Bilateral access control method combining trust management and purification
By combining trust management and purification, the problem of threatening the confidentiality and efficiency of data sharing in the industrial Internet of Things is solved, and effective blocking of malicious behaviors of data owners is achieved.
Patent Information
- Application Number
- CN202510223095.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-05-30
AI Technical Summary
Under the cloud-edge-end architecture of the Industrial Internet of Things, bilateral access control has problems with resisting the malicious behavior of data, which has threatened the confidentiality and efficiency of data sharing.
A bilateral access control method combining trust management and purification is adopted to prevent malicious behaviors of data owners through fine-grained bilateral access control mechanisms and purifier mechanisms. Trust management uses quality evaluation of decrypted data to calculate trust values, and purifiers emphasize randomized encrypted data to prevent unauthorized decryption.
It effectively prevents malicious behaviors of data owners and ensures the confidentiality and efficiency of data sharing under the cloud-edge-end architecture of the Industrial Internet of Things.
Smart Images

Figure CN120074923A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of industrial Internet of Things information security, and in particular to a bilateral access control method combining trust management and purification. Background Art
[0002] For the Industrial Internet of Things (IIoT), data sharing is one of the key elements for realizing intelligent interconnection of devices. With the popularization of the Internet of Things, a large amount of data generated by devices is being shared, promoting data circulation and operation in all walks of life. The cloud-edge-end technology plays an important role in data sharing. The "cloud" refers to the cloud layer, including cloud servers and authorization centers. Cloud servers are further divided into public cloud servers (for data sharing between enterprises), private cloud servers (for data sharing within enterprises), and various enterprise management applications, providing storage and computing resources. The functions include data storage, data processing, application services, and management control. The authorization center is responsible for managing and allocating access rights and security certifications for each layer of devices (cloud layer, edge layer, physical device layer) to ensure the secure transmission and legal access of data. The "edge" refers to the edge layer, which integrates various control, collection, and optimization containers, collectively referred to as edge nodes, and is responsible for data preprocessing, edge computing, and data forwarding, etc. The "end" refers to the physical device layer, which includes industrial devices such as controllers, sensors, and actuators that act as data owners and data users, collecting data and performing preliminary processing on the data. The devices at each layer in the cloud-edge-end architecture can be summarized as follows: the devices in the cloud layer are responsible for data storage, in-depth processing, and security management; the devices in the edge layer are responsible for real-time processing and low-latency transmission of data; while the devices in the physical device layer are responsible for data collection and preliminary processing. The collaborative cloud-edge-end architecture flexibly exchanges data between the physical device layer, edge layer, and cloud layer, improving the efficiency of data analysis.
[0003] Although cloud-edge-device technology has improved traditional cloud technology and brought great convenience to data sharing, it has also raised various data security issues. When sensitive data collected by devices at the physical device layer is shared to the edge layer and the cloud layer, it is crucial to protect the privacy of such data. In addition, in a multi-user scenario, it is very important to allow fine-grained bilateral access control over industrial data of data senders, i.e., data owners, and data receivers, i.e., data users. On the one hand, data owners hope to grant access rights to their encrypted data to data users with specific attributes. For example, a temperature sensor (data owner) encrypts the temperature data it has collected. Correspondingly, it formulates an access policy - permitting data users who are "senior engineers" or "intermediate engineers" and from the "data analysis department" to access, meaning that only senior or intermediate engineers in the data analysis department can decrypt this data. On the other hand, data users hope to access data encrypted by data owners with specific attributes. For example, an engineer (data user) formulates an access policy - "high precision" or "medium precision" and "temperature sensor", which means that he only wants to decrypt data encrypted by high-precision or medium-precision temperature sensors (data owners). The General Data Protection Regulation (GDPR) stipulates that data needs to be securely transmitted in an untrusted network environment, and it is also important to protect the rights of "natural persons" to control their data. If the security issues related to data sharing in cloud-edge-device are not resolved, it will be difficult to promote cloud-edge-device technology.
[0004] Matched Attribute - Based Encryption (MABE) is an encryption technology that combines the concept of Attribute - Based Encryption (ABE) to achieve fine - grained access control. Attributes refer to a series of information used to describe user characteristics or identities, such as identity, role, permission, department, access privilege, or time limit, etc. These attributes are used to control data access rights during the encryption process, ensuring that only users meeting specific attributes can decrypt and access the data. In the MABE system, the encryption and decryption processes rely on users' attributes rather than specific user identities, which better solves the above two data security problems: 1) Encryption ensures data confidentiality and prevents data leakage. 2) Attribute - based matching achieves fine - grained bilateral access control. In recent years, researchers have proposed many bilateral access control schemes for cloud - edge - device architectures based on MABE. However, these schemes ignore the malicious behavior of data owners, that is, malicious data owners release resistant data, namely adversarial data or data poisoning. Data poisoning is an adversarial attack that manipulates the behavior of a model by injecting malicious data into the training dataset. In fact, malicious data owners often exist in the device layer, especially with the following malicious behaviors: 1) Malicious data owners encrypt data in a harmful way. These data can be illegally decrypted by unauthorized users without a valid key, but their encrypted data forms seem correct. For example, a malicious device uploads industrial data assets that may be illegally accessed by competitors to a public cloud server, causing property losses to the enterprise. 2) Malicious data owners release inappropriate data. Such malicious data owners may upload inappropriate data such as incorrectly formatted, code - jumbled, pornographic content, etc., thus damaging data quality, occupying system resources, and causing industrial system interruptions, etc. For example, a malicious engineer uploads wrongly encrypted industrial data to the cloud. An application with attributes that satisfy the access policy in the encrypted data can decrypt the data, such as an ERP (Enterprise Resource Planning) system. The ERP analyzes the wrong data and sends wrong instructions to other entities, such as cloud - based PLC (a technology that migrates the functions of traditional Programmable Logic Controllers (PLCs) to the cloud for operation). The cloud - based PLC controls the device layer according to the wrong instructions, resulting in chaos in the entire industrial system. 3) There is a specific malicious behavior in MABE where the malicious data owner does not encrypt the encrypted data with the claimed access structure and attributes. The data user attributes (access structure) seem to satisfy the access structure (attributes) of the encrypted data, but the actual decryption (matching) cannot succeed.
[0005] Therefore, those skilled in the art are committed to developing a bilateral access control method that combines trust management and purification. Summary of the Invention
[0006] In view of the above defects of the prior art, the technical problem to be solved by the present invention is how to solve the problem of bilateral access control resisting the malicious behavior of the data owner, and ensure the confidentiality and efficiency of data sharing under the cloud-edge-end architecture of the industrial Internet of Things.
[0007] The applicant refines the granularity of the bilateral access control in the prior art, introduces a fine-grained bilateral access control mechanism. The data owner formulates the access policy for the data user, and requires that only the data user who meets the data user access policy can decrypt and access its encrypted data (encrypted data). The data user formulates the access policy for the data owner, and the data user only decrypts and accesses the encrypted data (encrypted data) of the data owner that meets the data owner access policy. A purifier (whose function is to retain the encrypted data that meets the data owner access policy and discard the illegal encrypted data) is used to re-randomize the encrypted data to prevent unauthorized data users from decrypting the encrypted data encrypted in a harmful way. Trust management is used to replace the algorithm of the general purifier to solve the problem that malicious data owners publish inappropriate data and do not encrypt with the claimed access policy or attributes.
[0008] Trust management uses the quality evaluation of the decrypted data as the basis for measurement, calculates the end-to-end (D-D) trust value with the direct trust value and the indirect trust value, and further calculates the global trust. The direct trust value is the trust evaluation of the data user who directly interacts with the data owner, and the direct trust value is calculated from the data evaluation of the data decrypted by the data user from the encrypted data of the data owner. The indirect trust value is the direct trust value of other data users to the data owner except the data user who directly interacts, and the indirect trust value is calculated based on the direct trust value of other data users to the data owner. The end-to-end trust value combines the direct trust value and the indirect trust value, and is the comprehensive trust evaluation of the data user who directly interacts with the data owner. The global trust value combines the end-to-end trust values of all data users to the data owner, and is the trust evaluation of the authorization center to the data owner. To protect the privacy of the data owner, an anonymous authentication protocol is introduced, that is, the encrypted data contains a false identity, and only the authorization center can convert the false identity into the real identity. The anonymous authentication protocol helps to implement trust management and can prevent irrelevant data users from knowing who the data owner of the encrypted data is.
[0009] The applicant combines fine-grained bilateral access control and trust management to prevent malicious behaviors of data owners. For the malicious behavior of "a malicious data owner encrypts data in a harmful way", the purifier is used to re-randomize the encrypted data to prevent unauthorized data users from decrypting the encrypted data encrypted in a harmful way. For the malicious behaviors of "a malicious data owner publishes inappropriate data" and "a malicious data owner does not encrypt the encrypted data with the claimed access structure and attributes", the direct trust value of the data owner is calculated using the data quality of the decrypted encrypted data. The direct trust value of the data owner who publishes inappropriate data is low. The purifier refuses to purify and upload the encrypted data of the data owner with a low global trust value, and the data user refuses to decrypt the encrypted data of the data owner with a low end-to-end trust value.
[0010] The applicant defines the functional modules under the cloud-edge-end architecture of the industrial Internet of Things according to their functions:
[0011] The data owner, that is, the owner of the data, has one or more, and owns the data owner attribute private key and the key pair for digital signature. The data owner attribute private key is the encryption key associated with the data owner attribute. The key pair for digital signature includes a digital signature private key and a digital signature public key. The data owner encrypts the digital digest with the digital signature private key, and the data user uses the digital signature public key to verify the digital signature, and confirms the integrity and authenticity of the received data by comparing the digital digest; the data owner formulates the data user access policy and embeds it with the data owner attribute private key into the encrypted data, and uses the identity identifier to generate a fake identity of the data owner, where the data user access policy is used to control and manage the rules and methods for the data user to access the data. The data owner requires that only the data users who meet the data user access policy can decrypt the encrypted data.
[0012] The data user, that is, the user of the data, has one or more, and owns the data user attribute private key. The data user attribute private key is the decryption private key associated with the data user attribute. The data user formulates the data owner access policy, and the data owner access policy is the access rule of the data user for the data owner who sends the encrypted data. The data user only decrypts the encrypted data of the data owner who meets the data owner access policy, decrypts the encrypted data that meets the data owner access policy, calculates the direct trust value based on the decrypted data, and calculates the end-to-end trust value of the data owner based on the direct trust value and the indirect trust value.
[0013] Edge nodes, there are one or more. The edge nodes transmit encrypted data between the cloud layer and the device layer, perform outsourced decryption using the blinded private key, and generate partially decrypted data. The blinded private key is obtained by the data user blinding their own data user attribute private key using a blinding factor; the edge nodes send the false identity of the data owner of the encrypted data to the data user to help the data user perform matching verification on the data owner. When the end-to-end trust value is lower than the trust threshold required by the data user, or the data owner attributes do not meet the data owner access policy, the edge nodes do not perform outsourced decryption; the edge nodes calculate the indirect trust value based on the direct trust values of other data owners. The direct trust values are calculated by the data users and uploaded to the edge nodes, and the indirect trust values are obtained by the data users calculating from the direct trust values of other data users obtained from the edge nodes;
[0014] Authorization center, there is one. It generates global public parameters, assigns identity identifiers to data owners, generates data owner attribute private keys, and calculates the global trust value of data owners based on the end-to-end trust values of data owners;
[0015] Attribute authorization centers, there are one or more. They manage data owner and data user attributes, generate public and private keys for attribute authorization, and generate attribute private keys for data owners and data users;
[0016] Purifier, a newly added logic function module compared with the prior art. There is one. It obtains the global trust value of the data owner from the authorization center, determines whether the data owner is trustworthy, receives the encrypted data of the trustworthy data owner, and performs purification using the purification algorithm, and sends the purified encrypted data to the cloud server;
[0017] Cloud server module, there is one. It receives the purified encrypted data and stores it.
[0018] In an embodiment of the present invention, a bilateral access control method combining trust management and purification is provided, including the following steps:
[0019] S100. Authorization center initialization. The authorization center selects a security level according to security requirements, generates global public parameters, and publishes the global public parameters to the attribute authorization center, the purifier, the edge nodes, the data owner, and the data user;
[0020] S200. Attribute key request. The data owner generates a false identity and a key pair for digital signature, sends the data owner attributes and the false identity to the attribute authorization center, and requests the data owner attribute private key; the data user sends the data user attributes to the attribute authorization center and requests the data user attribute private key;
[0021] S300. Attribute key generation: In response to a data owner attribute private key request, the attribute authorization center generates a data owner attribute private key and sends it to the data owner; in response to a data user attribute private key request, the attribute authorization center generates a data user attribute private key and sends it to the data user.
[0022] S400. Data encryption: The data owner generates an offline ciphertext in the offline stage, and generates encrypted data in the online stage and sends it to an edge node close to the data owner.
[0023] S500. Encrypted data purification: The edge node receiving the encrypted data sends the encrypted data to the purifier. The purifier judges the credibility of the data owner, uses a purification algorithm to purify the encrypted data of the credible data owner, and then saves it to the cloud server.
[0024] S600. Matching verification: In response to a data user's request to download encrypted data, the cloud server sends the encrypted data to the purifier. The purifier sends the encrypted data to an edge node close to the data user. The edge node close to the data user performs matching verification on the data owner of the encrypted data. After the matching verification passes, the edge node close to the data user requests a blinded private key from the data user.
[0025] S700. Partial decryption of encrypted data: The data user blinds the data user attribute private key to obtain a blinded private key and sends it to an edge node close to the data user. The edge node close to the data user uses the blinded key to perform partial decryption on the encrypted data and sends it to the data user.
[0026] S800. Decryption of encrypted data: In response to the partially decrypted encrypted data, the data user verifies the correctness of the decryption by the edge node, judges whether the data user access policy is embedded in the ciphertext, and after the verification is correct, uses the data user attribute private key to decrypt to obtain the plaintext data.
[0027] Further, in the bilateral access control method combining trust management and purification in the above embodiment, the purifier is a logical functional module, obtains the global trust value of the data owner from the authorization center, judges whether the data owner is credible, receives the encrypted data of the credible data owner, and uses a purification algorithm to purify it, and sends the purified encrypted data to the cloud server.
[0028] Further, in the bilateral access control method combining trust management and purification in the above embodiment, the global trust value synthesizes all the end-to-end trust values of data users for the data owner, and the trust evaluation of the data owner. The end-to-end trust value synthesizes the direct trust value and the indirect trust value, and is the comprehensive trust evaluation of the data owner by the directly interacting data users.
[0029] Furthermore, in the bilateral access control method combining trust management and purification in the above embodiments, the calculation methods of direct trust value, indirect trust value, end-to-end trust value, and global trust value are as follows:
[0030] S1000. Calculate the interaction record matrix. Assume that the interaction feedback of a data user x to a data owner y is f(x, y) k , where k represents the time of interaction, and the range of interaction feedback is from 0 to 1, which is proportional to the satisfaction degree of x with respect to y. h x,y (Δt) represents the record of all interaction feedbacks of x to y within time Δt, and is expressed as follows:
[0031] h x,y (Δt) = {f(x, y) 1 , f(x, y) 2 ,..., f(x, y) k ,..., f(x, y) Δt},
[0032] x stores the interaction record matrix with other n data owners, and the representation is as follows:
[0033]
[0034] where f(x, i) k represents the feedback of x to i in the k-th interaction;
[0035] S2000. Calculate the direct trust value. Define f(x, y) k ≥ 0.5 as a positive operation, and define the sum of the number of positive operation times as Σf(x, y) k+ , define f(x, y) k < 0.5 as a negative operation, and define the sum of the number of negative operation times as Σf(x, y) k- , define (0, ε·Δt) as long term, and (ε·Δt, Δt) as short term, where 0.5 < ε < 1;
[0036] The formula for calculating the direct trust value DTV of x to y at Δt moment is as follows:
[0037]
[0038] where, represents the long-term direct trust value, represents the short-term direct trust value, w l and w s represent the weights of the long-term direct trust value and the short-term direct trust value respectively, and β represents the time decay factor;
[0039] Long-term direct trust value and the short-term direct trust value The calculation formula is as follows:
[0040]
[0041] Among them, is a time decay function,
[0042] S3000, Indirect trust value calculation. All direct trust values of the edge node within time Δt are stored in DTV(Δt):
[0043] DTV(Δt) = {DTV 1 , DTV 2 ,..., DTV k ,..., DTV Δt}
[0044]
[0045] Among them, DTV k represents the direct trust value matrix at time k, represents the direct trust vector, which contains the direct trust values of n data users for y at time k, represents the direct trust value of x for y at time k;
[0046] The formula for calculating the indirect trust value IDTV of y at time Δt is as follows:
[0047]
[0048] Among them, w x,y represents the calculation weight of x for y, represents whether i uploaded the direct trust value of y at time k, represents the non-emptiness of the i-th row of, represents the emptiness of the i-th row of;
[0049] S4000, End-to-end trust value calculation. The formula for calculating the end-to-end trust value of x for y at time Δt is as follows:
[0050]
[0051] Among them, w D is the direct trust value weight, w I is the indirect trust value weight, and γ is a regulation factor. If x trusts its own interaction more, then the value of γ will be larger;
[0052] S5000, Global trust value calculation. The formula for calculating the global trust value of y at time Δt is as follows:
[0053]
[0054] Among them, z x represents the end-to-end trust value weight of x. i, j, and n are positive integers. i and j represent serial numbers, and n represents the number of data owners.
[0055] Optionally, in the bilateral access control method combining trust management and purification in the above embodiment, step S100 includes:
[0056] S110. Select a security level. The authorization center selects a security level. The higher the security requirement, the higher the selected security level. Select a bilinear mapping e: G×G→G T , where e refers to the bilinear mapping that maps two elements on the multiplicative cyclic group G to an element on the multiplicative cyclic group G T The bits of the multiplicative cyclic group G and the multiplicative cyclic group G T are λ, the order is p, g is the generator of G, λ is the security parameter representing the security level, and p is a prime number;
[0057] S120. Select an attribute universe function and an attribute authorization universe function. Select an attribute universe function f that maps the attribute universe u to the multiplicative cyclic group G, which is expressed by the formula f: u→G, where u is the attribute universe. Select an attribute authorization universe function f′ that maps the attribute universe to the attribute authorization universe, which is expressed by the formula f′: u→u θ , where u θ is the attribute authorization universe, and the arrow means mapping. The attribute universe is all the attributes included, and the attribute authorization universe is all the attribute authorization centers included;
[0058] S130. Select hash functions. The hash functions include H, H 0 , H 1 and H 2 , H is a hash function that maps the fake identity QID to an element of the multiplicative cyclic group G, H 0 is a hash function that maps the session key key of the symmetric key to a sequence of length l 0 , H 1 is a hash function that maps the session key key of the symmetric key to a sequence of length l 1 , H 2 is a hash function that maps the hash value KEY obtained by H 0 to the symmetric ciphertext CT sym and maps it to a sequence of length l 2 ;
[0059] S140. Generate global public parameters PK, PK = <p, G, G T , e, g, f, f', u, uθ ,H,H 0 ,H 1 ,H 2 >;
[0060] S150. Publish global public parameters. The authorization center publishes the global public parameter PK to the attribute authorization center, the purifier, the edge node, the data owner, and the data user.
[0061] Preferably, in the bilateral access control method combining trust management and purification in the above embodiment, p takes a value of 160 bits.
[0062] Further, in the bilateral access control method combining trust management and purification in the above embodiment, the security levels are low, medium, and high, and the corresponding λ lengths are 128 bits, 192 bits, and 256 bits.
[0063] Preferably, in the bilateral access control method combining trust management and purification in the above embodiment, the λ length takes a value of 128 bits.
[0064] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, step S200 includes:
[0065] S210. Calculate a false identity. The data owner calculates the false identity QID = AAP.Trans(GID), where AAP.Trans is a key generation algorithm commonly used for digital signatures, and GID is the identifier of the data owner.
[0066] S220. Calculate a digital signature key pair. The data owner calculates the key pair (sk GID , vk GID ) = AAP.GEN(λ), where sk GID is the private key of the digital signature, vk GID is the public key of the digital signature, and AAP.GEN is a key generation algorithm commonly used for digital signatures.
[0067] S230. Data owner attribute private key request. The data owner sends the data owner attributes and the false identity to the attribute authorization center and requests the data owner attribute private key.
[0068] S240. Data user attribute private key request. The data user sends the data user attributes to the attribute authorization center and requests the data user attribute private key.
[0069] Further, in the bilateral access control method combining trust management and purification in the above embodiment, the key generation algorithms commonly used for digital signatures include the RSA algorithm, the DSA algorithm (Digital Signature Algorithm), and the ECDSA algorithm (Elliptic Curve Digital Signature Algorithm).
[0070] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, step S300 includes:
[0071] S310. Receive data owner attributes. The attribute authorization center receives data owner attributes and a false identity QID, randomly select a variable t ∈ Z p , and calculate the data owner's private key SK 2 = g t , where S 1 , S 2 ,..., S r are attribute elements, r is a positive integer, and Z p is a finite field composed of p elements, that is, a set composed of integers 0, 1, 2,..., p - 1;
[0072] S320. Calculate the data owner attribute private key. For the attribute authorization center calculates the private key component of the data owner
[0073] S330. Send the data owner attribute private key. The attribute authorization center calculates the data owner attribute private key and sends it to the data owner;
[0074] S340. Receive data user attributes. The attribute authorization center receives data user attributes randomly select k ∈ Z p , and calculate the private key component RK 2 = g k ;
[0075] S350. Calculate the attribute private key of the data user. For the attribute authorization center calculates the private key component of the data user
[0076] S360. Send the data owner attribute private key. The attribute authorization center calculates the data owner private key and sends it to the data user.
[0077] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, step S400 includes:
[0078] S410. Calculate the symmetric key. The data owner randomly selects a session key key of the symmetric key in the offline phase, where key ∈ G T , calculates a hash value KEY = H 0 (key) and a symmetric key KEY * = H1 (key);
[0079] S420. Perform offline encryption. The data owner randomly selects \(s, t'\in\mathbb{Z}\) p , for the maximum attribute \(P\) of size \(l'\), randomly select \(\mu\) i , \(t\) i , \(\mu\) i '\(\in\mathbb{Z}\) p ;
[0080] For att i \(\in P\), the data owner calculates the offline ciphertext component:
[0081]
[0082] For the data owner calculates the offline ciphertext component:
[0083]
[0084] The data owner obtains the offline ciphertext:
[0085]
[0086] S430. Perform online encryption. The data owner calculates the symmetric ciphertext \(CT\) sym \( = SE.Enc(m, KEY\) * ) and the verification ciphertext \(CT\) m \( = H\) 2 (KEY||CT sym ), where \(SE.Enc\) is a symmetric encryption algorithm;
[0087] The data owner randomly selects a vector calculate the vector \(\lambda = (\lambda\) 1 , \(\lambda\) 2 ,..., \(\lambda\) l ) T \( = M\cdot v\), \(\lambda' = (\lambda\) 1 ', \(\lambda\) 2 ',..., \(\lambda\) l ') T \( = M\cdot v'\), where \(M\) is an \(l\times n\) matrix, and \(l\) and \(n\) are integers greater than or equal to 1;
[0088] For the data owner calculates the online ciphertext component \(C\) 5,i \( = \lambda\) i - \(\mu\) i , \(C\) 6,i \( = \lambda\) i ' - \(\mu\) i ', and the data owner obtains the online ciphertext \(CT\)key = <(M, ρ), C 0 , C 0 ′, {C 1,i , C 2,i , C 3,i , C 4,i , C 5,i , C 6,i}, i∈[l] , S′, {E 1,i}, i∈[r″] , E 2 >, the data owner calculates a digital signature using a general digital signature generation algorithm AAP.Sig is a general digital signature generation algorithm;
[0089] S440. Send the encrypted data, and the data owner obtains the encrypted data and send it to the edge node close to the data owner.
[0090] Furthermore, in the bilateral access control method combining trust management and purification in the above embodiment, the symmetric encryption algorithm includes DES (Data Encryption Standard), 3DES (Triple DES), and AES (Advanced Encryption Standard).
[0091] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, the general digital signature generation algorithm includes the RSA algorithm, DSA algorithm (Digital Signature Algorithm), and ECDSA algorithm (Elliptic Curve Digital Signature Algorithm).
[0092] Furthermore, in the bilateral access control method combining trust management and purification in the above embodiment, the general digital signature generation algorithm and the key generation algorithm of the general digital signature are consistent.
[0093] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, step S500 includes:
[0094] S510. Encrypted data forwarding, and the edge node receiving the encrypted data sends the encrypted data to the purifier;
[0095] S520. Global trust value request, the purifier requests the global trust value and verifies the identity of the data owner, and the purifier calculates the result of verifying the signature where AAP.Vrfy is a general digital signature verification algorithm. If α = 0, the identity verification of the data owner fails. Otherwise, the purifier requests the global trust value GTrust of the data owner from the authorization center u ;
[0096] S530, Global Trust Value Judgment. The purifier judges the global trust value GTrust u , if it is greater than the global trust threshold Trust t , continue to execute S530; otherwise, reject the encrypted data;
[0097] S540, Encrypted Data Purification. The purifier purifies the encrypted data of the data owner. The purifier randomly selects a vector and calculates the vector θ = (θ 1 , θ 2 ,..., θ l ) T = M·y, θ' = (θ 1 ', θ 2 ',..., θ l ')[[]END] T = M·y'. The purifier randomly selects a session key key' of the symmetric key from G T , and calculates the symmetric key KEY' * = H 1 (key') and the hash value KEY' = H 0 (key'). The purifier randomly selects r ∈ Z p , and calculates the purified encrypted data component:
[0098]
[0099] For i ∈ [l], the purifier calculates the purified encrypted data component, and the formula is as follows:
[0100]
[0101] S550, Encrypted Data Purification. The purifier purifies the encrypted data to obtain the purified encrypted data;
[0102] S560, Encrypted Data Storage. The purifier sends the purified encrypted data to the cloud server for storage.
[0103] Preferably, in the bilateral access control method combining trust management and purification in the above embodiment, the global trust threshold Trust t takes the value of 0.8.
[0104] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, the general digital signature verification algorithms include the RSA algorithm, the DSA algorithm (Digital Signature Algorithm), and the ECDSA algorithm (Elliptic Curve Digital Signature Algorithm).
[0105] Further, in the bilateral access control method combining trust management and purification in the above embodiment, the general digital signature verification algorithm, the general digital signature generation algorithm, and the key generation algorithm of the general digital signature are consistent.
[0106] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, the matching verification in step S600 includes that when the end-to-end trust value of the data owner is higher than the trust threshold required by the data user, and the data owner attributes meet the data owner access policy, the edge node close to the data user sends the encrypted data to the data user, otherwise the encrypted data is not sent.
[0107] Further, in the bilateral access control method combining trust management and purification in the above embodiment, step S600 includes:
[0108] S610. End-to-end trust value judgment, the data user verifies the end-to-end trust value DTrust of the data owner u , if it is less than the end-to-end trust threshold Trust DU , then return that the matching verification fails, otherwise execute S620;
[0109] S620. Data owner access policy judgment, the edge node close to the data user helps the data user verify the data owner attributes S' in the purified online ciphertext to see if it meets the data owner access policy (N, π). If it does not meet, then return that the matching verification fails, where N is an l'×n' matrix, and l' and n' are integers greater than or equal to 1;
[0110] S630. Blinded private key request. If the matching verification passes, the edge node close to the data user requests the blinded private key from the data user, otherwise the edge node close to the data user discards the encrypted data.
[0111] Further, in the bilateral access control method combining trust management and purification in the above embodiment, the end-to-end trust threshold Trust DU takes the value of 0.8.
[0112] Further, in the bilateral access control method combining trust management and purification in the above embodiment, step S620 includes:
[0113] S621. Vector calculation, the edge node close to the data user randomly selects vectors and The edge node calculates the vector η = (η 1 , η 2 ,..., η l′ ) T= N·z, η′ = (η 1 ′, η 2 ′,..., η l ″) T = N·z′, where T represents transpose;
[0114] S622. Matching verification. For the edge nodes close to the data user, set I = {i: π(i) ∈ S′}, and the edge nodes calculate the constants {ω i ∈ Z p} i∈I such that ∑ i∈I ω i ·N i = (1, 0,..., 0), where N i is the i-th row of matrix N, and the edge nodes calculate the matching verification result If return that the matching verification passes, otherwise return that the matching verification fails.
[0115] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, step S700 includes:
[0116] S710. Blinded private key calculation. In response to a blinded private key request, the data user randomly selects σ ∈ Z p , and calculates the blinded private key
[0117] S720. Partial decryption of encrypted data. The data user uploads the blinded private key to the edge nodes close to the data user. The edge nodes close to the data user use the blinded key to perform partial decryption on the encrypted data. For the purified key encrypted data, if the data user attribute R does not satisfy the data user access policy (M, ρ), then stop partial decryption. If the data user attribute R satisfies the data user access policy (M, ρ), for the set I = {i: ρ(i) ∈ R}, there exist constants {w i ∈ Z p} i∈I such that ∑ i∈I w i ·M i = (1, 0,..., 0), where M i is the i-th row of matrix M; the edge nodes close to the data user return the partially decrypted encrypted data TCT = {E, F, F′},
[0118]
[0119] Optionally, in the bilateral access control method combining trust management and purification in any of the above embodiments, step S800 includes:
[0120] S810. The data user performs complete decryption of the encrypted data, and the data user calculates the session key of the symmetric key. and
[0121] S820. Judgment of decryption correctness and complete decryption. The data user determines whether to verify that the ciphertext is equal to the hash value obtained by combining the decrypted session key and the symmetric ciphertext, that is, to determine whether the equation C m = H 2 (H 0 (key′) || C sym ) holds. If they are not equal, it means that the data user attribute R satisfies the data user access policy (M, ρ) but the actual decryption is not completed, and the complete decryption is stopped. Otherwise, step S830 is executed;
[0122] S830. Complete decryption. The data user calculates the symmetric ciphertext and the plaintext m = SE.Dec(CT sym , H 1 (key)), where SE.Dec is the symmetric decryption algorithm.
[0123] Furthermore, in the bilateral access control method combining trust management and purification in the above embodiment, the symmetric decryption algorithm corresponds to the symmetric encryption algorithm, including DES (Data Encryption Standard), 3DES (Triple DES), and AES (Advanced Encryption Standard).
[0124] The applicant combines fine-grained bilateral access control, introduces a purifier mechanism and trust management. For the malicious behavior of "malicious data owners encrypting data in a harmful way", the purifier re-randomizes the encrypted data to prevent the malicious behavior of the data owner and prevent unauthorized users from decrypting the encrypted data encrypted in a harmful way; the purifier refuses to purify and upload encrypted data encrypted by data owners with a low global trust value, and the data user refuses to decrypt encrypted data encrypted by data owners with a low end-to-end (D-D) trust value. The present invention solves the problem of bilateral access control against the malicious behavior of data owners and achieves the purpose of ensuring the confidentiality and efficiency of data sharing in the cloud-edge-end architecture of industrial Internet of Things.
[0125] The following will further illustrate the concept, specific structure and technical effects generated by the present invention with reference to the drawings to fully understand the purpose, features and effects of the present invention. Description of the Drawings
[0126] Figure 1FIG. 0 is a flowchart illustrating a bilateral access control method combining trust management and purification according to an exemplary embodiment. DETAILED DESCRIPTION
[0127] The following describes multiple preferred embodiments of the present invention with reference to the accompanying drawings of the specification to make its technical content clearer and easier to understand. The present invention can be embodied in many different forms of embodiments, and the protection scope of the present invention is not limited to the embodiments mentioned in the text.
[0128] In the drawings, components with the same structure are denoted by the same numerical labels, and components with similar structures or functions are denoted by similar numerical labels. The size and thickness of each component shown in the drawings are arbitrarily shown, and the present invention does not limit the size and thickness of each component. To make the drawings clearer, the thickness of some components is schematically exaggerated appropriately in the drawings.
[0129] The inventor has designed a bilateral access control method combining trust management and purification, as Figure 1 shown, including the following steps:
[0130] S100. The authorization center initializes. The authorization center selects a security level according to security requirements, generates global public parameters, and publishes the global public parameters to the attribute authorization center, the purifier, the edge node, the data owner, and the data user. The purifier is a logical function module that obtains the global trust value of the data owner from the authorization center, determines whether the data owner is trustworthy, receives the encrypted data of the trustworthy data owner, and uses a purification algorithm to purify it, and sends the purified encrypted data to the cloud server. The global trust value synthesizes all the end-to-end trust values of the data users for the data owner, and is a trust evaluation of the data owner. The end-to-end trust value synthesizes the direct trust value and the indirect trust value, and is a comprehensive trust evaluation of the data owner by the directly interacting data users. The calculation methods of the direct trust value, the indirect trust value, the end-to-end trust value, and the global trust value are as follows:
[0131] S1000. Calculate the interaction record matrix. Assume that the interaction feedback of a data user x for a data owner y is f(x, y) k , where k represents the moment of interaction, and the range of the interaction feedback is from 0 to 1, which is proportional to the satisfaction degree of x for y. h x,y (Δt) represents the record of all interaction feedbacks of x for y within the time Δt, and is expressed as follows:
[0132] h x,y (Δt) = {f(x, y) 1 , f(x, y) 2 ,..., f(x, y) k ,..., f(x, y) Δt},
[0133] The matrix x stores the interaction records with other n data owners, and the representation is as follows:
[0134]
[0135] Among them, f(x,i) k represents the feedback of x to i in the k-th interaction;
[0136] S2000, Calculate the direct trust value. Define f(x,y) k ≥0.5 as a positive operation, and define the sum of the number of positive operation times as ∑f(x,y) k+ , and define f(x,y) k <0.5 as a negative operation, and define the sum of the number of negative operation times as ∑f(x,y) k- , define (0, ε·Δt) as the long term, and define (ε·Δt, Δt) as the short term, where 0.5 < ε < 1;
[0137] The formula for calculating the direct trust value DTV of x to y at time Δt is as follows:
[0138]
[0139] Among them, represents the long-term direct trust value, represents the short-term direct trust value, w l and w s represent the weights of the long-term direct trust value and the short-term direct trust value respectively, and β represents the time decay factor;
[0140] Long-term direct trust value and short-term direct trust value The calculation formulas are as follows:
[0141]
[0142] Among them, is a time decay function,
[0143] S3000, Calculate the indirect trust value. All direct trust values of the edge nodes within time Δt are stored in DTV(Δt):
[0144] DTV(Δt) = {DTV 1 , DTV 2 ,..., DTV k ,..., DTV Δt}
[0145]
[0146] Among them, DTV k represents the direct trust value matrix at time k, represents the direct trust vector, which contains the direct trust values of n data users for y at time k, represents the direct trust value of x for y at time k;
[0147] The formula for calculating the indirect trust value IDTV of y at time Δt is as follows:
[0148]
[0149] Among them, w x,y represents the calculation weight of x for y, represents whether i uploaded the direct trust value of y at time k, represents the i-th row of is non-empty, represents the i-th row of is empty;
[0150] S4000. End-to-end trust value calculation. The formula for calculating the end-to-end trust value of x for y at time Δt is as follows:
[0151]
[0152] Among them, w D is the direct trust value weight, w I is the indirect trust value weight, γ is a regulation factor. If x trusts its own interaction more, then the value of γ will be larger;
[0153] S5000. Global trust value calculation. The formula for calculating the global trust value of y at time Δt is as follows:
[0154]
[0155] Among them, z x represents the end-to-end trust value weight of x, i, j, n are positive integers, i and j represent serial numbers, and n represents the number of data owners;
[0156] Step S100 specifically includes:
[0157] S110. Select the security level. The authorization center selects the security level. The higher the security requirement, the higher the selected security level. Select the bilinear mapping e: G×G→G T , where e refers to the bilinear mapping that maps two elements on the multiplicative cyclic group G to an element on the multiplicative cyclic group G T on, and the multiplicative cyclic group G and the multiplicative cyclic group G TThe bit is λ, the order is p, g is the generator of G, λ is the security parameter representing the security level. The security levels are low, medium, and high, and the corresponding λ length is taken as 128 bits. p is a prime number, and the value of p is 160 bits;
[0158] S120. Select the attribute universe function and the attribute authorization universe function. Select the attribute universe function f that maps the attribute universe u to the multiplicative cyclic group G, and the formula is expressed as f: u → G, where u is the attribute universe. Select the attribute authorization universe function f′ that maps the attribute universe to the attribute authorization universe, and the formula is expressed as f′: u → u θ , where u θ is the attribute authorization universe, and the arrow means mapping. The attribute universe is all the attributes included, and the attribute authorization universe is all the attribute authorization centers included;
[0159] S130. Select the hash functions. The hash functions include H, H 0 , H 1 and H 2 , H is the hash function that maps the fake identity QID to an element of the multiplicative cyclic group G, H 0 is the hash function that maps the session key key of the symmetric key to a sequence of length l 0 , H 1 is the hash function that maps the session key key of the symmetric key to a sequence of length l 1 , H 2 is the hash function that maps the hash value KEY obtained by H 0 to the symmetric ciphertext CT sym and maps it to a sequence of length l 2 ;
[0160] S140. Generate the global public parameter PK, PK = <p, G, G T , e, g, f, f′, u, u θ , H, H 0 , H 1 , H 2 >;
[0161] S150. Publish the global public parameter. The authorization center publishes the global public parameter PK to the attribute authorization center, the purifier, the edge node, the data owner, and the data user.
[0162] S200. Attribute key request. The data owner generates a fake identity and a key pair for digital signature, and sends the data owner's attributes and the fake identity to the attribute authorization center to request the data owner's attribute private key; the data user sends the data user's attributes to the attribute authorization center to request the data user's attribute private key; specifically including:
[0163] S210. Calculate a fake identity. The data owner calculates the fake identity QID = AAP.Trans(GID), where AAP.Trans is a key generation algorithm commonly used for digital signatures, GID is the identifier of the data owner, and the key generation algorithms commonly used for digital signatures include the RSA algorithm, the DSA algorithm (Digital Signature Algorithm), and the ECDSA algorithm (Elliptic Curve Digital Signature Algorithm).
[0164] S220. Calculate a digital signature key pair. The data owner calculates the key pair (sk GID , vk GID ) = AAP.GEN(λ), where sk GID is the private key of the digital signature, vk GID is the public key of the digital signature, and AAP.GEN is a key generation algorithm commonly used for digital signatures.
[0165] S230. Data owner attribute private key request. The data owner sends the data owner attributes and the fake identity to the attribute authorization center and requests the data owner attribute private key.
[0166] S240. Data user attribute private key request. The data user sends the data user attributes to the attribute authorization center and requests the data user attribute private key.
[0167] S300. Attribute key generation. In response to the data owner attribute private key request, the attribute authorization center generates the data owner attribute private key and sends it to the data owner; in response to the data user attribute private key request, the attribute authorization center generates the data user attribute private key and sends it to the data user. Specifically, it includes:
[0168] S310. Data owner attribute reception. The attribute authorization center receives the data owner attributes and the fake identity QID, randomly selects a variable t ∈ Z p , and calculates the data owner private key SK 2 = g t , where S 1 , S 2 ,..., S r are attribute elements, r is a positive integer, and Z p is a finite field composed of p elements, that is, a set composed of integers 0, 1, 2,..., p - 1.
[0169] S320. Data owner attribute private key calculation. For the attribute authorization center calculates the private key component of the data owner
[0170] S330. Data owner attribute private key sending. The attribute authorization center calculates the data owner attribute private key And send it to the data owner;
[0171] S340. Receive data user attributes. The attribute authorization center receives data user attributes Randomly select k ∈ Z p , and calculate the private key component RK of the data user 2 = g k ;
[0172] S350. Calculate the attribute private key of the data user. For The attribute authorization center calculates the private key component of the data user
[0173] S360. Send the attribute private key of the data owner. The attribute authorization center calculates the private key of the data owner And send it to the data user.
[0174] S400. Data encryption. The data owner generates an offline ciphertext in the offline stage, and the data owner generates encrypted data in the online stage and sends it to the edge node close to the data owner; specifically including:
[0175] S410. Calculate the symmetric key. The data owner randomly selects the session key key ∈ G of the symmetric key in the offline stage T , calculate a hash value KEY = H 0 (key) and a symmetric key KEY * = H 1 (key);
[0176] S420. Perform offline encryption. The data owner randomly selects s, t' ∈ Z p , for the largest attribute P of size l', Randomly select μ i , t i , μ i ' ∈ Z p ;
[0177] For att i ∈ P, the data owner calculates the offline ciphertext component:
[0178]
[0179] For The data owner calculates the offline ciphertext component:
[0180]
[0181] The data owner obtains the offline ciphertext:
[0182] CT' key = <C0 , C 0 ′, {C 1,i , C 1 ′ ,i , C 2,i , C 3,i , C 4,i} i∈[l′] , S′, {E 1,i} i∈[r″] , E 2 , KEY, KEY * , QID>;
[0183] S430. Perform online encryption, and the data owner calculates the symmetric ciphertext CT sym = SE.Enc(m, KEY * ) and verify the ciphertext CT m = H 2 (KEY || CT sym ), where SE.Enc is a symmetric encryption algorithm, including DES (Data Encryption Standard), 3DES (Triple DES), AES (Advanced Encryption Standard);
[0184] The data owner randomly selects a vector Calculate the vector λ = (λ 1 , λ 2 ,..., λ l ) T = M·v, λ′ = (λ 1 ′, λ 2 ′,..., λ l ′) T = M·v′, where M is an l×n matrix, and l and n are integers greater than or equal to 1;
[0185] For the data owner calculates the online ciphertext component C 5,i = λ i - μ i , C 6,i = λ i ′- μ i ′, and the data owner obtains the online ciphertext CT key = <(M, ρ), C 0 , C 0 ′, {C 1,i , C 2,i , C 3,i , C 4,i , C 5,i , C 6,i} i∈[l] , S′, {E1,i} i∈[r″] ,E 2 >, the data owner calculates a digital signature using a general digital signature generation algorithm AAP.Sig is a general digital signature generation algorithm, including the RSA algorithm, DSA algorithm (Digital Signature Algorithm), and ECDSA algorithm (Elliptic Curve Digital Signature Algorithm). The general digital signature generation algorithm is consistent with the key generation algorithm of the general digital signature;
[0186] S440. Send the encrypted data, and the data owner obtains the encrypted data and sends it to the edge node close to the data owner.
[0187] S500. Encrypted data purification. The edge node receiving the encrypted data sends the encrypted data to the purifier. The purifier judges the credibility of the data owner and uses the purification algorithm to purify the encrypted data of the credible data owner, and then saves it to the cloud server; specifically including:
[0188] S510. Encrypted data forwarding. The edge node receiving the encrypted data sends the encrypted data to the purifier;
[0189] S520. Global trust value request. The purifier requests the global trust value and verifies the identity of the data owner. The purifier calculates the result of verifying the signature where AAP.Vrfy is a general digital signature verification algorithm, including the RSA algorithm, DSA algorithm (Digital Signature Algorithm), and ECDSA algorithm (Elliptic Curve Digital Signature Algorithm). The general digital signature verification algorithm is consistent with the general digital signature generation algorithm and the key generation algorithm of the general digital signature. If α = 0, the identity verification of the data owner fails. Otherwise, the purifier requests the global trust value GTrust of the data owner from the authorization center u ;
[0190] S530. Global trust value judgment. The purifier judges the global trust value GTrust u , if it is greater than the global trust threshold Trust t , the global trust threshold Trust t takes a value of 0.8, continue to execute S530, otherwise, reject the encrypted data;
[0191] S540. Encrypted data purification. The purifier purifies the encrypted data of the data owner. The purifier randomly selects a vector and calculates the vector θ = (θ 1 ,θ 2 ,...,θ l ) T = M·y, θ' = (θ1 ′, θ 2 ′,..., θ l ′) T = M · y′, the purifier randomly selects the session key key′ of the symmetric key ∈ G T , calculates the symmetric key KEY′ * = H 1 (key′) and the hash value KEY′ = H 0 (key′), the purifier randomly selects r ∈ Z p , calculates the purified encrypted data component:
[0192]
[0193] For i ∈ [l], the purifier calculates the purified encrypted data component, and the formula is as follows:
[0194]
[0195] S550, Encrypted data purification, the purifier purifies the encrypted data to obtain the purified encrypted data;
[0196] S560, Encrypted data storage, the purifier sends the purified encrypted data to the cloud server for storage.
[0197] S600, Matching verification, in response to the request of the data user to download the encrypted data, the cloud server sends the encrypted data to the purifier, the purifier sends the encrypted data to the edge node close to the data user, and the edge node close to the data user performs matching verification on the data owner of the encrypted data. After the matching verification passes, the edge node close to the data user requests the blinding private key from the data user; the matching verification includes that when the end-to-end trust value of the data owner is higher than the trust threshold required by the data user and the data owner attributes meet the data owner access policy, the edge node close to the data user sends the encrypted data to the data user, otherwise it does not send the encrypted data; specifically includes:
[0198] S610, End-to-end trust value judgment, the data user verifies the end-to-end trust value DTrust of the data owner u , if it is less than the end-to-end trust threshold Trust DU , then return the matching verification failure, otherwise execute S620, the end-to-end trust threshold Trust DU takes the value of 0.8;
[0199] S620, Data owner access policy judgment, the edge node close to the data user helps the data user verify the purified online ciphertext Whether the data owner attribute S′ in it satisfies the data owner access policy (N, π). If not, return that the matching verification fails, where N is an l′×n′ matrix, and l′ and n′ are integers greater than or equal to 1; including:
[0200] S621. Vector calculation. The edge node close to the data user randomly selects a vector and The edge node calculates the vector η = (η 1 , η 2 ,..., η l′ ) T = N·z, η′ = (η 1 ′, η 2 ′,..., η′ l′ ) T = N·z′, where T represents transpose;
[0201] S622. Matching verification. The edge node close to the data user sets the set I = {i: π(i) ∈ S′}, and the edge node calculates the constant {ω i ∈ Z p} i∈I to make Σ i∈I ω i ·N i = (1, 0,..., 0), where N i is the i-th row of the matrix N. The edge node calculates the matching verification result . If return that the matching verification passes, otherwise return that the matching verification fails;
[0202] S630. Blinded private key request. If the matching verification passes, the edge node close to the data user requests the blinded private key from the data user. Otherwise, the edge node close to the data user discards the encrypted data.
[0203] S700. Partial decryption of the encrypted data. The data user blinds the data user attribute private key to obtain the blinded private key and sends it to the edge node close to the data user. The edge node close to the data user uses the blinded key to partially decrypt the encrypted data and sends it to the data user; specifically including:
[0204] S710. Blinded private key calculation. In response to the blinded private key request, the data user randomly selects σ ∈ Z p , and calculates the blinded private key
[0205] S720: Partial decryption of encrypted data. The data user uploads the blinded private key to an edge node close to the data user. The edge node close to the data user uses the blinded key to partially decrypt the encrypted data. Encrypt data. If the data user attribute R does not satisfy the data user access policy (M, ρ), stop partial decryption. If the data user attribute R satisfies the data user access policy (M, ρ), for the set I = {i: ρ(i)∈R}, there exists a constant {w i ∈Z p} i∈I , so that Σ i∈I w i ·M i =(1,0,...,0), where M i is the i-th row of the matrix M; the edge node close to the data user returns partially decrypted encrypted data TCT = {E, F, F′},
[0206]
[0207] S800, decryption of encrypted data. In response to partially decrypted encrypted data, the data user verifies the correctness of the edge node decryption, determines whether the data user access policy is embedded in the ciphertext, and decrypts using the data user attribute private key after verification to obtain plaintext data. Specifically, the process includes:
[0208] S810: The data user completely decrypts the encrypted data and calculates the session key of the symmetric key. and
[0209] S820, correctness judgment of decryption and complete decryption, the data user judges whether the verification ciphertext is equal to the hash value of the decrypted session key and the symmetric ciphertext, that is, the judgment equation C m =H 2 (H 0 (key′) ‖C sym ) is established, if they are not equal, it means that the data user attribute R satisfies the data user access policy (M, ρ) but the actual decryption is not completed, then the complete decryption is stopped, otherwise, step S830 is executed;
[0210] S830, complete decryption, symmetric ciphertext calculated by the user and plaintext m = SE.Dec(CT sym ,H 1(key)), SE.Dec is a symmetric decryption algorithm. The symmetric decryption algorithm corresponds to the symmetric encryption algorithm and includes DES (Data Encryption Standard), 3DES (Triple DES), and AES (Advanced Encryption Standard).
[0211] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative efforts. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field according to the concept of the present invention through logical analysis, reasoning, or limited experiments on the basis of the prior art should fall within the protection scope determined by the claims.
Claims
1. A bilateral access control method combining trust management and purification, characterized in that: The steps include: S100, the authorization center is initialized. The authorization center selects a security level according to security requirements, generates global public parameters, and publishes the global public parameters to the attribute authorization center, purifiers, edge nodes, data owners, and data users; S200, attribute key request, the data owner generates a pseudo identity and a key pair for digital signature, sends the data owner attributes and pseudo identity to the attribute authorization center, and requests the data owner attribute private key; the data user sends the data user attributes to the attribute authorization center, and requests the data user attribute private key; S300, attribute key generation: in response to the data owner's attribute private key request, the attribute authorization center generates the data owner's attribute private key and sends it to the data owner; in response to the data user's attribute private key request, the attribute authorization center generates the data user's attribute private key and sends it to the data user; S400, data encryption, the data owner generates offline ciphertext in the offline stage, and the data owner generates encrypted data in the online stage, and sends it to an edge node close to the data owner; S500, encrypted data purification, the edge node receiving the encrypted data sends the encrypted data to the purifier, the purifier determines the credibility of the data owner, uses a purification algorithm to purify the encrypted data of the trusted data owner, and then saves it to the cloud server; S600, matching verification: in response to the data user's request to download the encrypted data, the cloud server sends the encrypted data to the purifier, and the purifier sends the encrypted data to the edge node close to the data user. The edge node close to the data user performs matching verification on the data owner of the encrypted data. After the matching verification is passed, the edge node close to the data user requests the blinded private key from the data user. S700, partially decrypting the encrypted data, the data user blinds the data user attribute private key to obtain the blinded private key, and sends it to the edge node close to the data user, the edge node close to the data user uses the blinded key to partially decrypt the encrypted data, and sends it to the data user; S800, decryption of encrypted data. In response to partially decrypted encrypted data, the data user verifies the correctness of the decryption by the edge node and determines whether the data user access policy is embedded in the ciphertext. After verification, the data user attribute private key is used to decrypt the data to obtain plaintext data.
2. The bilateral access control method combining trust management and purification as claimed in claim 1, characterized in that: The purifier is a logical function module, which obtains the global trust value of the data owner from the authorization center, determines whether the data owner is trustworthy, receives the encrypted data of the trustworthy data owner, purifies it using a purification algorithm, and sends the purified encrypted data to the cloud server.
3. The bilateral access control method combining trust management and purification as claimed in claim 2, characterized in that: The global trust value integrates the end-to-end trust values of all data users on the data owner and their trust evaluation on the data owner. The end-to-end trust value integrates the direct trust value and the indirect trust value, and is the comprehensive trust evaluation of the data owner by the directly interacting data users.
4. The bilateral access control method combining trust management and purification as claimed in claim 3, characterized in that: The direct trust value, the indirect trust value, the end-to-end trust value and the global trust value are calculated as follows: S1000, interaction record matrix calculation, assuming that the interaction feedback from a data user x to a data owner y is f(x,y) k , where k represents the moment of interaction, and the range of interaction feedback is 0 to 1, which is proportional to the satisfaction of x with y. x,y (Δt) represents the record of all interactive feedback from x to y within time Δt, which is expressed as follows: h x,y (Δt)={f(x,y) 1 ,f(x,y) 2 ,...,f(x,y) k ,...,f(x,y) Δt }, x stores the interaction record matrix with other n data owners, expressed as follows: S2000, direct trust value calculation, f(x,y) k ≥0.5 is defined as a positive operation, and the sum of the number of positive operations is defined as ∑f(x,y) k+ , f(x,y) k <0.5 is defined as a negative operation, and the sum of the number of negative operations is defined as ∑f(x,y) k- , define (0,ε·Δt) as the long term and (ε·Δt,Δt) as the short term, where 0.5<ε<1; The formula for calculating the direct trust value DTV of x to y at time Δt is as follows: Long-term direct trust value and short-term direct trust value The calculation formula is as follows: S3000, indirect trust value calculation, all direct trust values of edge nodes within time Δt are stored in DTV(Δt): The formula for calculating the indirect trust value IDTV of y at time Δt is as follows: S4000, end-to-end trust value calculation, the formula for calculating the end-to-end trust value of x to y at time Δt is as follows: S5000, global trust value calculation, the formula for calculating the global trust value of y at time Δt is as follows:
5. The bilateral access control method combining trust management and purification as claimed in claim 4, characterized in that: The step S100 includes: S110, select the security level. The authorization center selects the security level. The higher the security requirement, the higher the security level selected. Select the bilinear mapping e:G×G→G T , e refers to a bilinear map, which maps two elements on the multiplication cyclic group G to the multiplication cyclic group G T An element on the multiplicative cyclic group G and the multiplicative cyclic group G T The position is λ, the order is p, g is the generator of G, λ is the security parameter, indicating the security level, and p is a prime number; S120, select an attribute universe function and an attribute authorization universe function, select the attribute universe function f to map the attribute universe u to the multiplication cyclic group G, the formula is expressed as f:u→G, where u is the attribute universe, select the attribute authorization universe function f′, map the attribute universe to the attribute authorization universe, the formula is expressed as f′:u→u θ , where u θ It is the attribute authorization universe, the arrow means mapping, the attribute universe is all the attributes contained, and the attribute authorization universe is all the attribute authorization centers contained; S130, select a hash function, the hash function includes H, H0, H1 and H2, H is a hash function that maps the pseudo identity QID to an element of the multiplication cyclic group G, H0 is a hash function that maps the session key key of the symmetric key to a sequence of length l0, H1 is a hash function that maps the session key key of the symmetric key to a sequence of length l1, and H2 is a hash function that maps the hash value KEY obtained by H0 to the symmetric ciphertext CT sym A hash function that maps to a sequence of length l2; S140, generate global public parameter PK, PK= <p,G,G T ,e,g,f,f',u,u θ ,H,H0,H1,H2>; S150, publishing global public parameters, the authorization center publishes the global public parameters PK to the attribute authorization center, the purifier, the edge node, the data owner and the data user.
6. The bilateral access control method combining trust management and purification as claimed in claim 4, characterized in that: The step S200 includes: S210, calculating a false identity, the data owner calculates a false identity QID=AAP.Trans(GID); S220, calculate the digital signature key pair, the data owner calculates the key pair for digital signature (sk GID ,vk GID ) = AAP.GEN(λ); S230, data owner attribute private key request, the data owner sends the data owner attributes and a fake identity to the attribute authorization center, requesting the data owner attribute private key; S240, data user attribute private key request, the data user sends the data user attributes to the attribute authorization center and requests the data user attribute private key.
7. The bilateral access control method combining trust management and purification as claimed in claim 4, characterized in that: The step S300 includes: S310: Receiving data owner attributes: the attribute authorization center receives the data owner attributes and the pseudo identity QID, randomly select a variable t∈Z p , and calculate the data owner's private key SK2 = g t ; S320, data owner attribute private key calculation, for The attribute authorization center calculates the private key component of the data owner S330: The data owner's attribute private key is sent, and the attribute authorization center calculates the data owner's attribute private key and send it to the data owner; S340: Receiving data user attributes: the attribute authorization center receives the data user attributes Randomly select k∈Z p , and calculate the private key component RK2=g of the data user k ; S350, data user's attribute private key calculation, for The attribute authorization center calculates the private key component of the data user S360: The data owner's attribute private key is sent, and the attribute authorization center calculates the data owner's private key And send it to the data user.
8. The bilateral access control method combining trust management and purification as claimed in claim 4, characterized in that: The step S400 includes: S410, calculate the symmetric key, the data owner randomly selects the session key key∈G of the symmetric key in the offline stage T , calculate a hash value KEY = H0 (key) and a symmetric key KEY * =H1(key); S420, perform offline encryption, the data owner randomly selects s, t′∈Z p , for the largest attribute P of size l′, Randomly select μ i ,t i ,μ i ′∈Z p ; for att i ∈P, the data owner calculates the offline ciphertext component: for The data owner calculates the offline ciphertext component: E2=SK2·g t′ =gt t+t′ ; The data owner obtains the offline ciphertext: CT′ key =<C0,C′0,{C 1,i ,C′ 1,i ,C 2,i ,C 3,i ,C 4,i } i∈[l′] ,S′,{E 1,i } i∈[r″] ,E2,KEY,KEY * ,QID>; S430, perform online encryption, the data owner calculates the symmetric ciphertext CT sym =SE.Enc(m,KEY * ) and verification ciphertext CT m =H2(KEY||CT sym ); The data owner randomly selects a vector Calculate the vector λ=(λ1,λ2,...,λ l ) T =M·v,λ′=(λ′1,λ′2,...,λ′ l ) T =M·v′; for The data owner calculates the online ciphertext component C 5,i =λ i -μ i , C 6,i =λ′ i -μ′ i , the data owner obtains the online ciphertext CT key =<(M,ρ),C0,C′0,{C 1,i ,C 2,i ,C 3,i ,C 4,i ,C 5,i ,C 6,i } i∈[l] ,S′,{E 1,i } i∈[r″] ,E2>, the data owner uses a universal digital signature generation algorithm to calculate a digital signature S440: Send the encrypted data, and the data owner obtains the encrypted data And send it to the edge node that is close to the data owner.
9. The bilateral access control method combining trust management and purification as claimed in claim 4, characterized in that: The step S500 includes. S510, forwarding encrypted data, the edge node receiving the encrypted data sends the encrypted data to the purifier; S520: Global trust value request. The purifier requests the global trust value and verifies the identity of the data owner. The purifier calculates the result of the verification signature. If α=0, the data owner identity authentication fails. Otherwise, the purifier requests the global trust value GTrust of the data owner from the authorization center. u ; S530: global trust value judgment: the purifier judges the global trust value GTrust u , if it is greater than the global trust threshold Trust t , continue to execute S530, otherwise, refuse to encrypt the data; S540: Encrypted data purification: the purifier purifies the encrypted data of the data owner. The purifier randomly selects vectors And calculate the vector θ=(θ1,θ2,...,θ l ) T =M·y,θ′=(θ1′,θ2′,...,θ l ′) T =M·y′, the purifier randomly selects a symmetric key session key key′∈G T , calculate the symmetric key KEY′ * =H1(key′) and hash value KEY′=H0(key′), the purifier randomly selects r∈Z p , calculate the cleansed encrypted data component: For i∈[l], the purifier calculates the purified encrypted data component as follows: S550: Encrypted data purification, the purifier purifies the encrypted data Get the purified encrypted data; S560, encrypted data storage, the purifier sends the purified encrypted data to the cloud server for storage.
10. The bilateral access control method combining trust management and purification as claimed in claim 4, characterized in that: The step S600 includes: S610, end-to-end trust value judgment, the data user verifies the end-to-end trust value DTrust of the data owner u , if it is less than the end-to-end trust threshold Trust DU , then the matching verification fails, otherwise, step S620 is executed; S620: Data owner access policy determination, the edge node close to the data user helps the data user to verify the purified online ciphertext Whether the data owner attribute S′ in satisfies the data owner access policy (N, π), if not, the matching verification failure is returned; S630, blinded private key request: if the matching verification is passed, the edge node close to the data user requests the blinded private key from the data user; otherwise, the edge node close to the data user discards the encrypted data.