Re-encrypted ciphertext c β The first part of ct β rank of; f is the control strategy; x i represents the component of the attribute vector x; B i is a public parameter; c i The ciphertext c α,x The second part of cc α,x The element of g T Re-encryption key rk α,f→β The first part of ; BD represents one of the vector decomposition functions; Represents the matrix c in and c f cascade, that is, [c in |c f ]; Q represents the re-encryption key rk α,f→β The second part of S63), output, that is: In the formula, ct β ,cc β Represent the re-encrypted ciphertext c β The first and second parts.
9. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 8, characterized in that: In step S7), the trustee uses the Update-sk algorithm to generate an updated private key based on the private key and the ciphertext used to update the private key, specifically including the following steps: S71), decrypting each element of the ciphertext up used to update the trustee's private key using parallel computing or multi-threading method; S72), convert the decrypted bit string into distribution, and recombined to obtain the matrix R′ α ; S73), output the updated private key sk′ β ,Right now: In the formula, represents the trapdoor of the trustee β; Indicates the second part of the trustee's updated public key.
10. The forward-secure and quantum-resistant updatable attribute conditional proxy re-encryption method according to claim 9, characterized in that: In step S8), the trustee uses the Decrypt algorithm and updates the private key sk′ according to the public parameters, the private key of the entrusting party, and the updated private key sk′. α Decrypting encrypted ciphertext or re-encrypted ciphertext includes the following steps: S81), decrypt the encrypted ciphertext, according to the public parameter pp = (B1, ..., B l ,χ), the original private key of the client and the public key pk of the client α The original ciphertext calculate For j∈[m], when μ j =1; otherwise, μ j =0; finally, output μ∈{0,1} m ; S82), decrypt the re-encrypted ciphertext, according to the public parameter pp = (B1, ..., B l ,χ), updated trustee private key and in the public key pk′ β The re-encrypted ciphertext calculate For j∈[m], when μ j =1; Otherwise, μ j =0, finally, output μ∈{0,1} m .
Citation Information
Patent Citations
Data sharing method based on key strategy
CN117478324A
Anti-quantum ciphertext equivalent test public key encryption method and system based on lattice
CN118400197A
Attribute-based re-encryption method capable of confusing ciphertext strategy
CN118869315A
Medical data security sharing method based on grid updatable proxy re-encryption
CN118984216A
Cited By
Anti-quantum threshold encryption method and system
CN121814321A
A quantum threshold resistant encryption method and system
CN121814321B