Controlled ciphertext retrieval method supporting dynamic data and key updating

By introducing multi-keyword symmetric searchable encryption and double-layer encryption mechanisms into symmetric searchable encryption technology, the limitations of the existing technology in access control, dynamic data updates and key leakage are solved, and efficient and secure dynamic data and key updates are achieved.

CN119995923AActive Publication Date: 2025-05-13NANJING UNIV OF SCI & TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411905437.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-13
Estimated Expiration
2044-12-23

AI Technical Summary

Technical Problem

The existing symmetric searchable encryption technology has limitations in access control and dynamic data updates, and it is difficult to ensure the confidentiality of the ciphertext in the event of key leakage.

Method used

A controlled ciphertext search method that supports dynamic data and key updates is proposed. Multi-keyword symmetric searchable encryption technology is adopted to realize dynamic hierarchical role access control, flexible update of data and keys, and the confidentiality of ciphertexts during key leakage is ensured through a two-layer encryption mechanism.

Benefits of technology

It realizes sublinear multi-key search efficiency, ensures data confidentiality, supports efficient data retrieval, and ensures the confidentiality of ciphertexts in the event of key leakage, improving the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995923A_ABST
    Figure CN119995923A_ABST
Patent Text Reader

Abstract

The invention discloses a controlled ciphertext retrieval method supporting dynamic data and key updating, and belongs to the technical field of computer application. The method comprises three entities, namely a trusted authorization mechanism, a user and a cloud server. The method comprises the following specific implementation steps of: initializing a system; the legal user updates the data; searching data by the legal user; key updating and corresponding data updating are carried out. The invention provides a multi-keyword symmetric searchable encryption method which supports dynamic hierarchical role access control, dynamic data updating and key updating by taking a symmetric searchable encryption technology as a core, and breaks through the limitation of the existing symmetric searchable encryption technology in the aspect of access control. According to the invention, role-based dynamic hierarchical access control can be efficiently realized, flexible and efficient data and key updating is supported, and the confidentiality of a newly generated ciphertext during a period from key leakage to key updating is ensured, so that a higher security requirement in a complex application scene is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of computer application, and in particular relates to a controlled ciphertext retrieval method supporting dynamic data and key update. Background Art

[0002] Symmetric Searchable Encryption (SSE) is a cryptographic technology. The core idea is to protect data through symmetric key encryption, while allowing users to search encrypted data without decrypting the data, making the data "available but invisible". Currently, symmetric searchable encryption technology is widely used in cloud storage, data sharing, medical care, finance and other fields. Compared with public key searchable encryption, symmetric searchable encryption has higher computational efficiency and lower processing overhead, so it is particularly suitable for scenarios with high performance requirements.

[0003] However, symmetric searchable encryption requires both parties to hold the same key, which is unrealistic in some application scenarios. For example, in an enterprise's internal file management system, employees in different departments or positions have obvious hierarchical differences in access rights to files: the general manager needs to view files from all departments, including sensitive data from the finance, R&D, and HR departments; department managers can only access files from their own departments, such as the finance manager can only view financial statements, and the R&D manager can only view technical documents; ordinary employees can only access files related to their specific work, such as only viewing project documents for which they are responsible. Therefore, it is necessary to design a searchable encryption method that supports hierarchical role access control to meet the above requirements.

[0004] In addition, data in actual scenarios is usually dynamically changing rather than static, which requires encryption methods to support dynamic updates of data. However, the dynamic nature of data will not only affect system efficiency, but may also pose challenges to data security and query security, thereby placing higher requirements on secret search methods. At the same time, existing methods are often based on a strong assumption that "client keys are secure." However, in actual environments, client keys may face the risk of leakage. For example, in existing technologies, cloud API keys are stolen, resulting in customer data leakage. This raises an important question: how to ensure that the newly generated ciphertext remains confidential from the time the key is leaked to the time the key is updated in the event of a key leak. This issue is not only related to the reliability of data security, but is also a key challenge that existing encryption technologies need to focus on. Summary of the invention

[0005] In response to the problems mentioned in the background technology, the present invention proposes a controlled ciphertext retrieval method that supports dynamic data and key updates. With symmetric searchable encryption technology as the core, a multi-keyword symmetric searchable encryption method that supports dynamic hierarchical role access control, dynamic data updates and key updates is set up, which breaks through the limitations of existing symmetric searchable encryption technology in access control, and realizes flexible updates of data and keys; and ensures the confidentiality of newly generated ciphertexts during key leakage to key updates, thereby meeting higher security requirements in complex application scenarios.

[0006] Technical solution: In order to solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0007] A controlled ciphertext retrieval method supporting dynamic data and key update includes three entities: a trusted authorization agency, a user, and a cloud server. The specific implementation steps are as follows:

[0008] S1: System initialization: The trusted authority generates the key, label, and public token required for key derivation for each type of user, and makes the label and public token of each type of user public. At the same time, the system is initialized and an empty encryption database is generated.

[0009] S2: Legitimate users update data: Legitimate users update their own user class data and submit update requests to the cloud server. They can also update the data of their own user class subnodes and submit subnode data update requests to the cloud server.

[0010] S3: Legitimate users search for data: Legitimate users query the data of their own user class and submit query requests to the cloud server. They can also query the data of their own user class subnodes and submit subnode data query requests to the cloud server.

[0011] S4: Key update and corresponding data update: The user submits a key update request and sends the updated key to the trusted authority. The trusted authority updates the public token associated with the user class, and the cloud server updates the corresponding ciphertext.

[0012] Preferably, in S1, the system is initialized: the trusted authority generates the key, label and public token required for key derivation for each type of user, and discloses the label and public token for each type of user; at the same time, the system is initialized, and the specific content of generating an empty encrypted database is,

[0013] The trusted authority runs the HKAS method to establish algorithm Setup2, which outputs each user class R i The key K i , Tag i and the public token Y i,j ; Specifically:

[0014]

[0015] Where H is a cryptographic hash function; K j Represents user class R j The key of Represents the exclusive OR operation.

[0016] As a preferred method, the client runs the DSSE′ method to establish the algorithm Setup1 and outputs the key K 1i , K 2i And the initial empty encrypted database EDB.

[0017] As a preferred method, in S2, a legitimate user updates data: a legitimate user updates the data of his own user class and submits an update request to the cloud server; at the same time, the legitimate user can also update the data of the sub-node of his own user class and submit a sub-node data update request to the cloud server, the specific content of which is:

[0018] S21: Update user class R i Data, directly use the key K 1i , K 2i Update the message;

[0019] S22: Update user class R j data, R j YesR i The user calls the key derivation algorithm KeyDerivation2 (R i , R j ) Generate user class R j The key K 1j , K 2j , then use the key K 1j , K 2j Update the message.

[0020] Preferably, in S21, update the user class R i Data, directly use the key K 1i , K 2i The specific content of the updated message is:

[0021] First, (tk w ,cnt w )=st[w];Count value updates cnt w =cnt w +1; Search token update tk′ w ←{0, 1} λ ; State quantity update st[w] = (tk′ w ,cnt w ), ciphertext

[0022] Send the ciphertext (X, Y, Z) to the cloud server, and the server performs the update operation EDB[X]←(Y, Z);

[0023] Where EDB represents an encrypted database, EDB[X] represents the location of the corresponding address X in the encrypted database, EDB[X]←(Y, Z) represents storing the ciphertext (Y, Z) in EDB[X], H1, H2, and H3 represent cryptographic hash functions, and tk w Represents the search token, tk′ w represents the updated search token; λ represents the security parameter, op represents the operation, and id represents the corresponding document identifier.

[0024] As a preferred method, in S3, a legitimate user searches for data: a legitimate user queries the data of his own user class and submits a query request to the cloud server; at the same time, he can also query the data of the sub-node of his own user class and submit a sub-node data query request to the cloud server. The specific content is:

[0025] S31: Search for user class R i Data, directly use the key K 1i , K 2i Calculate search tokens;

[0026] S32: Search for user class R j data, R j YesR i The user calls the key derivation algorithm KeyDerivation2 (R i , R j ) Generate user class R j The key K 1j , K 2j , then use the key K 1j , K 2j Calculates the search token.

[0027] Preferably, in S31, search for user class R i Data, directly use the key K 1i , K 2i The specific content of calculating the search token is,

[0028] First, (tk w ,cnt w )=st[w], then calculate (K1, X, Msk Y ,Msk Z ) is sent to the server via a secure channel;

[0029] The server performs a query operation, initializes an empty list I, and then retrieves the ciphertext from the corresponding position of the encrypted database EDB according to X, specifically: (Y, Z)←EDB[X];

[0030] When (Y, Z) ≠ (NULL, NULL), calculate Insert Z′ into list I and calculate based on the derived tk (Y, Z)←EDB[X], loop until (Y, Z)=(NULL, NULL);

[0031] Send the list, to the user, the user initializes an empty list IdList, and then the user decrypts each Z′ in the list, Z′ i ←I[i], If op i = add, then id i Insert into list IdList, if op i = delete, then id i Delete from the list IdList, and finally the user gets the query result IdList;

[0032] Among them, K1 represents the key, X represents the ciphertext, Msk Y Represents the component of Y, Msk Z Represents the components of Z, H1, H2, H3 represent cryptographic hash functions, tk represents the search token, Z′ represents the intermediate value; add represents the add operation, delete represents the delete operation, and NULL represents the null value.

[0033] As a preferred embodiment, in S4, the key is updated and the corresponding data is updated: the user submits a key update request, sends the updated key to the trusted authorization agency, the trusted authorization agency updates the public token related to the user class, and the cloud server updates the corresponding ciphertext, the specific content is,

[0034] First, select Update key K′ 1i ←K 1i Δ, K′ 2i ←K 2i Δ

[0035] In the public token update protocol PTokenUpdate2, the user class R i The updated key K′ 1i and K′ 2i Sent to the trusted authority, which then updates the user class R i The relevant public tokens are:

[0036] In the key update protocol KeyUpdate1, the client sends Δ to the cloud server through a secure channel, and the cloud server performs the corresponding ciphertext update, specifically:

[0037] X′←X Δ , Y′←Y Δ , Z′←Z Δ ,EDB[X′]←(Y′,Z′),

[0038] Then remove the ciphertext X, Y, and Z from the encrypted database EDB;

[0039] Where Δ represents the key update token, represents the multiplication group modulo q, X′ represents the updated ciphertext; Y′ represents the updated ciphertext; Z′ represents the updated ciphertext; EDB[X′] represents the new ciphertext storage location, X Δ represents the new ciphertext X′, Y obtained by exponential operation of the previous ciphertext X and the key update token Δ Δ represents the new ciphertext Y′, Z obtained by exponential operation of the previous ciphertext Y and the key update token Δ Δ Represents the new ciphertext Z′ obtained by exponentially operating the previous ciphertext Z and the key update token Δ.

[0040] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0041] (1) The present invention supports dynamic update of data and keys, achieves sublinear multi-key search efficiency, and realizes efficient data retrieval while ensuring data confidentiality. By introducing a double-layer encryption mechanism, even if the key is leaked, the present invention can still ensure the confidentiality of the newly generated ciphertext during the key update period, thereby improving the security and reliability of the system.

[0042] (2) Based on the traditional symmetric searchable encryption method, the present invention introduces a role-based dynamic hierarchical access control mechanism, which can flexibly configure multi-level, role-based refined access strategies according to the access requirements of different users, allowing legitimate users to access their own data and user data below their authority level. On the basis of protecting the privacy of sensitive data, reliable and efficient dynamic hierarchical role access control is effectively implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 It is a system model diagram of the present invention;

[0044] Figure 2 A schematic diagram of the hierarchical access control relationship of the present invention;

[0045] Figure 3 It is a data update schematic diagram of the present invention;

[0046] Figure 4 It is a data search schematic diagram of the present invention;

[0047] Figure 5 It is a schematic diagram of key update of the present invention. DETAILED DESCRIPTION

[0048] The present invention is further illustrated below in conjunction with specific examples. The examples are implemented based on the technical solutions of the present invention. It should be understood that these examples are only used to illustrate the present invention and are not used to limit the scope of the present invention.

[0049] The controlled ciphertext retrieval method supporting dynamic data and key update provided in this embodiment mainly includes three main participating entities (such as Figure 1 As shown in Figure 1, trusted authority, user, and cloud server. Different entities have different functions and responsibilities.

[0050] Trusted Authority (TA): Develops and maintains access control policies for user data; assigns keys and tags to each user class, and maintains the public tokens required for key derivation.

[0051] User: A user who is issued a key by a trusted authority, and a producer and owner of private data. In this system, legitimate users can apply to the cloud server to update data, query data, and access the data of its child nodes according to the position of the user class to which the user belongs in the access structure, otherwise it is not allowed. At the same time, users can also request the cloud server to update the key and request TA to update the public token.

[0052] Cloud server: provides remote data storage service to store data uploaded by users; provides users with secure remote updates, data queries, and key update requests.

[0053] The method of this embodiment is designed to defend against two types of potential attackers; the first type is an "honest but curious" cloud server, which may try to snoop on the user's private data while honestly executing the user's request; the second type is a "key stealer" who can steal the client's key, monitor the communication between the client and the server, and obtain a copy of the encrypted database. In addition, the method of this embodiment assumes that there is no collusion or collusion between the server and the key stealer.

[0054] The method provided in this embodiment supports dynamic data update and key update, aims to achieve efficient retrieval and secure update of data, and builds a secure and efficient dynamic hierarchical access control mechanism and dynamic update system.

[0055] Specific features include:

[0056] 1. Dynamic hierarchical role access control:

[0057] The present invention generates and maintains dynamic hierarchical access control strategies through a trusted authorization agency, assigns keys to each hierarchical node, and users can access their own data and their sub-node data based on their role permissions, thereby achieving refined permission management and ensuring that access permissions of users with different roles are isolated from each other.

[0058] 2. Dynamic data update:

[0059] The present invention allows users to safely update stored data to the cloud server as needed, achieving forward security and backward security. The solution can effectively defend against various attacks such as file injection attacks, while optimizing system efficiency while ensuring data privacy, and meeting actual application needs in a dynamically changing environment.

[0060] 3. Dynamic key update:

[0061] The present invention provides a double-layer encryption mechanism and a key update mechanism to achieve post-compromise security. The double-layer encryption mechanism ensures that even if the key is leaked, the newly generated ciphertext during the key update period is still safe. The key update mechanism achieves the rapid update of the ciphertext without the need to download the ciphertext, decrypt it, and then re-encrypt it, thereby significantly improving the security and availability of the system.

[0062] 4. Efficient and dense search:

[0063] The present invention supports efficient retrieval of multi-keyword encrypted data, allowing users to quickly obtain required data without decrypting all encrypted content, thereby taking into account both data availability and security.

[0064] This embodiment requires the application of a dynamic searchable encryption method that supports key update and a hierarchical key distribution method. The relevant algorithms are described as follows:

[0065] Table 1 Symmetric searchable encryption schemes supporting key updates

[0066]

[0067] Table 2 Hierarchical key distribution scheme

[0068]

[0069] Based on the above components, participating entities, and related technical methods, a controlled ciphertext retrieval method supporting dynamic data and key updates mainly includes:

[0070] S1: System initialization: TA generates the key, label and public token required for key derivation for each type of user, and discloses the label and public token of each type of user; at the same time, the system is initialized and an empty encryption database is generated;

[0071] like Figure 2 As shown, TA runs the HKAS method system to establish algorithm Setup2, and outputs each user class R i The key K i , Tag i and the public token Y required for key derivation i,j . Specifically,

[0072] Where H is a cryptographic hash function; K j Represents user class R j The key of Represents the exclusive OR operation.

[0073] The client runs the DSSE′ scheme system to establish the algorithm Setup1 and outputs the key K 1i , K 2i And the initial empty encrypted database EDB.

[0074] S2: Legitimate users update data: Legitimate users can update their own user class data by submitting update requests to the cloud server. They can also update the data of their own user class subnodes by submitting subnode data update requests to the cloud server.

[0075] like Figure 3 As shown, it belongs to user class R i User:

[0076] S21: If you want to update the user class R i Data, directly use the key K 1i , K 2i Update the message document identifier-keyword pair (id, w).

[0077] When updating, a two-layer encryption mechanism (ENC2(K, ENC1(R, op, id, w))) is used to encrypt the message, where K is the client's key and R is a random number; op is the operation and (id, w) is the message; the inner encryption ENC1 uses a traditional encryption scheme, while the outer encryption ENC2 is an encryption method specifically designed for key updates. This double-layer encryption mechanism ensures that even if an attacker obtains the client's key and all historical random numbers, no information can be decrypted from a newly generated ciphertext because new random numbers are used in the new ciphertext. Although the attacker can use the leaked key to decrypt the outer encryption of the ciphertext, the inner encryption cannot be decrypted due to the lack of the random number R. In the subsequent implementation, K is K1, K2, and the random number R is the search token tk.

[0078] First, (tk w ,cntt w )=st[w], the count value is updated cntt w =cntt w +1, search token update tk′ w ←{0, 1} λ , state quantity update st[w]=(tk′ w ,cnt w ), ciphertext The ciphertext (X, Y, Z) is sent to the cloud server, and the server performs an update operation, EDB[X]←(Y, Z).

[0079] Where EDB represents an encrypted database, EDB[X] represents the location of the corresponding address X in the encrypted database, EDB[X]←(Y, Z) represents storing the ciphertext Y, Z in EDB[X], (Y, Z) represents the ciphertext, H1, H2, H3 represent cryptographic hash functions, and tk w Represents the search token, tk′ w represents the updated search token (each state corresponds to a search token, and each update will regenerate a corresponding search token); λ represents the security parameter, op represents the operation, and id represents the corresponding document identifier.

[0080] S22: If you want to update the user class R j (R j In the access control policy graph, R i The user needs to call the key derivation algorithm KeyDerivation2 (R i , R j ) Generate user class R j The key K 1j , K 2j , then use the key K1j , K 2j Update the message (id, w).

[0081] First, (tk w ,cnt w )=st[w], the count value updates cnt w =cnt w +1, search token update tk′ w ←{0, 1} λ , state quantity update st[w]=(tk′ w ,cnt w ), ciphertext The ciphertext (X, Y, Z) is sent to the cloud server, and the server performs an update operation, EDB[X]←(Y, Z).

[0082] S3: Legitimate users search for data: Legitimate users can query the data of their own user class by submitting a query request to the cloud server. They can also query the data of their own user class subnodes by submitting a subnode data query request to the cloud server.

[0083] like Figure 4 As shown, it belongs to user class R i User:

[0084] S31: If you want to search for user class R i Data, directly use the key K 1i , K 2i Calculates the search token.

[0085] First, (tk w ,cnt w )=st[w], then calculate (K1, X, Msk Y ,Msk Z ) is sent to the server via a secure channel.

[0086] The server performs a query operation, initializes an empty list I, and then retrieves the ciphertext from the corresponding position of the encrypted database EDB according to X, specifically: (Y, Z)←EDB[X].

[0087] When (Y, Z) ≠ (NULL, NULL), calculate Insert Z′ into list I and calculate based on the derived tk (Y, Z)←EDB[X], and the calculation is repeated until (Y, Z)=(NULL, NULL).

[0088] Send the list, to the user, the user initializes an empty list IdList, and then the user decrypts each Z′ in the list, Z′ i ←I[i], If op i = add, then id i Insert into list IdList, if op i = delete, then id i Delete from the list IdList, and finally the user gets the query result IdList.

[0089] Among them, K1 represents the key, X represents the ciphertext, and is used to represent the position of the ciphertext Y and Z in the encrypted database EDB. Y Represents the component of Y, Msk Z It represents the components of Z, H1, H2, H3 represent cryptographic hash functions, tk represents the search token, and Z′ represents the intermediate value, which is obtained by Z and Msk Z The specific form is Used to decrypt op and id later. add indicates add operation, delete indicates delete operation, and NULL indicates null value.

[0090] S32: If you want to search for user class R j (R j In the access control policy graph, R i The user needs to call the key derivation algorithm KeyDerivation2 (R i , R j ) Generate user class R j The key K 1j , K 2j , then use the key K 1j , K 2j Calculates the search token.

[0091] First, (tk w ,cnt w )=st[w], then calculate (K1, X, Msk Y ,Msk Z ) is sent to the server via a secure channel.

[0092] The server performs a query operation, initializes an empty list I, and then retrieves the ciphertext from the corresponding position of the encrypted database EDB according to X. Specifically, (Y, Z)←EDB[X].

[0093] When (Y, Z) ≠ (NULL, NULL), calculate Insert Z′ into list I and calculate based on the derived tk (Y, Z)←EDB[X], and the calculation is repeated until (Y, Z)=(NULL, NULL).

[0094] Send the list, to the user, the user initializes an empty list IdList, and then the user decrypts each Z′ in the list, Z′ i ←I[i], If op i = add, then id i Insert into list IdList, if op i = delete, then id i Delete from the list IdList, and finally the user gets the query result IdList.

[0095] S4: Key update and corresponding data update: The user can submit a key update request and send the updated key to the TA. The TA updates the public token related to the user class, and the cloud server updates the corresponding ciphertext.

[0096] like Figure 5 As shown, user class R i Update the key regularly.

[0097] First, select Update key K′ 1i ←K 1i Δ, K′ 2i ←K 2i ·Δ.

[0098] Where Δ represents the key update token, Usually represents the multiplicative group modulo q.

[0099] In the public token update protocol PTokenUpdate2, the user class R i The updated key K′ 1i and K′ 2i Send it to TA, and then TA updates the user class R i Related public tokens, e.g. In the key update protocol KeyUpdate1, the client sends Δ to the cloud server through a secure channel, and the cloud server performs the corresponding ciphertext update, X′←X Δ , Y′←Y Δ , Z′←Z Δ , EDB[X′]←(Y′, Z′), and then remove the ciphertext X, Y, Z from the encrypted database EDB.

[0100] Among them, X′ represents the updated ciphertext, Y′ represents the updated ciphertext, Z′ represents the updated ciphertext, EDB[X′] represents the new ciphertext storage location, X Δ The previous ciphertext X and the key update token Δ are exponentially calculated to obtain the new ciphertext X′; Y Δ The previous ciphertext Y and the key update token Δ are exponentially calculated to obtain the new ciphertext Y′, Z Δ It means that the new ciphertext Z′ is obtained by performing exponential operation on the previous ciphertext Z and the key update token Δ.

[0101] In this embodiment, taking a single keyword as an example, if it is to be expanded to a multi-keyword Boolean query, it is only necessary to add two layers of encryption steps of the cross terms during the update, specifically:

[0102] Cross Term Introduce auxiliary value A1←H4(add||id)·(H5(w||cnt w )) -1 ,A2←H4(add||id)·(H5(w||cnt w )) -1 , A1 and A2 also exist in EDB[X]. At the same time, a new storage structure JSet is introduced, which is essentially an element counter that counts the number of each cross item: each time J is updated, JSet[J]←JSet[J]+1.

[0103] Among them, H4, H5, and H6 represent cryptographic hash functions, cnt w represents the count value, w represents the keyword, and .g represents the generator of the group G, where G is a group of prime order p.

[0104] Multiple keyword query q = (w1∧…∧w n ), when querying, we first assume that w1 is the keyword with the lowest keyword frequency. The client calculates the search token and sends it to the server. After the server executes a single keyword query on w1, it determines whether the document containing w1 contains other keywords. Specifically, it calculates the corresponding cross-term based on the auxiliary value, and then determines whether for i∈[2,n], (w i , id) Whether the number of cross-items of the operation op add is the same as the number of cross-items of the operation op delete. If they are different, it means that the file has not been deleted and the condition is met. Otherwise, the file will not be returned. (In this embodiment, it is assumed that all operations are executed correctly, that is, the delete operation must be executed after the add operation, and the same operation will not be repeated continuously.)

[0105] The present invention proposes a completely dynamic, secure and efficient controlled ciphertext retrieval method, which realizes efficient multi-keyword data retrieval while protecting data confidentiality, and supports dynamic update of data and keys at the same time. The method allows legitimate users to access their own data and the data of users whose access control authority level is lower than theirs. At the same time, the method can ensure the confidentiality of the ciphertext generated during the period from key leakage to key update in the event of key leakage, thereby improving the security and reliability of the system.

[0106] While protecting data confidentiality, the present invention realizes flexible and efficient access control, data update and key update, significantly improving the security, reliability and practicality of the system, and is suitable for various scenarios such as cloud storage and data sharing.

[0107] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A controlled ciphertext retrieval method supporting dynamic data and key updates, characterized in that: It includes three entities: trusted authorization agency, user and cloud server. The specific implementation steps are as follows: S1: System initialization: The trusted authority generates the key, label, and public token required for key derivation for each type of user, and makes the label and public token of each type of user public. At the same time, the system is initialized and an empty encryption database is generated. S2: Legitimate users update data: Legitimate users update their own user class data and submit update requests to the cloud server. They can also update the data of their own user class subnodes and submit subnode data update requests to the cloud server. S3: Legitimate users search for data: Legitimate users query the data of their own user class and submit query requests to the cloud server. They can also query the data of their own user class subnodes and submit subnode data query requests to the cloud server. S4: Key update and corresponding data update: The user submits a key update request and sends the updated key to the trusted authority. The trusted authority updates the public token associated with the user class, and the cloud server updates the corresponding ciphertext.

2. The controlled ciphertext retrieval method supporting dynamic data and key update according to claim 1, characterized in that: In S1, the system is initialized: the trusted authority generates the key, label and public token required for key derivation for each type of user, and discloses the label and public token of each type of user; at the same time, the system is initialized and generates an empty encrypted database with the following specific contents: The trusted authority runs the HKAS method to establish algorithm Setup2, which outputs each user class R i The key K i , Tag i and the public token Y i,j ; Specifically: Where H is a cryptographic hash function; K j Represents user class R j The key of Represents the exclusive OR operation.

3. The controlled ciphertext retrieval method supporting dynamic data and key update according to claim 2, characterized in that: The client runs the DSSE′ method to establish algorithm Setup1 and outputs the key K 1i , K 2i And the initial empty encrypted database EDB.

4. The controlled ciphertext retrieval method supporting dynamic data and key update according to claim 1, characterized in that: In S2, a legitimate user updates data: a legitimate user updates the data of his own user class and submits an update request to the cloud server; at the same time, he can also update the data of his own user class subnode and submit a subnode data update request to the cloud server. The specific content is: S21: Update user class R i Data, directly use the key K 1i , K 2i Update the message; S22: Update user class R j data, R j YesR i The user calls the key derivation algorithm KeyDerivation2 (R i ,R j ) Generate user class R j The key K 1j , K 2j , then use the key K 1j , K 2j Update the message.

5. The controlled ciphertext retrieval method supporting dynamic data and key update according to claim 4, characterized in that: In S21, update the user class R i Data, directly use the key K 1i , K 2i The specific content of the updated message is: First, (tk w ,cnt w )=st[w];Count value updates cnt w =cnt w +1; Search token update tk′ w ←{0,1} λ ; State quantity update st[w] = (tk′ w ,cnt w ), ciphertext Send the ciphertext (X, Y, Z) to the cloud server, and the server performs the update operation EDB[X]←(Y, Z); Where EDB represents an encrypted database, EDB[X] represents the location of the corresponding address X in the encrypted database, EDB[X]←(Y,Z) represents storing the ciphertext (Y,Z) in EDB[X], H1, H2, and H3 represent cryptographic hash functions, and tk w Represents the search token, tk′ w represents the updated search token; λ represents the security parameter, op represents the operation, and id represents the corresponding document identifier.

6. The controlled ciphertext retrieval method supporting dynamic data and key update according to claim 1, characterized in that: In S3, legitimate users search for data: Legitimate users query the data of their own user class and submit query requests to the cloud server; they can also query the data of the sub-nodes of their own user class and submit sub-node data query requests to the cloud server. The specific content is: S31: Search for user class R i Data, directly use the key K 1i , K 2i Calculate search tokens; S32: Search for user class R j data, R j YesR i The user calls the key derivation algorithm KeyDerivation2 (R i ,R j ) Generate user class R j The key K 1j , K 2j , then use the key K 1j , K 2j Calculates the search token.

7. The controlled ciphertext retrieval method supporting dynamic data and key update according to claim 6, characterized in that: In S31, search for user class R i Data, directly use the key K 1i , K 2i The specific content of calculating the search token is, First, (tk w ,cnt w )=st[w], then calculate (K1,X,Msk Y ,Msk Z ) is sent to the server via a secure channel; The server performs a query operation, initializes an empty list I, and then retrieves the ciphertext from the corresponding position of the encrypted database EDB according to X, specifically: (Y, Z)←EDB[X]; When (Y,Z)≠(NULL,NULL), calculate Insert Z′ into list I and calculate based on the derived tk (Y,Z)←EDB[X], loop until (Y,Z)=(NULL,NULL); Send the list I to the user, the user initializes an empty list IdList, and then the user decrypts each Z′ in the list I, Z′ i ←O[i], If op i = add, then id i Insert into list IdList, if op i = delete, then id i Delete from the list IdList, and finally the user gets the query result IdList; Among them, K1 represents the key, X represents the ciphertext, and Msk Y Represents the component of Y, Msk Z Represents the components of Z, H1, H2, H3 represent cryptographic hash functions, tk represents the search token, Z′ represents the intermediate value; add represents the add operation, delete represents the delete operation, and NULL represents the null value.

8. The controlled ciphertext retrieval method supporting dynamic data and key update according to claim 1, characterized in that: In S4, the key is updated and the corresponding data is updated: the user submits a key update request and sends the updated key to the trusted authority. The trusted authority updates the public token associated with the user class, and the cloud server updates the corresponding ciphertext. The specific content is: First, select Update key K′ 1i ←K 1i Δ, K′ 2i ←K 2i Δ In the public token update protocol PTokenUpdate2, the user class R i The updated key K′ 1i and K′ 2i Sent to the trusted authority, which then updates the user class R i The relevant public tokens are: In the key update protocol KeyUpdate1, the client sends Δ to the cloud server through a secure channel, and the cloud server performs the corresponding ciphertext update, specifically: X′←X Δ ,Y′←Y Δ ,Z′←Z Δ ,EDB[X ′ ]←(Y′,Z′), Then remove the ciphertext X, Y, and Z from the encrypted database EDB; Where Δ represents the key update token, represents the multiplication group modulo q, X′ represents the updated ciphertext; Y′ represents the updated ciphertext; Z′ represents the updated ciphertext; EDB[X′] represents the new ciphertext storage location, X Δ represents the new ciphertext X′, Y obtained by exponential operation of the previous ciphertext X and the key update token Δ Δ represents the new ciphertext Y′, Z obtained by exponential operation of the previous ciphertext Y and the key update token Δ Δ Represents the new ciphertext Z′ obtained by exponentially operating the previous ciphertext Z and the key update token Δ.

Citation Information

Patent Citations

  • Cross-domain fine-grained control system of Internet of things under social network environment

    CN105471868A

  • Dynamic searchable encryption method, decryption method, encryption device and decryption device

    CN116418513A

  • Dynamic searchable encryption method and device supporting multiple users and storage medium

    CN117459267A

  • Computer system for storing and retrieval of encrypted data items, client computer, computer program product and computer-implemented method

    WO2014076176A1