An encryption method based on registration keyword strategy hiding
By introducing a registration mechanism and user public key validity detection, combined with dual-system encryption and a set of arithmetic and non-double number sequences, the generation and aggregation of user public keys are optimized, solving the key escrow problem in multi-user scenarios, achieving both efficient keyword retrieval and security, and supporting fine-grained access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANTONG UNIV
- Filing Date
- 2026-03-24
- Publication Date
- 2026-07-03
Smart Images

Figure CN122339738A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of cryptography and information security technology, specifically relating to an encryption method based on registration keywords and hidden attributes. Background Technology
[0002] With the widespread application of cloud computing technology, massive amounts of data are centrally hosted on cloud servers in encrypted form, significantly improving resource utilization and cross-domain collaboration capabilities. However, the openness of cloud storage and the separation of data ownership pose serious challenges to data privacy protection. Users need to encrypt sensitive data before uploading it, but this renders traditional data retrieval methods ineffective—users need to download all encrypted data and decrypt it before they can find the information they need, resulting in huge computational and communication overhead.
[0003] To address these issues, searchable encryption (SE) technology emerged. In 2000, Song et al. first proposed a symmetric searchable encryption scheme; in 2004, Boneh et al. proposed the concept of Public Key Encryption with Keyword Search (PEKS), enabling keyword retrieval of encrypted data. However, simple searchable encryption schemes only support retrieval of encrypted data by a single user. If multiple users search for ciphertext, a new ciphertext needs to be generated for each user, resulting in significant waste. Therefore, constructing a searchable encryption scheme that meets the fine-grained access control requirements of multi-user scenarios has become a problem that needs to be solved.
[0004] Attribute-Based Encryption (ABE) offers a solution for fine-grained access control for multi-user systems. Researchers have combined ABE with searchable encryption to create Attribute-Based Searchable Encryption (ABSE). This system allows data owners to encrypt keywords based on access policies, and only users whose attributes meet the policy can generate valid trapdoors for retrieval, achieving flexible access control while protecting data privacy. However, ABSE faces the risk of key escrow. In traditional ABE schemes, the Attribute Authority (AA) is responsible for generating the user's attribute key. If the AA is attacked or is simply "curious," the user's decryption key may be leaked, leading to a key escrow problem. Existing schemes often employ a single trusted authority model; once this authority is compromised, the entire system's security collapses. Summary of the Invention
[0005] The purpose of this invention is to propose an encryption method based on registration keywords and with hidden strategy. By introducing a registration mechanism and user public key validity detection, the key escrow problem in traditional schemes is solved; by adding subgroup elements to the ciphertext and employing a dual-system encryption method, keyword privacy is achieved; and by utilizing a set of efficiently computable arithmetic-free and non-double-number sequences to construct system common parameters, the length of the common parameters is increased from... Reduced to ,in This invention optimizes system efficiency while ensuring complete security, considering the number of users in the system. Furthermore, it supports keyword search using arbitrary monotonic Boolean expressions, enhancing the expressive power of access strategies.
[0006] The inventive concept of this invention is as follows: In the method of this invention, the system administrator SM sets system security parameters. Keyword space The maximum value of the slot Calculate and publish the system's common parameters. .user Select the Each slot randomly selects and secretly stores its private key. Calculate and publish the public key SM receives the public keys of all users. Using system common parameters Verify user's public key It was generated legally. The system administrator received all of them. ( ) legitimate public key and legal keyword set Using system common parameters Aggregate the public keys and keywords of all legitimate users to generate and publish the system's master public key. At the same time, an auxiliary decryption key is generated for each user. And secretly sent to users Data receiver Use your private key Auxiliary decryption key Together with the set of keywords, they form a trapdoor. and will Send it to the cloud service provider. The data owner (DP) uses the system's master public key. Keyword access strategy Encryption, obtaining ciphertext Then Send to the cloud service provider. (User) Trapping Gate The message is sent to the cloud service provider along with a retrieval request; the cloud service provider then exploits a trap. All ciphertexts are checked; if a trapdoor is found... If the set of keywords in the ciphertext satisfies the policy in the ciphertext, then the cloud service provider will send the ciphertext to the user after the detection is passed. .
[0007] To achieve the aforementioned objectives, the specific technical solution adopted by this invention is as follows: a searchable encryption method based on registration keywords and with a hidden strategy, comprising the following steps:
[0008] S1. System Initialization: System administrator SM initializes system security parameters, keyword space and slot maximum values, constructs a composite order bilinear group, calculates and publishes system public parameters based on a set of arithmetic and non-double sequences;
[0009] S2, User Key Generation: The user selects an unused slot index, independently selects and secretly saves their private key, and calculates and publishes their public key;
[0010] S3. User Public Key Validity Detection: SM uses system public parameters to verify the validity of all user public keys and adds all valid user public keys to the list of valid users;
[0011] S4. Generate System Master Key: The system administrator aggregates the public keys and keyword sets of all legitimate users based on the public keys and keyword sets of the users in the list of legitimate users using the system's public parameters, calculates the system master public key and the user auxiliary decryption key, secretly sends the user auxiliary decryption key to the user, and publishes the system master key to the system bulletin board.
[0012] S5, Trapdoor Generation Stage: The user combines their private key, keyword-assisted decryption key, and keyword set to form a trapdoor. When the user needs to retrieve the keyword ciphertext, the user sends their trapdoor to the cloud server.
[0013] S6. Keywords of the encrypted access policy: The data owner selects a set of keywords based on the characteristics of the data to be retrieved, and formulates an access policy on the set of keywords. The key in the access policy is encrypted using the system master public key to obtain the keyword ciphertext, and the keyword ciphertext is sent to the cloud server for storage.
[0014] S7 Keyword Strategy Detection: The user sends the trapdoor to the cloud service provider and submits a search request. The cloud service provider uses the trapdoor to detect all ciphertext. If the set of keywords in the trapdoor satisfies the strategy in the ciphertext, the detection is passed, and the cloud service provider sends the search data that matches the keyword ciphertext to the user.
[0015] Furthermore, step S1 includes the following steps:
[0016] S11. System administrator SM sets a system security parameter. A keyword space The maximum value of the slot Then, SM runs the composite order group generator to obtain the parameter set of the composite order bilinear group. ,set up ,in, and yes Cyclic groups of order 1 They are groups of Subgroups of order.
[0017] S12, SM Settings , ,choose It is a set of numbers with no arithmetic progression and no double numbers that can be efficiently computed; set a function. , yes The set of sums of any two distinct elements in the set;
[0018] S13, SM selects a random generator , , , , Choose a hash function Choose a random number ,in ,calculate , ;
[0019] S14. For each slot index value SM calculation Choose a random number Calculate the first Parameters for each slot:
[0020]
[0021] S15. For each keyword SM calculation Choose a random number For each slot index value Sum of intersection and index values Calculate keyword-slot parameters
[0022]
[0023] and Keyword-Intersection Parameters
[0024]
[0025] S16, SM settings for system common parameters:
[0026] .
[0027] Furthermore, step S2 includes the following steps:
[0028] S21. When a user registers for the first time, they select an unused slot index. , will the The user of each slot is recorded as .user Choose a random number ,use calculate:
[0029] ,
[0030] For each slot index and ,user Calculate the first Intersection of each slot Obtain its public key .
[0031] S22, Based on its key characteristic set , public key and keyword set Send it to the SM and secretly keep their private key. Note: User public and private key pairs It is unrelated to its keyword set.
[0032] Furthermore, step S3 includes the following steps:
[0033] S31, SM receives the public keys of all users. and keyword set Using common parameters Detect user public key The legitimacy of which The SM verification equation is as follows:
[0034] (1)
[0035] (2)
[0036] (3)
[0037] For each slot reference value and SM verification equation:
[0038] (4)
[0039] (5)
[0040] Subsequently, SM verified The middle element does not contain and The elemental composition of the subgroup, i.e., the index value for each slot. and Verify the following equation:
[0041] (6)
[0042] (7)
[0043] If all of the above equations (1)–(7) hold true, then the user is said to be... public key It is legal.
[0044] S32, When the user public key It's legal, SM verified. Keyword set Is it included in the keyword space? If true, then it is called It is legal;
[0045] S33, SM will use all legitimate users' public keys and keyword set Add to the list of legitimate users middle.
[0046] Furthermore, step S4 includes the following steps:
[0047] S41, SM will list users The user public keys in the data are aggregated, where SM compute slot public key:
[0048] , ,
[0049] S42. For each keyword SM computes key public key and the slot public key of the keyword :
[0050] , ;
[0051] S43, SM sets the system master public key and user-assisted decryption keys ,Will Secretly sent to users and the system master public key Published in the system announcement section.
[0052] Furthermore, step S5 includes the following steps:
[0053] S51, User Use your private key Auxiliary decryption key Together with the set of keywords, they form a trapdoor. and will Send to the cloud server.
[0054] Furthermore, step S6 includes the following steps:
[0055] S61, Data owner DP selects the data to be retrieved. Keyword set In the keyword set Configure access policies ,in , It is a matrix the number of rows, It is a matrix The number of columns, It is an injective row labeling function. DP selects random numbers. Random elements And satisfy Select random elements DP uses the master public key The calculation is as follows:
[0056] ;
[0057] S62, DP selects random numbers Construct a column vector For each DP selects random numbers ,calculate:
[0058]
[0059]
[0060]
[0061] in, Representation matrix The OK;
[0062] S63, DP setting keyword ciphertext Among them, the composite function It is a hash function and mapping The composite function DP will cipher the key. Send it to the cloud server and save it on the cloud server.
[0063] Furthermore, step S7 includes the following steps:
[0064] S71, User Trapping Gate The message is sent to the cloud service provider along with a retrieval request; the cloud server then exploits a trap. Encryption of all keywords The strategy matching is performed sequentially, and the encrypted keywords that meet the keyword strategy are sent to the user. .
[0065] S72, cloud server computing ,if Not satisfying all keyword ciphertext Access policies in ,but Keyword set and If the keyword strategy in the search fails to match, output the error message and send a search failure message to the user. Otherwise, the cloud service provider's computing set , represents a matrix China satisfies All row numbers The set of, denoted as ,make Representation matrix Bank of China serial number is In Given a submatrix composed of row vectors, calculate a vector. , to satisfy ,make Representing vectors The One component. Cloud service providers exploit traps. calculate:
[0066]
[0067] if , then it means The private key and auxiliary decryption key and their claimed key set If no match is found, output the error message and send a keyword detection failure message to the user. ;if Output 1, indicating that... Keyword set and Keyword strategy matching in the middle, through detection, and ciphertext Send to user .
[0068] Meanwhile, the present invention proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed, it implements the steps of the method described in the present invention.
[0069] Furthermore, the present invention proposes a computer-readable storage medium having a computer program stored thereon, the computer program being configured to implement the steps of the method described in the present invention when invoked by a processor.
[0070] Finally, the present invention provides a computer program product comprising a computer program / instructions that, when executed by a processor, implement the steps of the method described in the present invention.
[0071] Table 1 explains the meaning of parameters or symbols in this invention:
[0072]
[0073] Compared with existing technical solutions, the beneficial effects of the present invention are:
[0074] (1) The method of this invention introduces a registration-based encryption mechanism. In this mechanism, the system administrator first sets the system public parameters according to the security parameters. Each user independently generates their own public-private key pair and corresponding keyword set, and submits this information to the administrator. After verifying the legality of the public-private key pairs and keyword sets of all users, the administrator aggregates the public keys and keyword sets of all users to generate the system public key and each user's unique auxiliary decryption key. Since the user's private key is generated and kept entirely by the user, the system administrator cannot obtain any user's private key, and therefore cannot decrypt any ciphertext on behalf of the user. This effectively solves the key escrow problem existing in traditional encryption schemes, and significantly improves the security of the system and the privacy of user data.
[0075] (2) The method of this invention constructs the system public parameters by introducing a set of arithmetic-free and non-double-number sequences that can be efficiently computed. In a searchable encryption mechanism based on registration attribute bases, the system public key is defined as the product of the public keys of all legitimate users. To ensure that legitimate users can decrypt, the system public parameters must contain cross terms between any two users; at the same time, to prevent decryption by users whose attributes do not meet the requirements, the system public parameters must not contain non-cross terms of a single user. This invention, through mathematical design, allows different users to share the same cross terms. Constructing public parameters using a set of arithmetic-free and non-double-number sequences can maximize the sharing rate of cross terms. While avoiding the introduction of non-cross terms, the length of the system public parameters is reduced from the traditional... shorten to This significantly compresses the length of common parameters, effectively reducing system overhead.
[0076] (3) Regarding security, this invention employs a dual-system encryption method based on a composite order group formed by the product of five prime numbers. By introducing the concepts of "semi-functional" ciphertext and private key, complete security under the standard model is achieved, overcoming the limitation of traditional schemes that can only prove selected security. Simultaneously, for keyword privacy protection, this invention adds random elements from specific subgroups to the ciphertext component during ciphertext generation. Utilizing the orthogonality between subgroups, these elements neither affect decryption correctness nor compromise the indistinguishability of the keywords, thus ensuring keyword privacy. Attached Figure Description
[0077] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof.
[0078] Figure 1 The flowchart illustrates a searchable encryption method based on registration keywords and with a hidden strategy, provided by this invention. Detailed Implementation
[0079] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. Of course, the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0080] See Figure 1 This embodiment provides a technical solution: a searchable encryption method based on registration keywords and with a hidden strategy, specifically including the following steps:
[0081] S1. System Initialization: System administrator SM initializes system security parameters, keyword space and slot maximum values, constructs a composite order bilinear group, calculates and publishes system public parameters based on a set of arithmetic and non-double sequences;
[0082] S2, User Key Generation: The user selects an unused slot index, independently selects and secretly saves their private key, and calculates and publishes their public key;
[0083] S3. User Public Key Validity Detection: SM uses system public parameters to verify the validity of all user public keys and adds all valid user public keys to the list of valid users;
[0084] S4. Generate System Master Key: The system administrator aggregates the public keys and keyword sets of all legitimate users based on the public keys and keyword sets of the users in the list of legitimate users using the system's public parameters, calculates the system master public key and the user auxiliary decryption key, secretly sends the user auxiliary decryption key to the user, and publishes the system master key to the system bulletin board.
[0085] S5, Trapdoor Generation Stage: The user combines their private key, keyword-assisted decryption key, and keyword set to form a trapdoor. When the user needs to retrieve the keyword ciphertext, the user sends their trapdoor to the cloud server.
[0086] S6. Keywords of the encrypted access policy: The data owner selects a set of keywords based on the characteristics of the data to be retrieved, and formulates an access policy on the set of keywords. The key in the access policy is encrypted using the system master public key to obtain the keyword ciphertext, and the keyword ciphertext is sent to the cloud server for storage.
[0087] S7 Keyword Strategy Detection: The user sends the trapdoor to the cloud service provider and submits a search request. The cloud service provider uses the trapdoor to detect all ciphertext. If the set of keywords in the trapdoor satisfies the strategy in the ciphertext, the detection is passed, and the cloud service provider sends the search data that matches the keyword ciphertext to the user.
[0088] Specifically, step S1 includes the following steps:
[0089] S11. System administrator SM sets a system security parameter. A keyword space The maximum value of the slot Then, SM runs the composite order group generator to obtain the parameter set of the composite order bilinear group. ,set up ,in, and yes Cyclic groups of order 1 They are groups of Subgroups of order.
[0090] S12, SM Settings , ,choose It is a set of numbers with no arithmetic progression and no double numbers that can be efficiently computed; set a function. , yes The set of sums of any two distinct elements in the set;
[0091] S13, SM selects a random generator , , , , Choose a hash function Choose a random number ,in ,calculate , ;
[0092] S14. For each slot index value SM calculation Choose a random number Calculate the first Parameters for each slot:
[0093]
[0094] S15. For each keyword SM calculation Choose a random number For each slot index value Sum of intersection and index values Calculate keyword-slot parameters
[0095]
[0096] and Keyword-Intersection Parameters
[0097]
[0098] S16, SM settings for system common parameters:
[0099] .
[0100] Specifically, step S2 includes the following steps:
[0101] S21. When a user registers for the first time, they select an unused slot index. , will the The user of each slot is recorded as .user Choose a random number ,use calculate:
[0102] ,
[0103] For each slot index and ,user Calculate the first Intersection of each slot Obtain its public key .
[0104] S22, Based on its key characteristic set , public key and keyword set Send it to the SM and secretly keep their private key. Note: User public and private key pairs It is unrelated to its keyword set.
[0105] Specifically, step S3 includes the following steps:
[0106] S31, SM receives the public keys of all users. and keyword set Using common parameters Detect user public key The legitimacy of which The SM verification equation is as follows:
[0107] (1)
[0108] (2)
[0109] (3)
[0110] For each slot reference value and SM verification equation:
[0111] (4)
[0112] (5)
[0113] Subsequently, SM verified The middle element does not contain and The elemental composition of the subgroup, i.e., the index value for each slot. and Verify the following equation:
[0114] (6)
[0115] (7)
[0116] If all of the above equations (1)–(7) hold true, then the user is said to be... public key It is legal.
[0117] S32, When the user public key It's legal, SM verified. Keyword set Is it included in the keyword space? If true, then it is called It is legal;
[0118] S33, SM will use all legitimate users' public keys and keyword set Add to the list of legitimate users middle.
[0119] Specifically, step S4 includes the following steps:
[0120] S41, SM will list users The user public keys in the data are aggregated, where SM compute slot public key:
[0121] , ,
[0122] S42. For each keyword SM computes key public key and the slot public key of the keyword :
[0123] , ;
[0124] S43, SM sets the system master public key and user-assisted decryption keys ,Will Secretly sent to users and the system master public key Published in the system announcement section.
[0125] Specifically, step S5 includes the following steps:
[0126] S51, User Use your private key Auxiliary decryption key Together with the set of keywords, they form a trapdoor. and will Send to the cloud server.
[0127] Specifically, step S6 includes the following steps:
[0128] S61, Data owner DP selects the data to be retrieved. Keyword set In the keyword set Configure access policies ,in , It is a matrix the number of rows, It is a matrix The number of columns, It is an injective row labeling function. DP selects random numbers. Random elements And satisfy Select random elements DP utilizes the master public key. The calculation is as follows:
[0129] ;
[0130] S62, DP selects random numbers Construct a column vector For each DP selects random numbers ,calculate:
[0131]
[0132]
[0133]
[0134] in, Representation matrix The OK;
[0135] S63, DP setting keyword ciphertext Among them, the composite function It is a hash function and mapping The composite function. DP ciphers the key. Send it to the cloud server and save it on the cloud server.
[0136] Specifically, step S7 includes the following steps:
[0137] S71, User Trapping Gate The message is sent to the cloud service provider along with a retrieval request; the cloud server then exploits a trap. Encryption of all keywords The strategy matching is performed sequentially, and the encrypted keywords that meet the keyword strategy are sent to the user. .
[0138] S72, cloud server computing ,if Not satisfying all keyword ciphertext Access policies in ,but Keyword set and If the keyword strategy in the search fails to match, output the error message and send a search failure message to the user. Otherwise, the cloud service provider's computing set , represents a matrix China satisfies All row numbers The set of, denoted as ,make Representation matrix Bank of China serial number is In Given a submatrix composed of row vectors, calculate a vector. , to satisfy ,make Representing vectors The One component. Cloud service providers exploit traps. calculate:
[0139]
[0140] if , then it means The private key and auxiliary decryption key and their claimed key set If no match is found, output the error message and send a keyword detection failure message to the user. ;if Output 1, indicating that... Keyword set and Keyword strategy matching in the middle, through detection, and ciphertext Send to user .
[0141] This invention can be widely applied in the following scenarios:
[0142] (1) Internet of Things (IoT) Paid Data Subscription Platform: Internet of Things (IoT) Paid Data Subscription Platform
[0143] A meteorological data company owns a large number of IoT sensors (such as farmland temperature and humidity sensors and traffic flow cameras). Third-party agricultural technology companies or individual researchers wish to subscribe to this real-time data. The platform administrator (as the SM) collects subscription fees and allocates a limited number of "slots" to each subscriber. Due to the use of aggregated public keys, the sensors only need to perform a simple encryption calculation once. The paying user (data recipient) uses their private key and an auxiliary decryption key to generate a trapdoor and request a search request from the cloud service provider. Once the cloud service provider detects that the user attributes ("paying user," "Beijing subscription package") meet the policy, it returns the ciphertext. This protects sensor data from unauthorized interception, supports a large number of subscribers, and minimizes the computational overhead at the encryption end (sensors).
[0144] (2) Hierarchical access control system for confidential internal documents
[0145] Scenario Description: In a large enterprise (such as a law firm, accounting firm, or military enterprise), internal servers store a large number of confidential documents (such as contracts, audit reports, and design drawings). The enterprise's Human Resources Department (as SM) assigns fixed employee IDs (corresponding to slots) to all employees. A key is generated when an employee joins the company, and their public key can be removed upon leaving (but this requires a dynamic update mechanism; otherwise, re-initialization is necessary). Aggregated Encryption: The department manager (as DP) uses the system's master public key to encrypt a document about the "2025 Salary Structure," setting the access policy as: ("Department = Human Resources Department" AND "Job Level = Managerial Level"). Only employees with both the "Human Resources Department" attribute and "Job Level = Managerial Level" can have their generated trapdoors detected by the cloud service provider and successfully decrypt the document. Ordinary employees cannot find or decrypt it. This prevents unauthorized access by internal personnel, and because aggregated public keys are used, the encryptor (department manager) does not need to remember the public keys of all senior executives.
[0146] (3) Regional sharing of electronic health records (EHRs)
[0147] Scenario Description: Sharing patient electronic medical records among multiple hospitals in a city for referrals or remote consultations. Doctor Registration: The National Health Commission (as the SM) assigns registration numbers (slots) to all practicing physicians. Encrypted Upload: Patient A visits Peking Union Medical College Hospital (PUMC). PUMC's system (DP) encrypts the medical record, setting a policy: ("Hospital = PUMC" AND "Department = Cardiology") OR "Patient ID = Patient_A". Precise Retrieval: When Patient A is transferred to People's Hospital, the cardiologist (user) at People's Hospital cannot retrieve the medical record using their own trapdoor (containing "Hospital = People's Hospital, Department = Cardiology"). However, if Patient A authorizes, a trapdoor can be generated using the patient's private key (if the patient also has a slot), or the system supports proxy re-encryption to transfer permissions. Advantages: Enables controlled data sharing across institutions, preventing patient privacy leaks.
[0148] In summary, this invention achieves a triple breakthrough in "security, efficiency, and functionality" in the field of encryption methods based on searchable keywords with registration attributes. It solves the core problems of high computational overhead and low security in existing technologies, and has outstanding substantive features and significant technological progress.
[0149] The following explains some of the names mentioned in this embodiment:
[0150] Bilinear mapping
[0151] set up They are two composite numbers Cyclic group of order, bilinear mapping It is a mapping, and satisfies
[0152] (1) Bilinear: for any , satisfy
[0153] (2) Non-degeneracy: If yes The generator, then yes Generators;
[0154] (3) Computability: For any There exists a polynomial-time algorithm for computation. .
[0155] set up It is a composite number The cyclic group of order , denoted by They are respectively of Subgroups They are respectively of Rank subgroup.
[0156] Subgroup Decision Assumption 1: Let... It is a composite number Cyclic group of order, bilinear mapping Random selection , , , , , ,set up Given If all polynomial-time adversaries are distinguished , If the advantage is negligible, then it is called a group. Subgroup Decision Assumption 1 is satisfied.
[0157] Subgroup Decision Assumption 2: Let It is a composite number Cyclic group of order, bilinear mapping Random selection , , , , , , ,set up Given If all polynomial-time adversaries are distinguished , If the advantage is negligible, then it is called a group. Subgroup criterion 2 is satisfied.
[0158] Subgroup Decision Assumption 3: Let It is a composite number Cyclic group of order, bilinear mapping Random selection , , , , , , ,set up
[0159] ,
[0160] Given If all polynomial-time adversaries are distinguished , If the advantage is negligible, then it is called a group. Subgroup criterion 3 is satisfied.
[0161] Choose security: Requires attackers to specify the challenge identity and challenge keyword in advance after obtaining the system's public key.
[0162] Complete security: Allows attackers to independently specify the challenge identity and challenge keyword after obtaining the system's public key.
[0163] Secret Channel: The system administrator uses the system public key to... Send to user after encryption It is claimed that the system administrator used a secret channel to... Send to user .
[0164] Set of sequences with no arithmetic progression and no double numbers: If Satisfy: 1) For They all ;2) They all Then it is called It is a set of sequences with no arithmetic progression and no double numbers.
[0165] Theorem: If the subgroup determination assumptions 1, 2, and 3 are in the group... If the above holds true, then the encryption method based on registration keywords and with hidden strategy in this invention can be proven to be completely secure.
[0166] Keyword strategy detection calculation process:
[0167] ,
[0168] ,
[0169] For all Due to the user public key validity verification algorithm
[0170] right Equation Established, calculated ,
[0171] ,
[0172] ,
[0173] From the decryption process, it can be seen that and so ,
[0174] therefore ,because , so
[0175] In this embodiment, the common parameter length of the participants will be explained, and the comparative advantages of this method and the well-known related scheme GLWW[2] will be pointed out, as shown in Table 2 below.
[0176] Table 2 Performance Comparison of Schemes
[0177]
[0178] In this embodiment, regarding the length of common parameters, compared with the well-known related scheme GLWW, it is assumed that... The maximum number of users in the system is the common parameter in the GLWW scheme, which is the same as the maximum number of users in the system. The number of positively correlated group elements, in this embodiment The number of positively correlated group elements greatly reduces the length of common parameters.
[0179] Example 2: This example proposes a searchable encryption method system based on registration keywords and with hidden policies. The system applies the steps of the method described in this invention and includes:
[0180] The system initialization module is configured to perform the following process: System administrator SM sets system security parameters. Keyword space The maximum value of the slot Calculate and publish the system's common parameters. .
[0181] The user private key generation module is configured to perform the following process: User Select the Each slot randomly selects and secretly stores its private key. Calculate and publish the public key :
[0182] The user public key validity verification module is configured to perform the following process: SM receives the public keys of all users. Using system common parameters Verify user's public key It was legally generated.
[0183] The system master key generation module is configured to execute the following process: The system administrator receives all ( ) legitimate public key and legal keyword set Using system common parameters Aggregate the public keys and keywords of all legitimate users to generate and publish the system's master public key. At the same time, an auxiliary decryption key is generated for each user. And secretly sent to users .
[0184] The trapdoor generation module is configured to execute the following process: Data receiver Use your private key Auxiliary decryption key Together with the set of keywords, they form a trapdoor. and will Send it to the cloud service provider.
[0185] The keywords of the encrypted access policy are configured to execute the following process: the data owner (DP) uses the system's master public key. Keyword access strategy Encryption, obtaining ciphertext Then Send it to the cloud service provider.
[0186] The keyword strategy detection module is configured to execute the following process: User trap The message is sent to the cloud service provider along with a retrieval request; the cloud service provider then exploits a trap. All ciphertext is checked; if a trapdoor is found... If the set of keywords in the ciphertext satisfies the policy in the ciphertext, then the cloud service provider will send the ciphertext to the user after the detection is passed. .
[0187] Example 3: This example proposes an electronic system, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method steps of the present invention.
[0188] Example 4: This example proposes a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the steps of the method described in this invention, which will not be repeated here.
[0189] Example 5: This example proposes a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, they implement the steps of the method described in this invention, which will not be repeated here.
[0190] It should be noted that the processing flow of embodiments 2-5 corresponds to the specific steps of the method provided in embodiment 1 of the present invention, and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in this embodiment can be found in the method provided in embodiment 1 of the present invention.
[0191] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0192] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A searchable encryption method based on registration keywords and with a hidden strategy, characterized in that, Includes the following steps: S1. System Initialization: System administrator SM initializes system security parameters, keyword space and slot maximum values, constructs a composite order bilinear group, calculates and publishes system public parameters based on a set of arithmetic and non-double sequences; S2, User Key Generation: The user selects an unused slot index, independently selects and secretly saves their private key, and calculates and publishes their public key; S3. User Public Key Validity Detection: SM uses system public parameters to verify the validity of all user public keys and adds all valid user public keys to the list of valid users; S4. Generate System Master Key: The system administrator aggregates the public keys and keyword sets of all legitimate users based on the public keys and keyword sets of the users in the list of legitimate users using the system's public parameters, calculates the system master public key and the user auxiliary decryption key, secretly sends the user auxiliary decryption key to the user, and publishes the system master key to the system bulletin board. S5, Trapdoor Generation Stage: The user combines their private key, keyword-assisted decryption key, and keyword set to form a trapdoor. When the user needs to retrieve the keyword ciphertext, the user sends their trapdoor to the cloud server. S6, Keywords for encrypted access policies; The data owner selects a set of keywords based on the characteristics of the data to be retrieved, formulates an access policy on the set of keywords, encrypts the keywords in the access policy using the system master public key to obtain the keyword ciphertext, and sends the keyword ciphertext to the cloud server for storage; S7 Keyword Strategy Detection: The user sends the trapdoor to the cloud service provider and submits a search request. The cloud service provider uses the trapdoor to detect all ciphertext. If the set of keywords in the trapdoor satisfies the strategy in the ciphertext, the detection is passed, and the cloud service provider sends the search data that matches the keyword ciphertext to the user.
2. The searchable encryption method based on registration keywords and with hidden strategy as described in claim 1, characterized in that, S1 includes the following steps: S11. System administrator SM sets a system security parameter. A keyword space The maximum value of the slot SM runs the composite order group generator to obtain the parameter set of the composite order bilinear group. ,set up ,in, and yes Cyclic groups of order 1 They are groups of Subgroups of order; S12, SM Settings , ,choose It is a set of numbers that can be computed efficiently without arithmetic progressions or double sequences; set a function. , yes The set of sums of any two distinct elements in the set; S13, SM selects a random generator , , , , Choose a hash function Select random number ,in ,calculate , ; S14. For each slot index value SM calculation Select random number Calculate the first Parameters for each slot: ; S15. For each keyword SM calculation Choose a random number For each slot index value Sum of intersection and index values Calculate the keyword-slot parameters: ; Keyword-intersection parameter: ; S16, SM settings for system common parameters: 。 3. The searchable encryption method based on registration keywords and with hidden strategy as described in claim 1, characterized in that, S2 includes the following steps: S21. When a user registers for the first time, they select an unused slot index. , will the The user of each slot is recorded as ,user Choose a random number ,use calculate: ; For each slot index and ,user Calculate the first Intersection of each slot Obtain its public key ; S21, Based on its key characteristic set , public key and keyword set Send it to the SM and secretly keep their private key. ,user public and private key pairs It is unrelated to its keyword set.
4. The searchable encryption method based on registration keywords and with hidden strategy as described in claim 1, characterized in that, S3 includes the following steps: S31, SM receives the public keys of all users. and keyword set Using common parameters Detect user public key The legitimacy of which The SM verification equation is as follows: (1); (2); (3); For each slot reference value and SM verification equation: (4); (5); SM verification The middle element does not contain and The elemental composition of the subgroup, i.e., the index value for each slot. and Verify the following equation: (6); (7); If all of the above equations (1)–(7) hold true, then the user is said to be... public key It is legal; S32, When the user public key It's legal, SM verified. Keyword set Is it included in the keyword space? If true, then it is called It is legal; S33 and SM will use all legitimate users' public keys and keyword set Add to the list of legitimate users middle.
5. A searchable encryption method based on registration keywords and with hidden strategy as described in claim 1, characterized in that, S4 includes the following steps: S41, SM will list users The user public keys in the data are aggregated, where SM compute slot public key: , ; S42. For each keyword SM computes key public key and the slot public key of the keyword : , ; S43, SM sets the system master public key and user-assisted decryption key ,Will Secretly sent to users and the system master public key Publish it in the system announcement section.
6. A searchable encryption method based on registration keywords and with hidden strategy as described in claim 1, characterized in that, Step S5 Includes the following steps: S51, User Use your private key Auxiliary decryption key Together with the set of keywords, they form a trapdoor. and will Send to the cloud server.
7. A searchable encryption method based on registration keywords and with hidden strategy as described in claim 1, characterized in that, S6 includes the following steps: S61, Data owner DP selects the data to be retrieved. Keyword set In the keyword set Configure access policies ,in , It is a matrix the number of rows, It is a matrix The number of columns, It is an injective row labeling function, and DP selects random numbers. Random elements And satisfy Select random elements DP uses the master public key The calculation is as follows: ; S62, DP selects random numbers Construct a column vector For each DP selects random numbers ,calculate: ; ; ; in, Representation matrix The OK; S63, DP setting keyword ciphertext Among them, the composite function It is a hash function and mapping The composite function DP will cipher the key. Send it to the cloud server and save it on the cloud server.
8. A searchable encryption method based on registration keywords and with hidden strategy as described in claim 1, characterized in that, S7 includes the following steps: S71, User Trapping Gate The message is sent to the cloud service provider along with a retrieval request; the cloud server then exploits a trap. Encryption of all keywords The strategy matching is performed sequentially, and the encrypted keywords that meet the keyword strategy are sent to the user. ; S72, cloud server computing ,if Not satisfying all keyword ciphertext Access policies in ,but Keyword set and If the keyword strategy in the search fails to match, output the error message and send a search failure message to the user. Otherwise, the cloud service provider's computing set , represents a matrix China satisfies All row numbers The set of, denoted as ,make Representation matrix Bank of China serial number is In Given a submatrix composed of row vectors, calculate a vector. , to satisfy ,make Representing vectors The One component, cloud service providers use traps calculate: ; if , then it means The private key and auxiliary decryption key and their claimed key set If no match is found, output the error message and send a keyword detection failure message to the user. ;if Output 1, indicating that... Keyword set and Keyword strategy matching in the middle, through detection, and ciphertext Send to user .
9. An encryption method system based on searchable keywords using registered attribute bases, characterized in that, The system comprising the steps of applying the method according to any one of claims 1 to 8, wherein the system includes: The system initialization module is configured to perform the following process: the system administrator SM initializes the system security parameters, keyword space and slot maximum values, constructs a composite order bilinear group, and calculates and publishes the system public parameters based on the set of arithmetic and non-double sequences. The user private key generation module is configured to perform the following process: the user selects an unused slot index, independently selects and secretly saves their own private key, and calculates and publishes their public key. The user public key validity verification module is configured to perform the following process: SM uses system public parameters to verify whether all user public keys are valid and adds all valid user public keys to the list of valid users; The system master key generation module is configured to perform the following process: The system administrator aggregates the public keys and keyword sets of all legitimate users based on the public keys and keyword sets of users in the list of legitimate users using system public parameters, calculates the system master public key and user auxiliary decryption key, secretly sends the user auxiliary decryption key to the user, and publishes the system master key to the system bulletin board; The trapdoor generation module is configured to perform the following process: the user combines their private key, keyword-assisted decryption key, and keyword set to form a trapdoor; when the user needs to retrieve the keyword ciphertext, the user sends their trapdoor to the cloud server. The keyword module of the encrypted access policy is configured to perform the following process: The data owner selects a set of keywords based on the characteristics of the data to be retrieved, formulates an access policy on the set of keywords, encrypts the keywords in the access policy using the system master public key to obtain the keyword ciphertext, and sends the keyword ciphertext to the cloud server for storage; The keyword policy detection module is configured to perform the following process: the user sends a trapdoor to the cloud service provider and submits a search request. The cloud service provider uses the trapdoor to detect all ciphertext. If the set of keywords in the trapdoor satisfies the policy in the ciphertext, the detection is passed, and the cloud service provider sends the search data that matches the keyword ciphertext to the user.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the computer program is executed, it implements the steps of the method as described in any one of claims 1 to 8.