Puncture and searchable attribute-based encrypted data sharing method based on block chain

By adopting a piercing searchable attribute-based encrypted data sharing method based on blockchain in the cloud system, the information leakage, privacy protection, data query and access control problems in cloud data sharing are solved, and multi-keyword search, flexible management and fine-grained revocation are realized, improving system performance and user experience.

CN120128309APending Publication Date: 2025-06-10FUDAN UNIVERSITY
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510192904.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The prior art is difficult to achieve correct disclosure of data sharing in cloud systems, prevent information leakage, protect data privacy, realize efficient data query and flexible management of data access control permissions. At the same time, the traditional searchable encryption solution only supports precise search of single keywords, relies on centralized institutions, and lacks effective undoing functions.

Method used

The piercible searchable attribute-based encryption data sharing method is adopted based on blockchain, and through the collaborative work of the key generation center, data owner, data user, blockchain, proxy server and data storage server, multi-keyword search, flexible management of data access rights and fine-grained revocation of data users.

Benefits of technology

It realizes multi-keyword search for cloud data, flexible management of data access rights and fine-grained revocation of data users, improves system performance and user experience, and reduces the dependence of centralized institutions and the risk of single point of failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128309A_ABST
    Figure CN120128309A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of attribute-based encryption certification, and particularly relates to a puncturable and searchable attribute-based encrypted data sharing method based on a block chain. According to the scheme, an existing attribute-based encryption algorithm is expanded in the aspect of functional characteristics, and the searchable encryption is introduced to realize fine-grained access control and keyword search of the ciphertext. Meanwhile, a puncturable technology is introduced, and fine-grained revocation of the data user is realized by adding a puncture strategy to the ciphertext, and meanwhile, the forward security of revocation of the data user is ensured. And after the operation is cancelled, the user of the cancelled data does not need to perform any operation, and only one puncture strategy needs to be added to the ciphertext, so that the calculation overhead of the system is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of attribute-based encryption proof, and particularly relates to a method for sharing attribute-based encrypted data that is puncturable and searchable based on a blockchain. Background Technique

[0002] With the advent of the 5G era, the network capacity and service quality have been significantly improved, and technologies such as big data and cloud computing have developed rapidly. The connections between enterprises have become increasingly close, generating a huge amount of data. To relieve the local storage pressure and improve the convenience of file sharing, enterprises have begun to widely adopt cutting-edge technologies such as cloud computing to upload data to the cloud. Information sharing between enterprises has the characteristics of a large amount of information, one-to-many, and a wide range of information involved. Protecting sensitive enterprise data and providing a convenient data sharing function for enterprises has become the goal of the data sharing system. How to ensure the public correctness of data sharing, prevent information leakage, protect data privacy, achieve efficient data query, and flexibly manage the access control rights of data in the cloud system has become an urgent problem to be solved.

[0003] The proposal of searchable encryption makes it possible for users to perform search operations on encrypted data without decrypting the ciphertext data. Users search for the keywords corresponding to the ciphertext and quickly find the target file, thus avoiding the leakage of ciphertext information. According to the search characteristics of keywords, searchable encryption with keywords can be classified: classified by the number of keywords, it can be divided into single-keyword searchable encryption and multi-keyword searchable encryption. Single-keyword searchable encryption allows users to retrieve a single keyword in encrypted data, and multi-keyword searchable encryption can support retrieving multiple keywords simultaneously, which is suitable for scenarios where data related to multiple concepts needs to be searched at one time; classified by retrieval accuracy, it can be divided into exact search encryption and fuzzy search encryption. Exact search encryption can only retrieve results when the input keyword is exactly equal to the keyword of the file index value, and fuzzy searchable encryption can handle "fuzzy" search queries, which is very suitable for scenarios where the search term may contain spelling mistakes or where semantically similar words need to be found. Obviously, multi-keyword search and fuzzy search can better meet the search needs of real scenarios. However, most of the existing solutions can only achieve single-keyword search and exact search. At the same time, although searchable encryption provides a solution for data query, traditional searchable encryption still has problems such as relying on a central institution for search and being unable to flexibly manage data.

[0004] Attribute-Based Encryption (ABE) is a newly emerging encryption technology. Its core feature is that it focuses the key to encryption and decryption on the attributes of users, enabling fine-grained access control of data. The data sender controls the access rights of the data by defining the attribute access policy associated with the encrypted data. Only when the attribute set matches the access policy of the encrypted data can the data be successfully decrypted and the original data be restored. If the attributes of the receiver do not match the encryption policy, the decryption will fail. Attribute-based encryption is mainly divided into two types: Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and Key-Policy Attribute-Based Encryption (KP-ABE). Attribute-based encryption has significant advantages in scenarios such as access control, privacy protection, and cloud storage adaptation: (1) Flexible access control: Breaking through the limitations of traditional one-to-one identity encryption, it allows access rules to be set based on complex attribute conditions, achieving precise matching of data access rights. (2) Privacy protection: The entire encryption and decryption process revolves around attributes, without the need to expose the true identity of the user. Even in the scenario of sharing data, it can conceal the identities of participants while ensuring data security. (3) Cloud storage adaptation: In the cloud environment, in the face of high-frequency interactions between a large number of users and data, attribute-based encryption enables cloud service providers to perform refined data authorization management according to user attributes. Different users can access encrypted cloud resources according to their attributes as needed, thus significantly improving the security and availability of cloud storage.

[0005] Blockchain is a distributed ledger technology that provides a new perspective for solving the problem of relying on central institutions and has now been widely applied in many fields such as finance, supply chain, and digital copyright. The basic building block of the blockchain is the block, which can be vividly compared to the "account page" in the distributed ledger. Each block records a batch of transaction information and also contains its own hash value and the hash value of the previous block. Through this front-to-back connected structure, the blocks are strung together in chronological order. As new blocks are continuously added to the end of the chain, the entire ledger is continuously updated and extended, forming the blockchain. Compared with traditional central institutions, the blockchain has attracted much attention due to its characteristics of decentralization, immutability, and transparency: (1) Decentralization: Traditional transaction systems rely on central institutions for accounting and verification, while the blockchain eliminates the dependence on a single central node through a decentralized design. Numerous nodes in the distributed network jointly participate in the recording and maintenance of data, thus effectively avoiding the risks of single-point failures and excessive power concentration and enhancing the security and stability of the system. (2) Immutability: Once a block is added to the chain, the data is difficult to modify. To change the content of a certain block, not only the hash values of this block and all subsequent blocks need to be updated simultaneously, but also more than 51% of the network computing power needs to be mastered to complete, which is almost impossible in a large distributed network, thus ensuring the high reliability of the data. (3) Transparency: Unless through special privacy design, the data on the blockchain is usually public to all participating nodes. The time, content, and participant information of transactions are all transparently traceable, and this transparency greatly enhances the trust among network participants.

[0006] In recent years, in order to simultaneously achieve fine-grained access control and search capabilities, scholars have combined attribute-based encryption and searchable encryption and proposed attribute-based searchable encryption (ABSE). This technology has been widely applied in scenarios such as enterprise data sharing and medical data sharing, but there are still some areas that need to be improved:

[0007] 1. Keyword search. Most encryption schemes only support the exact search of a single keyword, which severely restricts the flexibility and scalability of the system. With the continuous growth of the data scale, how to efficiently retrieve data has become a key issue to be solved, and traditional schemes are difficult to cope with this challenge. Using a search strategy that combines multiple keywords can improve the retrieval efficiency of encrypted data. Existing schemes still have deficiencies in search matching and retrieval efficiency and need to be further optimized to improve system performance and user experience.

[0008] 2. Dependence on the central trust architecture. Existing solutions generally rely only on the centralized trust architecture, where the central institution is responsible for data search operations, posing risks of single-point failure and privacy and security threats. If the centralized institution encounters technical failures or malicious attacks, it may lead to the paralysis of the entire system. In addition, the centralized institution centrally stores a large amount of user privacy data. In case of a security incident resulting in the leakage of user privacy data, the losses will be huge.

[0009] 3. Revocation function. Facing the situation of frequent changes in personnel and their identities, most current solutions lack effective support for user revocation and attribute revocation. Some solutions that support revocation rely on the centralized institution to maintain user and attribute record tables, which not only increases the storage burden on the central institution but also increases the system complexity. Some solutions adopt a version update mechanism. However, each time an attribute is updated, users who have not been revoked need to update their attribute keys, which brings significant inconvenience to users and limits the practical usability of the solutions.

[0010] In summary, to better achieve data sharing, this paper deeply analyzes the deficiencies of existing platforms, and combines blockchain, searchable encryption, and attribute-based encryption technologies to design an enterprise data sharing method that supports multi-keyword search and flexible management, and elaborates on its model process and technical implementation in detail. Summary of the Invention

[0011] The object of the present invention is to provide a blockchain-based puncturable searchable attribute-based encryption data sharing method.

[0012] A blockchain-based puncturable searchable attribute-based encryption data sharing method proposed by the present invention is implemented by a sharing system, which includes a Key Generation Center (KGC), a Data Owner (DO), a Data User (DU), a Blockchain (BC), a Proxy Server (PS), and a Data Storage Server (DSS): Among them: The data user is bidirectionally connected to the proxy server, the data storage server, and the blockchain respectively. The output end of the key generation center is connected to the data user and the data owner respectively. The output end of the data owner is connected to the data storage server and the blockchain respectively;

[0013] The key generation center generates a system public key and a key for the sharing system; and generates a unique user private key for the data user according to the attributes and tags owned by the data user;

[0014] The data owner is a sharing system entity that owns data. It is responsible for encrypting sensitive data under the access control policy and defining the puncturing policy. When the data owner wants to revoke the ciphertext and prevent access to it, the data owner will send the puncturing policy to the data storage server to update the ciphertext;

[0015] The data user is the entity that accesses the data. It needs to simultaneously satisfy having attributes that meet the access policy and an identity that does not meet the puncturing policy in order to successfully access the data;

[0016] The blockchain is a trusted consensus network that is responsible for recording the data user information and the index information of the encrypted data; in addition, the blockchain smart contract will execute the search step and return the encrypted data with keywords;

[0017] The proxy server is responsible for outsourcing the calculation and decrypting the ciphertext to obtain the pre-decrypted ciphertext;

[0018] The data storage server is responsible for managing the ciphertext. The data owner stores their ciphertext in the data storage server. The data storage manager is responsible for managing the access rights of the data so that when the data owner receives the puncturing policy, the ciphertext can be punctured;

[0019] The specific process of the sharing method is as follows:

[0020] (1) System initialization: Run the system initialization algorithm. The system is initialized with the security parameter as the input, and the system public key and the system master key are output. The system public key is made public and uploaded to the blockchain, while the system master key is saved well and kept confidential;

[0021] (2) Registration and login: Run the data user private key generation algorithm, which is responsible for generating the data user identity private key. The data user sets the identity identifier (including information such as the affiliated enterprise), registers, and uses the key generation algorithm with the system public key, the system master key, and the data user attribute set as the input to output the data user private key. The data user private key includes the attribute private key and the identity private key of the data user, generating the data user GID and the data user identity private key; The data user identity identifier information is made public, and the data user identity private key is sent to the data user; Among them: The ciphertext generation algorithm is divided into an index generation algorithm and an information encryption algorithm. The index generation algorithm generates an index matrix for the information, and the information encryption algorithm encrypts the plaintext information into ciphertext;

[0022] (3) Attribute Application: Run the user private key generation algorithm, which is responsible for generating the identity private key of the data user. The data user makes an attribute application and uses the index trapdoor generation algorithm. Taking the system public key, the master key, and the keyword set as inputs, it outputs keyword index information. The data user sends its own identity information and the attributes it wants to apply for to the system. The system generates the corresponding attribute private key for the data user and returns it to the data user;

[0023] (4) File Encryption: Run the index generation algorithm and the information encryption algorithm to generate index matrix information and encrypted ciphertext respectively; Use the encryption method. Taking the system public key, the access structure, the keyword index information, the plaintext, and the symmetric encryption key as inputs, encrypt the plaintext data with the symmetric key to obtain the symmetric encrypted ciphertext. The file data selects keywords and generates an index, encrypts the file data, stores the encrypted ciphertext data in the data storage server, and uploads the ciphertext data storage information and the index to the blockchain;

[0024] (5) Attribute Update: The system can choose to update the attributes and run the attribute update algorithm; The system will select new public and private keys for the attributes to be updated, and send the update information to the data users and ciphertexts with these attributes. The data users update the attribute private keys, and the ciphertexts update the attribute keys;

[0025] (6) Ciphertext Pruning: Using the pruning method, the data owner can choose to perform a pruning operation on the files it uploads, so that data users with certain identity information lose the ability to decrypt the ciphertext data. At the same time, update the ciphertext data in the data storage server;

[0026] (7) User Search: The data user inputs the query keywords, uses the search algorithm to generate a query index, uses the query trapdoor generation algorithm, and sends it to the blockchain for comparison with the information on the blockchain. If the search matches successfully, the storage information of the ciphertext data in the data storage server can be obtained, and the encrypted data can be requested from the data storage server according to the index information;

[0027] (8) Data Decryption: Data decryption is carried out in two steps; The data user sends its partial private key and the ciphertext data to the proxy server. The proxy server performs proxy decryption, uses the pre-decryption algorithm to generate the pre-decrypted ciphertext and returns it to the data user. Using the data user decryption algorithm, the data user decrypts again to obtain the file data.

[0028] In the present invention, in step (1), the system initialization mentioned, input the security parameter λ, select the multiplicative cyclic group G and G T , the generator of group G is g, the order is p, and the bilinear mapping e: G×G→G T , a hash function H:{0,1} *→ G to map the data user identifier to the group G; select a pseudorandom function F∶{0,1} λ ×{0,1} * →{0,1} λ , and select a string k of length λ as the key for the pseudorandom function F; randomly select α,β,a,b∈Z p , calculate g 1 =g α ,g 2 =g β ,e(g,g) a ,e(g,g) b ; let the maximum length of the keyword be c, generate rsk=(M 1 ,M 2 ,s), where M 1 ,M 2 are two randomly selected invertible matrices of rank l, and s is a binary vector of length c; use W to represent the set of 26 English letters, select a virtual character set J=(j ,j 1 ,j 2 ,...,j c ) that satisfies the length of c and 1 ,primes 2 ,...,primes c ); S is the attribute set, for each attribute i∈S, select yi∈Z p * as the private key of the attribute, UK i =g yi as the public key of the attribute; select a symmetric encryption algorithm, in this paper, AES is selected, and the symmetric encryption algorithm includes encryption and decryption operations, that is, AES={AES.Enc,AES.Dec};

[0029] The system public key is:

[0030] PK=<e,G,G T ,p,g,g 1 ,g 2 ,e(g,g) a ,e(g,g) b ,H,F,AES,{UK i =g yi ,i∈S}>

[0031] The system master private key is:

[0032] MSK=<rsk,k,Primes,J,α,β,a,b,{yi,i∈S}>

[0033] In the present invention, the user private key generation algorithm described in steps (2) and (3) is specifically as follows:

[0034] After a data user registers, the user obtains a global identifier GID. The data user can apply for a private key. The data user's private key includes two parts: an identity private key and an attribute private key. The system randomly selects two random numbers a 1 + a 2 that satisfy a = a 1 , a 2 , and calculates D 1 , D 2 For the attribute i in the attribute set S GID , calculates the attribute private key K i,GID . The composition of the data user's private key USK is as follows:

[0035] USK = <D 1 = g a1 * g αβ+b , D 2 = g a2 , {K i,GID = g a * H(GID) yi , i ∈ S}>.

[0036] In the present invention, the index trapdoor generation algorithm described in step (3) is specifically as follows:

[0037] The file File has a keyword set KW = {kw 1 ,..., kw m} that contains m keywords; uses the keyword set KW to generate an index matrix P ∈ R m×l :

[0038] (3.1) For the i-th keyword kw i , uses an algorithm to construct an l-dimensional vector p i ;

[0039] (3.1.1) For the keyword kw i , uses the virtual character set J to supplement the length of the keyword so as to hide the true length of the keyword. After the supplement process, each keyword will become a length of c;

[0040] (3.1.2) Selects an l-dimensional vector p i and initializes each of its elements to 1;

[0041] (3.1.3) Uses the prime numbers in the prime number set Primes to operate on the elements in p i ; for the keyword kw iFor the nth letter, first find the position σ of the letter in the vector p i in n = F k (kw i [n]), and then use the nth prime number primes n to multiply with the corresponding position p i [σ n ;

[0042] (3.1.4) Fill some of the remaining elements of pi with random prime numbers other than Primes to increase the randomness of the vector;

[0043] (3.2) Insert the vector p i as the ith row of the matrix P into the matrix P, i.e., P[i][*] ← p i ; Detailed explanation of the algorithm: For the generated index matrix P, use the encryption algorithm of the secure k-nearest neighbor algorithm to divide it into two matrices to obtain the index information Index, i.e., Index = (P a , P b ), where P a , P b ∈R m×l .

[0044] In the present invention, the information encryption algorithm in step (4) is as follows:

[0045] The data owner randomly selects ck ∈ Z p as the key for symmetric encryption, uses the symmetric encryption algorithm on the plaintext data to obtain the encrypted data AES.Enc ck (m) and saves it in the data storage server (DSS) to obtain the file storage address Addr; form a linear secret sharing scheme matrix (M, ρ) according to the access policy, where M is an n M × l M matrix, and ρ is a function that maps the matrix to the attribute set; then combine the system public key PK and the index information Index to generate the ciphertext CT:

[0046] Randomly select the secret s ∈ Z p to be shared, randomly select v 2 ,..., v nm , θ 2 ,..., θ nm ∈ Z p , obtain the column vectors v = (s, v 2 ,..., v nm ) and w = (0, θ 2 ,..., θ nm ), and calculate λ with each row M i of the matrixi = M i ·v and ω i = M i ·w;

[0047] Then calculate the ciphertext CT: Randomly select r 0 ∈ Z p , and obtain the initial ciphertext SK of the puncturing strategy 0 = {sk 0 = g 2 s}, calculate C 0 = ck·e(g, g) as , C 1 = g s ; Randomly select r for each row of the matrix i ∈ Z p , calculate

[0048] C 1,i = e(g, g) bλi ·e(g, g) a·ri

[0049] C 2,i = g ri

[0050] C 3,i = g yi·ri ·g ωi

[0051] Finally, obtain the ciphertext

[0052]

[0053] In the present invention, the puncturing algorithm in step (6) is specifically as follows: Assume that the punctured ciphertext in the ciphertext CT is SK k-1 . After receiving the puncturing strategy PPk, the data storage manager punctures the ciphertext with the puncturing strategy. For the puncturing strategy PP k , use De Morgan's law to transform it into the access strategy AP k according to the following rules: For non-leaf nodes in the puncturing strategy PP k :

[0054] (6.1). If it is an AND gate, transform it into a NOT gate;

[0055] (6.2). If it is a NOT gate, transform it into an AND gate;

[0056] (6.3). If it is a (k, n) threshold gate, transform it into an (n - k + 1, n) threshold gate;

[0057] For leaf nodes: In the puncturing strategy PP kAmong them, the leaf node is the identifier t related to the data user, and it is transformed into (not t). After determining the access policy AP k , randomly select λk ∈ Zp and perform the following calculations to update the SK in the ciphertext k-1 :

[0058] sk0′ = sk0 · g2 (-λk) = gβ (s-λ1-...-λk)

[0059] According to the generated access policy AP k Generate a linear secret sharing scheme, where the secret to be shared is s. For each row corresponding identifier Allocate and skj,2 = g1 λk,j . Define And update the SK in the ciphertext k-1 to SK k as follows:

[0060] SK k = <{PP i ,(M i ,ρ i )}i∈[1 - k],sk0′,sk 1 ,...,sk k-1 ,sk k >>.

[0061] In the present invention, the query trapdoor generation and search algorithm are involved in step (7). The query trapdoor generation and search algorithm are divided into two parts: the query trapdoor generation algorithm and the search algorithm. The query trapdoor generation algorithm generates a corresponding query matrix according to the keywords that the data user wants to search, and the search algorithm searches the ciphertext data according to the generated query matrix;

[0062] Query trapdoor generation algorithm:

[0063] The data user will query a keyword set KW′ = {kw 1 ′,...,kw γ ′} containing γ keywords. The data user uses algorithm 5 to construct a query matrix Q ∈ R l×γ : (1) For the i-th keyword kw i ′, construct an l-dimensional vector q i ; (2) Insert the vector q i as the i-th row of the matrix Q into the matrix Q, that is, Q[i][*] ← q i ;

[0064] (7.1). For the keyword kw i′, use the virtual character set J to supplement the length of the keyword to hide the true length of the keyword. After the supplementation process, each keyword will become length c;

[0065] (7.2). Select an l-dimensional vector q i and initialize each of its elements to 1;

[0066] (7.3). Use the prime numbers in the prime number set Primes to operate on the elements in q i ; For the nth character of the keyword kw i ′, if the character is "?", do not operate; otherwise, first find the position σ i in the vector q n =F k (kw i ′[n]), and then use the reciprocal of the nth prime number prime n to multiply the corresponding position q i in the vector; n in the vector;

[0067] (7.4). Fill the remaining partial elements of q i with random integers outside Primes to increase the randomness of the vector; For the generated index matrix Q, use the encryption algorithm of the secure k-nearest neighbor algorithm to divide it into two matrices to obtain the query information Query, that is, Query=(Q a ,Q b ), where Q a ,Q b ∈R l×m ;

[0068] Search algorithm:

[0069] Input the query information Query and the ciphertext data CT; Use the test algorithm in the secure k-nearest neighbor algorithm, the query information Query=(Q a ,Q b ) and the index information Index=(P a ,P b ) in the ciphertext data to generate the test matrix Test=P a *Q a +P b *Q b, it can be obtained that matrix Test is an m-row and γ-column matrix; where Test[i][j] = P[i][*]★Q[*][j], i ∈ [1 - m], j ∈ [1 - γ], which represents the matching degree between the i-th indexed keyword and the j-th query keyword. If Test[i][j] is an integer, it means that these two keywords match successfully; therefore, if the j-th keyword matches successfully, there is at least one integer in the j-th column of the Test matrix; at the same time, for "AND" and "OR" semantic queries, the following definitions are as follows: (1) For "AND" semantic query, each column of the Test matrix contains at least one integer; (2) For "OR" semantic query, at least one column of the Test matrix contains an integer; if the search condition is met, return 1; otherwise return 0.

[0070] In the present invention, in step (8), the decryption algorithm is divided into two parts: a pre-decryption algorithm and a user decryption algorithm. The proxy server calculates the pre-decrypted ciphertext and returns it to the data user, and the data user decrypts the ciphertext locally;

[0071] Pre-decryption algorithm:

[0072] The data user sends his partial private key USK' and the ciphertext CT to the proxy server (PS), where the partial private key is as follows:

[0073] USK' = <D1 = g a1 *g αβ+b ,{K i,GID = g a *H(GID) yi , i ∈ S}>

[0074] The proxy server obtains the system public key PK, the partial private key USK' and the ciphertext CT. S represents the attribute set corresponding to USK', and I = i∶ρ ∈ S represents the set of rows of the matrix corresponding to the attribute. The proxy server calculates the constant ci that satisfies ∑ i∈I ci·Mi = (1, 0,..., 0), and then performs the following calculations for each row in I:

[0075] C 1,i ·e(H(GID), C 3,i ) / e(K i,GID , C 2,i ) = e(g, g) b·λi ·e(H(GID), g) ωi

[0076] From the fact that the constant ci satisfies ∑ i∈I ci·Mi = (1, 0,..., 0), it can be deduced that ∑ i∈I λi·ci = s and ∑ i∈Iωi·ci = 0 can be obtained as follows:

[0077] W = ∏ i∈I (e(g,g) b·λi ·e(H(GID),g) ωi ) ci = e(g,g) bs

[0078] If the data user satisfies the access policy of the attribute, the secret e(g,g) can be recovered from (M,ρ). bs . Then the proxy server checks whether the tag carried by the data user matches the puncturing policy SK in the ciphertext, that is, whether it satisfies the puncturing policy PP k of the ciphertext 1 orPP 2 or...orPP k . If the tag carried by the data user is punctured, ⊥ is returned, indicating decryption failure. If the data user is not punctured, the data user can decrypt the puncturing policy in the following way: For each row of the puncturing policy (M i ,ρ i ) containing the information sk i,j , randomly select ri ∈ Zp and calculate T i,2 = (g 1 ) ri . At the same time, calculate the constant ci that satisfies ∑ i∈I ci·Mi = (1,0,...,0), and finally calculate Zi:

[0079] Zi = ∏ i∈I e(sk i,2 ,g 2 ·T i,1 )ci / ∏ i∈I e(sk i,1 ,T i,2 ) ci = e(g,g) αβλi

[0080] After recovering the secret value Zi = e(g,g) corresponding to the policy (M i ,ρ i ), the proxy server recovers Z0 from sk0' in the ciphertext according to the following method: αβλi

[0081] Z0 = e(sk0,g 1 ) = e(g,g) β(s-λ1-...-λk)

[0082] Finally, the proxy server calculates and obtains The proxy server calculates A according to the following method:​

[0083] A = e(D 1 ,C 1 ) / W = e(g,g) a1·s ·e(g,g) αβs

[0084] Then, the pre - decrypted ciphertext CTpre is obtained by calculating with the obtained A as follows:

[0085] CTpre = C0·B / A = ck·e(g,g) a2·s

[0086] User decryption:

[0087] After the data user obtains the pre - decrypted ciphertext CTpre, the symmetric encryption key ck of the ciphertext is obtained through the following calculation:

[0088] ck = CTpre / e(C1,D2)

[0089] The data user obtains the file AES.Enc ck (m) through the file storage address Addr in the ciphertext CT, and then decrypts the file using the symmetric encryption key ck: m = AES.Dec ck (AES.Enc ck (m)), and the final plaintext data m is obtained.

[0090] The beneficial effects of the present invention are as follows: The solution of the present invention expands the functional characteristics of the existing attribute - based encryption algorithm. By introducing searchable encryption, it realizes fine - grained access control and keyword search for ciphertexts. At the same time, the puncturable technology is introduced. By adding a puncturing strategy to the ciphertext, it realizes fine - grained revocation of data users and ensures the forward security of data user revocation. After the revocation operation, the revoked data user does not need to perform any operation, and only a puncturing strategy needs to be added to the ciphertext, greatly reducing the computational overhead of the system. Description of the Drawings

[0091] Figure 1 is the overall model of the present invention;

[0092] Figure 2 is the overall architecture of the system of the present invention;

[0093] Figure 3 is the sequence diagram of the system of the present invention. Detailed Embodiments

[0094] The present invention will be further described below through embodiments in conjunction with the drawings.

[0095] Embodiment 1:

[0096] Figure 1 This is the overall model diagram of the present invention, which includes the entities in the present invention and the interaction operation relationships between the entities. The entities include: Key Generation Center (KGC), Data Owner (DO), Data User (DU), Blockchain (BC), Proxy Server (PS), and Data Storage Server (DSS).

[0097] The specific functions are as follows:

[0098] (1) Key Generation Center (KGC): This entity generates public keys and private keys for the system. It generates unique user private keys for data users according to the attributes and tags owned by the data users.

[0099] (2) Data Owner (DO): This entity is a system entity that owns data. It can upload data and define a puncturing strategy for the data it uploads. Whenever the data owner wants to revoke the data user's access to the ciphertext, the data owner will send the puncturing strategy to the data storage server to update the ciphertext.

[0100] (3) Data User (DU): This entity is the entity that accesses data. It needs to simultaneously meet the attributes that satisfy the access policy and the identifiers that do not satisfy the puncturing strategy in order to successfully access the data.

[0101] (4) Blockchain (BC): This entity is a trusted consensus network, responsible for recording data user information and index information of encrypted data. In addition, the blockchain smart contract will execute the search step and return the encrypted data with keywords.

[0102] (5) Proxy Server (PS): This entity is responsible for outsourcing computing and decrypting the ciphertext to obtain a pre-decrypted ciphertext.

[0103] (6) Data Storage Server (DSS): This entity is responsible for managing ciphertexts. Data owners store their ciphertexts in the data storage server. The data storage manager part is responsible for managing the access rights of the data so that when the data owner receives the puncturing strategy, the ciphertext can be punctured.

[0104] Figure 2This is the overall architecture of the system of the present invention, which shows the core hierarchical structure of the data sharing system, including the application layer, the business layer contract layer, and the storage layer. Each layer works together to ensure the secure sharing and efficient utilization of data. The application layer includes the front-end display page, which is built using vue3. The business layer includes the back-end data processing and the interaction with the contract layer, which is implemented using the Spring-boot framework. The contract layer uses smart contracts in Hyperledger Fabric to execute contract operations. The storage layer uses MySQL and CouchDB to store data.

[0105] The interaction process framework of the system of the present invention is as follows:

[0106] (1) Start the system, and the system runs the system initialization algorithm to generate the system public and private keys;

[0107] (2) The data user registers, and the system runs the key generation algorithm to generate the user identity private key for the data user;

[0108] (3) The data user applies for attributes, and the system runs the key generation algorithm to generate the user attribute private key for the data user;

[0109] (4) The data owner runs the encryption algorithm to encrypt the ciphertext, runs the index generation algorithm to generate an index for the ciphertext data, uploads the ciphertext data to the data storage server, and uploads the index information to the blockchain;

[0110] (5) The data owner can choose to run the puncture algorithm to puncture the ciphertext data;

[0111] (6) The data user selects keywords, runs the query trapdoor generation algorithm to generate query information, and runs the search algorithm to search for the corresponding data file;

[0112] (7) When the data user wants to decrypt the ciphertext data, it requests the proxy server to run the proxy decryption algorithm to generate the pre-decrypted ciphertext. After the data user obtains the pre-decrypted ciphertext, it runs the user decryption algorithm to decrypt;

[0113] (8) The system runs the attribute update algorithm to update the attributes. The system will select new public and private keys for the attributes that need to be updated, send the update information to the data users and ciphertexts with this attribute. The data users update the attribute private keys, and the ciphertexts update the attribute keys.

[0114] Figure 3 This is the sequence diagram of the system of the present invention. The process of the present invention includes the following stages: system initialization, registration and login, attribute application, file encryption, attribute update, ciphertext puncture, user search, and data decryption. In each stage, operations are initiated by entities in the system.

[0115] (1) System initialization: Run the system initialization algorithm. The system is initialized, taking the security parameter as input, outputting the system public key and the system master key. The system public key is made public and uploaded to the blockchain, while the system master key is saved securely and kept confidential.

[0116] (2) Registration and login: Run the user private key generation algorithm, which is responsible for generating the private key of the data user's identity. The data user sets the identity identifier (including information such as the affiliated enterprise), registers, and uses the key generation algorithm. Taking the system public key, the system master key, and the data user's attribute set as input, it outputs the user private key, which includes the user's attribute private key and identity private key, and generates the user GID and the user identity private key. The user identity identifier information is made public, and the data user's identity private key is sent to the data user. Among them: The ciphertext generation algorithm is divided into the index generation algorithm and the information encryption algorithm. The index generation algorithm generates an index matrix for the information, and the information encryption algorithm encrypts the plaintext information into ciphertext.

[0117] (3) Attribute application: Run the user private key generation algorithm, which is responsible for generating the data user's attribute private key. The data user makes an attribute application and uses the index trapdoor generation algorithm. Taking the system public key, the master key, and the keyword set as input, it outputs the keyword index information. The data user sends his own identity identifier information and the attributes he wants to apply for to the system. The system generates the corresponding attribute private key for the data user and returns it to the data user.

[0118] (4) File encryption: Run the index generation algorithm and the information encryption algorithm to generate the index matrix information and the encrypted ciphertext respectively. Using the encryption method, taking the system public key, the access structure, the keyword index information, the plaintext, and the symmetric encryption key as input, the plaintext data is encrypted with the symmetric key to obtain the symmetric encrypted ciphertext. The file data selects keywords and generates an index, encrypts the file data, stores the encrypted ciphertext data in the data storage server, and uploads the ciphertext data storage information and the index to the blockchain. (5) Attribute update: The system can choose to update the attributes and run the attribute update algorithm. The system will select new public and private keys for the attributes to be updated, send the update information to the data users and ciphertexts with these attributes. The data users update their attribute private keys, and the ciphertexts update their attribute keys.

[0119] (6) Ciphertext puncturing: Using the puncturing method, the data owner can choose to perform a puncturing operation on the files he uploads, making data users with certain identity identifiers lose the ability to decrypt the ciphertext data. At the same time, the ciphertext data in the data storage server is updated.

[0120] (7) User Search: The data user inputs query keywords, generates a query index using a search algorithm, and uses a query trapdoor generation algorithm to send it to the blockchain for comparison with the information on the blockchain. If the search matches successfully, the storage information of the ciphertext data on the data storage server is obtained, and the encrypted data can be requested from the data storage server according to the index information;

[0121] (8) Data Decryption: Data decryption is carried out in two steps; the data user sends his own partial private key and the ciphertext data to the proxy server, and the proxy server performs proxy decryption. Using a pre-decryption algorithm, the pre-decrypted ciphertext is generated and returned to the data user. Using the user decryption algorithm, the user then decrypts to obtain the file data.

Claims

1. A blockchain-based puncturable and searchable attribute-based encrypted data sharing method, characterized by: The sharing method is implemented by a sharing system, which includes a key generation center, a data owner, a data user, a blockchain, a proxy server, and a data storage server: wherein the data user is bidirectionally connected to the proxy server, the data storage server, and the blockchain respectively, the output end of the key generation center is connected to the data user and the data owner respectively, and the output end of the data owner is connected to the data storage server and the blockchain respectively; The key generation center generates system public keys and secret keys for the shared system; it generates unique user private keys for data users based on the attributes and tags they possess; The data owner is a shared system entity that owns the data. It is responsible for encrypting sensitive data under the access control policy and defining the puncture policy. When the data owner wants to revoke the ciphertext for the data user and prevent him from accessing the ciphertext, the data owner will send the puncture policy to the data storage server and update the ciphertext. Data users are entities that access data. They need to have attributes that satisfy the access policy and identifiers that do not satisfy the puncture policy to successfully access the data. Blockchain is a trusted consensus network that records data user information and index information of encrypted data. In addition, blockchain smart contracts perform search steps and return encrypted data with keywords. The proxy server is responsible for outsourcing the computation and decrypting the ciphertext to obtain the pre-decrypted ciphertext; The data storage server is responsible for managing the ciphertexts. The data owners store their ciphertexts in the data storage server. The data storage manager is responsible for managing the access rights to the data so as to pierce the ciphertexts when the data owners receive the piercing policy. The specific process of the sharing method is as follows: (1) System initialization: Run the system initialization algorithm, initialize the system, take security parameters as input, output the system public key and system master key, and make the system public key public and upload it to the blockchain. At the same time, save the system master key and keep it confidential. (2) Registration and login: Run the user private key generation algorithm to generate the user identity private key. The data user sets the identity and registers. The key generation algorithm is used to take the system public key, the system master key and the user attribute set as inputs, and output the user private key. The user private key includes the user's attribute private key and identity private key. The data user GID and the data user identity private key are generated. The data user identity information is made public and the data user identity private key is sent to the data user. Among them: the ciphertext generation algorithm is divided into an index generation algorithm and an information encryption algorithm. The index generation algorithm generates an index matrix for information, and the information encryption algorithm encrypts the plaintext information into ciphertext. (3) Attribute application: Run the user private key generation algorithm to generate the user identity private key. The data user applies for the attribute and uses the index trapdoor generation algorithm. It takes the system public key, master key and keyword set as input, outputs keyword index information, and sends its own identity information and the attribute it wants to apply for to the system. The system generates the corresponding attribute private key for the data user and returns it to the data user. (4) File encryption: Run the index generation algorithm and information encryption algorithm to generate index matrix information and encrypted ciphertext respectively; adopt an encryption method, take the system public key, access structure, keyword index information, plaintext and symmetric encryption key as input, encrypt the plaintext data with the symmetric key to obtain symmetric encrypted ciphertext, select keywords for file data and generate indexes, encrypt file data, store the encrypted ciphertext data in the data storage server, and upload the ciphertext data storage information and index to the blockchain; (5) Attribute update: The system can choose to update attributes and run the attribute update algorithm. The system will select new public and private keys for the attributes that need to be updated, and send the update information to the data user and ciphertext with the attribute. The data user updates the attribute private key, and the ciphertext updates the attribute secret key. (6) Ciphertext puncture: Using the puncture method, the data owner chooses to perform a puncture operation on the file he or she uploaded, so that data users with certain identity identifiers lose the ability to decrypt the ciphertext data. At the same time, the ciphertext data in the data storage server is updated; (7) User search: The data user inputs the query keyword and uses the search algorithm to generate the query index. The query trapdoor generation algorithm is used and sent to the blockchain for comparison with the information on the blockchain. If the search matches successfully, the storage information of the ciphertext data in the data storage server is obtained. Based on the index information, the data storage server can be requested to return the encrypted data. (8) Data decryption: Data decryption is carried out in two steps. The data user sends part of his or her private key and ciphertext data to the proxy server. The proxy server performs proxy decryption and uses a pre-decryption algorithm to generate pre-decrypted ciphertext and returns it to the data user. The data user then uses a user decryption algorithm to decrypt the data and obtain the file data.

2. According to claim 1, a blockchain-based puncturable and searchable attribute-based encrypted data sharing method is characterized by: In step (1), the system is initialized, the security parameter λ is input, and the multiplication cycle groups G and G are selected. T , the generator of the group G is g, the order is p, the bilinear map e: G×G→G, a hash function H:{0,1} * →G to map the data user identifier to group G; select pseudo-random function F: {0,1} λ ×{0,1} * →{0,1} λ , and select a string k of length λ as the key of the pseudo-random function F; randomly select α, β, a, b∈Z p * , calculate g1 = g α ,g2=g β ,e(g,g) a ,e(g,g) b ; Let the maximum length of the keyword be c, generate rsk = (M1, M2, s), where: M1, M2 are two randomly selected reversible matrices of rank l, s is a binary vector of length c; use W to represent the set of 26 English letters, select a set that satisfies the length c and The virtual character set J = (j1, j2, ..., j c ); Randomly select c prime numbers to form the prime number set Primes = (primes1, primes2, ..., primes c ); S is the attribute set, for each attribute i∈S, select yi∈Z p * As the private key of the attribute, UK i =g yi As the attribute public key; select a symmetric encryption algorithm, the selected AES, the symmetric encryption algorithm includes encryption and decryption operations, that is, AES = {AES.Enc, AES.Dec}; The system public key is: PK=<e,G,G T ,p,g,g1,g2,e(g,g) a ,e(g,g) b ,H,F,AES,{UK i =g yi ,i∈S}> The system master private key is: MSK=<rsk,k,Primes,J,α,β,a,b,{yi,i∈S}> .

3. According to claim 1, a blockchain-based puncturable and searchable attribute-based encrypted data sharing method is characterized by: The user private key generation algorithm in step (2) and step (3) is specifically: After the data user registers, he obtains the global identifier GID and applies for a private key. The private key of the data user consists of two parts: the identity private key and the attribute private key. The sharing system randomly selects two random numbers a1 and a2 that satisfy a=a1+a2, calculates D1 and D2, and is the attribute set S GID Calculate the attribute private key K from the attribute i in i,GID , the composition of the data user's private key USK is as follows: USK=<D1=g a1 *g αβ+b ,D2=g a2 ,{K i,GID =g a *H(GID) yi ,i∈S}>。 4. According to claim 1, a blockchain-based puncturable and searchable attribute-based encrypted data sharing method is characterized by: The index trapdoor generation algorithm described in step (3) is specifically: The file File has a keyword set KW containing m keywords = {kw1,...,kw m }; Use the keyword set KW to generate the index matrix P∈R for the data file File to be uploaded m×l : (3.1) For the i-th keyword kw i , use the algorithm to construct an l-dimensional vector p i ; (3.1.1) For the keyword kw i ,Use virtual character set J to supplement the length of the keyword to achieve the purpose of hiding the real length of the keyword. After the supplementation process, each keyword will become length c; (3.1.2) Select an l-dimensional vector p i And initialize each of its elements to 1; (3.1.3) Use the prime numbers in the prime number set Primes to find p i Operate on the elements in; for the keyword kw i The nth letter, first find the letter in the vector p i The corresponding position σ n =F k (kw i [n]), and then use the nth prime number primes n To the corresponding position p in the vector i [σ n ] multiply; (3.1.4) Fill some of the remaining elements of pi with random prime numbers other than Primes to increase the randomness of the vector; (3.2) The vector p i Insert it into the matrix P as the i-th row of the matrix P, that is, P[i][*]←p i Detailed explanation of the algorithm: For the generated index matrix P, the encryption algorithm of the secure k-nearest neighbor algorithm is used to divide it into two matrices to obtain the index information Index, that is, Index = (P a ,P b ), where P a ,P b ∈R m×l .

5. According to claim 1, a blockchain-based puncturable and searchable attribute-based encrypted data sharing method is characterized by: The information encryption algorithm in step (4) has the following specific steps: The data owner randomly selects ck∈Z p As the key of symmetric encryption, the plaintext data is encrypted using the symmetric encryption algorithm AES.Enc ck (m) and save it to the data storage server to obtain the file storage address Addr; formulate a linear secret sharing scheme matrix (M, ρ) according to the access strategy, where M is an n M × M , ρ is a function that maps a matrix to a set of attributes; then the ciphertext CT is generated by combining the system public key PK and index information Index: Randomly select a secret s∈Z to share p , randomly select v2,...,v nm ,θ2,...,θ nm ∈Z p , get the column vector v=(s,v2,...,v nm ) and w=(0,θ2,...,θ nm ), and each row of the matrix M i Calculate λ i =M i v and ω i =M i ·w; Then calculate the ciphertext CT: Randomly select r0∈Z p , get the initial ciphertext of the puncture strategy SK0 = {sk0 = g2 s }, calculate C0 = ck·e(g,g) as ,C1=g s ; Randomly select r for each row of the matrix i ∈Z p ,calculate: C 1,i =e(g,g) bλi ·e(g,g) a·ri C 2,i =g ri C 3,i =g yi·ri ·g ωi Finally, we get the ciphertext, 6. The method for sharing blockchain-based puncturable and searchable attribute-based encrypted data according to claim 1, characterized in that: The puncture algorithm in step (6) is as follows: Assuming that the punctured ciphertext in the current ciphertext CT is SKk-1, after receiving the puncture strategy PPk, the data storage manager punctures the ciphertext using the puncture strategy. For the puncture strategy PPk, De Morgan's law is used to convert it into an access strategy APk according to the following rules: For non-leaf nodes in the puncture strategy PPk: (6.1). If it is an AND gate, convert it into a NOT gate; (6.2). If it is a NOT gate, convert it into an AND gate; (6.3). If it is a (k, n) threshold, convert it to a (n-k+1, n) threshold; For leaf nodes: In the puncture strategy PPk, the leaf node is the identifier t associated with the data user, which is transformed into (non-t), after determining the access policy APk, randomly select λk∈Zp and perform the following calculation to update SKk-1 in the ciphertext: sk0′=sk0·g2(-λk)=gβ(s-λ1-...-λk) Generate a linear secret sharing scheme based on the generated access policy APk, where the secret to be shared is s. For each row, the corresponding identifier distribute and skj,2=g1λk,j, define And update SKk-1 in the ciphertext to SKk as follows: SKk=<{PPi,(Mi,ρi)}i∈[1-k],sk0′,sk1,...,skk-1,skk>.

7. The method for sharing blockchain-based puncturable and searchable attribute-based encrypted data according to claim 1, characterized in that: Step (7) involves query trapdoor generation and search algorithm, which is divided into two parts: query trapdoor generation algorithm and search algorithm. The query trapdoor generation algorithm generates a corresponding query matrix according to the keywords that the data user wants to search, and the search algorithm searches the ciphertext data according to the generated query matrix. Query the trapdoor generation algorithm: The keyword set KW′={kw1′,...,kw γ ′}, the data user uses Algorithm 5 to construct the query matrix Q∈R l×γ :(1) For the i-th keyword kw i ′, construct an l-dimensional vector q i ; (2) vector q i Insert the i-th row of matrix Q into matrix Q, i.e. Q[i][*]←q i ; (7.1). For the keyword kw i ′, use the virtual character set J to supplement the length of the keyword to achieve the purpose of hiding the real length of the keyword. After the supplementation process, each keyword will become length c; (7.2). Select an l-dimensional vector q i And initialize each of its elements to 1; (7.3) Use the prime numbers in the prime number set Primes to compare q i Operate on the elements in; for the keyword kw i ′, if the character is "?", no operation is performed; otherwise, first find the letter in the vector q i The corresponding position σ n =F k (kw i ′[n]), and then use the nth prime number prime n The reciprocal of q in the corresponding position in the vector i [σ n ] multiply; (7.4) Fill q with random integers other than Primes i The remaining elements of the vector are used to increase the randomness of the vector; for the generated index matrix Q, the encryption algorithm of the secure k-nearest neighbor algorithm is used to divide it into two matrices to obtain the query information Query, that is, Query = (Q a ,Q b ), where Q a ,Q b ∈R l×m ; Search Algorithm: Input query information Query and ciphertext data CT; use the test algorithm in the secure k-nearest neighbor algorithm, query information Query = (Qa, Qb) and index information Index = (Pa, Pb) in the ciphertext data to generate a test matrix Test = Pa*Qa+Pb*Qb, and the matrix Test is an m-row, γ-column matrix; where Test[i][j] = P[i][*]★Q[*][j], i∈[1-m], j∈[1-γ], which represents the matching degree between the i-th index keyword and the j-th query keyword. If Test[i][j] is an integer, it means that the two keywords are matched successfully. Therefore, if the j-th keyword is matched successfully, there is at least one integer in the j-th column of the Test matrix. At the same time, for "AND" and "OR" semantic queries, the following definitions are made: (1) For "AND" semantic queries, each column of the Test matrix contains at least one integer; (2) For "OR" semantic queries, at least one column of the Test matrix contains an integer; if the search condition is met, 1 is returned; otherwise, 0 is returned.

8. The blockchain-based puncturable and searchable attribute-based encrypted data sharing method according to claim 1, characterized in that: The decryption algorithm in step (8) is divided into two parts: a pre-decryption algorithm and a user decryption algorithm. The proxy server calculates the pre-decryption ciphertext and returns it to the data user, who decrypts the ciphertext locally. Pre-decryption algorithm: The data user sends his partial private key USK′ and ciphertext CT to the proxy server, where the partial private key is as follows: USK′=<D1=ga1*gαβ+b,{Ki,GID=ga*H(GID)yi,i∈S}> The proxy server obtains the system public key PK, the partial private key USK′ and the ciphertext CT. S represents the attribute set corresponding to USK′, I=i∶ρ∈S represents the set of rows of the matrix corresponding to the attribute, and the proxy server calculates the constant ci that satisfies ∑i∈I c·Mi=(1,0,...,0), and then performs the following calculation on each row in I: C1,i·e(H(GID),C3,i) / e(Ki,GID,C2,i)=e(g,g)b·λi·e(H(GID),g)ωi, From the constant ci satisfying ∑i∈I ci·Mi=(1,0,...,0), we can deduce ∑i∈Iλi·ci=s and ∑i∈Iωi·ci=0: W=∏i∈I(e(g,g)b·λi·e(H(GID),g)ωi)ci=e(g,g)bs If the data user satisfies the access policy of the attribute, the secret e(g,g)bs can be recovered from (M,ρ). Then the proxy server checks whether the label carried by the data user matches the puncture strategy SKk in the ciphertext, that is, it satisfies the puncture strategy PP1orPP2or...orPPk of the ciphertext. If the label carried by the data user is punctured, ⊥ is returned, indicating that the decryption fails. If the data user is not punctured, the data user can decrypt the puncture strategy in the following way: For each row of the information ski,j contained in the puncture strategy (Mi,ρi), randomly select ri∈Zp and calculate Ti,2=(g1)ri, and at the same time calculate the constant ci that satisfies ∑i∈I ci·Mi=(1,0,...,0), and finally calculate Zi: Zi=∏i∈Ie(ski,2,g2·Ti,1)ci / ∏i∈I e(ski,1,Ti,2)ci=e(g,g)αβλi After recovering the secret value Zi=e(g,g)αβλi corresponding to the policy (Mi,ρi), the proxy server recovers Z0 using sk0′ in the ciphertext as follows: Z0=e(SK0,g1)=e(g,g)β(s-λ1-...-λk) Finally, the proxy server calculates B = ∏i = 0kZi = e(g, g)αβs The proxy server calculates A as follows: A=e(D1,C1) / W=e(g,g)a1·s·e(g,g)αβs Then, the pre-decrypted ciphertext CTpre is calculated from the obtained A as follows: CTpre=C0·B / A=ck·e(g,g)a2·s User decryption: After obtaining the pre-decrypted ciphertext CTpre, the data user obtains the symmetric encryption key c'k of the ciphertext through the following calculation: ck=CTpre / e(C1,D2) The data user obtains the file AES.Encck(m) through the file storage address Addr in the ciphertext CT, and then decrypts the file using the symmetric encryption key ck: m=AES.Decck(AES.Encck(m)) to obtain the final plaintext data m.

Citation Information

Cited By

  • Attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations

    CN120956419A

  • Lattice-based puncturable key strategy attribute searchable encryption method and system

    CN121567393A