A system and method for supporting multi-user cooperation in read-write authorization of ciphertext data
Patent Information
- Application Number
- CN202611029074.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-10
- Publication Date
- 2026-09-15
Smart Images

Figure CN122764656A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of privacy computing and data security technology, specifically to a confidential data read / write authorization system and method that supports multi-user collaboration. Background Technology
[0002] As enterprises advance their digital transformation, storing core data in the cloud or centralized databases has become the norm. With the trend towards data encryption throughout its entire lifecycle, how to support efficient retrieval and updating of encrypted data by multiple users without exposing plaintext data has become a focal point of concern for both academia and industry.
[0003] Existing encrypted databases and searchable encryption schemes are primarily designed for single-user or read-only query scenarios. In scenarios where multiple users simultaneously perform write operations on the same encrypted data object, each user independently generates a ciphertext index and submits it to the server. Because the data is in ciphertext and users are unaware of each other's modifications, traditional concurrency control mechanisms for plaintext databases are difficult to directly apply to multi-user encrypted collaborative write scenarios, especially in situations where the plaintext is not visible to the server, making conflict identification and version coordination challenging. Existing searchable encryption schemes generally lack mechanisms for version identification and conflict resolution of updates submitted concurrently by different users. Without trusted third-party coordination, this can easily lead to data version conflicts and inconsistency breaches.
[0004] Therefore, there is an urgent need to provide a secure data read / write authorization system and method that supports multi-user collaboration, enabling concurrent read / write by multiple users, thereby improving data read / write efficiency. Summary of the Invention
[0005] In view of this, it is necessary to provide a secure data read and write authorization system and method that supports multi-user collaboration, in order to solve the technical problem in the prior art that data version conflicts and inconsistency violations occur when multiple users concurrently read and write, which makes it impossible to achieve multi-user concurrent read and write and thus leads to low data read and write efficiency.
[0006] To address the aforementioned technical problems, in a first aspect, the present invention provides a encrypted data read / write authorization system that supports multi-user collaboration, comprising a data manager terminal, multiple collaborative user terminals, and an encrypted storage server. The data manager terminal is used to generate read / write tokens, user keys, public keys, and private keys for each of the collaborating user terminals; The collaborative user terminal is used to initiate write and read requests to the encrypted storage server based on the private key; the write request includes encrypted content, index entries, and digital signature; the read request includes user identity, partition address, and current time overlay set, the current time overlay set being generated based on the system time status maintained by the encrypted storage server; The encrypted storage server is used to respond to the write request, verify the validity of the read / write token, and verify the digital signature based on the public key. When the read / write token is valid and the digital signature verification is successful, the encrypted content and the index entry are written, and the system time status is updated. The encrypted storage server is also used to respond to the read request, determine the user index based on the user identity, locate the candidate token based on the user index and partition address, verify and decrypt the candidate token based on the current time coverage set to restore the search starting point, determine the row identifier and operation number based on the search starting point, globally merge the search results of different users based on the operation number, and return the encrypted text corresponding to the valid row identifier to the collaborating user terminal; the operation number is used to identify the version of the write request, and the global merge uses the largest operation number as the valid row identifier.
[0007] In one possible implementation, the data manager terminal is also used to send initialization parameters to the encrypted storage server, the initialization parameters including the maximum number of users, the number of recursive partition levels, the partition size, the time tree depth, and the initial time encoding; The encrypted storage server is also used to establish a user mapping table based on the maximum number of users, establish a partition index table based on the number of recursive partitioning levels and the partition size, and establish an initial value of the time code for the system time state based on the time tree depth and the initial time code. The user mapping table is used to map the user identity to the user index.
[0008] In one possible implementation, the index entries include keyword index entries, DSSE chained index entries, and partition index entries; The encrypted storage server is used to write the encrypted content into the encrypted content table, and to write the keyword index entries, DSSE chain index entries and partition index entries into the keyword index table, DSSE chain index table and partition index table respectively. The encrypted storage server is also used to respond to the read request, verify whether the partition address is valid based on the partition index table, and if valid, locate the candidate token in the keyword index table according to the user index and the partition address, verify and decrypt the candidate token based on the current time coverage set to restore the search starting point, and determine the row identifier and operation number in the DSSE chained index table according to the search starting point.
[0009] In one possible implementation, the collaborative user terminal is further configured to generate a current chain token based on the keyword to be written and the user key, generate a chain address based on the current chain token, concatenate the operation number, row identifier, and preceding token into a plaintext payload, and perform mask encryption on the plaintext payload to generate the DSSE chain index entry, wherein the chain address is used to locate the DSSE chain index entry in the DSSE chain index table; generate the partition index entry based on the partition identifier of the keyword to be written and the user key; construct the current time overlay set based on the current time encoding of the keyword to be written, and encrypt the current time overlay set to generate the keyword index entry.
[0010] In one possible implementation, the collaborative user terminal is further configured to generate an aggregation key based on the keywords corresponding to the keyword index entries; the aggregation key is generated in the following manner: ; In the formula, For aggregation key; To use random numbers For generators Random group elements generated by exponentiation; This is the first master key material; This is the material for the second master key; The shared secret of the j-th collaborating user terminal; To use random numbers and sharing secrets The sum of the generators Random group elements generated by exponentiation; For elements in group G1; For the identity identifier of the collaborating user terminal that initiated the read request; This is a hash operation; To use random numbers , and sharing secrets The sum of the generators Random group elements generated by exponentiation; The aggregation key is used to decrypt the candidate tokens and restore the search starting point.
[0011] In one possible implementation, the data manager terminal is further configured to generate attribute key material based on the identity and attributes of the collaborating user terminal, and distribute the attribute key material to the collaborating user terminal; For update or append operations, the collaborative user terminal is further configured to, before executing the write request, obtain the corresponding current version of ciphertext content from the ciphertext storage server according to the row identifier of the plaintext data to be written, decrypt the current version of ciphertext content based on the attribute key material to obtain the plaintext old value, perform a differential comparison between the plaintext data to be written and the plaintext old value to determine the changed plaintext data, and re-encrypt the changed plaintext data based on the attribute key material to generate the ciphertext content in the write request.
[0012] In one possible implementation, the collaborative user terminal is specifically used for: Read the current time number E maintained by the encrypted storage server and encode the current time number E into a ternary encoded string under the time tree depth limit; Construct the current time coverage set based on the ternary encoded string; The current time coverage set is: ; In the formula, The current time overlay set; To fill the ternary encoded string C(E) to a time tree depth of d using a fill function; To extract the first i bits of the ternary encoded string C(E); To retrieve the sibling node of the i-th layer of the ternary encoded string C(E); This is the union operator.
[0013] In one possible implementation, the read / write token is derived by the data manager terminal based on the login status, user identity, collaboration table identifier, and current valid time code of each collaborating user terminal. The encrypted storage server is also used to respond to the write request, verify whether the login status in the read / write token is in a valid session, whether the user identity is consistent with the user identity carried in the write request, whether the collaboration table identifier in the read / write token corresponds to the encrypted content table, keyword index table, DSSE chained index table and partition index table, and whether the current valid time code in the read / write token is within the valid time window of the system time status; If the login status in the read / write token is in a valid session, the user identity matches the user identity carried in the write request, the collaboration table identifier in the read / write token corresponds to the encrypted content table, keyword index table, DSSE chained index table, and partition index table, and the current valid time code in the read / write token is within the valid time window of the system time state, then the write operation is performed.
[0014] In one possible implementation, the data manager terminal is also used to respond to a permission revocation command and generate a permission revocation request; The encrypted storage server is also used to respond to the permission revocation request by advancing the current time number in the system time state to a new time number, wherein the new time number is greater than the current time number and is recursively generated in the encoding field under the time tree depth limit; The encrypted storage server is also used to delete the user mapping entry in the user mapping table corresponding to the permission revocation request, so that the identity of the cooperating user terminal corresponding to the permission revocation request cannot be converted into the user index.
[0015] Secondly, the present invention also provides a method for authorizing encrypted data read / write operations that supports multi-user collaboration, applicable to the encrypted data read / write authorization system supporting multi-user collaboration described in any of the above possible implementations, the method comprising: The control data manager terminal generates read / write tokens, user keys, public keys, and private keys for each collaborating user terminal; The control and collaboration user terminal is used to initiate write and read requests to the encrypted storage server based on the private key; the write request includes encrypted content, index entry and digital signature; the read request includes user identity, partition address and current time overlay set, the current time overlay set is generated based on the system time state maintained by the encrypted storage server; The control ciphertext storage server responds to the write request, verifies the validity of the read / write token, and verifies the digital signature based on the public key. When the read / write token is valid and the digital signature verification is successful, the ciphertext content and the index entry are written, and the system time status is updated. The control ciphertext storage server is also used to respond to the read request, determine the user index based on the user identity, locate the candidate token based on the user index and partition address, verify and decrypt the candidate token based on the current time coverage set to restore the search starting point, determine the row identifier and operation number based on the search starting point, globally merge the search results of different users based on the operation number, and return the ciphertext corresponding to the valid row identifier to the collaborating user terminal; the operation number is used to identify the version of the write request, and the global merge uses the largest operation number as the valid row identifier.
[0016] The beneficial effects of this invention are as follows: The encrypted data read / write authorization system supporting multi-user collaboration provided by this invention allows the encrypted storage server to perform only read / write token validity verification, digital signature verification, and writing and storing of encrypted content and index entries when responding to write requests. Write requests from different collaborating user terminals are independent and can be submitted without waiting for other collaborating user terminals to complete their writes, achieving non-blocking concurrency in the write phase. When responding to read requests, the system determines the row identifier and operation number based on the search starting point, globally merges the search results from different users based on the operation number, uses the largest operation number as the valid row identifier, and returns the encrypted text corresponding to the valid row identifier to the collaborating user terminal. In other words, this system shifts the resolution of concurrency conflicts from the write phase to the read phase. During the write phase, each user submits independently without locking or waiting, avoiding the problem of traditional database row locking mechanisms failing in encrypted states. During the read phase, merging is achieved through a global comparison of operation numbers, ensuring eventual consistency in multi-user concurrent write scenarios, fundamentally eliminating data version conflicts and consistency violations, and improving data read / write efficiency in multi-user collaborative scenarios.
[0017] Furthermore, in this invention, cryptographic operations such as data encryption / decryption, index generation, and signature / verification are all completed on the collaborative user terminal or data manager terminal. The ciphertext storage server is only responsible for storing the ciphertext content and the ciphertext index, performing signature verification based on the public key, and comparing based on the operation number. It does not access the plaintext data or the private key throughout the entire process, so that the ciphertext storage server can maintain data consistency and operational legitimacy without being trusted, which meets the requirements of the enterprise-level zero-trust security model. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram of an embodiment of the encrypted data read / write authorization system supporting multi-user collaboration provided by the present invention. Figure 2 A schematic diagram of the initialization process of the data manager terminal provided by the present invention; Figure 3 A schematic diagram illustrating an embodiment of the write request response provided by the present invention; Figure 4 A schematic diagram illustrating an embodiment of the present invention for responding to a read request; Figure 5 A schematic flowchart illustrating an embodiment of the authorization revocation provided by this invention; Figure 6 A schematic flowchart of an embodiment of the encrypted data read / write authorization method supporting multi-user collaboration provided by the present invention; Figure 7 A schematic diagram of an embodiment of the electronic device provided by the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0021] It should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this invention illustrate operations implemented according to some embodiments of the invention. It should be understood that the operations in the flowcharts may be implemented out of order, and steps without logical contextual relationships may be reversed or performed simultaneously. Furthermore, those skilled in the art, guided by the content of this invention, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0022] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0023] This invention proposes a secure data read / write authorization system and method that supports multi-user collaboration, which will be described in detail below.
[0024] Figure 1 This is a schematic diagram of an embodiment of the encrypted data read / write authorization system supporting multi-user collaboration provided by the present invention, as shown below. Figure 1 As shown, the encrypted data read / write authorization system 10 that supports multi-user collaboration includes a data manager terminal 100, multiple collaborative user terminals 200, and an encrypted storage server 300. The data manager terminal 100 is used to generate read / write tokens, user keys, public keys, and private keys for each collaborating user terminal; The collaborative user terminal 200 is used to initiate write and read requests to the encrypted storage server based on the private key; the write request includes the encrypted content, index entry and digital signature; the read request includes the user identity, partition address and current time overlay set, which is generated based on the system time status maintained by the encrypted storage server 300. The encrypted storage server 300 is used to respond to write requests, verify the validity of read / write tokens, and verify digital signatures based on public keys. When the read / write token is valid and the digital signature verification is successful, it writes the encrypted content and index entries, and updates the system time status. The encrypted storage server 300 is also used to respond to read requests, determine the user index based on the user's identity, locate the candidate token based on the user index and partition address, verify and decrypt the candidate token based on the current time overlay set to restore the search starting point, determine the row identifier and operation number based on the search starting point, globally merge the search results of different users based on the operation number, and return the encrypted text corresponding to the valid row identifier to the collaborating user terminal 200; the operation number is used to identify the version of the write request, and the global merge uses the largest operation number as the valid row identifier.
[0025] Specifically, the process of generating read / write tokens by the data manager terminal 100 is as follows: The data manager terminal 100 generates read / write tokens based on the login status, user identity, collaboration table identifier, and current valid time code of each collaborating user terminal 200. The generation of the read / write token ensures a strong binding between the token and user attributes and the time code. Possessing this read / write token is a prerequisite for users to successfully decrypt locally and effectively sign updates, proving their right to write under the current time code. This read / write token is sent to authorized users securely. The key point is that the data manager terminal 100 is responsible for configuring the authorization policy, while the encrypted storage server 300 is responsible for verification and execution.
[0026] The encrypted storage server 300 is also used to respond to write requests, verifying whether the login state in the read / write token is in a valid session, whether the user identity matches the user identity carried in the write request, whether the collaboration table identifier in the read / write token corresponds to the encrypted content table, keyword index table, DSSE chained index table, and partition index table, and whether the current valid time code in the read / write token is within the valid time window of the system time state; if the login state in the read / write token is in a valid session, the user identity matches the user identity carried in the write request, the collaboration table identifier in the read / write token corresponds to the encrypted content table, keyword index table, DSSE chained index table, and partition index table, and the current valid time code in the read / write token is within the valid time window of the system time state, then the write operation is performed.
[0027] Specifically, the data manager terminal 100 uses the SM2 algorithm to generate public and private keys. The user key is generated by the data manager terminal 100 during the system initialization phase and is managed uniformly as part of the system's main state.
[0028] It should be noted that the Data Manager Terminal 100 also defines an access policy structure, such as (Department = R&D AND Job Level >= Senior Engineer) OR Role = Data Administrator. The access policy structure defines the access rules, and the read / write token is determined based on the access policy structure.
[0029] Compared with existing technologies, the encrypted data read / write authorization system 10 supporting multi-user collaboration provided in this embodiment of the invention only performs read / write token validity verification, digital signature verification, and write storage of encrypted content and index entries when responding to write requests. Write requests from different collaborating user terminals 200 are independent and can be submitted without waiting for other collaborating user terminals 200 to complete their writes, achieving non-blocking concurrency in the write phase. When responding to read requests, the system determines the row identifier and operation number based on the search starting point, globally merges the search results from different users based on the operation number, uses the largest operation number as the valid row identifier, and returns the encrypted text corresponding to the valid row identifier to the collaborating user terminal. In other words, this system shifts the resolution of concurrency conflicts from the write phase to the read phase. During the write phase, each user submits independently without locking or waiting, avoiding the failure of traditional database row locking mechanisms in encrypted states. During the read phase, merging is achieved through global comparison of operation numbers, ensuring eventual consistency in multi-user concurrent write scenarios, fundamentally eliminating data version conflicts and consistency violations, and improving data read / write efficiency in multi-user collaborative scenarios.
[0030] Furthermore, in this embodiment of the invention, cryptographic operations such as data encryption / decryption, index generation, and signature / verification are all completed on the collaborating user terminal 200 or the data manager terminal 100. The ciphertext storage server 300 is only responsible for storing the ciphertext content and the ciphertext index, performing signature verification based on the public key, and comparing based on the operation number. It does not access the plaintext data and the private key throughout the entire process, so that the ciphertext storage server 300 can maintain data consistency and operational legitimacy without being trusted, which meets the requirements of the enterprise-level zero-trust security model.
[0031] Because the system needs to establish the basic structure for subsequent identification of collaborative user terminals 200 during the initialization phase, the data manager terminal 100 needs to send initialization parameters to the encrypted storage server 300 to complete the establishment of the system state. Without a unified initialization configuration, the encrypted storage server 300 will not be able to accurately identify the identity mapping relationship of the collaborative user terminals 200, nor will it be able to partition and locate data and manage the time dimension when multiple users write concurrently, thus affecting the security and collaboration efficiency of the entire system.
[0032] Therefore, in some embodiments of the present invention, the data manager terminal 100 is also used to send initialization parameters to the encrypted storage server 300. The initialization parameters include the maximum number of users, the number of recursive partitioning levels, the partition size, the time tree depth, and the initial time encoding. The encrypted storage server 300 is also used to establish a user mapping table based on the maximum number of users, establish a partition index table based on the number of recursive partition levels and partition size, and establish the initial value of the time code for the system time status based on the time tree depth and the initial time code. The user mapping table is used to map user identities to user indexes.
[0033] This invention, through setting a user mapping table corresponding to the maximum number of users, a partition index table corresponding to the number of recursive partitioning levels and partition size, and an initial time code value corresponding to the time tree depth and initial time code, achieves a unified establishment of the basic structure in three dimensions: identity mapping, partition location, and time evolution in a multi-user collaborative scenario. This provides a complete basic configuration for the subsequent identity verification of write requests, partition location of read requests, and monotonic progression of system time status by the 300-pair encrypted storage server.
[0034] Specifically, such as Figure 2 As shown, the specific execution steps for initializing the data manager terminal 100 are as follows: The system receives initialization input parameters from the business scenario, including department identifier, logical table identifier, and the maximum number of users supported by the collaboration table. Based on these inputs, a corresponding access control policy is generated, and an initialization request is constructed accordingly. The initialization request includes the maximum number of users, the number of recursive partitioning levels, the partition size, the time tree depth, the initial time encoding, and the basic key material used to establish collaboration relationships. Subsequently, the data manager terminal 100 generates encrypted initialization parameters and sends them to the encrypted storage server 300. After receiving the encrypted initialization parameters, the encrypted storage server 300 constructs a system state table and writes it into the system's main state, denoted as S, which is the core context for system operation. The main state can be formally represented as: ; In the formula, To read the key material; For file key materials, For common parameters; For each user The user key; Total number of users; To share secrets; This is a correlation matrix; These are the current time, the number of assigned users, the maximum number of users, the number of recursive partition levels, the partition size, and the time tree depth, respectively.
[0035] The user key is the user's secret key, used to generate keyword chain tokens, partition tags, and time overlay tokens within their user domain.
[0036] The initial values are set: current time code C(E) is 1, and the number of allocated users A is 0. Main state. The data is stored in the database using persistent functions and can be loaded into memory from the database using recovery functions, thus ensuring the consistency of the state when the system restarts or switches sessions.
[0037] After establishing the master state, a user mapping table is created to establish a mapping structure for user identities in the encrypted data read / write authorization system 10 that supports multi-user collaboration. For data administrators... The corresponding user index is calculated through the mapping function. : ; And construct the mapping entries: ; In the formula, For mapping functions; For modulo operation, user identities are evenly distributed to N slots through modulo operation to avoid local congestion of the index space caused by uneven distribution of user identities. For collaborative user terminals Mapping entries; User context ciphertext.
[0038] Maintain a count of the number A of assigned users, satisfying the constraints. .when When a new authorized user is assigned, it can be mapped to an unused slot; when At this point, the user pool is full, and it is necessary to revoke existing authorized users to accommodate new authorized users.
[0039] In some embodiments of the present invention, index entries include keyword index entries, DSSE chained index entries, and partition index entries; The encrypted storage server 300 is used to write the encrypted content into the encrypted content table, and to write the keyword index entries, DSSE chain index entries and partition index entries into the keyword index table, DSSE chain index table and partition index table respectively. The encrypted storage server 300 is also used to respond to read requests, verify the validity of the partition address based on the partition index table, and if valid, locate the candidate token in the keyword index table based on the user index and the partition address, verify and decrypt the candidate token based on the current time overlay set to restore the search starting point, and determine the row identifier and operation number in the DSSE chained index table based on the search starting point.
[0040] Specifically, the keyword index table, DSSE linked index table, and partition index table constitute a multi-level dense index structure, with each type of index table physically isolated using the identifier stateId as a naming prefix. Let the total set of indexes be... , can be represented as: ; Keyword Index Table It is used to store secret tokens associated with keywords, users, partitions, and time-covered nodes, and the record format is as follows. ,in Index for users, This is the physical partition address. This is a count index for this user's keywords. For time-covered nodes, For keywords, encrypted tokens, This refers to the number of times the keyword is displayed. The keyword index table is the primary search target for multi-user search suggestions and matching.
[0041] DSSE linked index table Used to carry secret address tokens traced along the chain, its record format ,in Index for users, It is a chained address, generated by hashing the first 16 bytes of the search token and then extracting the first 20 bytes. It is a secret chain token. An operation number based on a system timestamp. This is the time value. This table supports direct record location by address, allowing the search process to be iteratively recovered hop-by-hop along the chain.
[0042] Partition Index Table Used to support hierarchical and partitioned retrieval, its record format ,in Index for users, The address of the parent partition. For partitioned chain tokens, This is the time number. The table is organized according to the parent-child relationship of the recursive partition hierarchy. When searching, the server can locate the target physical partition layer by layer from the root partition based on the partition token, thereby narrowing the candidate matching range of the keyword token from the global to the internal range of a single partition.
[0043] Encrypted Content Table It is used to store line-level encrypted content, and its recording format is... This table is separate from the search index; the former carries the data ontology, while the latter carries the searchability. The two are linked through... They are logically related but physically independent.
[0044] In some embodiments of the present invention, the generation process of keyword index entries, DSSE chained index entries, and partitioned index entries is specifically as follows: The collaborative user terminal 200 is also used to generate a current chain token based on the keyword to be written and the user key, generate a chain address based on the current chain token, concatenate the operation number, row identifier, and previous token into a plaintext payload, and perform mask encryption on the plaintext payload to generate a DSSE chain index entry. The chain address is used to locate the DSSE chain index entry in the DSSE chain index table; generate a partition index entry based on the partition identifier and user key of the keyword to be written; construct a current time overlay set based on the current time encoding of the keyword to be written, and encrypt the current time overlay set to generate a keyword index entry.
[0045] The keywords to be written are plaintext data, and their input format is a set of mappings between row identifiers and column name value pairs. Let the row identifier to be written be... The column set contains There are 1 column, each column is named as follows: and plaintext values The input can be represented as: .
[0046] Plaintext data undergoes standardization preprocessing. First, the encrypted storage server (300) parses the identity of the currently authorized user. Find the corresponding index through the user mapping set. Then read the current time from the main state. And query the index table for the maximum number of times that already exists. To ensure monotonic progression in the time dimension, the logical time used for writing is the larger of the two values. This time number is a logical encoding obtained recursively under the time tree depth constraint d in the ternary encoding field. Let the ternary encoding string of the current time number be denoted as . The time code used for the next write is generated using a ternary recursive function: ; If the encoding length exceeds the depth limit due to recursion, the low-order bits are preserved using a truncation function: ; This time-count generation method organizes the time dimension into a tree-like overlay structure with a finite depth, preventing the coverage of old time-counts from extending indefinitely and providing a foundation for forward security control of subsequent search tokens.
[0047] For update or append operations, the plaintext data is further differentially split with the existing old value to reduce invalid duplicate writes. Let the old value of a certain column be... The new value is If the old value is not empty and is different from the new value, then a set of deleted items is generated respectively. and new item set : ; ; in This represents a null value. Through this differential partitioning, new index entries are generated only for columns that have actually changed, ensuring that the index chain accurately reflects the actual data changes and avoiding redundant rewriting of unchanged columns.
[0048] After preprocessing, for each keyword to be processed In users The following steps generate a dense index material. First, read and increment the count state of the keyword for this user: ; This counting state This variable, used to identify the update sequence number of the same keyword within the same user domain, is the core variable for implementing the chained index. Subsequently, the current chain token is generated, using the user key. Applying a pseudo-random function to the concatenation result of keywords and counts yields:
[0049] in It is a pseudo-random function. This indicates data concatenation. It also determines the preceding token: if this is the first update for this keyword under this user, then... If the condition is met, the preceding token is set to a 32-byte all-zero vector 032; otherwise, the preceding token is generated by concatenating the user key pair keyword with the previous count value using a pseudo-random function. ; The same keyword forms a unidirectional, incremental chain structure within the same user domain. This structure allows new updates to link to previous states to preserve update history, while also enabling the search phase to restore the latest state along the chain.
[0050] Construct the DSSE chain payload based on the current chain token. First, calculate the hash digest from the first 16 bytes of the current chain token: ; in This is a secure hash function. The first 20 bytes of the digest are used as the chain address for this update: ; This address In the DSSE index, it acts as a lookup key, mapping the current search state to the position of the next ciphertext record. It defines operation flags. When adding a new operation During deletion operation The operation flag, row identifier, and preceding token are concatenated to form the plaintext payload: ; Then, the payload is XOR-masked and encrypted using the portion of hash value H from byte offset 10 to offset 46 to obtain the encrypted DSSE token: ; in This indicates a bitwise XOR operation. Constructing a DSSE index entry: ; in This is an operation number based on the system timestamp, used for version comparison and conflict resolution in subsequent searches.
[0051] Simultaneously, calculate the partition-related tokens. First, calculate the keywords. The partition identifier is hashed using a public hash function, and then the first byte of the hash is modulo the total number of partitions P. This hash is then compared with the recursion level. Combining the results, we get: ; in Indicates left shift, This indicates a bitwise OR operation. The partition identifier maps keywords to a recursive partition space. Then, the partition label is generated using the user key and the partition identifier. ; Extract the first 20 bytes of the partition label as the physical partition address: ; This partition address will be used in the keyword index table. The value of the field. Based on the recursion level surrounding this partition address. Construct a set of partition chain tokens and generate partition index entries: ; in The address of the parent partition. For partitioned chain tokens.
[0052] To support forward secure search under time coverage, the collaborative user terminal 200 is specifically used to further generate user search tokens based on the current time encoding. and time tree depth Construct the current time coverage set It includes the padding format of the current time-encoded node, the padding format of each level of prefix nodes, and the padding format of sibling nodes at the same level: ; In the formula, The current time overlay set; To fill the ternary encoded string C(E) to a time tree depth of d using a fill function; To extract the first i bits of the ternary encoded string C(E); To retrieve the sibling node of the i-th layer of the ternary encoded string C(E); This is the union operator.
[0053] For each time coverage node in the current time coverage set The encrypted input is constructed as a concatenation of keywords and time-covered nodes: ; Use user key For the current chain token Encryption is performed to obtain the user search token corresponding to the node covered by the current time: ; in This is a symmetric encryption algorithm. All encryptions corresponding to the same keyword... and current time number The user search tokens constitute a token set, and corresponding keyword index entries are generated: ; Subsequently, the collaborative user terminal 200 packages the update request message, including four types of encrypted results: content entries, keyword entries, DSSE entries, and partition entries, forming a encrypted update response set. ,in Write the result to the content. For keyword indexing results, For DSSE index results, This is the partition index result. Using its own SM2 private key, the system digitally signs the key data for this update, generates a signature value, and attaches it to the message before sending it to the encrypted storage server 300.
[0054] After receiving a write request, the encrypted storage server 300, as follows: Figure 3 As shown, the system first obtains the corresponding public key based on the user's identity and verifies the digital signature in the write request. If the digital signature verification fails, the update request is rejected directly; if the digital signature verification passes, subsequent index updates and encrypted storage operations continue. For keyword entries, the encrypted storage server 300 will store the normalized user index... Partition address Token Index Time Coverage Nodes Secret token and time number Insert the combined keywords into the keyword index table. For DSSE chained index entries, the encrypted storage server 300 will... Chained addresses Secret token Operation number and time number After combining, insert into the DSSE linked index table. For partition entries, Parent partition address Partition Chain Token and time number After combining, insert into the partition index table.
[0055] After all index entries have been written, the encrypted storage server 300 updates the current time field in the master state, using the larger value to maintain monotonically advancing time. ; When restoring the context from the database thereafter, it can be ensured that the current time count is consistent with the maximum time count in the index table, thus preventing the old time state from being reused.
[0056] For content entries, the encrypted storage server 300 will encrypt the line-level text as... The primary key is used to write encrypted content to the table. Idempotent write operations are used to overwrite newly added or modified columns. For deleted columns, the corresponding column value is set to null but retained. Row structure to maintain row stability in content tables.
[0057] When collaborative user terminal 200 initiates a request for a certain keyword When making a search request, such as Figure 4 As shown, firstly, search suggestions are generated based on the current system state, and the current time is read from the main state. and time tree depth Construct the current time overlay set. The current time overlay set is formed by merging the padding form of the current time code, the padding form of each level of prefix nodes, and the padding form of sibling nodes at the same level. The current time overlay set is as follows: ; In the formula, The current time overlay set; To fill the ternary encoded string C(E) to a time tree depth of d using a fill function; To extract the first i bits of the ternary encoded string C(E); To retrieve the sibling node of the i-th layer of the ternary encoded string C(E); This is the union operator.
[0058] For every possible user This generates corresponding search suggestions. The search suggestions include the user index and keywords from that user domain. The corresponding physical partition address and the current time overlay set: ; The physical partition address is determined by the user key. and keywords partition identifier After deriving from a pseudo-random function, the first 20 bytes are truncated to obtain: ; The purpose of search suggestions is to inform the encrypted storage server 300 in which user domain, physical partition, and time-covered nodes to search for candidate encrypted text. Search suggestions for all users constitute a read request, which is then submitted to the encrypted storage server 300 for execution.
[0059] After receiving a read request, the encrypted storage server 300 processes each search suggestion. The candidate token filtering and recovery are performed separately. First, the server searches the keyword index table using the user index. and physical partition address To perform precise filtering based on the criteria, obtain all candidate keyword token records for this user within this partition: ; This filtering operation significantly narrows the candidate range from the global index to specific users and specific partitions, and is a key step in achieving sublinear search complexity.
[0060] Subsequently, the encrypted storage server 300 followed the token index. (i.e., the update count for this keyword under this user) Traverse the candidate token set in reverse order, prioritizing the newest token. For each candidate record, the secret key token... and its corresponding time coverage nodes The server covers the time set Attempt to decrypt and verify within the specified range. If the time-covered node is among the candidate tokens... Belongs to the current time coverage set And through user key If the decryption is successful, the starting point of the search will be restored: ; in It is a 32-byte search starting point (search token), and also a chain token for the latest status of this keyword under this user. If multiple candidate tokens can be successfully decrypted, then the token index is selected. The largest candidate is used as the final search starting point: ; After successfully restoring the search starting point, the encrypted storage server 300 cleans up outdated candidate records from the keyword index set, retaining only the latest available items to prevent the long-term accumulation of historical tokens and to enhance forward security.
[0061] After obtaining the search starting point, the encrypted storage server 300 enters the DSSE chained retrieval phase. Let the search token for the current step be... ,initial hour In the first First, the hash digest of the first 16 bytes of the current search token is calculated, and the first 20 bytes are used as the chain address for this search: ; The encrypted storage server 300 uses the user index in the DSSE linked index table. and chained addresses The search chain finds the corresponding DSSE entries based on the given conditions. If no match is found, the search chain terminates; if a match is found, the DSSE entries retrieved are: ; Perform an XOR operation to restore the encrypted token. First, calculate the hash mask based on the currently searched token: ; Then, the encrypted DSSE token is XORed and decrypted using the specified offset portion of the mask to recover the plaintext payload: ; plaintext payload The format is a concatenation of the operation flag, the row identifier, and the next-hop token: ; in This is an operation flag; when adding a new operation... During deletion operation ; For business line identification; This is the 32-byte search token for the next hop. Thus, the encrypted storage server 300 can recover a row identifier and its operation type at each step on the chain.
[0062] The encrypted storage server 300 maintains a state pair for each retrieved row identifier, recording the maximum operation number found for that row under the current user domain and its corresponding operation flag. If the same row identifier is hit multiple times during the chained search, only the record with the largest operation number is retained. ; in This is the largest operation number discovered in this line. The corresponding flag is used. This "latest operation first" single-user merging rule can be formally represented as: ; If the latest operation flag A value of 1 indicates the row is considered valid; a value of 0 indicates the row has been deleted and is invalid. Then... as the next hop token Continue iterating until the end of the chain or no match is found. The entire search chain follows a hop-by-hop recursive pattern: ; After all user domains corresponding to search suggestions have completed chained searches, the encrypted storage server 300 needs to perform a cross-user global merge of states from different user domains. Let user... Row label The given final state is The global state is then defined as the state with the largest operation number selected from all users: ; This merging rule is based on the principle of prioritizing the latest operation, ensuring that the state of the same document line converges to the latest version in scenarios with concurrent updates from multiple users, eliminating interference from older or duplicate versions. The final search result set R consists of valid line identifiers with a flag of 1 in all global states. ; Then the encrypted storage server 300, based on the result set The corresponding row and column of ciphertext are retrieved from the ciphertext content table, packaged, and returned to the collaborating user terminal. The collaborating user terminal uses the file key to decrypt the ciphertext.
[0063] Each update operation is accompanied by the monotonous progression of time: Furthermore, time encoding is limited by tree depth. This ensures that time encoding does not expand indefinitely. On the search side, search suggestions only include the current time overlay set. Time points outside this coverage area cannot participate in decryption verification. Therefore, historical search tokens can only access index data within their corresponding limited time window and cannot be used for newly added ciphertext records. After the search is complete, the server removes outdated candidate tokens from the keyword index set, explicitly eliminating the availability of old tokens. From a security perspective, for any two moments... ,time generated search token Unable to derive the time New index content .
[0064] To prevent attackers from constructing legitimate ciphertext for keyword guessing attacks, in some embodiments of this invention, the collaborating user terminal is also used to generate an aggregation key based on the keywords corresponding to the keyword index entries; the aggregation key is generated in the following way: ; In the formula, For aggregation key; To use random numbers For generators Random group elements generated by exponentiation; This is the first master key material; This is the material for the second master key; The shared secret of the j-th collaborating user terminal; To use random numbers and sharing secrets The sum of the generators Random group elements generated by exponentiation; For elements in group G1; For the identity identifier of the collaborating user terminal that initiated the read request; This is a hash operation; To use random numbers , and sharing secrets The sum of the generators Random group elements generated by exponentiation; The aggregation key is used to decrypt candidate tokens and restore the search starting point.
[0065] In this embodiment of the invention, the cooperating user terminal 200 introduces random numbers when generating the aggregation key. and And combined with the shared secret of each user in the authorized user subset and system master key materials and This ensures a constant aggregate key size, guaranteeing the compactness of the search token; simultaneously, since the generation of the aggregate key relies on the shared secret of each user in the authorized user subset... And share secrets The shared secret is held only by authorized users and cannot be obtained by adversaries. By constructing legitimate ciphertext to test the identity information in the aggregate key, keyword guessing attacks targeting the ciphertext index are blocked.
[0066] In real-world business scenarios, there are also situations where employees leave or permissions change within an enterprise. To achieve dynamic revocation of permissions and forward security, and to avoid the security risks of newly generated data being illegally stolen due to the leakage of old keys, in some embodiments of the present invention, the data manager terminal 100 is also used to respond to permission revocation instructions and generate permission revocation requests; The encrypted storage server 300 is also used to respond to permission revocation requests by advancing the current time in the system time state to a new time, which is greater than the current time and is recursively generated in the encoding field under the time tree depth limit; The encrypted storage server 300 is also used to delete the user mapping entry in the user mapping table corresponding to the permission revocation request, so that the identity of the cooperating user terminal corresponding to the permission revocation request cannot be converted into the user index.
[0067] Specifically, such as Figure 5 As shown, when it is necessary to revoke the permissions of an individual or a group of users, the data administrator terminal 100 initiates a permission revocation request. The data administrator terminal 100 locates the status of the collaboration table corresponding to the user to be revoked. With user identifier The system then retrieves the user's mapping record from the user mapping structure. If the record exists, it is deleted or marked as invalid. After the reversal is complete, when subsequent update or search requests arrive at the encrypted storage server 300 again, the encrypted storage server 300 first queries the mapping relationship based on the user's identity. If the corresponding user index does not exist, an error indicating invalid authorization is returned, and index generation, encrypted search, or result recovery is no longer performed.
[0068] After the permission revocation is completed, the data administrator terminal 100 advances the system's global time encoding, putting the system into a new time state. Subsequently, authorized users generate corresponding encrypted materials based on the new time encoding during subsequent updates or searches, ensuring that operations in the new state are temporally isolated from those in the old state. When the encrypted storage server 300 receives an update request, it verifies the time encoding information carried in the request and determines whether the request falls within the scope of valid authorization based on the current system time state.
[0069] For revoked users, their old materials remain bound to the old timestamps, therefore subsequent requests will no longer have access to the new collaboration table. Regarding historical data, after revocation, the user can no longer restore a valid user index through the collaboration table system, nor can they continue to access historical data; whether historical data remains in the storage layer does not affect their access permissions. For future data, revoked users cannot participate in encryption, signing, searching, and verification under the new timestamps, and their write or search requests based on the old timestamps will be rejected by the server.
[0070] In other words, this embodiment of the invention combines a time-coded forward security mechanism to achieve permission isolation after revocation. Under this mechanism, the main operation of the encrypted storage server 300 is to delete or invalidate the user mapping record and associate it with time coding in the verification logic; the encrypted storage server 300 does not delete the user's local materials, but through the invalidation of the mapping in the collaboration table and the advancement of time coding, the revoked user automatically loses effective access ability in the new system state. This achieves immediate effect of permission revocation and forward security isolation.
[0071] In summary, the present invention proposes a secret data read and write authorization system that supports multi-user collaboration. (1) By introducing attribute-based encryption and domestic cryptographic algorithms, the data manager terminal completes the initialization of the user key and the secret data object, authorizes the user to perform the decryption and editing of the secret data locally, and uses SM2 signature to submit the modified ciphertext and digest to the ciphertext storage server, thereby achieving concurrent secure writing of the same data object by multiple users while ensuring that the data is secret throughout the process. (2) The encrypted storage server does not touch the plaintext and user private key throughout the process. The server combines the login state, request signature, permission policy and collaboration state information to complete the write verification and version advancement, so that the encrypted storage server itself does not need to be trusted to maintain data consistency; (3) By introducing a forward security mechanism based on time coding, each data write is bound to the current time coding. When the permission is revoked, the data manager only needs to advance the time coding. The revoked user cannot decrypt the newly generated encrypted text because the key held is bound to the old time coding. Thus, without relying on the encrypted storage server to actively delete the user key material, the dynamic revocation of personnel permissions and forward security isolation are realized, eliminating the security risk of new data being illegally stolen due to the leakage of old keys; (4) The partitioned write and chain index structure is adopted. Each collaborative user updates the encrypted state index in an independent partition. When searching, the encrypted storage server locates the candidate token by partition and retrieves it on the DSSE chain. The version merging within the user domain and across users is carried out by operation number. Thus, while ensuring the correctness of the search results, the sublinear search complexity is achieved, which is suitable for large-scale multi-user collaboration scenarios.
[0072] On the other hand, embodiments of the present invention also provide a method for authorizing encrypted data read / write operations that supports multi-user collaboration, applicable to the encrypted data read / write authorization system supporting multi-user collaboration in any of the above embodiments, such as... Figure 6 As shown, the methods for authorizing encrypted data read / write operations that support multi-user collaboration include: S601, Control the data manager terminal to generate read / write tokens, user keys, public keys and private keys for each cooperating user terminal; S602, The control and cooperation user terminal is used to initiate write and read requests to the ciphertext storage server based on the private key; the write request includes the ciphertext content, index entry and digital signature; the read request includes the user identity, partition address and current time overlay set, the current time overlay set is generated based on the system time state maintained by the ciphertext storage server; S603: Control the encrypted storage server to respond to write requests, verify the validity of read / write tokens, and verify digital signatures based on public keys. When the read / write token is valid and the digital signature verification is successful, write the encrypted content and index entries, and update the system time status. S604, the control ciphertext storage server is also used to respond to read requests, determine the user index based on the user's identity, locate the candidate token based on the user index and partition address, verify and decrypt the candidate token based on the current time overlay set to restore the search starting point, determine the row identifier and operation number based on the search starting point, globally merge the search results of different users based on the operation number, and return the ciphertext corresponding to the valid row identifier to the collaborating user terminal; the operation number is used to identify the version of the write request, and the global merge uses the largest operation number as the valid row identifier.
[0073] It should be noted that the encrypted data read / write authorization method supporting multi-user collaboration provided in the above embodiments can realize the technical solutions described in the above encrypted data read / write authorization system embodiments supporting multi-user collaboration. The specific implementation principles of each step can be found in the corresponding content in the above encrypted data read / write authorization system embodiments supporting multi-user collaboration, and will not be repeated here.
[0074] like Figure 7 As shown, the present invention also provides an electronic device, the electronic device 700 including a processor 701, a computer-readable storage medium 702, and a network interface 703 for realizing data interaction between the processing results of the processor 701 and external devices.
[0075] Specifically, processor 701 may include, for example, a general-purpose microprocessor, an instruction set processor, a related chipset, and a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)). Processor 701 may also include onboard memory for caching purposes. Processor 701 may be a single processing unit or multiple processing units for performing different actions in the method flow according to embodiments of the present invention.
[0076] Computer-readable storage medium 702 can be any medium capable of containing, storing, transmitting, propagating, or transmitting instructions. For example, computer-readable storage medium 702 can include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, apparatuses, or propagation media. Specific examples of computer-readable storage medium 702 include: magnetic storage devices such as magnetic tape or hard disk drives (HDDs); optical storage devices such as optical discs (CD-ROMs); memory such as random access memory (RAM) or flash memory; and wired / wireless communication links.
[0077] The computer-readable storage medium 702 stores a computer program, which includes code / computer-executable instructions. When executed by the processor 701, the computer program enables the processor 701 to implement the encrypted data read / write authorization method supporting multi-user collaboration as described in the above embodiments, such as initialization setting parameters, read / write permission authorization, encrypted update and search, and permission revocation and forward security isolation.
[0078] It should be noted that the way and number of modules in a computer program are not fixed. Those skilled in the art can use appropriate program modules or combinations of program modules according to the actual situation. When these combinations of program modules are executed by the processor, it can ensure that each terminal collaboratively completes concurrent read and write operations and dynamic access control under full data security throughout the entire process.
[0079] The foregoing has provided a detailed description of a secure data read / write authorization system and method supporting multi-user collaboration provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A secure data read / write authorization system supporting multi-user collaboration, characterized in that, This includes a data manager terminal, multiple collaborating user terminals, and a encrypted storage server; The data manager terminal is used to generate read / write tokens, user keys, public keys, and private keys for each of the collaborating user terminals; The collaborative user terminal is used to initiate write and read requests to the encrypted storage server based on the private key; the write request includes encrypted content, index entries, and digital signature; the read request includes user identity, partition address, and current time overlay set, the current time overlay set being generated based on the system time status maintained by the encrypted storage server; The encrypted storage server is used to respond to the write request, verify the validity of the read / write token, and verify the digital signature based on the public key. When the read / write token is valid and the digital signature verification is successful, the encrypted content and the index entry are written, and the system time status is updated. The encrypted storage server is also used to respond to the read request, determine the user index according to the user identity, locate the candidate token according to the user index and the partition address, verify and decrypt the candidate token based on the current time coverage set to restore the search starting point, determine the row identifier and operation number based on the search starting point, globally merge the search results of different users based on the operation number, and return the encrypted text corresponding to the valid row identifier to the collaborating user terminal. The operation number is used to identify the version of the write request, and the global merge uses the largest of the operation numbers as the valid row identifier.
2. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 1, characterized in that, The data manager terminal is also used to send initialization parameters to the encrypted storage server. The initialization parameters include the maximum number of users, the number of recursive partition levels, the partition size, the time tree depth, and the initial time encoding. The encrypted storage server is also used to establish a user mapping table based on the maximum number of users, establish a partition index table based on the number of recursive partitioning levels and the partition size, and establish an initial value of the time code for the system time state based on the time tree depth and the initial time code. The user mapping table is used to map the user identity to the user index.
3. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 1, characterized in that, The index entries include keyword index entries, DSSE chained index entries, and partition index entries; The encrypted storage server is used to write the encrypted content into the encrypted content table, and to write the keyword index entries, DSSE chain index entries and partition index entries into the keyword index table, DSSE chain index table and partition index table respectively. The encrypted storage server is also used to respond to the read request, verify whether the partition address is valid based on the partition index table, and if valid, locate the candidate token in the keyword index table according to the user index and the partition address, verify and decrypt the candidate token based on the current time coverage set to restore the search starting point, and determine the row identifier and operation number in the DSSE chained index table according to the search starting point.
4. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 3, characterized in that, The collaborative user terminal is further configured to generate a current chain token based on the keyword to be written and the user key, generate a chain address based on the current chain token, concatenate the operation number, row identifier, and preceding token into a plaintext payload, and perform mask encryption on the plaintext payload to generate the DSSE chain index entry. The chain address is used to locate the DSSE chain index entry in the DSSE chain index table. It also generates a partition index entry based on the partition identifier of the keyword to be written and the user key; constructs a current time overlay set based on the current time encoding of the keyword to be written; and encrypts the current time overlay set to generate the keyword index entry.
5. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 3, characterized in that, The collaborative user terminal is also used to generate an aggregation key based on the keywords corresponding to the keyword index entries; the aggregation key is generated in the following way: In the formula, For aggregation key; To use random numbers For generators Random group elements generated by exponentiation; This is the first master key material; This is the material for the second master key; The shared secret of the j-th collaborating user terminal; To use random numbers and sharing secrets The sum of the generators Random group elements generated by exponentiation; For elements in group G1; For the identity identifier of the collaborating user terminal that initiated the read request; This is a hash operation; To use random numbers , and sharing secrets The sum of the generators Random group elements generated by exponentiation; The aggregation key is used to decrypt the candidate tokens and restore the search starting point.
6. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 1, characterized in that, The data manager terminal is also used to generate attribute key materials based on the identity and attributes of the collaborative user terminal, and distribute the attribute key materials to the collaborative user terminal; For update or append operations, the collaborative user terminal is further configured to, before executing the write request, obtain the corresponding current version of ciphertext content from the ciphertext storage server according to the row identifier of the plaintext data to be written, decrypt the current version of ciphertext content based on the attribute key material to obtain the plaintext old value, perform a differential comparison between the plaintext data to be written and the plaintext old value to determine the changed plaintext data, and re-encrypt the changed plaintext data based on the attribute key material to generate the ciphertext content in the write request.
7. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 1, characterized in that, The collaborative user terminal is specifically used for: Read the current time number E maintained by the encrypted storage server and encode the current time number E into a ternary encoded string under the time tree depth limit; Construct the current time coverage set based on the ternary encoded string; The current time coverage set is: In the formula, The current time overlay set; To fill the ternary encoded string C(E) to a time tree depth of d using a fill function; To extract the first i bits of the ternary encoded string C(E); To retrieve the sibling node of the i-th layer of the ternary encoded string C(E); This is the union operator.
8. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 3, characterized in that, The read / write token is derived by the data manager terminal based on the login status, user identity, collaboration table identifier, and current valid time code of each collaborating user terminal; The encrypted storage server is also used to respond to the write request, verify whether the login status in the read / write token is in a valid session, whether the user identity is consistent with the user identity carried in the write request, whether the collaboration table identifier in the read / write token corresponds to the encrypted content table, keyword index table, DSSE chained index table and partition index table, and whether the current valid time code in the read / write token is within the valid time window of the system time status; If the login status in the read / write token is in a valid session, the user identity matches the user identity carried in the write request, the collaboration table identifier in the read / write token corresponds to the encrypted content table, keyword index table, DSSE chained index table, and partition index table, and the current valid time code in the read / write token is within the valid time window of the system time state, then the write operation is performed.
9. The encrypted data read / write authorization system supporting multi-user collaboration according to claim 2, characterized in that, The data manager terminal is also used to respond to permission revocation commands and generate permission revocation requests; The encrypted storage server is also used to respond to the permission revocation request by advancing the current time number in the system time state to a new time number, wherein the new time number is greater than the current time number and is recursively generated in the encoding field under the time tree depth limit; The encrypted storage server is also used to delete the user mapping entry in the user mapping table corresponding to the permission revocation request, so that the identity of the cooperating user terminal corresponding to the permission revocation request cannot be converted into the user index.
10. A method for authorizing encrypted data read / write operations that supports multi-user collaboration, characterized in that, The method, applicable to the encrypted data read / write authorization system supporting multi-user collaboration as described in any one of claims 1-9, comprises: The control data manager terminal generates read / write tokens, user keys, public keys, and private keys for each collaborating user terminal; The control and collaboration user terminal is used to initiate write and read requests to the encrypted storage server based on the private key; the write request includes encrypted content, index entry and digital signature; the read request includes user identity, partition address and current time overlay set, the current time overlay set is generated based on the system time state maintained by the encrypted storage server; The control ciphertext storage server responds to the write request, verifies the validity of the read / write token, and verifies the digital signature based on the public key. When the read / write token is valid and the digital signature verification is successful, the ciphertext content and the index entry are written, and the system time status is updated. The control ciphertext storage server is also used to respond to the read request, determine the user index based on the user identity, locate the candidate token based on the user index and partition address, verify and decrypt the candidate token based on the current time coverage set to restore the search starting point, determine the row identifier and operation number based on the search starting point, globally merge the search results of different users based on the operation number, and return the ciphertext corresponding to the valid row identifier to the collaborating user terminal; the operation number is used to identify the version of the write request, and the global merge uses the largest operation number as the valid row identifier.