Broadcast encryption and decryption method and device, medium and equipment
Through the elliptic curve and polynomial secret sharing technology, public parameters and private keys are generated to realize the broadcast encryption and decryption method, solving the high computing and communication overhead problems of the SM2 encryption algorithm in one-to-many scenarios, and realizing secure data sharing with low overhead.
Patent Information
- Application Number
- CN202510266656.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-06
AI Technical Summary
As a one-to-one encryption mechanism, the SM2 encryption algorithm cannot be effectively applied in a one-to-many secure data sharing scenario, resulting in excessive computing cost and communication overhead.
By generating public parameters and private keys, the broadcast encryption and decryption method is realized using elliptic curves and polynomial secret sharing technology. This method generates a session key, performs encryption and decryption operations, and transmits the encrypted data through the public channel.
It realizes secure data sharing with low computing and communication overhead in multi-receiver scenarios. Only users in the target recipient set can decrypt it correctly, and non-collection users cannot obtain valid information.
Smart Images

Figure CN120110751A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encryption and decryption technology, and in particular to a broadcast encryption and decryption method, device, medium and equipment. Background Art
[0002] Under the same security strength, the SM2 encryption algorithm has the characteristics of short key, small system parameters and high security, and is widely used in fields such as the Internet of Things. However, as a one-to-one encryption mechanism, SM2 is subject to computational costs and communication overheads, and cannot be well applied in one-to-many secure data sharing scenarios.
[0003] With the continuous development of computer network technology, service-oriented network forms have gradually become the mainstream, and it is not uncommon for multiple users to request the same data. In this case, the server needs to respond to data requests from multiple users. If the traditional one-to-one public key encryption algorithm is used, it needs to perform multiple encryption operations repeatedly. The high encryption and decryption calculation cost will increase linearly with the number of recipients, resulting in huge overhead. Summary of the invention
[0004] In view of at least one of the above technical problems, an embodiment of the present invention provides a broadcast encryption and decryption method, device, medium, and equipment.
[0005] According to a first aspect, a broadcast encryption and decryption method provided by an embodiment of the present invention includes:
[0006] Determine the number s of message recipients;
[0007] Generate public parameters and s private keys according to the number s of message recipients and security parameters; wherein the public parameters include an elliptic curve and a base point of the elliptic curve;
[0008] Generate s public keys according to the base point and the s private keys; wherein each public key and the private key corresponding to the public key form a session key of the corresponding message recipient;
[0009] Generate a first random number r, perform r-times point operation on the base point to obtain coordinates of a first elliptic curve point, and convert the coordinates of the first elliptic curve point into a bit string type;
[0010] Perform r-times point operation on the public key of each message recipient to obtain the coordinates of the second elliptic curve point corresponding to the message recipient, and convert the coordinates of the second elliptic curve point into a bit string type;
[0011] Performing hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message receiver to obtain a first hash value;
[0012] Generate a second random number k, and generate a polynomial coefficient according to the first hash value corresponding to each message recipient and the second random number k;
[0013] Encrypting the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficient, and the second random number k to obtain a ciphertext;
[0014] The ciphertext, the bit string type coordinates of the first elliptic curve point and the polynomial coefficients are assembled into a broadcast message, and the broadcast message is broadcast to a public channel so that a message receiver with the session key can correctly decrypt the monitored broadcast message.
[0015] In one embodiment, generating s public keys based on the base point and the s private keys includes: traversing the s private keys one by one, and performing multiple point operations on the base point according to each traversed private key, and the multiple of the multiple point operation is the traversed private key, to obtain the public key corresponding to the traversed private key.
[0016] In one embodiment, the public parameters also include the cofactor h of the prime order of the base point; correspondingly, the method also includes: performing h times point operation on each public key to obtain the coordinates of the third elliptic curve point corresponding to the public key, and determining whether the coordinates of the third elliptic curve point corresponding to the public key are points at infinity; if so, the public key is invalid, an error is reported, and the encryption process is exited.
[0017] In one embodiment, the public parameters also include: a first hash function; correspondingly, performing a hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message recipient to obtain a first hash value, including: splicing the x-coordinate and y-coordinate of the bit string type of the second elliptic curve point corresponding to each message recipient to obtain spliced data; performing a hash calculation on the spliced data using the first hash function to obtain a first hash value, and the length of the first hash value output by the first hash function is the first length.
[0018] In one embodiment, generating polynomial coefficients according to the first hash values and the second random number k corresponding to each message recipient includes: calculating the polynomial coefficients using a calculation formula f(x):
[0019]
[0020] Among them, x is a formal variable, t i is the first hash value of the ith j is the jth polynomial coefficient, q is the number of elements in the finite field of the elliptic curve, and mod() is the area function.
[0021] In one embodiment, the public parameters also include a second hash function; correspondingly, encrypting the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficient and the second random number k includes: encrypting the plaintext to be encrypted using the following calculation formula:
[0022]
[0023] Among them, C 2 is the ciphertext, M is the plaintext to be encrypted, H 2 is the second hash function, C 1 is the bit string type coordinate of the first elliptic curve point, || is the concatenation symbol, a 0 ……a s-1 are the polynomial coefficients, [] τ-l means taking the first τ-l bits of [], [] l It means taking the last e bits of []. is the XOR symbol, and e is the first length.
[0024] In one embodiment, the decryption process of the message recipient includes:
[0025] Decomposing the bit string type coordinates of the first elliptic curve point from the broadcast message, and determining whether the coordinates of the first elliptic curve point corresponding to the bit string type coordinates conform to the elliptic curve equation; if not, reporting an error and exiting the decryption process; if conforming, continuing the decryption;
[0026] Perform h times point calculation on the coordinates of the first elliptic curve point to obtain the coordinates of the fourth elliptic curve point, and determine whether the coordinates of the fourth elliptic curve point are points at infinity. If so, report an error and exit the decryption process; otherwise, continue decryption; h is the cofactor of the prime order of the base point;
[0027] Using its own private key, perform multiple point operations on the coordinates of the first elliptic curve point to obtain the coordinates of the fifth elliptic curve point;
[0028] splicing the x-coordinate and the y-coordinate of the fifth elliptic curve point to obtain spliced data, performing hash calculation on the spliced data using the first hash function to obtain a second hash value of the first length, and determining whether the second hash value is an all-0 bit string; if so, reporting an error and exiting the decryption process, otherwise continuing the decryption;
[0029] Decomposing a polynomial coefficient from the broadcast message, and calculating a corresponding third random number according to the second Hash value and the polynomial coefficient;
[0030] Concatenate the bit string type coordinates of the first elliptic curve point, the polynomial coefficient and the third random number to obtain concatenated data, perform hash calculation on the concatenated data using a second hash function, and take the first τ-e bits of the hash calculation result;
[0031] Decomposing the ciphertext from the broadcast message;
[0032] Determine whether the first τ-1 bits of the ciphertext are the same as the first τ-1 bits taken from the hash calculation result;
[0033] If so, use Obtain the plaintext M corresponding to the ciphertext; wherein k1 is the third random number;
[0034] Otherwise, an error is reported and the decryption process is exited.
[0035] According to a second aspect, a broadcast encryption and decryption device provided by an embodiment of the present invention includes:
[0036] A first determination module, used to determine the number s of message recipients;
[0037] A first generating module, configured to generate public parameters and s private keys according to the number s of message recipients and security parameters; wherein the public parameters include an elliptic curve and a base point of the elliptic curve;
[0038] A second generation module is used to generate s public keys according to the base point and the s private keys; wherein each public key and the private key corresponding to the public key form a session key of the corresponding message recipient;
[0039] A third generating module is used to generate a first random number r, perform r times point operation on the base point to obtain the coordinates of the first elliptic curve point, and convert the coordinates of the first elliptic curve point into a bit string type;
[0040] A first calculation module is used to perform r-times point operation on the public key of each message recipient to obtain the coordinates of the second elliptic curve point corresponding to the message recipient, and convert the coordinates of the second elliptic curve point into a bit string type;
[0041] A second calculation module is used to perform hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message recipient to obtain a first hash value;
[0042] A fourth generating module, used to generate a second random number k, and generate a polynomial coefficient according to the first hash value corresponding to each message recipient and the second random number k;
[0043] a plaintext encryption module, configured to encrypt the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficients and the second random number k to obtain a ciphertext;
[0044] A message broadcast module is used to assemble the ciphertext, the bit string type coordinates of the first elliptic curve point and the polynomial coefficients into a broadcast message, and broadcast the broadcast message to a public channel so that a message receiver with the session key can correctly decrypt the monitored broadcast message.
[0045] According to a third aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, enables the computer to execute the method provided in the first aspect.
[0046] According to a fourth aspect, an embodiment of the present invention provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method provided in the first aspect is implemented.
[0047] The broadcast encryption and decryption method, device, medium, and equipment provided by the embodiment of the present invention generate public parameters and s private keys according to the number of message receivers s and security parameters, and then generate s public keys; generate a first random number r, perform r times point operation on the base point to obtain the coordinates of the first elliptic curve point, and convert the coordinates of the first elliptic curve point into a bit string type; perform r times point operation on the public key of each message receiver to obtain the coordinates of the second elliptic curve point corresponding to the message receiver, and convert the coordinates of the second elliptic curve point into a bit string type; perform hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message receiver to obtain a first hash value; generate a second random number k, and generate polynomial coefficients according to the first hash value and the second random number k corresponding to each message receiver; encrypt the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficients, and the second random number k to obtain a ciphertext, thereby assembling a broadcast message, and broadcasting the broadcast message to a public channel, so that only the message receiver with the session key can correctly decrypt the monitored broadcast message. Broadcast encryption is a one-to-many security encryption mechanism. s message receivers form the target receiving set. The data owner encrypts the data using the broadcast encryption algorithm and transmits the broadcast message through the public channel. All users who monitor the channel can obtain the broadcast message, but only users in the target receiving set can successfully decrypt the broadcast message using their own private key. Non-set users cannot obtain any valid information. In the scenario of secure data sharing, the broadcast encryption method can alleviate the huge overhead caused by repeated execution of public key encryption. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a flowchart of a broadcast encryption and decryption method according to an embodiment of the present invention;
[0049] Figure 2 It is a structural block diagram of a broadcast encryption and decryption device in one embodiment of the present invention. DETAILED DESCRIPTION
[0050] In a first aspect, an embodiment of the present invention provides a broadcast encryption and decryption method, see Figure 1 The method comprises the following steps S110 to S190:
[0051] S110, determining the number s of message receivers;
[0052] S120, generating public parameters and s private keys according to the number s of message recipients and security parameters; wherein the public parameters include an elliptic curve and a base point of the elliptic curve;
[0053] For example, if the number of message recipients s is 10, 10 private keys are generated.
[0054] Specifically, the initialization algorithm is based on (1 λ ,s) generates (PP, (sk i ) i∈[1,S] ). λ is a security parameter. PP is a public parameter, sk i is the i-th private key. Fq is a finite field with q elements, and the elliptic curve is defined as E(Fq). is a base point on the elliptic curve E(Fq), where x G and G is an element of the finite field Fq, p is the prime order of G, and h is the cofactor of p. Define the first hash function H 1 and the second hash function H 2 : Public parameters PP = (E(Fq), G, p, h, H 1 ,H 2 ).
[0055] Among them, H 1 : Its input is a binary string and a natural number, and its output is a binary string of length e; H 2 : The input is just a binary string, and the output is also a binary string of fixed length; H2 only receives one input parameter.
[0056] S130, generating s public keys according to the base point and the s private keys; wherein each public key and the private key corresponding to the public key form a session key of the corresponding message receiver;
[0057] In one embodiment, generating s public keys based on the base point and the s private keys may include: traversing the s private keys one by one, and performing a multiple point operation on the base point according to each traversed private key, and the multiple of the multiple point operation is the traversed private key, to obtain the public key corresponding to the traversed private key.
[0058] That is, the public key pk i =[sk i ]G. [ski]G means to perform multiple point operations on the elliptic curve on the base point G, with the multiple being sk i .
[0059] It can be seen that the key pairs (sk i , pk i ) i∈{1,s} , user U i The key pair includes the private key sk i and public key pk i .
[0060] S140, generating a first random number r, performing r-times point operation on the base point to obtain coordinates of a first elliptic curve point, and converting the coordinates of the first elliptic curve point into a bit string type;
[0061] That is, calculate the elliptic curve point C 1 =[r]G=(x 1 ,y 1 ), and (x 1 ,y 1 ) The coordinate type is converted to the bit string type. 1 is the first elliptic curve point.
[0062] In one embodiment, the public parameters may also include a cofactor h of the prime order of the base point; correspondingly, the method may also include: performing h times point operation on each public key to obtain the coordinates of the third elliptic curve point corresponding to the public key, and determining whether the coordinates of the third elliptic curve point corresponding to the public key are points at infinity; if so, the public key is invalid, an error is reported, and the encryption process is exited.
[0063] That is, calculate the third elliptic curve point P i =[h]pk i If P i If it is the infinite point O, an error is reported and the encryption process is exited. If it is not the infinite point O, S150 can be continued.
[0064] S150, performing r-times point operation on the public key of each message recipient to obtain the coordinates of the second elliptic curve point corresponding to the message recipient, and converting the coordinates of the second elliptic curve point into a bit string type;
[0065] That is to say, for user U i , calculate the second elliptic curve point [r]pk i =(x 2 i ,y 2 i ), and (x 2 i ,y 2 i )Coordinate type is converted to bit string type.
[0066] S160, performing hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message recipient to obtain a first hash value;
[0067] In one embodiment, the public parameters further include: a first hash function; correspondingly, performing hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message recipient to obtain the first hash value may include:
[0068] The x-coordinate and y-coordinate of the bit string type of the second elliptic curve point corresponding to each message recipient are spliced to obtain spliced data; the spliced data is hashed using a first hash function to obtain a first hash value, and the length of the first hash value output by the first hash function is the first length.
[0069] That is, user U i Corresponding first hash value: t i =H 1 (x 2 i ||y 2 i ,l), l is the first length.
[0070] S170, generating a second random number k, and generating a polynomial coefficient according to the first hash value corresponding to each message recipient and the second random number k;
[0071] In one embodiment, generating polynomial coefficients according to the first hash values and the second random number k corresponding to each message recipient may include: calculating the polynomial coefficients using a calculation formula f(x):
[0072]
[0073] Among them, x is a formal variable, t iis the first hash value of the ith j is the jth polynomial coefficient, q is the number of elements in the finite field of the elliptic curve, and mod() is the area function.
[0074] It can be seen that by calculating the formula f(x), s polynomial coefficients a can be calculated. 0 ……a s-1 .
[0075] S180, encrypting the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficient, and the second random number k to obtain a ciphertext;
[0076] In one embodiment, the public parameters may further include a second hash function; correspondingly, encrypting the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficients and the second random number k may include: encrypting the plaintext to be encrypted using the following calculation formula:
[0077]
[0078] Among them, C 2 is the ciphertext, M is the plaintext to be encrypted, H 2 is the second hash function, C 1 is the bit string type coordinate of the first elliptic curve point, || is the concatenation symbol, a 0 ……a s-1 are the polynomial coefficients, [] τ-l means taking the first τ-l bits of [], [] l It means taking the last e bits of []. is the XOR symbol, and e is the first length.
[0079] S190. Assemble the ciphertext, the bit string type coordinates of the first elliptic curve point and the polynomial coefficients into a broadcast message, and broadcast the broadcast message to a public channel so that a message receiver with the session key can correctly decrypt the monitored broadcast message.
[0080] It can be seen that the assembled broadcast message CT = (C 1 ,C 2 ,a 0 ,…,a s-1 ).
[0081] In order to ensure the unforgeability of the ciphertext, the anti-collision property of the hash function is used to calculate the hash value H for the selected random number k and the polynomial coefficient. 2 (C 1 ||a 0 ||...||as-1 ||k), and select the first e bits of the hash value to be XORed with the plaintext M, and the first τ-e bits of the hash value are involved in the verification.
[0082] Among them, the hash function, also known as the hash function, is a one-way function used to map data of any length to data of a fixed size. It is mainly used in data storage and retrieval. By performing hash calculation on the data, the data is mapped to a hash value of a fixed length, thereby facilitating data storage and fast retrieval. The hash function has the following properties: uniformity: for input values of any length, the hash function maps it to a uniformly distributed hash value, that is, the probability of each hash value should be as equal as possible; consistency: for the same input value, the hash function should always map to the same hash value; irreversibility: for the hash value, its original input value cannot be obtained by reverse calculation; anti-collision: for different input values, the hash function should map to different hash values to avoid hash collisions; efficiency: the hash function should be able to calculate the hash value in a reasonable time to achieve efficient data storage and retrieval.
[0083] In one embodiment, the decryption process of the message receiver includes S210 to S290:
[0084] S210, decomposing the bit string type coordinates of the first elliptic curve point from the broadcast message, and determining whether the first elliptic curve point coordinates corresponding to the bit string type coordinates conform to the elliptic curve equation; if not, reporting an error and exiting the decryption process; if conforming, continuing the decryption;
[0085] That is to say, C 1 Decompose it from CT and convert its data type to a point on the elliptic curve. After the conversion, verify C 1 Check whether the elliptic curve equation is satisfied. If not, an error is reported and the system exits. If satisfied, the system executes S220.
[0086] S220, performing h-times point calculation on the coordinates of the first elliptic curve point to obtain the coordinates of a fourth elliptic curve point, and determining whether the coordinates of the fourth elliptic curve point are points at infinity, if so, reporting an error and exiting the decryption process, otherwise continuing the decryption; h is the cofactor of the prime order of the base point;
[0087] That is, calculate the point P on the elliptic curve i =[h]C 1 , if P i It is a point at infinity, report an error and exit.
[0088] S230, using one's own private key to perform multiple point operations on the coordinates of the first elliptic curve point to obtain the coordinates of the fifth elliptic curve point;
[0089] That is, user U i Calculate [sk i ]C 1 =(x 2 i ,y 2 i ), and x 2 i ,y 2 i The data type is converted to string type.
[0090] S240, concatenating the x-coordinate and the y-coordinate of the fifth elliptic curve point to obtain concatenated data, performing hash calculation on the concatenated data using the first hash function to obtain a second hash value of the first length, and determining whether the second hash value is an all-0 bit string; if so, performing error processing and exiting the decryption process, otherwise continuing the decryption;
[0091] That is, calculate t i =H 1 (x 2 i ||y 2 i ,e), if t i If it is a string of all 0 bits, an error is reported and the program exits.
[0092] S250, decomposing polynomial coefficients from the broadcast message, and calculating a corresponding third random number according to the second Hash value and the polynomial coefficients;
[0093] That is, the s polynomial coefficients are separated from the broadcast message CT, and the third random number is solved Theoretically, the third random number k′ is equal to the second random number k.
[0094] S260, concatenating the bit string type coordinates of the first elliptic curve point, the polynomial coefficient and the third random number to obtain concatenated data, performing hash calculation on the concatenated data using a second hash function, and taking the first τ-1 bits of the hash calculation result;
[0095] That is, after S260, [H 2 (C 1 ||a 0 ||...||a s-1 ||k′)] τ-l .
[0096] S270, decomposing the ciphertext from the broadcast message;
[0097] That is, C is decomposed from the broadcast message 2 .
[0098] S280, determining whether the first τ-1 bits of the ciphertext are the same as the first τ-1 bits taken from the hash calculation result;
[0099] S290, if yes, then use Obtain the plaintext M corresponding to the ciphertext; wherein k1 is the third random number; otherwise, report an error and exit the decryption process.
[0100] It can be seen that the decrypted plaintext
[0101] Among them, an error symbol ⊥ can be returned when an error is reported.
[0102] Under the same security strength, the SM2 encryption algorithm has the characteristics of short key, small system parameters and high security, and is widely used in fields such as the Internet of Things. However, as a one-to-one encryption mechanism, SM2 is subject to computational cost and communication overhead, and cannot be well applied in one-to-many secure data sharing scenarios. In the era of data sharing, in order to adapt to the rapidly expanding application needs and expand the application of SM2 in the context of multiple receivers, a secure and efficient broadcast encryption method is proposed based on the national secret SM2 public key encryption algorithm and combined with polynomial secret sharing.
[0103] As a one-to-many security encryption mechanism, the broadcast ciphertext generated by the encryption algorithm should be able to be correctly decrypted by users in the receiving set. During the encryption phase, the broadcast encryption algorithm adds a receiver set as an input parameter to determine the target receiver. The broadcast message is transmitted through an open channel and can be obtained by any user who monitors the channel, but only the legitimate receiving users in the receiver set can complete the correct decryption.
[0104] Generally speaking, the broadcast encryption and decryption algorithm consists of the following three algorithms:
[0105] (1) Initialization algorithm (1 λ ,s): The initialization algorithm takes the security parameter λ and the total number of receivers s as input and outputs s user private keys (sk 1 ,sk 2 ,…,sk s ) and public parameters PP.
[0106] (2) Broadcast encryption algorithm (S, PP, M): The encryption algorithm takes plaintext, a set of receivers, and a public parameter PP as input and outputs a broadcast message CT.
[0107] (3) Broadcast decryption algorithm (S,i,sk i ,CT): The decryption algorithm uses the receiver set S and the private key sk corresponding to user i iand broadcast message CT as input and output the correct message M or the error symbol ⊥.
[0108] The beneficial effects of the embodiments of the present invention are as follows: in terms of security, under the Oracle Diffie-Hellman (ODH) difficulty assumption, the embodiments of the present invention meet indistinguishability security under chosen ciphertext attacks; in terms of algorithm efficiency, it has low computing and communication overhead, the system parameters and the sizes of public and private keys are fixed, and the ciphertext length is linearly related to the number of recipients; in terms of functional characteristics, it is dynamic and anonymous, and supports the system to add and reduce system users as needed. During decryption, the recipient cannot obtain information about other recipients in the set.
[0109] It can be seen that in order to solve the efficiency problem in the context of secure transmission with multiple receivers, the broadcast encryption and decryption method came into being. Broadcast encryption is a one-to-many secure encryption mechanism. In this method, after determining the target receiving set, the data owner uses the broadcast encryption algorithm to encrypt the data and transmits the broadcast message through a public channel. All users who monitor the channel can obtain the broadcast message, but only users in the target receiving set can successfully decrypt the broadcast message using their own private keys, and non-set users cannot obtain any valid information. In the scenario of secure data sharing, the application of broadcast encryption can alleviate the huge overhead caused by repeated execution of public key encryption. The advantages of the broadcast encryption and decryption method are as follows:
[0110] (1) Confidentiality: Only users in the receiver set can correctly decrypt the broadcast message;
[0111] (2) Anti-collusion attack: Users who are not in the receiver set cannot obtain the broadcast plaintext even if they join forces;
[0112] (3) Forward and backward security: Newly joined users cannot use the key to obtain previously broadcast plaintext, and exited users cannot use the key to continue decrypting subsequent broadcast plaintext.
[0113] In a second aspect, an embodiment of the present invention provides a broadcast encryption and decryption device, see Figure 2 , the device 100 comprises:
[0114] A first determination module 110, configured to determine the number s of message recipients;
[0115] A first generating module 120, configured to generate public parameters and s private keys according to the number s of message recipients and security parameters; wherein the public parameters include an elliptic curve and a base point of the elliptic curve;
[0116] A second generating module 130 is used to generate s public keys according to the base point and the s private keys; wherein each public key and the private key corresponding to the public key form a session key of the corresponding message receiver;
[0117] The third generating module 140 is used to generate a first random number r, perform r-times point operation on the base point to obtain the coordinates of the first elliptic curve point, and convert the coordinates of the first elliptic curve point into a bit string type;
[0118] A first calculation module 150 is used to perform r-times point operation on the public key of each message recipient to obtain the coordinates of the second elliptic curve point corresponding to the message recipient, and convert the coordinates of the second elliptic curve point into a bit string type;
[0119] A second calculation module 160 is used to perform hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message recipient to obtain a first hash value;
[0120] The fourth generating module 170 is used to generate a second random number k, and generate a polynomial coefficient according to the first hash value corresponding to each message recipient and the second random number k;
[0121] A plaintext encryption module 180, configured to encrypt the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficients and the second random number k to obtain a ciphertext;
[0122] The message broadcast module 190 is used to assemble the ciphertext, the bit string type coordinates of the first elliptic curve point and the polynomial coefficients into a broadcast message, and broadcast the broadcast message to a public channel so that the message receiver with the session key can correctly decrypt the monitored broadcast message.
[0123] In one embodiment, the first generation module is specifically used to: traverse the s private keys one by one, and according to each traversed private key, perform a multiple point operation on the base point, and the multiple of the multiple point operation is the traversed private key, to obtain the public key corresponding to the traversed private key.
[0124] In one embodiment, the common parameter also includes a cofactor h of the prime order of the base point; correspondingly, the device may further include:
[0125] The first verification module is used to perform h times point operation on each public key to obtain the coordinates of the third elliptic curve point corresponding to the public key, and determine whether the coordinates of the third elliptic curve point corresponding to the public key are points at infinity; if so, the public key is invalid, an error is reported and the encryption process is exited.
[0126] In one embodiment, the public parameters also include: a first hash function; correspondingly, the second calculation module is specifically used to: splice the x-coordinate and y-coordinate of the bit string type of the second elliptic curve point corresponding to each message recipient to obtain spliced data; use the first hash function to perform hash calculation on the spliced data to obtain a first hash value, and the length of the first hash value output by the first hash function is the first length.
[0127] In one embodiment, the fourth generating module is specifically used to calculate the polynomial coefficients using the calculation formula f(x):
[0128]
[0129] Among them, x is a formal variable, t i is the first hash value of the ith j is the jth polynomial coefficient, q is the number of elements in the finite field of the elliptic curve, and mod() is the area function.
[0130] In one embodiment, the public parameters also include a second hash function; correspondingly, the plaintext encryption module is specifically used to: encrypt the plaintext to be encrypted using the following calculation formula:
[0131]
[0132] Among them, C 2 is the ciphertext, M is the plaintext to be encrypted, H 2 is the second hash function, C 1 is the bit string type coordinate of the first elliptic curve point, || is the concatenation symbol, a 0 ……a s-1 are the polynomial coefficients, [] τ-l means taking the first τ-l bits of [], [] l It means taking the last l bits of []. is the XOR symbol, and l is the first length.
[0133] In one embodiment, the decryption process of the message receiver includes: decomposing the bit string type coordinates of the first elliptic curve point from the broadcast message, and determining whether the coordinates of the first elliptic curve point corresponding to the bit string type coordinates conform to the elliptic curve equation; if not, reporting an error and exiting the decryption process, if compliant, continuing decryption; performing h times point calculation on the coordinates of the first elliptic curve point to obtain the coordinates of the fourth elliptic curve point, and determining whether the coordinates of the fourth elliptic curve point are points at infinity, if so, reporting an error and exiting the decryption process, otherwise continuing decryption; h is the cofactor of the prime order of the base point; using one's own private key to perform multiple point operations on the coordinates of the first elliptic curve point to obtain the coordinates of the fifth elliptic curve point; splicing the x coordinate and y coordinate of the fifth elliptic curve point to obtain a spliced data, performing hash calculation on the concatenated data using the first hash function to obtain a second hash value of the first length, and determining whether the second hash value is an all-0 bit string; if so, performing error processing and exiting the decryption process, otherwise continuing decryption; decomposing the polynomial coefficients from the broadcast message, and calculating the corresponding third random number according to the second hash value and the polynomial coefficients; concatenating the bit string type coordinates of the first elliptic curve point, the polynomial coefficients and the third random number to obtain concatenated data, performing hash calculation on the concatenated data using the second hash function, and taking the first τ-1 bits of the hash calculation result; decomposing the ciphertext from the broadcast message; determining whether the first τ-1 bits of the ciphertext are the same as the first τ-1 bits taken from the hash calculation result; if so, using Obtain the plaintext M corresponding to the ciphertext; wherein k1 is the third random number; otherwise, report an error and exit the decryption process.
[0134] It is understandable that the explanation, specific implementation, beneficial effects, examples, etc. of the relevant contents in the device provided in the embodiment of the present invention can be found in the corresponding parts of the method provided in the first aspect, and will not be repeated here.
[0135] In a third aspect, an embodiment of the present invention provides a computer-readable medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the processor executes the method provided in the first aspect.
[0136] Specifically, a system or device equipped with a storage medium can be provided, on which software program code that implements the functions of any of the above-mentioned embodiments is stored, and a computer (or CPU or MPU) of the system or device can be enabled to read and execute the program code stored in the storage medium.
[0137] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute a part of the present invention.
[0138] The storage medium embodiments for providing the program code include a floppy disk, a hard disk, a magneto-optical disk, an optical disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), a magnetic tape, a non-volatile memory card, and a ROM. Alternatively, the program code can be downloaded from a server computer by a communication network.
[0139] In addition, it should be clear that the functions of any of the above embodiments can be implemented not only by executing the program code read by the computer, but also by enabling an operating system operating on the computer to complete part or all of the actual operations based on instructions from the program code.
[0140] In addition, it can be understood that the program code read from the storage medium is written to a memory provided in an expansion board inserted into the computer or to a memory provided in an expansion module connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or expansion module is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above-mentioned embodiments.
[0141] It is understandable that the explanation, specific implementation methods, beneficial effects, examples, etc. of the relevant contents in the computer-readable medium provided in the embodiment of the present invention can be found in the corresponding parts of the method provided in the first aspect, and will not be repeated here.
[0142] In a fourth aspect, an embodiment of the present specification provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method in any embodiment of the specification.
[0143] It is understandable that the explanation, specific implementation, beneficial effects, examples, etc. of the relevant contents in the computing device provided in the embodiment of the present invention can be found in the corresponding parts of the method provided in the first aspect, and will not be repeated here.
[0144] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0145] Those skilled in the art should be aware that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, widgets, or any combination thereof. When implemented by software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.
[0146] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made on the basis of the technical solution of the present invention should be included in the scope of protection of the present invention.
Claims
1. A broadcast encryption and decryption method, characterized in that: include: Determine the number s of message recipients; Generate public parameters and s private keys according to the number s of message recipients and security parameters; wherein the public parameters include an elliptic curve and a base point of the elliptic curve; Generate s public keys according to the base point and the s private keys; wherein each public key and the private key corresponding to the public key form a session key of the corresponding message recipient; Generate a first random number r, perform r-times point operation on the base point to obtain coordinates of a first elliptic curve point, and convert the coordinates of the first elliptic curve point into a bit string type; Perform r-times point operation on the public key of each message recipient to obtain the coordinates of the second elliptic curve point corresponding to the message recipient, and convert the coordinates of the second elliptic curve point into a bit string type; Performing hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message receiver to obtain a first hash value; Generate a second random number k, and generate a polynomial coefficient according to the first hash value corresponding to each message recipient and the second random number k; Encrypting the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficient, and the second random number k to obtain a ciphertext; The ciphertext, the bit string type coordinates of the first elliptic curve point and the polynomial coefficients are assembled into a broadcast message, and the broadcast message is broadcast to a public channel so that a message receiver with the session key can correctly decrypt the monitored broadcast message.
2. The method according to claim 1, characterized in that The generating of s public keys according to the base point and the s private keys comprises: traversing the s private keys one by one, and performing a multiple point operation on the base point according to each traversed private key, and the multiple of the multiple point operation is the traversed private key, to obtain the public key corresponding to the traversed private key.
3. The method according to claim 1, characterized in that The public parameters also include the cofactor h of the prime order of the base point; Correspondingly, the method further includes: performing h times point operation on each public key to obtain the coordinates of the third elliptic curve point corresponding to the public key, and determining whether the coordinates of the third elliptic curve point corresponding to the public key are points at infinity; If yes, the public key is invalid, an error is reported and the encryption process is exited.
4. The method according to claim 1, characterized in that: The public parameters also include: a first hash function; correspondingly, performing hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message recipient to obtain a first hash value, including: splicing the x coordinate and y coordinate of the bit string type of the second elliptic curve point corresponding to each message recipient to obtain spliced data; using the first hash function to perform hash calculation on the spliced data to obtain a first hash value, and the length of the first hash value output by the first hash function is the first length.
5. The method according to claim 1, characterized in that: The generating polynomial coefficients according to the first hash values corresponding to the respective message receivers and the second random number k includes: calculating the polynomial coefficients using a calculation formula f(x): Among them, x is a formal variable, t i is the first hash value of the ith j is the jth polynomial coefficient, q is the number of elements in the finite field of the elliptic curve, and mod() is the area function.
6. The method according to claim 1, characterized in that The public parameters also include a second Hash function; correspondingly, encrypting the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficients and the second random number k includes: encrypting the plaintext to be encrypted using the following calculation formula: Wherein, C2 is the ciphertext, M is the plaintext to be encrypted, H2 is the second hash function, C1 is the bit string type coordinate of the first elliptic curve point, || is the concatenation symbol, a0...a s-1 are the polynomial coefficients, [] τ-l means taking the first τ-l bits of [], [] l It means taking the last l bits of []. is the XOR symbol, and l is the first length.
7. The method according to claim 6, characterized in that The decryption process of the message receiver includes: Decomposing the bit string type coordinates of the first elliptic curve point from the broadcast message, and determining whether the coordinates of the first elliptic curve point corresponding to the bit string type coordinates conform to the elliptic curve equation; if not, reporting an error and exiting the decryption process; if conforming, continuing the decryption; Perform h times point calculation on the coordinates of the first elliptic curve point to obtain the coordinates of the fourth elliptic curve point, and determine whether the coordinates of the fourth elliptic curve point are points at infinity. If so, report an error and exit the decryption process; otherwise, continue decryption; h is the cofactor of the prime order of the base point; Using its own private key, perform multiple point operations on the coordinates of the first elliptic curve point to obtain the coordinates of the fifth elliptic curve point; splicing the x-coordinate and the y-coordinate of the fifth elliptic curve point to obtain spliced data, performing hash calculation on the spliced data using the first hash function to obtain a second hash value of the first length, and determining whether the second hash value is an all-0 bit string; if so, reporting an error and exiting the decryption process, otherwise continuing the decryption; Decomposing a polynomial coefficient from the broadcast message, and calculating a corresponding third random number according to the second Hash value and the polynomial coefficient; Concatenate the bit string type coordinates of the first elliptic curve point, the polynomial coefficient and the third random number to obtain concatenated data, perform hash calculation on the concatenated data using a second hash function, and take the first τ-e bits of the hash calculation result; Decomposing the ciphertext from the broadcast message; Determine whether the first τ-e bits of the ciphertext are the same as the first τ-e bits taken from the hash calculation result; If so, use Obtaining the plaintext M corresponding to the ciphertext; wherein k1 is the third random number; Otherwise, an error is reported and the decryption process is exited.
8. A broadcast encryption and decryption device, characterized in that: include: A first determination module, used to determine the number s of message recipients; A first generating module, configured to generate public parameters and s private keys according to the number s of message recipients and security parameters; wherein the public parameters include an elliptic curve and a base point of the elliptic curve; A second generation module is used to generate s public keys according to the base point and the s private keys; wherein each public key and the private key corresponding to the public key form a session key of the corresponding message recipient; A third generating module is used to generate a first random number r, perform r times point operation on the base point to obtain the coordinates of the first elliptic curve point, and convert the coordinates of the first elliptic curve point into a bit string type; A first calculation module is used to perform r-times point operation on the public key of each message recipient to obtain the coordinates of the second elliptic curve point corresponding to the message recipient, and convert the coordinates of the second elliptic curve point into a bit string type; A second calculation module is used to perform hash calculation on the bit string type coordinates of the second elliptic curve point corresponding to each message recipient to obtain a first hash value; A fourth generating module, used to generate a second random number k, and generate a polynomial coefficient according to the first hash value corresponding to each message recipient and the second random number k; a plaintext encryption module, configured to encrypt the plaintext to be encrypted according to the bit string type coordinates of the first elliptic curve point, the polynomial coefficients and the second random number k to obtain a ciphertext; A message broadcast module is used to assemble the ciphertext, the bit string type coordinates of the first elliptic curve point and the polynomial coefficients into a broadcast message, and broadcast the broadcast message to a public channel so that a message receiver with the session key can correctly decrypt the monitored broadcast message.
9. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed in a computer, the computer is caused to execute the method according to any one of claims 1 to 7.
10. A computing device, characterized in that: The method comprises a memory and a processor, wherein the memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
License list hiding method, license list verification method and license list verification system
CN122475915A