Fine-grained access control system and method based on combination of CPK and attribute permission

By combining the CPK with the public key mechanism and attribute permissions, and using matrix key generation and combination encryption and decryption mechanisms, the problems of key management complexity and low computing efficiency of traditional ABE technology under complex permission policies are solved, efficient and secure fine-grained access control is achieved, and system performance and scalability are improved.

CN120200847AActive Publication Date: 2025-06-24NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Patent Information

Application Number
CN202510657641.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-06-24
Estimated Expiration
2045-05-21

AI Technical Summary

Technical Problem

Traditional ABE technology faces the problems of key management complexity, low computing efficiency, reduced response speed of resource-constrained terminals and high energy consumption for encryption and decryption computing under complex permission strategies, which is difficult to meet the performance and scalability requirements of large-scale users and attribute scenarios.

Method used

By combining the CPK combination public key mechanism with attribute permissions, matrixed key generation, attribute public key combination encryption and private key combination decryption mechanisms are adopted to simplify key management and support dynamic attribute expansion and complex access policies.

Benefits of technology

It significantly improves performance and scalability in large-scale users and attribute scenarios, reduces key management complexity and computing overhead, and improves system efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200847A_ABST
    Figure CN120200847A_ABST
Patent Text Reader

Abstract

The invention discloses a fine-grained access control system and method based on combination of CPK and attribute authority, a key generation management unit generates a public and private key pair corresponding to each attribute, and an attribute and strategy management unit defines a system attribute set and formulates an access control strategy. The user and authorization management unit distributes attribute information for a user and determines an access authority according to the attribute information, the data access and encryption unit combines a plurality of attribute public keys according to an access control strategy to form a combined public key, and the data decryption and verification unit verifies user authority attributes and combines private keys of corresponding attributes to form a combined private key; and the local resource and authority management unit stores and updates the attribute private key and authority information of the user side. Through matrix key generation, attribute public key combined encryption and private key combined decryption mechanisms, the problems of complex key management and low efficiency of a traditional ABE scheme are solved, dynamic attribute extension and a complex access strategy are supported, and the performance and expandability under large-scale user and attribute scenes are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology. Specifically, it relates to a fine-grained access control system and method based on the combination of CPK and attribute permissions. Background Art

[0002] In the context of the rapid development of cloud computing and big data technologies, the demand for the storage, sharing, and processing of massive amounts of data has surged, and data security and privacy protection have become core challenges. To address this challenge, access control technologies based on attribute-based encryption (ABE) have emerged. Traditional ABE schemes dynamically associate user attributes with access permissions and construct an attribute matching mechanism for ciphertext and keys based on bilinear mapping, enabling the decryption of ciphertext only when the user attributes meet the preset access policy. This technology effectively realizes the fine-grained control of sensitive information by data owners in an open environment, enhancing data security while strengthening privacy protection capabilities.

[0003] However, with the continuous deepening of the demand for access control granularity in actual application scenarios, traditional ABE technologies face significant bottlenecks: First, as the complexity of permission policies increases, the scale of the attribute set that the system needs to manage grows linearly, resulting in a sharp increase in the number of public and private keys, and a significant increase in the complexity of key storage, distribution, and revocation. Especially in the scenario of multiple authorization agencies, the computational and communication overhead of the key management mechanism becomes a key constraint on the scalability of the system. Second, under complex permission policies, the number of bilinear pairing operations that the decryption algorithm needs to perform grows exponentially with the scale of the policy, causing the response speed of resource-constrained terminals to drop sharply in high-concurrency scenarios and making it difficult to meet real-time requirements. Third, the frequent bilinear mapping operations in existing schemes lead to excessive computational energy consumption in the encryption and decryption phases, especially in low-computing-power nodes such as Internet of Things edge devices, severely restricting the applicability of ABE technology in dynamic access control scenarios.

[0004] Although existing research has tried to optimize performance through methods such as policy hiding or partial outsourcing of computing, there are still problems such as limited flexibility in policy expression and reliance on third-party trust. Therefore, how to construct an efficient and low-power lightweight attribute encryption mechanism while ensuring fine-grained access control has become a key research direction for breaking through the practical application barriers of ABE technology. Summary of the Invention

[0005] The purpose of this application is to overcome the existing technical defects and provide a fine-grained access control system and method based on the combination of CPK and attribute permissions. Through the matrix-based key generation, attribute public key combined encryption, and private key combined decryption mechanisms, it solves the problems of complex key management and low efficiency in traditional ABE schemes, supports dynamic attribute expansion and complex access policies, and significantly improves the performance and scalability in large-scale user and attribute scenarios.

[0006] The purpose of this application is achieved through the following technical solutions: In a first aspect, this application proposes a fine-grained access control system based on the combination of CPK and attribute permissions. The fine-grained access control system includes a server and a client connected to the server; The server includes: A key generation and management unit, which is used to generate public and private key pairs corresponding to each attribute in the system attribute set based on the CPK combined public key cryptosystem; An attribute and policy management unit, which is used to define the system attribute set and formulate access control policies for file encryption and decryption permissions based on attributes; A user and authorization management unit, which is used to assign attribute information to users, determine access permissions according to the attribute information, manage user attribute changes, and adjust file access permissions; A data access and encryption unit, which is used to form a combined public key by combining multiple attribute public keys according to the access control policy, and use the combined public key to encrypt sensitive data; The client includes: A data decryption and verification unit, which is used to verify whether the user permission attributes conform to the access policy, combine the private keys corresponding to the attributes to form a combined private key, and decrypt the data with the combined private key to obtain the data plaintext; A local resource and permission management unit, which is used to store and update the attribute private keys and permission information of the client.

[0007] In a possible embodiment, the public and private key pairs include a public key matrix and a private key matrix , both of which are constructed by the elliptic curve cryptography algorithm. The private key matrix , is an element of the private key matrix, and the public key matrix , is an element of the public key matrix.

[0008] In a possible embodiment, the attribute and policy management unit is used for: Using a mapping function to map the independent attributes in the system attribute set to generate 32 8-bit binary sequences, and based on the modulo 32 operation, select from the public key matrix and the private key matrix Select corresponding elements from it and combine them to generate the corresponding private key and public key .

[0009] In a possible embodiment, a user and an authorization management unit are used to select corresponding attributes from the system attribute set according to data access control requirements{ } as the access permission policy for sensitive data Data, and distribute the permission information and the private key corresponding to this group of attributes{ } to the user side.

[0010] In a possible embodiment, the data access and encryption unit combines multiple attribute public keys corresponding to the access permission to form a combined public key , and uses the combined public key to encrypt the sensitive data plaintext to obtain the ciphertext where represents an asymmetric encryption algorithm.

[0011] In a possible embodiment, the decryption process of the user side is as follows: , is the modulus, and the sensitive data plaintext is restored through a single decryption operation , where represents an asymmetric decryption algorithm.

[0012] In a possible embodiment, the access control policy supports dynamic expansion, including addition and deletion of attributes, adjustment of permission rules, and real-time update of user attributes.

[0013] In a second aspect, the present application proposes a fine-grained access control method based on the combination of CPK and attribute permissions. The method is applied to the fine-grained access control system in the first aspect above. The method includes: Step 1: The server generates a private key matrix and a public key matrix, and assigns a public-private key pair to each attribute through attribute mapping; Step 2: The server formulates a data access policy and distributes the corresponding attribute private key to the user side; Step 3: The server combines multiple attribute public keys to encrypt sensitive data and generates a ciphertext; Step 4: After verifying the permission, the user side combines the attribute private keys to decrypt the data to implement fine-grained access control.

[0014] The main solution of the present application and its various further selection solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed by the present application; and in the present application, (each non-conflicting selection) can be freely combined between selections and with other selections. Those skilled in the art can understand that there are multiple combinations according to the prior art and common general knowledge after understanding the solution of the present application, all of which are the technical solutions to be protected by the present application and will not be enumerated here.

[0015] This application discloses a fine-grained access control system and method based on the combination of CPK and attribute permissions. The key generation and management unit generates public-private key pairs corresponding to each attribute in the system attribute set. The attribute and policy management unit defines the system attribute set and formulates access control policies. The user and authorization management unit assigns attribute information to users and determines access permissions based on the attribute information. The data access and encryption unit forms a combined public key by combining multiple attribute public keys according to the access control policy. The data decryption and verification unit verifies the user permission attributes and combines the private keys corresponding to the attributes to form a combined private key. The local resource and permission management unit stores and updates the attribute private keys and permission information of the user side. Through the matrix-based key generation, attribute public key combined encryption, and private key combined decryption mechanisms, it solves the problems of complex key management and low efficiency in traditional ABE schemes, supports dynamic attribute expansion and complex access policies, and significantly improves the performance and scalability in large-scale user and attribute scenarios. Brief Description of the Drawings

[0016] In order to more clearly illustrate the technical solutions of the embodiments of this application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 Shows a fine-grained access control system based on the combination of CPK and attribute permissions proposed in an embodiment of this application.

[0018] Figure 2 Shows a schematic flowchart of a fine-grained access control method based on the combination of CPK and attribute permissions proposed in an embodiment of this application. Detailed Embodiments

[0019] The following uses specific specific examples to illustrate the implementation manners of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0020] Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by this application.

[0021] In the prior art, however, as the user's demand for access control rights has changed from extensive management to more fine-grained control, the increase in the number of attributes has led to the growth of the number of public and private keys, significantly increasing the complexity of key management and the difficulty of maintenance. Moreover, in the case of relatively complex user permissions, the time complexity of the decryption process based on traditional attribute encryption technology also increases exponentially. Users usually need to perform multiple bilinear pairing operations, resulting in a large computational overhead, which affects the performance and response speed of the system, greatly limiting the efficiency and scalability of attribute-based encryption technology in practical applications and making it difficult to meet the requirements of fine-grained and fast access control application scenarios based on attributes.

[0022] Therefore, in order to solve the technical problems such as the complexity of key management and the low computational performance brought by fine-grained access control in existing attribute-based encryption schemes in large-scale systems, the embodiments of the present application propose a fine-grained access control system and method based on the combination of CPK and attribute permissions. By combining the CPK combined public key mechanism with attribute permissions and adopting the encryption method of attribute combined public keys, a solution that can not only ensure high-security fine-grained access control but also maintain high system performance and scalability in large-scale user and attribute scenarios is realized. Next, it will be described in detail.

[0023] Please refer to Figure 1 , Figure 1 FIG. shows a fine-grained access control system based on the combination of CPK and attribute permissions proposed by the embodiments of the present application. The fine-grained access control system includes a server and a user terminal connected to the server. The application scenarios of this system can include: First, enterprise internal data management, encrypting internal documents according to "department + position + confidentiality level" to ensure data security; Second, temporary authorization for external partners, providing attribute-based temporary access permissions for external partners, taking into account flexibility and security. Third, government data opening, controlling access to citizens' privacy data according to "place of household registration + business type" to ensure compliance and efficiency.

[0024] The server includes: A key generation and management unit, which is used to generate a public and private key pair corresponding to each attribute in the system attribute set based on the CPK combined public key cryptosystem; An attribute and policy management unit, which is used to define the system attribute set and formulate an access control policy for encrypting and decrypting files based on attributes; A user and authorization management unit, which is used to assign attribute information to users and determine access permissions according to the attribute information, manage changes in user attributes, and adjust file access permissions; A data access and encryption unit, which is used to form a combined public key by combining multiple attribute public keys according to the access control policy and use the combined public key to encrypt sensitive data; The user terminal includes: A data decryption and verification unit, which is used to verify whether the user permission attributes conform to the access policy, combine the private keys corresponding to the attributes to form a combined private key, and decrypt the data with the combined private key to obtain the data plaintext; A local resource and permission management unit, which is used to store and update the attribute private keys and permission information of the user side.

[0025] This system consists of two parts: a server side and a user side. The server side is responsible for key generation, attribute and policy management, user authorization, and data encryption. The user side is responsible for data decryption verification and local resource and permission management. The server side consists of four main units, each unit undertaking specific responsibilities, namely a key generation and management unit, an attribute and policy management unit, a user and authorization management unit, and a data access and encryption unit.

[0026] Based on the CPK combined public key cryptosystem, the key generation and management unit generates a pair of public and private keys for each attribute in the system. The public and private key pairs are used for subsequent encryption and decryption operations of sensitive data. It generates public and private key factors using matrix operations, supporting dynamic expansion of the number of attributes.

[0027] The attribute and policy management unit defines the attribute set of the system, such as "department", "position", "level", etc., formulates access control policies based on attributes, and clarifies which attribute combinations can access specific files or data. For example, accessing a certain file may require meeting the condition of "department = R & D department AND role = project manager".

[0028] The user and authorization management unit assigns attribute information to users, determines their access permissions based on these attributes, dynamically manages changes in users' attributes. When a user's position is adjusted or department is transferred, their permissions are updated in a timely manner, and it can also support flexible adjustment of file access permissions.

[0029] The data access and encryption unit selects multiple attribute public keys for combination according to the access control policy to form a combined public key, encrypts sensitive data with the combined public key, ensuring that only users with the corresponding attribute private keys can decrypt it, and it can also provide an external data access interface to facilitate legitimate users to obtain encrypted data.

[0030] The user side includes a data decryption and verification unit and a local resource and permission management unit. In the data decryption and verification unit, after receiving the encrypted data, the user side first verifies whether it has all the attributes that conform to the access policy. If the conditions are met, it combines the private keys corresponding to the attributes into a combined private key, and uses the combined private key to decrypt the encrypted data to obtain the data plaintext. The local resource and permission management unit stores and manages the attribute private keys and permission information of the user side, supports dynamic update of the user's attribute private keys and permissions, and ensures the real-time nature of access control.

[0031] Through the combination of the CPK combined public key mechanism and attribute permissions, efficient, flexible, and secure fine-grained access control is achieved. It not only simplifies key management but also significantly improves system performance, making it particularly suitable for large-scale and high-concurrency application scenarios.

[0032] The public-private key pair includes a public key matrix and a private key matrix , both of which are constructed through the elliptic curve cryptography algorithm. The private key matrix , is an element of the private key matrix, and the public key matrix , is an element of the public key matrix.

[0033] Through the elliptic curve cryptography (ECC) and SM2 algorithm, a 32×32 public key matrix and a private key matrix are constructed, providing the basic key factors for subsequent attribute encryption and decryption. First, initialize the elliptic curve parameters. The base point is a fixed point on the elliptic curve and is a public parameter. The random number range is , and the order is the order of the subgroup generated by the base point G on the elliptic curve. Second, generate the private key matrix , where the matrix structure is a 32-row × 32-column matrix, and each element is a random private key factor, and each is independently and randomly generated. Subsequently, generate the public key matrix . For each private key factor , calculate its corresponding public key factor: (elliptic curve multiple point operation). The matrix structure has the same dimension as the private key matrix, and the elements are elliptic curve points. Finally, perform the binding of the public and private key factors. The and at the same coordinates in the matrix are a pair of public and private key factors. For example, 's private key corresponds to the public key .

[0034] Through the matrix-based key structure and elliptic curve cryptography, an efficient and secure key factor pool is provided for the system. This design not only avoids the key explosion problem of traditional ABE schemes but also achieves national cryptography compliance through the SM2 algorithm.

[0035] The attribute and policy management unit is specifically used for: Using a mapping function to map the independent attributes in the system attribute set to generate 32 8-bit binary sequences, and based on modulo 32 operation, select the corresponding elements from the public key matrix and the private key matrix to combine and generate the corresponding private key and public key 。

[0036] Map system attributes (such as "role=manager", "department=R&D") to specific positions in the CPK matrix through the SM3 hash function to generate private keys corresponding to each attribute and public keys , supporting dynamic expansion of the number of attributes. Assume the system attribute set is where represents an independent attribute, such as "role", "position", "level", or "department", etc., supporting dynamic expansion of the number of attributes. Input the attribute , hash the attribute using the SM3 algorithm to generate a 256-bit (32-byte) hash value: , where each is an 8-bit binary number (1 byte), and the value range is 0 ≤ ≤ 255. Then calculate its row coordinates in the private key matrix and the public key matrix : . Finally, extract 32 elements (one per column) from the private key matrix , sum them up and take the modulus N to get the private key corresponding to each attribute , extract 32 elliptic curve points (one per column) from the public key matrix , perform point addition operations to get the public key . Through hash mapping and matrix coordinate positioning, any attribute is dynamically bound to multiple key factors in the CPK matrix to generate a unique public-private key pair.

[0037] User and authorization management unit, used to select corresponding attributes { } from the system attribute set as the access permission policy for sensitive data Data, and distribute the permission information and the private keys { } corresponding to this group of attributes to the user side.

[0038] According to the access policy of sensitive data, select a group of attributes from the system attribute set, distribute the corresponding attribute private keys to authorized users, and implement dynamic fine-grained permission control. First, input the access control requirements of sensitive data Data (such as the access permission is "department=R&D department AND role=project manager AND level=senior"), the system attribute set and its corresponding public and private keys, and then convert the access requirements into an attribute set { }, extract the private keys { } corresponding to these attributes from the private key matrix, send the private key set to the authorized user side through a secure channel, and finally obtain the private key set { } stored on the user side and the binding relationship between the permission policy recorded on the server side and the user attributes.

[0039] The data access and encryption unit combines multiple attribute public keys corresponding to access permissions to form a combined public key , and uses the combined public key to encrypt the sensitive data plaintext to obtain the ciphertext where represents the asymmetric encryption algorithm

[0040] By encrypting the sensitive data with the combined public key, it is ensured that only users with the corresponding attribute private keys can decrypt it, realizing attribute-based fine-grained access control. Specifically: The set of attribute public keys { } corresponding to the access policy is subjected to elliptic curve point addition operation to generate the combined public key , and then the combined public key is used to encrypt the sensitive data plaintext to obtain the ciphertext , represents the asymmetric encryption algorithm

[0041] The decryption process at the user side is as follows: The attribute private keys that satisfy the access policy are combined to form a combined private key , is the modulus, and the sensitive data plaintext is restored through a single decryption operation, where represents the asymmetric decryption algorithm

[0042] The user side generates a combined private key by combining the attribute private keys that satisfy the access policy, and uses this key to decrypt the sensitive data ciphertext at once, realizing efficient and secure access control. Specifically: The user side obtains the sensitive data ciphertext through the data access interface. According to the ciphertext permission information, the required attribute private keys are combined to form a combined private key , and the combined private key is used to encrypt the sensitive data ciphertext to obtain the plaintext , represents the asymmetric decryption algorithm

[0043] The access control policy supports dynamic expansion, including addition and deletion of attributes, adjustment of permission rules, and real-time update of user attributes

[0044] This access control policy has the ability of dynamic expansion. On the one hand, the system can flexibly add and delete attributes. When there are new business requirements or changes in data access scenarios, new attributes can be added in time or the no-longer applicable attributes can be removed. At the same time, the key generation and management unit generates public-private key pairs for the newly added attributes to adapt to the update of the attribute set. On the other hand, the permission rules can be adjusted according to the actual situation. The attribute and policy management unit redefines the rule set for file encryption and user decryption permissions, thereby changing the access control policy to finely manage data access permissions. In addition, the user and authorization management unit can update user attributes in real time. When the user's responsibilities, permissions, etc. change, their attribute information can be quickly adjusted, and the file access permissions can be changed accordingly to ensure secure and reasonable access control of data.

[0045] Figure 2 FIG. 4 shows a schematic flowchart of a fine-grained access control method based on the combination of CPK and attribute permissions proposed in an embodiment of the present application. This method is applied to the above-mentioned fine-grained access control system, and this method includes: Step 1: The server generates a private key matrix and a public key matrix, and assigns public-private key pairs to each attribute through attribute mapping; Step 2: The server formulates a data access policy and distributes the corresponding attribute private keys to the user side; Step 3: The server combines multiple attribute public keys to encrypt sensitive data and generates ciphertext; Step 4: After verifying the permissions, the user side combines the attribute private keys to decrypt the data to achieve fine-grained access control.

[0046] The server first constructs a private key matrix and a public key matrix using public-private key factors, and then maps the attribute information to the row coordinate and column coordinate sequences of the matrix. By selecting and combining matrix elements, public keys and private keys are generated for each attribute. Then the server formulates an access policy for sensitive data, and at the same time assigns access permissions to each user, and sends the permission information and the corresponding attribute private keys to the corresponding user side. According to the access policy of sensitive data, the server selects the corresponding multiple attribute public keys to be combined to generate a combined public key and encrypts the sensitive data. After receiving the ciphertext data, the user side verifies whether it can decrypt by checking whether it has all the attributes required for access permissions. If it meets the access requirements, the corresponding attribute private keys are combined into a combined private key, and the data is successfully decrypted; otherwise, the decryption fails and the sensitive data cannot be obtained.

[0047] Compared with the prior art, the embodiment of the present application has the following beneficial effects: First, by using a small number of public-private key factors and through a matrix-based key structure and combination strategy, the problem of the explosion of the number of attribute public-private key pairs caused by the increase in system complexity is avoided, and the complexity of key management is simplified; Second, by flexibly combining different attribute public keys, complex access policies are realized, and dynamic addition, deletion, and permission configuration of attributes are supported, enhancing scalability; Third, the data is encrypted and protected by a combined public key formed by merging multiple attribute public keys corresponding to its access policy. Only users with private keys that satisfy a specific attribute set can decrypt it, achieving fine-grained access control; Fourth, the authorized user merges the private keys of multiple attributes to form a combined private key, and only one decryption operation is required to achieve fast access, avoiding the multiple bilinear pairing operation processes in the traditional ABE scheme. Especially when there are many attributes, the decryption efficiency is significantly improved.

[0048] In summary, through the combination of the CPK mechanism and attribute permissions, this application reduces the complexity of key management, reduces the computational overhead during decryption, improves system efficiency, avoids the problems of excessive key management and computational burden in the traditional ABE scheme, and effectively realizes fine-grained and fast access control based on attributes. This mechanism not only ensures the security of the system but also has strong scalability, capable of meeting the needs of a large number of users and complex permission structures.

[0049] The above are only the preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent replacements, and improvements made within the spirit and principle of this application shall be included within the protection scope of this application.

Claims

1. A fine-grained access control system based on the combination of CPK and attribute permissions, characterized in that: The fine-grained access control system includes a server and a user terminal connected to the server; The server includes: A key generation management unit, used to generate a public-private key pair corresponding to each attribute in a system attribute set based on a CPK combined public key cryptography system; The attribute and policy management unit is used to define the system attribute set and formulate the access control policy for the file encryption and decryption permissions based on the attributes; The user and authorization management unit is used to assign attribute information to users and determine access rights based on the attribute information, manage user attribute changes, and adjust file access rights; A data access and encryption unit, used to combine multiple attribute public keys to form a combined public key according to the access control policy, and use the combined public key to encrypt sensitive data; The user terminal comprises: The data decryption and verification unit is used to verify whether the user's permission attributes comply with the access policy, and to combine the private keys of the corresponding attributes to form a combined private key, and to decrypt the data using the combined private key to obtain the data plaintext; The local resource and permission management unit is used to store and update the user's attribute private key and permission information.

2. The fine-grained access control system according to claim 1, characterized in that: The public-private key pair includes the public key matrix and the private key matrix , are constructed through the elliptic curve cryptography algorithm, the private key matrix , is the private key matrix element, the public key matrix , is the public key matrix element.

3. The fine-grained access control system according to claim 2, characterized in that: The attribute and policy management unit is used to: Use mapping functions to map individual properties in the system property set Mapping is performed to generate 32 8-bit binary sequences and then the public key matrix is ​​obtained based on the modulo 32 operation. and the private key matrix Select the corresponding elements and combine them to generate the corresponding private key and the public key .

4. The fine-grained access control system according to claim 3, characterized in that: The user and authorization management unit is used to select the corresponding attributes from the system attribute set according to the data access control requirements. } as the access permission policy for sensitive data Data, and associate the permission information with the private key corresponding to the group of attributes. }Distributed to the user end.

5. The fine-grained access control system according to claim 4, characterized in that: The data access and encryption unit combines multiple attribute public keys corresponding to the access rights to form a combined public key , use the combined public key to plaintext sensitive data Encrypt and get the ciphertext in Represents an asymmetric encryption algorithm.

6. The fine-grained access control system according to claim 5, characterized in that: The decryption process of the user end is: combining the attribute private keys that meet the access policy to form a combined private key , The modulus is used to restore the plaintext of sensitive data through a decryption operation. ,in Represents an asymmetric decryption algorithm.

7. The fine-grained access control system according to claim 1, characterized in that: Access control policies support dynamic expansion, including the addition and deletion of attributes, adjustment of permission rules, and real-time update of user attributes.

8. A fine-grained access control method based on the combination of CPK and attribute permissions, characterized in that: The method is applied to the fine-grained access control system described in any one of claims 1 to 7 above, and the method comprises: Step 1: The server generates a private key matrix and a public key matrix, and assigns a public-private key pair to each attribute through attribute mapping; Step 2: The server formulates data access strategies and distributes corresponding attribute private keys to the user; Step 3: The server combines multiple attribute public keys to encrypt sensitive data and generate ciphertext; Step 4: After verifying the permissions, the user combines the attribute private key to decrypt the data to achieve fine-grained access control.

Citation Information

Patent Citations

  • Cloud storage access control system based on attribute

    CN103327002A

  • File security management method, system and device, medium and program product

    CN116090000A

  • Mass data privacy protection system and method

    CN118427882A

  • Fine-grained security access control method and system, computer equipment and storage medium

    CN119316197A

  • Customers key protection for cloud native deployments

    US20240243913A1

Cited By

  • Trusted data encapsulation, decryption and transmission method and system based on attribute password

    CN120528599A

  • OpenVPN security customization method and system, and medium

    CN121217489A