Multi-authorization-mechanism traceable lightweight searchable attribute-based encryption method

By introducing the use of multi-authorized institutions and index files/trapped door files in attribute-based encryption technology, the problem of low efficiency of multi-keyword retrieval in the prior art is solved, and efficient and secure ciphertext retrieval and key management are achieved.

CN120050035APending Publication Date: 2025-05-27CHONGQING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510202844.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The existing searchable encryption technology based on attribute-based searchable encryption has insufficient search overhead, especially when processing multiple keyword search, the calculation overhead is too large and cannot effectively support multi-keyword retrieval, resulting in the efficiency of data encryption, decryption and search operations in large-scale data scenarios that cannot meet the actual application needs.

Method used

A lightweight searchable attribute-based encryption method that can be traced by multiple authorization agencies is proposed. Through the initialization of the central authorization center and the attribute authorization agency system, global public parameters and system public keys and master keys are generated, and the collaborative management of multiple authorization agencies is supported, and efficient multi-keyword retrieval is achieved through the use of index files and trapped files.

Benefits of technology

This method maintains constant storage overhead, significantly reducing the storage burden and communication burden of encryption and storage devices, ensuring that the calculation overhead in the encryption and decryption stages is constant as constant, supporting efficient multi-keyword subset query, improving the retrieval efficiency and accuracy of shared ciphertexts, and enhancing the security of key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050035A_ABST
    Figure CN120050035A_ABST
Patent Text Reader

Abstract

The invention relates to a multi-authorization-mechanism traceable lightweight searchable attribute-based encryption method, belongs to the technical field of network and information security, and aims to realize flexible access control of data needing to be shared in an encryption and decryption mode. Comprising the steps of system initialization, key generation, data encryption, trap door generation and retrieval, decryption, key tracking and permission revocation. According to the method, multiple authorizations are combined, and the security of the secret key is improved through multi-party collaborative management of the secret key; meanwhile, the tracking of the secret key and the revocation of the user permission are realized by utilizing symmetric encryption and a revocation list; a flexible multi-keyword retrieval function is realized based on a polynomial equation; in the encryption, decryption and ciphertext retrieval processes, the calculation overhead is constant, the calculation burden is not increased along with the increase of the number of the attributes, and the length of the ciphertext is kept constant, so that the storage and communication overhead of the ciphertext is effectively reduced; the method is suitable for a data sharing application scene with limited equipment computing power and storage resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network and information security, and relates to a lightweight searchable attribute-based encryption method with multiple authorization agencies and traceability. Background Art

[0002] Attribute-Based Encryption (ABE) has become an important research direction in the field of cryptography in recent years. It provides a flexible fine-grained access control mechanism that can manage the ciphertext decryption permission precisely according to the attributes of users, thereby effectively controlling who can access specific data. In addition, ABE can flexibly manage the relationship between ciphertexts and user security keys, so it is very useful in data protection scenarios that require detailed permission control and high security. Due to its unique advantages, ABE has been widely applied in many fields such as cloud computing, cloud medical services, and Internet of Things data sharing, and can meet the requirements of data privacy protection and access control in these fields.

[0003] Many encryption schemes rely on a single authorization agency to manage keys, which is not flexible and secure enough in scenarios of multi-party collaboration. Especially in the case of data sharing and access control, how to ensure the collaborative management among multiple authorization agencies while supporting the traceability and revocation of keys has become an important research direction. Collaborative management by multiple authorization agencies can improve the security of the system, ensure that user keys are not misused or leaked, and can revoke keys when needed to prevent unauthorized access.

[0004] As a method of data encryption and access control, Attribute-Based Searchable Encryption (ABE) has gradually become one of the key technologies for protecting data privacy in the cloud. However, existing attribute-based searchable encryption technologies have certain deficiencies in terms of retrieval overhead. Most existing schemes face the problem of excessive computational overhead when dealing with the retrieval of multiple keywords, and usually cannot effectively support multi-keyword retrieval. This makes the efficiency of data encryption / decryption and search operations unable to meet the actual application requirements in large-scale data scenarios.

[0005] In environments with limited computing resources such as the Internet of Things (IoT), the problem of ciphertext length in attribute-based encryption technology is particularly prominent. In traditional attribute-based encryption schemes, the ciphertext length usually increases with the increase in the number of encrypted attributes, thus bringing a huge burden on storage and transmission. IoT devices often have limited resources, with limited computing power and storage space. Therefore, the increase in ciphertext length may lead to a decline in device performance and even affect the efficiency of the entire system. Summary of the Invention

[0006] In view of this, the purpose of the present invention is to provide a lightweight searchable attribute-based encryption method that can be traced by multiple authorization agencies.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] A lightweight searchable attribute-based encryption method that can be traced by multiple authorization agencies, comprising the following steps:

[0009] S1: The central authorization center and the attribute authorization agency system are initialized to generate global public parameters and corresponding system public keys and master keys;

[0010] S2: The central authorization center generates partial keys for users applying for keys, signs the verified user attribute sets, and sends them to the corresponding attribute agencies, and the attribute agencies then generate attribute keys for them;

[0011] S3: The data owner encrypts the data file, encrypts the data file according to the access policy set by himself, extracts the keyword set in the data file, generates an index file according to the keyword set, and uploads it to the cloud server together with the encrypted file;

[0012] S4: The user generates a trapdoor file according to the keyword set he is interested in and combines his private key;

[0013] S5: The cloud server performs corresponding calculations based on the received trapdoor file and the ciphertext file and index file stored locally, and returns the encrypted file with successful calculation matching to the user;

[0014] S6: The user decrypts the encrypted file according to his private key;

[0015] S7: The central authorization center traces the user identity uid through the user's private key and maintains a revocation list through the cloud server to disable the permissions of the corresponding user.

[0016] Further, step S1 specifically includes the following steps:

[0017] S11: The central authorization center initializes and signs the confirmed user attributes, specifically as follows:

[0018] The central authorization center selects two multiplicative cyclic groups G and Gp with the same prime order, where the parameter g is the generator of G, and defines a binary mapping e: G×G→G on G T , and then the central authorization center randomly selects is the integer ring modulo p;

[0019] Let H 1 : is a hash function that maps any binary string to a random element of Zp*;

[0020] Let H 2 :{0,1}→G be a hash function that maps any binary string to a random element of the group G;

[0021] Let H 3 : be a hash function that maps any binary string to a random element of Zp*, and the data owner and user calculate keywords to hide keyword information;

[0022] The central authorization center is responsible for user registration and attribute authentication;

[0023] First, the central authorization center generates a pair of signature keys (SigKey, VerKey) for signing and verification, where VerKey is public;

[0024] The published public key is as follows:

[0025] CPK = (G, p, g, e, N = g λ , VerKey)

[0026] N is part of the public key, g is the generator of the finite cyclic group G, λ is a parameter randomly selected in Zp*; e(g, g) is a binary mapping that is a mapping value on the group Gt obtained by inputting two elements on the group G;

[0027] The central authorization center master key is as follows:

[0028] CMSK = (λ, SigKey)

[0029] The master key is saved by the central authorization center and is not publicly disclosed;

[0030] S12: The attribute authorization agency system is initialized, which specifically includes the following steps:

[0031] Each attribute authorization agency randomly selects according to the attribute set it manages i, j indicate that the attribute value is the jth attribute value of the ith type of attribute, 1 ≤ i ≤ n, 1 ≤ j ≤ m; then generate the corresponding key component for each attribute value

[0032] The published public key is as follows:

[0033] APK = (A i,j , Y i,j )i∈(1,n),j∈(1,m)

[0034] The attribute authorization agency master key is as follows:

[0035] AMSK = (a i,j ) where \(i\in(1,n)\) and \(j\in(1,m)\)

[0036] The master key is separately stored by each attribute authority and not publicly disclosed.

[0037] Furthermore, step S2 specifically includes the following steps:

[0038] S21: The central authorization center verifies the user attributes and generates partial keys, specifically including the following steps:

[0039] The user sends a registration application to the central authorization center. The central authorization center first generates a unique uid for the user, randomly selects a symmetric encryption key k, calculates \(sk = D_n\) k (GID), and then randomly selects sk 1 = b, and calculates

[0040] The central authorization center signs the verified user attribute set with the signature key SigKey and sends the signed attribute set to the attribute authority corresponding to the attribute generation permission;

[0041] S22: The attribute authority generates attribute keys for the user, specifically including the following steps:

[0042] The attribute authority uses the signature key VerKey to verify whether it is correct. Each attribute authority generates private keys for them according to the attribute set owned by the user verified in the system, and randomly selects Calculate sk 5 = g α ;

[0043] All keys \(sk=\{sk,sk 1 ,sk 2 ,\{sk 3,i,j ,sk 4,i,j \}(1\leq i\leq n,1\leq j\leq m),sk 5 \} are returned to the user together.

[0044] Furthermore, step S3 specifically includes:

[0045] The data owner himself completes the encryption of the data, and generates the corresponding ciphertext according to the access policy \(P=(p 1 ,p 2 ,\cdots,p n ), the data file M, and the publicly available APK and CPK; First, randomly select Calculate where A i,j and Y i,j correspond to each attribute in the access policy P;

[0046] The data owner extracts the keyword set in M generates a corresponding index file according to the access policy P, and randomly selects a secret value takes the keywords in the keyword set as the solutions of the polynomial equation, and constructs an l 1 degree polynomial, calculate

[0047] According to the access policy P, calculate the corresponding index file, I 1 = g nkr , I 2 = N nkr ,

[0048] The data owner uploads the encrypted file and the index file C = {C 1 , C 2 , C 3 , I 1 , I 2 , I 3} to the cloud server together.

[0049] Furthermore, step S4 specifically includes the following steps:

[0050] The user generates a corresponding trapdoor file according to the keyword set of interest randomly selects calculate T 2 = sk 1 ,

[0051] sk 1 , sk 2 , sk 3 , sk 4 are the user's own private keys; l 2 is the total number of keyword sets provided by the user; T 4,j is that the user first maps each keyword in the keyword set to a value on Zp*, then performs exponentiation on the mapped value of each keyword, and adds the values of the same exponentiation;

[0052] Generate a trapdoor file, specifically expressed as:

[0053] T = {T 1 , T 2 , T 3 , T4,j , T 5 , T 6}

[0054] Send the trapdoor file to the cloud server.

[0055] Furthermore, step S5 specifically includes the following steps:

[0056] The cloud server finds the matching ciphertext file through corresponding calculations based on the trapdoor file and the index file;

[0057] The cloud server first performs the following calculations to obtain the corresponding trapdoor file T and ciphertext C:

[0058]

[0059] If the equation holds, return the corresponding encrypted file to the user.

[0060] Furthermore, step S6 specifically includes the following steps:

[0061] The user decrypts using the private key according to the retrieved corresponding ciphertext. The specific steps are as follows:

[0062]

[0063]

[0064] If the user attributes meet the access policy requirements, output the correct data file M.

[0065] Furthermore, step S7 specifically includes the following steps:

[0066] When the user's private key is leaked or publicly sold, this method identifies malicious users and revokes their access rights. The specific process includes:

[0067] Trace malicious users: The central authorization center obtains the malicious key. According to the symmetric encryption key, calculate uid = De k (sk), where k is the symmetric key saved by the central authorization center. According to the user's unique uid, find the corresponding user;

[0068] Revoke user rights: Add the returned uid to the user revocation list maintained in the cloud server to record users prohibited from accessing.

[0069] The beneficial effects of the present invention are as follows: This method is suitable for application scenarios with limited computing power and limited storage capacity. The method maintains a constant storage overhead, significantly reducing the storage burden and communication burden of encryption and storage devices. At the same time, it ensures that the computational overhead in the encryption and decryption phases is constant as a constant; in addition, this method supports multi-keyword subset queries and does not increase the retrieval computational overhead as the number of keywords in the trapdoor increases, improving the retrieval efficiency and accuracy of shared ciphertext; at the same time, by introducing multiple authorization agencies, a key tracking mechanism, and a revocation list, the security of key management is further enhanced.

[0070] Other advantages, objectives, and features of the present invention will be described to some extent in the subsequent specification, and to some extent, will be obvious to those skilled in the art based on an investigation and study of the following text, or can be learned from the practice of the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the following specification. Brief Description of the Drawings

[0071] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be described in detail preferably in conjunction with the accompanying drawings, where:

[0072] Figure 1 It is a flowchart of the multi-authorization agency traceable lightweight searchable attribute-based encryption method according to an embodiment of the present invention. Detailed Embodiments

[0073] The following illustrates the embodiments of the present invention through specific specific examples. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present invention schematically. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0074] It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present invention schematically. Therefore, only the components related to the present invention are shown in the diagrams, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be an arbitrary change, and the component layout type may also be more complex.

[0075] In the following description, a large number of details are explored to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.

[0076] In this embodiment, a multi-keyword searchable attribute-based encryption method with multi-authority traceability is provided. As Figure 1 shown, in the adopted system model, five entities are involved: the Central Authority (CA), Attribute Authorities (AAs), data users (DUs), data owners (DOs), and cloud service providers (CSs).

[0077] CA: It is fully trusted and is used to verify the authenticity of the identities of different users during registration in the data sharing application scenario. It is responsible for system initialization, generating public parameters, generating a unique uid for each user, and sending the verified user attributes to the corresponding AA. At the same time, it can trace users through keys and revoke the permissions of users.

[0078] AAs: Each AA has sufficient storage and computing capabilities and can independently verify any user. The AA will verify its certificate according to the attributes submitted by the DU and generate the corresponding attribute keys on behalf of the CA. It is worth mentioning that the purpose of introducing multiple AAs is to relieve the heavy tasks of CA certificate verification and key generation, further reduce the possibility of a single-point performance bottleneck, and disperse the master key to be managed by multiple institutions, which can resist single-point key attacks.

[0079] CS: It is a semi-trusted third party that provides computing services and the function of storing encrypted files. It is responsible for storing the encrypted data from the DO, providing a search function for users, and maintaining a revocation list to record the ids of revoked users.

[0080] DO: The DO formulates an access policy for its data and encrypts the files according to the defined policy. It then sends all the encrypted data and the encrypted symmetric key to the CS. In this way, it can share its data with multiple DUs and significantly reduce the local storage and computing burden.

[0081] DU: The DU obtains a unique identifier from the CA and has a set of attributes of relevant information on its own. The DU authenticates its identity through the CA and obtains the attribute key from the corresponding AA. The DU generates a search trapdoor using the keywords of interest and its private key, sends it to the CS, and at the same time receives the search results returned by the CS, decrypts them to obtain the plaintext data.

[0082] This method specifically includes the following steps:

[0083] Step S1, the system initialization process:

[0084] The initialization part is mainly divided into two steps. The first step is the initialization of the CA, and the second step is the corresponding initialization of the AAs according to the parameters generated by the CA.

[0085] The first step: The CA selects two multiplicative cyclic groups G and Gp with the same prime order, where the parameter g is the generator of G, and defines a binary mapping e: G×G→G on G T , and then the central authorization center randomly selects is the integer ring modulo p. The CA randomly selects three hash functions H 1 , H 2 and H 3 , and makes them public. H 1 and H 2 map any binary string to a random element of Zp*. H 3 map any binary string to a random element of G.

[0086] The CA is also responsible for user registration and attribute authentication; first, the CA generates a pair of signature keys (SigKey, VerKey) and makes VerKey public.

[0087] When the DU registers, the CA generates a unique uid for each user.

[0088] The public key published by the CA is as follows:

[0089] CPK=(G,p,g,e,N = g λ ,VerKey)

[0090] N is a part of the public key, g is the generator of the finite cyclic group G, λ is a parameter randomly selected in Zp*, and e(g,g) is a binary mapping that obtains a mapping value on a group Gt by inputting two elements on the group G.

[0091] The CA master key is as follows:

[0092] CMSK=(λ,SigKey)

[0093] The master key is saved by the CA and not publicly disclosed.

[0094] Step 2: When the CA initializes, it divides all attributes and assigns different attribute sets to each different AA. Each AA only initializes and generates the attribute set it manages. Each AA randomly selects according to the attributes it manages Correspondingly, i and j indicate that the attribute value is the j-th attribute value of the i-th type of attribute (1 ≤ i ≤ n, 1 ≤ j ≤ m), and then a corresponding key component is generated for each attribute value

[0095] The public keys published by the AAs are as follows:

[0096] APK = (A i,j , Y i,j ) for i ∈ (1, n), j ∈ (1, m)

[0097] The master keys of the AAs are as follows:

[0098] AMSK = (a i,j ) for i ∈ (1, n), j ∈ (1, m)

[0099] The master key is saved separately by each AA and not publicly disclosed.

[0100] Step S2: Generate the corresponding private key for the DU:

[0101] It is mainly divided into two steps. First, the CA verifies whether the attributes of the DU are true and generates a partial key. Then, in the second step, the AAs generate the corresponding attribute keys for the DU.

[0102] Step 1: The DU sends a registration application to the CA. The CA first generates a unique uid for the user, randomly selects a symmetric encryption key k, which is saved by the CA for key tracking, calculates sk = Dn k (GID), and then randomly selects Calculate Generate the user's partial key, specifically expressed as:

[0103] sk = Dn k (GID)

[0104] sk 1 = b

[0105]

[0106] The CA signs the verified DU attributes with the signature key SigKey and sends the signed attribute set to the AA with the corresponding attribute generation permission.

[0107] Step 2: AA verifies whether it is correct using the signature key VerKey, and each attribute institution generates an attribute key for them according to the set of attributes that the users in the system have after verification, and randomly selects for each user Calculate sk 5 = g α ; Generate the user attribute key, specifically expressed as:

[0108]

[0109] sk 5 = g α

[0110] Return all keys sk = {sk, sk 1 , sk 2 , {sk 3,i,j , sk 4,i,j}(1 ≤ i ≤ n, 1 ≤ j ≤ m), sk 5} to the user together.

[0111] Step S3: Encrypt the plaintext data:

[0112] Mainly generate the corresponding ciphertext and index file according to the plaintext;

[0113] DO itself completes the encryption of the data, and generates the corresponding ciphertext according to the access policy P = (p 1 , p 2 ,..., p n ), the plaintext M, and the public APK and CPK. First, randomly select Generate the ciphertext component, specifically expressed as.

[0114]

[0115] Among them, Ai,j and Yi,j correspond to each attribute in the access policy P.

[0116] DO extracts the keyword set in the plaintext M Generates the corresponding index file according to the access policy P, and randomly selects the secret value Uses the keywords in the keyword set as the solutions of the polynomial equation to construct a polynomial of degree l 1 ; Calculate

[0117] According to the access policy P, calculate the corresponding index file, specifically expressed as:

[0118] I 1 = g nkr

[0119] I 2 = N nkr

[0120]

[0121] DO sends the ciphertext and the index file to CS together.

[0122] Step S4: DU generates a trapdoor file:

[0123] DU generates a corresponding trapdoor file according to its own keyword set of interest randomly selects calculates T 2 = sk 1 , sk 1 sk 2 sk 3 sk 4 are the user's own private keys, l 2 is the total number of keyword sets provided by DU, T 4,j is the value that DU first maps each keyword in the keyword set to Zp*, then performs exponentiation on the mapped values of each keyword, and adds the values with the same exponentiation. Generate a trapdoor file, specifically expressed as:

[0124] T = {T 1 , T 2 , T 3 , T 4,j , T 5 , T 6}

[0125] Step S5: Retrieve the ciphertext:

[0126] CS finds the matching ciphertext file through corresponding calculations based on the trapdoor file sent by DU and the index file stored locally.

[0127] CS obtains the corresponding trapdoor file T and ciphertext C and first calculates as follows:

[0128]

[0129] If the left and right sides of the equation are equal, return the corresponding ciphertext to DU.

[0130] Step S6: Decrypt the ciphertext:

[0131] DU decrypts the corresponding ciphertext obtained by retrieval using the private key. The specific steps are as follows:

[0132]

[0133] If the DU attribute meets the requirements, the correct plaintext is output.

[0134] Step S7: Tracking of the secret key and revocation of user permissions:

[0135] When a user's private key is leaked or publicly sold, the algorithm can identify malicious users and revoke their access permissions. The specific process includes two steps: tracking malicious users and revoking user permissions;

[0136] The central authorization center obtains the malicious key, calculates according to the symmetric encryption key, where k is the symmetric key saved by the central authorization center, and finds the corresponding user according to the user's unique uid.

[0137] Add the returned uid to the user revocation list maintained in the cloud server to record users whose access permissions are prohibited.

[0138] In the above embodiments, the reference in the specification to "this embodiment" means that the specific features, structures, or characteristics described in connection with the embodiment are included in at least some embodiments, but not necessarily all embodiments. Multiple occurrences of "this embodiment" do not necessarily all refer to the same embodiment.

[0139] In the above embodiments, although the present invention has been described in connection with specific embodiments of the present invention, many substitutions, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other storage structures (e.g., dynamic RAM (DRAM)) may be used in the embodiments discussed. Embodiments of the present invention are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims.

[0140] This embodiment also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements any one of the methods in this embodiment.

[0141] This embodiment also provides an electronic terminal, including: a processor and a memory;

[0142] The memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory so that the terminal executes any one of the methods in this embodiment.

[0143] For the computer-readable storage medium in this embodiment, those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to the computer program. The foregoing computer program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: various media such as ROM, RAM, magnetic disk, or optical disk that can store program codes.

[0144] The electronic terminal provided in this embodiment includes a processor, a memory, a transceiver, and a communication interface. The memory and the communication interface are connected to the processor and the transceiver and complete communication therebetween. The memory is used to store a computer program, the communication interface is used for communication, and the processor and the transceiver are used to run the computer program so that the electronic terminal executes each step of the above method.

[0145] In this embodiment, the memory may include a random access memory (RAM for short), and may also include a non-volatile memory, such as at least one disk memory.

[0146] The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0147] The present invention can be used in numerous general-purpose or special-purpose computing system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on.

[0148] The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in a distributed computing environment, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0149] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the present technical solution, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A lightweight, searchable, attribute-based encryption method that is traceable by multiple authorities, characterized in that: The following steps are involved: S1: The central authorization center and the attribute authorization agency system are initialized to generate global public parameters and the corresponding system public key and master key; S2: The central authorization center generates a partial key for the user who applied for the key, signs the successfully verified user attribute set, and sends it to the corresponding attribute agency, which then generates an attribute key for it; S3: The data owner encrypts the data file according to the access policy set by the data owner, extracts the keyword set in the data file, generates an index file based on the keyword set, and uploads it to the cloud server together with the encrypted file; S4: The user generates a trapdoor file based on the keyword set of interest and his / her private key; S5: The cloud server performs corresponding calculations based on the received trapdoor file and the locally stored ciphertext file and index file, and returns the encrypted file that has been successfully matched to the user; S6: The user decrypts the encrypted file using his / her private key; S7: The central authorization center tracks the user identity uid through the user private key and maintains a revocation list through the cloud server to disable the corresponding user's permissions.

2. The lightweight searchable attribute-based encryption method with multi-authority traceability according to claim 1, characterized in that: Step S1 specifically includes the following steps: S11: The central authorization center initializes and signs the confirmed user attributes, as follows: The central authority selects two multiplicative cyclic groups G and Gp of the same prime order, where the parameter g is the generator of G, and defines a binary map e:G×G→G on G T , then the central authorization center randomly selects is the ring of integers modulo p; set up is a hash function that maps any binary string to a random element of Zp*; Let H2:{0,1}→G be a hash function that maps any binary string to a random element of group G; set up is a hash function that maps any binary string to a random element of Zp*; The central authorization center is responsible for user registration and attribute authentication; First, the central authorization center generates a pair of signature keys (SigKey, VerKey) for signing and verification, where VerKey is public; The published public keys are as follows: CPK(G,p,g,e,Ng λ ,VerKey) N is part of the public key, g is the generator of the finite cyclic group G, and λ is a parameter randomly selected in Zp*; e(g,g) is a binary mapping, which is a mapping value on a group Gt obtained by inputting two elements on the group G; The central authorization center master key is as follows: CMSK=(λ,SigKey) The master key is kept by the central authorization center and is not disclosed to the public; S12: Initialization of the attribute authority system, specifically including the following steps: Each attribute authority randomly selects i, j indicates that the attribute value is the jth attribute value of the i-th attribute, 1≤i≤n,1≤j≤m; then generate the corresponding key component for each attribute value The published public keys are as follows: APK=(A i,j ,Y i,j )i∈(1,n),j∈(1,m) The attribute authority master key is as follows: AMSK=(a i,j )i∈(1,n),j∈(1,m) The master key is kept separately by each attribute authority and is not disclosed to the public.

3. The lightweight searchable attribute-based encryption method with traceability by multiple authorities according to claim 1, characterized in that: Step S2 specifically includes the following steps: S21: The central authorization center verifies the user attributes and generates a partial key, which specifically includes the following steps: The user initiates a registration application to the central authorization center, which first generates a unique uid for the user, randomly selects a symmetric encryption key k, and calculates sk = Dn k (GID), and then randomly select sk1=b,calculate The central authorization center will sign the verified user attribute set using the signature key SigKey, and send the signed attribute set to the attribute authorization agency with the corresponding attribute generation authority; S22: The attribute authority generates an attribute key for the user, which specifically includes the following steps: The attribute authority uses the signature key VerKey to verify whether it is correct. Each attribute authority generates a private key for the user based on the attribute set that the user has after verification in the system. calculate sk5=g α ; All keys sk={sk,sk1,sk2,{sk 3,i,j ,sk 4,i,j }(1≤i≤n,1≤j≤m),sk5} are returned to the user together.

4. The lightweight searchable attribute-based encryption method with traceability by multiple authorities according to claim 1, characterized in that: The step S3 specifically includes: The data owner completes the encryption of the data himself, according to the access policy P = (p1, p2, ..., p n ), data file M and the public APK and CPK generate corresponding ciphertext; first randomly select calculate Among them A i,j and Y i,j Corresponding to each attribute in the access policy P; The data owner extracts the keyword set in M Generate the corresponding index file according to the access policy P and randomly select the secret value The keywords in the keyword set are used as solutions to the polynomial equation to construct an l1-order polynomial. calculate According to the access policy P, calculate the corresponding index file, I1 = g nkr , I2=N nkr , The data owner uploads the encrypted file and index file C = {C1, C2, C3, I1, I2, I3} to the cloud server.

5. The lightweight searchable attribute-based encryption method with traceability by multiple authorities according to claim 1, characterized in that: Step S4 specifically includes the following steps: Users set keywords based on their interests Generate the corresponding trapdoor file and randomly select calculate T2=sk1, sk1, sk2, sk3, sk4 are the user's own private keys; l2 is the total number of keyword sets provided by the user; T 4,j The user first maps each keyword in the keyword set to a value on Zp*, then performs an exponential operation on the value after each keyword is mapped, and adds the values ​​of the same exponential operation; Generate a trapdoor file, specifically expressed as: <h2 style=";text-align:left;direction:ltr">T = {T1,T2,T3,T<h2 style=";text-align:left;direction:ltr"> 4,j <h2 style=";text-align:left;direction:ltr"> ,T5,T6} Send the trapdoor file to the cloud server.

6. The lightweight searchable attribute-based encryption method with multi-authority traceability according to claim 1, characterized in that: Step S5 specifically includes the following steps: The cloud server finds the matching ciphertext file through corresponding calculations based on the trapdoor file and index file; The cloud server obtains the corresponding trapdoor file T and ciphertext C and first calculates as follows: If the equation holds true, the corresponding encrypted file is returned to the user.

7. The lightweight searchable attribute-based encryption method with multi-authority traceability according to claim 1, characterized in that: Step S6 specifically includes the following steps: The user uses the private key to decrypt the corresponding ciphertext obtained through retrieval. The specific steps are as follows: If the user attributes meet the access policy requirements, the correct data file M is output.

8. The lightweight searchable attribute-based encryption method with multi-authority traceability according to claim 1, characterized in that: Step S7 specifically includes the following steps: When a user's private key is leaked or sold publicly, this method identifies malicious users and revokes their access rights. The specific process includes: Tracking malicious users: The central authorization center obtains the malicious key and calculates uid=De based on the symmetric encryption key k (sk), k is the symmetric key stored by the central authorization center, and the corresponding user is found according to the user's unique uid; Revoke user permissions: Add the returned uid to the user revocation list maintained in the cloud server to record users who are prohibited from access.