Multistage security access control method based on inverse matrix and asymmetric encryption

Through inverse matrix and asymmetric encryption technology, multi-level secure access control in the cloud computing environment is realized, solving the problems of high computing complexity and insufficient dynamic management in the existing technology, improving the reliability and security of data transmission, and adapting to complex attacks and permission changes.

CN120358044APending Publication Date: 2025-07-22NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510346917.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the cloud computing environment, the multi-level secure access control method has high computing complexity and insufficient dynamic management capabilities, which is difficult to meet the needs of data integrity and confidentiality, and cannot effectively deal with complex attacks and dynamic changes in permissions.

Method used

Inverse matrix and asymmetric encryption technology are adopted, through security level division and key allocation, combined with inverse matrix calculation and elliptic curve encryption algorithm, multi-level secure access control is realized, ensuring strict hierarchy and dynamic adjustment of data, and meeting the "prohibited write-up" and "prohibited read-up" characteristics of Biba model.

Benefits of technology

It reduces the complexity of computing and management, improves the reliability and security of data transmission, can dynamically respond to node changes, ensures data integrity and confidentiality, and enhances defense capabilities against malicious attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358044A_ABST
    Figure CN120358044A_ABST
Patent Text Reader

Abstract

The invention discloses a multilevel security access control method based on an inverse matrix and asymmetric encryption. The multilevel security access control method is used for improving data access control efficiency and security in a cloud environment. According to the method, by combining the characteristics of'forbidding down-reading 'and'forbidding up-writing' in a Biba model and based on a hierarchical key distribution mechanism, access authority control of multiple levels of users to data is realized through inverse matrix calculation and an asymmetric encryption technology. A data owner allocates read-write keys according to security levels, and key management is optimized through dynamic adjustment of an inverse matrix, so that the integrity and confidentiality of data circulation among different security levels are ensured. According to the method, the access control strategy is optimized, the elliptic curve encryption algorithm is introduced, the key derivation process is simplified through the public matrix, the dynamic and efficient requirements are met at the same time, the calculation complexity and the storage overhead are reduced, and the defense capacity for hostile attacks (such as collusion attacks) is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data security in the cloud computing environment, and particularly relates to a multi-level security access control method based on inverse matrix and asymmetric encryption. Background Art

[0002] With the rapid development of cloud computing technology, the storage, calculation and transmission of data have become more efficient and convenient. More and more enterprises and individuals choose to store data in cloud servers. This method not only reduces the data storage cost, but also improves the convenience of data sharing and management. However, since the services in the cloud environment are generally considered to be semi-trusted, the data is at risk of being leaked, tampered with or even destroyed.

[0003] In traditional security research, the confidentiality of data is mainly concerned. However, with the rapid development of applications such as e-commerce and the Internet of Things, the issues of data integrity and security have also attracted increasing attention. Especially in fields such as government and healthcare, the integrity of data is crucial for the continuity and accuracy of business. If the data is maliciously tampered with, serious consequences may occur. In a multi-user sharing environment, the access rights of different users are different. How to protect data security through a hierarchical security mechanism has become an important issue.

[0004] To solve this problem, researchers at home and abroad have proposed a variety of improvement methods. For example, Akl and Taylor proposed a hierarchical key assignment scheme (HKAS), which realizes the permission division of users at different security levels by assigning private keys and encryption keys to each security level; Hassen et al. improved the HKAS scheme by introducing a linear hierarchical structure key management, which improved the flexibility of member change; Tang et al. designed a security policy based on vector encryption, which can resist collusion attacks, but its computational overhead is relatively large. On the other hand, as a typical multi-level security model, the Biba model protects data integrity by restricting the direction of information flow. "Prohibiting reading down" and "prohibiting writing up" are the two core features of this model. However, when implementing the Biba model with traditional methods, problems such as high computational complexity and insufficient dynamic management ability are often faced.

[0005] Therefore, in recent years, researchers have introduced asymmetric encryption technology into multi-level security access control. For example, the key assignment scheme based on the elliptic curve encryption algorithm has significant advantages in terms of security and computational efficiency, but the storage overhead and dynamic adjustment ability still need to be further optimized. Using the situation awareness mechanism and context awareness technology to achieve network security monitoring is also an important research direction, but the complexity of these methods limits their application in large-scale cloud computing environments.

[0006] In summary, how to design an efficient, reliable and dynamically adjustable multi-level security access control method that can not only meet the integrity and confidentiality requirements of data, but also cope with complex attacks and dynamic changes in permissions has become an important research topic. By combining inverse matrix operations and asymmetric encryption technologies, the present invention proposes an improved multi-level security access control method that can reduce the computational overhead while improving the security and dynamic adaptability of the system. Summary of the Invention

[0007] To solve the technical problems mentioned in the above background art, the present invention proposes a multi-level security access control method based on inverse matrix and asymmetric encryption.

[0008] To achieve the above technical objectives, the technical solution of the present invention is as follows:

[0009] A multi-level security access control method based on inverse matrix and asymmetric encryption, comprising the following steps:

[0010] (1) According to the multi-level security requirements of the data in the system, through a security level division mechanism, users and data are assigned to different security level sets, and corresponding keys are assigned to each security level. Public information is generated by using inverse matrix calculations to provide support for multi-level security access control.

[0011] (2) The protocol divides the system into several security levels, establishes a public matrix, and realizes key derivation between different security levels. High-security level users can derive the write keys of low-security levels, while low-security level users cannot reverse-derive the keys of high-security levels, ensuring strict classification of data access permissions.

[0012] (3) When a node uploads data, first encrypt the data with a key, and then slice the data. The sliced data is distributed to the next-hop node set according to the security status and transmission requirements of the node. Even if some data slices are lost, the security and integrity of the overall data can be guaranteed.

[0013] Further, in step (1), the key distribution method for multi-level security access control is as follows:

[0014] (101) Through a security level division mechanism, users and data in the system are assigned to different security level sets S = {S1, S2,..., S n} where each level is disjoint;

[0015] (102) Randomly generate a private key d i for each security level S i , and calculate the corresponding public key Q i = d i P, where P is an elliptic curve E p(a, b) base point;

[0016] (103) Map the public key Q i to an integer k i uniquely through the Cantor pairing function e(Q i , and verify its uniqueness and invertibility;

[0017] (104) Construct matrix B, with each row corresponding to a security level, check if B is full rank, if not, regenerate the private vectors M i and F i until the requirements are met;

[0018] (105) Calculate the public matrix A = B -1 K, where K is a matrix generated according to the security level relationship, complete the initial key distribution, and publish the relevant public information.

[0019] Further, in step (2), the multi-level key derivation method is as follows:

[0020] (201) If there is a security level relationship S j ≤ S i , the high security level node S i can derive the write key Q j of the low security level node S j based on the public matrix A and private information, and the derivation formula is as follows:

[0021]

[0022] (202) The low security level node cannot reverse-derive the write key Q i of the high security level node through public information, satisfying the "no write up" feature of the Biba model;

[0023] (203) Based on the elliptic curve discrete logarithm problem (ECDLP), the high security level node cannot obtain the read key d j of the low security level node, satisfying the "no read down" feature of the Biba model;

[0024] (204) According to the key derivation result, dynamically adjust the access control policy to ensure the integrity and legality of data access permissions within the system.

[0025] Further, in step (3), the data encryption and transmission method is as follows:

[0026] (301) When a new security level S x is added, generate the corresponding private key d x , public key Q x and private vector M x, recalculate matrix A and update the relevant key distribution;

[0027] (302) Delete security level S x When doing so, regenerate the key related to this security level, update matrix A, and re-encrypt the affected data to ensure forward security;

[0028] (303) When a new addition or deletion occurs in the security level relationship, adjust the partial order relationship, and recalculate matrix A and the relevant key distribution scheme.

[0029] Beneficial effects brought by adopting the above technical solutions:

[0030] (1) The present invention proposes to encrypt and slice the data in multi-level security access control. When encountering attacks from malicious nodes, the unsliced data may be completely intercepted or discarded by malicious nodes, resulting in serious information loss. Through the data slicing technology of the present invention, the data is divided into multiple parts. Even if a certain node discards some sliced content, the other slices can still ensure the integrity of the data, thus significantly improving the transmission reliability and system security.

[0031] (2) The present invention realizes dynamic key distribution and security level management through inverse matrix and asymmetric encryption technologies. The system dynamically adjusts the key according to the security status and permissions of the nodes, ensuring that nodes with low security levels cannot access data with high security levels, and efficiently coping with the dynamic changes of the nodes. This mechanism improves data confidentiality while reducing the complexity of calculation and management, providing effective support for multi-level security in the cloud environment. Description of the Drawings

[0032] Figure 1 is the multi-level security access control system for encrypted data in the cloud environment of the present invention; Detailed Embodiments

[0033] The technical solutions of the present invention will be described in detail below with reference to the drawings.

[0034] A multi-level security access control method based on inverse matrix and asymmetric encryption includes the following steps:

[0035] (1) According to the multi-level security requirements of the data in the system, through the security level division mechanism, allocate users and data to different security level sets, and allocate corresponding keys to each security level. Use inverse matrix calculation to generate public information to provide support for multi-level security access control.

[0036] (2) The protocol divides the system into several security levels, establishes a public matrix, and realizes key derivation between different security levels. Users with a high security level can derive the write key of a low security level, while users with a low security level cannot derive the key of a high security level in reverse, ensuring strict classification of data access permissions.

[0037] (3) When a node uploads data, it first encrypts the data with a key and then slices the data. The sliced data is distributed to the next-hop node set according to the security status and transmission requirements of the node. Even if some data slices are lost, the security and integrity of the overall data can be guaranteed.

[0038] Furthermore, in step (1), the key distribution method for multi-level security access control is as follows:

[0039] (101) Through the security level division mechanism, users and data in the system are assigned to different security level sets S = {S1, S2,..., S n}, and each level is disjoint;

[0040] (102) Randomly generate a private key d i for each security level S i , and calculate the corresponding public key Q i = d i P, where P is the base point of the elliptic curve E p (a, b);

[0041] (103) Uniquely map the public key Q i to an integer k i through the Cantor pairing function e(Q i ), and verify its uniqueness and invertibility;

[0042] (104) Construct a matrix B, with each row corresponding to a security level, check if B is full rank. If not, regenerate the private vectors M i and F i until the requirements are met;

[0043] (105) Calculate the public matrix A = B -1 K, where K is a matrix generated according to the security level relationship, complete the initial key distribution, and publish the relevant public information.

[0044] Furthermore, in step (2), the multi-level key derivation method is as follows:

[0045] (201) If there is a security level relationship S j ≤ S i , a high security level node S i can derive the low security level node S j based on the public matrix A and private information.The write key Q j , and the derivation formula is as follows:

[0046]

[0047] (202) Low-security nodes cannot reverse-derive the write key Q of high-security nodes through public information i , which satisfies the "no write up" feature of the Biba model;

[0048] (203) Based on the elliptic curve discrete logarithm problem (ECDLP), high-security nodes cannot obtain the read key d of low-security nodes j , which satisfies the "no read down" feature of the Biba model;

[0049] (204) According to the key derivation result, dynamically adjust the access control policy to ensure the integrity and legality of data access rights within the system.

[0050] Furthermore, in step (3), the method for data encryption and transmission is as follows:

[0051] (301) When a new security level S x is added, generate the corresponding private key d x , public key Q x and private vector M x , recalculate matrix A, and update the relevant key distribution;

[0052] (302) When a security level S x is deleted, regenerate the keys related to this security level, update matrix A, and re-encrypt the affected data to ensure forward security;

[0053] (303) When new security level relationships are added or deleted, adjust the partial order relationship, recalculate matrix A and the relevant key distribution scheme.

Claims

1. A multi-level security access control method based on inverse matrix and asymmetric encryption, characterized in that It includes the following steps: (1) The protocol adopts the inverse matrix and elliptic curve asymmetric encryption technology to achieve multi-level security access control according to the multi-level security requirements of the data in the system. The specific steps are as follows: (101) Through the security level division mechanism, users and data in the system are assigned to different security level sets S = {S1, S2,..., S n}, and each level is disjoint; (102) For each security level S i Randomly generate a private key d i , and calculate the corresponding public key Q i = d i P, where P is the base point of the elliptic curve E p (a, b); (103) Map the public key Q i to the integer k i uniquely through the Cantor pairing function e(Q i ), and verify its uniqueness and invertibility; (104) Construct matrix B, with each row corresponding to a security level, check if B is full rank. If it is not full rank, then regenerate the private vector M i and F i until the requirements are met; (105) Calculate the public matrix A = B -1 K, where K is a matrix generated according to the security level relationship, complete the initial key distribution, and publish relevant public information. (2) The protocol uses the inverse matrix to achieve multi-level key derivation to ensure that the multi-level security access control meets the requirements of the Biba model. The specific steps are as follows: (201) If there is a security level relation S j ≤S i , high security level node S i The low security level node S can be derived based on the public matrix A and private information j Write key Q j , the derivation formula is as follows: (202) Low-security-level nodes cannot reverse-derive the write key Q of high-security-level nodes through public information i , satisfying the "no write up" property of the Biba model; (203) Based on the Elliptic Curve Discrete Logarithm Problem (ECDLP), high-security-level nodes cannot obtain the read key d of low-security-level nodes j , satisfying the "no read down" property of the Biba model; (204) According to the key derivation result, dynamically adjust the access control policy to ensure the integrity and legality of the data access permissions within the system. (3) The protocol supports dynamic security level management. When the security level changes, it can quickly adjust the relevant keys and access control policies. The specific steps are as follows: (301) New security level S x When it is generated, the corresponding private key d is generated x , public key Q x and private vector M x , recalculate matrix A, and update the relevant key distribution; (302) Delete security level S x When doing so, regenerate the key related to this security level, update matrix A, and re-encrypt the affected data to ensure forward security; (303) When a new addition or deletion occurs in the security level relationship, adjust the partial order relationship and recalculate matrix A and the relevant key distribution scheme.