Method and system for acquiring plaintext data, storage medium and electronic device
By implementing two-way identity authentication between data producers and data accessors in 5G+ industrial Internet, the problem of low security during data use is solved, and the secure exchange and decryption of data is realized, ensuring the privacy and legal access of data.
Patent Information
- Application Number
- CN202311594545.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-27
AI Technical Summary
In 5G+ industrial Internet, data is less secure during use, and the existing technology lacks an effective data management mechanism, which leads to malicious attackers who may forge false data or steal data.
By implementing two-way identity authentication between the data producer and the data accessor, it is ensured that only the authenticated data producer and the data accessor can exchange data keys, thereby obtaining and decrypting the target data.
It effectively prevents malicious attackers from forging false data and stealing data, improves the security of data during use, and ensures the privacy and legal access of target data.
Smart Images

Figure CN120050050A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communications, and more particularly, to a method and system for obtaining plaintext data, a storage medium, and an electronic device. Background Art
[0002] 5G + Industrial Internet is the foundation of the digital economy. Traditional industrial networks are closed networks, which are difficult to manage a large number of terminal devices and users, and have poor network scalability. After using 5G, industrial networks can conveniently manage a large number of industrial terminal devices and users with the help of 5G network elements. At the same time, users and devices can also conveniently access the industrial Internet through the 5G network. This makes the industrial network change from closed to open, and also enables users and devices to use the industrial network more conveniently, thus greatly improving the production efficiency of the industrial network. In addition, with the help of the storage capacity of 5G, industrial networks can obtain the ability to store a large amount of data at low cost.
[0003] In 5G + Industrial Internet, data producers in industrial networks (hereinafter referred to as "data producers") will store data in the 5G edge cloud (hereinafter referred to as "edge cloud"). Data accessors in industrial networks (hereinafter referred to as "data accessors") then access the data.
[0004] Functions of each entity in the 5G + Industrial Internet data storage service: In the above service, data producers provide industrial data, edge clouds store industrial data, and data accessors use the data.
[0005] In the prior art, edge clouds are often provided by telecommunications operators. When industrial network users use edge clouds to store industrial production data, there will be problems such as malicious attackers forging false data or other users stealing data, thus threatening the normal production process of enterprises, resulting in economic losses, and even legal disputes. That is, in the prior art, the data management mechanism is not perfect, resulting in low data security during use and other problems.
[0006] In view of the above problems, no effective solution has been proposed in the prior art. Summary of the Invention
[0007] The embodiments of the present application provide a method and system for obtaining plaintext data, a storage medium, and an electronic device, so as to at least solve the problems in the related art that the data management mechanism is not perfect, resulting in low data security during use and other problems.
[0008] According to an embodiment of the present application, a method for obtaining plaintext data is provided, which is applied to a data producer and includes: performing a first identity authentication on a data access party; and receiving an authentication result of a second identity authentication performed by the data access party on the data producer; when it is determined that the first identity authentication is passed and the second identity authentication is passed according to the authentication result of the second identity authentication, authorizing the data access party to obtain target data generated by the data producer, and sending a data key to the data access party, where the data key is used to decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data when the data access party obtains the target data.
[0009] In an exemplary embodiment, performing a first identity authentication on a data access party includes: generating a first parameter according to a randomly generated first random number and a first session key, and generating a second parameter according to the first random number; sending the first parameter and the second parameter to the data access party to instruct the data access party to determine a second session key according to the first parameter and the second parameter; receiving a second random number and a second digital signature sent by the data access party, where the second random number is randomly generated by the data access party, and the second digital signature is a digital signature obtained by the data access party signing the second session key based on the second random number; performing a first identity authentication on the data access party according to the second random number and the second digital signature.
[0010] In an exemplary embodiment, determining a first identity authentication of the data access party according to the second random number and the second digital signature includes: signing the first session key based on the second random number to obtain a first digital signature; when the first digital signature is consistent with the second digital signature, determining that the identity authentication of the data access party is passed; when the first digital signature is inconsistent with the second digital signature, determining that the identity authentication of the data access party is not passed.
[0011] In an exemplary embodiment, generating a first parameter according to a randomly generated first random number and a first session key includes: determining the first parameter T through the following formula 1 : ID v is the identification information of the data access party, pk b is the public key of the authentication server corresponding to the data producer, r 1 is the first random number, k 1 is the first session key.
[0012] In an exemplary embodiment, generating a second parameter according to the first random number includes: determining the second parameter R through the following formula 1 : where G is the group of the authentication server corresponding to the data access party, r 1 is the first random number, and g is the generator of the group.
[0013] In an exemplary embodiment, before authorizing the data access party to obtain the target data generated by the data producer, the method further includes: receiving the ciphertext data of the attribute value of the data access party and the third digital signature corresponding to the attribute value; decrypting the ciphertext data of the attribute value with a randomly generated first session key to obtain the plaintext data of the attribute value; signing the plaintext data of the attribute value based on the first session key to obtain a fourth digital signature; and determining whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of verifying the third digital signature with the fourth digital signature.
[0014] In an exemplary embodiment, determining whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of verifying the third digital signature with the fourth digital signature includes: when the verification result indicates that the fourth digital signature is consistent with the third digital signature, determining that the third digital signature verification passes and authorizing the data access party to obtain the target data generated by the data producer; when the verification result indicates that the fourth digital signature is inconsistent with the third digital signature, determining that the third digital signature verification fails and prohibiting authorizing the data access party to obtain the target data generated by the data producer.
[0015] In an exemplary embodiment, authorizing the data access party to obtain the target data generated by the data producer includes: determining the attribute information of the data access party according to the plaintext data of the attribute value; determining whether the data access party meets the access conditions according to the attribute information; and when the data access party meets the access conditions, authorizing the data access party to obtain the target data generated by the data producer.
[0016] In an exemplary embodiment, sending a data key to the data access party includes: encrypting the plaintext data of the data key to determine the ciphertext data of the data key; and signing the plaintext data of the data key based on a randomly generated first session key to obtain a fifth digital signature; and sending the ciphertext data of the data key and the fifth digital signature to the data access party to instruct the data access party to verify the plaintext data of the data key according to the ciphertext data of the data key and the fifth digital signature.
[0017] In an exemplary embodiment, before performing the first authentication on the data access party, the method further includes: encrypting the plaintext data of the target data according to the plaintext data of the data key to obtain the ciphertext data of the target data; and signing the plaintext data of the target data based on the plaintext data of the data key to obtain a seventh digital signature; and sending the ciphertext data of the target data and the seventh digital signature to the cloud server.
[0018] According to another embodiment of the present invention, there is provided a method for obtaining plaintext data, which is applied to a data access party and includes: performing a second authentication on the data producer and receiving the authentication result of the second authentication performed by the data producer on the data access party; determining whether the data producer authorizes the data access party to obtain the target data generated by the data producer when it is determined that the second authentication is passed and the first authentication is passed according to the authentication result of the first authentication; receiving the data key sent by the data producer when the data producer authorizes the data access party to obtain the target data generated by the data producer; and decrypting the target data according to the data key to obtain the plaintext data corresponding to the target data when the target data is obtained.
[0019] In an exemplary embodiment, performing a second authentication on the data producer includes: determining a second session key according to a first parameter and a second parameter sent by the data producer, where the first parameter is generated by the data producer according to a randomly generated first random number and a first session key, and the second parameter is generated by the data producer according to the first random number; signing the second session key based on a randomly generated second random number to obtain a second digital signature corresponding to the second session key, and sending the second random number and the second digital signature to the data producer to instruct the data producer to perform a first authentication on the data access party according to the second random number and the second digital signature; and determining the authentication result of the second authentication according to the authentication result of the first authentication.
[0020] In an exemplary embodiment, determining the authentication result of the second authentication according to the authentication result of the first authentication includes: determining that the second authentication is passed when the first authentication is passed; and determining that the second authentication is not passed when the first authentication is not passed.
[0021] In an exemplary embodiment, determining a second session key according to a first parameter and a second parameter sent by the data producer includes: determining the second session key k through the following formula2 : Wherein, Sk b is the private key of the authentication server corresponding to the data access party, T 1 is the first parameter, and R 1 is the second parameter.
[0022] In an exemplary embodiment, before determining whether the data producer authorizes the data access party to obtain the target data generated by the data producer, the method further includes: encrypting the plaintext data of the attribute value of the data access party according to the first session key randomly generated by the data producer to obtain the ciphertext data of the attribute value; and signing the plaintext data of the attribute value based on the first session key to obtain a third digital signature; sending the ciphertext data of the attribute value and the third digital signature to the data producer to instruct the data producer to determine whether to authorize the data access party to obtain the target data generated by the data producer according to the ciphertext data of the attribute value and the third digital signature.
[0023] In an exemplary embodiment, after receiving the data key sent by the data producer, the method further includes: receiving the ciphertext data of the data key sent by the data producer and the fifth digital signature corresponding to the data key; decrypting the ciphertext data of the data key according to the first session key randomly generated by the data producer to obtain the plaintext data of the data key; signing the plaintext data of the data key based on the first session key to obtain a sixth digital signature; and determining that the verification of the plaintext data of the data key passes when the sixth digital signature is consistent with the fifth data signature.
[0024] In an exemplary embodiment, after decrypting the target data according to the data key to obtain the plaintext data corresponding to the target data, the method further includes: obtaining the seventh digital signature corresponding to the target data on the cloud server; signing the plaintext data of the target data based on the plaintext data of the data key to obtain an eighth digital signature; and determining that the verification of the plaintext data of the target data passes when the seventh digital signature is consistent with the eighth data signature.
[0025] According to another embodiment of the present invention, a system for obtaining plaintext data is provided, including: a data producer, and a data access party connected to the data producer, wherein the data producer is configured to perform a first identity authentication on the data access party and send an authentication result of the first identity authentication to the data access party; the data access party is configured to perform a second identity authentication on the data producer and send an authentication result of the second identity authentication to the data producer; the data producer is further configured to authorize the data access party to obtain target data generated by the data producer and send a data key to the data access party when it is determined that the first identity authentication is passed and the second identity authentication is passed according to the authentication result of the second identity authentication; the data access party is further configured to decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data when the data producer authorizes the data access party to obtain the target data.
[0026] According to still another embodiment of the present application, a computer-readable storage medium is further provided. A computer program is stored in the computer-readable storage medium, wherein the computer program is configured to execute the steps in any one of the above method embodiments when running.
[0027] According to still another embodiment of the present application, an electronic device is further provided, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0028] Through the present application, since the data access party and the data producer in the present application need to perform two-way identity authentication, only the authenticated data producer can provide the key of the target data, preventing malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, preventing malicious attackers from impersonating legitimate data access parties to steal the target data; the data producer in the present application authorizes the data access party, and only the authorized data access party can decrypt to obtain the target data, preventing malicious attackers from stealing the target data, and the data producer encrypts the target data to ensure the privacy of the target data, solving the problems in the prior art that the data management mechanism is not perfect enough, resulting in low security during the use of data. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of the present application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0030] Figure 1It is a hardware structure block diagram of a computer terminal for a method of obtaining plaintext data according to an embodiment of the present invention;
[0031] Figure 2 It is a flowchart (I) of a method of obtaining plaintext data according to an embodiment of the present invention;
[0032] Figure 3 It is a flowchart (II) of a method of obtaining plaintext data according to an embodiment of the present invention;
[0033] Figure 4 It is a timing diagram of a method of obtaining plaintext data according to an embodiment of the present invention;
[0034] Figure 5 It is a system block diagram of a method of obtaining plaintext data according to an embodiment of the present invention;
[0035] Figure 6 It is a structure block diagram of a plaintext data acquisition system according to an embodiment of the present invention. Detailed implementation manners
[0036] In the following, embodiments of the present application will be described in detail with reference to the accompanying drawings and in combination with embodiments.
[0037] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence.
[0038] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 It is a hardware structure block diagram of a computer terminal for a method of obtaining plaintext data according to an embodiment of the present application. As Figure 1 shown, the computer terminal may include one or more ( Figure 1 only one is shown in Figure 1 a processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor (Central Processing Unit, MCU) or a field programmable gate array (Field Programmable Gate Array, FPGA)) and a memory 104 for storing data. Among them, the above-mentioned computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown in Figure 1 is only schematic and does not limit the structure of the above-mentioned computer terminal. For example, the computer terminal may further include more or fewer components than
[0039] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the method for obtaining plaintext data in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, the above-mentioned method is implemented. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0040] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of the computer terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (Radio Frequency, abbreviated as RF) module, which is used to communicate with the Internet wirelessly.
[0041] In this embodiment, a method for obtaining plaintext data running on the above computer terminal is provided. Specifically, the computer terminal is a data producer. Figure 2 It is a flowchart of the method for obtaining plaintext data according to the embodiments of the present application, as Figure 2 shown, and this process includes the following steps:
[0042] Step S202, perform a first identity authentication on the data access party, and receive the authentication result of the second identity authentication performed by the data access party on the data producer;
[0043] Step S204, when it is determined that the first identity authentication is passed and the second identity authentication is passed according to the authentication result of the second identity authentication, authorize the data access party to obtain the target data generated by the data producer, and send a data key to the data access party, where the data key is used to decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data when the data access party obtains the target data.
[0044] Through the above steps, since two-way authentication is required between the data access party and the data production party in this application, only the authenticated data production party can provide the key of the target data, preventing malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, preventing malicious attackers from impersonating legitimate data access parties to steal the target data; the data production party in this application authorizes the data access party, and only the authorized data access party can decrypt to obtain the target data, preventing malicious attackers from stealing the target data, and the data production party encrypts the target data to ensure the privacy of the target data, solving the problems in the prior art that the data management mechanism is not perfect enough, resulting in low security during the use of data, etc.
[0045] Optionally, the specific implementation manner of the above step S202 is as follows:
[0046] Step S2021: Generate a first parameter according to a randomly generated first random number and a first session key, and generate a second parameter according to the first random number;
[0047] Specifically, the first parameter T is determined by the following formula 1 : ID v is the identification information of the data access party, pk b is the public key of the authentication server corresponding to the data production party, r 1 is the first random number, k 1 is the first session key.
[0048] It should be noted that both h(x) and H(x) above are hash functions, and e(x,x) is the calculation formula of the bilinear pair.
[0049] Furthermore, in the initialization stage, the authentication server in the embodiment of this application will generate a group G with order p and generator g. The authentication server generates its own private key sk a ∈Z p and sk b ∈Z p , and generate the corresponding public keys and where, Z p is a positive integer less than p;
[0050] For the data production party ID prod ∈{0, 1} n , the authentication server calculates
[0051] For the data access party ID v ∈{0, 1} n , the authentication server calculates
[0052] The second parameter R is determined by the following formula 1 : G is the group of the authentication server corresponding to the data access party, r 1 is the first random number, and g is the generator of the group.
[0053] Step S2022: Send the first parameter and the second parameter to the data access party to instruct the data access party to determine a second session key according to the first parameter and the second parameter;
[0054] In the embodiment of the present application, the data access party determines the second session key according to the first parameter and the second parameter sent by the data producer, signs the second session key based on the randomly generated second random number to obtain a second digital signature corresponding to the second session key, and sends the second random number and the second digital signature to the data producer.
[0055] Further, the data access party determines the second session key k according to the following formula 2 :
[0056] where Sk b is the private key of the authentication server corresponding to the data access party, T 1 is the first parameter, and R 1 is the second parameter.
[0057] The second session key is signed by the following formula to obtain a second digital signature σ corresponding to the second session key M :
[0058] σ M = h(M, k 2 ); where k 2 is the second session key, M is the second random number, and σ M is the second digital signature.
[0059] It should be noted that, in the case that there is no error in the transmission of the first parameter and the second parameter, the second session key calculated by the data access party is the same as the first session key randomly generated by the data producer.
[0060] Step S2023: Receive the second random number and the second digital signature sent by the data access party, where the second random number is randomly generated by the data access party, and the second digital signature is obtained by the data access party signing the second session key based on the second random number;
[0061] Step S2024: Perform first authentication on the data access party according to the second random number and the second digital signature.
[0062] Specifically: Sign the first session key based on the second random number to obtain a first digital signature; when the first digital signature is consistent with the second digital signature, determine that the authentication of the data access party passes; when the first digital signature is inconsistent with the second digital signature, determine that the authentication of the data access party fails.
[0063] When the data producer receives M and σ M the data producer also signs the first session key k 1 based on M to obtain where Verify If determine that the authentication of the data access party passes; if determine that the authentication of the data access party fails.
[0064] Before the data producer authorizes the data access party, it is also necessary to verify the attribute information of the data access party. The specific verification method is as follows:
[0065] Receive the ciphertext data of the attribute value of the data access party and the third digital signature corresponding to the attribute value; decrypt the ciphertext data of the attribute value according to the randomly generated first session key to obtain the plaintext data of the attribute value; sign the plaintext data of the attribute value based on the first session key to obtain a fourth digital signature; determine whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of verifying the third digital signature with the fourth digital signature.
[0066] Specifically, when the verification result indicates that the fourth digital signature is consistent with the third digital signature, determine that the verification of the third digital signature passes, and authorize the data access party to obtain the target data generated by the data producer; when the verification result indicates that the fourth digital signature is inconsistent with the third digital signature, determine that the verification of the third digital signature fails, and prohibit authorizing the data access party to obtain the target data generated by the data producer.
[0067] In addition, determine the attribute information of the data access party according to the plaintext data of the attribute value; determine whether the data access party meets the access conditions according to the attribute information; when the data access party meets the access conditions, authorize the data access party to obtain the target data generated by the data producer.
[0068] That is, the data access party uses the first session key k obtained in the authentication phase 1 to encrypt the attribute information A of the data access party to obtain ciphertext data C A = Enc k (A), and generate a third digital signature σ A1 = h(A, k 1 ). The data access party sends the generated ciphertext data C A and the third digital signature σ A1 to the data producer; after receiving the ciphertext data C A and the third digital signature σ A1 , the data producer decrypts to obtain the plaintext data A of the attribute information A = Dec k (C A ). Then, according to the session key k 1 , the data producer digitally signs the attribute information A of the data access party to obtain a fourth digital signature σ A2 ; verify σ A1 ? = v A2 . If the equation holds, the verification passes; the data producer checks whether the attribute information A of the data access party meets the access conditions. If the attribute information A meets the access conditions, the data access party is authorized to obtain the target data generated by the data producer; otherwise, the data access party is refused to obtain the target data generated by the data producer.
[0069] According to the above embodiments, only data access parties that meet specific attribute information can be authorized to access the target data, implementing an attribute encryption mechanism.
[0070] After authorizing the data access party to obtain the target data generated by the data producer, the data producer sends a data key to the data access party in the following specific manner:
[0071] Encrypt the plaintext data of the data key to determine the ciphertext data of the data key; and, sign the plaintext data of the data key based on a randomly generated first session key to obtain a fifth digital signature; send the ciphertext data of the data key and the fifth digital signature to the data access party to instruct the data access party to verify the plaintext data of the data key according to the ciphertext data of the data key and the fifth digital signature.
[0072] That is, calculate the ciphertext data of the data key and the fifth digital signature where k F is the plaintext data of the data key, and k 1 is the first session key; send the generated and to the data access party.
[0073] The data access party receives the ciphertext data of the data key sent by the data producer and the fifth digital signature corresponding to the data key According to the first session key k randomly generated by the data producer 1 Decrypt the ciphertext data of the data key to obtain the plaintext data k of the data key F , where Sign the plaintext data of the data key based on the first session key to obtain a sixth digital signature, where In the sixth digital signature Consistent with the fifth data signature In the case of consistency, it is determined that the verification of the plaintext data of the data key passes
[0074] Optionally, before performing the first identity authentication on the data access party, the data producer also needs to send the target data to the edge cloud. Specifically: Encrypt the plaintext data of the target data according to the plaintext data of the data key to obtain the ciphertext data of the target data; and, Sign the plaintext data of the target data based on the plaintext data of the data key to obtain a seventh digital signature; Send the ciphertext data of the target data and the seventh digital signature to the cloud server
[0075] For the target data F to be uploaded, the data producer randomly generates a data key k F ∈Z p , then calculate the seventh digital signature σ of the plaintext data of the target data F =h(F,k F ); The data producer uses a symmetric encryption algorithm (exemplarily, AES) to encrypt the target data F to obtain ciphertext data The data producer uploads the ciphertext data C F and the seventh digital signature σ F to the cloud server
[0076] In the embodiment of the present application, the data producer encrypts the target data, ensuring the privacy of the target data
[0077] Furthermore, in this embodiment, a method for obtaining plaintext data running on the above computer terminal is also provided. Specifically, the computer terminal is the data access party Figure 3 is the flowchart of the method for obtaining plaintext data according to the embodiment of the present application, as Figure 3 shown, and this process includes the following steps
[0078] Step S302: Conduct a second identity authentication on the data producer and receive the identity authentication result of the second identity authentication performed by the data producer on the data access party.
[0079] Step S304: When it is determined that the second identity authentication is passed and the first identity authentication is passed according to the authentication result of the first identity authentication, determine whether the data producer authorizes the data access party to obtain the target data generated by the data producer.
[0080] Step S306: When the data producer authorizes the data access party to obtain the target data generated by the data producer, receive the data key sent by the data producer.
[0081] Step S308: When the target data is obtained, decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data.
[0082] Through the above steps, since the data access party and the data producer in the present application need to conduct two-way identity authentication, only the authenticated data producer can provide the key of the target data, preventing malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, preventing malicious attackers from impersonating legitimate data access parties to steal the target data; the data producer in the present application authorizes the data access party, and only the authorized data access party can decrypt to obtain the target data, preventing malicious attackers from stealing the target data, and the data producer encrypts the target data, ensuring the privacy of the target data, and solving the problems in the prior art that the data management mechanism is not perfect enough, resulting in low security during data use.
[0083] In an exemplary embodiment, conducting a second identity authentication on the data producer includes: determining a second session key according to the first parameter and the second parameter sent by the data producer, where the first parameter is generated by the data producer according to a randomly generated first random number and a first session key, and the second parameter is generated by the data producer according to the first random number; signing the second session key based on a randomly generated second random number to obtain a second digital signature corresponding to the second session key, and sending the second random number and the second digital signature to the data producer to instruct the data producer to conduct a first identity authentication on the data access party according to the second random number and the second digital signature; determining the authentication result of the second identity authentication according to the authentication result of the first identity authentication.
[0084] In an exemplary embodiment, determining the authentication result of the second identity authentication according to the authentication result of the first identity authentication includes: determining that the second identity authentication is passed when the first identity authentication is passed; determining that the second identity authentication is not passed when the first identity authentication is not passed.
[0085] In an exemplary embodiment, determining a second session key according to a first parameter and a second parameter sent by a data producer includes: determining the second session key k through the following formula 2 : where Sk b is the private key of the authentication server corresponding to the data access party, T 1 is the first parameter, and R 1 is the second parameter.
[0086] In an exemplary embodiment, before determining whether the data producer authorizes the data access party to obtain the target data generated by the data producer, the method further includes: encrypting the plaintext data of the attribute value of the data access party with a first session key randomly generated by the data producer to obtain the ciphertext data of the attribute value; and signing the plaintext data of the attribute value based on the first session key to obtain a third digital signature; sending the ciphertext data of the attribute value and the third digital signature to the data producer to instruct the data producer to determine whether to authorize the data access party to obtain the target data generated by the data producer according to the ciphertext data of the attribute value and the third digital signature.
[0087] In an exemplary embodiment, after receiving the data key sent by the data producer, the method further includes: receiving the ciphertext data of the data key sent by the data producer and the fifth digital signature corresponding to the data key; decrypting the ciphertext data of the data key with a first session key randomly generated by the data producer to obtain the plaintext data of the data key; signing the plaintext data of the data key based on the first session key to obtain a sixth digital signature; determining that the verification of the plaintext data of the data key is passed when the sixth digital signature is consistent with the fifth data signature.
[0088] In an exemplary embodiment, after decrypting the target data with the data key to obtain the plaintext data corresponding to the target data, the method further includes: obtaining a seventh digital signature corresponding to the target data on a cloud server; signing the plaintext data of the target data based on the plaintext data of the data key to obtain an eighth digital signature; determining that the verification of the plaintext data of the target data is passed when the seventh digital signature is consistent with the eighth data signature.
[0089] To better understand the process of the above method for obtaining plaintext data, the following further describes the process flow of the method for obtaining plaintext data in combination with optional embodiments, but it is not used to limit the technical solutions of the embodiments of the present application.
[0090] In an exemplary embodiment, a system framework diagram of a method for obtaining plaintext data is provided. Figure 4 It is a system framework diagram of the method for obtaining plaintext data according to the embodiments of the present application. As Figure 4 shown, the system of this embodiment includes:
[0091] An authentication server, a data producer and a data access party connected to the authentication server, and an edge cloud connected to the data producer and the data access party, wherein the data producer and the data access party have a connection relationship.
[0092] The authentication server is used to generate a public key and a private key of the authentication server. The authentication server holds the private key and discloses the public key to the data producer and the data access party. For the data producer and the data access party, the authentication server generates a private key for each of the data producer and the data access party;
[0093] The data producer is used to send the encrypted target data to the edge cloud, authenticate the identity of the data access party, and determine whether to authorize the data access party to obtain the target data generated by the data producer;
[0094] The data access party is used to authenticate the identity of the data producer, and in the case where the data producer authorizes the data access party to obtain the target data generated by the data producer, obtain the target data in the edge cloud;
[0095] The edge cloud is used to store the encrypted target data.
[0096] Specifically, the specific operation processes of the authentication server, the data producer, the data access party and the edge cloud in the above system are as Figure 5 shown, Figure 5 It is a schematic diagram of the method for obtaining plaintext data according to the embodiments of the present application. This embodiment altogether includes five stages: initialization, data upload, authentication, authorization and access control, and data download. The specific steps are as follows:
[0097] 1. In the initialization stage, the authentication server generates a public key and a private key of the authentication server according to the following steps. The authentication server holds the private key and discloses the public key. For the data producer and the data access party, the authentication server generates a private key for each of the data producer and the data access party respectively:
[0098] Step S401: The authentication server generates a group G with order p and a generator g;
[0099] Step S402: Generate the private key sk of the authentication server a ∈Z p and sk b ∈Z p ;
[0100] Step S403: The authentication server generates the corresponding public key and
[0101] Step S404: For the data producer ID prod ∈{0,1} n , the authentication server generates
[0102] Step S405: For the data accessor ID v ∈{0,1} n , the authentication server generates
[0103] 2. In the data upload stage of the data producer, the data producer uses the DupSys algorithm to encrypt the data and generate a signature. Specifically:
[0104] Step S501: For the target data F to be uploaded, the data producer randomly generates a number k F ∈Z p , and calculates the digital signature v of the plaintext data of the target data F =h(F,k F ).
[0105] Step S502: The data producer uses a symmetric encryption algorithm (such as AES) to encrypt the target data F to obtain the ciphertext data
[0106] Step S503: The data producer uploads the ciphertext data C F and the digital signature σ F to the edge cloud (equivalent to the cloud server in the above embodiment).
[0107] 3. In the stage of mutual authentication between the data producer and the data accessor, the data producer and the data accessor use the authentication algorithm to complete mutual authentication. Specifically:
[0108] Step S601: The data producer randomly generates r 1 ∈Z p and k 1 ∈Z p , calculates and and sends R 1 and T 1Send to the data access party.
[0109] Step S602: The data access party calculates and randomly generates M ∈ Z p , calculates σ M = h(M, k), and sends M and σ M to the data producer.
[0110] Step S603: The data producer verifies σ M ? = h(M, k 1 ). If the equation holds, then the two-way authentication between the data producer and the data access party passes; if the equation does not hold, then the two-way authentication between the data producer and the data access party fails.
[0111] 4. In the stage where the data producer authorizes the data access party to obtain the target data, the data producer completes the authorization through the authorization and access control algorithm. Specifically:
[0112] Step S701: The data access party uses the session key k obtained in the authentication stage 1 to encrypt the attribute value A of the data access party to obtain the ciphertext data C A = Enc k (A), and generates a digital signature σ A = h(A, k 1 ). The data access party sends the generated ciphertext data C A and the digital signature σ A to the data producer.
[0113] Step S702: After receiving the ciphertext data C A and the digital signature σ A , the data producer decrypts to obtain the plaintext data A = Dec k (C A ). Then it verifies σ A ? = h(A, k 1 ). If the equation holds, then the verification passes; if the equation does not hold, the data producer refuses to authorize the data access party to obtain the target data.
[0114] Step S703: The data producer checks the attribute value A of the data access party. If the requirements are met, the data producer authorizes the data access party to obtain the target data and calculates the ciphertext data and the digital signature and sends and to the data access party.
[0115] Step S704: The data access party decrypts to obtain the data key of the target data F and verifies If the equation holds, the verification passes. The data access party obtains the permission to access the target data F.
[0116] 5. In the stage where the data access party downloads the target data from the edge cloud, the data producer uses the DdlSys algorithm to decrypt the data and verify the signature. Specifically:
[0117] Step S801: The data access party downloads the ciphertext data C F and the digital signature σ F .
[0118] Step S802: The data access party uses a symmetric encryption algorithm (such as AES) to decrypt the target data F to obtain the plaintext data
[0119] Step S803: The data access party verifies σ F ? = h(F, k F ). If the equation holds, it is determined that the target data F has not been tampered with by the attacker.
[0120] Under the background of 5G + industrial Internet, the embodiments of this application have the following advantages:
[0121] First, only the authorized data access party can decrypt to obtain the target data, preventing illegal attackers from stealing the target data.
[0122] Second, the data producer encrypts the target data, ensuring the privacy of the target data.
[0123] Third, only the data access party that meets specific attributes can decrypt the target data, implementing the attribute encryption mechanism.
[0124] Fourth, only the authenticated data producer can provide the file decryption key, preventing malicious attackers from forging false data.
[0125] Fifth, only the authenticated data access party can obtain the file decryption key, preventing malicious attackers from impersonating legitimate data access parties to steal the target data.
[0126] Sixth, this application only uses bilinear and modular exponentiation operations in the authentication process, and lightweight cryptographic algorithms are used when processing a large amount of data. Therefore, it has high efficiency.
[0127] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as Read-Only Memory / Random Access Memory, ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.
[0128] In this embodiment, a system for obtaining plaintext data is further provided. This system is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0129] Figure 6 is a structural block diagram of the system for obtaining plaintext data according to an embodiment of the present application. As Figure 6 shown, the system includes a data producer 62 and a data accessor 64 connected to the data producer. Among them,
[0130] The data producer 62 is used to perform a first identity authentication on the data accessor 64 and send the authentication result of the first identity authentication to the data accessor; the data accessor 64 is used to perform a second identity authentication on the data producer 62 and send the authentication result of the second identity authentication to the data producer; the data producer 62 is further used to, when determining that the first identity authentication is passed and the second identity authentication is passed according to the authentication result of the second identity authentication, authorize the data accessor 64 to obtain the target data generated by the data producer 62 and send a data key to the data accessor 64; the data accessor 64 is further used to, when the data producer 62 authorizes the data accessor 64 to obtain the target data, decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data.
[0131] Through the above system, since the data access party and the data production party in this application need to perform two-way identity authentication, only the authenticated data production party can provide the key of the target data, preventing malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, preventing malicious attackers from impersonating legitimate data access parties to steal the target data; the data production party in this application authorizes the data access party, and only the authorized data access party can decrypt to obtain the target data, preventing malicious attackers from stealing the target data, and the data production party encrypts the target data, ensuring the privacy of the target data, and solving the problems in the prior art that the data management mechanism is not perfect enough, resulting in low security during the use of data.
[0132] In an exemplary embodiment, the data production party is further configured to randomly generate a first random number and generate a first session key; generate a first parameter according to the first session key and the first random number, and generate a second parameter according to the first random number; send the first parameter and the second parameter to the data access party;
[0133] The data access party is further configured to determine a second session key according to the first parameter and the second parameter, and randomly generate a third random number; sign the second session key based on the third random number to obtain a second digital signature corresponding to the second session key, and send the third random number and the second digital signature to the data production party.
[0134] In an exemplary embodiment, the data production party is further configured to determine a verification result for authenticating the data access party according to the third random number and the second digital signature;
[0135] The data access party is further configured to determine a verification result for authenticating the data production party according to the verification result of the data production party for authenticating the data access party.
[0136] In an exemplary embodiment, the data production party is further configured to sign the first session key based on the third random number to obtain a first digital signature;
[0137] In the case where the first digital signature is consistent with the second digital signature, it is determined that the authentication of the data access party passes;
[0138] In the case where the first digital signature is inconsistent with the second digital signature, it is determined that the authentication of the data access party fails.
[0139] In an exemplary embodiment, the data access party is further configured to determine that the authentication of the data production party is passed when the data production party determines that the authentication of the data access party is passed;
[0140] In the case where the data production party determines that the authentication of the data access party fails, it is determined that the authentication of the data production party fails.
[0141] In an exemplary embodiment, the data production party is further configured to determine the first parameter T through the following formula 1 :
[0142] ID v is the identification information of the data access party, pk b is the public key of the authentication server corresponding to the data production party, r 1 is the first random number, k 1 is the first session key.
[0143] In an exemplary embodiment, the data production party is further configured to determine the second parameter R through the following formula 1 :
[0144] G is the group of the authentication server corresponding to the data access party, r 1 is the first random number, and g is the generator of the group.
[0145] In an exemplary embodiment, the data access party is further configured to determine the second session key k through the following formula 2 :
[0146] Wherein, Sk b is the private key of the authentication server corresponding to the data access party, T 1 is the first parameter, and R 1 is the second parameter.
[0147] In an exemplary embodiment, the data access party is further configured to encrypt the plaintext of the attribute value of the data access party according to the first session key to obtain the ciphertext of the attribute value; and sign the plaintext of the attribute value based on the first session key to obtain the third digital signature; send the ciphertext of the attribute value and the third digital signature to the data production party, wherein the first session key is generated by the data production party;
[0148] The data producer is further configured to decrypt the ciphertext of the attribute value according to the first session key to obtain the plaintext of the attribute value; sign the plaintext of the attribute value based on the first session key to obtain a fourth digital signature; verify the third digital signature according to the fourth digital signature; and determine whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of the verification of the third digital signature.
[0149] In an exemplary embodiment, the data producer is further configured to, when the fourth digital signature is consistent with the third digital signature, determine that the verification of the third digital signature passes, and authorize the data access party to obtain the target data generated by the data producer;
[0150] In the case where the fourth digital signature is inconsistent with the third digital signature, determine that the verification of the third digital signature fails, and prohibit authorizing the data access party to obtain the target data generated by the data producer.
[0151] In an exemplary embodiment, the data producer is further configured to determine the attribute information of the data access party according to the plaintext of the attribute value; and determine whether the data access party meets the access conditions according to the attribute information;
[0152] When the data access party meets the access conditions and the fourth digital signature is consistent with the third digital signature, authorize the data access party to obtain the target data generated by the data producer;
[0153] In the case where the data access party does not meet the access conditions and / or the fourth digital signature is inconsistent with the third digital signature, prohibit authorizing the data access party to obtain the target data generated by the data producer.
[0154] In an exemplary embodiment, the data producer is further configured to encrypt the plaintext of the data key to determine the ciphertext of the data key, and sign the plaintext of the data key based on the first session key generated by the data producer to obtain a fifth digital signature; and send the ciphertext of the data key and the fifth digital signature to the data access party.
[0155] In an exemplary embodiment, the data access party is further configured to decrypt the ciphertext of the data key to determine the plaintext of the data key, and sign the plaintext of the data key based on the first session key generated by the data producer to obtain a sixth digital signature; and when the sixth digital signature is consistent with the fifth data signature, determine that the verification of the plaintext of the data key passes.
[0156] In an exemplary embodiment, the data access party is further configured to obtain a seventh digital signature of the target data on the cloud server, and sign the plaintext of the target data based on the plaintext of the data key to obtain an eighth digital signature; when the seventh digital signature is consistent with the eighth digital signature, it is determined that the verification of the plaintext of the target data passes.
[0157] In an exemplary embodiment, the data producer is further configured to encrypt the plaintext of the target data according to the plaintext of the data key to obtain the ciphertext of the target data, and sign the plaintext of the target data based on the plaintext of the data key to obtain a seventh digital signature; send the ciphertext of the target data and the seventh digital signature to the cloud server.
[0158] It should be noted that the above-mentioned respective modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited thereto: the above-mentioned modules are all located in the same processor; or, the above-mentioned respective modules are separately located in different processors in any combination.
[0159] For the convenience of understanding the technical solution provided by the present application, the following will elaborate in detail with reference to the embodiments of specific scenarios.
[0160] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, and wherein the computer program is configured to execute the steps in any one of the above method embodiments when running.
[0161] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: USB flash drive, read-only memory (ROM for short), random access memory (RAM for short), mobile hard disk, magnetic disk or optical disc, etc., various media that can store computer programs.
[0162] An embodiment of the present application further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0163] In an exemplary embodiment, the above electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the above processor, and the input / output device is connected to the above processor.
[0164] The specific examples in this embodiment may refer to the examples described in the above embodiments and exemplary embodiments, and will not be elaborated herein again.
[0165] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present application can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a sequence different from that here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the present application is not limited to any specific combination of hardware and software.
[0166] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for obtaining plaintext data, characterized in that, applied to the data producer, including: performing a first identity authentication on the data access party and receiving the authentication result of the second identity authentication performed by the data access party on the data producer; when it is determined that the first identity authentication is passed and the second identity authentication is passed according to the authentication result of the second identity authentication, authorizing the data access party to obtain the target data generated by the data producer and sending a data key to the data access party, where the data key is used to decrypt the target data based on the data key to obtain the plaintext data corresponding to the target data when the data access party obtains the target data.
2. The method according to claim 1, characterized in that, performing a first identity authentication on the data access party includes: generating a first parameter according to a randomly generated first random number and a first session key, and generating a second parameter according to the first random number; sending the first parameter and the second parameter to the data access party to instruct the data access party to determine a second session key according to the first parameter and the second parameter; receiving a second random number and a second digital signature sent by the data access party, where the second random number is randomly generated by the data access party, and the second data signature is a signature obtained by the data access party signing the second session key based on the second random number; performing a first identity authentication on the data access party according to the second random number and the second digital signature.
3. The method according to claim 2, characterized in that, determining to perform a first identity authentication on the data access party according to the second random number and the second digital signature includes: signing the first session key based on the second random number to obtain a first digital signature; when the first digital signature is consistent with the second digital signature, determining that the identity authentication of the data access party is passed; when the first digital signature is inconsistent with the second digital signature, determining that the identity authentication of the data access party fails.
4. The method according to claim 2, characterized in that, generating a first parameter according to a randomly generated first random number and a first session key includes: The first parameter T is determined by the following formula 1 :[[]]END]] ID v is the identification information of the data access party, pk b is the public key of the authentication server corresponding to the data producer, r 1 is the first random number, k 1 is the first session key.
5. The method according to claim 2, characterized in that, generating a second parameter according to the first random number includes: The second parameter R is determined by the following formula 1 :[[]]END]] Let \(G\) be the group of the authentication servers corresponding to the data access party, \(r\) 1 be the first random number, and \(g\) be the generator of the group.
6. The method according to claim 1, characterized in that, before authorizing the data access party to obtain the target data generated by the data producer, the method further includes: receiving the ciphertext data of the attribute value of the data access party and the third digital signature corresponding to the attribute value; decrypting the ciphertext data of the attribute value according to a randomly generated first session key to obtain the plaintext data of the attribute value; signing the plaintext data of the attribute value based on the first session key to obtain a fourth digital signature; determining whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of verifying the third digital signature according to the fourth digital signature.
7. The method according to claim 6, wherein, determining whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of verifying the third digital signature according to the fourth digital signature includes: when the verification result indicates that the fourth digital signature is consistent with the third digital signature, determining that the verification of the third digital signature passes, and authorizing the data access party to obtain the target data generated by the data producer; when the verification result indicates that the fourth digital signature is inconsistent with the third digital signature, determining that the verification of the third digital signature fails, and prohibiting authorizing the data access party to obtain the target data generated by the data producer.
8. The method according to claim 7, wherein, authorizing the data access party to obtain the target data generated by the data producer includes: determining the attribute information of the data access party according to the plaintext data of the attribute value; determining whether the data access party meets the access conditions according to the attribute information; when the data access party meets the access conditions, authorizing the data access party to obtain the target data generated by the data producer.
9. The method according to claim 1, wherein, sending the data key to the data access party includes: encrypting the plaintext data of the data key to determine the ciphertext data of the data key; and, signing the plaintext data of the data key based on a randomly generated first session key to obtain a fifth digital signature; sending the ciphertext data of the data key and the fifth digital signature to the data access party to instruct the data access party to verify the plaintext data of the data key according to the ciphertext data of the data key and the fifth digital signature.
10. The method according to claim 1, wherein, before performing the first identity authentication on the data access party, the method further includes: encrypting the plaintext data of the target data according to the plaintext data of the data key to obtain the ciphertext data of the target data; and, signing the plaintext data of the target data based on the plaintext data of the data key to obtain a seventh digital signature; sending the ciphertext data of the target data and the seventh digital signature to the cloud server.
11. A method for obtaining plaintext data, wherein, applied to a data access party, includes: performing a second identity authentication on the data producer and receiving the authentication result of the first identity authentication performed by the data producer on the data access party; when it is determined that the second identity authentication passes and it is determined that the first identity authentication passes according to the authentication result of the first identity authentication, determining whether the data producer authorizes the data access party to obtain the target data generated by the data producer; when the data producer authorizes the data access party to obtain the target data generated by the data producer, receiving the data key sent by the data producer; In the case of obtaining the target data, decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data.
12. The method according to claim 11, wherein, performing a second identity authentication on the data producer includes: determining a second session key according to a first parameter and a second parameter sent by the data producer, wherein the first parameter is generated by the data producer according to a randomly generated first random number and a first session key, and the second parameter is generated by the data producer according to the first random number; signing the second session key based on a randomly generated second random number to obtain a second digital signature corresponding to the second session key, and sending the second random number and the second digital signature to the data producer to instruct the data producer to perform a first identity authentication on the data access party according to the second random number and the second digital signature; determining the authentication result of the second identity authentication according to the authentication result of the first identity authentication.
13. The method according to claim 12, wherein, determining the authentication result of the second identity authentication according to the authentication result of the first identity authentication includes: determining that the second identity authentication passes in the case where the first identity authentication passes; determining that the second identity authentication fails in the case where the first identity authentication fails.
14. The method according to claim 12, wherein, determining a second session key according to a first parameter and a second parameter sent by the data producer includes: The second session key k is determined by the following formula 2 :[[]] k 2 = h(e(Sk b , R 1 )) ⊕ T 1 ; where Sk b is the private key of the authentication server corresponding to the data access party, T 1 is the first parameter, and R 1 is the second parameter.
15. The method according to claim 11, wherein, before determining whether the data producer authorizes the data access party to obtain the target data generated by the data producer, the method further includes: encrypting the plaintext data of the attribute value of the data access party according to the first session key randomly generated by the data producer to obtain the ciphertext data of the attribute value; and, signing the plaintext data of the attribute value based on the first session key to obtain a third digital signature; sending the ciphertext data of the attribute value and the third digital signature to the data producer to instruct the data producer to determine whether to authorize the data access party to obtain the target data generated by the data producer according to the ciphertext data of the attribute value and the third digital signature.
16. The method according to claim 11, wherein, after receiving the data key sent by the data producer, the method further includes: receiving the ciphertext data of the data key sent by the data producer, and the fifth digital signature corresponding to the data key; decrypting the ciphertext data of the data key according to the first session key randomly generated by the data producer to obtain the plaintext data of the data key; signing the plaintext data of the data key based on the first session key to obtain a sixth digital signature; determining that the verification of the plaintext data of the data key passes in the case where the sixth digital signature is consistent with the fifth data signature.
17. The method according to claim 11, wherein, after decrypting the target data according to the data key to obtain the plaintext data corresponding to the target data, the method further comprises: obtaining a seventh digital signature corresponding to the target data on a cloud server; signing the plaintext data of the target data based on the plaintext data of the data key to obtain an eighth digital signature; when the seventh digital signature is consistent with the eighth digital signature, determining that the verification of the plaintext data of the target data passes.
18. A system for obtaining plaintext data, wherein, it comprises: a data producer, and a data access party connected to the data producer, wherein, the data producer is configured to perform a first identity authentication on the data access party and send an authentication result of the first identity authentication to the data access party; the data access party is configured to perform a second identity authentication on the data producer and send an authentication result of the second identity authentication to the data producer; the data producer is further configured to, when determining that the first identity authentication passes and determining that the second identity authentication passes according to the authentication result of the second identity authentication, authorize the data access party to obtain the target data generated by the data producer and send a data key to the data access party; the data access party is further configured to, when the data producer authorizes the data access party to obtain the target data, decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data.
19. A computer-readable storage medium, wherein, a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented, or the steps of the method according to any one of claims 11 to 17 are implemented.
20. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, when the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented, or the steps of the method according to any one of claims 11 to 17 are implemented.