Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

37 results about "Access structure" patented technology

Access structures are used in the study of security system where multiple parties need to work together to obtain a resource. Groups of parties that are granted access are called qualified. In set theoretic terms they are referred to as qualified sets. In turn, the set of all such qualified sets is called the access structure of the system. Less formally it is a description of who needs to cooperate with whom in order to access the resource. In its original use in cryptography, the resource was a secret shared among the participants. Only subgroups of participants contained in the access structure, are able to join their shares to recompute the secret. More generally, the resource can also be a task that a group of people can complete together, such as creating a digital signature, or decrypting an encrypted message.

Decentralized identity management method based on trusted execution environment

PendingCN121098518AUser identity/authority verificationAccess structureComputer network
The invention discloses a decentralized identity management method based on a trusted execution environment, and the method comprises the steps: generating, isolating and storing a user decentralized identity in the trusted execution environment of equipment, carrying out the Hash signature of a decentralized identity document, and recording an uplink; the block chain consensus node verifies the decentralized document uplink transaction through a Byzantine fault-tolerant consensus mechanism and achieves consistency, and writes the metadata of the decentralized identity into the block; encrypting and storing the voucher in a trusted execution environment of the equipment by adopting a Pearson commitment, and supporting voucher Hash uplink and commitment uplink; and introducing a multilevel access structure based on a binary tree, and verifying the and / or logic combination voucher by adopting a depth-first search algorithm. According to the method, decentralized autonomy of the user identity and hardware security isolation are supported, and the reliability and privacy protection capability of user identity management are improved.
Owner:SOUTHEAST UNIV

Attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations

InactiveCN120956419AKey distribution for secure communicationAccess structureEngineering
The invention discloses an attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations, which is characterized in that a certificate issuing mechanism is responsible for initialization of a system and registration of an attribute issuing mechanism and a user, and the attribute issuing mechanism manages part of attributes authorized by the attribute issuing mechanism and generates a conversion key of an agency for outsourcing decryption; the data owner encrypts the data by using attribute-based encryption according to the defined access structure and the label structure; and the proxy server converts the access strategy formulated by the data owner into a puncture strategy and then punctures the conversion key so as to cancel the specified user group. According to the method, puncture revocation and outsourcing decryption attribute-based access control under a multi-authorization mechanism can be realized, and a feasible method is provided for lightweight and fine-grained user revocation under the multi-authorization mechanism.
Owner:NANJING UNIV OF POSTS & TELECOMM

A method and apparatus for constructing an LSSS access structure that supports collaborative decryption.

ActiveCN120281580BSecuring communicationAccess structureAlgorithm
This invention provides a method and apparatus for constructing an LSSS access structure that supports collaborative decryption. The method includes: constructing an LSSS access structure according to a collaborative access strategy, wherein an access matrix M in the LSSS access structure is used to determine a first column vector λ, and the first column vector λ includes a second column vector λ. s ; and the sub-access matrix M used to construct the sub-strategy sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used for encryption; Sub-access matrix M sub and the third column vector λ sub Used for decryption. In this embodiment of the invention, the second column vector λ is used... s Equal to the third column vector λ sub Thus, for the third column vector λ sub The relevant calculation results can be used in the relevant calculations for the first column vector λ, saving computational overhead and thus improving encryption and decryption efficiency.
Owner:THREE GORGES GROUP IND DEVELOPMENT (BEIJING) CO LTD +1

A blockchain-based distributed data encryption sharing method

PendingCN122119943ASecuring communicationAccess structureCiphertext
The application discloses a kind of distributed data encryption sharing methods based on block chain, and using block chain realizes the traceable management of search and authorization process.The scheme is first by multi-authorization center to carry out distributed management to attribute domain, and generates attribute key associated with identity for user;In access verification link, construct parameter masking mechanism based on bilinear pairing, so that user attribute private key is not directly exposed in block chain verification and query process.Secondly, data owner carries out layered encryption to shared data and session key, and constructs the improved multi-key search structure, index and ciphertext positioning information are recorded to block chain, to support fast positioning target ciphertext.In addition, the application uses linear secret sharing to set access structure, and designs subset determination mechanism of general attribute name set, binds the download permission of ciphertext with the attribute condition that user can satisfy, to prevent overreach download behavior.Finally, with the help of cloud, outsourcing decryption is executed to generate intermediate result, and terminal only needs to complete light recovery and decryption.The application can give consideration to fine-grained control, high-performance search access and terminal side low load, and is suitable for secure data encryption sharing in resource-limited scene.
Owner:SOUTHEAST UNIV

A method for constructing a minimal linear code, a secret sharing method and a secret sharing system

PendingCN122268585AKey distribution for secure communicationAccess structureDual code
The present application belongs to the technical field of information security and coding theory, and provides a minimal linear code construction method, a secret sharing method and a secret sharing system, comprising: first defining a trace function in a finite field, constructing a two-to-one mapping, a vector Boolean function with a finite discrete value of Walsh spectrum, and then defining a code word set based on the function, embedding the output of the trace function into a linear code generation expression to generate a minimal linear code with a weight set and a support without strict inclusion; then using the dual code to establish a one-to-one correspondence between the participants and the dual code coordinates, the minimal code word support and the minimum access structure, embed the secret generation share distribution, and the participants meeting the conditions restore the secret through linear combination. The system contains four functional modules, which are suitable for distributed storage, blockchain key management and other scenes, and realize safe, efficient and expandable secret sharing. The present application can improve the security, efficiency and flexibility of secret sharing, and is suitable for multiple scenes and easy to expand.
Owner:XI'AN UNIVERSITY OF ARCHITECTURE AND TECHNOLOGY

A method for supporting time-constrained data security controllable flow in a cloud-edge environment

ActiveCN121907585BImplement fine-grained write control functionsDouble constraints on encryption permissionsPlaintextCiphertext
This invention discloses a time-constrained, secure, and controllable data flow method in a cloud-edge environment, belonging to the field of mobile edge cloud computing. Specifically, it involves: First, establishing a communication scenario including an authorizing agency for both the sender and receiver, the sender, edge nodes, a cloud server, and the receiver. Given security parameters, the authorized agency for the receiver runs a global initialization algorithm, outputting public parameters and domain public / private keys. Then, the authorized agency for the sender inputs the public parameters and domain public key, outputting its own domain public / private key. For each sender, an access structure and a valid time interval are assigned, and an encryption key is generated. For each receiver, an attribute set is assigned, and a decryption key is generated. Finally, the sender runs the encryption algorithm and outputs the original ciphertext; the edge node verifies the sender's sending authority and outputs the cleaned ciphertext; and the legitimate receiver decrypts and outputs the plaintext. This invention meets the requirements for secure and controllable data flow in a cloud-edge environment.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Homomorphic secret sharing method

The invention discloses a homomorphic secret sharing method, which adopts a Shamir threshold secret sharing scheme, and can provide threshold security for the homomorphic secret sharing method, so that a server set or an access structure which does not meet a certain condition cannot recover a specific secret value from a given secret share; meanwhile, a Shamir threshold secret sharing scheme is combined with a homomorphic encryption algorithm, so that the degree of a polynomial of the homomorphic secret sharing scheme can be improved; a homomorphic encryption algorithm is adopted to perform encryption calculation on secret input, so that after the secret input is calculated by an unauthorized server, a calculation result can be decrypted by an output server to obtain a function value of the secret input under a given function.
Owner:GANSU ELECTRIC POWER INFORMATION COMM

A lightweight attribute-based encryption method based on OBDD access structure

This invention discloses a lightweight attribute-based encryption method based on the OBDD access structure. From the perspective of encryption and decryption efficiency, this method splits the encryption stage into an offline stage and an online stage. In the offline stage, paired master and slave ciphertext module pools are computed offline, improving the encryption efficiency of the online stage. The decryption stage is split into outsourced decryption and local decryption. Before outsourced decryption, the decryptor generates an auxiliary key and provides it to the decryption agent, ensuring that the agent cannot know the plaintext while transferring most of the computational work to the agent, thereby reducing the computational burden on the decryptor. This invention improves upon existing attribute-based encryption algorithms based on the OBDD access structure, enabling data terminals to obtain the final result with low-complexity computation when encrypting or decrypting data.
Owner:SOUTHEAST UNIV

Interactive attribute-based encryption and decryption method and system

The present application belongs to the field of encryption and decryption technology, and provides an interactive attribute-based encryption and decryption method and system, including: an attribute authorization agency AA executes an initialization algorithm to generate system public parameters, a master key and an attribute-based encrypted access structure; for each attribute, the attribute authorization agency generates an attribute-independent key component and an attribute-related key component based on the master key and the access structure; the data owner uses the system public parameters and the access structure to encrypt data and generate ciphertext; the data owner publishes the ciphertext and the access structure to the blockchain network; the authorized user obtains the ciphertext and the access structure from the blockchain network, executes the interactive attribute-based decryption algorithm, generates an intermediate key, and sends an interactive decryption task containing the intermediate key to the service provider; the authorized user receives the decryption result fed back by the service provider, thereby significantly reducing the computational burden of the lightweight device during the decryption process.
Owner:BEIJING GUODU INTERNET TECH CO LTD

A linear method for key sharing among five participants

The present invention provides a linear key sharing method for five participants, comprising the following steps: Step 1: Based on the access structure, query the corresponding linear capacity domain; Step 2: Establish a corresponding integer programming model based on the polar direction vector of the linear capacity domain and the input subkey size vector, and determine the combination coefficients used in the final method based on the feasible solution of the integer programming; Step 3: Based on the optimal solution of the integer programming, combine the methods corresponding to the polar direction vectors, and the combined method becomes the final linear key sharing method. The method of the present invention is applicable to any access structure and any integer subkey size vector for the five participants, and can obtain a relatively optimal master key size.
Owner:SOUTHEAST UNIV

A Blockchain-Based Hierarchical Sharing Method for Medical Data

ActiveCN119760734BLayered access control implementationlow costDatabase distribution/replicationDigital data protectionAccess structureCiphertext
This invention discloses a blockchain-based hierarchical sharing method for medical data. This method encrypts files with monotonic access structures according to different levels of sensitivity. The secret value is passed upwards through a secret value sharing mechanism, transferring the secret value of the low-sensitivity ciphertext to the high-sensitivity ciphertext. During the data decryption stage, a rapid comparison is performed to find the file with the highest sensitivity that the user can satisfy, and a pre-decryption is performed. This makes it easier to decrypt sensitive files in the file set, improving access control and effectively reducing the number of decryption steps in the medical data sharing process. This truly achieves multi-level attribute data sharing while ensuring privacy and security.
Owner:ANHUI NORMAL UNIV

Vehicle-mounted CAN bus safety communication method based on attribute grouping

The invention discloses a vehicle-mounted CAN (Controller Area Network) bus safety communication method based on attribute grouping. The method comprises the following steps: firstly, selecting a master key, a public key, a hash function and related parameters; the electronic control unit ECU registers with a gateway electronic control unit GECU; in the key generation stage, the GECU groups the ECUs and distributes key generation parameters to the ECUs in the groups, and the ECUs in the groups calculate group keys according to the key generation parameters; the ECUs in the group communicate with each other by using the group key; and in the key updating and ECU re-joining stage, the ECU can update the key without interaction. Through constructing a group key generation mechanism based on an access structure tree, group communication based on ECU function attributes is realized. And a key self-authentication mechanism is introduced, so that the interaction turns between the ECUs are reduced, and the communication load is reduced. The method is suitable for a vehicle-mounted network dynamic scene, and effectively resists attacks such as counterfeiting and replaying.
Owner:ANHUI UNIV

A ciphertext retrieval system, method, computer device and storage medium

The present application relates to a kind of ciphertext search system, method, computer equipment and storage medium, it is related to the field of encryption technology, the system is by data owner, data user, authority authentication center and cloud server 4 parts are made up of, also include access control module, index generation module and CP-ABE encryption module, access control module is used to improve access structure based on attribute-based encryption, and the weight strategy tree of weight strategy based on attribute-based encryption is designed.The present application ensures the security and reliability of cloud environment, with reliable, efficient, flexible searchable encryption performance of characteristic, weight strategy based on attribute-based encryption is improved design, corresponding algorithm is carried out;Design module and generation algorithm based on Word2Vec model, attribute-based encryption algorithm based on ciphertext search;Efficient and accurate search is thus realized;Dynamic updating operation to user authority is realized, a high-efficiency and safe DWC-SW scheme is realized.
Owner:SHENZHEN TECH UNIV

Yes and no secret sharing with hidden access structures

A secret sharing scheme with yes and no shares and having a hidden access structure. The secret sharing scheme may include share generation in which yes shares and no shares are generated for, and distributed to, each party in the secret sharing scheme. In turn, upon an attempt to reconstruct the secret, participants in the reconstruction each provide a share, which is unknown to be a yes share or a no share to the other participants. The secret is only reconstructable if the shares used in the reconstruction include yes shares of a minimal authorized subset of the parties. However, prior to secret reconstruction, the access structure remains hidden and the participants in a reconstruction are unaware of the character of the shares provided by other participants in the reconstruction attempt.
Owner:SEAGATE TECH LLC

Cross-carrier visual cryptography method, device and equipment based on XOR and OR operation

The embodiment of the invention discloses a cross-carrier visual cryptography method, device and equipment based on XOR and OR operation. A specific embodiment of the method comprises: according to a recovery threshold, a total number of participating ends and a participating end set, determining a participating end set group, the participating end set group comprising each participating end set, the participating end set having participating ends allocated with state tags; generating a division layer number and an access structure set according to the participating terminal set group; performing image sharing on the secret image according to the division layer number and the access structure set so as to generate each shared image; and sending the generated shared image to each participant in the participant set. According to the embodiment, the image recovery quality and security of a visual password scheme can be improved.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Multi-client intersection function encryption method with non-monotonic access control structure, storage medium and device

The application discloses a multi-client intersection function encryption method with a non-monotonic access control structure, a storage medium and equipment, wherein a user key is embedded in a non-monotonic access structure, and multiple clients are independently encrypted without interaction, and decryption is successful only when and if attributes in ciphertext meet an access strategy in a private key; wherein, an authorized user only obtains an intersection of any two set elements and cannot obtain any information other than this. The method is safe and reliable and more conforms to actual demands.
Owner:SOUTHEAST UNIV

Efficient multi-user cooperative access control method supporting specified user access in cloud environment

The invention discloses a high-efficiency multi-user cooperative access control method for supporting specified user access in a cloud environment, and belongs to the field of information processing. The cloud server and the user use the system public parameters to generate identity public and private keys, and the cloud server generates the system public parameters and an authorization list; the trusted center generates an outsourcing decryption key for the user; the data owner generates preparation information, selects one access structure to encrypt a plurality of data segments, generates an extended key for a specified user, and generates and uploads a ciphertext to the cloud server; the data user applies for accessing the cloud data, and if the data user is a specified user meeting an access structure, the cloud server performs data decryption for the user who accesses the cloud data for the first time, performs data collaborative decryption for the user who accesses the cloud data again in the later period, and generates and returns an outsourcing decryption ciphertext; the data user receives the outsourcing decryption ciphertext, and local final decryption is completed; according to the invention, the confidentiality and controllability of data are ensured; and the calculation and communication overhead is relatively low.
Owner:XIDIAN UNIV

An attribute-based dual access control data sharing method for internet of vehicles

The application discloses a kind of attribute-based Internet of Vehicles dual access control data sharing methods, user generates attribute key, and proxy key is generated using attribute key;Data owner is encrypted to data using attribute-based encryption algorithm according to defined semi-hidden access structure, considering the limited computing capacity of vehicle end, and the encryption process is divided into offline and online two stages;Cloud server filters out the false information sent by malicious user;(Access control is carried out to the download request sent by the user who wants to access data, so as to refuse EDOS attack;Only the user who satisfies access policy can decrypt ciphertext, and the decryption stage is also divided into two stages of outsourcing decryption and user decryption;Malicious user is revoked, and after malicious user is revoked, only the ciphertext related to revocation list needs to be updated, without updating the entire ciphertext.The application can realize the safe data sharing in Internet of Vehicles, and promotes the wide application of vehicle network.
Owner:ANHUI UNIV

Dynamic hierarchical data access control method based on resumable puncture encryption

The present invention discloses a dynamic hierarchical data access control method based on recoverable puncture encryption, wherein the user key consists of an attribute key and a puncture key; the hierarchical user revokes the access rights of some of its subordinate data according to needs; the hierarchical user restores the previously revoked data access rights of some of its subordinate data when necessary; the edge node updates the attribute conversion key stored therein using key update material; the data owner encrypts the data using puncture attribute-based encryption according to the defined access structure and data tag set; after the malicious user is revoked, the third-party cloud server is responsible for publicly updating the ciphertext; the edge node of the Internet of Things uses the conversion key to partially decrypt the ciphertext; the user can only access the ciphertext whose attributes meet the ciphertext access structure and does not contain the punctured key tag; the malicious user is revoked in the user revocation stage, and the key of the non-revoked user is updated; the present invention can realize fine-grained hierarchical dynamic access control, and provides a feasible method for dynamic permission control between hierarchical organizational levels.
Owner:ANHUI UNIV

A method for encrypting fine-grained predicate functions with convertible property in access structure

ActiveCN117278206BProgramming languageAccess structure
The application discloses a fine-grained predicate function encryption method with convertible property on access structure, and is characterized in that the steps include giving the definition of general access structure based on set theory, defining the matching operation of access structure vector and attribute set vector, designing predicate access control function, constructing a fine-grained access control predicate function encryption model with authority based on the proposed predicate access control function, and constructing a fine-grained predicate function encryption model with convertible property on access structure. The application can complete the conversion and unification between ciphertext policy predicate encryption and key policy predicate encryption according to actual application scenes, and can hide the attribute values of participants by using predicate coding, so that the privacy of users is protected, and the application can be more safely applied to complex and changeable cloud environments.
Owner:GUIZHOU UNIV

A cloud attribute-based multi-party privacy set intersection method and system

This invention provides a method and system for finding the intersection of multiple privacy datasets based on attribute bases in the cloud, relating to the field of information security technology. The method includes: each data owner generating ciphertext based on public parameters, access structure, and their own privacy datasets, and sending the ciphertext to a cloud server; the access structure is represented by a linear secret sharing scheme; the cloud server generating an aggregation token and a cryptographic Bloom filter based on the public parameters, request token, and ciphertext, and sending the aggregation token and cryptographic Bloom filter to the data user; and the data user determining the intersection based on the public parameters, aggregation token, and cryptographic Bloom filter. Embedding the access structure into the ciphertext set using a linear secret sharing scheme provides high flexibility; it can find the intersection of the privacy datasets of multiple data owners and data users, making it suitable for multi-party intersection scenarios; and generating the aggregation token and cryptographic Bloom filter through the cloud server improves the efficiency of finding the intersection of multiple parties.
Owner:XIDIAN UNIV

Attribute inner product function encryption method based on access structure

The invention relates to the technical field of information security and cryptography, in particular to an attribute inner product function encryption method based on an access structure. The method comprises the following steps: executing system initialization by a central authorization mechanism, and generating a public key and a master key; generating a user key based on the master key, the user attribute set and the function vector; the data owner uses the public key to encrypt the message vector according to the access structure to generate a ciphertext; and the data user decrypts the ciphertext by using the own key, and successfully outputs the inner product value of the message vector and the function vector when and only when the attribute set of the data user meets the access structure. According to the method, the access control capability of attribute-based encryption and the ciphertext calculation capability of function encryption are combined, controlled inner product operation on ciphertext data under a complex access strategy is realized, only a final inner product result is output, original data are not leaked, the security and privacy in the data sharing and calculation process are effectively improved, and the method is suitable for being applied to the field of data sharing and calculation. And the method has the capability of resisting cross-index replay and key string collusion attacks.
Owner:GUIZHOU UNIV

Network security detection method and system based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security detection method and system based on artificial intelligence, and the method comprises the steps: collecting multi-source security data in a target network environment, carrying out the entity analysis and relation matching, generating the interaction relation data among an identity entity, a service entity and a resource entity, and transmitting the interaction relation data to a server; constructing an association graph and a continuous graph structure snapshot sequence; performing incremental calculation on adjacent time window graph structures to form an access structure extension sub-graph corresponding to the identity node; establishing a legal extension mode set based on historical normal operation samples, performing structure matching on the current access structure extension sub-graphs, and screening abnormal structure sub-graphs; and mapping the abnormal structure sub-graph into an attack stage label, constructing a stage directed path graph, and judging whether an attack closed structure is formed or not through reachable path detection, so as to realize the recognition and alarm of progressive authority extension and transverse movement behaviors.
Owner:若昊新程(北京)科技有限公司

Attribute-aware dynamic encryption access control method

The invention relates to an attribute-aware dynamic encryption access control method, and belongs to the technical field of communication security. According to the technical scheme, the method comprises the steps that a multi-channel social attribute tensor is constructed by collecting a static social relation, a dynamic behavior relation, a bidirectional interaction relation and a deep social relation of a user, and a social attribute vector is obtained through vector embedding; a linear secret sharing structure access matrix is generated based on the vector, an access strategy is adjusted in real time according to a behavior deviation score and a neighborhood consistency index, a ring learning error lattice password is adopted to generate a user private key bound with a social state, and attribute-based encryption is performed according to an access structure to generate a ciphertext; during decryption, verifying social attribute satisfaction and then recovering a plaintext, and realizing verifiable revocation and social state tracking by using a Merkle tree and a fingerprint chain; according to the invention, the dynamic adaptability and security of access control can be obviously improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Privacy protection attribute-based security access control method and system, and storage medium

The embodiment of the invention provides a privacy protection attribute-based security access control method and system and a storage medium, and belongs to the technical field of data protection. The method comprises the following steps: a data owning end obtains an institution public key for encrypting a target plaintext from a cloud server, and determines an attribute mapping ciphertext and an access structure according to an attribute privacy sub-public key in the institution public key; and according to the first mechanism sub-public key, the second mechanism sub-public key and the access structure in the mechanism public key, determining a target ciphertext and sending the target ciphertext to the cloud server. The cloud server side performs semi-decryption on the target ciphertext and sends the target ciphertext to the data use side based on a stored first user token, a user end attribute key containing the target attribute token and a second user token in an access request initiated by the data use side; the user end attribute key is generated by the cloud server side based on a user original attribute key, a user public key and a first user token of the mechanism side; according to the embodiment of the invention, the privacy and security of data access can be improved at the same time.
Owner:DONGGUAN POLYTECHNIC

A sharing and circulation method and mechanism based on hydropower data elements

The present invention discloses a method and mechanism for sharing and circulating hydropower data elements. The method comprises: Step 1, parameter setting; Step 2, user authorization: a key management server authorizes each system participant through key distribution and records relevant information on a blockchain platform; Step 3, data transfer authorization: a data user generates a proxy file, sets an access structure, and sends a portion of the proxy signature key component to another user; Step 4, encrypted upload of hydropower data elements: the hydropower data owner encrypts the hydropower data file, generates a ciphertext index, uploads it to the blockchain platform, and stores it on the hydropower data cloud platform; Step 5, trapdoor generation; Step 6, data search and access; Step 7, verification and decryption; and Step 8, compliance review and user rights deprivation. The mechanism comprises: hydropower data resourceization; hydropower data componentization; and hydropower data productization. The present invention enables the sharing and circulation of hydropower data in a secure, efficient, and compliant manner.
Owner:GUODIAN DADU RIVER POWER ENG

Blockchain-based regulation and governance method, system and apparatus based on group attribute-based encryption

PCT designated stageWO2025241256A1Securing communicationAccess structureSmart contract
Disclosed in the present invention are a blockchain-based regulation and governance method, system and apparatus based on group attribute-based encryption. The method comprises: generating a regulation and governance group public key, generating private keys of objects under regulation, and forming a regulation key for a regulator; on the basis of a smart contract, selecting whether to configure an access structure for the related information, and uploading the related information to a blockchain; selecting an object under regulation and performing attribute encryption on the related information to generate an attribute key, and allowing access when the regulation key, the attribute key and the access structure are kept consistent; verifying the object under regulation by the regulator and verifying the related information on the blockchain, and performing tracking to obtain a tracking result; on the basis of the tracking result, setting a regulation mark for the object under regulation by the regulator, and uploading the tracking result to the blockchain; and checking the tracking result on the basis of the regulation and governance group public key, and performing a next governance operation on the basis of the regulation mark. The present invention achieves effective regulation on ecological security by regulators.
Owner:HANGZHOU YUNXIANG NETWORK TECH

Resource access control system and method

PendingCN121508959ASecuring communicationAccess structureCiphertext
The invention belongs to the technical field of data processing, and discloses a resource access control system and method. Authority management based on user attributes is realized through the constructed access structure tree, the public parameter, the original pull stream address and the access structure tree are input into the encryption algorithm, then the public parameter, the private key and the encrypted ciphertext are input into the decryption algorithm through the pull stream user side, and the authentication pull stream address is generated based on the decryption result. And the stream is pulled through the streaming media server based on the authentication stream pulling address, so that the access levels of the users with different attributes can be distinguished in the stream pulling process, and a refined authority management effect is achieved.
Owner:BEIJING QIANHAI YANXIANG ELECTRONIC TECHNOLOGY CO LTD

Controllable threshold proxy re-encryption method and system

The invention relates to the technical field of cryptology, and discloses a controllable threshold proxy re-encryption method, in the controllable threshold proxy re-encryption method, n proxy parties participate, a (t, n)-threshold access structure of the n proxy parties is specified, a proxy key fragment is generated according to the threshold, and the proxy key fragment is sent to the proxy key. On the basis that the agent performs pre-authorization on the ciphertext, as long as the agent meeting the access structure participates in re-encryption conversion, agent re-encryption can be completed. According to the method, proxy re-encryption of the threshold access structure can be realized, the situation that a single proxy is offline or untrusted in a traditional proxy re-encryption scheme is effectively avoided, the availability of the system is increased, and the robustness of the system is improved. The method has the advantages of correctness, unidirectivity, non-interactivity, non-linkability and safety.
Owner:SHANGHAI JIAOTONG UNIV

A hierarchical access control system for incubator enterprise files and a method for adjusting permissions.

This invention discloses a hierarchical access control system and permission adjustment method for enterprise archives in incubators, relating to the fields of archive information security and access control technology. It addresses the risks of exporting or retrying amplification and unauthorized access caused by cross-version policy fluctuations in enterprise archives within incubator scenarios. The system solidifies enterprise identifiers in enterprise archives, extracts sensitive elements based on archive metadata and text according to rules, and assigns weighted scores to generate archive security levels and upper limits for permission levels. It combines user enterprise affiliation, roles, and attribute sets to generate deterministic access control policies and form an equivalent encrypted access structure. Symmetric encryption is used to protect the text, and attribute-based encryption is used to encapsulate the data key. Upon requesting access, authentication is performed according to the policy. Then, within the same processing cycle, a request window is constructed to calculate process variables such as export aggregation, version jumps, and retry amplification, dynamically downgrading or rejecting the operation. Simultaneously, auditing is recorded, and chain-based summaries are used to prevent tampering and traceability.
Owner:QIFAN (SHENZHEN) TECHNOLOGY CO LTD