Anonymous collection of data from groups of eligible members
Through anonymous data collection scheme, the generation and verification of message signatures are solved, the data protection problem in autonomous driving systems is achieved, the anonymity and security of data is achieved, and the legality and privacy of data collection are ensured.
Patent Information
- Application Number
- CN202180004389.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-01-19
- Filing Date
- 2021-01-19
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2041-01-19
AI Technical Summary
Existing advanced driver assistance systems and autonomous vehicle systems have shortcomings in data protection, especially how to ensure the security and anonymity of data collection during autonomous operations.
An anonymous data collection scheme is adopted to ensure the anonymity and security of the data during the collection process by generating and verifying message signatures. The trusted unit generates secrets and generates signatures by qualified members. The collection unit verifies the signature without tracking the identity of the sender.
It realizes the anonymity and security protection of data in autonomous driving systems, prevents data leakage and identity exposure, and ensures the legality and privacy of data collection.
Smart Images

Figure CN114041173B_ABST
Abstract
Description
[0001] Priority Claim
[0002] This application claims the benefit of priority of U.S. Provisional Application Serial No. 62 / 963,047, filed on January 19, 2020, which is incorporated herein by reference in its entirety. Background Art
[0003] Advanced driver assistance systems (ADAS) and autonomous vehicle (AV) systems use cameras and other sensors, as well as object classifiers, which are designed to detect specific objects in the environment of vehicles traveling on a road. The object classifiers are designed to detect predefined objects and are used in ADAS and AV systems to control the vehicle or alert the driver based on the type of object whose location has been detected, etc.
[0004] As ADAS and AV systems evolve towards fully autonomous operation, it would be beneficial to protect the data generated by these systems. Summary of the Invention
[0005] The following detailed description refers to the accompanying drawings. Whenever possible, the same reference numerals are used in the drawings and the following description to refer to the same or like parts. Although several illustrative embodiments are described herein, modifications, adaptations, and other implementations are possible. For example, components illustrated in the drawings may be replaced, added, or modified, and the illustrative methods described herein may be modified by replacing, reordering, removing, or adding steps. Accordingly, the following detailed description is not limited to the disclosed embodiments and examples.
[0006] The disclosed embodiments provide systems and methods that can be used as part of or in conjunction with autonomous navigation / driving and / or driver assistance technology functions. Driver assistance technology refers to any suitable technology that assists a driver in navigating and / or controlling their vehicle, such as forward collision warning (FCW), lane departure warning (LDW), and traffic sign recognition (TSR), rather than full autonomous driving. In different embodiments, the system can include one, two, or more cameras and associated processors that can be mounted in a vehicle, and these cameras and processors monitor the environment of the vehicle. In further embodiments, additional types of sensors can be mounted in the vehicle and can be used in an autonomous navigation and / or driver assistance system. In some examples of the presently disclosed subject matter, the system can provide techniques for processing images of the environment in front of a vehicle traveling on a road for training a neural network or deep learning algorithm to estimate the future path of the vehicle based on the images. In yet further examples of the presently disclosed subject matter, the system can provide techniques for using a trained neural network to process images of the environment in front of a vehicle traveling on a road to estimate the future path of the vehicle.
[0007] Systems, methods as set forth in the claims and the specification are provided.
[0008] Any combination of any subject matter of any claim can be provided.
[0009] Any combination of any method and / or method steps disclosed in any of the figures and / or the specification can be provided.
[0010] Any combination of any units, devices, and / or components disclosed in any of the figures and / or the specification can be provided. Non-limiting examples of such units include an aggregation unit, an image processor, and the like. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The subject matter regarded as the invention is particularly pointed out and distinctly claimed at the end of the specification. However, the invention, together with the organization and method of operation thereof, its objects, features, and advantages, will best be understood from the following detailed description when read in connection with the accompanying drawings, in which:
[0012] Figure 1 is a block diagram representation of a system in accordance with the disclosed embodiments;
[0013] Figure 2A is a diagrammatic side view representation of an exemplary vehicle including a system in accordance with the disclosed embodiments;
[0014] Figure 2B is in accordance with the disclosed embodiments Figure 2ASchematic top view representation of a vehicle and system as shown;
[0015] Figure 2C is a schematic top view representation of another embodiment of a vehicle including a system in accordance with the disclosed embodiments;
[0016] Figure 2D is a schematic top view representation of yet another embodiment of a vehicle including a system in accordance with the disclosed embodiments;
[0017] Figure 2E is a schematic representation of an exemplary vehicle control system in accordance with the disclosed embodiments;
[0018] Figure 3 is a schematic view of the interior of a vehicle including a rearview mirror and a user interface for a vehicle imaging system in accordance with the disclosed embodiments;
[0019] Figure 4 Shows an example of a system and multiple enabling members;
[0020] Figure 5 is a flowchart showing a method for generating a secret according to an embodiment;
[0021] Figure 6 is a flowchart showing a method for generating a signature of a message by group members according to an embodiment;
[0022] Figure 7 is a flowchart of a method for verifying the signature of a message according to an embodiment;
[0023] Figure 8 is a flowchart showing a method for generating a secret according to an embodiment;
[0024] Figure 9 is a flowchart showing a method for generating a signature of a message by group members according to an embodiment;
[0025] Figure 10 is a flowchart of a method for verifying the signature of a message according to an embodiment;
[0026] Figure 11 is an example of a method executed by a collection unit according to an embodiment to implement a first scheme; and
[0027] Figure 12 is an example of a method executed by a collection unit according to an embodiment to implement a second scheme. Detailed Description
[0028] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the present invention. However, those skilled in the art will understand that the present invention may be practiced without these specific details. In other instances, well-known methods, procedures, and components have not been described in detail so as not to obscure the present invention.
[0029] The subject matter regarded as the invention is particularly pointed out and distinctly claimed at the end of the specification. However, when read in conjunction with the following detailed description, the organization and method of operation of the present invention, as well as its objectives, features, and advantages, may best be understood. Figure 1 It will be appreciated that, for simplicity and clarity of illustration, the elements shown in the figures are not necessarily drawn to scale. For example, the dimensions of some of the elements may be exaggerated relative to other elements for clarity. Further, where considered appropriate, reference numerals may be repeated among the figures to indicate corresponding or analogous elements.
[0030] Since the illustrated embodiments of the present invention can in most cases be implemented using electronic components and circuits known to those skilled in the art, details will not be explained in a greater extent than considered necessary above in order to understand and appreciate the basic concepts of the present invention and in order not to obscure or deviate from the teachings of the present invention.
[0031] Any reference in this specification to a method, with the necessary modifications, shall apply to a system capable of performing the method, and with the necessary modifications, shall apply to a non-transitory computer-readable medium storing instructions that, when executed by a computer, cause the method to be performed.
[0032] Any reference in this specification to a system and any other component, with the necessary modifications, shall apply to a method executable by a memory device, and with the necessary modifications, shall apply to a non-transitory computer-readable medium storing instructions executable by a memory device.
[0033] Any reference in this specification to a non-transitory computer-readable medium, with the necessary modifications, shall apply to a system capable of executing instructions stored in the non-transitory computer-readable medium, and with the necessary modifications, shall apply to a method executable by a computer that reads instructions stored in the non-transitory computer-readable medium.
[0034] Any combination of any modules or units listed in any of the figures, any part of the specification, and / or any of the claims may be provided. In particular, any combination of any claimed features may be provided.
[0035] A pixel may be a picture element obtained by a camera or a processed picture element.
[0036] A pixel may be a picture element obtained by a camera or a processed picture element.
[0037] Before discussing in detail examples of processing an image of the environment in front of a vehicle traveling on a road for training a neural network or a deep learning algorithm to estimate features of a future path of the vehicle based on the image or processing an image of the environment in front of a vehicle traveling on a road using a trained neural network to estimate features of a future path of the vehicle, a description is provided of various possible implementations and configurations of a vehicle mountable system that can be used to perform and implement the methods of examples according to the presently disclosed subject matter. In some embodiments, various examples of the system can be installed in a vehicle and can operate while the vehicle is in motion. In some embodiments, the system can implement the methods of examples according to the presently disclosed subject matter.
[0038] However, it will be appreciated that embodiments of the present disclosure are not limited to scenarios where a suspicious upright object indication is caused by a high - grade road. A suspicious upright object indication can be associated with various other situations, can be generated by other types of image data, and can also be generated by data that is not image - based or not entirely image - based.
[0039] Now referring to Figure 1 is a block diagram representation of a system in accordance with the disclosed embodiments. Depending on the requirements of a particular implementation, system 100 can include various components. In some examples, system 100 can include a processing unit 110, an image acquisition unit 120, and one or more memory units 140, 150. The processing unit 110 can include one or more processing devices. In some embodiments, the processing unit 110 can include an application processor 180, an image processor 190, or any other suitable processing device. Similarly, depending on the requirements of a particular application, the image acquisition unit 120 can include any number of image acquisition units and components. In some embodiments, the image acquisition unit 120 can include one or more image capture devices (e.g., cameras), such as image capture device 122, image capture device 124, and image capture device 126. In some embodiments, system 100 can also include a data interface 128 that communicatively connects the processing unit 110 to the image acquisition unit 120. For example, the data interface 128 can include any one or more wired and / or wireless links for transferring image data acquired by the image acquisition unit 120 to the processing unit 110.
[0040] Both the application processor 180 and the image processor 190 may include various types of processing devices. For example, either or both of the application processor 180 and the image processor 190 may include one or more microprocessors, preprocessors (such as image preprocessors), graphics processors, central processing units (CPUs), support circuits, digital signal processors, integrated circuits, memories, or any other type of device suitable for running applications and suitable for image processing and analysis. In some embodiments, the application processor 180 and / or the image processor 190 may include any type of single-core or multi-core processor, mobile device microcontroller, central processing unit, etc. Various processing devices may be used, including, for example, processors available from manufacturers such as etc., and various processing devices may include various architectures (such as x86 processors, etc.).
[0041] In some embodiments, the application processor 180 and / or the image processor 190 may include any one of the EyeQ series processor chips available from These processor designs each include multiple processing units with local memory and instruction sets. Such processors may include video inputs for receiving image data from multiple image sensors and may also include video output capabilities. In one example, uses 90 nanometer micron technology operating at 332Mhz. The architecture has two floating-point, hyper-threaded 32-bit RISC CPUs five vision computing engines (VCEs), three vector microcode processors Denali 64-bit mobile DDR controller, 128-bit internal acoustic interconnect, dual 16-bit video inputs and 18-bit video output controller, 16-channel DMA, and several peripheral devices. The MIPS34K CPU manages the five VCEs, three and the DMA, a second MIPS34K CPU, and multi-channel DMA, as well as other peripheral devices. The five VCEs, three and the MIPS34K CPU can perform the intensive vision computing required for multifunctional bundled applications. In another example, as a third-generation processor and six times more powerful than the can be used in the disclosed examples. In yet another example, (fourth-generation processor) can be used in the disclosed examples.
[0042] Although Figure 1Illustrates that the processing unit 110 includes two separate processing devices, but more or fewer processing devices may be used. For example, in some examples, a single processing device may be used to perform the tasks of the application processor 180 and the image processor 190. In other embodiments, these tasks may be performed by more than two processing devices.
[0043] The processing unit 110 may include various types of devices. For example, the processing unit 110 may include various devices such as a controller, an image pre-processor, a central processing unit (CPU), support circuitry, a digital signal processor, an integrated circuit, a memory, or any other type of device for image processing and analysis. The image pre-processor may include a video processor for capturing, digitizing, and processing images from an image sensor. The CPU may include any number of microcontrollers or microprocessors. The support circuitry may be any number of circuits generally known in the art, including cache, power supply, clock, and input-output circuits. The memory may store software that controls the operation of the system when executed by the processor. The memory may include a database and image processing software, such as including a trained system (such as a neural network). The memory may include any number of random access memories, read-only memories, flash memories, disk drives, optical storage, removable storage, and other types of storage. In one instance, the memory may be separate from the processing unit 110. In another instance, the memory may be integrated into the processing unit 110.
[0044] Each of the memories 140, 150 may include software instructions that, when executed by a processor (e.g., the application processor 180 and / or the image processor 190), may control the operation of various aspects of the system 100. These memory units may include various databases and image processing software. The memory units 140, 150 may include random access memory, read-only memory, flash memory, disk drive, optical storage, tape storage, removable storage, and / or any other type of storage. In some examples, the memory units 140, 150 may be separate from the application processor 180 and / or the image processor 190. In other embodiments, these memory units may be integrated into the application processor 180 and / or the image processor 190.
[0045] In some embodiments, the system may include a position sensor 130. The position sensor 130 may include any type of device adapted to determine the position associated with at least one component of the system 100. In some embodiments, the position sensor 130 may include a GPS receiver. Such a receiver may determine the user's position and speed by processing signals broadcast by global positioning system satellites. The position information from the position sensor 130 may be available to the application processor 180 and / or the image processor 190.
[0046] In some embodiments, system 100 may be operatively connected to various systems, devices, and units on a vehicle (in which system 100 may be installed), and via any suitable interface (e.g., a communication bus), system 100 may communicate with the vehicle's systems. Examples of vehicle systems with which system 100 may cooperate include: a throttle system, a braking system, and a steering system (e.g., Figure 2E throttle system 220, braking system 230, and steering system 240).
[0047] In some embodiments, the system 100 may include a user interface 170. The user interface 170 may include any device adapted to provide information to or receive input from one or more users of system 100, including, for example, a touch screen, a microphone, a keyboard, a pointing device, a trackball, a camera, a knob, a button, etc. Information may be provided by system 100 to the user via the user interface 170.
[0048] In some embodiments, the system 100 may include a map database 160. The map database 160 may include any type of database for storing digital map data. In some examples, the map database 160 may include data related to the locations of various items (including roads, water body features, geographical features, points of interest, etc.) in a reference coordinate system. The map database 160 may store not only the locations of such items but also descriptors associated with these items, including, for example, names associated with any of the stored features and other information related thereto. For example, the database may include the locations and types of known obstacles, information related to the terrain of a road or the grade at certain points along the road, and so on. In some embodiments, the map database 160 may be physically located together with other components of system 100. Alternatively or additionally, the map database 160 or portions thereof may be located remotely relative to other components of system 100 (e.g., processing unit 110). In such embodiments, information from the map database 160 may be downloaded via a wired or wireless data connection to a network (e.g., via a cellular network and / or the Internet, etc.).
[0049] Image capture devices 122, 124, and 126 may each include any type of device adapted to capture at least one image from the environment. Additionally, any number of image capture devices may be used to acquire images for input to an image processor. Some examples of the presently disclosed subject matter may include only a single image capture device or may be implemented using only a single image capture device, while other examples may include two, three, or even four or more image capture devices or may be implemented using two, three, or even four or more image capture devices. Reference will be made below toFigures 2B - 2E The image capture devices 122, 124, and 126 are further described.
[0050] It should be appreciated that system 100 may include other types of sensors or may be operatively associated with other types of sensors, such as, for example: acoustic sensors, radio frequency (RF) sensors (e.g., radar transceivers), LIDAR sensors. Such sensors may be used independently of image acquisition unit 120 or may be used in cooperation with image acquisition unit 120. For example, data from a radar system (not shown) may be used to verify processed information received from processing images acquired by image acquisition unit 120, such as to filter certain false positives resulting from processing images acquired by image acquisition unit 120, or data from a radar system may be combined with or otherwise complement image data from image acquisition unit 120 or some processed variant or derivative of the image data from image acquisition unit 120.
[0051] System 100 or its various components may be incorporated into a variety of different platforms. In some embodiments, system 100 may be included on a vehicle 200, as Figure 2A shown. For example, as described above with respect to Figure 1 vehicle 200 may be equipped with processing unit 110 and any other components of system 100. Although in some embodiments, vehicle 200 may be equipped with only a single image capture device (e.g., a camera), in other embodiments (such as those discussed in connection with Figures 2B - 2E ) multiple image capture devices may be used. For example, as Figure 2A shown, either of image capture devices 122 and 124 of vehicle 200 may be part of an ADAS (Advanced Driver Assistance System) imaging assembly.
[0052] The image capture devices included on vehicle 200 and that are part of image acquisition unit 120 may be positioned in any suitable location. In some embodiments, as Figures 2A - 2E and Figure 3 shown, image capture device 122 may be located near a rearview mirror. This location may provide a line of sight similar to that of the driver of vehicle 200, which may assist in determining what is visible and not visible to the driver.
[0053] Other locations of the image capture device for the image capture unit 120 can also be used. For example, the image capture device 124 can be located on or in the bumper of the vehicle 200. Such locations may be particularly suitable for image capture devices with a wide field of view. The line of sight of the image capture device located on the bumper can be different from that of the driver. The image capture devices (e.g., image capture devices 122, 124, and 126) can also be located in other positions. For example, the image capture device can be located on or in one or both of the side mirrors of the vehicle 200, on the roof of the vehicle 200, on the hood of the vehicle 200, on the trunk of the vehicle 200, on the side of the vehicle 200, mounted on any of the windows of the vehicle 200, positioned behind or in front of any of the windows of the vehicle 200, and mounted in or near the lamps on the front and / or rear of the vehicle 200, etc. The image capture unit 120, or an image capture device that is one of the multiple image capture devices used in the image capture unit 120, can have a field of view (FOV) different from that of the driver of the vehicle and does not always see the same objects. In one example, the FOV of the image capture unit 120 can extend beyond the FOV of a typical driver and can thus image objects outside the driver's FOV. In another example, the FOV of the image capture unit 120 is a certain part of the driver's FOV. In some embodiments, the FOV of the image capture unit 120 corresponds to a sector that covers the road area in front of the vehicle and may also cover the surrounding environment of the road.
[0054] In addition to the image capture device, the vehicle 200 can also include various other components of the system 100. For example, the processing unit 110 can be included on the vehicle 200, integrated with or separate from the engine control unit (ECU) of the vehicle. The vehicle 200 can also be equipped with a position sensor 130 (such as a GPS receiver) and can also include a map database 160 and memory units 140 and 150.
[0055] Figure 2A is a diagrammatic side view representation of a vehicle imaging system according to an example of the presently disclosed subject matter. Figure 2B is Figure 2A a diagrammatic top view illustration of the example shown in Figure 2BAs illustrated, the disclosed example may include a vehicle 200 that includes a system 100 having a first image capture device 122 positioned near a rearview mirror of the vehicle 200 and / or positioned near a driver of the vehicle 200, a second image capture device 124 positioned on a bumper area of the vehicle 200 (e.g., one of the bumper areas 210) or in the bumper area, and a processing unit 110.
[0056] As Figure 2C illustrated, both image capture devices 122 and 124 may be disposed near a rearview mirror of the vehicle 200 and / or near a driver of the vehicle 200. Additionally, although Figure 2B and Figure 2C two image capture devices 122 and 124 are shown, it should be understood that other embodiments may include more than two image capture devices. For example, in Figure 2D the illustrated embodiment, a first image capture device 122, a second image capture device 124, and a third image capture device 126 are included in the system 100 of the vehicle 200.
[0057] As Figure 2D illustrated, image capture devices 122, 124, and 126 may be disposed near a rearview mirror of the vehicle 200 and / or near a driver's seat of the vehicle 200. The disclosed example is not limited to any particular number and configuration of image capture devices, and the image capture devices may be positioned at any suitable location within the vehicle 200 and / or on the vehicle 1200.
[0058] It should also be understood that the disclosed embodiments are not limited to a particular type of vehicle 200 and may be applicable to all types of vehicles, including cars, trucks, trailers, motorcycles, bicycles, self-balancing transportation devices, and other types of vehicles.
[0059] The first image capture device 122 may include any suitable type of image capture device. The image capture device 122 may include an optical axis. In one instance, the image capture device 122 may include an Aptina M9V024WVGA sensor having a global shutter. In another example, a rolling shutter sensor may be used. The image acquisition unit 120 and any image capture device implemented as part of the image acquisition unit 120 may have any desired image resolution. For example, the image capture device 122 may provide a resolution of 1280x960 pixels and may include a rolling shutter.
[0060] The image acquisition unit 120 and any image capture device implemented as part of the image acquisition unit 120 may include various optical elements. In some embodiments, one or more lenses may be included to provide, for example, the required focal length and field of view for the image acquisition unit 120 and for any image capture device implemented as part of the image acquisition unit 120. In some examples, the image capture device implemented as part of the image acquisition unit 120 may include or be associated with any optical element, such as, for example, a 6 mm lens or a 12 mm lens. In some examples, the image capture device 122 may be configured to capture images with a desired (and known) field of view (FOV).
[0061] The first image capture device 122 may have a scan rate associated with the acquisition of each image scan line in the first series of image scan lines. The scan rate may refer to the rate at which the image sensor is able to acquire image data associated with each pixel included in a particular scan line.
[0062] Figure 2E is a graphical representation of a vehicle control system according to an example of the presently disclosed subject matter. As Figure 2E indicated, the vehicle 200 may include a throttle system 220, a brake system 230, and a steering system 240. The system 100 may provide inputs (e.g., control signals) to one or more of the throttle system 220, the brake system 230, and the steering system 240 via one or more data links (e.g., any wired and / or wireless link for transmitting data). For example, based on an analysis of images acquired by the image capture devices 122, 124, and / or 126, the system 100 may provide control signals to one or more of the throttle system 220, the brake system 230, and the steering system 240 to navigate the vehicle 1200 (e.g., by causing acceleration, turning, lane changes, etc.). Further, the system 100 may receive inputs from one or more of the throttle system 220, the brake system 230, and the steering system 240 indicating the operating condition of the vehicle 200 (e.g., speed, whether the vehicle 200 is braking and / or turning, etc.).
[0063] As Figure 3As shown, the vehicle 200 may further include a user interface 170 for interacting with a driver or passenger of the vehicle 200. For example, the user interface 170 in a vehicle application may include a touch screen 320, a knob 330, buttons 340, and a microphone 350. A driver or passenger of the vehicle 200 may also use a handle (e.g., a handle located on or near the steering column of the vehicle 200, including, for example, a turn signal handle), buttons (e.g., buttons located on the steering wheel of the vehicle 200), etc. to interact with the system 100. In some embodiments, the microphone 350 may be disposed adjacent to the rearview mirror 310. Similarly, in some embodiments, the image capture device 122 may be located near the rearview mirror 310. In some embodiments, the user interface 170 may further include one or more speakers 360 (e.g., speakers of a vehicle audio system). For example, the system 100 may provide various notifications (e.g., alerts) via the speakers 360.
[0064] As will be appreciated by those skilled in the art who benefit from this disclosure, many variations and / or modifications may be made to the foregoing disclosed embodiments. For example, not all components are necessary for the operation of the system 100. Further, any component may be located in any suitable part of the system 100, and the components may be rearranged into various configurations while providing the functions of the disclosed embodiments. Accordingly, the foregoing configurations are examples and regardless of the configurations discussed above, the system 100 may provide a wide range of functions to analyze the surrounding environment of the vehicle 200 and navigate and / or otherwise control and / or operate the vehicle 200 in response to that analysis. The navigation, control, and / or operation of the vehicle 200 may include enabling and / or disabling (either directly or via an intermediate controller such as the controller mentioned above) various functions, components, devices, modes, systems, and / or subsystems associated with the vehicle 200. The navigation, control, and / or operation may alternatively or additionally include interacting with users, drivers, passengers, passersby, and / or other vehicles or other users who may be located inside or outside the vehicle 200 by, for example, providing visual, audio, tactile, and / or other sensory alerts and / or indications.
[0065] As further discussed in detail below and in accordance with the various disclosed embodiments, system 100 can provide various functions related to autonomous driving, semi-autonomous driving, and / or driver assistance technologies. For example, system 100 can analyze image data, location data (e.g., GPS location information), map data, speed data, and / or data from sensors included in vehicle 200. System 100 can collect data from, for example, image acquisition unit 120, location sensor 130, and other sensors for analysis. Further, system 100 can analyze the collected data to determine whether vehicle 200 should take a certain action and then automatically take the determined action without human intervention. It will be appreciated that in some cases, the actions taken automatically by the vehicle are under human supervision, and the ability of a human to intervene, adjust, abort, or override the machine's actions is enabled in certain cases or at all times. For example, when vehicle 200 is traveling without human intervention, system 100 can automatically control the braking, acceleration, and / or steering of vehicle 200 (e.g., by sending control signals to one or more of throttle system 220, braking system 230, and steering system 240). Further, system 100 can analyze the collected data and issue warnings, instructions, recommendations, alerts, or commands to the driver, passengers, users, or others inside or outside the vehicle (or to other vehicles) based on the analysis of the collected data. Additional details regarding the various embodiments provided by system 100 are provided below.
[0066] The following terms and mathematical or textual expressions are used in the following text and figures. It should be noted that the term can be represented by other mathematical or textual expressions. For example, the second part of the message signature can be generated in various ways, and HMAC K is merely an example of the above second part. Other expressions can be used to represent other techniques for generating the above second part.
[0067] Message (M).
[0068] Message signature (S).
[0069] First part of the message signature (V).
[0070] Second part (HMAC K (M)).
[0071] Secret key (K).
[0072] First member secret Also referred to as the first intermediate matrix element.
[0073] Second member secret Also known as the second intermediate matrix element.
[0074] Random vector (L j )。
[0075] First set of secrets (Ai).
[0076] Second set of secrets (Bi).
[0077] Random vector assigned to eligible members
[0078] First product
[0079] First factor
[0080] Second product
[0081] Second factor
[0082] First base
[0083] First intermediate product
[0084] First intermediate factor
[0085] Second intermediate product
[0086] Second intermediate factor
[0087] Verification secret key (K’).
[0088] First verification product
[0089] First verification factor
[0090] Second verification product
[0091] Second verification factor
[0092] Verification intermediate result (H′ = HMAC K′ (M)).
[0093] Member secret
[0094] Random matrix (E x )。
[0095] Inverse of the random matrix (Ex -1 )。
[0096] Intermediate matrix
[0097] Third matrix
[0098] Factor matrix
[0099] Third intermediate matrix
[0100] Other intermediate matrix
[0101] Many services and applications are based on data collected by a collection unit (also referred to as a collection device) from eligible members. The collection unit can be a computerized system, or can include one or more computerized systems, one or more computerized subsystems, and so on. The collection unit can include communication circuitry to send and receive data from vehicles, sensors, or other data producers. For example, a road map application or a traffic control application collects data from many vehicles and generates maps, traffic load estimates, and so on. The collection unit can also include one or more processors for executing instructions to perform the methods and processes described herein.
[0102] An eligible member is a member eligible to provide data. A member can become an eligible member by applying any authentication and / or registration and / or other process.
[0103] An eligible member can be any type of data generating device, including vehicles, roadside units, sensor devices, monitoring devices, or other such devices. The data provided by an eligible member can be related to traffic, road conditions, or any other content.
[0104] A collection entity can aggregate information from multiple members, all of which are members of a group of eligible members. The collection unit is configured to collect only information sent from members with valid eligibility in the group.
[0105] Figure 4 An example of a system and multiple eligible members is shown. Figure 4 Includes a trusted unit 420, a collection unit 430, a processing unit 440, a network 410, a database 450, and eligible members such as a vehicle 402.
[0106] The trusted unit 420, the collection unit 430, and the processing unit 440 may include or be implemented using one or more computers. The trusted unit 420 may be trusted in the sense that it can generate and save secrets in a secure manner. The trusted unit 420 may be implemented using a secure enclave, a trusted execution environment (TEE), or other fortified security devices. Various methods may be used to isolate the trusted unit 420 from the collection unit 430 and the processing unit 440. For example, although a random access memory device may be shared between the trusted unit 420 and other units (the collection unit 430 or the processing unit 440), the area of the memory device used by the trusted unit 420 is encrypted.
[0107] The collection unit 430 is configured to collect data from eligible members and verify that the data was indeed sent from an eligible member. The processing unit 440 may process data from eligible members (e.g., generate a map) and store the result of the processing in the database 450. The processing unit 440 may be implemented using a processor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or any other programmable device or a device designed and hardwired to perform the functions described herein.
[0108] Anonymity is guaranteed for eligible members. The collection unit 430 cannot trace the identity of the sending delegated member. Further, the collection unit 430 cannot determine whether two messages originated from the same source. That is, the scheme maintains the anonymity of a given source. The security of the scheme relies on the assumption that the sequence of all signatures generated by the same group of members cannot be collected.
[0109] The scheme also provides for the revelation of user identity in certain special cases. For example, in certain special cases, such as when a member violates the usage rules, it is possible to trace back to discover the identity of the message originator. This ability is provided by introducing a trusted party that knows the secrets of all participants in the scheme and their identities as group members to whom they were distributed. The trusted party will also generate the secrets used by the scheme. In Figure 4 the environment shown, the trusted party is embodied in the trusted unit 420.
[0110] The scheme may provide additional security requirements, such as Non Impersonation and Traitor Tracing.
[0111] For non - imitation, a strategy can be implemented in a situation where one eligible member cannot imitate another eligible member. Generally, a coalition of group members of reasonable size with valid eligibility cannot imitate another valid group member outside the coalition. That is, they cannot generate a message and signature that, when sent to a trusted party, will cause the trusted party to act as if the message was received from a group member outside the coalition.
[0112] Another strategy is to provide traitor tracing. Generally, traitor tracing means that a coalition of valid group members (traitors) can generate new pseudo - group members such that the new pseudo - members can create signatures that are accepted by the collection unit. What is required is that once a coalition of traitors of reasonable size has generated a pseudo - signature, the trusted party can use the pseudo - signature to trace the identity of the traitors.
[0113] A method, system, and computer - readable medium are provided to implement a scheme for anonymously collecting data from eligible members.
[0114] The introduction of the proposed scheme (“the first scheme”) can be in a finite field F p , on which all algebraic operations can be performed. The number p (the number of bits representing a member in the finite field) should be long, for example, at least 160 bits. A variant of the scheme is also presented as “the second scheme”. The second scheme is not affected by a coalition of traitors who attempt to create a pseudo - identity and present a pseudo - signature. This second scheme works on a digital ring modulo N, where N is the product of two large prime numbers and factoring N into its prime factors is difficult. The scheme can be symmetric.
[0115] First solution
[0116] Generally, several operations are used to implement a scheme for anonymous data collection. In the first operation, secrets are generated. These secrets are stored in a trusted unit. In the second operation, a group member generates a signature for a message. The signature, along with the message, is transmitted to the collection unit. In the third operation, the collection unit verifies the signature. This is further discussed in Figures 5 - 7 In
[0117] Figure 5 is a flowchart showing a method 500 for generating secrets according to an embodiment. At 502, a trusted party can generate two or more secret sequences {A1,..., A n} and {B1,..., B n}, such that A i , B j∈ {1,..., p - 1}, where p is the size of the field F, and where the size of n is greater than 100 and can be on the order of hundreds. These two secret sequences are given to the collection unit for signature verification of group members.
[0118] At 504, for each eligible group member x, the trusted party generates m vectors where the size of m is greater than twenty (e.g., in the dozens), and where each vector is a vector of n small integer values such that, with respect to the small value D1, and the value is randomly selected from the range [-D1, D1].
[0119] Together with each vector two secrets are generated using the following formula:
[0120]
[0121]
[0122] At 506, these secrets - the vectors and the elements 1 ≤ j ≤ m_ are given to the group member x.
[0123] Figure 6 is a flowchart showing a method 600 for generating a signature of a message by a group member according to an embodiment.
[0124] At 602, an eligible group member can receive the secrets generated by method 500, namely and the elements 1 ≤ j ≤ m.
[0125] At 604, the group member x randomly selects m small integer values L from the range [-D2, D2] j , such that not all L j are 0.
[0126] At 606, the group member calculates the linear combination: and the value: K is used as the secret key for a standard symmetric digital signature of the message M, such as HMAC. Any other method for generating a secret key (other than HMAC) can be used. Thus, the digital signature S is a pair: (V, HMAC K (M))
[0127] At 608, the digital signature S is sent to the collection unit.
[0128] Figure 7It is a flowchart of a method 700 for verifying the signature of a message according to an embodiment. The signature can be verified by a collection unit. The collection unit receives the message M and the signature (V, HMAC K (M)). The verification of the signature is performed through the following steps.
[0129] At 702, the collection unit verifies that V≠0. If V = 0, the signature is invalid and rejected.
[0130] At 704, the collection unit calculates the key K′ using the equation.
[0131]
[0132] At 706, the collection unit performs a hash on the message M using the key K′. In particular, the collection unit calculates H′ = HMAC K ′(M).
[0133] At 708, a comparison is made between the generated hash H’ and the hash value HMAC K (M) sent in the signature S. If H′ = HMAC K (M), the signature is accepted. Otherwise, the signature is rejected. It can be verified according to the definition of V, K that a valid signature of the message M means K′ = K, so the signature is accepted.
[0134] The signature scheme is secure. To prove that the signature scheme is secure, it should be shown that an attacker who sees k valid signatures S1,..., S k of the messages M1,..., M k cannot produce a valid signature of the message . Suppose a valid signature of a new message M′ (i.e., for (V″, HMAC K″ (M′))) is produced. The security assumption of the HMAC scheme implies that it cannot be completed without knowing K″, i.e., the attacker would need to know the value of the non - zero vector V″
[0135] According to the HMAC security assumption, seeing the messages M1,..., M k and their signatures S1,..., S k does not give the attacker information about the key used to calculate their HMAC signatures. The hardness assumption is that even given the unknown values A1,..., A n and B1,..., B n and the corresponding vectors V1,..., V k of the values K1,..., K k , it is difficult to infer K″ for a new vector V″.
[0136] Additionally, the scheme also provides anonymity for the signer. The signature of message M can include a pair of signatures (V, HMAC K (M)), where the value HMAC K (M) cannot be distinguished from a random string unless K is known. Therefore, those who do not know K cannot distinguish the signatures of different group members using only HMAC K (M).
[0137] The key K is derived from the secrets {A1,..., A n} and {B1,..., B n} using V. However, inferring any information about K generated by the new vector V is considered a difficult problem (even if some oracles polynomially reveal many values {K i} i∈I corresponding to the vector set {V i} i∈I . In summary, the only information that an attacker can use to distinguish the signed messages of one group member from those of another group member is the vector V. The content of the message is not considered valid information for this task because the message can be encrypted.
[0138] Recall that the vector V is generated by the group member x as a linear combination of the secret vector and small integer coefficients L j , resulting in
[0139] The collecting unit and the observer in the communication do not have any information about the vector set or which vector set is assigned to which group member. For them, the vector V looks like a random vector of small n - integer values. In fact, even if the same group member generates up to m V vectors, they cannot be distinguished from m random small - integer - value vectors. However, if the same group member generates m + 1 V vectors, it is possible to distinguish them from m + 1 random small - value vectors because the (m + 1)×n matrix formed by these m + 1 line vectors has rank m, while a random set of m + 1 vectors has rank m + 1, and m < n.
[0140] Once the collecting unit (or the observer) knows m vectors V generated by a specific group member x, the anonymity feature of the scheme for the specific group member x is broken. Therefore, anonymity remains related to the security assumption that it is difficult to collect a set of m V vectors generated by the same group member.
[0141] In a practical situation, the anonymity of the group members should be preserved regardless of the number of signatures they generate or the number of signatures collected by the attacker. This requirement is met in the following scenarios:
[0142] a. The observed message traffic and their corresponding signatures are generated by several group members. An attacker collecting signatures cannot split the signatures into groups of messages from the same group member.
[0143] b. Each group member has several instances of the signature scheme, each with different parameters. Whenever it wishes to sign a message, it randomly selects one of the signature schemes to use for signing.
[0144] Both scenarios guarantee that messages with signatures generated by the same scheme are randomly mixed in with other messages.
[0145] The anonymity argument depends on the assumption that it is a difficult problem (in terms of non-deterministic polynomial time) to select a subset of signatures generated by the same scheme from a larger set of signatures.
[0146] The only information an attacker can use to reveal the signer's identity is the set of vectors C = {V1,..., V k}; V i ∈Z n . The attacker must find a subset of at least m + 1 vectors such that the subspace spanned by the vectors in D has a dimension less than or equal to m.
[0147] There are algorithms to solve this problem; however, they require either a small number of signature schemes involved or a small m. In our example, a large m and a large enough number of schemes involved should be used to solve the signer's identity problem.
[0148] There are certain situations in which the identity of the group member generating the message with the corresponding signature must be revealed. Such revelation of the signer's identity can be done with the help of a trusted party that knows the set of vectors
[0149] The signature has the form (V, HMAC K (M)), and the vector V is a linear combination of the vectors of some x . All possible x can be checked using the Gaussian elimination algorithm, regardless . The identity x is most likely to be unique. For random vectors and we have as long as m < n / 2..
[0150] When we divide the group members into n supergroups of almost equal size and require that for each supergroup y there exists a vector W y ∈Z n , for each x ∈ y and When this occurs, the process can be faster. That is, all and W y have a scalar product equal to 0 modulo p.
[0151] That is to say, the tracing is done as follows:
[0152] a. Find y such that <V, W y > = 0 mod p
[0153] b. Find x ∈ y such that
[0154] If we choose this method, the generation of vectors of x ∈ y is more complex and requires the use of the lattice basis reduction algorithm.
[0155] The coalition of traitors refers to the scenario where there are two (or more) schemes, that is, a given group member has the secret of group member x: and as well as the secret of group member x': and A given group member can create a new pseudo-identity z as follows:
[0156] For each 1 ≤ j ≤ m, choose 2m small integer values t j,i (1 ≤ i ≤ 2m):
[0157]
[0158]
[0159]
[0160] Second solution
[0161] It may provide a scheme that can provide security against traitors attempting to generate new pseudo-identities. The algebraic operations in this scheme are carried out in the ring of integers modulo a large number N, where the large number N is the product of two secret large prime numbers P and Q such that N = P · Q.
[0162] Factoring N into its prime factors is considered an intractable difficult problem. As explained in the previous section, several group members can collude and use their secrets to generate a new set of secrets. This is enabled because the secret terms belonging to any two identities x and x': and can be multiplied.
[0163] The new construction enables the calculation of the key K (depending on the vector V), however, combining the secrets of two different group members is as difficult as factoring N into its prime factors.
[0164] Similar to the first solution, several operations are used to implement the second solution for anonymous data collection. In the first operation, secrets are generated. These secrets are stored in a trusted unit. In the second operation, the signature of the message is generated by the group members. The signature is transmitted to the collection unit together with the message. In the third operation, the collection unit verifies the signature. This is further discussed in Figures 8 - 9 .
[0165] Figure 8 is a flowchart showing a method 800 for generating secrets according to an embodiment; at 802, a trusted party generates two sequences of secrets {A1,..., A n} and {B1,..., B n}, such that A i , B j ∈ {1,..., N - 1}, where N is the product of two secret large prime numbers P and Q, the size of n is greater than 100, and may be as large as several hundred. These two sequences of secrets are given to the collection unit for signature verification of the group members.
[0166] At 804, for each eligible group member x, the trusted party generates m vectors where the size of m is close to n, and can even be n - 1. Each vector is a vector of n small integer values, such that for a small value D1, the value is randomly selected from the range [-D1, D1].
[0167] Together with each vector , two secrets a and b are generated, where the
[0168] In addition, a random 2×2 matrix E x is selected, and the following set of m matrices is calculated.
[0169] At 806, for each group member x, the vector and the matrix
[0170] Figure 9 is a flowchart showing a method 900 for generating the signature of a message by a group member according to an embodiment. At 902, an eligible member x can receive and the element 1 ≤ j ≤ m.
[0171] At 904, the group member x randomly selects m small integer values L from the range [-D2, D2] jsuch that not all L j is 0.
[0172] At 906, the group members compute the following linear combination: Sum value: The trace of a matrix is the sum of the elements on the diagonal. K is used as the secret key for a standard symmetric digital signature of message M, such as HMAC. Any other method for generating the secret key (other than HMAC) can be used.
[0173] The digital signature S is the pair: (V, HMAC K (M)).
[0174] At 906, the digital signature is sent to the collection unit together with the message.
[0175] Figure 10 is a flowchart of method 1000 for verifying the signature of a message according to an embodiment.
[0176] The signature can be verified by the collection unit. The collection unit receives the message M and the signature (V, HMAC K (M)). Verification of the signature is performed through the following steps.
[0177] At 1002, the collection unit verifies that V≠0. If V = 0, the signature is invalid and rejected.
[0178] At 1004, the collection unit computes the key K'. This can be performed similar to how the key K' was computed in operation 704 discussed above.
[0179] It should be noted that the two methods of generating K produce the same value. That is (from operation 606) and (from operation 906) produce the same value of K. Thus for both schemes, the verification of the computation of K' can be the same.
[0180] Therefore, the two methods produce the same value of K. However, in the first version, the coalition of dishonest users can produce a new valid identity, which cannot be traced if needed, while in the second version, the coalition of dishonest users cannot use their secret matrices to generate new identities. This is because each user has its secret matrix encoded in a different matrix subspace, and if matrices from different subspaces can be combined to form a new identity, then N can be factored into its prime factors, which is considered a difficult problem. It can be seen that the actual value of K computed by both schemes is exactly the same, which is why the central unit performs verification in the same way for both versions.
[0181] At 1006, the collection unit performs a hash on the message M using the key K'. In particular, the collection unit calculates H′ = HMAC K′ (M).
[0182] At 1008, a comparison is made between the generated hash H' and the hash value HMAC K (M) sent in the signature S. If H′ = HMAC K (M), the signature is accepted. Otherwise, the signature is rejected. It is possible to verify that a valid signature of the message M means K′ = K according to the definition of V, K, so the signature is accepted.
[0183] The same aspects of security apply to the variant scheme (i.e., the second scheme) as they do to the first scheme. Similarly, aspects of anonymity also apply to the variant scheme. Here, when we take m = n - 1, the aspect of anonymity is even better than in the previous scheme; however, we do require that the signatures come from multiple group members such that they cannot be partitioned according to their origin. In the case where this requirement does not hold, then the second requirement is that whenever a message is to be signed, each group member uses a random set of keys selected from its key set. For m = n - 1, and for n of size several hundred, each group member having 7 - 8 key sets provides good anonymity.
[0184] The second scheme also provides a mechanism for revealing the identity of the signer. To identify the identity of the message sender, the trusted unit stores a vector W x ∈Z n for each group member x, satisfying: for all 1 ≤ i ≤ m, When the identity of the message sender is to be traced, the trusted unit extracts the vector V from the signature and checks whether <V, W y > = 0 for each identity y.
[0185] In the scenario of coalition of traitors, the secrets of at least two group members x and x' are used and calculations are introduced for some non - zero integer vectors T = (t1,..., t m ) and T′ = (t′1,..., t′ m ) to construct a pseudo - identity.
[0186] The secret matrix of x is: The secret matrix of x' is:
[0187] Define the matrices: and
[0188] Being able to calculate α means that one can partition the set of messages {C x′T′, I} The linear subspace of the generated matrix is embedded into the linear subspace of the matrix generated by {C xT , I}, and this embedding preserves the characteristic polynomial of the input matrix.
[0189] It can be shown that if such an embedding can be constructed between these matrix subspaces, then he can factor N. This result implies the difficulty of using colluding traitors to forge identities.
[0190] Figure 11 is an example of method 1100 performed by a collection unit according to an embodiment to implement the first scheme. Method 1100 is used to collect data from a group of eligible members.
[0191] At 1102, the collection unit receives a message and a message signature. The message signature received from an eligible member includes a first part and a second part. The second part is generated using a secret key. The secret key is calculated by applying a first plurality of mathematical operations to a first member secret assigned to the eligible member, a second member secret assigned to the eligible member, and a random vector.
[0192] At 1104, the collection unit verifies whether the message is received from one of the eligible members in the group without identifying the eligible member who sent the message, where the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and the first part of the message signature.
[0193] The first plurality of mathematical operations includes calculating the product of the multiplication of factors with a base and a random exponent. The first member secret is calculated based on the secret of the first set of secrets assigned to the group and a subset of the random vector assigned to the eligible member. The second member secret is calculated based on the secret of the second set of secrets assigned to the group and a subset of the random vector assigned to the eligible member. The first member secret and the second member secret are calculated by applying modular arithmetic and additional operations. The collection unit has access to the first set of secrets and the second set of secrets, but does not know the assignment of the first member secret and the second member secret to the eligible members of the group.
[0194] At 1106, when the message is not received from any eligible member in the group, the message is rejected by the collection unit.
[0195] At 1108, when the message is received from one of the eligible members in the group, the data embedded in the message is collected.
[0196] In an embodiment, the secret key is a function of a first product of a multiplication of a first factor and a second product of a multiplication of a second factor. In a further embodiment, each first factor has a first base calculated by applying a modulo operation (mod p) to a first intermediate product of a multiplication of a first intermediate factor. In a further embodiment, each second factor is a second base calculated by applying a modulo operation to a second intermediate product of a multiplication of a second intermediate factor.
[0197] In another embodiment, the first intermediate factor has a base that is a secret from a first set of secrets and has a random exponent that is an element of a subset of a random vector assigned to an eligible member; and the second intermediate factor has a base that is a secret from a second set of secrets and has a random exponent that is an element of a subset of a random vector assigned to an eligible member.
[0198] In an embodiment, verification includes calculating a verification secret key by a collection unit as a function of the first set of secrets, the second set of secrets, and a first part of the message signature. In a further embodiment, verification includes applying a modulo operation to a first verification product of a multiplication of a first verification factor and applying a modulo operation to a second verification product of a multiplication of a second verification factor.
[0199] In an embodiment, different first verification factors have bases that are secrets different from the first set of secrets and have different random exponents. In such embodiments, different second verification factors have bases that are secrets different from the second set of secrets and have different random exponents that belong to a second part of the message signature. In a further embodiment, the second part of the message signature is generated using an encryption process, where verification includes applying the encryption process using the verification secret key to provide a verification intermediate result. In a further embodiment, verification includes comparing the verification intermediate result with the second part of the signed message; and determining that the message is received from any one of the eligible members of the group when the first part of the message signature is non-zero and the verification intermediate result is equal to the second part of the signed message.
[0200] In an embodiment, a first plurality of mathematical operations are calculated over a finite field having a predefined size (p), where the modulo operation has a divisor equal to the predefined size.
[0201] In an embodiment, the collected data can be further processed by a processing unit.
[0202] Figure 12 is an example of method 1200 performed by a collection unit according to an embodiment to implement a second scheme. Method 1200 is for collecting data from a group of eligible members.
[0203] At 1202, a collection unit receives a message and a message signature. The message signature received from an eligible member includes a first part and a second part. The second part is generated using a secret key. The secret key is calculated by applying a first plurality of mathematical operations to a member secret and a random vector assigned to the eligible member.
[0204] At 1204, the collection unit verifies whether the message is received from one of the eligible members in the group without identifying the eligible member that sent the message, where the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and the first part of the message signature.
[0205] The first plurality of mathematical operations includes modular arithmetic and the calculation of a product of a multiplication having a base and a factor with a random exponent. The member secret is calculated based on secrets from a subset of a first set of secrets assigned to the group, a second set of secrets assigned to the group, a random matrix, and a random vector assigned to the eligible member. The collection unit has access to the first set of secrets and the second set of secrets, but does not know the assignment of the member secrets to the eligible members in the group.
[0206] At 1206, when the message is not received from any of the eligible members in the group, the message is rejected by the collection unit.
[0207] At 1208, when the message is received from one of the eligible members in the group, data embedded in the message is collected.
[0208] In an embodiment, the secret key is a function of a set of matrices, where different matrices in the set are functions of a random matrix, the inverse of the random matrix, and an intermediate matrix including a first intermediate matrix element and a second intermediate matrix element. In a further embodiment, the first intermediate matrix element is a first intermediate product of a multiplication of first intermediate factors; and wherein, the second intermediate matrix element is a second intermediate product of a multiplication of second intermediate factors.
[0209] In an embodiment, the first intermediate factor has a base that is a secret from the first set of secrets and a random exponent that is an element of a subset of the random vector assigned to the eligible member; and the second intermediate factor has a base that is a secret from the second set of secrets and a random exponent that is an element of a subset of the random vector assigned to the eligible member.
[0210] In an embodiment, the intermediate matrix is a diagonal matrix, the secret key is the trace of a third matrix, the third matrix is a product of a multiplication of factor matrices, each factor matrix having a random exponent and a base that is a third intermediate matrix, where different third intermediate matrices are products of a multiplication of a random matrix by a different intermediate matrix and by the inverse of the random matrix.
[0211] For example, any method in a method of describing steps may include: more steps than those illustrated in the figures, only the steps illustrated in the figures, or substantially only the steps illustrated in the figures. This also applies to components of a device, processor, or system and instructions stored in any non-transitory computer-readable storage medium.
[0212] The embodiments disclosed herein may also be implemented in a computer program for running on a computer system, including at least a code portion for performing the steps of the method according to the present invention when running on a programmable device such as a computer system, or causing the programmable device to perform the functions of the device or system according to the present invention. The computer program may cause the storage system to allocate disk drives to disk drive groups.
[0213] A computer program includes instructions for executing a specific application and / or operating system. A computer program may, for example, include one or more of the following: subroutines, functions, programs, object methods, object implementations, executable applications, micro-applications, small service programs, source code, object code, shared libraries / dynamic loading libraries, and / or other instruction sequences designed to execute on a computer system.
[0214] The computer program may be internally stored on a non-transitory computer-readable medium. All or some of the computer program may be provided on a computer-readable medium that is permanently, removably, or remotely coupled to the information processing system. The computer-readable medium may include, for example but not limited to, any number of media such as: magnetic storage media, including disk and tape storage media; optical storage media (such as compact disk media (e.g., CD-ROM, CD-R, etc.)) and digital video disk storage media; non-volatile memory storage media, including semiconductor-based memory cells (such as flash memory, EEPROM, EPROM, ROM); ferromagnetic digital memory; MRAM; volatile storage media, including registers, buffers, or caches, main memory, RAM, etc.
[0215] A computer process generally includes a program or a part of a program that is being executed (running), current program values and status information, and resources used by the operating system to manage the execution of the process. The operating system (OS) is software that manages the sharing of computer resources and provides an interface for programmers to access those resources. The operating system processes system data and user input and responds by allocating and managing tasks and internal system resources as a service to the users and programs of the system.
[0216] A computer system may include, for example, at least one processing unit, an associated memory, and multiple input / output (I / O) devices. When executing a computer program, the computer system processes information according to the computer program and generates result output information via the I / O devices.
[0217] In the foregoing specification, the invention has been described with reference to specific examples of embodiments of the invention. However, it will be apparent that various modifications and changes can be made to these embodiments without departing from the broader spirit and scope of the invention as set forth in the appended claims.
[0218] Moreover, the terms "front", "rear", "top", "bottom", "upper", "lower", etc. (if any) in the specification and claims are used for descriptive purposes and not necessarily to describe a permanent relative position. It should be understood that such terms are interchangeable under appropriate circumstances, such that embodiments of the invention described herein can operate in other orientations different from those illustrated or otherwise described herein.
[0219] The connections discussed herein can be any type of connection suitable for transmitting signals, for example, from or to corresponding nodes, units, or devices via an intermediate device. Thus, unless implied or stated otherwise, the connections can be, for example, direct connections or indirect connections. The connections can be shown or described with reference to being a single connection, multiple connections, unidirectional connections, or bidirectional connections. However, different embodiments can vary the implementation of the connections. For example, separate unidirectional connections can be used instead of bidirectional connections, and vice versa. Additionally, multiple connections can be replaced by a single connection that transmits multiple signals in a serial or time-division multiplexed manner. Similarly, a single connection carrying multiple signals can be separated into various different connections carrying subsets of those signals. Thus, there are many options for transmitting signals.
[0220] Although a specific conductivity type or polarity of a potential has been described in the examples, it will be appreciated that the conductivity type and the polarity of the potential can be reversed.
[0221] Each signal described herein can be designed as positive logic or negative logic. In the case of a negative logic signal, the signal is active low when the logical true state corresponds to a logic level 0. In the case of a positive logic signal, the signal is active high when the logical true state corresponds to a logic level 1. It should be noted that any of the signals described herein can be designed as a negative logic signal or a positive logic signal. Thus, in alternative embodiments, those signals described as positive logic signals can be implemented as negative logic signals, and those signals described as negative logic signals can be implemented as positive logic signals.
[0222] In addition, the terms "assert" or "set" and "negate" (or "de-assert" or "clear") are used herein to refer to presenting a signal, status bit, or similar device in its logically true or logically false state, respectively. If the logical true state is a logic level 1, the logical false state is a logic level 0. And if the logical true state is a logic level 0, the logical false state is a logic level 1.
[0223] Those skilled in the art will recognize that the boundaries between logic blocks are merely illustrative, and alternative embodiments may combine logic blocks or circuit elements, or impose alternative functional decompositions on various logic blocks or circuit elements. Thus, it should be understood that the architecture depicted in the text is merely exemplary, and in fact, many other architectures that achieve the same functionality can be implemented.
[0224] Any arrangement of components that achieves the same functionality is effectively "associated" such that the desired functionality is achieved. Thus, any two components herein combined to achieve a particular functionality can be considered "associated" with each other to achieve the desired functionality, regardless of the architecture or intermediate components. Similarly, any two components so associated can also be considered "operably connected" or "operably coupled" to each other to achieve the desired functionality.
[0225] Furthermore, those skilled in the art will recognize that the boundaries between the above operations are merely illustrative. Multiple operations can be combined into a single operation, a single operation can be distributed among additional operations, and operations can be performed at least partially overlapping in time. Additionally, alternative embodiments may include multiple instances of a particular operation, and the order of operations can be changed in various other embodiments.
[0226] Also, for example, in one embodiment, the illustrated embodiments can be implemented as circuits located on a single integrated circuit or within the same device. Alternatively, these examples can be implemented as any number of separate integrated circuits or separate devices interconnected in a suitable manner.
[0227] In addition, for example, an example or a portion thereof can be implemented as a physical circuit or a soft representation or code representation that can be converted into a physical circuit, such as in any suitable type of hardware description language.
[0228] Moreover, the present invention is not limited to physical devices or units implemented in non-programmable hardware, and can also be applied to programmable devices or units capable of performing the desired device functions by operating in accordance with appropriate program code, such as hosts, minicomputers, servers, workstations, personal computers, laptop computers, personal digital assistants, electronic games, automobiles, and other embedded systems, cellular phones, and various other wireless devices, generally referred to as "computer systems" in this application.
[0229] However, other modifications, variations and alternatives are also possible. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a restrictive sense.
[0230] Additional notes and examples:
[0231] Example 1 is a collection device for collecting data from a group of eligible members, the collection device comprising: a communication circuit for receiving a message and a message signature from an eligible member; and a hardware processor for: verifying whether the message is received from one of the eligible members of the group without identifying the eligible member who sent the message, wherein the verification comprises applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first portion of the message signature; rejecting the message when the message is not received from any of the eligible members of the group; and collecting data embedded in the message when the message is received from one of the eligible members of the group; wherein the message signature received from an eligible member comprises a first portion and a second portion; wherein the second portion is generated using a secret key; wherein the secret key is calculated by applying a first plurality of mathematical operations to a first member secret assigned to the eligible member, a second member secret assigned to the eligible member, and a random vector; wherein the first plurality of mathematical operations comprises calculating a product of multiplications of factors having a base and a random exponent; wherein the first member secret is calculated based on a secret from a first set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; wherein the second member secret is calculated based on a secret from a second set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; wherein the first member secret and the second member secret are calculated by applying a modulo operation and an additional operation; and wherein the collection device has access to the first set of secrets and the second set of secrets but does not know the assignment of the first member secret and the second member secret to the eligible members of the group.
[0232] In Example 2, the subject matter of Example 1 includes, wherein the secret key is a function of a first product of multiplications of a first factor and a second product of multiplications of a second factor.
[0233] In Example 3, the subject matter of Example 2 includes, wherein each first factor has a first base, which is calculated by applying a modulo operation (mod p) to a first intermediate product of multiplications of a first intermediate factor.
[0234] In Example 4, the subject matter of Example 3 includes, wherein each second factor is a second base, which is calculated by applying a modulo operation to a second intermediate product of multiplications of a second intermediate factor.
[0235] In Example 5, the subject matter of Example 4 includes where the first intermediate factor has as its base a secret from the first set of secrets and has as an element of a subset of the random vectors assigned to eligible members a random exponent; and where the second intermediate factor has as its base a secret from the second set of secrets and has as an element of a subset of the random vectors assigned to eligible members a random exponent.
[0236] In Example 6, the subject matter of Examples 1 - 5 includes where the verification includes calculating a verification secret key as a function of the first set of secrets, the second set of secrets, and the first part of the message signature.
[0237] In Example 7, the subject matter of Example 6 includes where the verification includes applying a modulo operation to a first verification product of a multiplication of a first verification factor; and applying a modulo operation to a second verification product of a multiplication of a second verification factor.
[0238] In Example 8, the subject matter of Examples 1 - 7 includes where different first verification factors have as their bases secrets different from the first set of secrets and have different random exponents; where different second verification factors have as their bases secrets different from the second set of secrets and have the different random exponents; and where the different random exponents belong to the second part of the message signature.
[0239] In Example 9, the subject matter of Example 8 includes where the second part of the message signature is generated using an encryption process; where the verification includes applying the encryption process using the verification secret key to provide a verification intermediate result.
[0240] In Example 10, the subject matter of Example 9 includes where the verification includes comparing the verification intermediate result with the second part of the signed message; and determining that the message is received from any one of the eligible members of the group when the first part of the message signature is non - zero and the verification intermediate result is equal to the second part of the signed message.
[0241] In Example 11, the subject matter of Examples 1 - 10 includes where the first plurality of mathematical operations are calculated over a finite field having a predefined size (p), where the modulo operation has a divisor equal to the predefined size.
[0242] Example 12 is a method for collecting data from a group of eligible members, the method comprising: receiving, by a collection unit, a message and a message signature; verifying, by the collection unit, whether the message is received from an eligible member among the eligible members of the group without identifying the eligible member who sent the message, wherein the verification comprises applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first portion of the message signature; rejecting, by the collection unit, the message when the message is not received from any eligible member of the group; and collecting, when the message is received from an eligible member among the eligible members of the group, data embedded in the message; wherein the message signature received from an eligible member comprises a first portion and a second portion; wherein the second portion is generated using a secret key; wherein the secret key is calculated by applying a first plurality of mathematical operations to a first member secret assigned to the eligible member, a second member secret assigned to the eligible member, and a random vector; wherein the first plurality of mathematical operations comprises calculating a product of multiplications of factors having a base number and a random exponent; wherein the first member secret is calculated based on a secret from a first set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; wherein the second member secret is calculated based on a secret from a second set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; wherein the first member secret and the second member secret are calculated by applying a modulo operation and an additional operation; and wherein the collection unit has access to the first set of secrets and the second set of secrets but does not know the assignment of the first member secret and the second member secret to the eligible members of the group.
[0243] In Example 13, the subject matter of Example 12 includes, wherein the secret key is a function of a first product of multiplications of a first factor and a second product of multiplications of a second factor.
[0244] In Example 14, the subject matter of Example 13 includes, wherein each first factor has a first base number, which is calculated by applying a modulo operation (mod p) to a first intermediate product of multiplications of a first intermediate factor.
[0245] In Example 15, the subject matter of Example 14 includes, wherein each second factor is a second base number, which is calculated by applying a modulo operation to a second intermediate product of multiplications of a second intermediate factor.
[0246] In Example 16, the subject matter of Example 15 includes, wherein the first intermediate factor has a base number from the first set of secrets and a random exponent that is an element of a subset of the random vector assigned to the eligible member; and wherein the second intermediate factor has a base number that is a secret from the second set of secrets and a random exponent that is an element of a subset of the random vector assigned to the eligible member.
[0247] In Example 17, the subject matter of Examples 12 - 16 includes where the verification includes calculating a verification secret key by a collection unit according to a function of a first set of secrets, a second set of secrets, and a first part of a message signature.
[0248] In Example 18, the subject matter of Example 17 includes where the verification includes: applying a modulo operation to a first verification product of a multiplication of a first verification factor; and applying a modulo operation to a second verification product of a multiplication of a second verification factor.
[0249] In Example 19, the subject matter of Examples 12 - 18 includes where different first verification factors have bases that are secrets different from the first set of secrets and have different random exponents; where different second verification factors have bases that are secrets different from the second set of secrets and have the different random exponents; and where the different random exponents belong to a second part of the message signature.
[0250] In Example 20, the subject matter of Example 19 includes where a second part of the message signature is generated using an encryption process; and where the verification includes using the verification secret key to apply the encryption process to provide a verification intermediate result.
[0251] In Example 21, the subject matter of Example 20 includes where the verification includes comparing the verification intermediate result with the second part of the signed message; and determining that the message is received from any of the eligible members of the group when the first part of the message signature is non - zero and the verification intermediate result is equal to the second part of the signed message.
[0252] In Example 22, the subject matter of Examples 12 - 21 includes where a first plurality of mathematical operations are calculated over a finite field having a predefined size (p), and where the modulo operation has a divisor equal to the predefined size.
[0253] Example 23 is a non-transitory computer-readable medium including instructions for collecting data from a group of eligible members, which when executed by a machine cause the machine to perform operations including: receiving, by a collection unit, a message and a message signature; verifying, by the collection unit, whether the message is received from an eligible member among the eligible members of the group without identifying the eligible member who sent the message, wherein the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; rejecting, by the collection unit, the message when the message is not received from any eligible member of the group; and collecting, when the message is received from an eligible member among the eligible members of the group, data embedded in the message; wherein the message signature received from an eligible member includes a first part and a second part; wherein the second part is generated using a secret key; wherein the secret key is calculated by applying a first plurality of mathematical operations to a first member secret assigned to an eligible member, a second member secret assigned to the eligible member, and a random vector; wherein the first plurality of mathematical operations includes calculating a product of multiplications of factors having a base and a random exponent; wherein the first member secret is calculated based on a secret from a first set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; wherein the second member secret is calculated based on a secret from a second set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; wherein the first member secret and the second member secret are calculated by applying a modulo operation and an additional operation; and wherein the collection unit has access to the first set of secrets and the second set of secrets but does not know the assignment of the first member secret and the second member secret to the eligible members of the group.
[0254] Example 24 is a collection device for collecting data from a group of eligible members. The collection device includes: a communication circuit for receiving a message and a message signature from an eligible member; and a hardware processor for: receiving the message and the message signature; verifying whether the message is received from one of the eligible members of the group without identifying the eligible member who sent the message, where the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; rejecting the message when the message is not received from any of the eligible members of the group; and collecting the data embedded in the message when the message is received from one of the eligible members of the group; where the message signature received from an eligible member includes a first part and a second part; where the second part is generated using a secret key; where the secret key is calculated by applying a first plurality of mathematical operations to a member secret assigned to the eligible member and a random vector; where the first plurality of mathematical operations includes a modulo operation and a calculation of the product of a multiplication of factors having a base and a random exponent; where the member secret is calculated based on a secret from a first set of secrets assigned to the group, a secret from a second set of secrets assigned to the group, a random matrix, and a subset of the random vector assigned to the eligible member; and where the collection unit has access to the first set of secrets and the second set of secrets but does not know the assignment of the member secrets to the eligible members of the group.
[0255] In Example 25, the subject matter of Example 24 includes, where the secret key is a function of a set of matrices, where different matrices in the set are functions of a random matrix, the inverse of the random matrix, and an intermediate matrix including a first intermediate matrix element and a second intermediate matrix element.
[0256] In Example 26, the subject matter of Example 25 includes, where the first intermediate matrix element is a first intermediate product of a multiplication of first intermediate factors; and where the second intermediate matrix element is a second intermediate product of a multiplication of second intermediate factors.
[0257] In Example 27, the subject matter of Examples 25 - 26 includes, where the first intermediate factor has a base from the first set of secrets and a random exponent that is an element of a subset of the random vector assigned to the eligible member; and where the second intermediate factor has a base that is a secret from the second set of secrets and a random exponent that is an element of a subset of the random vector assigned to the eligible member.
[0258] In Example 28, the subject matter of Examples 25-27 includes where the middle matrix is a diagonal matrix and where the secret key is the trace of a third matrix that is the product of the multiplication of factor matrices, each factor matrix having a random exponent and being the base of the third middle matrix, where different third middle matrices are the product of a random matrix multiplied by a different middle matrix and multiplied by the inverse of a random matrix.
[0259] Example 29 is a method for collecting data from a group of eligible members, the method comprising: receiving, by a collection unit, a message and a message signature; verifying, by the collection unit, whether the message was received from one of the eligible members of the group without identifying the eligible member who sent the message, where the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; rejecting, by the collection unit, the message when the message was not received from any of the eligible members of the group; and collecting, when the message was received from one of the eligible members of the group, data embedded in the message; where the message signature received from an eligible member includes a first part and a second part; where the second part is generated using a secret key; where the secret key is calculated by applying a first plurality of mathematical operations to a member secret assigned to the eligible member and a random vector; where the first plurality of mathematical operations includes modular arithmetic and the calculation of the product of the multiplication of factors having a base and a random exponent; where the member secret is calculated based on a secret from a first set of secrets assigned to the group, a secret from a second set of secrets assigned to the group, a random matrix, and a subset of the random vectors assigned to the eligible members; and where the collection unit has access to the first set of secrets and the second set of secrets but does not know the assignment of the member secrets to the eligible members of the group.
[0260] In Example 30, the subject matter of Example 29 includes where the secret key is a function of a set of matrices, where different matrices in the set are functions of a random matrix, the inverse of a random matrix, and a middle matrix including a first middle matrix element and a second middle matrix element.
[0261] In Example 31, the subject matter of Example 30 includes where the first middle matrix element is a first middle product of the multiplication of first middle factors; and where the second middle matrix element is a second middle product of the multiplication of second middle factors.
[0262] In Example 32, the subject matter of Examples 30-31 includes where the first middle factor has as its base a secret from the first set of secrets and has as elements of a subset of the random vectors assigned to the eligible members a random exponent; and where the second middle factor has as its base a secret from the second set of secrets and has as elements of a subset of the random vectors assigned to the eligible members a random exponent.
[0263] In Example 33, the subject matter of Examples 30 - 32 includes where the middle matrix is a diagonal matrix, and where the secret key is the trace of a third matrix that is the product of the multiplication of factor matrices, each factor matrix having a random exponent and serving as the base of the third middle matrix, where different third middle matrices are the product of a random matrix multiplied by a different middle matrix and multiplied by the inverse of a random matrix.
[0264] Example 34 is a non - transient computer - readable medium including instructions for collecting data from a group of eligible members, which when executed by a machine, cause the machine to perform operations including: receiving, by a collection unit, a message and a message signature;
[0265] verifying, by the collection unit, whether the message is received from any eligible member of the group without identifying the eligible member who sent the message;
[0266] wherein the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature;
[0267] when verifying that the message is not received from any eligible member of the group, rejecting the message by the collection unit;
[0268] and when verifying that the message is received from any one of the eligible members of the group, collecting the data embedded in the message;
[0269] wherein the message signature received from an eligible member includes a first part and a second part;
[0270] wherein the second part is generated using a key;
[0271] wherein a secret key is calculated by applying a first plurality of mathematical operations to a member secret assigned to an eligible member and a random vector;
[0272] wherein the first plurality of mathematical operations includes modular arithmetic and calculation of the product of multiplications of factors having a base and a random exponent;
[0273] wherein a member secret is calculated based on a secret from a first set of secrets assigned to the group, a secret from a second set of secrets assigned to the group, a random matrix, and a subset of random vectors assigned to eligible members;
[0274] and wherein the collection unit has access to the first set of secrets and the second set of secrets, but does not know the assignment of member secrets to the eligible members of the group.
[0275] Example 35 is at least one machine-readable medium including instructions that, when executed by a processing circuitry, cause the processing circuitry to perform operations to implement any one of Examples 1-34.
[0276] Example 36 is an apparatus including means for implementing any one of Examples 1-34.
[0277] Example 37 is a system for implementing any one of Examples 1-34.
[0278] Example 38 is a method for implementing any one of Examples 1-34.
[0279] In a claim, any reference signs placed in parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of other elements or steps than those listed in a claim. Further, the terms "a" or "an" as used herein are defined as one or more than one. Also, the use of introductory phrases such as "at least one" and "one or more" in a claim shall not be construed to imply that the introduction of another claim element by the indefinite article "a" or "an" limits any particular claim containing such introduced claim element to inventions containing only one such element, even when the same claim includes the introductory phrases "one or more" or "at least one" and indefinite articles such as "a" or "an". The same holds for the use of definite articles. Terms such as "first" and "second" are used to arbitrarily distinguish between elements so described. Thus, these terms are not necessarily intended to indicate a temporal or other precedence of such elements. The fact that certain measures are recited in mutually different claims does not indicate that a combination of these measures cannot be used to advantage.
[0280] Although certain features of the present invention have been illustrated and described herein, many modifications, substitutions, changes, and equivalents will now occur to those skilled in the art. Accordingly, it is to be understood that the appended claims are intended to cover all such modifications and changes as fall within the true spirit of the present invention.
Claims
1. A collection device for collecting data from a group of eligible members, the collection device comprising: A communication circuit for receiving messages and message signatures from eligible members; And A hardware processor for: Verifying whether the message is received from one of the eligible members of the group without identifying the eligible member who sent the message, wherein the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; Rejecting the message when the message is not received from any eligible member of the group; And Collecting the data embedded in the message when the message is received from one of the eligible members of the group; Wherein the message signature received from an eligible member includes a first part and a second part; Wherein the second part is generated using a secret key; Wherein the secret key is calculated by applying a first plurality of mathematical operations to a first member secret assigned to the eligible member, a second member secret assigned to the eligible member, and a random vector; Wherein the first plurality of mathematical operations includes calculating a product of multiplications of factors having a base number and a random exponent; Wherein the first member secret is calculated based on a secret of the first set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; Wherein the second member secret is calculated based on a secret of the second set of secrets assigned to the group and the subset of the random vector assigned to the eligible member; Wherein the first member secret and the second member secret are calculated by applying modular arithmetic and additional operations; and Wherein the collection device has access to the first set of secrets and the second set of secrets, but does not know the assignment of the first member secret and the second member secret to the eligible members of the group.
2. The collection device according to claim 1, wherein the secret key is a function of a first product of multiplications of a first factor and a second product of multiplications of a second factor.
3. The collection device according to claim 2, wherein each first factor has a first base number, and the first base number is calculated by applying modular arithmetic mod p to a first intermediate product of multiplications of a first intermediate factor.
4. The collection device according to claim 3, wherein each second factor is a second base number, and the second base number is calculated by applying the modular arithmetic to a second intermediate product of multiplications of a second intermediate factor.
5. The collection device according to claim 4, wherein the first intermediate factor has a base number that is a secret from the first set of secrets and a random exponent that is an element of the subset of the random vector assigned to the eligible member; and Among them, The second intermediate factor has a base number that is a secret from the second set of secrets and a random exponent that is an element of the subset of the random vector assigned to the eligible member.
6. The collection device according to claim 1, wherein the verification includes calculating a verification secret key as a function of the first set of secrets, the second set of secrets, and the first part of the message signature.
7. The collection device according to claim 6, wherein the verification includes: applying a modulo operation to a first verification product of a multiplication of a first verification factor; and applying the modulo operation to a second verification product of a multiplication of a second verification factor.
8. The collection device according to claim 1, wherein Different first verification factors have bases that are secrets different from the first set of secrets and have different random exponents; wherein different second verification factors have bases that are secrets different from the second set of secrets and have the different random exponents; and wherein the different random exponents belong to the second part of the message signature.
9. The collection device according to claim 8, wherein, The second part of the message signature is generated using an encryption process; wherein the verification includes applying the encryption process using the verification secret key to provide a verification intermediate result.
10. The collection device according to claim 9, wherein the verification includes comparing the verification intermediate result with the second part of the message signature; and determining that the message is received from any one of the eligible members of the group when the first part of the message signature is non-zero and the verification intermediate result is equal to the second part of the message signature.
11. The collection device according to claim 1, wherein, The first plurality of mathematical operations are calculated over a finite field having a predefined size p, wherein the modulo operation has a divisor equal to the predefined size.
12. A method for collecting data from a group of eligible members, the method comprising: receiving, by a collection unit, a message and a message signature; verifying, by the collection unit, whether the message is received from one of the eligible members of the group without identifying the eligible member that sent the message, wherein the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; rejecting, by the collection unit, the message when the message is not received from any eligible member of the group; and collecting, when the message is received from one of the eligible members of the group, data embedded in the message; wherein the message signature received from the eligible member includes a first part and a second part; wherein the second part is generated using a secret key; wherein the secret key is calculated by applying a first plurality of mathematical operations to a first member secret assigned to the eligible member, a second member secret assigned to the eligible member, and a random vector; wherein the first plurality of mathematical operations include calculating a product of a multiplication of a factor having a base and a random exponent; wherein the first member secret is calculated based on a secret assigned to the first set of secrets of the group and a subset of the random vector assigned to the eligible member; wherein the second member secret is calculated based on a secret assigned to the second set of secrets of the group and the subset of the random vector assigned to the eligible member; wherein the first member secret and the second member secret are calculated by applying modular arithmetic and additional arithmetic; and wherein the collection unit has access to the first set of secrets and the second set of secrets, but does not know the distribution of the first member secret and the second member secret to the eligible members of the group.
13. The method according to claim 12, wherein the secret key is a function of a first product of multiplication of a first factor and a second product of multiplication of a second factor.
14. The method according to claim 13, wherein each first factor has a first base number, and the first base number is calculated by applying a modular operation mod p to a first intermediate product of multiplication of a first intermediate factor.
15. The method according to claim 14, wherein each second factor is used as a second base number, and the second base number is calculated by applying the modular operation to a second intermediate product of multiplication of a second intermediate factor.
16. The method according to claim 15, wherein the first intermediate factor has a base number that is a secret from the first set of secrets and has a random exponent that is an element of the subset of the random vector assigned to the eligible members; and Among them, the second intermediate factor has a base number that is a secret from the second set of secrets and has a random exponent that is an element of the subset of the random vector assigned to the eligible members.
17. The method according to claim 12, wherein the verification includes the collection unit calculating a verification secret key according to a function of the first set of secrets, the second set of secrets, and the first part of the message signature.
18. The method according to claim 17, wherein the verification includes: applying a modular operation to a first verification product of multiplication of a first verification factor; and applying the modular operation to a second verification product of multiplication of a second verification factor.
19. The method according to claim 12, wherein the different first verification factors have bases that are secrets different from the first set of secrets and have different random exponents; and wherein, The different second verification factors have a base number that is a secret different from the second set of secrets and have the different random exponents; wherein the different random exponents belong to the second part of the message signature.
20. The method according to claim 19, wherein the second part of the message signature is generated using an encryption process; and Among them, the verification includes applying the encryption process using the verification secret key to provide a verification intermediate result.
21. The method according to claim 20, wherein the verification includes comparing the verification intermediate result with the second part of the message signature; and determining that the message is received from any one of the eligible members of the group when the first part of the message signature is non-zero and the verification intermediate result is equal to the second part of the message signature.
22. The method according to claim 12, wherein Calculating the first plurality of mathematical operations over a finite field having a predefined size p, wherein the modular operation has a divisor equal to the predefined size.
23. A non-transitory computer-readable medium, the non-transitory computer-readable medium comprising instructions for collecting data from a group of eligible members, which when executed by a machine cause the machine to perform operations including the following: The collection unit receives a message and a message signature; The collection unit verifies whether the message is received from one of the eligible members of the group without identifying the eligible member who sent the message, where the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; When the message is not received from any eligible member of the group, the collection unit rejects the message; And When the message is received from one of the eligible members of the group, the data embedded in the message is collected; Wherein, the message signature received from an eligible member includes a first part and a second part; Wherein, the second part is generated using a secret key; Wherein the secret key is calculated by applying a first plurality of mathematical operations to a first member secret assigned to the eligible member, a second member secret assigned to the eligible member, and a random vector; Wherein the first plurality of mathematical operations includes calculating the product of a multiplication of factors having a base number and a random exponent; Wherein the first member secret is calculated based on the secret of the first set of secrets assigned to the group and a subset of the random vector assigned to the eligible member; Wherein the second member secret is calculated based on the secret of the second set of secrets assigned to the group and the subset of the random vector assigned to the eligible member; Wherein, the first member secret and the second member secret are calculated by applying a modulo operation and an additional operation; and Wherein the collection unit has access to the first set of secrets and the second set of secrets, but does not know the assignment of the first member secret and the second member secret to the eligible members of the group.
24. A collection device for collecting data from a group of eligible members, the collection device comprising: A communication circuit for receiving a message and a message signature from an eligible member; And A hardware processor for: Receiving a message and a message signature; Verifying whether the message is received from one of the eligible members of the group without identifying the eligible member who sent the message, where the verification includes applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; When the message is not received from any eligible member of the group, rejecting the message; And When the message is received from one of the eligible members of the group, collecting the data embedded in the message; Wherein, the message signature received from an eligible member includes a first part and a second part; Wherein, the second part is generated using a secret key; Wherein the secret key is calculated by applying a first plurality of mathematical operations to a member secret and a random vector assigned to the eligible member; Wherein the first plurality of mathematical operations includes a modulo operation and calculating the product of a multiplication of factors having a base number and a random exponent; wherein the member secret is calculated based on a secret from the first set of secrets assigned to the group, a secret from the second set of secrets assigned to the group, a random matrix, and a subset of a random vector assigned to the eligible member; and wherein the collection device has access to the first set of secrets and the second set of secrets, but does not know the assignment of the member secret to the eligible members of the group.
25. The collection device according to claim 24, wherein the secret key is a function of a set of matrices, wherein different matrices in the set are functions of the random matrix, the inverse of the random matrix, and an intermediate matrix comprising a first intermediate matrix element and a second intermediate matrix element.
26. The collection device according to claim 25, wherein the first intermediate matrix element is a first intermediate product of a multiplication of a first intermediate factor; and Among them, the second intermediate matrix element is a second intermediate product of a multiplication of a second intermediate factor.
27. The collection device according to claim 25, wherein the first intermediate factor has a base that is a secret from the first set of secrets and has a random exponent that is an element of the subset of the random vector assigned to the eligible member; and Among them, The second intermediate factor has as its base a secret from the second set of secrets and has as its exponent a random number that is an element of the subset of the random vectors allocated to the eligible members.
28. The collection device according to claim 25, wherein the intermediate matrix is a diagonal matrix, and wherein the secret key is the trace of a third matrix, the third matrix being the product of the multiplication of factor matrices, each factor matrix having a random exponent and serving as the base of a third intermediate matrix, wherein, a different third intermediate matrix is a product of the random matrix multiplied by a different intermediate matrix and multiplied by the inverse of the random matrix.
29. A method for collecting data from a group of eligible members, the method comprising: receiving, by a collection unit, a message and a message signature; verifying, by the collection unit, whether the message is received from one of the eligible members of the group without identifying the eligible member that sent the message, wherein the verification comprises applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; rejecting, by the collection unit, the message when the message is not received from any eligible member of the group; and collecting, when the message is received from one of the eligible members of the group, data embedded in the message; wherein a message signature received from an eligible member comprises a first part and a second part; wherein the second part is generated using a secret key; wherein the secret key is calculated by applying a first plurality of mathematical operations to a member secret and a random vector assigned to the eligible member; wherein the first plurality of mathematical operations comprises modular arithmetic and calculation of a product of a multiplication of a factor having a base and a random exponent; wherein the member secret is calculated based on a secret from the first set of secrets assigned to the group, a secret from the second set of secrets assigned to the group, a random matrix, and a subset of a random vector assigned to the eligible member; and wherein the collection unit has access to the first set of secrets and the second set of secrets, but does not know the assignment of the member secret to the eligible members of the group.
30. The method according to claim 29, wherein the secret key is a function of a set of matrices, and different matrices in the set are functions of the random matrix, the inverse of the random matrix, and an intermediate matrix comprising a first intermediate matrix element and a second intermediate matrix element.
31. The method according to claim 30, wherein the first intermediate matrix element is a first intermediate product of a multiplication of a first intermediate factor; and wherein, The second intermediate matrix element is a second intermediate product of a multiplication of a second intermediate factor.
32. The method according to claim 30, wherein the first intermediate factor has a base that is a secret from the first set of secrets and has a random exponent that is an element of the subset of the random vectors assigned to the eligible members; and Among them, The second intermediate factor has as its base a secret from the second set of secrets and has as its exponent a random number that is an element of the subset of the random vectors assigned to the eligible members.
33. The method according to claim 30, wherein the intermediate matrix is a diagonal matrix, and wherein the secret key is the trace of a third matrix, the third matrix being the product of the multiplication of factor matrices, each factor matrix having a random exponent and serving as the base of a third intermediate matrix, wherein, Different third intermediate matrices are products of the random matrix multiplied by different intermediate matrices and multiplied by the inverse of the random matrix.
34. A non-transitory computer-readable medium, the non-transitory computer-readable medium comprising instructions for collecting data from a group of eligible members, which when executed by a machine cause the machine to perform operations comprising: Receiving a message and a message signature by a collection unit; The collection unit verifies whether the message is received from any eligible member of the group without identifying the eligible member who sent the message; wherein, The verification comprises applying a second plurality of mathematical operations to a first set of secrets, a second set of secrets, and a first part of the message signature; Rejecting the message by the collection unit when it is verified that the message is not received from any of the eligible members of the group; And Collecting data embedded in the message when it is verified that the message is received from any one of the eligible members of the group; wherein the message signature received from an eligible member comprises a first part and a second part; wherein the second part is generated using a secret key; wherein the secret key is calculated by applying a first plurality of mathematical operations to a member secret and a random vector assigned to the eligible member; wherein the first plurality of mathematical operations comprises modular arithmetic and calculation of a product of a multiplication of a factor having a base and a random exponent; wherein the member secret is calculated based on a secret from the first set of secrets assigned to the group, a secret from the second set of secrets assigned to the group, a random matrix, and a subset of the random vectors assigned to the eligible member; and wherein the collection unit has access to the first set of secrets and the second set of secrets, but does not know the assignment of the member secrets to the eligible members of the group.
Citation Information
Patent Citations
Democratic signature method with threshold tracking
CN101267308A
Motorcade-oriented safety management method based on extensible contribution group key negotiation
CN109640325A