Plaintext data acquisition method and system, storage medium, and electronic device

By implementing two-way identity authentication between data producers and data accessors in 5G+ industrial Internet, the problem of low security during use is solved, ensuring data privacy and security.

WO2025107709A1PCT designated stage expired Publication Date: 2025-05-30ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/108936
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-24
Filing Date
2024-07-31
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the prior art, data is less secure during use in 5G+ industrial Internet, especially during edge cloud storage and access, which is vulnerable to malicious attacks, resulting in data being forged or stolen.

Method used

By implementing two-way identity authentication between the data producer and the data accessor, it is ensured that only the authenticated data producer and the data accessor can exchange data keys, thereby obtaining and decrypting the target data.

Benefits of technology

It effectively prevents malicious attackers from forging false data and stealing target data, ensures the privacy and security of data, and solves the problem of low security caused by incomplete data management mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024108936_30052025_PF_FP_ABST
    Figure CN2024108936_30052025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a plaintext data acquisition method and system, a storage medium, and an electronic device. The plaintext data acquisition method comprises: performing first identity authentication on a data access party, and receiving an authentication result of second identity authentication performed by the data access party on a data producer; and when it is determined that the first identity authentication is passed and determined, on the basis of the authentication result of the second identity authentication, that the second identity authentication is passed, authorizing the data access party to acquire the target data generated by the data producer, and sending a data key to the data access party, wherein the data key is used as the basis of decrypting the target data when the data access party has acquired the target data, so as to obtain plaintext data corresponding to the target data. The use of the technical solution solves the problem in the prior art of low safety of data during use caused by the incomplete data management mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Method and system for obtaining plaintext data, storage medium and electronic device

[0001] This disclosure claims priority to the Chinese patent application filed with the China Patent Office on November 24, 2023, with application number 202311594545.5 and invention name “Method and system for obtaining plaintext data, storage medium and electronic device”, the entire content of which is incorporated by reference into this disclosure. Technical Field

[0002] The embodiments of the present disclosure relate to the field of communications, and in particular, to a method and system for acquiring plaintext data, a storage medium, and an electronic device. Background Art

[0003] 5G plus the Industrial Internet is the foundation of the digital economy. Traditional industrial networks are closed, making it difficult to manage large numbers of devices and users, and their scalability is poor. With 5G, industrial networks can conveniently manage a large number of industrial devices and users using 5G network elements. Furthermore, users and devices can easily access the Industrial Internet through 5G networks. This transforms industrial networks from closed to open, making it easier for users and devices to use industrial networks, significantly improving productivity. Furthermore, with the storage capabilities of 5G, industrial networks can store large amounts of data at a low cost.

[0004] In the 5G+ Industrial Internet, data producers in the industrial network (hereinafter referred to as "data producers") will store data in the 5G edge cloud (hereinafter referred to as "edge cloud"). Data accessors in the industrial network (hereinafter referred to as "data accessors") access the data.

[0005] Functions of each entity in the 5G+Industrial Internet data storage business: In the above business, the data producer provides industrial data, the edge cloud stores the industrial data, and the data accessor uses the data.

[0006] In existing technologies, edge clouds are often provided by telecom operators. When industrial network users use edge clouds to store industrial production data, there are risks such as malicious attackers forging false data or data theft by other users, which can threaten the normal production process of enterprises, cause economic losses, and even lead to legal disputes. In other words, the existing data management mechanisms are not perfect, resulting in low data security during use.

[0007] To address the above problems, no effective solutions have been proposed in the prior art.

[0008] Summary of the Invention

[0009] The embodiments of the present disclosure provide a method and system for obtaining plaintext data, a storage medium, and an electronic device, so as to at least solve the problem that the data management mechanism in the related art is not perfect, resulting in low security of the data during use.

[0010] According to one embodiment of the present disclosure, a method for obtaining plaintext data is provided, which is applied to a data producer, and includes: performing a first identity authentication on a data access party; and receiving an authentication result of a second identity authentication performed by the data access party on the data producer; when it is determined that the first identity authentication is passed, and when it is determined that the second identity authentication is passed based on the authentication result of the second identity authentication, authorizing the data access party to obtain target data generated by the data producer, and sending a data key to the data access party, wherein the data key is used to decrypt the target data according to the data key when the data access party obtains the target data, so as to obtain plaintext data corresponding to the target data.

[0011] According to another embodiment of the present disclosure, a method for obtaining plaintext data is provided, which is applied to a data access party and includes: performing a second identity authentication on a data producer, and receiving an identity authentication result of the second identity authentication performed by the data producer on the data access party; determining whether the data producer authorizes the data access party to obtain target data generated by the data producer when it is determined that the second identity authentication passes, and determining that the first identity authentication passes based on the authentication result of the first identity authentication; receiving a data key sent by the data producer when the data producer authorizes the data access party to obtain the target data generated by the data producer; and decrypting the target data according to the data key when the target data is obtained to obtain the plaintext data corresponding to the target data.

[0012] According to another embodiment of the present disclosure, a system for acquiring plaintext data is provided, comprising: a data producer, and a data access party connected to the data producer, wherein the data producer is configured to perform a first identity authentication on the data access party, and send an authentication result of the first identity authentication to the data access party; the data access party is configured to perform a second identity authentication on the data producer, and send an authentication result of the second identity authentication to the data producer; the data producer is further configured to, upon determining that the first identity authentication passes and determining that the second identity authentication passes based on the authentication result of the second identity authentication, authorize the data access party to acquire target data generated by the data producer, and send a data key to the data access party; the data access party is further configured to, upon the data producer authorizing the data access party to acquire the target data, decrypt the target data based on the data key to obtain plaintext data corresponding to the target data.

[0013] According to another embodiment of the present disclosure, a computer-readable storage medium is provided, in which a computer program is stored. The computer program is configured to execute the steps of any one of the above method embodiments when running.

[0014] According to another embodiment of the present disclosure, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any one of the above method embodiments.

[0015] Through the present disclosure, since the data access party and the data producer in the present disclosure need to perform two-way identity authentication, only the authenticated data producer can provide the key of the target data, which prevents malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, which prevents malicious attackers from impersonating legitimate data access parties to steal target data; the data producer in the present disclosure authorizes the data access party, and only the authorized data access party can decrypt the target data, which prevents malicious attackers from stealing target data, and the data producer encrypts the target data to ensure the privacy of the target data, solving the problem in the existing technology that the data management mechanism is not perfect, resulting in low security of data during use. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The exemplary embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:

[0017] FIG1 is a hardware structure block diagram of a computer terminal for a method for obtaining plaintext data according to an embodiment of the present disclosure;

[0018] FIG2 is a flow chart (I) of a method for obtaining plaintext data according to an embodiment of the present disclosure;

[0019] FIG3 is a flowchart (II) of a method for obtaining plaintext data according to an embodiment of the present disclosure;

[0020] FIG4 is a timing diagram of a method for acquiring plaintext data according to an embodiment of the present disclosure;

[0021] FIG5 is a system block diagram of a method for acquiring plaintext data according to an embodiment of the present disclosure;

[0022] FIG6 is a structural block diagram of a system for acquiring plaintext data according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0023] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.

[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0025] The method embodiments provided in the embodiments of the present disclosure can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 is a hardware structure block diagram of a computer terminal for a method for obtaining plaintext data in an embodiment of the present disclosure. As shown in Figure 1, the computer terminal may include one or more (only one is shown in Figure 1) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor (Central Processing Unit, MCU) or a programmable logic device (Field Programmable Gate Array, FPGA)) and a memory 104 for storing data, wherein the above-mentioned computer terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It can be understood by those skilled in the art that the structure shown in Figure 1 is only illustrative and does not limit the structure of the above-mentioned computer terminal. For example, the computer terminal may also include more or fewer components than those shown in Figure 1, or have a configuration different from that shown in Figure 1.

[0026] The memory 104 can be configured to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the method for obtaining plaintext data in the embodiment of the present disclosure. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implementing the above-mentioned method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0027] The transmission device 106 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by a computer terminal's communications provider. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module for wireless communication with the Internet.

[0028] In this embodiment, a method for obtaining plaintext data running on the above-mentioned computer terminal is provided. Specifically, the computer terminal is the data producer. FIG2 is a flow chart of the method for obtaining plaintext data according to an embodiment of the present disclosure. As shown in FIG2 , the flow chart includes the following steps:

[0029] Step S202: performing a first identity authentication on the data access party, and receiving an authentication result of a second identity authentication performed by the data access party on the data producer;

[0030] Step S204, when it is determined that the first identity authentication is passed, and when it is determined that the second identity authentication is passed based on the authentication result of the second identity authentication, the data access party is authorized to obtain the target data generated by the data producer, and a data key is sent to the data access party, wherein the data key is used to decrypt the target data according to the data key when the data access party obtains the target data, so as to obtain the plaintext data corresponding to the target data.

[0031] Through the above steps, since the data access party and the data producer in the present disclosure need to perform two-way identity authentication, only the authenticated data producer can provide the key of the target data, which prevents malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, which prevents malicious attackers from impersonating legitimate data access parties to steal target data; the data producer in the present disclosure authorizes the data access party, and only the authorized data access party can decrypt the target data, which prevents malicious attackers from stealing target data, and the data producer encrypts the target data to ensure the privacy of the target data, solving the problem in the existing technology that the data management mechanism is not perfect, resulting in low security of data during use.

[0032] Optionally, the specific implementation of step S202 is as follows:

[0033] Step S2021: Generate a first parameter based on a randomly generated first random number and a first session key, and generate a second parameter based on the first random number;

[0034] Specifically, the first parameter T1 is determined by the following formula: ID v is the identification information of the data access party, pk b is the public key of the authentication server corresponding to the data producer, r1 is the first random number, and k1 is the first session key.

[0035] It should be noted that h(x) and H(x) above are both hash functions, and e(x,x) is the calculation formula for bilinear pairing.

[0036] Furthermore, during the initialization phase, the authentication server in the disclosed embodiment generates a group G with an order of p and a generator of g. The authentication server generates its own private key sk a ∈Z p and sk b ∈Z p , and generate the corresponding public key and Among them, Z p is a positive integer less than p;

[0037] For data producer ID prod ∈{0,1} n , the authentication server calculates

[0038] For data accessor ID v ∈{0,1} n , the authentication server calculates

[0039] The second parameter R1 is determined by the following formula: G is the group of authentication servers corresponding to the data access party, r1 is the first random number, and g is the generator of the group.

[0040] Step S2022: sending the first parameter and the second parameter to the data access party to instruct the data access party to determine a second session key according to the first parameter and the second parameter;

[0041] In the embodiment of the present disclosure, the data access party determines the second session key based on the first parameter and the second parameter sent by the data producer, signs the second session key based on a randomly generated second random number to obtain a second digital signature corresponding to the second session key, and sends the second random number and the second digital signature to the data producer.

[0042] Furthermore, the data access party determines the second session key k2 according to the following formula:

[0043] Among them, Sk b is the private key of the authentication server corresponding to the data access party, T1 is the first parameter, and R1 is the second parameter.

[0044] The second session key is signed by the following formula to obtain a second digital signature σ corresponding to the second session key. M :

[0045] σ M =h(M,k2); where k2 is the second session key, M is the second random number, σ M The second digital signature.

[0046] It should be noted that, if there is no error in the transmission of the first parameter and the second parameter, the second session key calculated by the data access party is the same as the first session key randomly generated by the data production party.

[0047] Step S2023: Receive a second random number and a second digital signature sent by the data access party, wherein the second random number is randomly generated by the data access party, and the second digital signature is obtained by the data access party signing the second session key based on the second random number;

[0048] Step S2024: Perform a first identity authentication on the data access party based on the second random number and the second digital signature.

[0049] Specifically: the first session key is signed based on the second random number to obtain a first digital signature; when the first digital signature is consistent with the second digital signature, it is determined that the identity authentication of the data access party is passed; when the first digital signature is inconsistent with the second digital signature, it is determined that the identity authentication of the data access party is failed.

[0050] After receiving M and σ at the data producer M In the case of , the data producer also signs the first session key k1 based on M to obtain in, verify like Determine that the data access party has passed the identity authentication; if It is determined that the data access party identity authentication has failed.

[0051] Before the data producer authorizes the data accessor, the data accessor's attribute information needs to be verified. The specific verification method is as follows:

[0052] Receive the ciphertext data of the attribute value of the data access party and the third digital signature corresponding to the attribute value; decrypt the ciphertext data of the attribute value according to the randomly generated first session key to obtain the plaintext data of the attribute value; sign the plaintext data of the attribute value based on the first session key to obtain a fourth digital signature; determine whether the data access party is authorized to obtain the target data generated by the data producer based on the verification result of the third digital signature verified by the fourth digital signature.

[0053] Specifically, when the verification result indicates that the fourth digital signature is consistent with the third digital signature, it is determined that the third digital signature verification has passed, and the data access party is authorized to obtain the target data generated by the data producer; when the verification result indicates that the fourth digital signature is inconsistent with the third digital signature, it is determined that the third digital signature verification has failed, and the data access party is prohibited from being authorized to obtain the target data generated by the data producer.

[0054] Furthermore, the attribute information of the data access party is determined based on the plaintext data of the attribute value; whether the data access party meets the access conditions is determined based on the attribute information; and if the data access party meets the access conditions, the data access party is authorized to obtain the target data generated by the data producer.

[0055] That is, the data access party uses the first session key k1 obtained in the authentication phase to encrypt the attribute information A of the data access party to obtain the ciphertext data C A =Enck (A), and generate a third digital signature σ A1 =h(A,k1). The data access party will generate the ciphertext data C A and the third digital signature σ A1 Sent to the data producer; the data producer receives the ciphertext data C A and the third digital signature σ A1 After decryption, the plaintext data of the attribute information is obtained A=Dec k (C A ). Then, the attribute information A of the data access party is digitally signed according to the session key k1 to obtain the fourth digital signature σ A2 ; Verify σ A1 ? =σ A2 If the equation holds, the verification is successful; the data producer checks whether the attribute information A of the data accessor meets the access conditions. If the attribute information A meets the access conditions, the data accessor is authorized to obtain the target data generated by the data producer; otherwise, the data accessor is denied access to the target data generated by the data producer.

[0056] According to the above embodiment, only data access parties that meet specific attribute information can be authorized to access target data, thereby realizing an attribute encryption mechanism.

[0057] After the data access party authorizes the data access party to obtain the target data generated by the data producer, the data key is sent to the data access party in the following manner:

[0058] Encrypt the plaintext data of the data key to determine the ciphertext data of the data key; and sign the plaintext data of the data key based on the randomly generated first session key to obtain a fifth digital signature; send the ciphertext data of the data key and the fifth digital signature to the data access party to instruct the data access party to verify the plaintext data of the data key based on the ciphertext data of the data key and the fifth digital signature.

[0059] That is, the ciphertext data of the data key is calculated and the fifth digital signature Among them, k F is the plaintext data of the data key, k1 is the first session key; the generated and Sent to the data access party.

[0060] The data access party receives the ciphertext data of the data key sent by the data producer And the fifth digital signature corresponding to the data key The ciphertext data of the data key is decrypted according to the first session key k1 randomly generated by the data producer to obtain the plaintext data k of the data key. F ,in, The plaintext data of the data key is signed based on the first session key to obtain a sixth digital signature, wherein: In the sixth digital signature Signed with the fifth data If they are consistent, it is determined that the verification of the plaintext data of the data key has passed.

[0061] Optionally, before performing the first identity authentication on the data access party, the data producer also needs to send the target data to the edge cloud. Specifically: encrypt the plaintext data of the target data according to the plaintext data of the data key to obtain the ciphertext data of the target data; and sign the plaintext data of the target data based on the plaintext data of the data key to obtain a seventh digital signature; and send the ciphertext data of the target data and the seventh digital signature to the cloud server.

[0062] For the target data F to be uploaded, the data producer randomly generates a data key k F ∈Z p , then calculate the seventh digital signature σ of the plaintext data of the target data F =h(F,k F ); The data producer uses a symmetric encryption algorithm (exemplarily, AES) to encrypt the target data F and obtain the ciphertext data The data producer will ciphertext data C F and the seventh digital signature σ F Upload to the cloud server.

[0063] The data producer in the embodiment of the present disclosure encrypts the target data to ensure the privacy of the target data.

[0064] Furthermore, in this embodiment, a method for obtaining plaintext data running on the above-mentioned computer terminal is provided. Specifically, the computer terminal is the data access party. FIG3 is a flow chart of the method for obtaining plaintext data according to an embodiment of the present disclosure. As shown in FIG3 , the process includes the following steps:

[0065] Step S302: Perform a second identity authentication on the data producer, and receive an identity authentication result of the second identity authentication performed by the data producer on the data accessor;

[0066] Step S304: if it is determined that the second identity authentication is passed, and if it is determined that the first identity authentication is passed based on the authentication result of the first identity authentication, determining whether the data producer authorizes the data accessor to obtain the target data generated by the data producer;

[0067] Step S306: receiving the data key sent by the data producer when the data producer authorizes the data accessor to obtain the target data generated by the data producer;

[0068] Step S308: When the target data is obtained, the target data is decrypted according to the data key to obtain the plaintext data corresponding to the target data.

[0069] Through the above steps, since the data access party and the data producer in the present disclosure need to perform two-way identity authentication, only the authenticated data producer can provide the key of the target data, which prevents malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, which prevents malicious attackers from impersonating legitimate data access parties to steal target data; the data producer in the present disclosure authorizes the data access party, and only the authorized data access party can decrypt the target data, which prevents malicious attackers from stealing target data, and the data producer encrypts the target data to ensure the privacy of the target data, solving the problem in the existing technology that the data management mechanism is not perfect, resulting in low security of data during use.

[0070] In an exemplary embodiment, performing a second identity authentication on a data producer includes: determining a second session key based on a first parameter and a second parameter sent by the data producer, wherein the first parameter is generated by the data producer based on a randomly generated first random number and a first session key, and the second parameter is generated by the data producer based on the first random number; signing the second session key based on the randomly generated second random number to obtain a second digital signature corresponding to the second session key, and sending the second random number and the second digital signature to the data producer to instruct the data producer to perform a first identity authentication on the data access party based on the second random number and the second digital signature; and determining an authentication result of the second identity authentication based on the authentication result of the first identity authentication.

[0071] In an exemplary embodiment, determining the authentication result of the second identity authentication based on the authentication result of the first identity authentication includes: if the first identity authentication passes, determining that the second identity authentication passes; if the first identity authentication fails, determining that the second identity authentication fails.

[0072] In an exemplary embodiment, determining the second session key according to the first parameter and the second parameter sent by the data producer includes: determining the second session key k2 by the following formula: Among them, Sk b is the private key of the authentication server corresponding to the data access party, T1 is the first parameter, and R1 is the second parameter.

[0073] In an exemplary embodiment, before determining whether the data producer authorizes the data access party to obtain the target data generated by the data producer, the method further includes: encrypting the plaintext data of the attribute value of the data access party according to a first session key randomly generated by the data producer to obtain the ciphertext data of the attribute value; and signing the plaintext data of the attribute value based on the first session key to obtain a third digital signature; sending the ciphertext data of the attribute value and the third digital signature to the data producer to instruct the data producer to determine whether to authorize the data access party to obtain the target data generated by the data producer based on the ciphertext data of the attribute value and the third digital signature.

[0074] In an exemplary embodiment, after receiving the data key sent by the data producer, the method further includes: receiving the ciphertext data of the data key sent by the data producer, and a fifth digital signature corresponding to the data key; decrypting the ciphertext data of the data key according to the first session key randomly generated by the data producer to obtain the plaintext data of the data key; signing the plaintext data of the data key based on the first session key to obtain a sixth digital signature; and determining that the verification of the plaintext data of the data key has passed when the sixth digital signature is consistent with the fifth data signature.

[0075] In an exemplary embodiment, after decrypting the target data according to the data key to obtain the plaintext data corresponding to the target data, the method further includes: obtaining a seventh digital signature corresponding to the target data on a cloud server; signing the plaintext data of the target data based on the plaintext data of the data key to obtain an eighth digital signature; and determining that the verification of the plaintext data of the target data has passed when the seventh digital signature is consistent with the eighth digital signature.

[0076] In order to better understand the process of the above-mentioned method for obtaining plaintext data, the process of the above-mentioned method for obtaining plaintext data is described below in combination with an optional embodiment, but it is not used to limit the technical solution of the embodiment of the present disclosure.

[0077] In an exemplary embodiment, a system framework diagram of a method for obtaining plaintext data is provided. FIG4 is a system framework diagram of the method for obtaining plaintext data according to an embodiment of the present disclosure. As shown in FIG4 , the system of this embodiment includes:

[0078] An authentication server, a data producer and a data accessor connected to the authentication server, and an edge cloud connected to the data producer and the data accessor, wherein the data producer and the data accessor have a connection relationship.

[0079] The authentication server is configured to generate the public key and private key of the authentication server. The authentication server holds the private key and discloses the public key to the data producer and data accessor. For the data producer and data accessor, the authentication server generates a private key for each.

[0080] The data producer is configured to send encrypted target data to the edge cloud, authenticate the identity of the data accessor, and determine whether to authorize the data accessor to obtain the target data generated by the data producer;

[0081] The data access party is configured to authenticate the identity of the data producer and obtain the target data in the edge cloud when the data producer authorizes the data access party to obtain the target data generated by the data producer;

[0082] The edge cloud is configured to store the encrypted target data.

[0083] Specifically, the specific operation process of the authentication server, data producer, data accessor, and edge cloud in the above system is shown in FIG5 , which is a schematic diagram of a method for obtaining plaintext data according to an embodiment of the present disclosure. This embodiment includes five stages: initialization, data upload, authentication, authorization and access control, and data download. The specific steps are as follows:

[0084] 1. During the initialization phase, the authentication server generates its public and private keys according to the following steps. The authentication server holds the private key and makes the public key public. For data producers and data accessors, the authentication server generates private keys for each:

[0085] Step S401: The authentication server generates a group G with order p and generator g;

[0086] Step S402: Generate the authentication server's private key sk a ∈Z p and sk b ∈Z p ;

[0087] Step S403: The authentication server generates the corresponding public key and

[0088] Step S404: Data producer ID prod ∈{0,1} n , the authentication server generates

[0089] Step S405: Data access party ID v ∈{0,1} n , the authentication server generates

[0090] 2. When the data producer uploads data, the data producer uses the DupSys algorithm to encrypt the data and generate a signature. Specifically:

[0091] Step S501: For the target data F to be uploaded, the data producer randomly generates a number k F ∈Z p , and calculate the digital signature σ of the plaintext data of the target data F =h(F,k F ).

[0092] Step S502: The data producer uses a symmetric encryption algorithm (such as AES) to encrypt the target data F and obtain the ciphertext data

[0093] Step S503: The data producer sends the encrypted data C F and digital signature σ F Upload to the edge cloud (equivalent to the cloud server in the above embodiment).

[0094] 3. During the two-way authentication phase between the data producer and the data accessor, the data producer and the data accessor use an authentication algorithm to complete the two-way authentication. Specifically:

[0095] Step S601: The data producer randomly generates r1∈Z p and k1∈Z p ,calculate and And send R1 and T1 to the data access party.

[0096] Step S602: Data access party calculates And randomly generate M∈Z p , calculate σ M =h(M,k), and M and σ M Sent to the data producer.

[0097] Step S603: Data producer verifies σ M=h(M,k1). If the equation holds, then the mutual authentication between the data producer and the data accessor is successful; if the equation does not hold, then the mutual authentication between the data producer and the data accessor is unsuccessful.

[0098] 4. When the data producer authorizes the data accessor to obtain the target data, the data producer completes the authorization through the authorization and access control algorithm. Specifically:

[0099] Step S701: The data access party uses the session key k1 obtained in the authentication phase to encrypt the attribute value A of the data access party to obtain the ciphertext data C A =Enc k (A), and generate a digital signature σ A =h(A,k1). The data access party will generate the ciphertext data C A and digital signature σ A Sent to the data producer.

[0100] Step S702: The data producer receives the encrypted data C A and digital signature σ A After decryption, the plaintext data A=Dec k (C A ). Then verify σ A =h(A,k1). If the equation holds, the verification is successful; if not, the data producer refuses to authorize the data accessor to obtain the target data.

[0101] Step S703: The data producer checks the attribute value A of the data accessor. If the value meets the requirements, the data producer authorizes the data accessor to obtain the target data and calculates the ciphertext data. and digital signatures And and Sent to the data access party.

[0102] Step S704: The data access party decrypts and obtains the data key of the target data F and verify If the equation holds, the verification is successful, and the data access party obtains permission to access the target data F.

[0103] 5. When the data access party downloads the target data from the edge cloud, the data producer uses the DdlSys algorithm to decrypt the data and verify the signature. Specifically:

[0104] Step S801: The data access party downloads the encrypted data C from the edge cloud F and digital signature σ F .

[0105] Step S802: The data access party uses a symmetric encryption algorithm (such as AES) to decrypt the target data F and obtain the plaintext data

[0106] Step S803: Data access party verifies F ? =h(F,k F ), if the equation holds true, it is determined that the target data F has not been tampered with by the attacker.

[0107] In the context of 5G+Industrial Internet, the embodiments of the present disclosure have the following advantages:

[0108] First, only authorized data access parties can decrypt and obtain the target data, preventing illegal attackers from stealing the target data.

[0109] Second, the data producer encrypts the target data to ensure the privacy of the target data.

[0110] Third, only data access parties that meet specific attributes can decrypt the target data, realizing the attribute encryption mechanism.

[0111] Fourth, only authenticated data producers can provide file decryption keys, preventing malicious attackers from forging false data.

[0112] Fifth, only authenticated data access parties can obtain the file decryption key, preventing malicious attackers from impersonating legitimate data access parties to steal target data.

[0113] Sixth, the present disclosure uses bilinear and modular exponentiation operations only in the authentication process, and adopts lightweight cryptographic algorithms when processing large amounts of data, so it has high efficiency.

[0114] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory / random access memory (ROM / RAM), a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present disclosure.

[0115] This embodiment also provides a system for acquiring plaintext data, which is used to implement the above-mentioned embodiments and preferred embodiments. Details already described will not be repeated here. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.

[0116] FIG6 is a structural block diagram of a system for acquiring plaintext data according to an embodiment of the present disclosure. As shown in FIG6 , the system includes:

[0117] Data producer 62, data accessor 64 connected to the data producer, wherein:

[0118] The data producer 62 is configured to perform a first identity authentication on the data access party 64 and send the authentication result of the first identity authentication to the data access party; the data access party 64 is configured to perform a second identity authentication on the data producer 62 and send the authentication result of the second identity authentication to the data producer; the data producer 62 is also configured to authorize the data access party 64 to obtain the target data generated by the data producer 62 when it is determined that the first identity authentication is passed and when it is determined that the second identity authentication is passed based on the authentication result of the second identity authentication, and send a data key to the data access party 64; the data access party 64 is also configured to decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data when the data producer 62 authorizes the data access party 64 to obtain the target data.

[0119] Through the above system, since the data access party and the data producer in the present disclosure need to perform two-way identity authentication, only the authenticated data producer can provide the key of the target data, which prevents malicious attackers from forging false data, and only the authenticated data access party can obtain the key of the target data, which prevents malicious attackers from impersonating legitimate data access parties to steal target data; the data producer in the present disclosure authorizes the data access party, and only the authorized data access party can decrypt the target data, which prevents malicious attackers from stealing target data, and the data producer encrypts the target data to ensure the privacy of the target data, solving the problem in the existing technology that the data management mechanism is not perfect, resulting in low security of data during use.

[0120] In an exemplary embodiment, the data producer is further configured to randomly generate a first random number and a first session key; generate a first parameter based on the first session key and the first random number, and generate a second parameter based on the first random number; and send the first parameter and the second parameter to the data accessor;

[0121] The data access party is also configured to determine a second session key based on the first parameter and the second parameter, and randomly generate a third random number; sign the second session key based on the third random number to obtain a second digital signature corresponding to the second session key, and send the third random number and the second digital signature to the data producer.

[0122] In an exemplary embodiment, the data producer is further configured to determine a verification result of authenticating the data accessor based on the third random number and the second digital signature;

[0123] The data access party is further configured to determine a verification result of the identity authentication of the data producer according to a verification result of the identity authentication of the data access party by the data producer.

[0124] In an exemplary embodiment, the data producer is further configured to sign the first session key based on the third random number to obtain a first digital signature;

[0125] If the first digital signature is consistent with the second digital signature, determining that the data access party's identity authentication is passed;

[0126] When the first digital signature is inconsistent with the second digital signature, it is determined that the data access party identity authentication has failed.

[0127] In an exemplary embodiment, the data access party is further configured to determine that the data producer's identity authentication has passed if the data producer determines that the data access party's identity authentication has passed;

[0128] In the case where the data producer determines that the data accessor identity authentication has failed, it is determined that the data producer identity authentication has failed.

[0129] In an exemplary embodiment, the data producer is further configured to determine the first parameter T1 by the following formula:

[0130] ID v is the identification information of the data access party, pk bis the public key of the authentication server corresponding to the data producer, r1 is the first random number, and k1 is the first session key.

[0131] In an exemplary embodiment, the data producer is further configured to determine the second parameter R1 by the following formula:

[0132] G is the group of authentication servers corresponding to the data access party, r1 is the first random number, and g is the generator of the group.

[0133] In an exemplary embodiment, the data access party is further configured to determine the second session key k2 by the following formula:

[0134] Among them, Sk b is the private key of the authentication server corresponding to the data access party, T1 is the first parameter, and R1 is the second parameter.

[0135] In an exemplary embodiment, the data access party is further configured to encrypt the plaintext of the attribute value of the data access party according to a first session key to obtain a ciphertext of the attribute value; and sign the plaintext of the attribute value based on the first session key to obtain a third digital signature; and send the ciphertext of the attribute value and the third digital signature to the data producer, wherein the first session key is generated by the data producer;

[0136] The data producer is further configured to decrypt the ciphertext of the attribute value according to the first session key to obtain the plaintext of the attribute value; sign the plaintext of the attribute value based on the first session key to obtain a fourth digital signature; verify the third digital signature according to the fourth digital signature; and determine whether to authorize the data access party to obtain the target data generated by the data producer based on the verification result of the third digital signature.

[0137] In an exemplary embodiment, the data producer is further configured to determine that the third digital signature is verified to be successful if the fourth digital signature is consistent with the third digital signature, and authorize the data accessor to obtain the target data generated by the data producer;

[0138] In the case that the fourth digital signature is inconsistent with the third digital signature, it is determined that the third digital signature verification has failed, and the data access party is prohibited from being authorized to obtain the target data generated by the data producer.

[0139] In an exemplary embodiment, the data producer is further configured to determine attribute information of the data accessor based on the plain text of the attribute value; and determine whether the data accessor meets the access condition based on the attribute information;

[0140] If the data access party meets the access conditions and the fourth digital signature is consistent with the third digital signature, authorize the data access party to obtain the target data generated by the data producer;

[0141] In the event that the data access party does not meet the access conditions and / or the fourth digital signature is inconsistent with the third digital signature, the data access party is prohibited from being authorized to obtain the target data generated by the data producer.

[0142] In an exemplary embodiment, the data producer is further configured to encrypt the plaintext of the data key to determine the ciphertext of the data key, and to sign the plaintext of the data key based on the first session key generated by the data producer to obtain a fifth digital signature; and send the ciphertext of the data key and the fifth digital signature to the data access party.

[0143] In an exemplary embodiment, the data access party is also configured to decrypt the ciphertext of the data key to determine the plaintext of the data key, and sign the plaintext of the data key based on the first session key generated by the data producer to obtain a sixth digital signature; when the sixth digital signature is consistent with the fifth digital signature, it is determined that the verification of the plaintext of the data key has passed.

[0144] In an exemplary embodiment, the data access party is further configured to obtain the seventh digital signature of the target data on the cloud server, and sign the plaintext of the target data based on the plaintext of the data key to obtain an eighth digital signature; when the seventh digital signature is consistent with the eighth digital signature, it is determined that the verification of the plaintext of the target data is passed.

[0145] In an exemplary embodiment, the data producer is further configured to encrypt the plaintext of the target data according to the plaintext of the data key to obtain the ciphertext of the target data, and sign the plaintext of the target data based on the plaintext of the data key to obtain a seventh digital signature; and send the ciphertext of the target data and the seventh digital signature to the cloud server.

[0146] It should be noted that the above modules can be implemented through software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.

[0147] To facilitate understanding of the technical solutions provided by the present disclosure, embodiments of specific scenarios will be described in detail below.

[0148] An embodiment of the present disclosure further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps of any one of the above method embodiments when run.

[0149] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.

[0150] An embodiment of the present disclosure further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any one of the above method embodiments.

[0151] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0152] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail here.

[0153] Obviously, those skilled in the art should understand that the modules or steps of the present disclosure described above can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices, they can be implemented using program code executable by the computing device, and thus, they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be performed in a different order than herein, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present disclosure is not limited to any particular combination of hardware and software.

[0154] The above description is merely a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. Those skilled in the art will readily appreciate that the present disclosure is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the principles of the present disclosure shall be within the scope of protection of the present disclosure.

Claims

1. A method for obtaining plaintext data, applied to a data producer, comprising: Performing a first identity authentication on the data access party, and receiving an authentication result of a second identity authentication performed by the data access party on the data production party; When it is determined that the first identity authentication is passed, and when it is determined that the second identity authentication is passed based on the authentication result of the second identity authentication, the data access party is authorized to obtain the target data generated by the data producer, and a data key is sent to the data access party, wherein the data key is used to decrypt the target data based on the data key to obtain the plaintext data corresponding to the target data when the data access party obtains the target data.

2. The method according to claim 1, wherein: Perform the first identity authentication on the data access party, including: generating a first parameter based on a randomly generated first random number and a first session key, and generating a second parameter based on the first random number; Sending the first parameter and the second parameter to the data access party to instruct the data access party to determine a second session key according to the first parameter and the second parameter; Receive a second random number and a second digital signature sent by the data access party, wherein the second random number is randomly generated by the data access party, and the second digital signature is obtained by the data access party signing the second session key based on the second random number; A first identity authentication is performed on the data access party according to the second random number and the second digital signature.

3. The method according to claim 2, wherein: Determining to perform a first identity authentication on the data access party according to the second random number and the second digital signature includes: Signing the first session key based on the second random number to obtain a first digital signature; When the first digital signature is consistent with the second digital signature, determining that the data access party identity authentication is passed; When the first digital signature is inconsistent with the second digital signature, it is determined that the data access party identity authentication has failed.

4. The method according to claim 2, wherein: Generating a first parameter according to a randomly generated first random number and a first session key includes: The first parameter T1 is determined by the following formula: ID v is the identification information of the data access party, pk b is the public key of the authentication server corresponding to the data producer, r1 is the first random number, and k1 is the first session key.

5. The method according to claim 2, wherein: Generating a second parameter according to the first random number includes: The second parameter R1 is determined by the following formula: G is the group of authentication servers corresponding to the data access party, r1 is the first random number, and g is The generator of the group.

6. The method according to claim 1, wherein: Before authorizing the data access party to obtain the target data generated by the data producer, the method further includes: Receiving ciphertext data of the attribute value of the data access party and a third digital signature corresponding to the attribute value; Decrypting the ciphertext data of the attribute value according to the randomly generated first session key to obtain the plaintext data of the attribute value; Signing the plaintext data of the attribute value based on the first session key to obtain a fourth digital signature; Determine whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of the third digital signature verified by the fourth digital signature.

7. The method according to claim 6, wherein: Determining whether to authorize the data access party to obtain the target data generated by the data producer according to the verification result of the third digital signature by the fourth digital signature includes: If the verification result indicates that the fourth digital signature is consistent with the third digital signature, determine that the third digital signature verification is passed, and authorize the data access party to obtain the target data generated by the data producer; When the verification result indicates that the fourth digital signature is inconsistent with the third digital signature, it is determined that the third digital signature verification has failed, and the data access party is prohibited from being authorized to obtain the target data generated by the data producer.

8. The method according to claim 7, wherein: Authorizing the data access party to obtain the target data generated by the data producer, including: Determine the attribute information of the data access party according to the plaintext data of the attribute value; Determining whether the data access party meets the access condition according to the attribute information; In a case where the data access party meets the access condition, the data access party is authorized to obtain the target data generated by the data producer.

9. The method according to claim 1, wherein: Sending a data key to the data access party includes: Encrypting the plaintext data of the data key to determine the ciphertext data of the data key; and, Signing the plaintext data of the data key based on the randomly generated first session key to obtain a fifth digital signature; The ciphertext data of the data key and the fifth digital signature are sent to the data access party to instruct the data access party to verify the plaintext data of the data key according to the ciphertext data of the data key and the fifth digital signature.

10. The method according to claim 1, wherein: Before performing the first identity authentication on the data access party, the method further includes: Encrypting the plaintext data of the target data according to the plaintext data of the data key to obtain the ciphertext data of the target data; and Signing the plaintext data of the target data based on the plaintext data of the data key to obtain a seventh digital signature; The ciphertext data of the target data and the seventh digital signature are sent to the cloud server.

11. A method for obtaining plaintext data, applied to a data access party, comprising: Performing a second identity authentication on the data producer, and receiving an authentication result of the first identity authentication performed by the data producer on the data accessor; When it is determined that the second identity authentication is passed, and when it is determined that the first identity authentication is passed according to the authentication result of the first identity authentication, determining whether the data producer authorizes the data accessor to obtain the target data generated by the data producer; When the data producer authorizes the data accessor to obtain the target data generated by the data producer, receiving the data key sent by the data producer; When the target data is obtained, the target data is decrypted according to the data key to obtain the plaintext data corresponding to the target data.

12. The method according to claim 11, wherein: Perform a second identity authentication on the data producer, including: Determine a second session key according to a first parameter and a second parameter sent by a data producer, wherein the first parameter is generated by the data producer according to a randomly generated first random number and the first session key, and the second parameter is generated by the data producer according to the first random number; Signing the second session key based on a randomly generated second random number to obtain a second digital signature corresponding to the second session key, and sending the second random number and the second digital signature to the data producer to instruct the data producer to perform a first identity authentication on the data access party according to the second random number and the second digital signature; The authentication result of the second identity authentication is determined according to the authentication result of the first identity authentication.

13. The method according to claim 12, wherein: Determining the authentication result of the second identity authentication according to the authentication result of the first identity authentication includes: If the first identity authentication passes, determining that the second identity authentication passes; If the first identity authentication fails, it is determined that the second identity authentication fails.

14. The method according to claim 12, wherein: Determining a second session key according to a first parameter and a second parameter sent by a data producer includes: The second session key k2 is determined by the following formula: Among them, Sk b is the private key of the authentication server corresponding to the data access party, T1 is the first parameter, and R1 is the second parameter.

15. The method according to claim 11, wherein: Before determining whether the data producer authorizes the data accessor to obtain the target data generated by the data producer, the method further includes: Encrypting the plaintext data of the attribute value of the data access party according to the first session key randomly generated by the data producer to obtain the ciphertext data of the attribute value; and Signing the plaintext data of the attribute value based on the first session key to obtain a third digital signature; The ciphertext data of the attribute value and the third digital signature are sent to the data producer to instruct the data producer to determine whether to authorize the data access party to obtain the target data generated by the data producer based on the ciphertext data of the attribute value and the third digital signature.

16. The method according to claim 11, wherein: After receiving the data key sent by the data producer, the method further includes: Receiving the ciphertext data of the data key and the fifth digital signature corresponding to the data key sent by the data producer; Decrypting the ciphertext data of the data key according to the first session key randomly generated by the data producer to obtain the plaintext data of the data key; Signing the plaintext data of the data key based on the first session key to obtain a sixth digital signature; When the sixth digital signature is consistent with the fifth digital signature, it is determined that the verification of the plaintext data of the data key is successful.

17. The method according to claim 11, wherein: After decrypting the target data according to the data key to obtain the plaintext data corresponding to the target data, the method further includes: Obtaining a seventh digital signature corresponding to the target data on the cloud server; Signing the plaintext data of the target data based on the plaintext data of the data key to obtain an eighth digital signature; When the seventh digital signature is consistent with the eighth digital signature, it is determined that the verification of the plaintext data of the target data is passed.

18. A system for acquiring plaintext data, comprising: A data producer, and a data accessor connected to the data producer, wherein: The data producer is configured to perform a first identity authentication on the data accessor, and send an authentication result of the first identity authentication to the data accessor; The data access party is configured to perform a second identity authentication on the data producer, and send an authentication result of the second identity authentication to the data producer; The data producer is further configured to authorize the data accessor to obtain the target data generated by the data producer, and send a data key to the data accessor, when determining that the first identity authentication is passed and determining that the second identity authentication is passed based on the authentication result of the second identity authentication; The data access party is further configured to decrypt the target data according to the data key to obtain the plaintext data corresponding to the target data when the data producer authorizes the data access party to obtain the target data.

19. A computer-readable storage medium having a computer program stored therein, wherein: When the computer program is executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 10, or implements the steps of the method described in any one of claims 11 to 17.

20. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of claims 1 to 10, or implements the steps of the method described in any one of claims 11 to 17 when executing the computer program.

Citation Information

Patent Citations

  • A cloud storage access control method based on ciphertext policy attribute base encryption

    CN109040045A

  • Key negotiation method and device, electronic equipment and computer readable storage medium

    CN115065466A

  • Data transmission method and device, computer equipment and storage medium

    CN116232639A

  • Identity authentication method and device

    WO2018127118A1