A data processing method, apparatus, device, medium, and product

By generating aggregated trapdoors, data users and cloud servers collaborate to achieve efficient authorized retrieval of encrypted data without revealing access policies. This solves the problems of privacy leakage and low retrieval efficiency in sensitive data sharing during chip testing, and builds a secure and controllable data sharing platform.

CN122137598APending Publication Date: 2026-06-02HANGZHOU XINGUANG SEMICONDUCTOR CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU XINGUANG SEMICONDUCTOR CO LTD
Filing Date
2026-02-13
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing technologies struggle to achieve fast and secure data sharing in chip testing while ensuring the privacy of sensitive data. In particular, access strategies are easily leaked during keyword searches, leading to privacy breaches and low retrieval efficiency.

Method used

Data users generate aggregation trapdoors and send them to the cloud server. The cloud server filters encrypted data that meets the access policy based on the aggregation trapdoors and performs initial decryption. Data users then decrypt the data to obtain plaintext data. Efficient authorized retrieval is achieved by using the aggregation mechanism of attribute private keys and search keywords.

Benefits of technology

Without exposing user access policies, efficient authorized retrieval of encrypted data was achieved, a secure and controllable sensitive data sharing platform was built, and retrieval efficiency and privacy protection capabilities were improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137598A_ABST
    Figure CN122137598A_ABST
Patent Text Reader

Abstract

This invention discloses a data processing method, apparatus, device, medium, and product. The method includes: a data user aggregating an attribute private key and a search keyword to generate an aggregation trapdoor, and sending the aggregation trapdoor to a cloud server; the attribute private key is issued to the data user by a trusted institution; the cloud server filters encrypted data that conforms to an access policy based on the aggregation trapdoor; if the encrypted data contains the search keyword, the encrypted data is initially decrypted to obtain semi-decrypted data, and the semi-decrypted data is sent to the data user; the data user decrypts the semi-decrypted data based on the attribute private key to obtain plaintext data. Through the technical solution of this invention, efficient authorized retrieval of encrypted data can be achieved without exposing user access policies, providing key support for building a secure and controllable sensitive data sharing platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the fields of searchable encryption, attribute-based encryption, privacy protection, and data security, and particularly to a data processing method, apparatus, device, medium, and product. Background Technology

[0002] In today's era of rapid information technology development, data sharing is widely used in various fields, including semiconductors. Sharing chip testing data can improve testing efficiency and optimize testing processes. However, data such as design information and specific structural defects in chip testing are sensitive content, and their leakage can cause significant losses. Therefore, how to achieve rapid and secure data sharing while ensuring sensitivity and privacy has become a key concern in the industry.

[0003] The widespread application of cloud storage and big data analytics technologies has made keyword search the primary method for users to obtain target data in chip testing. However, in environments involving the sharing of sensitive test data, keyword search faces the dual challenges of privacy breaches and low retrieval efficiency. When a user initiates a query, their access intent is often closely related to the testing strategy and failure mode. Without effective protection, access strategies, attribute information, and even the user's query behavior trajectory may be leaked during the search process. To effectively protect the privacy and security of the testing party and improve system response performance, it is essential to simultaneously optimize access strategy concealment and keyword search efficiency. This requires not only establishing trust mechanisms in cross-organizational testing but also addressing issues such as attribute exposure and insufficient retrieval performance within a single organization.

[0004] Access policies typically map the accessible scope of chip test data. Without effective protection, these policies can be easily guessed by cloud servers or third parties during the search process, potentially leading to the leakage of sensitive testing intentions or policy configurations. Most current searchable encryption mechanisms fail to simultaneously achieve both access policy protection and search efficiency, limiting their practical application in scenarios involving the sharing of sensitive chip test data. In digital environments, data owners frequently need to share encrypted test data, while authorized users must execute search requests based on keywords. If the system cannot ensure the confidentiality of access behavior and policy intent, it will directly impact the platform's credibility and the company's willingness to cooperate. Therefore, anonymized access policies are a core prerequisite for achieving trusted access to shared sensitive data, while search efficiency directly affects system availability and user experience. Summary of the Invention

[0005] This invention provides a data processing method, apparatus, device, medium, and product to enable efficient authorized retrieval of encrypted data without exposing user access policies, providing key support for building a secure and controllable sensitive data sharing platform.

[0006] According to one aspect of the present invention, a data processing method is provided, comprising:

[0007] The data user aggregates the attribute private key and search keywords to generate an aggregation trapdoor, and sends the aggregation trapdoor to the cloud server; the attribute private key is issued to the data user by a trusted institution;

[0008] The cloud server filters out encrypted data that conforms to the access policy according to the aggregation trapdoor. If the encrypted data contains the search keyword, the encrypted data is initially decrypted to obtain semi-decrypted data, and the semi-decrypted data is sent to the data user.

[0009] The data user decrypts the semi-decrypted data based on the attribute private key to obtain plaintext data.

[0010] According to another aspect of the present invention, a data processing apparatus is provided, the apparatus comprising:

[0011] The trapdoor generation module is used to control data users to aggregate attribute private keys and search keywords to generate aggregate trapdoors, and send the aggregate trapdoors to the cloud server; the attribute private keys are issued to the data users by a trusted institution;

[0012] The data filtering module is used to control the cloud server to filter encrypted data that conforms to the access policy according to the aggregation trapdoor. If the encrypted data contains the search keyword, the encrypted data is initially decrypted to obtain semi-decrypted data, and the semi-decrypted data is sent to the data user.

[0013] The data decryption module is used to control the data user to decrypt the semi-decrypted data based on the attribute private key to obtain plaintext data.

[0014] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0015] At least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data processing method according to any embodiment of the present invention.

[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the data processing method described in any embodiment of the present invention.

[0019] According to another aspect of the present invention, embodiments of the present invention also provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the data processing method described in any embodiment of the present invention.

[0020] This invention, in its embodiments, aggregates attribute private keys and search keywords by data users to generate an aggregation trapdoor, which is then sent to a cloud server. The attribute private key is issued to the data user by a trusted institution. The cloud server uses the aggregation trapdoor to filter encrypted data that conforms to the access policy. If the encrypted data contains the search keyword, it performs initial decryption to obtain semi-decrypted data, which is then sent to the data user. The data user decrypts the semi-decrypted data using the attribute private key to obtain the plaintext data. This invention enables efficient authorized retrieval of encrypted data without exposing user access policies, providing crucial support for building a secure and controllable sensitive data sharing platform.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart of a data processing method according to an embodiment of the present invention;

[0024] Figure 2 This is an overall architecture diagram of an HCP-ABSE scheme according to an embodiment of the present invention;

[0025] Figure 3 This is a schematic diagram of the structure of a data processing device according to an embodiment of the present invention;

[0026] Figure 4 This is a schematic diagram of the structure of an electronic device that implements the data processing method of the present invention. Detailed Implementation

[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and their derivatives, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0029] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.

[0030] Example 1

[0031] The following are the definitions of abbreviations and key terms in this embodiment:

[0032] The DDH assumption (Decisional Diffie-Hellman): Given a large prime number of order... Cyclic group In the middle, set For generators, The index is randomly selected. The DDH assumption states that:

[0033] random quadruples ;

[0034] DDH Quadruple ;

[0035] Computationally indistinguishable—that is, no polynomial-time algorithm can determine the fourth component with a non-negligible advantage. Or random Specifically, an adversary A has the advantage of distinguishing between R and D:

[0036] ;

[0037] Where k is a safety parameter.

[0038] The DBDH assumption (Decisional Bilinear Diffie-Hellman assumption): Given a prime number of order... multiplication group and Randomly select generator and random numbers ,Will and Send to .Depend on determination Is it equal to If they are equal, Output 1; otherwise output 0.

[0039] Algorithm definition, The advantages of solving the above problems are:

[0040] ;

[0041] If no polynomial-time algorithm can solve the DBDH hypothesis with a non-negligible advantage, then we say that the DBDH hypothesis is in group... The middle is established.

[0042] Bilinear mapping: Consider two multiplicative cyclic groups and Their order is ,in It is a large prime number. Let it be... This is a generator. This leads to the mapping function. The definition of has the following properties:

[0043] Bilinear: for any element The following equation holds true. .

[0044] Non-degenerate: exists , making .

[0045] Computability: for all It can be calculated efficiently. The value of .

[0046] Multilinear mapping: The following is a brief introduction to multilinear mapping: given a security parameter 3 Cyclic group of order and 2 mappings Form a 3-multilinear mapping. A 3-multilinear mapping should satisfy the following definition:

[0047] Assumption yes The generator, then yes The generator.

[0048] .

[0049] It can be calculated efficiently.

[0050] ABE (Attribute-Based Encryption): Attribute-based encryption is a public-key encryption paradigm where encryption and decryption permissions are determined by a user's attribute set and access policy, rather than relying on traditional identity or certificate mechanisms. The encryptor embeds the access policy (or attribute set) into the ciphertext during encryption; when a user applies for a private key, they obtain the corresponding key component based on their attribute set; decryption can only be successful if the user's attributes satisfy the access policy.

[0051] Attribute-Based Encryption (ABE) is an attribute-based encryption technique used for fine-grained access control. In ABE, encryption and decryption operations depend on user attributes, rather than specific user identities. Based on different encryption and decryption strategies, ABE can be further divided into two main types: Key-Policy Attribute-Based Encryption (KP-ABE) and Ciphertext-Policy Attribute-Based Encryption (CP-ABE).

[0052] CP-ABE is a variant of ABE. The access policy is embedded into the ciphertext by the encryptor in the form of Boolean gating or an access tree, and the user's private key carries their set of attributes. Decryption is possible to obtain the plaintext only if the user's attributes satisfy the policy in the ciphertext. The basic strategy of CP-ABE includes four algorithms:

[0053] Initialization: This algorithm is in the initialization phase. Input security parameters, output system public key and master key.

[0054] Encryption: This algorithm is for the encryption phase. Input the plaintext to be encrypted and shared, along with the system public key generated during initialization and the access structure; output a ciphertext.

[0055] Key Generation: This algorithm is for generating the decryption key. It takes the input attribute set, the system public key generated during initialization, and the master key as input, and outputs a single key.

[0056] Decryption: This algorithm is for the decryption phase. Input the system public key, private key, and ciphertext; output the message.

[0057] Searchable Encryption (SE) is a cryptographic technique designed to enable efficient searching within encrypted datasets while protecting data privacy. Its primary goal is to allow searching of encrypted datasets in an encrypted state without revealing plaintext information. Searchable encryption is mainly divided into two basic algorithms: First, Symmetric Searchable Encryption (SSE), which encrypts data using a symmetric key and then constructs a searchable data structure using an index structure (such as an inverted index). Common SSE algorithms include symmetric encryption algorithms combined with a search index to implement search functionality. However, the main challenge of symmetric searchable encryption is the secure management of the search index. Second, Public Key Searchable Encryption (PEKS), which uses public-key cryptography to construct searchable encryption. Users encrypt search keywords using a public key, and the server uses the corresponding private key to compare the encrypted keywords with the encrypted data. PEKS provides a more flexible key management method but also increases complexity.

[0058] Figure 1 This is a flowchart of a data processing method according to an embodiment of the present invention. This embodiment is applicable to sensitive data processing. The method can be executed by the data processing device according to the present invention, which can be implemented in software and / or hardware, such as... Figure 1 As shown, the method specifically includes the following steps:

[0059] S101. The data user aggregates the attribute private key and search keywords to generate an aggregation trapdoor, and sends the aggregation trapdoor to the cloud server.

[0060] In this embodiment, a chip test data sharing platform is used as an example. The Trusted Authority (TA) acts as the system engine, responsible for generating multi-linear group parameters and distributing attribute private key components to all participants. Data Owners (DOs), such as chip design company A and semiconductor manufacturer B, are responsible for marking access policies for each test report data locally and performing attribute-based randomization encryption, then uploading the ciphertext with a searchable index. The Cloud Server Provider (CSP) acts as a storage and retrieval service provider, receiving the ciphertext and query token, completing policy verification through only one multi-linear pairing, and returning the matching result. Data Users (DUs), such as test analysts from a third-party test service provider C, use their own attribute private key and search keywords to generate an aggregation trapdoor locally, initiate a retrieval request to the Cloud Server CSP, perform preliminary decryption of the ciphertext and return it to the Data User DUs, who then perform final decryption to obtain the original test report.

[0061] It should be noted that the attribute private key can be the private key of the data user DUs. Specifically, the attribute private key is issued to the data user DUs by the trusted authority TA.

[0062] The search keywords can be the keywords that data users (DUs) provide when they want to retrieve data.

[0063] As is known, a trapdoor is a secret information or mechanism that allows users with a trapdoor to complete tasks more efficiently in certain computational or verification processes, while users without a trapdoor cannot complete the task or need to pay a higher price. In this embodiment, the aggregate trapdoor can be a trapdoor generated by data user DUs by aggregating their own attribute private key and search keywords.

[0064] Specifically, when a data user (DU) needs to retrieve sensitive data, the attribute private key and search keywords are aggregated locally at once to generate a fixed-size aggregate trapdoor, which is then submitted to the cloud server (CSP).

[0065] S102. The cloud server filters out encrypted data that meets the access policy based on the aggregation trapdoor. If the encrypted data contains search keywords, it performs initial decryption of the encrypted data to obtain semi-decrypted data, and sends the semi-decrypted data to the data user.

[0066] It should be noted that the access policy can be a pre-defined conditional policy for accessing sensitive data by the user. The encrypted data can be sensitive data encrypted in accordance with the access policy, and the semi-decrypted data can be data obtained after the cloud server CSP performs preliminary decryption on the encrypted data.

[0067] Specifically, the cloud server CSP filters encrypted data that conforms to the access policy based on the aggregation trapdoor submitted by the data user DUs. If the encrypted data contains search keywords, the encrypted data is initially decrypted to obtain semi-decrypted data, which is then sent to the data user DUs.

[0068] S103. The data user decrypts the semi-decrypted data based on the attribute private key to obtain the plaintext data.

[0069] It should be noted that plaintext data can be plaintext data obtained by fully decrypting partially decrypted data. For example, plaintext data can be sensitive data such as the original chip test report.

[0070] Specifically, data users (DUs) decrypt the semi-decrypted data returned by the cloud server (CSP) based on their own attribute private key to obtain plaintext data.

[0071] This invention, in its embodiments, aggregates attribute private keys and search keywords by data users to generate an aggregation trapdoor, which is then sent to a cloud server. The attribute private key is issued to the data user by a trusted institution. The cloud server uses the aggregation trapdoor to filter encrypted data that conforms to the access policy. If the encrypted data contains the search keyword, it performs initial decryption to obtain semi-decrypted data, which is then sent to the data user. The data user decrypts the semi-decrypted data using the attribute private key to obtain the plaintext data. This invention enables efficient authorized retrieval of encrypted data without exposing user access policies, providing crucial support for building a secure and controllable sensitive data sharing platform.

[0072] Optionally, before the data user aggregates the attribute private key and search keywords to generate an aggregation trapdoor and sends the aggregation trapdoor to the cloud server, the following steps are also included:

[0073] The trusted institution receives the initial security parameters, generates public parameters and a master key based on the initial security parameters, and then distributes the public parameters and master key to the data owner.

[0074] In this embodiment, the initialization security parameters can be achieved using... In this representation, public parameters can be represented by PK, and the master key can be represented by MK.

[0075] Specifically, input initial security parameters Then the trusted authority (TA) outputs a series of parameters, including the system public parameter PK and the master key MK.

[0076] The data owner uses attribute-based encryption to encrypt plaintext data based on public parameters, master key, and access policy to obtain ciphertext data, and then uploads the ciphertext data to the cloud server.

[0077] The ciphertext data can be encrypted data obtained by encrypting plaintext data using attribute-based encryption.

[0078] Specifically, the data owner (DOs) receives the public parameter PK and master key MK issued by the trusted authority (TA), and encrypts the plaintext sensitive data into ciphertext data according to the access policy.

[0079] Optionally, the data owner performs attribute-based encryption on the plaintext data based on public parameters, the master key, and the access policy to obtain ciphertext data, and then uploads the ciphertext data to the cloud server, including:

[0080] The data owner generates a pre-ciphertext based on public parameters and the master key, and sends the pre-ciphertext to the edge node.

[0081] The pre-ciphertext can be the ciphertext obtained by the data owner DOs after encrypting the plaintext data.

[0082] In this embodiment, edge nodes (ENs, the complex form of Edge Node) are responsible for a large number of complex encryption and decryption operations, undertaking most of the high-load tasks such as pairing operations and exponential calculations. This allows data owners (DOs) and data users (DUs) to perform only relatively simple token generation and local result verification. This outsourcing mechanism significantly reduces the computational burden on client devices and improves the scalability and feasibility of the entire data security sharing system.

[0083] Specifically, the data owner DOs only needs to perform a lightweight, constant number of operations to generate pre-encrypted ciphertext and send it to the upstream node, i.e., the edge node ENs.

[0084] Edge nodes encrypt the pre-ciphertext according to the access policy to obtain ciphertext data, and then upload the ciphertext data to the cloud server.

[0085] Specifically, the upstream edge nodes (ENs) will complete the remaining encryption calculations, obtain the ciphertext data, and upload the ciphertext data to the cloud server (CSP).

[0086] Optionally, the data owner generates a pre-ciphertext based on public parameters and the master key, and sends the pre-ciphertext to the edge node, including:

[0087] The data owner generates a pre-ciphertext based on a random number, public parameters, and the master key, and sends the pre-ciphertext to the edge node.

[0088] Each attribute corresponds to a random number.

[0089] In this embodiment, the data owner DOs randomly selects a number and generates a pre-ciphertext based on the random number, public parameters, and master key, and then sends the pre-ciphertext to the edge node.

[0090] Optionally, before the data user aggregates the attribute private key and search keywords to generate an aggregation trapdoor and sends the aggregation trapdoor to the cloud server, the following steps are also included:

[0091] The trusted institution receives the attribute set sent by the data user, generates the data user's attribute private key based on the attribute set and the master key, and then distributes the attribute private key to the data user.

[0092] In this embodiment, the attribute set can be used To express.

[0093] Specifically, the trusted authority (TA) distributes keys to data users (DUs) and simultaneously inputs a set of user attributes. The master key MK is used, and then the trusted authority TA generates and outputs the corresponding attribute private key SK for each data user DUs, so that the data user DUs can generate an aggregation trapdoor TW based on the attribute private key SK and the search keyword.

[0094] Optionally, the cloud server filters encrypted data that conforms to the access policy based on the aggregation trapdoor. If the encrypted data contains search keywords, it performs initial decryption of the encrypted data to obtain semi-decrypted data, which is then sent to the data user, including:

[0095] The cloud server performs multi-linear pairing operations based on the aggregation trapdoor. If the attribute set of the data user meets the access policy, then the encrypted data that meets the access policy is selected.

[0096] Specifically, the cloud server CSP can verify all attribute conditions and filter out encrypted data that meets the access policy by performing a single multi-line pairing operation based on the aggregation trapdoor.

[0097] If the encrypted data contains search keywords, the cloud server will initially decrypt the encrypted data to obtain semi-decrypted data, and then send the semi-decrypted data to the data user.

[0098] Specifically, if the attribute set of user DUs meets the preset access policy and the keywords match, the encrypted data can be decrypted to obtain the content key; otherwise, the plaintext content key cannot be returned.

[0099] The technical solution of this invention achieves complete concealment of access strategies by introducing independent random values ​​into attribute ciphertext. By constructing an aggregated keyword index, keywords scattered across multiple attribute ciphertexts are unified into a single search token. Users only need to perform one bilinear pairing calculation to quickly complete keyword matching and retrieval, avoiding the huge computational overhead caused by performing bilinear pairing for each attribute separately in traditional solutions. By outsourcing the recalculation task to edge nodes and cloud servers, this method significantly improves the efficiency of data retrieval, ensuring fast and efficient searching of ciphertext data within constant time.

[0100] Example 2

[0101] In existing large-scale cloud storage and collaborative computing environments, searchable encryption technologies must balance access policy privacy protection with efficient retrieval requirements; however, existing technologies struggle to achieve both simultaneously. Specifically, in sensitive data sharing scenarios, existing technologies generally suffer from low access policy concealment levels, insufficient retrieval efficiency, lack of fine-grained search support, and weak resistance to keyword guessing attacks. This invention proposes an attribute-based searchable encryption scheme, HCP-ABSE (Hierarchical Constant-Size Ciphertext Policy Attribute-Based Encryption, a hierarchical constant-size ciphertext policy attribute-based encryption scheme. This encryption scheme combines the features of Hierarchical Attribute-Based Encryption (HABE) and constant-size ciphertext (CP-ABE), aiming to provide a more efficient and flexible encryption mechanism, particularly suitable for scenarios requiring hierarchical management and access control), specifically addressing the following key technical issues:

[0102] 1. Structure for hiding sensitive data access strategies:

[0103] Existing CP-ABE searchable schemes use the same random number for all attribute components, preserving the correlation between attributes after encryption. This allows the cloud to crack the correlation between attributes and reconstruct access policies through pairing tests, potentially revealing access intentions for sensitive data and user permission configurations. This invention introduces an independent random component into the ciphertext of each attribute, making the attribute components independent within the ciphertext. Thus, even if the server possesses all the ciphertext, it cannot recover the original access policy through any correlation detection technology. This not only protects user permission configurations from being snooped on but also eliminates the possibility of adversaries using ciphertext patterns for side-channel analysis.

[0104] 2. Reduce the complexity of sensitive data search to constant level:

[0105] Traditional retrieval processes exhibit linear growth in complexity with the number of attributes, leading to a significant increase in the number of linear pairing operations and a sharp rise in search latency. This invention further optimizes the user-side query process by: in the Trapdoor stage, the user not only aggregates all their attribute private key components with the query keywords but also merges them with the randomized information corresponding to each attribute, generating a fixed-size "aggregated trapdoor" containing all verification information. The cloud only needs a single multi-linear pairing call to complete the verification of all attribute conditions in a single operation, simultaneously obtaining the matching status and strategy satisfaction index from the same pairing result. This method reduces search complexity from the original linear... Transform into constant order Even with a large number of attributes, it can significantly improve response speed and effectively enhance the system's concurrent retrieval capabilities and user experience.

[0106] 3. Reduce system overhead and ensure the security of sensitive data sharing:

[0107] In practical applications, searchable encryption systems face severe challenges such as a surge in attribute dimensions, high-concurrency queries, and potential side-channel attacks. Traditional global randomization and linear pairing retrieval methods are insufficient to meet these multiple challenges. This invention aims to construct a more robust attribute-based searchable encryption scheme: by introducing independent randomization for each attribute component during the encryption phase, aggregating all attribute private key components and random information all at once during the trapdoor generation phase, and performing only one multi-linear pairing during the search phase, the system ensures efficient and stable retrieval even in complex environments with a large number of attributes, a sharp increase in query requests, or the threat of correlation attacks, while strictly protecting access policy privacy and data security.

[0108] Figure 2 This is an overall architecture diagram of an HCP-ABSE scheme according to an embodiment of the present invention. Figure 2 As shown, the overall architecture of the HCP-ABSE scheme involves multiple different entities, each playing a key role, including Trusted Authority (TA), Data Owners (DOs), Data Users (DUs), Cloud Servers (CSPs), and Edge Nodes (ENs). The following section uses a chip test data sharing platform as an example to illustrate the specific application of this scheme.

[0109] Trusted institution (TA) acts as the system engine, responsible for generating multi-linear group parameters and distributing attribute private key components to all participants. Chip design company A and semiconductor manufacturer B, as data owners (DOs), locally annotate access policies for each test report data and perform attribute-level randomization encryption, then upload ciphertext with a searchable index. Cloud server (CSP) acts as a storage and retrieval service provider, receiving the ciphertext and query token, completing policy verification through only one multi-linear pairing, and returning the matching result. Test analysts from third-party testing service provider C, as data users (DUs), use their own attribute private keys and query keywords to generate aggregation trapdoors locally, initiate retrieval requests to cloud server CSP, cloud server CSP performs preliminary decryption of the ciphertext and returns it to data user DUs, and data user DUs perform final decryption of the returned ciphertext to obtain the original test report.

[0110] In the chip test data sharing platform, the entire searchable encryption process is as follows: First, the Trusted Organization (TA) generates multi-linear group parameters and a system master key, and publishes the public parameters to chip design companies and semiconductor manufacturers (data owners DOs) through a secure channel; next, the TA generates and distributes attribute private keys to each party based on the attribute sets (such as "core design team", "product confidentiality level A", "test analyst") submitted by chip design company A and third-party test service provider C (data users DUs); then, data owner company A (data owner DOs) collaborates with edge nodes ENs to perform attribute-level randomization encryption on each CPU test report locally according to the access policy ("core design team ∧ product confidentiality level A"), generating a searchable encryption key. The search index consists of independent encrypted components, and the complete encrypted text is uploaded to the cloud server CSP. When a test analyst (data user DUs) of a third-party testing service provider C needs to retrieve "high-power test" images, the data user DUs locally aggregates the "test analyst" attribute private key, keywords, and their randomization information to generate a fixed-size aggregation trapdoor, and submits it to the cloud server CSP. Subsequently, the cloud server CSP verifies all attribute conditions simultaneously with a single multi-linear pairing operation, filters out encrypted test reports that meet the policy, and returns them. Finally, the cloud server CSP performs preliminary decryption of the encrypted text and returns it to the data user DUs. The data user DUs use their own attribute private key to decrypt it locally, obtain the original test report, and perform data analysis and fault diagnosis. The entire process is clear and rigorous, ensuring that the access policy remains hidden throughout the cloud and that efficient retrieval is completed with a single pairing.

[0111] The Trusted Authority (TA) is responsible for generating the system master key (MK) and public parameters (PK); and for distributing keys and managing attributes to data owners (DOs) and data users (DUs) through secure channels.

[0112] Data Owner (DOs): In this system, the Data Owner (DOs) represents the data organization and is responsible for uploading data information to the Cloud Server (CSP). The Data Owner (DOs) uses an inverted index to divide the file into a keyword index set, and then uploads the encrypted file and the keyword index set to the Cloud Server (CSP).

[0113] Data Users (DUs): These are individuals or organizations that need to access data stored on a cloud server (CSP). They use their private keys and the keywords they want to retrieve to generate a trapdoor and upload it to the cloud server (CSP).

[0114] Cloud server CSP: A semi-trusted entity that provides encrypted storage and computation services. On one hand, it can honestly execute the configured computation protocol and return the correct results. On the other hand, it curiously speculates about the privacy of various entities and attempts to crack the encrypted ciphertext.

[0115] Edge nodes (ENs) are entities situated between data owners (DOs), data users (DUs), and cloud servers (CSPs), providing certain storage and computing resources. In this model, some of the computing overhead of data users (DUs) and data owners (DOs) is transferred to edge nodes (ENs) to reduce the computing overhead for end users.

[0116] In its implementation, the HCP-ABSE scheme consists of five main algorithms: setup, key generation and distribution, encryption, trapdoor generation, and search.

[0117] The initialization (Setup) process includes: The algorithm is executed by a trusted authority (TA). Input initialization security parameters. Then the trusted authority (TA) outputs a series of parameters, including the system public parameter PK and the master key MK.

[0118] Key generation and distribution (Keygen): The algorithm is executed by a trusted authority (TA). The TA distributes keys to data users (DUs). Simultaneously, a user attribute set is input. The master key MK is used, and then the trusted authority TA generates and outputs the corresponding attribute private key SK for each data user DUs.

[0119] Encryption: The algorithm is executed collaboratively by the data owner DOs and the edge nodes ENs. Inputs include the public parameter PK, the access control policy W, and the content key. and keywords According to access control policy W, plaintext... It is encrypted as ciphertext CW.

[0120] Trapdoor generation: The algorithm is executed by data user DUs. Input attributes include the private key SK and search keywords. Generates a polymer trapdoor TW.

[0121] Encryption Decryption (Search): The algorithm is executed collaboratively by data user DUs and cloud server CSP. Inputs include public parameter PK, ciphertext CW, and the data user's private key SK. If data user DUs satisfies the preset access policy W, the ciphertext CW can be decrypted into the plaintext content key. Otherwise, the plaintext key will not be returned.

[0122] The HCP-ABSE algorithm will be described in detail below:

[0123] In this scheme, we assume that the total number of attributes is n, and the attribute set is defined as follows: For each attribute .in It is an attribute The value of each attribute There is a set Let the user attribute vector be... ,in Set access policies. ,in Finally, list S will be defined as a list of attributes, if for all They all If the access strategy matches successfully, the HCP-ABSE scheme consists of five key algorithms: Setup, Keygen, Encrypt, Trapdoor, and Search.

[0124] Setup: This algorithm runs a swarm optimization generator algorithm. We obtain the group and the mapping. Let... and It is of two prime order. The multiplicative cyclic group, and yes The generator. Then, two anti-collusion hash functions are randomly selected: Finally, the generated nodes are randomly selected. MK serves as the master key for this system. System parameters. The generation process is as follows: Node generation calculation System parameters As shown in the following formula:

[0125] ;

[0126] ;

[0127] Trusted organization (TA) transmits system parameters through a secure channel Distributed to various entities.

[0128] Keygen: The algorithm will use a set of attributes The private key SK for the attribute of data user DU is generated as an input parameter and output as the attribute private key SK. The generation process of the attribute private key SK for data user DU is as follows:

[0129] First, the algorithm randomly selects... and calculate Secondly, for each attribute ,calculate Finally, the trusted authority (TA) generates a key for each user (DU). , The private key SK is represented by the following formula:

[0130] ;

[0131] Finally, the data user DU sends the attribute private key SK, which contains its own attributes, to the cloud server CSP.

[0132] Encrypt: This algorithm is executed collaboratively by the data owner DOs and the upstream edge nodes ENs. Input system parameters. Content key and multi-value access strategy and corresponding keywords The data owner (DOs) first generates the pre-encrypted ciphertext (CW) by performing a lightweight, constant number of operations and sends it to the upstream node. Then, the upstream edge nodes (ENs) complete the remaining encryption computation.

[0133] Data owner Encryption on the side: Data owner (Any data owner) randomly selects a number And make .make The ciphertext CW is then expressed by the following formula:

[0134] ;

[0135] Finally, the pre-ciphertext CW||{ It was sent to the edge node. (Any edge node).

[0136] edge nodes Side encryption: edge nodes Regarding AND gate Each attribute ,set up The ciphertext CW is then shown in the following formula:

[0137] ;

[0138] Final cipher Edge nodes After encryption, it is sent to the cloud server CSP.

[0139] Trapdoor: The algorithm is executed by data user DUs. Data user DUs will input the private key SK of the attribute to be searched and the search keywords. Data user DUs uses the attribute private key SK and the keyword to generate an aggregation trapdoor. Its construction method is shown in the following formula:

[0140] ;

[0141] Search: Input system parameters Aggregation trap And the private key SK of the attributes of data user DUs. If the attribute set S of data user DUs satisfies the access policy. Furthermore, the keywords match, enabling the decryption of the content key from the ciphertext CW. Otherwise, the corresponding key It cannot be decrypted, and the output is ⊥. Specifically, the cloud server CSP first decrypts the ciphertext CW and sends the partially decrypted ciphertext to the data user DUs. Then, the data user DUs only needs to perform a lightweight constant number of calculations to obtain the plaintext.

[0142] The algorithm consists of two phases: the matching phase and the decryption phase.

[0143] Matching Phase: Cloud Server CSPs will be matched using the following equation:

[0144] ;

[0145] Cloud server CSP checks whether a given ciphertext CW contains the trapdoor keyword TW by verifying the correctness of the equation. The following equation is the verification process for its correctness:

[0146] ;

[0147] if If the above equation holds true, the match is successful, and the cloud server CSP returns the corresponding data to the data user DUs; otherwise, it returns ⊥.

[0148] Decryption Phase: Decryption of CSP on the cloud server side: Decryption is performed by executing the following formula:

[0149] ;

[0150] Determine whether it is possible to obtain the decryption result by demonstrating the correctness of the decryption process. The verification process for the correctness of the decryption phase is shown by the following formula:

[0151] ;

[0152] if equal Then we can obtain The successful decryption of the algorithm proves the attribute set Satisfy access policy Keyword match successful. The cloud server CSP will X|| Send the data to the terminal user DU; otherwise, decryption fails and returns ⊥. Both the matching and decryption phases are indispensable.

[0153] Finally, the cloud server CSP will X|| Data is sent to the end user DU.

[0154] Decryption on the data user DU side: At this time, the terminal data user DU decrypts based on its own attribute private key. The content key can be decrypted and recovered through a simple exponential operation, as follows:

[0155] ;

[0156] Next, this solution will use the aforementioned DDH attack to illustrate how the proposed solution in this embodiment achieves access policy hiding. Assume an adversary knows the attribute set and wants to use public parameters and ciphertext to check whether the access policy is encrypted in the ciphertext.

[0157] Assuming the adversary receives access policy Encrypted ciphertext Then guess belong The formula for a DDH attack on the HCP-ABSE scheme is shown below:

[0158] ;

[0159] in this case, This is not true. Therefore, the adversary cannot determine which access strategy is used in the ciphertext, thus the construction of this scheme achieves access strategy concealment.

[0160] It is worth noting that this embodiment utilizes Aggregate functions generate properties and strategy By generating trapdoors, the search phase only requires one pairing for a fast search, eliminating the need to match all keys multiple times and enabling rapid keyword searching.

[0161] The technical solutions of the embodiments of the present invention bring the following beneficial effects:

[0162] 1. Conceal the structure of sensitive data access policies to enhance privacy protection capabilities:

[0163] To address the issue that access policies in existing technologies are easily inferred by the cloud, traditional ABSE schemes typically use uniform random numbers to encrypt all attribute components, resulting in comparability between attributes. The cloud can then analyze attribute relationships using techniques such as bilinear pairing to infer the user-defined access policy structure, posing a serious privacy risk. This invention introduces an independent random value for each attribute component, breaking the comparability between encrypted attribute components. Even if the cloud obtains the ciphertext and query traps, it cannot reconstruct the access policy structure through comparison and reasoning. This achieves complete policy hiding at the encryption structure level, effectively improving the privacy and attack resistance of chip test data access control.

[0164] 2. Aggregate keyword search to improve retrieval efficiency and response speed:

[0165] To address the issue of linearly increasing search complexity with the number of attributes in traditional solutions, the server needs to pair each attribute component individually, resulting in a heavy computational burden and low response efficiency. This invention proposes an aggregation trapdoor mechanism that integrates all attribute information and query keywords into a fixed-length query token on the user side. The cloud only needs one bilinear pairing to complete attribute verification, significantly reducing search overhead and improving the system's responsiveness in chip test data retrieval scenarios.

[0166] 3. Compress the encrypted structure to reduce system resources and communication overhead:

[0167] To address the computational and transmission burden caused by the expansion of ciphertext and trapdoor structures with the number of attributes, traditional solutions experience a significant increase in system pressure under high-dimensional strategies. This invention addresses this issue by employing attribute-level independent encryption and aggregated trapdoor design, maintaining constant ciphertext and trapdoor lengths without requiring expansion with the number of attributes. This significantly reduces the computational, storage, and communication resource consumption of both the client and server, improving the overall system's deployability and scalability.

[0168] Example 3

[0169] Figure 3 This is a schematic diagram of a data processing device according to an embodiment of the present invention. This embodiment is applicable to sensitive data processing. The device can be implemented in software and / or hardware, and can be integrated into any device that provides data processing functionality, such as... Figure 3 As shown, the data processing device specifically includes: a trapdoor generation module 201, a data filtering module 202, and a data decryption module 203.

[0170] The trapdoor generation module 201 is used to control the data user to aggregate the attribute private key and search keywords to generate an aggregated trapdoor, and send the aggregated trapdoor to the cloud server; the attribute private key is issued to the data user by a trusted institution.

[0171] The data filtering module 202 is used to control the cloud server to filter encrypted data that conforms to the access policy according to the aggregation trapdoor. If the encrypted data contains the search keyword, the encrypted data is initially decrypted to obtain semi-decrypted data, and the semi-decrypted data is sent to the data user.

[0172] The data decryption module 203 is used to control the data user to decrypt the semi-decrypted data based on the attribute private key to obtain plaintext data.

[0173] Optionally, the device further includes:

[0174] The generation module is used to control the trusted institution to receive initialization security parameters, generate public parameters and a master key based on the initialization security parameters, and send the public parameters and the master key to the data owner;

[0175] The encryption module is used to control the data owner to perform attribute-based encryption on plaintext data based on the public parameters, the master key, and the access policy to obtain ciphertext data, and then upload the ciphertext data to the cloud server.

[0176] Optionally, the encryption module includes:

[0177] A generation unit is used by the data owner to generate a pre-ciphertext based on the public parameters and the master key, and to send the pre-ciphertext to the edge node;

[0178] An encryption unit is used by the edge node to encrypt the pre-ciphertext according to the access policy to obtain ciphertext data, and then upload the ciphertext data to the cloud server.

[0179] Optionally, the generation unit is specifically used for:

[0180] The data owner generates a pre-ciphertext based on a random number, the public parameters, and the master key, and sends the pre-ciphertext to the edge node; wherein each attribute corresponds to a random number.

[0181] Optionally, the device further includes:

[0182] The generation and transmission module is used to control the trusted institution to receive the attribute set sent by the data user, generate the attribute private key of the data user according to the attribute set and the master key, and send the attribute private key to the data user.

[0183] Optionally, the data filtering module 202 is specifically used for:

[0184] The cloud server performs multi-linear pairing operations based on the aggregation trapdoor. If the attribute set of the data user satisfies the access policy, then the encrypted data that conforms to the access policy is filtered out.

[0185] If the encrypted data contains the search keyword, the cloud server performs initial decryption of the encrypted data to obtain semi-decrypted data, and sends the semi-decrypted data to the data user.

[0186] The above-mentioned products can execute the data processing methods provided in any embodiment of the present invention, and have the corresponding functional modules and beneficial effects of executing the methods.

[0187] Example 4

[0188] Figure 4 A schematic diagram of an electronic device 30 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0189] like Figure 4As shown, the electronic device 30 includes at least one processor 31 and a memory, such as a read-only memory (ROM) 32 or a random access memory (RAM) 33, communicatively connected to the at least one processor 31. The memory stores computer programs executable by the at least one processor. The processor 31 can perform various appropriate actions and processes based on the computer program stored in the ROM 32 or loaded from storage unit 38 into the RAM 33. The RAM 33 can also store various programs and data required for the operation of the electronic device 30. The processor 31, ROM 32, and RAM 33 are interconnected via a bus 34. An input / output (I / O) interface 35 is also connected to the bus 34.

[0190] Multiple components in electronic device 30 are connected to I / O interface 35, including: input unit 36, such as keyboard, mouse, etc.; output unit 37, such as various types of monitors, speakers, etc.; storage unit 38, such as disk, optical disk, etc.; and communication unit 39, such as network card, modem, wireless transceiver, etc. Communication unit 39 allows electronic device 30 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0191] Processor 31 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 31 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 31 performs the various methods and processes described above, such as data processing methods:

[0192] The data user aggregates the attribute private key and search keywords to generate an aggregation trapdoor, and sends the aggregation trapdoor to the cloud server; the attribute private key is issued to the data user by a trusted institution;

[0193] The cloud server filters out encrypted data that conforms to the access policy according to the aggregation trapdoor. If the encrypted data contains the search keyword, the encrypted data is initially decrypted to obtain semi-decrypted data, and the semi-decrypted data is sent to the data user.

[0194] The data user decrypts the semi-decrypted data based on the attribute private key to obtain plaintext data.

[0195] In some embodiments, the data processing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 38. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 30 via ROM 32 and / or communication unit 39. When the computer program is loaded into RAM 33 and executed by processor 31, one or more steps of the data processing method described above may be performed. Alternatively, in other embodiments, processor 31 may be configured to perform the data processing method by any other suitable means (e.g., by means of firmware).

[0196] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0197] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0198] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0199] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0200] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0201] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0202] In one embodiment, the present invention further includes a computer program product, which includes a computer program that, when executed by a processor, implements the data processing method of any embodiment of the present invention.

[0203] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0204] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0205] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A data processing method, characterized in that, include: Data users aggregate attribute private keys and search keywords to generate an aggregation trapdoor, and then send the aggregation trapdoor to the cloud server; The attribute private key is issued to the data user by a trusted institution; The cloud server filters out encrypted data that conforms to the access policy according to the aggregation trapdoor. If the encrypted data contains the search keyword, the encrypted data is initially decrypted to obtain semi-decrypted data, and the semi-decrypted data is sent to the data user. The data user decrypts the semi-decrypted data based on the attribute private key to obtain plaintext data.

2. The method according to claim 1, characterized in that, Before the data user aggregates the attribute private key and search keywords to generate an aggregation trapdoor, and sends the aggregation trapdoor to the cloud server, the process also includes: The trusted institution receives the initialization security parameters, generates public parameters and a master key based on the initialization security parameters, and sends the public parameters and the master key to the data owner; The data owner performs attribute-based encryption on the plaintext data based on the public parameters, the master key, and the access policy to obtain ciphertext data, and then uploads the ciphertext data to the cloud server.

3. The method according to claim 2, characterized in that, The data owner performs attribute-based encryption on the plaintext data based on the public parameters, the master key, and the access policy to obtain ciphertext data, and then uploads the ciphertext data to the cloud server, including: The data owner generates a pre-ciphertext based on the public parameters and the master key, and sends the pre-ciphertext to the edge node; The edge node encrypts the pre-ciphertext according to the access policy to obtain ciphertext data, and then uploads the ciphertext data to the cloud server.

4. The method according to claim 3, characterized in that, The data owner generates a pre-ciphertext based on the public parameters and the master key, and sends the pre-ciphertext to the edge node, including: The data owner generates a pre-ciphertext based on a random number, the public parameters, and the master key, and sends the pre-ciphertext to the edge node; wherein each attribute corresponds to a random number.

5. The method according to claim 2, characterized in that, Before the data user aggregates the attribute private key and search keywords to generate an aggregation trapdoor, and sends the aggregation trapdoor to the cloud server, the process also includes: The trusted institution receives the attribute set sent by the data user, generates the attribute private key of the data user based on the attribute set and the master key, and sends the attribute private key to the data user.

6. The method according to claim 1, characterized in that, The cloud server filters encrypted data that conforms to the access policy based on the aggregation trapdoor. If the encrypted data contains the search keyword, it performs initial decryption on the encrypted data to obtain semi-decrypted data, and sends the semi-decrypted data to the data user, including: The cloud server performs multi-linear pairing operations based on the aggregation trapdoor. If the attribute set of the data user satisfies the access policy, then the encrypted data that conforms to the access policy is filtered out. If the encrypted data contains the search keyword, the cloud server performs initial decryption of the encrypted data to obtain semi-decrypted data, and sends the semi-decrypted data to the data user.

7. A data processing apparatus, characterized in that, include: The trapdoor generation module is used to control data users to aggregate attribute private keys and search keywords to generate aggregate trapdoors, and send the aggregate trapdoors to the cloud server; the attribute private keys are issued to the data users by a trusted institution; The data filtering module is used to control the cloud server to filter encrypted data that conforms to the access policy according to the aggregation trapdoor. If the encrypted data contains the search keyword, the encrypted data is initially decrypted to obtain semi-decrypted data, and the semi-decrypted data is sent to the data user. The data decryption module is used to control the data user to decrypt the semi-decrypted data based on the attribute private key to obtain plaintext data.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data processing method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the data processing method according to any one of claims 1-6.

10. A computer program product comprising a computer program that, when executed by a processor, implements the data processing method according to any one of claims 1-6.