A Fine-Grained Access Control System and Method Based on the Combination of CPK and Attribute Permissions
Through a fine-grained access control system based on CPK and attribute permissions, the problem of complex key management and low computing efficiency in traditional ABE solutions is solved, efficient and secure fine-grained access control is achieved, and system performance and scalability are improved.
Patent Information
- Application Number
- CN202510657641.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-05-21
AI Technical Summary
Traditional ABE solutions are difficult to meet real-time requirements in terms of high key management complexity, low computing efficiency, slow response speed of resource-constrained terminals and excessive computing energy consumption, especially under large-scale users and complex permissions policies.
A fine-grained access control system based on the combination of CPK and attribute permissions is adopted. Through matrixed key generation, attribute public key combination encryption and private key combination decryption mechanisms, key management is simplified, dynamic attribute expansion and complex access policies are supported, and system performance and scalability are improved.
It realizes efficient and secure fine-grained access control, simplifies key management, reduces computing overhead, improves system response speed and scalability, and is suitable for large-scale users and complex permission scenarios.
Smart Images

Figure CN120200847B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a fine-grained access control system and method based on the combination of CPK and attribute permissions. Background Art
[0002] With the rapid development of cloud computing and big data technologies, the demand for storing, sharing, and processing massive amounts of data has surged, posing a significant challenge to data security and privacy. To address this challenge, access control technology based on attribute-based encryption (ABE) has emerged. Traditional ABE schemes dynamically associate user attributes with access rights and construct a ciphertext-key attribute matching mechanism based on bilinear mapping. This ensures that ciphertext can be decrypted only when user attributes meet the pre-defined access policy. This technology effectively enables data owners to control sensitive information in an open environment with fine-grained control, enhancing data security while strengthening privacy protection.
[0003] However, with the continuous deepening of the demand for access control granularity in actual application scenarios, traditional ABE technology faces significant bottlenecks: First, with the increase in the complexity of permission policies, the scale of the attribute set that the system needs to manage grows linearly, resulting in a sharp expansion in the number of public and private keys, and a significant increase in the complexity of key storage, distribution and revocation. Especially in the scenario of multiple authorized agencies, the computational and communication overhead of the key management mechanism becomes a key constraint on the scalability of the system; Second, under complex permission policies, the number of bilinear pairing operations required by the decryption algorithm grows exponentially with the scale of the policy, causing the response speed of resource-constrained terminals in high-concurrency scenarios to drop sharply, making it difficult to meet real-time requirements; Third, the frequent bilinear mapping operations in the existing schemes lead to excessively high computational energy consumption in the encryption and decryption stages, especially in low-computing power nodes such as IoT edge devices, which seriously restricts the applicability of ABE technology in dynamic access control scenarios.
[0004] Although existing research attempts to optimize performance through policy hiding or partial outsourcing of computation, issues such as limited flexibility in policy expression and reliance on third-party trust persist. Therefore, building an efficient, low-power, and lightweight attribute encryption mechanism while ensuring fine-grained access control has become a key research direction for breaking through the barriers to practical application of ABE technology. Summary of the Invention
[0005] The purpose of this application is to overcome the existing technical defects and provide a fine-grained access control system and method based on the combination of CPK and attribute permissions. Through matrix key generation, attribute public key combination encryption and private key combination decryption mechanism, it solves the problem of complex and inefficient key management of traditional ABE scheme, supports dynamic attribute expansion and complex access strategies, and significantly improves the performance and scalability in large-scale user and attribute scenarios.
[0006] The purpose of this application is achieved through the following technical solutions:
[0007] In a first aspect, the present application proposes a fine-grained access control system based on a combination of CPK and attribute permissions, wherein the fine-grained access control system includes a server and a user terminal connected to the server;
[0008] The server includes:
[0009] A key generation management unit is used to generate a public-private key pair corresponding to each attribute in the system attribute set based on the CPK combined public key cryptography system;
[0010] Attribute and policy management unit, which is used to define the system attribute set and formulate access control policies for setting file encryption and decryption permissions based on the attributes;
[0011] The user and authorization management unit is used to assign attribute information to users and determine access rights based on the attribute information, manage user attribute changes, and adjust file access rights;
[0012] A data access and encryption unit is used to combine multiple attribute public keys to form a combined public key according to the access control policy, and use the combined public key to encrypt sensitive data;
[0013] The user terminal includes:
[0014] The data decryption and verification unit is used to verify whether the user's permission attributes comply with the access policy, and to combine the private keys of the corresponding attributes to form a combined private key. The combined private key is used to decrypt the data to obtain the plaintext data.
[0015] The local resource and permission management unit is used to store and update the user's attribute private key and permission information.
[0016] In one possible embodiment, the public-private key pair includes a public key matrix and private key matrix , are constructed through elliptic curve cryptography, private key matrix , is the private key matrix element, the public key matrix , is the public key matrix element.
[0017] In a possible embodiment, the attribute and policy management unit is configured to:
[0018] Use mapping functions to map individual properties in the system property set Mapping is performed to generate 32 8-bit binary sequences and the public key matrix is obtained based on the modulo 32 operation. and private key matrix Select the corresponding elements and combine them to generate the corresponding private key and public key .
[0019] In a possible embodiment, the user and authorization management unit is used to select corresponding attributes from the system attribute set according to data access control requirements. }As the access permission policy for sensitive data Data, the permission information is associated with the private key corresponding to the set of attributes. }Distributed to the user end.
[0020] In a possible embodiment, the data access and encryption unit combines multiple attribute public keys corresponding to the access rights to form a combined public key , use the combined public key to plaintext sensitive data Encrypt and get ciphertext in Indicates an asymmetric encryption algorithm.
[0021] In a possible embodiment, the decryption process of the user terminal is: , The modulus is used to restore the sensitive data plaintext through a decryption operation. ,in Represents an asymmetric decryption algorithm.
[0022] In a possible embodiment, the access control policy supports dynamic extension, including addition and deletion of attributes, adjustment of permission rules, and real-time update of user attributes.
[0023] In a second aspect, the present application proposes a fine-grained access control method based on the combination of CPK and attribute permissions, which is applied to the fine-grained access control system of the first aspect above, and includes:
[0024] Step 1: The server generates a private key matrix and a public key matrix, and assigns a public-private key pair to each attribute through attribute mapping;
[0025] Step 2: The server formulates a data access policy and distributes the corresponding attribute private key to the user;
[0026] Step 3: The server combines multiple attribute public keys to encrypt sensitive data and generate ciphertext;
[0027] Step 4: After verifying the permissions, the user combines the attribute private key to decrypt the data to achieve fine-grained access control.
[0028] The above-mentioned main solution of this application and its various further options can be freely combined to form multiple solutions, all of which are solutions that can be adopted and protected by this application. Moreover, in this application, (non-conflicting options) can also be freely combined with each other and with other options. After understanding the solution of this application, those skilled in the art will understand that there are many combinations based on existing technology and common knowledge, all of which are technical solutions to be protected by this application, and this is not an exhaustive list.
[0029] This application discloses a fine-grained access control system and method based on the combination of CPK and attribute permissions. The key generation management unit generates a public-private key pair corresponding to each attribute in the system attribute set. The attribute and policy management unit defines the system attribute set and formulates the access control policy. The user and authorization management unit assigns attribute information to the user and determines the access rights based on the attribute information. The data access and encryption unit combines multiple attribute public keys to form a combined public key according to the access control policy. The data decryption and verification unit verifies the user's permission attributes and combines the private keys of the corresponding attributes to form a combined private key. The local resource and permission management unit stores and updates the user's attribute private key and permission information. Through matrix key generation, attribute public key combination encryption and private key combination decryption mechanism, the problem of complex and inefficient key management in the traditional ABE scheme is solved, dynamic attribute expansion and complex access policies are supported, and the performance and scalability in large-scale user and attribute scenarios are significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0031] Figure 1 A fine-grained access control system based on the combination of CPK and attribute permissions proposed in an embodiment of the present application is shown.
[0032] Figure 2 A flow chart of a fine-grained access control method based on the combination of CPK and attribute permissions proposed in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0033] The following describes the embodiments of the present application through specific examples. Those skilled in the art can easily understand the other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other unless they conflict.
[0034] Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative work shall fall within the scope of protection of this application.
[0035] In the existing technology, as users' demand for access control permissions shifts from extensive management to more fine-grained management, the increase in the number of attributes leads to an increase in the number of public and private keys, which significantly increases the complexity and maintenance difficulty of key management. In addition, when user permissions are more complex, the time complexity of the decryption process based on traditional attribute encryption technology also increases exponentially. Users usually need to perform multiple bilinear pairing operations, which has a large computational overhead and affects the performance and response speed of the system. As a result, the efficiency and scalability of attribute-based encryption technology in practical applications are greatly limited, making it difficult to meet the application scenario requirements of attribute-based fine-grained and fast access control.
[0036] Therefore, in order to solve the technical problems such as the complexity of key management and the inefficient computing performance caused by fine-grained access control encountered in existing attribute-based encryption schemes in large-scale systems, the embodiment of the present application proposes a fine-grained access control system and method based on the combination of CPK and attribute permissions. By combining the CPK combined public key mechanism with attribute permissions and adopting the encryption method of the attribute combined public key, a solution is implemented that can not only ensure high-security fine-grained access control but also maintain high system performance and scalability in large-scale user and attribute scenarios. It is described in detail below.
[0037] Please refer to Figure 1 , Figure 1 The present invention proposes a fine-grained access control system based on a combination of CPK and attribute permissions. The fine-grained access control system includes a server and a user terminal connected to the server. Application scenarios of the system include: First, internal enterprise data management, encrypting internal documents according to "department + position + confidentiality level" to ensure data security; Second, temporary authorization of external partners, providing external partners with temporary attribute-based access rights, taking into account flexibility and security. Third, open government data, controlling access to citizens' private data according to "place of residence + business type" to ensure compliance and efficiency.
[0038] The server includes:
[0039] A key generation management unit is used to generate a public-private key pair corresponding to each attribute in the system attribute set based on the CPK combined public key cryptography system;
[0040] Attribute and policy management unit, which is used to define the system attribute set and formulate access control policies for setting file encryption and decryption permissions based on the attributes;
[0041] The user and authorization management unit is used to assign attribute information to users and determine access rights based on the attribute information, manage user attribute changes, and adjust file access rights;
[0042] A data access and encryption unit is used to combine multiple attribute public keys to form a combined public key according to the access control policy, and use the combined public key to encrypt sensitive data;
[0043] The user terminal includes:
[0044] The data decryption and verification unit is used to verify whether the user's permission attributes comply with the access policy, and to combine the private keys of the corresponding attributes to form a combined private key. The combined private key is used to decrypt the data to obtain the plaintext data.
[0045] The local resource and permission management unit is used to store and update the user's attribute private key and permission information.
[0046] The system consists of two parts: a server and a client. The server is responsible for key generation, attribute and policy management, user authorization, and data encryption, while the client is responsible for data decryption verification and local resource and permission management. The server consists of four main units, each with specific responsibilities: the key generation management unit, the attribute and policy management unit, the user and authorization management unit, and the data access and encryption unit.
[0047] The key generation management unit generates a pair of public and private keys for each attribute in the system based on the CPK combined public key cryptography system. The public and private key pairs are used for subsequent encryption and decryption operations of sensitive data. Matrix operations are used to generate public and private key factors, supporting dynamic expansion of the number of attributes.
[0048] The attribute and policy management unit defines the system's attribute sets, such as "department", "position", "level", etc., formulates attribute-based access control policies, and clarifies which attribute combinations can access specific files or data. For example, access to a certain file may require "department = R&D department AND role = project manager".
[0049] The user and authorization management unit assigns attribute information to users and determines their access rights based on these attributes. It dynamically manages changes in user attributes, such as position adjustments or department transfers, and updates their permissions in a timely manner. It also supports flexible adjustment of file access rights.
[0050] The data access and encryption unit selects multiple attribute public keys and combines them according to the access control policy to form a combined public key. The combined public key is used to encrypt sensitive data to ensure that only users with the corresponding attribute private key can decrypt it. It also provides an external data access interface to facilitate legitimate users to obtain encrypted data.
[0051] The user side includes a data decryption and verification unit and a local resource and permission management unit. In the data decryption and verification unit, after receiving encrypted data, the user side first verifies whether it possesses all attributes that meet the access policy. If so, the user side combines the private keys for the corresponding attributes into a combined private key, which is then used to decrypt the encrypted data and obtain the plaintext data. The local resource and permission management unit stores and manages the user side's attribute private keys and permission information, supporting dynamic updates of user attribute private keys and permissions to ensure real-time access control.
[0052] By combining the CPK public key mechanism with attribute permissions, efficient, flexible, and secure fine-grained access control is achieved. It not only simplifies key management but also significantly improves system performance, making it particularly suitable for large-scale, high-concurrency application scenarios.
[0053] The public-private key pair includes the public key matrix and private key matrix , are constructed through elliptic curve cryptography, private key matrix , is the private key matrix element, the public key matrix , is the public key matrix element.
[0054] Construct a 32×32 public key matrix using elliptic curve cryptography (ECC) and SM2 algorithm and private key matrix , providing the basic key factor for subsequent attribute encryption and decryption. First, initialize the elliptic curve parameters, the base point Is a fixed point on the elliptic curve and is a public parameter. The random number range is , order It is the order of the subgroup generated by the base point G on the elliptic curve. Next, generate the private key matrix , where the matrix structure is a 32-row × 32-column matrix, each element is a random private key factor, and each Independent random generation. Then generate the public key matrix , for each private key factor , calculate its corresponding public key factor: (Elliptic curve doubling point operation), the matrix structure has the same dimensions as the private key matrix, and the elements are elliptic curve points. Finally, the public and private key factors are bound, and the same coordinates in the matrix and is a pair of public and private key factors, for example, The private key corresponds to the public key .
[0055] Through the matrix key structure and elliptic curve cryptography, an efficient and secure key factor pool is provided for the system. This design not only avoids the key explosion problem of the traditional ABE scheme, but also achieves national security compliance through the SM2 algorithm.
[0056] The attribute and policy management unit is specifically used to:
[0057] Use mapping functions to map individual properties in the system property set Mapping is performed to generate 32 8-bit binary sequences and the public key matrix is obtained based on the modulo 32 operation. and private key matrix Select the corresponding elements and combine them to generate the corresponding private key and public key .
[0058] Map system attributes (such as "role = manager", "department = R&D") to specific positions in the CPK matrix through the SM3 hash function to generate the private key corresponding to each attribute and public key , supports dynamic expansion of the number of attributes. Assume that the system attribute set is in Represents an independent attribute, such as "role", "position", "level" or "department", etc., and supports dynamic expansion of the number of attributes. Input attribute , hash the attribute using the SM3 algorithm to generate a 256-bit (32-byte) hash value: , where each It is an 8-bit binary number (1 byte) with a value range of 0≤ ≤255. Then calculate its value in the private key matrix ) and the public key matrix The row coordinates in : . Finally, from the private key matrix Extract 32 elements (one per column), sum them up and take modulo N to get each attribute Corresponding private key , from the public key matrix Extract 32 elliptic curve points (one in each column) and perform point addition to obtain the public key Through hash mapping and matrix coordinate positioning, any attribute is dynamically bound to multiple key factors of the CPK matrix to generate a unique public-private key pair.
[0059] The user and authorization management unit is used to select the corresponding attributes from the system attribute set according to the data access control requirements. }As the access permission policy for sensitive data Data, the permission information is associated with the private key corresponding to the set of attributes. }Distributed to the user end.
[0060] According to the access policy of sensitive data, a set of attributes is selected from the system attribute set, and the corresponding attribute private key is distributed to authorized users to achieve dynamic fine-grained permission control. First, input the access control requirements of sensitive data Data (such as access rights are "department = R&D department AND role = project manager AND level = senior"), the system attribute set and its corresponding public and private keys, and then convert the access requirements into attribute sets { }, extract the private keys corresponding to these attributes from the private key matrix { }, send the private key set to the authorized user end through a secure channel, and finally obtain the private key set stored by the user end { } and the binding relationship between the permission policy and user attributes recorded on the server.
[0061] The data access and encryption unit combines multiple attribute public keys corresponding to access rights to form a combined public key , use the combined public key to plaintext sensitive data Encrypt and get ciphertext in Indicates an asymmetric encryption algorithm.
[0062] By encrypting sensitive data with a combined public key, we ensure that only users with the corresponding attribute private key can decrypt it, thus achieving attribute-based fine-grained access control. Specifically, we set the attribute public key set corresponding to the access policy to { } Perform elliptic curve point addition to generate a combined public key , and then use the combined public key to clear the sensitive data Encrypt and get ciphertext , Indicates an asymmetric encryption algorithm.
[0063] The decryption process on the user side is: combine the attribute private keys that meet the access policy to form a combined private key , The modulus is used to restore the sensitive data plaintext through a decryption operation. ,in Represents an asymmetric decryption algorithm.
[0064] The user side generates a combined private key by combining attribute private keys that meet the access policy, and uses this key to decrypt sensitive data ciphertext at one time, achieving efficient and secure access control. Specifically:
[0065] The client obtains the ciphertext of sensitive data through the data access interface, and combines the required attribute private keys into a combined private key based on the ciphertext permission information. , use the combined private key to encrypt sensitive data Encrypt to get plaintext , Represents an asymmetric decryption algorithm.
[0066] Access control policies support dynamic expansion, including the addition and deletion of attributes, adjustment of permission rules, and real-time update of user attributes.
[0067] This access control strategy has the ability to dynamically expand. On the one hand, the system can flexibly add and delete attributes. When there are new business needs or changes in data access scenarios, new attributes can be added or no longer applicable attributes can be removed in a timely manner. At the same time, the key generation management unit generates public and private key pairs for the newly added attributes to adapt to the update of the attribute set; on the other hand, the permission rules can be adjusted according to actual conditions. The attribute and policy management unit redefines the rule set for file encryption and user decryption permissions, and then changes the access control strategy to finely control data access rights; in addition, the user and authorization management unit can update user attributes in real time. When user responsibilities, permissions, etc. change, its attribute information can be quickly adjusted, and file access rights can be changed accordingly to ensure data security and reasonable access control.
[0068] Figure 2 A flow chart of a fine-grained access control method based on combining CPK and attribute permissions proposed in an embodiment of the present application is shown. The method is applied to the above-mentioned fine-grained access control system and includes:
[0069] Step 1: The server generates a private key matrix and a public key matrix, and assigns a public-private key pair to each attribute through attribute mapping;
[0070] Step 2: The server formulates a data access policy and distributes the corresponding attribute private key to the user;
[0071] Step 3: The server combines multiple attribute public keys to encrypt sensitive data and generate ciphertext;
[0072] Step 4: After verifying the permissions, the user combines the attribute private key to decrypt the data to achieve fine-grained access control.
[0073] The server first constructs a private key matrix and a public key matrix using public and private key factors. It then maps attribute information into a sequence of row and column coordinates within the matrices. By selecting and combining matrix elements, it generates public and private keys for each attribute. The server then formulates an access policy for sensitive data and assigns access rights to each user. The server then distributes this access information and the corresponding attribute private key to the corresponding client. Based on the access policy for sensitive data, the server selects multiple attribute public keys to combine and generate a combined public key, which is then used to encrypt the sensitive data. Upon receiving the ciphertext data, the client verifies whether it can decrypt it by checking whether it possesses all the attributes required for access rights. If the access requirements are met, the corresponding attribute private keys are combined into a combined private key, successfully decrypting the data. Otherwise, decryption fails, and the sensitive data cannot be retrieved.
[0074] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0075] First, by utilizing a small number of public and private key factors, through a matrixed key structure and combination strategy, we avoid the problem of an explosion in the number of attribute public and private key pairs as the system complexity increases, thus simplifying the complexity of key management.
[0076] Second, by flexibly combining different attribute public keys, complex access policies can be implemented, and dynamic addition and deletion of attributes and permission configuration are supported, improving scalability.
[0077] Third, data is encrypted and protected by a composite public key, which is formed by combining multiple attribute public keys corresponding to its access policy. Only users with private keys that meet a specific set of attributes can decrypt it, achieving fine-grained access control.
[0078] Fourth, authorized users can combine the private keys of multiple attributes to form a combined private key, which can be quickly accessed with only one decryption operation, avoiding the multiple bilinear pairing operations in the traditional ABE-based scheme. Especially when there are many attributes, the decryption efficiency is significantly improved.
[0079] In summary, this application combines the CPK mechanism with attribute permissions to reduce key management complexity, reduce computational overhead during decryption, and improve system efficiency. It avoids the heavy key management and computational burdens of traditional ABE schemes and effectively implements fine-grained, attribute-based, and fast access control. This mechanism not only ensures system security but also offers strong scalability, meeting the needs of large-scale users and complex permission structures.
[0080] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A fine-grained access control system based on the combination of CPK and attribute permissions, characterized in that: The fine-grained access control system includes a server and a user terminal connected to the server; The server includes: A key generation management unit is used to generate a public-private key pair corresponding to each attribute in the system attribute set based on the CPK combined public key cryptography system; Attribute and policy management unit, which is used to define the system attribute set and formulate access control policies for setting file encryption and decryption permissions based on the attributes; The user and authorization management unit is used to assign attribute information to users and determine access rights based on the attribute information, manage user attribute changes, and adjust file access rights; Data access and encryption unit, used to combine multiple attribute public keys corresponding to access rights to form a combined public key , use the combined public key to plaintext sensitive data Encrypt and get ciphertext in Represents an asymmetric encryption algorithm; The user terminal includes: Data decryption and verification unit, used to verify whether the user's permission attributes comply with the access policy, and combine the attribute private keys that meet the access policy to form a combined private key , The modulus is used to restore the sensitive data plaintext through a decryption operation. ,in Represents an asymmetric decryption algorithm; The local resource and permission management unit is used to store and update the user's attribute private key and permission information.
2. The fine-grained access control system according to claim 1, characterized in that: The public-private key pair includes the public key matrix and private key matrix , are constructed through elliptic curve cryptography, private key matrix , is the private key matrix element, the public key matrix , is the public key matrix element.
3. The fine-grained access control system according to claim 2, characterized in that: The attribute and policy management unit is used to: Use mapping functions to map individual properties in the system property set Mapping is performed to generate 32 8-bit binary sequences and the public key matrix is obtained based on the modulo 32 operation. and private key matrix Select the corresponding elements and combine them to generate the corresponding private key and public key .
4. The fine-grained access control system according to claim 3, characterized in that: The user and authorization management unit is used to select the corresponding attributes from the system attribute set according to the data access control requirements. }As the access permission policy for sensitive data Data, the permission information is associated with the private key corresponding to the set of attributes. }Distributed to the user end.
5. The fine-grained access control system according to claim 1, characterized in that: Access control policies support dynamic expansion, including the addition and deletion of attributes, adjustment of permission rules, and real-time update of user attributes.
6. A fine-grained access control method based on the combination of CPK and attribute permissions, characterized in that: The method is applied to the fine-grained access control system according to any one of claims 1 to 5, and the method includes: Step 1: The server generates a private key matrix and a public key matrix, and assigns a public-private key pair to each attribute through attribute mapping; Step 2: The server formulates a data access policy and distributes the corresponding attribute private key to the user; Step 3: The server combines multiple attribute public keys corresponding to access permissions to form a combined public key , use the combined public key to plaintext sensitive data Encrypt and get ciphertext in Represents an asymmetric encryption algorithm; Step 4: After the user verifies the permissions, the attribute private keys that meet the access policy are combined to form a combined private key , The modulus is used to restore the sensitive data plaintext through a decryption operation. ,in Represents an asymmetric decryption algorithm to implement fine-grained access control.
Citation Information
Patent Citations
File security management method, system and device, medium and program product
CN116090000A
Mass data privacy protection system and method
CN118427882A