Encryption method, system and device for constructing switchable attributes based on LWE hypothesis and medium
Through the switchable attribute encryption method based on the LWE assumption, the shortcomings of user management and permission changes in the prior art are solved, and the flexibility and security of user dynamic management and data encryption are realized.
Patent Information
- Application Number
- CN202411403941.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-09
- Publication Date
- 2025-06-20
AI Technical Summary
Existing attribute encryption schemes cannot quickly implement user addition and revocation, and cannot meet changes in user permissions or changes in business needs.
Based on the LWE assumption, we build a encryption method with switchable attributes, generate public keys, public parameters and create master keys through the trap gate generator and sampling random matrix, build each user's own private key, and obtain the conversion key to achieve dynamic management of user permissions and flexibility in data encryption.
It realizes dynamic addition and revocation of users, supports rapid changes in user permissions, improves the security and flexibility of data sharing, and meets changes in business needs.
Smart Images

Figure CN120185845A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and relates to an encryption method, system, device and medium for constructing switchable attributes based on the LWE assumption. Background Art
[0002] As a major innovation in the field of information technology, cloud computing technology has become an important pillar of modern data processing and storage. Cloud computing has scalability and powerful data storage and processing capabilities, and also has significant advantages in terms of security and reliability, mainly including data encryption, access control and disaster recovery. However, data privacy and security are still important challenges faced by cloud computing, especially when outsourcing sensitive data to the cloud.
[0003] Traditional encryption schemes (such as AES or public key encryption) only grant the decryption right to the user with the corresponding key, and cannot effectively handle the scenario of sharing data among a large number of users. The proposed attribute-based encryption (ABE) solves this problem. By defining an access policy based on user attributes, it allows the data owner to flexibly control which users can access the encrypted data without knowing the keys of all legitimate users in advance. This greatly enhances the flexibility and security of data sharing. However, existing attribute-based encryption schemes still have some deficiencies in dealing with user dynamic management. For example, it is impossible to quickly add and revoke users, especially when a user wants to grant the decryption right to other users, it is impossible to implement the change of user permissions or the change of business requirements. Summary of the Invention
[0004] The purpose of the present invention is to solve the problem that the existing attribute-based encryption scheme cannot quickly add and revoke users and cannot meet the change of user permissions or the change of business requirements, and provide an encryption method, system, device and medium for constructing switchable attributes based on the LWE assumption.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions:
[0006] An encryption method for constructing switchable attributes based on the LWE assumption, including:
[0007] Set the basic architecture and security parameters of the system, and generate a public key, public parameters and create a master key through a trapdoor generator and a sampling random matrix;
[0008] Construct the private key of each user based on the master key and the attribute function of the user itself;
[0009] Obtain the conversion key based on the public key, the private key of the user itself, the attribute set corresponding to the user itself, and the generation matrix in the public parameters;
[0010] Encrypt the plaintext message under a given set of attributes to obtain the encrypted ciphertext;
[0011] When the set of attributes of the ciphertext does not match the access policy, convert the ciphertext from one set of attributes to another based on the conversion key so that the new ciphertext can match the new access policy;
[0012] Restore the encrypted data to plaintext based on the user's private key and the corresponding set of attributes to complete the decryption of the data.
[0013] A further improvement of the present invention lies in:
[0014] Furthermore, set the basic architecture and security parameters of the system, and generate the public key, public parameters and create the master key through the trapdoor generator and the sampling random matrix, specifically:
[0015] Set the security parameter λ, and generate the trapdoor information T based on the generation trapdoor generator TrapGen(1 n , m, q), where A is a matrix; A where A is a matrix;
[0016] Sample a uniformly random matrix represents the set of integers modulo q; sample uniformly random matrices
[0017] Based on the uniformly random matrix trapdoor information T A the uniformly random matrix and uniformly random matrices Output the public key the public parameters and the master key msk = (T A ); where is a B-bounded error distribution;
[0018] where TrapGen is the trapdoor generation algorithm, 1 n is the input security parameter, where n is a positive integer used to determine the security level; m represents the length or size of the message; in the trapdoor generator, q usually represents a prime number for modular arithmetic, which determines that all elements of the matrix and vector will be restricted to the set of integers modulo q; n, m, q, k are the dimensions and moduli of the matrix; σ is the standard deviation; is the error distribution; bounded means that in the encryption scheme, the range of the error value is restricted, indicating that the generated error value will not exceed a certain specific limit. Based on the LWE assumption, the security in the encryption process is controlled by ensuring the boundedness of the noise.
[0019] Furthermore, based on the master key and the user's own attribute function, the private key of each user is constructed as follows:
[0020] Based on the input master key msk and the function Calculate the matrix
[0021] Calculate the low-norm matrix Through matrix calculation to satisfy (A|B f )R f = U;
[0022] Run R f ←SampleLeft(A,B f ,T A ,U,σ) to generate the key conversion matrix and output the key sk f =(R f );
[0023] where f is the function defining the user attributes; B f is calculated from the matrix in the public key and the function f, and is used for encryption and decryption. R f is the low-norm matrix for decryption; the SampleLeft algorithm generates the matrix R f that satisfies specific conditions to ensure the equality required in the decryption process.
[0024] Furthermore, based on the public key, the user's own private key, the attribute set corresponding to the user itself, and the generation matrix in the public parameters, the conversion key is obtained as follows:
[0025] Input the public key pk, the private key sk f and the attribute set corresponding to the user itself and sample three matrices where is the error distribution;
[0026] Link the matrix A with the public key pk, the attribute set y corresponding to the user itself, and the generation matrix G in the public parameters to obtain the matrix
[0027] Based on the matrix H y , the matrix E0, the matrix E1, the matrix E2, and the private key sk f Calculate the conversion key
[0028]
[0029] where sk f is the private key, which contains the low-norm matrix R f, y is an attribute set, a new attribute vector for updating the secret key; E0, E1, E2 are randomly sampled matrices for generating the transformation key; G is the generating matrix in the public parameters; swk y is the transformation key.
[0030] Furthermore, encrypt the plaintext message under the given attribute set to obtain the encrypted ciphertext, specifically:
[0031] Input the public key pk, the message μ ∈ {0, 1} k , the attribute set and randomly select a vector
[0032] Select two error vectors Select matrices S i ∈ {±1} m×m ;
[0033] Based on the attribute set the generating matrix G in the public parameters, the matrix in the public key pk and the matrix A, obtain the matrix
[0034] Based on the matrix S i ∈ {±1} m×m , the error vector and the identity matrix I m , obtain the error vector
[0035] Based on the matrix H, the error vector e, the error vector e1, the vector and the message μ ∈ {0, 1} k , obtain H T s + e,
[0036] Output the ciphertext and the attribute set x;
[0037] where μ is the encrypted message, a bit string of length k; x is the attribute set, the attribute vector for encryption; S i is the randomly selected matrix for calculating the error vector; B i is the matrix in the public key.
[0038] Furthermore, when the attribute set of the ciphertext does not match the access policy, based on the transformation key, convert the ciphertext from one attribute set to another so that the new ciphertext can match the new access policy, specifically:
[0039] Input the transformation key swk yAnd the ciphertext CT, and parse the transformation key
[0040] Parse the ciphertext where c in = A T s + e0,
[0041] If f(x) = 1, output ⊥, otherwise continue with the following steps;
[0042] Calculate
[0043] Calculate the new ciphertext
[0044] Output the new transformation key CT' and the updated attribute set y;
[0045] where E0, E1, E2 are randomly sampled matrices for generating the transformation key; H y is a matrix calculated through the attribute set y, which contains the system matrix A, the attribute-related matrix B i and the matrix G in the public key; PowerT q (R f ) is a special transformation on the matrix R f ; is a all-zero matrix for maintaining the matrix structure; c in is a partial ciphertext, where A is the public key matrix, s is a randomly selected vector, and e0 is a noise vector; c i is a partial ciphertext, where B i is the matrix in the public key, x i is an element in the attribute vector, and G is the system parameter matrix; S i is a randomly selected matrix; e0 is a noise vector; c out is the last part of the ciphertext, where U is the matrix in the public key, e1 is another noise vector, and μ is the message; Eval ct is the evaluation function, which combines the attributes and the corresponding ciphertext parts and generates a new ciphertext component; BitD q is the bit decomposition operation, which is converted into a bit representation; cf is the result after function evaluation on the attribute-related part in the original ciphertext CT, reflecting the relationship between the original attributes and the access policy; f represents the access policy function, x is the attribute set associated with the original ciphertext CT, and f(x) = 1 means that the attribute set x satisfies the access policy f.
[0046] Furthermore, based on the user's private key and the corresponding attribute set, restore the encrypted data to plaintext, specifically:
[0047] Input the private key sk f and the ciphertext CT; Parse the input ciphertext where c in = A T s + e0,
[0048] Judge if f(x) = 1, output ⊥, otherwise continue with the following steps;
[0049] Calculate Calculate the new ciphertext Output the message
[0050] where s is a randomly selected vector for the encryption process; S i is a randomly selected matrix for noise generation in the encryption process; U is a uniformly randomly sampled matrix and belongs to the public key; The rounding operation is used to extract the message from the calculation result.
[0051] Construct a switchable attribute encryption system based on the LWE assumption, including:
[0052] A generation module that sets the basic architecture and security parameters of the system, and generates the public key, common parameters, and creates the master key through a trapdoor generator and a sampled random matrix;
[0053] A construction module that constructs each user's own private key based on the master key and the user's own attribute function;
[0054] An acquisition module that acquires the conversion key based on the public key, the user's own private key, the attribute set corresponding to the user, and the generation matrix in the common parameters;
[0055] An encryption module that encrypts the plaintext message under the given attribute set to obtain the encrypted ciphertext;
[0056] A conversion module that, when the attribute set of the ciphertext does not match the access policy, converts the ciphertext from one attribute set to another based on the conversion key so that the new ciphertext can match the new access policy;
[0057] A decryption module that restores the encrypted data to plaintext based on the user's private key and the corresponding attribute set to complete the decryption of the data.
[0058] A terminal device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the above method.
[0059] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0060] Compared with the prior art, the present invention has the following beneficial effects:
[0061] In the present invention, a public key, public parameters are generated through a trapdoor generator and a sampling random matrix, and a master key is created, and then a private key for each user is constructed; based on the public key, the user's own private key, the attribute set corresponding to the user, and the generation matrix in the public parameters, a conversion key is obtained; the encrypted ciphertext is converted from one attribute set to another through the conversion key, so that the new ciphertext can match the new access policy. Based on the LWE assumption, through the design of switchable attributes, users can quickly switch decryption permissions between different attribute sets without regenerating all keys; the present invention can support the dynamic addition and revocation of users, solving the deficiencies of existing attribute encryption technologies in user management; at the same time, based on the attribute-based access control policy, the data owner can define complex access conditions to ensure that only users meeting specific attributes can decrypt the data, improving the security and flexibility of data sharing. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required to be used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0063] Figure 1 It is a schematic flowchart of an encryption method for constructing switchable attributes based on the LWE assumption of the present invention;
[0064] Figure 2 It is a schematic structural diagram of an encryption system for constructing switchable attributes based on the LWE assumption of the present invention;
[0065] Figure 3 It is another flowchart of an encryption method for constructing switchable attributes based on the LWE assumption of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0066] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.
[0067] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0068] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0069] In the description of the embodiments of the present invention, it should be noted that if terms such as "upper", "lower", "horizontal", "inner", etc. are used to indicate the orientation or positional relationship, it is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the invention product is usually placed during use. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. In addition, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0070] In addition, if the term "horizontal" appears, it does not mean that the component is required to be absolutely horizontal, but it can be slightly inclined. For example, "horizontal" only means that its direction is more horizontal relative to "vertical", and does not mean that the structure must be completely horizontal, but it can be slightly inclined.
[0071] In the description of the embodiments of the present invention, it should also be noted that unless otherwise clearly specified and limited, if terms such as "set", "installed", "connected", "connected" are used, they should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0072] The following further describes the present invention in detail with reference to the accompanying drawings:
[0073] See Figure 1 , the present invention discloses an encryption method for constructing switchable attributes based on the LWE assumption, including:
[0074] S101: Set the basic architecture and security parameters of the system, generate a public key, common parameters and create a master key through a trapdoor generator and a sampling random matrix;
[0075] Set the security parameter λ, and generate the trapdoor information T based on the generated trapdoor generator TrapGen(1 n , m, q), where A is a matrix; A
[0076] Sample a uniformly random matrix denotes the set of integers modulo q; sample uniformly random matrices
[0077] Based on the uniformly random matrix trapdoor information T A , the uniformly random matrix and uniformly random matrices Output the public key Public parameters and the master secret key msk = (T A ); where is a B-bounded error distribution;
[0078] Among them, TrapGen is the trapdoor generation algorithm, 1 n is the input security parameter, where n is a positive integer used to determine the security level; m represents the length or size of the message; in the trapdoor generator, q usually represents a prime number for modular arithmetic, which determines that all elements of the matrices and vectors will be restricted to the set of integers modulo q; n, m, q, k are the dimensions and moduli of the matrices; σ is the standard deviation; is the error distribution. The security parameter is mainly used to define the security of the encryption system, affect the size and structure of the generated keys and other parameters, ensure the anti-attack ability, specifically determine the dimensions, randomness, and noise distribution of the matrices, thus affecting the difficulty of the LWE problem, and is not explicitly used. Among them, bounded means that in the encryption scheme, the range of the error (noise) value is restricted, indicating that the generated error value will not exceed a certain specific limit. Based on the LWE assumption, the present invention controls the security in the encryption process by ensuring the boundedness of the noise.
[0079] S102: Based on the master secret key and the user's own attribute function, construct the private key of each user;
[0080] Based on the input master secret key msk and the function calculate the matrix
[0081] Calculate the low-norm matrix By matrix calculation to satisfy (A|B f )R f = U;
[0082] Run R f ←SampleLeft(A,B f ,T A ,U,σ) to generate a key conversion matrix and output the secret key sk f =(R f );
[0083] Among them, f is a function defining user attributes; B f is calculated from the matrix in the public key and the function f, and is used for encryption and decryption. R f is a low-norm matrix and is used for decryption; The SampleLeft algorithm generates a matrix R f that satisfies specific conditions to ensure that the equations required in the decryption process hold.
[0084] S103: Based on the public key, the user's own private key, the attribute set corresponding to the user himself, and the generation matrix in the public parameters, obtain the conversion key;
[0085] Input the public key pk, the private key s k f and the attribute set corresponding to the user himself and sample three matrices Among them is the error distribution;
[0086] Link the matrix A with the public key pk, the attribute set y corresponding to the user himself, and the generation matrix G in the public parameters to obtain the matrix
[0087] Based on the matrix H y , the matrix E0, the matrix E1, the matrix E2, and the private key sk f calculate the conversion key
[0088]
[0089] Among them, sk f is the private key and contains the low-norm matrix R f , y is the attribute set, the new attribute vector, and is used to update the key; E0, E1, E2 are randomly sampled matrices and are used to generate the conversion key; G is the generation matrix in the public parameters; swk y is the conversion key.
[0090] S104: Encrypt the plaintext message under the given attribute set to obtain the encrypted ciphertext;
[0091] Input the public key pk, the message μ∈{0,1} k , the attribute set and randomly select a vector
[0092] Select two error vectors Select matrix S i ∈ {±1} m×m ;
[0093] Based on the attribute set the generating matrix G in the common parameters, the matrix in the public key pk and matrix A, obtain matrix
[0094] Based on matrix S i ∈ {±1} m×m error vector and the identity matrix I m , obtain error vector
[0095] Based on matrix H, error vector e, error vector e1, vector and message μ ∈ {0,1} k , obtain H T s + e,
[0096] Output the ciphertext and the attribute set x;
[0097] where μ is the encrypted message, a bit string of length k; x is the attribute set, the attribute vector for encryption; S i is a randomly selected matrix for calculating the error vector; B i is the matrix in the public key. In this scheme, the attribute set X is the attribute space of the entire system, defining all possible attributes. During the encryption process, the message is associated with a specific attribute set x ∈ X. And the attribute set y is a specific attribute set used in the SwitchKeyGen function for generating the switching key, allowing the ciphertext encrypted under the attribute set x to be converted to the ciphertext under the attribute set y. The main difference between these two attribute sets is that: X is the attribute space of the entire system, while x and y are specific instances in X. The same message can be switched from one set of attributes (x) to another set of attributes (y) without re-encryption.
[0098] S105: When the attribute set of the ciphertext does not match the access policy, convert the ciphertext from one attribute set to another based on the conversion key, so that the new ciphertext can match the new access policy;
[0099] Input the conversion key swk y and the ciphertext CT, and parse the conversion key
[0100] Parse the ciphertext where c in = A T s + e0,
[0101] If f(x) = 1, output ⊥, otherwise continue with the following steps;
[0102] Calculate
[0103] Calculate the new ciphertext
[0104] Output the new transformation key CT' and the new attribute set y;
[0105] where E0, E1, E2 are randomly sampled matrices used to generate the transformation key; H y is a matrix calculated through the attribute set y, which includes the system matrix A, the attribute-related matrix B i and the matrix G in the public key; PowerT q (R f ) is a special transformation on the matrix R f ; is a all-zero matrix used to maintain the matrix structure; c in is a partial ciphertext, where A is the public key matrix, s is a randomly selected vector, and e0 is a noise vector; c i is a partial ciphertext, where B i is the matrix in the public key, x i is an element in the attribute vector, and G is the system parameter matrix; S i is a randomly selected matrix; e0 is a noise vector; c out : the last part of the ciphertext, where U is the matrix in the public key, e1 is another noise vector, and μ is the message; Eval ct is an evaluation function that combines the attributes and the corresponding ciphertext parts and generates a new ciphertext component; BitD q is a bit decomposition operation that converts to a bit representation. cf is the result after function evaluation on the attribute-related part in the original ciphertext CT, which reflects the relationship between the original attributes and the access policy; f represents the access policy function, x is the attribute set associated with the original ciphertext CT, and f(x) = 1 means that the attribute set x satisfies the access policy f.
[0106] S106: Restore the encrypted data to plaintext based on the user's private key and the corresponding attribute set to complete the decryption of the data.
[0107] Input the private key sk f and the ciphertext CT; Parse the input ciphertext where c in = A T s + e0,
[0108] Judge that if f(x) = 1, output ⊥, otherwise continue with the following steps;
[0109] Calculate Calculate the new ciphertext Output the message
[0110] where s is a randomly selected vector for the encryption process; S i is a randomly selected matrix for noise generation in the encryption process; U is a matrix of uniformly random sampling and belongs to the public key; The rounding operation is used to extract the message from the calculation result.
[0111] See Figure 2 , the present invention discloses an encryption system with switchable attributes constructed based on the LWE assumption, including:
[0112] A generation module, which sets the basic architecture and security parameters of the system, and generates a public key, public parameters and creates a master key through a trapdoor generator and a sampling random matrix;
[0113] A construction module, which constructs the private key of each user based on the master key and the user's own attribute function;
[0114] An acquisition module, which acquires a conversion key based on the public key, the user's own private key, the attribute set corresponding to the user, and the generation matrix in the public parameters;
[0115] An encryption module, which encrypts the plaintext message under a given attribute set to obtain the encrypted ciphertext;
[0116] A conversion module, when the attribute set of the ciphertext does not match the access policy, converts the ciphertext from one attribute set to another based on the conversion key, so that the new ciphertext can match the new access policy;
[0117] A decryption module, which restores the encrypted data to the plaintext based on the user's private key and the corresponding attribute set to complete the decryption of the data.
[0118] Embodiment: See Figure 2 , the present invention discloses an encryption method with switchable attributes constructed based on the LWE assumption, specifically: the present invention uses KP-ABE-SA to implement the process of dynamically adding and revoking users in cloud computing.
[0119] Through the mutual cooperation of the parameter generation algorithm, key generation algorithm, attribute conversion key generation algorithm, encryption algorithm, attribute switching algorithm, and decryption algorithm, dynamic user addition and revocation in cloud computing are realized.
[0120] Among them, the parameter generation algorithm sets the basic architecture and security parameters of the system, and generates a public key, public parameters, and creates a master key through relevant processing of the trapdoor generator and sampling random matrix.
[0121] The key generation algorithm generates a key related to each user's access permission, and the key belonging to the user can decrypt the ciphertext that meets specific access policies.
[0122] The attribute conversion key generation algorithm generates a conversion key for switching ciphertext attributes. The conversion key allows modifying its attributes or access policies while keeping the ciphertext encrypted.
[0123] The encryption algorithm encrypts the plaintext message under a given set of attributes, so that only users who meet specific access policies can decrypt and obtain the plaintext.
[0124] The attribute switching algorithm is used when the set of attributes and access policy of the ciphertext do not match. By generating and applying the conversion key, the ciphertext is converted from one set of attributes to another set of attributes, so that the new ciphertext can match the new access policy.
[0125] In the decryption algorithm, the system restores the encrypted data to plaintext using the user's private key and the corresponding set of attributes, so that authorized users can read and use this data. Each ciphertext is associated with a set of attributes.
[0126] The algorithms of the present invention mainly include the following:
[0127] The parameter generation algorithm takes the security parameter λ as input and performs the following operations:
[0128] Generate a trapdoor generator TrapGen(1 n , m, q), and output matrix A and trapdoor information T A ; Sample a uniformly random matrix Sample uniformly random matrices The output is the public key The master key msk = (T A ) The first-level public parameter PP = (n, m, q, k, σ, χ);
[0129] Among them, λ is the security parameter used to determine the security level of the system; TrapGen is the trapdoor generation algorithm that generates matrix A and trapdoor information T A ; U is a random matrix used to provide polymorphism in the encryption and decryption processes; Let \(\mathbf{A}\) be a set of random matrices for constructing attribute encryption; \(\mathbf{PP}\) be the public parameters, including all public parameters required by the system; \(n,m,q,k\) be the dimensions and modulus of the matrices; \(\sigma\) be the standard deviation for the error distribution; \(\chi\) be the error distribution to ensure the security of the system.
[0130] The key generation algorithm takes the master key \(\mathbf{msk}\) and the function as inputs, calculates the matrix
[0131] and a low-norm matrix such that \((\mathbf{A}|\mathbf{B} f )\mathbf{R} f =\mathbf{U}\), which is achieved by running \(\mathbf{R} f \leftarrow\) SampleLeft(\(\mathbf{A},\mathbf{B} f ,\mathbf{T} A ,\mathbf{U},\sigma)\) and outputs the key \(\mathbf{sk} f =(\mathbf{R} f ).
[0132] Among them, \(\mathbf{msk}\) is the master key, containing the trapdoor information \(\mathbf{T} A ; \(f\) is the function defining user attributes; \(\mathbf{B} f is the matrix calculated from the matrix in the public key and the function \(f\), used for encryption and decryption; \(\mathbf{R} f is the low-norm matrix for decryption; the SampleLeft algorithm generates the matrix \(\mathbf{R} f satisfying specific conditions to ensure the equality required in the decryption process.
[0133] The attribute conversion key generation algorithm is: SwitchKeyGen(\(\mathbf{pk},\mathbf{sk} f ,y)\) takes the public key \(\mathbf{pk}\), the private key \(\mathbf{sk} f and the attribute set as inputs, samples three matrices where calculates and the conversion key
[0134] where, \(\mathbf{pk}\) is the public key, containing the public parameters; \(\mathbf{sk} f is the private key, containing the low-norm matrix \(\mathbf{R} f ; \(y\) is the attribute set, the new attribute vector, used to update the key; \(\mathbf{E}_0,\mathbf{E}_1,\mathbf{E}_2\) are randomly sampled matrices for generating the conversion key; \(\mathbf{H} y is the matrix obtained by concatenating \(\mathbf{A}\) and the matrix calculated according to the new attribute set \(y\); \(\mathbf{G}\) is the generating matrix in the public parameters; \(\mathbf{sek} y is the conversion key.
[0135] The encryption algorithm is as follows: Using the public key pk and the message μ ∈ {0, 1} k , and the attribute set Randomly and uniformly select a vector Select two error vectors Select matrices S i ∈ {±1} m×m , calculate the matrix Calculate the error vector Calculate and output the ciphertext and the attribute set x.
[0136] Where μ is the encrypted message, a bit string of length k; x is the attribute set, the attribute vector for encryption; e0, e1 are the error vectors, used to ensure the security of the encryption process; S i is the randomly selected matrix, used to calculate the error vector; B i is the matrix in the public key; I m is the identity matrix.
[0137] The attribute switching algorithm is Switch(swk y , CT), which takes the transformation key swk y and the ciphertext CT as inputs, parses the transformation key and the ciphertext where c in = A T s + e0, Then check the condition. If f(x) = 1, output ⊥, otherwise continue with the following steps:
[0138] (1) Calculate
[0139] (2) Calculate the new ciphertext
[0140] Output the new transformation key CT' and the new attribute set y.
[0141] Where E0, E1, E2 are randomly sampled matrices, used to generate the transformation key; H y is the matrix calculated through the attribute set y, which includes the system matrix A, the attribute-related matrix B i and the matrix G in the public key; U is a uniformly randomly sampled matrix, belonging to the public key; PowerT q (R f ) is for the matrix R fA special transformation performed; is a zero matrix used to maintain the matrix structure; c in is a partial ciphertext, where A is the public key matrix, s is a randomly selected vector, and e0 is a noise vector; c i is a partial ciphertext, where B i is the matrix in the public key, x i is an element in the attribute vector, G is the system parameter matrix, S i is a randomly selected matrix, and e0 is a noise vector; c out is the last part of the ciphertext, where U is the matrix in the public key, e1 is another noise vector, and μ is the message; Eval ct is the evaluation function that combines the attributes and the corresponding ciphertext parts and generates new ciphertext components; BitD q is the bit decomposition operation that converts to a bit representation.
[0142] The decryption algorithm is Dec(sk f , CT) which takes the private key sk f and the ciphertext CT as inputs, and parses the input ciphertext where c in = A T s + e0, If f(x) = 1, output ⊥, otherwise continue with the following steps:
[0143] (1) Calculate
[0144] (2) Calculate the new ciphertext
[0145] Output the message
[0146] Note: In Dec, the calculation of the Eval ct algorithm can be executed on the cloud server, thus reducing the local computing burden of the user. Therefore, the above decryption algorithm can be split into the following two algorithms:
[0147] PartDec(f, x, CT): Given the attribute function f, the attribute set x, and the ciphertext CT, parse the ciphertext where c in = A T s + e0, If f(x) = 1, output ⊥ indicating decryption failure, otherwise calculate and output the intermediate result (c in , c f , cout )。
[0148] FinaDec(sk f ,(c in ,c f ,c out )): Compute using the private key sk f = R f and the intermediate result (c in ,c f ,c out ), to calculate and the output decrypted message
[0149] where s is a uniformly randomly selected vector for the encryption process; S i is a randomly selected matrix for noise generation in the encryption process; U is a matrix of uniformly random samples and belongs to the public key; is a rounding operation used to extract the message from the calculation result.
[0150] Parameter selection: Based on the requirements of correctness and security
[0151] (1) λ = n / 2: This is the security parameter, usually used to define the security level of the system. By setting λ to n / 2, the security and performance can be balanced.
[0152] (2) k and are polynomial relationship parameters. These parameters are in polynomial relationship with n, ensuring that the complexity of the system increases with the increase of n, thus enhancing security.
[0153] (3) m = 2nlogq: m represents the number of columns of the matrix and is associated with n and logq. This choice ensures sufficient redundancy to support the encryption operation.
[0154] (4) σ is the standard deviation, used to define the error distribution. This value is selected to enhance security while maintaining correctness.
[0155] (5) B is the parameter for bounding the error distribution. Selecting this value ensures the correctness and security of the system.
[0156] (6) q is a large prime number. Selecting this value ensures the security of the system under the LWE assumption.
[0157] Correctness analysis: Given a truly generated and a transformation key swk y , consider the following two cases:
[0158] (1) For the ciphertext CT associated with the attribute set x and having the secret key sk f , if f(x) = 1, then by Eval ct The correctness of the algorithm is obtained where ||e f || ≤ 20Bm·(m + 1) d . Thus c' f = (c in |c f ) = (A|B f ) T s + e' f , where Since (A|B f )·R f = U, where most probably Therefore, there is where most probably Thus ensuring μ ∈ {0,1} k The importance of decryption.
[0159] (2) For the ciphertext CT associated with the attribute set x and the switching key swk of the attribute set y y , we can obtain a switched ciphertext CT' associated with the attribute set y through the Switch algorithm, that is, there is
[0160] Therefore, we can obtain
[0161] where
[0162]
[0163] Then, similar to case (1), using the secret key sk g to make g(y) = 0, the message μ ∈ {0,1} k can be correctly recovered from CT'.
[0164] Multiple switching property: It can be seen that any switched ciphertext has the same structure as the original ciphertext. Therefore, the original ciphertext and the switched ciphertext can be decrypted by performing the same decryption operation. Therefore, the above scheme is a multi-switching scheme, and any ciphertext can be switched multiple times as long as the selected parameters allow.
[0165] Dynamically adding and revoking users: By using key-policy ABE with switchable attributes, attribute switching can be achieved, thus enabling the dynamic addition and revocation of users. Consider a practical example: In a technology company, certain source files in a software development project must be kept private from external parties. However, participants from different departments should be able to access these source files. To this end, the source files need to be encrypted, and only authorized participants are granted the right to decrypt. For key-policy ABE with switchable attributes, the project manager first establishes the following requirements: He / she is a project manager, or a project developer actively involved in the project, or holds a senior management position with a tenure of no less than two years. Subsequently, the project manager assigns "1" to represent "yes" and "0" to represent "no", and then converts these requirements into an attribute set x = (x1, x2, x3, x4, x5) ∈ {0, 1} 5 . 1) x1: Is she / he a project manager? 2) x2: Is she / he a project developer? 3) x3: Is she / he actively involved in the project? 4) x4: Does she / he hold a senior management position? 5) x5: Is the tenure less than two years? Using the above key-policy ABE with switchable attributes, the project manager sets the attribute set to x = (1, 1, 1, 1, 0) and encrypts the source file with x. (If he / she sets x = (1, 1, 1, 1, 0), then only project developers can decrypt the ciphertext). Any employee of the software company can obtain the key from the system administrator. For example, the project manager can obtain the (Boolean) function f(x) = 1 - x1 + 0x2x3x4x5, and the senior manager can obtain the key sk f For the (Boolean) function f(x) = 0x1x2x3 + (1 - x4(1 - x5)).
[0166] (1) User addition: Returning to the above example. Suppose the project manager wants to remove the item "Is she / he actively working on the project", that is, change x3 = 1 to x3 = 0. Then, using the SwitchKeyGen and Switch algorithms of the above key-policy ABE with switchable attributes, (1, 1, 1, 1, 0) can be converted to (1, 1, 0, 1, 0). This means that any project developer who is not actively involved in the project can also access the source file, thus achieving the dynamic addition of users.
[0167] (2) User revocation: Similarly, assume that the project manager wants to revoke the decryption rights of all senior management, that is, x4 = 1 should be changed to x4 = 0. Then, using the SwitchKeyGen and Switch algorithms of the key-policy ABE with switchable attributes described above, (1, 1, 1, 1, 0) can be converted to (1, 1, 1, 0, 0), achieving dynamic user revocation. Note that since multiple users may share an attribute (e.g., there are multiple project developers in the above example), switching an attribute (even just one) will result in dynamic addition and revocation of multiple users. In other words, a single switching operation can dynamically add or revoke multiple users.
[0168] The terminal device provided by an embodiment of the present invention. The terminal device of this embodiment includes: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the above various method embodiments are implemented. Alternatively, when the processor executes the computer program, the functions of each module / unit in the above various device embodiments are implemented.
[0169] The computer program can be divided into one or more modules / units, and the one or more modules / units are stored in the memory and executed by the processor to complete the present invention.
[0170] The terminal device can be a computing device such as a desktop computer, a notebook, a handheld computer, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory.
[0171] The processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0172] The memory can be used to store the computer program and / or modules, and the processor realizes various functions of the terminal device by running or executing the computer program and / or modules stored in the memory, and by calling the data stored in the memory.
[0173] If the modules / units integrated in the terminal device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0174] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. An encryption method with switchable attributes based on the LWE assumption, characterized in that: include: Set the basic architecture and security parameters of the system, generate public keys and public parameters through trapdoor generator and sampled random matrix, and create master keys; Based on the master key and the user's own attribute function, build each user's own private key; Obtain the conversion key based on the public key, the user's own private key, the user's own corresponding attribute set and the generator matrix in the public parameters; Encrypt the plaintext message under a given set of attributes to obtain the encrypted ciphertext; When the attribute set of the ciphertext does not match the access policy, the ciphertext is converted from one attribute set to another attribute set based on the conversion key so that the new ciphertext can match the new access policy; Based on the user's private key and the corresponding attribute set, the encrypted data is restored to plain text to complete the data decryption.
2. The encryption method for constructing switchable attributes based on the LWE assumption according to claim 1, characterized in that: The basic architecture and security parameters of the system are set, and the public key and public parameters are generated by the trapdoor generator and the sampled random matrix, and the master key is created, specifically: Set the security parameter λ, based on the trapdoor generator TrapGen(1 n , m, q) to generate trapdoor information T A , where A is a matrix; Sampling a uniform random matrix represents the set of integers modulo q; samples l uniform random matrices Based on uniform random matrix trapdoor information T A , uniform random matrix and l uniform random matrices Output public key pk = (A, U, B1, ..., B l , PP), public parameters PP = (n, m, q, k, σ, χ) and master key msk = (T A );in χ is a B-bounded The error distribution of Among them, TrapGen is a trapdoor generation algorithm, 1 n is the input security parameter, where n is a positive integer used to determine the security level; m represents the length or size of the message; in the trapdoor generator, q usually represents a prime number used for modular operations, which determines that the elements of all matrices and vectors will be restricted to the set of integers modulo q; n, m, q, k are the dimensions and modulus of the matrix; σ is the standard deviation; χ is the error distribution; bounded means that in the encryption scheme, the range of error values is limited, indicating that the generated error value will not exceed a certain limit. Based on the LWE assumption, the security of the encryption process is controlled by ensuring the boundedness of the noise.
3. The encryption method for constructing switchable attributes based on the LWE assumption according to claim 2, characterized in that: The private key of each user is constructed based on the master key and the attribute function of the user itself, specifically: Based on the input master key msk and function Calculate the matrix B f =Eval pk (f, (B1, ..., B l )); Compute low-norm matrix By calculating the matrix, (A|B f )R f =U; Run R f ←SampleLeft(A,B f , T A , U, σ) generates the key transformation matrix and outputs the key sk f =(R f ); Where f is the function that defines the user attributes; B f From the matrix B1, ..., B in the public key l and function f for encryption and decryption, R f It is a low-norm matrix used for decryption; the SampleLeft algorithm generates a matrix R that meets specific conditions f , ensuring that the required equality during the decryption process holds.
4. The encryption method for constructing switchable attributes based on the LWE assumption according to claim 3, characterized in that: The conversion key is obtained based on the public key, the user's own private key, the user's own corresponding attribute set and the generator matrix in the public parameters, specifically: Enter the public key pk and private key sk f The attribute set y corresponding to the user itself = (y1, ..., y l )∈{0,1} l , and sample three matrices in χ is the error distribution; Link the matrix A with the public key pk, the attribute set y corresponding to the user, and the generator matrix G in the public parameters to obtain the matrix Based on the matrix H y , matrix E0, matrix E1 and matrix E2, private key sk f Calculate the conversion key Among them, sk f is the private key, containing the low-norm matrix Rf, y is the attribute set, the new attribute vector, used to update the key; E0, E1, E2 are randomly sampled matrices used to generate the conversion key; G is the generation matrix in the public parameters; swky is the conversion key.
5. The encryption method for constructing switchable attributes based on the LWE assumption according to claim 4, characterized in that: The plaintext message is encrypted under a given attribute set to obtain the encrypted ciphertext, specifically: Input public key pk, message μ∈{0,1} k , attribute set x = (x1, x2, ..., x l )∈{0,1} l , and randomly select a vector Choose two error vectors e0∈χ m , Select l matrices S i ∈{±1} m×m ; Based on the attribute set x=(x1, x2, ..., x l )∈{0,1} l , the generator matrix G in the public parameters, the matrix B1, ..., B in the public key pk l and matrix A, we get the matrix Based on the matrix S i ∈{±1} m×m , error vector e0∈χ m and the identity matrix Im, we get the error vector Based on the matrix H, error vector e, error vector e1, vector and message μ∈{0,1} k , we get H T s+e, Output ciphertext and attribute set x; Where μ is the encrypted message, a bit string of length k; x is the attribute set, the attribute vector used for encryption; S i is a randomly selected matrix used to calculate the error vector; B i is the matrix in the public key.
6. The encryption method for constructing switchable attributes based on the LWE assumption according to claim 5, characterized in that: When the attribute set of the ciphertext does not match the access policy, the ciphertext is converted from one attribute set to another attribute set based on the conversion key so that the new ciphertext can match the new access policy, specifically: Enter the conversion key swk y and ciphertext CT, and parse the conversion key Parsing ciphertext CT = (c in , c1,...,c l , c out ), where c in =A T s+e0, If f(x) = 1, output ⊥, otherwise continue with the following steps; calculate Calculate the new ciphertext Output the new transformation key CT' and update the attribute set y; Among them, E0, E1, E2 are randomly sampled matrices used to generate the conversion key; H y is the matrix calculated by the attribute set y, which includes the system matrix A and the attribute-related matrix B i and the matrix G in the public key; PowerT q (R f ) is the pair matrix R f A special transformation performed; 0 k×(l+1)m is an all-zero matrix used to maintain the matrix structure; c in is a partial ciphertext, where A is the public key matrix, s is a randomly selected vector, and e0 is a noise vector; c i is a partial ciphertext, where B i is the matrix in the public key, x i is the element in the attribute vector, G is the system parameter matrix; S i is a randomly selected matrix; e0 is a noise vector; c out is the last part of the ciphertext, where U is the matrix in the public key, e1 is another noise vector, and μ is the message; Eval ct To evaluate the function, the attribute and the corresponding ciphertext part are combined to generate a new ciphertext component; BitD g is a bit decomposition operation, converted into bit representation; cf is the result of function evaluation of the attribute-related part in the original ciphertext CT, reflecting the relationship between the original attributes and the access policy; f represents the access policy function, x is the attribute set associated with the original ciphertext CT, and f(x)=1 indicates that the attribute set x satisfies the access policy f.
7. The encryption method for constructing switchable attributes based on LWE assumption according to claim 6, characterized in that: The method of restoring the encrypted data to plain text based on the user's private key and the corresponding attribute set is as follows: Enter the private key sk f and ciphertext CT; parse input ciphertext in If f(x) = 1, output ⊥, otherwise continue with the following steps; calculate Calculate the new ciphertext Output Message Among them, s is a randomly selected vector used in the encryption process; S i is a randomly selected matrix used for noise generation in the encryption process; U is a uniformly randomly sampled matrix belonging to the public key; Rounding operation, used to extract the message from the calculation result.
8. Based on the LWE assumption, an encryption system with switchable attributes is constructed, characterized in that: include: A generation module, which sets the basic architecture and security parameters of the system, generates public keys and public parameters through a trapdoor generator and a sampled random matrix, and creates a master key; A construction module, wherein the construction module constructs each user's own private key based on the master key and the user's own attribute function; An acquisition module, wherein the acquisition module acquires a conversion key based on a public key, a private key of the user, a property set corresponding to the user, and a generator matrix in the public parameters; An encryption module, wherein the encryption module encrypts the plaintext message under a given attribute set to obtain an encrypted ciphertext; A conversion module, wherein when the attribute set of the ciphertext does not match the access policy, the conversion module converts the ciphertext from one attribute set to another attribute set based on a conversion key so that the new ciphertext can match the new access policy; The decryption module restores the encrypted data to plain text based on the user's private key and the corresponding attribute set to complete the decryption of the data.
9. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.