Data sharing method based on proxy re-encryption

Through proxy re-encryption technology that sets public and private keys for data owners and organizations, the problems of complex key management and inflexible permission control in traditional encryption solutions are solved, and efficient and secure data sharing among multi-level organizations are achieved.

CN120281541APending Publication Date: 2025-07-08INSPUR GENERSOFT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510464012.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

Traditional encryption solutions have problems such as complex key management, high risk of data leakage and inflexible permission control in data sharing, especially in data sharing scenarios between multi-level organizations.

Method used

A proxy re-encryption technology is used to set public and private keys for data owners, primary and secondary organizations respectively, and through hierarchical management mechanisms and permission verification, secure data transmission and flexible access control are achieved.

Benefits of technology

It simplifies the key management process, reduces the risk of data leakage, enhances data security and privacy protection, and provides a flexible access control mechanism suitable for efficient data sharing among multi-level organizations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281541A_ABST
    Figure CN120281541A_ABST
Patent Text Reader

Abstract

The invention discloses a data sharing method based on proxy re-encryption, which is used for a data owner to share data to a first-level organization and a second-level organization, and comprises the following steps: respectively setting a public key and a private key for the data owner, the first-level organization and the second-level organization; encrypting the authorization information and the public key of the second-level organization through the private key of the second-level organization, and transmitting the encrypted data to the first-level organization; according to the encrypted data, after authentication, the authentication information and the private key of the secondary organization are re-encrypted through the private key of the primary organization, and the re-encrypted data is transmitted to the data owner; and according to the re-encrypted data, after authentication, based on the shared data, performing encryption through a public key of the secondary organization, and transmitting the encrypted shared data to the secondary organization. Through the proxy re-encryption technology and the hierarchical management mechanism, the key management is simplified, the data security and privacy protection are enhanced, and the confidentiality and integrity of the data in the transmission process are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data sharing, and particularly relates to a data sharing method based on proxy re-encryption. Background Art

[0002] In modern information society, the security and privacy protection of data are of crucial importance. Especially in the data sharing scenarios within an enterprise or across organizations, how to ensure that data is not leaked during the transmission process and only authorized users can access the data has become an urgent problem to be solved. Although traditional encryption schemes can protect the confidentiality of data to a certain extent, there are some limitations in data sharing.

[0003] Proxy re-encryption allows a proxy to re-encrypt ciphertext from one key to another key. This technology can effectively solve the limitations of traditional encryption schemes in data sharing, but still faces some challenges. For example, in traditional encryption schemes, once the original key is shared with the recipient, the data owner loses control of the data, increasing the risk of data leakage.

[0004] In addition, in a large-scale data sharing environment, managing a large number of keys is a cumbersome task. Especially when multiple levels of organizations are involved, the distribution and management of keys become more complex. Moreover, traditional encryption schemes are difficult to provide a flexible access control mechanism, such as dynamically adjusting data access permissions according to the roles or permissions of users. Usually, it cannot provide fine-grained permission control and is difficult to meet the complex organizational structure and multi-level data access requirements. Summary of the Invention

[0005] The present invention provides a data sharing method based on proxy re-encryption to solve the problems of data leakage caused by the sharing of the original key in traditional encryption schemes, the complex management caused by a large amount of key data in a large-scale data sharing environment, and the lack of flexibility caused by the lack of fine-grained permission control for users.

[0006] The technical solution adopted by the present invention is as follows:

[0007] A data sharing method based on proxy re-encryption is used for a data owner to share data with a first-level organization and a second-level organization, where the second-level organization is a subordinate unit of the first-level organization. The method includes:

[0008] Set public keys and private keys for the data owner, the first-level organization, and the second-level organization respectively;

[0009] Encrypt the authorization information and public key of the second-level organization with the private key of the second-level organization, and transmit the encrypted data to the first-level organization;

[0010] According to the encrypted data, after authentication, re-encrypt the authentication information and the private key of the secondary organization using the private key of the primary organization, and transmit the re-encrypted data to the data owner;

[0011] According to the re-encrypted data, after authentication, encrypt it based on the shared data using the public key of the secondary organization, and transmit the encrypted shared data to the secondary organization.

[0012] The data sharing method based on proxy re-encryption in the present invention further includes the following additional technical features:

[0013] The public key and the private key are specifically:

[0014] Encrypt and decrypt data using the public key and the private key,

[0015] Among them, when encrypting data using the public key, decrypt it using the private key;

[0016] When encrypting data using the public key, decrypt it using the private key.

[0017] Set a private key for the data owner, the primary organization, and the secondary organization one by one, where the private key is unique to each level of unit;

[0018] Set a public key for the data owner, the primary organization, and the secondary organization one by one,

[0019] Among them, the public key is shared by each level of unit; or,

[0020] The public key of the lower-level unit is shared with the superior unit to which it belongs.

[0021] The authentication of the encrypted data is specifically:

[0022] Decrypt the encrypted data using the public key of the secondary organization;

[0023] Authenticate the authorization information of the secondary organization. When the secondary organization is an authorized unit, the encrypted data passes the authentication.

[0024] When the encrypted data passes the authentication, re-encrypt the authentication information and the private key of the secondary organization using the private key of the primary organization,

[0025] Among them, the authentication information further includes the authorization information of the primary organization.

[0026] The authentication of the re-encrypted data is specifically:

[0027] When the encrypted data passes the authentication and the primary organization is an authorized entity, the re-encrypted data passes the authentication and a data sharing operation is performed.

[0028] Encrypt using the public key of the secondary organization and transmit the encrypted shared data to the secondary organization. Specifically,

[0029] Transmit the encrypted shared data directly to the secondary organization; or transmit the encrypted shared data to the primary organization, and then to the secondary organization;

[0030] Decrypt the encrypted shared data using the private key of the secondary organization to obtain the shared data.

[0031] The data sharing method based on proxy re-encryption further includes:

[0032] Generate authorization information for the primary organization using the private key of the data owner to authorize the primary organization;

[0033] Generate authorization information for the secondary organization using the private key of the secondary organization to authorize the secondary organization.

[0034] When authorization is revoked, revoke the authorization of the secondary organization by the primary organization, and / or

[0035] Revoke the authorization of the primary organization by the data owner.

[0036] The present invention also provides an electronic device, including:

[0037] A memory for storing computer instructions;

[0038] A processor for implementing the data sharing method based on proxy re-encryption when executing the computer instructions.

[0039] Due to the adoption of the above technical solution, the beneficial effects obtained by the present invention are:

[0040] 1. In the present invention, the data sharing method based on proxy re-encryption is used for a data owner to share data with a primary organization and a secondary organization, where the secondary organization is a subordinate unit of the primary organization. The method includes: respectively setting public keys and private keys for the data owner, the primary organization, and the secondary organization. By respectively setting public keys and private keys for the data owner, the primary organization, and the secondary organization and using proxy re-encryption technology, the present invention significantly reduces the complexity of key management.

[0041] Specifically, the data owner only needs to manage their own key pair, rather than the key pairs associated with each recipient. This design significantly reduces the burden of key management because the data owner no longer needs to worry about key distribution or the risk of data leakage caused by improper key management.

[0042] Through the above method, the present invention simplifies the key management process. The data owner can focus on managing their own key pair and is responsible for handling complex encryption and decryption operations, thus achieving an efficient and secure data sharing mechanism. This design is particularly suitable for large-scale data sharing scenarios involving multi-level organizations and effectively solves the key management problems existing in traditional encryption schemes.

[0043] 2. In the present invention, the authorization information and public key of the secondary organization are encrypted using the private key of the secondary organization, and the encrypted data is transmitted to the primary organization; after authentication based on the encrypted data, the authentication information and the private key of the secondary organization are re-encrypted using the private key of the primary organization, and the re-encrypted data is transmitted to the data owner; after authentication based on the re-encrypted data, the shared data is encrypted using the public key of the secondary organization, and the encrypted shared data is transmitted to the secondary organization. By introducing proxy re-encryption technology and a hierarchical management mechanism, the present invention significantly enhances the security and privacy protection capabilities of data, ensuring that the data owner can securely share encrypted data with others without exposing the original private key, thereby always maintaining control over the data.

[0044] Specifically, proxy re-encryption technology allows the data owner to re-encrypt encrypted data into a form that can be decrypted by a specific recipient without directly sharing their private key. Even during the data sharing process, the data owner can still maintain control over the data. This means that the data owner can dynamically adjust the authorization scope, revoke access permissions, or restrict data access for specific users as needed, without worrying about the risk of key leakage. In addition, the data owner can monitor and record all authorization operations and data access situations to ensure the overall security and privacy of the data.

[0045] In summary, the present invention realizes effective control of data through proxy re-encryption technology, avoiding the problem of loss of data control rights caused by key sharing. This design not only improves the security and privacy protection level of data but also provides a more flexible and secure solution for data sharing between multi-level organizations.

[0046] 3. In the present invention, the authorization information and public key of the secondary organization are encrypted using the private key of the secondary organization, and the encrypted data is transmitted to the primary organization; based on the encrypted data, after authentication, the authentication information and the private key of the secondary organization are re-encrypted using the private key of the primary organization, and the re-encrypted data is transmitted to the data owner; based on the re-encrypted data, after authentication, the shared data is encrypted using the public key of the secondary organization, and the encrypted shared data is transmitted to the secondary organization. By using the proxy re-encryption technology, the present invention significantly improves the security of data during the transmission process.

[0047] Specifically, after receiving a data request from a subordinate organization, the request information is first decrypted using the public key of the superior organization to obtain the authorization information and the public key of the subordinate organization. Then, the required data is encrypted and transformed using the public key of the subordinate organization to ensure that only the subordinate organization holding the corresponding private key can decrypt and read the data content.

[0048] This mechanism ensures the confidentiality and integrity of data throughout the transmission process. Through the proxy re-encryption technology, the data is re-encrypted into a form that can be decrypted by a specific recipient (i.e., the subordinate organization) without exposing the original private key. In this way, even if the data is intercepted during the transmission process, the attacker cannot decrypt the data because only the subordinate organization holding the corresponding private key can decrypt it.

[0049] Moreover, decrypting the request information using the public key of the superior organization ensures the authenticity and integrity of the request information. This step verifies the legitimacy of the request and prevents man-in-the-middle attacks or other forms of data tampering.

[0050] In summary, through the proxy re-encryption technology and strict permission verification mechanism, the present invention effectively solves the security risks existing in the traditional encryption scheme during the data transmission process. It ensures the confidentiality and integrity of data during the transmission process, enabling the data owner and organizations at all levels to share and manage data in a highly secure environment.

[0051] 4. As a preferred implementation mode of the present invention, the authorization information of the first-level organization is generated through the private key of the data owner to authorize the first-level organization; the authorization information of the second-level organization is generated through the private key of the second-level organization to authorize the second-level organization. When the authorization is canceled, the authorization of the second-level organization is canceled by the first-level organization, and / or the authorization of the first-level organization is canceled by the data owner. The present invention realizes flexible and efficient multi-level data access control by adopting a hierarchical authorization method. Specifically, the superior organization can authorize the subordinate organization at one time, and the subordinate organization manages the access rights of its members by itself. This mechanism significantly simplifies the authentication and authorization process, while being able to provide a high degree of authorization granularity to facilitate authorization control.

[0052] First, when authorizing, the superior organization only needs to authorize the subordinate organization once, without having to manage the permissions of the subordinate organization's internal members one by one. This not only reduces the number of operation steps and management costs, but also ensures the consistency and accuracy of permission settings. Second, after obtaining authorization, the subordinate organization can flexibly manage and adjust the access rights of internal members according to its own needs, which enhances the flexibility and adaptability of permission control.

[0053] In addition, when authorization needs to be revoked, the data owner or the superior organization only needs to revoke the authorization of the subordinate organization to immediately terminate the subordinate organization and its members’ access to the data. This design not only simplifies the permission revocation process, but also avoids the cumbersome operations and potential errors caused by revoking permissions one by one.

[0054] In summary, the present invention effectively solves the challenges faced by traditional technical solutions in dealing with complex organizational structures and multi-level data access requirements through a hierarchical authorization mechanism. It not only simplifies the authentication and authorization process, but also provides highly fine-grained permission control, allowing data owners and superior organizations to ensure data security and privacy while maintaining efficient management. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0056] Figure 1 The figure is a flow chart of the data sharing method based on proxy re-encryption in one embodiment of the present invention. DETAILED DESCRIPTION

[0057] In order to more clearly illustrate the overall concept of the present invention, a detailed description is given below in an exemplary manner in conjunction with the accompanying drawings.

[0058] In the following description, many specific details are set forth in order to provide a thorough understanding of the present invention. However, the present invention may be practiced in other ways different from those described herein. Therefore, the scope of protection of the present invention is not limited by the specific embodiments disclosed below.

[0059] As Figure 1 shown, a data sharing method based on proxy re-encryption is used for a data owner to share data with a primary organization and a secondary organization, where the secondary organization is a subordinate unit of the primary organization. The method includes:

[0060] S100: Set public keys and private keys for the data owner, the primary organization, and the secondary organization respectively.

[0061] The main purpose of this step of setting public keys and private keys for the data owner, the primary organization, and the secondary organization respectively is to ensure the security and privacy protection of data during the sharing process. By using the key pair technology (i.e., public key and private key), secure data transmission and access control can be achieved, while reducing the complexity of key management.

[0062] It should be noted that a data owner refers to an entity (individual or organization) that owns and controls a specific data set. The data owner is responsible for generating and managing the data and deciding who can access the data and their access rights.

[0063] The primary organization is a direct subordinate unit of the data owner and usually has higher permissions. It can request access rights from the data owner and further allocate permissions to subordinate units (such as secondary organizations).

[0064] The secondary organization is a subordinate unit of the primary organization and usually has lower permissions. It needs to obtain access rights through the primary organization.

[0065] It can be understood that the data owner, the primary organization, and the secondary organization are only unit classifications in terms of data management. The data owner is the data owner, and the primary organization and the secondary organization are data requesters. The data owner shares data with the primary organization and / or the secondary organization.

[0066] In this step, each participating party (data owner, primary organization, and secondary organization) generates a unique pair of public key and private key. The public key and private key are used for encrypting and decrypting data. In this way, even if the data is intercepted during transmission, the attacker cannot decrypt the data because only the participating party holding the corresponding private key can decrypt the data.

[0067] In this step, it includes generating a key pair:

[0068] Each participating party (data owner, first-level organization, second-level organization) generates a pair of public and private keys respectively. These key pairs can be generated through standard encryption algorithms such as RSA or Elliptic Curve Cryptography (ECC).

[0069] Secondly, distribute the public keys:

[0070] Each participating party distributes the generated public key to other relevant parties. For example, the public key of the data owner is sent to the first-level organization, the public key of the first-level organization is sent to the second-level organization and the data owner, and the public key of the second-level organization is sent to the superior organization and the data owner. The public key can be distributed in a secure manner, such as through pre-shared or digital certificates issued by a Certificate Authority (CA).

[0071] Finally, store the private keys:

[0072] Each participating party stores its private key securely and strictly controls access rights to prevent the leakage of private keys. The private key should be stored in a secure environment, such as a Hardware Security Module (HSM) or a trusted secure storage device.

[0073] It can be understood that before each data transmission, the receiving party needs to verify whether the public key of the sending party comes from a trusted source. This is usually achieved through digital certificate chain verification to ensure the authenticity of the public key. By using their respective public and private keys, each participating party can achieve fine-grained access control during the data sharing process. For example, the data owner can dynamically adjust the authorization scope as needed and revoke the access rights of specific users.

[0074] In summary, the basic step of setting public keys and private keys for the data owner, first-level organization, and second-level organization respectively in this step is the foundation of the entire data sharing method. It not only simplifies key management but also significantly enhances data security and privacy protection capabilities, making efficient and secure data sharing between multi-level organizations possible.

[0075] S200: Encrypt the authorization information and public key of the second-level organization with the private key of the second-level organization, and transmit the encrypted data to the first-level organization.

[0076] The main purpose of this step is to ensure the confidentiality and integrity of the authorization information and public key of the second-level organization during transmission. By encrypting with the private key of the second-level organization, it can prevent unauthorized third parties from intercepting or tampering with this information, thus ensuring data security and privacy.

[0077] In this step, the secondary organization encrypts its authorization information and public key with its private key and sends the encrypted data to the primary organization. After receiving the encrypted data, the primary organization can decrypt it using the public key of the secondary organization to verify the authenticity and integrity of the information. This mechanism not only protects the security of the data but also ensures the credibility of the information source.

[0078] In this step, it includes generating authorization information:

[0079] The secondary organization generates authorization information containing access permissions.

[0080] Secondly, encrypt the authorization information and public key:

[0081] The secondary organization encrypts the authorization information and its public key with its own private key. This step ensures that even if the data is intercepted during transmission, attackers cannot decrypt or tamper with this information.

[0082] Thirdly, transmit the encrypted data:

[0083] The encrypted data is transmitted to the primary organization through a secure channel. This secure channel can be an encrypted communication protocol (such as TLS / SSL) or other secure transmission methods.

[0084] Finally, receive and decrypt the data:

[0085] After receiving the encrypted data, the primary organization decrypts it using the public key of the secondary organization to obtain the original authorization information and public key. This step verifies the authenticity and integrity of the data and ensures that the information has not been tampered with.

[0086] It should be noted that after receiving the encrypted data, the primary organization first needs to verify the authenticity of the data. This is usually done by decrypting it using the public key of the secondary organization. If the decryption is successful and the information content meets the expectations, the data is considered to be authentic.

[0087] The primary organization also needs to verify whether the permission requirements of the secondary organization are reasonable. For example, check whether the secondary organization has the right to request specific data access permissions and whether its request complies with the preset access control policy.

[0088] Through the above steps, the present invention ensures the security and credibility of the authorization information and public key during transmission, simplifies the permission management process, and at the same time improves the transparency and traceability of the system.

[0089] S300: According to the encrypted data, after authentication, re-encrypt the authentication information and the private key of the secondary organization with the private key of the primary organization, and transmit the re-encrypted data to the data owner.

[0090] The main purpose of this step is to ensure the confidentiality and integrity of the authentication information and the private key of the secondary organization during transmission. By re-encrypting using the private key of the primary organization, unauthorized third parties can be prevented from intercepting or tampering with this information, thus ensuring data security and privacy. In addition, this process also verifies the authenticity and legality of the request, ensuring that only authorized entities can access the data.

[0091] In this step, the primary organization authenticates the received encrypted data (verifying its authenticity and integrity), then re-encrypts the authentication information and the private key of the secondary organization using its private key, and sends the re-encrypted data to the data owner. After receiving the re-encrypted data, the data owner can decrypt it using the public key of the primary organization to obtain the original authentication information and the private key of the secondary organization.

[0092] This step includes receiving and authenticating the encrypted data:

[0093] The primary organization receives the encrypted data sent by the secondary organization. Decrypts the encrypted data using the public key of the secondary organization to obtain the authorization information and the public key of the secondary organization. Verifies the authenticity and integrity of the authorization information to ensure that the information has not been tampered with.

[0094] Secondly, generate the authentication information:

[0095] The primary organization generates authentication information containing the authentication result, confirming the identity and permission requirements of the secondary organization.

[0096] Thirdly, re-encrypt the authentication information and the private key of the secondary organization:

[0097] The primary organization re-encrypts the authentication information and the private key of the secondary organization using its private key. This step ensures that even if the data is intercepted during transmission, attackers cannot decrypt or tamper with this information.

[0098] Thirdly, transmit the re-encrypted data:

[0099] The re-encrypted data is transmitted to the data owner through a secure channel. This secure channel can be an encrypted communication protocol (such as TLS / SSL) or other secure transmission methods.

[0100] Finally, receive and decrypt the data:

[0101] After receiving the re-encrypted data, the data owner decrypts it using the public key of the primary organization to obtain the original authentication information and the private key of the secondary organization. The data owner verifies the authenticity and integrity of the data to ensure that the information has not been tampered with.

[0102] It should be noted that after receiving the re-encrypted data, the data owner first needs to verify the authenticity of the data. This is usually done by decrypting using the public key of the first-level organization. If the decryption is successful and the information content meets the expectations, the data is considered authentic.

[0103] The data owner also needs to verify whether the authentication result of the first-level organization is reasonable. For example, check whether the second-level organization has the right to request specific data access permissions and whether its request complies with the preset access control policy.

[0104] Through the above steps, the present invention ensures the security and credibility of the authentication information and the private key of the second-level organization during the transmission process, simplifies the permission management process, and improves the transparency and traceability of the system.

[0105] S400: According to the re-encrypted data, after authentication, based on the shared data, encrypt using the public key of the second-level organization and transmit the encrypted shared data to the second-level organization.

[0106] The main purpose of this step is to ensure the confidentiality and integrity of the shared data during the transmission process. By encrypting the shared data using the public key of the second-level organization, it can prevent unauthorized third parties from intercepting or tampering with this data, thus ensuring the security and privacy of the data. In addition, this process also verifies the authenticity and legality of the request, ensuring that only authorized entities can access the data.

[0107] In this step, the proxy server authenticates the received re-encrypted data (verifying its authenticity and integrity), then encrypts the shared data using the public key of the second-level organization based on the shared data, and sends the encrypted shared data to the second-level organization. After receiving the encrypted data, the second-level organization can use its private key to decrypt it to obtain the original shared data.

[0108] In this step, it includes receiving and authenticating the re-encrypted data:

[0109] The proxy server receives the re-encrypted data sent by the first-level organization. Decrypt the re-encrypted data using the public key of the first-level organization to obtain the authentication information and the private key of the second-level organization. Verify the authenticity and integrity of the authentication information to ensure that the information has not been tampered with.

[0110] Secondly, prepare the shared data:

[0111] The data owner generates the data to be shared according to the authentication result.

[0112] Thirdly, encrypt the shared data:

[0113] The proxy server encrypts the shared data using the public key of the secondary organization. This step ensures that even if the data is intercepted during transmission, attackers cannot decrypt or tamper with it.

[0114] Again, transmit the encrypted shared data:

[0115] The encrypted shared data is transmitted to the secondary organization through a secure channel. This secure channel can be an encrypted communication protocol (such as TLS / SSL) or other secure transmission methods.

[0116] Finally, receive and decrypt the data:

[0117] After receiving the encrypted shared data, the secondary organization decrypts it using its private key to obtain the original shared data. The secondary organization verifies the authenticity and integrity of the data to ensure that the information has not been tampered with.

[0118] It should be noted that after receiving the re-encrypted data, the proxy server first needs to verify the authenticity of the data. This is usually done by decrypting it using the public key of the primary organization. If the decryption is successful and the information content meets the expectations, the data is considered authentic.

[0119] The proxy server also needs to verify whether the secondary organization has the right to access specific shared data. For example, check whether the identity and permission requirements of the secondary organization comply with the preset access control policy.

[0120] Through the above steps, the present invention ensures the security and credibility of the shared data during transmission, simplifies the permission management process, and improves the transparency and traceability of the system.

[0121] As a preferred embodiment of the present invention, the public key and the private key are specifically

[0122] Data encryption and decryption are performed through the public key and the private key.

[0123] Among them, when data is encrypted using the public key, it is decrypted using the private key;

[0124] When data is encrypted using the public key, it is decrypted using the private key.

[0125] The main purpose of this embodiment is to ensure the confidentiality and integrity of the data during transmission. By using the key pair technology (i.e., public key and private key), unauthorized third parties can be prevented from intercepting or tampering with the data, thus ensuring the security and privacy of the data. This mechanism also allows the data owner to securely share the encrypted data with others without exposing their private key.

[0126] The key pair includes a public key and a private key. Both the public key and the private key can be used for encrypting and decrypting data. Each participant has its own key pair.

[0127] When encrypting data with the public key, decrypt with the private key. For example, encrypt the authorization information and public key of the secondary organization with the private key of the secondary organization, and transmit the encrypted data to the primary organization. After receiving the encrypted data, the primary organization decrypts the encrypted data with the public key of the secondary organization.

[0128] When encrypting data with the public key, decrypt with the private key. Based on the shared data, encrypt with the public key of the secondary organization, and transmit the encrypted shared data to the secondary organization. After receiving the encrypted shared data, the secondary organization decrypts it with its private key to obtain the shared data.

[0129] Through the above steps, the public key and private key are used for encrypting and decrypting data, ensuring the security and privacy protection of data during transmission.

[0130] As a preferred embodiment of this implementation manner, a private key is set for the data owner, the primary organization, and the secondary organization one by one, where the private key is unique to each level of unit;

[0131] A public key is set for the data owner, the primary organization, and the secondary organization one by one,

[0132] wherein, the public key is shared by each level of unit; or,

[0133] The public key of the lower-level unit is shared with its superior unit.

[0134] The main purpose of this embodiment is to ensure that each participant (data owner, primary organization, secondary organization) has a unique private key for encrypting and decrypting data, and at the same time has a corresponding public key for decrypting and encrypting data. This mechanism improves the level of data security and privacy protection.

[0135] Specifically, in this embodiment, each participant (such as the data owner, the primary organization, and the secondary organization) generates its own public key and private key respectively. The private key is unique to each level of unit and is strictly confidential.

[0136] Based on the shared data, it is encrypted using the public key of the secondary organization, and the encrypted shared data is transmitted to the secondary organization. When the secondary organization receives the encrypted shared data, it decrypts it using the private key of the secondary organization to obtain the shared data. Since the private key of the secondary organization is unique to the secondary organization, even if the primary unit or other units obtain the encrypted shared data, they cannot decrypt it without the corresponding private key and thus cannot obtain the shared data. This ensures the security and controllability of the data and prevents the data from being obtained by unauthorized persons or organizations.

[0137] The public key can be publicly distributed to other relevant parties, or in some cases, the public key of a lower-level unit can be shared with a higher-level unit. For example, the public key of the data owner is sent to the primary organization and the proxy server, the public key of the primary organization is sent to the secondary organization and the proxy server, and the public key of the secondary organization can be sent to its higher-level organization and the proxy server.

[0138] Alternatively, the public key of the secondary organization can be sent to its higher-level organization and the proxy server, while the public key of the primary organization is sent to the proxy server and not to the secondary organization which is its subordinate unit.

[0139] Using the private key of the secondary organization, the authorization information and public key of the secondary organization are encrypted, and the encrypted data is transmitted to the primary organization. After receiving the encrypted data, the primary organization needs to obtain the public key of the secondary organization to decrypt the encrypted data for verifying the authorization information.

[0140] Through the above steps, a unique private key and public key are set for each participating party to ensure the security and privacy protection of the data during transmission.

[0141] As a preferred embodiment of the present invention, the authentication of the encrypted data is specifically as follows

[0142] Decrypt the encrypted data using the public key of the secondary organization;

[0143] Authenticate the authorization information of the secondary organization. When the secondary organization is an authorized unit, the encrypted data passes the authentication.

[0144] The main purpose of this step is to verify the authenticity and integrity of the encrypted data and ensure that only authorized secondary organizations can access and decrypt the data. By decrypting using the public key of the secondary organization and verifying its authorization information, unauthorized entities can be prevented from accessing sensitive data, thus ensuring the security and privacy of the data.

[0145] Among them, to decrypt the encrypted data, use the public key of the secondary organization to decrypt the encrypted data to obtain the original data.

[0146] Authentication and authorization information is used to verify the authorization information of the secondary organization and confirm whether it has the right to access and process the data. If the secondary organization is an authorized entity, the encrypted data passes the authentication and further processing is allowed; otherwise, access is denied.

[0147] Specifically, in this embodiment, it includes receiving encrypted data:

[0148] The primary organization receives the encrypted data sent by the secondary organization.

[0149] Secondly, decrypt the encrypted data:

[0150] Use the public key of the secondary organization to decrypt the encrypted data to obtain the original authorization information and other relevant data.

[0151] Thirdly, authenticate the authorization information:

[0152] Check the authenticity of the authorization information. Verify the signature by using the public key of the secondary organization to verify the digital signature of the authorization information to ensure that it has not been tampered with; check the permissions. According to the preset access control policy, check whether the secondary organization has the right to request specific data access permissions.

[0153] Thirdly, transmit the decrypted data:

[0154] If the authentication is successful, the proxy server or the primary organization will pass the decrypted data to the corresponding processing party (such as the data owner or other superior organizations).

[0155] Through the above steps, use the public key of the secondary organization to decrypt the encrypted data and authenticate its authorization information to ensure the security and privacy protection of the data during transmission.

[0156] As a preferred embodiment of the present invention, when the encrypted data passes the authentication, re-encrypt the authentication information and the private key of the secondary organization by using the private key of the primary organization,

[0157] wherein, the authentication information further includes the authorization information of the primary organization.

[0158] The main purpose of this step is to ensure the confidentiality and integrity of the authentication information and the private key of the secondary organization during transmission. By using the private key of the primary organization to re-encrypt these information, it can prevent unauthorized third parties from intercepting or tampering with these data, thus ensuring the security and privacy of the data. In addition, this process also verifies the authenticity and legality of the request to ensure that only authorized entities can access the data.

[0159] In this embodiment, it includes receiving and authenticating encrypted data:

[0160] The primary organization receives the encrypted data sent by the secondary organization. It decrypts the encrypted data using the public key of the secondary organization to obtain the original authorization information and other relevant data.

[0161] Authentication authorization information:

[0162] Verify the authorization information of the secondary organization to confirm whether it has the right to access and process the data. If the secondary organization is an authorized entity, the encrypted data passes the authentication.

[0163] Generate new authentication information:

[0164] The primary organization generates new authentication information containing the authentication result to confirm the identity and permission requirements of the secondary organization. This new authentication information also includes the authorization information of the primary organization itself.

[0165] Re-encrypt the authentication information and the private key of the secondary organization:

[0166] The primary organization re-encrypts the newly generated authentication information and the private key of the secondary organization using its private key. This step ensures that even if the data is intercepted during transmission, the attacker cannot decrypt or tamper with this information.

[0167] Transmit the re-encrypted data:

[0168] The re-encrypted data is transmitted to the data owner through a secure channel.

[0169] Receive and decrypt the data:

[0170] After receiving the re-encrypted data, the data owner decrypts it using the public key of the primary organization to obtain the original authentication information and the private key of the secondary organization. The data owner verifies the authenticity and integrity of the data to ensure that the information has not been tampered with.

[0171] It can be understood that after receiving the re-encrypted data, the data owner or other relevant parties first need to verify the authenticity of the data. This is usually done by decrypting it using the public key of the primary organization. If the decryption is successful and the information content meets the expectations, the data is considered authentic.

[0172] The data owner also needs to verify whether the authentication result of the primary organization is reasonable. For example, check whether the secondary organization has the right to request specific data access permissions and whether its request complies with the preset access control policy.

[0173] Through the above steps, the authentication information and the private key of the secondary organization are re-encrypted using the private key of the primary organization to ensure the security and privacy protection of the data during transmission.

[0174] As a preferred embodiment of this implementation manner, the authentication of the re-encrypted data is specifically

[0175] When the encrypted data passes authentication and the primary organization is an authorized entity, the re-encrypted data passes authentication, and a data sharing operation is performed.

[0176] The main purpose of this embodiment is to ensure that in the multi-level data sharing process, only authenticated and authorized entities can access and process data. By verifying the authenticity of the encrypted data and the authorization status of the primary organization, the security and legality of the data are ensured, preventing unauthorized access and tampering.

[0177] Among them, for authenticating the encrypted data, it is verified whether the received encrypted data comes from a legitimate sender (such as a secondary organization), and it is confirmed that it has not been tampered with.

[0178] For verifying the authorization status of the primary organization, it is checked whether the primary organization has the right to further authorize and perform data sharing operations for the secondary organization.

[0179] Re-encrypt the data and pass authentication. Use the private key of the primary organization to re-encrypt the authentication information and the private key of the secondary organization, and verify the authenticity of these information again.

[0180] Perform the data sharing operation. If all authentication steps pass, the data sharing operation is performed to ensure that the data is securely transmitted to the final recipient (such as a secondary organization).

[0181] Specifically, use the public key of the primary organization to decrypt the encrypted data to obtain the original authorization information and other relevant data. Verify the authenticity and integrity of the authorization information to ensure that the information has not been tampered with. Check whether the identity and permission requirements of the primary organization comply with the preset access control policy. If the primary organization is an authorized entity, the encrypted data passes authentication.

[0182] Through the above steps, the security and legality of the data during the transmission process are ensured.

[0183] As a preferred implementation manner under the present invention, it is encrypted by the public key of the secondary organization, and the encrypted shared data is transmitted to the secondary organization. Specifically,

[0184] The encrypted shared data is directly transmitted to the secondary organization; or, the encrypted shared data is transmitted to the primary organization and then transmitted to the secondary organization;

[0185] Use the private key of the secondary organization to decrypt the encrypted shared data to obtain the shared data.

[0186] The main purpose of this step is to ensure that the encrypted shared data can be securely transmitted to the final recipient (i.e., the secondary organization), and the secondary organization decrypts it using its private key to obtain the original shared data. According to specific requirements and system design, data transmission can be carried out directly or through the relay of the primary organization to ensure data security and privacy protection.

[0187] Among them, the direct transmission method is that the encrypted shared data can be directly transmitted from the data owner or proxy server to the secondary organization.

[0188] The indirect transmission method is that the encrypted shared data can be relayed through the primary organization and then transmitted to the secondary organization. This method can increase flexibility and control in certain situations.

[0189] The method of decrypting data is that after receiving the encrypted shared data, the secondary organization decrypts it using its private key to obtain the original shared data.

[0190] Example 1: Adopt the direct transmission method.

[0191] Generate encrypted shared data: The data owner or proxy server encrypts the shared data using the public key of the secondary organization to generate encrypted shared data.

[0192] Transmit the encrypted shared data: Send the encrypted shared data directly to the secondary organization.

[0193] Receive and decrypt the data: After receiving the encrypted shared data, the secondary organization decrypts the received encrypted data using its private key to obtain the original shared data.

[0194] Example 2: Adopt the indirect transmission method.

[0195] Generate encrypted shared data: The data owner or proxy server encrypts the shared data using the public key of the secondary organization to generate encrypted shared data.

[0196] Transmit the encrypted shared data: Send the encrypted shared data to the primary organization.

[0197] The primary organization forwards the data: After receiving the encrypted shared data, the primary organization forwards it to the secondary organization.

[0198] Receive and decrypt the data: After receiving the encrypted shared data, the secondary organization decrypts the received encrypted data using its private key to obtain the original shared data.

[0199] In the direct transmission scheme, the data owner or the proxy server directly sends the encrypted shared data to the secondary organization. In the indirect transmission scheme, the encrypted shared data is sent to the primary organization, and after receiving the encrypted shared data, the primary organization forwards it to the secondary organization, so as to facilitate hierarchical management of data receivers.

[0200] The secondary organization uses its private key to decrypt the received encrypted data and verify the authenticity and integrity of the data. If the decryption is successful and the information content meets the expectations, the data is considered authentic. The private key of the secondary organization is unique, and even if the primary organization or other organizations obtain the encrypted shared data, they cannot decrypt it, thus ensuring the security of the shared data.

[0201] Through the above steps, the encrypted shared data can be securely transmitted to the final recipient, and the secondary organization uses its private key to decrypt it to obtain the original shared data.

[0202] As a preferred embodiment under the present invention, the data sharing method based on proxy re-encryption further includes,

[0203] Generating the authorization information of the primary organization through the private key of the data owner to authorize the primary organization;

[0204] Generating the authorization information of the secondary organization through the private key of the secondary organization to authorize the secondary organization.

[0205] The main purpose of this step is to ensure the authenticity and integrity of the authorization information of each level of organization (such as the primary organization and the secondary organization) through digital signature technology. By using the private keys of the data owner and the primary organization to generate their respective authorization information, it can be verified that these authorization information have not been tampered with and the legitimacy of their sources can be confirmed.

[0206] Among them, generating authorization information means that the data owner and the primary organization respectively generate authorization information containing access rights and other relevant information.

[0207] Digital signature means using their respective private keys to digitally sign the authorization information to ensure the authenticity and integrity of the authorization information.

[0208] Verifying authorization information means that the recipient uses the corresponding public key to verify the digital signature to ensure that the authorization information has not been tampered with and confirm the identity of the sender.

[0209] Specifically, this embodiment includes generating the authorization information of the primary organization.

[0210] The data owner generates authorization information, and the data owner generates authorization information including the access rights of the primary organization. Using the private key for digital signature, the data owner uses its private key to digitally sign the authorization information to generate the signed authorization information. Transmit the signed authorization information, and the data owner sends the signed authorization information to the primary organization. Verify the authorization information. After receiving the signed authorization information, the data owner uses the public key of the primary organization to verify the digital signature to ensure that the authorization information has not been tampered with and to confirm the identity of the primary organization.

[0211] Furthermore, generate the authorization information of the secondary organization.

[0212] The secondary organization generates authorization information, and the secondary organization generates authorization information including its own access rights. Using the private key for digital signature, the primary organization uses its private key to digitally sign the authorization information to generate the signed authorization information. Transmit the signed authorization information, and the secondary organization sends the signed authorization information to the primary organization. Verify the authorization information. After receiving the signed authorization information, the primary organization uses the public key of the secondary organization to verify the digital signature to ensure that the authorization information has not been tampered with and to confirm the identity of the secondary organization.

[0213] It should be noted that the public key of the secondary organization is used to decrypt the received signed authorization information to verify the authenticity of the digital signature. If the decryption is successful and the information content meets the expectations, the authorization information is considered to be authentic.

[0214] According to the preset access control policy, check whether the permission requirements in the authorization information meet the requirements. For example, check whether the primary organization or the secondary organization has the right to request specific data access rights.

[0215] Through the above steps, use the private keys of the data owner and the primary organization to generate authorization information, and use digital signature technology to ensure the authenticity and integrity of these authorization information.

[0216] As a preferred embodiment of this implementation manner, when canceling the authorization, cancel the authorization of the secondary organization through the primary organization, and / or,

[0217] Cancel the authorization of the primary organization through the data owner.

[0218] The main purpose of this embodiment is to ensure that in a multi-level data sharing system, the access rights of each level of organization can be revoked flexibly and securely. Through a clear authorization cancellation mechanism, unauthorized access can be prevented, and the security and privacy of sensitive data can be protected.

[0219] When it is necessary to cancel the access rights of a certain organization, the cancellation operation can be performed by its superior organization or the data owner.

[0220] Example 1: Cancel the authorization of a secondary organization by a primary organization.

[0221] Generate a cancellation authorization request. The primary organization generates a request containing the cancellation of the access permission of the secondary organization. Use the private key for digital signature. The primary organization uses its private key to digitally sign the cancellation authorization request, generating a signed cancellation authorization request. Execute the cancellation authorization operation. The primary organization updates the permission control list according to the cancellation authorization request and revokes the access permission of the secondary organization.

[0222] Example 2: Cancel the authorization of a primary organization by the data owner.

[0223] Generate a cancellation authorization request. The data owner generates a request containing the cancellation of the access permission of the primary organization. Use the private key for digital signature. The data owner uses its private key to digitally sign the cancellation authorization request, generating a signed cancellation authorization request. Execute the cancellation authorization operation. The data owner updates the permission control list according to the cancellation authorization request and revokes the access permission of the primary organization.

[0224] This embodiment supports multi-level permission management, allowing the superior organization or the data owner to flexibly manage and revoke the access permissions of subordinate organizations, improving the flexibility and control of the system. Through the above steps, the access permissions of each level of organization can be flexibly and securely cancelled by the primary organization or the data owner.

[0225] The present invention also provides an electronic device, including:

[0226] A memory for storing computer instructions;

[0227] A processor for implementing the data sharing method based on proxy re-encryption when executing the computer instructions.

[0228] Therefore, any effects of the data sharing method based on proxy re-encryption can be achieved, which will not be elaborated here.

[0229] What is not described in the present invention can be realized by adopting or referring to existing technologies.

[0230] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.

[0231] The above are only the embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. A data sharing method based on proxy re-encryption, characterized in that, For a data owner to share data with a first-level organization and a second-level organization, where the second-level organization is a subordinate unit of the first-level organization, the method includes: Set public keys and private keys for the data owner, the first-level organization, and the second-level organization respectively; Encrypt the authorization information and public key of the second-level organization with the private key of the second-level organization, and transmit the encrypted data to the first-level organization; After authentication based on the encrypted data, re-encrypt the authentication information and the private key of the second-level organization with the private key of the first-level organization, and transmit the re-encrypted data to the data owner; After authentication based on the re-encrypted data, encrypt the shared data based on the shared data with the public key of the second-level organization, and transmit the encrypted shared data to the second-level organization.

2. The data sharing method based on proxy re-encryption according to claim 1, characterized in that The public key and private key are specifically: Encrypt and decrypt data through the public key and the private key, Wherein, when encrypting data with the public key, decrypt with the private key; When encrypting data with the public key, decrypt with the private key.

3. The data sharing method based on proxy re-encryption according to claim 2, wherein: Set a private key for the data owner, the first-level organization, and the second-level organization one by one, where the private key is unique to each level of unit; Set a public key for the data owner, the first-level organization, and the second-level organization one by one, Wherein, the public key is shared by each level of unit; Or, The public key of the lower-level unit is shared with the superior unit to which it belongs.

4. The data sharing method based on proxy re-encryption according to claim 1, characterized in that The authentication of the encrypted data is specifically: Decrypt the encrypted data with the public key of the second-level organization; Authenticate the authorization information of the second-level organization. When the second-level organization is an authorized unit, the encrypted data passes the authentication.

5. The data sharing method based on proxy re-encryption according to claim 1, wherein: When the encrypted data passes the authentication, re-encrypt the authentication information and the private key of the second-level organization with the private key of the first-level organization, Wherein, the authentication information further includes the authorization information of the first-level organization.

6. The data sharing method based on proxy re-encryption according to claim 5, wherein The authentication of the re-encrypted data is specifically: When the encrypted data passes the authentication and the first-level organization is an authorized unit, the re-encrypted data passes the authentication, and perform the data sharing operation.

7. The data sharing method based on proxy re-encryption according to claim 1, characterized in that Encrypt with the public key of the second-level organization and transmit the encrypted shared data to the second-level organization, specifically: Directly transmit the encrypted shared data to the second-level organization; or transmit the encrypted shared data to the first-level organization and then to the second-level organization; Decrypt the encrypted shared data with the private key of the second-level organization to obtain the shared data.

8. The data sharing method based on proxy re-encryption according to claim 1, characterized in that, It further includes: Generate the authorization information of the first-level organization through the private key of the data owner to authorize the first-level organization; Generate the authorization information of the second-level organization through the private key of the second-level organization to authorize the second-level organization.

9. The data sharing method based on proxy re-encryption according to claim 8, wherein: When canceling the authorization, cancel the authorization of the second-level organization by the first-level organization, and / or The authorization of the first-level organization is cancelled by the data owner.

10. An electronic device, characterized in that, Including: A memory for storing computer instructions; A processor for implementing the proxy re-encryption-based data sharing method according to any one of claims 1 to 9 when executing the computer instructions.