CN104022869A

Fine-grained data access control method based on fragmenting of secret keys

Abstract

The invention claims a based on key distribution sheet the data of the fine grain access control method which mainly solves the problem that existing technology the safety is low and operation problem of the large quantity of the. The realizing steps are as follows: Data owner to the shared data encrypting to get cryptogram; Attribute authority for accessing group user generates two belongs to the private key are respectively sent to a reliable agent mechanism and accessing group user; When accessing group user satisfies the access control structure when a reliable agent mechanism is used for the first attribute private key cipher text to the middle of the result of accessing group user by the second attribute private key to decrypt the middle result to obtain the data shared; Using attributes private key slicing techniques controlling and accessing group user obtains the incomplete belongs to the key the data owner the executing cancelling after the operation and does not need to new encrypted shared data. The invention can be shared data the invention claims fine particles of the access control it improves the security can be used in cloud terminal shared data access control the lower part of the shared data access.

CN104022869A, drawing sheet 1
Sheet 1 of 23

Term

7.7 yearsto projected expiry

Projected expiry 17 June 2034, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

14 claims: 10 independent, 4 dependent

  1. 1
    based on key distribution sheet the data of the fine grain access control method comprises the following steps:Data owner do encrypted shared data to get cryptogram c: New users join into an access group: 2a when the new users join into an time data has to do it distributes one attribute aggregation w and unique identity iu;2b data owner do calculating attribute aggregation in the omega with attribute satisfy the access control structure of t the attribute of the compounding and ensure that the attribute combination properties of integrity;2c data owner do according to the calculated the attribute combination gather in the inner part is formed by the user list and the new user access state state value is able to visit the state of true;2d data owner do the new user satisfies the access control structure of t the attribute of the combination of new user number and visiting state terminal access state value can be true and it can be sent to a proxy signal mechanism and randomly selecting property compounding one of the attribute combination w to a proxy signal mechanism can be;2e new user is on the attribute aggregation w and unique identity iu to the attribute of authority *** attribute authority aa it generates two belongs to the private key 2 and the first sfcwiu4 attribute private key to a reliable agent mechanism to keep the second *** attribute private key to the new user to pipe;2f tower a reliable agent pyo machine according to said data owner do sending the attribute of the combined w ' attribute combination number of the access state state values and attribute authority aa sent by the first attribute at the private key is formed in the access control list visit group user visiting shared data: 3a accessing group user from yun service provider csp to get cryptogram c and the encrypted file c and a sole identity iu to a reliable agent mechanism a reliable agent verification mechanism for accessing group user identity if the access state terminal access state can be true and it satisfies access control structure an attribute of the combined amount is less than 0 then using the first attribute the private key c is transformed into cipher text in the middle of the processing result c 2' and the middle of the processing result c 2' sending accessing group user;3b accessing group user using the second attribute private key to decrypt the middle of the processing result c 2' so as to obtain the initial ming-wen m;Access of a group of user cancelling: 4a if the data owner do is stopped accessing group of some user visiting shared data owner can do is to cancel the accessing group user in the inner part of the user list in the access state state value is updated to control the access state false;4b data owner do is to cancel the accessing group user the access state state value can be sent to a proxy signal mechanism;4c a reliable agent mechanism according to the cancelling the access of the group of the user access state the state value of its access control list to cancel of the user access state is updated to control the access state false signal can be prevented a proxy mechanism is to cancel accessing group user process cipher text a conversion processing;Shared data property cancelling: 5a data owner do update the inner part of the user list to the accessing group user cancelling containing attribute the attribute combination and deleting the new counting the group user satisfies the access control structure of t the attribute combination number;5b data owner do the updated the attribute combination number can be sent to a proxy signal mechanism and randomly selecting property compounding one of the attribute combination w '' to a proxy signal mechanism can be;5c a reliable agent mechanism according to the data owner do sending the attribute of the combined w '' and the attribute combination number updating in the inner part of the access control list. 1.一种基于密钥分片的数据细粒度访问控制方法,包括如下步骤: (1)数据拥有者DO加密共享数据,得到密文C: (2)新用户加入访问群组: 2a)当有新用户加入时,数据拥有者DO为其分配一个属性集合ω和唯一身份Iu ;2b)数据拥有者DO计算属性集合ω中所有属性满足访问控制结构T的属性组合集合,并保证这些属性组合中属性的完整性; 2c)数据拥有者DO根据上述计算出的属性组合集合在其内部形成用户列表,并置该新用户访问状态State值为可访问状态True ; 2d)数据拥有者DO将新用户满足访问控制结构T的属性组合数目和新用户访问状态State值可访问状态True发送至半可信代理机构,并且随机选取属性组合集合中的一个属性组合ω,发至半可信代理机构; 2e)新用户上传属性集合ω和唯一身份Iu至属性权威机构ΑΑ,属性权威机构AA为其生成两个属性私钥2,并将第一属性私钥Sfcwiu4发至半可信代理机构进行保管,将第二属性私钥ζ发至该新用户保管; 2f)半可信代理机杓根据上述数据拥有者DO发送的属性组合ω'、属性组合数目、访问状态State值和属性权威机构AA发送的第一属性私钥在其内部形成访问控制表 (3)访问群组用户访问共享数据: 3a)访问群组用户从云服务提供商CSP获取密文C,并将密文c和唯一身份Iu上传至半可信代理机构,半可信代理机构验证访问群组用户身份,若其访问状态State为可访问状态True,且满足访问控制结构的属性组合数目大于0,则使用第一属性私钥将密文c转化为中间处理结果c',并将中间处理结果c'发回访问群组用户; 3b)访问群组用户使用第二属性私钥解密中间处理结果c',得到原始明文m;(4)访问群组中的用户撤销: 4a)如果数据拥有者DO要禁止访问群组中某个用户访问共享数据,数据拥有者DO可将要撤销的访问群组用户在其内部用户列表中的访问状态State值更新为禁止访问状态False ; 4b)数据拥有者DO将要撤销的访问群组用户的访问状态State值发送至半可信代理机构; 4c)半可信代理机构根据要撤销的访问群组用户的访问状态State值,将其访问控制表中要撤销用户的访问状态更新为禁止访问状态False,禁止半可信代理机构为要撤销访问群组用户进行密文c的转化处理; (5)共享数据属性撤销: 5a)数据拥有者DO更新其内部的用户列表,将所有访问群组用户含有撤销属性的属性组合删除,且重新统计所有群组用户满足访问控制结构T的属性组合数目; 5b)数据拥有者DO将更新后的属性组合数目发送至半可信代理机构,并且随机选取属性组合集合中的一个属性组合ω"发至半可信代理机构; 5c)半可信代理机构根据数据拥有者DO发送的属性组合ω"和属性组合数目更新其内部的访问控制表。
  2. 3
    According to claim the based on key distribution sheet the data of the fine grain access control method wherein said step ia generating master key mk and public key pk represented as follows:3.根据权利要求2所述的基于密钥分片的数据细粒度访问控制方法,其特征在于,所述步骤Ia)生成的主密钥mk和公钥pk,表示如下: 其中,G0是阶为P的乘法循环群,g是群Gtl的一个生成元,G1是阶为q的乘法循环群,e是双线性对hXh — Gpefe’gK为双线性映射,Zp是阶为P的整数域,a是Zp*的随机选取值,对于系统属性集合Ω = (a1;a2,…,an),对每一个a」e Ω随机选择一个t」e Zp, j表示系统属性集合Ω中属性的下标值。 3. G0 is in the step is p the product of the method of cyclic group g gtl group is one of the g1 generation unit as q is step the product of the method of cyclic group e is the double linear hxh gpefe or gk as the double linear mapping zp step is p is integer of a zp * the randomly selecting value corresponding to the system attribute aggregation ohm = a1;A2 and an e-mail to each a e ohm randomly select a e-mail zp t e j expressing system attribute aggregation ohm the attribute of the standard value.
  3. 4
    根据权利要求2所述的基于密钥分片的数据细粒度访问控制方法,其特征在于,步骤Ib)所述的数据拥有者DO采用CP-ABE加密共享数据,生成密文C,按如下步骤进行:1bl)根据数值S、Sp a、tj、明文m和群Gci的生成元g,计算中间变量Cci, C1, cJ; 1: 其中,g是群Gtl的一个生成元,Zp是阶为P的整数域,s是Zp中随机选取值,m是明文,Y = e (g, g) a为双线性映射,a是Zp中的随机选取值,Si为Zp中随机选取的值,i表示访问控制结构T中属性的序号,7}=/夂对于系统属性集合Ω = (&1,&2,一,&11),对每一个aj e Ω随机选择一个tj e Zp, j表不系统属性集合Ω中属性的下标值; lb2)根据中间变量Ctl, C1, Cj,i,得到密文c: 其中,a」」表不访问控制结构T中的属性,i表不访问控制结构T中属性的序号,j表不系统属性集合Ω中属性的下标值。 4. according to claim the based on key distribution sheet the data of the fine grain access control method wherein the step of ib the data owner uses do cp abe encrypted shared data to generate a cryptograph c carried out according to the following steps: 1bl according to the sp value s m and a tj ming-wen group gci generating unit g intermediate variable calculating cci- c1 cj;1: 4. Wherein g gtl group is one of the generating unit zp step is p is whole number of the s is zp randomly selecting ming-wen value m is y = g e a double linear mapping zp a random value is selected si zp randomly selecting expressed by i the value of access control structure of t in the character of the sequence number 7 } = or * on system attribute aggregation = ohm and a 1 2 and 11 to each aj e ohm randomly select a e j tj zp surface and system of attribute aggregation ohm the attribute of the standard value;Lb2 according to the intermediate variable ctl c1 cj i to get cryptogram c: 4. E-mail the e-mail of a surface and access control structure of t the attribute of i surface and access control structure of t in the character of the sequence number j surface and system of attribute aggregation ohm the attribute of the standard value.