Method, apparatus, non-transitory computer-readable storage device and system for data usage control using attribute-based encryption
Through the Attribute-Based Encryption (ABE) method, user agent keys are generated and data usage strategies are obfuscated, which solves the flexibility and privacy issues of data access control in the prior art, and realizes flexible data usage control and privacy protection.
Patent Information
- Application Number
- CN202280102546.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-24
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, data access control only provides binary yes/veto decisions, cannot express complex access and usage policies, and the privacy of data usage policies is difficult to guarantee.
The attribute-based encryption (ABE) method is used to generate a confusion between user agent key and data usage policy, and data access is only allowed when the attributes of the data user meet the policy. The ciphertext policy attribute-based encryption (CP-ABE) method is used to protect the privacy of the data usage policy.
It realizes flexible data usage control, protects the privacy of data usage policies, provides policy hiding, usage tracking and user revocation functions, ensuring the security and flexibility of data access.
Smart Images

Figure CN120359722A_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to methods, apparatuses, non-transitory computer-readable storage devices, and systems for data usage control, and more particularly to methods, apparatuses, non-transitory computer-readable storage devices, and systems for data usage control using attribute-based encryption. Background Art
[0002] Data sovereignty is crucial for data-driven businesses, and its goal is to support data owners in sharing their data while retaining control and confidentiality over such data. Typically, data is protected only by access control mechanisms, which provide only binary yes / no decisions, i.e., granting or not granting access rights. Summary of the Invention
[0003] According to one aspect of the present invention, there is provided a method, the method comprising: receiving a first ciphertext and a wrapped master secret key (MSK) from a data owner (DO), the first ciphertext including encrypted data and an encrypted and obfuscated data usage policy embedded in the encrypted data, the encrypted and obfuscated data usage policy being conditional on one or more attributes of the encrypted and obfuscated data usage policy; receiving a request from a data user (DU) to use the data; obtaining a user agent key, the user agent key being generated based on the wrapped MSK, a first public key, the public key of the DU, and the one or more attributes associated with the DU, the wrapped MSK being an encapsulated version of a first MSK; generating a second ciphertext based on a first private key, the user agent key, the public key of the DO, and the first ciphertext if and only if the one or more attributes associated with the DU satisfy the obfuscated data usage policy; sending the second ciphertext to the DU; the generating the second ciphertext including: checking whether the one or more attributes associated with the DU satisfy the obfuscated data usage policy without converting the obfuscated data usage policy into a plaintext form.
[0004] In some embodiments, the method further comprises: storing the user agent key and an identifier (ID) of the DU in a user agent key list.
[0005] In some embodiments, the method further comprises: removing the user agent key and the ID of the DU from the user agent key list.
[0006] In some embodiments, the wrapped MSK is the first MSK encapsulated by a wrapping key (e.g., a hardware-protected wrapping key).
[0007] In some embodiments, receiving the first ciphertext and the wrapped MSK includes: receiving a packet, the packet including: a manifest; the wrapped MSK; an encrypted dynamic state for tracking the use of the data; at least one entry of the first ciphertext.
[0008] In some embodiments, the manifest includes one or more of the following: a version number, a unique packet ID, the obfuscated data usage policy, and a plurality of public parameters generated in association with the first MSK.
[0009] In some embodiments, each entry of the at least one entry of the first ciphertext includes: at least one header entry, at least one ciphertext entry, at least one tag entry.
[0010] In some embodiments, the first ciphertext is obtained based on the data, the data usage policy, the private key of the DO, and the plurality of public parameters.
[0011] In some embodiments, the first ciphertext is obtained based on the data, a tree of the data usage policy, the private key of the DO, and the plurality of public parameters.
[0012] In some embodiments, the first MSK is obtained by: selecting a bilinear map e: G1×G2→G T , where G1, G2, and G T are cyclic groups of prime order p of k bits, and e: G1×G2→G T represents the bilinear map or pairing e, which takes an element from G1, takes another element from G2, and maps the two elements to an element in G T ; selecting g1 and g2, which are generators of G1 and G2 respectively; selecting two cryptographic hash functions H1: {0,1}*→G1 and , where {0,1}* represents a binary string of arbitrary length, represents a binary string whose length of the smallest integer is greater than or equal to log2p; randomly selecting α, β, γ from the set Z p * , where Z p * is a cyclic group of integers modulo prime p, and the integers do not include zero; obtaining and the first MSK msk = (α, β, γ).
[0013] In some embodiments, the first ciphertext is obtained by: starting from the root node of the data usage policy tree T, in a top-down manner, selecting a polynomial q for each node i in T including leaf nodesi ; Set the degree d i of each polynomial q i to t i– 1, where t i is the threshold for each node i; Randomly select s from the set Z p * and set q r (0) = s, where q r is the polynomial of the root node, and select d r other random points to fully define q r ; For any other node j, q j (0) = q parent(j) (index(j)), where parent(j) represents the parent node of node j in the data usage policy tree T, index(j) is the unique number associated with node j, and select d j other random points to fully define q j ; For each leaf node, calculate where prv s is the private key of the DO; Then, obfuscate one or more attributes att(l) of the data usage policy tree T by replacing the att(l) assigned to each leaf node with H2(s l ) to generate the obfuscated data usage policy (in these embodiments, it is a tree structure); Obtain an authenticated encryption with additional data (AEAD) key key AEAD ; Use the AEAD key key AEAD to encrypt the plaintext data data p by the AEAD method to obtain the encrypted data data e and the tag tag v ; Obtain the first ciphertext c, the first ciphertext c is at least a combination of the obfuscated data usage policy C' = h s , {C l1 ,C l2}, the encrypted data data e and the tag tag v , where L is the set of leaf nodes in T.
[0014] In some embodiments, the obtaining the AEAD key key AEAD includes: Taking Feed it into a hash - based key derivation function (HKDF) to generate the AEAD key key AEAD .
[0015] In some embodiments, obtaining the AEAD key key AEAD includes: randomly selecting an element m from G T ; and feeding m into a hash - based key derivation function (HKDF) to generate the AEAD key key AEAD .
[0016] In some embodiments, obtaining the first ciphertext c includes: obtaining the first ciphertext c, where the first ciphertext c is at least a combination of the obfuscated data usage policy C' = h s , {C l1 , C l2}, the encrypted data data e and the tag tag v , where L is the set of leaf nodes in T
[0017] In some embodiments, the user - agent key PrxK u is generated by: for any j in A u , randomly selecting r1, r2, r p * from the set Z j , where A u represents the one or more attributes related to the DU; obtaining the user - agent key where pub csp and pub u represent the first public key and the public key of the DU, respectively
[0018] In some embodiments, generating the second ciphertext includes: for each attribute in A u , calculating the attribute index I j = H2(s j ) set where s j = e(k j3 , pub s ) = e(H1(j) γ , pub s); Check the set of property indices u associated with the user agent key PrxK to see if it satisfies the obfuscated data usage policy embedded in the first ciphertext c without converting the obfuscated data usage policy to the plaintext form; if the set of property indices does not satisfy the obfuscated data usage policy embedded in the ciphertext c, return invalid ⊥; if the set of property indices satisfies the obfuscated data usage policy embedded in the ciphertext c, recursively calculate G T or a group element of ⊥ Calculate Output the second ciphertext v, where the second ciphertext v is at least a combination of e(g1, pub u ) αs , the encrypted data data e and the verification / authentication data tag v .
[0019] In some embodiments, the recursively calculating the group element includes: at each node x of , step A: If x is a leaf node, its attribute value z is obfuscated as H2(s x ), and if then return ⊥, otherwise return When x is a non-leaf node, use step A for each child node y of x and store the output F y , if there does not exist a set S x , where S x is a set of child nodes y of any t x size, and t x is the threshold of node x such that F y ≠ ⊥, then return ⊥, otherwise return
[0020] In some embodiments, the method further includes: using a user key generation function with a public / private key pair output pub o and prv o to generate the first public key and the first private key; the user key generation function includes the following steps: select x p ∈ R Z p * , obtain prv o = x p and The generating the first public key and the first private key using the user key generation function includes: using the user key generation function, setting pubo and prv o are respectively used as the first public key and the first private key.
[0021] In some embodiments, the public key and the private key of the DO are generated by the user key generation function.
[0022] In some embodiments, the public key and the private key of the DU are generated by the user key generation function.
[0023] In some embodiments, sending the second ciphertext to the DU is for the DU to use the private key prv of the DU u to perform a user decryption function on the second ciphertext v to obtain the AEAD key key using the information of the second ciphertext AEAD and use the tag v to verify and decrypt the encrypted data data e to obtain the data in plaintext form.
[0024] According to one aspect of the present invention, one or more processors are provided for executing instructions to perform the above method.
[0025] According to one aspect of the present invention, one or more non-transitory computer-readable storage media are provided, including computer-executable instructions for modifying a signal, wherein the instructions, when executed, cause a processing structure to perform the above method.
[0026] The above method, one or more processors, and one or more non-transitory computer-readable storage devices can solve at least one of the following technical problems:
[0027] 1. The data usage policy of the data owner is bound to its content or data and is executed cryptographically using the ciphertext policy attribute-based encryption (CP-ABE) method. Therefore, unless the attributes of the data satisfy the data usage policy of the data owner, the data user may not be able to access the data.
[0028] 2. Protect the privacy of the data owner's data usage policy by encrypting and obfuscating the attributes of the data, so that the data usage policy attributes are not shared in plaintext.
[0029] More specifically, the above method, apparatus, and one or more non-transitory computer-readable storage devices can provide a solution to protect data and execute a usage policy with policy hiding, usage tracking, user revocation, and decryption offloading.
[0030] The details and other benefits thereof will be described below with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 FIG. 1 is a schematic diagram of a computer network system for data sharing in connection with data usage control provided by some embodiments of the present invention;
[0032] Figure 2 FIG. 2 shows Figure 1 a schematic diagram of a simplified hardware structure of a computing device of the computer network system shown;
[0033] Figure 3 FIG. 3 shows Figure 1 a schematic diagram of a simplified software architecture of a computing device of the computer network system shown;
[0034] FIG. 4 is a schematic diagram showing a simplified process of data access control;
[0035] FIG. 5 is a schematic diagram showing a simplified process of attribute-based access control;
[0036] Figure 6 FIG. 6 is a schematic diagram showing a simplified process of attribute-based usage control;
[0037] Figure 7 FIG. 7 is a schematic diagram showing the relationship among data access control, data processing control, and data usage control;
[0038] Figure 8 FIG. 8 is a schematic diagram showing an example of a data usage policy tree having three (3) attributes as leaf nodes and two (2) threshold gates as non-leaf nodes;
[0039] Figure 9 FIG. 9 is a schematic diagram provided by some embodiments of the present invention showing a data sharing process Figure 1 performed by the computer network system shown for creating, sharing, and using protected data with data usage control based on attribute-based encryption (ABE);
[0040] Figure 10 FIG. 10 is a schematic diagram provided by some embodiments of the present invention showing Figure 9 an example of the data sharing process shown, in which functions or methods that each entity can perform for creating, sharing, and using protected data with ABE-based data usage control are shown;
[0041] Figure 11 and Figure 12 FIG. 11 and Figure 10 FIG. 12 are sequence diagrams showing an exemplary data sharing process shown, in which
[0042] Figure 11 is a sequence diagram showing the creation of shared data,
[0043] Figure 12 is a sequence diagram showing the use of shared data;
[0044] Figure 13 Some embodiments of the present invention provide a schematic diagram of an exemplary structure of a packet generated and used during the data sharing process shown in Figure 10 the data sharing process shown. Detailed Description of the Invention
[0045] Embodiments disclosed herein relate to methods, apparatuses, non-transitory computer-readable storage devices, and systems for controlling data usage using attribute-based encryption (ABE).
[0046] As will be described in more detail below, one or more modules or circuits may be used to perform the data usage control methods and processes described in the present invention.
[0047] Here, a "module" is an explanatory term that refers to a hardware structure implemented using technologies such as electrical technology and / or optical technology (and more specific examples of semiconductors) for performing defined operations or processes, such as a circuit. A "module" may alternatively refer to a combination of a hardware structure and a software structure, where the hardware structure may be implemented in a general manner using technologies such as electrical technology and / or optical technology (and more specific examples of semiconductors) to perform defined operations or processes according to the software structure stored in one or more non-transitory computer-readable storage devices or media in the form of an instruction set.
[0048] As those skilled in the art will understand, a module may be a part of a device, apparatus, system, etc., where the module may be coupled to or integrated with other parts of the device, apparatus, or system such that their combination forms the device, apparatus, or system. Alternatively, a module may be implemented as an independent device or apparatus.
[0049] The module can execute one or more processes for performing the methods described in the present invention. Here, a process has a general meaning equivalent to a method and does not necessarily correspond to the concept of a computer process (which is an instance of a computer program being executed). More specifically, a process here is a defined method implemented using hardware components for processing data. A process can include or use one or more functions and is implemented as one or more computer processes for processing data as designed. Here, a function is a defined sub - process or sub - method for computing (computing / calculating) or otherwise processing input data in a defined manner and generating or otherwise producing output data.
[0050] As will be understood by those skilled in the art, a process can be implemented as one or more software and / or firmware programs having the necessary computer - executable code or instructions and stored in one or more non - transitory computer - readable storage devices or media, which can be any volatile and / or non - volatile, non - removable or removable storage device, such as RAM, ROM, EEPROM, solid - state memory devices, hard disks, CDs, DVDs, flash memory devices, etc. The module can read the computer - executable code from the storage device and execute the computer - executable code to perform the process.
[0051] Alternatively, a process can be implemented as one or more hardware structures having the necessary electrical and / or optical components, circuits, logic gates, integrated circuit (IC) chips, etc.
[0052] A. System Structure
[0053] Now turning to Figure 1 , a computer network system is shown and is generally identified by the reference numeral 100. In these embodiments, the computer network system 100 is configured to share data with multiple users through data usage control.
[0054] As Figure 1 shown, the computer network system 100 includes one or more server computers 102, multiple client computing devices 104, and one or more client computer systems 106, which are functionally interconnected through a network 108 by suitable wired and wireless connections, such as the Internet, local area network (LAN), wide area network (WAN), metropolitan area network (MAN), etc.
[0055] The server computer 102 can be a computing device specifically designed to serve as a server, and / or a general-purpose computing device that acts as a server computer and can also be used by various users. Each server computer 102 can execute one or more server programs.
[0056] The client computing device 104 can be a portable and / or non-portable computing device, such as a laptop computer, a tablet computer, a smart phone, a personal digital assistant (PDA), a desktop computer, etc. Each client computing device 104 can execute one or more client applications, and the one or more client applications are sometimes referred to as "applications".
[0057] Generally, the computing devices 102 and 104 include similar hardware structures, such as Figure 2 the hardware structure 120 shown. As shown in the figure, the hardware structure 120 includes a processing structure 122, a control structure 124, one or more non-transitory computer-readable memories or storage devices 126, a network interface 128, an input interface 130, and an output interface 132, which are functionally interconnected by a system bus 138. The hardware structure 120 may also include other components 134 coupled to the system bus 138.
[0058] The processing structure 122 can be one or more single-core or multi-core computing processors, generally referred to as a central processing unit (CPU), such as a microprocessor (INTEL is a registered trademark of Intel Corp. in Santa Clara, California, USA), a microprocessor (AMD is a registered trademark of Advanced Micro Devices Inc. in Sunnyvale, California, USA), a microprocessor manufactured by various manufacturers such as Qualcomm in the architecture of the microprocessor (ARM is a registered trademark of Arm Ltd. in Cambridge, UK), etc. When the processing structure 122 includes multiple processors, the processors can cooperate through dedicated circuits such as a dedicated bus or through the system bus 138.
[0059] The processing structure 122 may also include one or more real-time processors, programmable logic controllers (PLCs), microcontroller units (MCUs), μ-controllers (UCs), dedicated / custom processors, hardware accelerators, and / or control circuits (also referred to as “controllers”), e.g., using field-programmable gate array (FPGA) or application-specific integrated circuit (ASIC) technology, etc. In some embodiments, the processing structure includes a CPU (otherwise referred to as the host processor) and a dedicated hardware accelerator that includes circuitry for performing calculations of neural networks such as tensor multiplication, matrix multiplication, etc. The host processor may transfer some of the calculations to the hardware accelerator to perform the calculation operations of the neural network. Examples of hardware accelerators include graphics processing units (GPUs), neural processing units (NPUs), and tensor processing units (TPUs). In some embodiments, the host processor and the hardware accelerator (e.g., GPU, NPU, and / or TPU) can generally be considered processors.
[0060] Generally, the processing structure 122 includes the necessary circuitry implemented using technologies such as electrical and / or optical hardware components for performing a data sharing process with data usage control.
[0061] For example, the processing structure 122 may include logic gates implemented by semiconductors to perform various computations, calculations, and / or processing. Examples of logic gates include AND gates, OR gates, XOR (exclusive OR) gates, and NOT gates, each of which receives one or more inputs and generates or otherwise produces an output based on the logic implemented therein. For example, a NOT gate receives an input (e.g., a high voltage, a state with current, a state with light emission, etc.), inverts the input (e.g., forms a low voltage, a state without current, a state without light, etc.), and outputs the inverted input as an output.
[0062] Although the inputs and outputs of logic gates are typically physical signals, and their logical or processing is a tangible operation with physical results (e.g., the output of a physical signal), their inputs and outputs are typically described using numbers (e.g., the digits "0" and "1"), and their operations are typically described as "computing" (the naming of "computers" or "computing devices") or "calculation", or more generally as "processing", for generating or producing an output from their inputs.
[0063] Complex combinations of logic gates in the form of logic gate circuits can be formed using multiple AND gates, OR gates, XOR gates, and / or NOT gates, such as processing structure 122. Such combinations of logic gates can be implemented using discrete semiconductors or, more often, implemented as an integrated circuit (IC).
[0064] The circuit of a logic gate can be a "hardwired" circuit that, once designed, can only perform the designed function. In this example, its process and function are "hardcoded" in the circuit.
[0065] With technological advancements, the circuits of logic gates (e.g., processing structure 122) can generally be designed in a general-purpose manner such that they can perform various processes and functions according to a "programming" instruction set that is implemented as firmware and / or software and stored in one or more non-transitory computer-readable storage devices or media. In this example, without meaningful firmware and / or software, circuits of logic gates such as processing structure 122 are generally useless.
[0066] Of course, those skilled in the art will understand that a process or function (and thus processing structure 122) can be implemented using other technologies such as analog technologies.
[0067] Return reference Figure 2 , the control structure 124 includes one or more control circuits, such as a graphics controller, an input / output chipset, etc., for coordinating the operations of various hardware components and modules of the computing device 102 / 104.
[0068] The memory 126 includes one or more storage devices or media accessible by the processing structure 122 and the control structure 124 for reading and / or storing instructions for execution by the processing structure 122, as well as reading and / or storing data, including input data and data generated by the processing structure 122 and the control structure 124. The memory 126 can be volatile and / or non-volatile, non-removable or removable memory, such as RAM, ROM, EEPROM, solid-state memory, hard disk, CD, DVD, flash memory, etc.
[0069] The network interface 128 includes one or more network modules for using Ethernet, (WI-FI is a registered trademark of Wi-Fi Alliance in Austin, Texas, USA), (BLUETOOTH is a registered trademark of Bluetooth Sig Inc. in Kirkland, Washington, USA), Bluetooth low energy (BLE), Z-Wave, Long Range (LoRa), (ZIGBEE is a registered trademark of ZigBee Alliance Corp. in San Ramon, California, USA), etc., suitable wired or wireless communication technologies, as well as wireless broadband communication technologies such as Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA), Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX), CDMA2000, Long Term Evolution (LTE), 3GPP, 5G New Radio (5G NR), and / or other 5G networks to connect to other computing devices or networks through the network 108. In some embodiments, parallel ports, serial ports, USB connections, optical connections, etc. can also be used to connect to other computing devices or networks, but they are generally considered input / output interfaces for connecting input / output devices.
[0070] The input interface 130 includes one or more input modules for one or more users to input data through, for example, a touch-sensitive screen, a touch-sensitive whiteboard, a touchpad, a keyboard, a computer mouse, a trackball, a microphone, a scanner, a camera, etc. The input interface 130 can be a physically integrated part of the computing device 102 / 104 (e.g., the touchpad of a laptop or the touch-sensitive screen of a tablet), or a device that is physically separated from other components of the computing device 102 / 104 (e.g., a computer mouse) but functionally coupled. In some implementations, the input interface 130 can be integrated with the display output to form a touch-sensitive screen or a touch-sensitive whiteboard.
[0071] The output interface 132 includes one or more output modules for outputting data to a user. Examples of output modules include displays (such as monitors, LCD displays, LED displays, projectors, etc.), speakers, printers, virtual reality (VR) headsets, augmented reality (AR) goggles, etc. The output interface 132 can be a physically integrated part of the computing device 102 / 104 (such as the display of a laptop or tablet), or a device that is physically separate but functionally coupled to other components of the computing device 102 / 104 (such as the display of a desktop computer).
[0072] The computing device 102 / 104 may also include other components 134, such as one or more positioning modules, temperature sensors, barometers, inertial measurement units (IMUs), etc.
[0073] The system bus 138 interconnects the various components 122 to 134, enabling them to send and receive data and control signals to and from each other.
[0074] Figure 3 A simplified software architecture 160 of the computing device 102 or 104 is shown. The software architecture 160 includes one or more application programs 164, an operating system 166, a logical input / output (I / O) interface 168, and a logical memory 172. The one or more application programs 164, the operating system 166, and the logical I / O interface 168 are typically implemented as computer-executable instructions or code stored in the logical memory 172 in the form of software programs or firmware programs, which can be executed by the processing structure 122.
[0075] The one or more application programs 164 are executed or run by the processing structure 122 to perform various tasks.
[0076] The operating system 166 manages the various hardware components of the computing device 102 or 104 through the logical I / O interface 168, manages the logical memory 172, and manages and supports the application programs 164. The operating system 166 also communicates with other computing devices (not shown) via the network 108 to support communication between the application programs 164 and application programs running on other computing devices. As will be understood by those skilled in the art, the operating system 166 can be any suitable operating system, such as, (MICROSOFT and WINDOWS are registered trademarks of Microsoft Corp. in Redmond, Washington, USA) OS X, iOS (APPLE is a registered trademark of Apple Inc. in Cupertino, California, USA), Linux, (ANDROID is a registered trademark of Google LLC in Mountain View, California, USA), etc. The computing devices 102 and 104 of the computer network system 100 may have the same operating system or different operating systems.
[0077] The logical I / O interface 168 includes one or more device drivers 170 for communicating with the corresponding input interface 130 and output interface 132 to transfer data with the corresponding input interface 130 and output interface 132. The received data can be sent to one or more applications 164 for processing by the one or more applications 164. The data generated by the application 164 can be sent to the logical I / O interface 168 for output (through the output interface 132) to various output devices.
[0078] The logical memory 172 is a logical mapping of the physical memory 126 to facilitate access by the application 164. In this embodiment, the logical memory 172 includes a storage memory area that can be mapped to non-volatile physical memories typically used for long-term data storage therein, such as hard disks, solid-state drives, flash drives, etc. The logical memory 172 also includes a working memory area that is typically mapped to high-speed memory (in some implementations, mapped to volatile physical memory, such as RAM), which is typically used for the application 164 to temporarily store data during program execution. For example, the application 164 can load data from the storage memory area into the working memory area and can store the data generated during its execution into the working memory area. The application 164 can also store some data into the storage memory area as needed or in response to a user's command.
[0079] In the server computer 102, one or more applications 164 typically provide server functions for managing network communication with the client computing device 104 and facilitating cooperation between the server computer 102 and the client computing device 104. Here, the term "server" can refer to the server computer 102 from a hardware perspective or to a logical server from a software perspective, depending on the context.
[0080] As described above, without meaningful firmware and / or software, the processing structure 122 is generally useless. Similarly, although a computer system such as the computer network system 100 may have the potential to perform various tasks, without meaningful firmware and / or software, it cannot perform any tasks and is of no use. As will be described in more detail later, the computer network system 100 and its modules, circuits, and components described herein, as a combination of hardware and software, generally produce tangible results associated with the physical world, where, for example, the tangible results described herein can facilitate improvements to the computer devices and systems themselves, modules, circuits, components, etc.
[0081] B. Data Usage Control Using Attribute - Based Encryption
[0082] The computer network system 100 generally requires proper management of data access and data usage / processing. As shown in FIG. 4 (see reference [2]) and as described above, data access control only provides a binary yes / no decision, i.e., granting or not granting access rights. In the prior art, classical security controls are already very well - developed. However, such classical security controls may not be flexible enough and may not be able to express complex situations.
[0083] Access control and data usage control can be based on one or more attributes. Here, an attribute is a characteristic or feature of an object that can be used to construct access or data usage control conditions. The object can be any object related to access or data usage control conditions, such as a user, a data segment, a system, a device, etc. Attributes can be, for example, the name of a user, the login name of a user, the location of a user, the specific time interval of a data segment (e.g., the start date and end date of using the data segment), the number of times a data segment is used, etc. For ease of description, the terms "data" and "content" can be used interchangeably.
[0084] As shown in FIG. 5 (see reference [2]), attribute - based access control can provide more expressive security control. However, attribute - based access control may still only support binary decisions.
[0085] Attribute - based usage control can provide sufficient flexibility in terms of decision - making and execution. For example, as Figure 6 shown (see reference [2]), attribute - based usage control methods can provide more specific execution decisions rather than binary decisions.
[0086] Therefore, as Figure 7 shown, data usage control 186 is a combination of data access control 182 (i.e., regulations) and data processing control 184 (i.e., obligations). In other words, data usage control 186 is a superset of data access control technology 182 (see reference [1]).
[0087] In the following, a data usage control method using ABE is described for enforcing data usage policies on shared data. Here, a data usage policy or data usage structure specifies a set of attributes required to access a certain secret. More formally, a data usage structure can be defined as follows:
[0088] Let {P1, P2, …, P n} be a set of relevant parties (i.e., attributes). If C, then the set is monotonic: if and then (i.e., if set B is in set , then all supersets C of B that contain B are also in set ). Then a (monotonic) data usage structure is a (monotonic) non-empty subset of the set of all possible combinations of {P1, P2, …, P n}, i.e., where denotes all possible combinations of P1, P2, …, P , and S\{a} denotes the set S excluding the subset that has the element a (e.g., n or the empty subset), and S (e.g., ). ). The sets in are called authorized sets, and the sets not in
[0089] are called unauthorized sets. Monotonicity embodies a natural idea that if authorized users acquire more attributes, they do not lose their privileges thereby. i and t i respectively represent the number of child nodes and the threshold at node i, where 1 ≤ t i ≤ n i . Then, when t i = 1, the threshold gate is an OR gate, and when t i = n i , the threshold gate is an AND gate. A data usage policy tree can represent any data usage policy in the form of a monotonic formula. Figure 8 FIG. shows an example of a data usage policy tree with three (3) attributes 202 (leaf nodes) and two (2) threshold gates 204 (non-leaf nodes).
[0090] Here, ABE is a public-key encryption method that helps implement a fine-grained and scalable data usage control system. ABE can be divided into two main categories: key policy ABE (KP-ABE) and ciphertext policy ABE (CP-ABE). In KP-ABE, ciphertext is created with reference to a list of attributes, and the data usage policy is encoded into the user's private key.
[0091] On the other hand, in CP-ABE, ciphertext is created with reference to the data usage policy. An example of a policy could be "Security_level≥3 AND Name=John". The private key of the data user is associated with a list of attributes. For example, a data user could have the following attributes: "Name=Sarah", "Age=27", "Security_level=2". The data user can decrypt the ciphertext if and only if the attributes of the data user satisfy the data usage policy used when creating the ciphertext.
[0092] Figure 9 FIG. is a schematic diagram showing a data sharing process 300 executed by a computer network system 100 provided by some embodiments of the present invention. This data sharing process is used to create, share, and use protected data with ABE-based data usage control. As shown, the computer network system 100 in these embodiments includes four types of entities:
[0093] · Attribute Authority (AA): AA 302 manages data sharing and generates a user agent key for the data user (described later) based on the attributes of the data user. AA 302 generates a master secret key MSK and corresponding public parameters. AA 302 also wraps the generated MSK.
[0094] · Data Owner (DO). DO 304 owns the data to be shared with other users, and this data has appropriate protection so that the shared data can be used by other users according to the specified policy. DO 304 encrypts the data to be shared into a first ciphertext and sends the first ciphertext to the cloud server proxy.
[0095] · Cloud Server Proxy (CSP). CSP 306 stores the protected data and is responsible for generating a second ciphertext based on the first ciphertext received from DO 304 and sharing the second ciphertext with one or more data users.
[0096] · Data User (DU). DU 308 is a user who wishes to access the DO data. DU 308 can receive the second ciphertext from CSP 306 and perform a final decryption operation to recover the DO data in plaintext form (i.e., unencrypted form).
[0097] In these embodiments, AA 302 and CSP 306 can be implemented as one or more applications and / or program modules 164 running on one or more server computers 102. Each DO 304 or DU 308 can be implemented as one or more applications and / or program modules 164 running on one or more client computing devices 104. Additionally, DO 304, CSP 306, and DU 308 can each have their respective public key / private key pairs (which will be described in more detail later).
[0098] As Figure 9 shown, DO 304 sends a request to AA 302 requesting the key and parameters for encrypting the data segments to be shared by DO 304 (step 322).
[0099] At step 332, AA generates the MSK and corresponding public parameters, wraps the generated MSK, and sends the wrapped MSK and corresponding public parameters to DO 304. In these embodiments, each shared data segment is associated with a corresponding MSK and public parameters. As will be described in more detail later, the public parameters are included in the packets sent to CSP 306 and DU 308 such that the public parameters are available at CSP 306 and DU 308 to be used as implicit inputs.
[0100] Then, DO 304 then creates a first ciphertext of the data segment in which the data usage policy is embedded, where the data segment is encrypted using the public parameters and the data usage policy is encrypted and obfuscated using the private key of the DO. At step 342, DO 304 uploads the first ciphertext and the wrapped MSK to CSP 306. As will be understood by those skilled in the art, steps 322 to 342 of creating the first ciphertext and the wrapped MSK and uploading the first ciphertext and the wrapped MSK to CSP 306 can be repeatedly executed to upload multiple first ciphertexts having multiple data segments in which different data usage policies are embedded.
[0101] At step 352, DU 308 can request CSP 306 to access the data segments of DO 304 (uploaded as the first ciphertext at step 342).
[0102] At step 362, CSP 306 extracts the wrapped MSK from the first ciphertext and sends the wrapped MSK, along with a request for the user agent key of DU 308, to AA 302 (via a secure and mutually authenticated channel).
[0103] In these embodiments, AA maintains a database of the IDs and attributes of all DUs (which can be created and maintained by a user such as an administrator). At step 372, AA 302 unwraps the wrapped MSK to retrieve the MSK and generates a user agent key based on the MSK, the attributes of the DU, the public key of the DU, and the public key of the CSP. Then, AA 302 sends the user agent key to CSP 306.
[0104] CSP 306 maintains a user agent key list, with each entry containing the ID of the corresponding DU 308 and the corresponding user agent key. At step 382, if and only if the attributes of the DU satisfy the data usage policy, CSP 306 uses the user agent key received from AA 302 and the private key of the CSP to generate a second ciphertext from the first ciphertext of the DO and sends the second ciphertext to DU 308.
[0105] At step 392, DU 308 decrypts the received second ciphertext using its private key to obtain the data segment of the DO in plaintext form.
[0106] Figure 10 is a schematic diagram showing an example of the data sharing process 300 in some embodiments, where each entity (i.e., AA 302, DO 304, CSP 306, or DU 308) shows the functions or methods that the entity can execute for creating, sharing, and using protected data with ABE-based data usage control. Figure 11 and Figure 12 is showing Figure 10 the sequence diagram of the exemplary data sharing process 300 shown, where Figure 11 is a sequence diagram showing the creation of shared data, Figure 12 is a sequence diagram showing the use of shared data.
[0107] As Figure 10 and Figure 11 shown in, at step 322, DO 304 sends a request to AA 302 for the key and parameters used to encrypt the data to be shared.
[0108] At step 324, AA 302 executes or runs a setup function to generate the MSK and the relevant public parameters for the data segment. More specifically, the setup function that can be expressed as Setup(1 k )→(params, msk) takes the security parameter 1 kTake a string representing k ones as input, and output multiple public parameters params and MSK msk by performing the following steps:
[0109] · Select a bilinear mapping e: G1 × G2 → G T , where G1, G2, and G T are cyclic groups of prime order p with k bits, and e: G1 × G2 →
[0110] G T represents the bilinear mapping or pairing e, which takes an element from G1, another element from G2, and maps these two elements to an element in G T . As those skilled in the art will understand, when G1 and G2 are the same, the bilinear mapping or pairing is called a symmetric pairing. When G1 and G2 are different, there may exist an efficiently computable homomorphism to map G2 to G1.
[0111] · Select g1 and g2, which are the generators of G1 and G2 respectively.
[0112] · Select two cryptographic hash functions H1: {0,1}* → G1 and where {0,1}* represents binary strings of arbitrary length, represents binary strings whose length of the smallest integer is greater than or equal to log2p.
[0113] · Select α, β, γ ∈ R Z p * , where a ∈ R S represents an element a (such as α, β, or γ) randomly selected from the set S (for example, the set Z p * ), and Z p * represents the cyclic group of integers modulo prime p, excluding zero (0).
[0114] · Obtain and msk = (α, β, γ) for output. It should be noted that e, G1, G2, g1, g2, H1, H2 are common to all packages, but msk and its associated public parameters h, d, and G α vary from package to package.
[0115] The public parameter params is an encryption / decryption related parameter, which is sent to DO 304 at step 332 and is included for sending to CSP 306 (at Figure 11 step 342 as shown) and DU 308 (at Figure 12In the package (described later) at step 382 shown, for their use during the data sharing process 300. In these embodiments, AA 302 wraps, encapsulates, or otherwise encrypts the generated MSK using its wrapping key (e.g., a wrapping key protected by hardware (HW)) through a suitable encryption method so as to securely store the MSK (as the wrapped MSK) in the package (described later), thereby avoiding any potential scalability issues.
[0116] At step 332, AA 302 sends the wrapped MSK and the public parameters params to DO 304.
[0117] At step 334, DO 304 executes a user key generation function to generate its own public / private key pair. More specifically, the user key generation function that can be expressed as UsrKGen() → (pub o ,prv o ) outputs the public / private key pair pub o and prv o , as the public key and private key pair pub s and prv s :
[0118] · Select x p ∈ R Z p * .
[0119] · Obtain prv o = x p and for output.
[0120] At step 336, DO 304 executes an encryption function to create a first ciphertext of the data segment in which the data usage policy is embedded, where the data segment is encrypted using the public parameters and the data usage policy is encrypted and obfuscated using the private key of DO. More specifically, the encryption function that can be expressed as Encrypt(data p ,T,prv s ) → c takes the plaintext data data p , the data usage policy tree T (see Figure 8 ) and the private key prv of DO s as inputs, uses the public parameters as implicit inputs, and outputs the first ciphertext c under the data usage policy tree T, where the data segment data p is encrypted using a suitable authenticated encryption with additional data (AEAD) method (such as AES-GCM)Encryption. More specifically, the AEAD method receives two inputs including a data segment data p and a key, and outputs encrypted data and verification / authentication data (which will be stored in the packet for sending to the DU 308; this will be described in more detail later).
[0121] The encryption function can perform the following steps:
[0122] · Starting from the root node of the data usage policy tree, in a top-down manner, select a polynomial q for each node i in T including the leaf nodes i .
[0123] · Set the degree d of each polynomial q i to t i – 1, where t i is the threshold of this node, as described above. i is the threshold of this node, as described above.
[0124] · Randomly select s ∈ R Z p * , and set q r (0) = s, where q r is the polynomial of the root node, and select d r other random points to fully define q r .
[0125] · For any other node j, q j (0) = q parent(j) (index(j)), where parent(j) is the parent node of node j in the data usage policy tree T, and index(j) is the unique number associated with node j. To fully define q j , select d j other random points.
[0126] · For each leaf node, calculate where prv s is the private key of the DO; then, by replacing the plaintext attribute att(l) assigned to each leaf node with H2(s l ) to obfuscate the attributes of the data usage policy tree T to generate an obfuscated data usage policy (in these embodiments, also a tree structure).
[0127] · Obtain the AEAD key key AEAD , and encrypt the plaintext data segment data AEAD using the AEAD key key p through the AEAD method. The AEAD method outputs the encrypted data data eand the label tag v , the label tag v is the verification / authentication data.
[0128] · Obtain the first ciphertext c, which is at least the obfuscated data usage policy C' = h s 、 {C l1 , C l2}(where L is the set of leaf nodes in T), the encrypted data data e and the verification / authentication data tag v combination.
[0129] Combine the first ciphertext c and the wrapped MSK into packet 400.
[0130] The formation of the first ciphertext c depends on the implementation. In some embodiments, is fed into a hash-based key derivation function (HKDF) to generate the AEAD key key AEAD . In these embodiments, the first ciphertext c is the obfuscated data usage policy C', C", {C l1 , C l2}(where e L is the set of leaf nodes in T), the encrypted data data v and the verification / authentication data tag
[0131] In some other embodiments, an element m is randomly selected from G T and then the element m is fed into the HKDF to generate the AEAD key key AEAD . In these embodiments, the first ciphertext c is the obfuscated data usage policy C', C", {C l1 , C l2}(where e L is the set of leaf nodes in T), the encrypted data data v and the verification / authentication data tag
[0132] At step 342, DO 304 uploads packet 400 to CSP 306. The steps 322 to 342 of creating the first ciphertext and the wrapped MSK and uploading the first ciphertext and the wrapped MSK to CSP 306 can be repeatedly executed to upload multiple first ciphertexts with multiple data segments in which different data usage policies are embedded.
[0133] Then, the creation of the shared data block is completed.
[0134] As Figure 11 shown, it is optional for the DO to execute the user key generation function (i.e., step 334). In other words, in some embodiments, the DO 304 may not execute the user key generation function during the data sharing process 300. Instead, the DO 304 may execute the user key generation function at the beginning of the data sharing process 300 after receiving the public parameters params, and may repeatedly use the generated private and public key pairs for each shared data segment in the shared data segment creation.
[0135] Figure 13 illustrates an exemplary structure of the encapsulation 400 provided by some embodiments of the present invention (in the left part of Figure 13 ), and explanations or details of some components of the encapsulation 400 (in the right part of Figure 13 ). As shown, the package 400 may include:
[0136] · A manifest entry 402, including metadata and details about the package 400 (see explanation 442).
[0137] For example, the manifest 402 may include a version number, a unique package ID, a confused data usage policy used when creating this package 400 the ABE public parameters params used when creating this package 400 (such that they can be extracted and used by other entities such as the CSP 306 and the DU 308), the public key pub of the DO s and so on.
[0138] · A wrapped MSK entry 404, containing the MSK created by the AA 302 for this package 400 and wrapped by the wrapping key of the AA (e.g., a HW-protected wrapping key) (see explanation 444).
[0139] Including the wrapped MSK entry 404 can enhance the security of the system 100 while maintaining its scalability. For example, storing the wrapped MSK in the package 400 eliminates the burden of separately and securely storing all wrapped MSKs at the AA 302. In addition, if the MSK is leaked or compromised, it may only affect one package 400 containing the leaked or compromised MSK.
[0140] · Encrypted dynamic state 406.
[0141] In some embodiments, the package 400 may include the dynamic state of the shared data segment (which may be initially set by the DO 304). The dynamic state may include the package ID, the hash of the manifest, the usage count, and the access policy for the dynamic state. For example, the dynamic state may be represented in JavaScript object notation (JSON) format as:
[0142]
[0143] Any suitable encryption method may be used to encrypt the dynamic state such that only the AA 302 can verify and modify it. For example, the dynamic state may be encrypted by an AEAD method using a key derived from a random element in G T where the AEAD method outputs the encrypted dynamic state and a tag for verification / authentication, which are stored in the encrypted state field 452 and the tag state field 454 of the encrypted dynamic state 406 of the package 400, respectively. The dynamic state access policy is stored in the policy field 448 of the encrypted dynamic state 406 of the package 400. The random element in G T is encrypted by ABE and then stored in the header state field 450 of the encrypted dynamic state 406 of the package 400.
[0144] During the use of the shared data segment, the dynamic state, such as the usage count, the header state 450, the encrypted state 452, and the tag state 456, may be updated to track the use of the shared data segment.
[0145] · One or more ABE header entries 410, one or more AEAD ciphertext entries 412, and one or more AEAD tag entries 414.
[0146] In these embodiments, the DO 304 may share one or more data (represented as one or more "input files") under the same data usage policy. Accordingly, each data may be encrypted separately using a suitable AEAD method such as AES-GCM as described above, and one or more encrypted data segments may be included in the package 400. More specifically, each set of ABE header entries 410, AEAD ciphertext entries 412, and AEAD tag entries 414 corresponds to an encrypted input file, where the i-th ABE header entry 410 (denoted as "header i") (for the i-th input file) contains the ABE header (i.e., the set of C', C", {C l1 , C l2}, and C, if a random element m selected from G T is used to generate the AEAD key key AEAD),the i-th AEAD ciphertext entry 412 (denoted as "AEAD ciphertext i") and the i-th AEAD tag entry 414 (denoted as "AEAD tag i") respectively contain the i-th encrypted input file data e and the corresponding tag tag v .
[0147] Now refer to Figure 10 and Figure 12 to describe the process of data shared using DO 304.
[0148] At step 344, DU 308 executes a user key generation function to generate its own public / private key pair. For example, DU308 can execute the above-mentioned UsrKGen function to output the public / private key pair pub o and prv o , as the public and private key pair pub u and prv u of DU 308.
[0149] At step 352, DU 308 can send a request to use a specific package 400 (hereinafter denoted as "the requested package") uploaded from DO 304 to CSP 306, as well as the package ID id pkg and the public key pub of DU u .
[0150] At step 354, CSP 306 executes a user key generation function to generate its own public / private key pair. For example, CSP 306 can execute the above-mentioned UsrKGen function to output the public / private key pair pub o and prv o , as the public and private key pair pub csp and prv csp of CSP 306.
[0151] At step 362, CSP 306 calculates the hash of the manifest 402 of the package and extracts the package ID, the wrapped MSK 404, and the encrypted dynamic state 406 from the requested package 400. Then, CSP 306 sends the ID id of DU u , the public key pub of DU u , the public key pub of CSP csp , the wrapped MSK 404, the encrypted dynamic state 406, the package ID id pkg and the hash of the package manifest 402, as well as a request for the user agent key of that specific DU 308.
[0152] At step 364, AA 302 decrypts the received encrypted dynamic state 406 and verifies that the received dynamic state indeed belongs to the requested packet 400. If the verification fails, AA 302 returns an error (not shown); otherwise, AA 302 unwraps the received wrapped MSK 404 to obtain MSK msk, and uses the proxy key generation function to create the user proxy key for the DU according to the attributes of the DU provided at AA 302 as described above. If needed, AA 302 can also update the dynamic state and re-encrypt it as needed to obtain the updated encrypted dynamic state 406.
[0153] For example, it can be expressed as PrxKGen(msk,pub csp ,pub u ,A u )→PrxK u The proxy key generation function that takes MSK msk = (α,β,γ), the public key of the CSP the public key of the DU and the attribute A associated with the DU 308 u as inputs and outputs the user proxy key PrxK for this DU 308 by performing the following steps u :
[0154] · Select r1, r2,
[0155] · Obtain the user proxy key
[0156]
[0157] At step 372, AA 302 responds to the CSP 306 by sending the attribute-based user proxy key PrxK of the DU u and the updated encrypted dynamic state (if any).
[0158] At step 374, the CSP 306 receives the user proxy key of the DU and generates a second ciphertext using the proxy decryption function. The CSP 306 can also replace the old encrypted dynamic state with the updated encrypted dynamic state received from AA 302 (if any).
[0159] For example, it can be expressed as PrxDec(prv csp ,PrxK u ,pub s ,c)→v. The proxy decryption function that takes the private key prv of the CSP csp the user proxy key PrxK of the DU u (which includes elements k, k' and {kj1 , k j2 , k j3}), the public key pub of DO s and the first ciphertext c (obtained from the requested packet) as inputs, and outputs the second ciphertext v for this DU 308 if and only if the attribute A u associated with DU 308 satisfies the data usage policy (T). More specifically, the proxy decryption function can perform the following steps:
[0160] · For each attribute in A u , calculate the attribute index I j = H2(s j ) set where s j = e(k j3 , pub s ) = e(H1(j) γ , pub s ).
[0161] · Check whether the set of attribute indices u associated with the user agent key PrxK of the DU satisfies the obfuscated data usage policy embedded in the ciphertext c.
[0162] In these embodiments, such a check may only require a simple comparison using each index of the attribute and may not reveal any plaintext attributes embedded in the ciphertext c (i.e., does not convert the encrypted and obfuscated attributes embedded in the ciphertext c into plaintext form).
[0163] · If the set of attribute indices does not satisfy the obfuscated data usage policy embedded in the ciphertext c, return ⊥ (i.e., invalid).
[0164] · If the set of attribute indices satisfies the obfuscated data usage policy embedded in the ciphertext c, then use the function (generated by the encryption function in step 336) on each node x to recursively calculate the group element of G or ⊥. More specifically, if x is a leaf node and its attribute value z is obfuscated as H2(s T ), then if x then DecNode returns ⊥, otherwise DecNode returns F , where x , where
[0165]
[0166] where, k z1 and k z2It is the user agent key PrxK u of k j1 and k j2 (i.e., j = z), C x1 and C x2 is C l1 and C l2 , where l = x.
[0167] o When x is a non - leaf node, DecNode is called for each child node y of x and stores the output F y . Let S x be a set of child nodes y of any size t x (where t x is the threshold of node x; such a threshold was also denoted as t of the i - th node in the previous description i ), such that F y ≠⊥. If such a set does not exist, then x does not satisfy, DecNode returns ⊥, otherwise, let the Lagrange coefficient Δ i, s, i ∈ Z p , and let the set S of elements in Z p be Return F x , where
[0168] where i = index(y), s x ′={index(y):y ∈ S x}
[0169]
[0170] o Using this recursive method, DecNode at the root node can be computed if and only if the attributes associated with the user agent key of DU satisfy the data - use policy according to which the ciphertext c was created. In this case, DecNode returns
[0171]
[0172] · Then, the proxy decryption function computes:
[0173]
[0174] · Outputs the second ciphertext v, which is a combination of e(g1, pub u ), the encrypted data data αs and the verification / authentication data tag e , or, if C is used, outputs C, e(g1, pub v ), the encrypted data data u ) αs 、the encrypted data datae and the verification / authentication data tag v combination. That is, the second ciphertext v is C (which uses for m masking and is the same as C in the first ciphertext) and e(g1, pub u ) αs combination.
[0175] At step 382, the CSP 306 updates the packet 400 by using the updated encrypted dynamic state to update the encrypted dynamic state entry 406. The CSP 306 also replaces the set of ABE headers 410 with the ABE headers generated by the proxy decryption function. As shown above, the second ciphertext v has the same encrypted message and tag. Therefore, the AEAD ciphertext and AEAD tags 412 and 414 are maintained. Then, the CSP 306 sends the updated packet 400 to the DU 308.
[0176] At step 392, the DU 308 runs the user decryption function on the received second ciphertext v using the private key prv u of the DU to obtain the shared data in plaintext form. More specifically, it can be expressed as UsrDec(prv u , v) → data p The user decryption function that takes the private key prv u of the DU and the second ciphertext v as inputs calculates the plaintext data segment data p (i.e., the shared data segment in plaintext form). More specifically, if the packet 400 received from the CSP 306 does not include C in the ABE header of the input file, the DU 308 will feed it into HKDF to generate the AEAD key key AEAD . If the packet 400 received from the CSP 306 includes C in the ABE header of the input file, the DU 308 calculates m as
[0177]
[0178] In other words, for
[0179]
[0180] Then, the DU 308 feeds m into HKDF to generate the AEAD key key AEAD .
[0181] After obtaining the AEAD key key AEAD , the DU 308 uses the AEAD key key AEAD to decrypt the encrypted data data e and the verification / authentication data tagv Perform AEAD verification and decryption to obtain the plaintext data segment data p (if the verification is successful).
[0182] Thus, the process of using the data shared by DO 304 is completed.
[0183] As Figure 12 shown, it is optional for DU 308 and CSP 306 to execute the user key generation function (i.e., steps 344 and 354). In other words, in some embodiments, during the data sharing process 300, DU 308 and / or CSP 306 may not execute the user key generation function. Instead, DU 308 and / or CSP 306 may execute the user key generation function before the start of the data sharing process 300 and may reuse the generated private and public key pairs to create each shared data.
[0184] In some embodiments, CSP 306 may also execute the user revocation function Revoke(id u ,L PrxK )→L' PrxK , which takes the ID id of the DU u and the user agent key list L PrxK as inputs, deletes the entry corresponding to id PrxK from the list L u , i.e., L' PrxK =L PrxK \{id u ,PrxK u} and outputs the updated proxy key list L' PrxK , thereby revoking the decryption ability of the DU.
[0185] In some embodiments, the user key generation function (UsrKGen) takes the input id i , which is the ID of the function caller, to generate the user key. More specifically, the UsrKGen function performs the following steps:
[0186] · Select s∈ R Z p *
[0187] · Obtain prv o =H3(id i ) s and
[0188] However, in these embodiments, a third hash function H3:{0,1} * →Z p is required.
[0189] In various embodiments, the computer network system 100 and the data sharing method with ABE-based data usage control described above can be used to enforce policies in various domains such as on-demand live television broadcasting, smart grid, e-health systems, cloud storage services, document / email sharing and protection, etc.
[0190] For example, sovereign data exchange (SDE) refers to the ability of a data owner to share its data with other users without compromising its sovereignty, that is, having autonomy over the access, processing, or protection of its data. Although there are many challenges in having SDE (see reference [3]), one of the challenges is data usage and access control. The computer network system 100 and the data sharing method with ABE-based data usage control described above can be used in SDE products or services to address this challenge.
[0191] Therefore, the computer network system 100 and the data sharing method with ABE-based data usage control described above can solve at least one of the following technical problems:
[0192] 1. The data usage policy of the data owner is bound to its content or data and is executed cryptographically using the ciphertext policy attribute-based encryption (CP-ABE) method. Therefore, the DU 308 may not be able to access the data unless the attributes related to the data satisfy the data usage policy of the DO.
[0193] 2. Protect the privacy of the DO's data usage policy by encrypting and obfuscating the attributes of the data, so that the data usage policy attributes are not shared in plaintext.
[0194] More specifically, the computer network system 100 and the data sharing method with ABE-based data usage control described above can provide a solution to protect the data and enforce usage policies with policy hiding, usage tracking, user revocation, and decryption offloading:
[0195] · Policy hiding: To protect the privacy of the DO's policy attributes, the data sharing method disclosed herein, more specifically, the ABE-based data usage control method encrypts and obfuscates the attributes, so that the DO's data usage policy is hidden in a secure and encrypted manner and no attributes are leaked.
[0196] · Usage Tracking: In some embodiments, an encrypted dynamic state is embedded in the protected content (i.e., packet 400). The encrypted dynamic state can be initially set by the DO 304. If needed, the AA 302 can decrypt the encrypted dynamic state, update the dynamic state (e.g., increment the usage count), and create an updated encrypted dynamic state. The user agent key PrxK of the DU u can be generated using the current counter value as one of its attributes. Thus, the computer network system 100 disclosed herein can track the actual usage of the protected data.
[0197] · Proxy-Assisted User Revocation: To revoke the DU 308, the CSP 306 can erase the key associated with the DU. This approach supports immediate revocation without compromising efficiency as it does not require data re-encryption or key updates.
[0198] · Decryption Offloading: The data sharing method and the ABE-based data usage control method disclosed herein outsource time-consuming computational tasks to the CSP 306, so that user decryption is completed in constant time and is independent of the number of their attributes.
[0199] In some embodiments, the computer network system 100 and the data sharing method with ABE-based data usage control use the CP-ABE method to achieve policy hiding, user revocation, and decryption offloading. To support usage tracking, the protected data is constructed such that the protected data includes an encrypted dynamic state that can only be updated by an authorized party. In some embodiments, such a dynamic state includes the current counter value. However, this can be generalized to other use cases, e.g., use cases where the dynamic state can include the date of the last access to the packet or the location of the DU that last accessed the packet.
[0200] In some embodiments, the computer network system 100 and the data sharing method use the CP-ABE method, which provides many benefits, such as:
[0201] · By executing its policy cryptographically, giving the DO 304 control over its data and hiding the DO's policy, thus there is no risk of privacy leakage;
[0202] · Supporting proxy-assisted user revocation;
[0203] · Providing decryption offloading.
[0204] In some embodiments, the computer network system 100 and the data sharing method use an advanced packet structure, which provides many advantages, such as:
[0205] · Supporting the update of the dynamic state of the packet, such as tracking the number of times it has been used;
[0206] · Enhanced security by storing the packaged MSK in the package itself while maintaining scalability.
[0207] C. References
[0208] [1] B. Otto, S. Lohmann, S. Auer, G. Brost, J. Cirullies, A. Eitel, T. Ernst, C. Haas, M. Huber, C.
[0209] Jung, J. Jürjens, C. Lange, C. Mader, N. Menz, R. Nagel, H. Pettenpohl, J. Pullmann, C Quix, J. Schon, D. Schulz, J. Schütte, M. Spiekermann and S. Wenzel “Reference Architecture Model for the Industrial DataSpace 3.0”, Fraunhofer-Gesellschaft zur der angewandten Forschung e.V. and Industrial Data Space e.V., Munich, 2019.
[0210] [2] Sebastian Steinbuβ, “How the IDS-RAM Standard Contributes to European Data Spaces (Introduction to IDS-RAM, & Data Usage Control)
[0211] (HOW THE IDS-RAM STANDARD CONTRIBUTES TO EUROPEAN DATA SPACES
[0212] (INTRODUCTION TO IDS-RAM,&DATA USAGE CONTROL))”, https: / / www.opendei.eu / wp-content / uploads / 2020 / 05 / OpenDei-1st-Webinar-Presentation_Sebastian-Steinbuss.pdf
[0213] [3] K. Schmidt, G. Munilla Garrido, A. Mühle, and C. Meinel (2022) "Mitigating the Challenges of Sovereign Data Exchanges: Planning with Privacy and Authenticity Enhancement Technologies", in International Conference on Trust and Privacy in Digital Business (pp. 50-65), Springer Cham.
[0214] Although the embodiments have been described above with reference to the accompanying drawings, those skilled in the art will understand that changes and modifications can be made without departing from the scope defined by the appended claims.
Claims
1. A method, characterized in that, Comprising: Receiving a first ciphertext and a wrapped master secret key (MSK) from a data owner (DO), where the first ciphertext includes encrypted data and an encrypted and obfuscated data usage policy embedded in the encrypted data, and the encrypted and obfuscated data usage policy is conditional on one or more attributes of the encrypted and obfuscated data usage policy; Receiving a request from a data user (DU) to use the data; Obtaining a user agent key, which is generated based on the wrapped MSK, a first public key, the public key of the DU, and the one or more attributes associated with the DU, and the wrapped MSK is an encapsulated version of a first MSK; Generating a second ciphertext based on a first private key, the user agent key, the public key of the DO, and the first ciphertext if and only if the one or more attributes associated with the DU satisfy the obfuscated data usage policy; Sending the second ciphertext to the DU; Wherein, generating the second ciphertext includes: Checking whether the one or more attributes associated with the DU satisfy the obfuscated data usage policy without converting the obfuscated data usage policy into a plaintext form.
2. The method according to claim 1, wherein Further comprising: Storing the user agent key and the identifier (ID) of the DU in a user agent key list.
3. The method according to claim 2, wherein Further comprising: Removing the user agent key and the ID of the DU from the user agent key list.
4. The method according to any one of claims 1 to 3, characterized in that The wrapped MSK is the first MSK encapsulated by a wrapping key.
5. The method according to claim 4, wherein The wrapping key is a hardware-protected wrapping key.
6. The method according to any one of claims 1 to 5, characterized in that The receiving the first ciphertext and the wrapped MSK includes: Receiving a packet, where the packet includes: A manifest, The wrapped MSK, An encrypted dynamic state for tracking the usage of the data, At least one entry of the first ciphertext.
7. The method according to claim 6, characterized in that, The manifest includes one or more of the following: a version number, a unique packet ID, the obfuscated data usage policy, and a plurality of public parameters generated in association with the first MSK.
8. The method according to claim 6 or 7, characterized in that, Each entry of the at least one entry of the first ciphertext includes: At least one header entry, At least one ciphertext entry, At least one tag entry.
9. The method according to claim 8, dependent on claim 7, characterized in that, The first ciphertext is obtained based on the data, the data usage policy, the private key of the DO, and the plurality of public parameters.
10. The method according to any one of claims 1 to 8, characterized in that The first ciphertext is obtained based on the data, a tree of the data usage policy, the private key of the DO, and the plurality of public parameters.
11. The method according to claim 10, wherein The first MSK is obtained by: Select a bilinear mapping e: G1×G2→G T , where G1, G2, and G T are cyclic groups of prime order p with k bits, and e: G1×G2→G T represents the bilinear mapping or pairing e, which takes one element from G1, another element from G2, and maps the two elements to an element in G T ; Selecting g1 and g2, which are generators of G1 and G2 respectively; Select two cryptographic hash functions H1: {0,1}* → G1 and H2: G T → {0,1} log 2 p , where {0,1}* represents binary strings of arbitrary length, represents binary strings with the length of the smallest integer greater than or equal to log2p; Select α, β, γ randomly from the set Z p * , where Z p * is a cyclic group of integers modulo a prime number p, excluding zero; Obtain and the first MSK msk = (α, β, γ).
12. The method according to claim 11, wherein The first ciphertext is obtained by: Starting from the root node of the data usage policy tree T, in a top-down manner, select a polynomial q for each node i in T that includes leaf nodes i ; Set the degree d i of each polynomial q i to t i – 1, where t i is the threshold of each node i; Randomly select s from the set Z p * and set q r (0) = s, where q r is the polynomial of the root node, and select d r other random points to fully define q r ; For any other node j, q j (0) = q parent(j) (index(j)), where parent(j) represents the parent node of node j in the data usage policy tree T, index(j) is the unique number associated with node j, and d j other random points are selected to fully define q j ; For each leaf node, compute where prv s is the private key of the said DO; then, by replacing the said att(l) assigned to each leaf node with H2(s l ) to obfuscate the one or more attributes att(l) of the said data usage policy tree T to generate the obfuscated data usage policy Obtain an authenticated encryption with additional data (AEAD) key key AEAD ; Using the AEAD key key through the AEAD method AEAD for the data data p to perform encryption to obtain encrypted data data e and tag tag v ; Obtain the first ciphertext c, where the first ciphertext c is at least the obfuscated data usage policy C' = h s , {C l1 , C l2}, the encrypted data data e and the tag tag v in combination, where L is the set of leaf nodes in T.
13. The method according to claim 12, characterized in that, Obtaining the AEAD key key AEAD includes: Feed into a hash-based key derivation function (HKDF) to generate the AEAD key key AEAD .
14. The method according to claim 12, wherein The obtaining of the AEAD key key AEAD comprises: Select an element m randomly from G T ; Feed m into a hash-based key derivation function (HKDF) to generate the AEAD key key AEAD .
15. The method according to claim 14, wherein The obtaining the first ciphertext c includes: Obtain the first ciphertext c, where the first ciphertext c is at least the obfuscated data usage policy C' = h s , {C l1 , C l2}, the encrypted data data e and the tag tag v in combination, where L is the set of leaf nodes in T.
16. The method according to any one of claims 12 to 15, characterized in that, The user agent key PrxK u is generated by the following operations: For A u For any j in p * randomly select r1, r2, r j from the set Z u where A represents the one or more attributes related to the DU; Obtain the user agent key wherein, pub csp and pub u respectively represent the first public key and the public key of the DU 17. The method according to claim 16, wherein The generating the second ciphertext includes: For A u For each attribute in j = H2(s j ) set where s j = e(k j3 , pub s ) = e(H1(j) γ , pub s ); Check the set of property indexes associated with the user agent key PrxK u to see if it satisfies the obfuscated data usage policy embedded in the first ciphertext c without converting the obfuscated data usage policy into the plaintext form; If the set of attribute indices does not satisfy the obfuscated data usage policy embedded in the ciphertext c, return invalid ⊥; If the set of attribute indices satisfies the obfuscated data usage policy embedded in the ciphertext c, then recursively compute G T or a group element of ⊥ Calculation Output the second ciphertext v, where the second ciphertext v is at least e(g1, pub u ) αs , the encrypted data data e and the verification / authentication data tag v combination.
18. The method according to claim 17, wherein Said recursively calculating the group elements includes: at each node x of Step A: If x is a leaf node, its attribute value z is confused with H2(s x ), and if then return otherwise return When x is a non-leaf node, apply step A to each child node y of x and store the output F y , if there does not exist a set S x , where S x is an arbitrary set of child nodes y of size t x , t x is the threshold of node x such that F y ≠ ⊥, then return Otherwise return 19. The method according to claim 18, characterized in that Further comprising: Generate the first public key and the first private key using a user key generation function with a public / private key pair output pub o and prv o ; Wherein, the user key generation function includes the following steps: Select x p ∈ R Z p * , Obtain prv o = x p and Wherein, the generating the first public key and the first private key using the user key generation function includes: Using the user key generation function, Use pub o and prv o as the first public key and the first private key respectively.
20. The method according to claim 19, wherein The public key and the private key of the DO are generated by the user key generation function.
21. The method according to claim 20, wherein The public key and the private key of the DU are generated by the user key generation function.
22. The method according to claim 21, wherein Sending the second ciphertext to the DU is to enable the DU to use its private key prv u to perform a user decryption function on the second ciphertext v to obtain the AEAD key key using the information of the second ciphertext AEAD and use the tag through the AEAD decryption method v to verify and decrypt the encrypted data data e to obtain the data in plaintext form.
23. One or more processors, characterized in that, For executing instructions to perform the method according to any one of claims 1 to 22.
24. One or more non-transitory computer-readable storage media, characterized in that, Comprising computer-executable instructions for modifying a signal, wherein the instructions, when executed, cause a processing structure to perform the method according to any one of claims 1 to 22.