Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7 results about "Attribute authority" patented technology

An attribute authority (also known as an attribute store) is a directory or database in which systems can securely add, modify, and save attributes. An attribute authority is a trusted source of data for ABAC decisions. Data sources such as MySQL databases, LDAP directories, Active Directories, and Web services can be configured as...

Blockchain-based verifiable key generation method in ma-cpabe

PendingCN122372200ASmart contractKey generation
This invention discloses a blockchain-based verifiable key generation method in MA-CPABE. The method includes: a data owner running a global setting algorithm to generate system parameters, and electing multiple decentralized attribute authorization nodes through a blockchain staking mechanism; each node generating public and private keys and uploading the public key to the blockchain; the data owner encrypting data based on a policy and publishing the ciphertext and its identifier to the blockchain; when a user requests a key, the attribute authorization node calls an optimized key generation circuit to generate a decryption key and a corresponding zero-knowledge proof, submitting the proof and related data to the blockchain, where a verification node verifies and records the key generation event; for the update history of the zero-knowledge proof, a chain-based evidence storage system is constructed through a smart contract event mechanism to achieve verifiable traceability of its change history. This invention achieves decentralized trusted key management, efficient off-chain computation and verifiability, and significantly reduced blockchain resource consumption.
Owner:YUNNAN UNIVERSITY OF FINANCE AND ECONOMICS +1

A data security storage and access control method of attribute classification and grading

ActiveCN115964751BFile systemEngineering
A kind of attribute classification and grading data security storage and access control method includes a central authority CA, N attribute authorities AAs and X sub-authorities aas, user, agency administrator, product transaction traceability public blockchain, information security supervision alliance blockchain and interstellar file system IPFS.The present application stores massive unstructured data and encrypted information using IPFS, only stores the file addressing hash generated by IPFS on the blockchain, reduces the data storage pressure and security risk of the blockchain;A multi-agency ciphertext policy-based attribute encryption algorithm is constructed to meet the needs of privacy information protection and dynamic fine-grained access control of the system;The combination of multi-authority hierarchical authorization and central authority disperses the system overhead, making it easier to supervise;Accurate tracking of malicious users is achieved, and users and attributes can be revoked immediately without updating keys or ciphertexts.
Owner:JIANGXI UNIV OF SCI & TECH

A traditional chinese medicine data sharing method based on attribute-based encryption and homomorphic encryption

This invention proposes a method for sharing traditional Chinese medicine (TCM) data based on attribute-based encryption and homomorphic encryption. The method includes an attribute authorization agency, TCM data owners, a blockchain, TCM data users, data user agents, and private key sharers. The attribute authorization agency is responsible for generating the homomorphic encryption public and private keys, attribute public and private keys, and verifying data compliance. The data owner encrypts the data using the homomorphic encryption public key and stores it on the blockchain after setting access policies using attribute-based encryption. When a data user initiates an access request, the data user agent verifies the user's access rights. Upon successful verification, a homomorphic operation is performed on the ciphertext. Subsequently, multiple private key sharers, who collaboratively manage fragments of the homomorphic private key, complete partial decryption. Finally, the TCM data user recovers the plaintext result. This method ensures that TCM data is usable but not visible through homomorphic encryption, achieves precise access control through attribute-based encryption, and reduces the risk of private key escrow through secret sharing.
Owner:XIAN MEDICAL UNIV

A blockchain-based bilateral fine-grained access control and privacy protection method

The application discloses a kind of bilateral fine-grained access control and privacy protection method based on block chain, applied to privacy protection technical field.The application includes the following steps: system initialization, attribute authorization agency, data owner and data user initiate identity registration request;Authorization center generates verification key and uploads to block chain;Attribute authority calculates encryption key and sends to data owner, calculates decryption key and sends to data user, and data user generates decryption component and uploads to block chain;Data owner encrypts data ciphertext and uploads to interstellar file system, encrypts symmetric key, generates attribute ciphertext component and uploads to block chain;Execute bilateral matching algorithm to verify two-way fine-grained matching mechanism;Matched data user restores symmetric key, obtains and decrypts shared data.The application can realize comprehensive management to access permission, and only when the bilateral access strategy of data user and data owner is satisfied, cross-domain data sharing is realized through block chain.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Decentralized attribute-based encryption method based on standard model

A decentralized attribute-based encryption method based on a standard model includes: global initialization; an authority generating public and private keys associated with attributes; generating a user's attribute private key; message encryption; and verification of whether the identity and attribute satisfy the access policy. If they satisfy, the plaintext is decrypted and recovered; otherwise, decryption fails. This invention achieves flexible, fine-grained access control by combining LSSS access policies and provides dual security constraints through a global identity and attribute binding mechanism. It is suitable for various practical scenarios of secure data sharing and distributed attribute management, especially for multi-source authorization, privacy protection, and cross-domain collaborative environments. It features high security, high scalability, and good deployment feasibility. This invention requires no central authority or trusted initialization setup; each attribute authority can operate independently and be responsible for the key management and issuance of its own attribute, fundamentally eliminating single-point trust and system bottlenecks.
Owner:SHAANXI NORMAL UNIV

An efficient data sharing method and system supporting user revocation and key tracking

PendingCN122293361AGuaranteed traceabilitytraceableInternet privacyEngineering
This invention belongs to, but is not limited to, the field of information security technology, and particularly relates to an efficient data sharing method and system supporting user revocation and key tracking, comprising: system initialization, where an attribute authority generates a master public key and a master private key; attribute key generation, where a data user sends a key request to the authority and receives the corresponding attribute key; data encryption, where the data owner formulates an access policy for their data and encrypts the data accordingly, then uploads the ciphertext to the cloud; update key generation, where the attribute authority generates an update key for its maintained revocation list; decryption key generation, where the data user executes to obtain the decryption key; ciphertext decryption, where users who meet the policy and have not been revoked can decrypt the data; and tracking data encryption and malicious user tracking, where any user can perform tracking encryption to complete malicious user tracking.
Owner:王文丽

Verifiable multi-authority attribute-based encryption method supporting attribute revocation under block chain

PendingCN122093048AKey distribution for secure communicationPlaintextAccess structure
The invention discloses a verifiable multi-authority attribute-based encryption method supporting attribute revocation under a block chain, and the method comprises the steps: enabling a system to initialize a central authorization center CA and an attribute authority AA, submitting attributes, attribute public keys, commitments and the like to a safety storage region of a block chain intelligent contract, and enabling the contract to only read a random number, uploading the attribute, the attribute public key and the commitment to a blockchain smart contract public area; a secret key is generated, and uplink operation of a user private key and a global identifier is realized through an intelligent contract; the smart contract reads the random number from the secure storage area, and verifies the attribute public key and the private key; performing encryption according to the encrypted plaintext, and recording a returned hash address addrCT and an access structure by the block chain; and decrypting the ciphertext and realizing attribute revocation, and updating the public key and promising to realize verification of a new public key and a new private key during revocation. Compared with the prior art, the method can prevent a malicious attribute authority from distributing wrong public keys, and is adaptive to an application scene of independent cooperation of multiple authoritative institutions.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY