Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

22 results about "Access structure" patented technology

Access structures are used in the study of security system where multiple parties need to work together to obtain a resource. Groups of parties that are granted access are called qualified. In set theoretic terms they are referred to as qualified sets. In turn, the set of all such qualified sets is called the access structure of the system. Less formally it is a description of who needs to cooperate with whom in order to access the resource. In its original use in cryptography, the resource was a secret shared among the participants. Only subgroups of participants contained in the access structure, are able to join their shares to recompute the secret. More generally, the resource can also be a task that a group of people can complete together, such as creating a digital signature, or decrypting an encrypted message.

A blockchain-based distributed data encryption sharing method

PendingCN122119943ASecuring communicationAccess structureCiphertext
The application discloses a kind of distributed data encryption sharing methods based on block chain, and using block chain realizes the traceable management of search and authorization process.The scheme is first by multi-authorization center to carry out distributed management to attribute domain, and generates attribute key associated with identity for user;In access verification link, construct parameter masking mechanism based on bilinear pairing, so that user attribute private key is not directly exposed in block chain verification and query process.Secondly, data owner carries out layered encryption to shared data and session key, and constructs the improved multi-key search structure, index and ciphertext positioning information are recorded to block chain, to support fast positioning target ciphertext.In addition, the application uses linear secret sharing to set access structure, and designs subset determination mechanism of general attribute name set, binds the download permission of ciphertext with the attribute condition that user can satisfy, to prevent overreach download behavior.Finally, with the help of cloud, outsourcing decryption is executed to generate intermediate result, and terminal only needs to complete light recovery and decryption.The application can give consideration to fine-grained control, high-performance search access and terminal side low load, and is suitable for secure data encryption sharing in resource-limited scene.
Owner:SOUTHEAST UNIV

A method for constructing a minimal linear code, a secret sharing method and a secret sharing system

PendingCN122268585AKey distribution for secure communicationAccess structureDual code
The present application belongs to the technical field of information security and coding theory, and provides a minimal linear code construction method, a secret sharing method and a secret sharing system, comprising: first defining a trace function in a finite field, constructing a two-to-one mapping, a vector Boolean function with a finite discrete value of Walsh spectrum, and then defining a code word set based on the function, embedding the output of the trace function into a linear code generation expression to generate a minimal linear code with a weight set and a support without strict inclusion; then using the dual code to establish a one-to-one correspondence between the participants and the dual code coordinates, the minimal code word support and the minimum access structure, embed the secret generation share distribution, and the participants meeting the conditions restore the secret through linear combination. The system contains four functional modules, which are suitable for distributed storage, blockchain key management and other scenes, and realize safe, efficient and expandable secret sharing. The present application can improve the security, efficiency and flexibility of secret sharing, and is suitable for multiple scenes and easy to expand.
Owner:XI'AN UNIVERSITY OF ARCHITECTURE AND TECHNOLOGY

A method for supporting time-constrained data security controllable flow in a cloud-edge environment

ActiveCN121907585BImplement fine-grained write control functionsDouble constraints on encryption permissionsPlaintextCiphertext
This invention discloses a time-constrained, secure, and controllable data flow method in a cloud-edge environment, belonging to the field of mobile edge cloud computing. Specifically, it involves: First, establishing a communication scenario including an authorizing agency for both the sender and receiver, the sender, edge nodes, a cloud server, and the receiver. Given security parameters, the authorized agency for the receiver runs a global initialization algorithm, outputting public parameters and domain public / private keys. Then, the authorized agency for the sender inputs the public parameters and domain public key, outputting its own domain public / private key. For each sender, an access structure and a valid time interval are assigned, and an encryption key is generated. For each receiver, an attribute set is assigned, and a decryption key is generated. Finally, the sender runs the encryption algorithm and outputs the original ciphertext; the edge node verifies the sender's sending authority and outputs the cleaned ciphertext; and the legitimate receiver decrypts and outputs the plaintext. This invention meets the requirements for secure and controllable data flow in a cloud-edge environment.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Homomorphic secret sharing method

The invention discloses a homomorphic secret sharing method, which adopts a Shamir threshold secret sharing scheme, and can provide threshold security for the homomorphic secret sharing method, so that a server set or an access structure which does not meet a certain condition cannot recover a specific secret value from a given secret share; meanwhile, a Shamir threshold secret sharing scheme is combined with a homomorphic encryption algorithm, so that the degree of a polynomial of the homomorphic secret sharing scheme can be improved; a homomorphic encryption algorithm is adopted to perform encryption calculation on secret input, so that after the secret input is calculated by an unauthorized server, a calculation result can be decrypted by an output server to obtain a function value of the secret input under a given function.
Owner:GANSU ELECTRIC POWER INFORMATION COMM

A lightweight attribute-based encryption method based on OBDD access structure

This invention discloses a lightweight attribute-based encryption method based on the OBDD access structure. From the perspective of encryption and decryption efficiency, this method splits the encryption stage into an offline stage and an online stage. In the offline stage, paired master and slave ciphertext module pools are computed offline, improving the encryption efficiency of the online stage. The decryption stage is split into outsourced decryption and local decryption. Before outsourced decryption, the decryptor generates an auxiliary key and provides it to the decryption agent, ensuring that the agent cannot know the plaintext while transferring most of the computational work to the agent, thereby reducing the computational burden on the decryptor. This invention improves upon existing attribute-based encryption algorithms based on the OBDD access structure, enabling data terminals to obtain the final result with low-complexity computation when encrypting or decrypting data.
Owner:SOUTHEAST UNIV

A Blockchain-Based Hierarchical Sharing Method for Medical Data

ActiveCN119760734BLayered access control implementationlow costDatabase distribution/replicationDigital data protectionAccess structureCiphertext
This invention discloses a blockchain-based hierarchical sharing method for medical data. This method encrypts files with monotonic access structures according to different levels of sensitivity. The secret value is passed upwards through a secret value sharing mechanism, transferring the secret value of the low-sensitivity ciphertext to the high-sensitivity ciphertext. During the data decryption stage, a rapid comparison is performed to find the file with the highest sensitivity that the user can satisfy, and a pre-decryption is performed. This makes it easier to decrypt sensitive files in the file set, improving access control and effectively reducing the number of decryption steps in the medical data sharing process. This truly achieves multi-level attribute data sharing while ensuring privacy and security.
Owner:ANHUI NORMAL UNIV

Vehicle-mounted CAN bus safety communication method based on attribute grouping

The invention discloses a vehicle-mounted CAN (Controller Area Network) bus safety communication method based on attribute grouping. The method comprises the following steps: firstly, selecting a master key, a public key, a hash function and related parameters; the electronic control unit ECU registers with a gateway electronic control unit GECU; in the key generation stage, the GECU groups the ECUs and distributes key generation parameters to the ECUs in the groups, and the ECUs in the groups calculate group keys according to the key generation parameters; the ECUs in the group communicate with each other by using the group key; and in the key updating and ECU re-joining stage, the ECU can update the key without interaction. Through constructing a group key generation mechanism based on an access structure tree, group communication based on ECU function attributes is realized. And a key self-authentication mechanism is introduced, so that the interaction turns between the ECUs are reduced, and the communication load is reduced. The method is suitable for a vehicle-mounted network dynamic scene, and effectively resists attacks such as counterfeiting and replaying.
Owner:ANHUI UNIV

A ciphertext retrieval system, method, computer device and storage medium

The present application relates to a kind of ciphertext search system, method, computer equipment and storage medium, it is related to the field of encryption technology, the system is by data owner, data user, authority authentication center and cloud server 4 parts are made up of, also include access control module, index generation module and CP-ABE encryption module, access control module is used to improve access structure based on attribute-based encryption, and the weight strategy tree of weight strategy based on attribute-based encryption is designed.The present application ensures the security and reliability of cloud environment, with reliable, efficient, flexible searchable encryption performance of characteristic, weight strategy based on attribute-based encryption is improved design, corresponding algorithm is carried out;Design module and generation algorithm based on Word2Vec model, attribute-based encryption algorithm based on ciphertext search;Efficient and accurate search is thus realized;Dynamic updating operation to user authority is realized, a high-efficiency and safe DWC-SW scheme is realized.
Owner:SHENZHEN TECH UNIV

Cross-carrier visual cryptography method, device and equipment based on XOR and OR operation

The embodiment of the invention discloses a cross-carrier visual cryptography method, device and equipment based on XOR and OR operation. A specific embodiment of the method comprises: according to a recovery threshold, a total number of participating ends and a participating end set, determining a participating end set group, the participating end set group comprising each participating end set, the participating end set having participating ends allocated with state tags; generating a division layer number and an access structure set according to the participating terminal set group; performing image sharing on the secret image according to the division layer number and the access structure set so as to generate each shared image; and sending the generated shared image to each participant in the participant set. According to the embodiment, the image recovery quality and security of a visual password scheme can be improved.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Efficient multi-user cooperative access control method supporting specified user access in cloud environment

The invention discloses a high-efficiency multi-user cooperative access control method for supporting specified user access in a cloud environment, and belongs to the field of information processing. The cloud server and the user use the system public parameters to generate identity public and private keys, and the cloud server generates the system public parameters and an authorization list; the trusted center generates an outsourcing decryption key for the user; the data owner generates preparation information, selects one access structure to encrypt a plurality of data segments, generates an extended key for a specified user, and generates and uploads a ciphertext to the cloud server; the data user applies for accessing the cloud data, and if the data user is a specified user meeting an access structure, the cloud server performs data decryption for the user who accesses the cloud data for the first time, performs data collaborative decryption for the user who accesses the cloud data again in the later period, and generates and returns an outsourcing decryption ciphertext; the data user receives the outsourcing decryption ciphertext, and local final decryption is completed; according to the invention, the confidentiality and controllability of data are ensured; and the calculation and communication overhead is relatively low.
Owner:XIDIAN UNIV

An attribute-based dual access control data sharing method for internet of vehicles

The application discloses a kind of attribute-based Internet of Vehicles dual access control data sharing methods, user generates attribute key, and proxy key is generated using attribute key;Data owner is encrypted to data using attribute-based encryption algorithm according to defined semi-hidden access structure, considering the limited computing capacity of vehicle end, and the encryption process is divided into offline and online two stages;Cloud server filters out the false information sent by malicious user;(Access control is carried out to the download request sent by the user who wants to access data, so as to refuse EDOS attack;Only the user who satisfies access policy can decrypt ciphertext, and the decryption stage is also divided into two stages of outsourcing decryption and user decryption;Malicious user is revoked, and after malicious user is revoked, only the ciphertext related to revocation list needs to be updated, without updating the entire ciphertext.The application can realize the safe data sharing in Internet of Vehicles, and promotes the wide application of vehicle network.
Owner:ANHUI UNIV

A cloud attribute-based multi-party privacy set intersection method and system

This invention provides a method and system for finding the intersection of multiple privacy datasets based on attribute bases in the cloud, relating to the field of information security technology. The method includes: each data owner generating ciphertext based on public parameters, access structure, and their own privacy datasets, and sending the ciphertext to a cloud server; the access structure is represented by a linear secret sharing scheme; the cloud server generating an aggregation token and a cryptographic Bloom filter based on the public parameters, request token, and ciphertext, and sending the aggregation token and cryptographic Bloom filter to the data user; and the data user determining the intersection based on the public parameters, aggregation token, and cryptographic Bloom filter. Embedding the access structure into the ciphertext set using a linear secret sharing scheme provides high flexibility; it can find the intersection of the privacy datasets of multiple data owners and data users, making it suitable for multi-party intersection scenarios; and generating the aggregation token and cryptographic Bloom filter through the cloud server improves the efficiency of finding the intersection of multiple parties.
Owner:XIDIAN UNIV

Attribute inner product function encryption method based on access structure

The invention relates to the technical field of information security and cryptography, in particular to an attribute inner product function encryption method based on an access structure. The method comprises the following steps: executing system initialization by a central authorization mechanism, and generating a public key and a master key; generating a user key based on the master key, the user attribute set and the function vector; the data owner uses the public key to encrypt the message vector according to the access structure to generate a ciphertext; and the data user decrypts the ciphertext by using the own key, and successfully outputs the inner product value of the message vector and the function vector when and only when the attribute set of the data user meets the access structure. According to the method, the access control capability of attribute-based encryption and the ciphertext calculation capability of function encryption are combined, controlled inner product operation on ciphertext data under a complex access strategy is realized, only a final inner product result is output, original data are not leaked, the security and privacy in the data sharing and calculation process are effectively improved, and the method is suitable for being applied to the field of data sharing and calculation. And the method has the capability of resisting cross-index replay and key string collusion attacks.
Owner:GUIZHOU UNIV

Network security detection method and system based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security detection method and system based on artificial intelligence, and the method comprises the steps: collecting multi-source security data in a target network environment, carrying out the entity analysis and relation matching, generating the interaction relation data among an identity entity, a service entity and a resource entity, and transmitting the interaction relation data to a server; constructing an association graph and a continuous graph structure snapshot sequence; performing incremental calculation on adjacent time window graph structures to form an access structure extension sub-graph corresponding to the identity node; establishing a legal extension mode set based on historical normal operation samples, performing structure matching on the current access structure extension sub-graphs, and screening abnormal structure sub-graphs; and mapping the abnormal structure sub-graph into an attack stage label, constructing a stage directed path graph, and judging whether an attack closed structure is formed or not through reachable path detection, so as to realize the recognition and alarm of progressive authority extension and transverse movement behaviors.
Owner:若昊新程(北京)科技有限公司

Attribute-aware dynamic encryption access control method

The invention relates to an attribute-aware dynamic encryption access control method, and belongs to the technical field of communication security. According to the technical scheme, the method comprises the steps that a multi-channel social attribute tensor is constructed by collecting a static social relation, a dynamic behavior relation, a bidirectional interaction relation and a deep social relation of a user, and a social attribute vector is obtained through vector embedding; a linear secret sharing structure access matrix is generated based on the vector, an access strategy is adjusted in real time according to a behavior deviation score and a neighborhood consistency index, a ring learning error lattice password is adopted to generate a user private key bound with a social state, and attribute-based encryption is performed according to an access structure to generate a ciphertext; during decryption, verifying social attribute satisfaction and then recovering a plaintext, and realizing verifiable revocation and social state tracking by using a Merkle tree and a fingerprint chain; according to the invention, the dynamic adaptability and security of access control can be obviously improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Resource access control system and method

PendingCN121508959ASecuring communicationAccess structureCiphertext
The invention belongs to the technical field of data processing, and discloses a resource access control system and method. Authority management based on user attributes is realized through the constructed access structure tree, the public parameter, the original pull stream address and the access structure tree are input into the encryption algorithm, then the public parameter, the private key and the encrypted ciphertext are input into the decryption algorithm through the pull stream user side, and the authentication pull stream address is generated based on the decryption result. And the stream is pulled through the streaming media server based on the authentication stream pulling address, so that the access levels of the users with different attributes can be distinguished in the stream pulling process, and a refined authority management effect is achieved.
Owner:BEIJING QIANHAI YANXIANG ELECTRONIC TECHNOLOGY CO LTD

Controllable threshold proxy re-encryption method and system

The invention relates to the technical field of cryptology, and discloses a controllable threshold proxy re-encryption method, in the controllable threshold proxy re-encryption method, n proxy parties participate, a (t, n)-threshold access structure of the n proxy parties is specified, a proxy key fragment is generated according to the threshold, and the proxy key fragment is sent to the proxy key. On the basis that the agent performs pre-authorization on the ciphertext, as long as the agent meeting the access structure participates in re-encryption conversion, agent re-encryption can be completed. According to the method, proxy re-encryption of the threshold access structure can be realized, the situation that a single proxy is offline or untrusted in a traditional proxy re-encryption scheme is effectively avoided, the availability of the system is increased, and the robustness of the system is improved. The method has the advantages of correctness, unidirectivity, non-interactivity, non-linkability and safety.
Owner:SHANGHAI JIAOTONG UNIV

A hierarchical access control system for incubator enterprise files and a method for adjusting permissions.

This invention discloses a hierarchical access control system and permission adjustment method for enterprise archives in incubators, relating to the fields of archive information security and access control technology. It addresses the risks of exporting or retrying amplification and unauthorized access caused by cross-version policy fluctuations in enterprise archives within incubator scenarios. The system solidifies enterprise identifiers in enterprise archives, extracts sensitive elements based on archive metadata and text according to rules, and assigns weighted scores to generate archive security levels and upper limits for permission levels. It combines user enterprise affiliation, roles, and attribute sets to generate deterministic access control policies and form an equivalent encrypted access structure. Symmetric encryption is used to protect the text, and attribute-based encryption is used to encapsulate the data key. Upon requesting access, authentication is performed according to the policy. Then, within the same processing cycle, a request window is constructed to calculate process variables such as export aggregation, version jumps, and retry amplification, dynamically downgrading or rejecting the operation. Simultaneously, auditing is recorded, and chain-based summaries are used to prevent tampering and traceability.
Owner:QIFAN (SHENZHEN) TECHNOLOGY CO LTD

Multi-authority attribute-based encryption protocol implementation method and system

The invention discloses a method and a system for realizing a multi-authority attribute-based encryption protocol. The method comprises the following steps that: 1, each attribute management authority center executes master key generation according to an attribute set managed by the attribute management authority center; 2, the client obtains a secret key corresponding to the attribute set from a plurality of attribute management authority centers; 3, the server selects a random number, encrypts the model parameters according to the access structure, and generates a ciphertext component containing policy information; 4, the client calculates a reconstruction coefficient by using a private key component held locally and combining parameters in the ciphertext; if the attribute meets the access structure, locally calculating a shared secret and decrypting the model parameters; and if the attribute does not meet the access structure, policy updating of the ciphertext without re-encryption is realized through the policy token. According to the protocol system provided by the invention, the flexibility and verifiability of authority management and the stability of system operation are remarkably improved in application scenarios with large-scale cooperation, long-term tasks and high supervision requirements.
Owner:ZHEJIANG SCI-TECH UNIV +1

A multi-authority attribute-based encryption protocol implementation method and system

The application discloses a kind of multi-authority attribute-based encryption protocol implementation method and system, method as follows: one, each attribute management authority center executes main key generation according to the attribute set managed by itself;Two, client obtains the key corresponding to attribute set from multiple attribute management authority centers;Three, server selects random number, encrypts model parameter according to access structure, generates ciphertext component containing policy information;Four, client reconstructs coefficient using the private key component held locally, calculates shared secret locally and decrypts model parameter if attribute satisfies access structure;If attribute does not satisfy access structure, ciphertext does not need re-encryption through policy token to realize policy update.The protocol system proposed in the application significantly improves the flexibility, verifiability and system stability of permission management in large-scale collaboration, long-term task and high supervision requirement application scenarios.
Owner:ZHEJIANG SCI-TECH UNIV +1

Data security controllable flow method supporting time constraint in cloud edge environment

ActiveCN121907585AImplement fine-grained write control functionsDouble constraints on encryption permissionsKey distribution for secure communicationPublic key for secure communicationPlaintextCiphertext
The invention discloses a data security controllable flow method supporting time constraint in a cloud edge environment, and belongs to the field of mobile edge cloud computing. The method specifically comprises the following steps: firstly, establishing a communication scene comprising a sender / receiver authorization mechanism, a sender, an edge node, a cloud server and a receiver; and giving security parameters, operating a global initialization algorithm by the receiver authorization mechanism, and outputting public parameters and domain public / private keys. Then, the sender authorization mechanism inputs a public parameter and a domain public key, and outputs a domain public / private key of the sender authorization mechanism; for each sender, an access structure and an effective time interval are allocated to the sender, and an encryption key is generated. For each receiver, a set of attributes is assigned to the receiver and a decryption key is generated. And finally, the sender operates the encryption algorithm to output the original ciphertext, the edge node verifies the sending authority of the sender and outputs the purified ciphertext, and the legal receiver decrypts and outputs the plaintext. According to the method, the requirement of safe and controllable flow of data in the cloud edge environment is met.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Verifiable multi-authority attribute-based encryption method supporting attribute revocation under block chain

PendingCN122093048AKey distribution for secure communicationPlaintextAccess structure
The invention discloses a verifiable multi-authority attribute-based encryption method supporting attribute revocation under a block chain, and the method comprises the steps: enabling a system to initialize a central authorization center CA and an attribute authority AA, submitting attributes, attribute public keys, commitments and the like to a safety storage region of a block chain intelligent contract, and enabling the contract to only read a random number, uploading the attribute, the attribute public key and the commitment to a blockchain smart contract public area; a secret key is generated, and uplink operation of a user private key and a global identifier is realized through an intelligent contract; the smart contract reads the random number from the secure storage area, and verifies the attribute public key and the private key; performing encryption according to the encrypted plaintext, and recording a returned hash address addrCT and an access structure by the block chain; and decrypting the ciphertext and realizing attribute revocation, and updating the public key and promising to realize verification of a new public key and a new private key during revocation. Compared with the prior art, the method can prevent a malicious attribute authority from distributing wrong public keys, and is adaptive to an application scene of independent cooperation of multiple authoritative institutions.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY