Ubiquitous network encrypted data security management system with cloud-edge collaboration
Through the collaborative architecture of user terminals, edge nodes and cloud servers, using attribute encryption and multi-level deduplication tags, combined with Shamir secret sharing and LWE lattice signatures, the problems of bandwidth waste, single node leakage and post-quantum signatures in cloud-edge collaborative ciphertext data management are solved, achieving efficient and secure data management.
Patent Information
- Application Number
- CN202511053518.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-07-30
AI Technical Summary
Existing technologies in cloud-edge collaborative ciphertext data management have problems such as bandwidth waste, ciphertext confidentiality degradation, single-node leakage risk, insufficient post-quantum signature security, and lack of user trust management, and lack a unified security management system.
Adopting a collaborative architecture among user terminals, edge nodes, and cloud servers, this paper generates attribute ciphertexts through attribute encryption and derives multi-level deduplication labels. Combining Shamir secret sharing and LWE-based lattice signatures, this paper implements ciphertext deduplication, backup, and integrity verification, and establishes a quantifiable trust management mechanism.
Without reducing encryption strength, it reduces network bandwidth waste, ensures unique cloud storage, achieves high disaster recovery and quantum integrity, dynamically isolates malicious users, and improves data storage and transmission efficiency.
Smart Images

Figure CN120582903B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network and information security technology, and specifically to a cloud-edge collaborative ubiquitous network encrypted data security management system. Background Art
[0002] With the rapid development of the Internet of Things, the Internet of Vehicles, and the Industrial Internet, the amount of data generated by edge devices is growing exponentially. Traditional centralized storage models with direct "end-to-cloud" connections have exposed bandwidth bottlenecks, latency sensitivity, and privacy leaks. To address this, academia and industry have proposed cloud-edge collaborative tiered storage architectures. These architectures perform preprocessing and computation at edge nodes close to the data source, uploading only encrypted or filtered data to the cloud. This shortens response times and reduces network load. Simultaneously, cutting-edge cryptographic advances such as attribute-based encryption (ABE), ciphertext deduplication techniques, Shamir secret sharing, and learning-with-error (LWE)-based lattice signatures have matured, enabling efficient management and security audits in the purely ciphertext domain. However, these advances are often implemented independently. Existing systems focus on either ciphertext retrieval and deduplication efficiency, or disaster recovery and post-quantum integrity verification. There is a lack of comprehensive solutions that systematically integrate these security mechanisms across the cloud, edge, and end layers.
[0003] Existing technologies still have the following major shortcomings: First, most ciphertext deduplication solutions are performed only at a single point in the cloud, ignoring bandwidth waste at the edge node layer. A few cloud-edge solutions often trade randomness for deduplication efficiency, resulting in degraded confidentiality. Second, backups generally use multiple replicas or erasure codes, lacking secondary encryption protection for ciphertext fragments, making data restoration possible even with a single node leak. Furthermore, backup and deduplication are often disconnected, failing to ensure that only unique ciphertexts are stored in the cloud while edge nodes and users retain recovery capabilities. Third, integrity verification often relies on RSA / ECC signatures, which offer insufficient security margins against quantum computing threats. Furthermore, integrating post-quantum signatures with ciphertext deduplication and distributed backup lacks unified process control. Fourth, existing solutions lack a quantifiable trust management mechanism between users and edge nodes, making it impossible to dynamically deny further interactions when verification fails or malicious behavior occurs. In summary, the industry urgently needs a unified security management system that can be implemented across user terminals, edge nodes, and cloud servers to address these shortcomings and meet the comprehensive data confidentiality, integrity, and availability requirements of future ubiquitous network environments. Summary of the Invention
[0004] (1) Technical problems solved: In response to the shortcomings of the existing technology, the present invention provides a cloud-edge collaborative ubiquitous network encrypted data security management system to solve the above problems.
[0005] (II) Technical solution: To achieve the above-mentioned purpose, the present invention provides the following technical solution: A cloud-edge collaborative ubiquitous network ciphertext data security management system, characterized in that it includes: a user-end module, used to calculate a simple label based on plaintext data to match it in a local index list, and when the match fails, perform attribute encryption on the plaintext data to generate attribute ciphertext, and generate a deduplication label at the same time, and send the attribute ciphertext together with at least one deduplication label to the edge node; an edge node module, used to match the received deduplication label in the edge index list, and when the match fails, feedback the result and forward the attribute ciphertext and deduplication label to the cloud server; a cloud server module, used to match the deduplication label in the cloud index list, and match When a failure occurs, the attribute ciphertext is stored and the deduplication label is recorded. When a match is successful, the duplicate ciphertext is deleted. A key server module is used to generate management attribute encryption parameters and public-private key pairs for each entity, and issue decryption private keys to users with legal attribute sets. A backup module is used to divide the attribute ciphertext into multiple fragments based on the Shamir secret sharing algorithm on the user side, and encrypt each fragment again with attributes, and then distribute them to multiple cloud servers for backup through the edge nodes, so that the attribute ciphertext can be restored when the number of fragments meets a predetermined threshold. An integrity verification module is used to perform quantum-resistant digital signature and verification during the upload, forwarding and recovery process of the attribute ciphertext or fragment, so as to achieve end-to-end integrity verification and responsibility traceability.
[0006] Furthermore, the local index list in the user-side module includes a simple tag, an attribute value, and a user private key field, and the simple tag is calculated by a one-way hash function: ;In the formula, For simple labels, is a cryptographically secure one-way hash function, The plain text to be uploaded.
[0007] Furthermore, the attribute encryption is performed on the plaintext data to generate attribute ciphertext, and a deduplication tag is generated at the same time, and the attribute ciphertext is sent together with at least one deduplication tag to the edge node, specifically: the simple tag Calculate the intermediate hash value through a one-way hash function .
[0008] Calling attribute encryption algorithm , generate attribute ciphertext and attribute values .
[0009] The attribute value With the intermediate hash value Bitwise XOR to get the first attribute value .
[0010] The plaintext data With the first attribute value Splicing, the first data string obtained .
[0011] By the first data string Hash calculation to obtain the first deduplication label .
[0012] After receiving the matching failure feedback from the edge node, further calculate the second attribute value and the third attribute value .
[0013] The plaintext data Respectively with the second attribute value Splicing, third attribute value Splice to get the second data string , the third data string .
[0014] By the second data string , the third data string Hash calculations are performed in sequence to obtain the second deduplication label and the third deduplication tag .
[0015] Furthermore, the attribute encryption algorithm is called , generate attribute ciphertext and attribute values , specifically including: from the system public key Get the cyclic group generator from , bilinear mapping parameters and a collection of attribute primitives ; From the prime order cyclic group The multiplication group of Random selection ; Based on access control policy Build a visit tree and create a root node and each leaf node Distributing secret sharing polynomials , making ; Calculate the attribute ciphertext component using the following formula: ;In the formula, The first component of the attribute ciphertext is used to carry the plaintext encrypted by the bilinear mapping; Represents the second component of the attribute ciphertext, used to carry random numbers The result of the power operation of ; Represents the third component of the attribute ciphertext, for each leaf node in the access tree Corresponding attributes The primitives are encrypted; is the plaintext data to be encrypted; , represents a bilinear map of The power result, Represents a cyclic group from prime order A random number randomly selected from ; Represents a cyclic group Generators of Represents visiting the leaf nodes in the tree Matched secret sharing polynomial The value at 0: Indicates the key server as an attribute Randomly selected attribute coefficient; set attribute value , and output attribute ciphertext based on the attribute ciphertext component and attribute values .
[0016] Furthermore, the edge index list in the edge node module includes the following fields: a first deduplication tag, used to detect whether the received attribute ciphertext is repeated with the stored data; a user public key, used to verify the grid signature generated by the user end when receiving the attribute ciphertext or its fragment; an edge node private key, used to generate an edge node signature for the attribute ciphertext or its fragment.
[0017] Furthermore, the cloud index list in the cloud server module includes a first deduplication tag field, a second deduplication tag field, a third deduplication tag field and an edge node public key field, which are used to match the attribute ciphertext corresponding to the same plaintext to determine whether there is duplicate data.
[0018] Furthermore, the integrity verification module uses a lattice signature algorithm based on the learning error problem to perform digital signature and verification.
[0019] Furthermore, the edge index list and the cloud index list further include a reputation value field and a reputation value threshold field, wherein the reputation value is used to evaluate the credibility of the data sender; the reputation value threshold field is used to reject its subsequent upload or storage request when the corresponding reputation value is lower than the threshold.
[0020] (III) Beneficial effects: Compared with the prior art, the present invention provides a cloud-edge collaborative ubiquitous network ciphertext data security management system with the following beneficial effects: 1. The cloud-edge collaborative ubiquitous network ciphertext data security management system, through a three-level collaborative ciphertext deduplication process of user end-edge node-cloud server, first calculates a simple label for the plaintext data on the user end and matches it in the local index list to avoid pushing duplicate data to the network; if there is a local miss, attribute encryption is performed to obtain the attribute ciphertext, and the first, second and third deduplication labels are derived in sequence; the first deduplication label is first sent to the edge node along with the attribute ciphertext, and the edge side can feedback the result by only using the label to determine the duplication, without destroying the randomness of the ciphertext; after a miss at the edge, the second and third deduplication labels are sent to the cloud to achieve global deduplication on the cloud side. Since the three labels are all derived from the attribute ciphertext and the attribute value through one-way hashing, they neither leak the plaintext information nor ensure that redundant transmission traffic can be cut off at each layer; thus, this solution eliminates bandwidth waste at the edge layer and transmission link without reducing encryption strength, and ensures that only unique ciphertext exists in the cloud.
[0021] 2. The cloud-edge collaborative ubiquitous network ciphertext data security management system selects the number of shards and the threshold according to the importance of the data through the user end, generates multiple fragments using the attribute ciphertext as a polynomial constant term, and encrypts each fragment again. The fragments are distributed to multiple cloud servers through the edge nodes. During recovery, only the number of fragments exceeding the threshold needs to be taken to reconstruct the attribute ciphertext. Therefore, the present invention avoids the redundancy caused by storing multiple copies in the cloud on the one hand, and on the other hand, even if a single node is leaked, the attribute ciphertext cannot be restored, taking into account both high disaster tolerance and fragment confidentiality.
[0022] 3. This cloud-edge collaborative ubiquitous network ciphertext data security management system superimposes a lattice signature based on the learning error problem for each upload, forwarding, and recovery operation. The user first generates a quantum-resistant signature for the attribute ciphertext or fragment. The edge node generates a quantum-resistant signature again after verification. The cloud server verifies the edge node's quantum-resistant signature. The verification log is synchronously written into the reputation value field of each layer index. If an entity's signature verification fails continuously, its reputation value falls below a threshold and is dynamically rejected for upload or storage. This invention thus achieves ciphertext-level integrity and accountability traceability under post-quantum threats and establishes a quantifiable trust regulation mechanism that can isolate malicious users or unreliable edge nodes in real time. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 Schematic diagram of the functional module composition of the cloud-edge collaborative ubiquitous network encrypted data security management system provided by the present invention.
[0024] Figure 2 Schematic diagram of data transmission and storage in the cloud-edge collaborative ubiquitous network encrypted data security management system provided by the present invention.
[0025] Figure 3 This is a timing flow chart of data deduplication and backup for the cloud-edge collaborative ubiquitous network encrypted data security management system provided by the present invention.
[0026] Figure 4 Schematic diagram of the distributed backup architecture of the cloud-edge collaborative ubiquitous network encrypted data security management system provided by the present invention. DETAILED DESCRIPTION
[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0028] In order to enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0029] See also Figure 1-3 , Figure 1 A schematic diagram of the functional modules of the cloud-edge collaborative ubiquitous network encrypted data security management system provided by the present invention; Figure 2 Schematic diagram of data transmission and storage of the cloud-edge collaborative ubiquitous network encrypted data security management system provided by the present invention; Figure 3 The present invention provides a data deduplication and backup timing flow chart of the cloud-edge collaborative ubiquitous network encrypted data security management system; the cloud-edge collaborative ubiquitous network encrypted data security management system includes: a user-end module for calculating a simple label based on the plaintext data to match it in the local index list, and when the match fails, performing attribute encryption on the plaintext data to generate attribute ciphertext, and generating a deduplication label at the same time, and sending the attribute ciphertext together with at least one deduplication label to the edge node.
[0030] Furthermore, the local index list in the user-side module includes a simple tag, an attribute value, and a user private key field, and the simple tag is calculated by a one-way hash function: ;In the formula, For simple labels, is a cryptographically secure one-way hash function, The plain text to be uploaded.
[0031] Specifically, the local index list stores simple tags, attribute values, and user private key fields in a key-value mapping manner, where simple tags Used to record plaintext data to be uploaded One-way hash function The calculated unique fingerprint is compared with previous records on the user side to quickly determine whether the plaintext has been stored, thereby avoiding redundant transmission; attribute value Used to perform attribute encryption algorithms Random number The derived value is returned along with the ciphertext. The value saved locally can be used as a seed when deriving the first, second, and third deduplication labels, and can also be used as an auxiliary parameter for access structure satisfaction during subsequent decryption. The user's private key The key server sets the user's attributes pass The algorithm is issued, and the local private key can be used to encrypt the downloaded attribute text. Decryption can be performed to restore the plaintext, and quantum lattice signatures can be generated during the integrity verification phase. To prove data ownership and the legitimacy of operations.
[0032] Furthermore, the attribute encryption is performed on the plaintext data to generate attribute ciphertext, and a deduplication tag is generated at the same time, and the attribute ciphertext is sent together with at least one deduplication tag to the edge node, specifically: the simple tag Calculate the intermediate hash value through a one-way hash function .
[0033] Calling attribute encryption algorithm , generate attribute ciphertext and attribute values .
[0034] The attribute value With the intermediate hash value Bitwise XOR to get the first attribute value .
[0035] The plaintext data With the first attribute value Splicing, the first data string obtained .
[0036] By the first data string Hash calculation to obtain the first deduplication label .
[0037] After receiving the matching failure feedback from the edge node, further calculate the second attribute value and the third attribute value .
[0038] The plaintext data Respectively with the second attribute value Splicing, third attribute value Splice to get the second data string , the third data string .
[0039] By the second data string , the third data string Hash calculations are performed in sequence to obtain the second deduplication label and the third deduplication tag .
[0040] Specifically, when the user completes local deduplication and confirms that it needs to be uploaded, the intermediate hash value is calculated through the above steps in sequence. , attribute ciphertext , attribute value , first attribute value , first data string , and finally calculate the first data string Hash the first deduplication tag ; The user end will cipher the attribute and the first deduplication tag Send it to the edge node together; the edge node matches the first deduplication label in the edge index list If the match fails, the failure result will be fed back to the user end, and it will not be uploaded to the cloud for the time being, thereby saving uplink bandwidth by using the fast duplication detection of the edge node. After the user end receives the match failure feedback, in order to ensure the global uniqueness of the cloud, the second attribute value is calculated through the above steps in sequence. , the third attribute value , the second data string And the third data string , and then hash the result to get the second deduplication label and the third deduplication tag ; Then the user end will cipher the attribute , first deduplication tag , Second deduplication tag and the third deduplication tag Resend to the edge node.
[0041] Furthermore, the attribute encryption algorithm is called , generate attribute ciphertext and attribute values , specifically including: from the system public key Get the cyclic group generator from , bilinear mapping parameters and a collection of attribute primitives ; From the prime order cyclic group The multiplication group of Random selection ; Based on access control policy Build a visit tree and create a root node and each leaf node Distributing secret sharing polynomials , making ; Calculate the attribute ciphertext component using the following formula: .
[0042] In the formula, The first component of the attribute ciphertext is used to carry the plaintext encrypted by the bilinear mapping; Represents the second component of the attribute ciphertext, used to carry random numbers The result of the power operation of ; Represents the third component of the attribute ciphertext, for each leaf node in the access tree Corresponding attributes The primitives are encrypted; is the plaintext data to be encrypted; , represents a bilinear map of The power result, Represents a cyclic group from prime order A random number randomly selected from ; Represents a cyclic group Generators of Represents visiting the leaf nodes in the tree Matched secret sharing polynomial The value at 0: Indicates the key server as an attribute Randomly selected attribute coefficient; set attribute value , and output attribute ciphertext based on the attribute ciphertext component and attribute values .
[0043] Specifically, the system public key Contains generators , bilinear mapping parameters and primitives for each property , which together define the access control space. The data owner first Randomly select ,Will Write to the root node Polynomial , and then recursively assign polynomials to each node of the visit tree , so that the polynomial reconstruction can be recovered only when the attribute set submitted by the user satisfies the access structure The ciphertext component constructed subsequently The plain text and mix, As a public random factor, The weight of each leaf attribute in the tree is embedded in the ciphertext. The key server is the attribute set Generate a private key , where the random number Used to resist conspiracy, legitimate users use private keys Computing in the pairing domain Eliminate random numbers and restore , and then from Remove Restore plaintext ; Any attribute set that does not satisfy the access tree cannot be reconstructed , so it cannot be decrypted, thus ensuring that only users with matching attributes can decrypt without exposing the plaintext.
[0044] The edge node module is used to match the received deduplication label in the edge index list, and when the match fails, it feedbacks the result and forwards the attribute ciphertext and deduplication label to the cloud server; further, the edge index list in the edge node module includes the following fields: a first deduplication label, used to detect whether the received attribute ciphertext is repeated with the stored data; a user public key, used to verify the grid signature generated by the user end when receiving the attribute ciphertext or its fragment; an edge node private key, used to generate an edge node signature for the attribute ciphertext or its fragment.
[0045] Specifically, the edge node receives the attribute ciphertext uploaded by the user for the first time First deduplication tag Then match the search in the "First Deduplication Label" field of the edge index list If it hits, it is determined that the ciphertext has been forwarded to the cloud by this node before, and then the message is discarded and the "already exists" feedback is returned to the user end; if it does not hit, then Write the edge index list and return a "match failure" feedback without uploading to the cloud, so that the edge layer can cut off redundant traffic first. After the client receives the match failure information, it will generate a second deduplication tag. and the third deduplication tag , send again To the edge node, the edge node will Append records to the corresponding fields in the index list, and then The entire ciphertext is forwarded to the cloud server; when the same-source ciphertext arrives again, it is immediately truncated by the local index, regardless of the level of tags it carries. This process enables the edge layer to quickly detect duplicates with a minimal set of tags and reduces traffic on the first upload link, while ensuring that the cloud still has access to the three tags for network-wide uniqueness determination. The "user public key" and "edge node private key" fields are reserved in the index for subsequent integrity verification module calls without affecting the current deduplication logic.
[0046] The cloud server module is used to match the deduplication tag in the cloud index list, store the attribute ciphertext and record the deduplication tag when the match fails, and delete the duplicate ciphertext when the match is successful; further, the cloud index list in the cloud server module includes a first deduplication tag field, a second deduplication tag field, a third deduplication tag field and an edge node public key field, which are used to match the attribute ciphertext corresponding to the same plaintext to determine whether there is duplicate data.
[0047] Specifically, when the cloud server receives the When a message is received, duplicate detection is first performed in the cloud index list according to the parallel matching search order of the first deduplication tag, the second deduplication tag, and the third deduplication tag. If any one of them hits, it is determined to be the same source as the existing attribute ciphertext and no longer needs to be saved. The attribute ciphertext is directly discarded. To eliminate cross-region redundancy; if all three items are not hit, Write to object storage, create a new index entry for the ciphertext in the cloud index list, and record it completely The edge node public key carried in the message is used for subsequent integrity verification module verification of edge-side signatures and reputation value statistics. Therefore, the cloud can guarantee system-level unique storage without parsing the plaintext, significantly saving cloud capacity and cross-data center synchronization bandwidth. The reserved edge node public key field not only enables the cloud server to quickly locate the corresponding edge node and complete signature verification, but also provides a key trust anchor for dynamic rejection or migration strategies based on reputation thresholds.
[0048] The key server module is used to generate management attribute encryption parameters and public and private key pairs of each entity, and issue decryption private keys to users with legal attribute sets; specifically, the key server module generates three types of parameters, the first type is the system public key As a global public amount, it is written to the user end, edge node and cloud server simultaneously. The user end executes the attribute encryption algorithm. Call and Calculate the ciphertext component; the edge node and the cloud server only use it to verify the consistency of the ciphertext format. The second type is the attribute private key Only sent to the target user end that meets the access policy for subsequent decryption of attribute ciphertext , and is also used to generate user-side grid signatures in the upload link; no other module can obtain this private key, fundamentally isolating the risk of unauthorized decryption. The third category is the grid signature key based on LWE for each communication entity. , public key Write the corresponding index list field and the user public key field to the edge node for verification , the edge node public key field is verified by the cloud server ; and the private key It is kept in the entity and is only used for local signature to ensure the quantum integrity and traceability of the entire link. and backup metadata It is encrypted and stored by the key server and is only called during disaster recovery or re-deriving the private key. No module is sent out.
[0049] The backup module is used to divide the attribute ciphertext into multiple fragments based on the Shamir secret sharing algorithm at the user end and encrypt the attributes of each fragment again, and then distribute it to multiple cloud servers for backup through the edge node, so that the attribute ciphertext can be restored when the number of fragments meets the predetermined threshold; specifically, the user end completes the multi-level deduplication and confirms the attribute ciphertext After the data is converted to non-duplicate data, the encrypted data stored by the key server is read from the local backup metadata. Parameter pair and server mapping template, where The total number of segments to be backed up. The minimum threshold for recovery is set in advance based on the importance of the data. The user then randomly selects coefficients , construct a polynomial: ; and select Non-repeating horizontal axes ,calculate get fragments , thereby ensuring that any less than Fragments could not be reconstructed , and any The fragments can be restored by Lagrange interpolation. To avoid single-piece leakage, the user end Perform attribute encryption again to generate encrypted fragments ; Then the client refers to the server mapping template, reorders the target list based on the current cloud cluster load and geographical distribution, and selects Tai Cloud Server will The data is forwarded in batches through edge nodes in sequence; the edge nodes only act as channels and do not parse the fragment content. After the data is sent successfully, the local index and key server will synchronize the metadata and write the latest data. Yes, so that the fragment can be accurately located during future restoration.
[0050] The integrity verification module is used to perform quantum-resistant digital signature and verification during the upload, forwarding, and recovery of the attribute ciphertext or fragments, so as to achieve end-to-end integrity verification and accountability traceability.
[0051] Furthermore, the integrity verification module uses a lattice signature algorithm based on the learning error problem to perform digital signature and verification.
[0052] For details, please refer to Figure 4 , Figure 4 This is a schematic diagram of the distributed backup architecture of the cloud-edge collaborative ubiquitous network encrypted data security management system provided by the present invention. The system uses the same lattice signature process based on the learning error (LWE) problem on all three links of the user end, edge node, and cloud server to ensure consistency in quantum strength. During initialization, the key server generates a lattice signature public and private key pair for each user end and each edge node. ; The public key is written into the user public key or edge node public key field of the corresponding index list, and the private key is only kept locally in this entity. or encrypted fragments Before, use the private key Randomly sampled vectors calculate , and by hash Constructing a signature ,in The complete message, including data and signature, is sent to the edge node. The edge node first relies on the stored public key verify Is it equal to If the verification fails, the message is discarded immediately. If the verification passes, the private key is used. Re-sign the same data to generate , and then forwarded to the cloud server along with its public key identifier. After receiving it, the cloud references the public key of the corresponding edge node in the cloud index list for a second verification and decides whether to store or discard the data. In the recovery scenario, the cloud also returns the fragment with a signature; the user end verifies it with the public key and then decrypts and reconstructs it. Finally, the simple label of the reconstructed plaintext is recalculated and compared with the simple label saved locally to achieve an end-to-end integrity closed loop.
[0053] Furthermore, the edge index list and the cloud index list further include a reputation value field and a reputation value threshold field, wherein the reputation value is used to evaluate the credibility of the data sender; the reputation value threshold field is used to reject its subsequent upload or storage request when the corresponding reputation value is lower than the threshold.
[0054] Specifically, the system maintains a reputation value field for each user in the edge node index list , the cloud index list also maintains a reputation value field for each edge node , and set the node's adjustable reputation value threshold and When the upload link starts, the edge node first reads the corresponding , if its value is less than , it will directly return the "upload rejection" feedback to the user end and discard the message; otherwise, it will continue to perform deduplication comparison and signature verification. After the verification is successful, the edge node will The default weight is incremented by 1; if the verification fails or the data is tampered with, the default weight is immediately decremented by 2, and the failure reason is written into the log, so that low-credibility users can trigger the threshold passive blocking in a short time. ,when Less than When a backup is detected, the cloud denies storage and alerts the operations console, prompting the operations team to migrate the backup fragments at an appropriate time. Otherwise, the cloud performs a de-rewriting and signature review. Each successful cloud verification adds 1 point to the edge node, while a failed one deducts 2 points. This allows for a dynamic global assessment of edge node service quality.
[0055] At this point, the entire process of the present invention is completed. In summary, the present invention constructs a cloud-edge collaborative ciphertext data security management system that runs through the user end, edge node and cloud server: first, simple tags are used on the user side to achieve local rapid deduplication, and attribute encryption is used to generate attribute ciphertext controlled by access policy; then, with the help of a two-stage multi-level deduplication tag mechanism, redundant upstream traffic is cut off at the edge node and unique storage is guaranteed in the cloud across the entire network; on this basis, Shamir secret sharing is used to perform threshold segmentation on the unique ciphertext, and then it is distributed to multiple clouds after secondary encryption to achieve high-reliability backup with minimum redundancy; data is attached with LWE-based lattice signatures throughout the upload, forwarding and recovery links, and cloud-edge-end multi-point verification is linked to dynamic access of reputation values, thereby combining post-quantum integrity and traceable accountability; the key server centrally manages attribute encryption parameters, distributes private keys and backup metadata, and provides a unified trusted root for the entire system. This comprehensive solution solves the problems of ciphertext deduplication, distributed disaster recovery, quantum-resistant integrity verification, and dynamic trust regulation without exposing plaintext, significantly improving data storage utilization, transmission efficiency, and full lifecycle security. It is suitable for the Internet of Vehicles, the Internet of Things, and other ubiquitous network scenarios with extremely high requirements for privacy and availability.
[0056] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0057] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A cloud-edge collaborative ubiquitous network encrypted data security management system, characterized by: include: The user-side module is configured to calculate a simple tag based on the plaintext data and match it in a local index list; when the match fails, perform attribute encryption on the plaintext data to generate attribute ciphertext, generate a deduplication tag, and send the attribute ciphertext together with at least one deduplication tag to the edge node; The edge node module is used to match the received deduplication label in the edge index list, and feedback the result when the match fails and forward the attribute ciphertext and deduplication label to the cloud server; A cloud server module is used to match the deduplication tag in the cloud index list, store the attribute ciphertext and record the deduplication tag when the match fails, and delete the duplicate ciphertext when the match succeeds; The key server module is used to generate the encryption parameters of management attributes and the public and private key pairs of each entity, and issue the decryption private key to the user of the legal attribute set; A backup module is used to divide the attribute ciphertext into multiple fragments based on the Shamir secret sharing algorithm on the user side, and then distribute the attribute of each fragment to multiple cloud servers for backup through the edge node, so that the attribute ciphertext can be restored when the number of fragments meets a predetermined threshold; An integrity verification module, configured to perform quantum-resistant digital signature and verification during the upload, forwarding, and recovery of the attribute ciphertext or fragments, to achieve end-to-end integrity verification and accountability traceability; The method of performing attribute encryption on the plaintext data to generate attribute ciphertext and generating a deduplication tag at the same time, and sending the attribute ciphertext together with at least one deduplication tag to the edge node is as follows: Calculate the intermediate hash value through a one-way hash function ;Call attribute encryption algorithm , generate attribute ciphertext and attribute values ; The attribute value With the intermediate hash value Bitwise XOR to get the first attribute value ; The plaintext data With the first attribute value Splicing, the first data string obtained ; By the first data string Hash calculation to get the first deduplication mark ; After receiving the matching failure feedback from the edge node, further calculate the second attribute value and the third attribute value ; The plaintext number Respectively with the second attribute value Splicing, third attribute value Splice to get the second data string , the third data string ; By the second data string , the third data string Hash calculations are performed in sequence to obtain the second deduplication label and the third deduplication tag .
2. The cloud-edge collaborative ubiquitous network encrypted data security management system according to claim 1 is characterized in that: The local index list in the client module includes a simple tag, an attribute value, and a user private key field. The simple tag is calculated using a one-way hash function: ;In the formula, For simple labels, is a cryptographically secure one-way hash function, The plain text to be uploaded.
3. The cloud-edge collaborative ubiquitous network encrypted data security management system according to claim 1 is characterized in that: The calling attribute encryption algorithm , generate attribute ciphertext and attribute values , specifically including: from the system public key Get the cyclic group generator from , bilinear mapping parameters and a collection of attribute primitives ; From the prime order cyclic group The multiplication group of Random selection ; Based on access control policy Build a visit tree and create a root node and each leaf node Distributing secret sharing polynomials , making ; Calculate the attribute ciphertext component using the following formula: ;In the formula, The first component of the attribute ciphertext is used to carry the plaintext encrypted by the bilinear mapping; Represents the second component of the attribute ciphertext, used to carry random numbers The result of the power operation of ; Represents the third component of the attribute ciphertext, for each leaf node in the access tree Corresponding attributes The primitives are encrypted; is the plaintext data to be encrypted; , represents a bilinear map of Power result; Represents a cyclic group from prime order A random number randomly selected from ; Represents a cyclic group Generators of Represents visiting the leaf nodes in the tree Matched secret sharing polynomial The value at 0: Indicates the key server as an attribute Randomly selected attribute coefficient; set attribute value , and output attribute ciphertext based on the attribute ciphertext component and attribute values .
4. The cloud-edge collaborative ubiquitous network encrypted data security management system according to claim 1 is characterized in that: The edge index list in the edge node module includes the following fields: a first deduplication tag, used to detect whether the received attribute ciphertext is repeated with the stored data; The user public key is used to verify the grid signature generated by the user end when receiving the attribute ciphertext or its fragment; the edge node private key is used to generate the edge node signature for the attribute ciphertext or its fragment.
5. The cloud-edge collaborative ubiquitous network encrypted data security management system according to claim 1 is characterized in that: The cloud index list in the cloud server module includes a first deduplication tag field, a second deduplication tag field, a third deduplication tag field and an edge node public key field, which are used to match the attribute ciphertext corresponding to the same plaintext to determine whether there is duplicate data.
6. The cloud-edge collaborative ubiquitous network encrypted data security management system according to claim 1, characterized in that: The integrity verification module uses a lattice signature algorithm based on the learning error problem to perform digital signature and verification.
7. The system according to any one of claims 1 to 6, characterized in that: The edge index list and the cloud index list both further include a reputation value field and a reputation value threshold field, wherein the reputation value is used to evaluate the credibility of the data sender; the reputation value threshold field is used to reject its subsequent upload or storage request when the corresponding reputation value is lower than the threshold.
Citation Information
Patent Citations
Cloud data de-duplication method based on certificateless agent re-encryption
CN110213042A
Cloud data deduplication method based on edge cloud collaboration
CN114499843A