Multi-user hierarchical data cloud storage sharing method and system based on secret sharing
Through the multi-user hierarchical data cloud storage sharing method based on secret sharing, using the secret sharing mechanism and access control server processing, the problem of high communication and computing complexity of the existing cloud storage encrypted data sharing method is solved, and concise and efficient data sharing and key security protection is achieved.
Patent Information
- Application Number
- CN202311866862.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
The existing cloud storage encrypted data sharing method has problems such as large communication overhead, high computing complexity, and equipment overhead not in line with the original intention of saving equipment overhead in the data sharing process, and the implementation process of the existing method is complicated.
The multi-user hierarchical data cloud storage sharing method based on secret sharing is adopted, and the encryption key is stored and protected by the secret sharing mechanism. The access control server performs interpolation, tilt and transposition processing is implemented to realize proxy re-encryption, reduce the key generation center, simplify the workflow, and use simple hashing operations.
It realizes the security protection of keys, simplifies the data sharing process, reduces system interaction, improves computing efficiency and resource utilization, and provides a simple and efficient data sharing solution.
Smart Images

Figure CN120238289A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more particularly to a multi-user hierarchical data cloud storage sharing method and system based on secret sharing. Background Art
[0002] With the development of network and storage technologies, cloud storage has been recognized by the industry as one of the most promising emerging service models. With the help of cloud storage technology, data owners can store local data in the cloud to achieve data sharing with multiple users. To prevent data from being stolen by illegal users, data owners need to take corresponding security measures for the data to ensure the confidentiality of the data.
[0003] Currently, there are mainly three schemes for implementing encrypted data cloud storage sharing: 1) traditional encryption method; 2) attribute-based encryption method; 3) proxy re-encryption method.
[0004] For the first traditional encryption method, the data owner encrypts the data and uploads it to the cloud for storage. When other users request the data, the data owner retrieves the data from the cloud, makes corresponding processing, and then forwards it to other users.
[0005] The second is the attribute-based encryption method. The data owner can use attribute encryption to define an access policy during the data encryption process, and only users who meet this access policy can decrypt the data, thereby realizing the sharing of ciphertexts.
[0006] The third is the proxy re-encryption method, which mainly converts the ciphertext of one user into a ciphertext that another user can decrypt through a proxy server without revealing the user's private key and plaintext information.
[0007] From the current cloud storage encrypted data sharing methods, it can be seen that although the first traditional encryption method reduces the local storage space occupied by the data owner through cloud storage, the data sharing process requires a large amount of communication overhead and computing cost, and it will also occupy the cache space of the data owner during the process, which does not conform to the original intention of users to save device overhead through cloud storage. The second attribute-based encryption method is based on bilinear mapping calculation, and the ciphertext can be decrypted only when the attributes in the user's private key satisfy the access policy of the ciphertext. The attribute-based encryption method is a one-to-many shared data encryption method. The third method, the proxy re-encryption method, mainly converts the ciphertext of one user into a ciphertext that another user can decrypt through a proxy server without revealing the user's private key and plaintext information. The proxy re-encryption method is mainly used for end-to-end data sharing encryption methods. Both the attribute-based encryption method and the proxy re-encryption method are implemented based on the public-private key encryption mechanism, and the implementation process is relatively complex. Summary of the Invention
[0008] In view of the above defects of the prior art, the present invention proposes a multi-user hierarchical data cloud storage sharing method and system based on secret sharing. Among them, the secret sharing mechanism is used to provide storage protection for the encryption key, which can effectively ensure the security of the key; different shared user groups and hierarchical content of shared data are set according to different key shares, which can equivalently implement attribute encryption; the access control server performs interpolation, slicing, transposition and other processes on the external storage key shares, which can efficiently and equivalently implement proxy re-encryption; the key shares are simultaneously used to implement processes such as setting up shared user groups, hierarchical encryption of shared data, two-way authentication between shared users and the access control server, and proxy re-encryption, so that the password resources are fully utilized. In addition, the present invention does not require a key generation center, reduces the interaction process among various roles in the system, and simplifies the work flow; and only simple hash operations are required, so that the password resources are generated more quickly and the calculation is more concise and efficient.
[0009] Specifically, the first aspect of the present invention relates to a multi-user hierarchical data cloud storage sharing method based on secret sharing, which includes a key share generation step, a hierarchical step, a key share distribution step, a data encryption step, an access control list generation step, a data upload step, a user access step and a data decryption step;
[0010] In the key share generation step, the data owner constructs and generates n key shares by using the key K according to the Shamir threshold secret sharing scheme SS(t,n), where t-1 key shares are external storage key shares, and the remaining n-t+1 key shares are reserved key shares;
[0011] In the hierarchical step, the data owner divides the data D into multiple levels of sub-data and classifies the users. Among them, the sub-data of the i-th level and the j-th group is denoted as D ij The users of the i-th level and the j-th group are denoted as U ij where i and j are natural numbers greater than 0;
[0012] In the key share distribution step, the data owner retains one reserved key share and denotes it as K0, and distributes one reserved key share to each group of users U other than the first-level users ij and denotes it as K ij where the user U ij also holds all the key shares distributed to its lower-level users, and the first-level user U 1j only holds the key K;
[0013] In the data encryption step, for each of the other sub-data D other than the first-level sub-data ij the data owner encrypts it by using the corresponding key share K ij to generate a sub-ciphertext E ij =ENC(K ij ,Dij ) and use the key K to encrypt all the first-level sub-data and sub-ciphertext to generate the ciphertext E;
[0014] In the access control list generation step, the data owner uses the key share K ij to generate a hash value H ij corresponding to the user U ij to construct an access control list, which includes the ID of the user U ij and the corresponding hash value H ij ;
[0015] In the data upload step, the data owner uses the reserved key share K0 to generate a hash value H0, uses the hash value H0 to generate a location parameter P0, inserts t - 1 external storage key shares into the ciphertext E according to the location parameter P0 to generate the ciphertext E', and uploads the ciphertext E' and the access control list to the access control server;
[0016] In the user access step, for non-first-level access user U ij , the access control server obtains t - 1 external storage key shares and the ciphertext E from the ciphertext E' according to the location parameter P0; uses the hash value H ij corresponding to the access user U ij to generate a location parameter P ij , inserts t - 1 external storage key shares into the ciphertext E according to the location parameter P ij to generate the ciphertext E", and sends the ciphertext E" to the access user U ij ;
[0017] In the data decryption step, for non-first-level access user U ij , the access user U ij uses its key share K ij to generate a hash value H ij , uses the hash value H ij to generate a location parameter P ij , and obtains t - 1 external storage key shares and the ciphertext E from the ciphertext E" according to the location parameter P ij ; according to the Shamir threshold secret sharing scheme SS(t,n), use the key share K ij and t - 1 external storage key shares to reconstruct and recover the key K; and, use the key K to decrypt the ciphertext E to obtain all the first-level sub-data and sub-ciphertext, and use the key share it holds to decrypt the sub-ciphertext to obtain the sub-data.
[0018] Furthermore, for the first-level access user U 1j: In the user access step, the access control server obtains t - 1 external storage key shares and ciphertext E from ciphertext E’ according to location parameter P0, and sends ciphertext E to access user U 1j ; In the data decryption step, access user U 1j decrypts ciphertext E using key K to obtain all first - level sub - data.
[0019] Further, in the data upload step, ciphertext E’ is uploaded to the access control server in the form of protected data F, and protected data F is formed by slicing and transposing ciphertext E’ based on hash value H0;
[0020] In the user access step, ciphertext E” is sent to the access user in the form of protected data G, where protected data F is restored to ciphertext E’ through slicing and transposing restoration processing based on hash value H0, and then protected data G is formed by slicing and transposing ciphertext E” based on hash value H ij ;
[0021] In the data decryption step, access user U ij also restores protected data G to ciphertext E” based on slicing and transposing restoration processing of hash value H ij ;
[0022] Preferably, the size of ciphertext E is modulo - generated by the value at one or more first preset positions in the hash value to generate the location parameter; and / or, the number of slices for slicing processing and slicing restoration processing is calculated according to the value at one or more second preset positions in the hash value; and / or, the transposition table for transposition processing and transposition restoration processing is determined according to the value at one or more third preset positions in the hash value.
[0023] Further, the multi - user hierarchical data cloud storage sharing method of the present invention further includes a two - way authentication step, which is used to implement two - way authentication between access user U ij and the access control server using the key share K ij of access user U ij before the user access step.
[0024] Further still, in the two - way authentication step: access user U ij generates a random number R ij , calculates the hash value H ij of key share K ij and the hash value a ij of the exclusive - OR value of random number R ij and hash value H ij , and sends the user ID, random number R ij and hash value a ijSend to the access control server; the access control server calculates a random number R ij The exclusive OR value with the hash value H ij The hash value a of the result ij ’, compare it with the received hash value a ij , and pass the user verification when the comparison is consistent; the access control server generates a random number R ij ’ when the user verification is passed, and calculates the hash value H ij The exclusive OR value with the random number R ij ’ to get the hash value S ij , and send the access control server ID, random number R ij ’ and hash value S ij To the access user U ij ; The access user U ij Calculates the hash value H ij The exclusive OR value with the random number R ij ’ to get the hash value S ij ’, compare it with the received hash value S ij , and pass the verification of the access control server when the comparison is consistent.
[0025] Furthermore, the access control server stores the received access control list locally, and sends the protected data F to the erasure code server to store the protected data F in a distributed manner in the cloud storage server by means of the erasure code algorithm.
[0026] Furthermore, the multi-user hierarchical data cloud storage sharing method of the present invention may further include a user maintenance step in which the data owner operates on the access control list.
[0027] The second aspect of the present invention relates to a multi-user hierarchical data cloud storage sharing system based on secret sharing, which includes a data owner client, a data sharer client, and an access control server;
[0028] The data owner client is configured for the above key share generation step, hierarchical step, key share distribution step, data encryption step, access control list generation step, and data upload step, to distribute key shares and / or keys to the data sharer client, and upload ciphertext and access control list to the access control server;
[0029] The access control server is configured to respond to the request of the data sharer client, and send ciphertext to the data sharer client according to the above user access step;
[0030] The data sharer client is configured to decrypt the ciphertext according to the above data decryption step.
[0031] Further, the data sharer client and the access control server are also configured to perform two-way authentication according to the above two-way authentication steps.
[0032] Further, the data owner client is also configured to allow modification of the access control list.
[0033] Further, the multi-user hierarchical data cloud storage sharing system of the present invention may also include an erasure server and a cloud storage server;
[0034] The access control server is also configured to store the received access control list locally and send the protected data F to the erasure server;
[0035] The erasure server is configured to generate a plurality of data blocks based on the protected data F by means of an erasure code algorithm and send them to the cloud storage server;
[0036] The cloud storage server is configured to disperse and process the received data blocks. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 Shows an example of a multi-user hierarchical data cloud storage sharing system based on secret sharing according to the present invention;
[0038] Figure 2 Shows an example of an initial setup process according to the present invention, which employs a secret sharing scheme SS(3,5);
[0039] Figure 3 Shows an example of a key share distribution process according to the present invention;
[0040] Figure 4 Shows an example of interpolation, chunking, and transposition processing in the data upload step according to the present invention;
[0041] Figure 5 Shows an example of a data upload step and an access control list generation step according to the present invention;
[0042] Figure 6 Shows an example of a two-way authentication step according to the present invention;
[0043] Figure 7 Shows an example of a user access step and a data decryption step according to the present invention;
[0044] Figure 8 Shows an example of a user maintenance step of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0045] In the following, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example so as to fully convey the spirit of the present invention to those skilled in the art to which the present invention pertains. Therefore, the present invention is not limited to the embodiments disclosed herein.
[0046] Figure 1 An example of a multi - user hierarchical data cloud storage sharing system based on secret sharing according to the present invention is shown, which includes a data owner client, a data sharer client, an access control server, an erasure server, and a cloud storage server.
[0047] The data owner client may include a secret sharing construction module, a data processing module, and a communication module.
[0048] The data owner can, by reasonably setting the t and n parameters of the Shamir threshold secret sharing scheme, with the help of the secret sharing construction module, according to the Shamir threshold secret sharing scheme SS(t,n), use the key K to construct and generate n key shares. Among them, t - 1 key shares are external storage key shares, and the remaining n - t + 1 key shares are reserved key shares.
[0049] Therefore, the data processing module can classify and group the data D and data sharing users according to the key shares, and generate the ciphertext of the data D using the key and key shares according to the classification and grouping situation, so as to transmit the ciphertext to the access control server through the communication module. At the same time, the key or key shares can also be distributed to the corresponding data sharer clients through the communication module so that the data sharers have the corresponding level of data sharing permissions.
[0050] The data sharer client may include a secret sharing reconstruction module, a data processing module, and a communication module. Among them, the secret sharing reconstruction module can allow the user to reconstruct the key using the key shares, thereby allowing the data processing module to decrypt the ciphertext using the key K and all the key shares it holds to obtain the corresponding plaintext data part.
[0051] The access control server can receive the ciphertext uploaded by the data owner client through the communication module, forward the received ciphertext to the erasure server, and send the ciphertext to the data sharer client in response to the request of the data sharer client.
[0052] The erasure server can use the erasure code algorithm to generate multiple data blocks based on the received ciphertext and send them to the cloud storage server.
[0053] The cloud storage server can then store the received multiple data blocks in a distributed storage manner.
[0054] For a better understanding of the present invention, the following will be based on Figure 1Examples are used to describe the multi - user hierarchical data cloud storage sharing method based on secret sharing of the present invention by way of examples, in order to more clearly illustrate the functions of each component module in the multi - user hierarchical data cloud storage sharing system of the present invention.
[0055] In the multi - user hierarchical data cloud storage sharing method based on secret sharing of the present invention, initial setup work needs to be carried out first, which involves the generation of key shares, and the grading of data and data sharing users according to the generated key shares, etc.
[0056] In the key share generation step, the data owner can, with the help of the data owner's client, construct and generate n key shares using the key K according to the set Shamir threshold secret sharing scheme SS(t,n). Among them, t - 1 key shares are external storage key shares, and the remaining n - t + 1 key shares are reserved key shares.
[0057] Therefore, in the grading step, the data owner can divide the (shared) data D into multiple parts (sub - data) for hierarchical management according to the key shares constructed by the secret sharing scheme, and conduct hierarchical management on data sharing users.
[0058] As an example, in the grading step, data sharing users can be divided into multiple levels according to different data sharing permissions, and multiple different groups can be set within the same level. Among them, the users in the j - th group of the i - th level are denoted as U ij , where i and j are natural numbers greater than 0.
[0059] Data D can be divided into multiple sub - data, and these sub - data are divided into multiple levels and possibly multiple groups within the same level corresponding to user groups. Among them, the sub - data corresponding to the users U ij in the j - th group of the i - th level can be graded as the sub - data of the j - th group of the i - th level, denoted as D ij .
[0060] To achieve the effect of attribute encryption, the present invention also uses the key share distribution step to distribute different key shares (keys) to different user groups.
[0061] Specifically, in the key share distribution step of the present invention, the data owner retains one copy from the reserved key shares and stores it locally, which is denoted as the key share K0. According to the present invention, the key share K0 retained by the data owner will be used to provide services such as re - encryption, which will be described in detail below.
[0062] For the users U 1j in the first level, they will be directly distributed the key K, so they do not hold any key shares.
[0063] For other groups of users U (except those in the first level)ij will be respectively distributed to a reserved key share, denoted as key share K ij .
[0064] Meanwhile, to enable each group of users U ij to also have the sharing permission for the subordinate sub-data, each group of users U ij also holds all the key shares distributed to its subordinate users. For example, assume that there are three user groups U 21 , U 22 and U 23 at the second level. Each user group U 21 , U 22 and U 23 is correspondingly distributed with key shares K 21 , K 22 and K 23 . Then, through the key share distribution step, the third-level user U 31 is not only distributed with the corresponding key share K 31 , but also holds all the key shares K 21 , K 22 and K 23 of its subordinate users.
[0065] After distributing key shares or keys to each user group through the key share distribution step, the present invention can encrypt each sub-data of data D according to the key share distribution situation to ensure the provision of the required data hierarchical sharing service.
[0066] Specifically, in the data encryption step of the present invention, the data owner can, for each of the other sub-data D ij except the first-level sub-data, use the corresponding key share K ij to encrypt it to generate a sub-ciphertext E ij = ENC(K ij , D ij ), and then use the key K to encrypt all the first-level sub-data and sub-ciphertexts to generate a ciphertext E, thereby realizing the hierarchical encryption of sub-data.
[0067] Figure 2 shows an example of the initial setup process according to the present invention, which involves processes such as key share generation, data and user hierarchical classification, key share distribution, and data encryption.
[0068] As Figure 2 shown, the data owner constructs and generates n = 5 key shares K0, K1, K2, K3, and K4 using the key K according to the secret sharing scheme SS(3,5), where: 2 key shares K3 and K4 are external storage key shares, and the remaining 3 key shares K0, K1, and K2 are reserved key shares.
[0069] Data sharing users can be divided into two levels and three groups, namely, users U at the first level (the first group) 11 , users U at the second level and the first group 21 and users U at the second level and the second group 22 .
[0070] Data D is divided into three sub - data D1, D2, and D3, and these sub - data are classified as follows: Sub - data D1 is the first - level sub - data, denoted as sub - data D 11 ; Sub - data D2 is the first - group sub - data at the second level, denoted as sub - data D 21 ; Sub - data D3 is the second - group sub - data at the second level, denoted as sub - data D 22 .
[0071] Through the key - share distribution step, the data owner retains a reserved key - share K0 = K0 by himself. User U 11 is only distributed with key K, and user U 21 is distributed with a reserved key - share K 21 = K1, and user U 22 is distributed with a reserved key - share K 22 = K2.
[0072] When there are multiple users in the same group, these users in the same group will be distributed with the same key - share. For example Figure 3 as shown in 21 : The users U at the second level and the first group include two users, User1 and User2, and both User1 and User2 are distributed with the same key - share K1; The users U at the second level and the second group include two users, User3 and User4, and both User3 and User4 are distributed with the same key - share K2. 22
[0073] See further Figure 2 , in the data encryption step of the present invention, the data owner will use the key - share K 22 = K2 to encrypt sub - data D 22 = D3 to generate sub - ciphertext E 22 = E2 = ENC(K2, D3), use the key - share K 21 = K1 to encrypt sub - data D 21 = D2 to generate sub - ciphertext E 21 = E1 = ENC(K1, D2), and finally use the key K to encrypt all the first - level sub - data D 11 = D1 and sub - ciphertexts E 22 = E2, E 21 = E1 to generate ciphertext E = ENC(K, E2 + E1+D1).
[0074] In the secret sharing scheme, when the data owner uploads the ciphertext, it also needs to upload the external storage key shares. To provide storage protection for the external storage key shares, in the data upload step of the present invention, before uploading the ciphertext and the external storage key shares, the external storage key shares can be inserted into the ciphertext E in a randomly located manner by means of an interpolation operation.
[0075] In the present invention, considering the randomness of the key shares and the uniqueness of the hash values, and the fact that the hash values have a fixed length (for example, the lengths of the hash values generated by the hash functions SHA-256 and SHA-512 are fixed at 256 bits and 512 bits respectively), the interpolation operation of the external storage key shares will be implemented by means of the hash values generated based on the key shares.
[0076] Specifically, in the data upload step, the data owner can generate a hash value H0 = Hash(K0) by performing a hash operation on the key share K0 it retains, and then generate a position parameter P0 based on the hash value H0, so as to insert t - 1 external storage key shares into the ciphertext E according to the position parameter P0 to generate the ciphertext E', providing storage protection for the external storage key shares.
[0077] As an example, the values at one or more first preset positions in the hash value can be modulo the size of the ciphertext E to generate the position parameter.
[0078] Furthermore, the present invention can also randomly cut and transpose the ciphertext E' before uploading the data to provide a proxy re-encryption effect for the uploaded data in an efficient manner.
[0079] In the present invention, based on the characteristic that the hash value length is fixed, the cutting and transposing operations can also be implemented by means of the hash value. Therefore, in the data upload step, the data owner can perform cutting and transposing operations on the ciphertext E' based on the hash value H0 to form the protected data F.
[0080] As an example, the number of cuts (cut restoration) for the cutting operation can be calculated according to the values at one or more second preset positions in the hash value, and the transposition table for the transposition (transposition restoration) operation can be determined according to the values at one or more third preset positions in the hash value.
[0081] Figure 4 Shows an example of the interpolation, cutting and transposing operations in the data upload step according to the present invention, which corresponds to Figure 2 correspondingly.
[0082] Such as Figure 4 shown, the length of the hash value H0 generated by the data owner using the key share K0 it retains is 256 bits.
[0083] In the interpolation operation, the number of data blocks in ciphertext E in units of 2k bytes can be calculated according to Z = (sizeof(E) / (2 * 1024)), where sizeof(E) is the number of bytes of ciphertext E.
[0084] Take the first 32 bits of the hash value H0 as the value X, and calculate the offset byte number x for interpolation according to x = (X mod Z) * 2 * 1024. Therefore, the external storage key shares K3 and k4 can be inserted into ciphertext E at the position corresponding to the offset byte number x to form ciphertext E'.
[0085] In the chunking operation, take the values NUM of the 33rd - 35th bits in the hash value H0, and obtain n = 4 according to n = (NUM mod 3) + 4 (which falls within the preset chunking value range of 4 - 6). Therefore, it is determined that ciphertext E' is cut into 4 data chunks.
[0086] Calculate the number of data blocks in ciphertext E' in units of 2k bytes according to Z' = (sizeof(E') / (2 * 1024)).
[0087] The successive 32 - bit values on the hash value H0 are Y1, …, Yi, i = n - 1, and calculate the size yi of each data chunk i for the chunking operation according to the formula yi = ((Yimod Z' / 2n) + (Z' / 2n)) * 2 * 1024, while the last data chunk y4 = z' - (y1 + y2 + y3). Thus, the size of each data chunk for the chunking operation can be randomly determined.
[0088] In the transposition operation, take the next 10 - bit value of the hash value H0 as the transposition mode MODE. When n takes the value 4, 4! = 24. Therefore, calculate the m value according to the formula m = (MODE mod 23) + 1, and then perform the corresponding transposition operation on the data chunks according to the transposition table found based on the m value (here it is the n = 4 transposition table) to form the protected data F.
[0089] Based on the above description of the process of forming the protected data F from ciphertext E through interpolation, chunking, and transposition operations using the hash value, those skilled in the art can also use the same hash value to perform reduction operations of transposition, chunking, and interpolation on the protected data F to restore the protected data F to ciphertext E. Therefore, the following will not elaborate on this when referring to the reduction operations of interpolation, chunking, and transposition.
[0090] According to the multi - user hierarchical data cloud storage sharing method of the present invention, when uploading ciphertext E' (for example, in the form of protected data F) to the access control server, it is also necessary to upload the access control list L. Therefore, the method of the present invention also includes an access control list generation step.
[0091] In the access control list generation step, the data owner can utilize the key shares K ij distributed to each group of users U ij to generate corresponding hash values H ij , thereby establishing a corresponding list of the IDs of users U ij and their corresponding hash values H ij to generate the access control list L.
[0092] Figure 5 FIG. shows an example of the data upload step and the access control list generation step according to the present invention, which corresponds to Figure 2-3 the relative one.
[0093] In Figure 5 the shown access control list L, the data owner (ID0) corresponds to the hash value H0 generated based on its key share K0, the two users User1 (ID1) and User2 (ID2) in the first group of the second level correspond to the hash value H1 generated based on their key share K1, and the two users User3 (ID3) and User4 (ID4) in the second group of the second level correspond to the hash value H2 generated based on their key share K2.
[0094] Further referring to Figure 5 , after the data owner generates the ciphertext E, the external storage key shares K3 and K4 are inserted into the ciphertext E according to the position parameters generated by using its hash value H0 to generate the ciphertext E'.
[0095] Then, based on the hash value H0, a chunking operation is performed to chunk the ciphertext E' into four data chunks 1, 2, 3, and 4.
[0096] Finally, through a transposition operation based on the hash value H0, the positions of the four data chunks are changed to 4, 3, 1, and 2, thereby forming the protected data F for sending to the access control server.
[0097] Continuing to refer to Figure 5 , as an example, when the access control server receives the protected data F and the access control list L, it can store the access control list L locally and send the protected data F to the erasure server at the same time.
[0098] The erasure server can utilize an erasure code algorithm, such as the EC(5,8) scheme, to split the protected data F and generate redundant chunks to form multiple data chunks, and randomly distribute all the data chunks to the cloud storage servers for distributed storage.
[0099] Preferably, as Figure 5As shown, quantum key distribution (QKD) devices can be deployed on the erasure correction server and the cloud storage server, enabling the generation of highly secure shared quantum keys between the two parties through QKD technology and realizing the encrypted and secure transmission of data between the two parties based on the shared quantum keys.
[0100] In the multi-user hierarchical data cloud storage sharing method of the present invention, a two-way authentication process is also provided, which is used to use the key shares of secret sharing as key resources to realize two-way authentication between the data sharing user and the access control server with the help of the access control list L before allowing the user to access the shared data.
[0101] Access user U ij Before requesting shared data from the access control server, calculate the hash value H ij of the key share K ij , and generate a random number R ij locally and perform an exclusive OR operation with the hash value H ij , and then calculate the hash value a ij = H(R ij ⊕H ij ), and send the user ID, random number R ij and hash value a ij to the access control server.
[0102] After receiving the data, the access control server looks up the corresponding hash value H ij from the access control list L according to the user ID, performs an exclusive OR operation on the random number R ij with the hash value H ij , then calculates the hash value a ij ' of the exclusive OR value, and compares it with the received hash value a ij . When the comparison is consistent, the user is authenticated.
[0103] When the user authentication is passed, the access control server generates a random number R ij ', performs an exclusive OR operation on the hash value H ij with the random number R ij ', then calculates the hash value S ij of the exclusive OR value, and sends the access control server ID, random number R ij ' and hash value S ij to the access user U ij .
[0104] Access user U ij After receiving the data, performs an exclusive OR operation on the hash value H ij with the random number R ij ', and calculates the hash value S ij’, and compare it with the received hash value S ij For comparison, when they are consistent, verify through the access control server, thereby completing the mutual authentication.
[0105] Figure 6 Fig. shows an example of the mutual authentication steps according to the present invention, wherein: the accessing user User1 belongs to the user group U 21 , who holds the key share K 21 = K1.
[0106] As Figure 6 shown, in the mutual authentication step, the user User1 generates a random number R 21 = R1, and uses the key share K 21 = K1 to generate a hash value H 21 = h1 through the Hash function, perform an exclusive OR operation on the hash value h1 and the random number R1, and then generate a hash value a 21 = a1 = H(h1⊕R1) through the Hash function.
[0107] Subsequently, the user User1 sends his own user ID1, hash value a1 and random number R1 to the access control server.
[0108] The access control server queries the access control list L according to ID1 to obtain the hash value h1, performs an exclusive OR operation on the hash value h1 and the received random number R1, and generates a hash value a 21 ’ = a1’ through the Hash function on the exclusive OR value h1⊕R1, and verifies whether the locally generated hash value a1’ is equal to the received hash value a1.
[0109] If the two are equal, the verification is passed and the subsequent process is executed, otherwise the request operation is terminated.
[0110] When the two are equal, the access control server generates a random number R 21 ’ = R2, performs an exclusive OR operation on the random number R2 and the hash value h1, and generates a hash value S 21 = s1 = H(h1⊕R2) through the Hash function, and returns its own IDs, hash value s1 and random number R2 to the user User1.
[0111] The user User1 performs an exclusive OR operation on the received random number R2 and the hash value h1 he holds, and generates a hash value S 21 ’ = s1’ through the Hash function on the exclusive OR value h1⊕R2, and verifies whether the locally generated hash value s1’ is equal to the received hash value s1.
[0112] If the two are equal, the verification is passed, otherwise the process is terminated.
[0113] When the two-way authentication is passed, the user is allowed to request shared data from the access control server through the user access step.
[0114] In the data access step of the present invention, the access control server may, in response to the request of the data sharing user, request the erasure server for, for example, the ciphertext E' in the form of the protected data F.
[0115] When the access control server receives the protected data F, it may restore the protected data F to the ciphertext E' based on the transposition and slicing restoration processing of the hash value H0, and obtain t-1 shares of the external storage key and the ciphertext E from the ciphertext E' by means of the interpolation restoration processing according to the position parameter P0.
[0116] For the access user U who is a level 1 user 1j , the access control server may send the ciphertext E to the access user U 1j .
[0117] For other access users U who are not level 1 users ij , the access control server may utilize the hash value H ij corresponding to the access user U ij to generate the position parameter P ij , and insert t-1 shares of the external storage key into the ciphertext E according to the position parameter P ij to generate the ciphertext E".
[0118] In a preferred example, the access control server may also perform slicing and transposition processing on the ciphertext E" based on the hash value H ij to form the protected data G, and send the ciphertext E" to the access user U in the form of the protected data G ij , so as to provide proxy re-encryption protection for the ciphertext E".
[0119] Further, when the access user receives the ciphertext E or the ciphertext E" (in the form of the protected data G) from the access control server, the corresponding shared data may be obtained through the data decryption step.
[0120] In the data decryption step of the present invention, for the access user U who is a level 1 user 1j , it may directly decrypt the ciphertext E with the key K when receiving the ciphertext E to obtain all the level 1 sub-data.
[0121] For other access users U ij , when receiving the ciphertext E" in the form of the protected data G, it may first perform transposition and slicing restoration processing based on the hash value H ij to restore the protected data G to the ciphertext E".
[0122] Then, based on the hash value H ij generate the position parameter P ij , and obtain t - 1 shares of the external storage key and the ciphertext E from the ciphertext E” according to the position parameter P ij .
[0123] Next, according to the Shamir threshold secret sharing scheme SS(t,n), use the key share K ij and t - 1 shares of the external storage key to reconstruct and recover the key K
[0124] Finally, use the key K to decrypt the ciphertext E to obtain all the first - level sub - data and sub - ciphertexts, and then use all the key shares it holds to decrypt the corresponding sub - ciphertexts to obtain the corresponding sub - data
[0125] Figure 7 shows an example of the user access steps and data decryption steps according to the present invention
[0126] As Figure 7 shown, when the access control server receives the protected data F, it performs transposition and slicing restoration operations based on the hash value h0, so that the positions of the data blocks in the data F are restored to 1, 2, 3, 4, and then restored to the ciphertext E’
[0127] Subsequently, the access control server also performs interpolation restoration operations based on the hash value h0, extracts the external storage key shares K3 and K4 from the ciphertext E’, and obtains the ciphertext E at the same time
[0128] Next, the access control server can perform interpolation operations based on the hash value h1 corresponding to the access user User1, insert the external storage key shares K3 and K4 into the ciphertext E to generate the ciphertext E”, and then perform slicing and transposition operations on the ciphertext E” based on the hash value h1 to form the new protected data G
[0129] When the access user User1 receives the protected data G, based on the hash value h1 generated by using the key share K1 it holds, it performs transposition and slicing restoration operations on the protected data G to restore the protected data G to the ciphertext E”; then based on the hash value h1, it performs interpolation restoration operations on the ciphertext E” to extract the external storage key shares K3 and K4 from the ciphertext E”, and obtains the ciphertext E at the same time
[0130] At this time, the access user User1 can, according to the Shamir threshold secret sharing scheme SS(3,5), use the external storage key shares K3, K4 and the key share K1 it holds to reconstruct and recover the key K, use the key K to decrypt the ciphertext E to obtain the sub - ciphertexts E1, E2 and the sub - data D1, and then use the key share K1 it holds to decrypt the corresponding sub - ciphertext E1 to obtain the second - level sub - data D2
[0131] In the present invention, by establishing an access control list L in the form of a list, the data owner can conveniently maintain users in the hierarchical shared data user group by operating on the access control list, such as adding, modifying, and deleting entries in the access control list.
[0132] Figure 8 An example of the user maintenance steps of the present invention is shown.
[0133] As Figure 8 shown, when the data owner expects to add a new user User5 to the first group of the second level including two users User1 and User2, the key share K1 corresponding to this user group can be distributed to the new user User5, and an entry is newly added to the access control list L, associating the ID5 of the user User5 with the hash value h1 generated based on the key share K1 to form a new access control list L', and sending it to the access control server.
[0134] In summary, the multi-user hierarchical data cloud storage sharing scheme based on secret sharing proposed by the present invention has the technical characteristics of being simple and efficient, more convenient for lightweight deployment, and having the characteristics of attribute-based encryption and proxy re-encryption methods at the same time.
[0135] Specifically, compared with the existing solutions, it has at least the following advantages:
[0136] i. Secret sharing of keys: The key K used for encryption is stored and protected by using the secret sharing mechanism, which can ensure the security of the key.
[0137] ii. Hierarchical shared data: Different data sharing user groups and hierarchical shared data content can be set according to different key shares, equivalently implementing an attribute-based encryption method.
[0138] iii. Proxy re-encryption: The access control server, for example, through its internal data conversion processing module, protects the key share in the form of interpolation in the ciphertext, and equivalently implements an efficient proxy re-encryption method through chunking and transposition processing.
[0139] iv. Rational utilization of password resources: The processes such as the shared user group setting, hierarchical encryption of shared data, two-way authentication between shared users and the access control server, and proxy re-encryption in the present invention are all implemented based on the key shares generated by secret sharing, which can achieve full and reasonable utilization of password resources.
[0140] v. The solution design is simple and efficient: This invention does not require a key generation center, reducing the interaction process among various roles in the system and simplifying the work flow. Different from the complex mathematical methods used in current attribute-based encryption and proxy re-encryption schemes, this invention only needs to use simple hash operations, generating password resources more quickly and calculating more simply and efficiently.
[0141] Although the present invention has been described through specific embodiments in conjunction with the accompanying drawings, it is easy for those skilled in the art to recognize that the above embodiments are merely exemplary, used to illustrate the principle of the present invention and will not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent replacements to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. A multi - user hierarchical data cloud storage sharing method based on secret sharing, which includes a key share generation step, a hierarchical step, a key share distribution step, a data encryption step, an access control list generation step, a data upload step, a user access step, and a data decryption step; In the key share generation step, the data owner constructs and generates n key shares by using the key K according to the Shamir threshold secret sharing scheme SS(t, n), where, t - 1 key shares are external storage key shares, and the remaining n - t + 1 key shares are reserved key shares; In the grading step, the data owner divides the data D into multi-level sub-data and grades the users. Among them, the sub-data of the j-th group at the i-th level is denoted as D ij , and the users of the j-th group at the i-th level are denoted as U ij , where i and j are natural numbers greater than 0; In the key share distribution step, the data owner retains a reserved key share denoted as K0, and distributes a reserved key share denoted as K to each group of users U other than the first-level users. Among them, user U also holds all the key shares distributed to its subordinate users, and the first-level user U only holds the key K. ij Distribute a reserved key share and denote it as K ij , where user U ij also holds all the key shares distributed to its subordinate users, and the first-level user U 1j only holds the key K; In the data encryption step, for each of the other sub-data D other than the first-level sub-data ij , the data owner uses the corresponding key share K ij to encrypt it to generate a sub-ciphertext E ij = ENC(K ij , D ij ), and uses the key K to encrypt all the first-level sub-data and sub-ciphertexts to generate a ciphertext E; In the access control list generation step, the data owner uses the key share K ij to generate a hash value H ij corresponding to the user U ij for constructing an access control list, which includes the ID of the user U ij and the corresponding hash value H ij ; In the data upload step, the data owner uses the reserved key share K0 to generate a hash value H0, uses the hash value H0 to generate a location parameter P0, inserts t - 1 external storage key shares into the ciphertext E according to the location parameter P0 to generate a ciphertext E', and uploads the ciphertext E' and the access control list to the access control server; In the user access step, for an access user U who is not at the first level ij , the access control server obtains t - 1 external storage key shares and ciphertext E from the ciphertext E' according to the location parameter P0; using the hash value H ij corresponding to the access user U ij to generate the location parameter P ij , according to the location parameter P ij insert t - 1 external storage key shares into the ciphertext E to generate the ciphertext E", and send the ciphertext E" to the access user U ij ; In the data decryption step, for an access user U other than the first level ij , the access user U ij uses its key share K ij to generate a hash value H ij , uses the hash value H ij to generate a position parameter P ij , and according to the position parameter P ij obtains t - 1 external storage key shares and the ciphertext E from the ciphertext E”; according to the Shamir threshold secret sharing scheme SS(t, n), uses the key share K ij and t - 1 external storage key shares to reconstruct and recover the key K; and, uses the key K to decrypt the ciphertext E to obtain all the first-level sub-data and sub-ciphertexts, and uses the key share it holds to decrypt the sub-ciphertexts to obtain the sub-data.
2. The multi-user hierarchical data cloud storage and sharing method according to claim 1, wherein, For the access user U at level 1 1j : In the user access step, the access control server obtains t-1 shares of the external storage key and the ciphertext E from the ciphertext E' according to the location parameter P0, and sends the ciphertext E to the accessing user U 1j ; In the data decryption step, access user U 1j Use the key K to decrypt the ciphertext E to obtain all the first-level sub-data.
3. The multi-user hierarchical data cloud storage and sharing method according to claim 1, wherein, In the data upload step, the ciphertext E' is uploaded to the access control server in the form of protected data F, and the protected data F is formed by slicing and transposing the ciphertext E' based on the hash value H0; In the user access step, the ciphertext E” is sent to the accessing user in the form of protected data G. Among them, the protected data F is restored to the ciphertext E’ through the slicing and transposition restoration process based on the hash value H0, and then based on the hash value H ij The ciphertext E” is sliced and transposed to form the protected data G; In the data decryption step, access user U ij also restores the protected data G to the ciphertext E based on the chunking and transposition reduction processing of the hash value H ij ".
4. The multi - user hierarchical data cloud storage sharing method according to claim 3, wherein: The size of the ciphertext E is modulo - taken by using the values at one or more first preset positions in the hash value to generate the location parameter; And / or, According to the values at one or more second preset positions in the hash value, calculate the number of slices for slicing processing and slice restoration processing; And / or, According to the values at one or more third preset positions in the hash value, determine the transposition table for transposition processing and transposition restoration processing.
5. The multi-user hierarchical data cloud storage sharing method according to claim 1 further includes a two-way authentication step, which is used to utilize the key share K ij of the accessing user U ij to implement two-way authentication between the accessing user U ij and the access control server before the user access step.
6. The multi-user hierarchical data cloud storage and sharing method according to claim 5, wherein, In the two - way authentication step: Access user U ij Generate a random number R ij and calculate the key share K ij to obtain the hash value H ij as well as the random number R ij and the exclusive OR value of the hash value H ij to obtain the hash value a ij , and send the user ID, random number R ij and hash value a ij to the access control server; The access control server calculates a random number R ij and the hash value H ij to obtain the hash value a of the exclusive OR value ij ' and compares it with the received hash value a ij for comparison, and passes the user verification when the comparison is consistent; The access control server generates a random number R when the user authentication is passed ij ’, calculates the hash value H ij and the random number R ij ’s hash value S of the exclusive OR value ij , and sends the access control server ID, the random number R ij ’ and the hash value S ij to the access user U ij ; Access user U ij Calculate hash value H ij With random number R ij The hash value S of the exclusive OR value of '' ij '', compare it with the received hash value S ij Make a comparison and, when the comparison is consistent, verify through the access control server.
7. The multi-user hierarchical data cloud storage and sharing method according to claim 3, wherein, The access control server stores the received access control list locally, and sends the protected data F to the erasure - coding server to disperse - store the protected data F in the cloud storage server by means of the erasure - coding algorithm.
8. The multi - user hierarchical data cloud storage sharing method according to claim 1, which further includes a user maintenance step in which the data owner operates on the access control list.
9. A multi - user hierarchical data cloud storage sharing system based on secret sharing, which includes a data owner client, a data sharer client, and an access control server; The data owner client is configured to, according to the key share generation step, hierarchical step, key share distribution step, data encryption step, access control list generation step, and data upload step described in any one of claims 1 - 4, distribute key shares and / or keys to the data sharer client, and upload the ciphertext and the access control list to the access control server; The access control server is configured to, in response to a request from the data sharer client, send the ciphertext to the data sharer client according to the user access step described in any one of claims 1 - 4; The data sharer client is configured to decrypt the ciphertext according to the data decryption step described in any one of claims 1 - 4.
10. The multi-user hierarchical data cloud storage and sharing system according to claim 9, wherein, The data sharer client and the access control server are also configured to perform two - way authentication according to the two - way authentication step described in claim 5 or 6.
11. The multi-user hierarchical data cloud storage and sharing system according to claim 9, wherein, The data owner client is also configured to allow modification of the access control list.
12. The multi - user hierarchical data cloud storage sharing system according to claim 9, which further includes an erasure - coding server and a cloud storage server; The access control server is also configured to store the received access control list locally and send the protected data F to the erasure server; The erasure server is configured to generate multiple data blocks based on the protected data F by means of an erasure code algorithm and send them to the cloud storage server; The cloud storage server is configured to process the received data blocks in a distributed manner.
Citation Information
Cited By
Hard disk encryption adapter for improving security of mobile data in various application scenarios
CN120880660A
A hard disk encryption adapter for improving mobile data security in various application scenarios
CN120880660B