A content detection based access control encryption and decryption method and system

By employing content-based access control encryption and decryption methods, and leveraging the synergy of a central authority and a purifier, fine-grained control over information flow is achieved. This solves the problem of malicious content propagation in public-key encryption technology and improves the security and legitimacy of information transmission.

CN120915602BActive Publication Date: 2025-12-16HUAZHONG UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511418240.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2025-12-16
Estimated Expiration
2045-09-30

AI Technical Summary

Technical Problem

Existing public-key encryption technology cannot effectively prevent malicious users from spreading malicious content through legitimate encrypted channels, increasing the burden of decryption and content review on the recipient, and the read and write access control of information flow is insufficient to cope with the threats in complex network environments.

Method used

The access control encryption and decryption method based on content inspection is adopted. Global parameters and master private keys are generated by a central authoritative institution. Combined with a purifier, the ciphertext is purified to ensure that only legitimate users can decrypt legitimate content. The purifier transforms illegal or malicious ciphertext to achieve fine-grained access control.

Benefits of technology

It effectively prevents the spread of malicious content, improves system security, ensures the secure transmission and storage of sensitive information, reduces the burden of decryption and content review on the recipient, and enhances the ability to combat internal threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915602B_ABST
    Figure CN120915602B_ABST
Patent Text Reader

Abstract

The application discloses a content detection-based access control encryption and decryption method and system, and belongs to the technical field of cryptography, which comprises the following steps: an access control strategy input by a central authority is initialized with global parameters and a master private key to generate a trapdoor; the master private key is sent to a sender authority to generate an encryption key for the sender; the sender encrypts information by using the encryption key, and then sends the ciphertext to a purifier; the purifier purifies the ciphertext, and broadcasts the purified ciphertext to all receivers; and no corresponding information can be transmitted and received by the method except the sender and the receiver who meet the access control strategy. Through the cooperation of all parties, the application realizes the encrypted transmission and identity authentication of user information on the basis of ensuring the monitoring efficiency of sensitive information, fully protects the privacy of sensitive information and identity information of users, and thus solves the technical problem that the transmission and storage of sensitive information in the prior art are at risk of being stolen.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of cryptography, and more particularly relates to an access control encryption and decryption method and system based on content detection. BACKGROUND

[0002] With the rapid development of information technology and the widespread application of the Internet, information security problems have become one of the major challenges faced by today's society. Especially in network communication, how to protect the confidentiality, integrity and availability of data, prevent unauthorized access and the spread of malicious content is a core problem in information security research. As a traditional encryption method, public key encryption (PKE) effectively protects the confidentiality of data in information transmission through the pairing of public and private keys. Specifically, the sender uses the public key of the receiver to encrypt the message, and only the receiver holding the corresponding private key can decrypt and access the message content. This encryption mechanism ensures the privacy of information flow in the transmission process and avoids the theft of unauthorized external users.

[0003] However, although the public key encryption technology can effectively protect the content of information from being accessed illegally, it also has certain limitations. In the PKE system, anyone can use the public key to encrypt information, so malicious users may send messages containing harmful content, such as malicious emails or phishing links, to the target user through a legitimate encryption channel. This makes the receiver need additional decryption and content review work, increasing the security risk and operational burden. In the face of increasingly complex network environment, protecting the privacy of information content alone cannot meet the security needs of modern communication. In some high-security application scenarios, in addition to the protection of information content, more fine-grained control of information flow transmission and reception is needed to ensure the legality of each party in communication and the credibility of information, and the read permission control of information flow is insufficient to cope with the evolving threats, and the write permission control of information flow is also particularly important. SUMMARY

[0004] In view of the above defects or improvement needs of the prior art, the present application provides an access control encryption and decryption method and system based on content detection, which aims to solve the technical problem that sensitive information transmission and storage exist the risk of theft in the prior art.

[0005] To achieve the above-mentioned purpose, according to one aspect of the present application, an access control encryption and decryption method based on content detection is provided, which is applied to an access control encryption and decryption system, the access control encryption and decryption system comprising: a central authority, a sender authority, a receiver authority, a sender, a purifier and a receiver; the method comprising:

[0006] S1: the center authority: according to the input security parameters and access control policy generate global parameters and master private key , and distribute the global parameters and master private key to the sender authority and the receiver authority; and generate the key pattern corresponding to the sensitive information corresponding trapdoor set, and send the trapdoor set to the purifier;

[0007] S2: the sender authority: when receiving the identity information of the sender , according to the identity information , the global parameters and the master private key generate encryption key and feedback to the sender;

[0008] S3: the receiver authority: when receiving the identity information of the receiver , according to the identity information , the global parameters and the master private key generate decryption key and feedback to the receiver;

[0009] S4: the sender: use the encryption key to encrypt the plaintext message into ciphertext , and send the ciphertext to the purifier;

[0010] S5: the purifier: receive the ciphertext , if the ciphertext meets the purification requirements, use the trapdoor set to purify and get the purified ciphertext ;

[0011] S6: the receiver: use the decryption key to decrypt the purified ciphertext .

[0012] Further, the S1 includes: the center authority performs the following operations:

[0013] S101: run the initialization algorithm of access control encryption technology ACE to get the public parameters of ACE and master private key : , access control policy , The numbers are random; the common parameters of D-PM are obtained by running the initialization algorithm of the decryptable pattern matching technique D-PM: The corresponding public-private key pair is obtained by running the D-PM key generation algorithm, a decryptable pattern matching technique. Finally, the master key is obtained. and the global parameters ; This is the maximum length limit of the keyword pattern;

[0014] S102: Generate keyword patterns corresponding to sensitive information The corresponding trapdoor set;

[0015] S103: Transmit the master private key and the global parameters To the sending authority and the receiving authority; transmit the trapdoors within the trapdoor set. To the purifier.

[0016] Further, step S102 includes: based on the master private key Keyword patterns corresponding to the sensitive information Generate the trapdoors within the trapdoor set. : ,in length .

[0017] Furthermore, S2 includes: the sending authority performing the following operations:

[0018] S201: When the sender's identity information is received... At that time, based on the master private key and the sender's identity information Run the ACE encryption key generation algorithm to obtain the ACE encryption key: ;

[0019] S202: Will It is used as an encryption key and transmitted to the corresponding sender.

[0020] Furthermore, S3 includes the recipient authority performing the following operations:

[0021] S301: When the identity information of the receiver is received... At that time, based on the master private key and the aforementioned identity information Run the ACE decryption key generation algorithm to obtain the ACE decryption key: ;

[0022] S302: obtaining the ciphertext as the decryption key and transmitting to the corresponding receiver.

[0023] Further, the S4 includes the sender performing the following operations:

[0024] S401: randomly selecting an auxiliary parameter , is a prime number, is a modulus of an integer field , represents uniform random selection;

[0025] S402: running the ACE encryption algorithm according to the encryption key to obtain the corresponding ACE encryption ciphertext and ; running the D-PM encryption algorithm to obtain the corresponding D-PM detection ciphertext ;

[0026] S403: integrating the ciphertext and transmitting to the purifier.

[0027] Further, the S5 includes the purifier performing the following operations:

[0028] S501: judging whether the received ciphertext meets all the trapdoor sets for all the trapdoors corresponding to the purifying requirements, and if so, performing S502; otherwise, ending;

[0029] S502: running the purifying algorithm of ACE on the ciphertext to obtain the to-be-purified ciphertext and ;

[0030] S503: parsing the to-be-purified ciphertext into , which does not carry any information about the plaintext, and which contains the effective information of the plaintext;

[0031] S504: selecting a randomization factor , running the randomization algorithm of D-PM on and to obtain ;

[0032] S505: integrating the purifying ciphertext and transmitting to the corresponding receiver.

[0033] Furthermore, S501 includes: trapdoors for all trapdoor sets. and the ciphertext Running the D-PM detection algorithm yields the corresponding output result set. ;like If the set is empty, it is considered as the ciphertext. If the corresponding purification requirements are met, proceed with S502; otherwise, the process ends.

[0034] Furthermore, S6 includes the pick-up / drop-off person performing the following operations:

[0035] S601: Based on the decryption key and the purified ciphertext Run the ACE decryption algorithm to obtain auxiliary parameters. Running the ACE decryption algorithm yields the detected ciphertext. ;

[0036] S602: Run the D-PM decryption algorithm. If both the receiver and the corresponding sender are legitimate users within the access control policy, the decrypted plaintext is obtained. .

[0037] According to another aspect of the present invention, an access control encryption and decryption system based on content detection is provided, comprising:

[0038] The central authority is used to determine the security parameters input. and access control policies Generate global parameters and the master private key and global parameters and master private key Distribute to the authoritative sending agency and the authoritative receiving agency; and generate keyword patterns corresponding to sensitive information. The corresponding trapdoor set is then sent to the purifier.

[0039] The sender's authoritative body is used to verify the sender's identity information upon receipt. At that time, based on the aforementioned identity information The global parameters and the master private key Generate encryption key And feedback is sent back to the sender;

[0040] The recipient's authoritative body is used to verify the recipient's identity information upon receipt. At that time, based on the identity information The global parameters and the master private key Generate decryption key and feedback to the receiver;

[0041] a sender, for using the encryption key to encrypt a plaintext message into a ciphertext and sending the ciphertext to a purifier;

[0042] a purifier, for receiving the ciphertext and, if the ciphertext meets the purifying requirement, purifying the ciphertext using the trapdoor set to obtain a purified ciphertext

[0043] a receiver, for using the decryption key to decrypt the purified ciphertext .

[0044] Overall, compared with the prior art, the above technical solutions conceived by the present application can achieve the following beneficial effects:

[0045] (1) The access control encryption and decryption method based on content detection provided by the present application, the access control strategy input by the central authority and the security parameter initialization global parameter and the master private key, and the trapdoor is generated according to the input content detection keyword mode. Then the central authority sends the master private key to the sender authority. The sender authority generates an encryption key for the sender according to the master private key and the user information. The sender uses the encryption key to encrypt the information, and then sends the ciphertext to the purifier. The purifier purifies the ciphertext and broadcasts the purified ciphertext to all receivers. Except for the receivers meeting the access control strategy, any other receiver cannot obtain the information sent by the sender through the method; except for the sender meeting the access control strategy, any other sender cannot generate a legal ciphertext and send it to a suitable receiver through the method. Through the cooperation and collaboration of each participant, the present application realizes the encrypted transmission and identity verification of user information on the basis of ensuring the efficiency of sensitive information supervision, fully protects the privacy of sensitive information and identity information of users, and thus solves the technical problem that the transmission and storage of sensitive information in the prior art are at risk of being stolen.

[0046] (2) The content detection of the sending ciphertext by the purifier, any ciphertext that does not meet the requirements (the ciphertext is illegally generated or the ciphertext contains malicious content) cannot be decrypted by the sender. Through the above "unread rule", "unwritable rule" and content detection of the ciphertext, the behavior of the sender and the behavior of the receiver are restricted, and the security of the system is guaranteed to the greatest extent.

[0047] ​​(3) The purifier purifies the ciphertext. If the ciphertext sent by the sender does not meet the requirements (the ciphertext is illegally generated or the ciphertext contains malicious content), the purifier will convert it into meaningless content. Otherwise, the purifier will broadcast the purified ciphertext to all receivers. If the receiver meets the corresponding access control policy, the receiver can decrypt the ciphertext. Thus, the spread of malicious content is effectively prevented. This extension method can improve the ability of the system to resist internal threats, prevent attackers from spreading malicious information through legitimate user identities, and ensure the overall security of the communication system. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 A schematic diagram of the content detection-based access control encryption and decryption system provided by the present application.

[0049] Figure 2 A flowchart of the content detection-based access control encryption and decryption method provided by the present application. DETAILED DESCRIPTION

[0050] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application. In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as they do not conflict with each other.

[0051] Figure 1 A schematic diagram of the content detection-based access control encryption and decryption system provided by the present application. The content detection-based access control encryption and decryption system provided by the present application includes a central authority, a sender authority, a receiver authority, a sender, a purifier, and a receiver.

[0052] The central authority has the functions of generating global parameters and a master private key according to input security parameters and access control policies, distributing the global parameters and the master private key to the sender authority and the receiver authority, generating corresponding trapdoors for keyword patterns corresponding to each sensitive information, virus feature, and illegal behavior that needs to be detected, and sending all trapdoors to the purifier. As a trusted entity, the central authority acts as a rule maker and can set global access control policies, providing a basis for key generation and access permission management in the system.

[0053] The sender authority has the functions of receiving global parameters and a master private key and the identity information of the sender, and generating corresponding encryption keys. As a trusted entity, the sender authority can independently generate encryption keys according to the identity of the sender, ensuring that only authorized senders can perform encryption operations.

[0054] The recipient authority has the capability to receive global parameters, the master private key, and the recipient's identity information, and generate the corresponding decryption key. As a trusted entity, the recipient authority independently generates the decryption key based on the recipient's identity, thereby ensuring the security and accuracy of the decryption operation.

[0055] The sender has the capability to receive the corresponding encryption key, use the encryption key to encrypt the plaintext message into ciphertext, and then send the ciphertext to the purifier. The sender does not communicate directly with the receiver; instead, it forwards messages through the purifier to ensure that the message flow complies with global access control rules under the purifier's control.

[0056] The purifier has a receiving trapdoor that purifies all received ciphertext and sends the purified ciphertext to all recipients. Specifically, it performs a series of calculations on the ciphertext according to a preset program. If the ciphertext does not meet the requirements (including illegally generated ciphertext and messages containing malicious content), the purifier will convert it into meaningless content; if the ciphertext meets the requirements, the purifier will convert it into purified ciphertext. As an honest but semi-trusted entity, the purifier strictly follows established rules and will not actively tamper with or disclose the ciphertext content. However, considering that the purifier may be curious about analyzing or interpreting the ciphertext, it is designed to be restricted from being fully trusted, unable to access the decryption key, and unable to understand the actual meaning of the ciphertext. Furthermore, the purifier cannot know the identity of the sender or receiver of the ciphertext, thus effectively avoiding potential privacy leaks.

[0057] The receiver has the ability to receive the corresponding decryption key and the cleaned ciphertext, and attempt to decrypt the ciphertext using the decryption key to recover the plaintext message. If the identities of the receiver and the ciphertext sender comply with the access control policy, the receiver will successfully decrypt; otherwise, if the identities of the communicating parties do not comply with the access control policy, or if the ciphertext has been converted into meaningless information by the cleaner, the receiver will fail to decrypt and will be unable to recover the plaintext.

[0058] Figure 2 The flowchart of the access control encryption and decryption method based on content detection provided by the present invention includes the following steps:

[0059] S1: The central authority: based on the input security parameters and access control policies Generate global parameters and the master private key The master private key is used not only in encryption keys during communication. With decryption key The generation of these keywords will also participate in keyword trapping by the central authoritative institution. The generation of global parameters by the central authoritative body. and the master private key is distributed to the sender authority and the receiver authority, while also generating the keyword pattern corresponding to each sensitive information, virus feature, violation behavior, etc. that needs to be detected corresponding trapdoor , and all trapdoors are sent to the purifier to facilitate its execution of the purification operation. As a trusted entity, the central authority acts as a rule maker, capable of setting global access control policies and providing a foundation for key generation and access management in the system.

[0060] S2: The sender authority: generates the corresponding encryption key based on the received global parameters and the master private key , as well as the sender's identity information . As a trusted entity, the sender authority can independently generate an encryption key based on the sender's identity, ensuring that only authorized senders can perform encryption operations.

[0061] S3: The receiver authority: generates the corresponding decryption key based on the received global parameters and the master private key , as well as the receiver's identity information . As a trusted entity, the receiver authority independently generates a decryption key based on the receiver's identity, ensuring the security and accuracy of the decryption operation.

[0062] S4: The sender: obtains the corresponding encryption key from the sender authority based on its own identity information . When the sender sends a message, it uses the encryption key to encrypt the plaintext message into ciphertext , and sends the ciphertext to the purifier. The sender does not directly communicate with the receiver, but instead forwards messages through the purifier to ensure that the message flow complies with the global access control rules under the control of the purifier.

[0063] S5: The purifier: performs purification processing on all received ciphertexts based on the received trapdoor . Specifically, it performs a series of operations on the ciphertext according to the preset program, and if the ciphertext does not meet the requirements (including illegally generated ciphertexts and messages containing malicious content), the purifier will convert it into meaningless content; if the ciphertext If the requirements are met, the purifier will convert it into purification ciphertext. As an honest but semi-trusted entity, the purifier strictly adheres to established rules and will not actively tamper with or disclose the ciphertext content. However, considering the purifier's potential curiosity about analyzing or deciphering the ciphertext, it is designed to be untrustworthy, unable to access the decryption key, or understand the actual meaning of the ciphertext. Furthermore, the purifier cannot know the identity of the sender or receiver of the ciphertext, thus effectively preventing potential privacy leaks.

[0064] S6: The recipient: based on their own identity information Obtain the corresponding decryption key from the recipient's authoritative institution. The recipient will also receive purified encrypted text from the purifier. And try to use the decryption key For ciphertext Decrypt to recover the plaintext message If the identities of the receiver and the sender of the ciphertext match the access control policy, the receiver will successfully decrypt the message; otherwise, if the identities of both parties do not match the access control policy, or if the ciphertext... If the plaintext has been converted into meaningless information by the purifier, the receiver will fail to decrypt it and will be unable to recover the original plaintext. .

[0065] In one embodiment, S1 includes the central authority performing the following operations:

[0066] S101: Utilizing safety parameters Access control policies and the maximum length limit of keyword patterns Initialization is performed. First, the initialization algorithm of the Access Control Encryption (ACE) technology is run to obtain the ACE public parameters and master private key: Then, the initialization algorithm of the decryptable pattern matching technique D-PM is run to obtain the common parameters of D-PM: Finally, the key generation algorithm of the decryptable pattern matching technique D-PM is run to obtain the corresponding public-private key pair: The system's master key is obtained through integration. and global parameters .

[0067] S102: Based on the generated master private key and keyword patterns Generate a trapdoor: ,in length .

[0068] S103: Transmit the master private key To the authoritative sending authority and the authoritative receiving authority; the transmission trapdoor. To the air purifier.

[0069] In one embodiment, S2 includes the sender authority performing the following operations:

[0070] S201: The sending authority uses the received master private key... and identity information Run the ACE encryption key generation algorithm to obtain the ACE encryption key: .

[0071] S202: Integrate and obtain the user's encryption key Transmit the encryption key. To each sender.

[0072] In one embodiment, prior to S201, the sender performs the following operation: submits its own identity information. Send to the authoritative organization that sent it.

[0073] In one embodiment, S3 includes the recipient authority performing the following operations:

[0074] S301: The recipient's authoritative institution uses the received master private key... and identity information Run the ACE decryption key generation algorithm to obtain the ACE decryption key: .

[0075] S302: Integrate and obtain the user's decryption key. Transmit the decryption key To each recipient.

[0076] In one embodiment, prior to S301, the receiver performs the following operation: submits its own identity information. Send to the recipient's authoritative organization.

[0077] In one embodiment, S4 includes the sender performing the following operation:

[0078] S401: The sender for each Random selection Record auxiliary parameters .in It is the corresponding value in the global parameters of D-PM.

[0079] S402: The sender uses the received encryption key. Run the ACE encryption algorithm to obtain the corresponding ACE encrypted ciphertext. , as well as .Notice, and In fact, it is for multiple elements The generated ACE ciphertext has a structure similar to The only part that truly changed was... Therefore, in actual implementation, all Share the same This reduces the ciphertext size to save storage space and computational overhead. The sender runs the D-PM encryption algorithm to obtain the corresponding D-PM detection ciphertext. .

[0080] S403: Integration yields the final ciphertext The sender will send the final encrypted message. Transmitted to the air purifier.

[0081] In one embodiment, S5 includes the purifier performing the following operation:

[0082] S501: Determine the received ciphertext. Does it satisfy the condition that all trapdoor sets are for all trapdoors? If the purification requirements are met, proceed to step S502; otherwise, the process ends.

[0083] S502: The purifier runs the ACE purification algorithm to obtain the purification ciphertext. , as well as .

[0084] S503: The purifier parses the input ciphertext into... This algorithm only uses the latter half, so for simplicity, it can be written as... ; Parse the purified ciphertext into ,as well as .

[0085] S504: Air purifier selection randomization factor The final purified ciphertext is obtained through calculation. In this step of the calculation, the purifier needs to perform some necessary group element type conversions.

[0086] S505: The air purifier will purify encrypted text. Transmitted to the receiver.

[0087] In one embodiment, S501: The purifier, based on the received keyword... Corresponding trapdoor and ciphertext Running the D-PM detection algorithm yields the corresponding output result set. The purifier will detect all detected traps. All of them were calculated to obtain the corresponding If all If all sets are empty, proceed to the next step; otherwise, if any one of them is empty... If it is not an empty set, then the purifier's purification algorithm outputs... The air purifier stopped operating.

[0088] In one embodiment, S6 includes the receiver performing the following operation:

[0089] S601: The receiver uses the received decryption key. and purification cipher Running ACE's decryption algorithm yields... and Record auxiliary parameters. .

[0090] S602: The receiver runs the ACE decryption algorithm to obtain the detection ciphertext. and If the identities of the receiver and the ciphertext sender conform to the access control policy, the receiver can obtain the decrypted plaintext by running the D-PM decryption algorithm. .

[0091] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A content-based access control encryption / decryption method, characterized in that, The method is applied to an access control encryption / decryption system, which includes: a central authority, a sender authority, a receiver authority, a sender, a purifier, and a receiver; the method includes: S1: The central authority: based on the input security parameters and access control policies Generate global parameters and the master private key and global parameters and master private key Distribute to the authoritative sending agency and the authoritative receiving agency; and generate keyword patterns corresponding to sensitive information. The corresponding trapdoor set is then sent to the purifier. S2: The authoritative institution of the sender: upon receiving the sender's identity information. At that time, based on the aforementioned identity information The global parameters and the master private key Generate encryption key And feedback is sent back to the sender; S3: The authoritative institution of the recipient: upon receiving the identity information of the recipient. At that time, based on the identity information The global parameters and the master private key Generate decryption key And feedback is sent to the recipient; S4: The sender: using the encryption key Plain text message Encrypt to ciphertext and ciphertext Send to the air purifier; S5: The purifier receives the encrypted message. If the ciphertext If the purification requirements are met, the purified ciphertext is obtained by using the trapdoor set. ; S6: The receiver: uses the decryption key For the purified ciphertext Decrypt; S1 includes the following operation performed by the central authority: S101: Run the initialization algorithm of the access control encryption technology ACE to obtain the public parameters of ACE. and the master private key : Access control policy , The numbers are random; the common parameters of D-PM are obtained by running the initialization algorithm of the decryptable pattern matching technique D-PM: The corresponding public-private key pair is obtained by running the D-PM key generation algorithm, a decryptable pattern matching technique. Finally, the master private key is obtained. and the global parameters ; This is the maximum length limit of the keyword pattern; S102: Generate the keyword pattern The corresponding trapdoor set; S103: Transmit the master private key and the global parameters To the sending authority and the receiving authority; transmit the trapdoors within the trapdoor set. To the purifier; S102 includes: based on the master private key and the keyword pattern Generate the trapdoors within the trapdoor set. : ,in length .

2. The access control encryption and decryption method based on content detection as described in claim 1, characterized in that, S2 includes: the sending authority performing the following operations: S201: When the sender's identity information is received... At that time, based on the master private key and the sender's identity information Run the ACE encryption key generation algorithm to obtain the ACE encryption key: ; S202: Will It is used as an encryption key and transmitted to the corresponding sender.

3. The access control encryption and decryption method based on content detection as described in claim 2, characterized in that, S3 includes the recipient authority performing the following operations: S301: When the identity information of the receiver is received... At that time, based on the master private key and the aforementioned identity information Run the ACE decryption key generation algorithm to obtain the ACE decryption key: ; S302: Will It is used as the decryption key and transmitted to the corresponding recipient.

4. The access control encryption and decryption method based on content detection as described in claim 3, characterized in that, S4 includes the sender performing the following operation: S401: Randomly select auxiliary parameters , It is a prime number. For modulus is integer field, This indicates uniform random selection; S402: According to the encryption key Running the ACE encryption algorithm yields the corresponding ACE encrypted ciphertext. as well as Running the D-PM encryption algorithm yields the corresponding D-PM detection ciphertext. ; S403: Integrate to obtain the ciphertext And then transmit it to the purifier.

5. The access control encryption and decryption method based on content detection as described in claim 4, characterized in that, S5 includes the purifier performing the following operation: S501: Determine the received ciphertext Does it satisfy the condition that all trapdoor sets are for all trapdoors? If the purification requirements are met, proceed to step S502; otherwise, the process ends. S502: Regarding the ciphertext The ciphertext to be cleaned is obtained by running the ACE cleanup algorithm. and ; S503: Parse the ciphertext to be purified into... , It does not carry any information about the plaintext, but The plaintext contains valid information; S504: Selecting the randomization factor ,right and Running the randomization algorithm of D-PM yields ; S505: Integrated to obtain purified ciphertext And transmit it to the corresponding receiver.

6. The access control encryption and decryption method based on content detection as described in claim 5, characterized in that, S501 includes: trapdoors for all trapdoor sets. and the ciphertext Running the D-PM detection algorithm yields the corresponding output result set. ;like If the set is empty, it is considered as the ciphertext. If the corresponding purification requirements are met, proceed with S502; otherwise, the process ends.

7. The access control encryption and decryption method based on content detection as described in claim 5, characterized in that, S6 includes the receiver performing the following operation: S601: Based on the decryption key and the purified ciphertext Run the ACE decryption algorithm to obtain auxiliary parameters. Running the ACE decryption algorithm yields the detected ciphertext. ; S602: Run the D-PM decryption algorithm. If both the receiver and the corresponding sender are legitimate users within the access control policy, the decrypted plaintext is obtained. .

8. An access control encryption and decryption system based on content detection, characterized in that, The method for executing the content-based access control encryption / decryption method according to any one of claims 1-7 includes: The central authority is used to determine the security parameters input. and access control policies Generate global parameters and the master private key and global parameters and master private key Distribute to the authoritative sending authority and the authoritative receiving authority; and generate the keyword pattern. The corresponding trapdoor set is then sent to the purifier. The sender's authoritative body is used to verify the sender's identity information upon receipt. At that time, based on the aforementioned identity information The global parameters and the master private key Generate encryption key And feedback is sent back to the sender; The recipient's authoritative body is used to verify the recipient's identity information upon receipt. At that time, based on the identity information The global parameters and the master private key Generate decryption key And feedback is sent to the recipient; The sender, used with the encryption key Plain text message Encrypt to ciphertext and ciphertext Send to the air purifier; Purifier, used to receive the ciphertext If the ciphertext If the purification requirements are met, the purified ciphertext is obtained by using the trapdoor set. ; The receiver, for using the decryption key For the purified ciphertext Decryption is performed.