Cloud re-encrypted data access control method and system based on attribute anti-quantum

By adopting a cloud-based re-encryption data access control method based on quantum resistance properties, this method solves the problems of traditional encryption being easily broken, inefficient, and coarse-grained sharing in cloud data sharing. It achieves high security and fine-grained sharing under quantum computer attack resistance and supports flexible authorization.

CN121508964APending Publication Date: 2026-02-10SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511669621.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-14
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing technologies, cloud-based data sharing suffers from problems such as traditional encryption schemes being easily broken by quantum computers, low efficiency, easy exposure of identity and privacy information, and the inability of coarse-grained sharing to meet fine-grained needs.

Method used

A cloud-based re-encryption data access control method based on attribute quantum resistance is adopted. The system parameters are generated through initialization by an authoritative center, the data owner sets the access policy and encrypts the resources, the data user generates the key, the cloud server performs re-encryption, the attribute base and access control tree are used to achieve flexible authorization, and the timestamp is used to determine the legal status.

Benefits of technology

It achieves resistance to quantum computer attacks, improves data security and privacy, supports fine-grained data sharing, and offers high authorization flexibility while reducing the exposure of identity information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508964A_ABST
    Figure CN121508964A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud re-encrypted data access control method and system based on attribute anti-quantum, and the method comprises the steps: firstly executing an initialization operation by an authority center to generate system parameters, including system public parameters, a master key and the like; the data owner sets an access strategy tree of the resource, encrypts the resource according to an access strategy and outputs a ciphertext; the data user generates a corresponding secret key according to own attributes; the cloud generates a re-encryption key of the resource; the cloud end re-encrypts the resources uploaded to the cloud; the data user generates a key for decrypting the resource; and the data user carries out decryption operation on the resource through the decryption key so as to obtain the plaintext. According to the method, quantum computer attack resistance is realized based on lattices; through a cloud re-encryption step, an attacker is prevented from exploring a potential relationship between a data owner and a data user; and data access control is realized by adopting an attribute base and an access control tree, so that the authorization flexibility is higher and the privacy is stronger.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of information security, and mainly relates to a cloud re-encryption data access control method and system based on attribute resistance to quantum. BACKGROUND

[0002] With the vigorous development of Internet technology, emerging technologies such as cloud computing and the Internet of Things are steadily becoming the backbone of intelligentization and digitization. More and more terminals upload data to the cloud for calculation, storage and sharing. With the wide application of cloud computing, secure sharing of cloud data has become an important problem to be solved.

[0003] However, the problem of data sharing is also increasingly prominent. First, with the development of quantum computers, the possibility of breaking traditional encryption schemes is increasing, and data security cannot be guaranteed. Second, the current data sharing mechanism generally has problems such as low efficiency and easy exposure of identity privacy information, which may bring great risks if obtained by the enemy. The existence of these problems not only restricts the circulation of data, but also poses a great threat to the privacy and security of data terminals. Data leakage and identity privacy leakage have become key problems restricting data sharing.

[0004] On the other hand, the total amount of contemporary data is growing explosively, which has caused not a small hindrance to the sharing of data. The encryption and decryption method based on identity or single password in the past can only achieve coarse-grained sharing and cannot meet the needs of fine-grained sharing in actual scenarios. SUMMARY

[0005] The present application is aimed at the problems existing in the prior art, and provides a cloud re-encryption data access control method and system based on attribute resistance to quantum. First, the authority center performs initialization operation to generate system parameters, including system public parameters and master key, etc. The data owner sets the access policy tree of the resource, encrypts the resource according to the access policy and outputs the ciphertext. The data user generates the corresponding key according to the attribute possessed by himself. The cloud generates the re-encryption key of the resource. The cloud re-encrypts the resource uploaded to the cloud. The data user generates the decryption key of the resource. The data user performs decryption operation on the resource through the decryption key, thereby obtaining the plaintext. The method of the present application is based on lattice to resist quantum computer attacks. Through the cloud re-encryption step, the potential relationship between the data owner and the data user is avoided to be explored by the attacker. The attribute-based and access control tree are adopted to realize data access control, so that the authorization flexibility is higher and the privacy is stronger. With the help of time stamp, the legal status of the current data user is determined.

[0006] In order to achieve the above purpose, the technical scheme adopted by the present application is: a cloud re-encryption data access control method based on attribute resistance to quantum, comprising the following steps:

[0007] S1, system initialization: according to the security parameters, the authority center CA performs system initialization to generate system parameters, the system parameters including system public parameters and master key , specifically:

[0008]

[0009] wherein, is obtained by sampling algorithm modular in the field dimension of random matrix, is the trapdoor matrix in the field modular dimension of ; is a random matrix in the field modular dimension of ; is the number of users in the system; is the public matrix in the field modular dimension of ; is the public vector in the field modular dimension of ; is the timestamp space; is the mapping function; is the identity matrix of the data owner; is the number of system attributes; is the system attribute set; is a complete binary tree, and each leaf node represents a terminal;

[0010] S2, data owner encrypts resource: the data owner sets access policy for the resource, and encrypts the plaintext resource to obtain ciphertext ; wherein, is the ciphertext component carrying plaintext information, is the auxiliary verification ciphertext component carrying attribute information, is the number of attributes contained in the access policy, is the auxiliary verification ciphertext component carrying leaf node information, is a complete binary tree, represents the leaf node of the complete binary tree;

[0011] S3, data user key generation: the authority center CA generates the key of the data user through The sampling algorithm obtains attribute trapdoor parameters associated with the identity of the data user and secretly distributes the attribute trapdoor parameters to the data user, and the data user uses the attribute trapdoor parameters to generate an attribute key to obtain a data user key; wherein the attribute trapdoor parameters are secretly stored by an authority center CA, and the attribute key is secretly stored by the data user;

[0012] S4, cloud server encryption key generation: the authority center CA uses The sampling algorithm generates trapdoor parameters and secretly distributes the trapdoor parameters to the cloud server, and the cloud server uses to generate an encryption key ;

[0013] S5, cloud server re-encryption resource: the data owner uploads the resource to the cloud, and the cloud server uses the encryption key to re-encrypt the original resource attribute parameters and uses the timestamp to re-encrypt the identity node parameters of the data user to obtain re-encrypted ciphertext ; wherein the re-encrypted ciphertext is returned to the terminal when the terminal accesses the resource, otherwise it is saved in the cloud;

[0014] S6, data user decryption key generation: the authority center CA generates the trapdoor parameters of the terminal through The sampling algorithm generates the trapdoor parameters of the terminal and binds them on the nodes corresponding to the full binary tree, and the data user uses the trapdoor parameters and the timestamp parameters to use The sampling algorithm obtains the timestamped trapdoor parameters, and uses the timestamped trapdoor parameters to use The sampling algorithm obtains the decryption key ;

[0015] S7, decrypting the resource: the data user decrypts the re-encrypted ciphertext returned by the cloud server and the decryption key of the data user to obtain plaintext information, realizing secure data access; the decryption formula is specifically:

[0016]

[0017] wherein, is the ciphertext component carrying the plaintext information, is the decryption key of the node at time , is a transpose symbol, is the re-encrypted ciphertext of the node in the tree for auxiliary verification, is the decryption key of the first attribute of the node , is the re-encrypted ciphertext component carrying the attribute information for auxiliary verification, for the number of attributes involved in the access policy, for the modulus, for the noise, for the plaintext information.

[0018] As an improvement of the present application, the data owner encryption process of step S2 specifically comprises the following steps:

[0019] S21, selecting random vectors: the data owner selects a corresponding number of random vectors according to the number of attributes involved in the access policy, and sums the vectors; the expression of the random vectors is:

[0020] ;

[0021] The expression of the vector sum is:

[0022] ;

[0023] wherein, is the number of attributes involved in the access policy; is the domain modulus dimension random vector;

[0024] S22, information part encryption: the data owner calculates the partial ciphertext carrying information using the parameters obtained in step S21 ; the expression of the ciphertext carrying information is:

[0025] ;

[0026] wherein, is the vector in the domain modulus dimension ; is the plaintext information; is the noise; is the modulus;

[0027] S23, attribute part encryption: the data owner calculates the partial ciphertext carrying attributes using the parameters obtained in step S21 ; the expression of the ciphertext carrying attributes is:

[0028] , ;

[0029] wherein, is the augmented form of and matrix; For attributes Hash mapping; For common parameters; For noise;

[0030] S24, Leaf node partial encryption: The data owner uses the parameters obtained in step S21. and common parameters Calculate the partial ciphertext carrying the leaf nodes. The encrypted expression carrying the information is:

[0031] ;

[0032] in, A complete binary tree Nodes in ; Represents a leaf node of a complete binary tree; for and The product of.

[0033] As another improvement of the present invention, in step S3, the attribute trapdoor parameter associated with the user identity is specifically as follows:

[0034] ;

[0035] in, For the attributes of data users, For the identity matrix of data users, It is the standard deviation parameter of the Gaussian distribution;

[0036] The expression for the attribute key is:

[0037] ;

[0038] Among them, attribute key .

[0039] As another improvement of the present invention, in step S4, the trapdoor parameter allocated to the cloud server is specifically as follows:

[0040] ;

[0041] The specific encryption key for each attribute of the terminal is as follows:

[0042] ;

[0043] in, It refers to the number of system attributes.

[0044] As another improvement of the present invention, in step S5, encrypting the original resource attribute parameters using an encryption key specifically involves:

[0045] ;

[0046] The expression for the verification formula is:

[0047] ;

[0048] in, It is a moment The timestamp belongs to the timestamp space. .

[0049] As another improvement of the present invention, in step S5, the trapdoor parameters generated by the authority center are stored in a complete binary tree structure and are public information, while the timestamped trapdoor parameters and decryption keys generated by data users are kept secret by the users themselves; the expression for the trapdoor parameters generated by the authority center is:

[0050] ;

[0051] The expression for the timestamped trapdoor parameter is:

[0052] ;

[0053] The decryption key expression for the data user is:

[0054] ;

[0055] in, for The trapdoor, These are common system parameters. This is the system master key. Let be the standard deviation parameter of the Gaussian distribution. for The trapdoor, for and The product of For a moment timestamp matrix, Represents a node At any moment The decryption key, These are common parameters.

[0056] To achieve the above objectives, the present invention also adopts the following technical solution: a cloud-based re-encrypted data access control system based on quantum resistance properties, comprising a computer program that, when executed, can implement the method described in any of the above-mentioned embodiments.

[0057] Compared with the prior art, the present invention has the following beneficial effects:

[0058] (1) This invention addresses the data security problem against quantum computer attacks based on lattices. It utilizes the difficulty of lattices and sampling algorithms to embed data information within the system, thereby protecting the confidentiality of the data information.

[0059] (2) In the method of the present invention, after the encrypted data is uploaded to the cloud, the cloud server performs re-encryption on the encrypted data and returns the re-encrypted ciphertext when the data user accesses the resource. Attackers cannot discover the relationship between the data owner and the data user through the re-encrypted ciphertext in the database, which is more secure and reliable.

[0060] (3) This invention uses attribute base and access control tree to implement data access control. Compared with identity base, attribute base is managed in batches through attribute rules. When the number of users increases, only attributes need to be added, without modifying the permission rules. This makes authorization more flexible and reduces the exposure of identity information.

[0061] (4) The timestamp element added in this invention can control the decryption capability based on whether the current state of the data user is legitimate. Users in an illegitimate state cannot decrypt correctly. Attached Figure Description

[0062] Figure 1 This is a system framework diagram of the method of the present invention;

[0063] Figure 2 This is a flowchart of the method of the present invention. Detailed Implementation

[0064] The present invention will be further illustrated below with reference to the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are for illustrative purposes only and are not intended to limit the scope of the invention.

[0065] Example 1

[0066] The symbols and their definitions in this scheme are shown in Table 1:

[0067] Table 1

[0068] This paper presents a cloud-based re-encryption data access control method based on attribute-based quantum resistance. It addresses the data security challenge of resisting quantum computer attacks by using lattice-based cryptography and employs attribute-based encryption to meet fine-grained requirements in real-world scenarios. Quantum-resistant cryptography is mainly divided into five types: lattice-based, encoding-based, hash-based, multivariate-based, and homology-based. Among them, lattice-based cryptography, which uses difficult problems such as the shortest vector problem in high-dimensional lattices, the nearest vector problem, and fault-tolerant learning as its security foundation, has become the most promising direction. Attribute-based encryption, addressing the fine-grained requirements in these scenarios, allows encryption and decryption operations to be based on attributes. Access permissions are controlled according to a set of attributes without needing to know the specific identity information of the data user.

[0069] A cloud-based re-encryption data access control method based on attribute quantum resistance in the Internet of Things (IoT) environment, applied to, for example... Figure 1 The framework shown includes four participants:

[0070] (1) Authority Center (CA): Responsible for performing system initialization operations, generating public parameters and broadcasting them within the system, holding the system master private key, and providing necessary parameter generation for other entities.

[0071] (2) Cloud server (CS): It has powerful storage and computing capabilities. All resources participating in the sharing are uploaded to the cloud server, and the cloud server re-encrypts the resources. When a terminal accesses the resources, the cloud server returns the re-encrypted resources to the terminal.

[0072] (3) Data Owner (DO): refers to the party that owns the data resources. The data owner encrypts the plaintext resources and uploads the encrypted resources to the cloud server, which stores them and sends them back to the terminal that needs the resources.

[0073] (4) Data user (DU): refers to the party that needs data resources. The data user obtains the re-encrypted ciphertext resources from the cloud server and decrypts them using its own legitimate key to obtain plaintext information.

[0074] Figure 2 The data interaction process and methodological steps of the entire scheme are demonstrated, including the following steps: A cloud-based re-encryption data access control method based on quantum resistance properties.

[0075] Step S1, System initialization. Based on security parameters. Determine the dimensions With modulus The authoritative center will perform the following steps:

[0076] (1.1) Running the trapdoor generation algorithm ,in For public matrices, for The trapdoor matrix, It is the system master private key;

[0077] (1.2) Selecting a random matrix , Choose a random vector ;

[0078] (1.3) Define the timestamp space matrix Define hash mapping function Define the identity space matrix of data users. ;

[0079] (1.4) Define the system attribute set The set includes all attributes involved in the system;

[0080] (1.5) Define a complete binary tree Each leaf node represents a terminal;

[0081] (1.6) Publicly disclose common parameters within the system Secretly store the master key The system common parameters and the master private key The expression is as follows:

[0082] ;

[0083] .

[0084] Step S2, the data owner encrypts the resource. The data owner encrypts the resource according to the access policy; the data owner performs the following encryption steps:

[0085] (2.1) Set access policies for resources, and randomly select based on the number of attributes involved in the policy. vectors ,make ;

[0086] (2.2) For the encrypted information part, the parameters obtained in step (2.1) are used. ,make Calculate the portion of the ciphertext carrying the information. :

[0087] ;

[0088] (2.3) For the encryption attribute part, use the parameters obtained in step (2.1). ,make Calculate the partial ciphertext carrying attributes :

[0089] , ;

[0090] (2.4) Encrypting the leaf nodes, using the parameters obtained in step (2.1). and common parameters Calculate the partial ciphertext carrying the leaf nodes. :

[0091] ;

[0092] (2.5) Obtain the complete encrypted information Afterwards, the data owner uploads the information to the cloud server.

[0093] Step S3: Data User Key Generation. The authority center provides attribute trapdoor parameters to the data user, who then performs the subsequent key generation process. The specific steps are as follows:

[0094] (3.1) The authoritative center bases its decisions on the attributes of the data users. and its identity matrix ,run The sampling algorithm obtains the trapdoor parameters of the attributes associated with the data user's identity:

[0095] ;

[0096] Then Secretly passed on to data users;

[0097] (3.2) Data users receive Then, using The sampling algorithm generates attribute keys:

[0098] ;

[0099] (3.3) Thus, the data user's key is obtained. .

[0100] Step S4: Cloud server encryption key generation. The authoritative center provides the trapdoor parameters to the cloud server, which then performs the subsequent key generation process. The specific steps are as follows:

[0101] (4.1) The authoritative center's view on the system attribute set All attributes in the calculation are trapdoors:

[0102] ;

[0103] Then The information was secretly transmitted to the cloud server.

[0104] (4.2) The cloud server received Then, using The sampling algorithm, for each complete binary tree Each attribute of a leaf node generates a corresponding encryption key:

[0105] ;

[0106] (4.3) Thus far, the cloud server has obtained the node The encryption key is .

[0107] Step S5: The cloud server re-encrypts the resource. The data owner uploads the resource to the cloud, and the cloud server uses the encryption key to encrypt the original ciphertext, obtaining the re-encrypted ciphertext. The specific steps are as follows:

[0108] (5.1) Cloud servers utilize data users (nodes) The encryption key is used to re-encrypt the original resource attribute parameters:

[0109] ;

[0110] (5.2) The cloud server generates a timestamp and uses the timestamp to re-encrypt the identity node parameters of the data user:

[0111] ;

[0112] (5.3) At this point, the data returned by the cloud server to the data user (node) is obtained. Re-encrypted ciphertext .

[0113] Step S6: Data user decryption key generation. The authoritative center provides the data user with trapdoor parameters, and the data user then performs the subsequent key generation process. The specific steps are as follows:

[0114] (6.1) The authoritative center is for data users (nodes) Generate trapdoor parameters:

[0115] ;

[0116] Then Secretly passed on to data users;

[0117] (6.2) Data users (nodes) )use and the current timestamp Generate a trapdoor with a timestamp:

[0118] ;

[0119] (6.3) Data users (nodes) ) Generate trapdoor parameters using the authority center and timestamped trapdoor Generate decryption key:

[0120] ;

[0121] Therefore, data users (nodes) At that moment The decryption key is .

[0122] Step S7, decrypt the resource. Data user (node) Using your own decryption key, you can decrypt the re-encrypted ciphertext returned by the cloud server to obtain the plaintext. The specific steps are as follows:

[0123] (7.1) Data users (nodes) Decrypting the resource:

[0124] ;

[0125] (7.2) If the user's key is valid and can be decrypted correctly, then the noise This can be ignored, thus obtaining plaintext information. .

[0126] Ultimately, data users achieve secure data access.

[0127] In summary, this invention discloses a cloud-based re-encryption data access control method based on attribute-resistant quantum computing. It is the first cloud-based re-encryption data access control method based on lattices, using an identity base, and utilizing timestamps. First, the authoritative center performs system initialization, generating the necessary parameters for system operation. Data users generate their own initial keys, where the attribute trapdoor parameters associated with identity are generated with the assistance of the authoritative center, and then the data users generate their own attribute keys. The authoritative center generates a re-encryption key, and the trapdoor parameters of the system attribute set are secretly allocated to the cloud server by the authoritative center. The cloud server then generates encryption keys for each attribute of the terminal, and these keys are generated once and used permanently without changing the terminal's attribute permissions. The cloud server uses the encryption key to re-encrypt the original resource attribute parameters. When the corresponding terminal accesses the resource, the data user's identity node parameters are encrypted using a timestamp. The re-encrypted ciphertext is returned to the terminal when it accesses the resource. The data user generates a real-time decryption key, generating a timestamped trapdoor parameter and a decryption key. The data user decrypts the resource by using the re-encrypted ciphertext returned by the cloud server and their own decryption key to obtain the plaintext. Ultimately, secure data access is achieved.

[0128] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A cloud-based re-encryption data access control method based on attribute quantum resistance, characterized in that: Includes the following steps: S1, System Initialization: Based on security parameters, the Authority Center (CA) performs system initialization and generates system parameters, including common system parameters. and master key Specifically: ; ; in, Through Domain obtained by sampling algorithm Medium model Dimensions random matrix, It is a domain Medium model Dimensions The trapdoor matrix; It is a domain Medium model Dimensions A random matrix; The number of users in the system; It is a domain Medium model Dimensions The common matrix; It is a domain Medium model Dimensions The common vector; For timestamp space; It is a mapping function; An identity matrix for data owners; The number of system attributes; A collection of system attributes; It is a complete binary tree, where each leaf node represents a terminal; S2, Data Owner Encrypts Resources: The data owner sets access policies for the resources, encrypting the plaintext resources to obtain ciphertext. ;in, For the ciphertext component carrying plaintext information, To assist in verifying ciphertext components that carry attribute information, The number of attributes included in the access strategy. This is an auxiliary verification ciphertext component that carries leaf node information. It is a complete binary tree. Represents a leaf node of a complete binary tree; S3, Data User Key Generation: Authoritative Center (CA) through... The sampling algorithm obtains attribute trapdoor parameters associated with the data user's identity and secretly assigns them to the data user. The data user generates an attribute key based on the attribute trapdoor parameters and obtains the data user key. The attribute trapdoor parameters are secretly stored by the authority center (CA) and the attribute key is secretly stored by the data user. S4, Cloud Server Encryption Key Generation: Authoritative CA (Certificate Authority) uses this key for attributes within the system's attribute set. The sampling algorithm generates trapdoor parameters and secretly assigns them to the cloud server. The cloud server then uses these parameters to analyze each attribute of the terminal. Generate encryption key: ; S5, Cloud Server Re-encrypts Resources: The data owner uploads resources to the cloud. The cloud server uses an encryption key to re-encrypt the original resource attribute parameters and uses a timestamp to re-encrypt the data user's identity node parameters, resulting in re-encrypted ciphertext. ; The re-encrypted ciphertext is returned to the terminal when the corresponding terminal accesses the resource; otherwise, it is stored in the cloud. S6, Data User Decryption Key Generation: Authoritative Center (CA) via... The sampling algorithm generates a trapdoor parameter for the terminal and binds it to the corresponding node in the complete binary tree. Data users then reuse the data using this trapdoor parameter and the timestamp parameter. The timestamped trapdoor parameters are obtained through sampling, and then used to... The decryption key is obtained by sampling. ; S7, Decryption Resource: Data users decrypt the re-encrypted ciphertext returned by the cloud server and their own decryption key to obtain plaintext information, thus achieving secure data access; the specific decryption formula is as follows: ; in, For the ciphertext component carrying plaintext information, For nodes At any moment The decryption key, It is the transpose symbol. For trees Middle node The re-encrypted ciphertext, For nodes The The decryption key for each attribute. For the re-encrypted ciphertext component carrying attribute information, The number of attributes included in the access strategy. For modulus, For noise, This is plaintext information.

2. The cloud-based re-encryption data access control method based on attribute-resistant quantum as described in claim 1, characterized in that: The data owner encryption process in step S2 specifically includes the following steps: S21, Selecting a random vector: The data owner selects a corresponding number of random vectors based on the number of attributes involved in the access strategy, and sums these vectors; the expression for the random vector is: ; The expression for the sum of the vectors is: ; in, The number of attributes involved in the access strategy; For domain Medium model Dimensions A random vector; S22, Information Partial Encryption: The data owner uses the parameters obtained in step S21. Calculate the portion of the ciphertext carrying the information. The encrypted expression carrying the information is: ; in, For domain Medium model Dimensions ; Plaintext information; For noise; Modulus; S23, Attribute Encryption: The data owner uses the parameters obtained in step S21. Calculate the partial ciphertext carrying attributes The ciphertext expression carrying the attribute is: , ; in, for and Augmented form of the matrix; For attributes Hash mapping; For common parameters; For noise; S24, Leaf node partial encryption: The data owner uses the parameters obtained in step S21. and common parameters Calculate the partial ciphertext carrying the leaf nodes. The encrypted expression carrying the information is: ; in, A complete binary tree Nodes in ; Represents a leaf node of a complete binary tree; for and The product of.

3. The cloud-based re-encryption data access control method based on attribute-resistant quantum as described in claim 1, characterized in that: In step S3, the attribute trapdoor parameter associated with the user's identity is specifically as follows: ; in, For the attributes of data users, For the identity matrix of data users, It is the standard deviation parameter of the Gaussian distribution; The expression for the attribute key is: ; Among them, attribute key .

4. The cloud-based re-encryption data access control method based on attribute-resistant quantum as described in claim 1, characterized in that: In step S4, the trapdoor parameters allocated to the cloud server are specifically as follows: ; The specific encryption key for each attribute of the terminal is as follows: ; in, It refers to the number of system attributes.

5. The cloud-based re-encryption data access control method based on attribute-resistant quantum as described in claim 1, characterized in that: In step S5, encrypting the original resource attribute parameters using the encryption key specifically involves: ; The expression for the verification formula is: ; in, It is a moment The timestamp belongs to the timestamp space. .

6. The cloud-based re-encryption data access control method based on attribute-resistant quantum as described in claim 5, characterized in that: In step S5, the trapdoor parameters generated by the authority center are stored in a complete binary tree structure and are public information. The timestamped trapdoor parameters and decryption keys generated by data users are kept secret by the users themselves. The expression for the trapdoor parameters generated by the authority center is: ; The expression for the timestamped trapdoor parameter is: ; The decryption key expression for the data user is: ; in, for The trapdoor, These are common system parameters. This is the system master key. Let be the standard deviation parameter of the Gaussian distribution. for The trapdoor, for and The product of For a moment timestamp matrix, Represents a node At any moment The decryption key, For common parameters, for and The product of.

7. A cloud-based re-encrypted data access control system based on attribute-resistant quantum technology, comprising a computer program, characterized in that: When the computer program is executed, it can implement the method as described in any one of claims 1-6.