Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

41 results about "Attribute authority" patented technology

An attribute authority (also known as an attribute store) is a directory or database in which systems can securely add, modify, and save attributes. An attribute authority is a trusted source of data for ABAC decisions. Data sources such as MySQL databases, LDAP directories, Active Directories, and Web services can be configured as...

On-cloud semi-homomorphic encryption method capable of resisting private key tracking

The invention discloses an on-cloud semi-homomorphic encryption method capable of resisting private key tracking, which comprises the following steps of: S1, generating a blind identity based on the real identity of a data user, and performing identity de-association processing; s2, the attribute authority generates a binding key pair based on the blind identity and returns the binding key pair; s3, the data user discloses a real identity and a public key to the data owner; s4, the data owner encrypts the plaintext after verifying the public key to form a ciphertext set; s5, uploading the ciphertext set to a cloud service provider, and performing classified storage; s6, the cloud service provider receives the analysis request and performs homomorphic addition aggregation on the ciphertext set to generate an aggregated ciphertext; and S7, the data user uses the private key to decrypt the aggregated ciphertext, and a plaintext analysis result is recovered. According to the method, the identity privacy of the user is protected while encrypted data analysis is realized, and the method has the characteristics of untraceability and lightweight deployment.
Owner:SHANXI TAIYIAN CRYPTOGRAPHIC TESTING CENTER CO LTD

Fine-grained access control system and method based on combination of CPK and attribute permission

The invention discloses a fine-grained access control system and method based on combination of CPK and attribute authority, a key generation management unit generates a public and private key pair corresponding to each attribute, and an attribute and strategy management unit defines a system attribute set and formulates an access control strategy. The user and authorization management unit distributes attribute information for a user and determines an access authority according to the attribute information, the data access and encryption unit combines a plurality of attribute public keys according to an access control strategy to form a combined public key, and the data decryption and verification unit verifies user authority attributes and combines private keys of corresponding attributes to form a combined private key; and the local resource and authority management unit stores and updates the attribute private key and authority information of the user side. Through matrix key generation, attribute public key combined encryption and private key combined decryption mechanisms, the problems of complex key management and low efficiency of a traditional ABE scheme are solved, dynamic attribute extension and a complex access strategy are supported, and the performance and expandability under large-scale user and attribute scenes are remarkably improved.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Intelligent lock access control method and system based on attributes

The invention relates to the technical field of intelligent locks, in particular to an attribute-based intelligent lock access control method and system.The method comprises the steps that main body attributes, object attributes, environment attributes and authority attributes are collected and stored, the main body attributes comprise unique identifiers, roles and positions of visitors, and the object attributes comprise device identifiers of intelligent locks; the environment attribute comprises access time, an access date and an access position, and the permission attribute comprises unlocking operation; establishing a corresponding relationship between attributes and permissions, and forming an attribute authorization list for checking in an access control execution stage; when an access request is received, the identity of a visitor is verified through an identity verification mechanism; analyzing the access request, and obtaining a subject attribute, an object attribute, an environment attribute and a requested operation; according to the attribute authorization list and a preset strategy set, whether the access request is authorized or not is judged, and the strategy set is stored in the intelligent lock; and executing or denying the access request according to a judgment result. The problems that an existing intelligent lock is poor in safety, complex in operation and insufficient in authority management dynamics can be solved.
Owner:SHENZHEN CSI YUNXING SMART IOT TECH CO LTD

Multi-authority attribute-based proxy signature method with flexible thresholds

The invention discloses a multi-authoritative attribute-based proxy signature method with a flexible threshold, and relates to the technical field of cyberspace security, the method comprises the following steps: constructing a multi-authoritative attribute-based proxy signature system with entities including a central attribute authority, a distributed attribute authority, an original signer, a proxy signer and a verifier, and establishing system parameters, carrying out system initialization; generating a secret key for an original signer and a secret key for a proxy signer through central attribute authority and distributed attribute authority respectively; the original signer generates a consignment and authorization to the proxy signer; after the proxy signer receives the authorization sent by the original signer, authorization verification is carried out; after the authorization verification is passed, the proxy signer calculates a proxy signature for the message according to the authorization sent by the original signer, and sends the message, the delegate and the proxy signature to the verifier; the verifier verifies the proxy signature based on the message and the delegate. The method is high in flexibility and adaptability.
Owner:ZHENGZHOU UNIVERSITY OF LIGHT INDUSTRY

Attribute-based encryption method and system supporting multi-authority responsibility-traceable and outsourcing calculation

The invention discloses an attribute-based encryption method and system based on support of multi-authority accountability and outsourcing calculation, and the method specifically comprises the steps: introducing a multi-attribute authority mechanism to be responsible for key distribution and management, reducing the dependence on a single mechanism, and improving the safety and reliability of the system; the cloud server locally updates the access strategy and the ciphertext according to the minimum change increment set uploaded by the data owner; a white-box tracking technology is adopted to bind a user identity with an attribute key, so that a system can locate a specific identity of a malicious user and a specific identity of a malicious attribute authority through a leaked key; intensive computing tasks in the encryption and decryption processes are outsourced to a cloud server, and meanwhile it is ensured that user privacy is not leaked in the outsourcing process; for the untrusted problem of the cloud server, the calculation result is verified by using the smart contract in the block chain, and it is ensured that the verification process is open and transparent and the result is trusted; and an attribute version mark is introduced, so that efficient revocation of old version attributes is realized, and the safety is further improved.
Owner:WUHAN UNIV

Blockchain-based verifiable key generation method in ma-cpabe

PendingCN122372200ASmart contractKey generation
This invention discloses a blockchain-based verifiable key generation method in MA-CPABE. The method includes: a data owner running a global setting algorithm to generate system parameters, and electing multiple decentralized attribute authorization nodes through a blockchain staking mechanism; each node generating public and private keys and uploading the public key to the blockchain; the data owner encrypting data based on a policy and publishing the ciphertext and its identifier to the blockchain; when a user requests a key, the attribute authorization node calls an optimized key generation circuit to generate a decryption key and a corresponding zero-knowledge proof, submitting the proof and related data to the blockchain, where a verification node verifies and records the key generation event; for the update history of the zero-knowledge proof, a chain-based evidence storage system is constructed through a smart contract event mechanism to achieve verifiable traceability of its change history. This invention achieves decentralized trusted key management, efficient off-chain computation and verifiability, and significantly reduced blockchain resource consumption.
Owner:YUNNAN UNIVERSITY OF FINANCE AND ECONOMICS +1

Interactive attribute-based encryption and decryption method and system

The present application belongs to the field of encryption and decryption technology, and provides an interactive attribute-based encryption and decryption method and system, including: an attribute authorization agency AA executes an initialization algorithm to generate system public parameters, a master key and an attribute-based encrypted access structure; for each attribute, the attribute authorization agency generates an attribute-independent key component and an attribute-related key component based on the master key and the access structure; the data owner uses the system public parameters and the access structure to encrypt data and generate ciphertext; the data owner publishes the ciphertext and the access structure to the blockchain network; the authorized user obtains the ciphertext and the access structure from the blockchain network, executes the interactive attribute-based decryption algorithm, generates an intermediate key, and sends an interactive decryption task containing the intermediate key to the service provider; the authorized user receives the decryption result fed back by the service provider, thereby significantly reducing the computational burden of the lightweight device during the decryption process.
Owner:BEIJING GUODU INTERNET TECH CO LTD

System architecture for secure highly available microservice applications with decentralized authorization using hybrid attribute authority tokens used for security enforcement in cloud platforms

A device includes one or more processors configured to receive, from a user device, an authentication request including credentials of a user. The one or more processors are also configured to obtain user attributes of the user from one or more user data records associated with one or more identity systems. The one or more processors are further configured to obtain one or more roles of the user based on one or more membership lists. The one or more processors are also configured to generate an authentication token indicating the user attributes and the one or more roles.
Owner:THE BOEING CO

A multi-authorized collaborative attribute and key management method with clear ownership based on RAFT consensus

The present invention relates to a multi-authorized party collaborative attribute and key management method with clear ownership based on RAFT consensus. During the system initialization phase, each attribute authorization agency (AA) registers and initializes its identity on the blockchain, and then generates and broadcasts a global attribute public key and constructs an attribute block through multi-party collaboration. During the user registration process, the data user (DU) submits an identity and attribute request to the system. After preliminary verification by the Leader AA, a consensus is reached among the AAs through the RAFT algorithm to ensure the consistency and security of the registration information. During the user attribute update phase, the user or organization needs to submit an attribute change request. The system processes and verifies the update request through the RAFT consensus mechanism to ensure the correctness and consistency of the attribute change. A new attribute key is generated after the update is confirmed and replaces the old key to ensure system security. The present invention utilizes the RAFT consensus algorithm to improve the system's fault tolerance and data consistency, and at the same time combines blockchain technology to enhance the security and immutability of the data.
Owner:FUJIAN NORMAL UNIV

A data security storage and access control method of attribute classification and grading

ActiveCN115964751BFile systemEngineering
A kind of attribute classification and grading data security storage and access control method includes a central authority CA, N attribute authorities AAs and X sub-authorities aas, user, agency administrator, product transaction traceability public blockchain, information security supervision alliance blockchain and interstellar file system IPFS.The present application stores massive unstructured data and encrypted information using IPFS, only stores the file addressing hash generated by IPFS on the blockchain, reduces the data storage pressure and security risk of the blockchain;A multi-agency ciphertext policy-based attribute encryption algorithm is constructed to meet the needs of privacy information protection and dynamic fine-grained access control of the system;The combination of multi-authority hierarchical authorization and central authority disperses the system overhead, making it easier to supervise;Accurate tracking of malicious users is achieved, and users and attributes can be revoked immediately without updating keys or ciphertexts.
Owner:JIANGXI UNIV OF SCI & TECH

Privacy security protection method based on multi-authority attribute encryption

The invention discloses a privacy security protection method based on multi-authority attribute encryption. The privacy security protection method specifically comprises the following steps: step 1, setting global parameters based on symmetric composite number order bilinear mapping; 2, setting a private key and a public key of an attribute authority k; 3, generating a secret key of an attribute in the access authority of the information receiver based on a threshold type access strategy; 4, encrypting the information sent by the information sender; and 5, when a certain information receiver needs to obtain the information sent by the information sender, the information receiver decrypts the ciphertext to obtain the related information. According to the encryption scheme provided by the invention, high-security decentration is realized on the basis of realizing efficient encryption and decryption.
Owner:NANJING UNIVERSITY OF AERONAUTICS & ASTRONAUTICS SHENZHEN RESEARCH INSTITUTE

Method for Implementing Fine-Grained Data Access and Sharing in 6G Networks Based on Fog Computing and Cloud Computing Environments

A method for implementing fine-grained data access sharing in 6G network based on fog computing and cloud computing environment includes: (1) a security parameter is given for initialization; (2) each user is registered as a user with the said attribute authority AA; (3) a corresponding user private key is generated given a set of attributes S of a user; (4) an access policy is given by the owner of the data and data encryption is performed; (5) the user performs the data decryption process according to the embedded policy for the set of owned attributes in different environments; (6) the update key generation process is performed; (7) after receiving the private key update key from the attribute authority AA, the user updates the private key component associated with the revoked attribute in order to complete the private key update process; (8) upon receiving the ciphertext update key from the attribute authority AA, the cloud server updates the ciphertext component associated with the revocation attribute to complete the ciphertext update process.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

A traditional chinese medicine data sharing method based on attribute-based encryption and homomorphic encryption

This invention proposes a method for sharing traditional Chinese medicine (TCM) data based on attribute-based encryption and homomorphic encryption. The method includes an attribute authorization agency, TCM data owners, a blockchain, TCM data users, data user agents, and private key sharers. The attribute authorization agency is responsible for generating the homomorphic encryption public and private keys, attribute public and private keys, and verifying data compliance. The data owner encrypts the data using the homomorphic encryption public key and stores it on the blockchain after setting access policies using attribute-based encryption. When a data user initiates an access request, the data user agent verifies the user's access rights. Upon successful verification, a homomorphic operation is performed on the ciphertext. Subsequently, multiple private key sharers, who collaboratively manage fragments of the homomorphic private key, complete partial decryption. Finally, the TCM data user recovers the plaintext result. This method ensures that TCM data is usable but not visible through homomorphic encryption, achieves precise access control through attribute-based encryption, and reduces the risk of private key escrow through secret sharing.
Owner:XIAN MEDICAL UNIV

Encryption method and system for policy hiding and puncturing based on attributes

The invention discloses an attribute-based strategy hiding and puncturing encryption method, which relates to the technical field of data encryption, and is characterized in that a user can autonomously update a secret key of the user, so that the user loses the decryption capability, and does not need to depend on a centralized secret key distribution mechanism. In the scheme, the seamless revocation of the decryption capability can be realized without deleting the key component in the key update. Besides, the scheme utilizes a block chain technology to verify an access policy by integrating an attribute authorization center into a consensus node, so that the calculation overhead is reduced. The invention further discloses an attribute-based strategy hiding and puncturing encryption system, the puncturing function is realized, the encryption scheme has forward security, and a user can actively cancel the key decryption function.
Owner:HUAIBEI NORMAL UNIVERSITY

Efficient access control method for supporting malicious authorization tracking and preventing collusion on chain

The invention provides an efficient access control method for supporting malicious authorization tracking and preventing collusion on a chain, and belongs to the technical field of information security, the method introduces a block chain to construct a plurality of attribute authorization centers, a central mechanism distributes an attribute set for the plurality of attribute authorization centers, and the attribute authorization centers are responsible for attribute authorization; the central mechanism only needs to manage issuing of attribute authorization authority, specific attribute authorization is completely realized by a plurality of authorization centers, and functions of the central mechanism are decomposed; malicious authorization of the attribute authorization center is tracked, and the malicious authorization center is revoked, so that the scheme authorization is ensured to be credible; in the authorization process of the authorization center, the secret keys mastered by the users are further segmented and randomized, so that part of the secret keys owned by the users are completely irrelevant to attributes, and the difficulty of collusion realization among the users is further increased; and the system calculation overhead is reduced by using outsourcing decryption and proxy re-encryption.
Owner:LANZHOU UNIVERSITY OF TECHNOLOGY

A multi-center attribute-based encryption method, a computer readable storage medium and a device

The present application relates to a data encryption method, in particular to a multi-center attribute-based encryption method supporting privacy protection for a smart medical system, a computer readable storage medium and equipment, which is used to solve the defects of single authorization center, insecure sensitive information, key abuse, and inability to guarantee the confidentiality and integrity of data based on attribute-based encryption technology in the smart medical system. The multi-center attribute-based encryption method uses the decentralized characteristics of the block chain, adopts multiple accounting nodes BN θ as a plurality of attribute authorization agencies to distribute keys, effectively avoiding the single point bottleneck problem; at the same time, the consensus node generates an anonymous identity certificate AIC for the data user DU to protect the sensitive information of the data user DU from being leaked. The present application can accurately track and revoke malicious data users DU, and can realize accountability to malicious data users DU and corrupt centers through tracking smart contracts.
Owner:XIAN UNIV OF POSTS & TELECOMM +1

Single sign-on access control method based on attribute encryption in cloud storage

The invention discloses a single sign-on access control method based on attribute encryption in cloud storage, and relates to the technical field of information security, and the method comprises the steps: S1, generating a system public parameter and a master key, and enabling an attribute authority to generate own public and private keys; s2, the user registers to an authentication server, and the authentication server issues a token to the user; s3, the authentication server generates a corresponding decryption key for each user; s4, the data owner formulates an access strategy, encrypts the message according to the access strategy and the system public parameters, calculates and uploads a ciphertext to the storage server; s5, the user sends a decryption request to the storage server, and a plaintext is obtained through decryption; s6, the attribute authority updates the ciphertext and the decryption key; the authentication server maintains a user revocation list. According to the method, dynamic fine-grained access control is realized on the premise that information such as user attributes is not leaked, the problem of privacy leakage caused by multiple times of registration of the user is relieved through a single sign-on method, and the method has high efficiency.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Attribute signature-based distributed supervision anonymous certificate method and system

PendingCN121283636AUser identity/authority verificationRegulatory authorityEngineering
The invention discloses a distributed supervision anonymous certificate method and system based on an attribute signature, and the method comprises the steps: a user submits an attribute application to a distributed attribute mechanism, and the attribute mechanism issues an attribute private key to the user through a chain type authorization method after the authentication is passed; the user submits a revocation right application to the supervision mechanism, and the supervision mechanism generates a revocation right for the user and publishes a certificate white list; the user uses the attribute private key and the revoked right to generate an anonymous certificate, and the anonymous certificate is shown to the verifier; the verifier verifies the attribute signature and certificate validity of the anonymous certificate; when a dispute occurs, the verifier can request arbitration, and the supervision mechanism recovers the real identity of the user or revokes the anonymous certificate of the user according to the dispute degree. Compared with the prior art, the anonymous certificate revocation method has the advantages that double decentration of the attribute mechanism and the supervision mechanism is realized, and the anonymous certificate revocation method is efficient.
Owner:ZHEJIANG UNIV

Data sharing encryption method and system supporting anonymity and attribute hiding

The invention provides a data sharing encryption method and system supporting anonymity and attribute hiding, and relates to the field of data sharing, and the system comprises a central authority which is used for generating a public parameter based on a security parameter; the attribute authority is used for generating a public key and a private key of the attribute authority based on the public parameters, and anonymizing the data use end; the central authority is also used for distributing corresponding secret values to attributes in the access strategy matrix submitted by the data uploading end; the central authority and the attribute authority are also used for generating an attribute private key of the data use end; the data uploading end is also used for encrypting the plaintext message based on the public parameter and the public key of the attribute authority to generate a ciphertext; the data use end is further used for judging whether the attribute of the data use end meets the access strategy of the ciphertext or not based on the public parameters and the attribute private key of the data use end, and if yes, decrypted data are generated, and the data sharing method and device have the advantage that the flexibility and safety of data sharing are improved.
Owner:DADU RIVER HYDROPOWER DEV

A method of attribute access control supporting multi-domain tracking and user management

The application relates to a property access control method supporting multi-domain tracking and user management, and belongs to the field of information security.The method comprises the following steps: a property authorization center generates a unique identity according to user properties, and completes the registration of a new data user; a data owner encrypts plaintext data to obtain intermediate ciphertext; a cloud server performs re-encryption on the intermediate ciphertext; the property authorization center generates a property key and identifies a legal user and a malicious user among the registered new data users based on a conversion key; a proxy server performs initial decryption conversion on the re-encrypted ciphertext; a legal user uses a user private key to complete final decryption, and obtains plaintext data. The method aims to solve the technical problems that the prior art is difficult to realize multi-domain tracking under a multi-domain environment, is difficult to realize user revocation under the premise of considering forward and backward security, and is difficult to realize user addition under the premise of ensuring forward security.
Owner:YUNNAN NORMAL UNIV

Method and system for policy-based access control based on distributed cuckoo filter

The application discloses a policy hidden access control method and system based on a distributed cuckoo filter, and specifically comprises the following steps: based on system parameters, making each attribute authority generate a respective public-private key pair, and making the public key of the public-private key pair public to all entities; based on the system parameters, the public-private key pair and a user attribute set, generating a corresponding user key component; making a data owner generate a policy fingerprint and an attribute fingerprint according to an access policy, and encrypting a plaintext by using the system parameters, the public-private key pair and the access policy to obtain a ciphertext containing the policy fingerprint; reconstructing the access policy by using a policy row set, and decrypting and verifying the ciphertext in combination with the user key component. The application designs a distributed cuckoo filter to realize a completely hidden policy, and converts the access policy and attributes into fingerprint information tables stored in the DCF, thereby hiding the mapping between the policy and the attributes.
Owner:HUNAN UNIV OF SCI & TECH

Policy hidden access control method and system based on distributed Cuckou filter

The invention discloses a strategy hidden access control method and system based on a distributed Cuckou filter, and the method specifically comprises the steps: enabling each attribute authorization mechanism to generate a public and private key pair based on system parameters, and enabling a public key of the public and private key pair to be public to all entities; generating a corresponding user key component based on the system parameters, the public and private key pair and the user attribute set; enabling a data owner to generate a strategy fingerprint and an attribute fingerprint according to an access strategy, and encrypting a plaintext by using a system parameter, a public and private key pair and the access strategy to obtain a ciphertext containing the strategy fingerprint; and reconstructing the access policy by using the policy row set, and decrypting and verifying the ciphertext in combination with the user key component. According to the method, a distributed Cuckou filter is designed to realize a completely hidden strategy, and an access strategy and attributes thereof are converted into mapping between the hidden strategy and the attributes in a fingerprint information table stored in a DCF through conversion.
Owner:HUNAN UNIV OF SCI & TECH

Fine-grained anonymous authentication method for multi-attribute authority system

A fine-grained anonymous authentication method for multi-attribute authority system, comprising a central authority, a plurality of attribute authorities, N users and M relying parties in the anonymous authentication system of multi-attribute authority. When the multi-attribute authority system is initialized, the central authority initializes public parameters and secret values; the attribute authority generates secret values for each managed attribute and publishes public parameters, and proves possession of the secret value by means of zero-knowledge proof; when the user joins, the user obtains an empty certificate from the central authority; the user successively looks for the attribute authority to sign the certificate, and finally obtains a certificate signed by multiple attributes; when the user obtains the service provided by the relying party, the user proves to the relying party that the required attribute is possessed, and the anonymous authentication is completed. The application generates secret values for each attribute by the attribute authority and publishes public parameters, solves the problem of user collusion with untrusted attribute authorities to forge attributes, and ensures the normal operation of the anonymous authentication of the multi-attribute authority system.
Owner:SHANGHAI JIAOTONG UNIV

Data capsule-oriented multi-condition triggering self-destruction method

The invention discloses a multi-condition triggering self-destruction method for a data capsule. The invention introduces a multi-condition self-destruction mechanism, and relates to data encryption, access control and data destruction. And encrypting and packaging the sensitive data through attribute-based encryption, generating a decryption strategy with an access strategy tree, binding decryption environment parameters and a use strategy, setting a self-destruction trigger condition, compiling to generate an executable capsule program embedded with a self-destruction mechanism, and issuing the executable capsule program to a data user. And the data user obtains the attribute voucher through the attribute authorization center, and encrypts and stores the attribute voucher through a local protection password. And decrypting and accessing under the condition that permission verification, environment detection and strategy conditions are met, otherwise, automatically triggering a self-destruction mechanism, terminating the operation of the program, and executing multiple rounds of data overwriting to realize physical erasing. According to the method, active sensing and self-destruction of the data capsule are realized, a life cycle closed loop from generation to active destruction is realized, and comprehensive control and safety guarantee of the life cycle of sensitive data are remarkably improved.
Owner:HANGZHOU UNIV OF ELECTRONIC SCI & TECH PINGHU DIGITAL TECH INNOVATION RES INST CO LTD

An access control method based on outsourced computing and attribute-based searchable encryption on blockchain

The present invention relates to the field of data sharing and specifically discloses an access control method based on outsourced computing and attribute-based searchable encryption on a blockchain. The method comprises the following steps: S1: an attribute authority initializes and generates a system public key and a master key, and generates a user's attribute private key; S2: a data owner formulates an access control policy and assists an outsourced encryption service provider in partial encryption. The data user and the outsourced encryption service provider encrypt keywords, data ciphertext storage addresses, and symmetric keys, and upload the encrypted ciphertext to the blockchain for storage; S3: the data user generates a search trapdoor and sends it to the blockchain to verify the user's attributes; S4: the data user assists an outsourced decryption service provider in partially decrypting the ciphertext, locally decrypting to obtain the data storage address and symmetric key, downloading the data ciphertext, and decrypting it using the symmetric key to obtain the data plaintext. The present invention reduces the computational burden of encryption and decryption for local users and improves the efficiency and security of data sharing.
Owner:HUBEI UNIV

Data processing method and device in federal learning, equipment, medium and product

The invention provides a data processing method and device in federal learning, equipment, a medium and a product, and relates to the technical field of data processing. According to the method, a distributed multi-center attribute authority chain system based on an alliance chain architecture is constructed, and an attribute set and an access control strategy of each participant of federal learning are pre-stored in the system, so that the risk that a single center is easy to face centralized attacks is avoided, and the multi-party trust degree is enhanced. Besides, in the data processing process, the target decryption key is generated after the key acquisition request is verified based on the attribute set and the access control strategy, it is ensured that only the permitted participant can acquire the key, and then the encryption model data is decrypted by using the key to obtain the plaintext model data. And finally executing local model processing operation to generate target model data. Therefore, an encryption protection mechanism based on the attribute set and the access control strategy is provided for model data transmission, the data leakage risk is reduced, and the security and reliability of federated learning joint modeling are improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

A supply chain data access control method that supports attribute revocation and updating

The embodiments of this application relate to the field of industrial data encryption processing technology, and disclose a supply chain data access control method that supports attribute revocation and update. This method is applied to an established supply chain data access control model, which consists of a data accesser, a data owner, an authentication and authorization center, an attribute authorization center, and a cloud service provider. Through global initialization, attribute key generation, data encryption, and data decryption, the data accesser can securely access the data provided by the data owner, achieving efficient and secure data access control. The supply chain data access control model supports complete revocation and update of user attributes. By applying elliptic curve digital signature algorithms, hash algorithms, and asynchronous update strategies, it effectively eliminates single-point performance bottlenecks and leakage problems, achieving efficient complete revocation and update of attributes.
Owner:XIDIAN UNIV

Attribute access control method supporting time-limited access, attribute dynamic management and policy update

ActiveCN121792243Bprevent unauthorized accessEnable forward and backward securitySecuring communicationTimestampDynamic management
The present application relates to a kind of attribute access control methods of supporting time-limited access, attribute dynamic management and strategy update, belong to information security technical field.The method includes: setting attribute authorization center, cloud server, data owner and data user four entities;Attribute authorization center generates data user key using system public key, master key and the attribute list of data user, then introduces timestamp coding parameter, chameleon hash parameter and attribute list associated random parameter;Data owner encrypts plaintext data, obtains intermediate ciphertext and embeds chameleon hash value, and cloud server re-encrypts intermediate ciphertext, obtains final ciphertext;Data user that meets decryption condition executes decryption operation to final ciphertext using data user key, obtains plaintext data.The purpose is to solve the technical problems that technology cannot support flexible addition, revocation, dynamic adjustment of access strategy and time-limited access control of attribute and key.
Owner:YUNNAN NORMAL UNIV

Medical cloud data sharing method based on blockchain and privacy security traceable and revocable multi-attribute authoritative CP-ABE

The invention discloses a medical cloud data sharing method based on a block chain and privacy security traceable and revocable multi-attribute authoritative CP-ABE. The method comprises the steps of multi-attribute authoritative mechanism collaboration, zero-knowledge proof identity authentication, hidden attribute value access strategy, accumulator encryption uplink and outsourcing decryption integrity verification. According to the invention, privacy protection and safe sharing of cross-institution medical data are realized.
Owner:YUNNAN UNIVERSITY OF FINANCE AND ECONOMICS

A blockchain-based bilateral fine-grained access control and privacy protection method

The application discloses a kind of bilateral fine-grained access control and privacy protection method based on block chain, applied to privacy protection technical field.The application includes the following steps: system initialization, attribute authorization agency, data owner and data user initiate identity registration request;Authorization center generates verification key and uploads to block chain;Attribute authority calculates encryption key and sends to data owner, calculates decryption key and sends to data user, and data user generates decryption component and uploads to block chain;Data owner encrypts data ciphertext and uploads to interstellar file system, encrypts symmetric key, generates attribute ciphertext component and uploads to block chain;Execute bilateral matching algorithm to verify two-way fine-grained matching mechanism;Matched data user restores symmetric key, obtains and decrypts shared data.The application can realize comprehensive management to access permission, and only when the bilateral access strategy of data user and data owner is satisfied, cross-domain data sharing is realized through block chain.
Owner:BEIJING UNIV OF POSTS & TELECOMM