Lattice-based inner product function encryption method supporting fine-grained revocation, storage medium and equipment
Through the grid-based internal product function encryption method, the problem of fine-grained revocation and forward security in the prior art is solved, and the calculation permission revocation and forward security of user functions in the quantum computing environment is realized to ensure data privacy protection.
Patent Information
- Application Number
- CN202510672097.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-08-05
AI Technical Summary
The existing internal product function encryption scheme cannot achieve fine-grained revocation and forward security, especially in the face of quantum computing attacks, it cannot support the revocation of the user's calculation permissions and prevent the function value of the ciphertext data generated before the revocation by the revocation of the user.
The grid-based internal product function encryption method is adopted to revoke some of the user's function computing capabilities through the stages of system initialization, group administrator initialization, user key generation, function key generation, encryption, decryption, group update, re-encryption key generation, re-encryption, function update and key update, and maintain forward security under quantum computer attacks and conspiracy attacks.
It realizes fine-grained revocation and forward security, and can resist quantum computer attacks and conspiracy attacks, while supporting the revocation of some functions of the user, ensuring that the revoked user cannot calculate the function value of the ciphertext data generated before revocation.
Smart Images

Figure CN120434007A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer security, and mainly relates to a lattice-based inner product function encryption method supporting fine-grained revocation, a storage medium and a device. Background Art
[0002] With the rapid development of cloud computing technology, more and more users are storing their data on third-party cloud servers to reduce storage costs and promote data sharing. To protect user privacy and data security, data is often stored in ciphertext. Traditional public key encryption can maintain data confidentiality, but it does not support selective computation on ciphertext. This means that users can either decrypt the entire plaintext or obtain no information about it. Functional encryption is a new paradigm in public key encryption. In functional encryption, a key is associated with a function. Using the key, users can compute the function value of the ciphertext corresponding to the plaintext data, but cannot obtain any other information about the plaintext data. Inner product functional encryption is a specific type of functional encryption that supports computing the inner product of ciphertext corresponding to plaintext data. In this scheme, the key and ciphertext are each associated with a vector. Using the key, users can decrypt the vector to obtain the inner product of the key and ciphertext. Inner product functional encryption has important applications in machine learning and data mining. For example, in medical data mining, the weighted average is an important indicator of data characteristics. Because medical data contains a large amount of sensitive patient information, encryption is necessary to protect patient privacy during data mining. Inner product function encryption allows authorized users to calculate weighted averages of medical data without leaking it, thereby promoting data sharing while protecting patient privacy. With the development of quantum computing, inner product function encryption schemes based on traditionally difficult problems (such as large prime number factorization and discrete logarithm problems) are threatened. Lattice-based inner product function encryption, due to its resistance to quantum attacks and simple construction, is considered one of the most promising quantum-resistant inner product function encryption schemes.
[0003] In the practical application of inner product function encryption, as users' work tasks adjust, their function computing permissions will change. For example, user u has computing permissions for functions f1, f2, and f3. When their work tasks change, user u's computing permissions for function f1 need to be revoked, which requires fine-grained revocation. However, in the current inner product function encryption scheme that supports revocation, only all user function computing permissions can be revoked; partial revocation of user function computing permissions is not supported, that is, fine-grained revocation is not supported. In addition, in the inner product function encryption scheme that supports revocation, it is necessary to ensure that the revoked user cannot compute functions on the ciphertext data generated before the revocation occurs, that is, forward security. Summary of the Invention
[0004] The present invention is aimed at the problems existing in the prior art and provides a lattice-based inner product function encryption method, storage medium and device that support fine-grained revocation, including a system initialization phase, a group administrator initialization phase, a user key generation phase, a function key generation phase, an encryption phase, a decryption phase, a group update phase, a re-encryption key generation phase, a re-encryption phase, a function update phase and a key update phase. The method of the present invention supports the revocation of part of the user's function computing capability, that is, fine-grained revocation. At the same time, the method of the present invention can achieve forward security while resisting quantum computer attacks and collusion attacks.
[0005] To achieve the above object, the technical solution adopted by the present invention is: a lattice-based inner product function encryption method supporting fine-grained revocation, comprising the following steps:
[0006] S1, system initialization phase: the central agency CA inputs a security parameter 1 λ And the upper bound N of the number of users, output the master private key msk, master public key mpk and system public parameter pp:
[0007] SystemSetup(1 λ ,N)→(msk,mpk,pp);
[0008] S2, group manager initialization phase: the group manager GM inputs the master public key mpk and the system public parameter pp, and outputs the group private key gsk ver and group public key gpk ver :
[0009] GroupSetup(mpk,pp)→(gsk ver ,gpk ver );
[0010] Ver represents the current version number of the system, and the initial system version number is 1;
[0011] S3, User key generation phase: Group administrator GM inputs master private key gsk ver , user identity id and system public parameter pp, output user key usk id :
[0012] UKeyGen(gsk ver ,id,pp)→usk id ;
[0013] S4, function key generation phase: the central agency CA inputs the master private key msk, master public key mpk, and group public key gpk ver , vector x, user identity id and system public parameter pp, output function key fsk x,id,ver :
[0014] FKeyGen(msk,mpk,gpk ver ,x,id,pp)→fsk x,id,ver ;
[0015] S5, encryption stage: the data owner DO inputs the master public key mpk and the group public key gpk ver , vector y and system public parameter pp, output ciphertext CT ver :
[0016] Enc(mpk,gpk ver ,y,pp)→CT ver ;
[0017] S6, Decryption stage: Data user DU inputs ciphertext CT ver 、User key usk id , function key fsk x,id,ver And the system public parameter pp, output inner product<x,y> :
[0018] Dec(CT ver ,usk id ,fsk x,id,ver ,pp)→<x,y> ;
[0019] S7, Group update phase: Group manager GM inputs master public key mpk and group private key gsk ver , group public key gpk ver And the system public parameter pp, output the new version of the group private key gsk ver+1 And the new version of the group public key gpk ver+1 :
[0020] GroupUpdate(mpk,gsk ver ,gpk ver ,pp)→(gsk ver+1 ,gpk ver+1 );
[0021] S8, re-encryption key generation phase: the central agency CA inputs the master private key msk, master public key mpk, and group public key gpk ver and the system public parameter pp, output the re-encryption key rk ver+1 :
[0022] RkGen(msk,mpk,gpk ver ,pp)→rk ver+1 ;
[0023] S9, re-encryption phase: the proxy server PS inputs the re-encryption key rk ver+1 , Ciphertext CT verAnd the system public parameter pp, output the re-encrypted ciphertext CT ver+1 :
[0024] ReEnc(rk ver+1 ,CT ver ,pp)→CT ver+1 ;
[0025] S10, function update phase: the group manager GM inputs the master public key mpk and the group private key gsk ver , group private key gsk ver+1 , vector x, revocation list R x And the system public parameter pp, output update information UPI x,ver+1 :
[0026] FUpdate(mpk,gsk ver ,gsk ver+1 ,x,R x ,pp)→UPI x,ver+1 ;
[0027] S11, key update phase: data user DU inputs user key usk x,id , function key fsk x,id,ver 、Update information UPI x,ver+1 And the system public parameter pp, output the new version of the function key fsk x,id,ver+1 :
[0028] KeyUpdate(usk x,id ,fsk x,id,ver ,UPI x,ver+1 ,pp)→fsk x,id,ver+1 .
[0029] In order to achieve the above-mentioned purpose, the present invention also adopts the following technical solution: a non-temporary machine-readable storage medium having executable code stored thereon, and when the executable code is executed by a processor of an electronic device, the processor executes the lattice-based inner product function encryption method supporting fine-grained revocation as described in claim 1 above.
[0030] In order to achieve the above object, the present invention also adopts a technical solution: a computer device comprising:
[0031] a memory, wherein executable code is stored in the memory;
[0032] The processor is configured to execute the executable code so that the computer device performs the operation of the lattice-based inner product function encryption method supporting fine-grained revocation as claimed in claim 1.
[0033] Compared with the prior art, the present invention has the following beneficial effects:
[0034] (1) In the method of the present invention, the group administrator can revoke part of the user's function computing capabilities, realizing fine-grained revocation.
[0035] (2) In the method of the present invention, the revoked user cannot calculate the function value of the encrypted data generated before the revocation, which achieves forward security.
[0036] (3) The keys of the same user are bound together to resist collusion attacks.
[0037] (4) The security of the method of the present invention is based on the problem of learning with errors (LWE) and can resist quantum computer attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 Flow chart of the steps of the method of the present invention. DETAILED DESCRIPTION
[0039] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.
[0040] Example 1
[0041] Lattice-based inner product function encryption method that supports fine-grained revocation, such as Figure 1 As shown, the following steps are included:
[0042] Step S1, system initialization phase:
[0043] The central authority CA enters a security parameter 1 λ And the upper bound N of the number of users, output the master private key msk, the master public key mpk and the system public parameter pp, that is
[0044] SystemSetup(1 λ ,N)→(msk,mpk,pp);
[0045] The central authority CA enters a security parameter 1 λ and the upper bound N of the number of users, select integers n,l1,X,Y, prime numbers Among them, real numbers Integer m≥2nlog p, k≥2,. Then, let q=p k ,l2=N+1,K=l1XY, gather and The central agency CA selects real numbers Next, the central authority CA selects a hash function and pseudorandom functions
[0046] Then, let pd be an initially empty public list, and the central agency CA runs the trapdoor generation algorithm TrapGen (1 n ,1 m )→(A,T A ) and randomly select The system's master private key msk=(T A ,k p ), the master public key mpk=(A,C), and the public parameters of the system are pp=(n,m,l1,l2,p,q,k,ρ1,ρ2,σ1,σ2,pd,H1,H2,PRF).
[0047] Among them, the trapdoor generation algorithm TrapGen(1 n ,1 m )→(A,T A ):
[0048] For any prime number p and integer n, m ≥ O(nlog p), the algorithm outputs a matrix Passive A short base T A ,in
[0049] Step S2: Group administrator initialization phase:
[0050] The group manager GM inputs the master public key mpk and the system public parameter pp, and outputs the group private key gsk ver , group public key gpk ver ,
[0051] GroupSetup(mpk,pp)→(gsk ver ,gpk ver ),
[0052] Ver represents the system version number.
[0053] Group administrator GM selection and calculate
[0054]
[0055] Finally, let the group private key gsk ver =(D,B ver ), group public key gpk ver =(F,U ver ), where ver=1.
[0056] Step S3: User key generation phase:
[0057] Group administrator GM enters the master private key gsk ver , user identity id and system public parameter pp, output user key usk id ,Right now
[0058] UKeyGen(gsk ver ,id,pp)→usk id ;
[0059] For user identity id, group manager GM calculates
[0060]
[0061] And the user key usk x,id =(id,u x,id ) is sent to the data user DU.
[0062] Step S4, function key generation phase:
[0063] The central authority CA inputs the master private key msk, master public key mpk, and group public key gpk ver , vector x, user identity id and system public parameter pp, output function key fsk x,id,ver ,Right now
[0064] FKeyGen(msk,mpk,gpk ver ,x,id,pp)→fsk x,id,ver ;
[0065] for User identity id, the central agency CA first runs the original image sampling algorithm SamplePre(A,T A ,C+U ver ,ρ1)→Z ver and calculate
[0066]
[0067] Among them, the original image sampling algorithm SamplePre(A,T A ,U,s)→Z
[0068] Given a prime number p, an integer n, m ≥ O(nlog p), the algorithm takes as input the matrix Trapdoor T A ,matrix and real numbers Output Matrix Where U = A·Z and Z follows the distribution
[0069] Then, the central authority CA calculates
[0070]
[0071] where v x,id = <id,t x >mod p.
[0072] if The central authority CA randomly selects calculate
[0073]
[0074] And (pd x,1 ,pd x,2 ) is stored in the public list pd. Finally, the central agency CA sends the function key fsk x,id,ver =(x,f x,id,ver ) to the data user DU.
[0075] Step S5, encryption phase:
[0076] The data owner DO inputs the master public key mpk and group public key gpk ver , vector y and system public parameter pp, output ciphertext CT ver ,Right now
[0077] Enc(mpk,gpk ver ,y,pp)→CT ver ;
[0078] For vector Data owner DO is randomly selected and calculate
[0079]
[0080] Finally, the data owner DO uploads CT ver =(c ver,1 ,c ver,2 ) to the proxy server PS.
[0081] Step S6, decryption stage:
[0082] Data user DU inputs ciphertext CT ver 、User key usk id , function key fsk x,id,ver And the system public parameter pp, output inner product<x,y> ,Right now
[0083] Dec(CT ver ,usk id ,fsk x,id,ver ,pp)→<x,y> ;
[0084] For ciphertext CT ver =(c ver,1 ,c ver,2 ), user key usk x,id =(id,u id ), function key fsk x,id,ver =(x,f x,id,ver ) and the public list pd, the data user DU first calculates
[0085]
[0086] And output where θ is such that |p k-1 ·θ-θ′| is the minimum value. Then, the data user DU calculates
[0087]
[0088] And output μ∈{0,…,K}, where μ makes is the minimum value.
[0089] Step S7, group update phase:
[0090] The group administrator GM enters the master public key mpk and the group private key gsk ver , group public key gpk ver And the system public parameter pp, output the new version of the group private key gsk ver+1 And the new version of the group public key gpk ver+1 ,Right now
[0091] GroupUpdate(mpk,gsk ver ,gpk ver ,pp)→(gsk ver+1 ,gpk ver+1 );
[0092] The group manager GM randomly selects and calculate Then, the group manager GM makes the group private key gsk ver+1 =(D,B ver+1 ), group public key gpk ver+1 =(F,U ver+1 ) and update the system version number ver=ver+1.
[0093] Step S8: Re-encryption key generation phase
[0094] Re-encryption key generation phase: The central authority CA inputs the master private key msk, master public key mpk, and group public key gpk verand the system public parameter pp, output the re-encryption key rk ver+1 ,Right now
[0095] RkGen(msk,mpk,gpk ver ,pp)→rk ver+1 ;
[0096] The central agency CA first runs the original image sampling algorithm SamplePre(A,T A ,C+U ver ,ρ1)→Z ver and randomly select Calculate the re-encryption key
[0097]
[0098] in Finally, the central authority CA re-encrypts the key rk ver+1 Sent to the proxy server PS.
[0099] Among them, PowerT p (y):
[0100] Given a vector Output
[0101] Step S9, re-encryption phase:
[0102] Proxy server PS input re-encryption key rk ver+1 , Ciphertext CT ver And the system public parameter pp, output the re-encrypted ciphertext CT ver+1 ,Right now
[0103] ReEnc(rk ver+1 ,CT ver ,pp)→CT ver+1 ;
[0104] For the re-encryption key rk ver+1 and ciphertext CT ver =(c ver,1 ,c ver,2 ), proxy server PS calculation:
[0105]
[0106] And output CT ver+1 =(c ver+1,1 ,c ver+1,2 ).
[0107] Among them, BitD p (x):
[0108] Given a vector Let x i ∈{0,1} n Make Output
[0109] For any have<x,y> = <BitD p (x),PowerT p (y)>(mod p).
[0110] Step S10, function update phase:
[0111] Function update phase: Group administrator GM inputs master public key mpk and group private key gsk ver , group private key gsk ver+1 , vector x, revocation list R x And the system public parameter pp, output update information UPI x,ver+1 ,Right now
[0112] FUpdate(mpk,gsk ver ,gsk ver+1 ,x,R x ,pp)→UPI x,ver+1 ;
[0113] Given a vector and the revocation list R x , the group manager GM first calculates So that for all id∈R x ,have Then, the group manager GM randomly selects calculate
[0114]
[0115] Where bin((B ver+1 -B ver )·x) represents (B ver+1 -B ver ) x in binary form. Finally, send the update information To all data users DU.
[0116] Step S11, key update phase:
[0117] Data user DU enters user key usk id , function key fsk x,id,ver 、Update information UPI x,ver+1 And the system public parameter pp, output the new version of the function key fsk x,id,ver+1 ,Right now
[0118] KeyUpdate(usk id ,fsk x,id,ver ,UPI x,ver+1 ,pp)→fsk x,id,ver+1 ;
[0119] For user key usk id =(id,u x,id ), function key and update information The data user DU first calculates
[0120]
[0121] And output in Make|p k-1 ·ν-ν′| is the minimum value.
[0122] Further calculation
[0123]
[0124] f x,id,ver+1 =f x,id,ver +(B ver+1 -B ver )·x,
[0125] Where bin((B ver+1 -B ver )·x) represents (B ver+1 -B ver )·x in binary form. Finally, the data user DU outputs the updated function key fsk x,id,ver+1 =(x,f x,id,ver+1 ).
[0126] It should be noted that the above content merely illustrates the technical idea of the present invention and cannot be used to limit the scope of protection of the present invention. For ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications all fall within the scope of protection of the claims of the present invention.
Claims
1. A lattice-based inner product function encryption method that supports fine-grained revocation, characterized by , including the following steps: S1, system initialization phase: the central agency CA inputs a security parameter 1 λ And the upper bound N of the number of users, output the master private key msk, master public key mpk and system public parameter pp: SystemSetup(1 λ ,N)→(msk,mpk,pp); S2, group manager initialization phase: the group manager GM inputs the master public key mpk and the system public parameter pp, and outputs the group private key gsk ver and group public key gpk ver : GroupSetup(mpk,pp)→(gsk ver ,gpk ver ); Ver represents the current system version number, and the initial system version number is 1; S3, User key generation phase: Group administrator GM inputs master private key gsk ver , user identity id and system public parameter pp, output user key usk id : UKeyGen(gsk ver ,id,pp)→usk id ; S4, function key generation phase: the central agency CA inputs the master private key msk, master public key mpk, and group public key gpk ver , vector x, user identity id and system public parameter pp, output function key fsk x,id,ver : FKeyGen(msk,mpk,gpk ver ,x,id,pp)→fsk x,id,ver ; S5, encryption phase: the data owner DO inputs the master public key mpk and the group public key gpk ver , vector y and system public parameter pp, output ciphertext CT ver : Enc(mpk,gpk ver ,y,pp)→CT ver ; S6, Decryption stage: Data user DU inputs ciphertext CT ver 、User key usk id , function key fsk x,id,ver And the system public parameter pp, output inner product<x,y> : Dec(CT ver ,usk id ,fsk x,id,ver ,pp)→<x,y>; S7, Group update phase: Group manager GM inputs master public key mpk and group private key gsk ver , group public key gpk ver And the system public parameter pp, output the new version of the group private key gsk ver+1 And the new version of the group public key gpk ver+1 : GroupUpdate(mpk,gsk ver ,gpk ver ,pp)→(gsk ver+1 ,gpk ver+1 ); S8, re-encryption key generation phase: the central agency CA inputs the master private key msk, master public key mpk, and group public key gpk ver and the system public parameter pp, output the re-encryption key rk ver+1 : RkGen(msk,mpk,gpk ver ,pp)→rk ver+1 ; S9, re-encryption phase: the proxy server PS inputs the re-encryption key rk ver+1 , Ciphertext CT ver And the system public parameter pp, output the re-encrypted ciphertext CT ver+1 : ReEnc(rk ver+1 ,CT ver ,pp)→CT ver+1 ; S10, function update phase: the group manager GM inputs the master public key mpk and the group private key gsk ver , group private key gsk ver+1 , vector x, revocation list R x And the system public parameter pp, output update information UPI x,ver+1 : FUpdate(mpk,gsk ver ,gsk ver+1 ,x,R x ,pp)→UPI x,ver+1 ; S11, key update phase: data user DU inputs user key usk x,id , function key fsk x,id,ver 、Update information UPI x,ver+1 And the system public parameter pp, output the new version of the function key fsk x,id,ver+1 : KeyUpdate(usk x,id ,fsk x,id,ver ,UPI x,ver+1 ,pp)→fsk x,id,ver+1 。 2. A non-transitory machine-readable storage medium, characterized in that: Executable codes are stored thereon, and when the executable codes are executed by a processor of an electronic device, the processor is caused to execute the lattice-based inner product function encryption method supporting fine-grained revocation as claimed in claim 1.
3. A computer device, characterized in that: include: a memory, wherein executable code is stored in the memory; The processor is configured to execute the executable code so that the computer device performs the operation of the lattice-based inner product function encryption method supporting fine-grained revocation as claimed in claim 1.