Verifiable searchable encryption method and system with flexible access control in cloud environment, and storage medium
Through hierarchical permission control and bilinear pairing, combined with inverted index and signature mechanism, the problem of permission management in cloud storage environment relying on honest servers is solved, and secure access control and search result integrity are achieved in the dishonest server environment.
Patent Information
- Application Number
- CN202510671085.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-09-09
AI Technical Summary
Existing searchable encryption schemes rely on the cooperation of honest servers for permission management in many-to-many cloud storage environments and cannot guarantee data security and access control when servers are dishonest.
A hierarchical permission control mechanism is adopted, with the system public key and master key, the public and private keys of the data owner and the user generated by a trusted authority. Combined with bilinear pairing and hash functions, data encryption and permission verification are achieved, and permission management is performed independently of the cloud server. An inverted index structure and signature mechanism are introduced to ensure the integrity of search results.
It achieves the ability to manage owner and user-level permissions without relying on honest cloud servers, resist unauthorized searches and attacks, ensure the integrity and authenticity of search results, and adapt to access control in complex many-to-many scenarios.
Smart Images

Figure CN120614151A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of searchable encryption technology, and in particular to a searchable encryption method, system and storage medium that can be verified and has flexible access control in a cloud environment. Background Art
[0002] The exponential growth of digital data demands secure and efficient cloud data management. Encryption techniques, particularly searchable and attribute-based encryption, have emerged as key mechanisms for enabling authorized users to access data and retrieve ciphertext. For complex many-to-many scenarios with multiple owners and users, existing searchable encryption schemes incorporate the fundamentals of attribute-based encryption to manage both owner- and user-level permissions. However, their permission management relies on the cooperation of an honest server, which may not be practical in many-to-many cloud storage environments. Summary of the Invention
[0003] The purpose of the present invention is to provide a searchable encryption method, system and storage medium that can be verified and have flexible access control in a cloud environment to solve the technical problems raised in the background technology.
[0004] To achieve the above object, the present invention provides the following technical solutions:
[0005] A searchable encryption method with verifiable and flexible access control in a cloud environment includes the following steps:
[0006] S1. The trusted authority constructs a symmetric bilinear pairing e and a hash function H, randomly selects a parameter selection domain and randomly selects elements therefrom to form public parameters, a first key sequence, and a second key sequence, and calculates and generates a system public key and a system master key. The public parameters include system key parameters, user key parameters, trapdoor generation parameters, keyword binding parameters, user permission verification parameters, cloud server key parameters, control index encryption parameters, and key permission verification parameters.
[0007] S2. The trusted authority obtains the pre-access list L containing the data owner's information and calculates the public key and private key of the cloud server, the public-private key pair of the data owner, and the private key of the data user based on the public parameters, the system public key, and the system master key. m represents the number of data owners;
[0008] S3. The data owner generates an encrypted index based on public parameters and public-private key pairs and uploads it to the cloud server. The data owner also generates signature information Sig and uploads it to a trusted authority.
[0009] S4. The data user uses the public parameters, the public key of the cloud server, and the private key of the data user to calculate and generate a search trapdoor, and sends it to the cloud server;
[0010] S5. The cloud server receives the data user's search trap and performs EqualTest 0 and EqualTest 1 Two-step equality test, after which the matching encrypted file is returned to the data user;
[0011] S6. The data user further verifies the integrity and authenticity of the encrypted file by performing a signature check on all file identifiers containing the keyword w based on the inverted index structure to confirm whether any returned results are omitted.
[0012] S7. The trusted authority responds in real time to update the private key of the data user whose permissions have been changed, and the data owner involved in the change updates the version number of his public key parameters.
[0013] Furthermore, the specific steps of step S1 are:
[0014] S11. The trusted authority randomly selects a large prime number p and a residue class ring Z modulo p. p As the parameter selection domain, select a p-order multiplication cyclic group G as the input group of the bilinear pairing, and then select another p-order multiplication cyclic group G T As the output group of bilinear pairing; construct symmetric bilinear pairing e:G×G→G T , and a secure hash function H:{0,1} * →Z p , {0,1} * Represents a string of 0 or 1 characters of any length;
[0015] S12. The trusted authority randomly selects elements from the parameter selection domain and records them as α, β, a, b, c as system key parameters, user key parameters, trapdoor generation parameters, keyword binding parameters and user authority verification parameters respectively; randomly selects 2n elements from the parameter selection domain to form the first key sequence (r1, r2, ..., r 2n ), randomly select 2n elements from G to form the second key sequence (x1, x2, ..., x 2n ); the trusted authority generates msk=(a,b,c,α,β,ver,(r1,r2,…,r 2n ),(x1,x2,…,x 2n )) as the system master key, As the system public key, where ver represents the version number and g represents the generator of the input group; x i represents the i-th element in the second key sequence, r i Represents the i-th element in the first key sequence.
[0016] Furthermore, the specific steps in step S2 are:
[0017] S21. Calculate the public and private keys of the cloud server: record the cloud server key parameter as β1 as the private key of the cloud server, and calculate the public key of the cloud server g represents the generator of the input group;
[0018] S22. Calculate the private key and public key of the data owner: denote the control index encryption parameter and key authority verification parameter randomly selected by the trusted authority for the i-th data owner as γ i1 and γ i2 , i∈[1,m], and use it as a component of the data owner's private key. Combined with the user key parameters and the cloud server key parameters, the other component of the data owner's private key is calculated. The data owner's private key can be recorded as Calculate the first part of the public key of the i-th data owner and the second part ver represents the version number, α represents the system key parameter, and the public key of the data owner is recorded as pk DO =({h 1,1 ,h 2,1 ,…,h m,1},{h 1,2 ,h 2,2 ,…,h m,2});
[0019] S23, calculate the private key of each data user: divide the private key of each data user into the first part auxiliary parameter Com and the second part auxiliary parameter (σ user ,y user ,v); Calculate the first part of the auxiliary parameters of the k-th data user's private key according to the pre-access list L. The data user checks whether each of its own attributes matches the attribute access policy of the data owner, and calculates the second part of the auxiliary parameters of the k-th data user's private key according to the matching results. The calculation formula is:
[0020]
[0021] v=g ac
[0022] If the matching result is yes, then The matching result is No.
[0023] In the above formula, α is the system key parameter, β is the user key parameter, and x k represents the kth element selected from the second key sequence, g represents the generator of the input group, r krepresents the kth element selected from the first key sequence; U is the number of data users, a and c are the trapdoor generation parameters and user authority verification parameters respectively, and finally the data user private key is recorded as sk DU =(Com,(σ user ,y user ,v)).
[0024] Furthermore, the specific steps of step S3 are:
[0025] S31. First, the data owner selects three random numbers r, t1, t2 from the parameter selection domain and calculates a component of the encrypted index. The calculation formula is:
[0026]
[0027] In the above formula, β is the user key parameter, β1 is the cloud server key parameter, γ i1 The control index encryption parameter of the i-th data owner, h i,2 The second part of the public key parameter of the i-th data owner, which contains the permission information of the data owner;
[0028] S32. For each keyword w∈WD keyword set, determine whether the keyword w matches the keyword access strategy, and calculate the encrypted index component u based on the matching result. gate Then, according to the inverted index structure, all files containing the keyword w are encrypted using a symmetric encryption algorithm to obtain the file ciphertext cphF w , and calculate the component W' that makes up the encrypted index, and record the encrypted index of the data owner as Upload to the cloud server, the calculation formula is as follows:
[0029]
[0030] If the matching result is yes, then If the match result is no, then
[0031] In the above formula, r i represents the i-th element selected from the first key sequence; a and b are the trapdoor generation parameters and keyword binding parameters respectively, H represents the hash function, and g represents the generator of the input group;
[0032] S33. Initialize an empty signature dictionary. Then, for each keyword w∈WD keyword set, calculate the parameter value of the signature dictionary through hash function and symmetric encryption. Add (w, value) to the signature dictionary to generate the signature information Sig containing the keyword. Then send Sig to the trusted authority. The calculation formula is:
[0033] value=H(E(f w,1 )||E(f w,2 )‖||…)
[0034] In the above formula, E represents symmetric encryption, f w,1 Represents the first file containing keyword w, f w,2 Represents the second file containing keyword w, and so on.
[0035] Furthermore, the specific steps of step S4 are:
[0036] S41. The data user selects two random numbers x and s from the parameter selection domain and uses the public key of the cloud server and the private key of the data user to calculate the first part (Ap1, Ap2) of the kth data user trapdoor. The calculation formula is:
[0037]
[0038] In the above formula, L is the pre-access list, β is the user key parameter, and β1 is the cloud server key parameter;
[0039] S42, using the data user private key and public parameters to calculate the second part of the trapdoor ((y user ) s ,(σ user ) s ,v s ,tok1,tok2), where y user ,σ user ,v represent the second part of the auxiliary parameters of the data user's private key; the calculation formulas of tok1 and tok2 are as follows:
[0040] tok1=(g a+bH(w) ) s
[0041] tok2=g cs
[0042] In the above formula, a, b, c represent the trapdoor generation parameters, keyword binding parameters and user authority verification parameters respectively, and w represents the keyword. The data user search trapdoor can be recorded as Tk w =((Ap1,Ap2),((y user ) s ,(σ user ) s ,v s ,tok1,tok2)).
[0043] Furthermore, the specific steps of step S5 are as follows:
[0044] S51, EqualTest0 Test: Test EqualTest 0 Test whether the equation is true and verify the data owner's permissions. If it is true, the data user has the permission to access the data owner. The test equation is:
[0045]
[0046] In the above formula, i∈[1,m], It is an auxiliary value for accurate verification of the permissions of a specific data owner. Pub is the aggregate value of the data owner's public key. i1 is the control index encryption parameter of the i-th data owner, γ i2 is the key permission verification parameter of the i-th data owner, c1, c2, c3 are the encryption index parameters of the data owner, β1 is the cloud server key parameter, Ap1 and Ap2 are the parameters for data users to search for trapdoors;
[0047] S52, EqualTest 1 Test: Test EqualTest 1 Test whether the equation is true, check whether the data user permissions match the keywords, and if true, return the encrypted document cphF containing all keywords w w For data users, the test equation is:
[0048]
[0049] In the above formula, a, b, and c are trapdoor generation parameters, keyword binding parameters, and user permission verification parameters, respectively. H represents the hash function, w represents the keyword, t1 and t2 represent random numbers selected by the data owner from the parameter selection domain, tok2 and tok1 represent the parameters in the data user's search trapdoor, and y user ,σ user ,v both represent the second part of the auxiliary parameters of the data user's private key.
[0050] Furthermore, the step S6 is specifically as follows: obtaining the encrypted document cphF containing all the keywords w returned by the cloud server w , split it into f1||f2||…, and then check whether the hash value of the encrypted file and the signature information match through the hash function. If H(f1||f2||…)=Sig[w], the returned result is correct; otherwise, the returned result is omitted by the cloud server.
[0051] A verifiable searchable encryption system with flexible access control in a cloud environment includes: a trusted authority for initializing system public parameters and key sequences to generate a system public key and a system master key, and for calculating and distributing the public and private keys of cloud servers, the public and private key pairs of data owners, and the private keys of data users, and for updating permissions to change the private keys of data users;
[0052] The data owner is responsible for generating an encrypted index and uploading it to the cloud server, generating signature information and uploading it to the trusted authority, and updating the public key involved in the change;
[0053] The cloud server is used to store encrypted indexes, receive data users to search for trapdoors, and return encrypted files to data users after permission verification;
[0054] Data users are used to generate search traps and send them to the cloud server to verify the encrypted files returned by the cloud server.
[0055] A non-volatile storage medium stores computer instructions, wherein the instructions are executed by a processor to perform the method according to any one of claims 1 to 7.
[0056] Beneficial effects:
[0057] The present invention can manage both owner-level and user-level permissions at the same time, but the management of owner-level permissions is independent of the cloud server; through a lightweight permission update method, it can not only resist unauthorized searches and attacks, but also achieve fine-grained access control to encrypted data without sacrificing privacy; the addition of the function of verifying search results ensures the integrity and authenticity of search results. In response to the problem of relying on the cooperation of honest cloud servers, the present invention can ensure data security and access control even when the server may be dishonest, and is adaptable to a wider range of real-world scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] In order to more clearly illustrate the technical solutions implemented in the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0059] Figure 1 A flowchart of the searchable encryption method of the present invention;
[0060] Figure 2 The encryption system schematic diagram can be searched for in the present invention. DETAILED DESCRIPTION
[0061] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0062] The trusted authority is considered fully trustworthy and plays a key role in the entire process, from generating system public parameters and master keys to distributing keys to cloud servers, data owners, and data users. All parties involved are dependent on it. Cloud servers are assumed to be harmless but careless. Under normal circumstances, they will execute search algorithms and return results to data users, but they may inadvertently neglect to execute certain algorithms or may miss some search results. Each data owner is considered fully trustworthy and will upload encrypted indexes to the cloud server and signed information to the trusted authority. Each data user is assumed to be potentially malicious. They submit legitimate search requests to the cloud server and verify search results, but they may also attempt to infer the plaintext behind the keywords searched by other data users.
[0063] like Figure 1-Figure 2 As shown, the present invention provides a searchable encryption method that can be verified and has flexible access control in a cloud environment. The specific steps are as follows:
[0064] S1. The trusted authority constructs a symmetric bilinear pairing e and a hash function H, randomly selects a parameter selection domain and randomly selects elements therefrom to form public parameters, a first key sequence, and a second key sequence, and calculates and generates a system public key and a system master key. The public parameters include system key parameters, user key parameters, trapdoor generation parameters, keyword binding parameters, user permission verification parameters, cloud server key parameters, control index encryption parameters, and key permission verification parameters.
[0065] In this embodiment, in order to further illustrate step S1, the specific steps are as follows:
[0066] S11. The trusted authority randomly selects a large prime number p and a residue class ring Z modulo p. p As a parameter selection domain, in order to select a large number of random numbers in the future, select a p-order multiplication cyclic group G as the input group of the bilinear pairing, and then select another p-order multiplication cyclic group G T As the output group of bilinear pairing; construct symmetric bilinear pairing e:G×G→G T , and a secure hash function H:{0,1} * →Z p , {0,1} * Represents a string of 0 or 1 characters of any length;
[0067] S12, the trusted authority randomly selects elements from the parameter selection domain and records them as α, β, a, b, c as system key parameters, user key parameters, trapdoor generation parameters, keyword binding parameters and user authority verification parameters respectively; p Randomly select 2n elements to form the first key sequence (r1, r2, ..., r 2n ), randomly select 2n elements from G to form the second key sequence (x1, x2, ..., x 2n );
[0068] The trusted authority generates msk=(a,b,c,α,β,ver,(r1,r2,…,r2n),(x1,x2,…,x 2n )) as the system master key, As the system public key, ver represents the version number, which is used for subsequent permission updates, and g represents the generator of the input group; x i represents the i-th element in the second key sequence, r i represents the i-th element in the first key sequence. This embodiment places more emphasis on randomness and distribution uniformity when selecting public parameters to ensure the unpredictability and security of key generation.
[0069] S2. The trusted authority obtains the pre-access list L containing the data owner's information and calculates the public key and private key of the cloud server, the public-private key pair of the data owner, and the private key of the data user based on the public parameters, the system public key, and the system master key. m represents the number of data owners;
[0070] In this embodiment, in order to further illustrate step S2, the specific steps are as follows:
[0071] S21. Calculate the public and private keys of the cloud server: record the cloud server key parameter as β1 as the private key of the cloud server, and calculate the public key of the cloud server g represents the generator of the input group.
[0072] S22. Calculate the private key and public key of the data owner: The trusted authority selects two random numbers from the parameter selection domain for each data owner as the control index encryption parameter and key authority verification parameter. The control index encryption parameter and key authority verification parameter corresponding to the i-th data owner are denoted as γ i1 and γ i2 , i∈[1,m], γ i1 and γ i2It is an independent random number that controls index encryption and permission verification respectively. It is used as a component of the data owner's private key. The other component of the data owner's private key is calculated by combining the user key parameter and the cloud server key parameter. The data owner's private key can be recorded as
[0073] Calculate the first part of the public key of the i-th data owner and the second part ver represents the version number, α represents the system key parameter, and the public key of the data owner is recorded as pk DO =({h 1,1 ,h 2,1 ,…,h m,1},{h 1,2 ,h 2,2 ,…,h m,2}).
[0074] By designing the first part of the data owner's public key {h 1,1 ,h 2,1 ,…,h m,1}For encryption, the second part of the data owner's public key {h 1,2 ,h 2,2 ,…,h m,2}It is used for permission binding to achieve fine-grained access control, can realize key versioning, flexibly respond to permission revocation through ver, separate encryption and verification permissions, and reduce the risk of key leakage.
[0075] S23, calculate the private key of each data user: divide the private key of each data user into the first part auxiliary parameter Com and the second part auxiliary parameter (σ user ,y user ,v);
[0076] Calculate the first auxiliary parameter Com: Calculate the first auxiliary parameter of the kth data user's private key based on the pre-access list L. The calculation formula is:
[0077]
[0078] In the above formula, β is the user key parameter, which ensures permission binding and contains data owner-level permission control information;
[0079] Calculate the second part of the auxiliary parameters of the data user's private key: The data user checks whether each of its own attributes matches the attribute access policy of the data owner, and calculates the second part of the auxiliary parameters of the kth data user's private key based on the matching results. The calculation formula is:
[0080]
[0081] v=g ac
[0082] If the matching result is yes, then The matching result is No.
[0083] In the above formula, x k represents the kth element selected from the second key sequence, g represents the generator of the input group, r k represents the kth element selected from the first key sequence; y user and σ user Used to construct the attribute verification component, U is the number of data users, a, c are the trapdoor generation parameters and user authority verification parameters, (σ user ,y user ,v) As the second part of the auxiliary parameter of the data user private key, it contains the user level permission control information. Finally, the data user private key is recorded as sk DU =(Com,(σ user ,y user ,v)).
[0084] Compared with single-level permission control (such as attribute-based or role-based), the present invention implements dual permission verification through a hierarchical product structure and dynamic attribute mapping. It can support complex permission management in many-to-many scenarios, resist collusion attacks through dynamic attribute matching, and achieve efficient permission verification by combining bilinear pairing.
[0085] S3. The data owner generates an encrypted index based on public parameters and public-private key pairs and uploads it to the cloud server. The data owner generates signature information Sig and uploads it to a trusted authority. The encrypted index allows data to be retrieved based on keywords without revealing the privacy of the underlying information.
[0086] In this embodiment, in order to further illustrate step S3, the specific steps are as follows:
[0087] S31. First, the data owner selects three random numbers r, t1, t2 from the parameter selection domain and calculates a component of the encrypted index. The calculation formula is:
[0088]
[0089] In the above formula, β is the user key parameter, β1 is the cloud server key parameter, γ i1 The control index encryption parameter of the i-th data owner, h i,2 The second part of the public key parameter of the i-th data owner, which contains the permission information of the data owner;
[0090] S32. For each keyword w∈WD keyword set, determine whether the keyword w matches the keyword access strategy, and calculate the encrypted index component u based on the matching result. gate , to achieve dynamic access control, and then according to the inverted index structure, use the symmetric encryption algorithm to encrypt all files containing the keyword w to obtain the file ciphertext cphF w , and calculate the component W' that makes up the encrypted index, and record the encrypted index of the data owner as Upload to the cloud server; the calculation formula is as follows:
[0091]
[0092] If the matching result is yes, then If the match result is no, then
[0093] In the above formula, r i represents the i-th element selected from the first key sequence; a, b are the trapdoor generation parameters and keyword binding parameters respectively, H represents the hash function, and g represents the generator of the input group.
[0094] Existing searchable encryption schemes usually only use a single layer of permission control (such as user attributes). The present invention divides permissions into the data owner level (controlling who can encrypt data) and the user level (controlling who can search) through the inverted index structure and attribute-associated parameters, achieving dual dynamic authorization.
[0095] S33. Initialize an empty signature dictionary. Then, for each keyword w∈WD keyword set, calculate the parameter value of the signature dictionary through hash function and symmetric encryption. Add (w, value) to the signature dictionary to generate the signature information Sig containing the keyword. Then send Sig to the trusted authority. The calculation formula is:
[0096] value=H(E(f w,1 )||E(f w,2 )‖||…)
[0097] In the above formula, E represents symmetric encryption, f w,1 Represents the first file containing keyword w, f w,2 Represents the second file containing keyword w, and so on.
[0098] S4: The data user uses the public parameters, the cloud server's public key, and the data user's private key to calculate the first and second parts of the trapdoor to generate a search trapdoor, and sends it to the cloud server. When a data user queries an encrypted file containing the keyword w, a search trapdoor needs to be sent to the cloud server.
[0099] In this embodiment, in order to further illustrate step S4, the specific steps are as follows:
[0100] S41. The data user selects two random numbers x and s from the parameter selection domain to ensure that the trapdoor cannot be forged. Then, the cloud server's public key and the data user's private key are used to calculate the first part of the k-th data user's trapdoor (Ap1, Ap2). The calculation formula is:
[0101]
[0102]
[0103] In the above formula, L is the pre-access list, β is the user key parameter, and β1 is the cloud server key parameter, which contains owner-level control information and controls which data owners' data can be searched;
[0104] S42, using the data user private key and public parameters to calculate the second part of the trapdoor ((y user ) s ,(σ user ) s ,v s ,tok1,tok2), where y user ,σ user ,v represent the second part of the auxiliary parameters of the data user's private key, including user-level permission control, which controls which users can access the data; the calculation formulas for tok1 and tok2 are as follows:
[0105] tok1=(g a+bH(w) ) s
[0106] tok2=g cs
[0107] In the above formula, a, b, c represent the trapdoor generation parameters, keyword binding parameters and user authority verification parameters respectively, and w represents the keyword. The data user search trapdoor can be recorded as Tk w =((Ap1,Ap2),((y user ) s ,(σ user ) s ,v s ,tok1,tok2)); Compared with relying on a single trapdoor, the present invention achieves fine-grained access control by generating trapdoors in stages (the first part verifies the owner's permissions, and the second part verifies the user's attributes), avoiding the burden of the server needing to store the complete policy.
[0108] S5. The cloud server receives the data user's search trap and performs EqualTest 0 and EqualTest1 Two-step equality test to verify the owner-level permissions of the data owner and the user-level permissions of the data user. After the test passes, the matching encrypted file is returned to the data user. 0 The test passes the data user can access the data owner's data, EqualTest 1 The test ensures that only authorized users can access encrypted files.
[0109] EqualTest 0 and EqualTest 1 The specific steps of the two-step equality test are as follows:
[0110] S51, EqualTest 0 Test: Test EqualTest 0 Test whether the equation is true and verify the data owner's permissions. The test equation is:
[0111]
[0112] In the above formula, i∈[1,m], It is an auxiliary value for accurate verification of the permissions of a specific data owner, realizing dynamic aggregation of permissions of multiple data owners and supporting complex many-to-many scenarios. Pub is the aggregate value of the data owner's public key, reflecting the user's access rights to multiple owners. i1 is the control index encryption parameter of the i-th data owner, γ i2 is the key permission verification parameter of the i-th data owner, c1, c2, c3 are the encryption index parameters of the data owner, β1 is the cloud server key parameter, Ap1 and Ap2 are the parameters for data user search trapdoor; EqualTest 0 If the test equation is established, the equality test passes, and the data user can access the data of the i-th data owner, but whether the file containing the specific keyword w can be retrieved still needs to wait for the equality test EqualTest. 1 inspection.
[0113] S52, EqualTest 1 Test: Test EqualTest 1 Test whether the equality is established, verify whether the data user permissions match the keywords, if the equality test is established, the equality test passes, and return the encrypted document cphF containing all keywords w w , the cloud server returns it to the data user, and the test equation is:
[0114]
[0115] In the above formula, a, b, and c are trapdoor generation parameters, keyword binding parameters, and user permission verification parameters, respectively. H represents the hash function, w represents the keyword, t1 and t2 represent random numbers selected by the data owner from the parameter selection domain, tok2 and tok1 represent the parameters in the data user's search trapdoor, and y user ,σ user ,v both represent the second part of the auxiliary parameters of the data user's private key; compared with the bilinear pairing application based on static permission verification or simplification, the present invention achieves finer-grained access control through dynamic parameter aggregation and multiple permission verification mechanisms.
[0116] The introduction of cloud server private keys and random numbers, through hierarchical calculation of bilinear pairings, defends against collusion attacks. Finally, through complex matching on both sides of the equation, permission verification is ensured to cover both the data owner level and the user level, preventing unauthorized access. Dynamic permission adjustment (such as user attribute changes or owner revocation) is supported on demand to adapt to the changing needs of the cloud environment. The nested use of multiple random parameters and bilinear pairings significantly improves anti-attack capabilities. Pre-calculation of public key aggregate values and two-step equality testing reduces the real-time computing overhead of the cloud server. All verification results can be audited by third-party authorities, enhancing system credibility.
[0117] S6. The data user further verifies the integrity and authenticity of the encrypted file by performing a signature check on all file identifiers containing the keyword w based on the inverted index structure to confirm whether any returned results are omitted.
[0118] Specifically: Get the encrypted document cphF containing all keywords w returned by the cloud server w , splitting it into f1||f2||…. Then, a hash function is used to check whether the hash value and signature information of the encrypted file match. If H(f1||f2||…) = Sig[w], the returned result is correct; otherwise, the returned result is omitted by the cloud server. By comparing the hash value and signature information of the encrypted file, it is ensured that the encrypted file is not omitted. Compared with complex data structures such as binary trees, the use of a lightweight inverted index structure not only improves retrieval efficiency in massive encrypted data, but also makes search results more intuitive and visual. In addition, existing dual-authority schemes do not consider the verification of search results. This scheme adds a verifiable link for search results, which helps prevent cloud services from omitting search results.
[0119] S7. The trusted authority updates the private key of the data user whose permissions are changed. The owner of the data involved in the change updates the version number of its public key parameters, flexibly responding to the revocation and update of permissions to enhance the security and flexibility of the system.
[0120] The trusted authority updates the pre-access list containing the data owner information. When the trusted authority updates the private key of the data user, the data user may use the old key to generate a trapdoor. To ensure that the old key becomes invalid after the permission is revoked, the version number in the public key of the data owner involved in the change is updated to ver * ∈Z p It is a new version number, which prevents data users from accessing the data owner's data after the permission is revoked. Compared with relying on the cloud server to update permissions, the present invention is independent of the cloud server and allows the data owner to update his or her own public key, that is, to update the version number. The data user updates the private key in order to change the pre-access list range permissions of the searched data owner information, thereby enhancing the security and flexibility of the system.
[0121] The present invention also provides a searchable encryption system that is verifiable and has flexible access control in a cloud environment, comprising:
[0122] Trusted authority, used to initialize the system public parameters and key sequence to generate the system public key and system master key, and respectively calculate and distribute the public key and private key of the cloud server, the public-private key pair of the data owner and the private key of the data user, and update the private key of the data user with permission to change;
[0123] The data owner is responsible for generating an encrypted index and uploading it to the cloud server, generating signature information and uploading it to the trusted authority, and updating the public key involved in the change;
[0124] The cloud server is used to store encrypted indexes, receive data users to search for trapdoors, and return encrypted files to data users after permission verification;
[0125] Data users are used to generate search traps and send them to the cloud server to verify the encrypted files returned by the cloud server.
[0126] The present invention also provides a computer-readable storage medium storing computer instructions, which are used by a processor to execute the searchable encryption method provided above.
[0127] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be included therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.
[0128] In addition, it should be understood that although this specification is described in terms of implementation methods, not every implementation method contains only one independent technical solution. This narrative method of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.
Claims
1. A searchable encryption method with verifiable and flexible access control in a cloud environment, characterized by: The following steps are involved: S1. The trusted authority constructs a symmetric bilinear pairing e and a hash function H, randomly selects a parameter selection domain and randomly selects elements therefrom to form public parameters, a first key sequence, and a second key sequence, and calculates and generates a system public key and a system master key. The public parameters include system key parameters, user key parameters, trapdoor generation parameters, keyword binding parameters, user permission verification parameters, cloud server key parameters, control index encryption parameters, and key permission verification parameters. S2. The trusted authority obtains the pre-access list L containing the data owner's information and calculates the public key and private key of the cloud server, the public-private key pair of the data owner, and the private key of the data user based on the public parameters, the system public key, and the system master key. m represents the number of data owners; S3. The data owner generates an encrypted index based on public parameters and public-private key pairs and uploads it to the cloud server. The data owner also generates signature information Sig and uploads it to a trusted authority. S4. The data user uses the public parameters, the cloud server's public key, and the data user's private key to calculate and generate a search trapdoor, and sends it to the cloud server. S5. The cloud server receives the data user's search trap and performs EqualTest 0 and EqualTest 1 Two-step equality test, after which the matching encrypted file is returned to the data user; S6. The data user further verifies the integrity and authenticity of the encrypted file by performing a signature check on all file identifiers containing the keyword w based on the inverted index structure to confirm whether any returned results are omitted. S7. The trusted authority responds in real time to update the private key of the data user whose permissions have been changed, and the data owner involved in the change updates the version number of his public key parameters.
2. The searchable encryption method according to claim 1, wherein: The specific steps of step S1 are: S11. The trusted authority randomly selects a large prime number p and a residue class ring Z modulo p. p As the parameter selection domain, select a p-order multiplication cyclic group G as the input group of the bilinear pairing, and then select another p-order multiplication cyclic group G T As the output group of bilinear pairing; construct symmetric bilinear pairing e:G×G→G T , and a secure hash function H:{0,1} * →Z p , {0,1} * Represents a string of 0 or 1 characters of any length; S12. The trusted authority randomly selects elements from the parameter selection domain and records them as α, β, a, b, c as system key parameters, user key parameters, trapdoor generation parameters, keyword binding parameters and user authority verification parameters respectively; randomly selects 2n elements from the parameter selection domain to form the first key sequence (r1, r2, ..., r 2n ), randomly select 2n elements from G to form the second key sequence (x1, x2, ..., x 2n ); the trusted authority generates msk=(a,b,c,α,β,ver,(r1,r2,…,r2n),(x1,x2,…,x 2n )) as the system master key, As the system public key, where ver represents the version number and g represents the generator of the input group; x i represents the i-th element in the second key sequence, r i Represents the i-th element in the first key sequence.
3. The searchable encryption method according to claim 1, wherein: The specific steps in step S2 are: S21. Calculate the public and private keys of the cloud server: record the cloud server key parameter as β1 as the private key of the cloud server, and calculate the public key of the cloud server g represents the generator of the input group; S22. Calculate the private key and public key of the data owner: denote the control index encryption parameter and key authority verification parameter randomly selected by the trusted authority for the i-th data owner as γ i1 and γ i2 , i∈[1,m], and use it as a component of the data owner's private key. Combined with the user key parameters and the cloud server key parameters, the other component of the data owner's private key is calculated. The data owner's private key can be recorded as Calculate the first part of the public key of the i-th data owner and the second part ver represents the version number, α represents the system key parameter, and the public key of the data owner is recorded as pk DO =({h 1,1 ,h 2,1 ,…,h m,1 },{h 1,2 ,h 2,2 ,…,h m,2 }); S23, calculate the private key of each data user: divide the private key of each data user into the first part auxiliary parameter Com and the second part auxiliary parameter (σ user ,y user ,v); Calculate the first part of the auxiliary parameters of the k-th data user's private key according to the pre-access list L. The data user checks whether each of its own attributes matches the attribute access policy of the data owner, and calculates the second part of the auxiliary parameters of the k-th data user's private key according to the matching results. The calculation formula is: v=g ac If the matching result is yes, then The matching result is No. In the above formula, α is the system key parameter, β is the user key parameter, and x k represents the kth element selected from the second key sequence, g represents the generator of the input group, r k represents the kth element selected from the first key sequence; U is the number of data users, a and c are the trapdoor generation parameters and user authority verification parameters respectively, and finally the data user private key is recorded as sk DU =(Com,(σ user ,y user ,v)).
4. The searchable encryption method according to claim 1, wherein: The specific steps of step S3 are: S31. First, the data owner selects three random numbers r, t1, t2 from the parameter selection domain and calculates a component of the encrypted index. The calculation formula is: In the above formula, β is the user key parameter, β1 is the cloud server key parameter, γ i1 The control index encryption parameter of the i-th data owner, h i,2 The second part of the public key parameter of the i-th data owner, which contains the permission information of the data owner; S32. For each keyword w∈WD keyword set, determine whether the keyword w matches the keyword access strategy, and calculate the encrypted index component u based on the matching result. gate Then, according to the inverted index structure, all files containing the keyword w are encrypted using a symmetric encryption algorithm to obtain the file ciphertext cphF w , and calculate the component W' that makes up the encrypted index, and record the encrypted index of the data owner as Upload to the cloud server, the calculation formula is as follows: If the matching result is yes, then If the match result is no, then In the above formula, r i represents the i-th element selected from the first key sequence; a and b are the trapdoor generation parameters and keyword binding parameters respectively, H represents the hash function, and g represents the generator of the input group; S33. Initialize an empty signature dictionary. Then, for each keyword w∈WD keyword set, calculate the parameter value of the signature dictionary through hash function and symmetric encryption. Add (w, value) to the signature dictionary to generate the signature information Sig containing the keyword. Then send Sig to the trusted authority. The calculation formula is: value=H(E(f w,1 )||E(f w,2 )||…) In the above formula, E represents symmetric encryption, f w,1 Represents the first file containing keyword w, f w,2 Represents the second file containing keyword w, and so on.
5. The searchable encryption method according to claim 1, wherein: The specific steps of step S4 are: S41. The data user selects two random numbers x and s from the parameter selection domain and uses the public key of the cloud server and the private key of the data user to calculate the first part (Ap1, Ap2) of the kth data user trapdoor. The calculation formula is: In the above formula, L is the pre-access list, β is the user key parameter, and β1 is the cloud server key parameter; S42, using the data user private key and public parameters to calculate the second part of the trapdoor ((y user ) s ,(σ user ) s ,v s ,tok1,tok2), where y user ,σ user ,v represent the second part of the auxiliary parameters of the data user's private key; the calculation formulas of tok1 and tok2 are as follows: tok1=(g a+bH(w) ) s tok2=g cs In the above formula, a, b, c represent the trapdoor generation parameters, keyword binding parameters and user authority verification parameters respectively, and w represents the keyword. The data user search trapdoor can be recorded as Tk w =((Ap1,Ap2),((y user ) s ,(σ user ) s ,v s ,tok1,tok2)).
6. The searchable encryption method according to claim 1, wherein: The specific steps of step S5 are as follows: S51, EqualTest 0 Test: Test EqualTest 0 Test whether the equation is true and verify the data owner's permissions. If it is true, the data user has the permission to access the data owner. The test equation is: In the above formula, i∈[1,m], It is an auxiliary value for accurate verification of the permissions of a specific data owner. Pub is the aggregate value of the data owner's public key. i1 is the control index encryption parameter of the i-th data owner, γ i2 is the key permission verification parameter of the i-th data owner, c1, c2, c3 are the encryption index parameters of the data owner, β1 is the cloud server key parameter, Ap1 and Ap2 are the parameters for data users to search for trapdoors; S52, EqualTest 1 Test: Test EqualTest 1 Test whether the equation is true, check whether the data user permissions match the keywords, and if true, return the encrypted document cphF containing all keywords w w For data users, the test equation is: In the above formula, a, b, and c are trapdoor generation parameters, keyword binding parameters, and user permission verification parameters, respectively. H represents the hash function, w represents the keyword, t1 and t2 represent random numbers selected by the data owner from the parameter selection domain, tok2 and tok1 represent the parameters in the data user's search trapdoor, and y user ,σ user ,v both represent the second part of the auxiliary parameters of the data user's private key.
7. The searchable encryption method according to claim 1, wherein: The step S6 is specifically as follows: obtaining the encrypted document cohF containing all the keywords w returned by the cloud server w , split it into f1||f2||…, and then check whether the hash value of the encrypted file and the signature information match through the hash function. If H(f1||f2||…)=Sig[w], the returned result is correct; otherwise, the returned result is omitted by the cloud server.
8. A searchable encryption system with flexible access control and verifiable in a cloud environment, applicable to the searchable encryption method according to any one of claims 1 to 7, characterized in that: include: Trusted authority, used to initialize the system public parameters and key sequence to generate the system public key and system master key, and respectively calculate and distribute the public key and private key of the cloud server, the public-private key pair of the data owner and the private key of the data user, and update the private key of the data user with permission to change; The data owner is responsible for generating an encrypted index and uploading it to the cloud server, generating signature information and uploading it to the trusted authority, and updating the public key involved in the change; The cloud server is used to store encrypted indexes, receive data users to search for trapdoors, and return encrypted files to data users after permission verification; Data users are used to generate search traps and send them to the cloud server to verify the encrypted files returned by the cloud server.
9. A non-volatile storage medium storing computer instructions, wherein the instructions are executed by a processor to perform the method according to any one of claims 1 to 7.
Citation Information
Cited By
Verifiable and authorizable public key equivalent test method
CN122053088A