CT high-voltage power supply remote diagnosis data fine-grained access encryption method and system
By adopting the attribute-based keyword searchable encryption method that supports ciphertext forward search function in the cloud storage of remote diagnostic data of CT high-voltage power supply, the problems of search privacy leakage, lack of fault tolerance and high communication overhead are solved, and efficient and flexible fine-grained access control is achieved.
Patent Information
- Application Number
- CN202510535169.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art has problems such as search privacy leakage, lack of fault tolerance and high communication overhead in fine-grained access control of remote diagnostic data of CT high-voltage power supply stored in the cloud.
The attribute-based keyword searchable encryption method that supports ciphertext forward search function is adopted to realize the intersection search function without keyword domains, support outsourcing pre-decryption function, and allow data users to verify their correctness without downloading the complete part of the decrypted ciphertext.
It effectively protects the search privacy of data users, improves the system's search flexibility and fault tolerance, and reduces the computing and communication overhead of the user side.
Smart Images

Figure CN120068121A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of medical data processing, and particularly to a fine-grained access encryption method and system for CT high-voltage power supply remote diagnosis data. Background Art
[0002] CT (Computed Tomography), that is, computed tomography, is a medical imaging technology. It uses an X-ray beam to perform tomographic scanning on the human body and generates detailed images of the internal structure of the body with the aid of computer processing. CT scanning is widely used in the diagnosis of various diseases due to its fast and clear imaging ability. The high-voltage power supply is one of the core components in a CT device. After receiving the exposure parameter instructions of the CT system, it controls the electron beam in the X-ray tube to perform a series of actions such as preheating, acceleration, and deflection to generate invisible X-rays. The X-ray tube is a consumable passive execution device, and the predictability of its lifespan is very important for improving the operation efficiency of the system. The high-voltage power supply can implement the lifespan diagnosis function of the X-ray tube and contains the X-ray tube lifespan data inside. Because of the importance and privacy of the data, it is uploaded to the cloud for storage. How to achieve fine-grained access control for this data has become an urgent problem to be solved.
[0003] Traditional cryptographic systems only share data at a coarse-grained level, restricting users' ability to selectively share data at a fine-grained level. Therefore, the Attribute-Based Encryption (ABE) mechanism emerged as the times require. Attribute-based encryption is a powerful encryption algorithm that uses a set of attributes to identify user identities, enabling each user to have its own unique identity characteristics and flexibly represent access control policies. Therefore, the ABE scheme has broad application prospects in the field of fine-grained access control. Attribute-Based Keyword-Searchable Encryption (ABSE) combines searchable encryption and attribute-based encryption, and is an effective method to solve the problems of fine-grained access control and secure retrieval of cloud ciphertext data. In attribute-based keyword-searchable encryption, the data user needs to upload a search token to the cloud server (i.e., the ciphertext storage server); the cloud server executes the search algorithm, finds and returns the matching ciphertext to the data user. However, cloud servers are usually not fully trusted and may illegally save the search tokens of data users and perform statistical analysis on the frequencies of the keywords therein, thereby leading to the leakage of the search privacy of data users. For the above problems, existing attribute-based keyword-searchable encryption methods lack effective countermeasures. Secondly, existing attribute-based keyword-searchable encryption methods only support exact search, that is, the keyword set in the search token is a subset of the keyword set in the ciphertext or the two keyword sets are exactly the same. This means that even if a data user enters a single wrong character, the search will fail, so there is a lack of fault tolerance. In addition, existing attribute-based keyword-searchable encryption methods with the function of outsourcing pre-decryption either do not support the validity verification of partially decrypted ciphertexts, or require the data user to download the complete partially decrypted ciphertext to complete the validity verification. The former cannot guarantee the correctness of outsourcing pre-decryption, while the latter results in the user needing to download the complete ciphertext even if the cloud server executes the outsourcing pre-decryption dishonestly, which will increase the communication overhead of the user. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a fine-grained access encryption method and system for CT high-voltage power supply remote diagnosis data in view of the deficiencies of the above-mentioned prior art. The proposed method supports the function of forward search of ciphertexts, enabling the search token to be only used to search for ciphertexts generated before its generation time, effectively solving the problem of unauthorized search by cloud servers; supports the intersection search function without keyword domains, realizing flexible multi-keyword fuzzy search, and enhancing the practicability and fault tolerance of the system; supports the function of outsourcing pre-decryption and the data user can complete the correctness verification of outsourcing pre-decryption without downloading the complete partially decrypted ciphertext, effectively reducing the calculation and communication overhead of the data user.
[0005] To solve the above technical problems, the technical solutions adopted by the present invention are as follows: On the one hand, the present invention provides a fine-grained access encryption method for CT high-voltage power supply remote diagnosis data, comprising the following steps: Step 1: Create system global parameters and a master private key according to security parameters and the global attribute set of the CT high-voltage power supply remote diagnosis data fine-grained access encryption system; Step 2: Create an attribute key for the data user according to the system global parameters, the master private key, and the attribute set of the data user {doctor, technician, researcher}; Step 3: Create a private key and a pre-decryption key for the data user according to the system global parameters, the attribute key of the data user, and the attribute set; Step 4: Generate offline ciphertext according to the system global parameters and the total number of system keywords; Step 5: Generate online ciphertext according to the system global parameters, the authorized access structure, the plaintext, the offline ciphertext, the keyword set, and the current system time; the keyword set is {tube filament diameter, cumulative exposure time, cumulative ignition frequency, anode rotation time, scan count statistics, full-load exposure ratio}; Step 6: Generate a search token according to the system global parameters, the search threshold, the search keyword set, the private key of the data user, and the current system time; Step 7: Search for ciphertext matching the search token according to the system global parameters, the online ciphertext, the search token, and the pre-decryption key of the data user and generate a partially decrypted ciphertext; Step 8: Verify the validity of the partially decrypted ciphertext and decrypt and recover the plaintext according to the system global parameters, the private key of the data user, and the pre-decrypted ciphertext.
[0006] Furthermore, the specific method of Step 1 is as follows: Step 1.1: The central authority determines a k bit large prime number k and generates a p -order cyclic group p and a G -order cyclic group p T G T , and defines a bilinear mapping p -order cyclic group G and a p -order cyclic group G T e e : G × G → G T e e : G ×G → G T is the Cartesian product G × G to p a cyclic group of order G T mapping, i.e., a function z = e ( u , v ), where u , v G is the independent variable, z G T is the dependent variable; Step 1.2: The central authority selects a random generator p from the cyclic group of order G and two random elements g 0 and g 1 g 1 , defines Z p * ={1, 2, …, p - 1}, selects three random integers Z p * from α ; β and γ ; calculates four parameters X = g β , Y = g γ , E 1 =e ( g α , g ) and E 2 =e ( X , g 1 ); for each attribute in the system global attribute set U , selects| p |random elements G from the cyclic group of order U | h 1 , h 2 , …, h|U| , where U | represents the number of attributes in the system global attribute set U ; select a hash function H :{0,1} * → Z p * , where {0,1} * is the set of binary symbol strings of variable length; Step 1.3: The central authority selects a data encapsulation scheme , a commitment scheme , a message authentication code scheme and a key derivation function KDF : G T → , where, is the encryption algorithm of the data encapsulation scheme is the decryption algorithm of the data encapsulation scheme is the commitment phase of the commitment scheme is the opening phase of the commitment scheme is the output algorithm of the message authentication code scheme is the verification algorithm of the message authentication code scheme is the set of symmetric keys of a specific length; create system global parameters gp =( p , G , G T , e , g , g 0 , g 1 , h 1 ,..., h |U| , X , Y , E 1 , E 2 , H , , , , KDF ) and the master private key msk =( α ,β , γ )。
[0007] Furthermore, the specific method of step 2 is as follows: Step 2.1: The central authority obtains the attribute set of the data user att du , and selects a random integer z Z p * ; Step 2.2: According to the system global parameters gp and the master private key msk , the central authority calculates , k 1 = g α g βz , k 2 = g z and , where x att du , att du is the attribute set of the data user, and the attribute key returned to the data user is ask du =( k 0 , k 1 , k 2 , ).
[0008] Furthermore, the specific method of step 3 is as follows: Step 3.1: After the data user receives the attribute key ask du , it selects a random integer λ Z p * ; Step 3.2: According to the attribute key ask du and its own attribute set att du , the data user calculates , and , where x att du , create a private key sk du =( ask du , λ ) and a pre - decryption key pdk du =( att du , K 1 , K 2 , ).
[0009] Furthermore, the specific method of step 4 is as follows: Step 4.1: According to the total number of system keywords n , for each keyword j [1, n , the ciphertext sender selects a random integer u j Z p * ; Step 4.2: According to the system global parameters gp , the ciphertext sender calculates , generating an offline ciphertext .
[0010] Furthermore, the specific method of step 5 is as follows: Step 5.1: According to the system global parameters gp and the authorized access structure AS , the ciphertext sender generates a linear secret sharing scheme AS of the authorized access structure LS , and selects a random column vector = ( s , v 2 , v 3 , ... , v col ) T , where s , v 2 , v 3 , ... , v col Z p* , being a random integer, col is a linear secret sharing scheme LS in the sharing matrix M of the number of columns; Step 5.2: According to the system global parameters gp , the linear secret sharing scheme LS and the plaintext m , the ciphertext sender selects a random integer d Z p * and a random group element k G T , extracts the symmetric key key = KDF ( k ), calculates = ( key , m ), mac = ( key , ), ( com , dom ) = ( key , m , k ), C com = ( key , dom ), C 1 = g s , C 2 = Y s , μ i = M i , , C 4 = g d and , where M i is the linear secret sharing scheme LSShared matrix M The i row of is a mapping in the linear secret sharing scheme LS . Set the ciphertext of the plaintext m to be C m = ( M , , mac , com , C com , C 1 , C 2 , C 3 , C 4 , ), where row is the number of rows of the shared matrix LS in the linear secret sharing scheme M ; Step 5.3: According to the system global parameters gp , C m , the number of keywords in the encryption algorithm n 1 , the given keyword set ws = { w 1 , w 2 , ... , }, the system current time t and the offline ciphertext ct off , the ciphertext sender executes the 0- encoding algorithm to convert the time t into the set T , calculate and W j = H ( w j )- s + u j , where τ T , j [1, n 1 , set the ciphertext of the keyword set ws to beC w = ( T , , ); and then the online ciphertext ct on = ( C m , C w ) is sent to the ciphertext storage server.
[0011] Furthermore, the specific method of step 6 is as follows: Step 6.1: The data user executes algorithm 1- encoding to convert the current system time t′ into a set T′ ; Step 6.2: According to the system global parameter gp , the data user's private key sk du , the number of keywords of the trapdoor generation algorithm n 2 , the search threshold R and the search keyword set ws' = , the data user selects a random integer κ Z p * , and calculates t 1 = g λ , t 2 = g κ , , t 4 = λκ , and , where τ' T′ , j [1, n 2 ; and then is used as the search token, and the search token td and its own pre-decryption key pdk du are sent to the ciphertext storage server.
[0012] Furthermore, the specific method of step 7 is as follows: Step 7.1: The ciphertext storage server receives the search token from the data usertd and the pre - decryption key pdk du After that, according to the online ciphertext ct on judge T ∩ T′ whether it holds; Step 7.2: If it holds, the ciphertext storage server randomly selects an element y T ∩ T′ , and according to the search token td , the online ciphertext ct on and the data user's pre - decryption key pdk du calculate , where x att du , then execute Step 7.3; otherwise, the search fails and output ; Step 7.3: Judge whether it holds; if the verification holds, then calculate , where N = { i : ρ ( i ) att du} [1,..., row , and satisfies =(1,0,0,…,0), then take pct m = ( , mac , com , C com , C 3 , TF ) as the partial decrypted ciphertext; otherwise, the search fails and output .
[0013] Furthermore, the specific method of Step 8 is as follows: Step 8.1: The data user downloads the partial decrypted ciphertext pct m in( mac , com , Ccom , C 3 , TF ), according to the system global parameters gp and its own private key sk du , calculate successively k = C 3 / ( TF ) 1 / λ , key = KDF ( k ) and dom' = ( key , C com ), and then verify ( com , dom' ) is equal to 1; Step 8.2: If ( com , dom' ) = 1, the data user downloads and decrypts part of the ciphertext pct m in , according to the system global parameters gp and the decryption key dk calculate m = ( key , ), and verify ( key , m , ) is equal to 1; if ( key , m , ) = 1, the decryption is valid, and the plaintext m is obtained, otherwise, return ; If the algorithm outputs 0, indicating that the verification fails, and the algorithm outputs .
[0014] On the other hand, the present invention also provides a fine-grained access encryption system for CT high-voltage power supply remote diagnosis data, which is used to implement the fine-grained access encryption method for CT high-voltage power supply remote diagnosis data. The system includes a system initialization module, an attribute key creation module, a user key creation module, an offline encryption module, an online encryption module, a search token generation module, a search & pre-decryption module, and a verification & decryption module: The system initialization module is used to create system global parameters and a master private key according to security parameters and the global attribute set of the fine-grained access encryption system for CT high-voltage power supply remote diagnosis data; The attribute key creation module creates user attribute keys according to the system global parameters, the master private key, and the attribute set of the data user {doctor, technician, researcher}; The user key creation module creates a private key and a pre-decryption key for the data user according to the system global parameters, the attribute key of the data user, and the attribute set; The offline encryption module generates offline ciphertext according to the system global parameters and the total number of system keywords; The online encryption module generates online ciphertext according to the system global parameters, the authorized access structure, the plaintext, the offline ciphertext, the keyword set, and the current system time; the keyword set is {tube filament diameter, cumulative exposure time, cumulative ignition frequency, anode rotation time, scan count statistics, full-load exposure ratio}; The search token generation module generates a search token according to the system global parameters, the search threshold, the search keyword set, the private key of the data user, and the current system time; The search & pre-decryption module searches for ciphertexts matching the search token and generates partially decrypted ciphertexts according to the system global parameters, the online ciphertext, the search token, and the pre-decryption key of the data user; The verification & decryption module verifies the validity of the partially decrypted ciphertext and decrypts to recover the plaintext according to the system global parameters, the private key of the data user, and the pre-decrypted ciphertext.
[0015] The beneficial effects of adopting the above technical scheme are: a fine-grained access encryption method and system for remote diagnostic data of a CT high-voltage power supply provided by the present invention, firstly, because the present invention supports the ciphertext forward search function, the search token can only be used to search for the ciphertext generated before its generation time; even if the cloud server illegally saves the search token of the data user and performs an unauthorized search, it cannot obtain new information from multiple search results, thereby effectively protecting the search privacy of the data user; secondly, because the present invention provides a multi-keyword fuzzy matching search method without a keyword domain, as long as the number of keywords contained in the intersection of the keyword set in the ciphertext and the keyword set in the search token is greater than a preset threshold value, a matching ciphertext can be found, so it has better search flexibility and fault tolerance than the existing method; thirdly, because the present invention allows data users to verify the correctness of the cloud server outsourced pre-decryption without downloading the complete partially decrypted ciphertext, and then download the remaining partially decrypted ciphertext to complete the decryption, thereby effectively reducing the communication overhead on the user side. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 A flow chart of a fine-grained access encryption method for CT high-voltage power supply remote diagnostic data provided by an embodiment of the present invention; Figure 2 A flowchart of operations performed by a cryptographic system provided by an embodiment of the present invention; Figure 3 A schematic diagram of a fine-grained access control encryption system for remote diagnostic data of a CT high-voltage power supply provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0017] The specific implementation of the present invention is further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0018] The fine-grained access control encryption method for remote diagnostic data of a CT high-voltage power supply of this embodiment can be implemented using bilinear mapping. At the same time, the construction of the method requires the use of access structure, linear secret sharing scheme, data encapsulation scheme, commitment scheme, message authentication code scheme, key derivation function and 0-1 encoding. The following first briefly introduces their basic definitions.
[0019] make p is a large prime number, G and G T For two p If defined in a cyclic group G and G T A mapping on e : G × G →G T If the following three properties are satisfied, then this mapping is called a valid bilinear mapping. Among them, e : G × G → G T is a cyclic group G and the Cartesian product of itself G × G to the cyclic group G T is a mapping, that is, the bilinear mapping e : G × G → G T refers to the function z = e ( u , v ) where u , v G are independent variables, z G T is the dependent variable.
[0020] A valid bilinear mapping e : G × G → G T needs to satisfy the following three properties: (1) Bilinearity: For any u , v G and any x , y Z p * , the equation e ( u x , v y )= e ( u , v ) xy always holds.
[0021] (2) Non-degeneracy: There exists u , v G such that e ( u , v ) , where is a cyclic group G T is the identity element of
[0022] (3) Computability: For any u , v G , there exists an effective algorithm to compute e ( u , v ).
[0023] Among them, the concept of cyclic group is: Let G be a group. If there exists a group element g G such that G= { g n | n Z}, then G is called a cyclic group, and g is called the generator of the group G . If the order of the generator g is p (that is, p is the smallest positive integer such that g to the power of G is equal to the identity element of the group G ), then p is called a Z p * ={1, 2,..., p - 1}, where Z p refers to the residue class of integers modulo p , that is, Z p ={0, 1,..., p - 1}.
[0024] Access structure: Let U be the set of system global attributes. The authorized access structure U on the set AS is a set of non-empty subsets of U , that is, . If for and , then C AS , then AS is called monotonic.
[0025] Linear Secret Sharing Scheme for Access Structure: Let S AS be the access structure AS 's authorized sets, p be a large prime number, and s Z p * be a secret. A linear secret sharing scheme satisfies the following conditions: (1) Each share for the secret s is a vector over Z p * ; (2) There exists a row row col column sharing matrix M Z p row×col and a function such that the function maps each row of the matrix M to an attribute in the authorized set S ; (3) If = ( s , v 2 , v 3 , ... , v col ) T is a column vector, where s , v 2 , v 3 , ... , v col Z p * , then is s 's row share values; (4) If M i represents the M 's i row, then corresponds to the attribute .
[0026] Data Encapsulation Scheme: The data encapsulation scheme Consists of an encryption algorithm and a decryption algorithm . Among them, the encryption algorithm takes as input a symmetric key key and plaintext m , and outputs ciphertext ; the decryption algorithm takes as input a symmetric key key and ciphertext , and outputs plaintext m .
[0027] Commitment scheme: The commitment scheme consists of a commitment algorithm and an opening algorithm . Among them, the commitment algorithm takes as input a symmetric key key declaration x and a random number r , and outputs a commitment value com and a de-commitment value dom ; the opening algorithm takes as input a commitment value com and a de-commitment value dom , and outputs 1 indicating that ( com , dom ) is a valid commitment pair, or 0 indicating invalidity.
[0028] Message authentication code scheme: The message authentication code scheme consists of a message authentication code generation algorithm and a message authentication code verification algorithm . Among them, the message authentication code generation algorithm takes as input a symmetric key key and the information to be authenticated m , and outputs a message authentication code mac ; the message authentication code verification algorithm takes as input a symmetric key key , information m and a message authentication code mac , and outputs 1 indicating mac valid; or 0 indicating invalidity.
[0029] Key derivation function: The key derivation function KDF is used to generate a symmetric key of a specified length. Its input is a random value and its output is a symmetric key.
[0030] 0-1 encoding: 0-1 encoding consists of a 0- encoding algorithm and a 1- encoding algorithm. Let t = t n tn-1 ... t 1 {0, 1} n is a binary symbol string of length n . 0 - encoding The algorithm can convert t into a set of binary symbol strings { t n t n-1 ... t i+1 1 | t i = 0, 1 ≤ i ≤ n}, denoted as ; while the 1 - encoding algorithm converts t into a set of binary symbol strings { t n t n-1 ... t i | t i = 1, 1 ≤ i ≤ n}, denoted as . For any two binary numbers of equal length t and t' , if , then t < t′ .
[0031] The entities involved in the method described in this embodiment are as follows: Central Authority: A trusted entity of the system, responsible for creating the global parameter set and master key of the system, as well as the attribute keys of all data users; Ciphertext Sender: The entity that sends the ciphertext, encrypts the plaintext to be sent into ciphertext, and then encrypts the set of keywords associated with the plaintext into an index ciphertext and attaches it to the ciphertext and sends it to the ciphertext storage server; Data User: The entity that receives the ciphertext, generates a pre - decryption key and a search token for the set of keywords to be searched and sends them to the ciphertext storage server, authorizing the ciphertext storage server to retrieve the ciphertext through the search token and use the pre - decryption key to perform pre - decryption on the matching ciphertext to generate a partially decrypted ciphertext; System Time Server: The entity responsible for generating the system time, providing the system current time for the ciphertext sender when generating ciphertext or the data user when generating a search token; Cloud server: Responsible for storing the ciphertexts published by entities in the system. After receiving the pre-decryption key and search token from the data user, it retrieves the ciphertexts and pre-decrypts the matching ciphertexts.
[0032] As Figure 1 and Figure 2 shown, the method of this embodiment is described as follows.
[0033] Step 1: Create system global parameters and the master private key according to the security parameters and the fine-grained access encryption system global attribute set of the CT high-voltage power supply remote diagnostic data. The specific method is as follows: Step 1.1: The central authority determines a k bit large prime number k and generates a p -order cyclic group p and a G -order cyclic group p T G T , and defines a bilinear mapping p -order cyclic group G and a p -order cyclic group G T T e : G × G → G T T is the set of positive integers; the bilinear mapping e : G × G → G T T G × G to p -order cyclic group G T T z = e ( u , v ) u , v where G T T
[0034] Step 1.2: The central authority selects a random generator p from the G -order cyclic group g and two random elements g 0 andg 1 , define Z p * = {1, 2, …, p - 1}, select three random integers from Z p * ; calculate four parameters α 、 β and γ ; for each attribute in the system global attribute set X = g β 、 Y = g γ 、 E 1 =e ( g α , g ) and E 2 =e ( X , g 1 ); for each attribute in the system global attribute set U , select | p | random elements G 1 U | from the h 1 、 h 2 、…、 h |U| ,where | U | represents the number of attributes in the system global attribute set U ; select a hash function H : {0, 1} * → Z p * ,where {0, 1} * is the set of binary symbol strings of variable length.
[0035] Step 1.3: The central authority selects a data encapsulation scheme , a commitment scheme , a message authentication code scheme and a key derivation function KDF : G T → , where is the encryption algorithm of the data encapsulation scheme , is the data encapsulation scheme The decryption algorithm of is the commitment phase of the commitment scheme The commitment phase of is the commitment scheme The opening phase of is the output algorithm of the message authentication code scheme The output algorithm of is the message authentication code scheme The verification algorithm of is a set of symmetric keys of a specific length; create system global parameters gp =( p , G , G T , e , g , g 0 , g 1 , h 1 ,..., h |U| , X , Y , E 1 , E 2 , H , , , , KDF ) and the master private key msk =( α , β , γ ).
[0036] Step 2: Create the attribute key of the data user according to the system global parameters, the master private key, and the attribute set of the data user {doctor, technician, researcher}. The specific method is as follows: Step 2.1: The central authority obtains the attribute set of the data user att du , and selects a random integer z Z p * .
[0037] Step 2.2: According to the system global parameters gp and the master private key msk , the central authority calculates , k 1 = g αg βz , k 2 = g z and , where x att du , att du is the attribute set of the data user, and the attribute key returned for the data user is ask du =( k 0 , k 1 , k 2 , ).
[0038] Step 3: Create the private key and pre-decryption key of the data user according to the system global parameters, the attribute key, and the attribute set of the data user. The specific method is as follows: Step 3.1: After the data user receives the attribute key ask du , select a random integer λ Z p * .
[0039] Step 3.2: According to the attribute key ask du and its own attribute set att du , the data user calculates , and , where x att du , create the private key sk du =( ask du , λ ) and the pre-decryption key pdk du =( att du , K 1 , K 2 , ).
[0040] Step 4: Generate the offline ciphertext according to the system global parameters and the total number of system keywords. The specific method is as follows: Step 4.1: According to the total number of system keywords n , for each keyword by the ciphertext sender j [1, n , select a random integer u j Z p * .
[0041] Step 4.2: According to the system global parameters gp , the ciphertext sender calculates to generate the offline ciphertext .
[0042] Step 5: Generate the online ciphertext according to the system global parameters, the authorized access structure, the plaintext, the offline ciphertext, the keyword set, and the current system time; the keyword set is {tube filament diameter, cumulative exposure time, cumulative arcing frequency, anode rotation time, scan count statistics, full-load exposure ratio}. The specific method is as follows: Step 5.1: According to the system global parameters gp and the authorized access structure AS , the ciphertext sender generates the linear secret sharing scheme AS of the authorized access structure LS , and selects a random column vector = ( s , v 2 , v 3 , ... , v col ) T , where s , v 2 , v 3 , ... , v col Z p * are random integers, col is the linear secret sharing scheme LS in the shared matrix M of the number of columns.
[0043] Step 5.2: According to the system global parameters gp, Linear Secret Sharing Scheme LS and the plaintext m , the ciphertext sender selects a random integer d Z p * and a random group element k G T , extracts the symmetric key key = KDF ( k ) and calculates = ( key , m ), mac = ( key , ),( com , dom ) = ( key , m , k ), C com = ( key , dom ), C 1 = g s , C 2 = Y s , μ i = M i , , C 4 = g d and , where M i is the LS th row of the sharing matrix M in the linear secret sharing scheme i , is the mapping in the linear secret sharing scheme LS , and sets the ciphertext of the plaintext m to be C m = (M , , mac , com , C com , C 1 , C 2 , C 3 , C 4 , ), where row is a linear secret sharing scheme LS in the sharing matrix M the number of rows.
[0044] Step 5.3: According to the system global parameters gp 、 C m , the number of keywords in the encryption algorithm n 1 , the keyword set ws = { w 1 , w 2 , ... , }, the system current time t and the offline ciphertext ct off , the ciphertext sender executes the 0- encoding algorithm to convert the time t into the set T , calculate and W j = H ( w j )- s + u j , where τ T , j [1, n 1 , set the ciphertext of the keyword set ws to be C w = ( T , , ); Then the online ciphertext ct on = (C m , C w ) Send it to the ciphertext storage server. The keyword set among them ws is given. The IND-CKA security guarantee is that given the keyword sets ws0 and ws1, the adversary cannot distinguish whether the challenge keyword ciphertext is encrypted for ws0 or ws1.
[0045] Step 6: Generate a search token according to the system global parameters, search threshold, search keyword set, the private key of the data user, and the current system time. The specific method is as follows: Step 6.1: The data user executes 1- encoding algorithm to convert the current system time t′ into a set T′ .
[0046] Step 6.2: According to the system global parameters gp , the private key of the data user sk du , the number of keywords in the trapdoor generation algorithm n 2 , the search threshold R and the search keyword set ws' = , the data user selects a random integer κ Z p * , calculate t 1 = g λ , t 2 = g κ , , t 4 = λκ , and , where τ' T′ , j [1, n 2 ; then use as the search token, and send the search token td and its own pre-decryption key pdk du to the ciphertext storage server.
[0047] Step 7: Search for the ciphertext that matches the search token and generate a partial decrypted ciphertext based on the system global parameters, the online ciphertext, the search token, and the pre-decryption key of the data user. The specific method is as follows: Step 7.1: The ciphertext storage server receives the search token of the data user td and the pre-decryption key pdk du and then, based on the online ciphertext ct on judge T ∩ T whether it holds.
[0048] Step 7.2: If it holds, the ciphertext storage server randomly selects an element y T ∩ T′ , and calculates td according to the search token ct on , the online ciphertext pdk du and the pre-decryption key of the data user , where x att du , and then execute Step 7.3; otherwise, the search fails and is output.
[0049] Step 7.3: Judge whether it holds; if the verification holds, then calculate , where N = { i : ρ ( i ) att du} [1,..., row , and satisfies =(1,0,0,…,0), and then take pct m = ( , mac , com , C com , C 3 , TF ) as the partial decrypted ciphertext; otherwise, the search fails and is output.
[0050] Step 8: Verify the validity of the partially decrypted ciphertext and decrypt and recover the plaintext based on the system global parameters, the private key of the data user, and the pre-decrypted ciphertext. The specific method is as follows: Step 8.1: The data user downloads the partially decrypted ciphertext pct m in mac , com , C com , C 3 , TF ), and according to the system global parameters gp and its own private key sk du , calculate successively k = C 3 / ( TF ) 1 / λ , key = KDF ( k ) and dom' = ( key , C com ), and then verify whether ( com , dom' ) is equal to 1.
[0051] Step 8.2: If ( com , dom' ) = 1, the data user downloads pct m in the , and according to the system global parameters gp and the decryption key dk calculate m = ( key , ), and verify whether ( key , m , ) is equal to 1; if ( key , m , ) = 1, then the decryption is valid, and the plaintext m is obtained, otherwise, return .
[0052] If The algorithm outputs 0, indicating that the verification fails. The algorithm output .
[0053] As Figure 3 shown, this embodiment also provides a fine-grained access control encryption system for CT high-voltage power supply remote diagnosis data, which is used to implement the above-mentioned fine-grained access control encryption method for CT high-voltage power supply remote diagnosis data. The system includes a system initialization module, an attribute key creation module, a user key creation module, an offline encryption module, an online encryption module, a search token generation module, a search & pre-decryption module, and a verification & decryption module.
[0054] The system initialization module creates system global parameters and a master private key according to the security parameters and the global attribute set of the CT high-voltage power supply remote diagnosis data fine-grained access encryption system. The specific method is as in step 1.
[0055] The attribute key creation module creates an attribute key for the data user according to the system global parameters, the master private key, and the attribute set of the data user {doctor, technician, researcher}. The specific method is as in step 2.
[0056] The user key creation module creates a private key and a pre-decryption key for the data user according to the system global parameters, the attribute key of the data user, and the attribute set. The specific method is as in step 3.
[0057] The offline encryption module generates an offline ciphertext according to the system global parameters and the total number of system keywords. The specific method is as in step 4.
[0058] The online encryption module generates an online ciphertext according to the system global parameters, the authorized access structure, the plaintext, the offline ciphertext, the keyword set, and the current system time. The keyword set is {tube filament diameter, exposure cumulative time, cumulative sparking frequency, anode rotation time, scan count statistics, full-load exposure ratio}. The specific method is as in step 5.
[0059] The search token generation module generates a search token according to the system global parameters, the search threshold, the search keyword set, the private key of the data user, and the current system time. The specific method is as in step 6.
[0060] The search & pre-decryption module searches for the ciphertext matching the search token and generates a partial decryption ciphertext according to the system global parameters, the online ciphertext, the search token, and the pre-decryption key of the data user. The specific method is as in step 7.
[0061] The verification & decryption module verifies the validity of the partial decryption ciphertext and decrypts to recover the plaintext according to the system global parameters, the private key of the data user, and the pre-decryption ciphertext. The specific method is as in step 8.
[0062] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope defined by the claims of the present invention.
Claims
1. A fine-grained access encryption method for remote diagnostic data of a CT high-voltage power supply, characterized in that: The method comprises the following steps: Step 1: Create system global parameters and master private key based on the security parameters and CT high-voltage power supply remote diagnostic data fine-grained access encryption system global attribute set; Step 2: Create the data user's attribute key based on the system global parameters, the master private key and the data user's attribute set {doctor, technician, researcher}; Step 3: Create the data user's private key and pre-decryption key based on the system global parameters, the data user's attribute key and attribute set; Step 4: Generate offline ciphertext based on system global parameters and the total number of system keywords; Step 5: Generate online ciphertext based on system global parameters, authorized access structure, plaintext, offline ciphertext, keyword set and system current time; the keyword set is {bulb filament diameter, cumulative exposure time, cumulative ignition frequency, anode rotation time, scanning number statistics, full load exposure ratio}; Step 6: Generate a search token based on the system global parameters, search threshold, search keyword set, data user's private key and system current time; Step 7: Based on the system global parameters, online ciphertext, search token and pre-decryption key of the data user, search for the ciphertext matching the search token and generate a partial decrypted ciphertext; Step 8: Based on the system global parameters, the data user's private key and the pre-decrypted ciphertext, verify the validity of the partially decrypted ciphertext and decrypt and restore the plaintext.
2. According to claim 1, a CT high-voltage power supply remote diagnosis data fine-grained access encryption method is characterized in that: The specific method of step 1 is: Step 1.1: The central authority determines the security parameters k Determine one k Large prime number of bits p ,generate p Cyclic group of order G and p Cyclic group of order G T , and defined in p Cyclic group of order G and p Cyclic group of order G T Bilinear Maps on e : G × G → G T ,in is a set of positive integers; a bilinear map e : G × G → G T is the Cartesian product G × G arrive p Cyclic group of order G T The mapping of z = e ( u , v ),in u , v G is the independent variable, z G T is the dependent variable; Step 1.2: Central authority from p Cyclic group of order G Choose a random generator from g and two random elements g 0 and g 1. Definition Z p * ={1,2,…, p -1}, from Z p * Choose three random integers from α , β and γ ; Calculate four parameters X = g β , Y = g γ , E 1 =e ( g α , g )and E 2 =e ( X , g 1); corresponding to the system global attribute set U Each attribute in p Cyclic group of order G Select | U | random elements h 1. h 2. … h |U| , where | U |Represents the system global property set U The number of attributes in; choose a hash function H :{0,1} * → Z p * , where {0,1} * It is a set of binary symbol strings of variable length; Step 1.3: The central authority chooses a data encapsulation solution A commitment plan , a message authentication code scheme and a key derivation function KDF : G T → ,in, It is a data encapsulation solution The encryption algorithm, It is a data encapsulation solution The decryption algorithm, It is a commitment plan The commitment stage, It is a commitment plan The opening phase, It is a message authentication code scheme The output algorithm is It is a message authentication code scheme The verification algorithm, Is a set of symmetric keys of a specific length; create system global parameters gp =( p , G , G T , e , g , g 0, g 1, h 1,..., h |U| , X , Y , E 1, E 2, H , , , , KDF ) and the master private key msk =( α , β , γ ).
3. According to claim 2, a CT high-voltage power supply remote diagnosis data fine-grained access encryption method is characterized in that: The specific method of step 2 is: Step 2.1: The central authority obtains the attribute set of the data user att du , and choose a random integer z Z p * ; Step 2.2: According to the system global parameters gp and the master private key msk , Central Authoritative Computing , k 1= g α g βz , k 2= g z and ,in x att du , att du is the attribute set of the data user, and the attribute key of the returned data user is ask du =( k 0, k 1, k 2, ).
4. According to claim 3, a CT high-voltage power supply remote diagnosis data fine-grained access encryption method is characterized in that: The specific method of step 3 is: Step 3.1: Data user receives attribute key ask du Then, choose a random integer λ Z p * ; Step 3.2: Based on the attribute key ask du and its own set of attributes att du , Data User Computing , and ,in x att du , create a private key sk du =( ask du , λ ) and the pre-decryption key pdk du =( att du , K 1, K 2, ).
5. According to claim 4, a CT high-voltage power supply remote diagnosis data fine-grained access encryption method is characterized in that: The specific method of step 4 is: Step 4.1: Based on the total number of system keywords n , the ciphertext sender for each keyword j [1, n ], choose a random integer u j Z p * ; Step 4.2: According to the system global parameters gp , the ciphertext sender calculates , generating offline ciphertext .
6. A CT high voltage power supply remote diagnosis data fine-grained access encryption method according to claim 5, characterized in that: The specific method of step 5 is: Step 5.1: According to the system global parameters gp and the authorization access structure AS , the ciphertext sender generates an authorization access structure AS Linear secret sharing scheme LS , and select a random column vector = ( s , v 2, v 3, ... , v col ) T ,in s , v 2, v 3, ... , v col Z p * , is a random integer, col Linear secret sharing scheme LS Shared Matrix M The number of columns; Step 5.2: According to the system global parameters gp , Linear Secret Sharing Scheme LS and plain text m , the ciphertext sender chooses a random integer d Z p * and a random group element k G T , extract the symmetric key key = KDF ( k ),calculate = ( key , m ), Mac = ( key , )、( com , dom ) = ( key , m , k ), C com = ( key , dom ), C 1= g s , C 2= Y s , μ i = M i , , C 4= g d and ,in M i It is a linear secret sharing scheme LS Shared Matrix M No. i OK, It is a linear secret sharing scheme LS The mapping in the plain text m The ciphertext is C m = ( M , , Mac , com , C com , C 1, C 2, C 3, C 4, ),in row Linear secret sharing scheme LS Shared Matrix M number of rows; Step 5.3: According to the system global parameters gp , C m , Number of encryption algorithm keywords n 1. Given a set of keywords ws ={ w 1, w 2,... , }、Current system time t and offline ciphertext ct off , the ciphertext sender executes 0- encoding The algorithm converts time t Convert to Collection T ,calculate and W j = H ( w j )- s + u j ,in τ T , j [1, n 1], set keyword set ws The ciphertext is C w = ( T , , ) ; then the online ciphertext ct on =( C m , C w ) is sent to the ciphertext storage server.
7. A CT high voltage power supply remote diagnosis data fine-grained access encryption method according to claim 6, characterized in that: The specific method of step 6 is: Step 6.1: Data User Execution 1- encoding The algorithm converts the system current time t′ Convert to Collection T′ ; Step 6.2: According to the system global parameters gp , data user private key sk du , Number of keywords in trapdoor generation algorithm n 2. Search threshold R and search keyword set ws' = , the data user chooses a random integer κ Z p * ,calculate t 1 = g λ , t 2 = g κ , , t 4 = λκ , and ,in τ' T′ , j [1, n 2]; then As the search token, the search token td And its own pre-decryption key pdk du Sent to the ciphertext storage server.
8. A CT high-voltage power supply remote diagnosis data fine-grained access encryption method according to claim 7, characterized in that: The specific method of step 7 is: Step 7.1: The ciphertext storage server receives the data user's search token td and the pre-decryption key pdk du After that, according to the online ciphertext ct on judge T ∩ T′ whether it is established; Step 7.2: If true, the ciphertext storage server randomly selects an element y T ∩ T′ , based on the search token td , Online Ciphertext ct on and the data user's pre-decryption key pdk du calculate ,in x att du , then proceed to step 7.3; Otherwise, the search fails and the output is ; Step 7.3: Judgement Is it true? If the verification is true, then calculate ,in N ={ i : ρ ( i ) att du } [1,..., row ],and satisfy =(1,0,0,…,0), then pct m = ( , Mac , com , C com , C 3, TF ) as a partially decrypted ciphertext; Otherwise, the search fails and the output is .
9. A CT high voltage power supply remote diagnosis data fine-grained access encryption method according to claim 8, characterized in that: The specific method of step 8 is: Step 8.1: Data user downloads partially decrypted ciphertext pct m In ( Mac , com , C com , C 3, TF ), according to the system global parameters gp And your own private key sk du , calculate successively k = C 3 / ( TF ) 1 / λ , key = KDF ( k )and dom' = ( key , C com ), then verify ( com , dom' ) is equal to 1; Step 8.2: If ( com , dom' ) = 1, data user downloads partial decrypted ciphertext pct m In , according to the system global parameters gp and the decryption key dk calculate m = ( key , ) and verify ( key , m , ) is equal to 1; if ( key , m , ) = 1, the decryption is valid and the plaintext is obtained m Otherwise, return ; like The algorithm outputs 0, indicating that the verification failed. The algorithm outputs .
10. A CT high-voltage power supply remote diagnosis data fine-grained access encryption system, used to implement the CT high-voltage power supply remote diagnosis data fine-grained access encryption method according to claim 1, characterized in that: The system includes a system initialization module, an attribute key creation module, a user key creation module, an offline encryption module, an online encryption module, a search token generation module, a search & pre-decryption module, and a verification & decryption module: The system initialization module is used to access the global attribute set of the encrypted system in fine-grained manner according to the security parameters and the CT high-voltage power supply remote diagnosis data, and to create the system global parameters and the master private key; The attribute key creation module creates the user's attribute key based on the system global parameters, the master private key and the data user's attribute set {doctor, technician, researcher}; The user key creation module creates the data user's private key and pre-decryption key based on the system global parameters, the data user's attribute key and attribute set; The offline encryption module generates offline ciphertext according to the system global parameters and the total number of system keywords; The online encryption module generates online ciphertext according to the system global parameters, authorized access structure, plaintext, offline ciphertext, keyword set and system current time; the keyword set is {bulb filament diameter, cumulative exposure time, cumulative ignition frequency, anode rotation time, scanning number statistics, full load exposure ratio}; A search token generation module generates a search token based on system global parameters, search threshold, search keyword set, data user's private key and system current time; The search & pre-decryption module searches for ciphertext matching the search token and generates partially decrypted ciphertext based on the system global parameters, online ciphertext, search token and pre-decryption key of the data user; The verification & decryption module verifies the validity of the partially decrypted ciphertext and decrypts and restores the plaintext based on the system global parameters, the data user's private key and the pre-decrypted ciphertext.
Citation Information
Patent Citations
An attribute-based ciphertext search method capable of controlling search authority
CN109740364A
Searchable encryption method and system for fine-grained query authorization
CN109981643A
Attribute-based encryption method and system supporting keyword Boolean search
CN111966802A
Method suitable for safely sharing user privacy data in medical internet of things scene
CN116132048A
Multi-terminal medical data query method with forward and backward privacy
CN116186095A
Cited By
CT high-voltage power supply signal acquisition system and method
CN120468711A