A method and apparatus for constructing an LSSS access structure that supports collaborative decryption.

By constructing an LSSS access structure that supports collaborative decryption, the problem of high computational overhead in user collaborative decryption is solved, and an efficient encryption and decryption process is achieved.

CN120281580BActive Publication Date: 2025-10-28THREE GORGES GROUP IND DEVELOPMENT (BEIJING) CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510757674.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-10-28
Estimated Expiration
2045-06-09

AI Technical Summary

Technical Problem

In attribute-based encryption (ABE) technology that supports collaborative decryption, data users incur significant computational overhead and low decryption efficiency when performing decryption.

Method used

Construct an LSSS access structure that supports collaborative decryption. By making the column vectors of the access matrix M of the collaborative access strategy the same as the column vectors of the sub-access matrix Msub of the sub-strategy, the computational load in the encryption and decryption process is reduced.

Benefits of technology

It improves the computational efficiency of encryption and decryption, and reduces computational overhead and ciphertext size.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281580B_ABST
    Figure CN120281580B_ABST
Patent Text Reader

Abstract

This invention provides a method and apparatus for constructing an LSSS access structure that supports collaborative decryption. The method includes: constructing an LSSS access structure according to a collaborative access strategy, wherein an access matrix M in the LSSS access structure is used to determine a first column vector λ, and the first column vector λ includes a second column vector λ. s ; and the sub-access matrix M used to construct the sub-strategy sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used for encryption; Sub-access matrix M sub and the third column vector λ sub Used for decryption. In this embodiment of the invention, the second column vector λ is used... s Equal to the third column vector λ sub Thus, for the third column vector λ sub The relevant calculation results can be used in the relevant calculations for the first column vector λ, saving computational overhead and thus improving encryption and decryption efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer security technology, and in particular to a method, apparatus, electronic device, and computer-readable storage medium for constructing an LSSS access structure that supports collaborative decryption. Background Technology

[0002] Attribute-Based Encryption (ABE) is an encryption technology that controls data access based on user attributes. By binding access policies to user attributes, it enables fine-grained access control. User attributes can include user identity information, roles, departments, access permissions, etc., enabling dynamic authorization and management of data access.

[0003] Attribute-based encryption schemes that support collaborative decryption are an enhanced version of the aforementioned attribute-based encryption techniques. They integrate the cryptographic mechanisms of attribute-based encryption and collaborative decryption, aiming to address the limitation of single-user decryption capabilities in traditional ABE while maintaining fine-grained access control. In ABE technologies supporting collaborative decryption, data users must first provide a calculation result to prove their decryption authority before the plaintext is obtained through a decryption algorithm.

[0004] In this process, data users need to perform a lot of calculations, resulting in high computational costs and low decryption efficiency. Summary of the Invention

[0005] In view of the above problems, embodiments of the present invention are proposed to provide a method, apparatus, electronic device and computer-readable storage medium for constructing an LSSS access structure that supports cooperative decryption, which overcomes or at least partially solves the above problems.

[0006] On one hand, embodiments of the present invention provide a method for constructing an LSSS access structure that supports collaborative decryption, the method comprising:

[0007] Determine a collaborative access strategy, which includes collaborative attributes and sub-policies;

[0008] Based on the cooperative access strategy, an LSSS access structure is constructed, the LSSS access structure includes an access matrix M, the access matrix M includes row vectors that correspond one-to-one with the sub-strategy;

[0009] The access matrix M is used to determine the first column vector λ during the encryption process, and the first column vector λ includes the second column vector λ. s ; and a sub-access matrix M for constructing the sub-policy during the encryption process. subDetermine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used to encrypt plaintext;

[0010] The access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process. sub Determine the third column vector λ sub The sub-access matrix M sub and the third column vector λ sub Used to decrypt ciphertext.

[0011] Optionally, the sub-access matrix M of the sub-strategy sub It is constructed based on the following formula:

[0012]

[0013] Among them, M s It is a matrix constructed based on the row vectors corresponding to the sub-strategies in the access matrix M.

[0014] Optionally, the sub-access matrix M of the sub-strategy sub It is also used to determine intermediate results during the decryption process. The intermediate results Used to decrypt the ciphertext.

[0015] Optionally, the third column vector λ sub It is based on the sub-vector v corresponding to the sub-strategy. sub Determined, the subvector v sub Used for encryption and decryption.

[0016] Optionally, the first column vector λ is determined according to the following formula:

[0017]

[0018] Wherein, column vector λ is used to distribute the share of secret s, M is the access matrix, and v is the random vector corresponding to column vector λ;

[0019] The random vector v is determined according to the following formula:

[0020]

[0021] s is the secret, and y is a randomly selected element.

[0022] Optionally, the sub-vector v corresponding to the sub-strategy sub It is determined according to the following formula:

[0023]

[0024] in, k is the number of sub-policies in the collaborative access policy.

[0025] On the other hand, embodiments of the present invention provide a method for using an LSSS access structure that supports collaborative decryption, applicable to data owners, the method comprising:

[0026] Obtain the access matrix M in the LSSS access structure; the LSSS access structure is constructed based on a cooperative access strategy, which includes cooperative attributes and sub-strategies; the access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0027] Based on the access matrix M, a first column vector λ is determined, and the first column vector λ includes a second column vector λ. s ;

[0028] Based on the access matrix M, construct the sub-access matrix M of the sub-strategy. sub ;

[0029] Determine the sub-access matrix M of the sub-strategy sub The corresponding third column vector λ sub So that the third column vector λ sub Equal to the second column vector λ s ;

[0030] Based on the first column vector λ and the third column vector λ sub Encrypt the plaintext.

[0031] Optionally, determining the first column vector λ based on the access matrix M includes:

[0032] The first column vector λ is determined according to the following formula:

[0033]

[0034] Where M is the access matrix, v is the random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute the share of secret s.

[0035] Optionally, determining the first column vector λ includes:

[0036] The random vector v is determined according to the following formula:

[0037]

[0038] Where s is the secret and y is a randomly selected element.

[0039] Optionally, the step of constructing the sub-access matrix M of the sub-strategy based on the access matrix M is... sub ,include:

[0040] Determine the row vector corresponding to the sub-strategy in the access matrix M;

[0041] Based on the row vector corresponding to the sub-strategy, construct the sub-access matrix M of the sub-strategy according to the following formula. sub :

[0042]

[0043] Among them, M s It is a matrix constructed based on the row vectors corresponding to the sub-strategies in the access matrix M.

[0044] Optionally, the sub-access matrix M for determining the sub-strategy sub The corresponding third column vector λ sub ,include:

[0045] The sub-vector v of the sub-strategy is determined according to the following formula. sub :

[0046]

[0047] in, Let v be the row vector corresponding to the sub-strategy in the access matrix M, and v be the random vector corresponding to the column vector λ. k is the number of sub-policies in the collaborative access policy;

[0048] According to the sub-vector v of the sub-strategy sub Determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub .

[0049] On the other hand, embodiments of the present invention provide a method for using an LSSS access structure that supports collaborative decryption, applicable to data users, the method comprising:

[0050] Obtain the sub-access matrix M of the sub-strategy sub The sub-access matrix M of the sub-strategy subIt is constructed by the data owner based on the access matrix M of the collaborative access strategy. The access matrix M is obtained from the LSSS access structure, which is constructed based on the collaborative access strategy. The collaborative access strategy includes collaborative attributes and the sub-strategies. The access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0051] Obtain the sub-access matrix M of the sub-strategy sub The corresponding third column vector λ sub The third column vector λ sub It is determined by the data owner based on the sub-access matrix M of the sub-policy. sub It is determined that the third column vector λ sub Equal to the second column vector λ s The second column vector λ s It is determined based on the first column vector λ of the access matrix M;

[0052] According to the sub-access matrix M of the sub-strategy sub and the third column vector λ sub Decrypt the ciphertext.

[0053] Optionally, the sub-access matrix M based on the sub-strategy sub and the third column vector λ sub Decrypting the ciphertext includes:

[0054] According to the sub-access matrix M of the sub-strategy sub Determine whether the attribute set of the data user satisfies the sub-policy;

[0055] Given that the attribute set of the data user satisfies the sub-strategy, based on the third column vector λ sub The intermediate result R is obtained. sub ;

[0056] According to the intermediate result R sub To decrypt the ciphertext.

[0057] Optionally, the step of basing the intermediate result R sub Decrypting the ciphertext includes:

[0058] Construct the access matrix for decryption ;

[0059] According to the access matrix used for decryption Determine whether the attribute set of the data user satisfies the collaborative access strategy;

[0060] Decryption parameters are obtained after determining that the attribute set of the data user satisfies the collaborative access policy;

[0061] Based on the decryption parameters and the intermediate result R sub To decrypt the ciphertext.

[0062] Optionally, the access matrix M includes row vectors corresponding to the collaboration attributes;

[0063] The access matrix constructed for decryption ,include:

[0064] Construct the access matrix according to the following formula. :

[0065]

[0066] Among them, the and stated It is obtained based on the access matrix M, the The row vector in the access matrix M corresponding to the collaboration attribute, This is the row vector corresponding to the sub-strategy in the access matrix M.

[0067] On the other hand, embodiments of the present invention provide an LSSS access structure construction apparatus that supports collaborative decryption, the apparatus comprising:

[0068] The collaboration strategy determination module is used to determine the collaboration access strategy, which includes collaboration attributes and sub-strategies;

[0069] An access structure construction module is used to construct an LSSS access structure according to the cooperative access strategy. The LSSS access structure includes an access matrix M, which includes row vectors that correspond one-to-one with the sub-strategies.

[0070] The access matrix M is used to determine the first column vector λ during the encryption process, and the first column vector λ includes the second column vector λ. s ; and a sub-access matrix M for constructing the sub-policy during the encryption process. sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used to encrypt plaintext;

[0071] The access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process.sub Determine the third column vector λ sub The sub-access matrix M sub and the third column vector λ sub Used to decrypt ciphertext.

[0072] On the other hand, embodiments of the present invention provide an apparatus for using an LSSS access structure that supports collaborative decryption, applicable to data owners, the apparatus comprising:

[0073] The access matrix acquisition module is used to acquire the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a cooperative access strategy, which includes cooperative attributes and sub-strategies; the access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0074] The first column vector determination module is used to determine a first column vector λ based on the access matrix M, wherein the first column vector λ includes a second column vector λ. s ;

[0075] The sub-access matrix construction module is used to construct the sub-access matrix M of the sub-strategy based on the access matrix M. sub ;

[0076] The third column vector determination module is used to determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub So that the third column vector λ sub Equal to the second column vector λ s ;

[0077] The encryption module is used to perform encryption based on the first column vector λ and the third column vector λ. sub Encrypt the plaintext.

[0078] On the other hand, embodiments of the present invention provide an apparatus for using an LSSS access structure that supports collaborative decryption, applied to data users, the apparatus comprising:

[0079] The sub-access matrix acquisition module is used to obtain the sub-access matrix M of the sub-strategy. sub The sub-access matrix M of the sub-strategy sub It is constructed by the data owner based on the access matrix M of the collaborative access strategy. The access matrix M is obtained from the LSSS access structure, which is constructed based on the collaborative access strategy. The collaborative access strategy includes collaborative attributes and the sub-strategies. The access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0080] The third column vector acquisition module is used to obtain the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub The third column vector λ sub It is determined by the data owner based on the sub-access matrix M of the sub-policy. sub It is determined that the third column vector λ sub Equal to the second column vector λ s The second column vector λ s It is determined based on the first column vector λ of the access matrix M;

[0081] The first decryption module is used to decrypt the sub-access matrix M according to the sub-strategy. sub and the third column vector λ sub Decrypt the ciphertext.

[0082] On the other hand, embodiments of the present invention provide an electronic device, including: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the steps of the LSSS access structure construction method supporting cooperative decryption as described above, or implements the steps of the LSSS access structure usage method supporting cooperative decryption as described above.

[0083] On the other hand, embodiments of the present invention provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the LSSS access structure construction method supporting cooperative decryption as described above, or implements the steps of the LSSS access structure usage method supporting cooperative decryption as described above.

[0084] The embodiments of the present invention have the following advantages:

[0085] This invention constructs an LSSS access structure based on a cooperative access strategy. The cooperative access strategy includes cooperative attributes and sub-policies. The LSSS access structure includes an access matrix M, which comprises row vectors corresponding one-to-one with the sub-policies. Specifically, the access matrix M is used to determine the first column vector λ of the access matrix M during the encryption process, and to construct the sub-access matrix M of the sub-policies. sub Determine the sub-access matrix M sub The corresponding third column vector λ sub ; and make the second column vector λ in the first column vector λ s Equal to the third column vector λ sub Because during the encryption process, it is necessary to use the first column vector λ and the third column vector λ sub The invention performs encryption-related calculations separately by making the second column vector λ in the first column vector λ... sEqual to the third column vector λ sub Thus, for the third column vector λ sub The encryption-related calculation results can be used in the encryption-related calculations for the first column vector λ, saving computational overhead and thus improving encryption efficiency.

[0086] In addition, the access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process. sub Determine the third column vector λ sub Since the decryption process also requires information based on the first column vector λ and the third column vector λ... sub Perform decryption-related calculations separately, focusing on the third column vector λ. sub The decryption-related calculation results can be used in the decryption calculation for the first column vector λ, further saving computational overhead and thus improving decryption efficiency. Attached Figure Description

[0087] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0088] Figure 1 This is a flowchart illustrating the steps of a method for constructing an LSSS access structure that supports collaborative decryption, as provided in an embodiment of the present invention.

[0089] Figure 2 This is a flowchart illustrating the steps of a method for using an LSSS access structure that supports collaborative decryption, as provided in an embodiment of the present invention.

[0090] Figure 3 This is a flowchart of another method for using an LSSS access structure that supports collaborative decryption, provided by an embodiment of the present invention.

[0091] Figure 4 This is a structural block diagram of an LSSS access structure construction device that supports collaborative decryption provided in an embodiment of the present invention;

[0092] Figure 5 This is a structural block diagram of an LSSS access structure usage device that supports collaborative decryption, provided in an embodiment of the present invention.

[0093] Figure 6 This is a structural block diagram of another LSSS access structure usage device that supports collaborative decryption provided in an embodiment of the present invention. Detailed Implementation

[0094] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0095] Attribute-Based Encryption (ABE) is an encryption technology that controls data access based on user attributes. By binding access policies to user attributes, it enables fine-grained access control. User attributes can include user identity information, roles, departments, access permissions, etc., enabling dynamic authorization and management of data access permissions.

[0096] The attribute-based encryption scheme that supports collaborative decryption is an enhanced encryption technology among the aforementioned attribute-based encryption techniques. It integrates the cryptographic mechanisms of attribute-based encryption and collaborative decryption, aiming to solve the problem of limited decryption capabilities for a single user in traditional ABE, while maintaining fine-grained access control characteristics.

[0097] In the ABE scheme, access strategies can be represented as Boolean formulas, threshold expressions, or Linear Secret Sharing Scheme (LSSS) matrices. Among these, the LSSS matrix is ​​widely used as a more general and efficient representation of access strategies.

[0098] For a secret-sharing scheme Π containing P participants, if there exists a scheme composed of participants and constructed on... A vector on, and there exists a If the access matrix M is given, then Π is called a linear secret-sharing scheme. For the access matrix M, a mapping function is defined. , each row in the matrix Mapped to each attribute of the participants, and used The tag is called the LSSS access structure ( ,ρ).

[0099] When a secret needs to be shared At that time, first select randomly And construct random vectors Then through calculation Get a way to share secrets. Row and column vectors λ, where Let represent the i-th participant. The linear reconstruction property of LSSS helps in reconstructing the secret s, if we let Π be the access structure. Let A∈ be any set of authorizations, and define LSSS. for Therefore, there always exists a set of constants. make Valid. If λ i If it is the legitimate share of secret s, then secret s can be calculated. recover.

[0100] In ABE-related technologies that support collaborative decryption, let's assume a collaborative access policy is... In this context, ca represents the collaboration attribute, and p1 and p2 represent sub-policies. For a data user to decrypt ciphertext, they must first perform calculations related to the sub-policies to prove they have decryption privileges and can participate in collaborative decryption. Then, they must perform calculations related to the collaborative access policy to decrypt the ciphertext. This process involves significant computational overhead and low decryption efficiency.

[0101] One of the core concepts of this invention is to use the calculation results related to the sub-policy in the calculation related to the cooperative access policy, thereby reducing the amount of calculation and improving the calculation efficiency.

[0102] This invention constructs an LSSS access structure that supports cooperative decryption, such that the column vectors corresponding to the access matrix M of the cooperative access strategy are aligned with the sub-access matrix M of the sub-strategy. sub The column vectors are the same, so in the encryption and decryption process, the calculation result of the column vector corresponding to the sub-policy can be used in the calculation of the column vector corresponding to the cooperative access policy, reducing the amount of computation in the encryption and decryption process and thus improving the encryption and decryption efficiency.

[0103] Figure 1 This is a flowchart illustrating the steps of an LSSS access structure construction method that supports collaborative decryption, as provided in an embodiment of the present invention.

[0104] like Figure 1 As shown, the method may specifically include the following steps:

[0105] Step 101: Determine the collaborative access strategy, which includes collaborative attributes and sub-policies;

[0106] The regular access policy is converted into a cooperative access policy, which includes cooperative attributes and sub-policies. This allows subsequent calculations to be performed on the sub-policies, and the results are used to calculate the cooperative access policy, thereby reducing the amount of computation.

[0107] As an example, the regular access policy Switch to collaborative access policy .

[0108] In practical applications, users perform encryption and decryption operations within an encryption / decryption management system. If user 1 satisfies sub-policy p1, according to the collaborative access policy, if user 1 wants to decrypt the ciphertext, user 1 must prove that they satisfy sub-policy p1 and are qualified to obtain collaborative attributes before they can decrypt the plaintext. Whether user 1 is qualified to obtain collaborative attributes needs to be determined by the encryption / decryption management system. In this invention, users are predefined as having the qualification to obtain collaborative attributes.

[0109] Step 102: Construct an LSSS access structure according to the cooperative access strategy. The LSSS access structure includes an access matrix M, which includes row vectors that correspond one-to-one with the sub-strategies.

[0110] The access matrix M is used to determine the first column vector λ during the encryption process, and the first column vector λ includes the second column vector λ. s ; and a sub-access matrix M for constructing the sub-policy during the encryption process. sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used to encrypt plaintext;

[0111] The access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process. sub Determine the third column vector λ sub The sub-access matrix M sub and the third column vector λ sub Used to decrypt ciphertext.

[0112] In practical applications, the data owner determines the first column vector λ and constructs the sub-access matrix M of the sub-strategy based on the access matrix M of the collaborative access strategy. sub Determine the sub-access matrix M sub The corresponding third column vector λ sub And based on the first column vector λ and the third column vector λ sub Encrypt the plaintext.

[0113] By the data user according to the sub-access matrix M sub and the third column vector λ sub The encrypted text will be decrypted. The specific process will be explained below.

[0114] As an example, based on collaborative access policies Construct the following access matrix M:

[0115]

[0116] in, It is a row vector representing the collaboration attribute ca. It is a mapper strategy The submatrix is ​​constructed following the general construction method of LSSS matrices. It is a structure Repeated row vectors generated during the process.

[0117] In the collaborative access strategy CP, ca is the collaborative attribute, and p1, p2 and p3 are sub-strategies. Each sub-strategy contains several attributes. The access matrix M includes row vectors that correspond one-to-one with each attribute. The dashed lines in the access matrix M divide the access matrix M into different regions according to the sub-strategies, which are used to extract sub-matrices of different sub-strategies.

[0118] In some embodiments, the sub-access matrix M of the sub-policy sub It is constructed based on the following formula:

[0119]

[0120] Among them, M s It is a matrix constructed based on the row vectors corresponding to the sub-strategies in the access matrix M.

[0121] Each sub-strategy has its own sub-access matrix M sub Specifically, a set of row vectors corresponding to the sub-strategy is extracted from the access matrix M, and the column vectors containing all zeros are removed to obtain matrix M. s Then in matrix M s Add a column vector of all 1s to the left side to obtain the sub-access matrix M. sub Sub-access matrix M sub Used to determine the third column vector λ corresponding to the sub-strategy sub .

[0122] In some embodiments, the sub-access matrix M of the sub-policy sub It is also used to determine intermediate results during the decryption process. The intermediate results Used to decrypt the ciphertext.

[0123] During the decryption process, it is first necessary to determine whether the data user's attribute set satisfies one of the sub-policies in the collaborative access strategy. This process requires calculation based on the sub-access matrix M. sub Perform calculations and obtain intermediate results. Through intermediate results Decrypting ciphertext can save computational costs, thereby improving decryption efficiency.

[0124] In some embodiments, the third column vector λ sub It is based on the sub-vector v corresponding to the sub-strategy. sub Determined, the subvector v sub Used for encryption and decryption.

[0125] In the LSSS scheme, when a secret s needs to be shared, a random vector v is typically constructed. The first element of the random vector v is s, and the other elements are randomly selected. Then, the column vector λ of the access matrix M used for sharing the secret s is calculated using λ=Mv.

[0126] This invention relates to the sub-access matrix M of the sub-strategy. sub Determine its third column vector λ sub Instead of determining the value by constructing a random vector as described above, a fixed sub-vector v is set. sub Then determine the third column vector λ sub And through this determined subvector v sub This makes the third column vector λ sub It is equal to accessing the second column vector λ in the first column vector λ of matrix M. s This reduces the computational load when performing encryption and decryption calculations related to column vectors.

[0127] That is to say, ,in , The second column vector λ s This corresponds to the row vector of the sub-strategy in the access matrix M, and the third column vector.

[0128] λ sub This corresponds to the sub-access matrix M of the sub-strategy. sub The row vectors in the matrix, and the second column vector λ. s It is also a part of the first column vector λ, that is, the elements of the corresponding sub-strategies in the first column vector λ and the third column vector λsub are the same.

[0129] In some embodiments, the first column vector λ is determined according to the following formula:

[0130]

[0131] Wherein, column vector λ is used to distribute the share of secret s, M is the access matrix, and v is the random vector corresponding to column vector λ;

[0132] The random vector v is determined according to the following formula:

[0133]

[0134] s is the secret, and y is a randomly selected element.

[0135] In some embodiments, the sub-vector v corresponding to the sub-policy sub It is determined according to the following formula:

[0136]

[0137] in, k is the number of sub-policies in the collaborative access policy.

[0138] By setting the above subvector v sub And based on the subvector v sub Determine the third column vector λ sub Therefore, it is not necessary to construct new random variables for the sub-policy, nor is it necessary to recalculate the third column vector λ. sub This directly makes the second column vector λs in the first column vector λ equal to the third column vector λ. sub The second column vector λs corresponds to the row vector of the sub-strategy in the access matrix M, which is the first column vector λ and the third column vector λs. sub The elements of the corresponding sub-strategies are all the same.

[0139] The third column vector λ sub Each element in the vector corresponds to an attribute in the sub-strategy, the first column vector λ and the third column vector λ. sub The elements of the corresponding sub-strategies are all the same, that is, the third column vector λ. sub The processing results of the attributes of each sub-strategy in the related calculations can be reused in the related calculations of the first column vector λ to process the attributes of each sub-strategy, thereby avoiding the processing of each attribute in the collaborative access strategy multiple times and thus improving processing efficiency.

[0140] Figure 2 This is a flowchart of the steps of an LSSS access structure usage method that supports collaborative decryption, provided by an embodiment of the present invention, and applied to data owners.

[0141] like Figure 2 As shown, the method may specifically include the following steps:

[0142] Step 201: Obtain the access matrix M in the LSSS access structure; the LSSS access structure is constructed based on a cooperative access strategy, which includes cooperative attributes and sub-strategies; the access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0143] The access matrix M is constructed using the method described above, and will not be repeated here.

[0144] In an encryption / decryption system, the data owner encrypts the data using access policies and stores it in the cloud, relying on the cloud for data maintenance. The data owner can be a company or an individual.

[0145] Step 202: Determine the first column vector λ based on the access matrix M, wherein the first column vector λ includes the second column vector λ. s ;

[0146] In some embodiments, step 202 specifically includes the following sub-steps:

[0147] Sub-step S11: Determine the first column vector λ according to the following formula:

[0148]

[0149] Where M is the access matrix, v is the random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute the share of secret s.

[0150] In some embodiments, step 202 specifically includes the following sub-steps:

[0151] Sub-step S21: Determine the random vector v according to the following formula:

[0152]

[0153] Where s is the secret and y is a randomly selected element.

[0154] Step 203: Construct the sub-access matrix M of the sub-strategy based on the access matrix M. sub ;

[0155] In some embodiments, step 203 specifically includes the following sub-steps:

[0156] Sub-step S31: Determine the row vector corresponding to the sub-strategy in the access matrix M;

[0157] Sub-step S32: Based on the row vector corresponding to the sub-strategy, construct the sub-access matrix M of the sub-strategy according to the following formula. sub :

[0158]

[0159] Among them, M s It is a matrix constructed based on the row vectors corresponding to the sub-strategies in the access matrix M.

[0160] Each sub-strategy has its own sub-access matrix M subSpecifically, a set of row vectors corresponding to the sub-strategy is extracted from the access matrix M, and the column vectors containing all zeros are removed to obtain matrix M. s Then in matrix M s Add a column vector of all 1s to the left side to obtain the sub-access matrix M. sub Sub-access matrix M sub Used to determine the third column vector λ corresponding to the sub-strategy sub .

[0161] Step 204: Determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub So that the third column vector λ sub Equal to the second column vector λ s ;

[0162] In collaborative decryption, it's necessary to determine if the decrypting party is qualified to collaborate. Therefore, they need to provide proof of a computational result satisfying a specific sub-policy, requiring separate processing of the sub-policy and the collaborative access policy. The collaborative access policy embeds a secret `s`. Decrypting the collaborative access policy requires restoring secret `s`. For each sub-policy, the decrypting party needs to prove that it satisfies the sub-policy. This can also be viewed as the sub-policy embedding different secrets `s'`. The decrypting party must first restore the secret `s'` of the sub-policy to prove they have decryption privileges (satisfying a specific sub-policy) and can participate in the collaboration before they can decrypt the collaborative access policy, restore secret `s`, and thus decrypt the ciphertext.

[0163] In the above process, both the encryptor and decryptor need to process the cooperative access policy and sub-policies simultaneously, and each attribute in the policy is processed during this process. Since the cooperative access policy contains sub-policies, meaning it contains sub-policy attributes, each attribute is processed twice during encryption and decryption, increasing computational cost and ciphertext size. Therefore, this invention allows the calculation result of each attribute to be used simultaneously for both sub-policy decryption and cooperative access policy decryption, that is, to make the third column vector λ of the sub-policy... sub The second column vector λ equals the collaborative access strategy s (Second column vector λ) s (This refers to the row vector corresponding to the sub-policy in λ=Mv). In this way, the encryptor no longer needs to recalculate the third column vector λ. sub This improves encryption efficiency and reduces ciphertext size.

[0164] In some embodiments, step 204 specifically includes the following sub-steps:

[0165] Sub-step S41: Determine the sub-vector v of the sub-strategy according to the following formula. sub :

[0166]

[0167] in, Let v be the row vector corresponding to the sub-strategy in the access matrix M, and v be the random vector corresponding to the column vector λ. k is the number of sub-policies in the collaborative access policy;

[0168] Sub-step S42, based on the sub-vector v of the sub-strategy sub Determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub .

[0169] In the LSSS scheme, when a secret s needs to be shared, a random vector v is typically constructed. The first element of the random vector v is s, and the other elements are randomly selected. Then, the column vector λ of the access matrix M used for sharing the secret s is calculated using λ=Mv.

[0170] This invention relates to the sub-access matrix M of the sub-strategy. sub Determine its third column vector λ sub Instead of determining the value by constructing a random vector as described above, a fixed sub-vector v is set. sub Then determine the third column vector λ sub And through this determined subvector v sub This makes the third column vector λ sub It is equal to accessing the second column vector λ in the first column vector λ of matrix M. s Therefore, there is no need to reselect v. sub It is no longer necessary to recalculate λ. sub This reduces the amount of computation.

[0171] Step 205, based on the first column vector λ and the third column vector λ sub Encrypt the plaintext.

[0172] In practical applications, the data owner uses the first column vector λ and the third column vector λ sub And the encryption key is used to encrypt the plaintext data to obtain the ciphertext data.

[0173] Figure 3 This is a flowchart of another method for using an LSSS access structure that supports collaborative decryption, provided by an embodiment of the present invention, and applied to data users.

[0174] like Figure 3 As shown, the method may specifically include the following steps:

[0175] Step 301: Obtain the sub-access matrix M of the sub-strategy. sub The sub-access matrix M of the sub-strategy sub It is constructed by the data owner based on the access matrix M of the collaborative access strategy. The access matrix M is obtained from the LSSS access structure, which is constructed based on the collaborative access strategy. The collaborative access strategy includes collaborative attributes and the sub-strategies. The access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0176] In an encryption / decryption system, data users access data shared by data owners in the cloud, download the data they need, and can decrypt the data using their own key, provided that the data user's attribute set meets the data access policy.

[0177] Step 302: Obtain the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub The third column vector λ sub It is determined by the data owner based on the sub-access matrix M of the sub-policy. sub It is determined that the third column vector λ sub Equal to the second column vector λ s The second column vector λ s It is determined based on the first column vector λ of the access matrix M;

[0178] Sub-access matrix M of the sub-policy obtained by the data user sub and the third column vector λ sub The ciphertext was determined by the aforementioned data owner, and will not be elaborated further here.

[0179] Step 303, based on the sub-access matrix M of the sub-strategy sub and the third column vector λ sub Decrypt the ciphertext.

[0180] In some embodiments, step 303 specifically includes the following sub-steps:

[0181] Sub-step S51, based on the sub-access matrix M of the sub-strategy sub Determine whether the attribute set of the data user satisfies the sub-policy;

[0182] Similar to the access matrix M of the cooperative access strategy, for the sub-access matrix M of the sub-strategy sub To determine whether the attribute set of a data user satisfies the sub-policy, it is necessary to recover the sub-access matrix M. sub The secret within.

[0183] Sub-step S52: Given that the attribute set of the data user satisfies the sub-strategy, based on the third column vector λ... sub The intermediate result R is obtained. sub ;

[0184] As an example, the access structure of a sub-policy is as follows: Define the authorization set for Data users can find a set of constants satisfy Then, data users can obtain... And calculate the intermediate results. .

[0185] Sub-step S53, based on the intermediate result R sub To decrypt the ciphertext.

[0186] In some embodiments, sub-step S53 includes the following sub-steps:

[0187] Sub-step S531: Construct the access matrix for decryption. According to the access matrix used for decryption The process involves determining whether the attribute set of the data user satisfies the collaborative access policy; if the attribute set of the data user satisfies the collaborative access policy, obtaining decryption parameters; and then, based on the decryption parameters and the intermediate result R... sub To decrypt the ciphertext.

[0188] In some embodiments, sub-step S531 includes the following sub-steps:

[0189] Sub-step S5311: Construct the access matrix according to the following formula. :

[0190]

[0191] Among them, the and stated It is obtained based on the access matrix M, the The row vector in the access matrix M corresponding to the collaboration attribute, This is the row vector corresponding to the sub-strategy in the access matrix M.

[0192] For access matrix The sub-policy is treated as a single attribute. This determines whether the data user's attribute set satisfies the collaborative access policy, that is, whether it satisfies both the collaborative attribute and the sub-policy attribute. If the data user's attribute set satisfies the collaborative access policy, the decryption parameters can be obtained. Based on these decryption parameters and the intermediate result R...sub To decrypt the ciphertext.

[0193] In this process, data users first interact with M sub The related decryption calculations yielded the intermediate result R. sub Can be used directly This saves computational overhead and improves decryption efficiency in the relevant decryption calculations.

[0194] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0195] Figure 4 This is a structural block diagram of an LSSS access structure construction device that supports collaborative decryption provided in an embodiment of the present invention.

[0196] like Figure 4 As shown in the diagram, an embodiment of the present invention provides a structural block diagram of an LSSS access structure construction device that supports collaborative decryption, which may specifically include the following modules:

[0197] The collaboration strategy determination module 401 is used to determine the collaboration access strategy, which includes collaboration attributes and sub-strategies.

[0198] Access structure construction module 402 is used to construct an LSSS access structure according to the cooperative access strategy. The LSSS access structure includes an access matrix M, which includes row vectors that correspond one-to-one with the sub-strategies.

[0199] The access matrix M is used to determine the first column vector λ during the encryption process, and the first column vector λ includes the second column vector λ. s ; and a sub-access matrix M for constructing the sub-policy during the encryption process. sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used to encrypt plaintext;

[0200] The access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process. subDetermine the third column vector λ sub The sub-access matrix M sub and the third column vector λ sub Used to decrypt ciphertext.

[0201] Figure 5 This is a structural block diagram of an LSSS access structure usage device that supports collaborative decryption, provided by an embodiment of the present invention, and is applied to data owners.

[0202] like Figure 5 As shown, the device may specifically include the following modules:

[0203] Access matrix acquisition module 501 is used to acquire the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a cooperative access strategy, the cooperative access strategy includes cooperative attributes and sub-strategies; the access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0204] The first column vector determination module 502 is used to determine a first column vector λ based on the access matrix M, wherein the first column vector λ includes a second column vector λ. s ;

[0205] Sub-access matrix construction module 503 is used to construct the sub-access matrix M of the sub-strategy based on the access matrix M. sub ;

[0206] The third column vector determination module 504 is used to determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub So that the third column vector λ sub Equal to the second column vector λ s ;

[0207] Encryption module 505 is used to encrypt the first column vector λ and the third column vector λ. sub Encrypt the plaintext.

[0208] In some embodiments, the first column vector determination module 502 includes the following sub-modules:

[0209] The first column vector determination submodule is used to determine the first column vector λ according to the following formula:

[0210]

[0211] Where M is the access matrix, v is the random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute the share of secret s.

[0212] In some embodiments, the first column vector determination module 502 includes the following sub-modules:

[0213] The random vector determination submodule is used to determine the random vector v according to the following formula:

[0214]

[0215] Where s is the secret and y is a randomly selected element.

[0216] In some embodiments, the sub-access matrix construction module 503 includes the following sub-modules:

[0217] The row vector determination submodule is used to determine the row vector corresponding to the sub-strategy in the access matrix M;

[0218] The sub-access matrix construction submodule is used to construct the sub-access matrix M of the sub-strategy according to the row vectors corresponding to the sub-strategy and the following formula. sub :

[0219]

[0220] Among them, M s It is a matrix constructed based on the row vectors corresponding to the sub-strategies in the access matrix M.

[0221] In some embodiments, the third column vector determination module 504 includes the following sub-modules:

[0222] The sub-vector determination submodule is used to determine the sub-vector v of the sub-strategy according to the following formula. sub :

[0223]

[0224] in, Let v be the row vector corresponding to the sub-strategy in the access matrix M, and v be the random vector corresponding to the column vector λ. k is the number of sub-policies in the collaborative access policy;

[0225] The third column vector determines the submodule, used to determine the subvector v based on the sub-strategy. sub Determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub .

[0226] Figure 6 This is a structural block diagram of an LSSS access structure usage device that supports collaborative decryption, provided by an embodiment of the present invention, and applied to data users.

[0227] like Figure 6As shown, the device may specifically include the following modules:

[0228] Sub-access matrix acquisition module 601 is used to acquire the sub-access matrix M of the sub-strategy. sub The sub-access matrix M of the sub-strategy sub It is constructed by the data owner based on the access matrix M of the collaborative access strategy. The access matrix M is obtained from the LSSS access structure, which is constructed based on the collaborative access strategy. The collaborative access strategy includes collaborative attributes and the sub-strategies. The access matrix M includes row vectors that correspond one-to-one with the sub-strategies.

[0229] The third column vector acquisition module 602 is used to acquire the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub The third column vector λ sub It is determined by the data owner based on the sub-access matrix M of the sub-policy. sub It is determined that the third column vector λ sub Equal to the second column vector λ s The second column vector λ s It is determined based on the first column vector λ of the access matrix M;

[0230] The first decryption module 603 is used to decrypt the sub-access matrix M according to the sub-strategy. sub and the third column vector λ sub Decrypt the ciphertext.

[0231] In some embodiments, the first decryption module 603 includes the following sub-modules:

[0232] The first attribute determination submodule is used to determine the sub-access matrix M based on the sub-strategy. sub Determine whether the attribute set of the data user satisfies the sub-policy;

[0233] The intermediate result acquisition submodule is used to, under the condition that the attribute set of the data user satisfies the sub-strategy, obtain the result based on the third column vector λ. sub The intermediate result R is obtained. sub ;

[0234] The second decryption submodule is used to decrypt the intermediate result R. sub To decrypt the ciphertext.

[0235] In some embodiments, the second decryption submodule includes the following units:

[0236] Decryption matrix construction unit, used to construct the access matrix for decryption. ;

[0237] The second attribute determination unit is used to determine the access matrix used for decryption. Determine whether the attribute set of the data user satisfies the collaborative access strategy;

[0238] The decryption parameter acquisition unit is used to obtain decryption parameters based on the condition that the attribute set of the data user satisfies the collaborative access policy.

[0239] The third decryption unit is used to decrypt the parameters and the intermediate result R. sub To decrypt the ciphertext.

[0240] In some embodiments, the decryption matrix construction unit includes the following sub-units:

[0241] The decryption matrix construction sub-unit is used to construct the access matrix according to the following formula. :

[0242]

[0243] Among them, the and stated It is obtained based on the access matrix M, the The row vector in the access matrix M corresponding to the collaboration attribute, This is the row vector corresponding to the sub-strategy in the access matrix M.

[0244] As the apparatus embodiment is basically similar to the method embodiment, it is described in a relatively simple manner. For relevant details, please refer to the description of the method embodiment.

[0245] This invention also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the various processes of the embodiments of the above-described method for constructing or using an LSSS access structure that supports cooperative decryption, and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0246] This invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described embodiments of the LSSS access structure construction method or the LSSS access structure usage method supporting cooperative decryption, and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0247] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0248] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0249] Embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0250] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0251] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0252] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0253] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0254] The foregoing has provided a detailed description of the LSSS access structure construction method, apparatus, electronic device, and computer-readable storage medium supporting collaborative decryption provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A method for constructing an LSSS access structure that supports collaborative decryption, characterized in that, The method includes: Determine a collaborative access strategy, which includes collaborative attributes and sub-policies; Based on the cooperative access strategy, an LSSS access structure is constructed, the LSSS access structure includes an access matrix M, the access matrix M includes row vectors that correspond one-to-one with the sub-strategy; The access matrix M is used to determine the first column vector λ during the encryption process, and the first column vector λ includes the second column vector λ. s ; and a sub-access matrix M for constructing the sub-policy during the encryption process. sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used to encrypt plaintext; The access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process. sub Determine the third column vector λ sub The sub-access matrix M sub and the third column vector λ sub Used to decrypt ciphertext.

2. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 1, characterized in that, The sub-access matrix M of the sub-strategy sub It is constructed based on the following formula: Among them, M s It is a matrix constructed based on the row vectors corresponding to the sub-strategies in the access matrix M.

3. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 2, characterized in that, The sub-access matrix M of the sub-strategy sub It is also used to determine intermediate results during the decryption process. The intermediate results Used to decrypt the ciphertext.

4. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 1, characterized in that, The third column vector λ sub It is based on the sub-vector v corresponding to the sub-strategy. sub Determined, the subvector v sub Used for encryption and decryption.

5. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 1, characterized in that, The first column vector λ is determined according to the following formula: Wherein, column vector λ is used to distribute the share of secret s, M is the access matrix, and v is the random vector corresponding to column vector λ; The random vector v is determined according to the following formula: s is the secret, and y is a randomly selected element.

6. The method for constructing an LSSS access structure supporting collaborative decryption according to claim 4, characterized in that, The sub-vector v corresponding to the sub-strategy sub It is determined according to the following formula: in, k is the number of sub-policies in the collaborative access policy.

7. A method for using an LSSS access structure that supports collaborative decryption, characterized in that, Applied to data owners, the method includes: Obtain the access matrix M in the LSSS access structure; the LSSS access structure is constructed based on a cooperative access strategy, which includes cooperative attributes and sub-strategies; the access matrix M includes row vectors that correspond one-to-one with the sub-strategies. Based on the access matrix M, a first column vector λ is determined, and the first column vector λ includes a second column vector λ. s ; Based on the access matrix M, construct the sub-access matrix M of the sub-strategy. sub ; Determine the sub-access matrix M of the sub-strategy sub The corresponding third column vector λ sub So that the third column vector λ sub Equal to the second column vector λ s ; Based on the first column vector λ and the third column vector λ sub Encrypt the plaintext.

8. The method for using the LSSS access structure supporting collaborative decryption according to claim 7, characterized in that, Determining the first column vector λ based on the access matrix M includes: The first column vector λ is determined according to the following formula: Where M is the access matrix, v is the random vector corresponding to the first column vector λ, and the first column vector λ is used to distribute the share of secret s.

9. The method for using the LSSS access structure supporting collaborative decryption according to claim 8, characterized in that, Determining the first column vector λ includes: The random vector v is determined according to the following formula: Where s is the secret and y is a randomly selected element.

10. The method for using the LSSS access structure supporting collaborative decryption according to claim 7, characterized in that, The sub-access matrix M of the sub-strategy is constructed based on the access matrix M. sub ,include: Determine the row vector corresponding to the sub-strategy in the access matrix M; Based on the row vector corresponding to the sub-strategy, construct the sub-access matrix M of the sub-strategy according to the following formula. sub : Among them, M s It is a matrix constructed based on the row vectors corresponding to the sub-strategies in the access matrix M.

11. The method for using the LSSS access structure supporting collaborative decryption according to claim 9, characterized in that, The sub-access matrix M for determining the sub-strategy sub The corresponding third column vector λ sub ,include: The sub-vector v of the sub-strategy is determined according to the following formula. sub : in, Let v be the row vector corresponding to the sub-strategy in the access matrix M, and v be the random vector corresponding to the column vector λ. k is the number of sub-policies in the collaborative access policy; According to the sub-vector v of the sub-strategy sub Determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub .

12. A method for using an LSSS access structure that supports collaborative decryption, characterized in that, Applied to data users, the method includes: Obtain the sub-access matrix M of the sub-strategy sub The sub-access matrix M of the sub-strategy sub It is constructed by the data owner based on the access matrix M of the collaborative access strategy. The access matrix M is obtained from the LSSS access structure, which is constructed based on the collaborative access strategy. The collaborative access strategy includes collaborative attributes and the sub-strategies. The access matrix M includes row vectors that correspond one-to-one with the sub-strategies. Obtain the sub-access matrix M of the sub-strategy sub The corresponding third column vector λ sub The third column vector λ sub It is determined by the data owner based on the sub-access matrix M of the sub-policy. sub It is determined that the third column vector λ sub Equal to the second column vector λ s The second column vector λ s It is determined based on the first column vector λ of the access matrix M; According to the sub-access matrix M of the sub-strategy sub and the third column vector λ sub Decrypt the ciphertext.

13. The method for using the LSSS access structure supporting collaborative decryption according to claim 12, characterized in that, The sub-access matrix M based on the sub-strategy sub and the third column vector λ sub Decrypting the ciphertext includes: According to the sub-access matrix M of the sub-strategy sub Determine whether the attribute set of the data user satisfies the sub-policy; Given that the attribute set of the data user satisfies the sub-strategy, based on the third column vector λ sub The intermediate result R is obtained. sub ; According to the intermediate result R sub To decrypt the ciphertext.

14. The method for using the LSSS access structure supporting collaborative decryption according to claim 13, characterized in that, The intermediate result R sub Decrypting the ciphertext includes: Construct the access matrix for decryption ; According to the access matrix used for decryption Determine whether the attribute set of the data user satisfies the collaborative access strategy; Decryption parameters are obtained after determining that the attribute set of the data user satisfies the collaborative access policy; Based on the decryption parameters and the intermediate result R sub To decrypt the ciphertext.

15. The method for using the LSSS access structure supporting collaborative decryption according to claim 14, characterized in that, The access matrix M includes row vectors corresponding to the collaboration attributes; The access matrix constructed for decryption ,include: Construct the access matrix according to the following formula. : Among them, the and stated It is obtained based on the access matrix M, the The row vector in the access matrix M corresponding to the collaboration attribute, This is the row vector corresponding to the sub-strategy in the access matrix M.

16. A device for constructing an LSSS access structure that supports collaborative decryption, characterized in that, The device includes: The collaboration strategy determination module is used to determine the collaboration access strategy, which includes collaboration attributes and sub-strategies; An access structure construction module is used to construct an LSSS access structure according to the cooperative access strategy. The LSSS access structure includes an access matrix M, which includes row vectors that correspond one-to-one with the sub-strategies. The access matrix M is used to determine the first column vector λ during the encryption process, and the first column vector λ includes the second column vector λ. s ; and a sub-access matrix M for constructing the sub-policy during the encryption process. sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used to encrypt plaintext; The access matrix M is also used to determine the sub-access matrix M of the sub-strategy during the decryption process. sub Determine the third column vector λ sub The sub-access matrix M sub and the third column vector λ sub Used to decrypt ciphertext.

17. An apparatus for using an LSSS access structure that supports collaborative decryption, characterized in that, For use by data owners, the device includes: The access matrix acquisition module is used to acquire the access matrix M in the LSSS access structure; the LSSS access structure is constructed according to a cooperative access strategy, which includes cooperative attributes and sub-strategies; the access matrix M includes row vectors that correspond one-to-one with the sub-strategies. The first column vector determination module is used to determine a first column vector λ based on the access matrix M, wherein the first column vector λ includes a second column vector λ. s ; The sub-access matrix construction module is used to construct the sub-access matrix M of the sub-strategy based on the access matrix M. sub ; The third column vector determination module is used to determine the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub So that the third column vector λ sub Equal to the second column vector λ s ; The encryption module is used to perform encryption based on the first column vector λ and the third column vector λ. sub Encrypt the plaintext.

18. An apparatus for using an LSSS access structure that supports collaborative decryption, characterized in that, For use by data users, the device includes: The sub-access matrix acquisition module is used to obtain the sub-access matrix M of the sub-strategy. sub The sub-access matrix M of the sub-strategy sub It is constructed by the data owner based on the access matrix M of the collaborative access strategy. The access matrix M is obtained from the LSSS access structure, which is constructed based on the collaborative access strategy. The collaborative access strategy includes collaborative attributes and the sub-strategies. The access matrix M includes row vectors that correspond one-to-one with the sub-strategies. The third column vector acquisition module is used to obtain the sub-access matrix M of the sub-strategy. sub The corresponding third column vector λ sub The third column vector λ sub It is determined by the data owner based on the sub-access matrix M of the sub-policy. sub It is determined that the third column vector λ sub Equal to the second column vector λ s The second column vector λ s It is determined based on the first column vector λ of the access matrix M; The first decryption module is used to decrypt the sub-access matrix M according to the sub-strategy. sub and the third column vector λ sub Decrypt the ciphertext.

19. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when executed by the processor, the computer program implements the steps of the method for constructing an LSSS access structure supporting cooperative decryption as claimed in any one of claims 1-6, or implements the steps of the method for using an LSSS access structure supporting cooperative decryption as claimed in any one of claims 7-11 or 12-15.

20. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method for constructing an LSSS access structure supporting cooperative decryption as claimed in any one of claims 1-6, or the steps of the method for using an LSSS access structure supporting cooperative decryption as claimed in any one of claims 7-11 or 12-15.

Citation Information

Patent Citations

  • Lattice attribute-based signature method capable of supporting LSSS matrix

    CN111030809A

  • Cross-domain ciphertext data sharing method and system supporting access behavior auditing

    CN117675297A