Hybrid proxy re-encryption method supporting keyword retrieval
By introducing identification and attribute threshold generation and testing algorithms into the hybrid proxy re-encryption method, the problem of lack of keyword search function for encrypted data sharing in the prior art is solved, and efficient secret keyword retrieval is realized, data reading efficiency is improved and storage and computing overhead is reduced.
Patent Information
- Application Number
- CN202510230154.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-28
AI Technical Summary
The existing one-to-many encrypted data sharing scheme lacks the keyword retrieval function of ciphertext, resulting in low data reading efficiency and parameter redundancy problems in large-scale data sharing scenarios in cloud environments, which increases storage and computing overhead.
A hybrid proxy re-encryption method that supports keyword retrieval is proposed. By adding four algorithms: identification threshold generation, attribute threshold generation, identification threshold testing, and attribute threshold testing, the secret keyword retrieval function based on one-to-many encrypted data sharing is realized.
It realizes efficient keyword retrieval of encrypted data in a cloud environment, improves data reading efficiency, solves parameter redundancy problems, reduces storage and computing overhead, and ensures the security of the data sharing process.
Smart Images

Figure CN120074815A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of data security and data encryption, and specifically relates to a hybrid proxy re-encryption method and system supporting keyword retrieval. Background Art
[0002] One-to-many encrypted data sharing refers to converting ciphertext that can be decrypted by a single user into ciphertext that can be decrypted by multiple users through an authorized key without decrypting the plaintext information. Currently, the solutions supporting one-to-many encrypted data sharing mainly include Identity-based Broadcast Proxy Re-encryption (IB-BPRE) (G. Chunpeng, Z. Liu, J. Xia, and F. Liming, “Revocable identity-based broadcast proxy re-encryption for data sharing in clouds,” IEEE Transactions on Dependable and Secure Computing, 2019), and Hybrid Proxy Re-encryption (HyPRE) (X. Feng et al., “HyPRE: Hybrid Proxy Re-Encryption for Secure Multimedia Data Sharing on Mobile Devices,” 2024 IEEE International Conference on Multimedia and Expo (ICME), Niagara Falls, ON, Canada, 2024, pp. 1-6). The former idea is to convert the data encryption scheme based on a single identity into a data encryption scheme based on a set composed of multiple identities, while the latter idea is to convert the data encryption scheme based on a single identity into a data encryption scheme based on attributes and policies composed of attributes.
[0003] The disadvantage of the IB-BPRE scheme is that all identities need to be enumerated during the re-encryption phase, which introduces exponential performance overhead in the re-encryption key generation and re-encryption ciphertext decryption phases. The HyPRE scheme has more flexible access control capabilities and is generally considered more suitable for the scenario of one-to-many data encryption. However, so far, all existing one-to-many encrypted data sharing schemes do not support keyword retrieval relative to ciphertexts. For the data sharing scenario based on the cloud environment, when the data scale is large, keyword retrieval is an important technology for efficient data reading and has important value for cloud-assisted encrypted data sharing. Summary of the Invention
[0004] Object of the Invention: To solve the problems that there is a certain redundancy in the public parameters in the existing one-to-many encrypted data sharing method, which will introduce certain storage and calculation overheads and the lack of keyword retrieval for ciphertexts, the present invention proposes a hybrid proxy re-encryption method and system supporting keyword retrieval. By adding four keyword retrieval-related algorithms, namely identity threshold generation, attribute threshold generation, identity threshold test, and attribute threshold test, the function of ciphertext keyword retrieval based on one-to-many encrypted data sharing is realized.
[0005] Technical Solution: A hybrid proxy re-encryption method supporting keyword retrieval includes the following steps:
[0006] The key generation center generates an identity key for the data owner and sends the identity key to the data owner through a secure channel; the key generation center generates an attribute key for a user with specific attributes and distributes the attribute key to the user through a secure channel; the specific attributes are attribute information abstracted according to user characteristics;
[0007] The data owner encrypts the original data using its own identity ID to obtain the original ciphertext, and uploads the original ciphertext to the cloud server for storage;
[0008] The data owner generates a re-encryption key according to its own identity key and the access control policy corresponding to the attributes of the authorized users;
[0009] The data owner uploads the re-encryption key to the cloud server, and the cloud server re-encrypts the original ciphertext using the re-encryption key to obtain the re-encrypted ciphertext;
[0010] When data sharing is performed, the cloud server distributes the re-encrypted ciphertext to the corresponding authorized users, and the authorized users decrypt the re-encrypted ciphertext using their respective attribute keys to obtain the original data;
[0011] When performing ciphertext data retrieval, the data owner uses their identity key to generate an identity threshold and uploads the identity threshold to the cloud server for ciphertext data retrieval. The cloud server performs an identity threshold test on the original ciphertext based on the data owner's identity threshold and returns the corresponding test result; each authorized user uses their attribute key to generate a corresponding attribute threshold and uploads the attribute threshold to the cloud server for re-encrypted ciphertext retrieval. The cloud server performs an attribute threshold test on the re-encrypted ciphertext based on each authorized user's attribute threshold and returns the corresponding test result.
[0012] Furthermore, the key generation center generates an identity key for the data owner, specifically including:
[0013] Select a random number and
[0014] Calculate g a , g b , g c ; The system public parameters pp and the master secret key msk are respectively expressed as:
[0015] pp = g, g a , g b , g c , u, h, w, v, f, e(g, g) α
[0016] msk = (α, a, b)
[0017] In the formula, the bilinear mapping e(·): means mapping two elements in the group to an element in the group, the set corresponding to the group is the set composed of the Cartesian product of the elements in the group, and G T are two different multiplicative cyclic groups defined on the elliptic curve;
[0018] Select a random number r and calculate K 0 = g α w r , K 1 = (u ID h) -r , K 2 = g r , V = g (ac-r) / b , Z = f r ;
[0019] The identity key of the data owner corresponding to the identity ID is expressed as: sk ID = (K 0 , K1 , K 2 , V, Z).
[0020] Furthermore, the key generation center generates attribute keys for users with specific attributes, specifically including:
[0021] Randomly select And calculate
[0022] For any i ∈ [k], where k represents the number of attributes, calculate In the formula, A i Represents the value of each attribute;
[0023] Users with specific attributes The corresponding attribute key is expressed as:
[0024]
[0025] In the formula, Represents the attribute information set.
[0026] Furthermore, the data owner encrypts the original data using its own identity ID to obtain the original ciphertext, specifically including:
[0027] The data owner selects a random element And calculates C = m · e(g, g) αs , C 0 = g s , C 1 = g t , C 2 = u ID h) t w -s , C 3 = f s , where m represents the plaintext message;
[0028] Randomly select And calculates W = g cd , W 0 = g a(d+s) g bdH(KW) , W 1 = g bs , E = f s (u ID h) s , where H(·) represents the hash function that maps the keyword KW to The group, and KW represents the keyword bound during the original encryption;
[0029] The original ciphertext is expressed as:
[0030] ct ID =(C, C 0 , C 1 , C 2 , C 3 , W, W 0 , W 1 , E).
[0031] Furthermore, the data owner generates a re-encryption key according to its identity key and the access control policy corresponding to the authorized user attributes, specifically including:
[0032] Define the access control policy W = (M, ρ) corresponding to the authorized user attributes, where and ρ: l represents the row number, and a row of the matrix is mapped to a specific attribute value;
[0033] The data owner with the identity key sk ID selects where, represents a random vector, s' represents a random number, y n represents a random element, and n represents the number of attributes of the authorized user attributes;
[0034] Select a random number Subsequently, calculate d 0 = K 0 · f t′ , d 1 = K 1 , d 2 = K 2 ;
[0035] For j ∈ [l], calculate where, λ' j represents a random number, and ρ(j) represents the attribute value corresponding to the j-th row of the matrix M
[0036] Subsequently, calculate d 6 = F(e(g, g) αs′ )· g t′ , d 7 = g s′ , F(·) represents the hash function that maps group elements to group;
[0037] Randomly select and calculate e 0 = g cd′ , e 1 = g a(d′+s′) g bd′H(KW) , e 2 = g bs′ , for any j ∈ [l], calculate
[0038] The re-encryption key is represented as:
[0039] rk ID→W =(d 0 ,d 1 ,d 2 ,{d j,3 ,d j,4 ,d j,5} j∈[l] ,d 6 ,d 7 ,e 0 ,e 1 ,e 2 ,{e j,3} j∈[l] ).
[0040] Furthermore, the cloud server re-encrypts the original ciphertext using the re-encryption key to obtain the re-encrypted ciphertext, specifically including:
[0041] First, calculate B = e(d 0 ,C 0 )·e(d 1 ,C 1 )·e(d 2 ,C 2 );
[0042] Subsequently, calculate C′ = C / B;
[0043] The re-encrypted ciphertext is represented as:
[0044] ct′=(C′,C′ 0 ,{C′ j,1 ,C′ j,2 ,C′ j,3} j∈[l] ,C′ 4 ,C′ 5 ,W′ 0 ,W′ 1 ,W′ 2 ,{W′ j,3} j∈[l] )
[0045] Where:
[0046] {C′ j,1 =d j,3 ,C′ j,2 =d j,4 ,C′ j,3 =d j,5} j∈[l]
[0047] C′ 4= C 3 = f s
[0048] C' 5 = d 7 , W' 0 = e 0 , W' 1 = e 1
[0049] {W' j,3 = e j,3} j∈[l] 。
[0050] Furthermore, the cloud server distributes the re-encrypted ciphertext to the corresponding authorized users, and the authorized users decrypt the re-encrypted ciphertext with their respective attribute keys to obtain the original data, which specifically includes:
[0051] For the original ciphertext, calculate B = e(K 0 , C 0 )·e(K 1 , C 1 )·e(K 2 , C 2 ), and then calculate the plaintext message m = C / B;
[0052] For the re-encrypted ciphertext, calculate:
[0053]
[0054] Then calculate g t′ = C' 0 / F(e(g, g) αs′ ), and finally calculate the plaintext message m = C'·e(g t′ , C' 4 ).
[0055] Furthermore, the data owner generates an identity threshold with his own identity key, which specifically includes:
[0056] The data owner with the identity key sk ID selects a random element and calculates:
[0057] τ 1 = (g a g bH(KW′) ) γ , τ 2 = g cγ , τ 3 = V γ , Z' = Z γ ;
[0058] Wherein, KW′ represents the keyword provided during retrieval;
[0059] sk ID The corresponding identification threshold is expressed as:
[0060] τ ID =(τ 1 ,τ 2 ,τ 3 ,K′ 1 ,K′ 2 ,Z′)
[0061] The cloud server performs an identification threshold test on the original ciphertext based on the identification threshold of the data owner and returns the corresponding test result, specifically including:
[0062] Calculate the following formula:
[0063]
[0064] If e(W,τ 1 )·(W 1 ,τ 3 )·F = e(W 0 ,τ 2 ), it indicates a successful retrieval, that is, KW' = KW, and return 1; otherwise, the retrieval fails, that is, KW' ≠ KW, and return 0.
[0065] Furthermore, each authorized user generates a corresponding attribute threshold with their own attribute key, specifically including:
[0066] The user with the attribute key selects a random number and calculates:
[0067] Y′ = Y γ , Z′ = Z γ ;
[0068] For any i ∈ [k], calculate Y i ′ = Y i γ ;
[0069] The attribute threshold corresponding to the attribute key is expressed as:
[0070]
[0071] The cloud server performs an attribute threshold test on the re-encrypted ciphertext based on the attribute threshold of each authorized user and returns the corresponding test result, specifically including:
[0072] Calculate the following formula:
[0073]
[0074] If e(W 0 ′,τ 1 )·(W 2 ′,τ 3 )·F = e(W 1 ′,τ 2 ) indicates a successful retrieval, i.e., KW' = KW, and returns 1; otherwise, the retrieval fails, i.e., KW' ≠ KW, and returns 0.
[0075] Beneficial effects: Compared with the prior art, the present invention has the following advantages:
[0076] (1) Through the method of the present invention, one-to-many data encryption sharing based on an untrusted cloud can be achieved, that is, data storage, sharing, and keyword retrieval without revealing any privacy information can be realized under the assumption that the third-party cloud server is honest but curious.
[0077] (2) In the method of the present invention, on the one hand, the data owner can encrypt the original data with his own private key and upload the ciphertext to the cloud server for outsourcing storage, thus saving local storage space; on the other hand, when data sharing is required for multiple people, the data owner only needs to generate an authorization key with his own private key to authorize the cloud server to convert the stored ciphertext into a ciphertext that the target (shared) user can decrypt; in addition, both the data owner and the authorized user can generate a threshold with their own private keys to realize keyword retrieval of data on the cloud, thereby improving the data reading efficiency. It should be noted that all the above operations are performed in ciphertext form on the cloud without revealing any plaintext data or user-related sensitive information, thus ensuring the security of the entire data sharing process.
[0078] (3) The method of the present invention solves the problem of parameter redundancy existing in the existing one-to-many encrypted data sharing scheme. The method of the present invention adds four keyword retrieval-related algorithms, namely identity threshold generation, attribute threshold generation, identity threshold test, and attribute threshold test, to realize the ciphertext keyword retrieval function based on one-to-many encrypted data sharing. Description of the Drawings
[0079] Figure 1 It is a schematic flowchart of a hybrid proxy re-encryption method supporting keyword retrieval in the data encryption sharing stage;
[0080] Figure 2 It is a schematic flowchart of a hybrid proxy re-encryption method supporting keyword retrieval in the ciphertext data retrieval stage;
[0081] Figure 3Schematic diagram of an application of a hybrid proxy re-encryption method supporting keyword search in a medical scenario proposed by the present invention;
[0082] Figure 4 Schematic diagram of the performance test of each algorithm proposed by the present invention, where Figure 4 in (a) is the schematic diagram of the performance test of the key generation algorithm, Figure 4 in (b) is the schematic diagram of the performance test of the encryption algorithm, Figure 4 in (c) is the schematic diagram of the performance test of the threshold generation algorithm, Figure 4 in (d) is the schematic diagram of the performance test of the re-encryption related algorithm, Figure 4 in (e) is the schematic diagram of the performance test of the threshold test algorithm, Figure 4 in (f) is the schematic diagram of the performance test of the decryption algorithm. Detailed implementation manners
[0083] To make the objectives, technical solutions and advantages of the present invention clearer, the following will further describe a hybrid proxy re-encryption method and system supporting keyword search proposed by the present invention with reference to the accompanying drawings in the present invention.
[0084] Example 1:
[0085] This example proposes a hybrid proxy re-encryption method supporting keyword search for realizing data encryption and sharing. The specific implementation steps are as Figure 1 shown and include:
[0086] Step 101: The key generation center KGC generates an identity key for the data owner and sends the corresponding key to the data owner through a secure channel (such as HTTPS). The specific implementation steps include:
[0087] System initialization Setup(1 λ )→(pp, msk), where λ is a security parameter, and 1 λ represents the bit length corresponding to the security parameter λ. The key generation center KGC first selects random numbers and Subsequently, calculate g a , g b , g c . The system public parameters pp and the master key msk can be respectively expressed as:
[0088] pp = g, g a , g b , g c , u, h, w, v, f, e(g, g) α
[0089] msk = (α, a, b)
[0090] In the formula, the bilinear mapping e(·): represents mapping elements from two groups to elements in group, that is, e(g, g) α is an element in the group, and the set corresponding to the group is the set formed by the Cartesian product of the elements in the group and G T are two different multiplicative cyclic groups defined on the elliptic curve;
[0091] Identity key generation KeyGen(pp, msk, ID) → sk ID : The key generation center KGC selects a random number r and calculates K 0 = g α w r , K 1 = (u ID h) -r , K 2 = g r , V = g (ac-r) / b , Z = f r , and the identity key corresponding to the identity ID can be expressed as: sk ID = (K 0 , K 1 , K 2 , V, Z).
[0092] Step 102: The key generation center KGC generates attribute keys for users with specific attributes and distributes the corresponding attribute keys to different users through a secure channel (such as HTTPS). The specific attribute is the attribute information abstracted from the user characteristics, generally identified by a string. For example, in the medical scenario, the attributes may be "doctor", "patient", "hypertension", "heart disease", "general surgery", "neurology", etc. In the education scenario, they may be "student", "teacher", "Peking University", "Tsinghua University", "higher mathematics", "abstract algebra", etc. The specific implementation steps include:
[0093] Attribute key generation The key generation center KGC randomly selects and calculates For any i ∈ [k], where k represents the number of attributes, calculate In the formula, A i represents the value of the attribute;
[0094] The key for the user with specific attributes can be expressed as:
[0095]
[0096] In the formula, represents a set of attribute information, which is a set composed of the specific attributes mentioned above and is used to describe a specific entity. For example, in a medical scenario, when describing a doctor, the set of attribute information can be {"doctor", "general surgery department"}, and when describing a patient, the set of attribute information can be {"patient", "heart disease", "neurology department"}.
[0097] Step 103: The data owner encrypts the original data with his own identification ID to obtain the original ciphertext. The specific implementation steps include:
[0098] Data encryption Encrypt(pp, m, ID, KW) → ct ID : The data owner selects a random element and calculates C = m · e(g, g) αs , C 0 = g s , C 1 = g t , C 2 = (u ID h) t w -s , C 3 = f s , m represents the plaintext message. Subsequently, a random is selected and W = g cd , W 0 = g a(d+s) g bdH(KW) , W 1 = g bs , E = f s (u ID h) s , where H(·) represents a hash function that maps the keyword KW to the group), and KW represents the keyword bound during the original encryption;
[0099] The original ciphertext can be expressed as:
[0100] ct ID = (C, C 0 , C 1 , C 2 , C 3 , W, W 0 , W 1 , E)
[0101] Step 104: The data owner uploads the original ciphertext to the cloud server for storage;
[0102] Step 105: When data sharing is required, the data owner generates a re-encryption key based on its identity key and the access control policy corresponding to the attributes of the user whose key is to be shared (here, it is assumed to be the user who has obtained the key from the KGC in Step 102); the specific implementation steps are as follows:
[0103] Re-encryption key generation RKGen(pp,sk ID ,W,KW)→rk ID→W : The data owner with the identity key sk ID based on the policy W=(M,ρ) encoded in the LSSS, where and ρ: l represents the row number, and a row of the matrix is mapped to specific attribute values. First, select where represents a random vector, s′ represents a random number, y n represents a random element, and n represents the number of attributes of the authorized user attributes;
[0104] Select a random number Subsequently, calculate d 0 =K 0 ·f t′ , d 1 =K 1 , d 2 =K 2 .
[0105] For j∈[l], calculate where λ′ j represents a random number, and ρ(j) represents the attribute value corresponding to the j-th row of the matrix M;
[0106] Subsequently, calculate d 6 =F(e(g,g) αs′ )·g t′ , d 7 =g s′ , F(·) represents a hash function, F(e(g,g) αs′ ) represents the hash function that maps the group element to the group, and the content inside is the result of the bilinear mapping.
[0107] To achieve the feature of ciphertext retrieval, randomly select and calculate e 0 =g cd′ , e 1 =g a(d'+s′) g bd'H(KW) , e 2 =g bs' , and for any j∈[l], calculate The re-encryption key can be expressed as:
[0108] rk ID→W =(d 0 ,d 1 ,d 2 ,{d j,3 ,d j,4 ,d j,5}} j∈[l] ,d 6 ,d 7 ,e 0 ,e 1 ,e 2 ,}e j,3}} j∈[l] )
[0109] Step 106: The data owner uploads the re-encryption key to the cloud server;
[0110] Step 107: The cloud server re-encrypts the original ciphertext uploaded in Step 104 using the re-encryption key uploaded in Step 106 to obtain a re-encrypted ciphertext; The specific implementation steps include:
[0111] Re-encryption Input the re-encryption key rk ID→W and the original ciphertext ct ID , The re-encryption algorithm first calculates B = e(d 0 ,C 0 )·e(d 1 ,C 1 )·e(d 2 ,C 2 ), and then calculates C' = C / B.
[0112] Other components of the re-encrypted ciphertext include:
[0113] {C′ j,1 =d j,3 ,C′ j,2 =d j,4 ,C′ j,3 =d j,5}} j∈[l]
[0114] C′ 4 =C 3 =f s
[0115] C′ 5 =d 7 ,W 0 ′=e 0 ,W 1 ′=e 1 ,
[0116] {W′ j,3 =e j,3} j∈[l]
[0117] The re-encrypted ciphertext can be expressed as:
[0118] ct′=(C′,C′ 0 ,{C′ j,1 ,C′ j,2 ,C′ j,3} j∈[l] ,C′ 4 ,C′ 5 ,W 0 ′,W 1 ′,W 2 ′,{W′ j,3} j∈[l] )
[0119] Step 108: The cloud server distributes the re-encrypted ciphertext to the corresponding authorized user (assumed to be the user in Step 102).
[0120] Step 109: The authorized user decrypts the re-encrypted ciphertext distributed in Step 108 with their respective keys to obtain the original data. The specific implementation steps include:
[0121] Data decryption Decrypt(ct,sk)→m: For the original ciphertext, calculate B = e(K 0 ,C 0 )·e(K 1 ,C 1 ), then calculate the plaintext message m = C / B; 2 ,C 2 )
[0122] For the re-encrypted ciphertext, the decryption algorithm calculates:
[0123]
[0124] Then calculate g t′ = C′ 0 / F(e(g,g) αs′ ), and finally calculate the plaintext message m = C'·e(g t′ ,C′ 4 ).
[0125] Embodiment 2:
[0126] Based on Embodiment 1, this embodiment proposes a hybrid proxy re-encryption method that supports keyword search for implementing ciphertext data retrieval. The specific execution steps are as Figure 2 shown and include:
[0127] According to the steps disclosed in Embodiment 1, the following were generated:
[0128] The identification key ct' = (C′, C′ 0 , {C′ j,1 , C′ j,2 , C′ j,3} j∈[l] , C′ 4 , C′ 5 , W 0 ′, W 1 ′, W 2 ′, {W′ j,3} j∈[l] )
[0129] The attribute key
[0130] The original ciphertext ct ID = (C, C 0 , C 1 , C 2 , C 3 , W, W 0 , W 1 , E)
[0131] The re-encryption key rk ID→W = (d 0 , d 1 , d 2 , {d j,3 , d j,4 , d j,5} j∈[l] , d 6 , d 7 , e 0 , e 1 , e 2 , {e j,3} j∈[l] )
[0132] The re-encrypted ciphertext ct' = (C′, C′ 0 , {C′ j,1 , C′ j,2 , C′ j,3} j∈[l] , C′ 4 , C′ 5 , W 0 ′, W 1 ′, W 2 ′, {W′ j,3} j∈[l] )
[0133] That is Figure 2 Steps 201 and 202 in
[0134] Step 203: The data owner uses its identity key sk ID to generate an identity threshold and upload it to the cloud server for ciphertext data retrieval. The specific implementation steps include:
[0135] Generate the identity threshold Trapdoor ID (pp, sk ID , KW′) → τ ID : The data owner with the identity key sk ID selects a random element and calculates τ 1 = (g a g bH(KW′) ) γ , τ 2 = g cγ , τ 3 = V γ , Z′ = Z γ , sk ID The corresponding identity threshold can be expressed as: τ ID = (τ 1 , τ 2 , τ 3 , K′ 1 , K′ 2 , Z′). KW′ represents the keyword for retrieval.
[0136] Step 204: Each authorized user (assumed to be the corresponding user in Step 202) uses its attribute key to generate the corresponding attribute threshold and uploads the attribute threshold to the cloud server for re-encrypted ciphertext retrieval. The specific implementation steps include:
[0137] Generate the attribute threshold The user with the attribute key selects a random number and calculates Y′ = Y γ , Z′ = Z γ , for any i ∈ [k], calculates Y i ′ = Y i γ , The attribute threshold corresponding to the attribute key can be expressed as:
[0138]
[0139] Step 205: The cloud server performs an identity threshold test on the original ciphertext based on the identity threshold of the data owner and returns the corresponding test result. The specific implementation steps include:
[0140] Identity threshold test Test ID (ctID , τ ID ) → {0, 1}: Calculate:
[0141]
[0142] If e(W, τ 1 ) · (W 1 , τ 3 ) · F = e(W 0 , τ 2 ), it means the retrieval is successful, i.e., KW' = KW, return 1; otherwise, the retrieval fails, i.e., KW' ≠ KW, return 0.
[0143] Step 206: The cloud server performs an attribute threshold test on the re-encrypted ciphertext based on the attribute threshold of each authorized user and returns the corresponding test result. The specific implementation steps include:
[0144] Attribute Threshold Test First, calculate:
[0145]
[0146] If e(W 0 ′, τ 1 ) · (W 2 ′, τ 3 ) · F = e(W 1 ′, τ 2 ), it means the retrieval is successful, i.e., KW' = KW, return 1; otherwise, the retrieval fails, i.e., KW' ≠ KW, return 0.
[0147] Example 3:
[0148] Apply the hybrid proxy re-encryption method supporting keyword retrieval proposed in Example 1 or Example 2 to the medical scenario. As Figure 3 shown, after the patient obtains the physical examination report, the patient can encrypt the report with his own identity key and store the ciphertext in the cloud server. When the patient needs a multi-doctor joint consultation, the patient can authorize the corresponding doctor to access the physical examination report by uploading the authorization key. In this process, multiple doctors can correspond to the same re-encrypted ciphertext without complex ciphertext and key management.
[0149] For this scenario, based on the Ubuntu 20.04 LTS Desktop system and the 3.0 GHz AMD Ryzen 5 4600H CPU and 16 GB RAM environment, as Figure 4As shown below, the performance tests are as follows: For the key generation algorithm, the time overhead for identity key generation remains basically unchanged at 6.80 milliseconds, while the time overhead for the attribute key generation algorithm grows linearly with the increase in the number of attributes; the time overhead for the original ciphertext encryption algorithm also stabilizes at around 9.5 milliseconds; for the threshold generation algorithm, the time overhead for the identity threshold generation algorithm is approximately constant at 6 milliseconds, while the time overhead for the attribute threshold generation algorithm grows linearly with the increase in the number of attributes; the time overhead for the re-encryption key generation algorithm grows linearly with the increase in the number of attributes of the authorized users, while the time overhead for the re-encryption process is fixed at around 2 milliseconds; for the threshold testing algorithm, the time overhead for identity threshold testing remains constant at approximately 3.5 milliseconds, while the time overhead for the attribute threshold testing grows linearly with the increase in the number of attributes; for the decryption algorithm, the time overhead for the original ciphertext decryption algorithm remains unchanged at approximately 1.7 milliseconds, while the time overhead for the re-encrypted ciphertext decryption grows linearly with the increase in the number of attributes.
[0150] All of the above operations are performed in ciphertext form on the cloud, without leaking any plaintext data or sensitive information related to users, thus ensuring the security of the entire data sharing process.
Claims
1. A hybrid proxy re-encryption method supporting keyword retrieval, characterized by: The following steps are involved: The key generation center generates an identification key for the data owner and sends the identification key to the data owner through a secure channel; the key generation center generates an attribute key for a user with a specific attribute and distributes the attribute key to the user through a secure channel; the specific attribute is attribute information abstracted from user characteristics; The data owner uses his own ID to encrypt the original data, obtains the original ciphertext, and uploads the original ciphertext to the cloud server for storage; The data owner generates a re-encryption key based on his / her identification key and the access control policy corresponding to the authorized user attributes; The data owner uploads the re-encryption key to the cloud server, and the cloud server uses the re-encryption key to re-encrypt the original ciphertext to obtain the re-encrypted ciphertext; When data is shared, the cloud server distributes the re-encrypted ciphertext to the corresponding authorized users, and the authorized users use their own attribute keys to decrypt the re-encrypted ciphertext and obtain the original data; When searching for ciphertext data, the data owner generates an identification threshold using his / her own identification key and uploads the identification threshold to the cloud server for ciphertext data retrieval. The cloud server performs an identification threshold test on the original ciphertext based on the identification threshold of the data owner and returns the corresponding test result. Each authorized user generates a corresponding attribute threshold with his or her own attribute key and uploads the attribute threshold to the cloud server for re-encrypted ciphertext retrieval. The cloud server performs an attribute threshold test on the re-encrypted ciphertext based on the attribute threshold of each authorized user and returns the corresponding test result.
2. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 1, characterized in that: The key generation center generates an identification key for the data owner, specifically including: Pick a random number as well as Calculate g a ,g b ,g c ; The system public parameter pp and the master key msk are expressed as: pp=g,g a ,g b ,g c ,u,h,w,v,f,e(g,g) α msk=(α,a,b) In the formula, the bilinear mapping Indicates that two The elements in the group are mapped to The elements in the group, The corresponding set of groups is The set consisting of the Cartesian product of the elements in the group, and G T are two different multiplicative cyclic groups defined on elliptic curves; Select a random number r and calculate K0=g α w r , K1=(u ID h) -r , K2=g r , V = g (ac-r) / b , Z = f r ; The identification key of the data owner corresponding to the identification ID is expressed as: sk ID =(K0,K1,K2,V,Z).
3. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 2, characterized in that: The key generation center generates attribute keys for users with specific attributes, specifically including: Random Selection And calculate For any i∈[k], where k is the number of attributes, calculate In the formula, A i Indicates the value of each attribute; Possessing specific attributes The attribute key corresponding to the user is expressed as: In the formula, Represents a collection of attribute information.
4. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 3, characterized in that: The data owner uses his own ID to encrypt the original data to obtain the original ciphertext, which specifically includes: The data owner selects a random element And calculate C = m·e(g,g) αs , C0=g s , C1=g t , C2=(u ID h) t w -s , C3=f s , m represents the plaintext message; Random Selection And calculate W = g cd , W0=g a(d+s) g bdH(KW) , W1=g bs , E = f s (u ID h) s , where H(·) represents mapping the keyword KW to The hash function of the group, KW represents the keyword bound during the original encryption; The original ciphertext is represented as: ct ID =(C,C0,C1,C2,C3,W,W0,W1,E)。 5. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 4, characterized in that: The data owner generates a re-encryption key according to his / her identification key and the access control policy corresponding to the authorized user attributes, specifically including: Define the access control policy W = (M, ρ) corresponding to the authorized user attributes, where and l represents the row number, and a row of the matrix is mapped to a specific attribute value; Owns the identification key sk ID Data owner selection in, represents a random vector, s′ represents a random number, y n represents a random element, and n represents the number of attributes of the authorized user attributes; Pick a random number Then calculate d0 = K0·f t′ , d1=K1, d2=K2; For j∈[l], calculate Among them, λ′ j represents a random number, ρ(j) represents the attribute value corresponding to the jth row of matrix M Then calculate d6 = F(e(g,g) αs′ )·g t′ , d7 = g s′ , F(·) means Group elements are mapped to Hash functions in groups; Random Selection And calculate e0 = g cd′ , e1=g a(d′+s′) g bd'H(KW) , e2=g bs′ , for any j∈[l], calculate The re-encryption key is represented as: rk ID→W =(d0,d1,d2,{d j,3 ,d j,4 ,d j,5 } j∈[l] ,d6,d7,e0,e1,e2,{e j,3 } j∈[l] )。 6. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 5, characterized in that: The cloud server re-encrypts the original ciphertext using the re-encryption key to obtain the re-encrypted ciphertext, which specifically includes: First, calculate B = e(d0, C0)·e(d1, C1)·e(d2, C2); Then, calculate C'=C / B; The re-encrypted ciphertext is represented as: ct'=(C′,C′0,{C′ j,1 ,C′ j,2 ,C′ j,3 } j∈[l] ,C′4,C5′,W0′,W1′,W2′,{W′ j,3 } j∈[l] ) in: {C′ j,1 =d j,3 ,C′ j,2 =d j,4 ,C′ j,3 =d j,5 } j∈[l] C′4=C3=f s C′5=d7,W0′=e0,W1′=e1 {W′ j,3 =e j,3 } j∈[l] .
7. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 6, characterized in that: The cloud server distributes the re-encrypted ciphertext to the corresponding authorized users, and the authorized users decrypt the re-encrypted ciphertext with their own attribute keys to obtain the original data, specifically including: For the original ciphertext, calculate B = e(K0,C0)·e(K1,C1)·e(K2,C2), and then calculate the plaintext message m = C / B; For the re-encrypted ciphertext, calculate: Then calculate g t′ =C′0 / F(e(g,g) αs′ ), and finally calculate the plaintext message m = C'·e(g t′ ,C′4).
8. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 6, characterized in that: The data owner generates an identification threshold using his own identification key, which specifically includes: Owns the identification key sk ID The data owner selects a random element And calculate: τ1=(g a g bH(KW′) ) γ ,τ2=g cγ ,τ3=V γ , Z′=Z γ ; In the formula, KW′ represents the keywords provided during the search; sk ID The corresponding identification threshold is expressed as: t ID =(τ1,τ2,τ3,K1′,K′2,Z′) The cloud server performs an identification threshold test on the original ciphertext based on the identification threshold of the data owner, and returns the corresponding test results, which specifically include: Calculate the following formula: If e(W,τ1)·(W1,τ3)·F=e(W0,τ2), it means the retrieval is successful, that is, KW'=KW, and 1 is returned; otherwise, the retrieval fails, that is, KW'≠KW, and 0 is returned.
9. A hybrid proxy re-encryption method supporting keyword retrieval according to claim 6, characterized in that: Each authorized user generates a corresponding attribute threshold using his own attribute key, specifically including: Has attribute key sk S The user picks a random number And calculate: Y′=Y γ ,Z′=Z γ ; For any i∈[k], calculate Y i ′=Y i γ ; Attribute key sk s The corresponding attribute threshold is expressed as: t s =(τ1,τ2,τ3,Y′,{Y i ′} i∈[k] ,Z′) The cloud server performs an attribute threshold test on the re-encrypted ciphertext based on the attribute threshold of each authorized user, and returns the corresponding test results, including: Calculate the following formula: If e(W0′,τ1)·(W2′,τ3)·F=e(W1′,τ2), it means the retrieval is successful, that is, KW'=KW, and 1 is returned; otherwise, the retrieval fails, that is, KW'≠KW, and 0 is returned.
Citation Information
Patent Citations
Property base keyword searching method supporting efficient revocation in cloud environment
CN106330865A
Ciphertext retrieval system and method for supporting proxy re-encryption in combination with identity and attribute
CN108400871A
Verifiable semantic security multi-keyword search method in cloud storage
CN109450935A
Content safe sharing method and system based on proxy re-encryption
CN109660555A
An attribute-based ciphertext search method capable of controlling search authority
CN109740364A