Anonymous and keyword-guessing-attack-resistant attribute-based rapid ciphertext retrieval method
By introducing the attribute part hidden structure and public key authentication keyword search, the problems of attribute leakage and keyword guessing attacks in attribute-based searchable encryption are solved, and efficient and flexible access control and privacy protection are achieved, which is suitable for cloud storage environments in multi-permission collaboration scenarios.
Patent Information
- Application Number
- CN202510594752.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-08-15
AI Technical Summary
The existing attribute-based searchable encryption scheme has the problems of attribute information leakage and susceptibility to keyword guessing attacks, and cannot support flexible access control policies, making it difficult to meet the needs of high efficiency and privacy protection.
The attribute partial hidden structure and random segmentation technology are used, combined with public key authentication keyword search, and the user key and data owner public and private key pairs are generated. Through partial hidden attribute values and keyword matching, a fast ciphertext retrieval that resists keyword guessing attacks is achieved.
While maintaining polynomial-level computing efficiency, it hides sensitive attributes, resists keyword guessing attacks, and supports the combined and disjunction access control policies of any monotonic Boolean formula, improving retrieval efficiency and security.
Smart Images

Figure CN120498647A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of searchable encryption technology in network security, and in particular to an attribute-based rapid ciphertext retrieval method that is anonymous and resistant to keyword guessing attacks. Background Art
[0002] With the rapid adoption of cloud storage services, global data is migrating to the cloud at an exponential rate. While this revolution in storage paradigms unlocks business potential, it also exposes a critical pain point: the structural contradiction between encrypted data and business utility. While traditional encryption mechanisms can provide a data protection barrier, they render cloud data unretrievable as "dark data," severely restricting enterprises' development and utilization of core data assets. Enabling secure and controllable data retrieval in a ciphertext environment has become a key issue in the evolution of cloud storage in the digital age, leading to the emergence of searchable encryption technology. Song et al. first proposed the concept of searchable encryption, enabling users to perform keyword searches in the ciphertext domain. When data is stored in ciphertext on cloud servers, keyword searches can be performed using the powerful computing power of cloud servers. This not only effectively protects user privacy but also significantly improves retrieval efficiency. However, symmetric searchable encryption suffers from complex key management and, in multi-user scenarios, requires a key distribution protocol, which can introduce additional risks. Boneh et al. proposed the concept of PEKS, or asymmetric public key searchable encryption, which significantly simplifies key management. Byun et al. revealed a vulnerability in the PEKS system known as a keyword guessing attack (KGA), which allows attackers to exploit the limited keyword space to perform offline exhaustive searches. Several methods have been proposed to combat this attack, including fuzzy keyword search, designated server, dual server, registered keyword search, public key authenticated keyword search, and secure channelless keyword search. Public key authenticated keyword search is a very promising technique. The data sender not only encrypts the keyword but also authenticates the encrypted index. This ensures that the verifier can only generate the encrypted keyword from the sender, preventing the adversary from encrypting it and launching an offline keyword guessing attack. We introduce this technique to prevent keyword guessing attacks.
[0003] In some scenarios, where collaboration among multiple users with multiple permissions is required, more fine-grained access control over encrypted data is necessary. Zheng et al. first constructed a verifiable attribute-based public-key searchable encryption (ABSE) scheme to implement policy-driven fine-grained retrieval. Its innovative verification mechanism ensures that cloud servers faithfully execute retrieval operations. However, ABSE schemes are generally subject to attribute privacy leakage risks. In other words, the ciphertext, key, attribute values in the trapdoor, and access control policies in the scheme are exposed in plaintext. For example, when applied to sensitive scenarios such as medical record sharing, exposing attribute metadata such as "diagnostic department" and "job level" may still pose a privacy risk.
[0004] Numerous studies have addressed the risk of attribute metadata leakage. Wang et al. proposed a scheme that hides access policies and optimizes search performance, agnostic to multiple values and with constant storage overhead. Chaudhari et al. proposed keySey, which hides access policies and optimizes search time. The number of pairing operations is minimized and constant regardless of the number of attributes in the access policy. Miao et al. proposed the ABKS-SM system, which protects privacy, hides access policies, and tracks malicious data users in shared multi-owner settings. However, these attribute-based searchable encryption schemes only support AND gate access control structures. The search algorithm in Miao et al.'s scheme requires a large number of bilinear pairing operations, which increases linearly with the number of attributes. Overall, current research on attribute-based searchable encryption that hides attributes or policies can only support AND gate access control policies, significantly limiting the flexibility of access control policies. Schemes that support conjunctions and disjunctions of any monotone Boolean formulas have so far only appeared in the ABE scheme. Katz et al. proposed inner product encryption (IPE), which can fully protect the privacy of attribute sets without leaking any information. However, this results in a superpolynomial increase in the size of the ciphertext and trapdoor, significantly increasing communication overhead, making it extremely inefficient and difficult to deploy in practice. The partially hidden structure introduced by Meng et al. addresses the attribute exposure issue in traditional ABE. This method hides attribute values by exposing attribute names. This method hides attribute values by matching attribute names first and then matching attribute values. It also uses a random splitting technique to prevent the vulnerability to attribute guessing attacks common in existing KP-ABE. Although this method exposes attribute names, such as the title in "Title: Professor," simply exposing the attribute name of "Title" is not that significant, and it is far more efficient than IPE techniques. Therefore, I introduced a partially hidden structure and random splitting technique to address the attribute exposure issue in traditional KP-ABSE. This method can hide sensitive attributes while maintaining polynomial-level computational efficiency, making it significantly more feasible than IPE solutions.
[0005] In terms of performance optimization, Riepel et al. demonstrated breakthrough progress in their attribute-based scheme, implemented using a multi-challenge ciphertext architecture. This provides a new paradigm for building efficient attribute-based searchable encryption systems. In particular, translating theoretical results from the random oracle model into practical algorithms can significantly reduce the computational overhead of policy matching. We have transformed this into a fast attribute-based searchable encryption algorithm, which is significantly more efficient than existing attribute-based searchable encryption algorithms.
[0006] Attribute-based searchable encryption (ABSE) offers unique advantages in multi-authority collaboration scenarios, such as medical data collaboration, through its fine-grained access control mechanism. These scenarios require not only privacy protection for encrypted message content but also mitigation of attribute metadata leakage risks. This requires ensuring that sensitive information, such as patient diagnostic records, cannot be accessed by unauthorized parties, while preventing attribute information, such as physician titles and department affiliations, from exposing access policy structures.
[0007] However, existing research has significant flaws in achieving dual privacy protection: First, most schemes focus solely on ciphertext indistinguishability while ignoring the security risks involved in trapdoor generation, allowing attackers to infer keyword information through statistical analysis. Second, mainstream ABSE schemes still rely on the early attribute-based encryption framework, resulting in encryption and decryption time increasing linearly with attribute size, making it difficult to meet the efficiency requirements of real-time clinical collaboration. More critically, most existing technologies fail to achieve attribute anonymization, and sensitive attributes remain in plaintext within ciphertext policies, creating security risks such as traceable access patterns. Even though a few schemes can achieve anonymous attribute-based searchable encryption, these schemes cannot support access control policies based on conjunctions and disjunctions of any monotone Boolean formula, but can only support access control policies based on AND gates, which greatly limits the flexibility of access control policies.
[0008] Therefore, there is an urgent need to construct an attribute-based searchable encryption scheme that is anonymous and resistant to keyword guessing attacks, improve the overall efficiency of the algorithm, and support access control strategies for conjunctions and disjunctions of any monotone Boolean formulas. Summary of the Invention
[0009] In view of this, the present invention is based on the attribute-based public key cryptography theory and provides an anonymous attribute-based fast ciphertext retrieval method that is resistant to keyword guessing attacks, so as to at least solve the above technical problems.
[0010] The embodiment of the present invention provides an anonymous attribute-based rapid ciphertext retrieval method that is resistant to keyword guessing attacks, including: step S1, system establishment, generation of master key and system parameters: the authorization center initializes the system, selects and inputs security parameter λ, generates system public parameter PP and master key MK, and broadcasts the system public parameter PP; step S2, key generation phase: the authorization center receives a key application request from a data user, inputs the system public parameter PP and master key MK, and inputs an access control structure A according to the attribute permissions of the data user to generate a user key sk u And send it to the data user, the data owner generates the public and private key pair (pk o ,sk o ); Step S3, encryption index generation phase: the data owner enters the system public parameter PP, the data owner's private key sko , attribute set S and keyword w, output and upload the searchable encrypted index ct to the cloud server. Step S4, searchable trapdoor generation phase: data users input the public key pk of the data owner o , user key sk of the data user u and keyword w, output and send the searchable trapdoor tw to the cloud server to obtain search results; step S5, matching stage: the cloud server inputs the received searchable trapdoor tw and matches it with the searchable encrypted index. If the attribute set in the searchable encrypted index meets the access control policy in the trapdoor and the keyword matches, a success result is returned, otherwise a failure result is returned.
[0011] Optionally, the step S1 specifically includes: step S11, the authorization center selects a security parameter λ, generates a system public parameter PP, defines G1, G2 and G T are three multiplicative cyclic groups of prime order p, g and g2 are generators of G1 and G2 respectively, e: G1×G2→G T For bilinear pairing operation, the authorization center randomly selects Elements a, b, c on the group, and calculate g1 = g a , define the hash function H1: {0,1} * →G1, H2: Step S12: The authorization center outputs the system public parameters PP = {p, e, G1, G2, G T ,g2,g,g1,H1,H2}, master key MK=(a,b,c), and output the system public parameter PP, retaining the master key MK.
[0012] Optionally, the step S2 specifically includes: step S21, the data user applies for a key from the authorization center, the authorization center runs the data user key generation algorithm, the authorization center inputs the master key MK according to the user's attribute identity, the system public parameter PP, and calculates the user key sk u , and the user key sk u Send to data users; Step S22, the data owner encrypts the index and authenticates the encrypted index with his own private key to prevent keyword guessing attacks. The data owner inputs the system public parameter PP and finally outputs the data owner's public and private key pair (pk o ,sk o ).
[0013] Optionally, the specific implementation process of step S21 is as follows: Step S211, input the system public key PK r , master key MK, access control structure Among them, the attributes is the attribute name, is the attribute value; Step S212, the authorization center randomly selects Z P The integer r on The vector v on the vector v; Step S213, the authorization center calculates: Step S214: The final authorization center outputs the user key and sent to data users.
[0014] Optionally, the specific implementation process of step S22 is as follows: Step S221, the data owner enters the system public key PK r , and randomly select Z P Integer d on the above; Step S222, the data owner calculates Output public-private key pair sk o =d, Step S223: The data owner broadcasts the public key pk o And keep the private key sk o .
[0015] Optionally, the step S3 specifically includes: step S31, the data owner runs the key generation algorithm, the data owner inputs the system public parameter PP, the data owner private key sk o , attribute set Where attribute S={u i} i∈[m] ={n i ,v i} i∈[m] ,{n i} i∈[m] is the attribute name, {v i} i∈[m] is the attribute value; Step S32, the data owner randomly selects Z P On integers s1, s2, let s=s1+s2, the data owner calculates ct 1,i =H(u i ) s 、 and Step S33: The data owner outputs a searchable encrypted index ct = ({n i} i∈[m] ,{ct 1,i} i∈[m] ,ct2,ct3,ct4) and uploaded to the cloud server for retrieval.
[0016] Optionally, the step S4 specifically includes: step S41, the data user runs the key generation algorithm, and the data user inputs the user key sk u , data owner public key pk o , keyword w, randomly select ZP Integer u on the above; Step S42, the data user randomly selects Z P Integer u on step S43, the data user calculates and Step S44: Data user outputs searchable trapdoor And sent to the cloud server for retrieval.
[0017] Optionally, step S5 specifically includes: step S51, the cloud server executes a matching algorithm, the cloud server inputs the user's searchable trapdoor tw of the user's credentials, and matches the searchable encrypted index; step S52, first checks whether the attribute name in the attribute set complies with the access control policy, if not, returns 0, if it complies, runs the following algorithm:
[0018]
[0019] Step S53: If the equation (*) holds, return 1; if the equation (*) does not hold, the cloud server tries other subsets of I to verify whether the equation (*) holds; if all subsets of I cannot make the equation hold, return 0.
[0020] Compared with the prior art, the present invention has the following beneficial effects:
[0021] (1) Existing attribute-based searchable encryption schemes generally leak attribute information. Although some schemes can guarantee that attribute information is not leaked, they cannot support access control policies based on conjunctions and disjunctions of any monotone Boolean formula, which greatly limits the flexibility of access control policies. This invention, however, introduces a partially hidden attribute structure and random segmentation technology to hide sensitive attributes while maintaining polynomial-level computational efficiency.
[0022] (2) In response to the problem that existing attribute-based searchable encryption schemes are generally unable to resist keyword guessing attacks, and even if there are a few studies that can resist this attack, the general computational efficiency is low, the present invention introduces public key authenticated keyword search into attribute-based searchable encryption, and achieves resistance to keyword guessing attacks with a small increase in communication and time overhead.
[0023] (3) Fast attribute-based searchable encryption method. The present invention transforms the fast attribute-based encryption algorithm into a fast attribute-based searchable encryption functional algorithm. Only four bilinear pairing operations are required for one match. Compared with the existing attribute-based searchable encryption scheme (the number of bilinear pairing operations generally required for matching increases linearly with the number of attributes), the efficiency is greatly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0025] Figure 1 The present invention is a flowchart of the steps of an anonymous attribute-based rapid ciphertext retrieval method that is resistant to keyword guessing attacks.
[0026] Figure 2 Schematic diagram of a partial attribute hiding structure of the present invention.
[0027] Figure 3 For Figure 1 Schematic diagram of the corresponding anonymous attribute-based fast ciphertext retrieval process that is resistant to keyword guessing attacks. DETAILED DESCRIPTION
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0029] The purpose of the invention is to address the common problems of attribute exposure and vulnerability to keyword guessing attacks in attribute-based searchable encryption, and to propose an anonymous and keyword guessing-attack-resistant attribute-based fast ciphertext retrieval method, improve the underlying attribute-based searchable encryption algorithm to improve the overall algorithm efficiency, and support the access control strategy of conjunction and disjunction of any monotone Boolean formula. The method of the present invention can play a huge role in certain application scenarios. For example, in some scenarios such as hospital collaboration that require the division of labor and cooperation among multiple users with multiple permissions, not only the patient's case information needs to be protected, but also the privacy of some attributes such as department and position information needs to be protected. By applying the method of the present invention, it is possible to protect the privacy of attributes while protecting the privacy of messages.
[0030] In addition, the present invention improves the overall efficiency of the algorithm. Therefore, the results of the present invention have important theoretical significance and practical value for promoting the sustainable development of attribute-based searchable encryption and its application in some high-security multi-authority division of labor and cooperation scenarios.
[0031] See also Figure 1 The steps of the anonymous attribute-based rapid ciphertext retrieval method resistant to keyword guessing attacks of the present invention mainly include:
[0032] Step S1: System establishment, generation of master key and system parameters:
[0033] The authorization center initializes the system, selects and enters the security parameter λ, generates the system public parameter PP and the master key MK, and broadcasts the system public parameter PP;
[0034] Step S2, key generation phase:
[0035] The authorization center receives the key application request from the data user, inputs the system public parameter PP and the master key MK, and inputs the access control structure A according to the attribute authority of the data user to generate the user key sk u And send it to the data user, the data owner generates the public and private key pair (pk o ,sk o );
[0036] Step S3: Encrypted index generation phase:
[0037] The data owner enters the system public parameter PP and the data owner's private key sk o , the attribute set S and the keyword w are output and uploaded to the searchable encrypted index ct to the cloud server;
[0038] Step S4: Searchable trapdoor generation stage:
[0039] The data user enters the public key pk of the data owner o , user key sk of the data user u and keyword w, output and send the searchable trapdoor tw to the cloud server to obtain search results;
[0040] Step S5, matching stage:
[0041] The cloud server inputs the received searchable trapdoor tw and matches it with the searchable encrypted index. If the attribute set in the searchable encrypted index satisfies the access control policy in the trapdoor and the keyword matches, a success result is returned, otherwise a failure result is returned.
[0042] Optionally, the step S1 specifically includes: step S11, the authorization center selects a security parameter λ, generates a system public parameter PP, defines G1, G2 and G T are three multiplicative cyclic groups of prime order p, g and g2 are generators of G1 and G2 respectively, e: G1×G2→G T For bilinear pairing operation, the authorization center randomly selects Elements a, b, c on the group, and calculate g1 = g a , define the hash function H1: {0,1} * →G1, H2: Step S12: The authorization center outputs the system public parameters PP = {p, e, G1, G2, G T ,g2,g,g1,H1,H2}, master key MK=(a,b,c), and output the system public parameter PP, retaining the master key MK.
[0043] Optionally, the step S2 specifically includes: step S21, the data user applies for a key from the authorization center, the authorization center runs the data user key generation algorithm, the authorization center inputs the master key MK according to the user's attribute identity, the system public parameter PP, and calculates the user key sk u , and the user key sk u Send to data users; Step S22, the data owner encrypts the index and authenticates the encrypted index with his own private key to prevent keyword guessing attacks. The data owner inputs the system public parameter PP and finally outputs the data owner's public and private key pair (pk o ,sk o ).
[0044] Optionally, the specific implementation process of step S21 is as follows: Step S211, input the system public key PK r , master key MK, access control structure Among them, the attributes is the attribute name, is the attribute value; Step S212, the authorization center randomly selects Z P The integer r on The vector v on the vector v; Step S213, the authorization center calculates: Step S214: The final authorization center outputs the user key and sent to data users.
[0045] Optionally, the specific implementation process of step S22 is as follows: Step S221, the data owner enters the system public key PK r , and randomly select Z P Integer d on the above; Step S222, the data owner calculates Output public-private key pair sk o =d, Step S223: The data owner broadcasts the public key pk o And keep the private key sk o .
[0046] Optionally, the step S3 specifically includes: step S31, the data owner runs the key generation algorithm, the data owner inputs the system public parameter PP, the data owner private key sk o , attribute set Where attribute S={u i} i∈[m] ={n i ,v i} i∈[m] ,{n i} i∈[m] is the attribute name, {v i} i∈[m] is the attribute value; Step S32, the data owner randomly selects Z P On integers s1, s2, let s=s1+s2, the data owner calculates ct 1,i =H(u i ) s 、 and Step S33: The data owner outputs a searchable encrypted index ct = ({n i} i∈[m] ,{ct 1,i} i∈[m] ,ct2,ct3,ct4) and uploaded to the cloud server for retrieval.
[0047] Optionally, the step S4 specifically includes: step S41, the data user runs the key generation algorithm, and the data user inputs the user key sk u , data owner public key pk o , keyword w, randomly select Z P Integer u on the above; Step S42, the data user randomly selects Z P Integer u on step S43, the data user calculates and Step S44: Data user outputs searchable trapdoor And sent to the cloud server for retrieval.
[0048] Optionally, step S5 specifically includes: step S51, the cloud server executes a matching algorithm, the cloud server inputs the user's searchable trapdoor tw of the user's credentials, and matches the searchable encrypted index; step S52, first checks whether the attribute name in the attribute set complies with the access control policy, if not, returns 0, if it complies, runs the following algorithm:
[0049]
[0050] Step S53: If the equation (*) holds, return 1; if the equation (*) does not hold, the cloud server tries other subsets of I to verify whether the equation (*) holds; if all subsets of I cannot make the equation hold, return 0.
[0051] In summary, compared with the prior art, the present invention has the following beneficial effects:
[0052] (1) Existing attribute-based searchable encryption schemes generally leak attribute information. Although some schemes can guarantee that attribute information is not leaked, they cannot support access control policies based on conjunctions and disjunctions of any monotone Boolean formula, which greatly limits the flexibility of access control policies. This invention, however, introduces a partially hidden attribute structure and random segmentation technology to hide sensitive attributes while maintaining polynomial-level computational efficiency.
[0053] (2) In response to the problem that existing attribute-based searchable encryption schemes are generally unable to resist keyword guessing attacks, and even if there are a few studies that can resist this attack, the general computational efficiency is low, the present invention introduces public key authenticated keyword search into attribute-based searchable encryption, and achieves resistance to keyword guessing attacks with a small increase in communication and time overhead.
[0054] (3) Fast attribute-based searchable encryption method. The present invention transforms the fast attribute-based encryption algorithm into a fast attribute-based searchable encryption functional algorithm. Only four bilinear pairing operations are required for one match. Compared with the existing attribute-based searchable encryption scheme (the number of bilinear pairing operations generally required for matching increases linearly with the number of attributes), the efficiency is greatly improved.
[0055] Specifically, the solution of the present invention is further described according to the following examples:
[0056] The present invention is based on the theory of attribute-based public key cryptography and proposes an anonymous attribute-based fast ciphertext retrieval method that is resistant to keyword guessing attacks. The method is applied to a cloud storage environment with multi-authority division of labor and collaboration and high security requirements.
[0057] The authorization center initializes the system, inputs security parameters, generates system public parameters and a master key, and broadcasts the system public parameters. Data users request keys from the authorization center. The authorization center inputs the system public parameters and the master key, and based on the data user's attribute permissions, generates a user key using the access control structure and sends it to the data user. To ensure anonymity, attribute values are hidden, while attribute names are retained. To prevent keyword guessing attacks, the data owner inputs the system public parameters, generates a public-private key pair, and broadcasts the public key. The data owner inputs the system public parameters, the data owner's private key, the attribute set, and keywords. This ultimately outputs a searchable encrypted index and uploads it to the cloud server. Data users input their public key, user secret key, and keywords of interest. This ultimately outputs a searchable trapdoor and sends it to the cloud server for search results. The cloud server inputs the received searchable trapdoor, matches it against the searchable encrypted index, and returns the matching results.
[0058] Reference Figure 2 The partially hidden structure adopted by the present invention is specifically implemented as follows:
[0059] Divide each attribute into a common attribute name and an attribute value.
[0060] While attribute values are not disclosed in either the private key or the ciphertext, the partially hidden access structure and attribute set only disclose the attributes. For example, consider an access structure such as "(Department: Internal Medicine: AND Title: Chief Physician) OR Emergency Status: First Aid" and an attribute set "[Department: Internal Medicine, Title: Chief Physician, Emergency Status: First Aid]." The partially hidden access structure becomes "(Department and Title) OR Emergency Status," while the partially hidden attribute set becomes "[Internal Medicine, Chief Physician, First Aid]." During decryption, the algorithm first matches the attribute names and then tests whether the attribute values match.
[0061] Reference Figure 3 , the specific implementation of the present invention is as follows:
[0062] Step 1. System establishment and generation of system parameters:
[0063] Step 1-1: The authorization center selects a security parameter λ and generates the system public parameter PP, defining G1, G2 and G T are three multiplicative cyclic groups of prime order p, g and g2 are generators of G1 and G2 respectively, e: G1×G2→G T is a bilinear pairing operation. The authorized center randomly selects Elements a, b, c on the group, and calculate g1 = g a , define the hash function H1: {0,1} * →G1, H2:
[0064] Step 1-2: The authorization center outputs the system public parameters PP = {p, e, G1, G2, G T ,g2,g,g1,H1,H2},master key MK=(a,b,c), and output the system public parameter PP, retaining the master key MK.
[0065] Step 2. Generate data user key and data owner key:
[0066] Step 2-1: The data user applies for a key from the authorization center. The authorization center runs the data user key generation algorithm. The authorization center calculates the user key sk based on the user's attribute identity, inputs the master key MK, and the system public parameter PP. u , and send the user key to the data user (to ensure attribute anonymity, hide attribute values and retain attribute names). The specific implementation of this process is as follows:
[0067] Step 2-1-1: Enter the system public key PK r , master key MK, access control structure Among them, the attributes is the attribute name, is the attribute value.
[0068] Step 2-1-2: The authorization center randomly selects Z P The integer r on The vector v on .
[0069] Step 2-1-3: Authorization Center Calculation
[0070]
[0071] Step 2-1-4: The final authorization center outputs the user key and sent to data users.
[0072] Step 2-2: To prevent keyword guessing attacks, the data owner needs to authenticate the encrypted index with his or her own private key while encrypting the index. The data owner inputs the system public parameter PP, and finally outputs the data owner's public and private key pair (pk o ,sk o ), the specific implementation is as follows:
[0073] Step 2-2-1: The data owner enters the system public key PK r , and randomly select Z P An integer d on .
[0074] Step 2-2-2: Data owner calculation Output public-private key pair sk o =d, Broadcast the public key and keep the private key.
[0075] Step 2-2-3: Data owner broadcasts public key pk o And keep the private key sk o .
[0076] Step 3. Generate encrypted index:
[0077] Step 3-1: The data owner runs the key generation algorithm. The data owner enters the system public parameter PP and the data owner's private key sk o , attribute set Where attribute S={u i} i∈[m] ={n i ,v i} i∈[m] ,{n i} i∈[m] is the attribute name, {v i} i∈[m] is the attribute value.
[0078] Step 3-2: The data owner randomly selects Z P On integers s1, s2, let s=s1+s2, the data owner calculates ct 1,i =H(u i ) s ,
[0079] Step 3-3: The data owner outputs the searchable encrypted index ct = ({n i} i∈[m] ,{ct 1,i} i∈[m] ,ct2,ct3,ct4), and upload them to the cloud server for retrieval.
[0080] Step 4. Searchable trapdoor generation:
[0081] Step 4-1: The data user runs the key generation algorithm and inputs the user key sk u , data owner public key pk o , keyword w. Randomly select Z P An integer u on .
[0082] Step 4-2: Data users randomly select Z P An integer u on .
[0083] Step 4-3: Data User Calculation
[0084] Step 4-4: Data user outputs searchable trapdoor And sent to the cloud server for retrieval.
[0085] Step 5. Index matching:
[0086] Step 5-1: The cloud server executes the matching algorithm, and the cloud server inputs the user's trapdoor tw and matches the searchable encrypted index.
[0087] Step 5-2: First check whether the attribute name in the attribute set complies with the access control policy. If not, return 0. If it does, run the following algorithm:
[0088]
[0089] Step 5-3: If the equation (*) holds, return 1 (i.e., return a successful result); if the equation (*) does not hold, the cloud server tries other subsets of I to verify whether the equation (*) holds. If all subsets of I cannot make the equation hold, return 0 (i.e., return a failed result).
[0090] In summary, the present invention includes an attribute authorization center that initializes and generates system parameters and a master key and discloses the system parameters, and generates a user key based on the attribute information of each user. In order to resist keyword guessing attacks, the data owner generates a public-private key pair of the data owner and discloses the public key. Before uploading the encrypted data, the data owner performs attribute-based searchable encryption on the keyword index. The data user uses the user key and the keyword of interest to generate a searchable trapdoor and sends it to the cloud server. The cloud server matches the encrypted index with the trapdoor. If the attributes contained in the ciphertext meet the access control policy in the trapdoor and the keywords match, the match is successful. The present invention introduces an attribute partial hiding structure and a public key authentication keyword search to hide attribute values and resist keyword guessing attacks, respectively, and improves the attribute-based ciphertext retrieval method, which greatly improves the computational efficiency of the algorithm and reduces communication overhead, achieving an anonymous and keyword guessing attack-resistant attribute-based efficient ciphertext retrieval.
[0091] Compared with the prior art, the present invention has the following beneficial effects:
[0092] (1) Existing attribute-based searchable encryption schemes generally leak attribute information. Although some schemes can guarantee that attribute information is not leaked, they cannot support access control policies based on conjunctions and disjunctions of any monotone Boolean formula, which greatly limits the flexibility of access control policies. This invention, however, introduces a partially hidden attribute structure and random segmentation technology to hide sensitive attributes while maintaining polynomial-level computational efficiency.
[0093] (2) In response to the problem that existing attribute-based searchable encryption schemes are generally unable to resist keyword guessing attacks, and even if there are a few studies that can resist this attack, the general computational efficiency is low, the present invention introduces public key authenticated keyword search into attribute-based searchable encryption, and achieves resistance to keyword guessing attacks with a small increase in communication and time overhead.
[0094] (3) Fast attribute-based searchable encryption method. The present invention transforms the fast attribute-based encryption algorithm into a fast attribute-based searchable encryption functional algorithm. Only four bilinear pairing operations are required for one match. Compared with the existing attribute-based searchable encryption scheme (the number of bilinear pairing operations generally required for matching increases linearly with the number of attributes), the efficiency is greatly improved.
[0095] Furthermore, it should be noted that the present invention may be a method, system, apparatus and / or computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present invention.
[0096] Computer-readable storage medium can be a tangible device that can keep and store the instructions used by the instruction execution device.Computer-readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device or any suitable combination thereof.More specific examples (non-exhaustive list) of computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, for example, a punch card or a convex structure in a groove having instructions stored thereon, and any suitable combination thereof.Computer-readable storage medium used herein is not interpreted as a transient signal itself, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagated by waveguides or other transmission media (for example, light pulses by fiber optic cables), or electrical signals transmitted by wires.
[0097] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in the computer-readable storage medium in each computing / processing device.
[0098] The computer program instructions for performing the operation of the present invention can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, Python, and conventional procedural programming languages such as "C" language or similar programming languages. The computer readable program instructions can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), is personalized by utilizing the state information of the computer readable program instructions, and the electronic circuit can execute the computer readable program instructions, thereby realizing various aspects of the present invention.
[0099] Various aspects of the present invention are described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0100] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device is generated that implements the functions / actions specified in one or more blocks in the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, where these instructions cause the computer, programmable data processing device, and / or other device to operate in a specific manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks in the flowchart and / or block diagram.
[0101] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more blocks in the flowchart and / or block diagram.
[0102] The flowcharts and block diagrams in the accompanying drawings show the possible implementation architecture, functions and operations of the systems, methods and computer program products according to multiple embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, program segment or part of an instruction, and the module, program segment or part of the instruction contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions. It is well known to those skilled in the art that implementation by hardware, implementation by software, and implementation by a combination of software and hardware are all equivalent.
[0103] While various embodiments of the present invention have been described above, the foregoing description is intended to be illustrative, non-exhaustive, and not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical applications, or technological improvements in the marketplace, or to enable others skilled in the art to understand the embodiments disclosed herein. The scope of the present invention is defined by the appended claims.
Claims
1. An anonymous attribute-based fast ciphertext retrieval method that is resistant to keyword guessing attacks, characterized by: include: Step S1: System establishment, generation of master key and system parameters: The authorization center initializes the system, selects and enters the security parameter λ, generates the system public parameter PP and the master key MK, and broadcasts the system public parameter PP; Step S2, key generation phase: The authorization center receives the key application request from the data user, inputs the system public parameter PP and the master key MK, and inputs the access control structure A according to the attribute authority of the data user to generate the user key sk u And send it to the data user, the data owner generates the public and private key pair (pk o ,sk o ); Step S3: Encrypted index generation phase: The data owner enters the system public parameter PP and the data owner's private key sk o , the attribute set S and the keyword w are output and uploaded to the searchable encrypted index ct to the cloud server; Step S4: Searchable trapdoor generation stage: The data user enters the public key pk of the data owner o , user key sk of the data user u and keyword w, output and send the searchable trapdoor tw to the cloud server to obtain search results; Step S5, matching stage: The cloud server inputs the received searchable trapdoor tw and matches it with the searchable encrypted index. If the attribute set in the searchable encrypted index satisfies the access control policy in the trapdoor and the keyword matches, a success result is returned, otherwise a failure result is returned.
2. The method according to claim 1, characterized in that The step S1 specifically includes: Step S11: The authorization center selects a security parameter λ and generates a system public parameter PP, defining G1, G2 and G T are three multiplicative cyclic groups of prime order p, g and g2 are generators of G1 and G2 respectively, e: G1×G2→G T For bilinear pairing operation, the authorization center randomly selects Elements a, b, c on the group, and calculate g1 = g a , define the hash function H1: {0,1} * →G1, H2: Step S12: The authorization center outputs the system public parameters PP = {p, e, G1, G2, G T ,g2,g,g1,H1,H2}, master key MK=(a,b,c), and output the system public parameter PP, retaining the master key MK.
3. The method according to claim 1, characterized in that The step S2 specifically includes: Step S21: The data user applies for a key from the authorization center. The authorization center runs the data user key generation algorithm. The authorization center calculates the user key sk based on the user's attribute identity, inputs the master key MK, and the system public parameter PP. u , and the user key sk u Send to data users; Step S22: The data owner encrypts the index and authenticates it with his / her own private key to prevent keyword guessing attacks. The data owner inputs the system public parameter PP, and finally outputs the data owner's public and private key pair (pk o ,sk o ).
4. The method according to claim 3, characterized in that The specific implementation process of step S21 is as follows: Step S211: Input the system public key PK r , master key MK, access control structure A={M,π,{π(i)} i∈[l] }, where the attribute {π(i)} i∈[l] ={n π(i) ,v π(i) } i∈[l] ,{n π(i) } i∈[l] is the attribute name, {v π(i) } i∈[l] is the attribute value; Step S212: The authorization center randomly selects Z P The integer r on vector v on ; Step S213: The authorization center calculates: Step S214: The final authorization center outputs the user key sk r =(M,π,{n π(i) } i∈[ l ] ,sk1,{sk} 2,i } i∈[l] ,{sk} 3,i } i∈[l] ) and sent to the data user.
5. The method according to claim 4, characterized in that The specific implementation process of step S22 is as follows: Step S221: The data owner enters the system public key PK r , and randomly select Z P integer d on ; Step S222: Data owner calculation Output public-private key pair sk o =d, Step S223: The data owner broadcasts the public key pk o And keep the private key sk o .
6. The method according to claim 1, characterized in that The step S3 specifically includes: Step S31: The data owner runs the key generation algorithm. The data owner inputs the system public parameter PP and the data owner's private key sk o , attribute set S={u i } i∈[m] ={n i ,v i } i∈[m] ,w}, where attribute S={u i } i∈[m] ={n i ,v i } i∈[m] ,{n i } i∈[m] is the attribute name, {v i } i∈[m] is the attribute value; Step S32: The data owner randomly selects Z P On integers s1, s2, let s=s1+s2, the data owner calculates ct 1,i =H(u i ) s 、 and Step S33: The data owner outputs the searchable encrypted index ct = ({n i } i∈[m] ,{ct 1,i } i∈[m] ,ct2,ct3,ct4) and uploaded to the cloud server for retrieval.
7. The method according to claim 1, characterized in that The step S4 specifically includes: Step S41: The data user runs the key generation algorithm and inputs the user key sk u , data owner public key pk o , keyword w, randomly select Z P integer u on ; Step S42: Data user randomly selects Z P integer u on ; Step S43: Data user calculation and Step S44: Data user outputs searchable trapdoor And sent to the cloud server for retrieval.
8. The method according to claim 1, characterized in that The step S5 specifically includes: Step S51: The cloud server executes a matching algorithm, and the cloud server inputs the user's searchable trapdoor tw and matches the searchable encrypted index; Step S52: First check whether the attribute name in the attribute set complies with the access control policy. If not, return 0. If yes, run the following algorithm: Step S53: If the equation (*) holds, return 1; if the equation (*) does not hold, the cloud server tries other subsets of I to verify whether the equation (*) holds; if all subsets of I cannot make the equation hold, return 0.