Privacy security protection method based on multi-authority attribute encryption
Through (t,n) threshold access control and Lagrangian difference method combined with bilinear mapping of combined number-order bilinear groups, the efficient encryption and decryption and decentralization of multi-authority attribute encryption schemes in electronic medical care in the prior art is solved, and high security privacy data protection is achieved.
Patent Information
- Application Number
- CN202510268385.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-07-29
AI Technical Summary
The existing multi-authoritative attribute-based encryption solutions cannot achieve efficient encryption and decryption in electronic medical care and achieve high security decentralization, resulting in an increased risk of patient privacy data leakage.
The (t,n) threshold access control structure and Lagrangian difference method are used to combine the combined order bilinear group and symmetric combined order bilinear mapping to achieve efficient encryption and decryption and selection security. By setting the private and public keys with the attribute authoritative, the key of the attribute in the access rights of the information recipient is generated, and data encryption and decryption are performed.
It realizes an efficient encryption and decryption process in distributed electronic medical systems, while ensuring high security decentralization and protecting patient privacy data from being leaked.
Smart Images

Figure CN120387173A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of electronic medical technology, and particularly to a privacy and security protection method based on multi-authority attribute encryption. Background Art
[0002] In recent years, with the development of Internet of Things (IoT) technology, eHealthcare has received extensive attention. In eHealthcare applications, hospitals and other medical centers collect information such as patients' body temperature and blood pressure through IoT devices, and then transmit this information to doctors. Based on the transmitted information, doctors can timely judge the patients' health conditions and give corresponding solutions. EHealthcare can timely monitor the physical conditions of patients and effectively guarantee people's physical health.
[0003] Due to the large number of patients, medical centers (HCs) cannot afford such a huge amount of data and computing, so cloud servers are usually used in eHealthcare. Although using a third-party cloud server can effectively reduce the burden of computing and storing data, it also brings data security problems. Since cloud servers are provided by untrusted or semi-trusted third parties, these third parties may steal data during the data transmission process, resulting in the leakage of patients' privacy. Encryption is the key to protecting personal medical information. Compared with traditional encryption algorithms, attribute-based encryption (ABE) can encrypt data and achieve fine-grained access control with less computing and storage resources, so it has received extensive attention.
[0004] In order to provide services to more patients, medical centers can set up multiple medical institutions at different locations, that is, a distributed eHealthcare system. In a distributed eHealthcare system, patients can receive medical services from different regions and different hospitals. This greatly improves the medical services enjoyed by patients.
[0005] However, there are many problems in existing multi-authority attribute-based encryption schemes. First, the data in eHealthcare contains a large amount of private data, so multi-authority attribute encryption with high security (chosen security under the random oracle model) is required; second, since the patients' conditions need to be monitored in real time, multi-authority attribute encryption needs to achieve efficient encryption and decryption; finally, due to the distributed scenario, multi-authority attribute encryption needs to be decentralized. Existing research does not have a decentralized multi-authority attribute encryption scheme that can achieve efficient encryption and decryption while achieving high security, so a secure and efficient decentralized multi-authority attribute-based encryption method is needed. Summary of the Invention
[0006] Object of the Invention: In order to solve the problems existing in the above-mentioned prior art, the present invention provides a privacy and security protection method based on multi-authority attribute encryption.
[0007] Technical solution: The present invention provides a privacy and security protection method based on multi-authority attribute encryption, which specifically includes the following steps:
[0008] Step 1: Set global parameters GP based on the symmetric composite-order bilinear mapping e;
[0009] Step 2: Set the private key SK and public key K A of the attribute authority k; and keep the private key confidential and make the public key public;
[0010] Step 3: Generate the key D of the i-th attribute in the access permission of the information recipient u based on the threshold access policy k,i , i = 1, 2,..., I, where I represents the k total number of attributes in A k , and A
[0011] is the set of attributes controlled by the attribute authority k; N Step 4: The information sender selects a random number s in Z k,i , encrypts the plaintext information of the information sender based on the random number to obtain the encrypted ciphertext E, and encrypts the i-th attribute belonging to the attribute authority k in the ciphertext sent by the information sender to obtain the ciphertext E k,i ; Combine E and E N to form the final ciphertext C; Z
[0012] represents the integer group of order N; N = p1p2p3, where p1, p2, and p3 are three different large prime numbers;
[0013] Step 5: When a certain information recipient needs to obtain the information sent by the information sender, the information recipient decrypts the ciphertext C to obtain relevant information. Furthermore, the global parameter GP in Step 1 = (e, N, g1, g3, H), where the symmetric composite-order bilinear mapping e: G1×G1→G3, G1 and G3 are composite-order bilinear groups of order N, g1 and g3 are the generators of the subgroups and of the group G1,
[0014] Furthermore, for the i-th attribute in A k , randomly select two numbers in Z N and denote them as t k,i , r k,i , and randomly select a number in Z N for the attribute authority k and denote it as yk ; According to making t k,i , r k,i and y k Set the private key SK of the attribute authority k A and the public key K A :
[0015] SK A =(y k , t k,i , r k,i )
[0016] K A =(Y k , T k,i , R k,i )
[0017] Among them, the expressions of Y k , T k,i , R k,i are as follows:
[0018]
[0019] Furthermore, step 3 is specifically: For the i-th attribute controlled by the attribute authority k, randomly select a polynomial p k of degree d k (i), d k represents the threshold of the attribute authority k, and 1 ≤ d k ≤ |A k |. For the key D k,i of the attribute i in the access permission of the information receiver u, the expression is:
[0020]
[0021] Among them, GID u represents the global identity identifier of the information receiver u.
[0022] Furthermore, in step 4, the plaintext M to be encrypted is encrypted using the following formula:
[0023]
[0024] Among them, K represents the total number of authoritative attributes.
[0025] Furthermore, in step 4, the information sender randomly selects K polynomials q1, q2,..., q k ,..., q K of degrees d1, d2,..., d k ,..., q K , d k represents the threshold of the attribute authority k, 1 ≤ dk ≤|A k |, and q1, q2, …, q k , …, q K satisfy the following conditions:
[0026] q1(0) + q2(0) + … + q K (0) = 0
[0027] q K (0) represents the calculation result of a polynomial of degree d when i = 0 K .
[0028] For the ciphertext sent by the information sender, the ciphertext E of attribute i belonging to attribute authority k is calculated using the following formula k,i :
[0029]
[0030] where q(i) = q1(i) + q2(i) + … + q K (i), and q K (i) represents the calculation result of a polynomial of degree d corresponding to the i-th attribute K .
[0031] Furthermore, step 6 is specifically as follows: If all the authoritative attributes of information receiver u satisfy: then information receiver u can obtain e(D k,j , E k,j ), j = 1, 2, …, J, where J is the total number of attributes in the set , and then use the Lagrange interpolation method to simplify all e(D k,j , E k,j ) to obtain the following formula:
[0032]
[0033] where K represents the total number of attribute authorities represents the set of all attributes controlled by attribute authority k in the ciphertext of the information sender represents the set of attributes controlled by attribute authority k in the access control privilege of information receiver u;
[0034] Information receiver u obtains the decrypted plaintext M:
[0035]
[0036] Beneficial effects: The present invention realizes efficient encryption and decryption by using the (t,n) threshold access control structure and Lagrange interpolation; and realizes selective security under the random oracle model by using composite-order bilinear groups and symmetric composite-order bilinear maps. The encryption scheme proposed by the present invention realizes high-security decentralization while achieving efficient encryption and decryption. Brief Description of the Drawings
[0037] Figure 1 is the flowchart of the method of the present invention;
[0038] Figure 2 is the system structure diagram of the present invention applied to the distributed electronic medical service scenario. Detailed Embodiments
[0039] The accompanying drawings that form a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention.
[0040] As Figure 1 shown, the present invention mainly includes eight parts: system setup, attribute authority public and private key generation, data user key generation, data encryption, re-encryption key generation, re-encryption, initial ciphertext decryption, and re-encryption ciphertext decryption. The specific process is as follows:
[0041] System setup ((λ) → GP): where λ represents system parameters and GP represents global parameters. The groups G1 and G3 are composite-order bilinear groups of order N = p1p2p3, where p1, p2, and p3 are three distinct large prime numbers, respectively represent subgroups of order p1, p2, and p3 in the group G1. Let e represent a symmetric composite-order bilinear map, e: G1 × G1 → G3. Let g1 and g3 be the generators of the subgroups and respectively, randomly select a hash function:
[0042]
[0043] This means that the hash function H can map the global identity GID of the doctor to an element in the subgroup . Finally, output the global parameters GP = (e, N, g1, g3, H), {0,1} * represents a long string.
[0044] Attribute authority setup ((GP) → PK A , SK A ): For each attribute authority k, let A k represent the set of all attributes controlled by the attribute authority k. Each attribute authority selects a random number yk , y k ∈Z N , Z N represents the integer group of order N. Then, for each attribute i in A k , two random numbers t N and r k,i are selected in Z k,i . Then, the attribute authority k calculates the private key SK A and the public key K A :
[0045]
[0046] Wherein,
[0047] The attribute authority k keeps SK A confidential and makes PK A public.
[0048] Key Generation ((GP, GID, {d k}}, {i}, SK A ) → D k,i ): Since for any attribute authority k in the (t, n)-threshold access structure, the size of the threshold d k of the attribute authority k needs to satisfy 1 ≤ d k ≤ |A k |. Therefore, when generating the key of doctor u, the attribute authority k randomly selects a polynomial p k of degree d k - 1, and makes the value of p k (i) at i = 0 be y k . Then, for each key of the attribute i belonging to the attribute authority k in the access permission of doctor u:
[0049]
[0050] Wherein, GID u represents the global identity identifier of doctor u.
[0051] Encryption Let represent the set of all attributes controlled by the attribute authority k in the generated ciphertext sent by the patient. The patient selects a random number s in Z N . For the plaintext M to be encrypted, the patient calculates the encrypted ciphertext:
[0052]
[0053] Then, the patient randomly selects K polynomials of degrees d1, d2,..., d k,…d K Polynomials q1, q2, …, q K , d k Denote the threshold of the attribute authority k, and let:
[0054] q = q1 + q2 + … + q K
[0055] where
[0056] q(0) = q1(0) + q2(0) + … + q K (0) = 0
[0057] Then for each attribute authority k and all attributes i of all patients belonging to that attribute authority k, calculate the encrypted ciphertext E k,i :
[0058]
[0059] The final output ciphertext M is:
[0060] C = (E, E k,i )
[0061] Decryption ((C, {d k}, {D k,i}, GP) → M): Let denote the set of attributes belonging to the attribute authority k in the access control privilege of doctor u. For all attribute authorities k, if it satisfies:
[0062]
[0063] That is, the access control privilege of the doctor satisfies the patient's attributes, then doctor u can calculate and obtain
[0064]
[0065] Then according to the Lagrange interpolation formula, doctor u who meets the conditions can calculate and obtain:
[0066]
[0067] Finally, doctor u can decrypt the plaintext:
[0068]
[0069] The system structure of the application scenario of this embodiment, the distributed electronic medical service scenario, is as Figure 2 shown, and the specific structure is as follows:
[0070] (1) Patient: In the proposed system model, patients send and store relevant information needed for diagnosis, such as past electronic medical records and various examination data (body temperature, blood routine), to a third-party cloud server. Obviously, this data contains a large amount of patient privacy information. In order to prevent the leakage of patients' privacy data, this data needs to be encrypted before being sent and stored. Generally speaking, patients are completely trustworthy in this process.
[0071] (2) Cloud Server: Since each diagnosis of a patient requires the storage of encrypted data, hospitals cannot afford such a large amount of storage space on their own. Therefore, hospitals usually choose to use third-party cloud servers to store patients' encrypted data. The cloud server will store the patient's encrypted data after receiving it, and doctors can download this encrypted data from the cloud server. Since cloud storage services are provided by third-party cloud service providers, cloud servers are generally considered semi-trusted.
[0072] (3) Attribute Authority: The attribute authority is the core part of the distributed electronic medical system. It is responsible for managing the attributes of each patient and generating keys for authorized doctors. The patient encrypts the corresponding data based on the attributes assigned to him by the attribute authority and sends it to the cloud server. In the distributed electronic medical system, since patients and doctors involved in diagnosis are managed by multiple departments in multiple regions, there are multiple attribute authorities responsible for managing patient attributes and generating keys. These attribute authorities are responsible for managing their own attributes. There is no data exchange between them, and their status is equal. There is no central attribute authority.
[0073] (4) Doctors: In a distributed electronic medical system, doctors are user users. When a patient needs to be diagnosed, the hospital determines the list of doctors participating in the diagnosis, and then the attribute authority assigns a specific access policy based on the patient's attributes and the list of doctors. According to the access policy, the doctors participating in the diagnosis can obtain the key to decrypt the user's ciphertext. If a doctor wants to obtain encrypted information from different patients, he must have the keys to the access policies corresponding to all these patients. And the doctor must be a legitimate doctor participating in the diagnosis to obtain a specific access policy and the corresponding key. Therefore, in this system model, the privacy and security of the patient are well protected.
[0074] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any appropriate manner without contradiction. To avoid unnecessary repetition, the present invention will not further describe various possible combinations.
Claims
1. A privacy and security protection method based on multi-authority attribute encryption, characterized in that, Specifically, it includes the following steps: Step 1: Set global parameters GP based on the symmetric composite order bilinear mapping e; Step 2: Set the private key SK of the attribute authority k A and the public key K A ; keep the private key confidential and make the public key public; Step 3: Generate the key \(D\) of attribute \(i\) in the access privilege of information receiver \(u\) based on the threshold access policy k,i , where \(i = 1, 2, \ldots, I\), and \(I\) represents k the total number of attributes in \(A\), k and \(A\) is the set of attributes controlled by attribute authority \(k\); Step 4: The information sender selects a random number s in Z N , encrypts the plaintext information of the information sender based on the random number to obtain the encrypted ciphertext E, and encrypts the i-th attribute belonging to the attribute authority k in the ciphertext sent by the information sender to obtain the ciphertext E k,i ; Combine E and E k,i to form the final ciphertext C; Z N represents an integer group of order N; N = p1p2p3, where p1, p2, and p3 are three distinct large prime numbers; Step 5: When a certain information recipient needs to obtain the information sent by the information sender, the information recipient decrypts the ciphertext C to obtain relevant information.
2. The privacy and security protection method based on multi-authority attribute encryption according to claim 1, wherein The global parameter GP in the step 1 is GP = (e, B, g1, g3, H), where the symmetric composite order bilinear map e: G1×G1→G3, G1 and G3 are composite order bilinear groups of order N, and g1 and g3 are the and generators of the subgroups which is a subgroup of order p1 in the group G1, which is a subgroup of order p3 in the group G3, and H represents a hash function that can map the global identity GID of the information recipient to an element in the subgroup 3. The privacy and security protection method based on multi-authority attribute encryption according to claim 2, characterized in that, For A k For the i-th attribute in N Randomly select two numbers in Z and denote them as t k,i , r k,i ; for the attribute authority k, randomly select a number in Z N and denote it as y k ; according to t k,i , r k,i and y k set the private key SK A and the public key K A of the attribute authority k: SK A =(y k ,t k,i ,r k,i ) K A = (Y k , T k,i , R k,i ) Among them, Y k , T k,i , R k,i The expressions of are as follows:
4. A privacy and security protection method based on multi-authority attribute encryption according to claim 3, characterized in that, Step 3 specifically is: For the \(i\)-th attribute controlled by the attribute authority \(k\), randomly select a polynomial \(p\) of degree \(d - 1\), where \(d\) represents the threshold of the attribute authority \(k\), and \(1\leq d\leq|A|\). For the key \(D\) of attribute \(i\) in the access permission of the information receiver \(u\), the expression is: k -th degree polynomial \(p\) k (i), \(d\) k represents the threshold of the attribute authority \(k\), and \(1\leq d\) k \(\leq|A|\) k |. For the key \(D\) of attribute \(i\) in the access permission of the information receiver \(u\) k,i the expression is: Among them, GID u represents the global identity of the information receiver u.
5. A privacy and security protection method based on multi-authority attribute encryption according to claim 3, characterized in that, In Step 4, the plaintext M to be encrypted is encrypted using the following formula: Where K represents the total number of authoritative attributes.
6. A privacy and security protection method based on multi-authority attribute encryption according to claim 3, characterized in that, In step 4, the information sender randomly selects K polynomials q1, q2, …, q k , …, q K with degrees d1, d2, …, d k , …, d K , where d k represents the threshold of the attribute authority k, 1 ≤ d k ≤ |A k |, and q1, q2, …, q k , …, q K satisfy the following conditions: q1(0)+q2(0)+…+q K (0) = 0 q K (0) represents the calculation result of a polynomial of order d when i = 0 K For the ciphertext sent by the information sender, the ciphertext E of attribute i belonging to attribute authority k is calculated using the following formula k,i : where q(i) = q1(i) + q2(i) + … + q K (i), q K (i) represents the calculation result of a polynomial of order d corresponding to the i-th attribute K .
7. A privacy and security protection method based on multi-authority attribute encryption according to claim 3, characterized in that, The specific content of step 6 is as follows: If all the authoritative attributes of the information receiver u satisfy: then the information receiver u can obtain e(D k,j , E k,j ), j = 1, 2, …, J, where J is the total number of attributes in the set , and then the Lagrange interpolation method is used to simplify all e(D k,j , E k,j ) to obtain the following formula: where K represents the total number of attribute authorities, represents the set of all attributes controlled by the attribute authority k in the ciphertext of the information sender, represents the set of attributes controlled by the attribute authority k in the access control privilege of the information recipient u; The information recipient u obtains the decrypted plaintext M: