Attribute-based searchable encryption-based payment-by-time digital copyright management method and system

Through an attribute-based searchable encryption scheme and using a certificate server to verify user attribute tokens and policy ciphertexts, the system bottleneck problem caused by malicious collusion is solved, efficient and secure pay-per-view search digital product management is achieved, and the security and scalability of digital rights management are improved.

CN120602080APending Publication Date: 2025-09-05SOUTH CHINA AGRICULTURAL UNIVERSITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510714871.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In the pay-per-view search model for digital products, collusion between malicious authorized users and unauthorized users results in damage to the interests of digital copyright owners. Existing technologies cannot effectively solve the communication overhead problem of user authentication, leading to system bottlenecks.

Method used

An attribute-based searchable encryption (ABE) scheme is adopted to verify the matching of the user's attribute token and the policy ciphertext through the certificate server, generate certificates and perform secure searches, reduce interaction overhead, introduce a decoupling mechanism to prevent unauthorized users from consuming resources, support multi-keyword AND/OR expressions and resist keyword guessing attacks.

Benefits of technology

It improves the security and search efficiency of digital rights management, reduces communication overhead and computing burden, prevents resource consumption by unauthorized users, is suitable for large-scale attribute scenarios, and optimizes the access control process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602080A_ABST
    Figure CN120602080A_ABST
Patent Text Reader

Abstract

The invention discloses a per-time payment digital copyright management method and system based on attribute-based searchable encryption, and the method comprises the steps: receiving an attribute token transmitted by a user side and a strategy ciphertext transmitted by a data transmitting end, the attribute token being generated by the user side according to an attribute key; the policy ciphertext is generated by the data sending end according to the access policy, the public parameter, the master key, the public key of the user side and the private key of the data sending end; and verifying the matching between the attribute token and the policy ciphertext, generating a certificate during matching, and sending the certificate to the cloud server, so that the cloud server executes security search and returns a matching result according to the certificate, the query trap door sent by the user side and the keyword ciphertext sent by the data sending side, the query trap door is generated by the user side according to the query keyword, the public parameter, the public key of the data sending side and the private key of the user side, and the keyword ciphertext is generated by encrypting the keyword by the data sending side. According to the invention, efficient and reliable technical guarantee is provided for the digital copyright payment per time service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a pay-per-view digital copyright management method and system based on attribute-based searchable encryption, belonging to the field of cloud computing data security and search technology. Background Art

[0002] Cloud services, thanks to their convenience and reliability, have become a cost-effective data storage solution widely adopted by individuals and businesses. They support large-scale data storage, allowing users to easily upload, search, and update data without worrying about data loss, significantly improving the efficiency and convenience of data management. Currently, a pay-per-view model for digital search is gradually emerging and becoming mainstream. In this model, digital copyright holders charge users based on the amount of data accessed. Most cloud service providers, including IBM Cloud, Amazon Athena, and Google Cloud, have adopted this pricing model.

[0003] In this model, the digital copyright owner needs to create a digital copyright management project in the cloud and bind his or her payment account to the project. The digital copyright owner then uploads the ciphertext of the digital product to the project. When a user is interested in the data in the project, he or she can obtain search authorization by paying the digital copyright owner. Authorized users can query the ciphertext of the digital product, while unauthorized users cannot perform such operations. However, the authorization of the pay-per-view search model for digital products mainly relies on the user's specific index, which can easily lead to the phenomenon of data users "free riding". Specifically, if Figure 1 As shown, the traditional pay-per-view search model for digital products involves three entities: the digital rights owner, the digital product storage provider, and the digital product search provider. The digital rights owner uploads their digital products to cloud servers for storage. To facilitate management, the search function is only available to authorized users. For example, the digital rights owner distributes specific keywords to authorized users, allowing them to search for files based on these keywords, while limiting each authorized user to a maximum of 100 queries per day. However, a malicious authorized user might pass their specific keywords to an unauthorized user, allowing them to search for files without deducting the malicious authorized user's query quota. This collusion between malicious and unauthorized users undoubtedly severely damages the interests of the digital rights owner.

[0004] Inspired by attribute-based encryption (ABE), Sun et al. and Zheng et al. proposed attribute-based keyword search (ABKS) schemes, respectively. ABKS can be viewed as an integration of ABE and public-key encryption keyword search (PEKS). In this concept, keyword search is performed only when the user's attributes match the policy in the ciphertext. Due to this characteristic, ABKS is well-suited to the pay-per-view search model for digital products.

[0005] However, directly using the ABKS scheme in a pay-per-query business model is not feasible. When a user issues a search request, the checking system interacts with the billing server to verify whether the user has obtained service permissions. Once the number of users increases dramatically, the frequent interactions between the two servers may consume a large amount of communication overhead, leading to system bottlenecks. Therefore, designing an effective authentication mechanism is key to access control in a pay-per-query business model. To better address the above issues, we propose a new conditional attribute-based keyword search (CABKS) method. Summary of the Invention

[0006] In view of this, the present invention provides a pay-per-use digital copyright management method, device, system and storage medium based on attribute-based searchable encryption, which has the characteristics of high security, fast speed and high efficiency, can be widely used in the privacy protection and retrieval of digital products, and plays a vital role in promoting the development of digital product systems.

[0007] The first object of the present invention is to provide a pay-per-view digital rights management method based on attribute-based searchable encryption.

[0008] A second object of the present invention is to provide a pay-per-view digital rights management device based on attribute-based searchable encryption.

[0009] The third object of the present invention is to provide a pay-per-view digital rights management system based on attribute-based searchable encryption.

[0010] A fourth object of the present invention is to provide a computer-readable storage medium.

[0011] The first object of the present invention is achieved by adopting the following technical solutions:

[0012] A pay-per-view digital rights management method based on attribute-based searchable encryption, applied to a certificate server, comprising:

[0013] Receive an attribute token sent by the user and a policy ciphertext sent by the data sender, where the attribute token is generated by the user based on the attribute key, and the policy ciphertext is generated by the data sender based on the access policy, public parameters, master key, the user's public key, and its own private key;

[0014] Verify the matching of the attribute token and the policy ciphertext, generate a certificate when matching, and send the certificate to the cloud server, so that the cloud server performs a secure search based on the certificate, the query trapdoor sent by the user end, and the keyword ciphertext sent by the data sender, and returns the matching result. The query trapdoor is generated by the user end based on the query keyword, public parameters, the public key of the data sender, and the private key of the user end. The keyword ciphertext is generated by the data sender by encrypting the keywords in the keyword set.

[0015] Furthermore, the attribute key is generated by the trusted authority center based on the attribute set and the master key sent by the user terminal. The generation process of the attribute key includes:

[0016] Randomly select u∈Z p , for each attribute x in the attribute set S k ∈S selects a random value t∈Z p , calculate the user-side attribute key in H1 is the first hash function in the public parameters, g1 and g2 are generators of the cyclic group in the public parameters, and d is an element in the master key MSK.

[0017] Furthermore, the process of generating the attribute token includes:

[0018] Pick a random value τ∈Z p , and calculate the attribute token on the user side in

[0019] Furthermore, the process of generating the policy ciphertext includes:

[0020] Construct access policy matrix M n×l and mapping function ρ, randomly select vector calculate Where β is a random number at the data sending end, M i represents the i-th row of matrix M;

[0021] Calculation strategy ciphertext PCT=(M,ρ,{PCT 1,i ,PCT 2,i} i∈[1,n] ,PCT3,PCT4), where H1 is the first hash function in the public parameters, g1 and g2 are the generators of the cyclic group in the public parameters, The public key PK of the user r Elements in, c is the private key SK of the data sender sThe elements in , d is the element in the master key MSK.

[0022] Furthermore, the query trapdoor generation process includes:

[0023] Convert the query statement into query structure Q=(N n*l ,κ,{η(κ(i))} i∈[1,n] ), where N n*l Represents a matrix with n rows and l columns;

[0024] Randomly select vector calculate where N i represents the i-th row of matrix N;

[0025] Pick a random value r∈Z p , generate query trapdoor TD=(N,κ,{TD 1,i ,TD 2,i} i∈[1,n] ,TD3,TD4), where H2 is the second hash function in the public parameters, g1 and g2 are the generators of the cyclic group in the public parameters, b1, b2 and δ are the private keys SK of the user end r The elements in and PK is the public key of the data sender s Elements in .

[0026] Furthermore, the certificate generation process includes:

[0027] calculate Where β is a random number at the data sending end, TK 1,i and TK 2,k The first and second parts of the attribute token TK, PCT 1,i and PCT 2,i are the first and second parts of the policy ciphertext PCT, g1 and g2 are the generators of the cyclic group in the public parameters;

[0028] Calculate the certificate CER = (CER1, CER2), where PCT3 and PCT4 are the third and fourth parts of the policy ciphertext PCT respectively. The public key PK of the user r Elements in, c is the private key SK of the data sender s Elements in .

[0029] Furthermore, performing a secure search and returning matching results includes:

[0030] Check whether the equation TD4 = CER1 holds, where TD4 is the fourth part of the query trapdoor TD and CER1 is the first part of the certificate. If the equation does not hold, the user's certificate does not exist, and ⊥ is returned. If the equation holds, the keyword type set in the keyword ciphertext CT of the data sender is used to obtain the matrix row number set I1 using the mapping function κ.

[0031] When the query structure Q satisfies the keyword set W in the index, there exists a vector ω1 such that

[0032] Check the equation Is it established? TD 1,i , TD 2,i and TD3 are the first, second and third parts of the query trapdoor TD, CT1, CT2, CT 3,j and CT4 are the first, second, third, and fourth parts of the keyword ciphertext CT and the second part of the CER2 certificate respectively. If the equation holds, the search is successful and Y is returned. If the equation does not hold, the search fails and ⊥ is returned.

[0033] The second object of the present invention is achieved by adopting the following technical solutions:

[0034] A pay-per-view digital rights management device based on attribute-based searchable encryption, applied to a certificate server, comprising:

[0035] A receiving module, configured to receive an attribute token sent by a user end and a policy ciphertext sent by a data sending end, wherein the attribute token is generated by the user end according to the attribute key, and the policy ciphertext is generated by the data sending end according to the access policy, public parameters, a master key, the public key of the user end, and its own private key;

[0036] The verification and search module is used to verify the matching of the attribute token and the policy ciphertext, generate a certificate when a match is found, and send the certificate to the cloud server so that the cloud server can perform a secure search based on the certificate, the query trap sent by the user end, and the keyword ciphertext sent by the data sender, and return the matching result. The query trap is generated by the user end based on the query keyword, public parameters, the public key of the data sender, and the private key of the user end. The keyword ciphertext is generated by the data sender by encrypting the keywords in the keyword set.

[0037] The third object of the present invention is achieved by adopting the following technical solutions:

[0038] A pay-per-use digital copyright management system based on attribute-based searchable encryption, the system comprising a trusted authority center, a user terminal, a data sending terminal, a certificate server, and a cloud server, the cloud server being connected to the trusted authority center, the user terminal, the data sending terminal, and the certificate server, respectively; the certificate server being connected to the user terminal and the data sending terminal, respectively; and the trusted authority center being connected to the user terminal;

[0039] The trusted authority center is used to generate public parameters and a master key based on the security parameters, and to generate an attribute key based on the attribute set and the master key sent by the user terminal, and return the attribute key to the user terminal;

[0040] The user terminal is configured to generate a public-private key pair based on the public parameters, send an attribute set to the trusted authority center, receive an attribute key returned by the trusted authority center, generate an attribute token based on the attribute key, send the attribute token to the certificate server, and generate a query trapdoor based on the query keyword, the public parameters, the public key of the data sender, and the private key of the user terminal, and send the query trapdoor to the cloud server;

[0041] The data sending end is used to generate a public-private key pair based on the public parameters, extract a keyword set from the file, generate a keyword ciphertext based on the keyword set, send the keyword ciphertext to the cloud server, and generate a policy ciphertext based on the access policy, public parameters, master key, the public key of the user end and its own private key, and send the policy ciphertext to the certificate server;

[0042] The certificate server is used to receive the attribute token sent by the user terminal and the policy ciphertext sent by the data sending terminal, verify the matching of the attribute token and the policy ciphertext, generate a certificate when a match is found, and send the certificate to the cloud server;

[0043] The cloud server is used to perform a secure search based on the certificate, the query trap sent by the user end, and the keyword ciphertext sent by the data sending end, and return a matching result.

[0044] The fourth object of the present invention is achieved by adopting the following technical solutions:

[0045] A computer-readable storage medium stores a program, which, when executed by a processor, implements the above-mentioned pay-per-view digital rights management method.

[0046] The present invention has the following beneficial effects compared to the prior art:

[0047] 1. This invention supports multi-keyword AND / OR expressions, resists keyword guessing attacks, and reduces interaction overhead by separating policy ciphertext from keyword ciphertext. It is suitable for large-scale attribute scenarios and significantly improves security, search efficiency, and scalability compared to existing technical solutions, providing efficient and reliable technical support for digital copyright pay-per-view services.

[0048] 2. The present invention introduces a decoupling mechanism that effectively prevents unauthorized users from consuming cloud server resources by decoupling the access control structure from the keyword ciphertext, making it more secure and efficient.

[0049] 3. This invention avoids repeated access control. Once a user generates their own certificate through the certificate server, they no longer need to go through access control to generate a certificate when searching. The cloud server can directly use the previous certificate, thus greatly reducing the workload of access control.

[0050] 4. This invention can resist offline message keyword guessing attacks. The encryption algorithm uses the private key generated by the data sender as part of its input, ensuring that the encryption algorithm cannot be executed by entities other than the data sender. Furthermore, this invention supports large attribute sets. Therefore, this invention is faster and more secure.

[0051] 5. Compared with traditional attribute-based keyword search, the present invention not only inherits the basic functions, but also adds new functional features, allowing the checker to test the ciphertext only when it holds a valid credential generated by another designated server; at the same time, it implements access control in the pay-per-view search model for digital products without introducing additional paid servers; finally, it optimizes the number of communication rounds and the computational burden, reducing the potential bottleneck risk in providing services to a large number of users. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying any creative work.

[0053] Figure 1 A diagram illustrating the "free rider" problem of existing pay-per-view digital rights management.

[0054] Figure 2 This is a structural block diagram of a pay-per-view digital rights management system based on attribute-based searchable encryption according to embodiment 1 of the present invention.

[0055] Figure 3This is a flow chart for implementing the pay-per-view digital rights management system based on attribute-based searchable encryption according to embodiment 1 of the present invention.

[0056] Figure 4 This is a flow chart of a pay-per-view digital rights management method based on attribute-based searchable encryption according to embodiment 1 of the present invention.

[0057] Figure 5 This is a structural block diagram of a pay-per-view digital rights management device based on attribute-based searchable encryption according to embodiment 2 of the present invention. DETAILED DESCRIPTION

[0058] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0059] Example 1:

[0060] like Figure 2 As shown, this embodiment provides a pay-per-view digital copyright management system based on attribute-based searchable encryption. The system includes a trusted authority center, a user terminal, a data sending terminal, a certificate server and a cloud server. The cloud server is respectively connected to the trusted authority center, the user terminal, the data sending terminal and the certificate server. The certificate server is respectively connected to the user terminal and the data sending terminal, and the trusted authority center is connected to the user terminal.

[0061] like Figure 3 As shown, the specific implementation process of the pay-per-view digital copyright management system based on attribute-based searchable encryption in this embodiment is as follows:

[0062] (1) System initialization

[0063] Initialization is completed through the trusted authority center. According to the security parameter λ, the public parameter PP and the master key MSK are set. The specific process is as follows:

[0064] With the security parameter λ as input, let the bilinear map e:G1×G2→G T , where G1, G2, G T Both are cyclic groups of prime order p. g1 is the generator of G1, g2 is the generator of G2, and two hash functions H1 and H2 are defined: {0,1} * →G1. Random selection Generate public parameters PP and master key MSK:

[0065]

[0066] (2) User-side key generation

[0067] The user terminal generates a public-private key pair (SK r , PK r ), where SK r The user's private key, PK r is the user's public key. The specific process is:

[0068] Randomly select elements α,b1,b2,δ∈Z p , and generate the user's private key SK r =(α,b1,b2,δ) and public key

[0069] (3) Data sending end key generation

[0070] Generate a public-private key pair (SK) based on the public parameter PP s , PK s ), where SK r The private key of the data sender, PK r is the public key of the data sender. The specific process is:

[0071] Randomly select an element c∈Z p , and generate the data sender's private key SK s =c and public key

[0072] (4) Attribute key generation

[0073] The user sends its own attribute set to the trusted authority (TA) for attribute registration. The trusted authority generates the user's attribute key SK based on the user's attribute set S and the system master key MSK. a The specific process is:

[0074] First select a random value u∈Z p , and then for each attribute in the attribute set S, select a random value t∈Z p , then calculate the user's attribute key in H1 is the first hash function in the public parameters, g1 and g2 are generators of the cyclic group in the public parameters, and d is an element in the master key MSK.

[0075] The trusted authority center will generate the attribute key SK a Return to the user.

[0076] (5) Keyword and policy encryption

[0077] The data sending end extracts the corresponding keyword set W from the file, and then divides the keyword set W into a keyword type set type and a keyword value set value. The data sending end encrypts the keyword into a keyword ciphertext CT, and then sends the keyword ciphertext CT to the cloud server for storage. Then, the data sending end converts the access policy P = (M n×l ,ρ) is encrypted into the policy ciphertext PCT, where M n×l It is a matrix with n rows and l columns, generated by the access policy of the data sender. ρ is a mapping function used to map the row index of the matrix to the attribute category. The data sender sends the policy ciphertext PCT to the certificate server for storage.

[0078] The specific process of encrypting a keyword into keyword ciphertext CT is as follows:

[0079] Randomly select s1,s2,β∈Z p , and calculate s=s1+s2.

[0080] Calculate the parts of the keyword ciphertext:

[0081]

[0082] in, e(g1,g2) α and The public key PK of the user r The elements in , the final generated keyword ciphertext is:

[0083] CT=(CT1,CT2,{type j ,CT 3,j} j∈[1,|W|] ,CT4)

[0084] The specific process of encrypting the access policy P into the policy ciphertext PCT is as follows:

[0085] Construct access policy matrix M n×l and mapping function ρ, randomly select vector calculate Where β is a random number at the data sending end, M i represents the i-th row of matrix M, λ i The vector representing the concatenation of the i-th row of matrix M and β and V is multiplied by the vector inner product. That is, the first vector of the i-th row of M is multiplied by the first vector + the second vector of the i-th row of M is multiplied by the second vector + ... + the last vector of the i-th row of M is multiplied by the last vector.

[0086] Calculate the various parts of the policy ciphertext PCT:

[0087]

[0088] Where H1 is the first hash function in the public parameters, g1 and g2 are the generators of the cyclic group in the public parameters, The public key PK of the user r Elements in, c is the private key SK of the data sender s The elements in , d is the element in the master key MSK, and the final generated policy ciphertext is:

[0089] PCT=(M,ρ,{PCT 1,i ,PCT 2,i} i∈[1,n] ,PCT3,PCT4)

[0090] (6) Attribute Token Generation

[0091] The client receives the attribute key SK returned by the trusted authority center a Then, using the attribute key SK a Generate your own attribute token TK. The specific process is:

[0092] Pick a random value τ∈Z p , and calculate the attribute token on the user side in

[0093] (7) Certificate Generation

[0094] The user end applies for a certificate from the certificate server based on the attribute token. After receiving the attribute token sent by the user end and the policy ciphertext sent by the data sender, the certificate server uses the mapping function ρ to map the attribute set S of the data receiver to the matrix row set I. When the attribute set S of the attribute token TK satisfies the access policy P of the policy ciphertext PCT, there exists a vector ω such that where ω i Indicates the dimension of the vector.

[0095] Certificate Server Computing Where β is a random number at the data sending end, TK 1,i and TK 2,k The first and second parts of the attribute token TK, PCT 1,i and PCT 2,i They are the first and second parts of the policy ciphertext PCT respectively, g1 and g2 are the generators of the cyclic group in the public parameters, and F records a result, which is used to calculate the CER2 part of the certificate later.

[0096] The certificate server generates a certificate CER=(CER1, CER2), where PCT3 and PCT4 are the third and fourth parts of the policy ciphertext PCT respectively. The public key PK of the user r Elements in, c is the private key SK of the data sender s Elements in .

[0097] The certificate server sends the generated certificate CER to the cloud server.

[0098] (8) Query trap generation

[0099] The user generates a query trapdoor TD using the keywords of their interest through the user terminal. The specific process is as follows:

[0100] Convert the query statement into query structure Q=(N n*l ,κ,{η(κ(i))} i∈[1,n] ), where N n*l Represents a matrix with n rows and l columns;

[0101] Randomly select vector calculate where N i represents the i-th row of matrix N;

[0102] Pick a random value r∈Z p , calculate the parts of the query trapdoor:

[0103]

[0104] Among them, H2 is the second hash function in the public parameters, g1 and g2 are the generators of the cyclic group in the public parameters, b1, b2 and δ are the private keys SK of the user end r The elements in and PK is the public key of the data sender s The elements in the query trapdoor are: TD=(N,κ,{TD 1,i ,TD 2,i} i∈[1,n] ,TD3,TD4).

[0105] The client sends the generated query trapdoor to the cloud server.

[0106] (9) Search

[0107] After receiving the query trapdoor TD from the user, the cloud server first checks whether it has received the corresponding certificate CER. If not, it directly returns ⊥. Otherwise, it checks whether the keyword ciphertext CT matches the query trapdoor TD. If the match is successful, it means the search is successful and returns Y; if the match is not successful, it means the search failed and returns ⊥. The specific process is as follows:

[0108] Check whether the equation TD4=CER1 holds, where TD4 is the fourth part of the query trapdoor TD and CER1 is the first part of the certificate. If the equation does not hold, the user's certificate does not exist and ⊥ is returned. If the equation holds, the keyword type set in the keyword ciphertext CT of the data sender is converted to the matrix row number set I1 using the mapping function κ.

[0109] When the query structure Q satisfies the keyword set W in the index, there exists a vector ω1 such that

[0110] Check the equation Is it established? TD 1,i , TD 2,i and TD3 are the first, second and third parts of the query trapdoor TD, CT1, CT2, CT 3,j and CT4 are the first, second, third, and fourth parts of the keyword ciphertext CT and the second part of the CER2 certificate respectively. If the equation holds, the search is successful and Y is returned. If the equation does not hold, the search fails and ⊥ is returned.

[0111] like Figure 4 As shown, this embodiment provides a pay-per-view digital rights management method based on attribute-based searchable encryption. The method is mainly implemented through the above steps (4) to (9), with the certificate server as the execution subject. The specific description is as follows:

[0112] S401. Receive the attribute token sent by the user end and the policy ciphertext sent by the data sending end, wherein the attribute token is generated by the user end based on the attribute key, and the policy ciphertext is generated by the data sending end based on the access policy, public parameters, master key, user end public key and its own private key.

[0113] S402. Verify the matching of the attribute token and the policy ciphertext, generate a certificate when a match occurs, and send the certificate to the cloud server so that the cloud server performs a secure search based on the certificate, the query trap sent by the user end, and the keyword ciphertext sent by the data sender, and returns the matching result. The query trap is generated by the user end based on the query keyword, public parameters, the public key of the data sender, and the private key of the user end, and the keyword ciphertext is generated by the data sender by encrypting the keyword in the keyword set.

[0114] It should be noted that although the method operations of the above embodiments are described in a particular order in the accompanying drawings, this does not require or imply that the operations must be performed in this particular order, or that all of the illustrated operations must be performed to achieve the desired results. Rather, the depicted steps may be performed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into a single step, and / or a single step may be broken down into multiple steps.

[0115] Example 2:

[0116] like Figure 5 As shown, this embodiment provides a pay-per-view digital rights management device based on attribute-based searchable encryption, which is applied to a certificate server. The device includes a receiving module and a verification and search module. The specific description of each module is as follows:

[0117] Receiving module 501, configured to receive an attribute token sent by a user end and a policy ciphertext sent by a data sending end, wherein the attribute token is generated by the user end based on the attribute key, and the policy ciphertext is generated by the data sending end based on the access policy, public parameters, master key, the user end's public key, and its own private key;

[0118] The verification and search module 502 is used to verify the matching of the attribute token and the policy ciphertext, generate a certificate when a match occurs, and send the certificate to the cloud server so that the cloud server can perform a secure search based on the certificate, the query trap sent by the user end, and the keyword ciphertext sent by the data sending end, and return the matching result. The query trap is generated by the user end based on the query keyword, public parameters, the public key of the data sending end, and the private key of the user end. The keyword ciphertext is generated by the data sending end by encrypting the keywords in the keyword set.

[0119] It should be noted that the device provided in the above embodiment is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure can be divided into different functional modules to complete all or part of the functions described above.

[0120] Example 3:

[0121] This embodiment provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the pay-per-view digital rights management method of the first embodiment is implemented as follows:

[0122] Receive the attribute token sent by the user end and the policy ciphertext sent by the data sending end, the attribute token is generated by the user end according to the attribute key, and the policy ciphertext is generated by the data sending end according to the access policy, public parameters, master key, the public key of the user end and its own private key; verify the matching of the attribute token and the policy ciphertext, generate a certificate when it matches, and send the certificate to the cloud server, so that the cloud server performs a secure search based on the certificate, the query trap sent by the user end and the keyword ciphertext sent by the data sending end, and returns the matching result, the query trap is generated by the user end according to the query keyword, public parameters, the public key of the data sending end and the private key of the user end, and the keyword ciphertext is generated by the data sending end by encrypting the keywords in the keyword set.

[0123] The computer-readable storage medium of the present embodiment can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0124] In summary, compared with traditional attribute-based keyword search, the present invention not only inherits the basic functions but also adds new functional features, allowing the checker to test the ciphertext only when it holds a valid credential generated by another designated server; at the same time, it implements access control in the pay-per-view search model for digital products without introducing additional paid servers; finally, it optimizes the number of communication rounds and the computational burden, reducing the potential bottleneck risk in providing services to a large number of users.

[0125] The above is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes based on the technical solution and inventive concept of the present invention within the scope disclosed by the present invention, which falls within the scope of protection of the present invention.

Claims

1. A pay-per-view digital rights management method based on attribute-based searchable encryption, applied to a certificate server, characterized in that: The method comprises: Receive an attribute token sent by the user and a policy ciphertext sent by the data sender, where the attribute token is generated by the user based on the attribute key, and the policy ciphertext is generated by the data sender based on the access policy, public parameters, master key, the user's public key, and its own private key; Verify the matching of the attribute token and the policy ciphertext, generate a certificate when matching, and send the certificate to the cloud server, so that the cloud server performs a secure search based on the certificate, the query trapdoor sent by the user end, and the keyword ciphertext sent by the data sender, and returns the matching result. The query trapdoor is generated by the user end based on the query keyword, public parameters, the public key of the data sender, and the private key of the user end. The keyword ciphertext is generated by the data sender by encrypting the keywords in the keyword set.

2. The pay-per-view digital rights management method according to claim 1, wherein: The attribute key is generated by the trusted authority center based on the attribute set and the master key sent by the user. The attribute key generation process includes: Randomly select u∈Z p , for each attribute x in the attribute set S k ∈S selects a random value t∈Z p , calculate the user-side attribute key in H1 is the first hash function in the public parameters, g1 and g2 are generators of the cyclic group in the public parameters, and d is an element in the master key MSK.

3. The pay-per-view digital rights management method according to claim 2, wherein: The process of generating the attribute token includes: Pick a random value τ∈Z p , and calculate the attribute token on the user side in 4. The pay-per-view digital rights management method according to claim 1, wherein: The process of generating the policy ciphertext includes: Construct access policy matrix M n×l and mapping function ρ, randomly select vector calculate Where β is a random number at the data sending end, M i represents the i-th row of matrix M; Calculation strategy ciphertext PCT=(M,ρ,{PCT 1,i ,PCT 2,i } i∈[1,n] ,PCT3,PCT4), where H1 is the first hash function in the public parameters, g1 and g2 are the generators of the cyclic group in the public parameters, The public key PK of the user r Elements in, c is the private key SK of the data sender s The elements in , d is the element in the master key MSK.

5. The pay-per-view digital rights management method according to claim 1, wherein: The generation process of the query trapdoor includes: Convert the query statement into query structure Q=(N n*l ,κ,{η(κ(i))} i∈[1,n] ), where N n*l Represents a matrix with n rows and l columns; Randomly select vector calculate where N i represents the i-th row of matrix N; Pick a random value r∈Z p , generate query trapdoor TD=(N,κ,{TD 1,i ,TD 2,i } i∈[1,n] ,TD3,TD4), where H2 is the second hash function in the public parameters, g1 and g2 are the generators of the cyclic group in the public parameters, b1, b2 and δ are the private keys SK of the user end r The elements in and PK is the public key of the data sender s Elements in .

6. The pay-per-view digital rights management method according to claim 1, wherein: The certificate generation process includes: calculate Where β is a random number at the data sending end, TK 1,i and TK 2,k The first and second parts of the attribute token TK, PCT 1,i and PCT 2,i are the first and second parts of the policy ciphertext PCT, g1 and g2 are the generators of the cyclic group in the public parameters; Generate certificate CER = (CER1, CER2), where PCT3 and PCT4 are the third and fourth parts of the policy ciphertext PCT respectively. The public key PK of the user r Elements in, c is the private key SK of the data sender s Elements in .

7. The pay-per-view digital rights management method according to claim 1, wherein: The safe search is performed and matching results are returned, including: Check whether the equation TD4 = CER1 holds, where TD4 is the fourth part of the query trapdoor TD and CER1 is the first part of the certificate. If the equation does not hold, the user's certificate does not exist, and ⊥ is returned. If the equation holds, the keyword type set in the keyword ciphertext CT of the data sender is used to obtain the matrix row number set I1 using the mapping function κ. When the query structure Q satisfies the keyword set W in the index, there exists a vector ω1 such that Check the equation Is it established? TD 1,i , TD 2,i and TD3 are the first, second and third parts of the query trapdoor TD, CT1, CT2, CT 3,j and CT4 are the first, second, third, and fourth parts of the keyword ciphertext CT and the second part of the CER2 certificate respectively. If the equation holds, the search is successful and Y is returned. If the equation does not hold, the search fails and ⊥ is returned.

8. A pay-per-view digital rights management device based on attribute-based searchable encryption, applied to a certificate server, characterized in that: The device comprises: A receiving module, configured to receive an attribute token sent by a user end and a policy ciphertext sent by a data sending end, wherein the attribute token is generated by the user end according to the attribute key, and the policy ciphertext is generated by the data sending end according to the access policy, public parameters, a master key, the public key of the user end, and its own private key; The verification and search module is used to verify the matching of the attribute token and the policy ciphertext, generate a certificate when a match is found, and send the certificate to the cloud server so that the cloud server can perform a secure search based on the certificate, the query trap sent by the user end, and the keyword ciphertext sent by the data sender, and return the matching result. The query trap is generated by the user end based on the query keyword, public parameters, the public key of the data sender, and the private key of the user end. The keyword ciphertext is generated by the data sender by encrypting the keywords in the keyword set.

9. A pay-per-view digital rights management system based on attribute-based searchable encryption, characterized in that: The system includes a trusted authority center, a user terminal, a data sending terminal, a certificate server and a cloud server, wherein the cloud server is connected to the trusted authority center, the user terminal, the data sending terminal and the certificate server respectively, the certificate server is connected to the user terminal and the data sending terminal respectively, and the trusted authority center is connected to the user terminal; The trusted authority center is used to generate public parameters and a master key based on the security parameters, and to generate an attribute key based on the attribute set and the master key sent by the user terminal, and return the attribute key to the user terminal; The user terminal is configured to generate a public-private key pair based on the public parameters, send an attribute set to the trusted authority center, receive an attribute key returned by the trusted authority center, generate an attribute token based on the attribute key, send the attribute token to the certificate server, and generate a query trapdoor based on the query keyword, the public parameters, the public key of the data sender, and the private key of the user terminal, and send the query trapdoor to the cloud server; The data sending end is used to generate a public-private key pair based on the public parameters, extract a keyword set from the file, generate a keyword ciphertext based on the keyword set, send the keyword ciphertext to the cloud server, and generate a policy ciphertext based on the access policy, public parameters, master key, the public key of the user end and its own private key, and send the policy ciphertext to the certificate server; The certificate server is used to receive the attribute token sent by the user terminal and the policy ciphertext sent by the data sending terminal, verify the matching of the attribute token and the policy ciphertext, generate a certificate when a match is found, and send the certificate to the cloud server; The cloud server is used to perform a secure search based on the certificate, the query trap sent by the user end, and the keyword ciphertext sent by the data sending end, and return a matching result.

10. A computer-readable storage medium storing a program, characterized in that: When the program is executed by a processor, the pay-per-view digital rights management method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Multi-keyword query method based on vector inner product encryption

    CN121561977A