Lightweight safe formation method for mobile intelligent nodes

Through the combination of IPFS and Groth16 zk-SNARK, the lightweight and secure formation of mobile smart nodes is realized, and the problem of low efficiency of public key distribution and verification is solved. It supports anonymity and efficient verification of cross-domain formations, and improves the scalability and stability of the system.

CN120474713AActive Publication Date: 2025-08-12CHANGCHUN UNIV OF SCI & TECH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510801720.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-08-12
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

In the prior art, the public key distribution and verification of mobile smart nodes are inefficient, the signature and signature verification overhead are large, and the cross-domain identity is easily associated, making it difficult to meet the needs of real-time fleet reconstruction and efficient and secure communication.

Method used

Using IPFS-based decentralized public key distribution, Groth16 zk-SNARK's public key holding proof, cross-domain one-time regional anonymous identification update, short-ring aggregation signature and efficient batch signature verification, including system initialization, public key legality verification, cross-domain authentication and regional identification update, signature generation and release, signature verification and other steps, IPFS storage and Groth16 zk-SNARK are used to construct non-interactive zero-knowledge proofs to generate and verify lightweight signatures.

Benefits of technology

It realizes secure distribution and rapid verification of public keys in an environment without centralized trust anchors, reduces communication and computing overhead, supports anonymous collaborative decision-making and efficient parallel verification in dynamic cross-regional fleets, and improves the scalability and operational stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474713A_ABST
    Figure CN120474713A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of safe formation of intelligent nodes, and discloses a lightweight safe formation method for mobile intelligent nodes. In the system initialization stage, elliptic curve publication parameters and an IPFS public key set are generated; in the public key legality verification stage, efficient holding certification is carried out on the anonymous public key based on Groth16zk-SNARK; in the cross-domain authentication stage, a one-time region temporary identifier is generated, and an IPFS set is updated; in the signature generation stage, a short-ring signature algorithm is adopted to construct an aggregation signature so as to support batch efficient signature verification; and extracting traceable factors to locate a real signer in the responsibility-traceable stage. The method gives consideration to node anonymity, light weight and responsibility traceability, and is suitable for resource-limited scenes such as the Internet of Vehicles and the Internet of Things.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent node security formation, and in particular to a lightweight security formation method for mobile intelligent nodes. Background Art

[0002] In recent years, with the rapid development of connected vehicles (VANETs), drone swarms, and multi-robot systems, mobile intelligent node formation technology has garnered widespread attention. Early research focused on formation maintenance and path planning based on centralized control, where formation commands are issued in real time by a central node or ground control station to achieve synchronized control of multiple nodes. However, as network scale and node numbers increase, these approaches suffer from high communication overhead and the risk of single points of failure. Subsequently, distributed formation control algorithms emerged, leveraging neighborhood information exchange and consensus protocols to maintain formation stability among nodes without a central controller. Furthermore, to enable rapid formation reconfiguration in dynamic environments, researchers have proposed formation decision-making methods based on graph theory, queueing theory, and graph neural networks, exploring node topology, formation transitions, and path planning. Cryptographic techniques such as PKI, public key exchange, group signatures, and ring signatures have been introduced to ensure the confidentiality, integrity, and authentication of inter-node communications, providing a secure foundation for formation decision-making and collaborative control.

[0003] While existing technologies have made some progress in distributed teaming and secure communication, several pressing challenges remain. First, most anonymous authentication schemes (such as group signatures and ring signatures) are unsuitable for mobile nodes with limited computing power and energy consumption due to their large signature size or computational complexity, making them difficult to meet the requirements of real-time teaming reconstruction. Second, when teaming across regions or subnets, there is still a lack of efficient and secure solutions for seamlessly switching node identities and dynamically updating team member information, making it difficult to ensure anonymity while also ensuring backward accountability. Furthermore, existing teaming verification mechanisms often rely on individual signature verification or centralized aggregation, lacking methods for rapid parallel verification of batch signatures or multiple messages, resulting in significant performance bottlenecks in large-scale collaborative scenarios. Furthermore, current teaming management security policies for node joining, exiting, and identity expiration are relatively simple, making it difficult to address complex threats such as replay attacks, identity impersonation, and fault hijacking. These deficiencies hinder the efficient teaming and secure communication performance of mobile intelligent nodes in multiple scenarios. Summary of the Invention

[0004] (1) Technical problems solved: In response to the shortcomings of the existing technology, the present invention provides a lightweight security formation method for mobile intelligent nodes, which has the advantages of decentralized public key distribution and management based on IPFS, efficient public key possession proof based on Groth16 zk-SNARK, cross-domain one-time regional anonymous identification and unrelated update, short-ring aggregate signature and efficient batch verification. It solves the problems of low efficiency of public key distribution and verification, high signature and verification overhead, and easy association of cross-domain identities in the existing technology.

[0005] (II) Technical Solution: To achieve the aforementioned IPFS-based decentralized public key distribution, Groth16 zk-SNARK public key possession proof, cross-domain one-time regional anonymous identity update, short-ring aggregate signature, and efficient batch signature verification, the present invention provides the following technical solution: a lightweight secure teaming method for mobile intelligent nodes, characterized by comprising: System initialization: The management party generates system public parameters and public reference strings; each mobile intelligent node generates a private key and an anonymous public key, which are published through the IPFS platform to form the current member public key set; Public key legitimacy verification: Each mobile intelligent node generates a public key possession certificate based on its own private key, and other nodes or roadside units in the formation verify the public key possession certificate to confirm the legitimacy of the anonymous public key; Cross-domain authentication and regional identity update: When the mobile intelligent node crosses the communication area, it sends an authentication request message to the roadside unit in the target area; after the roadside unit verifies the message, it generates a new regional anonymous identity for the mobile intelligent node and updates the regional anonymous identity set of the formation members; Signature generation and release: The signing node downloads the updated anonymous identification set of the formation member regions in the current region; constructs a formation structure based on the anonymous identification set of the formation member regions and generates an aggregate signature using a short ring signature algorithm; broadcasts the aggregate signature together with the message content; the aggregate signature includes a traceability factor, a response value, and a challenge value; Signature verification: The receiver verifies the aggregate signature using a ring signature verification algorithm; Accountable identity disclosure: When accountability is required, the authorized department extracts the traceable factor in the aggregated signature and locates the real signer through a mapping query on IPFS.

[0006] Furthermore, the mobile node deletes the locally expired anonymous identifier and public key information at a predetermined period, and pulls an updated public key set for replacement.

[0007] Furthermore, the public key possession proof is specifically a non-interactive zero-knowledge proof constructed based on Groth16 zk-SNARK.

[0008] Furthermore, the message includes a timestamp, a non-interactive zero-knowledge proof, an anonymous public key, a hardware fingerprint, an original area identifier, and a target area identifier.

[0009] Furthermore, after verifying the message, the roadside unit generates a new regional anonymous identifier for the mobile intelligent node, including: Check whether the timestamp is within a valid time window to prevent replay attacks; Verifying the non-interactive zero-knowledge proof based on the public reference string and the anonymous public key to confirm that the mobile intelligent node holds the corresponding private key; The anonymous public key, hardware fingerprint, and target area identifier are concatenated and hashed to generate an anonymous area identifier, which is then uploaded to IPFS, and the local area binding record of the roadside unit is updated.

[0010] Furthermore, constructing a formation structure based on the set of anonymous identifications of formation members and generating an aggregate signature using a short ring signature algorithm includes: The regional anonymous identification set of the formation members is regarded as the corresponding public key list to construct the formation structure, denoted as ; Calculate the traceability factor using the signer's private and public keys : ; In the formula, is the signer's private key; is the signer's public key; is a hash function that maps to elliptic curve points; The signer randomly selects a challenge value for each member of the formation except himself; The signer selects a random number and calculates a one-time commitment based on the system's public parameters. : ; In the formula, is a random number; It is a generator of the elliptic curve group; Calculate the initial challenge value based on the message, traceability factor and one-time commitment : ; In the formula, The signer's challenge value for the next position in the ring signature; is the hash function among the public parameters of the system; Message to be signed; It is a traceability factor; It’s a one-time commitment; is the byte string concatenation operator; Following the order of the members in the formation, the commitment value is reconstructed for each member and the subsequent challenge value is calculated, until the challenge value of the signer's position is obtained again to complete the closure of the challenge chain: ;In the formula, It is The commitment value corresponding to each member; It is Challenge value at each position; It is public keys of each member; It is Random response for each location; It is a generator of the elliptic curve group; It is New challenge value for each position; is the hash function among the public parameters of the system; Message to be signed; It is a traceability factor; is the byte string concatenation operator; Indicates the location of the signer Starting from the next member, the challenge chain is recursively passed to the previous position of the signer in the order of the formation, completing the closure of the entire challenge chain; Calculate the response value based on the sum of all challenge values: ;In the formula, is the number of members in the formation; It is Challenge value at each position; is a random number chosen randomly by the signer to generate a one-time commitment; is the signer's own private key scalar; is the order of the underlying elliptic curve group; Output contains traceability factors , a response value and The aggregate signature of the challenge value.

[0011] Furthermore, the ring signature verification algorithm includes: Reconstruct the commitment value of each member based on the challenge value and response value in the received aggregate signature; Recalculate each challenge value based on the reconstructed commitment value and a predefined hash function; Compare the recalculated challenge value with the challenge value in the aggregate signature one by one; When all comparisons pass, the output verification is successful, otherwise the output verification fails.

[0012] Furthermore, the authorization department can extract the traceability factor in the aggregate signature and locate the real signer through a mapping query on IPFS.

[0013] (III) Beneficial Effects: Compared with the prior art, the present invention provides a lightweight and secure formation method for mobile intelligent nodes, which has the following beneficial effects: 1. This lightweight secure teaming method for mobile intelligent nodes publishes the anonymous public keys generated by each mobile intelligent node to a decentralized storage network based on IPFS during the system initialization phase. During the public key legitimacy verification phase, a non-interactive zero-knowledge proof based on Groth16 is introduced to achieve secure distribution and rapid verification of public keys in an environment without a centralized trust anchor. This step utilizes IPFS's content addressing and distributed hash table mechanisms to ensure the high availability and tamper resistance of the public key set. At the same time, with Groth16's short, millisecond-level verification delay, resource-constrained mobile intelligent nodes can efficiently complete public key possession verification locally without exposing any identity information. This significantly reduces communication and computing overhead while ensuring anonymity, improving the system's scalability and operational stability.

[0014] 2. The lightweight secure formation method of the mobile intelligent node generates a new, unassociated regional pseudo-identity for the mobile intelligent node each time it enters a new area through cross-domain authentication and a one-time regional anonymous identification update step. In the signature generation and release phase, the formation structure is constructed based on the identification set, and a lightweight short-ring aggregate signature algorithm is used to generate the signature. Combined with the batch verification mechanism in the ring signature verification phase, anonymous collaborative decision-making and efficient parallel verification in dynamic cross-regional formations are realized. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 Flowchart of the lightweight security formation method for mobile intelligent nodes provided by the present invention; Figure 2 Schematic diagram of the lightweight security formation method for mobile intelligent nodes provided by the present invention; Figure 3 A comparison chart of the time consumption for signature generation of the lightweight secure formation method for mobile intelligent nodes provided by the present invention; Figure 4 A comparison chart of the signature verification time consumption of the lightweight security formation method for mobile intelligent nodes provided by the present invention; Figure 5 A comparison chart of signature lengths for the lightweight secure formation method for mobile intelligent nodes provided by the present invention. DETAILED DESCRIPTION

[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0017] See also Figure 1 A lightweight security formation method for mobile intelligent nodes, characterized by comprising: System initialization: The administrator generates system public parameters and a public reference string; each mobile intelligent node generates a private key and an anonymous public key, which are published through the IPFS platform to form the public key set of the current regional members; Public key legitimacy verification: Each mobile intelligent node generates a public key possession certificate based on its own private key, and other nodes or roadside units in the formation verify the public key possession certificate to confirm the legitimacy of the anonymous public key; Cross-domain authentication and regional identity update: When the mobile intelligent node crosses the communication area, it sends an authentication request message to the roadside unit in the target area; after the roadside unit verifies the message, it generates a new regional anonymous identity for the mobile intelligent node and updates the regional anonymous identity set of the formation members; Signature generation and release: The signing node downloads the updated anonymous identification set of the formation member regions in the current region; constructs a formation structure based on the anonymous identification set of the formation member regions and generates an aggregate signature using a short ring signature algorithm; broadcasts the aggregate signature together with the message content; the aggregate signature includes a traceability factor, a response value, and a challenge value; Signature Verification: The receiver verifies the aggregate signature using a ring signature verification algorithm.

[0018] This lightweight and secure platooning method targets typical scenarios involving mobile intelligent nodes interacting with roadside units (RSUs) and the IPFS network. The method primarily involves five phases: system initialization, public key validation, cross-domain authentication and regional identity update, signature generation and issuance, and signature verification. The platooning operation mode described in this invention requires the initial platooning deployment to sequentially execute these six phases. However, subsequent routine platooning maintenance only requires the execution of the four phases: public key validation, cross-domain authentication and regional identity update, signature generation and issuance, and signature verification.

[0019] During the system initialization phase, the management first generates the system public parameters in the formation control center, including the elliptic curve group parameters (curve equation, generator , group level ), hash function under the random oracle model Mapping Function , and a public reference string (CRS); then, each mobile intelligent node generates a unique private key locally based on the above public parameters and the corresponding anonymous public key , the node will Upload through IPFS to form a "current area member public key collection" document that can be accessed through IPNS or agreed path to ensure that all participants can obtain the latest public key list in a decentralized and highly available manner during the subsequent formation process.

[0020] During the public key legitimacy verification phase, each mobile intelligent node Based on private key and the predefined hash function in the system's public reference string, constructing a non-interactive zero-knowledge proof of possession through Groth16 ; Subsequently, the node Will contain the current timestamp , anonymous public key and proof The authentication request message is sent to the RSU in this area; after receiving it, the RSU first verifies Is it within the allowed time window to prevent replay attacks, then call Algorithm verification Confirm the correctness Only after obtaining a legal and unrevoked public key can the node be allowed to continue the subsequent formation process.

[0021] During the cross-domain authentication and regional identity update phase, the mobile intelligent node After entering the target area B, send an authentication request message containing the following fields to the roadside unit in area B: Current timestamp , non-interactive zero-knowledge proof based on private key generation , anonymous public key , PUF hardware fingerprint , original regional logo and target area identification ; After receiving the message, the roadside unit first verifies Is it within the preset valid time window to prevent replay attacks, and then call Verify the public key ownership certificate to confirm the node is legitimate; after verification, the roadside unit Calculate new region anonymous identifier , and will include all nodes in this area The collection file is uploaded to IPFS, and the anonymous identification mapping table of its formation member regions is updated at the same time for use in the subsequent signing and verification stages.

[0022] In the signature generation and release phase, the signing node first pulls the anonymous identification set of the team members in the current region from the IPFS platform and constructs the team structure based on the set; then, the node uses its own private key and public key Calculating the traceability factor , and generate a one-time commitment through the short ring signature algorithm , Challenge Value With the response value , thus obtaining the final aggregate signature ; Finally, the signing node will sign the aggregated signature With the formation action message to be released It is also broadcast to the roadside unit and other fleet members to achieve anonymous collaborative decision-making and subsequent efficient batch verification.

[0023] During the signature verification phase, the receiver will verify the information based on the system public parameters, formation public key list, and formation action instruction message. and the received aggregate signature , reconstruct the commitment value of each member , and recalculate the challenge value , then check each Is it equal to the signature , and verify the response value With all The cumulative relationship is established to confirm the integrity and legitimacy of the signature; after verification, the receiver accepts and processes the formation action instruction message, otherwise it refuses to receive it.

[0024] As a preferred embodiment, Figure 2 As shown, an embodiment of the present invention provides a lightweight security formation method for mobile intelligent nodes, which specifically includes the following steps: A lightweight security formation method for mobile intelligent nodes, characterized by including: System initialization: The administrator generates system public parameters and a public reference string; each mobile intelligent node generates a private key and an anonymous public key, which are published through the IPFS platform to form the public key set of the current regional members; Public key legitimacy verification: Each mobile intelligent node generates a public key possession certificate based on its own private key, and other nodes or roadside units in the formation verify the public key possession certificate to confirm the legitimacy of the anonymous public key; Cross-domain authentication and regional identity update: When the mobile intelligent node crosses the communication area, it sends an authentication request message to the roadside unit in the target area; after the roadside unit verifies the message, it generates a new regional anonymous identity for the mobile intelligent node and updates the regional anonymous identity set of the formation members; Signature generation and release: The signing node downloads the updated anonymous identification set of the formation member regions in the current region; constructs a formation structure based on the anonymous identification set of the formation member regions and generates an aggregate signature using a short ring signature algorithm; broadcasts the aggregate signature together with the message content; the aggregate signature includes a traceability factor, a response value, and a challenge value; Signature Verification: The receiver verifies the aggregate signature using a ring signature verification algorithm.

[0025] Furthermore, the mobile node deletes the locally expired anonymous identifier and public key information at a predetermined period, and pulls an updated public key set for replacement.

[0026] Specifically, during the regular local node maintenance phase, the system automatically triggers an update at midnight each day or when cache capacity exceeds a preset threshold. The node first scans the locally stored regional anonymous identifiers and public key information, deleting expired or revoked entries based on their respective generation timestamps to free up storage space and prevent the use of expired credentials. It then pulls the latest published public key collection file from a pre-configured IPFS address, verifies its integrity, and replaces the existing local cache. This ensures that mobile nodes always use the latest, legitimate key material while controlling local resource usage, achieving both lightweight and secure system optimization.

[0027] Furthermore, the public key possession proof is specifically a non-interactive zero-knowledge proof constructed based on Groth16 zk-SNARK. Specifically, in the public key possession proof generation phase, the mobile intelligent node first generates a Groth16 public-private key pair using the key ownership proof circuit corresponding to the anonymous public key in the trusted setup phase, and issues the generated verification key as part of the system's public reference string (CRS); subsequently, the node constructs a non-interactive zero-knowledge proof using Groth16 based on the CRS locally, and calculates a short proof data. , it only contains proof elements of a fixed size and can be verified without multiple rounds of interaction; Groth16 zk-SNARK has extremely low proof size and verification overhead while ensuring zero knowledge and soundness, and can run efficiently in mobile environments with limited computing power and bandwidth, thus taking into account the security, anonymity and lightweight requirements of the system.

[0028] Furthermore, the message includes a timestamp, a non-interactive zero-knowledge proof, an anonymous public key, a hardware fingerprint, an original area identifier, and a target area identifier.

[0029] Specifically, in the construction of the cross-domain authentication request message, the mobile intelligent node will use the current timestamp , Groth16 non-interactive zero-knowledge proof based on private key and public reference string , anonymous public key , PUF hardware fingerprint , original regional logo and target area identification This structured authentication request is packaged and sent to the RSU via a secure channel. A timestamp is introduced to defend against replay attacks, a zero-knowledge proof is used to verify the node's ownership of the public key without revealing the private key, an anonymous public key is used to identify the node while maintaining privacy, a hardware fingerprint is bound to the device's physical properties to prevent forgery of fake nodes, and the original and target region identifiers provide the necessary input for generating new temporary region identifiers and updating the IPFS collection. By carrying these multiple fields, the RSU can efficiently complete cross-domain legitimacy verification and one-time region identifier updates in a decentralized trust anchor environment, ensuring node anonymity, security, and accountability.

[0030] Furthermore, after verifying the message, the roadside unit generates a new regional anonymous identifier for the mobile intelligent node, including: checking whether the timestamp is within the valid time window to prevent replay attacks; verifying the non-interactive zero-knowledge proof based on the public reference string and the anonymous public key to confirm that the mobile intelligent node holds the corresponding private key; concatenating the anonymous public key, hardware fingerprint, and target area identifier, performing a hash operation to generate a regional anonymous identifier, and uploading the regional anonymous identifier to IPFS, while updating the local area binding record of the roadside unit.

[0031] Specifically, the roadside unit After completing cross-domain authentication, first verify the timestamp in the message Is it within the preset valid time window? To prevent replay attacks, call Non-interactive zero-knowledge proof Verify to confirm that the node actually holds the corresponding private key; then, Anonymous public key , PUF hardware fingerprint and target area identification according to Formula splicing and hashing to generate a new regional anonymous identifier ;at last, Will include all this area Upload the collection file to IPFS (for example, overwrite the / ipfs / regionB / member_list path) and use it in the local binding record. Replace the original identifier. On the one hand, the time window and zero-knowledge verification are used to double-guarantee the timeliness and legitimacy of cross-domain requests. On the other hand, the generated It is irreversible and one-time, and can be distributed with high availability in a decentralized storage network, while keeping node identities unlinkable and accountable.

[0032] Furthermore, constructing a formation structure based on the set of anonymous identifications of formation members and generating an aggregate signature using a short ring signature algorithm includes: The regional anonymous identification set of the formation members is regarded as the corresponding public key list to construct the formation structure, denoted as ; Calculate the traceability factor using the signer's private and public keys : ; In the formula, is the signer's private key; is the signer's public key; is a hash function that maps to elliptic curve points; The signer randomly selects a challenge value for each member of the formation except himself; The signer selects a random number and calculates a one-time commitment based on the system's public parameters. : ; In the formula, is a random number; It is a generator of the elliptic curve group; Calculate the initial challenge value based on the message, traceability factor and one-time commitment : ; In the formula, The signer's challenge value for the next position in the ring signature; is the hash function among the public parameters of the system; Message to be signed; It is a traceability factor; It’s a one-time commitment; is the byte string concatenation operator; Following the order of the members in the formation, the commitment value is reconstructed for each member and the subsequent challenge value is calculated, until the challenge value of the signer's position is obtained again to complete the closure of the challenge chain: ;In the formula, It is The commitment value corresponding to each member; It is Challenge value at each position; It is public keys of each member; It is Random response for each location; It is a generator of the elliptic curve group; It is New challenge value for each position; is the hash function among the public parameters of the system; Message to be signed; It is a traceability factor; is the byte string concatenation operator; Indicates the location of the signer Starting from the next member, the challenge chain is recursively passed to the previous position of the signer in the order of the formation, completing the closure of the entire challenge chain; Calculate the response value based on the sum of all challenge values: ;In the formula, is the number of members in the formation; It is Challenge value at each position; is a random number chosen randomly by the signer to generate a one-time commitment; is the signer's own private key scalar; is the order of the underlying elliptic curve group; Output contains traceability factors , a response value and The aggregate signature of the challenge value .

[0033] Specifically, the node will pull the temporary identification set of the region from IPFS Treated as a list of corresponding public keys Construct the formation structure; then, the signer uses his own private key and the mapping function in the public parameters Calculating the traceability factor , this factor can not only uniquely identify the signer in the subsequent accountability, but also does not affect the anonymity of the signature; then, the signer randomly selects a scalar based on the public parameters , and calculate the one-time commitment , and the signer is based on the message to be signed Calling the hash function Calculate the initial challenge value , ensuring that no member in the ring can know the starting point of the challenge chain in advance; then, the nodes reconstruct the commitments of each member in the order of the formation structure And calculate the subsequent challenge value until the loop is closed; this mechanism can simultaneously ensure the integrity and non-tampering of the signature; finally, the node obtains the response value by summing up all the challenge values , thereby obtaining an aggregate signature; while ensuring anonymity, accountability and signature integrity, this aggregate signature greatly compresses the signature size and supports parallel batch verification, achieving the beneficial effects of lightweight and high efficiency.

[0034] Furthermore, the ring signature verification algorithm includes: reconstructing the commitment value of each member based on the challenge value and response value in the received aggregate signature; recalculating each challenge value based on the reconstructed commitment value and a predefined hash function; comparing the recalculated challenge value with the challenge value in the aggregate signature one by one; when all comparisons pass, outputting verification success, otherwise outputting verification failure.

[0035] Specifically, according to the received aggregate signature Challenge value in and response values Reconstruct the commitment value of each member and restore the commitment node originally constructed by the signer: ; Then based on the reconstructed commitment value , formation action command message , and traceability factors , using a predefined hash function Recalculate each challenge value: ; Then recalculate the challenge value Original challenge value in the aggregate signature The signatures are compared one by one, and only when all comparisons are consistent can the signature be confirmed to be untampered and indeed signed by a legitimate member of the team. If all comparisons pass, the algorithm outputs "Verification Successful," and the recipient trusts the message and makes subsequent team decisions. If any comparison fails, the algorithm outputs "Verification Failed" and refuses to process the message to prevent forgery or tampering.

[0036] Furthermore, the authorization department can extract the traceability factor in the aggregate signature and locate the real signer through a mapping query on IPFS.

[0037] Specifically, the authorized department first accesses the traceability factor pre-published on IPFS To the anonymous public key The mapping index file, through Used as the query key to retrieve the corresponding anonymous public key ; Subsequently, the authorized department will To the real node identification mapping table, Convert to a mobile smart node The actual identity information of the node is kept; thus, the anonymity of the node signature is maintained in the public network, and only when authorized can the precise accountability for malicious or abnormal behavior be achieved by relying on the IPFS decentralized mapping and local filing system.

[0038] The embodiments of the present invention have achieved some positive results during the development or use process, and indeed have great advantages over the existing technology. The following content describes them in conjunction with data, charts, etc. from the experimental process.

[0039] like Figure 3 As shown in the figure, as the number of formation members increases from 2 to 128, the signature generation time of the LARRS method increases linearly from about 10ms to about 270ms, the DualRing method soars from about 15ms to 650ms, and the present invention always maintains a small fluctuation below 10ms (even at 128 nodes, it is only about 25ms). The present invention uses a single random commitment and a one-time response. Merging the signatures of multiple members avoids repeated resampling and hashing operations for each member, thereby achieving almost constant signature generation overhead and greatly improving real-time performance in large-scale formation scenarios.

[0040] like Figure 4 As shown in the figure, within the same scale range, the signature verification time of the LARRS method increases from about 15ms to about 260ms, and the DualRing method jumps from about 20ms to about 640ms, while the verification time of the present invention is stable below 10ms (about 20ms when 128 nodes). The present invention adopts an aggregated challenge value chain and a single response. The reconstruction-hashing closure mechanism makes the total complexity of reconstructing commitments and recomputing challenges linear in the number of members, but with a smaller constant, while also supporting batch parallel processing. This ensures integrity verification without performance bottlenecks during large-scale ring signature verification.

[0041] like Figure 5 As shown in Figure 2, as the number of members increases from 1 to 64, the signature length of the LARRS method rapidly expands from about 13KB to about 63KB; the DualRing (linked) scheme remains at about 5-10 KB; the signature length of the present invention is slightly higher than that of the DualRing method, but remains stable between 6-8 KB. The present invention outputs a traceability factor , a response value and Challenge value , avoiding the practice of generating an independent response for each member, thereby controlling the signature volume to a range that is linear with the number of members but with a very small coefficient, while taking into account anonymity and accountability, it also meets the storage and transmission requirements of resource-constrained nodes.

[0042] At this point, the entire process ends.

[0043] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0044] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A lightweight security formation method for mobile intelligent nodes, characterized in that: include: System initialization: The administrator generates system public parameters and a public reference string; each mobile intelligent node generates a private key and an anonymous public key, which are published through the IPFS platform to form the public key set of the current regional members; Public key legitimacy verification: Each mobile intelligent node generates a public key possession certificate based on its own private key, and other nodes or roadside units in the formation verify the public key possession certificate to confirm the legitimacy of the anonymous public key; Cross-domain authentication and area identification update: When the mobile intelligent node crosses the communication area, it sends an authentication request message to the roadside unit in the target area; After confirming the message, the roadside unit generates a new regional anonymous identifier for the mobile intelligent node and updates the regional anonymous identifier set of the formation members; Signature generation and release: The signature node downloads the anonymous identification set of the formation member area after the current area is updated; constructs the formation structure based on the anonymous identification set of the formation member area and generates an aggregate signature using the short ring signature algorithm; Broadcasting the aggregate signature together with the message content; the aggregate signature includes a traceability factor, a response value, and a challenge value; Signature Verification: The receiver verifies the aggregate signature using a ring signature verification algorithm.

2. A lightweight secure formation method for mobile intelligent nodes according to claim 1, characterized in that: The mobile node deletes the local expired anonymous identification and public key information according to a predetermined period, and pulls the updated public key set for replacement.

3. A lightweight secure formation method for mobile intelligent nodes according to claim 2, characterized in that: The public key possession proof is specifically a non-interactive zero-knowledge proof constructed based on Groth16 zk-SNARK.

4. A lightweight secure formation method for mobile intelligent nodes according to claim 3, characterized in that: The message includes a timestamp, a non-interactive zero-knowledge proof, an anonymous public key, a hardware fingerprint, an original area identifier, and a target area identifier.

5. A lightweight security formation method for mobile intelligent nodes according to claim 4, characterized in that: After confirming the message, the roadside unit generates a new regional anonymous identifier for the mobile intelligent node, including: Check whether the timestamp is within a valid time window to prevent replay attacks; Verifying the non-interactive zero-knowledge proof based on the public reference string and the anonymous public key to confirm that the mobile intelligent node holds the corresponding private key; The anonymous public key, hardware fingerprint, and target area identifier are concatenated and hashed to generate an anonymous area identifier, which is then uploaded to IPFS, and the local area binding record of the roadside unit is updated.

6. A lightweight security formation method for mobile intelligent nodes according to claim 5, characterized in that: The constructing of a formation structure based on the set of anonymous identifications of the formation members and generating an aggregate signature using a short ring signature algorithm include: The regional anonymous identification set of the formation members is regarded as the corresponding public key list to construct the formation structure, denoted as ; Calculate the traceability factor using the signer's private and public keys : ; In the formula, is the signer's private key; is the signer's public key; is a hash function that maps to elliptic curve points; The signer randomly selects a challenge value for each member of the formation except himself; The signer selects a random number and calculates a one-time commitment based on the system's public parameters. : ; In the formula, is a random number; It is a generator of the elliptic curve group; Calculate the initial challenge value based on the message, traceability factor and one-time commitment : ; In the formula, The signer's challenge value for the next position in the ring signature; is the hash function among the public parameters of the system; Message to be signed; It is a traceability factor; It’s a one-time commitment; is the byte string concatenation operator; Following the order of the members in the formation, the commitment value is reconstructed for each member and the subsequent challenge value is calculated, until the challenge value of the signer's position is obtained again to complete the closure of the challenge chain: ; In the formula, It is The commitment value corresponding to each member; It is Challenge value at each position; It is public keys of each member; It is Random response for each position; It is a generator of the elliptic curve group; It is New challenge value for each position; is the hash function among the public parameters of the system; Message to be signed; It is a traceability factor; is the byte string concatenation operator; Indicates the location of the signer Starting from the next member, the challenge chain is recursively passed to the previous position of the signer in the order of the formation, completing the closure of the entire challenge chain; Calculate the response value based on the sum of all challenge values: ;In the formula, is the number of members in the formation; It is Challenge value at each position; is a random number chosen randomly by the signer to generate a one-time commitment; is the signer's own private key scalar; is the order of the underlying elliptic curve group; Output contains traceability factors , a response value and The aggregate signature of the challenge value.

7. A lightweight security formation method for mobile intelligent nodes according to claim 6, characterized in that: The ring signature verification algorithm includes: Reconstruct the commitment value of each member based on the challenge value and response value in the received aggregate signature; Recalculate each challenge value based on the reconstructed commitment value and a predefined hash function; Compare the recalculated challenge value with the challenge value in the aggregate signature one by one; When all comparisons pass, the output verification is successful, otherwise the output verification fails.

8. A lightweight secure formation method for mobile intelligent nodes according to claim 7, characterized in that: The authorization department can extract the traceability factor in the aggregate signature and locate the real signer through the mapping query on IPFS.

Citation Information

Patent Citations

  • Motorcade safety management system and method based on ring signature and vehicle management platform

    CN109698754A

  • Privacy protection method based on certificateless ring signcryption in vehicle-mounted ad hoc network

    CN110166228A

  • Lightweight loop signature method based on zk-SNARK

    CN114329551A

  • Tracing ring signature data sharing method based on block chain hierarchical nodes

    CN116488804A

  • Aggregate anonymous credentials for decentralized identity in blockchain

    US20230403161A1