Hybrid encryption method supporting access control and controllable data search

By combining the hybrid encryption method of CP-ABE and SSE, combined with a trusted execution environment and blockchain smart contract, strict access control and targeted search of data in an untrusted cloud environment is achieved, solving the problem of insufficient access control and search efficiency in traditional technologies, and improving the security and availability of data sharing.

CN120337245APending Publication Date: 2025-07-18XIDIAN UNIV
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510380730.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The prior art is difficult to implement strict access control and targeted search of data in an untrusted cloud environment, and cannot meet the needs of two-way control. In addition, traditional searchable encryption solutions have shortcomings in computing efficiency and privacy protection.

Method used

A hybrid encryption method combining ciphertext policy attribute-based encryption (CP-ABE) and symmetric searchable encryption (SSE) is adopted to realize access control through CP-ABE, SSE realizes controllable search, and combines a trusted execution environment (TEE) and blockchain smart contracts to ensure data security and computing efficiency.

Benefits of technology

It realizes the dual guarantees of fine-grained permission control and complex queries, improves the security and availability of data sharing, supports fuzzy search and efficient data retrieval, and is suitable for massive data environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337245A_ABST
    Figure CN120337245A_ABST
Patent Text Reader

Abstract

The invention discloses a hybrid encryption method supporting access control and controllable data search, and relates to the field of secure data sharing. According to the method, a CP-ABE (Ciphertext Policy Attribute Based Encryption) technology and a symmetric searchable Encryption (SSE) technology are creatively combined, and a data authorization access function and a data controllable search function are integrated. As for data authorization access, CP-ABE is dominated, fine-grained access control is achieved by embedding attribute information, and it is ensured that only authorized users conforming to a preset strategy can decrypt data. For data controllable search, SSE is dominated, a data storage service provider is allowed to execute a search task based on keywords on the premise of not decrypting data, and expansion of fuzzy keyword search is supported in combination with a trusted execution environment technology. According to the method, the problems that user access is not limited and data sharing is easy to leak to an untrusted party are effectively solved. Through strict user right control, unauthorized access is prevented. And meanwhile, the targeted search of the shared data is realized, and bidirectional requirements are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of secure data sharing, and provides a hybrid encryption method that supports access control and controllable data search. Background Art

[0002] The release of the core value of data elements has driven the development of data computing applications. Data sharing and retrieval have become key requirements in information management. However, in an untrusted cloud environment, how to effectively implement data access control and sharing, while protecting data files and search privacy, and meeting the bilateral control requirements of data owners to control the access rights of data requesters and data requesters to obtain shared data targeted, remains a challenge.

[0003] Attribute-Based Encryption (ABE), as an effective access control technology, supports flexible control of data access rights by introducing attributes in the encryption and decryption processes. However, in scenarios of dynamic permission adjustment and complex policies, existing standard ciphertext-policy ABE (CP-ABE) and key-policy ABE (KP-ABE) have significant limitations. They only support one-way authorization and cannot fully meet the two-way requirements of authorized access and data identification, resulting in relatively fixed application scenarios.

[0004] Searchable Encryption (SE) aims to support secure retrieval while encrypting data. However, most existing solutions only support single-keyword queries, far from meeting the diverse requirements in practical applications (such as complex queries and fuzzy queries). In addition, public-key-based SE solutions often face performance bottlenecks and high computational costs when dealing with massive data, making it difficult to meet the actual needs of frequent data retrieval.

[0005] In summary, how to prevent unauthorized access through strict user permission access control on the one hand, and achieve targeted search of shared data on the other hand to meet the two-way requirements while ensuring data security, remains a crucial and challenging issue. Summary of the Invention

[0006] The present invention aims to protect data files and search privacy while achieving precise control of access rights by data owners and targeted acquisition of shared data by data requesters, meeting bilateral control requirements, and provides a hybrid encryption method that supports access control and controllable data search.

[0007] Specifically, this method integrates data authorization access and data controllable search functions, achieving efficient and secure data sharing. It allows data owners to define access policies and delegate lightweight authorization verification to smart contracts on the blockchain, thus avoiding excessive blockchain storage and computing burdens. At the same time, it allows data owners to encrypt and outsource the files to be shared, and entrust the high-frequency data retrieval tasks to the off-chain storage service providers equipped with servers, enabling them to complete symmetric searchable encryption operations based on keywords without decrypting the data. Compared with traditional broadcast encryption and public key searchable encryption, this method improves the computing efficiency while optimizing the privacy protection mechanism, achieving a better balance between security and usability.

[0008] Furthermore, the core technologies of this method adopt Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and Symmetric Searchable Encryption (SSE), which are respectively applied to the access control layer and the outsourced data encryption layer:

[0009] By embedding attribute information in the key generation and data encryption processes, CP-ABE is responsible for implementing attribute-based access control to ensure that only authorized users who meet the preset access policies can decrypt and obtain the data. In this method, the SSE key is stored as the encryption object, and only authorized users who have successfully decrypted through CP-ABE can obtain the SSE key, thus initiating a keyword search request. Therefore, this mechanism not only strictly controls data access rights but also ensures that only legitimate authorized users can perform subsequent SSE retrievals, eliminating the risk of unauthorized access.

[0010] In addition, this method combines SSE technology with Trusted Execution Environment (TEE) to implement an efficient and secure symmetric searchable encryption scheme in an untrusted cloud environment, while ensuring the privacy security of search keywords and outsourced shared files. The proposed method supports fuzzy keyword search based on set thresholds, meets complex query requirements, and further improves the security and usability of data sharing. For massive data storage and diverse application scenarios, this scheme overcomes the limitations of traditional searchable encryption methods in terms of computing efficiency, storage cost, and only supporting single-keyword search, significantly improving the system performance and applicability.

[0011] Furthermore, the system model involves five types of entities: Key Generation Center (KGC), Blockchain (BC), Storage Service Provider (Storage), Data Owner (DO), and Data User (DU). The responsibilities of each entity are as follows:

[0012] (1) Key Generation Center KGC: Responsible for generating, distributing, and managing system parameters and keys related to attributes, ensuring the legality and security of keys. Specifically, KGC mainly undertakes the key management task in the CP-ABE scheme, distributes the private key associated with the user's attribute set to the user DU, enabling it to decrypt data that conforms to the access policy.

[0013] (2) Blockchain BC: Deploys smart contracts and is responsible for verifying CP-ABE access authorization requests. The data owner DO stores the ciphertext embedded with the access policy in the blockchain. Before requesting access to data, the data user DU needs to verify their identity and permissions through the smart contract to ensure that only legitimate authorized users can obtain the plaintext data.

[0014] (3) Storage Service Provider Storage: Possesses powerful computing and storage resources, responsible for storing the encrypted data uploaded by the data owner DO and processing search requests from the data user DU. The Storage Service Provider Storage internally integrates a server environment, uses hardware isolation technology to generate a secure enclave Enclave, and combines with the AES-GCM symmetric encryption algorithm to ensure the security of the data storage and retrieval process. After receiving a data retrieval request, Storage matches the encrypted index based on keywords, retrieves the relevant ciphertext and forwards it to the requester, and at the same time completes the symmetric searchable encryption SSE calculation task without decrypting the data.

[0015] (4) Data Owner DO: Allows encrypting its own data, constructs an inverse keyword index table, and outsources the encrypted data to the Storage Service Provider Storage. DO needs to initialize the key of SSE and delegate the calculation task to an off-chain storage server. At the same time, DO encrypts the SSE key through CP-ABE to ensure that only authorized users who conform to the access policy can decrypt the key and further perform the keyword search task.

[0016] (5) Data User DU: Associates a set of attribute sets and is granted the permission to perform search tasks when the access policy is met. The authorized user can use CP-ABE to decrypt the SSE key, and then generate a search trapdoor τ w , initiate a search request to the Storage Service Provider Storage, and obtain the shared data file.

[0017] Furthermore, the symmetric encryption algorithm adopted is the AES-GCM algorithm. The encryption and decryption of this algorithm both use the same key, and the random vector iv can be used to ensure the uniqueness of encryption (under the condition of the same key, if the same iv is used, encrypting the same plaintext will produce the same ciphertext). The encryption and decryption processes are as follows:

[0018] (1) Encryption process: Use the symmetric key K and combine it with the vector iv to encrypt the plaintext m to generate the ciphertext C. The ciphertext C not only contains the encrypted data c, but also the length of the encrypted data and the authentication tag tag, that is, C = {c, l, tag}, to ensure data integrity and anti-tampering. Mathematically, this encryption process can be expressed as: C ← AES-Enc K (m, iv).

[0019] (2) Decryption process: Use the same symmetric key K and vector iv to decrypt the ciphertext C to restore the original plaintext m and verify the validity of the tag tag to ensure that the data has not been tampered with. This process can be formally expressed as: m ← AES-Dec K (C, iv).

[0020] Furthermore, the authorized access to the data covers three core links: CP-ABE initialization, ciphertext uploading to the blockchain, and data request, which specifically include the following steps:

[0021] Step 1: The key generation center KGC executes the initialization algorithm Setup, sets up the EIGamal encryption system that meets the security strength, including setting the elliptic curve group and the bilinear mapping on it, declaring the collision-resistant hash function, etc., and broadcasts the public parameters (such as the master public key mpk) to all entities in the system. The algorithm, Setup(1 λ , Ω) → (mpk, msk): takes the security parameter 1 λ and the global attribute space Ω as inputs, and outputs the global master public key mpk and the global master private key msk. Specifically, first determine the multiplicative cyclic group of prime order on the elliptic curve and its generator g, and there is also a bilinear mapping e: where is the target mapping multiplicative cyclic group. Define three collision-resistant hash functions, and to map strings of any length into a coordinate point or a random integer on the elliptic curve. Select two random numbers calculate to obtain the master public key and the master private key msk = g a .

[0022] Step 2: The key generation center KGC executes the key generation algorithm KeyGen, and generates the transformation key (stored in the blockchain) and the decryption key (held by the user) related to the attributes for the data user DU according to the attribute set of the data user DU. The algorithm, takes the master private key msk and a set of attribute sets as inputs, and outputs the corresponding transformation key tk and decryption key sk. Specifically, randomly select an integer calculate:

[0023]

[0024] Output transformation key The decryption key sk = r2.

[0025] Step 3: The data owner DO executes the encryption algorithm Encrypt, specifies the access policy, and embeds it into the ciphertext of the original data to be encrypted. Subsequently, the ciphertext is submitted to the blockchain BC for storage. The algorithm takes the public master key mpk and the LSSS-type access policy and the original data to be encrypted ek as inputs and outputs the ciphertext c. Specifically, first randomly select elements and a random vector where the secret value is placed at the first element of the vector and then calculate The ciphertext includes information of the Elgamal ciphertext layer (for encrypting data) and the access control layer (for restricting access), where

[0026] ① Elgamal ciphertext layer

[0027]

[0028] ② Access control layer

[0029]

[0030] where are two ciphertexts of length used to hide the secret s, and is random numbers for masking.

[0031] Finally, the ciphertext

[0032] Step 4: The blockchain BC executes the ciphertext transformation algorithm Transform to verify the identity and permissions of the data requester, ensuring that only the attribute set that conforms to the access policy can be successfully decrypted. At the same time, the blockchain BC transforms the ciphertext and completes partial decryption operations to reduce the computational burden of the data user and improve the decryption efficiency. The algorithm, Transform(c, tk) → ct / ⊥: takes the ciphertext c and the transformation key tk as inputs and outputs the transformed ciphertext ct if the condition is met. Set as the distribution of each attribute label in the attribute set in the matrix. If meets the access control policy then there exists a set of constants {ω i} i∈ICan be successfully calculated Then calculate the following formula to obtain:

[0033]

[0034] Output the transformed ciphertext ct = (ct1, ct2, ct3); otherwise, the attribute set Does not satisfy the access control policy Output ⊥.

[0035] Step Five: The data user DU executes the decryption algorithm Decrypt to decrypt the transformed ciphertext to obtain the original message. The algorithm, Decrypt(ct, sk) → ek / ⊥: takes the transformed ciphertext ct and the decryption key sk as inputs, and outputs the decrypted message ek if the conditions are met. Specifically, using the private key sk = r2, calculate and Verify the equation and Whether it holds. If it holds, the message can be successfully reconstructed; otherwise, prompt failure and output ⊥.

[0036] Furthermore, the LSSS-type access policy is an attribute access policy constructed based on the Linear Secret Sharing Scheme. The specific conditions are as follows:

[0037] (1) For the participant set The share of each participant belongs to the vector space over the finite field On.

[0038] (2) There exists a share generation matrix Which contains Rows and n columns. For each Matrix The i-th row of is labeled with a certain participant Consider the column vector Where Is the secret to be shared, Are randomly selected values, then Constitute A vector of secret shares. The share Is assigned to the participant x i , where Represents the i-th row of the matrix , and v i Represents the i-th element in the vector .

[0039] There is a property: Let Be an LSSS-type access policy. For any authorized attribute set Among them, Ω represents the attribute universe, and ① there exists a set of valid shares where I = {i: π(i) ∈ A}; ② there exists an effective algorithm (such as Gaussian elimination) to calculate a set of constants such that by calculating the secret s can be recovered from the valid shares.

[0040] Furthermore, for the data controllable search, the data owner DO holds the original dataset to be shared with a total of n files. To achieve controllable search of data identification files for authorized DUs, the DO will build an index table for the owned data, and after encrypting the data, outsource the ciphertext to the data storage service provider Storage for remote storage and management. In addition, to ensure the security of the outsourced data, timestamps are embedded in the encryption and decryption processes of the ciphertext, and the DU will publicly disclose the time identifier iv of this time period to all users in the system at each time cycle (e.g., daily, weekly). Specifically, the DO sequentially performs the following steps to complete the initialization of the outsourced shared data, including generating the data ciphertext and index:

[0041] (1) Number each data file in sequence as f i , where i ∈ [1, n]. Extract several keywords from the data files to pre - define the keyword set T w = {w1, w2,..., w l}}.

[0042] (2) According to the relationship between the data files and the keywords, generate a plaintext inverse index in the form of (keyword:: {data file number}) (i.e., "keyword - file" mapping). For example, if the keywords {w1, w3, w4} are included in the data file numbered f1, the keywords {w1, w2, w5} are included in the data file numbered f2, and the keywords {w1, w2, w3} are included in the data file numbered f3, then this index table can be represented as follows:

[0043] (w1:: {f1, f2, f3})

[0044] (w2:: {f2})

[0045] (w3:: {f1, f3})

[0046] (w4:: {f1})

[0047] (w5:: {f2})

[0048] For ease of representation, according to the inverse keyword index table, the file set related to the keyword w j is uniformly represented as F j , such as (w1:: F1), (w2:: F2), etc.

[0049] (3) Generate symmetric keys K1 and K2, where key K3 is generated by the key derivation function KDF from the message ek, i.e., K3 ← KDF(ek), and ek is also shared with the authorized data user DU during the CP-ABE phase. Subsequently, the keyword set and the associated file are encrypted using symmetric keys K1 and K2 through a symmetric encryption algorithm to obtain the keyword ciphertext Ciphertext of the data file Combining these ciphertexts, a ciphertext inverse index table in the form of etc. is obtained based on the plaintext inverse index. The ciphertext index table and all its ciphertext files are outsourced and stored in the storage service provider Storage for subsequent searches

[0050] (4) Through certificate verification, the data owner DO and the secure enclave Enclave in the data storage service provider's server complete remote identity authentication. Subsequently, DO and Enclave use the Diffie-Hellman key exchange protocol to generate a shared key and establish an authenticated secure communication channel. Finally, the symmetric keys K1, K2, and K3 are securely transmitted to Enclave through this secure channel

[0051] Furthermore, the symmetric searchable encryption SSE protocol adopts an execution method that combines an offline phase and an online phase

[0052] (1) Offline phase

[0053] To improve the efficiency of searchable encryption, the server loads the outsourced data from DO and transmits the keyword ciphertext set to Enclave. Enclave uses the symmetric key K1 through a decryption algorithm to recover all the plaintext keywords w in the set, where j ∈ [1, l], and l is the length of the complete keyword set. The recovered plaintext keyword set T j ={w1, w2, …, w w} is securely stored in the isolated space for subsequent keyword matching algorithms l}

[0054] (2) Online phase

[0055] ① Search trapdoor generation

[0056] The authorized DU generates the symmetric key K3 ← KDF(ek) through a derivation function, selects the keyword w, and generates a trapdoor after encryption Subsequently, the trapdoor τ w is sent as a request to the storage service provider Storage for searching

[0057] ② Secure Search

[0058] The server receives τ w and forwards it to the Enclave. The Enclave decrypts it to obtain the plaintext keyword Within the set edit distance d, the Enclave uses the Levenshtein edit distance algorithm to sequentially compare the keyword w with the set T of plaintext keywords stored in the isolated space w to calculate their similarity, find all keywords that satisfy the condition Levenshtein(w, w j ) ≤ d, and store their position indexes in the array Index[]. For example, Index[6] = {i1, i2,..., i6} represents 6 matching keywords, where i1 = 13 represents the 13th matching position. Subsequently, the Enclave returns the matching position indexes to the server. Without decrypting, the server traverses all ciphertexts that meet the fuzzy search conditions according to the indexes and returns them to the Enclave one by one.

[0059] The secure enclave Enclave decrypts to obtain the set of plaintext files Then it re-encrypts the file set R using the key K3 accessible to authorized users The proxy re-encryption process will be processed in a loop until all results are returned to the data user DU.

[0060] ③ Decrypt Data

[0061] The DU decrypts the returned result to obtain the plaintext data identification file

[0062] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0063] 1. Dual locking mechanism of attribute-based access control and retrieval permission. Specifically, the method of the present invention innovatively deeply integrates the CP-ABE and SSE technologies to construct a "dual-stage security barrier of access control - retrieval trigger". At the access control layer, the system takes user attributes as the core to drive the encryption and decryption processes of CP-ABE, encrypts and protects the SSE key as the core sensitive data, and ensures that only when the user attributes meet the access policy can the SSE key be decrypted to obtain and trigger the subsequent keyword search operation. This design realizes fine-grained permission control and progressive verification of operation permissions: unauthorized users can neither directly access the original data nor initiate a retrieval request to the off-chain storage service provider through the SSE interface, thus blocking the illegal access path at the source.

[0064] 2. Privacy - balanced architecture for efficient and secure data sharing and fuzzy keyword query. Through the deep integration of SSE technology and the trusted execution environment TEE, this solution constructs a two - layer protection system that takes into account both efficiency and privacy for data sharing in an untrusted storage server environment. Specifically, data processing is jointly executed by the built - in server of the off - chain storage service provider and the hardware - level secure enclave Enclave: the server is responsible for hosting encrypted documents and only supports ciphertext processing; relying on the hardware isolation feature, Enclave performs calculations in plaintext in the protected memory and finally collaborates with the server to complete tasks. In addition, Enclave can re - encrypt the calculation results using the SSE key of the authorized user to ensure that only the authorized user can decrypt and obtain the plaintext content, thus realizing end - to - end privacy protection in the whole process of data storage, calculation, and delivery. At the same time, a dynamic threshold fuzzy search mechanism based on the Levenshtein edit distance algorithm is innovatively introduced. Combining computational analysis and semantic similarity determination models, users can customize the keyword matching error - tolerance threshold according to actual needs (such as character difference tolerance or synonym association rules), breaking through the limitation that traditional SSE solutions only support exact matching. Compared with traditional searchable encryption technologies, this solution significantly improves the adaptability to complex query scenarios while ensuring the privacy and security of the keywords to be searched and the outsourced data, solves core problems such as low efficiency and single function, and provides scalable technical support for secure sharing and efficient retrieval in a large - scale data environment. Brief Description of the Drawings

[0065] Figure 1 It is a schematic diagram of the overall system model of the method of the present invention.

[0066] Figure 2 It is a schematic diagram of the ciphertext - policy attribute - based encryption CP - ABE process of the method of the present invention.

[0067] Figure 3 It is a schematic diagram of the symmetric searchable encryption SSE process of the method of the present invention. Specific Implementation Method

[0068] In order to make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0069] Such as Figure 1 、 Figure 2 and Figure 3As shown in the figure, the present invention provides a hybrid encryption method that supports access control and controllable data search, covering two major technologies: CP-ABE and SSE.

[0070] For data authorized access, it includes the following steps:

[0071] Step 1: The key generation center KGC executes the initialization algorithm Setup(1 λ , Ω) → (mpk, msk): Taking the security parameter 1 λ and the global attribute space Ω as inputs, and outputs the global public master key mpk and the global private master key msk. In the instance of this application, the multiplicative cyclic group is generated based on the A-type elliptic curve. For the convenience of calculation, small parameters (r: 20 bits, q: 64 bits) are selected, and the specific values are as follows.

[0072]

[0073] The selected generator is g = [963767505378102618, 10616632186748733]. Define three collision-resistant hash functions, and Subsequently, KGC selects two random numbers a = 12400, b = 208116, and then calculates g b = [118987997967393881, 435255021411230195], e(g, g) a = [3408712029331810, 261495663717767842]. Finally, the public master key and the private master key msk = g a = [668800578060240012, 452776659380642738] are obtained. The public master key mpk is broadcast to all other entities, while the private master key msk is maintained privately to ensure its non-disclosure.

[0074] Step 2: The key generation center KGC executes the key generation algorithm Taking the private master key msk and a set of attribute sets as inputs, and outputs the corresponding transformation key tk and the decryption key sk. Specifically, assume that in this example, the user attribute set is The selected integers r1 = 161220, r2 = 340204, and the calculated results are:

[0075]

[0076] Output the transformation key The decryption key sk = r2 = 340204. In particular, the transformation key tk is stored in the blockchain for executing the transformation algorithm Transform, while the decryption key sk is held by the user for completing the final decryption algorithm Decrypt.

[0077] Step 3: The data owner DO executes the encryption algorithm using the master public key mpk and the LSSS-type access policy with the original data ek to be encrypted as the input, and outputs the ciphertext c. Specifically, assume that in the example of this application, the threshold-type access policy defined by the data owner DO is (A1, A2, A3, A4, A5, 5), which means that only data users DU including these five attributes have the right to access the data. After the LSSS transformation, the formed matrix-type access policy is specifically represented as follows:

[0078]

[0079] Thus, the matrix has rows

[0080] and n = 5 columns. Assume the original data ek to be encrypted = 0001101100000110111011101011111010000100101000111111000111010001001110100110010000011111111110110111100110110010000110111101010010100010111011010000100110111110110000101001101110000001011110011111101001001001110001001111001011111000101000110111001100110110 which can be used to derive the symmetric key. Select the element R = [238494193262282727, 141340838152094959] and a random vector where the secret value is placed at the first element of the vector The ciphertext includes information of the Elgamal ciphertext layer (for encrypting data) and the access control layer (for restricting access), and is calculated as:

[0081] ① ElGamal ciphertext layer

[0082] c1 = R · e(g, g) as= [641975303667938113, 921734598795114329]

[0083]

[0084] c3 = g s = [968768018444525013, 580134117005029967]

[0085] ② Access control layer

[0086]

[0087]

[0088] Among them, the randomly selected numbers are φ1 = 69549, φ2 = 259430, φ3 = 225280, φ4 = 59749, φ5 = 314859

[0089] Finally, the ciphertext is output

[0090] Step 4: The blockchain BC executes the ciphertext conversion algorithm Taking the ciphertext c and the conversion key tk as inputs, if the conditions are met, the converted ciphertext ct is output. Obviously, in this embodiment, the threshold access policy defined by the data owner DO is (A1, A2, A3, A4, A5, 5), and the attribute set of the data user DU is Attribute set Meet the access control policy Therefore, there exists a constant set { ω i} i∈I Can be successfully calculated Furthermore, the following formula can be successfully calculated to obtain:

[0091] ct1 = c1 = [641975303667938113, 921734598795114329]

[0092] ct2 = c2 = 0010011110011101001111110110011000011010110100000100100011101001110010101010000100000001101100001111100111011100111101010111000011001110101110001000010110101111111000110000110100011100110011001000011100001101000001101010001101011111011001000111100011110011

[0093]

[0094] Output the transformed ciphertext ct = (ct1, ct2, ct3).

[0095] Step 5: Data user DU executes the decryption algorithm Decrypt(ct, sk) → ek / ⊥: Using the transformed ciphertext ct and the decryption key sk as inputs, if the conditions are met, output the decrypted message ek. Specifically, using the private key sk = r2 = 340204, calculate and The equation ct1 = R·e(g,g) as , holds, so the reconstructed message ek = 0001101100000110111011101011111010000100101000111111000111010001001110100110010000011111111110110111100110110010000110111101010010100010111011010000100110111110110000101001101110000001011110011111101001001001110001001111001011111000101000110111001100110110 is correct.

[0096] For data - controllable search, it includes the following steps:

[0097] Data owner DO holds the original dataset to be shared There are a total of n files. To achieve controllable search for data identification files for authorized DUs, the DO will construct an index table for the data it owns. After encrypting the data, the ciphertext will be outsourced to the data storage service provider Storage for remote storage and management. In addition, to ensure the security of the outsourced data, timestamps are embedded in both the encryption and decryption processes of the ciphertext. The DU will publicly disclose the time identifier iv for this time period to all users in the system at each time cycle (e.g., daily, weekly). Specifically, the DO sequentially performs the following steps to complete the initialization of the outsourced shared data, including generating the data ciphertext and index:

[0098] (1) Number each data file sequentially as f i , where i ∈ [1, n]. Extract several keywords from the data files to pre-define the keyword set T w = {w1, w2,..., w l}.

[0099] (2) According to the relationship between the data files and the keywords, generate a plaintext inverse index in the form of (keyword:: {data file number}) (i.e., the "keyword - file" mapping). For example, if the keywords {w1, w3, w4} are included in the data file numbered f1, the keywords {w1, w2, w5} are included in the data file numbered f2, and the keywords {w1, w2, w3} are included in the data file numbered f3, then this index table can be represented as follows:

[0100] (w1:: {f1, f2, f3})

[0101] (w2:: {f2})

[0102] (w3:: {f1, f3})

[0103] (w4:: {f1})

[0104] (w5:: {f2})

[0105] For ease of representation, according to the inverse keyword index table, the file set related to the keyword w j is uniformly represented as F j , such as (w1:: F1), (w2:: F2), etc.

[0106] (3) Generate symmetric keys K1, K2, where the key K3 is generated by the message ek through the key derivation function KDF, i.e., K3 ← KDF(ek), and ek is also shared with the authorized data user DU in the CP - ABE phase. Subsequently, use the symmetric keys K1, K2 to encrypt the keyword set and the associated files through the symmetric encryption algorithm to obtain the keyword ciphertext data file ciphertext Combining these ciphertexts, based on the plaintext inverse index, we obtain a ciphertext inverse index table in the form of and so on. The ciphertext index table and all its ciphertext files are outsourced and stored in the storage service provider Storage for subsequent searches.

[0107] (4) Through certificate verification, the data owner DO and the secure enclave Enclave in the data storage service provider's server complete remote identity authentication. Subsequently, DO and Enclave use the Diffie-Hellman key exchange protocol to generate a shared key and establish an authenticated secure communication channel. Finally, through this secure channel, the symmetric keys K1, K2, and K3 are securely transmitted to Enclave.

[0108] The searchable encryption SSE protocol adopts an execution method that combines an offline phase and an online phase:

[0109] (1) Offline phase:

[0110] To improve the efficiency of searchable encryption, the server loads the outsourced data from DO and transmits the keyword ciphertext set to Enclave. Enclave uses the symmetric key K1 through the decryption algorithm to recover all the plaintext keywords w in the set, where j ∈ [1, l], and l is the length of the complete keyword set. The recovered plaintext keyword set T j ={w1, w2,..., w w} is securely stored in the isolated space for subsequent keyword matching algorithms. l} is securely stored in the isolated space for subsequent keyword matching algorithms.

[0111] (2) Online phase:

[0112] ① Search trapdoor generation

[0113] The authorized DU generates the symmetric key K3 ← KDF(ek) through a derivation function, selects the keyword w, and generates a trapdoor after encryption Subsequently, the trapdoor τ w is sent as a request to the storage service provider Storage for search.

[0114] ② Secure search

[0115] After the server receives τ w it forwards it to Enclave. Enclave decrypts to obtain the plaintext keyword Within the set edit distance d, Enclave uses the Levenshtein edit distance algorithm to compare the keyword w with the plaintext keyword set T stored in the isolated space wPerform sequential comparison, calculate its similarity, and find all keywords that satisfy the condition Levenshtein(w, w j ) ≤ d, and store their position indexes in the array Index[]. For example, Index[6] = {i1, i2,..., i6} represents 6 matching keywords, where i1 = 13 represents the 13th matching position. Subsequently, the Enclave returns the matching position indexes to the server. Without decrypting, the server traverses all ciphertexts that meet the fuzzy search conditions according to the indexes and returns them to the Enclave one by one.

[0116] The secure enclave Enclave decrypts to obtain the plaintext file set Then re-encrypt the file set R with the key K3 accessible to authorized users The proxy re-encryption process will be processed in a loop until all results are returned to the data user DU.

[0117] ③ Decrypt the data

[0118] The DU decrypts the returned result to obtain the plaintext data identification file

[0119] The above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Those of ordinary skill in the art can modify or equivalently transform the technical solutions of the present invention without departing from the spirit and scope of the present invention. The protection scope of the present invention shall be subject to what is described in the claims.

Claims

1. A hybrid encryption method supporting access control and controllable data search, characterized in that, This method integrates data authorized access and data controllable search functions, achieving efficient and secure data sharing. This method allows data owners to define access policies and delegate lightweight authorization verification to smart contracts on the blockchain, thus avoiding excessive blockchain storage and computing burdens. At the same time, it allows data owners to encrypt and outsource the files to be shared and entrust the high-frequency data retrieval tasks to off-chain storage service providers equipped with servers, enabling them to complete symmetric searchable encryption operations based on keywords without decrypting the data. Compared with traditional broadcast encryption and public key searchable encryption, this method improves the computing efficiency while optimizing the privacy protection mechanism, achieving a better balance between security and usability. Specifically, the core technology of this method adopts Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and Symmetric Searchable Encryption (SSE), which are applied to the access control layer and the outsourced data encryption layer respectively: By embedding attribute information in the key generation and data encryption processes, CP-ABE is responsible for implementing attribute-based access control to ensure that only authorized users who meet the preset access policies can decrypt and obtain the data. In this method, the SSE key is stored as the encryption object, and only authorized users who have successfully decrypted through CP-ABE can obtain the SSE key to initiate a keyword search request. Therefore, this mechanism not only strictly controls data access rights but also ensures that only legitimate authorized users can perform subsequent SSE retrievals, eliminating the risk of unauthorized access. In addition, this method combines SSE technology with a Trusted Execution Environment (TEE) to implement an efficient and secure symmetric searchable encryption scheme in an untrusted cloud environment, while ensuring the privacy security of search keywords and outsourced shared files. The proposed method supports fuzzy keyword search based on set thresholds, meets complex query requirements, and further enhances the security and usability of data sharing. For massive data storage and diverse application scenarios, this scheme overcomes the limitations of traditional searchable encryption methods in terms of computing efficiency, storage cost, and only supporting single-keyword search, significantly improving the system performance and applicability.

2. The hybrid encryption method for supporting access control and controllable data search according to claim 1, characterized in that The described system model involves five types of entities: the Key Generation Center (KGC), the Blockchain (BC), the Storage Service Provider (Storage), the Data Owner (DO), and the Data User (DU). The responsibilities of each entity are as follows: (1) Key Generation Center (KGC): Responsible for generating, distributing, and managing system parameters and keys related to attributes to ensure the legality and security of the keys. Specifically, KGC mainly undertakes the key management tasks in the CP-ABE scheme, distributing private keys associated with the user's DU attribute set to enable it to decrypt data that conforms to the access policy. (2) Blockchain BC: Deploy smart contracts to verify CP-ABE access authorization requests. The data owner DO stores the ciphertext embedded with access policies in the blockchain. Before requesting access to data, the data user DU needs to verify their identity and permissions through the smart contract to ensure that only legitimate authorized users can obtain the plaintext data. (3) Storage Service Provider Storage: It has powerful computing and storage resources, responsible for storing the encrypted data uploaded by the data owner DO and processing search requests from the data user DU. The Storage Service Provider Storage integrates a Server environment internally and uses hardware isolation technology to generate a secure enclave (i.e., a trusted execution environment TEE), combined with the AES-GCM symmetric encryption algorithm, to ensure the security of the data storage and retrieval process. After receiving a data retrieval request, Storage matches the encrypted index based on keywords, retrieves the relevant ciphertext and forwards it to the requester, and simultaneously completes the symmetric searchable encryption SSE calculation task without decrypting the data. (4) Data Owner DO: Allows encrypting its own data, constructs an inverse keyword index table, and outsources the encrypted data to the Storage Service Provider Storage. DO needs to initialize the key of SSE and delegate the calculation task to an off-chain storage server. At the same time, DO encrypts the SSE key through CP-ABE to ensure that only authorized users who meet the access policy can decrypt the key and further perform the keyword search task. (5) Data User DU: Associates a set of attribute sets and is granted the permission to execute search tasks when the access policy is satisfied. The authorized user can use CP-ABE to decrypt the SSE key and then generate a search trapdoor τ w , and initiate a search request to the storage service provider Storage to obtain shared data files.

3. A hybrid encryption method for supporting access control and controllable data search according to claim 1, characterized in that, The symmetric encryption algorithm used is the AES-GCM algorithm. Both the encryption and decryption of this algorithm use the same key, and the uniqueness of encryption can be ensured by means of a random vector iv (under the same key condition, if the same iv is used, encrypting the same plaintext will generate the same ciphertext). The encryption and decryption processes are as follows: (1) Encryption process: Using the symmetric key K and combining it with the vector iv, encrypt the plaintext m to generate the ciphertext C. The ciphertext C not only contains the encrypted data c, but also the length of the encrypted data and the authentication tag tag, that is, C = {c, l, tag}, to ensure data integrity and anti-tampering. Mathematically, this encryption process can be expressed as: C ← AES-Enc K (m, iv). (2) Decryption process: Use the same symmetric key K and vector iv to decrypt the ciphertext C to restore the original plaintext m and verify the validity of the tag tag to ensure that the data has not been tampered with. This process can be formally expressed as: m←AES-Dec K (C, iv).

4. A hybrid encryption method for supporting access control and controllable data search according to claim 1, characterized in that, The data authorized access covers three core links: CP-ABE initialization, ciphertext on-chain, and data request, and specifically includes the following steps: Step 1: The Key Generation Center (KGC) executes the initialization algorithm Setup to set up the EkGamal encryption system that meets the security strength, including setting the elliptic curve group and the bilinear mapping thereon, declaring the collision-resistant hash function, etc., and broadcasts the public parameters (such as the master public key mpk) to all entities within the system. The algorithm, Setup(1λ, Ω) → (mpk, msk): takes the security parameter 1λ and the global attribute space Ω as inputs, and outputs the global master public key mpk and the global master private key msk. Specifically, first determine the multiplicative cyclic group of prime order, on the elliptic curve and its generator g, and at the same time there is a bilinear mapping where is the target mapping multiplicative cyclic group. Define three collision-resistant hash functions, and to map a string of any length into a coordinate point or a random integer on the elliptic curve. Select two random numbers Calculate to obtain the master public key and the master private key msk = g a . Step 2: The Key Generation Center (KGC) executes the key generation algorithm KeyGen. According to the attribute set of the Data User (DU), it generates an attribute-related transformation key (stored in the blockchain) and a decryption key (held by the user) for the DU. The algorithm, uses the master private key msk and a set of attribute sets as inputs, and outputs the corresponding transformation key tk and decryption key sk. Specifically, randomly select an integer Compute: Output conversion key The decryption key sk = r2. Step 3: The data owner DO executes the encryption algorithm Encrypt, specifies the access policy, and embeds it into the ciphertext of the original data to be encrypted. Subsequently, the ciphertext is submitted to the blockchain BC for storage. The algorithm, takes the master public key mpk and the LSSS-type access policy the original data ek to be encrypted as input and outputs the ciphertext c. Specifically, first randomly select elements and a random vector where the secret value is placed at the first element of the vector and then calculate The ciphertext includes information of the Elgamal ciphertext layer (for encrypting data) and the access control layer (for restricting access), where ① ElGamal Ciphertext Layer ② Access Control Layer Among them are two ciphertexts with lengths of used to hide the secret s, while is random numbers for masking. Finally, the output ciphertext is Step 4: The blockchain BC executes the ciphertext conversion algorithm Transform to verify the identity and permissions of the data requester, ensuring that only the attribute set that conforms to the access policy can be successfully decrypted. Meanwhile, the blockchain BC converts the ciphertext to complete partial decryption operations to reduce the computational burden of data users and improve the decryption efficiency. The algorithm, Transform(c, tk) → ct / ⊥: takes the ciphertext c and the conversion key tk as inputs and outputs the converted ciphertext ct if the conditions are met. Let the set be the distribution of each attribute label in the attribute set in the matrix. If meets the access control policy then there exists a constant set {ω i} i∈I that can be successfully calculated and then calculate the following formula to obtain: ct1 = c1, ct2 = c2 Output the transformed ciphertext ct = (ct1, ct2, ct3); otherwise, the attribute set does not satisfy the access control policy Output ⊥. Step 5: The data user DU executes the decryption algorithm Decrypt to decrypt the transformed ciphertext to obtain the original message. For the algorithm, Decrypt(ct, sk) → ek / ⊥: taking the transformed ciphertext ct and the decryption key sk as inputs, if the conditions are met, the decrypted message ek is output. Specifically, using the private key sk = r2, calculate and Verify the equation and Whether it holds. If it holds, the message can be successfully reconstructed; otherwise, prompt failure and output ⊥.

5. A hybrid encryption method for supporting access control and controllable data search according to claim 1, characterized in that The LSSS-type access policy is an attribute access policy constructed based on the Linear Secret Sharing Scheme, with the following specific conditions: (1) For the set of participants The share of each participant belongs to a vector space over a finite field as follows. (2) There exists a share generation matrix which contains m rows and n columns. For each matrix the i-th row of the matrix is labeled with a certain participant Considering the column vector where s is the secret to be shared, and r are randomly selected values, then forms a i vector of m secret shares. The share is assigned to participant x , where i represents the i-th row of the matrix and v i represents the i-th element in the vector . Existence property: Let be an LSSS-type access policy. For any authorized attribute set where Ω represents the attribute universe, ① there exists a set of valid shares where I = {i: π(i) ∈ A}; ② there exists an efficient algorithm (such as Gaussian elimination) to compute a set of constants such that by computing the secret s can be recovered from the valid shares.

6. A hybrid encryption method supporting access control and controllable data search according to claim 1, characterized in that, For the data-controllable search, the data owner DO holds the original dataset to be shared There are a total of n files. To enable data-identifier file controllable search for authorized DUs, DO will build an index table for the data it owns, encrypt the data, and then outsource the ciphertext to the data storage service provider Storage for remote storage and management. In addition, to ensure the security of the outsourced data, timestamps are embedded in the encryption and decryption processes of the ciphertext. DUs will publicly disclose the time identifier iv for this time period to all users in the system at each time cycle (e.g., daily, weekly). Specifically, DO sequentially performs the following steps to complete the initialization of the outsourced shared data, including generating the data ciphertext and index: (1) Sequentially number each data file as f i , where i ∈ [1, n]. Extract several keywords from the data files to pre-define the keyword set T w = {w1, w2,..., w l}. (2) According to the relationship between the data file and the keyword, generate a plaintext inverse index in the form of (keyword:: {data file number}) (i.e., the "keyword - file" mapping). For example, if the keywords {w1, w3, w4} are included in the data file numbered f1, the keywords {w1, w2, w5} are included in the data file numbered f2, and the keywords {w1, w2, w3} are included in the data file numbered f3, then this index table can be expressed similarly as: (w1:: {f1, f2, f3}) (w2:: {f2}) (w3:: {f1, f3}) (w4:: {f1}) (w5:: {f2}) For the sake of convenience of representation, according to the inverse keyword index table, the set of documents related to the keyword w j is uniformly represented as F j , such as (w1::F1), (w2::F2), etc. (3) Generate symmetric keys K1 and K2, where the key K3 is generated from the message ek by a key derivation function KDF, i.e., K3 ← KDF(ek), and ek is also shared with the authorized data user DU during the CP-ABE phase. Subsequently, the keyword set and the associated file are encrypted using the symmetric keys K1 and K2 through a symmetric encryption algorithm to obtain the keyword ciphertext Ciphertext of the data file Combining these ciphertexts, a ciphertext inverted index table in the form of etc. is obtained based on the plaintext inverted index. The ciphertext index table and all its ciphertext files are outsourced and stored in the storage service provider Storage for subsequent searches. (4) Through certificate verification, the data owner DO completes remote identity authentication with the secure enclave Enclave in the data storage service provider's server. Subsequently, DO and Enclave use the Diffie-Hellman key exchange protocol to generate a shared key and establish an authenticated secure communication channel. Finally, the symmetric keys K1, K2, and K3 are securely transmitted to Enclave through this secure channel.

7. A hybrid encryption method for supporting access control and controllable data search according to claim 1, characterized in that, The symmetric searchable encryption SSE protocol adopts an execution method that combines an offline phase and an online phase: (1) Offline phase: To improve the efficiency of searchable encryption, the server loads outsourced data from DO And the keyword ciphertext set Transmitted to Enclave. Enclave uses the symmetric key K1 through the decryption algorithm Recover all plaintext keywords w in the set j , where j∈[1, l] is the length of the complete keyword set. The restored plaintext keyword set T w ={w1, w2, ..., w l } is securely stored in an isolated space for use by subsequent keyword matching algorithms. (2) Online phase: ① Search trapdoor generation Authorize RU to generate a symmetric key K3 ← KDF(ek) through a derived function, select a keyword w, and generate a trapdoor through encryption Subsequently, the trapdoor τ w is sent as a request to the storage service provider Storage for searching. ② Secure search The server receives τ w and forwards it to the Enclave. The Enclave decrypts it to obtain the plaintext keyword Within the set edit distance d, the Enclave uses the Levenshtein edit distance algorithm to sequentially compare the keyword w with the set of plaintext keywords T stored in the isolated space w to calculate their similarity, find all keywords that satisfy the condition Levenshtein(w, w j ) ≤ d, and store their position indices in the array Index[]. For example, Index[6] = {i1, i2,..., i6} represents 6 matching keywords, where i1 = 13 represents the 13th matching position. Subsequently, the Enclave returns the matching position indices to the server. Without decrypting, the server traverses all ciphertexts that meet the fuzzy search conditions according to the indices and returns them to the Enclave one by one. The secure enclave decrypts to obtain the plaintext file set Then re-encrypt the file set R using the key K3 accessible to authorized users The proxy re-encryption process will loop until all results are returned to the data user RU ③ Decrypt data DU decrypts the returned result to obtain the plaintext data identification file

Citation Information

Cited By

  • Zero-trust multi-party security data exchange method

    CN120856334A

  • Enhanced symmetric searchable encryption method and system

    CN121118099A