Fine-grained data access control method based on fragmenting of secret keys
Abstract
The invention claims a based on key distribution sheet the data of the fine grain access control method which mainly solves the problem that existing technology the safety is low and operation problem of the large quantity of the. The realizing steps are as follows: Data owner to the shared data encrypting to get cryptogram; Attribute authority for accessing group user generates two belongs to the private key are respectively sent to a reliable agent mechanism and accessing group user; When accessing group user satisfies the access control structure when a reliable agent mechanism is used for the first attribute private key cipher text to the middle of the result of accessing group user by the second attribute private key to decrypt the middle result to obtain the data shared; Using attributes private key slicing techniques controlling and accessing group user obtains the incomplete belongs to the key the data owner the executing cancelling after the operation and does not need to new encrypted shared data. The invention can be shared data the invention claims fine particles of the access control it improves the security can be used in cloud terminal shared data access control the lower part of the shared data access.

Term
7.7 yearsto projected expiry
Projected expiry 17 June 2034, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
14 claims: 10 independent, 4 dependent
- 1based on key distribution sheet the data of the fine grain access control method comprises the following steps:Data owner do encrypted shared data to get cryptogram c: New users join into an access group: 2a when the new users join into an time data has to do it distributes one attribute aggregation w and unique identity iu;2b data owner do calculating attribute aggregation in the omega with attribute satisfy the access control structure of t the attribute of the compounding and ensure that the attribute combination properties of integrity;2c data owner do according to the calculated the attribute combination gather in the inner part is formed by the user list and the new user access state state value is able to visit the state of true;2d data owner do the new user satisfies the access control structure of t the attribute of the combination of new user number and visiting state terminal access state value can be true and it can be sent to a proxy signal mechanism and randomly selecting property compounding one of the attribute combination w to a proxy signal mechanism can be;2e new user is on the attribute aggregation w and unique identity iu to the attribute of authority *** attribute authority aa it generates two belongs to the private key 2 and the first sfcwiu4 attribute private key to a reliable agent mechanism to keep the second *** attribute private key to the new user to pipe;2f tower a reliable agent pyo machine according to said data owner do sending the attribute of the combined w ' attribute combination number of the access state state values and attribute authority aa sent by the first attribute at the private key is formed in the access control list visit group user visiting shared data: 3a accessing group user from yun service provider csp to get cryptogram c and the encrypted file c and a sole identity iu to a reliable agent mechanism a reliable agent verification mechanism for accessing group user identity if the access state terminal access state can be true and it satisfies access control structure an attribute of the combined amount is less than 0 then using the first attribute the private key c is transformed into cipher text in the middle of the processing result c 2' and the middle of the processing result c 2' sending accessing group user;3b accessing group user using the second attribute private key to decrypt the middle of the processing result c 2' so as to obtain the initial ming-wen m;Access of a group of user cancelling: 4a if the data owner do is stopped accessing group of some user visiting shared data owner can do is to cancel the accessing group user in the inner part of the user list in the access state state value is updated to control the access state false;4b data owner do is to cancel the accessing group user the access state state value can be sent to a proxy signal mechanism;4c a reliable agent mechanism according to the cancelling the access of the group of the user access state the state value of its access control list to cancel of the user access state is updated to control the access state false signal can be prevented a proxy mechanism is to cancel accessing group user process cipher text a conversion processing;Shared data property cancelling: 5a data owner do update the inner part of the user list to the accessing group user cancelling containing attribute the attribute combination and deleting the new counting the group user satisfies the access control structure of t the attribute combination number;5b data owner do the updated the attribute combination number can be sent to a proxy signal mechanism and randomly selecting property compounding one of the attribute combination w '' to a proxy signal mechanism can be;5c a reliable agent mechanism according to the data owner do sending the attribute of the combined w '' and the attribute combination number updating in the inner part of the access control list. 1.一种基于密钥分片的数据细粒度访问控制方法,包括如下步骤: (1)数据拥有者DO加密共享数据,得到密文C: (2)新用户加入访问群组: 2a)当有新用户加入时,数据拥有者DO为其分配一个属性集合ω和唯一身份Iu ;2b)数据拥有者DO计算属性集合ω中所有属性满足访问控制结构T的属性组合集合,并保证这些属性组合中属性的完整性; 2c)数据拥有者DO根据上述计算出的属性组合集合在其内部形成用户列表,并置该新用户访问状态State值为可访问状态True ; 2d)数据拥有者DO将新用户满足访问控制结构T的属性组合数目和新用户访问状态State值可访问状态True发送至半可信代理机构,并且随机选取属性组合集合中的一个属性组合ω,发至半可信代理机构; 2e)新用户上传属性集合ω和唯一身份Iu至属性权威机构ΑΑ,属性权威机构AA为其生成两个属性私钥2,并将第一属性私钥Sfcwiu4发至半可信代理机构进行保管,将第二属性私钥ζ发至该新用户保管; 2f)半可信代理机杓根据上述数据拥有者DO发送的属性组合ω'、属性组合数目、访问状态State值和属性权威机构AA发送的第一属性私钥在其内部形成访问控制表 (3)访问群组用户访问共享数据: 3a)访问群组用户从云服务提供商CSP获取密文C,并将密文c和唯一身份Iu上传至半可信代理机构,半可信代理机构验证访问群组用户身份,若其访问状态State为可访问状态True,且满足访问控制结构的属性组合数目大于0,则使用第一属性私钥将密文c转化为中间处理结果c',并将中间处理结果c'发回访问群组用户; 3b)访问群组用户使用第二属性私钥解密中间处理结果c',得到原始明文m;(4)访问群组中的用户撤销: 4a)如果数据拥有者DO要禁止访问群组中某个用户访问共享数据,数据拥有者DO可将要撤销的访问群组用户在其内部用户列表中的访问状态State值更新为禁止访问状态False ; 4b)数据拥有者DO将要撤销的访问群组用户的访问状态State值发送至半可信代理机构; 4c)半可信代理机构根据要撤销的访问群组用户的访问状态State值,将其访问控制表中要撤销用户的访问状态更新为禁止访问状态False,禁止半可信代理机构为要撤销访问群组用户进行密文c的转化处理; (5)共享数据属性撤销: 5a)数据拥有者DO更新其内部的用户列表,将所有访问群组用户含有撤销属性的属性组合删除,且重新统计所有群组用户满足访问控制结构T的属性组合数目; 5b)数据拥有者DO将更新后的属性组合数目发送至半可信代理机构,并且随机选取属性组合集合中的一个属性组合ω"发至半可信代理机构; 5c)半可信代理机构根据数据拥有者DO发送的属性组合ω"和属性组合数目更新其内部的访问控制表。
- 3According to claim the based on key distribution sheet the data of the fine grain access control method wherein said step ia generating master key mk and public key pk represented as follows:3.根据权利要求2所述的基于密钥分片的数据细粒度访问控制方法,其特征在于,所述步骤Ia)生成的主密钥mk和公钥pk,表示如下: 其中,G0是阶为P的乘法循环群,g是群Gtl的一个生成元,G1是阶为q的乘法循环群,e是双线性对hXh — Gpefe’gK为双线性映射,Zp是阶为P的整数域,a是Zp*的随机选取值,对于系统属性集合Ω = (a1;a2,…,an),对每一个a」e Ω随机选择一个t」e Zp, j表示系统属性集合Ω中属性的下标值。 3. G0 is in the step is p the product of the method of cyclic group g gtl group is one of the g1 generation unit as q is step the product of the method of cyclic group e is the double linear hxh gpefe or gk as the double linear mapping zp step is p is integer of a zp * the randomly selecting value corresponding to the system attribute aggregation ohm = a1;A2 and an e-mail to each a e ohm randomly select a e-mail zp t e j expressing system attribute aggregation ohm the attribute of the standard value.
- 4根据权利要求2所述的基于密钥分片的数据细粒度访问控制方法,其特征在于,步骤Ib)所述的数据拥有者DO采用CP-ABE加密共享数据,生成密文C,按如下步骤进行:1bl)根据数值S、Sp a、tj、明文m和群Gci的生成元g,计算中间变量Cci, C1, cJ; 1: 其中,g是群Gtl的一个生成元,Zp是阶为P的整数域,s是Zp中随机选取值,m是明文,Y = e (g, g) a为双线性映射,a是Zp中的随机选取值,Si为Zp中随机选取的值,i表示访问控制结构T中属性的序号,7}=/夂对于系统属性集合Ω = (&1,&2,一,&11),对每一个aj e Ω随机选择一个tj e Zp, j表不系统属性集合Ω中属性的下标值; lb2)根据中间变量Ctl, C1, Cj,i,得到密文c: 其中,a」」表不访问控制结构T中的属性,i表不访问控制结构T中属性的序号,j表不系统属性集合Ω中属性的下标值。 4. according to claim the based on key distribution sheet the data of the fine grain access control method wherein the step of ib the data owner uses do cp abe encrypted shared data to generate a cryptograph c carried out according to the following steps: 1bl according to the sp value s m and a tj ming-wen group gci generating unit g intermediate variable calculating cci- c1 cj;1: 4. Wherein g gtl group is one of the generating unit zp step is p is whole number of the s is zp randomly selecting ming-wen value m is y = g e a double linear mapping zp a random value is selected si zp randomly selecting expressed by i the value of access control structure of t in the character of the sequence number 7 } = or * on system attribute aggregation = ohm and a 1 2 and 11 to each aj e ohm randomly select a e j tj zp surface and system of attribute aggregation ohm the attribute of the standard value;Lb2 according to the intermediate variable ctl c1 cj i to get cryptogram c: 4. E-mail the e-mail of a surface and access control structure of t the attribute of i surface and access control structure of t in the character of the sequence number j surface and system of attribute aggregation ohm the attribute of the standard value.
Independent claims3
167 paragraphs, as filed
The technical field of
[0001] this invention belongs to information security technology field especially claims a data access control method can be used to storage yun service in a user visiting shared data of a scene the data owner defined user to visiting shared data of the fine grit access control.
Background technology
[0002] connected with the internet and yun computer technology xing-qi in the opening of the environment in the data to share the requirement of the club and the daily increased. Yun memory is gauze counting the whole system in the important basis of service facility yun storage to high reliability low cost and convenience for storing service realizes gexin. With the same time the yun environment data in safety problem also becomes yun calculating the user as the centre of a core it solves the problem that.
[0003] yun calculating the user data stored in the cloud end so it eliminates the data the control of any to the data access control can be completely rely yun service provider csp the invention is the user of the worry about. Because of the csp can be as the commercial benefit it is not followed or the meaning is yun storage platform access control mechanism obtaining user the valuable information.
[0004] on the csp is not completely safe and credible under the condition of the data of the privacy is introduced into the cryptograph of the access control is very necessary with. Of the traditional symmetrical key mechanism and asymmetric key mechanism for realizing access control is possible by but its access control granularity the authorization and it is lack of flexibility. If he yun end of the user data to carry out fine particle size of the access control to present a hot gate research problem.
0005 ] and [ sahai performance liquid based on the identity of the encryption ibe mechanism on the basis of the invention claims based on attribute of the encryption abe mechanism. Abe mechanism the data owner it only needs according to attribute of the encrypted data and it does not need to pay attention to the user group the number of identity and reduces the data encryption overhead and protect user privacy and it accords with the file attribute access structure requirement the group member decrypting it can ensure the data confidential. The more important is that abe mechanism for supporting flexibly of the access control strategy it can realize the property of the threshold or not and operation. Of the existing abe mechanism that can be divided into two kinds of: Based on strategy of the key kp abe mechanism and based on the text policy the cp abe mechanism.
[0006] kp abe mechanism user cryptographic key and the access control policy related with a pair of cipher text attribute aggregation only related with the group properties it satisfies the requirement of user access structure of the user only can decipher cryptogram. Kp abe mechanism it has the following characteristics: Access control the active using right is accessing user; Accessing user according to the received message to the requirement of it is suitable for inquiry category of the application such as paying television system video frequency ordering program system and so on.
[0007] cp abe mechanism confidential file and access control policy related data owner will give accessing user distributing a group property user key and the group property only related with the group property satisfies access control structure of the user only can decipher cryptogram. Cp abe it has the following characteristics: Access control the active using right in the data owner; Data owner predetermined encrypted file access strategy and it is suitable for access control type application such as social network access and.
[0008] in practical application user group which may be facing to the member or the properties of the frequent changing so that it introduces how it can effectively cancel user or cancelling attribute of the problem that also adopts abe mechanism to carry out yun terminal user data to fine granularity access control of the necessary to solve the problem of.
[0009] shucheng yu cong wang kui ren and wenjing lou such as human between achieving the secure scalable and fine grained data access control in cloud computing a file the invention claims a method for using kp abe and proxy heavy encryption method of combining utility model claims a fine granularity access under the control of users and attributes of effectively cancel the article the surface of the computer communication international meeting inf 0c0 m 2010 on the main idea is: By using symmetrical encryption algorithm for original data is encrypted and then using kp abe the data encryption key to encrypt so as to realize the data key of the fine grit access control. When the system is set in the user cancelling when operating it can not only can avoid the ground to the data key to be encrypted and the weight is to access the user to perform property of key updating and re-distribute. The method following problems:
[0010] in the whole procedure of method in the data encryption key and there is no renewing the original data is not encrypts again the safety hidden trouble.
[0011] 2 is set at the user terminal accessing user through the sealing a cryptographic text can recover the original data key because of the existing of safety hidden trouble will cause the user even it is cancelling the access authority is still can be used one time for resuming the data key decrypting original code.
The content of invention
Between 0012 ] the purpose of this invention is aiming at the existing technology the shortage of the invention claims a based on key sheet the data of the fine grain access control method so as to assure that the access to data safety.
[0013] the technology scheme of the invention is realized like this:
[0014] technology principle:
[0015] in order to solve yun end of the data shared fine granularity access control in scene the safety problem of the invention adopts based on attribute of the encryption machine to realize the fine grain access control and using attributes key distribution sheet of realizing share data security protecting.
[0016] the scheme comprises two parts:
[0017] using based on attribute of the encryption machine to realize the shared data of the fine grit access control. This proposal adopts the cp abe encryption machine which is made by the data owner is data defining a plurality of attribute aggregation and a controlling access structure and for access user and distributes a attribute aggregation. Data owner encrypted shared data encrypted with the access control structure of relevant. Authorization issue mechanism belonging to key to access the user attribute key and accessing the user data has attribution concentration relative. When it only when accessing user has the data of the attribute aggregation satisfies the data defining the access of the structure of the user can decipher cryptogram obtained original data.
[0018] 2 using attributes key distribution sheet of realizing share data security protecting. The project is introduced in the middle of the half trust proxy mechanism belongs to key is divided into two parts are separately composed of a trusted agent and accessing user keeping. The middle of the half trust proxy mechanism to be legal user for the cryptograph of the initial processing access the user can use the own and the other part is cipher key to decrypt the processing result so as to make the access the user does not obtain complete and it belongs to the key under the condition that it still can be used for visiting shared data.
[0019] second symbol and abbreviate
[0020] m is shared data;
0021 c ] [ the data owner do encryption original document after the encrypted;
0022 t ] [ the data owner do encrypted shared data of m access control structure;
0023 c ] [ ' is a reliable agent mechanism for processing confidential file c the of the middle result;
[0024] aa the attribute of authority;
[0025] pk the attribute of authority generates public key of aa;
[0026] mk the attribute of authority aa generated by the main key;
[0027] w the data owner do for access user distribution attribute aggregation;
[0028] iu the data owner to access generated by user unique identity;
[0029] ska ! u: 1 is the first attribute private key;
[0030] sk0ilui2 the first and second attribute private key;
[0031] w or the data owner do is to group accessing user randomly selecting one of the minimum attribute aggregation;
[0032] terminal group as the access of user visiting state is a boolean variable;
[0033] w '' to the shared attribute cancelling time again selecting the smallest attribute aggregation;
[0034] ohm to the system attribute aggregation;
[0035] bj system is set in the attribute;
[0036] g0 is designed into is p the product of the method of cyclic group;
[0037] or g is group gtl one of the generating unit;
[0038] zp is designed into p is integer of;
0039 a t ] [ e-mail s si uj zp is in the random number;
[0040] aj; I to access control structure of the attribute of i t represents access control structure of t in the character of the sequence number j expressing system attribute aggregation ohm the attribute of the standard value;
[0041] d0 belongs to the private key public part of the;
[0042] cl e-mail ! d e-mail 2 the attribute of attribute of the private key part;
[0043] e g utility model claims a linear mapping.
[0044] three realization steps:
[0045] according to said theory the realization of this invention comprises following steps as follows:
[0046] based on key distribution sheet the data of the fine grain access control method comprises the following steps:
[0047] data owner do encrypted shared data:
[0048] ia attribute authority aa and generate a master key mk and public key pk and the public key pk sending it to the data owner do;
[0049] ib data owner do as shared data mark distributing a group property and an access control structure of t and the shared data by the cp m abe for encrypting to get cryptogram c;
[0050] ic data owner do the encrypted file c at yun service provider csp;
[0051] new users join into an access group:
[0052] 2a when the new users join into an time data has to do it distributes one attribute aggregation w and unique identity iu;
[0053] 2b data owner do calculating attribute aggregation in the omega with attribute satisfy the access control structure of t the attribute of the compounding and ensure that the attribute combination properties of integrity;
[0054] 2c data owner do according to the calculated the attribute combination gather in the inner part is formed by the user list and the new user access state state value is able to visit the state of true;
[0055] 2d data owner do the new user satisfies the access control structure of t the attribute of the combination of new user number and visiting state terminal access state value can be true and it can be sent to a proxy signal mechanism and randomly selecting property compounding one of the attribute combination w to a proxy signal mechanism can be;
[0056] 2e new user is on the attribute aggregation w and unique identity iu to the attribute of authority *** attribute authority aa generating two to the attribute private key 4 ton *** sfcww in the first and the attribute private key to a reliable agent mechanism to keep the second attribute private key 2 to the new user to pipe;
[0057] 2f tower a reliable agent mechanism according to said data owner sending the attribute of the combined w attribute combination number of the access state state values and attribute authority aa sent by the first attribute private key power l in the inner part is formed by the access control list;
[0058] accessing group user visiting shared data:
] and [ 0059 accessing group user from yun service provider csp to get cryptogram c and the encrypted file c and a sole identity iu to a reliable agent mechanism a reliable agent verification mechanism for accessing group user identity if the access state terminal access state can be true and it satisfies access control structure an attribute of the combined amount is less than 0 then using the first attribute the private key c is transformed into cipher text in the middle of the processing result c 2' and the middle of the processing result c 2' sending accessing group user;
[0060] 3b accessing group user using the second attribute private key # 2 u w and decryption the middle of the processing result c 2' so as to obtain the initial ming-wen m;
[0061] access of a group of user cancelling:
[0062] 4a if the data owner do is stopped accessing group of some user visiting shared data owner can do is to cancel the accessing group user in the inner part of the user list in the access state state value is updated to control the access state false;
[0063] 4b data owner do is to cancel the accessing group user the access state state value can be sent to a proxy signal mechanism;
[0064] 4c a reliable agent mechanism according to the cancelling the access of the group of the user access state the state value of its access control list to cancel of the user access state is updated to control the access state false signal can be prevented a proxy mechanism is to cancel accessing group user process cipher text a conversion processing;
[0065] shared data property cancelling:
[0066] 5a data owner do update the inner part of the user list to the accessing group user cancelling containing attribute the attribute combination and deleting the new counting the group user satisfies the access control structure of t the attribute combination number;
[0067] 5b data owner do the updated the attribute combination number can be sent to a proxy signal mechanism and randomly selecting property compounding one of the attribute combination w '' to a proxy signal mechanism can be;
[0068] 5c a reliable agent mechanism according to the data owner do sending the attribute of the combined w '' and the attribute combination number updating in the inner part of the access control list.
[0069] this invention compared with existing technology has the advantages as follows:
[0070] the first security strong.
[0071] this invention uses the attribute of the key are chip technology to realize accessing group user does not obtain complete and it belongs to the key under the condition of decrypts the cryptograph it ensures the data shared high security.
[0072] of the second motor tightness high.
[0073] this invention uses the credible proxy mechanism the access control list and it ensures that the access control structure of t of high confidentiality.
[0074] the third calculation amount of.
[0075] this invention uses the attribute of the key are chip technology to make the accessing group user does not obtain complete and it belongs to the key so as to cancel accessing group user the data owner do not need to the new encrypted shared data ming-wen.
Specification attached drawing
[0076] picture 1 is the invention the total flow chart;
[0077] picture 2 in the invention in data has to do encryption for data sharing electronic flow chart;
[0078] picture 3 is in the invention new users join into an access group of the electronic flow chart;
[0079] drawing 4 the invention the accessing group user visiting shared data flow chart of the subsidiary;
0080 image ] [ 5 is in this invention access group of user cancelling the rotor of flow chart;
[0081] picture 6 is in the invention belongs to shared data and cancelling the rotor of flow chart.
Specific implementing manner
[0082] a lower surface through the attached drawing and specific implementing manner to further explain the invention embodiment.
[0083] with reference to figure 1 the invention claims the realizing steps are as follows:
[0084] step i data owner do encrypted shared data.
[0085] reference image the step can be specifically as follows:
[0086] la attribute authority aa and generate a master key mk and public key pk represented as follows;
[0087]
<img id="idf0001" file="CN104022869AD00101.tif" img-content="drawing" img-format="tif" />
[0089] gtl is in the step is p the product of the method of cyclic group g gtl group is one of the g1 generation unit as q is step the product of the method of cyclic group e is the double linear gtlxgtl ^ e g g1 ° is double linear mapping zp step is p is whole number of region a is 25 in the randomly selecting value corresponding to the system attribute aggregation ohm = a1; A2 '' ^ an to a e-mail e ohm randomly select a e-mail zp t e j expressing system attribute aggregation ohm the attribute of the standard value;
[0090] ib data owner from the system do attribute aggregation ohm selects a subset as shared data of m attribute aggregation;
[0091] ic data owner do as shared data mark define one access control structure of t:
[0092] icl access control structure of t is a tree structure of the leaf node as the data owner from the system do attribute aggregation ohm selected subset of the element;
[0093] lc2 access control structure of t and the leaf node is a group of the data owner do defined relationship operation symbols or it comprises the threshold and so on and it is used for controlling the accessing group user to the shared data of m access.
[0094] id data owner do encrypted shared data to generate a cryptograph c m:
[0095] idl according to the sp value s m a t e-mail ming-wen and group gtl generating unit g intermediate variable calculating cq c1 cj; 1:
[0096] c0 = gs
[0097] c1 m = ys/t michael e = g as
0098 chi = t ] [ 1 = cgtos ^
[0099] wherein g gtl group is one of the generating unit zp step is p is whole number of the s is zp randomly selecting ming-wen value m is y = g e a double linear mapping z11 a random value is selected si zp randomly selecting expressed by i the value of access control structure of t in the character of the sequence number 7 } = or *** on system attribute aggregation ohm = ai a2
A e-mail e ohm randomly select a e j tj zp surface and system of attribute aggregation ohm the attribute of the standard value;
[0100] ld2 according to the intermediate variable cq c1 cj i to get cryptogram c:
<img id="idf0002" file="CN104022869AD00102.tif" img-content="drawing" img-format="tif" />
[0102] the ap represents access control structure of the attribute of i t represents access control structure of t in the character of the sequence number j expressing system attribute aggregation ohm the attribute of the standard value;
[0103] ie data owner do the encrypted file c at yun service provider csp.
V- 0104 ] [ step 2 new users join into an access group.
[0105] reference picture 3 the step can be specifically as follows:
[0106] 2a new user request access;
[0107] 2b data owner do as new user and distributes a attribute aggregation w and unique identity iu;
[0108] 2c data owner do calculating attribute aggregation w satisfy the access control structure of t the attribute of the combined:
[0109] to the attribute aggregation w in the element attribute data owner do according to access control structure of t the attribute of logic relation calculating these property satisfies access control structure of the attribute combination wherein the attribute combination it must be that satisfy the access control structure of t the minimal assembly which;
[0110] 2d data owner do according to the calculated the attribute combination gather in the inner part is formed by the user list and the new user access state state value is able to visit the state of true;
[0111] 2e data owner do the attribute aggregation w and unique identity iu to new user the user access related information to a proxy signal mechanism can be;
[0112] 2f attribute authority output as new user to generate the first attribute awu *** private key and the second attribute private key skaiiu
[0113] 2fl computer secret key public part of the dq
[0114] is d0 = ga uid
[0115] wherein g gtl group is one of the generating unit zp step is p is whole number of region a zp is randomly selecting value uid is 25 randomly selecting value;
[0116] 2f2 calculation of the private key attribute part wherein cljj2
<img id="idf0003" file="CN104022869AD00111.tif" img-content="drawing" img-format="tif" />
0119 ] and [ system in attribution concentration and an ohm a = 2 to a e-mail e ohm randomly select a tj zp e j expressing system attribute aggregation ohm the attribute of the standard value omega is the data owner do are assigned to the access group of the user attribute aggregation for each attribute is a e w uj zp is randomly selecting value;
[0120] 2f3 private key according to public part of the cltl and attribute part dm 7 2 to obtain the first attribute private key *** # e-mail and the second belongs to the private key 2:
<img id="idf0004" file="CN104022869AD00112.tif" img-content="drawing" img-format="tif" />
[0123] wherein omega is the data owner do are assigned to the access group of the user attribute aggregation;
[0124] 2g attribute authority aa the first attribute private key is 0 or ***: 1 to a reliable agent mechanism the second attribute private key
2 to new user;
[0125] for 2 hours a reliable agent mechanism to form access control list:
[0126] half trust proxy mechanism according to said data owner do sending the attribute of the combined w attribute combination number of the access state state values and attribute authority aa sent by the first attribute private key and omega and *** in the inner part is formed by the access control list.
[0127] step 3 accessing group user visiting shared data.
[0128] reference picture 4 the step can be specifically as follows:
] and [ 0129 accessing group user is on the encrypted file c and a sole identity iu to a reliable agent;
[0130] 3b if accessing group user attribute for and meet the access control structure of t carrying out from; Or else returns error access authority;
[0131] from a trusted agent c the encrypted text is converted into the middle of the processing result c 2' sending accessing group user to execute 3d
[0132] the middle of the processing result or represented as follows c:
<img id="idf0005" file="CN104022869AD00121.tif" img-content="drawing" img-format="tif" />
[0134] zp the step is p is whole number of the omega ' is a data owner can do to a proxy signal mechanism the attribute of the combination of each attribute is a e w ' uj zp is randomly selecting value = tj gtj zp si as randomly selecting the value of
Expressed by i access control structure of t in the character of the sequence number g gtl group is one of the generating unit to system attribute aggregation ohm = a1; A2 and an e-mail to each a e ohm randomly select a e j t e-mail zp surface and system of attribute aggregation ohm in the bottom of the tag attribute value e and g
<img id="idf0006" file="CN104022869AD00122.tif" img-content="drawing" img-format="tif" />
Is double linear mapping;
[0135] 3d accessing group user encrypting to get plaintext c or m:
[0136] accessing group user using the second attribute private key to decrypt the middle of the processing result c 2' so as to obtain the initial ming-wen m
Carried out according to the following steps:
[0137] 3bi calculated intermediate variable c '':
<img id="idf0007" file="CN104022869AD00123.tif" img-content="drawing" img-format="tif" />
[0139] zp the step is p is whole number of the omega ' is a data owner can do to a proxy signal mechanism the attribute of the combination of each attribute a e-mail w e ' uj and uid zp is randomly selecting value = tj gti zp si as randomly selecting expressed by i the value of access control structure of t in the character of the sequence number g gtl group is one of the generating unit to system attribute aggregation ohm = a1; A2 and an e-mail to each a e ohm randomly select a e j t e-mail zp surface and system of attribute aggregation ohm the attribute of the standard value e and g
<img id="idf0008" file="CN104022869AD00124.tif" img-content="drawing" img-format="tif" />
Is double linear mapping;
[0140] 3b2 intermediate variable calculating cm
<img id="idf0009" file="CN104022869AD00131.tif" img-content="drawing" img-format="tif" />
[0142] the c l is encrypted file c part of the private key is d0 public part of the c ' is a proxy signal mechanism can be transformed in the middle of the processing result c '' juice as the result of intermediate variable zp step is p is integer number s and the alpha is zp randomly selecting value e gs ga and the double linear mapping;
[0143] 3b3 according to the intermediate variable cni to get plaintext m
<img id="idf0010" file="CN104022869AD00132.tif" img-content="drawing" img-format="tif" />
[0145] c1 is the encrypted file c a component of cffl to the calculated intermediate variable zp step is p is integer number of s and a zp randomly selecting value e gs ° g and g e utility model claims a linear mapping.
[0146] step 4 access of a group of user cancelling.
[0147] 5 reference image the step can be specifically as follows:
[0148] 4a if the data owner do is stopped accessing group of some user visiting shared data owner can do is to cancel the accessing group user in the inner part of the user list in the access state state value is updated to control the access state false;
[0149] 4b data owner do is to cancel the accessing group user the access state state value can be sent to a proxy signal mechanism;
[0150] 4c a reliable agent mechanism according to the cancelling the access of the group of the user access state the state value of its access control list to cancel of the user access state is updated to control the access state false signal can be prevented a proxy mechanism is to cancel accessing group user process cipher text a conversion processing.
[0151] step 5 share data property cancelling.
[0152] with reference to figure 6 this step can be specifically as follows:
[0153] 5a data owner do update the inner part of the user list to the accessing group user cancelling containing attribute the attribute of the combination of deleting;
[0154] 5b data owner do the new counting the group user satisfies the access control structure of t the attribute combination number;
[0155] 5c data owner do the updated the attribute combination number can be sent to a proxy signal mechanism and randomly selecting property compounding one of the attribute combination w '' to a proxy signal mechanism can be;
[0156] 5d a reliable agent mechanism according to the data owner do sending the attribute of the combined w '' and the attribute combination number updating in the inner part of the access control list.
23 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23
Every citation, both waysCites: the store holds 3 of 4
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN113179270A | Cited by | China | – | Search report | – |
| CN109246096A | Cited by | China | – | Search report | – |
| CN104320393A | Cited by | China | – | Search report | – |
| CN108880801A | Cited by | China | – | Search report | – |
| CN106452735A | Cited by | China | – | Search report | – |
| US10797865B2 | Cited by | United States of America | – | Applicant | – |
| CN111641636A | Cited by | China | – | Search report | – |
| CN111008855A | Cited by | China | – | Search report | – |
| US11095437B2 | Cited by | United States of America | – | Applicant | – |
| CN105681355A | Cited by | China | – | Search report | – |
| CN109889494A | Cited by | China | – | Search report | – |
| US10873449B2 | Cited by | United States of America | – | Applicant | – |
| WO2020143131A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| CN106612271A | Cited by | China | – | Search report | – |
| CN111723385A | Cited by | China | – | Search report | – |
| CN107465505A | Cited by | China | – | Search report | – |
| US11356250B2 | Cited by | United States of America | – | Applicant | – |
| CN108400871A | Cited by | China | – | Search report | – |
| CN102916954A | Cites | China | A | Search report | 1-7 |
| CN103179114A | Cites | China | A | Search report | 1-7 |
| WO2011045723A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1-7 |
| JAHID S,MITTAL P ,BORISOV N,EASIER: "encryption -based access control in social networks with efficient revocation", 《COMPUTER AND COMMUNICATIONS SECURITY》 | Non-patent | – | – | Search report | – |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201410269762 | China | A | |
| CN20141269762 | – | – | – |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Termination of patent right due to non-payment of annual feeCF01 | CF01 | |
| Patent grantGrantedGR01 | GR01 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 104022869
- Publication, DOCDB
- 104022869
- Publication, EPODOC
- CN104022869
- Application
- 102697621
- Application, DOCDB
- 201410269762
- Application, EPODOC
- CN20141269762
Titles3
- English
- Based on key sheet the data of the fine grain access control method
- Chinese
- 基于密钥分片的数据细粒度访问控制方法
- English
- Fine-grained data access control method based on fragmenting of secret keys
Classification
- IPC, 2
- H04L9 08
- H04L29 06