Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

48 results about "Access structure" patented technology

Access structures are used in the study of security system where multiple parties need to work together to obtain a resource. Groups of parties that are granted access are called qualified. In set theoretic terms they are referred to as qualified sets. In turn, the set of all such qualified sets is called the access structure of the system. Less formally it is a description of who needs to cooperate with whom in order to access the resource. In its original use in cryptography, the resource was a secret shared among the participants. Only subgroups of participants contained in the access structure, are able to join their shares to recompute the secret. More generally, the resource can also be a task that a group of people can complete together, such as creating a digital signature, or decrypting an encrypted message.

Revocable attribute-based encryption method with strategy hiding

The invention discloses a revocable attribute-based encryption method with strategy hiding, which is based on ciphertext strategy attribute encryption, solves the problem that user privacy is leaked due to disclosure of an access strategy, realizes revocation of fine-grained user attribute access authority, and is proved to be completely safe. In a system establishment stage, system parameters are disclosed, a public key and a master key are generated, an authoritative authority authorizes a data user, distributes a private key and generates an AGK tree and an attribute group key, a data owner generates a ciphertext according to the public key, an access structure set by the data owner and a selected secret value, and the ciphertext is transmitted to the data owner. And then hiding the mapping function by using a cuckoo filter, positioning the attribute by a data user through the cuckoo filter, updating a private key by using an attribute group key, and finally decrypting the ciphertext to obtain the wanted information.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Decentralized identity management method based on trusted execution environment

PendingCN121098518AUser identity/authority verificationAccess structureComputer network
The invention discloses a decentralized identity management method based on a trusted execution environment, and the method comprises the steps: generating, isolating and storing a user decentralized identity in the trusted execution environment of equipment, carrying out the Hash signature of a decentralized identity document, and recording an uplink; the block chain consensus node verifies the decentralized document uplink transaction through a Byzantine fault-tolerant consensus mechanism and achieves consistency, and writes the metadata of the decentralized identity into the block; encrypting and storing the voucher in a trusted execution environment of the equipment by adopting a Pearson commitment, and supporting voucher Hash uplink and commitment uplink; and introducing a multilevel access structure based on a binary tree, and verifying the and / or logic combination voucher by adopting a depth-first search algorithm. According to the method, decentralized autonomy of the user identity and hardware security isolation are supported, and the reliability and privacy protection capability of user identity management are improved.
Owner:SOUTHEAST UNIV

Lattice-based lightweight ciphertext strategy attribute-based encryption method

The invention discloses a lattice-based lightweight ciphertext policy attribute-based encryption method, and belongs to the technical field of access control based on cryptography. According to the method, grid trap door generation is replaced by a grid public and private key pair strategy, discrete Gaussian distribution is replaced by sampling center binomial distribution, and fast number theory transformation is used on an integer polynomial ring, so that the storage overhead and the calculation overhead of the whole scheme are reduced. According to the lattice-based lightweight ciphertext policy attribute-based encryption method, one-to-many data security sharing in a cloud environment is realized, and a public and private key pair policy encrypted by a public key on a lattice is combined with a linear secret sharing access structure, so that fine-grained access control on encrypted data is realized; and the time complexity and the space complexity of the algorithm are effectively reduced. In addition, the method also meets the characteristics of resisting quantum attacks and collusion attacks.
Owner:JIANGSU UNIV

Attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations

InactiveCN120956419AKey distribution for secure communicationAccess structureEngineering
The invention discloses an attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations, which is characterized in that a certificate issuing mechanism is responsible for initialization of a system and registration of an attribute issuing mechanism and a user, and the attribute issuing mechanism manages part of attributes authorized by the attribute issuing mechanism and generates a conversion key of an agency for outsourcing decryption; the data owner encrypts the data by using attribute-based encryption according to the defined access structure and the label structure; and the proxy server converts the access strategy formulated by the data owner into a puncture strategy and then punctures the conversion key so as to cancel the specified user group. According to the method, puncture revocation and outsourcing decryption attribute-based access control under a multi-authorization mechanism can be realized, and a feasible method is provided for lightweight and fine-grained user revocation under the multi-authorization mechanism.
Owner:NANJING UNIV OF POSTS & TELECOMM

Privacy protection method for alliance chain agricultural product supply chain traceability

The invention relates to a privacy protection method for alliance chain agricultural product supply chain traceability, and belongs to the technical field of information security. The method comprises the following steps: a registration stage: a supply chain entity participating in traceability registers by using own identity information, and a key management center generates a pseudonym by using the identity information and sends the pseudonym to the supply chain entity; an access structure defining stage: the supply chain entity sends an attribute set of the traceability information to a key management center, the key management center generates a private attribute key and a dynamic pseudonym for the supply chain entity, and the supply chain entity defines a decryption access structure according to the private attribute key; a data encryption stage: the supply chain entity encrypts data by using the private attribute key, and sends an encryption result and a dynamic pseudonym to a supervision department; in the data decryption stage, the supervision department decrypts and audits the received data, and the supply chain entity links the encrypted traceability information; and the supply chain entity with the traceability demand checks the traceability information of the agricultural products in the supply chain by decrypting the data on the chain.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

A method and apparatus for constructing an LSSS access structure that supports collaborative decryption.

ActiveCN120281580BSecuring communicationAccess structureAlgorithm
This invention provides a method and apparatus for constructing an LSSS access structure that supports collaborative decryption. The method includes: constructing an LSSS access structure according to a collaborative access strategy, wherein an access matrix M in the LSSS access structure is used to determine a first column vector λ, and the first column vector λ includes a second column vector λ. s ; and the sub-access matrix M used to construct the sub-strategy sub Determine the sub-access matrix M sub The corresponding third column vector λ sub The second column vector λ s Equal to the third column vector λ sub The first column vector λ and the third column vector λ sub Used for encryption; Sub-access matrix M sub and the third column vector λ sub Used for decryption. In this embodiment of the invention, the second column vector λ is used... s Equal to the third column vector λ sub Thus, for the third column vector λ sub The relevant calculation results can be used in the relevant calculations for the first column vector λ, saving computational overhead and thus improving encryption and decryption efficiency.
Owner:THREE GORGES GROUP IND DEVELOPMENT (BEIJING) CO LTD +1

Decentralized multi-authority attribute-based encryption from bilinear diffie-hellman assumptions

ActiveUS12375286B2Key distribution for secure communicationUser identity/authority verificationAccess structureAttribute-based encryption
The invention relates to systems, methods, network devices, and machine-readable media for encrypting and decrypting messages in a decentralized multi-authority attribute-based encryption (MA-ABE) scheme for access structures described by monotone LSSS under the decisional bilinear Diffie-Hellman assumptions. The construction can also be modified to obtain an MA-ABE scheme under computational bilinear Diffie-Hellman assumptions.
Owner:NTT RESEARCH INC

A blockchain-based distributed data encryption sharing method

PendingCN122119943ASecuring communicationAccess structureCiphertext
The application discloses a kind of distributed data encryption sharing methods based on block chain, and using block chain realizes the traceable management of search and authorization process.The scheme is first by multi-authorization center to carry out distributed management to attribute domain, and generates attribute key associated with identity for user;In access verification link, construct parameter masking mechanism based on bilinear pairing, so that user attribute private key is not directly exposed in block chain verification and query process.Secondly, data owner carries out layered encryption to shared data and session key, and constructs the improved multi-key search structure, index and ciphertext positioning information are recorded to block chain, to support fast positioning target ciphertext.In addition, the application uses linear secret sharing to set access structure, and designs subset determination mechanism of general attribute name set, binds the download permission of ciphertext with the attribute condition that user can satisfy, to prevent overreach download behavior.Finally, with the help of cloud, outsourcing decryption is executed to generate intermediate result, and terminal only needs to complete light recovery and decryption.The application can give consideration to fine-grained control, high-performance search access and terminal side low load, and is suitable for secure data encryption sharing in resource-limited scene.
Owner:SOUTHEAST UNIV

A method for constructing a minimal linear code, a secret sharing method and a secret sharing system

PendingCN122268585AKey distribution for secure communicationAccess structureDual code
The present application belongs to the technical field of information security and coding theory, and provides a minimal linear code construction method, a secret sharing method and a secret sharing system, comprising: first defining a trace function in a finite field, constructing a two-to-one mapping, a vector Boolean function with a finite discrete value of Walsh spectrum, and then defining a code word set based on the function, embedding the output of the trace function into a linear code generation expression to generate a minimal linear code with a weight set and a support without strict inclusion; then using the dual code to establish a one-to-one correspondence between the participants and the dual code coordinates, the minimal code word support and the minimum access structure, embed the secret generation share distribution, and the participants meeting the conditions restore the secret through linear combination. The system contains four functional modules, which are suitable for distributed storage, blockchain key management and other scenes, and realize safe, efficient and expandable secret sharing. The present application can improve the security, efficiency and flexibility of secret sharing, and is suitable for multiple scenes and easy to expand.
Owner:XI'AN UNIVERSITY OF ARCHITECTURE AND TECHNOLOGY

A method for supporting time-constrained data security controllable flow in a cloud-edge environment

ActiveCN121907585BImplement fine-grained write control functionsDouble constraints on encryption permissionsPlaintextCiphertext
This invention discloses a time-constrained, secure, and controllable data flow method in a cloud-edge environment, belonging to the field of mobile edge cloud computing. Specifically, it involves: First, establishing a communication scenario including an authorizing agency for both the sender and receiver, the sender, edge nodes, a cloud server, and the receiver. Given security parameters, the authorized agency for the receiver runs a global initialization algorithm, outputting public parameters and domain public / private keys. Then, the authorized agency for the sender inputs the public parameters and domain public key, outputting its own domain public / private key. For each sender, an access structure and a valid time interval are assigned, and an encryption key is generated. For each receiver, an attribute set is assigned, and a decryption key is generated. Finally, the sender runs the encryption algorithm and outputs the original ciphertext; the edge node verifies the sender's sending authority and outputs the cleaned ciphertext; and the legitimate receiver decrypts and outputs the plaintext. This invention meets the requirements for secure and controllable data flow in a cloud-edge environment.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Homomorphic secret sharing method

The invention discloses a homomorphic secret sharing method, which adopts a Shamir threshold secret sharing scheme, and can provide threshold security for the homomorphic secret sharing method, so that a server set or an access structure which does not meet a certain condition cannot recover a specific secret value from a given secret share; meanwhile, a Shamir threshold secret sharing scheme is combined with a homomorphic encryption algorithm, so that the degree of a polynomial of the homomorphic secret sharing scheme can be improved; a homomorphic encryption algorithm is adopted to perform encryption calculation on secret input, so that after the secret input is calculated by an unauthorized server, a calculation result can be decrypted by an output server to obtain a function value of the secret input under a given function.
Owner:GANSU ELECTRIC POWER INFORMATION COMM

A lightweight attribute-based encryption method based on OBDD access structure

This invention discloses a lightweight attribute-based encryption method based on the OBDD access structure. From the perspective of encryption and decryption efficiency, this method splits the encryption stage into an offline stage and an online stage. In the offline stage, paired master and slave ciphertext module pools are computed offline, improving the encryption efficiency of the online stage. The decryption stage is split into outsourced decryption and local decryption. Before outsourced decryption, the decryptor generates an auxiliary key and provides it to the decryption agent, ensuring that the agent cannot know the plaintext while transferring most of the computational work to the agent, thereby reducing the computational burden on the decryptor. This invention improves upon existing attribute-based encryption algorithms based on the OBDD access structure, enabling data terminals to obtain the final result with low-complexity computation when encrypting or decrypting data.
Owner:SOUTHEAST UNIV

Interactive attribute-based encryption and decryption method and system

The present application belongs to the field of encryption and decryption technology, and provides an interactive attribute-based encryption and decryption method and system, including: an attribute authorization agency AA executes an initialization algorithm to generate system public parameters, a master key and an attribute-based encrypted access structure; for each attribute, the attribute authorization agency generates an attribute-independent key component and an attribute-related key component based on the master key and the access structure; the data owner uses the system public parameters and the access structure to encrypt data and generate ciphertext; the data owner publishes the ciphertext and the access structure to the blockchain network; the authorized user obtains the ciphertext and the access structure from the blockchain network, executes the interactive attribute-based decryption algorithm, generates an intermediate key, and sends an interactive decryption task containing the intermediate key to the service provider; the authorized user receives the decryption result fed back by the service provider, thereby significantly reducing the computational burden of the lightweight device during the decryption process.
Owner:BEIJING GUODU INTERNET TECH CO LTD

A linear method for key sharing among five participants

The present invention provides a linear key sharing method for five participants, comprising the following steps: Step 1: Based on the access structure, query the corresponding linear capacity domain; Step 2: Establish a corresponding integer programming model based on the polar direction vector of the linear capacity domain and the input subkey size vector, and determine the combination coefficients used in the final method based on the feasible solution of the integer programming; Step 3: Based on the optimal solution of the integer programming, combine the methods corresponding to the polar direction vectors, and the combined method becomes the final linear key sharing method. The method of the present invention is applicable to any access structure and any integer subkey size vector for the five participants, and can obtain a relatively optimal master key size.
Owner:SOUTHEAST UNIV

A Blockchain-Based Hierarchical Sharing Method for Medical Data

ActiveCN119760734BLayered access control implementationlow costDatabase distribution/replicationDigital data protectionAccess structureCiphertext
This invention discloses a blockchain-based hierarchical sharing method for medical data. This method encrypts files with monotonic access structures according to different levels of sensitivity. The secret value is passed upwards through a secret value sharing mechanism, transferring the secret value of the low-sensitivity ciphertext to the high-sensitivity ciphertext. During the data decryption stage, a rapid comparison is performed to find the file with the highest sensitivity that the user can satisfy, and a pre-decryption is performed. This makes it easier to decrypt sensitive files in the file set, improving access control and effectively reducing the number of decryption steps in the medical data sharing process. This truly achieves multi-level attribute data sharing while ensuring privacy and security.
Owner:ANHUI NORMAL UNIV

Vehicle-mounted CAN bus safety communication method based on attribute grouping

The invention discloses a vehicle-mounted CAN (Controller Area Network) bus safety communication method based on attribute grouping. The method comprises the following steps: firstly, selecting a master key, a public key, a hash function and related parameters; the electronic control unit ECU registers with a gateway electronic control unit GECU; in the key generation stage, the GECU groups the ECUs and distributes key generation parameters to the ECUs in the groups, and the ECUs in the groups calculate group keys according to the key generation parameters; the ECUs in the group communicate with each other by using the group key; and in the key updating and ECU re-joining stage, the ECU can update the key without interaction. Through constructing a group key generation mechanism based on an access structure tree, group communication based on ECU function attributes is realized. And a key self-authentication mechanism is introduced, so that the interaction turns between the ECUs are reduced, and the communication load is reduced. The method is suitable for a vehicle-mounted network dynamic scene, and effectively resists attacks such as counterfeiting and replaying.
Owner:ANHUI UNIV

A ciphertext retrieval system, method, computer device and storage medium

The present application relates to a kind of ciphertext search system, method, computer equipment and storage medium, it is related to the field of encryption technology, the system is by data owner, data user, authority authentication center and cloud server 4 parts are made up of, also include access control module, index generation module and CP-ABE encryption module, access control module is used to improve access structure based on attribute-based encryption, and the weight strategy tree of weight strategy based on attribute-based encryption is designed.The present application ensures the security and reliability of cloud environment, with reliable, efficient, flexible searchable encryption performance of characteristic, weight strategy based on attribute-based encryption is improved design, corresponding algorithm is carried out;Design module and generation algorithm based on Word2Vec model, attribute-based encryption algorithm based on ciphertext search;Efficient and accurate search is thus realized;Dynamic updating operation to user authority is realized, a high-efficiency and safe DWC-SW scheme is realized.
Owner:SHENZHEN TECH UNIV

Yes and no secret sharing with hidden access structures

A secret sharing scheme with yes and no shares and having a hidden access structure. The secret sharing scheme may include share generation in which yes shares and no shares are generated for, and distributed to, each party in the secret sharing scheme. In turn, upon an attempt to reconstruct the secret, participants in the reconstruction each provide a share, which is unknown to be a yes share or a no share to the other participants. The secret is only reconstructable if the shares used in the reconstruction include yes shares of a minimal authorized subset of the parties. However, prior to secret reconstruction, the access structure remains hidden and the participants in a reconstruction are unaware of the character of the shares provided by other participants in the reconstruction attempt.
Owner:SEAGATE TECH LLC

Encoding and decoding method for distributed multi-user key sharing problem under strong privacy conditions

The present invention provides an encoding and decoding method for the distributed multi - user key sharing problem under strong privacy conditions. The method includes the following steps: Step 1: Initialize an N×(∑ k∈[K] R k +N) generating matrix V according to the access structure and the key information rate array; Step 2: Obtain the corresponding K(K - 1) row index sets according to the access structure and the key information rate array, and extract K sub - matrices from the generating matrix V by these sets. The strong privacy condition is equivalent to the full rank of each sub - matrix; Step 3: Calculate the determinants according to each sub - matrix, multiply them to obtain a polynomial, find a set of feasible solutions that make the polynomial not equal to 0, then set the remaining variables in the generating matrix V to 0, then extract the decoding method from the generating matrix V, and finally perform Gaussian elimination on the generating matrix V to obtain the encoding method. The method of the present invention can be applied to any access structure and can achieve the optimal key information rate.
Owner:SOUTHEAST UNIV

Cross-carrier visual cryptography method, device and equipment based on XOR and OR operation

The embodiment of the invention discloses a cross-carrier visual cryptography method, device and equipment based on XOR and OR operation. A specific embodiment of the method comprises: according to a recovery threshold, a total number of participating ends and a participating end set, determining a participating end set group, the participating end set group comprising each participating end set, the participating end set having participating ends allocated with state tags; generating a division layer number and an access structure set according to the participating terminal set group; performing image sharing on the secret image according to the division layer number and the access structure set so as to generate each shared image; and sending the generated shared image to each participant in the participant set. According to the embodiment, the image recovery quality and security of a visual password scheme can be improved.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Multi-client intersection function encryption method with non-monotonic access control structure, storage medium and device

The application discloses a multi-client intersection function encryption method with a non-monotonic access control structure, a storage medium and equipment, wherein a user key is embedded in a non-monotonic access structure, and multiple clients are independently encrypted without interaction, and decryption is successful only when and if attributes in ciphertext meet an access strategy in a private key; wherein, an authorized user only obtains an intersection of any two set elements and cannot obtain any information other than this. The method is safe and reliable and more conforms to actual demands.
Owner:SOUTHEAST UNIV

Lattice-based Additive Homomorphic Threshold Decryption Method

ActiveCN116846538BCommunication with homomorphic encryptionAccess structureCiphertext
The present invention discloses a lattice-based additive homomorphic threshold decryption method, which determines the organizations that need collaborative decryption and the members within each organization, and sets a threshold for collaborative decryption for each organization; the system is initialized to generate public parameters, a master public key, and a master private key. When generating the master private key, a polynomial is defined for each organization; for the members of each organization, user public keys and user private keys are generated according to the corresponding polynomial; the system encrypts the message, and when a member wants to decrypt the ciphertext, each organization must invite at least members exceeding the organization's threshold to form a decryption set to participate in the decryption, and the system will verify and collaboratively decrypt after the collaborative information is calculated. The present invention is more suitable for scenarios that require flexible access structures, such as banks, FL, etc. At the same time, compared with other lattice-based solutions, the present invention has higher computational efficiency, and compared with other solutions based on traditional problems, our invention can resist quantum attacks.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Efficient multi-user cooperative access control method supporting specified user access in cloud environment

The invention discloses a high-efficiency multi-user cooperative access control method for supporting specified user access in a cloud environment, and belongs to the field of information processing. The cloud server and the user use the system public parameters to generate identity public and private keys, and the cloud server generates the system public parameters and an authorization list; the trusted center generates an outsourcing decryption key for the user; the data owner generates preparation information, selects one access structure to encrypt a plurality of data segments, generates an extended key for a specified user, and generates and uploads a ciphertext to the cloud server; the data user applies for accessing the cloud data, and if the data user is a specified user meeting an access structure, the cloud server performs data decryption for the user who accesses the cloud data for the first time, performs data collaborative decryption for the user who accesses the cloud data again in the later period, and generates and returns an outsourcing decryption ciphertext; the data user receives the outsourcing decryption ciphertext, and local final decryption is completed; according to the invention, the confidentiality and controllability of data are ensured; and the calculation and communication overhead is relatively low.
Owner:XIDIAN UNIV

An attribute-based dual access control data sharing method for internet of vehicles

The application discloses a kind of attribute-based Internet of Vehicles dual access control data sharing methods, user generates attribute key, and proxy key is generated using attribute key;Data owner is encrypted to data using attribute-based encryption algorithm according to defined semi-hidden access structure, considering the limited computing capacity of vehicle end, and the encryption process is divided into offline and online two stages;Cloud server filters out the false information sent by malicious user;(Access control is carried out to the download request sent by the user who wants to access data, so as to refuse EDOS attack;Only the user who satisfies access policy can decrypt ciphertext, and the decryption stage is also divided into two stages of outsourcing decryption and user decryption;Malicious user is revoked, and after malicious user is revoked, only the ciphertext related to revocation list needs to be updated, without updating the entire ciphertext.The application can realize the safe data sharing in Internet of Vehicles, and promotes the wide application of vehicle network.
Owner:ANHUI UNIV

Dynamic hierarchical data access control method based on resumable puncture encryption

The present invention discloses a dynamic hierarchical data access control method based on recoverable puncture encryption, wherein the user key consists of an attribute key and a puncture key; the hierarchical user revokes the access rights of some of its subordinate data according to needs; the hierarchical user restores the previously revoked data access rights of some of its subordinate data when necessary; the edge node updates the attribute conversion key stored therein using key update material; the data owner encrypts the data using puncture attribute-based encryption according to the defined access structure and data tag set; after the malicious user is revoked, the third-party cloud server is responsible for publicly updating the ciphertext; the edge node of the Internet of Things uses the conversion key to partially decrypt the ciphertext; the user can only access the ciphertext whose attributes meet the ciphertext access structure and does not contain the punctured key tag; the malicious user is revoked in the user revocation stage, and the key of the non-revoked user is updated; the present invention can realize fine-grained hierarchical dynamic access control, and provides a feasible method for dynamic permission control between hierarchical organizational levels.
Owner:ANHUI UNIV

A method for encrypting fine-grained predicate functions with convertible property in access structure

ActiveCN117278206BProgramming languageAccess structure
The application discloses a fine-grained predicate function encryption method with convertible property on access structure, and is characterized in that the steps include giving the definition of general access structure based on set theory, defining the matching operation of access structure vector and attribute set vector, designing predicate access control function, constructing a fine-grained access control predicate function encryption model with authority based on the proposed predicate access control function, and constructing a fine-grained predicate function encryption model with convertible property on access structure. The application can complete the conversion and unification between ciphertext policy predicate encryption and key policy predicate encryption according to actual application scenes, and can hide the attribute values of participants by using predicate coding, so that the privacy of users is protected, and the application can be more safely applied to complex and changeable cloud environments.
Owner:GUIZHOU UNIV

A cloud attribute-based multi-party privacy set intersection method and system

This invention provides a method and system for finding the intersection of multiple privacy datasets based on attribute bases in the cloud, relating to the field of information security technology. The method includes: each data owner generating ciphertext based on public parameters, access structure, and their own privacy datasets, and sending the ciphertext to a cloud server; the access structure is represented by a linear secret sharing scheme; the cloud server generating an aggregation token and a cryptographic Bloom filter based on the public parameters, request token, and ciphertext, and sending the aggregation token and cryptographic Bloom filter to the data user; and the data user determining the intersection based on the public parameters, aggregation token, and cryptographic Bloom filter. Embedding the access structure into the ciphertext set using a linear secret sharing scheme provides high flexibility; it can find the intersection of the privacy datasets of multiple data owners and data users, making it suitable for multi-party intersection scenarios; and generating the aggregation token and cryptographic Bloom filter through the cloud server improves the efficiency of finding the intersection of multiple parties.
Owner:XIDIAN UNIV

Attribute inner product function encryption method based on access structure

The invention relates to the technical field of information security and cryptography, in particular to an attribute inner product function encryption method based on an access structure. The method comprises the following steps: executing system initialization by a central authorization mechanism, and generating a public key and a master key; generating a user key based on the master key, the user attribute set and the function vector; the data owner uses the public key to encrypt the message vector according to the access structure to generate a ciphertext; and the data user decrypts the ciphertext by using the own key, and successfully outputs the inner product value of the message vector and the function vector when and only when the attribute set of the data user meets the access structure. According to the method, the access control capability of attribute-based encryption and the ciphertext calculation capability of function encryption are combined, controlled inner product operation on ciphertext data under a complex access strategy is realized, only a final inner product result is output, original data are not leaked, the security and privacy in the data sharing and calculation process are effectively improved, and the method is suitable for being applied to the field of data sharing and calculation. And the method has the capability of resisting cross-index replay and key string collusion attacks.
Owner:GUIZHOU UNIV

Threshold secret sharing with hidden access structures

Cryptographic sharing of a cryptographic secret among multiple parties provides a share of the cryptographic secret is generated for each party. Multiple threshold access structure tokens are generated for each party of the multiple parties. The threshold access structure tokens are generated for a party from one or more random token polynomials selected from a finite field based on the numbers of the multiple parties capable of attempting to reconstruct the cryptographic secret. The share of the cryptographic secret and the multiple threshold access structure tokens generated for each party are distributed to the corresponding party. At least a threshold number of the parties can reconstruct the cryptographic secret using the shares of the cryptographic secret and threshold access structure tokens corresponding to at least a threshold number of the parties attempting to reconstruct the cryptographic secret while less than the threshold number of parties cannot reconstruct the cryptographic secret.
Owner:SEAGATE TECH LLC

Network security detection method and system based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security detection method and system based on artificial intelligence, and the method comprises the steps: collecting multi-source security data in a target network environment, carrying out the entity analysis and relation matching, generating the interaction relation data among an identity entity, a service entity and a resource entity, and transmitting the interaction relation data to a server; constructing an association graph and a continuous graph structure snapshot sequence; performing incremental calculation on adjacent time window graph structures to form an access structure extension sub-graph corresponding to the identity node; establishing a legal extension mode set based on historical normal operation samples, performing structure matching on the current access structure extension sub-graphs, and screening abnormal structure sub-graphs; and mapping the abnormal structure sub-graph into an attack stage label, constructing a stage directed path graph, and judging whether an attack closed structure is formed or not through reachable path detection, so as to realize the recognition and alarm of progressive authority extension and transverse movement behaviors.
Owner:若昊新程(北京)科技有限公司