Data security sharing method based on proxy re-encryption and supporting bilateral access control

By introducing bilateral access control mechanism and ciphertext conversion function of cloud servers in the proxy re-encryption method, the problems of low data sharing efficiency and untrusted data sources in the prior art are solved, and efficient and secure data sharing is achieved.

CN120128384APending Publication Date: 2025-06-10JINAN UNIVERSITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510294779.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The proxy re-encryption method in the prior art lacks bilateral access control, and the matching encryption scheme lacks ciphertext proxy forwarding function, resulting in inefficient data sharing and untrusted data source.

Method used

The data security sharing method based on proxy re-encryption is adopted, combined with the bilateral access control mechanism, and the ciphertext conversion is performed through the cloud server as a proxy to ensure that both the data sender and the receiver meet the predefined identity conditions before the data exchange can be completed.

Benefits of technology

It realizes efficient ciphertext forwarding, ensures the authenticity and security of data sources, improves the efficiency and flexibility of data sharing, and prevents identity forgery and data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128384A_ABST
    Figure CN120128384A_ABST
Patent Text Reader

Abstract

The invention discloses a data security sharing method and device based on proxy re-encryption and supporting bilateral access control, computer equipment and a storable medium. Compared with a traditional proxy re-encryption technology, a bilateral access control mechanism is introduced for the first time, and the security and flexibility of data sharing are remarkably improved. Specifically, the method not only supports the data sender to authorize the receiver, but also endows the data receiver with the capability of specifying the sender identity, and data sharing can be completed only when the two parties meet the identity conditions specified by each other at the same time. The bidirectional verification mechanism effectively prevents a malicious sender from counterfeiting identity to spread false data, ensures that a receiver can only access data from a trusted sender, makes up for the deficiency of a traditional proxy re-encryption technology in the aspect of identity verification, realizes dual guarantee of privacy and authenticity in a data sharing process, and improves the data sharing efficiency. And a safer and more reliable solution is provided for a complex data sharing scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of privacy data sharing, and particularly relates to a data security sharing method, device, computer device, and storable medium based on proxy re-encryption and supporting bilateral access control. Background Art

[0002] In the context of the widespread application of distributed systems such as cloud computing, big data, and blockchain, data security sharing faces challenges such as centralized trust issues, low sharing efficiency, and lack of bilateral authentication. Although traditional encryption methods (such as identity-based encryption and attribute encryption) can protect the confidentiality of data, they usually cannot achieve data source authentication and bilateral access control. These methods only support one-way access control, that is, only verify whether the recipient has the decryption permission, while ignoring the authenticity of the sender's identity. This not only makes it difficult to guarantee the authenticity and credibility of the data, but also may lead to the spread of forged data or the problem of untrusted data sources. To solve these problems, Matchmaking Encryption (ME) technology has emerged. Matchmaking Encryption allows the sender and recipient to respectively specify access policies or attribute sets, and the data can only be decrypted when the policies and attributes of both parties match, thus achieving two-way fine-grained access control. However, existing matchmaking encryption schemes lack the function of proxy to forward ciphertext, resulting in low data sharing efficiency.

[0003] Proxy Re-Encryption (PRE) technology realizes decentralized, secure and efficient data sharing by allowing the data holder to authorize the proxy to perform data conversion without exposing the plaintext. However, the traditional proxy re-encryption access control mechanism only focuses on whether the recipient has the decryption permission, but ignores the authenticity of the sender's identity, which may lead to the spread of forged data or the problem of untrusted data sources. For example, in the medical field, an attacker may forge a doctor's identity to send incorrect medical records or prescriptions to patients, endangering the health of patients; in the financial system, malicious actors may pose as legitimate institutions to spread false transaction information, resulting in financial losses and market chaos. Therefore, combining proxy re-encryption with matchmaking encryption and introducing a bilateral access control mechanism, so that both the sender and recipient of the data need to meet predefined identity conditions to complete the data exchange, thus effectively preventing identity forgery, while ensuring data privacy and access permission control, ensuring the authenticity and security of the data source, has become an important development direction for future secure data sharing. Summary of the Invention

[0004] The main objective of the present invention is to overcome the drawbacks and deficiencies in the existing proxy re-encryption method, such as the lack of bilateral access control and the absence of ciphertext proxy forwarding function in the matching encryption scheme, and to provide a data security sharing method, device, computer equipment, and storage medium based on proxy re-encryption and supporting bilateral access control. The data security sharing method based on proxy re-encryption and supporting bilateral access control proposed by the present invention not only inherits the bidirectional fine-grained access control and data source authentication functions of matching encryption but also realizes efficient ciphertext forwarding through proxy re-encryption technology.

[0005] To achieve the above objective, the present invention adopts the following technical solutions:

[0006] In the first aspect, the present invention provides a data security sharing method based on proxy re-encryption and supporting bilateral access control, which is applied to an application system. The application system includes a key generation center (KGC) responsible for system initialization and user registration, a cloud server (CS) responsible for storing user ciphertexts and converting user original ciphertexts with re-encryption keys, a data sender A, and a data receiver B. Hereinafter, the key generation center is simply referred to as KGC, and the cloud server is simply referred to as CS. The data security sharing method includes the following steps:

[0007] S1. The KGC initializes the application system and generates the main key and public parameters of the application system, and the process is as follows:

[0008] S11. Generate multiplicative cyclic groups G and G with order q, T assuming that g is the generator of group G and h is an element in group G, generate a bilinear mapping e(,): G×G→G T , which means mapping two group elements from the multiplicative cyclic group G to a group element from group G T ;

[0009] S12. Select five secure hash functions: H 1 ( ): {0,1} * →G, H 2 ( ): G T →G, H 4 ( ): G T →{0,1} * H 5 (): G×G×{0,1} * →G, where H 1 () represents mapping any length string {0,1} composed of 0 or 1 * to an element in the multiplicative cyclic group G, H 2 () represents mapping an element in group G T to an element in group G, H 3() represents an arbitrary-length string {0, 1} composed of 0 or 1 * is mapped to an element in the integer group modulo q in, H 4 () represents mapping the elements in group G T to an arbitrary-length string {0, 1} composed of 0 or 1 * , H 5 () represents mapping the concatenation of two elements in group G and an arbitrary-length string {0, 1} composed of 0 or 1 * to an element in group G;

[0010] S13. Randomly select s and x from the integer group as the master key of the application system, and calculate g s , g x as the master public key of the application system;

[0011] S2. The data sender A sends a registration request to the KGC and obtains the secret key ek σ , and the process is as follows:

[0012] The data sender A sends its own identity σ to the KGC, and the KGC calculates the secret key ek σ = H 1 (σ) s , binds the system master key s to the identity σ of the data sender A, and sends ek σ to the data sender A through a secure channel;

[0013] S3. The data receiver B sends a registration request to the KGC and obtains the decryption key dk ρ , and the process is as follows:

[0014] The data receiver B sends its own identity ρ to the KGC, and the KGC calculates the decryption key dk ρ,1 = H 1 (ρ) x , dk ρ,2 = H 1 (ρ) s , binds the system master keys s and x to the identity ρ of the data receiver B respectively, and sends dk ρ = (dk ρ,1 , dk ρ,2 ) to the data receiver B;

[0015] S4. The data sender A encrypts the data m ∈ {0, 1} * it wants to share to obtain the ciphertext, and stores the ciphertext on the cloud server to save local storage space, and the process is as follows:

[0016] S41. The data sender A selects a random number to calculate the hash value r = H 3 (m||η), the first ciphertext C 1 = h r , the second ciphertext C 2 = g r , the third ciphertext The fourth ciphertext C 4 = H 5 (C 1 ||C 2 ||C 3 ), r The symbol "||" means concatenating strings, and the symbol means performing an exclusive OR operation on the string;

[0017] S42. The data sender A uploads the ciphertext C = (C 1 , C 2 , C 3 , C 4 ) to the cloud server;

[0018] S5. The data sender A selects the identity rcv of the data recipient, generates a re - encryption key rk to share the data with the user with the identity rcv, and sends the re - encryption key rk to the cloud server;

[0019] S6. The cloud server re - encrypts the ciphertext C using the re - encryption key rk and converts the ciphertext into a re - encrypted ciphertext C' that can be decrypted by the user with the identity rcv;

[0020] S7. The data recipient B and the data sender A mutually verify their identities. When both parties verify through the identities specified by each other, they proceed to the next step to perform the decryption operation;

[0021] S8. The data sender A downloads the original ciphertext C from the cloud server and decrypts it using its own key to recover the plaintext m. The specific process is as follows:

[0022] S81. The data sender A first checks the correctness of the original ciphertext C, checks whether it holds. If not, the application system interrupts the decryption operation; otherwise, it continues to the next step;

[0023] S82. Recover the plaintext and the random number

[0024]

[0025] Calculate the hash value r = H 3 (m||η);

[0026] S83. Check Whether it holds. If it holds, it indicates successful decryption and completes data security sharing; otherwise, decryption fails.

[0027] Further, the process of step S5 is as follows:

[0028] S51. The data sender A calculates the re-encryption key rk according to its own encryption key ek σ and the specified recipient identity rcv, selects a random number to calculate the first part of the re-encryption key rk 1 = g y , and the second part of the re-encryption key rk 2 = ek σ ·h y ·H 2 (e(g x , H 1 (rcv)) y )·H 2 (e(ek σ , H 1 (rcv))); Embed the data sender's encryption key ek σ in the re-encryption key, aiming to provide a convenient authentication mechanism for the data recipient to ensure the authenticity and credibility of the data source; at the same time, embed the specified recipient identity information rcv in the re-encryption key to achieve precise control of data access permissions and ensure that only recipients meeting predefined conditions can access the data; in this way, the present invention can effectively implement bilateral access control, which not only protects the privacy and security of the data but also improves the flexibility and efficiency of data sharing;

[0029] S52. The data sender A sends the re-encryption key rk = (rk 1 , rk 2 ) to the cloud server so that the cloud server encrypts the original ciphertext C of the data sender A and converts it into a ciphertext that the data recipient B can decrypt.

[0030] Further, the process of step S6 is as follows:

[0031] S61. Before calculating the re-encrypted ciphertext, the cloud server first verifies the correctness of the original ciphertext C = (C 1 , C 2 , C 3 , C 4 ): Check whether and hold. If not, the application system is interrupted; otherwise, proceed to the next step;

[0032] S62. The cloud server calculates the fifth ciphertext C 5 = rk1 = g y 、

[0033] The sixth ciphertext

[0034]

[0035] Then the re-encrypted ciphertext is C′ = (C 2 , C 3 , C 4 , C 6 ), where the ciphertext part C 2 is used to verify the correctness of decryption, the ciphertext part C 3 embeds the plaintext information for recovering the plaintext, the ciphertext part C 5 embeds a random number for bilinear pairing; the ciphertext part C 6 embeds the encryption key of the data sender and the identity of the data receiver for accurate matching of bilateral access control policies.

[0036] Furthermore, the process of step S7 is as follows:

[0037] S71. The data receiver B uses the decryption key dk ρ = (dk ρ,1 , dk ρ,2 ) and the specified sender identity snd for decryption. Decryption can be performed if and only if both parties meet the specified identities of each other, that is, when ρ = rcv and σ = snd, calculate

[0038]

[0039] Recover the plaintext and the random number Calculate the hash value r = H 3 (n||η);

[0040] S72. Verify whether the decryption is successful: Check Whether it holds. If it holds, it means the decryption is successful; otherwise, the decryption fails. If the data receiver B does not meet the identity specified by the data sender A, that is, ρ ≠ rcv; or the data sender A does not meet the identity specified by the data receiver B, that is, σ ≠ snd, then Q ≠ e(H 1 (σ) s , g r ), then the plaintext m and the random number η cannot be correctly recovered. At this time, the verification will fail.

[0041] Second aspect, the present invention provides a data security sharing device based on proxy re-encryption and supporting bilateral access control, which is used to execute the above-mentioned data security sharing method based on proxy re-encryption and supporting bilateral access control. The data security sharing device based on proxy re-encryption and supporting bilateral access control includes:

[0042] A KGC initialization module, which is used for the KGC to initialize the application system and generate the main key and public parameters of the application system;

[0043] A sender registration request module, which is used for the data sender A to initiate a registration request to the KGC and obtain the key ek σ ;

[0044] A receiver registration request module, which is used for the data receiver B to initiate a registration request to the KGC and obtain the decryption key dk ρ ;

[0045] A shared data encryption module, which is used for the data sender A to encrypt the data m ∈ {0, 1} * that it wants to share to obtain a ciphertext, and store the ciphertext on the cloud server;

[0046] A data sender processing module, which is used for the data sender A to select the identity rcv of the data receiver, generate a re-encryption key rk, so as to share the data with the user with the identity rcv, and send the re-encryption key rk to the cloud server;

[0047] A cloud server processing module, which is used for the cloud server to re-encrypt the ciphertext C using the re-encryption key rk and convert the ciphertext into a re-encrypted ciphertext C' that can be decrypted by the user with the identity rcv;

[0048] An identity authentication module, which is used for the data receiver B and the data sender A to mutually authenticate their identities. When both parties verify each other's specified identities, they transfer to the plaintext recovery module to perform the decryption operation;

[0049] A plaintext recovery module, which is used for the data sender A to download the original ciphertext C from the cloud server and decrypt it using its own key to recover the plaintext m.

[0050] Third aspect, the present invention provides a computer device, including a processor and a memory for storing the executable program of the processor. The characteristic is that when the processor executes the program stored in the memory, it implements the above-mentioned data security sharing method based on proxy re-encryption and supporting bilateral access control.

[0051] Fourth aspect, the present invention provides a storage medium, storing a program, which when executed by a processor, implements the above-mentioned data security sharing method based on proxy re-encryption and supporting bilateral access control.

[0052] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0053] (1) Compared with the existing identity-based matching encryption, the present invention introduces a cloud server as an agent, allowing the cloud server to perform ciphertext conversion without decrypting. When sharing data, the data sender only needs to generate a re-encryption key, without the need for complex decryption and re-encryption operations, greatly saving computational overhead and communication overhead, and improving data sharing efficiency.

[0054] (2) Compared with traditional proxy re-encryption technology, the present invention introduces an innovative bilateral access control mechanism. This mechanism not only gives the data sender the ability to finely control data access permissions, but also allows the data recipient to verify the legitimacy of the data source. Specifically, when generating the re-encryption key, the data sender embeds its own private key and the specified data recipient identity information. When decrypting, the data recipient must explicitly specify the identity of the data sender. Only when the identities of both the data sender and the recipient meet the predefined conditions can the data exchange be successfully completed. This two-way verification mechanism effectively prevents malicious senders from forging data, while ensuring the privacy and authenticity of the data, providing a high level of security for data sharing.

[0055] (3) While protecting data privacy, the present invention also comprehensively protects the identity information of data senders and recipients, truly realizing anonymous communication. In the ciphertext structure of the present invention, no identity information of any data sender or recipient is included. This means that any third party unable to decrypt cannot obtain any information about the data sender or recipient from the transmitted ciphertext. This design not only protects the privacy of the data content, but also further safeguards the identity privacy of both communication parties, providing users with extremely high security and privacy, so that they do not need to worry about the risk of identity leakage during the data sharing process. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0057] Figure 1 It is a design diagram of an application system for a privacy data sharing method based on proxy re-encryption and supporting bilateral access control disclosed in Embodiment 1 of the present invention;

[0058] Figure 2 It is a flowchart of a privacy data sharing method based on proxy re-encryption and supporting bilateral access control disclosed in Embodiment 1 of the present invention;

[0059] Figure 3 It is a schematic structural diagram of a privacy data sharing device for proxy re - encryption and supporting bilateral access control disclosed in Embodiment 2 of the present invention;

[0060] Figure 4 It is a structural diagram of an electronic device disclosed in Embodiment 3 of the present invention. Detailed implementation manners

[0061] In order to enable those skilled in the art of the present technology to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0062] Referring to "embodiment" in the present application means that the specific features, structures or characteristics described in combination with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described in the present application can be combined with other embodiments.

[0063] Embodiment 1

[0064] As Figure 1 shown, the privacy data sharing method based on proxy re - encryption and supporting bilateral access control proposed by the present invention is characterized in that it can not only ensure the authenticity and privacy of data simultaneously, but also achieve refined bilateral access control; in addition, the present invention combines proxy re - encryption technology to further support the function of proxy forwarding of ciphertext, thereby significantly improving the efficiency of data sharing. The present invention mainly involves four types of entities: a key generation center, a cloud server, a data sender, and a data receiver, and each entity performs the following operations:

[0065] Key Generation Center (KGC): It is completely trustworthy and is responsible for system initialization and user registration;

[0066] Cloud Server (CS): It is honest but curious and is responsible for storing the ciphertext of users and converting the original ciphertext of users with re - encryption keys;

[0067] Data Sender A: Such as a patient, needs to first register with the KGC to obtain an encryption key, and then upload the ciphertext of the data to be shared and the re - encryption key to the cloud server.

[0068] Data Receiver B: Such as a medical institution or a doctor, verifies the authenticity of the data source before receiving the data and only receives data from the specified sender.

[0069] Next, in conjunction with Figure 2 the specific process of the privacy data sharing method based on proxy re-encryption and supporting bilateral access control disclosed in this embodiment will be described in detail. The steps are as follows:

[0070] S1. The Key Generation Center (KGC) initializes the application system to generate the system master key and public parameters.

[0071] In a specific application, the initialization of the data sharing system by the Key Generation Center KGC mainly includes the following steps:

[0072] S11. Generate multiplicative cyclic groups G and G with order q. T Assume that g is the generator of group G and h is an element in group G, and generate a bilinear mapping e(,): G×G→G T , which means mapping two group elements from the multiplicative cyclic group G to a group element from group G T ;

[0073] S12. Select 5 secure hash functions: H 1 (): {0, 1} * →G, H 2 (): G T →G, H 4 (): G T →{0, 1} * H 5 (): G×G×{0, 1} * →G, where H 1 means mapping an arbitrary-length string composed of 0 or 1 to an element in the multiplicative cyclic group G, H 2 means mapping an element in group G T to an element in group G, H 3 means mapping an arbitrary-length string composed of 0 or 1 to an integer group modulo q, H 4 means mapping an element in group G T to an arbitrary-length string composed of 0 or 1, H 5 means mapping the concatenation of two elements in group G and an arbitrary-length string composed of 0 or 1 to an element in group G;

[0074] S13. Randomly select s and x from the integer group as the system master key, and calculate g s,g x As the system's public master key.

[0075] S2. The data sender A initiates a registration request to the KGC and obtains the encryption key ek σ .

[0076] In a specific application, the registration process of the data sender A is as follows:

[0077] The data sender A sends its own identity σ to the KGC, and the KGC calculates the key ek σ = H 1 (σ) s , and sends ek σ to A through a secure channel.

[0078] S3. The data receiver B initiates a registration request to the KGC and obtains the decryption key dk ρ .

[0079] In a specific application, the registration process of the data receiver B is as follows:

[0080] The data receiver B sends its own identity ρ to the KGC, and the KGC calculates the decryption key dk ρ,1 = H 1 (ρ) x , dk ρ,2 = H 1 (ρ) s , and sends dk ρ = (dk ρ,1 , dk ρ,2 ) to B through a secure channel.

[0081] S4. The data sender A encrypts the data m ∈ {0, 1} * it wants to share and stores the ciphertext on the cloud service to save local storage space.

[0082] In a specific application, the data encryption process of the data sender A is as follows:

[0083] S41. The data sender A selects a random number and calculates the hash value r = H 3 (m || η), the first ciphertext C 1 = h r , the second ciphertext C 2 = g r , the third ciphertext The fourth ciphertext C 4 = H 5 (C 1 || C 2 || C 3 ) r; The symbol "||" means to concatenate strings, and the symbol means to perform an exclusive OR operation on the string;

[0084] S42. The data sender A sends the ciphertext C = (C 1 , C 2 , C 3 , C 4 ) to the cloud server.

[0085] S5. The data sender A selects the identity rcv of the data recipient, generates a re-encryption key rk to share the data with the user with the identity rcv, and sends the re-encryption key rk to the cloud server.

[0086] In a specific application, the process of the data sender A generating the re-encryption key is as follows:

[0087] The data sender A calculates the re-encryption key rk = (rk σ , rk 1 ) according to its own encryption key ek 2 and the specified recipient identity rcv. Specifically, a random number is selected to calculate the first part of the re-encryption key rk 1 = g y , and the second part of the re-encryption key rk 2 = ek σ ·h y ·H 2 (e(g x , H 1 (rcv)) y )·H 2 (e(ek σ , H 1 (rcv))).

[0088] S6. The cloud server re-encrypts the ciphertext C using rk and converts the ciphertext into a re-encrypted ciphertext C' that can be decrypted by the user with the identity rcv.

[0089] In a specific application, the process of the cloud server re-encrypting is as follows:

[0090] S61. The cloud server first verifies the correctness of the original ciphertext. Check whether it holds. If it does not hold, the system is interrupted; otherwise, continue to the next step;

[0091] S62. The cloud server calculates the fifth ciphertext C 5 = rk 1 = g y ,

[0092] The sixth ciphertext

[0093]

[0094] Then the re-encrypted ciphertext is C′=(C 2 , C 3 , C 5 , C 6 ).

[0095] S7. The data receiver B verifies the identity of the data sender A. Only when both parties meet the identities specified by each other can the decryption be performed.

[0096] In a specific application, the decryption process of the data receiver B is as follows:

[0097] S71. The data receiver B uses the decryption key dk ρ =(dk ρ,1 , dk ρ,2 ) and the specified sender identity snd for decryption. Only when both parties meet the identities specified by each other can the decryption be performed, that is, when ρ = rcv and σ = snd, calculate

[0098] Recover the plaintext and the random number Calculate the hash value r = H 3 (m||η).

[0099] S72. Check Whether it holds. If it holds, it means the decryption is successful and the data security sharing is completed; otherwise, the decryption fails. Only when ρ = rcv and σ = snd can the decryption be successful; if ρ ≠ rcv or σ = snd, the decryption must fail.

[0100] S8. When the data sender A wants to recover the data, download the original ciphertext C from the cloud server and decrypt it using its own key to recover the plaintext m.

[0101] In a specific application, the decryption process of the data sender A is as follows:

[0102] S81. The data sender A first checks the correctness of the original ciphertext C and verifies Whether it holds. If it does not hold, the system is interrupted; otherwise, proceed to the next step;

[0103] S82. Recover the plaintext and the random number

[0104]

[0105] Calculate the hash value r = H 3 (m||η).

[0106] S83. Check Whether it holds. If it holds, it indicates successful decryption; otherwise, decryption fails.

[0107] To more clearly demonstrate the innovation and practicality of the present invention, the present embodiment will be compared and analyzed in detail with the literature [1-4] from two key dimensions: function richness and operation efficiency.

[0108] The source of the literature [1] is specifically: Yan Z, Qu H, Zhang X, et al. Identity-based proxy matchmaking encryption for cloud-based anonymous messaging systems[J]. Journal of Systems Architecture, 2023, 142: 102950.

[0109] The source of the literature [2] is specifically: Chen J, Li Y, Wen J, et al. Identity-based matchmaking encryption from standard assumptions[C] / / International Conference on the Theory and Application of Cryptology and Information Security. Cham: Springer Nature Switzerland, 2022: 394-422.

[0110] The source of the literature [3] is specifically: Chen B, Xiang T, Ma M, et al. CL-ME: Efficient certificateless matchmaking encryption for Internet of Things[J]. IEEE Internet of Things Journal, 2021, 8(19): 15010-15023.

[0111] The source of the literature [4] is specifically: Shao J. Anonymous ID-based proxy re-encryption[C] / / Australasian Conference on Information Security and Privacy. Berlin, Heidelberg: Springer Berlin Heidelberg, 2012: 364-375.

[0112] In terms of functionality, the comparison results between this embodiment and the literature [1-4] are shown in Table 1. Among them, Fun1 represents data confidentiality; Fun2 represents data source authentication; Fun3 represents anonymity; Fun4 represents bilateral access control; Fun5 represents ciphertext proxyability. It can be seen from Table 1 that the literature [1-3] fails to achieve the ciphertext proxyability function. In these schemes, when the data owner shares data, multiple encryption operations need to be performed on the data. This not only leads to a significant increase in computational overhead but also greatly reduces the efficiency of data sharing. Although the literature [4] successfully realizes ciphertext proxyability, enabling the data owner to only generate proxy re-encryption keys when sharing data and delegate complex encryption operations to the proxy server, thus effectively saving computational resources and improving the data sharing efficiency, this scheme has obvious defects: it fails to achieve data source authentication and bilateral access control functions, which makes the data vulnerable to forgery or abuse during the sharing process, thus threatening the security and authenticity of the data.

[0113] In contrast, the present invention has achieved a major breakthrough in both security and efficiency. It can not only ensure data confidentiality, data source authentication, anonymity, and bilateral access control, thus comprehensively protecting the privacy and authenticity of the data, but also successfully realizes the ciphertext proxyability function, further improving the efficiency of data sharing. Therefore, the present invention has significant advantages in terms of functionality richness and practicality and can better meet the security and efficiency requirements in the data sharing scenario.

[0114] Table 1. Functional comparison between the present invention and related schemes

[0115] Solution Fun1 Fun2 Fun3 Fun4 Fun5 Document [1] √ √ √ √ × Document [2] √ √ √ √ × Document [3] √ √ √ √ × Document [4] √ × √ × √ The present invention √ √ √ √ √

[0116] In terms of efficiency, the comparison results between this embodiment and the literature [1-4] are shown in Table 2. Among them, h represents the hash operation mapping to group elements, e represents the exponentiation operation, p represents the bilinear pairing operation, and m represents the multiplication operation between group elements. Generally, the hash operation mapping to group elements and the bilinear pairing operation take a long time, much higher than the exponentiation operation and the multiplication operation. It can be analyzed from Table 2 that the computational overhead of each stage in the literature [3] is the largest; the computational overhead of each stage in the literature [2] is the smallest, but the literature [2] does not have the function of ciphertext proxy, which to a certain extent limits its applicability and flexibility in practical applications. In the encryption key and decryption key generation stages of the present invention, the computational overhead is close to that of the literature [1] and [4]; in the encryption stage, the computational overhead is lower than that of the literature [1] and [3], and is close to that of the literature [4]; in the decryption stage, although the computational overhead of the present invention is slightly higher than that of other literatures, it is still lower than that of the literature [3], and the functions of data source authentication and ciphertext proxy are realized, which are not available in other literatures. Generally speaking, while maintaining high computational performance, the present invention significantly enriches the functions, realizes the dual optimization of data security and sharing efficiency, and provides a more comprehensive and reliable solution for practical applications.

[0117] Table 2. Efficiency Comparison between the Present Invention and Related Schemes

[0118]

[0119] Embodiment 2

[0120] As Figure 3 shown, this embodiment provides a data security sharing device based on proxy re-encryption and supporting bilateral access control. The data security sharing device includes: a KGC initialization module 301, a sender registration request module 302, a receiver registration request module 303, a shared data encryption module 304, a data sender processing module 305, a cloud server processing module 306, an identity authentication module 307, and a plaintext recovery module 308. The specific functions of each module are as follows:

[0121] The KGC initialization module 301 is used to initialize the application system by the KGC, and generate the main key and public parameters of the application system;

[0122] The sender registration request module 302 is used for the data sender A to initiate a registration request to the KGC to obtain the key ek σ ;

[0123] The receiver registration request module 303 is used for the data receiver B to initiate a registration request to the KGC to obtain the decryption key dk ρ ;

[0124] The shared data encryption module 304 is used for the data sender A to share its own data m ∈ {0, 1}* The ciphertext is obtained through encryption and stored on the cloud server;

[0125] The data sender processing module 305 is used for data sender A to select the identity rcv of the data receiver, generate the re-encryption key rk, so as to share the data with the user with the identity rcv, and send the re-encryption key rk to the cloud server;

[0126] The cloud server processing module 306 is used for the cloud server to re-encrypt the ciphertext C by using the re-encryption key rk, and convert the ciphertext into a re-encrypted ciphertext C' that can be decrypted by the user with the identity rcv;

[0127] The identity authentication module 307 is used for data receiver B and data sender A to mutually authenticate their identities. When both parties verify and pass the identities specified by each other, it transfers to the plaintext recovery module to perform the decryption operation;

[0128] The plaintext recovery module 308 is used for data sender A to download the original ciphertext C from the cloud server and decrypt it by using its own key to recover the plaintext m.

[0129] Embodiment 3

[0130] This embodiment provides a computer device, which can be a computer. As Figure 4 shown, it includes a processor 402, a memory, an input device 403, a display 404, and a network interface 405 connected through a system bus 401. The processor is used to provide computing and control capabilities. The memory includes a non-volatile storage medium 406 and an internal memory 407. The non-volatile storage medium 406 stores an operating system, a computer program, and a database. The internal memory 407 provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. When the processor 402 executes the computer program stored in the memory, it implements a data security sharing method based on proxy re-encryption and supporting bilateral access control proposed in Embodiment 1 above. The data security sharing method based on proxy re-encryption and supporting bilateral access control includes the following steps:

[0131] S1. The KGC initializes the application system and generates the application system master key and public parameters;

[0132] S2. Data sender A sends a registration request to the KGC and obtains the key ek σ ;

[0133] S3. Data receiver B sends a registration request to the KGC and obtains the decryption key dk ρ ;

[0134] S4. Data sender A shares its own data m ∈ {0, 1} *Encrypt to obtain ciphertext and store the ciphertext on the cloud server to save local storage space;

[0135] S5. The data sender A selects the identity rcv of the data receiver, generates a re-encryption key rk to share the data with the user with the identity rcv, and sends the re-encryption key rk to the cloud server;

[0136] S6. The cloud server re-encrypts the ciphertext C using the re-encryption key rk and converts the ciphertext into a re-encrypted ciphertext C' that can be decrypted by the user with the identity rcv;

[0137] S7. The data receiver B and the data sender A mutually verify their identities. When both parties verify the identities specified by each other, they proceed to the next step to perform the decryption operation;

[0138] S8. The data sender A downloads the original ciphertext C from the cloud server and decrypts it using its own key to recover the plaintext m.

[0139] Embodiment 4

[0140] This embodiment provides a storage medium, which is a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements a data security sharing method based on proxy re-encryption and supporting bilateral access control proposed in Embodiment 1 above. The data security sharing method based on proxy re-encryption and supporting bilateral access control includes the following steps:

[0141] S1. The KGC initializes the application system, generates the main key and public parameters of the application system;

[0142] S2. The data sender A sends a registration request to the KGC and obtains the key ek σ ;

[0143] S3. The data receiver B sends a registration request to the KGC and obtains the decryption key dk ρ ;

[0144] S4. The data sender A encrypts the data m ∈ {0, 1} * that it wants to share to obtain ciphertext and stores the ciphertext on the cloud server to save local storage space;

[0145] S5. The data sender A selects the identity rcv of the data receiver, generates a re-encryption key rk to share the data with the user with the identity rcv, and sends the re-encryption key rk to the cloud server;

[0146] S6. The cloud server re-encrypts the ciphertext C using the re-encryption key rk and converts the ciphertext into a re-encrypted ciphertext C' that can be decrypted by the user with the identity rcv;

[0147] S7. The data receiver B and the data sender A mutually verify each other's identities. When both parties verify the identities specified by each other, they proceed to the next step to perform the decryption operation.

[0148] S8. The data sender A downloads the original ciphertext C from the cloud server and decrypts it using its own key to recover the plaintext m.

[0149] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0150] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

Claims

1. A data security sharing method based on proxy re-encryption and supporting bilateral access control is applied to an application system, which includes a key generation center responsible for system initialization and user registration, a cloud server responsible for storing user ciphertexts and converting user original ciphertexts with re-encryption keys, a data sender A and a data receiver B. The key generation center is referred to as KGC and the cloud server is referred to as CS. The method is characterized in that: The data security sharing method comprises the following steps: S1. KGC initializes the application system and generates the application system master key and public parameters. The process is as follows: S11. Generate multiplicative cyclic groups G and G of order q T , assuming that g is a generator of the group G and h is an element of the group G, generate a bilinear map e(,): G×G→G T , which means mapping two group elements from the multiplicative cyclic group G to a group from the group G through a bilinear pairing operation T The group elements of S12. Select 5 secure hash functions: H1( ): {0,1} * →G, H2( ):G T →G, H4( ): G T →{0,1} * , H5( ): G×G×{0,1} * →G, where H1() represents a string of any length {0,1} consisting of 0 or 1. * Mapped to the elements of the multiplication cyclic group G, H2( ) represents the group G T The elements in are mapped to the elements in group G, and H3( ) represents a string of any length {0,1} consisting of 0 or 1. * Mapping to the group of integers modulo q The elements in H 4() Indicates that group G T The elements in are mapped to strings of any length consisting of 0 or 1 {0, 1} * , H 5() It means to convert two elements in group G into a string of any length consisting of 0 or 1 {0,1} * The concatenation map of is an element in the group G; S13. From the integer group Randomly select s and x as the master key of the application system and calculate g respectively. s , g x As the master public key of the application system; S2. Data sender A initiates a registration request to KGC and obtains the key ek σ , the process is as follows: Data sender A sends his identity σ to KGC, and KGC calculates the key ek for data sender A σ =H1(σ) s , and ek σ Send to data sender A through a secure channel; S3. Data recipient B initiates a registration request to KGC and obtains the decryption key dk ρ , the process is as follows: Data receiver B sends his identity to KGC, and KGC calculates the decryption key dk for data receiver B. ρ,1 =H1(ρ) x ,dk ρ,2 =H1(ρ) s , and dk ρ =(dp ρ,1 ,dk ρ,2 ) is sent to data recipient B; S4, data sender A sends the data m∈{0, 1} to be shared * Encrypt the ciphertext and store it on the cloud server to save local storage space. The process is as follows: S41. Data sender A selects a random number Calculate the hash value r = H3 (m||η), the first ciphertext C1 = h r , the second ciphertext C2 = g r , the third ciphertext The fourth ciphertext C4=H5(C1||C2||C3) r , the symbol "||" means to concatenate the strings, the symbol Indicates an XOR operation on a string; S42, data sender A uploads the ciphertext C=(C1, C2, C3, C4) to the cloud server; S5. The data sender A selects the identity of the data receiver rcv, generates a re-encryption key rk, so as to share the data with the user with the identity rcv, and sends the re-encryption key rk to the cloud server; S6. The cloud server re-encrypts the ciphertext C using the re-encryption key rk, and converts the ciphertext into a re-encrypted ciphertext C′ that can be decrypted by the user with the identity rcv; S7, the data receiver B and the data sender A verify each other's identities. When both parties verify each other's designated identities, they proceed to the next step to perform the decryption operation; S8. Data sender A downloads the original ciphertext C from the cloud server and decrypts it using its own key to restore the plaintext m. The specific process is as follows: S81, data sender A first checks the correctness of the original ciphertext C, and then checks Is it true? If not, the application system interrupts the decryption operation; otherwise, proceed to the next step; S82, restore plaintext and random numbers Calculate the hash value r = H3(m||η); S83, Inspection Is it true? If so, it means that the decryption is successful and data security sharing is completed; otherwise, the decryption fails.

2. The data security sharing method based on proxy re-encryption and supporting bilateral access control according to claim 1 is characterized in that: The process of step S5 is as follows: S51, data sender A uses its own encryption key ek σ Calculate the re-encryption key rk with the specified recipient identity rcv and select a random number Calculate the first part of the re-encryption key rk1=g y , and the second part of the re-encryption key rk2 = ek σ h y ·H2(e(g x ,H1(rcv)) y )·H2(e(ek σ , rH1(rcv))); S52. Data transmission A sends the re-encryption key rk=(rk1, rk2) to the cloud server.

3. The data security sharing method based on proxy re-encryption and supporting bilateral access control according to claim 2 is characterized in that: The process of step S6 is as follows: S61, the cloud server first verifies the correctness of the original ciphertext: Check and Is it established? If not, the application system is interrupted; otherwise, proceed to the next step; S62, the cloud server calculates the fifth ciphertext C5=rk1=g y , The Sixth Cipher The re-encrypted ciphertext is C′=(C2, C3, C5, C6).

4. The data security sharing method based on proxy re-encryption and supporting bilateral access control according to claim 1 is characterized in that: The process of step S7 is as follows: S71, data recipient B uses decryption key dk ρ =(dk ρ,1 ,dk ρ,2 ) and the specified sender identity snd for decryption. Decryption can only be performed if and only if both parties meet the identities specified by each other, that is, ρ=rcv, σ=snd. Recover plaintext and random numbers Calculate the hash value r = H3(m||η); S72, Inspection Is it true? If so, it means the decryption is successful; otherwise, the decryption fails.

5. A data security sharing device based on proxy re-encryption and supporting bilateral access control, used to execute the data security sharing method based on proxy re-encryption and supporting bilateral access control as described in any one of claims 1 to 4, characterized in that: The data security sharing device based on proxy re-encryption and supporting bilateral access control includes: KGC initialization module, used for KGC initialization application system, generating application system master key and public parameters; The sender registration request module is used by the data sender A to initiate a registration request to KGC and obtain the key ek σ ; The receiver registration request module is used by the data receiver B to initiate a registration request to KGC and obtain the decryption key dk ρ ; The shared data encryption module is used by the data sender A to encrypt the data m∈{0, 1} to be shared. * Encrypt to obtain ciphertext, and store the ciphertext on the cloud server; The data sender processing module is used for the data sender A to select the identity of the data receiver rcv, generate the re-encryption key tk, so as to share the data with the user with the identity rcv, and send the re-encryption key rk to the cloud server; A cloud server processing module, used for the cloud server to re-encrypt the ciphertext C using the re-encryption key rk, and convert the ciphertext into a re-encrypted ciphertext C′ that can be decrypted by the user with the identity rcv; The identity authentication module is used for the data receiver B and the data sender A to verify the identities of each other. When both parties have verified the identities specified by each other, they will enter the plaintext recovery module to perform decryption operations; The plaintext recovery module is used by the data sender A to download the original ciphertext C from the cloud server and decrypt it using its own key to recover the plaintext m.

6. A computer device comprising a processor and a memory for storing a program executable by the processor, characterized in that: When the processor executes the program stored in the memory, it implements the data security sharing method based on proxy re-encryption and supporting bilateral access control as described in any one of claims 1 to 4.

7. A storage medium storing a program, characterized in that: When the program is executed by a processor, the data security sharing method based on proxy re-encryption and supporting bilateral access control as described in any one of claims 1 to 4 is implemented.

Citation Information

Cited By

  • Cloud chain collaborative medical data security sharing method based on PRE

    CN121907492A