Data access control system and method
Abstract
A data access control system and method. First, the master key is divided into n sub-keys to n sub-key custodians by secret sharing. The master key reorganization program can use the secret shared with the sub-key custodians. To obtain the m (1 <m <n) sub-keys, and then recombine the master key according to the (m, n) -threshold strategy. The system then uses this master key to encrypt and decrypt the data to be kept secret. Therefore, m child keys must be obtained in order to reconstruct the master key to modify or read the data in the system. In this way, the confidentiality and security of the data in the system can be effectively protected, and when the custodian of the sub-key leaves or reassigns, only the sub-key needs to be replaced to reorganize the master key without having to replace the master key, which can reduce Changes to passwords affect access to ciphertext data.
Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
14 claims: 14 independent, 0 dependent
- 1526643 經濟部中央標準局員工消費合作社印製 Α8 Β8 C8 D8 六、申請專利範圍 法,其中之任意數Cl係由保管上述子金鑰f(Ci)之保管 者保管,且當該些保管者動態登入時,將所保管的對應 Ci傳送給該主金鑰重組程序。 6·如申請專利範圍第4項所述之安全控管資料存取方 法,其中該密碼爲[g〇〇f,t爲該些保管者登入次數, g(x)爲佈於該有限體的一多項式,kt爲一個亂數,可隨 t値不同而變,而其中該格式爲[f(x,i)]pt+[g(x)]kt(t+d),d 爲前述共享的秘密,f(x)= Σ f〇U)。 ^[Ι,η] 7·如申請專利範圍第2項所述之安全控管資料存取方 法,其中該啓動程序與主金鑰重組程序同步計數,所記 錄的該些保管者登入次數有相同値。 8· —種資料存取控管系統,用以存取一資料,此系統包 括: 一資料儲存媒體,儲存該資料; 一主金鑰,加解密該資料; 一子金鑰控管模組,將該主金鑰分成複數把第一子金 鑰,由複數保管者保管; 一主金繪重組模組’利用一保管者動態登入方式取得複 數把第二子金鐺,重組出該主金鑰;以及 一資料控管模組,利用從上述主金鑰重組模組重組出之 主金鑰,控管該資料儲存媒體中該資料的存取。 9.如申請專利範圍第8項所述之資料存取控管系統,其中 一保管者登入系統時,利用一啓動模組接收由該主金鑰 重組模組送出之一對應密碼,前述密碼係隨該保管者登 入次數而改變,且該啓動模組利用前述密碼、以及該主 金鑰重組模組與該保管者一共享的秘密,將該保管者所 保管的第一子金鑰以一格式包裝爲第二子金鑰,送回給 該主金鑰重組模組。 12 本紙張尺度適用中國國家標準(CNS ) Α4規格(210 X 297公釐) ----------苹 (請先閱讀背面之注意事項再填寫本頁) 訂 線 526643 Α8 Β8 C8 D8 經濟部中央標準局員工消費合作社印製 六、申讀專利範圍 10. 如申請專利範圍第9項所述之資料存取控管系統,其 中之該些第一子金输係利用一(^1,11)_門檻策略取得,m 爲大於1小於η的自然數,且該些第一子金鑰的個數 爲η,該些第二子金鑰的個數爲m。 11. 如申請專利範圍第10項所述之資料存取控管系統,其 中利用該(m,n)-門檻策略取得該些第一子金鑰時,包 括: 產生佈於一有限體GF(p)的一(m-1)次多項式f(x),ρ爲 一質數,且f(〇)爲上述之主金鑰;並 給定複數個互不相同的任意數A,I = 1,…,η,Cl e [1,...,p-1],得出該些第一子金鑰f(Ci)。 12. 如申請專利範圍第11項所述之資料存取控管系統,其 中之任意數4係由保管上述子金鑰f(Cl)之保管者保 管,且當該些保管者動態登入時,將所保管的對應q 傳送給該主金綸重組程序。 13. 如申請專利範圍第11項所述之資料存取控管系統,其 中該密碼爲[g(x)f,t爲該些保管者登入次數,g(x)爲 佈於該有限體的一多項式,心爲-^個亂數,可隨t値不 同而變,而其中該格式爲[f(x,〇]pt+[g(x)]kt(t+d),d爲前 述共享的秘密,f(x)= Σ f(x,0。 i e [1, η] 14. 如申請專利範圍第9項所述之資料存取控管系統,其 中該啓動模組與主金鑰重組模組同步計數,所記錄的 該些保管者登入次數有相同値。 (請先閱讀背面之注意事項再填寫本頁) -裝· 訂 12_ 本紙張尺度適用中國國家標準(CNS ) Α4規格(210Χ297公釐)
61 paragraphs, as filed
Data access control system and method
<p>11. . .System user</p><p>13. . .Internet</p><p>15. . .Data access control system</p><p>151. . .Storage processing unit</p><p>153. . .Data storage media</p><p>twenty one. . .Bookmaker</p><p>31. . .Master Key Reorganization Module</p><p>33. . .Child key custodian</p><p>331. . .Start the module</p><p>41. . .System user</p><p>43. . .Internet</p><p>45. . .Data access control system</p><p>451. . .Master Key Reorganization Module</p><p>453. . .Child key custodian</p><p>4531. . .Start the module</p><p>455. .Data Control Module</p><p>457. . .Data storage media</p>
Figure 1 shows a structure diagram of a conventional data access control system;
Figure 2 shows a structure diagram of a secret multi-person reorganization system;
FIG. 3 is a schematic diagram of a dynamic login function according to a preferred embodiment of the present invention; and
FIG. 4 is a structural diagram according to a preferred embodiment of the present invention.
The invention relates to a data access control system and method. <sub>,</sub> In particular, the invention relates to a system and method for improving data access security by using secret sharing and dynamic password login functions.
Due to the rapid development of computer and storage media technology, various systems access data electronically, such as: online transactions, letter delivery, database, and electronic data transmission systems. As these activities become more and more popular and bring convenience to people, they also bring many problems, because after the information is electronicized, counterfeiting and tampering are more difficult to detect and track. Taking the bank transaction system as an example, the bank's credit card payment system stores the card number of the cardholder, each transaction and related personal data. If the bank does not have a good control process, the cardholder's personal privacy will not be protected, so It is necessary to encrypt important data to facilitate better control by management and to keep relevant personnel away from temptation.
As mentioned above, in order to protect the confidentiality of the data, the data must be encrypted. However, in a more general case, that is, if the data is only visible to those who should see it, we must consider the data manager (DataAdministrator) Whether all data should be accessible, and when the data manager is replaced, how can we ensure that the data is not accessed again by the original data manager, without changing too much ciphertext data. Such problems are commonly encountered in our general applications. For example: a server that does electronic transactions, its database must include the personal data of many cardholders, as well as a bank process. Control systems or data management systems, etc. They want to control data files so that one person can not complete all procedures, and easily access or change all data, especially when the data in these systems have the following characteristics:
1. The recorded data can represent the status of the process and should not be changed arbitrarily.
2. All or part of the information should not or should not be seen.
Please refer to FIG. 1 for a structure diagram of a conventional data access control system. When the system user 11 accesses the data online or locally, the input data will be sent to the data access control system 15 via the Internet 13 in Cipher Text mode or directly. The server or the storage processing unit 151 encrypts the data to be encrypted, and finally sends the data to the data storage medium 153 for storage. The storage processing unit 151 uses a key K to control data access in the system to protect the data in the system from being read by unauthorized persons. However, this key K is usually under the full control of the data administrator alone, which often leads to the following problems: (1) The data administrator can intervene in the normal processing flow without supervision and tamper or steal the data in the data storage medium.
(2) Because the key is completely controlled by one person, the selection of the key custodian staff will be troublesome.
(3) When the key custodian is the management level, the key may be entrusted to others for some reasons, which may easily lead to a dead end in the control process.
(4) When it is necessary to change the key (key custodian leaves or reassigns), all ciphertext information must be replaced, which will be quite time-consuming.
No. 5,764,767 to Beimel et al. Mentions a system for secret sharing. Please refer to FIG. 2A, which is a structure diagram of a multi-person sharing secret reorganization system. In this patent, in order to keep secrets from being exclusive to individuals, Dealer 21 uses a method proposed by Shamir and Blakley to divide Secret S (such as the password of a safe) into n sub-secrets (Secretshared S). <sub>i</sub> (i = 1 ~ n), combined with n keys (Key) K <sub>i</sub> For n Participants P <sub>i</sub> . Please refer to FIG. 2B, the key Ki is in turn n-1 Key Constituent k <img file="TW526643B_D0001.tif" /> (j = l ~ n-1), as participant Pi and other participants Pj (j <img file="TW526643B_D0002.tif" /> [1, n], j i) for communication. Please refer to Figure 2C. The step of reorganizing secret S is performed by n participants P. <sub>i</sub> Find m (1 <m <n) Participants P <img file="TW526643B_D0003.tif" /> (j <img file="TW526643B_D0004.tif" /> [1, m]), and thus m participants P <img file="TW526643B_D0005.tif" /> At least one of the participants P <img file="TW526643B_D0006.tif" /> (k <img file="TW526643B_D0007.tif" /> [1, n]) is executed as the recipient (Recipient). Recipient P <img file="TW526643B_D0008.tif" /> By other m-1 participants P <img file="TW526643B_D0009.tif" /> (j k) receive the encrypted sub-secret S <img file="TW526643B_D0010.tif" /> , After decrypting (Decrypted), use this m-1 sub-secrets S <img file="TW526643B_D0011.tif" /> And the child secret S <img file="TW526643B_D0012.tif" /> (Total m sub secrets S <sub>i</sub> ), The secret S can be reconstructed. Where this recipient P <img file="TW526643B_D0013.tif" /> Is to use the above n-1 to hold the secondary key k <img file="TW526643B_D0014.tif" /> To get this m-1 sub-secrets S <img file="TW526643B_D0015.tif" /> , And work on decryption.
The above-mentioned secret reorganization system mainly divides a secret data into multiple sub-secret data to provide multiple participants to share. Each participant must obtain the consent of other participants to obtain sufficient sub-secret information. Only then can the secret information be reorganized to achieve the purpose of protecting the secret information. However, the main purpose of this system is to avoid participants' exclusive private information. If one person's negligence will cause irreparable consequences, it is not designed for the system management level's access to secret data, and the recipient uses the secondary key to Other participants obtain encrypted sub-secrets. This encryption method does not change with different login times. If the system is restarted, it will be seen through repeated use.
In view of this, the main object of the present invention is to provide a data access control system and method, which divides a master key into several sub-keys for different sub-key custodians, which can decentralize the storage of the data administrator. Taking power to solve the above-mentioned problems, and the child key can also be packaged into a dynamic password to log in, which can further improve the security of the system.
According to the present invention, an access control system and method based on secret sharing is proposed, which is briefly described as follows: First, a master key is divided into n sub-keys to n different sub-key custodians. When fetching data, the master key recombination program needs to obtain m (1 <m <n) subkeys, and then reconstruct the master key according to the (m, n) -threshold scheme, and output it to the server. The server then uses this master key to access the ciphertext data. Therefore, anyone including the database administrator who wants to modify or read the data in the system must obtain m child keys to reorganize the master key. It can effectively protect the security of the data in the system, and when the sub-key custodian leaves or transfers, only the sub-key needs to be replaced, and the master key can still be reorganized, because the master key does not have to be replaced, so the change of the password to the original can be reduced. Impact of ciphertext data.
In addition, when the system wants to access the data, the master key reorganization program can also use the secret shared with the sub-key custodian and use the dynamic login function to obtain m (1 <m <n) sub-keys.
In order to make the objects, features, and advantages of the present invention more comprehensible, a preferred embodiment is given below in conjunction with the accompanying drawings for detailed description as follows:
Schematic illustration
Figure 1 shows a structure diagram of a conventional data access control system;
Figure 2 shows a structure diagram of a secret multi-person reorganization system;
FIG. 3 is a schematic diagram of a dynamic login function according to a preferred embodiment of the present invention; and
FIG. 4 is a structural diagram according to a preferred embodiment of the present invention.
Explanation of main component symbols
11. . .System user
13. . .Internet
15. . .Data access control system
151. . .Storage processing unit
153. . .Data storage media
twenty one. . .Bookmaker
31. . .Master Key Reorganization Module
33. . .Child key custodian
331. . .Start the module
41. . .System user
43. . .Internet
45. . .Data access control system
451. . .Master Key Reorganization Module
453. . .Child key custodian
4531. . .Start the module
455. .Data Control Module
457. . .Data storage media
Preferred embodiment
This embodiment assumes that a data management system uses a master key to control access to data. According to the secret sharing method, this master key is divided into multiple sub-keys and distributed to multiple custodians for safekeeping. The system must obtain more than two sub-keys to reconstruct the master key. The number n of sub-keys used to reconstruct the master key is set by the system.
Given arbitrary numbers c different from each other <sub>i</sub> , i = 1, ..., n, c <sub>i</sub><img file="TW526643B_D0016.tif" /> [1, ..., p-1], using the (m, n) -threshold strategy proposed by Shamir and Blakley, to generate a (m-1) degree polynomial f (x), 1 <m <n, where f ( x) distributed in FiniteField GF (p), where p is a prime number, the system hides the master key in the constant term f (0), so that n child keys f (c <sub>i</sub> ), i = l, ..., n. This (ml) degree polynomial f (x) can be expressed as follows:
<maths><img file="TW526643B_D0017.tif" /></maths>
Where mod is the congruence operator, b <sub>o</sub> , Bi 0, b <sub>i</sub><img file="TW526643B_D0018.tif" /> [l, ..., pl].
The system will f (c <sub>i</sub> ) Is distributed to n child key custodians, and f (c) must be obtained by at least m child key custodians to obtain the master key. <sub>i</sub> ) And c <sub>i</sub> , And ci can be stored by the ith child key custodian or directly in the system. Then use Lagrang's interpolation theorem to obtain f (x) to obtain the master key f (0), as shown in formula (1), and this m value is the threshold value of the (m, n) -threshold strategy (Threshold Value ), This value can be determined by the system in advance.
<maths><img file="TW526643B_D0019.tif" /></maths>
Furthermore, since the above-mentioned data storage system requires multiple operations (such as restarting the system), if the system has the function of dynamic login, the security of the data in the system can be more protected.
Please refer to FIG. 3, which is a schematic diagram of a dynamic login function according to a preferred embodiment of the present invention. First, the master key reorganization module 31 (or master key reorganization program) sends the t-th password [g (x)] <sup>kt</sup> , Where g (x) is the element of GF (p), which is the secret shared by the child key custodian 33 and the master key reorganization module 31 in advance, k <sub>t</sub> It is a random number, which can be changed with the value t of the sub-key login times to achieve the function of confidentiality. Next, the i-th sub-key custodian 33 uses an activation module 331 (or a startup program), such as a smart card, to copy the i-th sub-key f (c <sub>i</sub> ) Is packaged into another polynomial H (x, i, t) greater than m times, as shown in formulas (2), (3), and returned to the master key reconstruction module 31, where d is a sufficiently large number Such that in the known [g (x)] <sup>kt (t + d)</sup> In the case of trying to solve d, it becomes a discrete logarithm problem (DLP), which is also the secret shared by the sub-key custodian 33 and the master key reorganization module 31, and the activation module 331 and the master key The number of reorganization modules 31 is Synchronism, that is, the recorded t values are the same. Finally, the master key reconstruction module 31 first obtains m polynomials H (x, i, t) (i <img file="TW526643B_D0020.tif" /> [l, n]), find the sum, and then follow the formula (4) and the previous password [g (x)] <sup>kt</sup> And the number of times t, deducting the g (x) part, the function f (x) = <img file="TW526643B_D0021.tif" /> f (x, i) to obtain the master key f (0), where formula (4) follows the characteristics of finite bodies.
<maths><img file="TW526643B_D0022.tif" /></maths>
<maths><img file="TW526643B_D0023.tif" /></maths>
<maths><img file="TW526643B_D0024.tif" /></maths>
Please refer to FIG. 4, which is a structural diagram of a preferred embodiment of the present invention. When the system is started, the master key reorganization module 451 (or program) uses the dynamic login method described above to obtain them from m (l <m <n) child key custodians 453 through the startup module 4531 (or program). The stored sub-key is returned to f (x) by using formula (l) to obtain the main key K (that is, the value of f (0)) and output it to the data control module 455 (or program). The module 455 obtains the master key K, and can control the access to the ciphertext data in the data storage medium 457, and the master key K only needs to be reorganized each time the system restarts. When the system user 41 wants to access data, the Internet 43 sends the input data to the data access control system 45 in cipher text or locally, and the data control module 455 then Use master key K to control access to ciphertext data.
Therefore, the features of the present invention are as follows: (1) The master key must be obtained with the consent of multiple sub-key custodians, which can prevent the management layer from tampering with or stealing the data in the system. And can effectively protect the security of the system.
(2) When the sub-key custodian leaves or transfers, only the sub-key needs to be replaced, and the master key does not need to be replaced, which can reduce the impact of changing the password on the ciphertext data.
(3) Use the dynamic password login method to obtain the sub-key. When the system needs to be used multiple times, the password can be avoided and the system's security can be more protected.
In summary, although the present invention has been disclosed as above with a preferred embodiment, it is not intended to limit the present invention. Any person skilled in the art can make various changes without departing from the spirit and scope of the present invention. With retouch.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP3671520A1 | Cited by | European Patent Office (EPO) | Applicant |
| US10873449B2 | Cited by | United States of America | Applicant |
| US11356250B2 | Cited by | United States of America | Applicant |
| US11095437B2 | Cited by | United States of America | Applicant |
| TWI686073B | Cited by | Taiwan Province of China | Examiner |
| US10158627B2 | Cited by | United States of America | Applicant |
| US9825943B2 | Cited by | United States of America | Applicant |
| US10797865B2 | Cited by | United States of America | Applicant |
2 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 88108252 | Taiwan Province of China | A | |
| TW19990108252 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| TW526643BThis record | Taiwan Province of China | B | |
| US6748084B1 | United States of America | B1 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Expiration of patent term of an invention patentMK4A | MK4A | |
| Issue of patent certificate for granted invention patentGrantedGD4A | GD4A |
Numbers
- Publication
- 526643
- Publication, DOCDB
- 526643
- Publication, EPODOC
- TW526643B
- Application
- 88108252
- Application, DOCDB
- 88108252
- Application, EPODOC
- TW19990108252
Titles4
- English
- Data access control system and method
- Chinese
- 資料存取控管系統及方法
- Unlabeled
- 資料存取控管系統及方法
- Unlabeled
- Data access control system and method
Classification
- CPC, 1
- H04L9/085
- IPC, 1
- H04L9 08