Traceable and revocable attribute-based encryption method suitable for cloud computing

By adopting a traceable revocable attribute-based encryption method in the cloud computing environment, using the KEK tree and key detection and tracking module, the problems of user key tracking and attribute revocation in cloud storage are solved, efficient data sharing and fine-grained access control are realized, and computing burden and data transmission delay are reduced.

CN120074860APending Publication Date: 2025-05-30HUAIYIN INSTITUTE OF TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510016666.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing attribute-based encryption method is difficult to achieve traceability of user keys and real-time revocation of attributes in cloud storage, especially on devices with limited resources, and there is a problem of data transmission delay.

Method used

The traceable revocable attribute-based encryption method suitable for cloud and fog computing is adopted. By sharing the encryption and decryption calculation tasks between cloud service providers and fog devices, the attribute-level user revocation is achieved using the KEK tree, and the usage of user keys is tracked through the key detection tracking module.

Benefits of technology

It realizes the traceability of user keys and revocability of attributes in cloud storage, reduces the computing burden of local devices, improves the system's response speed, and reduces data transmission delay.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074860A_ABST
    Figure CN120074860A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of cloud computing and fog computing security, and discloses a traceable and revocable attribute-based encryption method suitable for cloud computing, which comprises the following steps of: initializing system parameters, and generating a system public key, a system main private key, an attribute manager public key and an attribute manager main private key; according to a user identity, a system public key, an attribute manager public key, a system main private key and a data user attribute set, a user private key, an initial attribute group key, a conversion key and an attribute group key of a user are generated, encryption is carried out according to the public key, an access strategy and the like, and encryption is carried out with the help of fog equipment in the encryption process; the data user carries out decryption and requests outsourcing decryption help from the fog equipment; and tracking and positioning the data, further updating the user attribute group key, and updating the ciphertext according to the ciphertext information and the revoked attribute. Compared with the prior art, the method can achieve the tracking of the user key and the revocation of the attribute in the cloud storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing and fog computing security, and in particular to a traceable and revocable attribute-based encryption method applicable to cloud and fog computing, which realizes the traceability of user keys and the revocation of attributes in cloud storage. Background Art

[0002] Attribute-Based Encryption (ABE) can achieve data confidentiality and fine-grained access control, and is considered to be the most promising method for protecting the security of cloud storage data. Existing ABE can be divided into Key-Policy Attribute-Based Encryption (KP-ABE) and Ciphertext-Policy Attribute-Based Encryption (CP-ABE). Compared with KP-ABE, the CP-ABE scheme is more suitable for cloud storage application scenarios.

[0003] Attribute revocation is a key function of ABE. In 2006, Pirretti et al. first proposed a CP-ABE scheme to achieve indirect revocation of users, which associates the expiration date of attributes with the attributes and realizes the revocation of attributes by periodically updating keys, but requires the attribute authorization to be online in real time and cannot achieve real-time revocation of attributes. In 2010, Li et al. constructed a CP-ABE scheme. Data users must have both the private key and the attribute group key to successfully decrypt the ciphertext. When an attribute is revoked, the system updates the attribute group key and the ciphertext. Once the attribute group key and the ciphertext are updated, the data users with the revoked attributes will lose the decryption permission. In 2011, Hur et al. introduced the concept of attribute groups and proposed an attribute-level user revocation CP-ABE scheme based on a key-encrypted key tree, which realizes fine-grained attribute revocation, but cannot resist the collusion attack between revoked users and non-revoked users. In 2020, Liu et al. introduced a key tree to achieve attribute-level revocation, but some information related to attributes in all keys needs to be stored in the ciphertext, resulting in a high storage overhead.

[0004] Due to the problems of key abuse and attribute revocation, the revocation and traceability research of ABE has received widespread attention. In 2013, Liu et al. constructed a white-box traceable CP-ABE scheme, which can track malicious users through leaked decryption keys. In 2015, Liu et al. proposed a black-box traceable CP-ABE scheme, which can identify malicious users who leak their decryption rights as decryption black boxes for some economic benefits or other incentives from the decryption device. In 2016, Ma et al. proposed an adaptively secure and traceable CP-ABE scheme, which can not only adaptively track malicious users, but also further enhance the security of the ABE system, and has certain theoretical and application value.

[0005] In 2023, Guo et al. proposed an efficient, traceable and revocable outsourced attribute-based encryption scheme. Attribute-based encryption is implemented on resource-constrained devices, cloud computing is used to reduce the computational workload of local users, and the identity of malicious users who leaked keys can be tracked. Finally, the attribute-level user revocation is achieved through key encryption key tree.

[0006] 3.2 The most similar prior art implementation to the present invention

[0007] In 2023, Guo et al. designed an efficient, traceable and revocable outsourced attribute-based encryption scheme. The scheme aims to implement attribute-based encryption operations on resource-constrained devices, outsourcing a large amount of computing to cloud servers to reduce the computing burden of local users. At the same time, the scheme can also track the identity of users who maliciously leak keys, and use the key encryption key tree mechanism to implement the attribute-level user revocation function.

[0008] In many practical application scenarios, such as intelligent transportation systems, the data stored by sensors, cameras and other devices are extremely sensitive and real-time, which requires that the computing pressure of local devices must be reduced as much as possible during data transmission, while greatly improving the response speed. Guo et al.'s solution reduces the computing burden of resource-constrained devices to a certain extent through outsourcing technology, but the cloud storage server in this solution is far away from the data source and the user end, resulting in a large delay problem in data transmission in scenarios with extremely high real-time requirements. In contrast, fog computing, with its unique advantages of distributed architecture, can realize parallel processing of data on multiple nodes in the network, which can significantly enhance the overall processing capacity and scalability of the system, and better meet the high requirements of intelligent transportation systems for data real-time and processing efficiency. Summary of the invention

[0009] Objective of the Invention: Aiming at the problems in the background art, the present invention discloses a traceable and revocable attribute-based encryption method applicable to cloud fog computing, which can ensure secure data sharing and fine-grained access control in the cloud fog environment, effectively alleviate the decryption computing cost of users with limited computing resources, and enable the traceability of user keys and the revocation of attributes in cloud storage.

[0010] Technical Solution: The present invention discloses a traceable and revocable attribute-based encryption method applicable to cloud fog computing, which includes the following steps:

[0011] Step 1: System Parameter Initialization: Input the security parameter λ, and the attribute authority AA outputs the system public key PK and the system master private key MSK. The attribute manager AM outputs the attribute manager public key APK and the attribute manager master private key ASK according to the system public key PK, and sends the system public key PK and the system master private key MSK to the encryption module, the key detection and tracing module, and the key generation module, sends the attribute manager public key APK to the key generation module, sends the attribute manager master private key ASK to the encryption module, and initializes the user revocation list at the same time.

[0012] Step 2: Key Generation Module: The AA generates the user private key SK, the initial attribute group key IAGK, and the transformation key TK according to the user identity ID, the system public key PK, the attribute manager public key APK, the system master private key MSK, and the data user attribute set S, and sends the transformation key TK to the decryption module, sends the user key SK to the decryption module and the key tracing module. The AM generates the user's attribute group key AGK according to the initial attribute group key IAGK and the data user attribute set S and sends it to the decryption module and the key detection and tracing module.

[0013] Step 3: Encryption Module: The data owner DO outputs the ciphertext header Hdr and the ciphertext CT according to the system public key PK, the access policy matrix (M, ρ), the plaintext m, and the attribute manager master private key ASK, and sends the ciphertext header Hdr and the ciphertext CT to the attribute revocation module and the decryption module. The data owner DO is divided into two specific types, DOf and DOc. In the cloud fog computing environment, DOf is located at the bottom layer. Before storing the data in the cloud service provider CSP, DOf needs to access the target fog device FD, and the fog device FD outputs the ciphertext header Hdr and the ciphertext CT. DOc is in the middle layer. DOc directly outputs the ciphertext header Hdr and the ciphertext CT and outsources the data to the cloud service provider CSP without the help of the fog device FD.

[0014] Step 4: Decryption Module: The data user DU decrypts the output plaintext m based on the received ciphertext header Hdr, ciphertext CT, user private key SK, transformation key TK, and the user's attribute group key AGK. According to the computing power and storage capacity of the data user DU, DU is specifically divided into two types: DUf and DUc. DUf is located at the bottom layer of the fog and cloud computing environment. After obtaining data from the CSP, DUf requests outsourcing decryption assistance from the target fog device FD. DUc is in the middle layer, that is, in the cloud computing environment, DUc directly decrypts the data from the CSP without the help of the fog device FD.

[0015] Step 5: Key Detection and Tracking Module: The AM checks whether the user private key SK is a key with the correct format based on the system public key PK, system master private key MSK, and user private key SK. If not, it sends an instruction to the attribute revocation module for attribute revocation and uses the attribute manager's master private key ASK, user attribute group key AGK, and the revoked attribute att x as input to output a new user attribute group key and send it to the decryption module; if it is a correct key, no attribute revocation will be performed.

[0016] Step 6: Attribute Revocation Module: The AM outputs a new ciphertext header x and a new ciphertext and sends them to the decryption module based on the ciphertext header Hdr, ciphertext CT, and the revoked attribute att .

[0017] Furthermore, the system parameter initialization in Step 1 is specifically as follows:

[0018] Step 1.1: Input the security parameter λ, and the AA selects two multiplicative cyclic groups G and G of prime order p T , where g is the generator of G and e is the bilinear mapping G×G→G T ;

[0019] Step 1.2: The AA selects the hash function H 1 :{0,1} * →G, and H:{0,1} * →G. H has collision resistance. Select k 1 , k 2 ∈K as the key of the symmetric encryption algorithm, and output the system public key PK of the attribute authorization agency = {g, e(g, g) α , g a , H 1 , H 2 , H} and the system master private key MSK = {g α , k 1 , k2}, initialize the user revocation list;

[0020] Step 1.3: For each attribute att i , randomly select an exponent Calculate Output the attribute manager public key APK = {t i | 1 ≤ i ≤ n} and the attribute manager master private key ASK = {t i | 1 ≤ i ≤ n}.

[0021] Furthermore, the generation process of the user private key SK, transformation key TK, and initial attribute group key IAGK in Step 2 is as follows:

[0022] AA randomly selects Using k 1 as the key to symmetrically encrypt ID to generate ζ. Similarly, using k 2 as the key to symmetrically encrypt ζ || θ to generate δ, that is, calculate Calculate L = g δ , K = g α+aδ and K 1 = g aδz H(0 || 1 || 1 || 1) δz , for any attribute att i ∈ S, calculate k i = H(att i || 1 || 1) δz and Output the user private key SK = {K, L, RK = z}, transformation key and initial attribute group key AA distributes the user private key SK to the user through a secure channel, sends the transformation key TK to the decryption module on the cloud service provider CSP, and sends the initial attribute group key IAGK to AM.

[0023] Furthermore, the specific generation process of the user's attribute group key AGK in Step 2 is as follows:

[0024] Step 2.1: Let U = {u 1 , u 2 ,..., u n} represent the user set, L = {λ 1 , λ 2 ,..., λ n} represent the set of all users' attributes in the system, represents the set of users who own the attribute λ i in the KEK tree, as an access list or revocation list for a certain attribute λ i , G = {G 1,G 2 ,...,G n} represents the set of attribute groups;

[0025] Step 2.2: AM calculates and constructs a KEK tree to generate relevant parameters for users according to the following process. The leaf nodes in the binary tree represent the users in the user set U, and each non-leaf node v j stores a random value θ j ;

[0026] Step 2.3: Path node algorithm Path(u k ): For each user u k , all the nodes from the leaf node to the root node are defined as the path nodes of user u k ;

[0027] Step 2.4: Minimum covering set algorithm Mincs(G i ): For the attribute group G i with the attribute λ i in the KEK tree, the smallest node set in the tree that can cover G i is the minimum covering set;

[0028] Step 2.5: Intersection of Path(u k ) and Mincs(G i ): If user u k has the attribute λ i in the KEK tree, that is, u k ∈G i , then the intersection has exactly one node v j storing the random value θ j ;

[0029] Step 2.6: AM generates an attribute group key for the user according to the KEK tree. For any attribute att i ∈S, AM calculates to judge whether it is empty. If AM stops the calculation. If AM calculates where the node corresponding to the random value θ j AM outputs

[0030] Furthermore, the encryption process in step 3 is specifically as follows:

[0031] Step 3.1: DOf inputs the system public key PK, the plaintext m, and the access policy matrix (M, ρ). Assume the matrix M has l rows and n columns. The function ρ maps the matrix M to the user attribute set, and defines M i,jis the (i,j)-th element of matrix M. Let s = H 2 (m, R), where The specific encryption process is as follows:

[0032]

[0033] Calculate k = H(R), and use the symmetric key k to encrypt the plaintext m, that is, CT m = Enc k (m), and output the intermediate ciphertext CT'=(CT m , C, C', {C i} i∈[l] ) and send it to the fog device FD;

[0034] Step 3.2: For each attribute att i in the access policy matrix (M, ρ) of the fog device FD, 1 ≤ i ≤ n, randomly select and call the minimum cover set algorithm Mincs(G i ), re-encrypt the intermediate ciphertext CT' to obtain the ciphertext Calculate the ciphertext header The fog device FD uploads (CT, Hdr) to the CSP for storage;

[0035] Step 3.3: The DOc inputs the system public key PK, the plaintext m, the access policy matrix (M, ρ), and the attribute manager master private key ASK, repeats the encryption processes of Step 3.1 and Step 3.2, and during the repetition process, the intermediate ciphertext is not sent to the fog device FD, and directly calculates the ciphertext and the ciphertext header at the Doc end and uploads (CT, Hdr) to the CSP for storage.

[0036] Furthermore, the decryption module in Step 4 has the following specific process:

[0037] Step 4.1: The DUf sends an outsourced decryption request to the CSP through the FD. When the CSP receives the decryption request, it first determines whether the data user is in the user revocation list according to the ID of the data user. If so, the algorithm returns the termination symbol ⊥; if the attribute set S of the data user satisfies the access policy matrix (M, ρ), then there exists a set of constants {w i} i∈[I] , such that ∑ i∈I w i M i =(1, 0,..., 0), otherwise, the algorithm returns the termination symbol ⊥; The CSP calculates the transformed ciphertext TCT in the following way:

[0038]

[0039] The CSP sends the transformed ciphertext TCT to the FD;

[0040] Step 4.2: DUc directly sends an outsourcing decryption request to the CSP. When the CSP receives the decryption request, it first determines whether the data user is in the user revocation list according to the ID of the data user. If so, the algorithm returns the termination symbol ⊥; if the attribute set S of the data user satisfies the access policy matrix (M, ρ), then there exists a set of constants {w i} i∈[I] , such that ∑ i∈I w i M i =(1, 0,..., 0). Otherwise, the algorithm returns the termination symbol ⊥. The CSP calculates the transformed ciphertext TCT in the following way:

[0041]

[0042] The CSP sends the transformed ciphertext TCT to DUc;

[0043] Step 4.3: After receiving the transformed ciphertext TCT, the FD calculates R′ according to the following calculation steps:

[0044]

[0045] The FD sends the calculated R′ to DUf;

[0046] Step 4.4: After receiving R′, DUf calculates k = H(R′), m = Dec k (CT m ). If holds, then m is the correctly decrypted ciphertext; otherwise, m is invalid;

[0047] Step 4.5: After receiving the transformed ciphertext TCT, DUc can recover the plaintext m according to the following calculation steps:

[0048]

[0049] Calculate k = H(R′), m = Dec k (CT m ). If holds, then m is the correctly decrypted ciphertext; otherwise, m is invalid.

[0050] Furthermore, the specific operation of the key detection and tracking module in Step 5 is as follows:

[0051] Step 5.1: AA verifies whether the user's private key meets the following conditions: Let A = e(K, g), B = e(L, g a ), calculate A / B. If A / B = e(g, g) α, the key check algorithm returns 1; otherwise, the key check algorithm returns 0;

[0052] Step 5.2: When a key leakage occurs, AA executes the following key tracing algorithm: If the key check algorithm outputs 0, it means that the user's private key SK is not a well - formed key. If the key check algorithm outputs 1, then the user's private key SK is a well - constructed key; The tracing algorithm extracts the identity ID from the user's private key SK according to the following calculation method:

[0053] Calculate The user's ID is obtained through and add the user's identity to the user revocation list, and send the user revocation list to the CSP; Denotes the symmetric decryption process;

[0054] Otherwise, the tracing algorithm outputs ⊥;

[0055] Step 5.3: When the attribute att i of user u x is revoked, AM randomly selects σ x and calculates and Use and to replace T in APK and ASK x and t x , to obtain the new attribute manager public key and private key Update the user attribute group and recalculate the minimum covering set algorithm For each user AM calculates After that, calculate and where The corresponding node Finally, AM uses to replace {att x ,v j ,agk x ,AGK x} in the KEK tree as the new user attribute group key

[0056] Furthermore, the attribute revocation module in step 6 operates as follows:

[0057] AM randomly selects Update the ciphertext and ciphertext header:

[0058] When i = x, AM calculates When 1 ≤ i ≤ n, i ≠ x, AM outputs a new ciphertext header and a new ciphertext and then upload them to the CSP.

[0059] Advantageous effects:

[0060] 1. The data owner (such as the traffic management department) of the present invention designates access policies and encrypts the data. These policies are based on user attributes such as position, responsibility, permission level, etc. Only when the attributes possessed by the user satisfy the access policies can the user decrypt and access the data. For example, when a traffic planner needs to access specific traffic flow data, the traffic planner first sends a request to the cloud service provider and provides their private key, attribute group key, and transformation key. After receiving the request, the cloud service provider first verifies the user's attributes through the attribute authorization agency. After successful verification, the data provider encrypts the plaintext into ciphertext through attribute-based encryption with ciphertext policies and uploads the ciphertext to the cloud server. The data providers of the present invention are divided into two categories according to their computing capabilities. Among them, the data providers with stronger computing capabilities will directly encrypt the data and upload it to the cloud server, while the data providers with weaker computing capabilities will perform initial encryption on the data and upload it to the fog node, and the fog node will perform re-encryption and upload it to the cloud server. When the cloud server receives the encrypted data, it will perform preliminary decryption on the data and send the obtained transformation ciphertext to the traffic planner, and the traffic planner will perform re-decryption. If the data user sending the access data request is a device with poor computing capabilities, the cloud server will send the transformation ciphertext to the fog device, and the fog device will undertake the remaining part of the decryption content on behalf of the device with poor computing capabilities, reducing the computing burden on the device with poor computing capabilities.

[0061] 2. The present invention utilizes the flexibility and scalability of cloud and fog computing resources, stores a large amount of traffic data in the cloud, and uses the fog node as a proxy server to undertake part of the encryption and decryption computing tasks on behalf of local devices, thereby reducing the computing burden on local devices and improving the response speed of the system. At the same time, the fog node is closer to the local device, which can reduce data transmission latency.

[0062] 3. The present invention can record and track which users or systems have accessed which data, which helps to quickly locate and hold responsible parties accountable in the event of data leakage or abuse. For example, if an unauthorized user accesses sensitive data, the system can immediately track their access trajectory. When a user's attributes change (such as leaving the job, changing positions, etc.), or their access permissions are revoked, this method can ensure that these users can no longer access the data they were previously authorized to access. Description of the drawings

[0063] Figure 1 is a working schematic diagram of the system of the present invention;

[0064] Figure 2 System architecture of the present invention

[0065] Figure 3 Example of a KEK tree Detailed implementation manners

[0066] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and cannot be used to limit the protection scope of the present invention.

[0067] As Figure 2 shown, the traceable and revocable attribute-based encryption method applicable to fog computing provided by the present invention mainly has the following six entities

[0068] Attribute Authority (AA): The AA is responsible for implementing the parameter setting of the system, generating the public key and the master key of the system, generating keys and transformation keys for data users, generating the initial attribute group key for the attribute manager, and initializing the identity revocation list.

[0069] Attribute Manager (AM): The AM is responsible for maintaining the KEK tree and generating the attribute group key. In addition, it re-encrypts the ciphertext uploaded by the data owner and updates the attribute group key and the ciphertext when an attribute revocation occurs.

[0070] Cloud Service Provider (CSP): The CSP stores the encrypted data and provides a ciphertext update service for attribute revocation and dynamic user management.

[0071] Fog Device (FD). The FDs are deployed at the network edge and provide various services. They re-encrypt the ciphertext and upload the entire ciphertext to the CSP. In addition, they can also help the user DUf decrypt the ciphertext from the CSP.

[0072] Data Owner (DO): The DO is the data provider / owner who hopes to store data in the cloud and share the data with the desired target group. According to the computing power and storage capacity of the DO, the DO is divided into two specific types: DOf and DOc. The DOf can be intelligent sensors, wearable devices, and other intelligent objects with limited computing and storage resources. In the fog and cloud computing environment, the DOf is located at the bottom layer. Before storing the data in the CSP, the DOf needs to access the target FD for further services. The DOc can be a mobile phone, a desktop, or other intelligent devices with moderate computing and storage resources. In the fog and cloud computing environment, the DOc is in the middle layer, that is, the DOc is the traditional data owner in the cloud computing environment. Different from the DOf, the DOc can directly outsource the data to the CSP without the help of the FD.

[0073] Data User (DU): The DU is the data consumer / user who wishes to access the data stored in the cloud. According to the computing power and storage capacity of the DU, the DU is specifically divided into two types: DUf and DUc. The DUf can be an intelligent sensor, a wearable device, and other intelligent objects with limited computing and storage resources. The DUf is located at the bottom layer of the fog and cloud computing environment. After obtaining data from the CSP, the DUf needs to request outsourcing decryption assistance from the target FD. The DUc can be a mobile phone, a desktop, and other intelligent devices with medium computing and storage resources. In the fog and cloud computing environment, the DUc is in the middle layer, that is, in the cloud computing environment, the DUc is a traditional data user. Different from the DUf, the DUc can directly decrypt the data from the CSP without the help of the FD.

[0074] As Figure 1 shown, the present invention provides a traceable and revocable attribute-based encryption method applicable to fog and cloud computing, including the following six modules:

[0075] System Parameter Setting Module: Input the security parameter λ, and the Attribute Authority (AA) outputs the public key PK and the master private key MSK. The Attribute Manager (AM) outputs the public key APK and the master private key ASK of the attribute manager according to the public key PK generated by the AA. The public key PK and the master private key MSK are sent to the encryption module, the key detection and tracing module, and the key generation module. The public key APK of the attribute manager is sent to the key generation module, and the master private key ASK of the attribute manager is sent to the encryption module.

[0076] Key Generation Module: The AA generates the data user private key SK, the initial attribute group key IAGK, and the transformation key TK according to the user identity ID, the system public key PK, the public key APK of the attribute manager, the system master private key MSK, and the data user attribute set S, and sends the data user private key SK and the transformation key TK to the decryption module. The AM generates the user's attribute group key AGK according to the initial attribute group key IAGK and the user attribute set S and sends it to the decryption module and the key detection and tracing module.

[0077] Encryption Module: The Data Owner (DO) outputs the ciphertext header Hdr and the ciphertext CT according to the system parameter PK, the representation of the access structure (M, ρ), the plaintext m, and the master private key ASK of the attribute manager. The ciphertext CT is sent to the user attribute revocation module and the decryption module.

[0078] Decryption Module: The Data User (DU) outputs the plaintext m according to the received ciphertext header Hdr, ciphertext CT, private key SK, transformation key TK, and the user's attribute group key AGK.

[0079] Key detection and tracking module: AM checks whether the private key SK is a correctly formed key according to the public key PK, the master private key MSK, and the user private key SK. If not, it conveys to the user attribute revocation module and uses the private key ASK of the attribute manager, the user attribute group key AGK, and the revoked attribute att x as input and outputs a new user attribute group key and sends it to the decryption module.

[0080] Attribute revocation module: AM outputs a new ciphertext header x and a new ciphertext according to the ciphertext header Hdr, the ciphertext CT, and the revoked attribute att and sends them to the decryption module.

[0081] Next, each module of the system will be specifically described in combination with Figure 1 .

[0082] The system parameter setting module performs the following steps:

[0083] Step 1.1: Input the security parameter λ. AA selects two multiplicative cyclic groups G and G of order prime p T , where g is the generator of G and e is the bilinear mapping G×G→G T .

[0084] Step 1.2: AA selects the hash functions H 1 :{0,1} * →G, and H:{0,1} * →G, where H has collision resistance. Select k 1 , k 2 ∈K as the key of the symmetric encryption algorithm. Output the public key PK of the attribute authorization agency = {g, e(g,g) α , g a , H 1 , H 2 , H} and the master private key MSK = {g α , k 1 , k 2}, and initialize the user revocation list.

[0085] Step 2: For each attribute att i (1 ≤ i ≤ n), AM randomly selects an exponent and calculates Output the public key APK of the attribute manager = {t i |1 ≤ i ≤ n} and the master private key ASK = {t i |1 ≤ i ≤ n}.

[0086] The system key generation module performs the following steps:

[0087] Step 3: AA randomly selects Calculate Calculate L = g δ , K = g α+aδ and K 1 = g aδz H(0||1||1||1) δz . For any attribute att i ∈S, calculate k i = H(att i ||1||1) δz and Output the user private key SK = {K, L, RK = z}, the transformation key and the initial attribute group key AA distributes the private key SK to the user through a secure channel, sends the transformation key TK to the CSP, and sends the initial attribute group key IAGK to the AM.

[0088] Step 4.1: Let U = {u 1 , u 2 ,..., u n} represent the user set, and L = {λ 1 , λ 2 ,..., λ n} represent the set of all users' attributes in the system. Represents the user set that owns the attribute λ i in the KEK tree, as an access list or revocation list for a certain attribute λ i . G = {G 1 , G 2 ,..., G n} represent the attribute group set.

[0089] Step 4.2: The AM calculates and constructs a KEK tree to generate relevant parameters for the user according to the following process. The leaf nodes in the binary tree represent the users in the user set U, and each non-leaf node v j stores a random value θ j .

[0090] Step 4.3: Path node algorithm Path(u k ): For each user u k , all the nodes from the leaf node to the root node are defined as the path nodes of the user u k .

[0091] Step 4.4: Minimum cover set algorithm Mincs(G i ): For the attribute λ that owns in the KEK treei The attribute group G i , the smallest node set in the tree that can cover G i and all users is the minimum cover set.

[0092] Step 4.5: The intersection of Path(u k ) and Mincs(G i ): If the user u k has the attribute λ in the KEK tree i , that is, u k ∈G i , then the intersection has exactly one node v j storing the random value θ j .

[0093] Step 4.6: AM generates the attribute group key for the user according to the KEK tree. For any attribute att i ∈S, AM calculates to judge whether it is empty. If AM stops the calculation. If AM calculates where the random value θ j corresponding node AM outputs

[0094] This encryption module performs the following steps:

[0095] Step 5.1: DOf inputs the public key PK, the message m, and the access policy matrix (M, ρ). Assume the matrix M has l rows and n columns, and the function ρ maps the matrix M to the user attribute set. Define M i,j as the (i, j) - th element of the matrix M. Let s = H 2 (m, R), where The specific encryption process is as follows:

[0096]

[0097] Calculate k = H(R), encrypt the message m using the symmetric key k, that is, CT m = Enc k (m), output the intermediate ciphertext CT′=(CT m , C, C′, {C i} i∈[l] ) and send it to FD.

[0098] Step 5.2: For each attribute att i in the access policy matrix (M, ρ) (1 ≤ i ≤ n), randomly select and call Mincs(G i) Algorithm, re-encrypt the intermediate ciphertext CT′ to obtain the ciphertext Calculate the ciphertext header The fog device FD uploads (CT, Hdr) to the CSP for storage.

[0099] Step 5.3: DOc inputs the public key PK, the message m, the access policy matrix (M, ρ), and the master private key ASK of the attribute manager, repeats the encryption processes of the above steps 5.1 and 5.2, and during the repetition process, the intermediate ciphertext is not sent to the fog device FD, and directly calculates the ciphertext at the Doc side and the ciphertext header and uploads (CT, Hdr) to the CSP for storage.

[0100] The decryption module performs the following steps:

[0101] Step 6.1: DUf sends an outsourced decryption request to the CSP through the FD. When the CSP receives the decryption request, it first determines whether the data user is in the user revocation list according to the ID of the data user. If it exists, the algorithm returns the termination symbol ⊥. If the attribute set S of the data user satisfies the access policy (M, ρ), then there exists a set of constants {w i} i∈[I] , such that ∑ i∈I w i M i =(1, 0,..., 0), otherwise, the algorithm returns the termination symbol ⊥. The CSP calculates the transformed ciphertext TCT in the following way.

[0102]

[0103] The CSP sends the transformed ciphertext TCT to the FD.

[0104] Step 6.2: DUc directly sends an outsourced decryption request to the CSP. When the CSP receives the decryption request, it first determines whether the data user is in the user revocation list according to the ID of the data user. If it exists, the algorithm returns the termination symbol ⊥. If the attribute set S of the data user satisfies the access policy (M, ρ), then there exists a set of constants {w i} i∈[I] , such that ∑ i∈I w i M i =(1, 0,..., 0), otherwise, the algorithm returns the termination symbol ⊥. The CSP calculates the transformed ciphertext TCT in the following way.

[0105]

[0106] The CSP sends the transformed ciphertext TCT to the DUc.

[0107] Step 7.1: After FD receives the transformed ciphertext TCT, it calculates R′ according to the following calculation steps:

[0108]

[0109] FD sends the calculated R′ to DUf.

[0110] Step 7.2: After DUf receives R′, it calculates k = H(R′), m = Dec k (CT m ). If holds, then m is the correctly decrypted ciphertext; otherwise, m is invalid.

[0111] Step 7.3: After DUc receives the transformed ciphertext TCT, according to the following calculation steps, the message m can be recovered.

[0112]

[0113] Calculate k = H(R′), m = Dec k (CT m ). If holds, then m is the correctly decrypted ciphertext; otherwise, m is invalid.

[0114] This key detection and tracing module performs the following steps:

[0115] Step 8: AA verifies whether the user's private key meets the following conditions: Let A = e(K, g), B = e(L, g a ), calculate A / B, if A / B = e(g, g) α , the key check algorithm returns 1. Otherwise, the key check algorithm returns 0.

[0116] Step 9: When a key leakage occurs, AA executes the following key tracing algorithm: If the key check algorithm outputs 0, this means that SK is not a well - formed key. If the key check algorithm outputs 1, then SK is a well - constructed key. The tracing algorithm can extract the identity ID from the private key SK according to the following calculation method. Otherwise, the tracing algorithm outputs ⊥. Calculate The user's ID can be obtained through and add the user identity to the user revocation list and send the user revocation list to the CSP.

[0117] Step 10: When the attribute att i of user u x is revoked, AM randomly selects σ x and calculates and Use and to replace T in APK and ASKx and t x , obtain a new public key of the attribute manager and a private key Update the user attribute group and recalculate the minimum covering set For each user AM calculates Then calculate and where the corresponding node Finally, AM uses to replace {att in KEK x , v j , agk x , AGK x}.

[0118] Step 11: AM randomly selects Update the ciphertext and the ciphertext header:

[0119] When i = x, AM calculates When 1 ≤ i ≤ n, i ≠ x, AM outputs the new ciphertext header and the new ciphertext and uploads to the CSP.

[0120] The above embodiments are only for illustrating the technical concept and features of the present invention, and the purpose is to enable those who are familiar with this technology to understand the content of the present invention and implement it accordingly, and it should not be used to limit the protection scope of the present invention. Any equivalent transformation or modification made according to the spirit of the present invention should be covered within the protection scope of the present invention.

Claims

1. A traceable and revocable attribute-based encryption method suitable for cloud computing, characterized in that: The steps include: Step 1: System parameter initialization: input security parameter λ, attribute authorization agency AA outputs system public key PK and system master private key MSK, attribute manager AM outputs attribute manager public key APK and attribute manager master private key ASK according to system public key PK, sends system public key PK and system master private key MSK to encryption module, key detection and tracking module, key generation module, sends attribute manager public key APK to key generation module, sends attribute manager master private key ASK to encryption module, and initializes user revocation list at the same time; Step 2: Key generation module: AA generates user private key SK, initial attribute group key IAGK and conversion key TK according to user identity ID, system public key PK, attribute manager public key APK, system master private key MSK and data user attribute set S, and sends the conversion key TK to the decryption module, and the user key SK is sent to the decryption module and the key tracking module. AM generates the user's attribute group key AGK according to the initial attribute group key IAGK and the data user attribute set S and sends it to the decryption module and the key detection and tracking module; Step 3: Encryption module: The data owner DO outputs the ciphertext header Hdr and the ciphertext CT according to the system public key PK, the access policy matrix (M, ρ), the plaintext m and the attribute manager master private key ASK, and sends the ciphertext header Hdr and the ciphertext CT to the attribute revocation module and the decryption module; the data owner DO is divided into two specific types: DOf and DOc. In the fog and cloud computing environment, DOf is at the bottom layer. Before storing the data in the cloud service provider CSP, DOf needs to access the target fog device FD and output the ciphertext header Hdr and the ciphertext CT through the fog device FD; DOc is in the middle layer. DOc directly outputs the ciphertext header Hdr and the ciphertext CT and outsources the data to the cloud service provider CSP without the help of the fog device FD; Step 4: Decryption module: The data user DU decrypts the plaintext m according to the received ciphertext header Hdr, ciphertext CT, user private key SK, conversion key TK and user attribute group key AGK; according to the computing amount and storage capacity of the data user DU, DU is specifically divided into two types: DUf and DUc. DUf is located at the bottom layer of the fog and cloud computing environment. After obtaining data from CSP, DUf requests outsourced decryption help from the target fog device FD; DUc is in the middle layer, that is, in the cloud computing environment, DUc directly decrypts the data from CSP without the help of the fog device FD; Step 5: Key detection and tracking module: AM checks whether the user private key SK is a key of the correct form according to the system public key PK, the system master private key MSK, and the user private key SK. If not, it sends an instruction to the attribute revocation module to revoke the attribute and uses the attribute manager master private key ASK, the user attribute group key AGK, and the revoked attribute att x As input, output new user attribute group key And send it to the decryption module; if it is the correct key, the attribute will not be revoked; Step 6: Attribute revocation module: AM revoked the attribute att according to the ciphertext header Hdr, the ciphertext CT and the revoked attribute x , output the new ciphertext header and new ciphertext And send it to the decryption module.

2. The traceable and revocable attribute-based encryption method applicable to cloud fog computing according to claim 1 is characterized in that: The system parameter initialization in step 1 is specifically as follows: Step 1.1: Input security parameter λ, AA selects two multiplicative cyclic groups G and G with order p as prime number T , g is the generator of G, and e is the bilinear mapping G×G→G T ; Step 1.2: AA selection Hash function H1:{0,1} * →G. and H:{0,1} * →G, H are collision-resistant, select k1, k2∈K as the key of the symmetric encryption algorithm, and output the system public key PK of the attribute authority = {g, e(g, g) α ,g a ,H1,H2,H} and the system master private key MSK={g α ,k1,k2}, initialize the user revocation list; Step 1.3: AM for each attribute att i , 1≤i≤n randomly selected index calculate Output property manager public key APK = {t i |1≤i≤n} and the attribute manager master private key ASK={t i |1≤i≤n}.

3. The traceable and revocable attribute-based encryption method applicable to cloud fog computing according to claim 2 is characterized in that: The generation process of the user private key SK, the conversion key TK, and the initial attribute group key IAGK in step 2 is: AA random selection Use k1 as the key to symmetric encrypt ID to generate ζ. Similarly, use k2 as the key to symmetric encrypt ζ||θ to generate δ. That is, calculate Calculate L = g δ ,K=g α+aδ and K1 = g aδz H(0||1||1||1) δz , for any attribute att i ∈S, calculate k i =H(att i ||1||1) δz and Output user private key SK = {K, L, RK = z}, convert key and the initial attribute group key AA distributes the user private key SK to the user through a secure channel, sends the conversion key TK to the decryption module on the cloud service provider CSP, and sends the initial attribute group key IAGK to AM.

4. The traceable and revocable attribute-based encryption method applicable to cloud fog computing according to claim 3 is characterized in that: The specific generation process of the user's attribute group key AGK in step 2 is as follows: Step 2.1: Let U = {u1,u2,...,u n } represents the user set, L = {λ1,λ2,...,λ n } represents the attribute set of all users in the system. Indicates that it has the attribute λ in the KEK tree i The user set of i The access list or revocation list, G = {G1, G2, ..., G n } represents a set of attribute groups; Step 2.2: AM calculates and constructs the KEK tree according to the following process to generate relevant parameters for the user. The leaf nodes in the binary tree represent the users in the user set U. Each non-leaf node v j Store a random value θ j ; Step 2.3: Path node algorithm Path(u k ): For each user u k , all nodes from the leaf node to the root node are defined as user u k Path nodes; Step 2.4: Minimum Covering Set Algorithm Mincs(G i ): For the attribute λ in the KEK tree i The attribute group G i , the tree can cover G i The minimum node set of all users is the minimum covering set; Step 2.5: Path(u k ) and Mincs(G i ):If user u k Has the attribute λ in the KEK tree i , that is u k ∈G i , then the intersection has only one node v j The random value θ is stored j ; Step 2.6: AM generates an attribute group key for the user based on the KEK tree. For any attribute att i ∈S, AM calculation judge Is it empty? AM stops calculating if AM calculation Among them, the random value θ j The corresponding node AM Output 5. The traceable and revocable attribute-based encryption method applicable to cloud fog computing according to claim 4 is characterized in that: The encryption process in step 3 is as follows: Step 3.1: DOf inputs the system public key PK, plaintext m and access policy matrix (M, ρ). Assume that the matrix M has l rows and n columns. Function ρ maps the matrix M to the user attribute set. Define M i,j is the (i,j)th element of matrix M, let s = H2(m,R), where The specific encryption process is as follows: Calculate k = H (R), use the symmetric key k to encrypt the plaintext m, that is, CT m =Enc k (m), output intermediate ciphertext CT′=(CT m ,C,C′,{C i } i∈[l] ) and sent to the fog device FD; Step 3.2: The fog device FD accesses each attribute att in the policy matrix (M, ρ) i , 1≤i≤n, randomly selected And call the minimum cover set algorithm Mincs (G i ), re-encrypt the intermediate ciphertext CT′ to obtain the ciphertext Calculate the ciphertext header The fog device FD uploads (CT, Hdr) to CSP for storage; Step 3.3: DOc inputs the system public key PK, plaintext m, access policy matrix (M, ρ) and attribute manager master private key ASK, and repeats the encryption process of steps 3.1 and 3.

2. In the repeated process, the intermediate ciphertext is not sent to the fog device FD, and the ciphertext is calculated directly on the Doc end. And the ciphertext header And upload (CT, Hdr) to CSP for storage.

6. The traceable and revocable attribute-based encryption method applicable to cloud fog computing according to claim 5, characterized in that: The decryption module in step 4 has the following specific process: Step 4.1: DUf sends an outsourced decryption request to CSP through FD. When CSP receives the decryption request, it first determines whether the data user is in the user revocation list based on the data user's ID. If so, the algorithm returns the termination symbol ⊥; if the data user's attribute set S satisfies the access policy matrix (M, ρ), then there exists a set of constants {w i } i∈[I] , so that i∈I w i M i =(1,0,...,0), otherwise, the algorithm returns the termination symbol ⊥; CSP calculates the transformed ciphertext TCT as follows: CSP sends the converted ciphertext TCT to FD; Step 4.2: DUc directly sends an outsourced decryption request to CSP. When CSP receives the decryption request, it first determines whether the data user is in the user revocation list based on the data user's ID. If so, the algorithm returns the termination symbol ⊥; if the data user's attribute set S satisfies the access policy matrix (M, ρ), then there exists a set of constants {w i } i∈[I] , so that i∈I w i M i =(1,0,...,0), otherwise, the algorithm returns the termination symbol ⊥, and CSP calculates the transformed ciphertext TCT as follows: CSP sends the converted ciphertext TCT to DUc; Step 4.3: After FD receives the converted ciphertext TCT, it calculates R′ according to the following calculation steps: FD sends the calculated R′ to DUf; Step 4.4: After receiving R', DUf calculates k = H(R'), m = Dec k (CT m ),like If true, then m is the correct ciphertext to be decrypted; otherwise, m is invalid; Step 4.5: After DUc receives the converted ciphertext TCT, it can recover the plaintext m by following the following calculation steps: Calculate k = H (R '), m = Dec k (CT m ),like If it holds, then m is the correct ciphertext to be decrypted; otherwise, m is invalid.

7. The traceable and revocable attribute-based encryption method applicable to cloud fog computing according to claim 5, characterized in that: The specific operation of the key detection and tracking module in step 5 is: Step 5.1: AA verifies whether the user's private key meets the following conditions: Let A = e(K, g), B = e(L, g a ), calculate A / B, if A / B=e(g,g) α , the key check algorithm returns 1; otherwise, the key check algorithm returns 0; Step 5.2: When a key leak occurs, AA executes the following key tracing algorithm: If the key check algorithm outputs 0, it means that the user's private key SK is not a well-formed key. If the key check algorithm outputs 1, the user's private key SK is a well-formed key. The tracing algorithm extracts the identity ID from the user's private key SK according to the following calculation method: calculate The user's ID is passed Obtain and add the user identity to the user revocation list, and send the user revocation list to the CSP; Represents the symmetric decryption process; Otherwise, the tracking algorithm outputs ⊥; Step 5.3: When user u i The attribute att x When revoked, AM randomly selects σ x And calculate and use and Replace T in APK and ASK x and t x , get the new property manager public key and private key Update user attribute group And recalculate the minimum covering set algorithm For each user AM calculation Then calculate and in Corresponding node Finally, AM uses Replace {att in the KEK tree x ,v j ,agk x AGK x } as the new user attribute group key 8. The traceable and revocable attribute-based encryption method applicable to cloud fog computing according to claim 7, characterized in that: The attribute revocation module in step 6 specifically operates as follows: AM Random Selection Update the ciphertext and ciphertext header: When i = x, AM calculates When 1≤i≤n,i≠x, AM outputs new ciphertext header and new ciphertext and will Upload to CSP.