LSSS access structure construction method and device supporting cooperative decryption
The LSSS access structure method addresses high computational overhead in ABE systems by sharing decryption results across levels, enhancing decryption efficiency and reducing computational load.
Patent Information
- Application Number
- CN202510757674.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-09
AI Technical Summary
Existing attribute-based encryption (ABE) systems with user collaboration decryption face high computational overhead and low decryption efficiency due to the need for extensive calculations by data users to prove decryption permissions.
The proposed method constructs a LSSS access structure with a shared column vector between the access matrix and sub-matrix, allowing reuse of decryption results across different levels, reducing computational load and enhancing efficiency.
This approach significantly reduces computational overhead and improves decryption efficiency by allowing shared calculations across access and sub-access strategies, thereby optimizing the decryption process.
Smart Images

Figure CN120281580A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and particularly to a method, apparatus, electronic device, and computer-readable storage medium for constructing an LSSS access structure supporting collaborative decryption. Background Art
[0002] Attribute-Based Encryption (ABE) technology is an encryption technology that controls data access based on user attributes. By binding access policies to user attributes, fine-grained access control can be achieved. Its user attributes can be user identity information, roles, departments, access permissions, etc. Based on these user attributes, dynamic authorization and management of data access can be realized.
[0003] An attribute-based encryption scheme supporting user collaborative decryption is an enhanced encryption technology in the above-mentioned attribute-based encryption technology. It combines the cryptographic mechanisms of attribute-based encryption and collaborative decryption, aiming to solve the problem of limited decryption ability of a single user in traditional ABE, while maintaining the characteristics of fine-grained access control. In the related technologies of ABE supporting user collaborative decryption, when a data user decrypts a ciphertext, it is necessary to first provide a calculation result to prove its decryption permission, and then calculate the plaintext through a decryption algorithm.
[0004] In this process, the data user needs to perform a large amount of calculations, so the calculation overhead is large and the decryption efficiency is low. Summary of the Invention
[0005] In view of the above problems, embodiments of the present invention are proposed to provide a method, apparatus, electronic device, and computer-readable storage medium for constructing an LSSS access structure supporting collaborative decryption that overcomes the above problems or at least partially solves the above problems.
[0006] On the one hand, an embodiment of the present invention provides a method for constructing an LSSS access structure supporting collaborative decryption, the method comprising: Determine a collaborative access policy, the collaborative access policy including collaborative attributes and sub-policies; Construct an LSSS access structure according to the collaborative access policy, the LSSS access structure including an access matrix M, the access matrix M including row vectors corresponding one-to-one to the sub-policies; Wherein, the access matrix M is used to determine a first column vector λ during the encryption process, the first column vector λ including a second column vector λ s ; and is used to construct a sub-access matrix M of the sub-policy during the encryption process sub , determine the third column vector λ corresponding to the sub-access matrix M sub sub The second column vector λ s is equal to the third column vector λ sub The first column vector λ and the third column vector λ sub are used to encrypt the plaintext; The access matrix M is also used to determine the sub - access matrix M of the sub - policy during the decryption process sub and determine the third column vector λ sub The sub - access matrix M sub and the third column vector λ sub are used to decrypt the ciphertext.
[0007] Optionally, the sub - access matrix M of the sub - policy sub is constructed according to the following formula:
[0008] where M s is a matrix constructed from the row vectors corresponding to the sub - policy in the access matrix M.
[0009] Optionally, the sub - access matrix M of the sub - policy sub is also used to determine an intermediate result during the decryption process, and the intermediate result is used to decrypt the ciphertext.
[0010] Optionally, the third column vector λ sub is determined according to the sub - vector v corresponding to the sub - policy sub The sub - vector v sub is used for encryption and decryption.
[0011] Optionally, the first column vector λ is determined according to the following formula:
[0012] where the column vector λ is used to distribute the shares of the secret s, M is the access matrix, and v is the random vector corresponding to the column vector λ; The random vector v is determined according to the following formula:
[0013] s is the secret and y is a randomly selected element.
[0014] Optionally, the sub - vector v corresponding to the sub - policy sub is determined according to the following formula:
[0015] where , where k is the number of sub - policies in the collaborative access policy.
[0016] On the other hand, an embodiment of the present invention provides a method for using a LSSS access structure supporting collaborative decryption, which is applied to a data owner. The method includes: Obtain the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a collaborative access policy, and the collaborative access policy includes collaborative attributes and sub - policies; the access matrix M includes row vectors corresponding one - to - one with the sub - policies. Determine a first column vector λ according to the access matrix M, and the first column vector λ includes a second column vector λ s ; Construct a sub - access matrix M of the sub - policy according to the access matrix M sub ; Determine a third column vector λ corresponding to the sub - access matrix M of the sub - policy sub , so that the third column vector λ sub is equal to the second column vector λ sub ; s ; Encrypt the plaintext according to the first column vector λ and the third column vector λ sub .
[0017] Optionally, the step of determining the first column vector λ according to the access matrix M includes: Determine the first column vector λ according to the following formula:
[0018] where M is the access matrix, v is the random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute shares of the secret s.
[0019] Optionally, the step of determining the first column vector λ includes: Determine the random vector v according to the following formula:
[0020] where s is the secret and y is a randomly selected element.
[0021] Optionally, the step of constructing the sub - access matrix M of the sub - policy according to the access matrix M sub includes: Determine the row vector corresponding to the sub - policy in the access matrix M; Construct the sub - access matrix M of the sub - policy according to the row vector corresponding to the sub - policy according to the following formula sub :
[0022] Among them, M s is a matrix constructed according to the row vector corresponding to the sub - policy in the access matrix M.
[0023] Optionally, determining the sub - access matrix M of the sub - policy sub corresponding to the third column vector λ sub , includes: Determining the sub - vector v of the sub - policy according to the following formula sub :
[0024] Wherein, is the row vector corresponding to the sub - policy in the access matrix M, v is the random vector corresponding to the column vector λ, , k is the number of sub - policies in the collaborative access policy; According to the sub - vector v of the sub - policy sub , determining the third column vector λ corresponding to the sub - access matrix M of the sub - policy sub sub .
[0025] On the other hand, an embodiment of the present invention provides a method for using an LSSS access structure supporting collaborative decryption, which is applied to a data user. The method includes: Obtaining the sub - access matrix M of the sub - policy sub , the sub - access matrix M of the sub - policy sub is constructed by the data owner according to the access matrix M of the collaborative access policy. The access matrix M is obtained from the LSSS access structure, and the LSSS access structure is constructed according to the collaborative access policy. The collaborative access policy includes collaborative attributes and the sub - policy; the access matrix M includes row vectors corresponding one - to - one with the sub - policies; Obtaining the third column vector λ corresponding to the sub - access matrix M of the sub - policy sub sub , the third column vector λ sub is determined by the data owner according to the sub - access matrix M of the sub - policy sub , the third column vector λ sub is equal to the second column vector λ s , the second column vector λ s is determined according to the first column vector λ of the access matrix M; Decrypting the ciphertext according to the sub - access matrix M of the sub - policy sub and the third column vector λ sub .
[0026] Optionally, the sub - access matrix M according to the sub - policy sub and the third column vector λ sub are used to decrypt the ciphertext, including: Based on the sub - access matrix M of the sub - policy sub , determine whether the attribute set of the data user satisfies the sub - policy; On the condition that it is determined that the attribute set of the data user satisfies the sub - policy, according to the third column vector λ sub , obtain the intermediate result R sub ; Based on the intermediate result R sub , decrypt the ciphertext.
[0027] Optionally, the decryption of the ciphertext based on the intermediate result R sub , includes: Construct an access matrix for decryption ; Based on the access matrix for decryption , determine whether the attribute set of the data user satisfies the collaborative access policy; On the condition that it is determined that the attribute set of the data user satisfies the collaborative access policy, obtain decryption parameters; Based on the decryption parameters and the intermediate result R sub , decrypt the ciphertext.
[0028] Optionally, the access matrix M includes row vectors corresponding to the collaborative attributes; The construction of the access matrix for decryption , includes: Construct an access matrix according to the following formula :
[0029] wherein, the and the are obtained from the access matrix M, the is the row vector corresponding to the collaborative attribute in the access matrix M, and the is the row vector corresponding to the sub - policy in the access matrix M.
[0030] On the other hand, an embodiment of the present invention provides a device for constructing an LSSS access structure supporting collaborative decryption, the device includes: A collaborative policy determination module, configured to determine a collaborative access policy, where the collaborative access policy includes collaborative attributes and sub - policies; An access structure construction module, configured to construct an LSSS access structure according to the collaborative access policy, where the LSSS access structure includes an access matrix M, and the access matrix M includes row vectors corresponding one by one to the sub-policies; Wherein, the access matrix M is used to determine a first column vector λ during the encryption process, and the first column vector λ includes a second column vector λ s ; and is used to construct a sub-access matrix M of the sub-policy during the encryption process sub , determine the sub-access matrix M sub corresponding third column vector λ sub , and the second column vector λ s is equal to the third column vector λ sub , and the first column vector λ and the third column vector λ sub are used to encrypt the plaintext; The access matrix M is further used to determine the sub-access matrix M of the sub-policy during the decryption process sub , determine the third column vector λ sub , and the sub-access matrix M sub and the third column vector λ sub are used to decrypt the ciphertext.
[0031] On the other hand, an embodiment of the present invention provides an LSSS access structure usage device supporting collaborative decryption, which is applied to a data owner, and the device includes: An access matrix acquisition module, configured to acquire the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a collaborative access policy, and the collaborative access policy includes collaborative attributes and sub-policies; the access matrix M includes row vectors corresponding one by one to the sub-policies; A first column vector determination module, configured to determine a first column vector λ according to the access matrix M, where the first column vector λ includes a second column vector λ s ; A sub-access matrix construction module, configured to construct a sub-access matrix M of the sub-policy according to the access matrix M sub ; A third column vector determination module, configured to determine a third column vector λ corresponding to the sub-access matrix M of the sub-policy sub , so that the third column vector λ sub is equal to the second column vector λ sub ; s ; An encryption module, configured to encrypt the plaintext according to the first column vector λ and the third column vector λ sub .
[0032] On the other hand, an embodiment of the present invention provides an apparatus for using an LSSS access structure supporting collaborative decryption, which is applied to a data user. The apparatus includes: A sub-access matrix acquisition module, configured to acquire a sub-access matrix M of a sub-policy sub , where the sub-access matrix M of the sub-policy sub is constructed by a data owner based on an access matrix M of a collaborative access policy. The access matrix M is obtained from an LSSS access structure, and the LSSS access structure is constructed according to the collaborative access policy. The collaborative access policy includes collaborative attributes and the sub-policy; the access matrix M includes row vectors corresponding one-to-one to the sub-policy; A third column vector acquisition module, configured to acquire a third column vector λ corresponding to the sub-access matrix M of the sub-policy sub , where the third column vector λ sub is determined by the data owner according to the sub-access matrix M of the sub-policy sub , and the third column vector λ sub is equal to a second column vector λ sub , where the second column vector λ s is obtained based on a first column vector λ of the access matrix M; s is obtained based on a first column vector λ of the access matrix M; A first decryption module, configured to decrypt a ciphertext according to the sub-access matrix M of the sub-policy sub and the third column vector λ sub .
[0033] On the other hand, an embodiment of the present invention provides an electronic device, including: a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the steps of the above-mentioned method for constructing an LSSS access structure supporting collaborative decryption, or implements the steps of the above-mentioned method for using an LSSS access structure supporting collaborative decryption.
[0034] On the other hand, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the above-mentioned method for constructing an LSSS access structure supporting collaborative decryption, or implements the steps of the above-mentioned method for using an LSSS access structure supporting collaborative decryption.
[0035] Embodiments of the present invention have the following advantages: The present invention constructs an LSSS access structure according to a collaborative access policy. The collaborative access policy includes collaborative attributes and sub-policies. The LSSS access structure includes an access matrix M, and the access matrix M includes row vectors corresponding one by one to the sub-policies. Among them, the access matrix M is used to determine the first column vector λ of the access matrix M during the encryption process, and construct the sub-access matrix M of the sub-policy sub , and determine the sub-access matrix M sub corresponding third column vector λ sub ; and make the second column vector λ in the first column vector λ s equal to the third column vector λ sub . Since during the encryption process, encryption-related calculations need to be performed according to the first column vector λ and the third column vector λ sub respectively, the present invention makes the second column vector λ in the first column vector λ s equal to the third column vector λ sub , so that the encryption-related calculation results for the third column vector λ sub can be used in the encryption-related calculations for the first column vector λ, saving the calculation overhead, and thus improving the encryption efficiency.
[0036] In addition, the access matrix M is also used to determine the sub-access matrix M of the sub-policy during the decryption process sub , and determine the third column vector λ sub . Since decryption-related calculations also need to be performed according to the first column vector λ and the third column vector λ sub respectively during the decryption process, the decryption-related calculation results for the third column vector λ sub can be used in the decryption calculations for the first column vector λ, further saving the calculation overhead, and thus improving the decryption efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0038] Figure 1 is a flowchart of the steps of a method for constructing an LSSS access structure supporting collaborative decryption provided by an embodiment of the present invention; Figure 2 is a flowchart of the steps of a method for using an LSSS access structure supporting collaborative decryption provided by an embodiment of the present invention; Figure 3 is a flowchart of the steps of another method for using an LSSS access structure supporting collaborative decryption provided by an embodiment of the present invention; Figure 4 It is a structural block diagram of a device for constructing an LSSS access structure that supports collaborative decryption provided by an embodiment of the present invention; Figure 5 It is a structural block diagram of a device for using an LSSS access structure that supports collaborative decryption provided by an embodiment of the present invention; Figure 6 It is a structural block diagram of another device for using an LSSS access structure that supports collaborative decryption provided by an embodiment of the present invention. Detailed implementation manners
[0039] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners.
[0040] Attribute - Based Encryption (ABE) technology is an encryption technology that controls data access based on user attributes. By binding access policies to user attributes, fine - grained access control can be achieved. Its user attributes can be user identity information, roles, departments, access permissions, etc. Based on these user attributes, dynamic authorization and management of data access permissions can be realized.
[0041] The attribute - based encryption scheme that supports user collaborative decryption is an enhanced encryption technology in the above - mentioned attribute - based encryption technology. It is a cryptographic mechanism that combines the ideas of attribute - based encryption and collaborative decryption, aiming to solve the problem of limited decryption ability of a single user in traditional ABE, while maintaining the characteristics of fine - grained access control.
[0042] In the ABE scheme, the access policy can be represented in forms such as Boolean formulas, threshold expressions, or Linear Secret Sharing Scheme (LSSS) matrices, etc. Among them, the LSSS matrix is widely used as a more general and efficient way to represent access policies.
[0043] For a secret sharing scheme Π that contains P participants, if there exists a vector composed of participants and constructed on and there exists an access matrix M, then Π is called a linear secret sharing scheme. For the access matrix M, define a mapping function , which maps each row in the matrix to each attribute of the participant, and is marked with , then it is called an LSSS access structure ( , ρ).
[0044] When a secret needs to be shared At this time, first randomly select and construct a random vector , then by calculating obtain a row-column vector λ for sharing the secret s, where represents the i-th participant. The linear reconstruction property of LSSS helps to reconstruct the secret s. If Π is the LSSS of the access structure , let A ∈ be any authorized set, and define as , then there always exists a constant set such that holds. If λ is a legal share of the secret s, then the secret s can be recovered by calculating i .
[0045] In the ABE-related technologies that support user collaborative decryption, assume that a collaborative access policy is , where ca is the collaborative attribute, and p1, p2 are sub-policies. If a data user wants to decrypt the ciphertext, they first need to perform calculations related to the sub-policies to prove that they have the decryption permission and can participate in collaborative decryption, and then perform calculations related to the collaborative access policy to decrypt the ciphertext. In this process, the data user needs to perform a large amount of calculations, so the computational overhead is large and the decryption efficiency is low.
[0046] One of the core concepts of the embodiments of the present invention is to use the calculation results related to the sub-policies in the calculations related to the collaborative access policy, thereby reducing the amount of calculations and improving the calculation efficiency.
[0047] The present invention constructs an LSSS access structure that supports collaborative decryption, making the column vectors corresponding to the access matrix M of the collaborative access policy partially the same as the column vectors of the sub-access matrix M sub of the sub-policy. Furthermore, in the encryption and decryption processes, the calculation results for the column vectors corresponding to the sub-policy can be used in the calculations for the column vectors corresponding to the collaborative access policy, reducing the amount of calculations in the encryption and decryption processes, thereby improving the encryption and decryption efficiency.
[0048] Figure 1 is a flowchart of the steps of a method for constructing an LSSS access structure that supports collaborative decryption provided by the embodiments of the present invention.
[0049] As Figure 1 shown, the method may specifically include the following steps: Step 101, determine the collaborative access policy, where the collaborative access policy includes a collaborative attribute and sub-policies; Convert a conventional access policy into a collaborative access policy, where the collaborative access policy includes collaborative attributes and sub-policies, so as to be able to perform subsequent calculations on the sub-policies and use the calculation results for the calculations on the collaborative access policy to achieve the effect of reducing the amount of calculation.
[0050] As an example, convert the conventional access policy into a collaborative access policy .
[0051] In an actual application scenario, when a user is performing encryption and decryption operations in an encryption and decryption management system, if User 1 meets the sub-policy p1, according to the collaborative access policy, if User 1 wants to decrypt the ciphertext, then User 1 needs to prove that it meets the sub-policy p1, and User 1 has the qualification to obtain the collaborative attributes before User 1 can decrypt to obtain the plaintext. Whether User 1 has the qualification to obtain the collaborative attributes needs to be judged by the encryption and decryption management system. In the present invention, it is set that the user has the qualification to obtain the collaborative attributes.
[0052] Step 102, construct an LSSS access structure according to the collaborative access policy, where the LSSS access structure includes an access matrix M, and the access matrix M includes row vectors corresponding one by one to the sub-policies; Wherein, the access matrix M is used to determine a first column vector λ during the encryption process, and the first column vector λ includes a second column vector λ s ; and is used to construct a sub-access matrix M of the sub-policy during the encryption process sub , determine the third column vector λ corresponding to the sub-access matrix M sub , and the second column vector λ sub is equal to the third column vector λ s , and the first column vector λ and the third column vector λ sub are used to encrypt the plaintext; sub sub The access matrix M is further used to determine the sub-access matrix M of the sub-policy during the decryption process sub , determine the third column vector λ sub , and the sub-access matrix M sub and the third column vector λ sub are used to decrypt the ciphertext.
[0053] In an actual application scenario, the data owner determines the first column vector λ according to the access matrix M of the collaborative access policy, and constructs the sub-access matrix M of the sub-policy sub , determines the third column vector λ corresponding to the sub-access matrix M sub . And encrypt the plaintext according to the first column vector λ and the third column vector λ sub . sub
[0054] The data user decrypts the ciphertext according to the sub - access matrix M sub and the third column vector λ sub The specific process will be explained below.
[0055] As an example, according to the collaborative access policy Construct the following access matrix M:
[0056] Wherein, is the row vector representing the collaborative attribute ca, is the sub - matrix of the mapping sub - policy Its construction follows the general construction method of the LSSS matrix, is the construction The repeated row vector generated during the process.
[0057] In the collaborative access policy CP, ca is the collaborative attribute, p1, p2, and p3 are sub - policies, each sub - policy contains several attributes, and the access matrix M includes row vectors corresponding one - to - one with each attribute. The dashed lines in the above - mentioned access matrix M divide the access matrix M into different regions according to the sub - policies, for extracting the sub - matrices of different sub - policies.
[0058] In some embodiments, the sub - access matrix M of the sub - policy sub is constructed according to the following formula:
[0059] Wherein, M s is the matrix constructed according to the row vectors corresponding to the sub - policy in the access matrix M.
[0060] Each sub - policy has its own sub - access matrix M sub , specifically, a group of row vectors corresponding to the sub - policy are taken out from the access matrix M, and the column vectors that are all 0 are removed to obtain the matrix M s , then a column vector of all 1s is added to the left side of the matrix M s to obtain the sub - access matrix M sub . The sub - access matrix M sub is used to determine the third column vector λ sub corresponding to the sub - policy.
[0061] In some embodiments, the sub - access matrix M of the sub - policy sub is also used to determine the intermediate result during the decryption process, and the intermediate result is used to decrypt the ciphertext.
[0062] During the decryption process, it is first necessary to determine whether the attribute set of the data user satisfies one of the sub-policies in the collaborative access policy. In this process, calculations need to be performed according to the sub-access matrix M sub and intermediate results can be obtained , and the ciphertext is decrypted through the intermediate results , which can save the computational overhead and thus improve the decryption efficiency.
[0063] In some embodiments, the third column vector λ sub is determined according to the sub-vector v sub corresponding to the sub-policy, and the sub-vector v sub is used for encryption and decryption.
[0064] In the LSSS scheme, when a secret s needs to be shared, a random vector v usually needs to be constructed. The first element of the random vector v is s, and the other elements are randomly selected. Then the column vector λ of the access matrix M for sharing the secret s is calculated through λ = Mv.
[0065] In the present invention, for the sub-access matrix M of the sub-policy sub , when determining its third column vector λ sub , it is not determined by constructing the above random vector, but a determined sub-vector v sub is set, and then the third column vector λ sub is determined. And through the determined sub-vector v sub , the third column vector λ sub is made equal to the second column vector λ in the first column vector λ of the access matrix M s , so as to reduce the amount of calculation when performing encryption and decryption calculations related to column vectors.
[0066] That is , where , . The second column vector λ s corresponds to the row vector of the access matrix M corresponding to the sub-policy, and the third column vector λ sub corresponds to the row vector in the sub-access matrix M sub of the sub-policy, and the second column vector λ s is also a part of the first column vector λ, that is, the elements corresponding to the sub-policy in the first column vector λ and the third column vector λsub are the same.
[0067] In some embodiments, the first column vector λ is determined according to the following formula:
[0068] Among them, the column vector λ is used to distribute the shares of the secret s, M is the access matrix, and v is the random vector corresponding to the column vector λ; The random vector v is determined according to the following formula:
[0069] s is the secret, and y is a randomly selected element.
[0070] In some embodiments, the sub-vector v corresponding to the sub-policy sub is determined according to the following formula:
[0071] Among them, , and k is the number of sub-policies in the collaborative access policy.
[0072] By setting the above sub-vector v sub , and according to this sub-vector v sub to determine the third column vector λ sub , thus eliminating the need to construct new random variables for sub-policies and recalculate the third column vector λ sub , directly making the second column vector λs in the first column vector λ equal to the third column vector λ sub , and the second column vector λs corresponds to the row vector of the sub-policy in the access matrix M, that is, the elements of the corresponding sub-policy in the first column vector λ and the third column vector λ sub are the same.
[0073] Each element in the third column vector λ sub corresponds to an attribute in the sub-policy. The elements of the corresponding sub-policy in the first column vector λ and the third column vector λ sub are the same, that is, the processing results of the attributes of each sub-policy in the relevant calculations of the third column vector λ sub can be reused in the relevant calculations of the first column vector λ for the attributes of each sub-policy, thus avoiding the repeated processing of each attribute in the collaborative access policy and improving the processing efficiency.
[0074] Figure 2 is a flowchart of the steps of a method for using an LSSS access structure supporting collaborative decryption provided by an embodiment of the present invention, which is applied to a data owner.
[0075] As Figure 2 shown, the method may specifically include the following steps: Step 201, obtain the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a collaborative access policy, and the collaborative access policy includes collaborative attributes and sub-policies; the access matrix M includes row vectors corresponding one-to-one to the sub-policies. The access matrix M is constructed by adopting the above construction method, which will not be elaborated here.
[0076] In the encryption and decryption system, the data owner encrypts the data using the access policy and stores the data in the cloud, relying on the cloud to maintain the data. The data owner can be an enterprise or an individual.
[0077] Step 202, determine the first column vector λ according to the access matrix M, and the first column vector λ includes a second column vector λ s ; In some embodiments, step 202 specifically includes the following sub-steps: Sub-step S11, determine the first column vector λ according to the following formula:
[0078] where M is the access matrix, v is the random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute the share of the secret s.
[0079] In some embodiments, step 202 specifically includes the following sub-steps: Sub-step S21, determine the random vector v according to the following formula:
[0080] where s is the secret and y is a randomly selected element.
[0081] Step 203, construct the sub-access matrix M of the sub-policy according to the access matrix M sub ; In some embodiments, step 203 specifically includes the following sub-steps: Sub-step S31, determine the row vector corresponding to the sub-policy in the access matrix M; Sub-step S32, construct the sub-access matrix M of the sub-policy according to the row vector corresponding to the sub-policy according to the following formula sub :
[0082] where M s is a matrix constructed according to the row vector corresponding to the sub-policy in the access matrix M.
[0083] Each sub-policy has its own sub-access matrix Msub Specifically, a group of row vectors corresponding to the sub-policy are taken from the access matrix M, and the column vectors that are all 0 are removed to obtain the matrix M s , and then to the left of the matrix M s a column vector all of whose elements are 1 is added, so as to obtain the sub-access matrix M sub . The sub-access matrix M sub is used to determine the third column vector λ corresponding to the sub-policy sub .
[0084] Step 204: Determine the third column vector λ corresponding to the sub-access matrix M of the sub-policy sub , so that the third column vector λ sub is equal to the second column vector λ sub of the sub-policy s ; In collaborative decryption, it is necessary to determine whether the decrypting party has the qualification for collaboration. Therefore, the decrypting party needs to provide a proof of the calculation result that satisfies a certain sub-policy. Thus, it is necessary to process the sub-policy and the collaborative access policy separately. The collaborative access policy embeds the secret s. Decrypting the collaborative access policy requires restoring the secret s. For each sub-policy, the decrypting party needs to prove that it satisfies the sub-policy, which can also be regarded as the sub-policy embedding different secret s'. The decrypting party needs to first restore the secret s' of the sub-policy to prove that it has the decryption permission (satisfies a certain sub-policy) and can participate in the collaboration, and then can decrypt the collaborative access policy to restore the secret s and thus decrypt the ciphertext.
[0085] In the above process, both the encrypting party and the decrypting party need to process the collaborative access policy and the sub-policy simultaneously, and each attribute in the policy will be processed during the process. The collaborative access policy contains sub-policies, that is, the collaborative access policy contains sub-policy attributes. This results in each attribute being processed twice when processing the collaborative access policy and the sub-policy during encryption and decryption, thus increasing the computational cost and the size of the ciphertext. Therefore, in the present invention, the calculation result of each attribute can be used simultaneously for decrypting the sub-policy and decrypting the collaborative access policy, that is, the third column vector λ sub of the sub-policy is made equal to the second column vector λ s of the collaborative access policy s (the second column vector λ sub is the row vector corresponding to the sub-policy in λ = Mv). In this way, the encrypting party no longer needs to recalculate the third column vector λ
[0086] In some embodiments, step 204 specifically includes the following sub-steps: Sub-step S41: Determine the sub-vector v of the sub-policy according to the following formula sub :
[0087] Among them, is the row vector corresponding to the sub-policy in the access matrix M, v is the random vector corresponding to the column vector λ, , and k is the number of sub-policies in the collaborative access policy; Sub-step S42, according to the sub-vector v of the sub-policy sub , determine the sub-access matrix M of the sub-policy sub corresponding to the third column vector λ sub .
[0088] In the LSSS scheme, when sharing a secret s, it is usually necessary to construct a random vector v. The first element of the random vector v is s, and other elements are randomly selected. Then, the column vector λ for sharing the secret s of the access matrix M is calculated by λ = Mv.
[0089] For the sub-access matrix M of the sub-policy of the present invention sub , when determining its third column vector λ sub , it is not determined by constructing the above random vector, but by setting the determined sub-vector v sub , and then determining the third column vector λ sub . And through the determined sub-vector v sub , the third column vector λ sub is equal to the second column vector λ in the first column vector λ of the access matrix M s , so that there is no need to re-select v sub , and there is no need to recalculate λ sub , reducing the computational complexity.
[0090] Step 205, encrypt the plaintext according to the first column vector λ and the third column vector λ sub .
[0091] In an actual application scenario, the data owner encrypts the data plaintext according to the first column vector λ, the third column vector λ sub and the encryption key to obtain the data ciphertext.
[0092] Figure 3 is the flowchart of the steps of another method for using the LSSS access structure supporting collaborative decryption provided by the embodiment of the present invention, which is applied to the data user.
[0093] As Figure 3 shown, the method may specifically include the following steps: Step 301, obtain the sub-access matrix M of the sub-policy sub , the sub-access matrix M of the sub-policy sub, which is constructed by the data owner according to the access matrix M of the collaborative access policy. The access matrix M is obtained from the LSSS access structure, and the LSSS access structure is constructed according to the collaborative access policy. The collaborative access policy includes collaborative attributes and the sub-policy; the access matrix M includes row vectors corresponding one-to-one to the sub-policies; In the encryption and decryption system, the data user accesses the data shared by the data owner in the cloud, downloads the data it needs, and can decrypt the data with its own key under the condition that the attribute set of the data user can meet the access policy of the data.
[0094] Step 302, obtain the sub-access matrix M of the sub-policy sub The corresponding third column vector λ sub , the third column vector λ sub is determined by the data owner according to the sub-access matrix M of the sub-policy sub , and the third column vector λ sub is equal to the second column vector λ s , and the second column vector λ s is determined according to the first column vector λ of the access matrix M; The sub-access matrix M of the sub-policy obtained by the data user sub and the third column vector λ sub for the ciphertext are both determined by the above-mentioned data owner, which will not be elaborated here.
[0095] Step 303, decrypt the ciphertext according to the sub-access matrix M of the sub-policy sub and the third column vector λ sub ;
[0096] In some embodiments, step 303 specifically includes the following sub-steps: Sub-step S51, according to the sub-access matrix M of the sub-policy sub , determine whether the attribute set of the data user meets the sub-policy; Similar to the access matrix M of the collaborative access policy, for the sub-access matrix M of the sub-policy sub , to determine whether the attribute set of the data user meets the sub-policy, that is, to recover the secret s' in the sub-access matrix M sub ;
[0097] Sub-step S52, under the condition that it is determined that the attribute set of the data user meets the sub-policy, according to the third column vector λ sub , obtain the intermediate result R sub ; As an example, the access structure of the sub-policy is , define the authorization set For , the data user can find a set of constants that satisfy . Then, the data user can obtain and calculate the intermediate result .
[0098] Sub-step S53, decrypt the ciphertext according to the intermediate result R sub .
[0099] In some embodiments, sub-step S53 includes the following sub-steps: Sub-step S531, construct an access matrix for decryption ; according to the access matrix for decryption , determine whether the attribute set of the data user satisfies the collaborative access policy; under the condition that it is determined that the attribute set of the data user satisfies the collaborative access policy, obtain decryption parameters; according to the decryption parameters and the intermediate result R sub , decrypt the ciphertext.
[0100] In some embodiments, sub-step S531 includes the following sub-steps: Sub-step S5311, construct an access matrix according to the following formula :
[0101] wherein, the and the are obtained according to the access matrix M, the is the row vector corresponding to the collaborative attribute in the access matrix M, and the is the row vector corresponding to the sub-policy in the access matrix M.
[0102] For the access matrix , regard the sub-policy as a single attribute, and determine whether the attribute set of the data user satisfies the collaborative access policy, that is, whether it satisfies the collaborative attribute and the sub-policy attribute. If the attribute set of the data user satisfies the collaborative access policy, decryption parameters can be obtained, and thus, according to the decryption parameters and the intermediate result R sub , decrypt the ciphertext.
[0103] In this process, the data user first performs decryption calculations related to M sub , and the intermediate result R sub obtained can be directly used in related decryption calculations, thus saving the calculation overhead and improving the decryption efficiency.
[0104] It should be noted that, for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, some steps can be carried out in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0105] Figure 4 It is a structural block diagram of a device for constructing an LSSS access structure supporting collaborative decryption provided by an embodiment of the present invention.
[0106] As Figure 4 shown, a structural block diagram of a device for constructing an LSSS access structure supporting collaborative decryption provided by an embodiment of the present invention may specifically include the following modules: A collaborative strategy determination module 401, configured to determine a collaborative access strategy, where the collaborative access strategy includes collaborative attributes and sub-strategies; An access structure construction module 402, configured to construct an LSSS access structure according to the collaborative access strategy, where the LSSS access structure includes an access matrix M, and the access matrix M includes row vectors corresponding one by one to the sub-strategies; Wherein, the access matrix M is used to determine a first column vector λ during the encryption process, and the first column vector λ includes a second column vector λ s ; and is used to construct a sub-access matrix M of the sub-strategy during the encryption process sub , determine the third column vector λ corresponding to the sub-access matrix M sub , and the second column vector λ sub is equal to the third column vector λ s , and the first column vector λ and the third column vector λ sub are used to encrypt the plaintext; sub The access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process , determine the third column vector λ sub , and the sub-access matrix M sub and the third column vector λ sub are used to decrypt the ciphertext. sub
[0107] Figure 5 It is a structural block diagram of a device for using an LSSS access structure supporting collaborative decryption provided by an embodiment of the present invention, which is applied to a data owner.
[0108] As Figure 5 shown, the device may specifically include the following modules: The access matrix acquisition module 501 is configured to acquire an access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a collaborative access policy, and the collaborative access policy includes collaborative attributes and sub-policies; the access matrix M includes row vectors corresponding to the sub-policies one by one. The first column vector determination module 502 is configured to determine a first column vector λ according to the access matrix M, and the first column vector λ includes a second column vector λ s ; The sub-access matrix construction module 503 is configured to construct a sub-access matrix M of the sub-policy according to the access matrix M sub ; The third column vector determination module 504 is configured to determine a third column vector λ corresponding to the sub-access matrix M of the sub-policy sub such that the third column vector λ sub is equal to the second column vector λ sub ; s ; The encryption module 505 is configured to encrypt the plaintext according to the first column vector λ and the third column vector λ sub .
[0109] In some embodiments, the first column vector determination module 502 includes the following sub-modules: The first column vector determination sub-module is configured to determine the first column vector λ according to the following formula:
[0110] where M is the access matrix, v is a random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute shares of the secret s.
[0111] In some embodiments, the first column vector determination module 502 includes the following sub-modules: The random vector determination sub-module is configured to determine the random vector v according to the following formula:
[0112] where s is the secret and y is a randomly selected element.
[0113] In some embodiments, the sub-access matrix construction module 503 includes the following sub-modules: The row vector determination sub-module is configured to determine the row vector corresponding to the sub-policy in the access matrix M; The sub-access matrix construction sub-module is configured to construct the sub-access matrix M of the sub-policy according to the row vector corresponding to the sub-policy according to the following formula sub :
[0114] Among them, M s It is a matrix constructed according to the row vector corresponding to the sub-strategy in the access matrix M.
[0115] In some embodiments, the third column vector determination module 504 includes the following submodules: The sub-vector determination sub-module is used to determine the sub-vector v of the sub-strategy according to the following formula sub :
[0116] in, is the row vector corresponding to the sub-strategy in the access matrix M, v is the random vector corresponding to the column vector λ, , k is the number of sub-strategies in the collaborative access strategy; The third column vector determination submodule is used to determine the subvector v of the substrategy according to the substrategy sub , determine the sub-access matrix M of the sub-strategy sub The corresponding third column vector λ sub .
[0117] Figure 6 It is a structural block diagram of an LSSS access structure using device supporting collaborative decryption provided by an embodiment of the present invention, which is applied to data users.
[0118] like Figure 6 As shown, the device may specifically include the following modules: The sub-access matrix acquisition module 601 is used to obtain the sub-access matrix M of the sub-strategy. sub , the sub-access matrix M of the sub-strategy sub , is constructed by the data owner according to the access matrix M of the collaborative access strategy, the access matrix M is obtained from the LSSS access structure, the LSSS access structure is constructed according to the collaborative access strategy, the collaborative access strategy includes the collaborative attribute and the sub-strategy; the access matrix M includes row vectors corresponding to the sub-strategies one by one; The third column vector acquisition module 602 is used to obtain the sub-access matrix M of the sub-strategy sub The corresponding third column vector λ sub , the third column vector λ sub is the sub-access matrix M of the data owner according to the sub-strategy sub Determined, the third column vector λ sub Equal to the second column vector λ s , the second column vector λ s is determined according to the first column vector λ of the access matrix M; The first decryption module 603 is configured to decrypt the ciphertext according to the sub - access matrix M of the sub - policy sub and the third column vector λ sub
[0119] In some embodiments, the first decryption module 603 includes the following sub - modules: The first attribute determination sub - module is configured to determine whether the attribute set of the data user satisfies the sub - policy according to the sub - access matrix M of the sub - policy sub The intermediate result acquisition sub - module is configured to obtain an intermediate result R according to the third column vector λ when it is determined that the attribute set of the data user satisfies the sub - policy sub sub ; The second decryption sub - module is configured to decrypt the ciphertext according to the intermediate result R sub
[0120] In some embodiments, the second decryption sub - module includes the following units: The decryption matrix construction unit is configured to construct an access matrix for decryption The second attribute determination unit is configured to determine whether the attribute set of the data user satisfies the collaborative access policy according to the access matrix for decryption The decryption parameter acquisition unit is configured to obtain decryption parameters when it is determined that the attribute set of the data user satisfies the collaborative access policy; The third decryption unit is configured to decrypt the ciphertext according to the decryption parameters and the intermediate result R sub
[0121] In some embodiments, the decryption matrix construction unit includes the following sub - units: The decryption matrix construction sub - unit is configured to construct an access matrix according to the following formula :
[0122] wherein, the and the are obtained according to the access matrix M, the is the row vector corresponding to the collaborative attribute in the access matrix M, and the is the row vector corresponding to the sub - policy in the access matrix M.
[0123] For the apparatus embodiments, since they are basically similar to the method embodiments, they are described relatively simply. For the relevant parts, please refer to the corresponding descriptions in the method embodiments.
[0124] An embodiment of the present invention further provides an electronic device, including: a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements each process of the above-described embodiments of the method for constructing an LSSS access structure supporting collaborative decryption or the method for using an LSSS access structure supporting collaborative decryption, and can achieve the same technical effects. To avoid repetition, details are not described herein again.
[0125] An embodiment of the present invention further provides a computer-readable storage medium with a computer program stored thereon. When the computer program is executed by a processor, it implements each process of the above-described embodiments of the method for constructing an LSSS access structure supporting collaborative decryption or the method for using an LSSS access structure supporting collaborative decryption, and can achieve the same technical effects. To avoid repetition, details are not described herein again.
[0126] Each embodiment in this specification is described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0127] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0128] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the method, terminal device (system), and computer program product according to the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowcharts and / or block diagrams can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0129] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 specified in one block or multiple blocks.
[0130] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, such that a series of operation steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 specified in one block or multiple blocks.
[0131] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.
[0132] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.
[0133] The above has introduced in detail a method, apparatus, electronic device and computer-readable storage medium for constructing an LSSS access structure that supports collaborative decryption. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A method for constructing an LSSS access structure that supports collaborative decryption, characterized in that, The method includes: Determine a collaborative access policy, where the collaborative access policy includes collaborative attributes and sub-policies; Construct an LSSS access structure according to the collaborative access policy, where the LSSS access structure includes an access matrix M, and the access matrix M includes row vectors corresponding one-to-one to the sub-policies; Among them, the access matrix M is used to determine the first column vector λ during the encryption process, and the second column vector λ is included in the first column vector λ s ; and the sub-access matrix M for constructing the sub-policy during the encryption process sub , determine the sub-access matrix M sub corresponding third column vector λ sub , the second column vector λ s is equal to the third column vector λ sub , the first column vector λ and the third column vector λ sub are used to encrypt the plaintext; The access matrix M is also used to determine the sub-access matrix M of the sub-policy during the decryption process sub , to determine the third column vector λ sub , the sub-access matrix M sub and the third column vector λ sub are used to decrypt the ciphertext.
2. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 1, characterized in that, The sub-access matrix M of the sub-policy sub is constructed according to the following formula: Among them, M s is a matrix constructed according to the row vector corresponding to the sub-policy in the access matrix M.
3. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 2, characterized in that, The sub - access matrix M of the sub - strategy sub is also used to determine intermediate results during the decryption process , and the intermediate results are used to decrypt the ciphertext.
4. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 1, wherein, The third column vector λ sub , is determined according to the sub-vector v sub corresponding to the sub-strategy, and the sub-vector v sub is used for encryption and decryption.
5. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 1, characterized in that, The first column vector λ is determined according to the following formula: where the column vector λ is used to distribute shares of the secret s, M is the access matrix, and v is a random vector corresponding to the column vector λ; The random vector v is determined according to the following formula: s is the secret, and y is a randomly selected element.
6. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 4, characterized in that The sub-vector v corresponding to the sub-strategy sub is determined according to the following formula: Among them, , where k is the number of sub-policies in the collaborative access policy.
7. A method for using an LSSS access structure supporting collaborative decryption, characterized in that, Applied to a data owner, the method includes: Obtain the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a collaborative access policy, where the collaborative access policy includes collaborative attributes and sub-policies; the access matrix M includes row vectors corresponding one-to-one to the sub-policies; Determine a first column vector λ according to the access matrix M, where the first column vector λ includes a second column vector λ s ; Construct a sub - access matrix M of the sub - policy according to the access matrix M sub ; Determine the sub - access matrix M of the sub - policy sub The corresponding third column vector λ sub , so that the third column vector λ sub is equal to the second column vector λ s ; According to the first column vector λ and the third column vector λ sub encrypt the plaintext.
8. The method for using the LSSS access structure supporting collaborative decryption according to claim 7, characterized in that, The determining the first column vector λ according to the access matrix M includes: Determine the first column vector λ according to the following formula: where M is the access matrix, v is a random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute shares of the secret s.
9. The method for using an LSSS access structure supporting collaborative decryption according to claim 8, wherein The determining the first column vector λ includes: Determine the random vector v according to the following formula: where s is the secret, and y is a randomly selected element.
10. The method for using the LSSS access structure supporting collaborative decryption according to claim 7, characterized in that, Construct the sub-access matrix M of the sub-policy according to the access matrix M sub , including: Determine the row vector corresponding to the sub-policy in the access matrix M; Construct the sub-access matrix M of the sub-strategy according to the row vector corresponding to the sub-strategy and the following formula sub : Among them, M s is a matrix constructed according to the row vector corresponding to the sub-strategy in the access matrix M.
11. The method for using an LSSS access structure supporting collaborative decryption according to claim 9, characterized in that, Determining the sub - access matrix M of the sub - policy sub The corresponding third - column vector λ sub , including: Determine the sub-vector v of the sub-strategy according to the following formula sub : Among them, is the row vector corresponding to the sub-policy in the access matrix M, v is the random vector corresponding to the column vector λ, , and k is the number of sub-policies in the collaborative access policy; Sub-vector v of the sub-strategy sub , determine the sub-access matrix M of the sub-strategy sub corresponding to the third column vector λ sub .
12. A method for using an LSSS access structure supporting collaborative decryption, characterized in that, Applied to a data user, the method includes: Obtain the sub - access matrix M of the sub - policy sub , the sub - access matrix M of the sub - policy sub , is constructed by the data owner according to the access matrix M of the collaborative access policy. The access matrix M is obtained from the LSSS access structure, and the LSSS access structure is constructed according to the collaborative access policy. The collaborative access policy includes collaborative attributes and the sub - policy; the access matrix M includes row vectors corresponding one - to - one with the sub - policies; Obtain the sub - access matrix M of the sub - policy sub The corresponding third - column vector λ sub , the third - column vector λ sub is determined by the data owner according to the sub - access matrix M of the sub - policy sub , the third - column vector λ sub is equal to the second - column vector λ s , the second - column vector λ s is determined according to the first - column vector λ of the access matrix M; Sub - access matrix M according to the sub - strategy sub and the third column vector λ sub Decrypt the ciphertext.
13. The method for using the LSSS access structure supporting collaborative decryption according to claim 12, wherein The sub - access matrix M according to the sub - policy sub and the third column vector λ sub Decrypt the ciphertext, including: Sub - access matrix M according to the sub - policy sub , determine whether the attribute set of the data user satisfies the sub - policy; Under the condition that it is determined that the attribute set of the data user satisfies the sub-policy, according to the third column vector λ sub , an intermediate result R sub ; Based on the intermediate result R sub , decrypt the ciphertext.
14. The method for using an LSSS access structure supporting collaborative decryption according to claim 13, characterized in that, According to the intermediate result R sub , decrypt the ciphertext, including: Construct an access matrix for decryption ; According to the access matrix for decryption , determine whether the attribute set of the data user satisfies the collaborative access policy; Obtain decryption parameters under the condition that it is determined that the attribute set of the data user satisfies the collaborative access policy; Based on the decryption parameter and the intermediate result R sub , decrypt the ciphertext.
15. The method for using an LSSS access structure supporting collaborative decryption according to claim 14, wherein The access matrix M includes row vectors corresponding to the collaborative attributes; The structure is an access matrix for decryption , including: Construct an access matrix according to the following formula :[[-END]] Among them, the and the are obtained according to the access matrix M, the is the row vector corresponding to the collaboration attribute in the access matrix M, and the is the row vector corresponding to the sub-strategy in the access matrix M.
16. An LSSS access structure construction device supporting collaborative decryption, characterized in that, The apparatus includes: A collaborative policy determination module, configured to determine a collaborative access policy, where the collaborative access policy includes collaborative attributes and sub-policies; An access structure construction module, configured to construct an LSSS access structure according to the collaborative access policy, where the LSSS access structure includes an access matrix M, and the access matrix M includes row vectors corresponding one-to-one to the sub-policies; Among them, the access matrix M is used to determine the first column vector λ during the encryption process, and the second column vector λ is included in the first column vector λ s ; and the sub-access matrix M for constructing the sub-policy during the encryption process sub , determine the sub-access matrix M sub corresponding third column vector λ sub , the second column vector λ s is equal to the third column vector λ sub , the first column vector λ and the third column vector λ sub are used to encrypt the plaintext; The access matrix M is also used to determine the sub-access matrix M of the sub-policy during the decryption process sub , to determine the third column vector λ sub , the sub-access matrix M sub and the third column vector λ sub are used to decrypt the ciphertext.
17. An apparatus for using an LSSS access structure supporting collaborative decryption, characterized in that Applied to a data owner, the apparatus includes: An access matrix acquisition module, configured to obtain the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a collaborative access policy, where the collaborative access policy includes collaborative attributes and sub-policies; the access matrix M includes row vectors corresponding one-to-one to the sub-policies; The first column vector determination module is configured to determine a first column vector λ according to the access matrix M, where the first column vector λ includes a second column vector λ s ; The sub-access matrix construction module is used to construct the sub-access matrix M of the sub-policy according to the access matrix M sub ; The third column vector determination module is configured to determine the sub-access matrix M of the sub-strategy sub The corresponding third column vector λ sub , so that the third column vector λ sub is equal to the second column vector λ s ; Encryption module, for encrypting plaintext according to the first column vector λ and the third column vector λ sub 18. An apparatus for using an LSSS access structure supporting collaborative decryption, characterized in that, Applied to a data user, the apparatus includes: Sub-access matrix acquisition module, for acquiring the sub-access matrix M of the sub-policy sub , the sub-access matrix M of the sub-policy sub , is constructed by the data owner according to the access matrix M of the collaborative access policy, the access matrix M is obtained from the LSSS access structure, the LSSS access structure is constructed according to the collaborative access policy, and the collaborative access policy includes collaborative attributes and the sub-policy; the access matrix M includes row vectors corresponding one-to-one to the sub-policies; The third column vector obtaining module is configured to obtain the sub-access matrix M of the sub-policy sub The corresponding third column vector λ sub , the third column vector λ sub is determined by the data owner according to the sub-access matrix M of the sub-policy sub , the third column vector λ sub is equal to the second column vector λ s , the second column vector λ s is determined according to the first column vector λ of the access matrix M; The first decryption module is used to decrypt the ciphertext according to the sub-access matrix M of the sub-policy sub and the third column vector λ sub 19. An electronic device, characterized in that, including: A processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the steps of the LSSS access structure construction method for supporting collaborative decryption according to any one of claims 1-6, or implements the steps of the LSSS access structure usage method for supporting collaborative decryption according to any one of claims 7-11 or 12-15.
20. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements the steps of the method for constructing an LSSS access structure supporting collaborative decryption as described in any one of claims 1-6, or implements the steps of the method for using an LSSS access structure supporting collaborative decryption as described in any one of claims 7-11 or 12-15.
Citation Information
Patent Citations
Lattice attribute-based signature method capable of supporting LSSS matrix
CN111030809A
Cross-domain ciphertext data sharing method and system supporting access behavior auditing
CN117675297A
Attribute-based hierarchical data encryption and decryption method and device and storage medium
CN118041622A
Decentralized multi-authority attribute-based encryption with fully adaptive security
WO2022232042A1