Access control method based on privacy review and attribute encryption
By dividing user attributes into privacy and non-privacy attributes and using ciphertext policy attribute encryption technology, the problem of user privacy attribute exposure in cloud computing is solved, and the protection of user privacy and system efficiency is achieved in access control.
Patent Information
- Application Number
- CN202510352958.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-07-25
AI Technical Summary
In the cloud computing environment, traditional access control models cannot effectively protect user privacy, especially when the number of users is large and the permission management is complex, user attribute information is easily leaked, resulting in increased privacy risks.
The access control method based on privacy review and attribute encryption is adopted. By dividing user attributes into privacy attributes and non-privacy attributes, non-privacy attributes are stored on the user side, and the access policy and user attributes are matched using ciphertext policy attribute-based encryption technology to protect user privacy.
Without affecting the efficiency of the system, effectively protect user privacy and ensure flexibility and security of access control. Especially when privacy attributes are included in the access policy, the security and availability balance of user attributes are achieved through a small amount of data encryption verification.
Smart Images

Figure CN120372676A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of access control research, and particularly relates to an access control method based on privacy review and attribute encryption. Background Art
[0002] At present, the development of cloud computing has provided users with highly flexible, scalable, cheap and convenient data services, but at the same time has also posed new challenges to information security. The dynamic changes of users, resources and the environment in the cloud environment make the traditional access control model no longer applicable. In Attribute-Based Access Control (ABAC), access permissions are dynamically calculated based on multiple attributes such as users, resources, and the environment. Therefore, it can perform access control more flexibly according to the context. In an environment where data is not sensitive but user privacy is more sensitive, especially when the number of users is large and permission management is complex, the privacy protection of users is one of the main challenges faced by access control. In this paper, we mainly focus on the security of user privacy attributes in ABAC.
[0003] In traditional ABAC, after a user initiates a read / write operation request for a resource, the policy decision point evaluates it according to predefined access policies and the attributes of the user and the resource. For performance and efficiency considerations, user attributes are usually stored in an attribute storage point or provided by a third-party service that specifically stores user information. However, in either case, the user's attribute information will be directly exposed, increasing the risk of user privacy leakage. How to protect the privacy of users while ensuring the security and high availability of the system has become one of the current research hotspots in academia and industry. Summary of the Invention
[0004] In order to solve the technical problems mentioned in the above background art, the present invention proposes an access control method based on privacy review and attribute encryption.
[0005] In order to achieve the above technical objectives, the technical solution of the present invention is as follows:
[0006] An access control method based on privacy review and attribute encryption, comprising the following steps:
[0007] (1) In the initial stage, the system selects encryption public parameters and generates a master key; after the user completes attribute authentication, the attribute authorization agency AA generates a private key according to the user attributes and sends it to the user.
[0008] (101) Initialization: Generate group and bilinear mapping public parameters <e, g, G1, G T , Z r >, where g is the generator of G1, e: G1×G1→G T ; select a random number a ∈ Zr , compute \(Y = e(g,g)\) a ; Select a random number \(b\in\mathbb{Z}\) r , compute \(g^b\) b ; Generate the system master key \(g^b\) a , public key \(pk=\langle Y,g^b\rangle\) b >; Each attribute corresponds to an element in the \(G_1\) group, which can be pre-selected or hashed when used.
[0009] (102) Generate the secret key: Select a random number \(t\), compute \(D = g^t\) a g^b bt , \(D_0 = g^t\) t ; For each attribute \(i\) in the user attribute list \(AttrList\), compute \(D_i = H(i)\) i , where \(H\) is a hash algorithm. Generate the user's private key \(sk=\langle D,D_0,\{D_i\}\rangle\). t i i∈AttrList >
[0010] (2) When the user requests a resource, send the access request to the Policy Enforcement Point (PEP), and the PEP passes the relevant information to the Policy Decision Point (PDP). The specific steps are as follows:
[0011] (201) The PDP searches for the policies in the policy management point. After obtaining the relevant policies, the PDP sends the policies to the privacy review module for evaluation.
[0012] (202) The privacy review module checks the user attribute part in the policy. If it does not involve the user's privacy attributes, it directly responds that there are no privacy attributes in the PDP policy and enters (205); otherwise, it enters (203).
[0013] (203) The privacy review module extracts the access tree structure of the user attribute part in the policy, selects a random number, and encrypts the random number using the access tree structure, then sends the ciphertext to the PEP.
[0014] (204) After receiving the ciphertext sent by the privacy review module, the PEP forwards it to the user and waits for the user's response. After receiving the ciphertext, the user decrypts it using the private key and sends the decryption result to the PEP. The PEP passes the decryption result to the privacy review module. The privacy review module compares the decrypted data with the random number. If they are equal, it means that the user attributes are the authorized set of the access tree and the result is allowed; if they are not equal, it means that the user attributes are the unauthorized set and the result is rejected. Then it sends the result to the PDP.
[0015] (205) The PDP receives the response from the review module. If it does not involve privacy attributes, it obtains the user's non-privacy attributes and other relevant attributes from the Attribute Authorization Management AA and makes a determination based on the policy. If the response from the privacy review module is allowed or denied, the result is brought into the policy access tree, and the remaining part of the policy is determined to obtain the result. The final determination result depends on the rules set by the system. In addition to the traditional allow and deny, results such as partially allowed can be extended. Subsequently, the result is sent to the PEP, and the PEP controls the user's access to resources according to the determination result of the PDP.
[0016] (3) Secret key refresh and privacy review: When the user's attributes change, re-authenticate the attributes to the Attribute Authority AA, and the AA issues a new user secret key according to the new user attribute information. By reviewing the attributes of the subject (usually the user) in each policy, check whether it involves the user's privacy attributes.
[0017] (301) If it does not involve the user's privacy attributes, the PDP obtains the user's non-privacy attribute information from the AA according to the traditional ABAC process and conducts policy evaluation.
[0018] (302) If the policy involves the user's privacy attributes, intercept the access tree of the user attribute part in the policy, generate a random number, encrypt the random number using the ciphertext policy attribute-based encryption algorithm, and send it to the user. After receiving the ciphertext, the user decrypts it using the attribute key issued by the attribute authority at the beginning. Only when the user's attributes satisfy the access tree structure can the data be decrypted, otherwise it cannot be decrypted.
[0019] (303) If the user decrypts the plaintext and then sends it to the privacy review module, the privacy review module compares the plaintext data with the generated random number. If the two are equal, the user attribute part in the policy meets the authorization requirements. If the user cannot decrypt the data, the privacy module determines that the user attributes do not meet the authorization requirements and sends the determination result to the PDP for subsequent processing.
[0020] Beneficial effects brought by adopting the above technical solutions:
[0021] (1) In the present invention, aiming at the problem of attribute exposure in the ABAC model, we propose an ABAC model that can protect the user's privacy attributes and give a formal definition. In the model, the user's attributes are divided into privacy attributes and non-privacy attributes. By storing the privacy attributes on the user side, the security of the user's privacy attributes is ensured, and the ciphertext policy attribute-based encryption means are used to match the access policy and the user's attributes;
[0022] (2) In general application scenarios, when the access policy does not contain privacy attributes, the model in this paper has similar efficiency to the ABAC model. When the access policy contains privacy attributes, a small amount of data is encrypted through the access policy for authorization verification, balancing user privacy protection and system availability. Brief Description of the Drawings
[0023] Figure 1 is a diagram of the access control model of the present invention;
[0024] Figure 2 is a diagram of the secure access control tree of the present invention;
[0025] Figure 3 is a diagram of the policy access tree of the present invention;
[0026] Figure 4 is a flowchart of the privacy review module of the present invention. Detailed Embodiment
[0027] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings.
[0028] As Figure 1 shown, an access control method based on privacy review and attribute encryption includes the following steps:
[0029] Step 1: In the initial stage, the system selects encryption public parameters and generates a master key; after the user completes attribute authentication, the attribute authorization authority AA generates a private key according to the user attributes and sends it to the user;
[0030] Step 2: When the user requests a resource, the access request is sent to the policy enforcement point PEP, and the PEP passes the relevant information to the policy decision point PDP. In the ABAC of the present invention, the logic gates of the non-leaf nodes of the access control tree are usually only represented as "AND" and "OR", as Figure 2 shown;
[0031] Step 3: The working process of the privacy review module is as Figure 4 shown. When the user attributes change, the user re-authenticates the attributes to the attribute authorization authority AA, and the AA issues a new user key according to the new user attribute information. By reviewing the attributes of the subject in each policy, usually the user's attributes, it is checked whether user privacy attributes are involved.
[0032] In this embodiment, the above step 1 can be implemented by the following preferred solution:
[0033] 101. Initialization: Generate group and bilinear mapping public parameters <e, g, G1, G T , Z r >, where g is the generator of G1, and e: G1×G1→G T ; Select a random number a∈Zr , compute Y = e(g, g) a ; Select a random number b ∈ Z r , compute g b ; Generate the system master key g a , public key pk = <Y, g b >; Each attribute corresponds to an element in the G1 group, which can be pre-selected or hashed for the attribute when used.
[0034] 102. Generate the secret key: Select a random number t, compute D = g a g bt , D0 = g t ; For each attribute i in the user attribute list AttrList, compute D i = H(i) t , where H is the hash algorithm. Generate the user private key sk = <D, D0, {D i} i∈AttrList >.
[0035] In this embodiment, the above step 2 can be implemented by the following preferred solution:
[0036] 201. The PDP searches for the policy in the policy management point. After the PDP obtains the relevant policy, it sends the policy to the privacy review module for evaluation.
[0037] 202. The privacy review module checks the user attribute part in the policy. If it does not involve the user privacy attribute, it directly responds that there is no privacy attribute in the PDP policy and enters (205), otherwise it enters (203).
[0038] 203. The privacy review module extracts the access tree structure of the user attribute part in the policy, selects a random number, and encrypts the random number using the access tree structure, and sends the ciphertext to the PEP.
[0039] 204. After receiving the ciphertext sent by the privacy review module, the PEP forwards it to the user and waits for the user's response. After receiving the ciphertext, the user decrypts it using the private key and sends the decryption result to the PEP. The PEP passes the decryption result to the privacy review module. The privacy review module compares the decrypted data with the random number. If the two are equal, it means that the user attribute is the authorized set of the access tree and the result is allowed. If they are not equal, it means that the user attribute is the unauthorized set and the result is rejected, and then sends the result to the PDP.
[0040] 205. When the PDP receives the response from the review module, if it does not involve the privacy attribute, it obtains the user non-privacy attributes and other relevant attributes from the attribute authorization management AA and makes a determination according to the policy. If the response from the privacy review module is allowed or rejected, it brings the result into the policy access tree, as Figure 3As shown, the remaining part of the policy is judged to obtain the result. The final judgment result depends on the rules set by the system. In addition to the traditional allow and deny, results such as partially allow can be extended. Subsequently, the result is sent to the PEP, and the PEP controls the user's access to resources according to the judgment result of the PDP.
[0041] In this embodiment, the above step 3 can be implemented by adopting the following preferred scheme, specifically as follows Figure 4 :
[0042] 301. If the user privacy attribute is not involved, the PDP obtains the user non-privacy attribute information from the AA according to the traditional ABAC process and conducts policy evaluation;
[0043] 302. If the user privacy attribute is involved in the policy, intercept the access tree of the user attribute part in the policy, generate a random number, encrypt the random number using the ciphertext policy attribute-based encryption algorithm, and send it to the user. After receiving the ciphertext, the user decrypts it using the attribute key issued by the attribute authority at the beginning. Only when the user attribute meets the access tree structure can the data be decrypted, otherwise it cannot be decrypted;
[0044] 303. If the user decrypts the plaintext and then sends it to the privacy review module, the privacy review module compares the plaintext data with the generated random number. If the two are equal, the user attribute part in the policy meets the authorization requirements. If the user cannot decrypt the data, the privacy module determines that the user attribute does not meet the authorization requirements and sends the judgment result to the PDP for subsequent processing.
Claims
1. An access control method based on privacy review and attribute encryption, characterized in that, It includes the following steps: (1) In the initial stage, the system selects encryption public parameters and generates a master key; After the user completes attribute authentication, the attribute authorization authority AA generates a private key according to the user attributes and sends it to the user. (101) Initialization: Generate the public parameters of the group and the bilinear mapping <e, g, G1, G T , Z r >>, where g is the generator of G1, and e: G1×G1→G T ; Select a random number a ∈ Z r , and calculate Y = e(g, g) a ; Select a random number b ∈ Z r , and calculate g b ; Generate the system master key g a , and the public key pk = <Y, g b >; Each attribute corresponds to an element in the G1 group, which can be pre-selected or the attribute can be hashed when used. (102) Generate a secret key: Select a random number t, and calculate D = g a g bt , D0 = g t ; For each attribute i in the user attribute list AttrList, calculate D i = H(i) t , where H is a hash algorithm. Generate the user's private key sk = <D, D0, {D i} i∈AttrList >. (2) When the user requests a resource, the access request is sent to the policy enforcement point PEP, and the PEP passes the relevant information to the policy decision point PDP. The specific steps are as follows: (201) The PDP searches for the policies in the policy management point. After the PDP obtains the relevant policies, it sends the policies to the privacy review module for evaluation. (202) The privacy review module checks the user attribute part in the policy. If the user privacy attribute is not involved, it directly responds that there is no privacy attribute in the PDP policy and enters (205). Otherwise, it enters (203). (203) The privacy review module extracts the access tree structure of the user attribute part in the policy, selects a random number, encrypts the random number using the access tree structure, and sends the ciphertext to the PEP. (204) After receiving the ciphertext sent by the privacy review module, the PEP forwards it to the user and waits for the user's response. After receiving the ciphertext, the user decrypts it using the private key and sends the decryption result to the PEP. The PEP passes the decryption result to the privacy review module. The privacy review module compares the decrypted data with the random number. If the two are equal, it means that the user attributes are the authorized set of the access tree and the result is allowed. If they are not equal, it means that the user attributes are the unauthorized set and the result is rejected. Then the result is sent to the PDP. (205) When the PDP receives the response from the review module, if the privacy attribute is not involved, it obtains the user's non-privacy attributes and other relevant attributes from the attribute authorization management AA and makes a determination according to the policy. If the response from the privacy review module is allowed or rejected, the result is brought into the policy access tree, and the remaining part of the policy is determined to obtain the result. The final determination result depends on the rules set by the system. In addition to the traditional allow and reject, results such as partial allow can be extended. Then the result is sent to the PEP, and the PEP controls the user's access to the resource according to the determination result of the PDP. (3) Secret key refresh and privacy review:: When the user attributes change, the user re-authenticates the attributes to the attribute authorization authority AA, and the AA issues a new user key according to the new user attribute information. By reviewing the attributes of the subject (usually the user) in each policy, it is checked whether the user privacy attribute is involved. (301) If the user privacy attribute is not involved, the PDP obtains the user's non-privacy attribute information from the AA according to the traditional ABAC process and conducts policy evaluation. (302) If the policy involves the user privacy attribute, the access tree of the user attribute part in the policy is intercepted, a random number is generated, and the random number is encrypted using the ciphertext policy attribute-based encryption algorithm and sent to the user. After receiving the ciphertext, the user decrypts it using the attribute key issued by the attribute authority at the beginning. Only when the user attributes satisfy the access tree structure can the data be decrypted. Otherwise, it cannot be decrypted. (303) If the user decrypts the plaintext and sends it to the privacy review module, the privacy review module compares the plaintext data with the generated random number. If the two are equal, the user attribute part in this policy meets the authorization requirements. If the user cannot decrypt the data, the privacy module determines that the user attributes do not meet the authorization requirements and sends the determination result to the PDP for subsequent processing.