Collaborative secret state task matching method based on edge calculation in mobile crowdsourcing

By combining a fuzzy extractor and an authentication encryption method with associated data, along with inner product encryption technology with function hiding and the Paillier cryptographic algorithm, the problems of identity leakage and privacy leakage in mobile crowdsourcing systems are solved. This achieves low-cost collaborative authentication and accurate task matching, thereby improving the system's security and privacy protection.

CN121308940APending Publication Date: 2026-01-09SHAANXI NORMAL UNIV
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511481165.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-16
Publication Date
2026-01-09

AI Technical Summary

Technical Problem

Existing mobile crowdsourcing systems face risks of identity and privacy leaks in edge computing, and existing privacy protection methods are computationally complex and costly, making it impossible to achieve accurate secret matching.

Method used

Local user authentication is performed using a fuzzy extractor and an authentication encryption method with associated data. Combined with inner product encryption technology with function hiding and the Paillier cryptographic algorithm, collaborative authentication and secret task matching between workers and requesters are achieved.

Benefits of technology

It reduces computational costs, improves security and privacy protection, and enables task-worker matching and answer submission in encrypted form, meeting the needs of highly secure and private mobile crowdsourcing applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121308940A_ABST
    Figure CN121308940A_ABST
Patent Text Reader

Abstract

The invention discloses a collaborative secret state task matching method based on edge calculation in mobile crowdsourcing. The method comprises the steps of system initialization and key generation, requester-cloud platform registration authentication, worker-edge server registration authentication, login authentication and attribute submission, requester task issuing, cloud platform task delegation, secret state matching, worker task content decryption, worker answer submission, answer forwarding and decryption. According to the invention, cooperative authentication of workers and requesters and precise task matching based on attributes are realized under an edge-cloud architecture. A fuzzy extractor and an authentication encryption method with associated data are introduced, so that low-cost user local authentication and registration and authentication of a joining system are realized, the security is improved, and the calculation cost is reduced. Through function hidden inner product encryption and a Paillier cryptographic algorithm, task-worker matching and task answer submission are realized in a ciphertext state, and the requirements of a mobile crowdsourcing application scene with high safety, high privacy and dispersed cost are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, and in particular relates to edge computing, collaborative authentication and encrypted task matching in mobile crowdsourcing. Background Technology

[0002] With the rapid development of 5G networks and mobile technologies, widely adopted mobile devices are equipped with powerful processors, memory, and wireless communication capabilities. Mobile crowdsourcing has gained widespread attention, leveraging smart terminals and mobile networks to complete large-scale data collection and computation through collective effort. Tasks are posted on the platform by requesters, which recruits and assigns workers. Workers complete the tasks and submit results via mobile devices. Faced with the surge in data processing volume due to the increase in users and mobile devices, MCS (Multi-Channel System) is gradually evolving from the traditional centralized cloud platform model to an edge-cloud collaborative model. Tasks can be processed on edge servers closer to the data source, thereby reducing the management burden of the cloud center, significantly reducing communication latency and bandwidth consumption, and improving the system's real-time performance and scalability. Therefore, it shows great potential in application scenarios such as smart cities, intelligent transportation, and emergency response.

[0003] Existing mobile crowdsourcing systems combining edge computing still have significant shortcomings in terms of security and privacy protection. First, during registration and task execution, users need to submit identity information and attribute data; without effective protection mechanisms, they are vulnerable to identity leaks or impersonation attacks. Second, during task allocation and matching, platforms often need to directly obtain sensitive attributes such as workers' location, skills, or preferences, leading to privacy risks. Existing differential privacy or functional encryption methods suffer from high computational costs and insufficient matching accuracy. Third, if workers do not use secure encryption and authentication mechanisms when submitting task results, sensitive information is easily leaked, making them susceptible to eavesdropping, tampering, and replay attacks. Although some solutions mitigate privacy leaks using homomorphic encryption or federated learning, they generally suffer from high communication costs and computational complexity, and cannot guarantee accurate cryptographic matching. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to overcome the shortcomings of the prior art and provide a collaborative encrypted task matching method based on edge computing in mobile crowdsourcing with low communication cost, low computational complexity and good confidentiality performance.

[0005] The technical solution adopted to solve the above technical problems consists of the following steps:

[0006] (1) System initialization and key generation

[0007] 1) Trusted organization (TA) based on security parameters and vector dimension Obtain public parameters Secret parameters Master key Master private key :

[0008]

[0009]

[0010]

[0011]

[0012] in, It is a prime number of order. Multiplication cyclic group, and They are generator, It is a bilinear pairing: random numbers finite field , For group elements, master private key , and Choose two large prime numbers for the trusted institution TA. For random group elements, A trusted authority (TA) defines a hash function. Modular prime multiplication group , Represents the elements in the multiplicative group of the modulo prime r. and prime numbers The greatest common divisor.

[0013] 2) Generate parameters and lists

[0014] Trusted institution TA determines the decryption parameters according to formula (1). :

[0015] (1)

[0016] in, For random group elements, .

[0017] The cloud platform CP initializes a property list. Stores the attribute types and their order, along with an attribute value.

[0018] gather Stores all attribute values.

[0019] 3) Generate cloud platform edge server and user keys

[0020] Cloud platform CP generates public key and private key Among them, the private key Generate the formula according to formula (2)

[0021] key :

[0022] (2)

[0023] K edge servers All generate edge server public keys and edge server private key , And generate the edge server public key according to formula (3). :

[0024] (3)

[0025] in, Represents elements of a random group. i is a positive integer less than or equal to K, representing different edge servers. Different random group elements will be generated, and the edge server public key will be used. and random group elements Public, edge server private key By edge server Save this for yourself.

[0026] Potential requesters Generate requester's public key and the requester's private key ,in, , .

[0027] potential workers Generate worker public key and worker private key ,in, , .

[0028] (2) Requester - Cloud Platform Registration and Authentication

[0029] 1) Requester Send the requester's identity to the trusted authority (TA). and the requester's public key .

[0030] 2) Trusted institutions (TAs) use the master public key. Regarding the identity of the requester Sign the document to obtain a digital signature. .

[0031] 3) The trusted institution TA generates the requester according to formula (4). homomorphic public key Generate the requester according to formula (5) homomorphic private key :

[0032] (4)

[0033]

[0034] (5)

[0035]

[0036]

[0037]

[0038] Among them, elements , It is a model Multiplication group ,element It is a model Multiplication group generator, express and The least common multiple of .

[0039] 4) The requester Received digital signature Then submit a registration request to the cloud platform CP. .

[0040] 5) Cloud platform CP uses master public key Verify the validity of the digital signature, and verify the digital signature. If the conditions are met, the requester will be verified. Successful verification will result in registration rejection; otherwise, verification will fail. Upon successful verification, the cloud platform provider (CP) will become the requester. Generate requester system identity j is less than or equal to the requester The quantity is a positive integer and stored locally. .

[0041] (3) Worker-Edge Server Registration and Authentication

[0042] 1) Workers Choose a password ,submit For mobile devices ,in As a worker, This refers to biometric information.

[0043] 2) Mobile devices After receiving, the generation algorithm is processed by the fuzz extractor. Generate biometric keys Non-secret help strings .

[0044] 3) Mobile devices Generate the key according to formula (6). :

[0045] (6)

[0046] Use this key to perform biometric key according to formula (7) Authentication encryption with associated data is used:

[0047] (7)

[0048]

[0049] in, It is a random number. To associate the data, output the ciphertext. and certification labels .

[0050] 4) Mobile devices Send to trusted institution (TA) Trusted TA Verification Workers worker status and for workers Generate a certificate :

[0051] ,

[0052] in, This is the expiration date.

[0053] 5) Mobile devices Registration message Send to edge server Edge server use Verify the validity of the certificate on the edge server. Check the local database to verify the worker's identity. If the registration already exists, accept the registration; otherwise, refuse duplicate registration.

[0054] 6) Edge Server For workers Generate worker system identity k is less than or equal to the number of workers. A positive integer representing the quantity, and send an acknowledgment message. For mobile devices , It is a length of The string, It is a point in time, for workers Tasks can be assigned before this, edge servers Local storage .

[0055] 7) Mobile devices After receiving the confirmation message, store locally. .

[0056] (4) Login authentication and attribute submission

[0057] 1) Login authentication

[0058] 1-1) Workers Input information For mobile devices ,in This provides new biometric information.

[0059] 1-2) Mobile devices Regeneration algorithm using fuzzy extractor Obtain new biometric keys .

[0060] 1-3) If two biometric information and If the Hamming distance between them is within an acceptable range, the original biometric key can be recovered. .

[0061] 1-4) Mobile devices calculate The new biometric key is processed according to formula (8). Authentication encryption with associated data is used:

[0062] (8)

[0063] If probability If the authentication is successful, the worker... Login successful.

[0064] 2) Attribute submission

[0065] workers To edge servers Submit your attribute information to receive tasks.

[0066] in, Indicates workers The set of attribute values, One-hot or bucket coding methods are used to encode the attribute value set. Each attribute value in the algorithm is converted into a binary vector. The vector dimension d is determined by partitioning the attribute space. One-hot encoding creates an independent dimension for each attribute value, while bucket encoding groups and maps similar attribute values.

[0067] 2-1) Use one-hot or bucket encoding methods to encode workers. Attribute value set Encoded as attribute vector Only for workers Set the attribute to 1 at the corresponding position and set all other positions to 0, thus setting the attribute vector. Recorded as , where each component This represents the i-th attribute. The vector dimension is .

[0068] 2-2) Mobile devices Encryption algorithm using FH-IPE , obtain the attribute vector ciphertext :

[0069] (9)

[0070]

[0071]

[0072]

[0073]

[0074] Where r represents a random number, .

[0075] 2-3) Mobile devices send To edge servers , Indicates the attribute submission timestamp.

[0076] 2-4) Edge Server verify Whether it is valid, For receiving time, To allow for time differences, if the condition is met, the information is saved locally for the worker. The record becomes Edge server Workers who will publicly submit local attributes The quantity.

[0077] (5) The requester publishes the task

[0078] 1) System Identity The requester Task 1 is assigned to the cloud platform CP, formalized as follows: .

[0079] in, Indicates the task strategy. Indicates the task content. Indicates a reward. Indicates the number of answers required.

[0080] 2) Before publication, to protect privacy, the requester... Task strategy is needed and task content Encryption processing is performed.

[0081] 2-1) System Identity The requester Task strategy Mapped to policy vector It still uses one-hot or bucket encoding methods, with a strategy vector. In the context of task strategy Set the position that meets the requirement to 1, and set the other positions to non-zero random numbers, and set the policy vector. Recorded as , where each component This represents the i-th attribute. , For vector dimensions.

[0082] 2-2) The policy vector Send to a trusted authority (TA), which uses a token generation algorithm. For the requester Generate a token :

[0083] (10)

[0084]

[0085]

[0086]

[0087]

[0088]

[0089] in, It is a vector dimension, and its values ​​are composed of a set of attribute values. Number of elements And the one-hot or bucket coding method used for each attribute category is determined.

[0090] 2-3) Regarding the task content System identity The requester Generate the encrypted task content according to formula (11). :

[0091] (11)

[0092]

[0093]

[0094]

[0095] in, and It is a random number. , It is a modular multiplication group.

[0096] 3) System Identity The requester Will Submitted to the cloud platform CP, among which This indicates the requester homomorphic public key, This refers to a digital signature.

[0097] 4) Cloud platform CP verification of digital signature Accept the task upon successful completion and assign a task identifier to it. .

[0098] (6) Cloud platform task assignment

[0099] The cloud platform CP is based on the task identifier. Number of answers required for the task From all K edge servers Randomly assigned to a group of edge servers The workers they have The quantities are as follows: , … The resource constraints are satisfied as shown in equation (12):

[0100] (12)

[0101] in, It is a predefined integer parameter. It is an edge server that is assigned tasks. quantity, Each edge server Need to collect One answer, Represents each edge server The number of answers assigned.

[0102] (7) Dense-state matching

[0103] Edge server Received task identifier is After completing the task, match the task with a qualified worker. and encrypt the mission content Send to selected workers .

[0104] 1) For each of the edge servers Workers who register and submit attributes Edge server They will all use a dense-state matching algorithm To determine the worker Does the task strategy meet the requirements? Determine the worker Is it suitable to complete the task identifier? Tasks, edge servers Calculate according to formula (13) Value:

[0105] (13)

[0106] Substituting equations (9) and (10) into equation (13), we obtain the value of z as shown in equation (14):

[0107] (14)

[0108] like and Inner product relation If it is established, then This indicates a successful match. ,but Returns a non-zero value, as shown in equation (15):

[0109] (15)

[0110] in, It is a non-zero value.

[0111] 2) Edge server The system identity of the successfully matched worker Add to candidate set In, until the candidate set workers The number reaches each edge server Number of answers needed At that time, edge server Stop targeting the remaining workers. Execute the dense state matching algorithm .

[0112] 3) For the candidate set Each system identity workers Edge server Generate auxiliary decryption parameters according to formula (16). :

[0113] (16)

[0114] in, Indicates system identity workers Worker public key, edge server For system identity workers Select random number , Confirm parameters .

[0115] 4) Edge Server Records stored locally ,Will Send to each system identity workers .

[0116] (8) Workers decrypt the task content

[0117] Each system identity workers Upon receiving Then, restore the task content according to formula (17). :

[0118] (17)

[0119] in, Indicates system identity workers The worker's private key.

[0120] (9) Workers submit answers

[0121] 1) Each system identity workers The task completion identifier is After completing the task, you will receive the answer. The answer is given by equation (18). Calculate the ciphertext of the answer :

[0122] (18)

[0123] in, For the requester's system identity The requester homomorphic public key , Part of It is the worker Randomly selected values, .

[0124] 2) Each system identity workers All towards edge servers submit ,in, Indicates workers The system identity, Indicates the task identifier. This indicates confirmation of the parameters. This indicates the encrypted answer.

[0125] 3) Edge server After receiving, check if the record exists in the local database. And check and confirm the parameters Are they consistent?

[0126] 3-1) If a record exists Confirm parameters Consistency indicates system identity workers You have the right to submit an answer.

[0127] 3-2) Otherwise, edge server Refuse to accept this answer;

[0128] 4) After collecting the total number of all assigned answers After that, edge servers Calculate the aggregation result Result according to formula (19):

[0129] (19)

[0130] 5) Edge Server Use the edge server private key Generate digital signatures for answers Digitally sign the answer The aggregated result (Result) is sent to the cloud platform CP.

[0131] (10) Forwarding the answer and decryption

[0132] 1) The cloud platform CP uses the edge server public key. Verify the digital signature of the answer .

[0133] 2) Upon receiving An edge server that was assigned a task Send the aggregated result (Result) and verify the digital signature of the answer. After success, the cloud platform CP will receive The aggregated result (Result) is sent to the corresponding requester. .

[0134] 3) The requester Use your own homogeneous private key :

[0135]

[0136] Perform the Paillier decryption algorithm on each received aggregation result Result to obtain Sum the results of each decrypted aggregation to get the number of answers required. There are an equal number of answers.

[0137] In step (1) of the present invention, the system initialization and key generation step 1), the following... It is a prime number of order. The multiplicative cyclic group, in which It is to satisfy Large prime numbers; the aforementioned and Two large prime numbers selected for the trusted institution TA satisfy the following conditions: .

[0138] In step (3) of the present invention, 6) of worker-edge server registration and authentication, the k is less than or equal to

[0139] For workers A positive integer between 100 and 200.

[0140] In step (6) of the present invention, the cloud platform dispatching task formula (12) is described as follows: It is a predefined integer parameter. .

[0141] This invention proposes a collaborative encrypted task matching method that achieves collaborative authentication of workers and requesters in an edge-cloud architecture, enabling precise task matching based on attributes. It introduces a fuzzy extractor and an authentication encryption method with associated data to achieve low-cost local user authentication and system registration and authentication, improving security and reducing computational costs. Furthermore, through function-hidden inner product encryption and the Paillier cryptographic algorithm, task-worker matching and task answer submission can be achieved in encrypted form, meeting the needs of future mobile crowdsourcing applications requiring high security, high privacy, and decentralized costs. Attached Figure Description

[0142] Figure 1 This is a flowchart of Example 1 of the present invention.

[0143] Figure 2 This is a computer simulation result of the collaborative dense-state task matching method based on edge computing in mobile crowdsourcing according to Embodiment 1 of the present invention. Detailed Implementation

[0144] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments, but the present invention is not limited to the following embodiments.

[0145] Example 1

[0146] The collaborative dense-state task matching method based on edge computing in mobile crowdsourcing in this embodiment consists of the following steps:

[0147] (1) System initialization and key generation

[0148] 1) Trusted organization (TA) based on security parameters and vector dimension Obtain public parameters Secret parameters Master key Master private key :

[0149]

[0150]

[0151]

[0152]

[0153] in, It is a prime number of order. The multiplicative cyclic group, in which, To meet Large prime numbers, in this embodiment The value is 2 255 +95, and They are generator, It is a bilinear pairing: random numbers finite field , For group elements, master private key , and Choose two large prime numbers for the trusted institution TA that satisfy... In this embodiment and The value is 2 1023 +1155, For random group elements, A trusted authority (TA) defines a hash function. Modular prime multiplication group , Represents the elements in the multiplicative group of the modulo prime r. and prime numbers The greatest common divisor.

[0154] 2) Generate parameters and lists

[0155] Trusted institution TA determines the decryption parameters according to formula (1). :

[0156] (1)

[0157] in, For random group elements, ;

[0158] The cloud platform CP initializes a property list. Stores the attribute categories and their order, and a collection of attribute values. Stores all attribute values.

[0159] 3) Generate cloud platform edge server and user keys

[0160] Cloud platform CP generates public key and private key Among them, the private key Generate the public key according to formula (2). :

[0161] (2)

[0162] K edge servers All generate edge server public keys and edge server private key , And generate the edge server public key according to formula (3). :

[0163] (3)

[0164] in, Represents elements of a random group. i is a positive integer less than or equal to K, representing different edge servers. Different random group elements will be generated, and the edge server public key will be used. and random group elements Public, edge server private key By edge server Save this for yourself.

[0165] Potential requesters Generate requester's public key and the requester's private key ,in, . ;

[0166] potential workers Generate worker public key and worker private key ,in, , ;

[0167] (2) Requester - Cloud Platform Registration and Authentication

[0168] 1) Requester Send the requester's identity to the trusted authority (TA). and the requester's public key .

[0169] 2) Trusted institutions (TAs) use the master public key. Regarding the identity of the requester Sign the document to obtain a digital signature. .

[0170] 3) The trusted institution TA generates the requester according to formula (4). homomorphic public key Generate the requester according to formula (5) homomorphic private key :

[0171] (4)

[0172]

[0173] (5)

[0174]

[0175]

[0176]

[0177] Among them, elements , It is a model Multiplication group ,element It is a model Multiplication group generator, express and The least common multiple of .

[0178] 4) The requester Received digital signature Then submit a registration request to the cloud platform CP. .

[0179] 5) Cloud platform CP uses master public key Verify the validity of the digital signature, and verify the digital signature. If the conditions are met, the requester will be verified. Successful verification will result in registration rejection; otherwise, verification will fail. Upon successful verification, the cloud platform provider (CP) will become the requester. Generate requester system identity j is less than or equal to the requester The quantity is a positive integer and stored locally. .

[0180] (3) Worker-Edge Server Registration and Authentication

[0181] 1) Workers Choose a password ,submit For mobile devices ,in As a worker, This refers to biometric information.

[0182] 2) Mobile devices After receiving, the generation algorithm is processed by the fuzz extractor. Generate biometric keys Non-secret help strings .

[0183] 3) Mobile devices Generate the key according to formula (6). :

[0184] (6)

[0185] Use this key to perform biometric key according to formula (7) Authentication encryption with associated data is used:

[0186] (7)

[0187]

[0188] in, It is a random number. To associate the data, output the ciphertext. and certification labels .

[0189] 4) Mobile devices Send to trusted institution (TA) Trusted TA Verification Workers worker status and for workers Generate a certificate :

[0190] ,

[0191] in, This is the expiration date.

[0192] 5) Mobile devices Registration message Send to edge server Edge server use Verify the validity of the certificate on the edge server. Check the local database to verify the worker's identity. If the registration already exists, accept the registration; otherwise, refuse duplicate registration.

[0193] 6) Edge Server For workers Generate worker system identity The k mentioned is less than or equal to the worker. The quantity is a positive integer between 100 and 200. In this embodiment, k is less than or equal to the number of workers. A positive integer of 150. And send an acknowledgment message. For mobile devices , It is a length of The string, It is a point in time, for workers Tasks can be assigned before this, edge servers Local storage .

[0194] 7) Mobile devices After receiving the confirmation message, store locally. .

[0195] (4) Login authentication and attribute submission

[0196] 1) Login authentication

[0197] 1-1) Workers Input information For mobile devices ,in This provides new biometric information.

[0198] 1-2) Mobile devices Regeneration algorithm using fuzzy extractor Obtain new biometric keys .

[0199] 1-3) If two biometric information and If the Hamming distance between them is within an acceptable range, the original biometric key can be recovered. .

[0200] 1-4) Mobile devices calculate The new biometric key is processed according to formula (8). Authentication encryption with associated data is used:

[0201] (8)

[0202] If probability If the authentication is successful, the worker... Login successful.

[0203] 2) Attribute submission

[0204] workers To edge servers Submit your attribute information to receive tasks.

[0205] in, Indicates workers The set of attribute values, One-hot or bucket coding methods are used to encode the attribute value set. Each attribute value in the data is converted into a binary vector and then processed through the attribute space.

[0206] The partitioning determines the vector dimension d, where one-hot encoding creates an independent dimension for each attribute value, while bucketing...

[0207] Encoding then groups and maps similar attribute values.

[0208] 2-1) Use one-hot or bucket encoding methods to encode workers. Attribute value set Encoded as attribute vector Only for workers Set the attribute to 1 at the corresponding position and set all other positions to 0, thus setting the attribute vector. Recorded as , where each component This represents the i-th attribute. The vector dimension is .

[0209] 2-2) Mobile devices Encryption algorithm using FH-IPE , obtain the attribute vector ciphertext :

[0210] (9)

[0211]

[0212]

[0213]

[0214]

[0215] Where r represents a random number, .

[0216] 2-3) Mobile devices send To edge servers , Indicates the attribute submission timestamp.

[0217] 2-4) Edge Server verify Whether it is valid, For receiving time, To allow for time differences, if the condition is met, the information is saved locally for the worker. The record becomes Edge server Workers who will publicly submit local attributes The quantity.

[0218] (5) The requester publishes the task

[0219] 1) System Identity The requester Task 1 is assigned to the cloud platform CP, formalized as follows: ,

[0220] in, Indicates the task strategy. Indicates the task content. Indicates a reward. Indicates the number of answers required.

[0221] 2) Before publication, to protect privacy, the requester... Task strategy is needed and task content Encryption processing is performed.

[0222] 2-1) System Identity The requester Task strategy Mapped to policy vector It still uses one-hot or bucket encoding methods, with a strategy vector. In the context of task strategy Set the position that meets the requirement to 1, and set the other positions to non-zero random numbers, and set the policy vector. Recorded as , where each component This represents the i-th attribute. , For vector dimensions.

[0223] 2-2) The policy vector Send to a trusted authority (TA), which uses a token generation algorithm. For the requester Generate a token :

[0224] (10)

[0225]

[0226]

[0227]

[0228]

[0229]

[0230] in, It is a vector dimension, and its values ​​are composed of a set of attribute values. Number of elements And the one-hot or bucket coding method used for each attribute category is determined.

[0231] 2-3) Regarding the task content System identity The requester Generate the encrypted task content according to formula (11). :

[0232] (11)

[0233]

[0234]

[0235]

[0236] in, and It is a random number. , It is a modular multiplication group.

[0237] 3) System Identity The requester Will Submitted to the cloud platform CP, among which This indicates the requester homomorphic public key, This refers to a digital signature.

[0238] 4) Cloud platform CP verification of digital signature Accept the task upon successful completion and assign a task identifier to it. .

[0239] (6) Cloud platform task assignment

[0240] The cloud platform CP is based on the task identifier. Number of answers required for the task From all K edge servers Randomly assigned to a group of edge servers The workers they have The quantities are as follows: , … The resource constraints are satisfied as shown in equation (12):

[0241] (12)

[0242] in, It is a predefined integer parameter. In this embodiment, the value of h is 3. It is an edge server that is assigned tasks. quantity, Each edge server Need to collect One answer, Represents each edge server The number of answers assigned.

[0243] (7) Dense-state matching

[0244] Edge server Received task identifier is After completing the task, match the task with a qualified worker. and encrypt the mission content Send to selected workers .

[0245] 1) For each of the edge servers Workers who register and submit attributes Edge server They will all use a dense-state matching algorithm To determine the worker Does the task strategy meet the requirements? Determine the worker Is it suitable to complete the task identifier? Tasks, edge servers Calculate according to formula (13) Value:

[0246] (13)

[0247] Substituting equations (9) and (10) into equation (13), we obtain the value of z as shown in equation (14):

[0248] (14)

[0249] like and Inner product relation If it is established, then This indicates a successful match. ,but Returns a non-zero value, as shown in equation (15):

[0250] (15)

[0251] in, It is a non-zero value.

[0252] 2) Edge server The system identity of the successfully matched worker Add to candidate set In, until the candidate set workers The number reaches each edge server Number of answers needed At that time, edge server Stop targeting the remaining workers. Execute the dense state matching algorithm .

[0253] 3) For the candidate set Each system identity workers Edge server Generate auxiliary decryption parameters according to formula (16). :

[0254] (16)

[0255] in, Indicates system identity workers Worker public key, edge server For system identity workers Select random number , Confirm parameters .

[0256] 4) Edge Server Records stored locally ,Will Send to each system identity workers .

[0257] (8) Workers decrypt the task content

[0258] Each system identity workers Upon receiving Then, restore the task content according to formula (17). :

[0259] (17)

[0260] in, Indicates system identity workers The worker's private key.

[0261] (9) Workers submit answers

[0262] 1) Each system identity workers The task completion identifier is After completing the task, you will receive the answer. The answer is given by equation (18). Calculate the ciphertext of the answer :

[0263] (18)

[0264] in, For the requester's system identity The requester homomorphic public key , Part of It is the worker Randomly selected values, .

[0265] 2) Each system identity workers All towards edge servers submit ,in, Indicates workers The system identity, Indicates the task identifier. This indicates confirmation of the parameters. This indicates the encrypted answer.

[0266] 3) Edge server After receiving, check if the record exists in the local database. And check and confirm the parameters Are they consistent?

[0267] 3-1) If a record exists Confirm parameters Consistency indicates system identity workers You have the right to submit an answer.

[0268] 3-2) Otherwise, edge server This answer will not be accepted.

[0269] 4) After collecting the total number of all assigned answers After that, edge servers Calculate the aggregation result Result according to formula (19):

[0270] (19)

[0271] 5) Edge Server Use the edge server private key Generate digital signatures for answers Digitally sign the answer The aggregated result (Result) is sent to the cloud platform CP.

[0272] (10) Forwarding the answer and decryption 1) Cloud platform CP uses edge server public key Verify the digital signature of the answer .

[0273] 2) Upon receiving An edge server that was assigned a task Send the aggregated result (Result) and verify the digital signature of the answer. After success, the cloud platform CP will receive The aggregated result (Result) is sent to the corresponding requester. .

[0274] 3) The requester Use your own homogeneous private key :

[0275]

[0276] Perform the Paillier decryption algorithm on each received aggregation result Result to obtain Sum the results of each decrypted aggregation to get the number of answers required. There are an equal number of answers.

[0277] Complete a collaborative dense-state task matching method based on edge computing in mobile crowdsourcing.

[0278] Example 2

[0279] The collaborative dense-state task matching method based on edge computing in mobile crowdsourcing in this embodiment consists of the following steps:

[0280] (1) System initialization and key generation

[0281] 1) Trusted organization (TA) based on security parameters and vector dimension Obtain public parameters Secret parameters Master key Master private key :

[0282]

[0283]

[0284]

[0285]

[0286] in, It is a prime number of order. The multiplicative cyclic group, in which, To meet Large prime numbers, in this embodiment The value is 2 255 , and They are generator, It is a bilinear pairing: random numbers finite field , For group elements, master private key , and Choose two large prime numbers for the trusted institution TA that satisfy... In this embodiment and The value is 2 1023 Other parameters, variables, and their value ranges are the same as in Example 1.

[0287] The steps are the same as in Example 1.

[0288] (2) Requester - Cloud Platform Registration and Authentication

[0289] The steps are the same as in Example 1.

[0290] (3) Worker-Edge Server Registration and Authentication

[0291] Steps 1) to 5) are the same as in Example 1.

[0292] 6) Edge Server For workers Generate worker system identity The k mentioned is less than or equal to the worker. The quantity is a positive integer between 100 and 200. In this embodiment, k is less than or equal to the number of workers. A positive integer of 100. And send an acknowledgment message. For mobile devices , It is a length of The string, It is a point in time, for workers Tasks can be assigned before this, edge servers Local storage .

[0293] 7) Mobile devices After receiving the confirmation message, store locally. .

[0294] (4) Login authentication and attribute submission

[0295] The steps are the same as in Example 1.

[0296] (5) The requester publishes the task

[0297] The steps are the same as in Example 1.

[0298] (6) Cloud platform task assignment

[0299] The cloud platform CP is based on the task identifier. Number of answers required for the task From all K edge servers Randomly assigned to a group of edge servers The workers they have The quantities are as follows: , … The resource constraints are satisfied as shown in equation (12):

[0300] The expression of equation (12) is the same as that in Example 1.

[0301] In equation (12), It is a predefined integer parameter. In this embodiment, h is set to 1. Other parameters, variables, and their value ranges are the same as in Embodiment 1.

[0302] The other steps are the same as in Example 1. This completes the collaborative dense-state task matching method based on edge computing in mobile crowdsourcing.

[0303] Example 3

[0304] The collaborative dense-state task matching method based on edge computing in mobile crowdsourcing in this embodiment consists of the following steps:

[0305] (1) System initialization and key generation

[0306] 1) Trusted organization (TA) based on security parameters and vector dimension Obtain public parameters Secret parameters Master key Master private key :

[0307]

[0308]

[0309]

[0310]

[0311] in, It is a prime number of order. The multiplicative cyclic group, in which, To meet Large prime numbers, in this embodiment The value is 2 256 -1, and They are generator, It is a bilinear pairing: random numbers finite field , For group elements, master private key , and Choose two large prime numbers for the trusted institution TA that satisfy... In this embodiment and The value is 2 1024 -1. Other parameters and variables, as well as their value ranges, are the same as in Example 1.

[0312] (2) Requester - Cloud Platform Registration and Authentication

[0313] The steps are the same as in Example 1.

[0314] (3) Worker-Edge Server Registration and Authentication

[0315] Steps 1) to 5) are the same as in Example 1.

[0316] 6) Edge Server For workers Generate worker system identity The k mentioned is less than or equal to the worker. The quantity is a positive integer between 100 and 200. In this embodiment, k is less than or equal to the number of workers. A positive integer of 200. And send an acknowledgment message. For mobile devices , It is a length of The string, It is a point in time, for workers Tasks can be assigned before this, edge servers Local storage .

[0317] 7) Mobile devices After receiving the confirmation message, store locally. .

[0318] (4) Login authentication and attribute submission

[0319] The steps are the same as in Example 1.

[0320] (5) The requester publishes the task

[0321] The steps are the same as in Example 1.

[0322] (6) Cloud platform task assignment

[0323] The cloud platform CP is based on the task identifier. Number of answers required for the task From all K edge servers Randomly assigned to a group of edge servers The workers they have The quantities are as follows: , … The resource constraints are satisfied as shown in equation (12):

[0324] The expression of equation (12) is the same as that in Example 1.

[0325] In equation (12), It is a predefined integer parameter. In this embodiment, the value of h is 5. Other parameters, variables, and their value ranges are the same as in Embodiment 1.

[0326] The other steps are the same as in Example 1. This completes the collaborative dense-state task matching method based on edge computing in mobile crowdsourcing.

[0327] To verify the beneficial effects of the present invention, a computer simulation experiment was conducted using the collaborative dense-state task matching method based on edge computing in mobile crowdsourcing according to Embodiment 1 of the present invention. The experimental results are shown below. Figure 2 ,Depend on Figure 2 As can be seen, the horizontal axis represents the number of workers, and the vertical axis represents the computation time. Taking the vector dimension d=5, the six colored bars show the computation time distribution of the registration, login, attribute submission, task posting, secret matching, and answer submission stages. When the number of workers is 10, the computation time for the attribute submission and secret matching stages is 1200ms, the computation time for the task posting stage is 600.9ms, and the computation times for the registration, login, and answer submission stages are 15.7, 0.4, and 0.5ms, respectively. When the number of workers is 50, the computation time for the attribute submission and secret matching stages is 6000ms, the computation time for the task posting stage is 600.9ms, and the computation times for the registration, login, and answer submission stages are 47, 1.8, and 2.5ms, respectively. Therefore, the computation time is mainly distributed in the attribute submission, task posting, and matching stages, while the computation time for the registration, login, and answer submission stages can be ignored.

Claims

1. A collaborative dense-state task matching method based on edge computing in mobile crowdsourcing, characterized in that... It consists of the following steps: (1) System initialization and key generation 1) Trusted organization (TA) based on security parameters and vector dimension Obtain public parameters Secret parameters Master key Master private key : in, It is a prime number of order. Multiplication cyclic group, and They are generator, It is a bilinear pairing: random numbers finite field , For group elements, master private key , and Choose two large prime numbers for the trusted institution TA. For random group elements, A trusted authority (TA) defines a hash function. Modular prime multiplication group , Represents the elements in the multiplicative group of the modulo prime r. and prime numbers The greatest common divisor; 2) Generate parameters and lists Trusted institution TA determines the decryption parameters according to formula (1). : (1) in, For random group elements, ; The cloud platform CP initializes a property list. Stores the attribute categories and their order, and a collection of attribute values. Stores all attribute values; 3) Generate cloud platform edge server and user keys Cloud platform CP generates public key and private key Among them, the private key Generate the formula according to formula (2) key : (2) K edge servers All generate edge server public keys and edge server private key , And generate the edge server public key according to formula (3). : (3) in, Represents elements of a random group. i is a positive integer less than or equal to K, representing different edge servers. Different random group elements will be generated, and the edge server public key will be used. and random group elements Public, edge server private key By edge server Save it for yourself; Potential requesters Generate requester's public key and the requester's private key ,in, , ; potential workers Generate worker public key and worker private key ,in, , ; (2) Requester - Cloud Platform Registration and Authentication 1) Requester Send the requester's identity to the trusted authority (TA). and the requester's public key ; 2) Trusted institutions (TAs) use the master public key. Regarding the identity of the requester Sign the document to obtain a digital signature. ; 3) The trusted institution TA generates the requester according to formula (4). homomorphic public key Generate the requester according to formula (5) homomorphic private key : (4) (5) Among them, elements , It is a model Multiplication group ,element It is a model Multiplication group generator, express and The least common multiple; 4) The requester Received digital signature Then submit a registration request to the cloud platform CP. ; 5) Cloud platform CP uses master public key Verify the validity of the digital signature, and verify the digital signature. If the conditions are met, the requester will be verified. Successful verification will result in registration rejection; otherwise, verification will fail. Upon successful verification, the cloud platform provider (CP) will become the requester. Generate requester system identity j is less than or equal to the requester The quantity is a positive integer and stored locally. ; (3) Worker-Edge Server Registration and Authentication 1) Workers Choose a password ,submit For mobile devices ,in As a worker, Biometric information; 2) Mobile devices After receiving, the generation algorithm is processed by the fuzz extractor. Generate biometric keys Non-secret help strings ; 3) Mobile devices Generate the key according to formula (6). : (6) Use this key to perform biometric key according to formula (7) Authentication encryption with associated data is used: (7) in, It is a random number. To associate the data, output the ciphertext. and certification labels ; 4) Mobile devices Send to trusted institution (TA) Trusted TA Verification Workers worker status and for workers Generate a certificate : , in, Valid until expiration; 5) Mobile devices Registration message Send to edge server Edge server use Verify the validity of the certificate on the edge server. Check the local database to verify the worker's identity. If the registration already exists, accept the registration; otherwise, refuse duplicate registration. 6) Edge Server For workers Generate worker system identity k is less than or equal to the number of workers. A positive integer representing the quantity, and send an acknowledgment message. For mobile devices , It is a length of The string, It is a point in time, for workers Tasks can be assigned before this, edge servers Local storage ; 7) Mobile devices After receiving the confirmation message, store locally. ; (4) Login authentication and attribute submission 1) Login authentication 1-1) Workers Input information For mobile devices ,in For new biometric information; 1-2) Mobile devices Regeneration algorithm using fuzzy extractor Obtain new biometric keys ; 1-3) If two biometric information and If the Hamming distance between them is within an acceptable range, the original biometric key can be recovered. ; 1-4) Mobile devices calculate The new biometric key is processed according to formula (8). Authentication encryption with associated data is used: (8) If probability If the authentication is successful, the worker... Login successful; 2) Attribute submission workers To edge servers Submit your attribute information to receive tasks. in, Indicates workers The set of attribute values, One-hot or bucket coding methods are used to encode the attribute value set. Each attribute value in the algorithm is converted into a binary vector. The vector dimension d is determined by partitioning the attribute space. One-hot encoding creates an independent dimension for each attribute value, while bucketing encoding groups and maps similar attribute values. 2-1) Use one-hot or bucket encoding methods to encode workers. Attribute value set Encoded as attribute vector Only for workers Set the attribute to 1 at the corresponding position and set all other positions to 0, thus setting the attribute vector. Recorded as , where each component This represents the i-th attribute. The vector dimension is ; 2-2) Mobile devices Encryption algorithm using FH-IPE , obtain the attribute vector ciphertext : (9) Where r represents a random number, ; 2-3) Mobile devices send To edge servers , Indicates the attribute submission timestamp; 2-4) Edge Server verify Whether it is valid, For receiving time, To allow for time differences, if the condition is met, the information is saved locally for the worker. The record becomes Edge server Workers who will publicly submit local attributes Quantity; (5) The requester publishes the task 1) System Identity The requester Task 1 is assigned to the cloud platform CP, formalized as follows: , in, Indicates the task strategy. Indicates the task content. Indicates a reward. Indicates the number of answers required; 2) Before publication, to protect privacy, the requester... Task strategy is needed and task content Encryption processing is performed; 2-1) System Identity The requester Task strategy Mapped to policy vector It still uses one-hot or bucket encoding methods, with a strategy vector. In the context of task strategy Set the position that meets the requirement to 1, and set the other positions to non-zero random numbers, and set the policy vector. Recorded as , where each component This represents the i-th attribute. , For vector dimensions; 2-2) The policy vector Send to a trusted authority (TA), which uses a token generation algorithm. For the requester Generate a token : (10) in, It is a vector dimension, and its values ​​are composed of a set of attribute values. Number of elements And the choice between one-hot or bucket coding for each attribute category is determined; 2-3) Regarding the task content System identity The requester Generate the encrypted task content according to formula (11). : (11) in, and It is a random number. , It is a modular multiplication group; 3) System Identity The requester Will Submitted to the cloud platform CP, among which This indicates the requester homomorphic public key, Indicates a digital signature; 4) Cloud platform CP verification of digital signature Accept the task upon successful completion and assign a task identifier to it. ; (6) Cloud platform task assignment The cloud platform CP is based on the task identifier. Number of answers required for the task From all K edge servers Randomly assigned to a group of edge servers The workers they have The quantities are as follows: , … The resource constraints are satisfied as shown in equation (12): (12) in, It is a predefined integer parameter. It is an edge server that is assigned tasks. quantity, Each edge server Need to collect One answer, Represents each edge server The number of answers assigned; (7) Dense-state matching Edge server Received task identifier is After completing the task, match the task with a qualified worker. and encrypt the mission content Send to selected workers ; 1) For each of the edge servers Workers who register and submit attributes Edge server They will all use a dense-state matching algorithm To determine the worker Does the task strategy meet the requirements? Determine the worker Is it suitable to complete the task identifier? Tasks, edge servers Calculate according to formula (13) Value: (13) Substituting equations (9) and (10) into equation (13), we obtain the value of z as shown in equation (14): (14) like and Inner product relation If it is established, then This indicates a successful match. ,but Returns a non-zero value, as shown in equation (15): (15) in, It is a non-zero value; 2) Edge server The system identity of the successfully matched worker Add to candidate set In, until the candidate set workers The number reaches each edge server Number of answers needed At that time, edge server Stop targeting the remaining workers. Execute the dense state matching algorithm ; 3) For the candidate set Each system identity workers Edge server Generate auxiliary decryption parameters according to formula (16). : (16) in, Indicates system identity workers Worker public key, edge server For system identity workers Select random number , Confirm parameters ; 4) Edge Server Records stored locally ,Will Send to each system identity workers ; (8) Workers decrypt the task content Each system identity workers Upon receiving Then, restore the task content according to formula (17). : (17) in, Indicates system identity workers The worker's private key; (9) Workers submit answers 1) Each system identity workers The task completion identifier is After completing the task, you will receive the answer. The answer is given by equation (18). Calculate the ciphertext of the answer : (18) in, For the requester's system identity The requester homomorphic public key , Part of It is the worker Randomly selected values, ; 2) Each system identity workers All towards edge servers submit ,in, Indicates workers The system identity, Indicates the task identifier. This indicates confirmation of the parameters. This indicates the ciphertext of the answer; 3) Edge server After receiving, check if the record exists in the local database. And check and confirm the parameters Are they consistent? 3-1) If a record exists Confirm parameters Consistency indicates system identity workers You have the right to submit answers; 3-2) Otherwise, edge server Refuse to accept this answer; 4) After collecting the total number of all assigned answers After that, edge servers Calculate the aggregation result Result according to formula (19): (19) 5) Edge Server Use the edge server private key Generate digital signatures for answers Digitally sign the answer The aggregated result (Result) is sent to the cloud platform CP. (10) Forwarding the answer and decryption 1) The cloud platform CP uses the edge server public key. Verify the digital signature of the answer , 2) Upon receiving An edge server that was assigned a task Send the aggregated result (Result) and verify the digital signature of the answer. After success, the cloud platform CP will receive The aggregated result (Result) is sent to the corresponding requester. ; 3) The requester Use your own homogeneous private key : Perform the Paillier decryption algorithm on each received aggregation result Result to obtain Sum the results of each decrypted aggregation to get the number of answers required. There are an equal number of answers.

2. The collaborative dense-state task matching method based on edge computing in mobile crowdsourcing according to claim 1, characterized in that... In step (1), system initialization and key generation, the aforementioned It is a prime number of order. The multiplicative cyclic group, in which It is to satisfy Large prime numbers; the aforementioned and Two large prime numbers selected for the trusted institution TA satisfy the following conditions: .

3. The collaborative dense-state task matching method based on edge computing in mobile crowdsourcing according to claim 1, characterized in that... In step (3) of worker-edge server registration and authentication (6), k is less than or equal to the worker. A positive integer between 100 and 200.

4. The collaborative dense-state task matching method based on edge computing in mobile crowdsourcing according to claim 1, characterized in that... In step (6) of the cloud platform's task assignment formula (12), the aforementioned It is a predefined integer parameter. .

Citation Information

Cited By

  • Key extraction method based on bucket replacement and related device

    CN121585366A

  • A key extraction method based on bucket permutation and related device

    CN121585366B