Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Attribute authority" patented technology

An attribute authority (also known as an attribute store) is a directory or database in which systems can securely add, modify, and save attributes. An attribute authority is a trusted source of data for ABAC decisions. Data sources such as MySQL databases, LDAP directories, Active Directories, and Web services can be configured as...

Blockchain-based verifiable key generation method in ma-cpabe

PendingCN122372200ASmart contractKey generation
This invention discloses a blockchain-based verifiable key generation method in MA-CPABE. The method includes: a data owner running a global setting algorithm to generate system parameters, and electing multiple decentralized attribute authorization nodes through a blockchain staking mechanism; each node generating public and private keys and uploading the public key to the blockchain; the data owner encrypting data based on a policy and publishing the ciphertext and its identifier to the blockchain; when a user requests a key, the attribute authorization node calls an optimized key generation circuit to generate a decryption key and a corresponding zero-knowledge proof, submitting the proof and related data to the blockchain, where a verification node verifies and records the key generation event; for the update history of the zero-knowledge proof, a chain-based evidence storage system is constructed through a smart contract event mechanism to achieve verifiable traceability of its change history. This invention achieves decentralized trusted key management, efficient off-chain computation and verifiability, and significantly reduced blockchain resource consumption.
Owner:YUNNAN UNIVERSITY OF FINANCE AND ECONOMICS +1

A data security storage and access control method of attribute classification and grading

ActiveCN115964751BFile systemEngineering
A kind of attribute classification and grading data security storage and access control method includes a central authority CA, N attribute authorities AAs and X sub-authorities aas, user, agency administrator, product transaction traceability public blockchain, information security supervision alliance blockchain and interstellar file system IPFS.The present application stores massive unstructured data and encrypted information using IPFS, only stores the file addressing hash generated by IPFS on the blockchain, reduces the data storage pressure and security risk of the blockchain;A multi-agency ciphertext policy-based attribute encryption algorithm is constructed to meet the needs of privacy information protection and dynamic fine-grained access control of the system;The combination of multi-authority hierarchical authorization and central authority disperses the system overhead, making it easier to supervise;Accurate tracking of malicious users is achieved, and users and attributes can be revoked immediately without updating keys or ciphertexts.
Owner:JIANGXI UNIV OF SCI & TECH

Method for Implementing Fine-Grained Data Access and Sharing in 6G Networks Based on Fog Computing and Cloud Computing Environments

A method for implementing fine-grained data access sharing in 6G network based on fog computing and cloud computing environment includes: (1) a security parameter is given for initialization; (2) each user is registered as a user with the said attribute authority AA; (3) a corresponding user private key is generated given a set of attributes S of a user; (4) an access policy is given by the owner of the data and data encryption is performed; (5) the user performs the data decryption process according to the embedded policy for the set of owned attributes in different environments; (6) the update key generation process is performed; (7) after receiving the private key update key from the attribute authority AA, the user updates the private key component associated with the revoked attribute in order to complete the private key update process; (8) upon receiving the ciphertext update key from the attribute authority AA, the cloud server updates the ciphertext component associated with the revocation attribute to complete the ciphertext update process.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

A traditional chinese medicine data sharing method based on attribute-based encryption and homomorphic encryption

This invention proposes a method for sharing traditional Chinese medicine (TCM) data based on attribute-based encryption and homomorphic encryption. The method includes an attribute authorization agency, TCM data owners, a blockchain, TCM data users, data user agents, and private key sharers. The attribute authorization agency is responsible for generating the homomorphic encryption public and private keys, attribute public and private keys, and verifying data compliance. The data owner encrypts the data using the homomorphic encryption public key and stores it on the blockchain after setting access policies using attribute-based encryption. When a data user initiates an access request, the data user agent verifies the user's access rights. Upon successful verification, a homomorphic operation is performed on the ciphertext. Subsequently, multiple private key sharers, who collaboratively manage fragments of the homomorphic private key, complete partial decryption. Finally, the TCM data user recovers the plaintext result. This method ensures that TCM data is usable but not visible through homomorphic encryption, achieves precise access control through attribute-based encryption, and reduces the risk of private key escrow through secret sharing.
Owner:XIAN MEDICAL UNIV

Efficient access control method for supporting malicious authorization tracking and preventing collusion on chain

The invention provides an efficient access control method for supporting malicious authorization tracking and preventing collusion on a chain, and belongs to the technical field of information security, the method introduces a block chain to construct a plurality of attribute authorization centers, a central mechanism distributes an attribute set for the plurality of attribute authorization centers, and the attribute authorization centers are responsible for attribute authorization; the central mechanism only needs to manage issuing of attribute authorization authority, specific attribute authorization is completely realized by a plurality of authorization centers, and functions of the central mechanism are decomposed; malicious authorization of the attribute authorization center is tracked, and the malicious authorization center is revoked, so that the scheme authorization is ensured to be credible; in the authorization process of the authorization center, the secret keys mastered by the users are further segmented and randomized, so that part of the secret keys owned by the users are completely irrelevant to attributes, and the difficulty of collusion realization among the users is further increased; and the system calculation overhead is reduced by using outsourcing decryption and proxy re-encryption.
Owner:LANZHOU UNIVERSITY OF TECHNOLOGY

A multi-center attribute-based encryption method, a computer readable storage medium and a device

The present application relates to a data encryption method, in particular to a multi-center attribute-based encryption method supporting privacy protection for a smart medical system, a computer readable storage medium and equipment, which is used to solve the defects of single authorization center, insecure sensitive information, key abuse, and inability to guarantee the confidentiality and integrity of data based on attribute-based encryption technology in the smart medical system. The multi-center attribute-based encryption method uses the decentralized characteristics of the block chain, adopts multiple accounting nodes BN θ as a plurality of attribute authorization agencies to distribute keys, effectively avoiding the single point bottleneck problem; at the same time, the consensus node generates an anonymous identity certificate AIC for the data user DU to protect the sensitive information of the data user DU from being leaked. The present application can accurately track and revoke malicious data users DU, and can realize accountability to malicious data users DU and corrupt centers through tracking smart contracts.
Owner:XIAN UNIV OF POSTS & TELECOMM +1

Data sharing encryption method and system supporting anonymity and attribute hiding

The invention provides a data sharing encryption method and system supporting anonymity and attribute hiding, and relates to the field of data sharing, and the system comprises a central authority which is used for generating a public parameter based on a security parameter; the attribute authority is used for generating a public key and a private key of the attribute authority based on the public parameters, and anonymizing the data use end; the central authority is also used for distributing corresponding secret values to attributes in the access strategy matrix submitted by the data uploading end; the central authority and the attribute authority are also used for generating an attribute private key of the data use end; the data uploading end is also used for encrypting the plaintext message based on the public parameter and the public key of the attribute authority to generate a ciphertext; the data use end is further used for judging whether the attribute of the data use end meets the access strategy of the ciphertext or not based on the public parameters and the attribute private key of the data use end, and if yes, decrypted data are generated, and the data sharing method and device have the advantage that the flexibility and safety of data sharing are improved.
Owner:DADU RIVER HYDROPOWER DEV

A method of attribute access control supporting multi-domain tracking and user management

The application relates to a property access control method supporting multi-domain tracking and user management, and belongs to the field of information security.The method comprises the following steps: a property authorization center generates a unique identity according to user properties, and completes the registration of a new data user; a data owner encrypts plaintext data to obtain intermediate ciphertext; a cloud server performs re-encryption on the intermediate ciphertext; the property authorization center generates a property key and identifies a legal user and a malicious user among the registered new data users based on a conversion key; a proxy server performs initial decryption conversion on the re-encrypted ciphertext; a legal user uses a user private key to complete final decryption, and obtains plaintext data. The method aims to solve the technical problems that the prior art is difficult to realize multi-domain tracking under a multi-domain environment, is difficult to realize user revocation under the premise of considering forward and backward security, and is difficult to realize user addition under the premise of ensuring forward security.
Owner:YUNNAN NORMAL UNIV

Method and system for policy-based access control based on distributed cuckoo filter

The application discloses a policy hidden access control method and system based on a distributed cuckoo filter, and specifically comprises the following steps: based on system parameters, making each attribute authority generate a respective public-private key pair, and making the public key of the public-private key pair public to all entities; based on the system parameters, the public-private key pair and a user attribute set, generating a corresponding user key component; making a data owner generate a policy fingerprint and an attribute fingerprint according to an access policy, and encrypting a plaintext by using the system parameters, the public-private key pair and the access policy to obtain a ciphertext containing the policy fingerprint; reconstructing the access policy by using a policy row set, and decrypting and verifying the ciphertext in combination with the user key component. The application designs a distributed cuckoo filter to realize a completely hidden policy, and converts the access policy and attributes into fingerprint information tables stored in the DCF, thereby hiding the mapping between the policy and the attributes.
Owner:HUNAN UNIV OF SCI & TECH

Policy hidden access control method and system based on distributed Cuckou filter

The invention discloses a strategy hidden access control method and system based on a distributed Cuckou filter, and the method specifically comprises the steps: enabling each attribute authorization mechanism to generate a public and private key pair based on system parameters, and enabling a public key of the public and private key pair to be public to all entities; generating a corresponding user key component based on the system parameters, the public and private key pair and the user attribute set; enabling a data owner to generate a strategy fingerprint and an attribute fingerprint according to an access strategy, and encrypting a plaintext by using a system parameter, a public and private key pair and the access strategy to obtain a ciphertext containing the strategy fingerprint; and reconstructing the access policy by using the policy row set, and decrypting and verifying the ciphertext in combination with the user key component. According to the method, a distributed Cuckou filter is designed to realize a completely hidden strategy, and an access strategy and attributes thereof are converted into mapping between the hidden strategy and the attributes in a fingerprint information table stored in a DCF through conversion.
Owner:HUNAN UNIV OF SCI & TECH

Data processing method and device in federal learning, equipment, medium and product

The invention provides a data processing method and device in federal learning, equipment, a medium and a product, and relates to the technical field of data processing. According to the method, a distributed multi-center attribute authority chain system based on an alliance chain architecture is constructed, and an attribute set and an access control strategy of each participant of federal learning are pre-stored in the system, so that the risk that a single center is easy to face centralized attacks is avoided, and the multi-party trust degree is enhanced. Besides, in the data processing process, the target decryption key is generated after the key acquisition request is verified based on the attribute set and the access control strategy, it is ensured that only the permitted participant can acquire the key, and then the encryption model data is decrypted by using the key to obtain the plaintext model data. And finally executing local model processing operation to generate target model data. Therefore, an encryption protection mechanism based on the attribute set and the access control strategy is provided for model data transmission, the data leakage risk is reduced, and the security and reliability of federated learning joint modeling are improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Attribute access control method supporting time-limited access, attribute dynamic management and policy update

ActiveCN121792243Bprevent unauthorized accessEnable forward and backward securitySecuring communicationTimestampDynamic management
The present application relates to a kind of attribute access control methods of supporting time-limited access, attribute dynamic management and strategy update, belong to information security technical field.The method includes: setting attribute authorization center, cloud server, data owner and data user four entities;Attribute authorization center generates data user key using system public key, master key and the attribute list of data user, then introduces timestamp coding parameter, chameleon hash parameter and attribute list associated random parameter;Data owner encrypts plaintext data, obtains intermediate ciphertext and embeds chameleon hash value, and cloud server re-encrypts intermediate ciphertext, obtains final ciphertext;Data user that meets decryption condition executes decryption operation to final ciphertext using data user key, obtains plaintext data.The purpose is to solve the technical problems that technology cannot support flexible addition, revocation, dynamic adjustment of access strategy and time-limited access control of attribute and key.
Owner:YUNNAN NORMAL UNIV

A blockchain-based bilateral fine-grained access control and privacy protection method

The application discloses a kind of bilateral fine-grained access control and privacy protection method based on block chain, applied to privacy protection technical field.The application includes the following steps: system initialization, attribute authorization agency, data owner and data user initiate identity registration request;Authorization center generates verification key and uploads to block chain;Attribute authority calculates encryption key and sends to data owner, calculates decryption key and sends to data user, and data user generates decryption component and uploads to block chain;Data owner encrypts data ciphertext and uploads to interstellar file system, encrypts symmetric key, generates attribute ciphertext component and uploads to block chain;Execute bilateral matching algorithm to verify two-way fine-grained matching mechanism;Matched data user restores symmetric key, obtains and decrypts shared data.The application can realize comprehensive management to access permission, and only when the bilateral access strategy of data user and data owner is satisfied, cross-domain data sharing is realized through block chain.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Decentralized attribute-based encryption method based on standard model

A decentralized attribute-based encryption method based on a standard model includes: global initialization; an authority generating public and private keys associated with attributes; generating a user's attribute private key; message encryption; and verification of whether the identity and attribute satisfy the access policy. If they satisfy, the plaintext is decrypted and recovered; otherwise, decryption fails. This invention achieves flexible, fine-grained access control by combining LSSS access policies and provides dual security constraints through a global identity and attribute binding mechanism. It is suitable for various practical scenarios of secure data sharing and distributed attribute management, especially for multi-source authorization, privacy protection, and cross-domain collaborative environments. It features high security, high scalability, and good deployment feasibility. This invention requires no central authority or trusted initialization setup; each attribute authority can operate independently and be responsible for the key management and issuance of its own attribute, fundamentally eliminating single-point trust and system bottlenecks.
Owner:SHAANXI NORMAL UNIV

Credible low-altitude perception and data evidence storage platform based on block chain and attribute password

The invention provides a credible low-altitude perception and data storage platform based on a block chain and an attribute password, which comprises a user interaction layer, a logic processing layer, a block chain and a storage layer. A server side of a flight identity authentication and authority management module, a server side of a flight state perception and anomaly detection module and a server side of an algorithm support module are established on a server of a user, and a user side of the algorithm support module is established on the server of the user and is responsible for locally storing sensitive privacy data such as an asymmetric secret key, a user private key, an attribute private key and an authorized attribute private key of the user. Key pair generation, attribute creation, attribute authorization, data decryption and other operation support related to privacy data are provided, it is ensured that user data are locally stored and used, and no privacy information is exposed to the outside; according to the invention, a low-altitude flight management infrastructure integrating identity management, flight supervision and data security is constructed.
Owner:FUDAN UNIVERSITY +1

An attribute-based policy hiding and puncturing encryption method and system

The application discloses an encryption method based on attribute-based strategy hiding and puncturing, relates to the technical field of data encryption, and can enable a user to autonomously update a secret key, so that the user loses decryption capability, thereby not needing to rely on a centralized secret key distribution mechanism.In the scheme, the secret key update does not need to delete secret key components, and seamless revocation of decryption capability can be realized.In addition, the scheme utilizes blockchain technology, verifies an access strategy by integrating an attribute authorization center into a consensus node, and thus reduces a calculation cost.The application also discloses an encryption system based on attribute-based strategy hiding and puncturing, realizes a puncturing function, and is a forward security encryption scheme, so that a user can actively revoke a secret key decryption function.
Owner:HUAIBEI NORMAL UNIVERSITY

An efficient data sharing method and system supporting user revocation and key tracking

This invention belongs to, but is not limited to, the field of information security technology, and particularly relates to an efficient data sharing method and system supporting user revocation and key tracking, comprising: system initialization, where an attribute authority generates a master public key and a master private key; attribute key generation, where a data user sends a key request to the authority and receives the corresponding attribute key; data encryption, where the data owner formulates an access policy for their data and encrypts the data accordingly, then uploads the ciphertext to the cloud; update key generation, where the attribute authority generates an update key for its maintained revocation list; decryption key generation, where the data user executes to obtain the decryption key; ciphertext decryption, where users who meet the policy and have not been revoked can decrypt the data; and tracking data encryption and malicious user tracking, where any user can perform tracking encryption to complete malicious user tracking.
Owner:王文丽

A child health care data storage protection method and system based on federated learning

The present application relates to the technical field of data security access, in particular to a child health care data storage protection method and system based on federated learning, comprising obtaining a distributed attribute authorization data set, the attribute authorization data set including an attribute definition data set, a policy management data set and a key distribution data set; receiving an authorization instruction through the policy management data set, and generating an access control policy according to the authorization instruction; when a federated learning platform initiates a data access request, creating an isolated cloud computing sandbox environment for a federated learning task according to the access control policy; dynamically calculating and using a differential privacy parameter matched with a use purpose, and applying the parameter to child health care data within the authorized range; executing the federated learning task in the cloud computing sandbox environment, monitoring and limiting data processing operations; providing a permission dynamic adjustment mechanism, when modifying the authorized range and / or revoking the authorization, updating the access control policy to take effect immediately, and pushing a permission change instruction to all computing nodes.
Owner:LIAOYI (SHANDONG) NETWORK INFORMATION TECHNOLOGY CO LTD +1

Verifiable multi-authority attribute-based encryption method supporting attribute revocation under block chain

PendingCN122093048AKey distribution for secure communicationPlaintextAccess structure
The invention discloses a verifiable multi-authority attribute-based encryption method supporting attribute revocation under a block chain, and the method comprises the steps: enabling a system to initialize a central authorization center CA and an attribute authority AA, submitting attributes, attribute public keys, commitments and the like to a safety storage region of a block chain intelligent contract, and enabling the contract to only read a random number, uploading the attribute, the attribute public key and the commitment to a blockchain smart contract public area; a secret key is generated, and uplink operation of a user private key and a global identifier is realized through an intelligent contract; the smart contract reads the random number from the secure storage area, and verifies the attribute public key and the private key; performing encryption according to the encrypted plaintext, and recording a returned hash address addrCT and an access structure by the block chain; and decrypting the ciphertext and realizing attribute revocation, and updating the public key and promising to realize verification of a new public key and a new private key during revocation. Compared with the prior art, the method can prevent a malicious attribute authority from distributing wrong public keys, and is adaptive to an application scene of independent cooperation of multiple authoritative institutions.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY