Data security sharing method and device supporting multi-user cross-domain cooperation

Through blockchain and smart contract technology, data security sharing with multi-user cross-domain collaboration in the industrial Internet is realized, solving the security and communication overhead of existing solutions, ensuring the secure and controllable decryption of data and communication efficiency.

CN120281577AActive Publication Date: 2025-07-08THREE GORGES GROUP IND DEVELOPMENT (BEIJING) CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510753307.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-08
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

The existing multi-user cross-domain collaborative data security sharing schemes have security defects and large communication overhead. Especially in the industrial Internet, during the data decryption process between the dispatching center and other departments, the existing scheme cannot effectively control the decryption permissions and requires a large amount of communication.

Method used

Using blockchain technology and smart contracts, the data owner generates a collaborative ciphertext and public key. After satisfying the sub-policy of the collaboration policy, the data user joins the collaboration channel. The attribute authorization agency sends the private key for decryption, achieving secure and controllable multi-user cross-domain collaboration to avoid direct communication between users.

Benefits of technology

Improve data security, reduce communication overhead during decryption, and realize secure and controllable multi-person collaboration, so that users can decrypt themselves without communicating with each other.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281577A_ABST
    Figure CN120281577A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data security sharing method and device supporting multi-user cross-domain collaboration, which can join a collaboration channel under the condition that an attribute set of a data user meets at least one sub-strategy of a collaboration strategy. In this way, only a user who enters the channel and meets a certain sub-strategy of the collaboration strategy can decrypt the data, the security of the data is improved, when the attribute authorization mechanism determines that the collaboration channel is in the completed state and the data user is in the user list of the collaboration channel, the collaboration private key is sent to the data user, and the data user can decrypt the data. According to the method, under the condition that all the cooperation strategies are met, the cooperation private key is sent to the data users participating in cooperation, safe and controllable multi-user cooperation is achieved, the users participating in cooperation can decrypt by themselves without mutual communication, and a large amount of communication overhead in the decryption process is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and in particular, to a data security sharing method and device supporting multi-user cross-domain collaboration. Background Art

[0002] Industrial Internet generally involves multiple security domains, which have their own security boundaries and security mechanisms, and some data often needs to be accessed by users from different security domains through collaboration. For example, in the power industrial Internet, the dispatching center will send the power generation situations of each power station it collects to other interested departments such as power sales companies and lower-level dispatching centers to support business. To ensure the confidentiality of messages and limit the scope of message dissemination, the dispatching center uses "hydropower station AND power sales company" as an access policy to encrypt data. However, a department cannot have both attributes in the policy at the same time. Therefore, the three departments need to cooperate in decryption to obtain the data.

[0003] Currently, there are two types of solutions to achieve collaborative decryption to obtain data. The first type of solution uses the "group" method to share data. If the combined attribute set of all users in the group satisfies the policy, all users in the group are allowed to decrypt. This type of solution expands the control of data. However, users in the group who do not satisfy a certain attribute of the policy can still decrypt, and there are serious security flaws.

[0004] Another type of solution allows users to achieve collaborative decryption through interaction. When encrypting data, the encrypting party needs to set one or more attributes as "conversion attributes". Users with this attribute can convert the decryption intermediate result of this attribute into a decryption intermediate result that other users can use. For example, if "hydropower station" is set as a "conversion attribute", then hydropower station A can convert the decryption intermediate result of "hydropower station" and send it to power sales company B. At this time, B has both the decryption intermediate result of "hydropower station" and the decryption intermediate result of "power sales company", and can decrypt the data. However, this method only allows one party to have the final decryption ability. Unless "power sales company" is also set as a "conversion attribute" or B sends the decryption result to A, A cannot decrypt alone, and this type of solution requires a large amount of communication. Summary of the Invention

[0005] In view of the above problems, embodiments of the present invention are proposed to provide a data security sharing method and device supporting multi-user cross-domain collaboration that overcome the above problems or at least partially solve the above problems.

[0006] To solve the above problems, embodiments of the present invention disclose a data security sharing system supporting multi-user cross-domain collaboration, and the system includes a data owner, a data user, an attribute authorization agency, and a blockchain; The data owner is used to obtain a collaboration policy and collaboration attributes; encrypt the data according to the collaboration policy to obtain a collaboration ciphertext, and upload the collaboration ciphertext to a cloud server; generate a collaboration public key corresponding to the collaboration attributes, and upload the collaboration public key to the blockchain; The data user is used to download the collaboration ciphertext from the cloud server; join a collaboration channel when the attribute set of the data user satisfies at least one sub-policy of the collaboration policy; receive an attribute private key and a collaboration private key sent by the attribute authorization agency, and decrypt the collaboration ciphertext according to the attribute private key and the collaboration private key to obtain the data; the collaboration channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaboration ciphertext; The attribute authorization agency is used to obtain the attribute set of the data user, generate an attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner; obtain the collaboration public key from the blockchain, and generate a collaboration private key corresponding to the collaboration public key and send the collaboration private key to the data user when the collaboration channel is in a completed state and the data owner is in the user list of the collaboration channel; the collaboration channel being in a completed state means that the attribute sets of the data users in the user list of the collaboration channel satisfy all sub-policies of the collaboration policy.

[0007] Optionally, the data user is used to call the smart contract to join the collaboration channel according to the attribute private key and the collaboration ciphertext; The attribute authorization agency is used to obtain the output parameters of the smart contract, and determine whether the collaboration channel is in a completed state and whether the data user is in the user list of the collaboration channel according to the output parameters.

[0008] Optionally, the data owner is further used to obtain a system public key from the blockchain; encrypt the data according to the collaboration policy and the system public key to obtain a collaboration ciphertext.

[0009] Optionally, the attribute authorization agency is further used to generate a system public key and send it to the blockchain.

[0010] Optionally, the attribute authorization agency is further used to generate a master key, and generate an attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

[0011] Optionally, the attribute authorization agency is used to determine a generator of a cyclic group G of order ; for each attribute, randomly select ; for each group, randomly select ; randomly select ; generate a system public key according to the following formula: .

[0012] Optionally, the attribute authority is used to generate a master key according to the following formula: .

[0013] Optionally, for each data user in the group the attribute authority randomly selects and calculates an attribute private key according to the following formula: .

[0014] Optionally, a collaboration strategy includes sub - strategies; The data owner is used to determine a random vector, where the random vector includes a secret; Obtain the collaboration matrix corresponding to the collaboration strategy; According to the collaboration matrix and the random vector, determine a column vector for distributing secret shares, where the column vector includes shares corresponding to collaboration attributes and shares corresponding to each sub - strategy respectively; Encrypt the data according to the column vector and the system public key to obtain a collaboration ciphertext.

[0015] Optionally, the data owner is used to calculate the column vector for distributing secret shares according to the following formula:

[0016] where λ is the column vector for distributing secret shares, ca is the collaboration attribute, is the number of sub - strategies in the collaboration strategy, M is the collaboration matrix, v is the random vector,

[0017] where s is the secret; Calculated according to the following sub - matrix:

[0018] where the matrix is obtained by respectively taking a group of row vectors corresponding to sub - strategies from the collaboration matrix and removing the columns with all 0s.

[0019] Optionally, the data owner is used to encrypt the data according to the following formula to obtain a collaboration ciphertext:

[0020] Among them, the random number , the random number , the random number and it is a random number for the collaboration attribute, and satisfies and is constructed according to .

[0021] Optionally, the data owner is used to calculate the collaboration public key according to the following formula:

[0022] Among them, cpk is the collaboration public key; The attribute authorization agency is used to calculate the collaboration private key according to the following formula:

[0023] Among them, csk is the collaboration private key.

[0024] Optionally, the attribute set S of the data user satisfies one of the sub-policies in the collaboration policy, and the access structure of the sub-policy is , where is matrix; The data user is used to calculate the plaintext message through the following formula:

[0025] Among them, M is the plaintext message, , two constants and satisfies , is , sub-matrix is extracted from and the size is , , , a group of constants and satisfies , the authorization set is .

[0026] Optionally, the data owner is used to determine the random number , input the parameter to the smart contract, so that the smart contract updates the first output parameter and the second output parameter. The first output parameter indicates whether all sub-policies of the collaboration policy are satisfied, and the second output parameter indicates the user list including the user identity; The attribute authorization institution is configured to determine whether the collaboration channel is in a completed state according to the first output parameter, and determine whether the data user is in the user list of the collaboration channel according to the second output parameter.

[0027] Correspondingly, an embodiment of the present invention discloses a data security sharing method for supporting multi-user cross-domain collaboration, which is applied to a data user. The method includes: Download the collaboration ciphertext from the cloud server; When the attribute set of the data user satisfies at least one sub-policy of the collaboration policy, join the collaboration channel; the collaboration channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaboration ciphertext; Receive the attribute private key and the collaboration private key sent by the attribute authorization institution, and decrypt the collaboration ciphertext according to the attribute private key and the collaboration private key to obtain the data; the collaboration private key is sent to the data user when the collaboration channel is in a completed state and the data owner is in the user list of the collaboration channel. The collaboration channel is in a completed state when the attribute sets of the data users in the user list of the collaboration channel satisfy all the sub-policies of the collaboration policy.

[0028] Optionally, the joining the collaboration channel includes: Invoke the smart contract to join the collaboration channel according to the attribute private key and the collaboration ciphertext.

[0029] Optionally, the attribute private key is generated by the attribute authorization institution according to the attribute set of the data user and the master key.

[0030] Optionally, the master key is generated by the attribute authorization institution according to the following formula:

[0031] Wherein, is a generator of a cyclic group G of order , random number , random number .

[0032] Optionally, the attribute private key is , wherein the random number and corresponds to each data user in the corresponding group .

[0033] Optionally, the collaboration private key is calculated by the attribute authorization institution according to the following formula:

[0034] Wherein, csk is the collaboration private key and cpk is the collaboration public key.

[0035] Optionally, decrypting the collaborative ciphertext according to the attribute private key and the collaborative private key to obtain the data includes: Calculating a plaintext message through the following formula:

[0036] where M is the plaintext message, , two constants and satisfying , is , sub-matrix is extracted from and has a size of , , , a set of constants and satisfying , authorization set is .

[0037] Correspondingly, an embodiment of the present invention discloses a data security sharing method supporting multi-user cross-domain collaboration, which is applied to an attribute authorization agency. The method includes: Obtaining the attribute set of the data user, generating an attribute private key corresponding to the data owner according to the attribute set, and sending the attribute private key to the data owner; Obtaining a collaborative public key from the blockchain, and generating a collaborative private key corresponding to the collaborative public key and sending the collaborative private key to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel; the collaborative channel being in a completed state means that the attribute sets of the data users in the user list of the collaborative channel satisfy all sub-policies of the collaboration policy.

[0038] Optionally, the generating a collaborative private key corresponding to the collaborative public key and sending the collaborative private key to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel includes: Obtaining the output parameters of the smart contract, and determining whether the collaborative channel is in a completed state and whether the data user is in the user list of the collaborative channel according to the output parameters.

[0039] Optionally, the method further includes: Generating a system public key and sending it to the blockchain.

[0040] Optionally, the generating a system public key includes: Determining a generator of a cyclic group G of order ; For each attribute, randomly select ; For each group, randomly select ; Randomly select ; Generate the system public key according to the following formula: .

[0041] Optionally, the method further includes: Generate a master key; The generating the attribute private key corresponding to the data owner according to the attribute set includes: Generate the attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

[0042] Optionally, the generating the master key includes: Generate the master key according to the following formula:

[0043] The generating the attribute private key corresponding to the data owner according to the attribute set of the data user and the master key includes: For each data user in the group , randomly select ; Calculate the attribute private key according to the following formula: .

[0044] Correspondingly, an embodiment of the present invention discloses a data security sharing device supporting multi-user cross-domain collaboration, which is applied to a data user, and the device includes: A collaborative ciphertext download module, configured to download a collaborative ciphertext from a cloud server; A joining collaborative channel module, configured to join a collaborative channel when the attribute set of the data user satisfies at least one sub-policy of a collaboration policy; the collaborative channel is formed by creating a smart contract in a blockchain, and the smart contract is bound to the collaborative ciphertext; A decryption module, configured to receive an attribute private key and a collaborative private key sent by an attribute authority, and decrypt the collaborative ciphertext according to the attribute private key and the collaborative private key to obtain data; the collaborative private key is sent to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel, and the collaborative channel is in a completed state means that the attribute sets of the data users in the user list of the collaborative channel satisfy all sub-policies of the collaboration policy.

[0045] Optionally, the joining collaborative channel module includes: A collaboration channel sub-module is added, which is used to call the smart contract to join the collaboration channel according to the attribute private key and the collaboration ciphertext.

[0046] Optionally, the attribute private key is generated by the attribute authority according to the attribute set and the master key of the data user.

[0047] Optionally, the master key is generated by the attribute authority according to the following formula:

[0048] Wherein, is a generator of a cyclic group G of order , random number , random number .

[0049] Optionally, the attribute private key is , wherein, random number and corresponding to each data user in the group .

[0050] Optionally, the collaboration private key is calculated by the attribute authority according to the following formula:

[0051] Wherein, csk is the collaboration private key and cpk is the collaboration public key.

[0052] Optionally, the decryption module includes: A decryption sub-module, which is used to calculate the plaintext message through the following formula:

[0053] Wherein, M is the plaintext message, , two constants and satisfy , is , sub-matrix is extracted from and has a size of , , , a group of constants and satisfy , authorization set is .

[0054] Correspondingly, an embodiment of the present invention discloses a data security sharing device for supporting multi-user cross-domain collaboration, which is applied to an attribute authority, and the device includes: An attribute private key sending module, configured to obtain the attribute set of the data user, generate the attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner; A collaborative private key sending module, configured to obtain the collaborative public key from the blockchain, and generate the collaborative private key corresponding to the collaborative public key and send the collaborative private key to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel; the collaborative channel being in a completed state means that the attribute sets of the data users in the user list of the collaborative channel satisfy all sub-policies of the collaboration policy.

[0055] Optionally, the collaborative private key sending module includes: An output parameter acquisition sub-module, configured to obtain the output parameters of the smart contract, and determine whether the collaborative channel is in a completed state and whether the data user is in the user list of the collaborative channel according to the output parameters.

[0056] Optionally, the apparatus further includes: A system public key generation module, configured to generate a system public key and send it to the blockchain.

[0057] Optionally, the system public key generation module includes: A parameter determination sub-module, configured to determine the generator of the cyclic group G of order ; for each attribute, randomly select ; for each group, randomly select ; randomly select ; A system public key generation sub-module, configured to generate a system public key according to the following formula: .

[0058] Optionally, the apparatus further includes: A master key generation module, configured to generate a master key; The attribute private key sending module includes: An attribute private key generation sub-module, configured to generate the attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

[0059] Optionally, the master key generation module includes: A master key generation sub-module, configured to generate a master key according to the following formula: ; The attribute private key generation sub-module includes: A random number selection unit, for group Each data user randomly selects ; The attribute private key generation unit is used to calculate the attribute private key according to the following formula: .

[0060] The embodiments of the present invention have the following advantages: A data security sharing system supporting multi-user cross-domain collaboration according to an embodiment of the present invention includes a data owner, data users, an attribute authorization agency, and a blockchain. Among them, the data owner is used to obtain a collaboration policy and collaboration attributes, encrypt the data according to the collaboration policy to obtain a collaboration ciphertext, upload the collaboration ciphertext to a cloud server, generate a collaboration public key corresponding to the collaboration attributes, and upload the collaboration public key to the blockchain; the data users are used to download the collaboration ciphertext from the cloud server. When the attribute set of the data users satisfies at least one sub-policy of the collaboration policy, they join the collaboration channel, receive the attribute private key and the collaboration private key sent by the attribute authorization agency, and decrypt the collaboration ciphertext according to the attribute private key and the collaboration private key to obtain the data. The collaboration channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaboration ciphertext. In the way that only when the attribute set of the data users satisfies at least one sub-policy of the collaboration policy can they join the collaboration channel, only the users who satisfy a certain sub-policy of the collaboration policy and enter the collaboration channel can decrypt, which improves the security of the data.

[0061] The attribute authorization agency is used to obtain the attribute set of the data users, generate the attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner; obtain the collaboration public key from the blockchain. When the collaboration channel is in a completed state and the data owner is in the user list of the collaboration channel, generate the collaboration private key corresponding to the collaboration public key, and send the collaboration private key to the data users. The collaboration channel being in a completed state means that the attribute sets of the data users in the user list of the collaboration channel satisfy all the sub-policies of the collaboration policy. When the attribute authorization agency determines that the collaboration channel is in a completed state and the data user is in the user list of the collaboration channel, it sends the collaboration private key to the data user, that is, when all the collaboration policies are satisfied, it sends the collaboration private key to the data users participating in the collaboration, realizing secure and controllable multi-person collaboration. The users participating in the collaboration can decrypt by themselves without communicating with each other, avoiding a large amount of communication overhead in the decryption process. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 is a schematic structural diagram of a data security sharing system supporting multi-user cross-domain collaboration according to an embodiment of the present invention; Figure 2 is a schematic diagram of a strategy conversion according to an embodiment of the present invention; Figure 3 It is a flowchart of the steps of a data security sharing method for supporting multi-user cross-domain collaboration according to an embodiment of the present invention; Figure 4 It is a flowchart of the steps of another data security sharing method for supporting multi-user cross-domain collaboration according to an embodiment of the present invention; Figure 5 It is a structural block diagram of a data security sharing device for supporting multi-user cross-domain collaboration according to an embodiment of the present invention; Figure 6 It is a structural block diagram of another data security sharing device for supporting multi-user cross-domain collaboration according to an embodiment of the present invention. Specific embodiments

[0063] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0064] Industrial Internet of Things generally involves multiple security domains, which have their own security boundaries and security mechanisms, and some data often needs to be accessed by users from different security domains through collaboration. For example, in the power Industrial Internet of Things, the dispatching center will send the power generation situation of each power station collected to other interested departments such as power sales companies and lower-level dispatching centers to support the business. To ensure the confidentiality of messages and limit the scope of message dissemination, the dispatching center uses "hydropower station AND power sales company" as an access policy to encrypt the data. However, a department cannot have both attributes in the policy at the same time. Therefore, the three departments need to cooperate in decryption to obtain the data.

[0065] Currently, there are two types of solutions to achieve cooperative decryption to obtain data. The first type of solution uses the "group" method to share data. If the combined attribute set of all users in the group meets the policy, all users in the group are allowed to decrypt. This type of solution expands the control of data. However, users in the group who do not meet a certain attribute of the policy can still decrypt, and there are serious security flaws.

[0066] Another type of solution allows users to achieve collaborative decryption in an interactive manner. When encrypting data, the encryptor needs to set one or more attributes as "conversion attributes". Users with this attribute can convert the decryption intermediate result of this attribute into a decryption intermediate result that other users can use. For example, if "hydropower station" is set as a "conversion attribute", then Hydropower Station A can convert the decryption intermediate result of "hydropower station" and send it to Power Sales Company B. At this time, B has both the decryption intermediate result of "hydropower station" and the decryption intermediate result of "power sales company", and can then decrypt the data. However, this method only allows one of the parties to have the final decryption ability. Unless "power sales company" is also set as a "conversion attribute" or B sends the decryption result to A, A cannot decrypt alone, and this type of solution requires a large amount of communication.

[0067] One of the core concepts of the embodiments of the present invention is that in the case where the attribute set of the data user satisfies at least one sub-strategy of the collaboration strategy, the way to join the collaboration channel is adopted, so that only users who satisfy a certain sub-strategy of the collaboration strategy can decrypt, improving the security of the data; when the attribute authorization agency determines that the collaboration channel is in a completed state and the data user is in the user list of the collaboration channel, the collaboration private key is sent to the data user, that is, when all the collaboration strategies are satisfied, the collaboration private key is sent to the data users participating in the collaboration, realizing secure and controllable multi-user collaboration. The users participating in the collaboration can decrypt by themselves without communicating with each other, avoiding a large amount of communication overhead in the decryption process.

[0068] Refer to Figure 1 , which shows a schematic structural diagram of a data security sharing system supporting multi-user cross-domain collaboration according to an embodiment of the present invention, including a data owner, a data user, an attribute authorization agency, a cloud server, and a blockchain.

[0069] The cloud server (Cloud Server, CS) is a data storage and sharing platform that allows registered users to freely upload, download, and share data through an encryption mechanism, while ensuring the confidentiality and integrity of the data. Assuming that the cloud server is semi-trusted, the cloud server will strictly follow protocol specifications (such as data storage, retrieval, and access control), faithfully execute user requests, but may attempt to analyze metadata (such as access patterns, file sizes, or user relationships) to infer sensitive information.

[0070] The data owner is used to obtain the collaboration strategy and collaboration attributes; encrypt the data according to the collaboration strategy to obtain the collaboration ciphertext, and upload the collaboration ciphertext to the cloud server; generate the collaboration public key corresponding to the collaboration attributes, and upload the collaboration public key to the blockchain.

[0071] The Data Owner (DO) is a user or entity that legally generates, controls, and manages data, and is responsible for data uploading, encryption, access authorization, and lifecycle management (such as updates, revocation, or deletion). In a cloud storage environment, after encrypting the data according to the access policy, the Data Owner uploads the encrypted data to the cloud server. The encrypted data is divided into two types: ordinary ciphertext and collaborative ciphertext. The encryption method of ordinary ciphertext is similar to the traditional Ciphertext-Policy Attribute-Based Encryption (CP-ABE) scheme. For collaborative ciphertext, the Data Owner needs to convert the conventional policy into a collaborative policy and then encrypt the data according to the collaborative policy to obtain the collaborative ciphertext. Referring to Figure 2 , a schematic diagram of a policy conversion in an embodiment of the present invention is shown. Figure 2 The left figure in

[0072] represents the conventional policy, including sub-policies p1 and p2, and the right figure represents the collaborative policy, which introduces the collaborative attribute ca for conversion, that is, converting from the conventional policy in the left figure to the collaborative policy in the right figure. The obtained collaborative policy includes sub-policies p1 and p2.

[0073] The data user is used to download the collaborative ciphertext from the cloud server; when the attribute set of the data user satisfies at least one sub-policy of the collaborative policy, it joins the collaborative channel; receives the attribute private key and the collaborative private key sent by the attribute authorization agency, and decrypts the collaborative ciphertext according to the attribute private key and the collaborative private key to obtain the data; the collaborative channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaborative ciphertext.

[0074] The Data User (DU) belongs to a certain group, and there can be multiple data users in the group. In a cloud storage system, a group is a logically set of users used to simplify permission management. The Data Owner can define groups (such as "Finance Department", "Project A Group") based on organizational structure, role, or business requirements, and assign access permissions to the entire group rather than individual data owners.

[0075] Data users can download the ciphertext from the cloud server and decrypt it. After the data user downloads the collaborative ciphertext, when the attribute set satisfies at least one sub-policy of the collaboration policy, the data user joins the collaboration channel. The collaboration channel is formed by collaborators in the same group as the data user creating a smart contract in the blockchain, and the smart contract is bound to the collaborative ciphertext. After joining the collaboration channel, the collaborative ciphertext can be successfully decrypted with two types of private keys: one is the attribute private key (Attribute SK) corresponding to its attribute set, and the other is the collaborative private key (CollaborativeSK) corresponding to the collaborative attribute ca in the ciphertext. Only when the data user joins a channel created by collaborators in the same group and with a status of "completed" can the data user obtain the collaborative private key from the attribute authorization center.

[0076] The attribute authorization agency is used to obtain the attribute set of the data user, generate the attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner; obtain the collaborative public key from the blockchain, and when the collaboration channel is in the completed state and the data owner is in the user list of the collaboration channel, generate the collaborative private key corresponding to the collaborative public key, and send the collaborative private key to the data user; the collaboration channel is in the completed state means that the attribute sets of the data users in the user list of the collaboration channel satisfy all sub-policies of the collaboration policy.

[0077] The attribute authorization agency (Attribute Authority, AA) is used to receive the attribute set sent by the data user, generate the attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner. For the collaborative private key, the attribute authorization agency needs to obtain the collaborative public key from the blockchain ledger and verify whether the following two conditions are met: one is whether the collaboration channel is in the completed state, and the other is whether the data user is in the user list of the collaboration channel. Only when both conditions are satisfied will the attribute authorization agency distribute the collaborative private key generated from the collaborative public key. Here, the attribute authorization agency is assumed to be completely trusted because the attribute authorization agency needs to generate the attribute private key and the collaborative private key and must be completely trusted, otherwise, private key leakage will occur.

[0078] The blockchain records the collaborative public key during operation and executes the smart contract for the collaborative channel. The collaborative channel smart contract is created by the collaborative initiator and bound to the collaborative ciphertext. Data users in the same group as the collaborators can join the channel if the set of their attributes satisfies a certain sub-policy in the collaboration policy. If all sub-policies in the collaboration policy are satisfied, the collaborative channel is considered "completed". Data users within a collaborative channel in the "completed" state can obtain the collaborative private key from the attribute authorization agency and decrypt the collaborative ciphertext corresponding to the collaborative channel based on the attribute private key and the collaborative private key. Due to the randomization process, the collaborative private key of each data user is different. The blockchain can be a permissioned chain or a permissionless chain that supports smart contracts.

[0079] In the embodiment of the present invention, the data user can join the collaborative channel only when the set of attributes of the data user satisfies at least one sub-policy of the collaboration policy, which enables only users who meet a certain attribute of the collaboration policy to decrypt, improving the security of the data; when the attribute authorization agency determines that the collaborative channel is in the completed state and the data user is in the user list of the collaborative channel, the attribute authorization agency sends the collaborative private key to the data user, that is, when all sub-policies of the collaboration policy are satisfied, the collaborative private key is sent to the data users participating in the collaboration, realizing secure and controllable multi-person collaboration. The users participating in the collaboration can decrypt by themselves without communicating with each other, avoiding a large amount of communication overhead during the decryption process.

[0080] In the embodiment of the present invention, a data user is used to call a smart contract to join a collaborative channel according to an attribute private key and a collaborative ciphertext; An attribute authorization agency is used to obtain the output parameters of the smart contract, and determine whether the collaborative channel is in the completed state and whether the data user is in the user list of the collaborative channel according to the output parameters.

[0081] Specifically, a data user is used to input parameters according to an attribute private key and a collaborative ciphertext, and call a smart contract to join a collaborative channel. After the data user inputs parameters to join the collaborative channel, the output parameters of the smart contract will be updated accordingly. An attribute authorization agency is used to obtain the output parameters of the smart contract, and determine whether the collaborative channel is in the completed state and whether the data user is in the user list of the collaborative channel according to the output parameters.

[0082] In the embodiment of the present invention, a data owner is further used to obtain a system public key from the blockchain; encrypt the data according to the collaboration policy and the system public key to obtain a collaborative ciphertext.

[0083] Specifically, a data owner is further used to obtain a system public key from the blockchain, and encrypt the data according to the collaboration policy and the system public key to obtain a collaborative ciphertext.

[0084] In an embodiment of the present invention, the attribute authorization authority is further configured to generate a system public key and send it to the blockchain.

[0085] Specifically, the attribute authorization authority is further configured to generate a system public key and record the system public key in the blockchain ledger. The system public key is a public key used for encryption, which acts on the system globally and is also used by the data owner to generate a collaboration public key. The collaboration public key is a public key generated by the user himself and bound to the collaboration ciphertext, and only acts on the collaboration ciphertext.

[0086] In an embodiment of the present invention, the attribute authorization authority is further configured to generate a master key, and generate an attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

[0087] Specifically, the attribute authorization authority is further configured to generate a master key, and generate an attribute private key corresponding to the data owner according to the attribute set of the data user and the master key. The master key is used to generate the attribute private key.

[0088] In an embodiment of the present invention, the attribute authorization authority first selects a cyclic group of order , and is its generator. For each attribute, the attribute authorization authority randomly selects . For each group, the attribute authorization authority randomly selects . In addition, the attribute authorization authority randomly selects . Finally, the system public key is:

[0089] In an embodiment of the present invention, the attribute authorization authority is used to generate the master key according to the following formula: .

[0090] In an embodiment of the present invention, for each data user in the group , the attribute authorization authority randomly selects , and calculates the attribute private key according to the following formula: .

[0091] In an embodiment of the present invention, a collaboration policy includes sub - policies; the data owner is used to determine a random vector, the random vector includes a secret; obtain a collaboration matrix corresponding to the collaboration policy; determine a column vector for distributing secret shares according to the collaboration matrix and the random vector, the column vector includes shares corresponding to collaboration attributes and shares corresponding to each sub - policy respectively; encrypt the data according to the column vector and the system public key to obtain a collaboration ciphertext.

[0092] Specifically, the data owner needs to randomly select a random vector. The first random number of the random vector is the secret. Obtain the cooperation matrix corresponding to the cooperation strategy. According to the cooperation matrix and the random vector, determine the column vector for distributing the secret shares. The column vector includes the shares corresponding to the cooperation attributes and the shares corresponding to each sub-strategy respectively. Encrypt the data according to the column vector and the system public key to obtain the cooperation ciphertext.

[0093] In the embodiment of the present invention, the data owner first randomly selects a random vector. The random vector v is as follows: , Next, calculate , where the column vector is obtained by calculating from the following sub-matrices , where is extracted from the cooperation matrix. The extraction method is to separately take out a group of row vectors corresponding to the sub-strategy k from the cooperation matrix and remove the columns all of which are 0 to form . The cooperation matrix is as follows: , where is the row vector representing the cooperation attribute ca, is the sub-matrix that maps , and its construction follows the general construction method of the LSSS matrix. is the repeated row vector generated during the construction of .

[0094] In the embodiment of the present invention, the data owner is used to construct according to . In order to make , the data owner sets as follows: . For the cooperation attribute ca, the data owner selects a random number and calculates , which is the cooperation public key. In addition, the data owner randomly selects , and .

[0095] The final ciphertext is: .

[0096] In the embodiment of the present invention, the data owner is used to calculate the cooperation public key according to the following formula: , where cpk is the cooperation public key; The attribute authorization agency is used to calculate the collaborative private key according to the following formula: , where csk is the collaborative private key.

[0097] In the embodiment of the present invention, the attribute set S of the data user satisfies one of the sub-policies in the collaboration policy, and its access structure is , where is matrix, and the defined authorization set is . The data user can find a set of constants that satisfy . Then, the data user can obtain and calculate .

[0098] Next, the data user obtains the collaborative attribute ca and extracts the sub-matrix . The extraction method is to respectively take out a set of row vectors corresponding to the sub-policy k from the collaboration matrix and remove the column vectors that are all 0. Regarding the sub-policy as a single attribute and defining as , then the data user can calculate two constants that satisfy .

[0099] Next, the data user calculates

[0100] Finally, the data user obtains the plaintext message through the following calculation

[0101]

[0102] In the embodiment of the present invention, when the data user satisfies a certain sub-policy , it can calculate . Randomly select two random numbers , and call the collaborative channel smart contract CSC, that is, input the parameter to the smart contract, so that the smart contract updates the first output parameter and the second output parameter. The first parameter AC is an array, and its index represents the sub-policy. If the value of each element in the array AC is 1, it means that all sub-policies are satisfied. At this time, the channel is regarded as in a completed state, and the data users in the user list UL can obtain the collaborative attributes. The second parameter UL is a user list containing user identities. The attribute authorization agency is used to determine whether the collaborative channel is in a completed state according to the first output parameter, and determine whether the data user is in the user list of the collaborative channel according to the second output parameter.

[0103] Exemplarily, the collaborative channel smart contract is as follows:

[0104] The consensus nodes will collect blockchain transactions and create a CSC for the collaboration initiator. Before instantiating the CSC, the consensus nodes will check whether the group ID and group public key in the CSC are correct. If correct, the consensus nodes will continue to instantiate the CSC and package it into the next new block. If incorrect, the creation of the CSC will fail.

[0105] Referring to Figure 3 , a step flowchart of a data security sharing method for supporting multi-user cross-domain collaboration according to an embodiment of the present invention is shown, which is applied to a data user and may specifically include the following steps: Step 101, download the collaboration ciphertext from the cloud server.

[0106] Step 102, when the attribute set of the data user satisfies at least one sub-policy of the collaboration policy, join the collaboration channel; the collaboration channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaboration ciphertext.

[0107] Step 103, receive the attribute private key and collaboration private key sent by the attribute authorization agency, decrypt the collaboration ciphertext according to the attribute private key and collaboration private key to obtain the data; the collaboration private key is sent to the data user when the collaboration channel is in a completed state and the data owner is in the user list of the collaboration channel. The collaboration channel is in a completed state when the attribute set of the data user in the user list of the collaboration channel enables each sub-policy of the collaboration policy to be satisfied.

[0108] The method of joining the collaboration channel only when the attribute set of the data user satisfies at least one sub-policy of the collaboration policy enables only users who meet a certain attribute of the collaboration policy to decrypt, improving the security of the data.

[0109] In the embodiment of the present invention, step 102 may specifically include the following sub-steps: Sub-step S11, call the smart contract to join the collaboration channel according to the attribute private key and the collaboration ciphertext.

[0110] In the embodiment of the present invention, the attribute private key is generated by the attribute authorization agency according to the attribute set of the data user and the master key.

[0111] In the embodiment of the present invention, the master key is generated by the attribute authorization agency according to the following formula:

[0112] Wherein, is a generator of a cyclic group G of order , random number , random number .

[0113] In the embodiment of the present invention, the attribute private key is , where the random number and corresponding to each data user in the group .

[0114] Optionally, the collaborative private key is calculated by the attribute authorization agency according to the following formula:

[0115] where csk is the collaborative private key and cpk is the collaborative public key.

[0116] In the embodiment of the present invention, step 103 may specifically include the following sub-steps: Sub-step S21, calculate the plaintext message through the following formula:

[0117] where M is the plaintext message, , two constants and satisfy , is , sub-matrix is extracted from and the size is , , , a set of constants and satisfy , authorization set is .

[0118] Referring to Figure 4 , a step flowchart of another data security sharing method supporting multi-user cross-domain collaboration in the embodiment of the present invention is shown, which is applied to the attribute authorization agency and may specifically include the following steps: Step 201, obtain the attribute set of the data user, generate the attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner.

[0119] Step 202, obtain the collaborative public key from the blockchain. When the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel, generate the collaborative private key corresponding to the collaborative public key and send the collaborative private key to the data user; the collaborative channel being in a completed state means that the attribute sets of the data users in the user list of the collaborative channel make each sub-strategy of the collaboration policy be satisfied.

[0120] When the attribute authorization agency determines that the collaboration channel is in a completed state and the data user is in the user list of the collaboration channel, it sends the collaboration private key to the data user. That is, when all collaboration policies are satisfied, it sends the collaboration private key to the data users participating in the collaboration, achieving secure and controllable multi-person collaboration. The users participating in the collaboration can decrypt by themselves without communicating with each other, avoiding a large amount of communication overhead in the decryption process.

[0121] In the embodiment of the present invention, step 202 may specifically include the following sub-steps: Obtain the output parameters of the smart contract, and determine whether the collaboration channel is in a completed state and whether the data user is in the user list of the collaboration channel according to the output parameters.

[0122] In the embodiment of the present invention, the method further includes: Generate a system public key and send it to the blockchain.

[0123] In the embodiment of the present invention, generating the system public key includes: Determine the generator of the cyclic group G of order ; for each attribute, randomly select ; for each group, randomly select ; randomly select ; Generate the system public key according to the following formula: .

[0124] In the embodiment of the present invention, the method further includes: Generate a master key; Generate the attribute private key corresponding to the data owner according to the attribute set, including: Generate the attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

[0125] In the embodiment of the present invention, generating the master key includes: Generate the master key according to the following formula:

[0126] Generate the attribute private key corresponding to the data owner according to the attribute set of the data user and the master key, including: For each data user in the group , randomly select ; Calculate the attribute private key according to the following formula: .

[0127] It should be noted that for method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0128] Referring to Figure 5 , a structural block diagram of a data security sharing device supporting multi-user cross-domain collaboration according to an embodiment of the present invention is shown, which is applied to data users and specifically may include the following modules: A collaborative ciphertext download module 301, configured to download collaborative ciphertext from a cloud server; A join collaborative channel module 302, configured to join a collaborative channel when the attribute set of the data user satisfies at least one sub-policy of the collaboration policy; the collaborative channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaborative ciphertext; A decryption module 303, configured to receive an attribute private key and a collaboration private key sent by an attribute authorization agency, and decrypt the collaborative ciphertext according to the attribute private key and the collaboration private key to obtain data; the collaboration private key is sent to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel, and the collaborative channel is in a completed state when the attribute set of the data user in the user list of the collaborative channel makes each sub-policy of the collaboration policy satisfied.

[0129] In the way that a collaborative channel can be joined only when the attribute set of the data user satisfies at least one sub-policy of the collaboration policy, only users who meet a certain attribute of the collaboration policy can decrypt, which improves the security of the data.

[0130] In the embodiment of the present invention, the join collaborative channel module includes: A join collaborative channel sub-module, configured to call a smart contract to join the collaborative channel according to the attribute private key and the collaborative ciphertext.

[0131] In the embodiment of the present invention, the attribute private key is generated by an attribute authorization agency according to the attribute set of the data user and the master key.

[0132] In the embodiment of the present invention, the master key is generated by an attribute authorization agency according to the following formula:

[0133] Where is a generator of a cyclic group G of order , a random number , a random number 。

[0134] In the embodiment of the present invention, the attribute private key is , where the random number and corresponding to each data user in the group .

[0135] In the embodiment of the present invention, the collaborative private key is calculated by the attribute authorization agency according to the following formula:

[0136] where csk is the collaborative private key and cpk is the collaborative public key.

[0137] In the embodiment of the present invention, the decryption module includes: A decryption sub-module for calculating the plaintext message through the following formula:

[0138] where M is the plaintext message, , two constants and satisfying , is , the sub-matrix is extracted from and has a size of , , , a set of constants and satisfying , the authorization set is .

[0139] Referring to Figure 6 , a structural block diagram of another data security sharing device supporting multi-user cross-domain collaboration in the embodiment of the present invention is shown, which is applied to the attribute authorization agency and specifically may include the following modules: An attribute private key sending module 401, configured to obtain the attribute set of the data user, generate the attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner; A collaborative private key sending module 402, configured to obtain the collaborative public key from the blockchain, and generate the collaborative private key corresponding to the collaborative public key and send the collaborative private key to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel; the collaborative channel being in a completed state means that the attribute sets of the data users in the user list of the collaborative channel satisfy all sub-strategies of the collaboration strategy.

[0140] When the attribute authorization agency determines that the collaboration channel is in a completed state and the data user is in the user list of the collaboration channel, it sends the collaboration private key to the data user. That is, when all collaboration policies are satisfied, it sends the collaboration private key to the data users participating in the collaboration, realizing secure and controllable multi-person collaboration. The users participating in the collaboration can decrypt by themselves without communicating with each other, avoiding a large amount of communication overhead in the decryption process.

[0141] In an embodiment of the present invention, the collaboration private key sending module includes: An output parameter acquisition sub-module, configured to acquire the output parameters of the smart contract, and determine whether the collaboration channel is in a completed state and whether the data user is in the user list of the collaboration channel according to the output parameters.

[0142] In an embodiment of the present invention, the device further includes: A system public key generation module, configured to generate a system public key and send it to the blockchain.

[0143] In an embodiment of the present invention, the system public key generation module includes: A parameter determination sub-module, configured to determine a generator of a cyclic group G of order ; for each attribute, randomly select ; for each group, randomly select ; randomly select ; A system public key generation sub-module, configured to generate a system public key according to the following formula: .

[0144] In an embodiment of the present invention, the device further includes: A master key generation module, configured to generate a master key; The attribute private key sending module includes: An attribute private key generation sub-module, configured to generate an attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

[0145] In an embodiment of the present invention, the master key generation module includes: A master key generation sub-module, configured to generate a master key according to the following formula: ; The attribute private key generation sub-module includes: A random number selection unit, configured to, for each data user in the group , randomly select ; An attribute private key generation unit, configured to calculate the attribute private key according to the following formula: 。

[0146] For the device embodiments, since they are basically similar to the method embodiments, they are described relatively simply. For related parts, refer to the corresponding descriptions in the method embodiments.

[0147] The embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, refer to each other.

[0148] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, devices, or computer program products. Therefore, the embodiments of the present invention can take the form of all-hardware embodiments, all-software embodiments, or embodiments combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0149] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processors of the computer or other programmable data processing terminal devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0150] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0151] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1Steps of the functions specified in one or more boxes.

[0152] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.

[0153] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.

[0154] The above has introduced in detail the method and device for multi-user cross-domain collaborative data security sharing provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A data security sharing system that supports multi-user cross-domain collaboration, characterized in that The system includes a data owner, a data user, an attribute authorization agency, and a blockchain; The data owner is configured to obtain a collaboration policy and collaboration attributes; encrypt data according to the collaboration policy to obtain a collaboration ciphertext, and upload the collaboration ciphertext to a cloud server; generate a collaboration public key corresponding to the collaboration attributes, and upload the collaboration public key to the blockchain; The data user is configured to download the collaboration ciphertext from the cloud server; join a collaboration channel when the attribute set of the data user satisfies at least one sub-policy of the collaboration policy; receive an attribute private key and a collaboration private key sent by the attribute authorization agency, and decrypt the collaboration ciphertext according to the attribute private key and the collaboration private key to obtain the data; the collaboration channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaboration ciphertext; The attribute authorization agency is configured to obtain the attribute set of the data user, generate an attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner; obtain the collaboration public key from the blockchain, and generate a collaboration private key corresponding to the collaboration public key and send the collaboration private key to the data user when the collaboration channel is in a completed state and the data owner is in the user list of the collaboration channel; the collaboration channel is in a completed state when the attribute sets of the data users in the user list of the collaboration channel satisfy all sub-policies of the collaboration policy.

2. The data security sharing system according to claim 1, wherein the data user is configured to call the smart contract to join the collaboration channel according to the attribute private key and the collaboration ciphertext; the attribute authorization agency is configured to obtain the output parameters of the smart contract, and determine whether the collaboration channel is in a completed state and whether the data user is in the user list of the collaboration channel according to the output parameters.

3. The data security sharing system according to claim 2, wherein the data owner is further configured to obtain a system public key from the blockchain; encrypt data according to the collaboration policy and the system public key to obtain a collaboration ciphertext.

4. The data security sharing system according to claim 3, wherein the attribute authorization agency is further configured to generate a system public key and send it to the blockchain.

5. The data security sharing system according to claim 4, wherein the attribute authorization agency is further configured to generate a master key, and generate an attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

6. The data security sharing system according to claim 5, wherein The attribute authorization agency is used to determine a generator of a cyclic group G of order ; for each attribute, randomly select ; for each group, randomly select ; randomly select ; randomly select ; generate a system public key according to the following formula: 。 7. The data security sharing system according to claim 6, wherein the attribute authorization agency is configured to generate a master key according to the following formula: 。 8. The data security sharing system according to claim 7, wherein The attribute authorization agency is used to randomly select for each data user in the group and calculate the attribute private key according to the following formula: ​ 。 9. The data security sharing system according to claim 8, wherein A collaboration strategy includes sub-strategies; the data owner is configured to determine a random vector, and the random vector includes a secret; Obtain the cooperation matrix corresponding to the cooperation strategy; Determine the column vector for distributing secret shares according to the cooperation matrix and the random vector, where the column vector includes the shares corresponding to cooperation attributes and the shares corresponding to each sub-strategy respectively; Encrypt the data according to the column vector and the system public key to obtain the cooperation ciphertext.

10. The data security sharing system according to claim 9, wherein The data owner is used to calculate the column vector for distributing secret shares according to the following formula: Among them, λ is a column vector for distributing secret shares, ca is a collaborative attribute, is the number of sub-strategies in the collaborative strategy, M is a collaborative matrix, v is a random vector, where s is the secret; Calculated based on the following sub-matrix: Among them, the matrix is obtained by separately extracting a set of row vectors corresponding to the sub-strategies from the collaboration matrix and removing the column vectors that are all 0.

11. The data security sharing system according to claim 10, wherein The data owner is used to encrypt the data according to the following formula to obtain the cooperation ciphertext: Among them, the random number , the random number , the random number and it is a random number for the collaboration attribute, and satisfies and is constructed according to .

12. The data security sharing system according to claim 11, wherein The data owner is used to calculate the cooperation public key according to the following formula: where cpk is the cooperation public key; The attribute authorization agency is used to calculate the cooperation private key according to the following formula: where csk is the cooperation private key.

13. The data security sharing system according to claim 12, wherein The attribute set S of the data user satisfies one of the sub-policies in the collaboration policy, and the access structure of the sub-policy is , where is matrix; The data user is used to calculate the plaintext message through the following formula: Where M is the plaintext message, , two constants and satisfy , is , the submatrix is extracted from and has a size of , , , a set of constants and satisfy , the authorization set is .

14. The data security sharing system according to claim 13, wherein The data owner is used to determine a random number , and input parameters into the smart contract , so that the smart contract updates a first output parameter and a second output parameter, where the first output parameter indicates whether sub - strategies of the cooperation strategy are all satisfied, and the second output parameter indicates a user list including user identities; The attribute authorization agency is used to determine whether the cooperation channel is in a completed state according to the first output parameter, and determine whether the data user is in the user list of the cooperation channel according to the second output parameter.

15. A data security sharing method for supporting multi-user cross-domain collaboration, applied to data users, characterized in that, The method includes: Download the cooperation ciphertext from the cloud server; Join the cooperation channel when the attribute set of the data user satisfies at least one sub-strategy of the cooperation strategy; the cooperation channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the cooperation ciphertext; Receive the attribute private key and the cooperation private key sent by the attribute authorization agency, and decrypt the cooperation ciphertext according to the attribute private key and the cooperation private key to obtain the data; the cooperation private key is sent to the data user when the cooperation channel is in a completed state and the data owner is in the user list of the cooperation channel, and the cooperation channel is in a completed state when the attribute sets of the data users in the user list of the cooperation channel satisfy all sub-strategies of the cooperation strategy.

16. The data security sharing method according to claim 15, wherein The joining the cooperation channel includes: Call the smart contract to join the cooperation channel according to the attribute private key and the cooperation ciphertext.

17. The data security sharing method according to claim 16, wherein The attribute private key is generated by the attribute authorization agency according to the attribute set of the data user and the master key.

18. The data security sharing method according to claim 17, wherein The master key is generated by the attribute authorization agency according to the following formula: Among them, is a generator of a cyclic group G of order , random number , random number .

19. The data security sharing method according to claim 18, wherein The attribute private key is , where the random number and corresponding group for each data user in.

20. The data security sharing method according to claim 19, wherein The collaborative private key is calculated by the attribute authorization agency according to the following formula: where csk is the cooperation private key and cpk is the cooperation public key.

21. The data security sharing method according to claim 20, wherein The decrypting the cooperation ciphertext according to the attribute private key and the cooperation private key to obtain the data includes: Calculate the plaintext message through the following formula: Where M is the plaintext message, , two constants and satisfy , is , the submatrix is extracted from and has a size of , , , a set of constants and satisfy , the authorization set is .

22. A data security sharing method for supporting multi-user cross-domain collaboration, applied to an attribute authorization agency, characterized in that, The method includes: Obtain the attribute set of the data user, generate the attribute private key corresponding to the data owner according to the attribute set, and send the attribute private key to the data owner; Obtain the collaborative public key from the blockchain. When the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel, generate the collaborative private key corresponding to the collaborative public key, and send the collaborative private key to the data user; the collaborative channel being in a completed state means that the attribute set of the data users in the user list of the collaborative channel enables each sub-strategy of the collaboration policy to be satisfied.

23. The data security sharing method according to claim 22, wherein The step of generating the collaborative private key corresponding to the collaborative public key and sending the collaborative private key to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel includes: Obtain the output parameters of the smart contract, and determine whether the collaborative channel is in a completed state and whether the data user is in the user list of the collaborative channel according to the output parameters.

24. The data security sharing method according to claim 23, wherein The method further includes: Generate a system public key and send it to the blockchain.

25. The data security sharing method according to claim 24, wherein The step of generating the system public key includes: Determine the generator of the cyclic group G of order ; For each attribute, randomly select ; For each group, randomly select ; Randomly select ; ; Generate the system public key according to the following formula: 。 26. The data security sharing method according to claim 25, wherein The method further includes: Generate a master key; The step of generating the attribute private key corresponding to the data owner according to the attribute set includes: Generate the attribute private key corresponding to the data owner according to the attribute set of the data user and the master key.

27. The data security sharing method according to claim 26, wherein The step of generating the master key includes: Generate the master key according to the following formula: The step of generating the attribute private key corresponding to the data owner according to the attribute set of the data user and the master key includes: For each data user in the group , randomly select ; Calculate the attribute private key according to the following formula: 。 28. A data security sharing device supporting multi-user cross-domain collaboration, characterized in that, When applied to the data user, the device includes: A collaborative ciphertext download module for downloading the collaborative ciphertext from the cloud server. A collaborative channel joining module for joining the collaborative channel when the attribute set of the data user satisfies at least one sub-strategy of the collaboration policy; the collaborative channel is formed by creating a smart contract in the blockchain, and the smart contract is bound to the collaborative ciphertext. A decryption module for receiving the attribute private key and the collaborative private key sent by the attribute authority, and decrypting the collaborative ciphertext according to the attribute private key and the collaborative private key to obtain the data; the collaborative private key is sent to the data user when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel, and the collaborative channel being in a completed state means that the attribute set of the data users in the user list of the collaborative channel enables each sub-strategy of the collaboration policy to be satisfied.

29. A data security sharing device supporting multi-user cross-domain collaboration, characterized in that, When applied to the attribute authority, the device includes: An attribute private key sending module for obtaining the attribute set of the data user, generating the attribute private key corresponding to the data owner according to the attribute set, and sending the attribute private key to the data owner. A collaborative private key sending module, which is used to obtain a collaborative public key from a blockchain, generate a collaborative private key corresponding to the collaborative public key when the collaborative channel is in a completed state and the data owner is in the user list of the collaborative channel, and send the collaborative private key to the data user; the collaborative channel being in a completed state means that the attribute set of the data users in the user list of the collaborative channel enables each sub-strategy of the collaboration policy to be satisfied.

Citation Information

Patent Citations

  • Multi-party cooperation data sharing method supporting access strategy updating

    CN114979149A

  • Ciphertext data sharing method and system based on collaborative searchable

    CN115694974A

  • On-chain and off-chain cooperative medical data hierarchical access control and sharing method

    CN117155644A

  • Cross-domain multi-authority collaborative attribute-based encryption access control method

    CN117614618A

  • Methods and Apparatus for Data Access Control

    US20150281193A1