Cloud storage image privacy protection encryption method based on cross-plane dynamic grouping

Through the cross-plane dynamic packet encryption method, cloud storage images are preprocessed and permission tag construction are constructed, which solves the problem of insufficient adaptability of image encryption methods in cloud storage environments, realizes efficient access control and retrieval, and improves data security and convenience of use.

CN120343171APending Publication Date: 2025-07-18NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510610600.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing cloud storage image encryption methods have shortcomings in adaptability, access control, retrieval and visual semantic adjustment, and cannot meet the dynamic needs of cloud storage environments, resulting in limited data security and convenience of use.

Method used

The cross-plane dynamic packet encryption method is adopted to preprocess the image, and the ciphertext image structure containing permission tags and visual adjustment information is constructed, and uploaded to the cloud storage system through a secure transmission protocol to realize dynamic packet and permission control.

Benefits of technology

It improves the security and adaptability of encrypted images, supports access control and efficient retrieval for multiple users, and enhances data security and convenience in cloud storage environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120343171A_ABST
    Figure CN120343171A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud storage image privacy protection encryption method based on cross-plane dynamic grouping, and belongs to the technical field of information security and cloud storage. The method comprises the following steps: acquiring an image in a cloud storage environment, and preprocessing the image; encrypting the image by adopting a dynamic grouping cross-plane encryption method; constructing a ciphertext image structure containing permission labels and visual adjustment information and a data packet used for realizing access control and semantic hierarchical display; and uploading the ciphertext information to a cloud storage system through a secure transmission protocol. According to the method, dynamic grouping cross-plane encryption is adopted, so that the security of the encrypted image is improved, and security vulnerabilities caused by a fixed grouping mode are avoided; in combination with cloud storage, data access and authority control are adaptively optimized, so that different users can access corresponding encrypted data according to authorization levels, and the adaptability of the encryption method is improved; the effectiveness of local disturbance is improved through dynamic grouping, large information leakage is effectively avoided, and the data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical fields of information security and cloud storage, and particularly relates to a cloud storage image privacy protection encryption method based on cross-plane dynamic grouping. Background Art

[0002] With the rapid development of cloud computing, big data, and artificial intelligence technologies, cloud storage has gradually become an important way of modern data management. Especially in fields such as medical imaging, social media, intelligent monitoring, and e-government, a large amount of image data relies on cloud storage for efficient management. However, the security issues of image data in the cloud environment have become increasingly prominent, covering multiple aspects such as storage security, access control, and secure retrieval. Traditional image encryption technologies mainly rely on symmetric or asymmetric encryption algorithms such as AES, DES, and RSA. Although these methods perform well in the field of general data encryption, they expose many limitations in the cloud storage environment. For example, algorithms such as AES have a high computational complexity and are difficult to meet the real-time requirements of the cloud for large-scale data processing. In addition, these methods generally do not consider the special structure of image data, especially the encryption optimization of multi-channel information such as RGB, resulting in certain limitations in encryption efficiency and security. At the same time, most traditional encryption methods adopt a fixed key management mechanism, which cannot flexibly support the dynamic authorization requirements in the cloud storage environment, making data sharing and access control difficult.

[0003] In recent years, some local cross-plane image encryption methods have been proposed, which improve security by transforming different channels of images. However, in terms of the adaptability to the cloud storage environment, they still have certain deficiencies. First of all, most methods adopt a fixed grouping strategy and are vulnerable to known plaintext attacks during storage and transmission. Secondly, these methods lack optimization for cloud storage and are difficult to effectively support multi-user access control and key management, resulting in data security depending on static policies and being difficult to adapt to the changing requirements in the cloud environment. In addition, current encryption methods generally lack search encryption capabilities, and encrypted image data is difficult to be effectively retrieved without decryption, thus affecting data availability and storage efficiency. At the same time, existing methods are also relatively lacking in visual semantic adjustment and cannot provide partial visualization or blurring processing suitable for cloud application scenarios, restricting their applications in privacy protection computing, visual storage, etc.

[0004] In a cloud storage environment, data is usually stored on third-party servers, reducing users' physical control over the data and further exacerbating data security risks. Traditional encryption methods often fail to adapt well to this dynamic environment, mainly manifested by deficiencies in key management mechanisms, lack of data searchability, and lack of visual semantic adjustment capabilities. Current encryption schemes lack an effective dynamic key management mechanism and cannot implement attribute-based access control, making data security management complex. In addition, it is usually difficult to retrieve the content of encrypted images without decryption, which affects the storage efficiency and usability of the data. In practical applications, some users may hope to blur or partially hide encrypted images to meet different security requirements, but the existing methods still have limited support in this regard.

[0005] Therefore, in the case of many limitations in data sharing, access control, and retrieval conditions, how to solve the problem of insufficient adaptability of cloud storage image encryption methods, so as to improve the security and adaptability of cloud storage image encryption is the technical problem that the present invention wants to solve. Summary of the Invention

[0006] The purpose of the present invention is to provide a cloud storage image privacy protection encryption method based on cross-plane dynamic grouping to solve the problems raised in the above background technology.

[0007] The object of the present invention is achieved as follows: A cloud storage image privacy protection encryption method based on cross-plane dynamic grouping, characterized in that: the method includes the following steps:

[0008] Step S1: Obtain an image in a cloud storage environment and preprocess the image;

[0009] Step S2: Encrypt the image using a dynamic grouping cross-plane encryption method;

[0010] Step S3: Construct a ciphertext image structure containing permission tags and visual adjustment information for realizing data packets for access control and semantic hierarchical display;

[0011] Step S4: Upload the ciphertext information to the cloud storage system through a secure transmission protocol.

[0012] Preferably, in step S1, the preprocessing of the image is specifically:

[0013] Step S1-1: Uniformly standardize the input image, including: format conversion, size adjustment, and bit normalization;

[0014] Format conversion: Uniformly convert the input image into a standardized RGB three-channel format, ensuring that each pixel point is represented in the form of (x, y, z). If the image is in grayscale format, copy its grayscale value to the R, G, and B channels; if it contains an Alpha channel, remove the transparency information through weighted fusion. Specifically:

[0015] A color image consists of three channels: R, G, and B. Each channel is a two-dimensional numerical matrix, where each element value belongs to {0, 1, 2,..., 255};

[0016] A color image I with dimensions m×n is represented as:

[0017]

[0018] where p m,n where m = 1, 2, 3, 4... i, n = 1, 2, 3, 4... j;

[0019] p i,j =(x, y, z); p i,j indicates that this is the point at the i-th row and j-th column of the image. Each point is a vector:

[0020] In the formula, x, y, and z are the elements of the i-th row and j-th column of the R, G, and B channels respectively; each pixel point is represented as (x, y, z) ∈ Z256; corresponding to the grayscale values of the R, G, and B channels respectively, forming a three-dimensional structure image matrix with dimensions m×n;

[0021] Size adjustment: Uniformly resize to the preset standard size of 512×512 pixels;

[0022] Bit normalization: Standardize all image bit depths to 8-bit unsigned integer format, and map non-8-bit pixel values to the range of 0 to 255 through the normalization and quantization process;

[0023] Step S1-2: Use the local entropy and Canny edge detection algorithms to extract the texture complexity and structural boundary information of the local area of the image.

[0024] Preferably, in step S1-2, the local entropy and Canny edge detection algorithms are used to extract the texture complexity and structural boundary information of the local area of the image. Specifically:

[0025] Local entropy extraction: Divide the image into several small windows, and calculate the probability distribution of the grayscale values of the pixels in each window based on the Shannon entropy formula:

[0026]

[0027] where p iis the probability that the pixel grayscale value in the window is equal to iii, where iii ranges from 0 to 255;

[0028] Canny edge detection includes: performing a Gaussian filtering operation on the original image and convolving it with a Gaussian kernel of size 5×5;

[0029] Using the Sobel operator to calculate the gradient components of the image in the horizontal and vertical directions respectively, obtaining the gradient magnitude and direction of each pixel. The specific calculation method is:

[0030]

[0031] where G represents the edge strength and θ represents the edge direction angle, which is used to judge the edge trend; is the gradient value of the image in the horizontal direction; is the gradient value of the image in the vertical direction;

[0032] After obtaining the preliminary edge gradient information, perform non-maximum suppression operation: that is, check whether each pixel is a local maximum along the gradient direction. If not, set it to zero to retain the most accurate edge response;

[0033] Adopt a double-threshold strategy for edge judgment:

[0034] Set a high threshold value T H and a low threshold value T L , classify the pixels into strong edges, weak edges, and non-edges. Through the hysteresis connection method, only retain the weak edge pixels connected to the strong edges, and finally output a binary edge map;

[0035] Strong edges are G≥T H , weak edges are T L ≤G<T H , non-edges are G<T L ;

[0036] The edge map and the local entropy map jointly constitute the structural sensitive area identification of the image, guiding the subsequent grouping process of the dynamic encryption unit, so that the edge contour and high-complexity area of the image are encrypted preferentially;

[0037] Generate two guidance maps through local entropy and the Canny edge detection algorithm. One records the local entropy value distribution for dynamic encryption block size adjustment, and the other records the edge area for preferential encryption, forming a content-aware grouping basis.

[0038] Preferably, in step S2, the dynamic grouping cross-plane encryption method is used to encrypt the image. Specifically:

[0039] Step S2-1: Generate a key and perform segmentation;

[0040] Obtain a 256-bit key K. The key K is divided into two equal parts. One part is used to guide cross-plane substitution encryption, and the other part is used to generate a local permutation index matrix;

[0041] Generate a pseudo-random sequence based on the Logistic map to drive the construction of a random matrix:

[0042] x n+1 = r * x n *(1 - x n );

[0043] where x n is the state value of the current iteration step, with a value range of 0 < x n < 1, x n+1 is the value generated for the next iteration, which is a new pseudo-random number obtained by recurrence based on the current value, and r is the control parameter;

[0044] Step S2-2: Use the cross-plane encryption method to obtain new pixel points of the cross-channel mixed image;

[0045] Step S2-2-1: Select an original point p = (x, y, z), and calculate the sum s of the values of its elements, s = x + y + z;

[0046] Construct a triple set:

[0047] Φ s = {(x ′ , y ′ , z ′ ) ∈ (Z 256 ) 3 ∣ x ′ + y ′ + z ′ = s};

[0048] Step S2-2-2: Enumerate all points with the same sum of element values to form a set Φ s , which has π elements; The points in Φ s correspond one-to-one with the integers in the integer sequence from 1 to π - 1, and each point has an integer as its number, called the feature r;

[0049] Step S2-2-3: Introduce the function rank s (·) to extract features from points:

[0050]

[0051] τ b The expression of is:

[0052]

[0053] Among them, p1 represents the sum of x, y, and z, and p2 represents the number of channels;

[0054] Step S2-2-4: Calculate the rank value of all pixels in the image to form an index matrix R. Perform modulo addition operations on the corresponding elements between the index matrix R and Ω, and the operation result is the matrix Re, and perform modulo addition perturbation with Ω1:

[0055] R e (i,j)=(R(i,j)+Ω1(i,j))modπ(s);

[0056] Among them, Ω1 is a pseudo-random perturbation matrix, with the same dimension as the image, and is generated by key driving; R e (i,j) is the position index of the pixel in the encrypted space; R is the original rank value matrix, calculated by the function ranks(·);

[0057] Step S2-2-5: Regenerate three elements: Pass the result obtained from the matrix Re through The function calculates the new pixel value after perturbation to obtain the encrypted image Ies after replacement, specifically:

[0058] x = τ b (s,3)+t, where t is:

[0059]

[0060] The generation of y and z is:

[0061]

[0062] z = s - x - y;

[0063] Step S2-3: Perform image block segmentation on cross-plane pixels and construct a permutation index;

[0064] Step S2-4: Introduce spatial position perturbation to break the original spatial structure of the image.

[0065] Preferably, in step S2-3, performing image block segmentation on cross-plane pixels and constructing a permutation index specifically includes:

[0066] Step S2-3-1: Divide the encrypted image I e into several three-dimensional blocks of a fixed size, and the pixel set in each block forms a local encryption unit;

[0067] Step S2-3-: Use the Ω2 matrix to construct a local permutation index matrix Ω3, specifically:

[0068] The encrypted image Ies to be replaced is divided into several three-dimensional image blocks according to a fixed size of b×b×3. Each image block contains a vector group composed of b 2 ×3 pixel channel values and serves as an arrangement unit;

[0069] For each image block B k , relying on the corresponding sub-block in the generated pseudo-random perturbation matrix Ω2, extract the original values and perform ascending sorting to construct a unique perturbation index matrix Introduce the continuous integer set Λ = {1, 2,..., b 2 ×3} as the target rearrangement reference set;

[0070] Arrange the elements of each block in Ω2 in ascending order;

[0071] Introduce the integer set Λ = {1, 2,..., b·b·3};

[0072] Correspond the ascending sorting result with Λ, where the maximum value corresponds to the maximum number and the minimum value corresponds to 1;

[0073] Obtain the new index distribution Ω3 to guide the spatial permutation of pixels.

[0074] Preferably, in step S2-4, spatial position perturbation is introduced to break the original spatial structure of the image. Specifically:

[0075] Map the original pixel vector (x k , y i , z i ) in the image block B i to a new position sequence, and the rearrangement operation is performed simultaneously on three channels, that is:

[0076] Within each block, for all pixels in the R, G, and B channels, rearrange the positions in the order of ;

[0077] If , then the original i-th vector is moved to the j-th position.

[0078] Preferably, in step S3, a ciphertext image structure including a permission label and visual adjustment information is constructed. Specifically:

[0079] After encryption, the perturbed image matrix is encapsulated into a ciphertext image structure, which includes three parts of information:

[0080] Main ciphertext body: That is, the image data after perturbation, encoded in a standard image format, which is convenient for cloud compatibility transmission and decoding;

[0081] Permission tag field: Add a permission tag field to each image to record the access control level applicable to the image, so as to facilitate the verification and control of the permission matching module when accessing from the cloud;

[0082] Visual adjustment information: record the encryption degree parameters of the current image, the encryption degree parameters include the perturbation block α, α∈[0,1];

[0083] When α=1.0, all image blocks are perturbed to achieve full image encryption, and the image appears in a completely unreadable ciphertext state;

[0084] When α=0.5, only half of the image blocks are encrypted, retaining part of the original structure and presenting a semi-blurred image. Users can perceive the contour information but cannot recognize the specific content.

[0085] When α = 0.0, no disturbance is added, the image remains as it is, and is only used for testing or comparative experiments;

[0086] The selection of perturbation blocks is based on pseudo-random sequence control and is prioritized according to the complexity of the local structure of the image. Areas containing high-frequency textures or edge details are encrypted first, ensuring that the visual protection effect of the encrypted image is strong and the structural information is fully hidden under the same perturbation ratio.

[0087] Compared with the prior art, the present invention has the following improvements and advantages:

[0088] 1. By adopting dynamic grouping cross-plane encryption, the security of encrypted images is improved and security vulnerabilities caused by fixed grouping methods are avoided; combined with cloud storage adaptation to optimize data access and permission control, ensure that different users can access the corresponding encrypted data according to the authorization level, and improve the adaptability of the encryption method.

[0089] 2. The image is divided into encryption units through the security adaptation strategy of the cloud storage environment, and the unit size and position are dynamically adjusted to make the regional encryption granularity highly correlated with the content characteristics. Dynamic grouping not only improves the effectiveness of local perturbations, but also effectively avoids the leakage of large blocks of information, improves the robustness and anti-attack capabilities of the overall system, and thus further improves the security of the data.

[0090] 3. The method of the present invention has achieved breakthrough innovations in image structure division, encryption dynamics, multi-channel collaborative processing, cloud access control and visual availability protection, thereby significantly improving the overall security, flexibility and application universality of the system; at the same time, it supports efficient access control and search encryption, making encrypted images more practical in cloud environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0091] Figure 1 The figure is a schematic diagram of the overall process of the method of the present invention.

[0092] Figure 2 Schematic diagram of the encryption process after converting the image into a standardized data matrix. DETAILED DESCRIPTION

[0093] The present invention is further summarized below with reference to the accompanying drawings.

[0094] like Figure 1 As shown, a cloud storage image privacy protection encryption method based on cross-plane dynamic grouping includes the following steps:

[0095] Step S1: Obtain an image in a cloud storage environment and preprocess the image, specifically:

[0096] Step S1-1: uniformly standardize the input image, including:

[0097] Format conversion: Convert the input image into a standardized RGB three-channel format to ensure that each pixel is represented in the form of (x, y, z). If the image is in grayscale format, copy its grayscale value to the R, G, and B channels; if it contains an Alpha channel, remove transparent information through weighted fusion, as follows:

[0098] like Figure 2 As shown, a color image consists of three channels: R, G, and B. Each channel is a two-dimensional numerical matrix, in which each element value belongs to {0, 1, 2, ···, 255};

[0099] A color image I of size m×n is represented as:

[0100]

[0101] Among them, p m,n where m = 1, 2, 3, 4…i, n = 1, 2, 3, 4…j;

[0102] p i,j =(x,y,z);p i,j Indicates that this is the point on the i-th row and j-th column of the image, and each point is a vector:

[0103] Where x, y, z are the i-th row and j-th column elements of channels R, G, and B respectively; each pixel is represented by (x, y, z)∈Z256; corresponding to the grayscale values of the R, G, and B channels respectively, forming a three-dimensional structure image matrix of size m×n;

[0104] Adjust the structure of images in different formats such as JPEG, PNG, and BMP, and use bilinear or bicubic interpolation algorithms to unify them to a preset resolution to adapt to the division requirements of fixed encryption units; if the image is in grayscale format, copy its grayscale value to the R, G, and B channels; if it contains an Alpha channel, remove the transparency information through weighted fusion.

[0105] Size adjustment: Unify to the preset standard size of 512×512 pixels;

[0106] Bit normalization: To ensure the unity of pixel data, the bit depth of all images is standardized to 8-bit unsigned integer format, and non-8-bit pixel values are mapped to the range of 0 to 255 through the normalization and quantization processes;

[0107] For different channels of the image, break the local correlation through dynamic pixel replacement to improve the randomness of the encrypted data, thereby enhancing the ability to resist known plaintext attacks and statistical analysis attacks.

[0108] Through the above processing, a unified image representation foundation with consistent structure and numerical values is established, providing a reliable precondition guarantee for dynamic grouping and cross-plane encryption.

[0109] Step S1-2: Use local entropy and Canny edge detection algorithms to extract the texture complexity and structural boundary information of the local area of the image, specifically:

[0110] Local entropy extraction: Divide the image into several small windows, and calculate the gray distribution probability of pixels in each window based on the Shannon entropy formula:

[0111]

[0112] where p i is the probability that the pixel gray value in the window is equal to iii, and iii ranges from 0 to 255;

[0113] Canny edge detection includes: performing a Gaussian filtering operation on the original image and convolving it with a 5×5 Gaussian kernel;

[0114] Use the Sobel operator to calculate the gradient components of the image in the horizontal and vertical directions respectively to obtain the gradient magnitude and direction of each pixel table. The specific calculation method is:

[0115]

[0116] where G represents the edge strength, and θ represents the edge direction angle, which is used to judge the edge trend; is the gradient value of the image in the horizontal direction; is the gradient value of the image in the vertical direction;

[0117] After obtaining the preliminary edge gradient information, perform non-maximum suppression operation: that is, check whether each pixel is a local maximum along the gradient direction. If not, set it to zero to retain the most accurate edge response;

[0118] Adopt a double-threshold strategy for edge determination:

[0119] Set a high-sensitivity value T H and a low threshold T L , classify pixels into strong edges, weak edges, and non-edges. Through the hysteresis connection method, only retain the weak edge pixels connected to the strong edges, and finally output a binary edge map;

[0120] Strong edges are G≥T H , weak edges are T L ≤G<T H , non-edges are G<T L ;

[0121] The edge map and the local entropy map jointly constitute the structural sensitive area identification of the image, guiding the subsequent grouping process of the dynamic encryption unit, so that the edge contours and high-complexity regions of the image are encrypted preferentially;

[0122] Generate two guidance maps through the local entropy and the Canny edge detection algorithm. One records the local entropy value distribution for dynamic encryption block size adjustment, and the other records the edge region for preferential encryption, forming a content-aware grouping basis.

[0123] In step S2, a dynamic grouping cross-plane encryption method is used to encrypt the image. Specifically:

[0124] Step S2-1: Generate a key and perform segmentation;

[0125] Obtain a 256-bit key K. The key K is divided into two equal parts. One part is used to guide the cross-plane substitution encryption, and the other part is used to generate the local permutation index matrix;

[0126] Generate a pseudo-random sequence based on the Logistic map to drive the construction of the random matrix:

[0127] x n+1 =r*x n *(1-x n );

[0128] Among them, x n is the state value of the current iteration step, and its value range is 0<x n <1, x n+1 is the value generated in the next iteration and is a new pseudo-random number recursively obtained based on the current value. r is the control parameter;

[0129] In the replacement stage, the present invention application dynamically generates a pseudo-random sequence based on the lightweight chaotic map Logistic Map, combines the local characteristics of the encryption unit, and controls the cross-replacement of pixel values among the RGB three channels to break the problem of residual color correlation caused by traditional single-channel encryption. The local Arnold permutation is combined with cross-channel cross-perturbation to further increase the irregularity of pixel arrangement in the spatial distribution and enhance the unpredictability and resistance of the ciphertext image. Compared with the traditional method, CPDGE can achieve higher information entropy and more pixel diffusion effects under lower computational complexity, thus effectively improving the security strength of the system against statistical analysis attacks, known plaintext attacks, and differential attacks.

[0130] Step S2-2: Use the cross-plane encryption method to obtain new pixel points of the cross-channel mixed image;

[0131] Step S2-2-1: Select an original point p=(x, y, z), calculate the sum s of the values of its elements, s=x + y + z;

[0132] Construct a triple set:

[0133] φ s ={(x ′ ,y ′ ,z ′ )∈(Z 256 ) 3 ∣x ′ +y ′ +z ′ =s};

[0134] Step S2-2-2: Enumerate all points with the same sum of element values to form a set Φ s , which has π elements; The points in Φ s correspond one-to-one with the integers in the integer sequence from 1 to π - 1, and each point has an integer as its number, called the feature r;

[0135] Step S2-2-3: Introduce the function rank s (·) to extract features from points:

[0136]

[0137] τ b The expression of is:

[0138]

[0139] Among them, p1 represents the sum of x, y, and z, and p2 represents the number of channels;

[0140] Step S2-2-4: Calculate the rank value of all pixels in the image to form an index matrix R. Perform modulo addition operations on the corresponding elements between the index matrix R and Ω to obtain a matrix Re as the operation result, and perform modulo addition perturbation with Ω1:

[0141] R e (i,j) = (R(i,j) + Ω1(i,j)) mod π(s);

[0142] where Ω1 is a pseudo-random perturbation matrix with the same dimension as the image, generated by key driving; R e (i,j) is the position index of the pixel in the encrypted space; R is the original rank value matrix, calculated by the function ranks(·);

[0143] Step S2-2-5: Regenerate three elements: Pass the result obtained from the matrix Re through the function to calculate the new pixel value after perturbation to obtain the substitution-encrypted image Ies, specifically:

[0144] x = τ b (s,3) + t;

[0145] t is:

[0146]

[0147] The generation of y and z is:

[0148]

[0149] z = s - x - y;

[0150] Step S2-3: Perform image block segmentation on cross-plane pixels and construct permutation indexes;

[0151] Step S2-3-1: Divide the encrypted image I e into several three-dimensional blocks of a fixed size. The pixel set in each block forms a local encryption unit;

[0152] Step S2-3-2: Use the Ω2 matrix to construct a local permutation index matrix Ω3, specifically:

[0153] Divide the substitution-encrypted image Ies into several three-dimensional image blocks according to a fixed size of b×b×3. Each image block contains a vector group composed of b 2 ×3 pixel channel values as a permutation unit;

[0154] For each image block B k, relying on the corresponding sub-blocks in the generated pseudo-random perturbation matrix Ω2, extract the original values and sort them in ascending order to construct a unique perturbation index matrix Introduce the set of consecutive integers Λ = {1, 2,..., b 2 × 3} as the target rearrangement reference set;

[0155] Arrange the elements of each block in Ω2 in ascending order;

[0156] Introduce the set of integers Λ = {1, 2,…, b·b·3};

[0157] Correspond the ascending sorting result with Λ, with the maximum value corresponding to the largest number and the minimum value corresponding to 1;

[0158] Obtain the new index distribution Ω3 to guide the spatial permutation of pixels.

[0159] Step S2-4: Introduce spatial position perturbation to break the original spatial structure of the image.

[0160] Map the original pixel vector (x k , y i , z i , z i ) in the image block B to a new position sequence, and the rearrangement operation is performed simultaneously on three channels, that is:

[0161] Within each block, for all pixels in the R, G, and B channels, rearrange the positions in the order of ;

[0162] If then the original i-th vector is moved to the j-th position.

[0163] After the image is normalized, to meet the locality requirements of image encryption and the implementation of the spatial structure perturbation strategy, the image is structurally divided into multiple independently operable encryption units; the normalized three-channel image is divided into multiple three-dimensional image blocks of size b×b×3, such as 8×8×3; each image block contains b2 pixels, and each pixel is composed of the R, G, and B channel values together.

[0164] This block division strategy is essentially different from the common two-dimensional plane block division (such as single-channel 8×8 DCT blocks) in traditional image encryption methods: traditional methods often ignore the coupling between channels and only perform scrambling independently on a single color channel, making it easy for attackers to reconstruct information using color correlations. The three-dimensional block division strategy of the method of the present invention clearly binds the three color channels in one encryption unit, ensuring synchronous perturbation in the spatial dimension and color dimension during the encryption operation, thereby effectively destroying the structural redundancy of the original image and the statistical relationship between channels.

[0165] After the image is normalized, its parameters such as size, channel order, and bit depth are uniformly converted into a structured matrix format supported by the encryption module, and cross-plane grouping encryption is performed through the CPDGE mechanism to generate an image ciphertext with high perturbation and visual confusion; on this basis, an encapsulated ciphertext image structure is further constructed, which not only includes the main image ciphertext data body, but also includes an encrypted index segment generated by keywords, a permission attribute label, and an integrity check field;

[0166] In step S3, a ciphertext image structure including a permission label and visual adjustment information is constructed, specifically:

[0167] After encryption is completed, the perturbed image matrix is encapsulated into a ciphertext image structure, which includes three parts of information:

[0168] Main ciphertext body: That is, the image data after perturbation, encoded in a standard image format, which is convenient for cloud compatibility transmission and decoding;

[0169] Permission label field: Attach a permission label field to each image, record the access control level applicable to the image, and facilitate the call of the permission matching module for verification control during cloud access;

[0170] Visual adjustment information: Record the encryption degree parameter of the current image, and the encryption degree parameter includes the perturbation block α, α ∈ [0, 1];

[0171] When α = 1.0, all image blocks are perturbed to achieve full-image encryption, and the image presents a completely unreadable ciphertext state;

[0172] When α = 0.5, only half of the image blocks participate in encryption, retaining part of the original structure, presenting a semi-blurred image, and the user can perceive the contour information but cannot recognize the specific content;

[0173] When α = 0.0, no perturbation is added, and the image remains unchanged, only used for testing or comparative experiments;

[0174] The selection method of the perturbation block is controlled based on a pseudo-random sequence, and priority sorting is performed in combination with the local structure complexity of the image. Priority is given to encrypting areas containing high-frequency textures or edge details to ensure that under the same perturbation ratio, the visual protection effect of the encrypted image is strong and the structural information is hidden sufficiently.

[0175] The ciphertext image structure adopts a segmented design, which is not only convenient for the quick binding and parsing of encrypted information, but also provides data structure support for subsequent retrievability and permission control operations in the cloud.

[0176] After completing cross-plane replacement encryption and local pixel arrangement perturbation, the image \(I_{ep}\) generated by the system already has a high degree of pixel value and spatial structure perturbation. To achieve its secure and efficient storage and invocation in the cloud environment, in step S4 of the present invention application: the ciphertext information is uploaded to the cloud storage system through a secure transmission protocol, specifically as follows:

[0177] First, the system reorganizes the final perturbed image \(I_{ep}\) into a standard ciphertext image structure according to the unified image formats PNG and BMP. On the basis of maintaining the readability of the image, this structure facilitates compatibility between platforms and optimization of transmission efficiency. During the construction process, the system attaches the following types of metadata to enhance subsequent security and management capabilities:

[0178] Image integrity marker: The system calculates the hash value (such as SHA-256) of the main body of the ciphertext image and embeds it as a verification field in the image header or footer to detect whether the image has been damaged or tampered with during upload or storage;

[0179] Blur feature label: To support the visual semantic adjustment mechanism, the system records the encryption degree of the current image (such as the proportion of perturbed blocks) and writes it as a label into the metadata field to assist subsequent access judgment and image presentation optimization in the cloud;

[0180] Basic description information: including image size, color channel structure, perturbation type flag, etc., which is convenient for the cloud to quickly identify and classify and manage;

[0181] After construction, the system uploads the ciphertext image to the cloud server through the standard transmission protocol HTTPS. The upload process has the following functions:

[0182] Resume breakpoint mechanism: The system supports automatically resuming the unfinished part of the upload task according to the image block number after the transmission is interrupted, avoiding repeated transmission;

[0183] Multi-threaded concurrency mechanism: The ciphertext image is divided into blocks, and parallel threads are used for multi-path upload to improve the transmission efficiency of large images;

[0184] Transmission verification mechanism: Each upload segment has its own verification value, and the cloud server immediately conducts integrity comparison after receiving it to ensure the secure transmission of data;

[0185] After successful upload, the cloud platform classifies and stores the image into the corresponding directory structure according to the meta-information contained in the ciphertext image, and configures its access priority according to factors such as image encryption intensity and visual blur label.

[0186] Through systematic innovations in multiple core aspects such as image normalization processing, dynamic grouping mechanism, cross-plane encryption strategy, cloud adaptation architecture, and visual semantic protection mechanism, the present invention application has formed a brand-new encryption framework different from traditional image encryption schemes. This framework not only makes up for the defects of traditional methods in terms of dynamics, channel coupling, retrieval friendliness, and visual protection, but also has the engineering practice advantages of efficient computing, flexible deployment, and wide application, with outstanding technical innovation value and industrialization potential.

[0187] The above are only the embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, various changes and modifications can be made to the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. A cloud storage image privacy protection encryption method based on cross-plane dynamic grouping, characterized in that: The method comprises the following steps: Step S1: Acquire an image in a cloud storage environment and pre-process the image; Step S2: Encrypt the image using a dynamic grouping cross-plane encryption method; Step S3: construct a ciphertext image structure containing permission labels and visual adjustment information, which is used to implement access control and semantic hierarchical display of data packets; Step S4: Upload the encrypted information to the cloud storage system via a secure transmission protocol.

2. The cloud storage image privacy protection encryption method based on cross-plane dynamic grouping according to claim 1, characterized in that: In step S1, the image is preprocessed, specifically: Step S1-1: standardize the input image, including format conversion, size adjustment and bit normalization; Format conversion: Convert the input image into a standardized RGB three-channel format to ensure that each pixel is represented in the form of (x, y, z). If the image is in grayscale format, copy its grayscale value to the R, G, and B channels; if it contains an Alpha channel, remove transparent information through weighted fusion, as follows: A color image consists of three channels: R, G, and B. Each channel is a two-dimensional numerical matrix, in which each element value belongs to {0, 1, 2, ···, 255}; A color image I of size m×n is represented as: where p m,n where m = 1, 2, 3, 4...i and n = 1, 2, 3, 4...j; p i,j =(x, y, z); p i,j represents the point at the i-th row and j-th column of the image, and each point is a vector: Where x, y, z are the i-th row and j-th column elements of channels R, G, and B respectively; each pixel is represented by (x, y, z)∈Z256; corresponding to the grayscale values of the R, G, and B channels respectively, forming a three-dimensional structure image matrix of size m×n; Size adjustment: unified to the preset standard size of 512×512 pixels; Bit normalization: All image bit depths are standardized to 8-bit unsigned integer format, and non-8-bit pixel values are mapped to the range of 0 to 255 through normalization and quantization processes; Step S1-2: Using local entropy and Canny edge detection algorithm, extract the texture complexity and structural boundary information of the local area of the image.

3. The cloud storage image privacy protection encryption method based on cross-plane dynamic grouping according to claim 2, wherein: In step S1-2, local entropy and Canny edge detection algorithm are used to extract texture complexity and structural boundary information of the local area of the image, specifically: Local entropy extraction: Divide the image into several small windows, and calculate the grayscale distribution probability of pixels in each window based on the Shannon entropy formula: where p i is the probability that the pixel gray value within the window is equal to iii, and the value range of iii is from 0 to 255; Canny edge detection includes: performing Gaussian filtering operation on the original image and convolving with a Gaussian kernel of size 5×5; The Sobel operator is used to calculate the gradient components of the image in the horizontal and vertical directions respectively, and the gradient amplitude and direction of each image table are obtained. The specific calculation method is: Among them, G represents the edge strength, and θ represents the edge direction angle, which is used to judge the edge trend; is the gradient value of the image in the horizontal direction; is the gradient value of the image in the vertical direction; After obtaining the preliminary edge gradient information, a non-maximum suppression operation is performed: that is, each pixel is checked along the gradient direction to see if it is a local maximum. If not, it is set to zero to retain the most accurate edge response. Adopt double straight strategy for edge judgment: Set the high-sensitivity value T H and the low threshold T L , divide the pixels into strong edges, weak edges and non-edges, and through the hysteresis connection method, only retain the weak edge pixels connected to the strong edges, and finally output a binary edge map; Strong edges are G ≥ T H , weak edges are T L ≤ G < T H , non - edges are G < T L ; The edge map and the local entropy map are combined to form the structure-sensitive area identification of the image, which guides the grouping process of the subsequent dynamic encryption units, so that the edge contours and high-complexity areas of the image are encrypted first; Two guide maps are generated through local entropy and Canny edge detection algorithm. One maps records the local entropy value distribution for dynamic encryption block size adjustment, and the other maps records the edge area for priority encryption, forming a content-aware grouping basis.

4. A cloud storage image privacy protection encryption method based on cross-plane dynamic grouping according to claim 1, characterized in that: In step S2, the dynamic grouping cross-plane encryption method is used to encrypt the image, specifically as follows: Step S2-1: Generate a key and split it; Obtain a 256-bit key K. The key K is divided into two equal parts. One part is used to guide cross-plane substitution encryption, and the other part is used to generate a local permutation index matrix; Generate a pseudo-random sequence based on the Logistic map to drive the construction of a random matrix: x n+1 = r * x n * (1 - x n ) where x n is the state value of the current iteration step, and its value range is 0 < x n < 1, and x n+1 is the value generated in the next iteration, which is a new pseudo-random number obtained by recurrence based on the current value, and r is the control parameter; Step S2-2: Use the cross-plane encryption method to obtain new pixel points of the cross-channel mixed image; Step S2-2-1: Select an original point p = (x, y, z), and calculate the sum s of the values of its elements, s = x + y + z; Construct a triple set: Φ s = {(x ′ , y ′ , z ′ ) ∈ (Z 256 ) 3 | x ′ + y ′ + z ′ = s}; Step S2-2-2: Enumerate all points with the same element value to form a set Φ s , which has π elements; the points in Φ s are in one-to-one correspondence with the integers in the integer sequence from 1 to π - 1, and each point has an integer as its number, called feature r; Step S2-2-3: Introduce the function rank s (·), which is used to extract features from points: τ b The expression for: Among them, p1 represents the sum of x, y, and z, and p2 represents the number of channels; Step S2-2-4: Calculate the rank value of all pixels in the image to form an index matrix R. The corresponding elements between the index matrix R and Ω perform modulo addition operations to obtain the operation result as matrix Re, and perform modulo addition perturbation with Ω1: R e (i, j) = (R(i, j) + Ω1(i, j)) mod π(s); Among them, Ω1 is a pseudo-random perturbation matrix with the same dimension as the image, which is generated by key driving; R e (i, j) is the position index of the pixel in the encrypted space; R is the original rank value matrix, which is calculated by the function ranks(·); Step S2-2-5: Regenerate the three elements: Pass the result obtained from matrix Re through the function to calculate the new pixel values after perturbation, obtaining the encrypted image Ies after replacement, specifically: x = τ b (s,3)+t; t is: The generation of y and z is as follows: z = s - x - y; Step S2-3: Perform image block segmentation on the cross-plane pixels and construct a permutation index; Step S2-4: Introduce spatial position perturbation to break the original spatial structure of the image.

5. The cloud storage image privacy protection encryption method based on cross-plane dynamic grouping according to claim 4, characterized in that: In step S2-3, the cross-plane pixels are segmented into image blocks and a permutation index is constructed, specifically as follows: Step S2-3-1: Divide the encrypted image I e into a number of three-dimensional blocks of a fixed size, and the set of pixels in each block forms a local encryption unit; Step S2-3-2: Use the Ω2 matrix to construct a local permutation index matrix Ω3, specifically: The encrypted image Ies to be replaced is divided into several three-dimensional image blocks according to a fixed size of b×b×3. Each image block contains a vector group composed of b 2 ×3 pixel channel values and serves as an arrangement unit; For each image block B k , relying on the corresponding sub-block in the generated pseudo-random perturbation matrix Ω2, the original values are extracted and sorted in ascending order to construct a unique perturbation index matrix Introduce a set of consecutive integers Λ = {1, 2,..., b 2 ×3} as the target rearrangement reference set; Arrange the elements of each block in Ω2 in ascending order; Introduce the integer set Λ = {1, 2,..., b·b·3}; Correspond the ascending sorting result with Λ, with the maximum value corresponding to the maximum number and the minimum value corresponding to 1; Obtain a new index distribution Ω3 to guide the spatial permutation of pixels.

6. A cloud storage image privacy protection encryption method based on cross-plane dynamic grouping according to claim 4, characterized in that: In step S2-4, spatial position perturbation is introduced to break the original spatial structure of the image, specifically: Map the original pixel vector (x k , y i , z i ) in the image block B to a new position sequence, and the rearrangement operation is performed simultaneously on three channels, i.e.: i ​ Within each block, for all pixels in the R, G, and B channels, rearrange their positions in the order specified by ; If then the original $i$-th vector is moved to the $j$-th position.

7. A cloud storage image privacy protection encryption method based on cross-plane dynamic grouping according to claim 1, characterized in that: In step S3, a ciphertext image structure containing permission tags and visual adjustment information is constructed, specifically: After encryption, the perturbed image matrix is encapsulated into a ciphertext image structure. The ciphertext image structure contains three parts of information: Main ciphertext body: That is, the image data after perturbation, encoded in a standard image format, which is convenient for cloud compatibility transmission and decoding; Permission tag field: Add a permission tag field to each image to record the access control level applicable to the image, which is convenient for calling the permission matching module for verification control during cloud access; Visual adjustment information: Record the encryption degree parameter of the current image. The encryption degree parameter includes the perturbation block α, α ∈ [0, 1]; When α = 1.0, all image blocks are perturbed to achieve full-image encryption, and the image presents a completely unreadable ciphertext state; When α = 0.5, only half of the image blocks participate in encryption, retaining part of the original structure, presenting a semi-blurred image. The user can perceive the contour information but cannot recognize the specific content; When α = 0.0, no perturbation is added, and the image remains unchanged, which is only used for testing or comparative experiments; The selection method of the perturbation blocks is controlled based on a pseudo-random sequence, and priority sorting is performed in combination with the local structure complexity of the image. Areas containing high-frequency textures or edge details are preferentially encrypted, ensuring that under the same perturbation ratio, the visual protection effect of the encrypted image is strong and the structural information is sufficiently hidden.

Citation Information

Cited By

  • Ultra-deep diaphragm wall construction dynamic supervision method and system based on Internet of Things

    CN121262235A

  • A privacy protection task allocation method and system for mobile group cognitive perception

    CN122554230A

  • A privacy protection task allocation method and system for mobile group cognitive perception

    CN122554230B