Data sharing method based on SM9 attribute-based proxy re-encryption
Through the SM9-based attribute-based proxy re-encryption method, the problem of low static and cross-system collaboration efficiency in the existing technology is solved, fine-grained access control and cross-domain data sharing are realized, dynamic update of access policies is supported, and the national secrets standards are met, and the efficiency and security of data sharing are improved.
Patent Information
- Application Number
- CN202510418870.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-04
AI Technical Summary
The existing attribute-based encryption scheme is inefficient and lacks flexibility in handling policy updates, cross-system collaboration and dynamic permission adjustments, making it difficult to meet the fine-grained access control needs of complex shared scenarios of multiple users, and does not adopt the national secret standards.
The SM9-based attribute-based proxy re-encryption method is adopted to generate the attribute private keys of the data owner and user through the trusted center. The data owner uses the system main public key and access policy to encrypt the original ciphertext. The proxy service provider re-encrypts it, and the data user decrypts the plaintext, which supports dynamic updates of access policies and cross-domain sharing.
It realizes "one-to-many" data sharing with fine-grained access control, supports the replacement of access policies, meets the national secret standards, improves the efficiency and security of data sharing, and can resist ciphertext forgery attacks.
Smart Images

Figure CN120263480A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cryptography, and in particular to a data sharing method based on SM9 attribute-based proxy re-encryption. Background Art
[0002] Attribute-based encryption (ABE) provides fine-grained access control capabilities for the "one-to-many" sharing scenario by binding data access rights to user attributes. However, its practical application still faces multiple challenges: (1) Traditional ABE schemes need to re-encrypt data when dealing with policy updates, cross-system collaboration, and dynamic permission adjustments, which is inefficient and lacks flexibility; (2) The current attribute-based proxy re-encryption technology has not adopted the national cryptographic standard.
[0003] In practical applications, data sharing often involves multiple users rather than a single entity. The expressive ability of conditional proxy re-encryption is limited and difficult to meet the needs of multi-user complex sharing scenarios, that is, it cannot accurately express the diverse permission relationships and dynamically changing access permissions among users. In addition, when the sharing policy needs to be adjusted (such as enterprise business adjustment or user role change), it may involve re-encrypting a large amount of data or regenerating keys. The update process is cumbersome and costly, thus affecting the continuity and efficiency of data sharing. Summary of the Invention
[0004] The purpose of the present invention is to provide a data sharing method based on SM9 attribute-based proxy re-encryption, which can not only meet the "one-to-many" data sharing requirements of fine-grained access control, but also allow the data owner to authorize the proxy service provider to re-encrypt the attribute ciphertext to implement the replacement of the access policy. At the same time, it can meet the security requirements and regulatory requirements of our country and ensure autonomy and controllability.
[0005] A data sharing method based on SM9 attribute-based proxy re-encryption includes:
[0006] The trusted center generates the attribute private key of the data owner and the attribute private key of the data user;
[0007] The data owner encrypts the data using the system public key and a predefined access policy to generate the original ciphertext and sends it to the proxy service provider;
[0008] The proxy service provider re-encrypts the original ciphertext to generate the re-encrypted ciphertext and sends it to the data user;
[0009] The data user decrypts the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext.
[0010] Preferably, before the trusted center generates the attribute private key of the data owner and the attribute private key of the data user, it further includes generating system parameters, specifically:
[0011] System parameter setting algorithm Setup(k, U) → (pp, mpk, msk):
[0012] is an additive cyclic group of order ρ, is a multiplicative cyclic group of order p, where p is a large prime number, and P1, P2 are respectively generators of; e: is a bilinear mapping;
[0013] The trusted center randomly selects hid is the identifier of the encryption private key generation function selected by the trusted center, which is identified by one byte, KDF is the key derivation function selected by the trusted center, and MAC is the message authentication code function selected by the trusted center;
[0014] Set the hash function H2: H3: H4: H5: H6:
[0015] The master private key is msk = (α, a), calculate Let the master public key mpk = (pk1, pk2). The trusted center secretly stores the master private key msk and publicly discloses the master public key mpk and the public parameters
[0016] Preferably, the trusted center generates the attribute private key of the data owner and the attribute private key of the data user, including:
[0017] The user submits a key application to the trusted center and sends the identity information and the attribute set S = {x1,..., x n}, assuming the user has n attributes. The trusted center calculates t1 = H1(ID||hid, p) + α. If t1 = 0, the trusted center re-runs the system parameter setting algorithm, regenerates the system public and private key pairs, and updates the encryption private keys of the existing users;
[0018] Otherwise, randomly select Then calculate the user's private key sk S The calculation formula is as follows:
[0019]
[0020] Finally, output the private key
[0021] Preferably, the data owner encrypts the data using the system master public key and a predefined access policy to generate the original ciphertext and sends it to the proxy service provider, including:
[0022] Taking the LSSS access structure (M, ρ) and the message m ∈ {0, 1}^k as inputs, the specific encryption process is as follows:
[0023] Select β ∈_R {0, 1}^k, compute s = H3(m||β), and randomly select a vector v = (s, y2, …, y n ), where
[0024] For i = 1 to l, compute λ i = v·M i representing the share of the secret value for each attribute;
[0025] Compute the element in the group The element g = e(pk1, P2) in the group , z = g s = e(P1, P2) αs ;
[0026] Compute K1||K2 = KDF(ID||z||c1, klen), where K1 is the first mlen bits and the rest is K2, and compute
[0027] c3 = MAC(c2, K2), MAC being the message authentication code function;
[0028] Select For i = 1 to l, compute
[0029] Compute D = H4(c1||c3||c2, A3, (B1, C1), …, (B l , C l ), (M, ρ)) s ;
[0030] Output the original ciphertext: C (M,ρ) = ((M, ρ), c1||c3||c2, A2, A3, (B1, C1), …, (B l , C l ), D).
[0031] Preferably, before the proxy service provider re - encrypts the original ciphertext to generate a re - encrypted ciphertext and sends it to the data user, it further includes the data owner generating a re - encryption key, specifically:
[0032] Input the private key sk of the data owner S = {K, L, K x}, its corresponding attribute set S, and a LSSS access structure (M′, ρ′). The re-encryption key generation process is expressed as:
[0033] Select β′, δ ∈ R{0,1} k , calculate s′ = H3(δ||β′), randomly select a vector v′ = (s′, y′2,…, y′ n ), where
[0034] For i = 1 to l′, calculate λ′ i = v′·M′ i indicating the share of the secret value occupied by each attribute;
[0035] Calculate the element in the group K′1||K′2 = KDF(ID||z||c′1, klen), where K′1 is the first mlen bits and the rest is K′2, calculate c′3 = MAC(c′2, K′2),
[0036] Select For i = 1 to l′, calculate
[0037] Calculate D′ = H6(c′1||c′3||c′2, A′2, (B′1, C′1),…, (B′ l , C′ l ), (M′, ρ′)) s ′;
[0038] Output the ciphertext C (M′,ρ′) = ((M′, ρ′), A′1, A′2, (B′1, C′1),…, (B′ l , C′ l ), D′);
[0039] Select Calculate rk4 = C (M′,ρ′) ;
[0040] Output the re-encryption key rk S→(M′,ρ′) = (S, rk1, rk2, rk3, rk4, R x ).
[0041] Preferably, the proxy service provider re-encrypts the original ciphertext to generate a re-encrypted ciphertext and sends it to the data user, including:
[0042] Input the re-encryption key rk S→(M′,ρ′)and the original ciphertext C (M,ρ) , let the index set be I = {i: ρ(i) ∈ S}. If the user attribute set S satisfies the access structure (M, ρ), then a set of constants can be found such that ∑i ∈l ω i λ i = s;
[0043] Verify whether the re - encryption key rk s→(M′,ρ′) is a valid re - encryption key for S → (M′, ρ′):
[0044]
[0045] Verify whether the original ciphertext C (M,ρ) is valid:
[0046]
[0047] Calculate:
[0048]
[0049] Output the re - encrypted ciphertext:
[0050]
[0051] Preferably, the data user decrypts the re - encrypted ciphertext with its own attribute private key to obtain the plaintext, including:
[0052] Input the re - encrypted ciphertext and the private key of the data user Let the index set be I′ = {i: ρ′(i) ∈ S′}. If the user attribute set S′ satisfies the access structure (M′, ρ′), then a set of constants can be found such that ∑ i∈I′ ω′ i λ′ i = s′;
[0053] Decrypt the ciphertext C (M′,ρ′) , to obtain the blinding factor δ;
[0054] If
[0055]
[0056] does not hold, output ⊥. If it holds, then calculate:
[0057]
[0058] K′1||K′2 = KDF(ID||hid||z′),
[0059]
[0060] If c′3 = MAC(c′2, K′2) holds, then output the blinding factor δ; otherwise, output ⊥.
[0061] Decrypt the re-encrypted ciphertext Obtain the message m:
[0062]
[0063] K1||K2 = KDF(ID||hid||z′, p),
[0064]
[0065] KDF is a key derivation function. If c3 = MAC(c2, K2) holds, then output the message m; otherwise, output ⊥.
[0066] Preferably, it further includes decrypting the original ciphertext, specifically:
[0067] Input the original ciphertext C (M,ρ) = ((M, ρ), c1||c3||c2, A2, A3, (B1, C1), …, (B l , C l ), D) and the user's private key SK S = {K, L, K x}, Let the index set be I = {i: ρ(i) ∈ S}. If the user attribute set S satisfies the access structure (M, ρ), then a set of constants can be found such that ∑ i∈I ω i λ i = s;
[0068] Verify
[0069] If the equation does not hold, then output ⊥; if it holds, then calculate:
[0070]
[0071] K1||K2 = KDF(ID||hid||z′, p),
[0072]
[0073] If c3 = MAC(c2, K2) holds, then output the message m.
[0074] An SM9-based attribute-based proxy re-encryption data sharing system, comprising:
[0075] A key generation module, used for the trusted center to generate the attribute private key of the data owner and the attribute private key of the data user;
[0076] A raw ciphertext generation module, used for the data owner to encrypt the data using the system public key and a predefined access policy to generate a raw ciphertext and send it to the proxy service provider;
[0077] A re-encrypted ciphertext generation module, used for the proxy service provider to re-encrypt the raw ciphertext to generate a re-encrypted ciphertext and send it to the data user;
[0078] A decryption module, used for the data user to decrypt the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext.
[0079] The beneficial effects of the present invention are as follows: The present invention proposes a data sharing method based on SM9 attribute-based proxy re-encryption, which can not only meet the "one-to-many" data sharing requirements of fine-grained access control, but also allow the data owner to authorize the proxy service provider to re-encrypt the attribute-based ciphertext to achieve the replacement of the access policy. At the same time, it can meet China's own security needs and regulatory requirements to ensure autonomy and control. Moreover, the LSSS matrix access structure used in the present invention can support any monotonic access formula including the "AND" gate access structure, and has stronger access control expression ability. In addition, the present invention meets the security of chosen ciphertext, can effectively resist ciphertext forgery attacks, is more in line with the real attack scenario, and has stronger security. BRIEF DESCRIPTION OF THE DRAWINGS
[0080] The accompanying drawings here are incorporated into the specification and form a part of this specification, indicating the embodiments that conform to the present invention, and are used together with the specification to explain the principles of the present invention.
[0081] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0082] Figure 1 It is a flowchart of a data sharing method based on SM9 attribute-based proxy re-encryption of the present invention;
[0083] Figure 2 It is a structural diagram of a data sharing system based on SM9 attribute-based proxy re-encryption of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0084] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0085] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative position relationship, movement conditions, etc. between components in a specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.
[0086] In addition, the descriptions involving "first", "second", etc. in the present invention are only for descriptive purposes, and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.
[0087] In practical applications, data sharing often involves multiple users rather than a single entity. The expression ability of conditional proxy re-encryption is limited and it is difficult to meet the needs of multi-user complex sharing scenarios, that is, it cannot accurately express the diverse permission relationships and dynamically changing access permissions between users. In addition, when the sharing policy needs to be adjusted (such as enterprise business adjustment or user role change), it may involve re-encryption of a large amount of data or re-generation of keys. The update process is cumbersome and costly, thus affecting the continuity and efficiency of data sharing.
[0088] The present invention proposes a data sharing method based on SM9 attribute-based proxy re-encryption. This method can not only meet the "one-to-many" data sharing requirements of fine-grained access control, but also allow the data owner to authorize the proxy service provider to re-encrypt the attribute-based ciphertext to achieve the replacement of the access policy. At the same time, it can meet the security needs and regulatory requirements of our country to ensure autonomy and control. Moreover, the LSSS matrix access structure used in the present invention can support any monotonic access formula including the "AND" gate access structure, and has stronger expression ability for access control. In addition, the present invention meets the selective ciphertext security, can effectively resist ciphertext forgery attacks, is more in line with the real attack scenario, and has stronger security.
[0089] Embodiment 1
[0090] A data sharing method based on SM9 attribute-based proxy re-encryption, refer to Figure 1 , including:
[0091] S100, the trusted center generates the attribute private key of the data owner and the attribute private key of the data user;
[0092] S200, the data owner encrypts the data using the system master public key and a predefined access policy to generate the original ciphertext and sends it to the proxy service provider;
[0093] S300, the proxy service provider re-encrypts the original ciphertext to generate the re-encrypted ciphertext and sends it to the data user;
[0094] S400, the data user decrypts the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext.
[0095] The present invention discloses an SM9-based attribute-based proxy re-encryption scheme, aiming to solve the problem of static access policies in traditional attribute-based encryption systems, and to realize a fine-grained data access control and a data sharing mechanism that supports dynamic update of access policies. In an attribute-based encryption system, user attributes or access policies are directly embedded in the encryption process, and the decryption permission is determined by an attribute set or a logical policy, so that all users who meet the conditions can decrypt after a single encryption, without the need to encrypt data separately for each user. This good feature has many practical applications in reality, such as cloud storage security, medical data sharing, and e-government. However, in traditional attribute-based encryption systems, the access policy is fixed and cannot be dynamically adjusted, making it difficult to adapt to the authorization requirements of users' real-time attribute changes (such as dynamic information such as identity, role, position, or behavior). Attribute-based proxy re-encryption, on the other hand, can support the update of access policies and achieve dynamic authorization based on attributes. This function that supports dynamic changes in attributes is exactly what many practical applications need. The SM9-based attribute-based proxy re-encryption method proposed by the present invention supports the update of access policies while ensuring the security and privacy of user data, and realizes efficient cross-domain and cross-institutional data sharing. SM9 is a cryptographic algorithm independently developed by our country, which conforms to national cryptographic standards, has independent intellectual property rights, and is not restricted by foreign technologies and policies. The SM9-based attribute-based proxy re-encryption method not only caters to the policy trend of domesticating cryptography, but also can effectively protect the data security of users, promote the flow of data value, and has broad application scenarios and high economic benefits.
[0096] The algorithms of the present invention include: CP-ABPRE-Setup, CP-ABPRE-KeyGen, CP-ABPRE-Encrypt, CP-ABPRE-RKeyGen, CP-ABPRE-ReEncrypt, CP-ABPRE-Decrypt (CP-ABPRE, Ciphertext-Policy Attribute-Based Proxy Re-Encryption). Among them, the CP-ABPRE-Setup algorithm is used to generate the system master public-private key pair and public parameters in the attribute-based proxy re-encryption scheme; the CP-ABPRE-KeyGen algorithm is used to generate the user private key; the CP-ABPRE-Encrypt algorithm is used to encrypt the message to generate the ciphertext; the CP-ABPRE-RKeyGen algorithm is used to generate the re-encryption key; the CP-ABPRE-ReEncrypt algorithm is used to convert the ciphertext containing the predefined access policy into the ciphertext containing the updated access policy; the CP-ABPRE-Decrypt algorithm is used to decrypt the re-encrypted ciphertext to obtain the plaintext message.
[0097] System parameter setup Setup(k, U) → (pp, mpk, msk): Input the security parameter and the universal set of attributes U, and output the public parameters pp and the public-private key pair (mpk, msk) of the trusted key generation center.
[0098] Preferably, before the trusted center generates the attribute private key of the data owner and the attribute private key of the data user, it also includes generating system parameters, specifically:
[0099] System parameter setup algorithm Setup(k, U) → (pp, mpk, msk):
[0100] is an additive cyclic group of order p, is a multiplicative cyclic group of order p, p is a large prime number, P1 and P2 are respectively generators of, e: is a bilinear mapping;
[0101] The trusted center randomly selects hid is the identifier of the encryption private key generation function selected by the trusted center, identified by one byte, KDF is the key derivation function selected by the trusted center, and MAC is the message authentication code function selected by the trusted center;
[0102] Set the hash function H2: H3: H4: H5: H6:
[0103] The master private key is msk = (α, a), and calculate Let the master public key be mpk = (pk1, pk2). The trusted center secretly stores the master private key msk, and publicly discloses the master public key mpk and the public parameters
[0104] User Key Generation KeyGen(pp, msk, S) → sk s : Given the public parameters pp, the private key msk, and an attribute set S that describes the key, output the user's private key skS. Each private key skS is associated with an attribute set S.
[0105] Preferably, the trusted center generates the attribute private key of the data owner and the attribute private key of the data user, including:
[0106] The user submits a key application to the trusted center and sends the identity information and the attribute set S = {x1,..., x n}, assuming the user has n attributes. The trusted center calculates t1 = H1(ID||hid, p) + α. If t1 = 0, the trusted center re-runs the system parameter setting algorithm, re-generates the system public and private key pairs, and updates the encryption private keys of the existing users;
[0107] Otherwise, randomly select Then calculate the user's private key sk S , and the calculation formula is as follows:
[0108]
[0109] Finally, output the private key
[0110] Encryption Enc((M, ρ), m) → C (M,ρ) : Given the LSSS access structure (M, ρ) on the full set of attributes U and the plaintext message m ∈ {0, 1} k , output the original ciphertext C (M,ρ) .
[0111] Preferably, the data owner encrypts the data using the system master public key and a predefined access policy to generate the original ciphertext and sends it to the proxy service provider, including:
[0112] Take the LSSS access structure (M, ρ) and the message m ∈ {0, 1} k as the input. The specific encryption process is expressed as:
[0113] Select β ∈ R {0, 1} k , calculate s = H3(m||β), and randomly select a vector v = (s, y2,..., yn ), where
[0114] For \(i = 1\) to \(l\), calculate \(\lambda\) i \(= v\cdot M\) i indicating the share of the secret value occupied by each attribute;
[0115] Calculate the element in the group The group The element \(g = e(pk1, P2)\) in the group, \(z = g\) s \(= e(P1, P2)\) αs ;
[0116] Calculate \(K1||K2 = KDF(ID||z||c1, klen)\), where \(K1\) is the first \(mlen\) bits and the rest is \(K2\), calculate
[0117] \(c3 = MAC(c2, K2)\), where \(MAC\) is a message authentication code function;
[0118] Select For \(i = 1\) to \(l\), calculate
[0119] Calculate \(D = H4(c1||c3||c2, A3, (B1, C1), \ldots, (B\) l , C l ), (M, \rho)) s ;
[0120] Output the original ciphertext: \(C\) (M,ρ) \(= ((M, \rho), c1||c3||c2, A2, A3, (B1, C1), \ldots, (B\) l , C l ), D)\).
[0121] Re-encryption key generation \(ReKeyGen(sk\) S , S, (M', \rho')) \to rk S→(M′,ρ′) : Input the private key \(sk\) of the data owner S and the attribute set \(S\) corresponding to the private key \(sk\) of the data owner S and the LSSS access structure \((M', \rho')\) on the universal attribute set \(U\), output the re-encryption key \(rk\) S→(M′,ρ′) . Among them, \((M, \rho)\) and \((M', \rho')\) are disjoint.
[0122] Preferably, before the proxy service provider re-encrypts the original ciphertext to generate a re-encrypted ciphertext and sends it to the data user, it also includes the data owner generating a re-encryption key, specifically:
[0123] The private key sk of the input data owner S ={K, L, K x}, its corresponding attribute set S, and an LSSS access structure (M′, ρ′). The re-encryption key generation process is as follows:
[0124] Select β′, δ ∈ R{0, 1} k , compute s′ = H3(δ||β′), and randomly select a vector v′ = (s′, y′2, …, y′ n ), where
[0125] For i = 1 to l′, compute λ′ i = v′·M′ i represents the share of the secret value occupied by each attribute;
[0126] Compute the element in the group K′1||K′2 = KDF(ID||z||c′1, klen), where K′1 is the first mlen bits and the rest is K′2, and compute c′3 = MAC(c′2, K′2),
[0127] Select For i = 1 to l′, compute
[0128] Compute D′ = H6(c′1||c′3||c′2, A′2, (B′1, C′1), …, (B′ l , C′ l ), (M′, ρ′)) s′ ;
[0129] Output the ciphertext C (M′,ρ′) = ((M′, ρ′), A′1, A′2, (B′1, C′1), …, (B′ l , C′ l ), D′);
[0130] Select Compute rk4 = C (M′,ρ′) ;
[0131] Output the re-encryption key rk S→(M′,ρ′) = (S, rk1, rk2, rk3, rk4, R x ).
[0132] Re-encryption Input the re-encryption key rkS→(M′,ρ′) and the original ciphertext C (M,ρ) , if then output the re-encrypted ciphertext
[0133] Preferably, the proxy service provider re-encrypts the original ciphertext to generate a re-encrypted ciphertext and sends it to the data user, including:
[0134] Input the re-encryption key rk S→(M′,ρ′) and the original ciphertext C (M,ρ) , let the index set be l = {i: ρ(i) ∈ S}. If the user attribute set S satisfies the access structure (M, ρ), then a set of constants can be found such that ∑ i∈I ω i λ i = s;
[0135] Verify the re-encryption key rk S→(M′,ρ′) whether it is a valid re-encryption key for S → (M′, ρ′):
[0136]
[0137] Verify the original ciphertext C (M,ρ) whether it is valid:
[0138]
[0139] Calculate:
[0140]
[0141] Output the re-encrypted ciphertext:
[0142]
[0143] Decrypt the re-encrypted ciphertext Input the attribute set S′ and the corresponding private key sk S′ , if then output the plaintext message m.
[0144] Preferably, the data user decrypts the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext, including:
[0145] Input the re-encrypted ciphertext and the private key of the data user Let the index set be I′ = {i: ρ′(i) ∈ S′}. If the user attribute set S′ satisfies the access structure (M′, ρ′), then a set of constants can be found such that ∑ i∈I′ ω′ i λ′i = s′;
[0146] Decrypt the ciphertext C (M′,ρ′) to obtain the blinding factor δ;
[0147] If
[0148]
[0149] does not hold, output ⊥, if it holds, then calculate:
[0150]
[0151] K′1||K′2 = KDF(ID||hid||z′),
[0152]
[0153] If c′3 = MAC(′2,K′2) holds, then output the blinding factor δ, otherwise output ⊥;
[0154] Decrypt the re - encrypted ciphertext to obtain the message m:
[0155]
[0156] K1||K2 = KDF(ID||hid||z′,p),
[0157]
[0158] KDF is a key - derivation function. If c3 = MAC(c2,K2) holds, then output the message m, otherwise output ⊥.
[0159] Decrypt the original ciphertext Dec(S,sk S ,C (M,ρ) ) → m: Input the attribute set S and its corresponding private key sk S and the original ciphertext C (M,ρ) , if then output the plaintext message m.
[0160] Preferably, it further includes decrypting the original ciphertext, specifically:
[0161] Input the original ciphertext C (M,ρ) = ((M,ρ),c1||c3||c2,A2,A3,(B1,C1),…,(B l ,C l ),D) and the user's private key SK S = {K,L,K x} and set the index set Let \(I = \{i:\rho(i)\in S\}\). If the user attribute set \(S\) satisfies the access structure \((M,\rho)\), then a set of constants can be found such that \(\sum\) i∈I \(\omega\) i \(\lambda\) i \(= s\);
[0162] Verify
[0163] If the equation does not hold, then output \(\perp\); if it holds, then calculate:
[0164]
[0165] \(K1||K2 = KDF(ID||hid||z',p)\),
[0166]
[0167] If \(c3 = MAC(c2,K2)\) holds, then output the message \(m\).
[0168] Example 2
[0169] An SM9-based attribute-based proxy re-encryption data sharing system, referring to Figure 2 , includes:
[0170] A key generation module for the trusted center to generate the attribute private key of the data owner and the attribute private key of the data user;
[0171] A raw ciphertext generation module for the data owner to encrypt the data using the system master public key and a predefined access policy to generate a raw ciphertext and send it to the proxy service provider;
[0172] A re-encrypted ciphertext generation module for the proxy service provider to re-encrypt the raw ciphertext to generate a re-encrypted ciphertext and send it to the data user;
[0173] A decryption module for the data user to decrypt the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext.
[0174] The system of the present invention includes four modules, namely: a trusted authority (TA), User A, an agent, and User B. User A is the ciphertext conversion client; the agent is responsible for storing the attribute-based ciphertexts of all users. If the access policy of User A changes, then the agent converts the attribute-based ciphertexts and forwards the converted ciphertexts to the corresponding users; User B is responsible for receiving the converted ciphertexts and decrypting them. First, the TA generates the public parameters in the attribute-based proxy re-encryption scheme and makes the parameters public. Then, the TA uses the public parameters to generate the public and private key pairs of the users respectively, makes the public keys public, and secretly sends the private keys to the users. After that, other users who want to communicate with User A confidentially encrypt the messages using the system master public key and the attribute-based access policy, generate attribute-based ciphertexts, and send the attribute-based ciphertexts to the agent for storage and management. Due to the needs of their own lives or work, if the predefined access policy of User A changes, then at this time User A uses its own attribute set, its own private key, and the updated access policy to generate a re-encryption key, and secretly sends the key to the agent. After receiving the re-encryption key sent by User A, the agent uses the key to convert the ciphertexts that satisfy the access policy and forwards the converted ciphertexts to User B. After receiving the converted ciphertexts, User B decrypts the ciphertexts using its own attribute set and private key.
[0175] The present invention proposes a data sharing method based on SM9 attribute-based proxy re-encryption. This method can not only meet the "one-to-many" data sharing requirements of fine-grained access control, but also allow the data owner to authorize the proxy service provider to re-encrypt the attribute-based ciphertexts to achieve the replacement of the access policy. At the same time, it can meet the security needs and regulatory requirements of our country to ensure autonomy and control. Moreover, the LSSS matrix access structure used in the present invention can support any monotonic access formula including the "AND" gate access structure, and has stronger access control expression ability. In addition, the present invention satisfies chosen-ciphertext security, can effectively resist ciphertext forgery attacks, is more in line with real attack scenarios, and has stronger security.
[0176] The above are only the specific implementation manners of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A data sharing method based on SM9 attribute-based proxy re-encryption, characterized in that Including: The trusted center generates the attribute private key of the data owner and the attribute private key of the data user; The data owner encrypts the data using the system master public key and a predefined access policy to generate the original ciphertext and sends it to the proxy service provider; The proxy service provider re-encrypts the original ciphertext to generate the re-encrypted ciphertext and sends it to the data user; The data user decrypts the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext.
2. The data sharing method based on SM9 attribute-based proxy re-encryption according to claim 1, wherein Before the trusted center generates the attribute private key of the data owner and the attribute private key of the data user, it also includes generating system parameters, specifically: System parameter setting algorithm Setup(k,U)→(pp,mpk,msk): is an additive cyclic group of order p, is a multiplicative cyclic group of order p, where p is a large prime number, and P1, P2 are respectively generators of is a bilinear mapping; The trusted center randomly selects hid is the identifier of the encryption private key generation function selected by the trusted center, which is identified by one byte. KDF is the key derivation function selected by the trusted center, and MAC is the message authentication code function selected by the trusted center; Set a hash function The master secret key is msk = (α, a), and calculate Let the master public key be mpk = (pk1, pk2). The trusted center secretly stores the master secret key msk and publishes the master public key mpk and the public parameters 3. A data sharing method based on SM9 attribute-based proxy re-encryption according to claim 1, characterized in that The trusted center generating the attribute private key of the data owner and the attribute private key of the data user includes: The user submits a key application to the trusted center and sends the identity information and the attribute set S = {x1, …, x n}, assuming the user has n attributes, the trusted center calculates t1 = H1(ID||hid,p) + α. If t1 = 0, the trusted center re-runs the system parameter setting algorithm, regenerates the system public and private key pairs, and updates the encryption private keys of the existing users; Otherwise, randomly select Then calculate the user's private key sk S , and the calculation formula is as follows: Finally output the private key 4. A data sharing method based on SM9 attribute-based proxy re-encryption according to claim 1, characterized in that The data owner using the system master public key and a predefined access policy to encrypt the data to generate the original ciphertext and send it to the proxy service provider includes: Taking the LSSS access structure (M,ρ) and the message m∈{0,1}k as inputs, the specific encryption process is expressed as: Select β ∈ R {0, 1} k , compute s = H3(m||β), randomly select a vector v = (s, y2, …, y n ), where For i = 1 to l, calculate λ i = v·M i Indicates the share of the secret value occupied by each attribute; Computational group Elements in Group The element g = e(pk1, P2) in the group, z = g s = e(P1, P2) αs ; Calculate K1||K2 = KDF(ID||z||c1,klen), where K1 is the first mlen bits and the rest is K2, and calculate c3 = MAC(c2, K2), MAC is a message authentication code function; Select For i = 1 to l, calculate Calculate D = H4(c1||c3||c2, A3, (B1, C1), …, (B l , C l ), (M, ρ))s; Output the original ciphertext: C (M,ρ) = ((M, ρ), c1||c3||c2, A2, A3, (B1, C1), …, (B l , C l ), D).
5. A data sharing method based on SM9 attribute-based proxy re-encryption according to claim 1, characterized in that Before the proxy service provider re-encrypts the original ciphertext to generate the re-encrypted ciphertext and sends it to the data user, it also includes the data owner generating the re-encryption key, specifically: The private key sk of the input data owner S ={K, L, K x}, its corresponding attribute set S, and an LSSS access structure (M′, ρ′). The re-encryption key generation process is expressed as: Select β′, δ ∈ R {0, 1}k, compute s′ = H3(δ || β′), randomly select a vector v′ = (s′, y′2, …, y′ n ), where For i = 1 to l′, calculate λ′ i = v′·M′ i Indicates the share of the secret value occupied by each attribute; Computation group Elements in K′1||K′2 = KDF(ID||z||c′1, klen), where K′1 is the first mlen bits and the rest is K′2, compute Select For i = 1 to l′, calculate Compute D′ = H6(c′1||c′3||c′2,A′2,(B′1,C′1),…,(B′l,C′l),(M′,ρ′)) s′ ; Output ciphertext C (M′,ρ′) = ((M′, ρ′), A′1, A′2, (B′1, C′1), …, (B′ l , C′ l ), D′); Select Calculate rk4 = C (M′,ρ′) ; Output re-encryption key rk S→(M′,ρ′) =(S, rk1, rk2, rk3, rk4, R x ) 6. The data sharing method based on SM9 attribute-based proxy re-encryption according to claim 5, wherein The proxy service provider re-encrypting the original ciphertext to generate the re-encrypted ciphertext and sending it to the data user includes: Input the re-encryption key rk S→(M′,ρ′) and the original ciphertext C (M,ρ) , let the index set be I = {i: ρ(i) ∈ S}. If the user attribute set S satisfies the access structure (M, ρ), then a set of constants can be found such that ∑ i∈I ω i λ i = s; Verify the re-encryption key rk S→(M′,ρ′) is a valid re-encryption key for S → (M′, ρ′): Verify the original ciphertext C ( M, ρ ) Whether it is valid: Calculate: Output the re-encrypted ciphertext:
7. A data sharing method based on SM9 attribute-based proxy re-encryption according to claim 6, characterized in that The data user decrypting the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext includes: Input re-encrypted ciphertext and the private key of the data user Let the index set be I′ = {i: ρ′(i) ∈ S′}. If the user attribute set S′ satisfies the access structure (M′, ρ′), then a set of constants can be found such that ∑ i∈I′ ω′ i λ′ i = s′; Decrypt the ciphertext C (M′,ρ′) to obtain the blinding factor δ; If does not hold, output ⊥, if it holds, then calculate: K′1||K′2 = KDF(ID||hid||z′), If c′3 = MAC(c′2,K′2) holds, then output the blinding factor δ, otherwise output ⊥; Decrypted and re-encrypted ciphertext Obtain message m: K1||K2 = KDF(ID||hid||z′,p), KDF is a key derivation function. If c3 = MAC(c2,K2) holds, then output the message m, otherwise output ⊥.
8. A data sharing method for attribute-based proxy re-encryption based on SM9 according to claim 1, characterized in that, It also includes decrypting the original ciphertext, specifically: Input the original ciphertext C (M,ρ) = ((M, ρ), c1||c3||c2, A2, A3, (B1, C1), …, (B l , C l ), D) and the user's private key SK S = {K, L, K x}}, let the index set be I = {i: ρ(i) ∈ S}. If the user attribute set S satisfies the access structure (M, ρ), then a set of constants can be found such that ∑ i∈I ω i λ i = s; Verification If the equation does not hold, then output ⊥; if it holds, then calculate: K1||k2 = KDF(ID||hid||z′,p), If c3 = MAC(c2,K2) holds, then output the message m.
9. An attribute-based proxy re-encryption data sharing system based on SM9, characterized in that Including: A key generation module for the trusted center to generate the attribute private key of the data owner and the attribute private key of the data user; An original ciphertext generation module for the data owner to encrypt the data using the system master public key and a predefined access policy to generate the original ciphertext and send it to the proxy service provider; A re-encrypted ciphertext generation module for the proxy service provider to re-encrypt the original ciphertext to generate the re-encrypted ciphertext and send it to the data user; A decryption module for the data user to decrypt the re-encrypted ciphertext according to its own attribute private key to obtain the plaintext.
Citation Information
Cited By
Distributed data storage method and system based on attribute proxy re-encryption and secret key sharing
CN121150948A
Trusted data space construction method, equipment, storage medium and system
CN121356911A