Data sharing method and device in cloud environment, equipment and storage medium
By using a fully triple tree encryption and blockchain verification method in a cloud environment, combined with edge computing and Pedersen secret sharing protocol, fine-grained ciphertext retrieval permission control is achieved, solving security and resource management problems in the data sharing process in the cloud environment, and reducing the risk of privacy leakage.
Patent Information
- Application Number
- CN202510521515.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-18
AI Technical Summary
In the cloud environment, the existing technology cannot effectively realize fine-grained ciphertext retrieval permission control, and faces the risk of computing resource fluctuations and privacy information leakage caused by dynamic changes in users.
By using secret values and data access structures in a complete tritree to encrypt shared files and keyword sets, generate file ciphertexts and keyword indexes, and use blockchain verification to retrieve transactions, edge computing nodes perform partial decryption, and combine Pedersen secret sharing protocol to generate attribute private keys to achieve fine-grained permission control and dynamic user management.
It improves the security of data transmission, storage and computing during data sharing in the cloud environment, reduces the risk of private information leakage caused by illegal access, and realizes balanced allocation and dynamic scheduling of computing resources.
Smart Images

Figure CN120342705A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a data sharing method, device, equipment and storage medium in a cloud environment. Background Art
[0002] With the rapid development of computing network and cloud computing technologies, their advantages in data resource sharing, distributed storage and efficient computing have become increasingly prominent, providing powerful capabilities for processing massive data and supporting complex computing tasks. However, this high concentration and cross-domain sharing of data also faces challenges in privacy protection. How to ensure the security of data during transmission, storage and computing and prevent illegal access has become a key issue that needs to be solved urgently, especially in data ciphertext retrieval and sharing scenarios. Traditional attribute-based search encryption schemes do not essentially utilize attribute encryption keywords, that is, they cannot provide fine-grained retrieval permission control. In addition, in actual scenarios, a large number of users often leave or pour into the system at the same time, which may cause instantaneous fluctuations in computing resources, resulting in congestion, insufficient bandwidth or increased transmission delays. Therefore, how to solve the above challenges to achieve secure data sharing is an urgent problem to be solved in the current cloud environment. Summary of the invention
[0003] The purpose of the present invention is to provide a data sharing method, device, equipment and medium in a cloud environment, aiming to solve the problems of low security and easy leakage of user privacy in the transmission, storage and calculation processes of cloud shared data due to existing technologies.
[0004] In one aspect, the present invention provides a data sharing method in a cloud environment, the method comprising the following steps:
[0005] The data owner encrypts the shared file and the keyword set of the shared file according to the secret value and data access structure stored in the leaf node of the data owner in the pre-built complete ternary tree, obtains the file ciphertext and the keyword index, and uploads the file ciphertext and the keyword index to the computing power server;
[0006] The data recipient generates a retrieval token and retrieval transaction based on its own attribute private key and the set of keywords to be accessed;
[0007] When the blockchain verifies that the retrieval transaction is valid and the attribute set of the data recipient satisfies the data access structure, the computing power server sends the file storage address matching the retrieval token to the data recipient;
[0008] The edge computing node partially decrypts the file ciphertext obtained from the file storage address and sent by the data receiver according to the attribute private key of the data receiver, and sends the semi-decrypted ciphertext after partial decryption to the data receiver;
[0009] The data receiver restores the shared file according to the semi-decrypted ciphertext.
[0010] Preferably, before the step that the data receiver generates a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed, the method further includes:
[0011] According to the secret value stored in the leaf node where the data receiver belongs in the complete ternary tree and the attribute set of the data receiver, the attribute authority generates an attribute private key for the data receiver by using the Pedersen secret sharing protocol.
[0012] Preferably, the step that the computing power server sends the file storage address matching the retrieval token to the data receiver includes:
[0013] The computing power server retrieves the keyword index matching the retrieval token according to the data access structure, and sends the file storage address corresponding to the retrieved keyword index to the data receiver.
[0014] Preferably, the method further includes:
[0015] When the valid user set is updated, the attribute authority sends a ciphertext update identifier to the edge computing node, where the valid user set is the smallest node set determined by level traversing the complete ternary tree and covering all non-revoked users in the complete ternary tree;
[0016] The edge computing node updates some ciphertext components in the file ciphertext and keyword index corresponding to the node to be updated by using a preset data update strategy, and sends the updated file ciphertext and keyword index to the computing power server.
[0017] On the other hand, the present invention provides a data sharing device in a cloud environment, and the device includes:
[0018] A file encryption unit, configured to encrypt a shared file and the keyword set of the shared file respectively by a data owner according to the secret value stored in the leaf node where the data owner belongs in a pre-constructed complete ternary tree and a data access structure, obtain a file ciphertext and a keyword index, and upload the file ciphertext and the keyword index to a computing power server;
[0019] A token generation unit, configured to generate a retrieval token and a retrieval transaction by a data receiver according to its own attribute private key and the keyword set to be accessed;
[0020] An address sending unit, configured to when the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver satisfies the data access structure, the computing power server sends the file storage address matching the retrieval token to the data receiver;
[0021] A partial decryption unit, configured to the edge computing node partially decrypts the file ciphertext obtained from the file storage address sent by the data receiver according to the attribute private key of the data receiver, and sends the partially decrypted semi-decrypted ciphertext to the data receiver;
[0022] A file recovery unit, configured to the data receiver restores the shared file according to the semi-decrypted ciphertext.
[0023] Preferably, the apparatus further includes:
[0024] An attribute private key generation unit, configured to according to the secret value stored in the leaf node to which the data receiver belongs in the full ternary tree and the attribute set of the data receiver, the attribute institution generates an attribute private key for the data receiver by using the Pedersen secret sharing protocol.
[0025] Preferably, the address sending unit includes:
[0026] An address matching unit, configured to the computing power server retrieves the keyword index matching the retrieval token according to the data access structure, and sends the file storage address corresponding to the retrieved keyword index to the data receiver.
[0027] Preferably, the apparatus further includes:
[0028] An update flag sending unit, configured to when the valid user set is updated, the attribute institution sends a ciphertext update flag to the edge computing node, where the valid user set is the smallest node set determined by level traversing the full ternary tree and covering all non-revoked users in the full ternary tree;
[0029] A ciphertext component update unit, configured to the edge computing node updates partial ciphertext components in the file ciphertext and keyword index corresponding to the node to be updated by using a preset data update strategy, and sends the updated file ciphertext and keyword index to the computing power server.
[0030] On the other hand, the present invention further provides a computing device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the steps described in the data sharing method in the above cloud environment are implemented.
[0031] On the other hand, the present invention also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps described in the data sharing method in the cloud environment as above are implemented.
[0032] In the present invention, the data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which the data owner belongs in the complete ternary tree and the data access structure, obtains the file ciphertext and the keyword index, and uploads the file ciphertext and the keyword index to the computing power server. The data receiver generates a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed. When the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver satisfies the data access structure, the computing power server sends the file storage address matching the retrieval token to the data receiver. The edge computing node partially decrypts the file ciphertext sent by the data receiver and obtained from the file storage address according to the attribute private key of the data receiver, and sends the partially decrypted semi-ciphertext to the data receiver. The data receiver restores the shared file according to the semi-ciphertext, thereby realizing fine-grained control of ciphertext retrieval permissions, improving the security of data transmission, storage and calculation in the data sharing process in the cloud environment, and reducing the risk of privacy information leakage caused by illegal access. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 is a flowchart of the implementation of the data sharing method in the cloud environment provided in the first embodiment of the present invention;
[0034] Figure 2 is a flowchart of the implementation of the data sharing method in the cloud environment provided in the second embodiment of the present invention;
[0035] Figure 3 is a schematic structural diagram of the data sharing device in the cloud environment provided in the third embodiment of the present invention;
[0036] Figure 4 is a schematic structural diagram of the computing device provided in the fourth embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0038] It should be understood that, as used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups. And the terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in this specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms. The terms "first", "second" and similar words do not denote any order, quantity or importance, but are only used to distinguish different components. "Connection" or "coupling" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right", etc. are only used to indicate relative position relationships. When the absolute position of the object being described changes, the relative position relationship may also change accordingly. The term "plurality" means two or more, and other quantifiers are similar.
[0039] To keep the following description of the embodiments of the present invention clear and concise, the detailed descriptions of some known functions and known components are omitted in this specification.
[0040] The following describes in detail the specific implementation of the present invention in conjunction with specific embodiments:
[0041] Embodiment 1:
[0042] Figure 1 The implementation process of the data sharing method provided in Embodiment 1 of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown and are described in detail as follows:
[0043] In step S101, the data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which it belongs in the pre-constructed complete ternary tree and the data access structure, obtains the file ciphertext and the keyword index, and uploads the file ciphertext and the keyword index to the computing power server.
[0044] Embodiments of the present invention are applicable to computing devices, such as personal computers, servers, etc. In the embodiments of the present invention, for a data owner u existing in the effective user set cover(rl) (i.e., u ∈ cover(rl)), through the following steps, the data owner realizes the encryption of the shared file and the keyword set of the shared file. Here, rl represents the revocation list for recording the revoked users in the complete ternary tree, and cover(rl) represents the smallest node set determined by level traversing the complete ternary tree and covering all non-revoked users (i.e., not in the revocation list rl) in the complete ternary tree. Specifically:
[0045] (1) The data owner formulates a specific data access structure (A, ρ, Attr), where, represents a linear secret sharing matrix of size l×n, l represents the number of rows of A, n represents the number of columns of A, ρ represents a function mapping each row of the matrix to an attribute name, and Attr represents the attribute set;
[0046] (2) The data owner uses the secret value r stored in the leaf node where it belongs in the pre-constructed complete ternary tree u to recover the symmetric key k = ψ mod r u , where ψ is the key mask generated by the attribute authority using the symmetric key k;
[0047] (3) The data owner encrypts the shared file f using the symmetric key k to generate the first sub-ciphertext C, denoted as C = Enc k (f);
[0048] (4) The data owner calculates the second sub-ciphertext the third sub-ciphertext C1 = g and the fourth sub-ciphertext C2 = g as according to the system global parameters generated by the attribute authority s , where G, respectively represent cyclic multiplicative groups of prime order p, satisfying g is the generator of G, w and a are random numbers, and w ∈ G, H, F, and R represent three collision-resistant hash functions, Y0, Y1, and Y2 represent three public sub-parameters, represents the multiplicative group formed by all non-zero elements in the finite field Z p of order p;
[0049] (5) The data owner randomly selects a group of constants and constructs a vector
[0050] (6) For each row attribute i (1 ≤ i ≤ l) of A, the data owner selects a group of random numbers And calculate the fifth sub-ciphertext Wherein, ρ(i) represents the attribute name mapped by the i-th row of A, and τ ρ(i) represents the attribute value associated with the attribute name ρ(i);
[0051] (7) The data owner generates the sixth sub-ciphertext according to the secret value mask Wherein, Y u represents the secret value mask;
[0052] (8) Generate the file ciphertext CT = {(A, ρ, Attr), C, C0, C1, C2, {C i,1 , C i,u} i∈[1,l]}} according to the data access structure, the first, second, third, fourth, fifth, and sixth sub-ciphertexts;
[0053] (9) The data owner extracts the keyword set W = {w1,..., w m}} j∈[1,m] from the shared file f;
[0054] (10) The data owner calculates the first sub-index the second sub-index the third sub-index the fourth sub-index
[0055] (11) The data owner generates the keyword index I W = {I j,1 , I j,2 , I i,j,1 , I i,j,u}} i∈[1,l],j∈[1,m] ;
[0056] (12) The data owner uploads the file ciphertext CT and the keyword index I W to the computing power server for storage.
[0057] The above steps (1) to (12) are based on the attribute-based search encryption technology, and encrypt and share the file and keywords in combination with the access structure, realizing fine-grained access control.
[0058] In a feasible embodiment, the data owner uses the Elgamal digital signature to generate a signature and a storage transaction according to the file storage address Addr returned by the computing power server. The specific operations are as follows:
[0059] Select a timestamp Time to prevent replay attacks, and randomly select an η that satisfies 1 < η < p - 1 and gcd(η, p - 1) = 1;
[0060] Compute signature where δ = R(Addr||Time||R(CT||I W ))
[0061] Generate storage transaction TR Enc = {sign δ , R(CT||I W ), Addr}, and send the storage transaction TR Enc to the blockchain for verification, thereby using the Elgamal digital signature technology and the immutability of the blockchain to store and verify the validity of the transaction, improving the security of data during transmission, storage, and calculation, and effectively preventing the leakage of privacy information caused by unauthorized illegal access.
[0062] In another feasible embodiment, after the blockchain receives the storage transaction TR Enc , the consensus node recalculates δ according to the parameters in the transaction TR Enc . Then, first perform signature legality verification. Specifically, verify the equation whether it holds. If it holds, it indicates that the signature sign δ is legal. Then perform data integrity verification. Specifically, check whether the hash value R(CT||I W ) carried in the transaction is consistent with the recalculated hash value R(CT||I W )′, that is If they are equal, it means that CT and I W have not been tampered with. If both stages of verification pass, the transaction is legal and the data is complete; otherwise, it is marked as an invalid transaction.
[0063] In another feasible embodiment, before the data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which it belongs in the pre-constructed complete ternary tree and the data access structure, several attribute authorities generate the system global parameter GP and the master private key Msk based on the Pedersen secret sharing protocol. The specific implementation process is as follows:
[0064] ① The attribute authority inputs the system security parameters, let G and be two cyclic multiplicative groups of prime order p, the generator of G is g, and it satisfies and select a random number w ∈ G;
[0065] ② Select three random numbers α, β, and a from , that is Generate the master private key Msk = {α, β, a}, and share the private keys α and β among each attribute authority using the Pedersen secret sharing protocol. Then each attribute authority AA x holds its own secret share α x 、β x , where x represents the subscript of the attribute authority;
[0066] ③ K attribute authorities reconstruct α and β based on their respective held secret shares α x 、β x and calculate
[0067] where 1 ≤ K ≤ K 总 , K 总 represents the total number of attribute authorities, and L(·) represents the Lagrange formula;
[0068] ④ Select three collision-resistant hash functions F: {0, 1} * → G, R: {0, 1} * → {0, 1} K ;
[0069] ⑤ Generate the system global parameters
[0070] In another feasible embodiment, before the data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which it belongs in the pre-constructed complete ternary tree and the data access structure, the attribute authority constructs a complete ternary tree with the number of leaf nodes being L for managing users (including the data owner and the data receiver). Each leaf node of this tree corresponds to a user u, that is, 1 ≤ u ≤ L, and the secret value r of the associated user is stored in each leaf node u . Through such a structural setting, it is possible to use the complete ternary tree as an indexing framework to achieve the precise associated storage of users and their respective secret values, providing an efficient and secure data organization form for subsequent services involving the processing of user private information such as data encryption and access permission verification.
[0071] In yet another feasible embodiment, the attribute authority generates respective secret values, secret value masks, and key masks for the users corresponding to each leaf node in the complete ternary tree. The specific implementation process is as follows:
[0072] For each user u, select a random number as the secret value of the user, and calculate h u = H(GID||Y u ), and set Y uAs the corresponding secret value r u The secret value mask of , in order to hide the secret value, where GID represents the user's unique identity, h u represents identity masking to anonymize the identity;
[0073] Randomly select a symmetric key k and calculate ψ = υ·k, using ψ as the key mask of k, where f u Satisfy u ×f u ≡1modr u , U represents the total number of valid users in the complete ternary tree (i.e., users not in the revocation list rl);
[0074] Y u , ψ are sent to the corresponding users.
[0075] In step S102, the data recipient generates a retrieval token and a retrieval transaction according to its own attribute private key and the set of keywords to be accessed.
[0076] In the embodiment of the present invention, the data receiver first extracts the to-be-accessed keyword set Q = {q1, q2, ..., q m′}, then, based on its own attribute private key, the set of keywords to be accessed, and the system global parameters, it generates a retrieval token and a retrieval transaction, sends the retrieval transaction to the blockchain, and initiates a retrieval request to the computing power server. The retrieval request contains a retrieval token. The specific implementation operations for generating a retrieval token and a retrieval transaction are as follows:
[0077] (1) Select a random number
[0078] (2) Calculate the first sub-token Second sub-token The third sub-token Among them, D u,i,4 It is the fourth sub-attribute private key in the attribute private key;
[0079] (3) Generate a search token T = {T j,1 ,T j,2 ,T j,3} j∈[1,m′] ;
[0080] (4) Select a timestamp Time′ and randomly select an η′ that satisfies 1<η′<p-1, gcd(η′,p-1)=1;
[0081] (5) Calculate σ = R(T||Time′) and signature in,
[0082]
[0083] (6) Generate the retrieval transaction TR Token = {sign σ , R(T||Time′)}.
[0084] Through the above steps (1) to (6), the retrieval token is constructed based on attributes, thus ensuring fine-grained ciphertext retrieval permissions.
[0085] In a feasible embodiment, before the step that the data receiver generates the retrieval token and the retrieval transaction according to its own attribute private key and the set of keywords to be accessed, according to the secret value stored in the leaf node where the data receiver belongs in the complete ternary tree and the attribute set of the data receiver, the attribute authority generates the attribute private key for the data receiver by using the Pedersen secret sharing protocol.
[0086] In the embodiment of the present invention, for the data receivers existing in the valid user set cover(rl) (i.e., u ∈ cover(rl)), the attribute authority generates respective attribute private keys for each data receiver by using the Pedersen secret sharing protocol. The specific implementation process is as follows:
[0087] ① Each attribute authority AA x Selects a random parameter where i ∈ I s , I s represents the attribute set of the u-th user;
[0088] ② Each attribute authority AA x Calculates its own secret share
[0089] ③ K attribute authorities reconstruct the attribute secret value for generating the attribute private key
[0090] ④ Calculate the first sub-attribute private key The second sub-attribute private key The third sub-attribute private key The fourth sub-attribute private key
[0091] ⑤ Generate the attribute private key
[0092] Through the above steps ① to ⑤, multiple attribute authorities share the secret shares, realizing the decentralized collaborative generation of attribute private keys by multiple authorization authorities and avoiding single point of failure.
[0093] In step S103, when the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver satisfies the data access structure, the computing power server sends the file storage address matching the retrieval token to the data receiver.
[0094] In the embodiment of the present invention, after the blockchain receives the retrieval transaction TR Token it verifies calculates σ′ = R(T||Time′), and judges If the equation holds, it sends the result that the retrieval transaction is valid to the computing power server. When the computing power server determines that the retrieval transaction corresponding to the retrieval token in the retrieval request initiated by the data receiver is valid and the attribute set of the data receiver satisfies the data access structure, it retrieves the keyword index matching the retrieval token T, and sends the file storage address corresponding to the retrieved keyword index to the data receiver. Specifically: select a set of random numbers {c i ′} i∈I to make it satisfy ∑ i∈I c i ′A i = (1, 0,..., 0). For I = {i ∈ [1, l]: ρ(i) ∈ I s}, calculate According to the retrieved index I j,1 obtain its corresponding file storage address, so as to reasonably distribute the time-consuming and complex retrieval calculation to the computing power server, and realize the balanced distribution and dynamic scheduling of computing resources.
[0095] In step S104, the edge computing node partially decrypts the file ciphertext obtained from the file storage address and sent by the data receiver according to the attribute private key of the data receiver, and sends the partially decrypted semi-decrypted ciphertext to the data receiver.
[0096] In the embodiment of the present invention, after the data receiver obtains the file ciphertext CT from the file storage address, it sends a file decryption request to the edge computing node. The request contains the attribute private key of the data receiver and the file ciphertext. After receiving the file decryption request, the edge computing node partially decrypts the file ciphertext using a preset outsourcing decryption algorithm, and sends the partially decrypted semi-decrypted ciphertext to the data receiver. The specific implementation process is as follows:
[0097] When the attribute set of the data receiver satisfies the access policy corresponding to the data access structure formulated by the data owner, the edge computing node selects a set of constant sets {c i} i∈I to make it satisfy ∑ i∈I c i A i = {1, 0,..., 0}, then there is ∑ i∈I c i λi = s, where I = {i ∈ [1, l]: ρ(i) ∈ I s};
[0098] Execute outsourced decryption to generate a semi - decrypted ciphertext and send it to the data receiver, so as to achieve balanced allocation and dynamic scheduling of computing resources by reasonably distributing the decryption task to edge computing nodes.
[0099] In step S105, the data receiver recovers the shared file according to the semi - decrypted ciphertext.
[0100] In the embodiment of the present invention, the data receiver first calculates the symmetric key according to the semi - decrypted ciphertext and then uses the symmetric key k to recover the original shared file f = Dec (f). k (f).
[0101] In the embodiment of the present invention, the data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which it belongs in the complete ternary tree and the data access structure, obtains the file ciphertext and the keyword index, and uploads the file ciphertext and the keyword index to the computing power server. The data receiver generates a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed. When the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver meets the data access structure, the computing power server sends the file storage address matching the retrieval token to the data receiver. The edge computing node partially decrypts the file ciphertext obtained from the file storage address sent by the data receiver according to the attribute private key of the data receiver, and sends the partially decrypted semi - decrypted ciphertext to the data receiver. The data receiver recovers the shared file according to the semi - decrypted ciphertext, thereby realizing fine - grained control of ciphertext retrieval permissions, improving the security of data transmission, storage and calculation in the data sharing process in the cloud environment, and reducing the risk of privacy information leakage caused by illegal access.
[0102] Example 2:
[0103] Figure 2 The implementation process of the data sharing method in the cloud environment provided by the second embodiment of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiment of the present invention are shown and are described in detail as follows:
[0104] When a user batch revokes and / or joins the current file sharing system, the relevant information of the shared file stored in the cloud is batch - updated through the following steps:
[0105] In step S201, when the valid user set is updated, the attribute authority sends a ciphertext update identifier to the edge computing node, where the valid user set is the smallest node set determined by level traversal of a complete ternary tree and covering all non-revoked users in the complete ternary tree.
[0106] In an embodiment of the present invention, when the attribute authority receives revocation requests of several users, the attribute authority updates the revocation list and updates the valid user set cover(rl). Specifically, when the attribute authority receives revocation requests of several users, it first adds the revoked users to the revocation list, that is, rl′ = rl ∪ {u 撤}, and then starts from the node corresponding to the revoked user in the complete ternary tree and backtracks upward along the path to dynamically verify the coverage status of each ancestor node: if there are non-covered non-revoked users in the subtree of the node and they are not covered by higher-level nodes, add it to the valid user set; if there are no non-revoked users in the subtree of the node, remove it from the valid user set; if a lower-level node becomes redundant due to new coverage by a higher-level node, remove the lower-level node. Finally, ensure that the valid user set cover(rl) is still the minimum cover set through a greedy strategy. Subsequently, the attribute authority reselects a symmetric key k′ and calculates ψ′ = υ′·k′, where u 撤 represents the revoked user. As an example, if u 撤 includes u3, u5, u7, then rl′ = rl ∪ {u3, u5, u7},
[0107] When the attribute authority receives registration requests of several users, it inserts the new users into the leaf nodes of the complete ternary tree and backtracks upward along their paths to dynamically update the valid user set cover(rl). The valid user set can be determined by a greedy algorithm, which preferentially selects higher-level nodes that can cover the most non-revoked users to ensure covering all non-revoked users and having the minimum number of nodes. Subsequently, the attribute authority reselects a symmetric key k′ and calculates ψ′ = υ′·k′, where u 加 represents the newly added users. As an example, if u 加 includes u2, u4, u6, then it is necessary to calculate
[0108] Then, send the updated value ψ′ to the users corresponding to the leaf nodes in the complete ternary tree. After receiving ψ′, the non-revoked users can calculate ψ′ mod r u = k′, so as to recover the new key k′, while the revoked users cannot recover the new key;
[0109] In view of the new valid user set cover(rl)′, the attribute authority randomly selects an element Calculation Obtain the ciphertext update identifier After that, send it through the secure channel To the edge computing node
[0110] In step S202, the edge computing node updates some ciphertext components in the file ciphertext and keyword index corresponding to the node to be updated by using a preset data update strategy, and sends the updated file ciphertext and keyword index to the computing power server
[0111] In the embodiment of the present invention, based on the Chinese Remainder Theorem, the edge computing node updates some ciphertext components in the file ciphertext and keyword index corresponding to the node to be updated, and sends the updated file ciphertext and keyword index to the computing power server, where the node to be updated is the node corresponding to the newly added or revoked user in the complete ternary tree, and the specific implementation process is as follows
[0112] If u ∈ cover(rl)′ and u = u′, then C i,u′ = C i,u , I i,j,u′ = I i,j,u , where u′ represents the user corresponding to the node to be updated
[0113] If u ∈ cover(rl)′ and u is an ancestor node of u′, then path(u′) = path(u) ∪ {l dept(u)+1 ,..., l dept(u′)}, where l dept(u) = u, l dept(u′) = u′
[0114] From b = dept(u) to b = dept(u′) - 1, perform the calculation
[0115] Only need to update the above-mentioned partial ciphertext components, while other components remain unchanged, that is, C0′ = C0, C1′ = C1, C′2 = C2, C′ i,1 = C i,1 , I′ j,1 = I j,1 , I′ j,2 = I j,2 , I′ i,j,1 = I i,j,1 , and then, the edge computing node sends the updated ciphertext CT′ = {C′0, C′1, C′2, {C′ i,1 , C i,u′} i∈[1,l]} and the index I W′ = {I′ j,1 , I′ j,2,{I′ i,j,1 ,I i,j,u′} i∈[1,l]} j∈[1,m] To the computing power server.
[0116] In the embodiments of the present invention, when the valid user set is updated, the attribute authority sends the ciphertext update identifier to the edge computing node. The edge computing node updates some ciphertext components in the file ciphertext and keyword index corresponding to the node to be updated by using a preset data update strategy, and sends the updated file ciphertext and keyword index to the computing power server, so as to realize efficient batch user revocation or addition based on the Chinese Remainder Theorem, only need to perform addition, subtraction operations and update some ciphertext and index components, and at the same time outsource all these calculations to the edge computing node, significantly reducing the computing overhead of users and improving resource utilization.
[0117] Example 3:
[0118] Figure 3 Shows the structure of the data sharing device in the cloud environment provided by the third embodiment of the present invention. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown, including:
[0119] The file encryption unit 31 is used for the data owner to encrypt the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which the data owner belongs in the pre-constructed complete ternary tree and the data access structure, obtain the file ciphertext and keyword index, and upload the file ciphertext and keyword index to the computing power server;
[0120] The token generation unit 32 is used for the data receiver to generate a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed;
[0121] The address sending unit 33 is used for the computing power server to send the file storage address matching the retrieval token to the data receiver when the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver meets the data access structure;
[0122] The partial decryption unit 34 is used for the edge computing node to partially decrypt the file ciphertext obtained from the file storage address sent by the data receiver according to the attribute private key of the data receiver, and send the partially decrypted semi-ciphertext to the data receiver;
[0123] The file recovery unit 35 is used for the data receiver to recover the shared file according to the semi-ciphertext.
[0124] Preferably, the data sharing device in the cloud environment of the embodiments of the present invention further includes:
[0125] An attribute private key generation unit, which is used to generate an attribute private key for a data receiver by an attribute authority using the Pedersen secret sharing protocol according to the secret value stored in the leaf node where the data receiver belongs in a complete ternary tree and the attribute set of the data receiver.
[0126] Preferably, the address sending unit 33 includes:
[0127] An address matching unit, which is used for a computing power server to retrieve a keyword index matching a retrieval token according to a data access structure and send the file storage address corresponding to the retrieved keyword index to the data receiver.
[0128] Another preferably, the data sharing device in the cloud environment of the embodiment of the present invention further includes:
[0129] An update flag sending unit, which is used for the attribute authority to send a ciphertext update flag to an edge computing node when the valid user set is updated, where the valid user set is the smallest node set determined by level traversing a complete ternary tree and covering all non-revoked users in the complete ternary tree;
[0130] A ciphertext component update unit, which is used for the edge computing node to update some ciphertext components in the file ciphertext and keyword index corresponding to the node to be updated by using a preset data update strategy, and send the updated file ciphertext and keyword index to the computing power server.
[0131] In the embodiment of the present invention, for the convenience and conciseness of description, only the above-mentioned functional units and modules are divided for illustration. In actual applications, the above functions can be allocated to different functional units and modules as needed, that is, the internal structure of the data sharing device in the cloud environment is divided into different functional units or modules to implement all or part of the functions described above. Each unit and module of the data sharing device in the cloud environment can be implemented by corresponding hardware or software units. Each unit and module can be an independent software or hardware unit, or can be integrated into a software or hardware unit, which is not used to limit the present invention here. In addition, the specific names of the functional units and modules are only for easy distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in this device can refer to the corresponding description in the foregoing method embodiments and will not be elaborated here.
[0132] Example 4:
[0133] Figure 4 The structure of the computing device provided in the fourth embodiment of the present invention is shown. For the convenience of description, only the parts related to the embodiment of the present invention are shown.
[0134] The computing device 4 in the embodiment of the present invention includes a processor 40, a memory 41, and a computer program 42 stored in the memory 41 and executable on the processor 40. When the processor 40 executes the computer program 42, it implements the steps in the data sharing method embodiment in the above cloud environment, such as Figure 1 the steps S101 to S105 shown. Alternatively, when the processor 40 executes the computer program 42, it implements the functions of each unit in the above device embodiments, such as Figure 3 the functions of the shown unit.
[0135] In the embodiment of the present invention, the data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which it belongs in the complete ternary tree and the data access structure, obtains the file ciphertext and the keyword index, and uploads the file ciphertext and the keyword index to the computing power server. The data receiver generates a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed. When the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver meets the data access structure, the computing power server sends the file storage address matching the retrieval token to the data receiver. The edge computing node partially decrypts the file ciphertext sent by the data receiver and obtained from the file storage address according to the attribute private key of the data receiver, and sends the partially decrypted semi-ciphertext to the data receiver. The data receiver restores the shared file according to the semi-ciphertext, thereby realizing fine-grained ciphertext retrieval permission control, improving the security of data transmission, storage and calculation in the data sharing process in the cloud environment, and reducing the risk of privacy information leakage caused by illegal access.
[0136] The computing device in the embodiment of the present invention can be a personal computer or a server. The steps implemented when the processor 40 in the computing device 4 executes the computer program 42 to implement the data sharing method in the cloud environment can refer to the description of the foregoing method embodiments and will not be elaborated herein.
[0137] Embodiment Five:
[0138] In the embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, it implements the steps in the data sharing method embodiment in the above cloud environment, such as, Figure 1 the steps S101 to S105 shown. Alternatively, when the computer program is executed by a processor, it implements the functions of each unit in the above device embodiments, such as Figure 3 the functions of the shown unit.
[0139] In the embodiment of the present invention, the data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which it belongs in the complete ternary tree and the data access structure, obtains the file ciphertext and the keyword index, and uploads the file ciphertext and the keyword index to the computing power server. The data receiver generates a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed. When the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver meets the data access structure, the computing power server sends the file storage address matching the retrieval token to the data receiver. The edge computing node partially decrypts the file ciphertext sent by the data receiver and obtained from the file storage address according to the attribute private key of the data receiver, and sends the partially decrypted semi-decrypted ciphertext to the data receiver. The data receiver restores the shared file according to the semi-decrypted ciphertext, thereby realizing fine-grained control of ciphertext retrieval permissions, improving the security of data transmission, storage and calculation in the data sharing process in the cloud environment, and reducing the risk of privacy information leakage caused by illegal access.
[0140] The computer-readable storage medium in the embodiment of the present invention may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EEPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiment of the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device.
[0141] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that the scope of disclosure involved in the above embodiments is not limited to the technical solutions formed by the specific combination of the above technical features, but also should cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. Any modification, equivalent replacement, and improvement made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
[0142] Moreover, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the foregoing discussion, these should not be construed as limitations on the scope of the invention. Certain features that are described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, the various features that are described in the context of a single embodiment can also be implemented separately or in any suitable sub-combination in multiple embodiments.
Claims
1. A data sharing method in a cloud environment, characterized in that, The method includes the following steps: The data owner encrypts the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which the data owner belongs in a pre-constructed complete ternary tree and the data access structure, obtains the file ciphertext and the keyword index, and uploads the file ciphertext and the keyword index to the computing power server; The data receiver generates a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed; When the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver satisfies the data access structure, the computing power server sends the file storage address matching the retrieval token to the data receiver; The edge computing node partially decrypts the file ciphertext sent by the data receiver and obtained from the file storage address according to the attribute private key of the data receiver, and sends the partially decrypted semi-ciphertext to the data receiver; The data receiver restores the shared file according to the semi-ciphertext; 2. The method according to claim 1, characterized in that, Before the step that the data receiver generates a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed, the method further includes: According to the secret value stored in the leaf node to which the data receiver belongs in the complete ternary tree and the attribute set of the data receiver, the attribute institution generates an attribute private key for the data receiver by using the Pedersen secret sharing protocol.
3. The method according to claim 1, characterized in that The step that the computing power server sends the file storage address matching the retrieval token to the data receiver includes: The computing power server retrieves the keyword index matching the retrieval token according to the data access structure, and sends the file storage address corresponding to the retrieved keyword index to the data receiver.
4. The method according to claim 2, wherein The method further includes: When the valid user set is updated, the attribute institution sends a ciphertext update identifier to the edge computing node, where the valid user set is the smallest node set determined by level traversing the complete ternary tree and covering all non-revoked users in the complete ternary tree; The edge computing node updates some ciphertext components in the file ciphertext and the keyword index corresponding to the node to be updated by using a preset data update strategy, and sends the updated file ciphertext and keyword index to the computing power server.
5. A data sharing device in a cloud environment, characterized in that, The device includes: A file encryption unit, configured to enable the data owner to encrypt the shared file and the keyword set of the shared file respectively according to the secret value stored in the leaf node to which the data owner belongs in a pre-constructed complete ternary tree and the data access structure, obtain the file ciphertext and the keyword index, and upload the file ciphertext and the keyword index to the computing power server; A token generation unit, configured to enable the data receiver to generate a retrieval token and a retrieval transaction according to its own attribute private key and the keyword set to be accessed; An address sending unit, configured to enable the computing power server to send the file storage address matching the retrieval token to the data receiver when the blockchain verifies that the retrieval transaction is valid and the attribute set of the data receiver satisfies the data access structure; A partial decryption unit, configured to enable an edge computing node to perform partial decryption on a file ciphertext obtained from the file storage address and sent by the data receiver according to the attribute private key of the data receiver, and send the semi-decrypted ciphertext after partial decryption to the data receiver; A file recovery unit, configured to enable the data receiver to recover the shared file according to the semi-decrypted ciphertext; 6. The device according to claim 5, characterized in that The apparatus further includes: An attribute private key generation unit, configured to generate an attribute private key for the data receiver by an attribute authority using the Pedersen secret sharing protocol according to the secret value stored in the leaf node to which the data receiver belongs in the complete ternary tree and the attribute set of the data receiver; 7. The device according to claim 5, characterized in that, The address sending unit includes: An address matching unit, configured to enable the computing power server to retrieve a keyword index matching the retrieval token according to the data access structure, and send the file storage address corresponding to the retrieved keyword index to the data receiver; 8. The device according to claim 6, characterized in that The apparatus further includes: An update identifier sending unit, configured to enable the attribute authority to send a ciphertext update identifier to the edge computing node when the valid user set is updated, where the valid user set is the smallest node set determined by level traversing the complete ternary tree and covering all non-revoked users in the complete ternary tree; A ciphertext component update unit, configured to enable the edge computing node to update partial ciphertext components in the file ciphertext and keyword index corresponding to the node to be updated by using a preset data update strategy, and send the updated file ciphertext and keyword index to the computing power server; 9. A computing device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented; 10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 4 are implemented.