Proxy re-encryption method and system based on secret sharing

Through the proxy re-encryption method based on secret sharing, using Shamir threshold secret sharing scheme and hashing operations, the system complexity and security issues in cloud storage data sharing are solved, and the lightweight and fast data encryption and decryption process is realized, which simplifies the workflow and improves computing efficiency.

CN120238290APending Publication Date: 2025-07-01QUANTUMCTEK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311866875.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

Smart Images

  • Figure CN120238290A_ABST
    Figure CN120238290A_ABST
Patent Text Reader

Abstract

The invention provides a proxy re-encryption method and system based on secret sharing, which are based on a secret sharing mechanism, and can ensure secret sharing secure storage protection of a session key while realizing data proxy re-encryption. A key generation center and public and private keys are not needed, and lightweight and rapid deployment of the system can be realized; the backed-up secret key share is stored along with the ciphertext, and the security of the secret key share is ensured in a mode of inserting a random value into the ciphertext while the storage convenience is realized; the key encryption key, the re-encryption key and the re-decryption key are all replaced by the key share generated by the session key through secret sharing, so that the proxy re-encryption function is realized, and password resources are fully and reasonably applied. In addition, a key generation center is not needed, the interaction process of roles in the system is reduced, and the working process is simplified; and only simple Hash operation is needed, so that the generation of password resources is quicker, and the calculation is simpler.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and more particularly to a proxy re-encryption method and system based on secret sharing. Background Art

[0002] With the development of cloud storage technology, new options are brought for data sharing. However, while cloud storage provides convenience for data sharing, it also brings new challenges - the security issue of shared data. Since most cloud service providers cannot be fully trusted, there is a risk of leakage of users' private data. The most direct solution to this problem is to encrypt the data. To ensure the security of cloud storage data and prevent privacy leakage, the data owner encrypts the uploaded data before uploading it.

[0003] The traditional public key cryptosystem encryption method is not suitable for directly applying to cloud storage data sharing. This is because the usual way of using the public key cryptosystem encryption is that the data owner encrypts the data with its own private key and then uploads it to the cloud storage server, and the data authorized user needs to decrypt the data with the public key of the data owner. This method is not secure for the data in cloud storage because the public key is publicly released. Another way of using is that the data owner encrypts the data with its own public key and then uploads it to the cloud storage server. In this case, the private key of the data owner is required for decryption. If the data owner directly provides its private key to the data authorized user, the leakage of the private key will endanger the identity security of the data owner and more security risks, which is obviously not advisable. The data owner can also first download the encrypted data from the cloud storage server back to the local, decrypt it into plaintext with its own private key, then encrypt the data with the public key of the data authorized user, and then send the encrypted data to the data authorized user. However, this data sharing method brings huge computational overhead to the data owner and occupies communication bandwidth and local storage resources, which also goes against the purpose of using the cloud storage server to store and share data to reduce local overhead. Therefore, the traditional public key cryptosystem encryption method is not suitable for directly applying to cloud storage data sharing.

[0004] Currently, proxy re-encryption technology is generally used for cloud storage data sharing. This cryptographic technology can help data owners achieve secure data sharing of the data stored in the cloud. In proxy re-encryption, a semi-trusted proxy server re-encrypts the ciphertext uploaded by the data owner using a transformation key and sends the re-encrypted ciphertext to the data authorized user. The data authorized user can decrypt this ciphertext with their own private key to obtain the plaintext. During the process of ciphertext re-encryption, the proxy server cannot obtain any information about the plaintext and private key through the ciphertext and the transformation key. Using proxy re-encryption technology, the proxy server can convert the original ciphertext into a ciphertext that can be decrypted by the data authorized user using the transformation key without obtaining the private key of the data owner. During the data sharing process, the data owner does not need to download the data to the local, thus saving costs.

[0005] Figure 1 Fig. shows a traditional proxy re-encryption data sharing scheme, which includes the following main processes:

[0006] 1. Alice (data owner) and Bob (data authorized user) respectively request public-private key pairs from the Key Generation Center (KGC). After receiving the requests, the Key Generation Center (KGC) generates public-private key pairs {pki, ski} and {pkj, skj} respectively and sends them to Alice and Bob.

[0007] 2. Alice encrypts the plaintext M using her public key pki to generate the ciphertext Ci = ENC(pki, M).

[0008] 3. Alice sends the ciphertext Ci to the proxy re-encryption server.

[0009] 4. The proxy re-encryption server is responsible for sending the ciphertext Ci to the cloud storage server for storage.

[0010] 5. To generate the re-encryption key, Bob sends his public key pkj to Alice.

[0011] 6. Alice uses the re-encryption key generation algorithm ReKeyGen with the input system public parameter par, her own private key ski, and Bob's public key pkj as parameters to generate the re-encryption key rkij = ReKeyGen(par, ski, pkj).

[0012] 7. Alice sends the re-encryption key rkij to the proxy re-encryption server.

[0013] 8. The proxy re-encryption server retrieves the ciphertext Ci from the cloud storage server.

[0014] 9. The proxy re-encryption server takes the input system public parameters par, the re-encryption key rkij, and the ciphertext Ci as parameters, and uses the re-encryption algorithm ReEnc to generate a re-encrypted ciphertext Cj = ReEnc(par, rkij, Ci) that can be decrypted by Bob using his own private key skj.

[0015] 10. The proxy re-encryption server sends the re-encrypted ciphertext Cj to Bob.

[0016] 11. After receiving the re-encrypted ciphertext Cj, Bob takes the input system public parameters par, his own private key skj, and the re-encrypted ciphertext Cj as parameters, and uses the re-decryption algorithm ReDec to decrypt the plaintext M = ReDec(par, skj, Cj).

[0017] For efficiency considerations, the data owner generally does not directly encrypt the data using public and private keys, but generates a session key as the encryption key, encrypts the data using a symmetric algorithm, and protects the encryption key using a key encapsulation mechanism (KEM).

[0018] Figure 2 A traditional proxy re-encryption data sharing scheme with a KEM mechanism is shown, and its working process is as follows:

[0019] 1. Alice (data owner) and Bob (data authorized user) respectively request public and private key pairs from the key generation center (KGC). After receiving the requests, the key generation center (KGC) generates public and private key pairs {pki, ski} and {pkj, skj} respectively, and sends them to Alice and Bob.

[0020] 2. Alice generates a session key as the encryption key x, encrypts the plaintext M using a symmetric encryption algorithm, and generates ciphertext data C = ENC(x, M).

[0021] 3. Alice uses her own public key pki to encrypt and encapsulate the encryption key x, and generates ciphertext data Ci = ENC(pki, x).

[0022] 4. Alice sends the ciphertext data C||Ci to the proxy re-encryption server.

[0023] 5. The proxy re-encryption server is responsible for sending the ciphertext data C to the cloud storage server for storage, and locally saves Ci.

[0024] 6. To generate the re-encryption key, Bob sends his public key pkj to Alice.

[0025] 7. Alice uses the re-encryption key generation algorithm ReKeyGen with the input system public parameter par, her own private key ski, and Bob's public key pkj as parameters to generate the re-encryption key rkij = ReKeyGen(par, ski, pkj).

[0026] 8. Alice sends the re-encryption key rkij to the proxy re-encryption server.

[0027] 9. The proxy re-encryption server retrieves the ciphertext data C from the cloud storage server.

[0028] 10. The proxy re-encryption server uses the re-encryption algorithm ReEnc with the input system public parameter par, the re-encryption key rkij, and the locally stored Ci as parameters to generate the re-encrypted ciphertext Cj = ReEnc(par, rkij, Ci) that can be decrypted by Bob using his own private key skj.

[0029] 11. The proxy re-encryption server sends the ciphertext data C || Cj to Bob.

[0030] 12. After receiving the ciphertext data C || Cj, Bob uses the re-decryption algorithm ReDec with the input system public parameter par, his own private key skj, and the re-encrypted ciphertext Cj as parameters to decrypt the encryption key x = ReDec(par, skj, Cj).

[0031] 13. Bob uses the key x to decrypt the ciphertext data C to obtain the plaintext M = Dec(x, C).

[0032] By analyzing the above solution, it can be found that there are at least the following deficiencies in the prior art: Based on the public key system, the system construction and maintenance are relatively troublesome; there are many roles and a lot of communication interactions in the proxy re-encryption workflow; the design and implementation of the re-encryption algorithm and the re-encryption key generation algorithm are complex. Summary of the Invention

[0033] In view of the above deficiencies of the prior art, the present invention proposes a proxy re-encryption method and system based on secret sharing. Based on the secret sharing mechanism, it can ensure the secure storage and protection of the secret sharing of the session key while realizing data proxy re-encryption; it does not require a key generation center and the use of public and private keys, and can realize the lightweight and rapid deployment of the system; the backup key shares are saved together with the ciphertext, which ensures the security of the key shares by inserting random values into the ciphertext while realizing convenient storage; its key encryption key, re-encryption key, and re-decryption key are all replaced by the key shares generated by the session key through secret sharing, which not only realizes the proxy re-encryption function but also makes reasonable use of cryptographic resources. In addition, the present invention does not require a key generation center, reduces the interaction process among various roles in the system, simplifies the work process; and only needs to use simple hash operations, so that the generation of cryptographic resources is faster and the calculation is more concise.

[0034] Specifically, a first aspect of the present invention relates to a proxy re-encryption method based on secret sharing, which includes a key share generation step, a data encryption and upload step, a data download step, and a data decryption step;

[0035] In the key share generation step, the Alice side generates a session key X; and, according to the Shamir threshold secret sharing scheme SS(t,n), uses the session key X to construct and generate n key shares X i , and distributes one of the key shares X j to the Bob side, where j is a natural number and 1 ≤ j ≤ n - t + 1, i = 1,..., n;

[0036] In the data encryption and upload step, the Alice side calculates the hash values H j and H k of the key shares X j and X k , 1 ≤ k ≤ n - t + 1, and k is a natural number different from j; uses the hash value H k to generate a position parameter P k ; encrypts the plaintext M with the session key X to generate a ciphertext C, and inserts t - 1 key shares X k into the ciphertext C according to the position parameter P m to generate a ciphertext C',

[0037] m = n - t + 2,..., n; and, sends the ciphertext C' and the hash values H j and H k to the proxy re-encryption server;

[0038] In the data download step, the proxy re-encryption server uses the hash value H k to generate a position parameter P k , and according to the position parameter Pk Obtain t - 1 key shares X from the ciphertext C'. m and the ciphertext C; utilize the hash value H j to generate the position parameter P j , and according to the position parameter P j insert the t - 1 key shares X m into the ciphertext C to generate the ciphertext C"; and, send the ciphertext C" to the Bob side;

[0039] In the data decryption step, the Bob side calculates the hash value H j of the key share X j , and utilizes the hash value H j to generate the position parameter P j ; according to the position parameter P j obtain t - 1 key shares X from the ciphertext C" m and the ciphertext C; according to the Shamir threshold secret sharing scheme SS(t,n), utilize the key share X j and the t - 1 key shares X m to reconstruct and recover the session key X; and, utilize the session key X to decrypt the ciphertext C to generate the plaintext M.

[0040] Preferably, the position parameter is generated by taking the modulus of the size of the ciphertext C with respect to the value at one or more preset positions in the hash value.

[0041] Preferably, in the data encryption and upload step, the ciphertext C' and the hash values H j and H k are sent to the proxy re - encryption server in the form of a data connection C'||H j ||H k .

[0042] Preferably, in the data encryption and upload step, the proxy re - encryption server stores the received ciphertext C' on the cloud storage server and stores the hash values H j and H k locally; and, in the data download step, the proxy re - encryption server retrieves the ciphertext C' from the cloud storage server.

[0043] Optionally, t = 3, n = 4.

[0044] The second aspect of the present invention relates to a proxy re - encryption system based on secret sharing, which includes an Alice side, a Bob side, and a proxy re - encryption server;

[0045] The Alice side is configured to: generate a session key X; according to the Shamir threshold secret sharing scheme SS(t,n), utilize the session key X to construct and generate n key shares X i, and distribute one of the key shares X j to the Bob side, where

[0046] j is a natural number and 1 ≤ j ≤ n - t + 1, i = 1,..., n; calculate the key shares X j and X k of the hash values H j and H k , 1 ≤ k ≤ n - t + 1, and k is a natural number different from j; use the hash value H k to generate the position parameter P k ; use the session key X to encrypt the plaintext M to generate the ciphertext C, and according to the position parameter P k insert t - 1 key shares X m into the ciphertext C to generate the ciphertext C', m = n - t + 2,..., n; and, send the ciphertext C' and the hash values H j and H k to the proxy re-encryption server;

[0047] The proxy re-encryption server is configured to: use the hash value H k to generate the position parameter P k , and according to the position parameter P k obtain t - 1 key shares X m and the ciphertext C from the ciphertext C'; use the hash value H j to generate the position parameter P j , and according to the position parameter P j insert t - 1 key shares X m into the ciphertext C to generate the ciphertext C"; and, send the ciphertext C" to the Bob side;

[0048] The Bob side is configured to: calculate the hash value H j of the key share X j , and use the hash value H j to generate the position parameter P j ; according to the position parameter P j obtain t - 1 key shares X m and the ciphertext C from the ciphertext C"; according to the Shamir threshold secret sharing scheme SS(t,n), use the key share X j and t - 1 key shares X m to reconstruct and recover the session key X; and, use the session key X to decrypt the ciphertext C to generate the plaintext M.

[0049] Preferably, the position parameter is generated by taking the modulus of the size of the ciphertext C with the value at one or more preset positions in the hash value.

[0050] Preferably, the Alice side is also configured to send the ciphertext C' and the hash value Hj and H k in the form of a data connection C’||H j ||H k and sent to the proxy re-encryption server.

[0051] Furthermore, the proxy re-encryption system of the present invention further includes a cloud storage server; wherein,

[0052] the proxy re-encryption server is further configured to send the received ciphertext C’ to the cloud storage server and locally store the hash value H j and H k ; and,

[0053] the cloud storage server is configured to store the ciphertext C’ and send the ciphertext C’ to the proxy re-encryption server.

[0054] Optionally, t = 3, n = 4. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 Schematically shows a proxy re-encryption data sharing scheme in the prior art;

[0056] Figure 2 Schematically shows a proxy re-encryption data sharing scheme with a KEM mechanism in the prior art;

[0057] Figure 3 Schematically shows an example of a proxy re-encryption method and system based on secret sharing according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0058] Hereinafter, the exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example so as to fully convey the spirit of the present invention to those skilled in the art to which the present invention pertains. Therefore, the present invention is not limited to the embodiments disclosed herein.

[0059] Secret sharing is a cryptographic technique for splitting and storing secrets. Secret sharing splits a secret in an appropriate way, and each split share is managed by a different participant. A single participant cannot recover the secret information, and only a certain number of participants working together can recover the secret information. More importantly, when a small number of these participants have problems, the secret remains secure and available and can be correctly recovered by other participants. For example, the Shamir (t, n) threshold secret sharing scheme SS(t, n) divides a secret into n shares and distributes them to different users. When any t of these shares are obtained, the original secret can be reconstructed, and when fewer than t shares are obtained, the original secret cannot be reconstructed.

[0060] Secret sharing can effectively prevent attacks from external enemies of the system and betrayals by users within the system. Secret sharing can achieve the secure splitting and secure storage of secrets. Considering the utilization efficiency of the storage space for secret shares, secret sharing is more suitable for the secret sharing of small-sized data such as keys, rather than for the secret sharing of large-sized data or files.

[0061] Based on the realization of the secret sharing of keys, the present invention will propose a proxy re-encryption method and system based on secret sharing.

[0062] Figure 3 An example of the proxy re-encryption method and system based on secret sharing according to the present invention is schematically shown.

[0063] As Figure 3 shown, the proxy re-encryption system of the present invention mainly includes an Alice side, a Bob side, a proxy re-encryption server, and a cloud storage server.

[0064] In the present invention, different from the prior art, the Alice side will be both the data owner and the key owner, while the Bob side is both the data authorized user and the key share holder.

[0065] In the present invention, based on this proxy re-encryption system, through steps such as a key share generation step, a data encryption and upload step, a data download step, and a data decryption step, etc., the above-mentioned proxy re-encryption method based on secret sharing can be realized.

[0066] According to the present invention, first, the Alice side can execute the key share generation step and the data encryption and upload step.

[0067] Specifically, in the key share generation step, the Alice side can first generate a session key X for the plaintext M, and then, according to the selected Shamir threshold secret sharing scheme SS(t,n), use the session key X to construct and generate n key shares X i , and distribute one of the key shares X j to the Bob side, where j is a natural number and 1 ≤ j ≤ n - t + 1, i = 1,..., n.

[0068] For example, in Figure 3 the example, after generating the session key X, the Alice side can, according to the selected Shamir threshold secret sharing scheme SS(3,4) it chooses, use the session key X to construct and generate 4 key shares x1, x2, x3, and x4, and distribute one of the key shares x2 to the Bob side.

[0069] Subsequently, in the data encryption and upload step, the Alice side can respectively calculate two of the key shares X jand X k the hash value H of j and H k where 1 ≤ k ≤ n - t + 1 and k is a natural number different from j.

[0070] For example, in Figure 3 the example, the Hash function can be used to perform hash operations on the key shares x1 and x2 respectively to generate the hash values H1 = Hash(x1) and H2 = Hash(x2).

[0071] On this basis, the Alice side can, according to the pre - agreed rules, use the hash value H k to generate the position parameter P k .

[0072] As an example, the size of the ciphertext C can be modulo - taken with the value at one or more preset positions in the hash value to generate the position parameter.

[0073] For example, in Figure 3 the example, the position parameter P1 can be derived by taking the first 16 - bit value in the hash value H1 and then modulo - taking the size of the ciphertext C.

[0074] Therefore, after the Alice side encrypts the plaintext M with the session key X to generate the ciphertext C, according to the position parameter P k insert t - 1 key shares X m into the ciphertext C to generate the ciphertext C’, and send the generated ciphertext C’, together with the hash value H j and H k to the proxy re - encryption server, where m = n - t + 2,..., n.

[0075] As an example, the Alice side can form a data packet C’||H j and H k in the form of a data connection and send it to the proxy re - encryption server. j ||H k

[0076] For example, in Figure 3 the example, after the Alice side encrypts the plaintext M with the session key X to generate the ciphertext C = ENC(X,M), it inserts 2 key shares x3||x4 into the ciphertext C according to the position parameter P1 to form the ciphertext C’, and sends the data C’||H1||H2 to the proxy re - encryption server.

[0077] The proxy re - encryption server, after receiving the ciphertext C’ and the hash value H j and H k ​After the data, the ciphertext C' among them can be sent to the cloud storage server for storage, and the hash values H j and H k are stored locally.

[0078] Therefore, when Bob needs to download and obtain the plaintext M, the proxy re-encryption server can retrieve the ciphertext C' from the cloud storage server and perform the data download step.

[0079] In the data download step, the proxy re-encryption server can, according to the above-mentioned pre-agreed rules, use the hash value H k to generate the position parameter P k , and according to the position parameter P k obtain t - 1 key shares X m and the ciphertext C from the ciphertext C'. That is, the proxy re-encryption server can, according to the position parameter P k , extract t - 1 key shares X m from the ciphertext C', and at the same time restore the ciphertext C' to the ciphertext C.

[0080] For example, in the Figure 3 example, the proxy re-encryption server can derive the position parameter P1 by taking the first 16 bits of the hash value H1 and taking the modulus of the size of the ciphertext C. Subsequently, according to the position parameter P1, the key shares x3||x4 are extracted from the ciphertext C', and at the same time the ciphertext C is obtained.

[0081] On this basis, the proxy re-encryption server can then use another hash value H j , generate the position parameter P j according to the pre-agreed rules, and according to the position parameter P j insert the t - 1 key shares X m into the ciphertext C again to generate the ciphertext C", and send the ciphertext C" to the Bob side.

[0082] For example, in the Figure 3 example, the proxy re-encryption server can derive the position parameter P2 by taking the first 16 bits of the hash value H2 and taking the modulus of the size of the ciphertext C. Subsequently, according to the position parameter P2, the key shares x3||x4 are inserted into the ciphertext C to obtain the ciphertext C", and the ciphertext C" is sent to the Bob side.

[0083] After receiving the ciphertext C", the Bob side can decrypt the ciphertext C" to generate the plaintext M by performing the data decryption step.

[0084] Specifically, in the data decryption step, the Bob side can perform a hash operation on the previously distributed key shares X j to obtain the corresponding hash value H j, and according to the above - mentioned pre - agreed rules, use the hash value H j to generate the position parameter P j .

[0085] For example, in Figure 3 the example of, the Bob side can perform a hash operation on the secret share x2 distributed locally using the Hash function to generate the hash value H2 = Hash(x2). Subsequently, by taking the first 16 - bit value in the hash value H2 and taking the modulus of the size of the ciphertext C, the position parameter P2 is derived.

[0086] On this basis, the Bob side can obtain t - 1 key shares X j from the ciphertext C” according to the position parameter P m and the ciphertext C, and then, according to the Shamir threshold secret sharing scheme SS(t,n), use the key share X j previously distributed to this side and the t - 1 key shares X m extracted from the ciphertext C” to reconstruct and recover the session key X, and use the session key X to decrypt the ciphertext C to generate the plaintext M.

[0087] For example, in Figure 3 the example of, the Bob side can extract the key shares x3||x4 from the ciphertext C” according to the position parameter P2, and at the same time obtain the ciphertext C.

[0088] Then, use the existing key share x2 and the extracted key share x3||x4 to reconstruct and recover the session key X according to the Shamir threshold secret sharing scheme SS(3,4) scheme, and use the session key X to decrypt the ciphertext C to generate the plaintext M = Dec(X,C).

[0089] Based on the above description of the proxy re - encryption scheme based on secret sharing of the present invention, the proxy re - encryption scheme of the present invention and the existing proxy re - encryption schemes are analyzed and compared in the form of a list below, so as to more clearly understand the features and advantages of the present invention.

[0090]

[0091]

[0092]

[0093] In summary, the proxy re - encryption scheme based on secret sharing proposed by the present invention has at least the following advantages over the prior art:

[0094] i. Security protection of the key: Based on the secret sharing mechanism, the present invention can ensure the secure storage protection of the secret sharing of the session key while realizing data proxy re - encryption.

[0095] ii. Implement proxy re-encryption using symmetric cryptography mechanism: Traditional proxy re-encryption schemes are implemented using the asymmetric cryptography mechanism of public and private keys, while the proxy re-encryption mechanism of the present invention uses the symmetric cryptography mechanism. Moreover, the present invention does not require a key generation center, does not need to use public and private keys, can achieve lightweight and rapid deployment of the system, and is more convenient for system implementation and maintenance compared with traditional proxy re-encryption schemes.

[0096] iii. Co-storage protection of key shares and ciphertext: The backup key shares are saved together with the ciphertext. While achieving convenient storage, the method of inserting random values into the ciphertext further ensures the security of the key shares.

[0097] iv. Rational utilization of cryptographic resources: The present invention is implemented based on secret sharing. Its key encryption key, re-encryption key, and re-decryption key are all replaced by key shares generated by secret sharing of the encryption key, which fully realizes the rational application of cryptographic resources while achieving the proxy re-encryption function.

[0098] v. Simplified workflow and more concise calculation: The present invention does not require a key generation center, reduces the interaction process among various roles in the system, and simplifies the workflow. Different from traditional proxy re-encryption schemes that require complex mathematical methods such as homomorphic encryption and bilinear pairing for processes such as re-encryption and re-encryption key generation, the present invention only needs to use simple hash operations, generates cryptographic resources more quickly, and the calculation is more concise.

[0099] Although the present invention has been described above in conjunction with specific embodiments with reference to the accompanying drawings, it is easy for those skilled in the art to recognize that the above embodiments are merely exemplary and are used to illustrate the principle of the present invention, which will not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications, and equivalent replacements to the above embodiments without departing from the spirit and scope of the present invention.

Claims

1. A proxy re-encryption method based on secret sharing, which includes a key share generation step, a data encryption and upload step, a data download step, and a data decryption step; In the secret key share generation step, the session key X is generated at the Alice side; and, according to the Shamir threshold secret sharing scheme SS(t,n), the session key X is used to construct and generate n secret key shares X i , and one of the secret key shares X j is distributed to the Bob side, where j is a natural number and 1 ≤ j ≤ n - t + 1, i = 1, …, n; In the data encryption and upload step, at the Alice side, the key shares X j and X k are respectively calculated for their hash values H j and H k , where k is a natural number and 1 ≤ k ≤ n - t + 1, j ≠ k; the location parameter P k is generated using the hash value H k ; the plaintext M is encrypted using the session key X to generate the ciphertext C, and according to the location parameter P k , t - 1 key shares X m are inserted into the ciphertext C to generate the ciphertext C’, where m = n - t + 2, …, n; and, the ciphertext C’ and the hash values H j and H k are sent to the proxy re-encryption server; In the data download step, the proxy re-encryption server utilizes the hash value H k to generate the location parameter P k , and based on the location parameter P k obtains t - 1 key shares X m and the ciphertext C from the ciphertext C'; utilizes the hash value H j to generate the location parameter P j , and based on the location parameter P j inserts the t - 1 key shares X m into the ciphertext C to generate the ciphertext C"; and, sends the ciphertext C" to the Bob side; In the data decryption step, Bob calculates the key share X j The hash value H j , and use the hash value H j Generate position parameter P j ; According to the position parameter P j Obtain t-1 key shares X from the ciphertext C" m and ciphertext C; according to Shamir threshold secret sharing scheme SS(t,n), using key share X j and t-1 shares of the key X m Reconstruct and recover the session key X; and use the session key X to decrypt the ciphertext C to generate the plaintext M.

2. The proxy re-encryption method according to claim 1, wherein, Generating a position parameter by taking the modulus of the size of the ciphertext C with the value at one or more preset positions in the hash value.

3. The proxy re-encryption method according to claim 1, wherein, In the data encryption and upload step, the ciphertext C' and the hash value H j and H k in the form of a data connection C'||H j ||H k are sent to the proxy re-encryption server.

4. The proxy re-encryption method according to claim 1, wherein, In the data encryption and upload step, the proxy re-encryption server sends the received ciphertext C' to be stored on the cloud storage server and locally stores the hash value H j and H k ; moreover, in the data download step, the proxy re-encryption server retrieves the ciphertext C' from the cloud storage server.

5. The proxy re-encryption method according to any one of claims 1-4, wherein t = 3, n = 4.

6. A proxy re-encryption system based on secret sharing, which includes an Alice side, a Bob side, and a proxy re-encryption server; The Alice side is configured to: generate a session key X; construct and generate n key shares X by using the session key X according to the Shamir threshold secret sharing scheme SS(t, n). i and distribute one of the key shares X j to the Bob side, where j is a natural number and 1 ≤ j ≤ n - t + 1, i = 1, …, n; calculate the key shares X j and X k 's hash values H j and H k , k is a natural number and 1 ≤ k ≤ n - t + 1, j ≠ k; use the hash value H k to generate the position parameter P k ; encrypt the plaintext M with the session key X to generate the ciphertext C, and according to the position parameter P k insert t - 1 key shares X m into the ciphertext C to generate the ciphertext C', m = n - t + 2, …, n; and, send the ciphertext C' and the hash values H j and H k to the proxy re - encryption server; The proxy re-encryption server is configured to: utilize the hash value H k generate the location parameter P k , and based on the location parameter P k obtain t - 1 key shares X m and the ciphertext C from the ciphertext C'; utilize the hash value H j generate the location parameter P j , and based on the location parameter P j insert the t - 1 key shares X m into the ciphertext C to generate the ciphertext C"; and, send the ciphertext C" to the Bob side; Bob is configured to: calculate the key share X j The hash value H j , and use the hash value H j Generate position parameter P j ; According to the position parameter P j Obtain t-1 key shares X from the ciphertext C" m and ciphertext C; according to Shamir threshold secret sharing scheme SS(t,n), using key share X j and t-1 shares of the key X m Reconstruct and recover the session key X; and use the session key X to decrypt the ciphertext C to generate the plaintext M.

7. The proxy re-encryption system according to claim 6, wherein Generating a position parameter by taking the modulus of the size of the ciphertext C with the value at one or more preset positions in the hash value.

8. The proxy re-encryption system according to claim 6, wherein, The Alice side is also configured to send the ciphertext C’ and the hash value H j and H k in the form of a data connection C’||H j ||H k to the proxy re-encryption server.

9. The proxy re-encryption system according to claim 6, further comprising a cloud storage server; wherein, The proxy re-encryption server is also configured to send the received ciphertext C' to the cloud storage server and locally store the hash values H j and H k ; and, The cloud storage server is configured to store the ciphertext C', and send the ciphertext C' to the proxy re-encryption server.

10. The proxy re-encryption system according to any one of claims 6-9, wherein t = 3, n = 4.