Cloud image privacy protection method, system and device based on trusted hardware
By creating a trusted execution module on the cloud server, the private image is encrypted and private key decrypted, and disturbed in the module, the problem of untrustworthy cloud server programs is solved, and the secure encryption, decryption and processing of private images is realized.
Patent Information
- Application Number
- CN202210365808.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-04-08
AI Technical Summary
In the prior art, when cloud servers protect private images, cloud server programs are untrustworthy, resulting in insecure encryption and decryption processes and image processing processes of private images.
The cloud image privacy protection method based on trusted hardware is adopted. By creating a trusted execution module on the server, encrypting and decrypting the private images using public key encryption and private key decryption, and adding perturbations to the trusted execution module to protect privacy.
Ensure the secret and security of private images during transmission, prevent the risks of untrustworthy by third parties, and make the entire privacy protection operation more secure and trustworthy.
Smart Images

Figure CN114866232B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of image privacy protection, and in particular to a cloud image privacy protection method, system and device based on trusted hardware. Background Art
[0002] With the development of social informatization, various biometric information recognition technologies based on personal characteristics, such as face payment and fingerprint payment, have been widely used. At the same time, the prosperity of social networks has also prompted users to post images with personal information more frequently on Internet content platforms, which poses a great challenge to protecting users' identity privacy and security. More specifically, the images posted by users on content platforms are likely to involve personal biometrics. If illegal elements or advertising alliances can locate personal information through these images, these images will lead to user privacy leakage.
[0003] Although existing technical solutions can generate noise for images that is sufficient to protect personal privacy, it is difficult for users to generate and add noise to images locally due to constraints such as computing power and operating environment. If the images are handed over to a third party for processing, the third party may not be trustworthy, resulting in privacy leakage. Summary of the invention
[0004] The present invention aims to at least solve the technical problems existing in the prior art. To this end, the present invention proposes a cloud image privacy protection method, system and device based on trusted hardware, which can solve the problem that the cloud server program is untrustworthy when protecting and processing private images based on the cloud server, making the encryption and decryption process of private images and the image processing process safer.
[0005] In a first aspect, an embodiment of the present invention provides a cloud image privacy protection method based on trusted hardware, which is used in a trusted execution module created by a server through trusted hardware. The cloud image privacy protection method includes the following steps:
[0006] Obtaining system parameters from a server, and generating a public key and a private key according to the system parameters;
[0007] Receiving a first request message from a user terminal requesting to send the public key, and sending the public key to the user terminal according to the first request message;
[0008] Receiving a private image encrypted by the public key from a user end, decrypting the private image by using the private key, and adding disturbance to the private image; the private image carries the user's private information;
[0009] The private image after adding disturbance is sent to the user end.
[0010] According to the embodiments of the present invention, there are at least the following technical effects:
[0011] (1) When receiving the private image from the user, the private image is encrypted with the public key; when returning the private image to the user, the private image is perturbed. The above measures ensure the confidentiality and security of the private image during transmission.
[0012] (2) The trusted execution module completes the decryption of the private image and the addition of disturbances. Since the variables of the trusted execution module cannot be read or written by third-party programs on the server during operation, this process does not leak the original private image information to the server, making the entire privacy protection operation safe and reliable.
[0013] (3) Adding perturbations to private images is run by a trusted execution module and does not depend on the user's local environment, which makes the image privacy protection process simpler and more feasible.
[0014] According to some embodiments of the present invention, before receiving the private image encrypted by the public key from the user end, the method further includes the following steps:
[0015] Receive a second request message from a user end requesting authentication of the identity of a trusted execution module; generate a response based on the second request message and sign it using an authentication private key; send the response and the signature to the user end, so that the user end sends the response and the signature to an authentication center, and authenticates the identity of the trusted execution module through the authentication center.
[0016] According to some embodiments of the present invention, the system parameters are {p, g}, where p is a large prime number and g is a cyclic group Z p The generator on .
[0017] According to some embodiments of the present invention, generating a public key and a private key according to the system parameters includes: selecting a random number x as a private key within the range of p-2, and using the formula y=g x Calculate the public key.
[0018] According to some embodiments of the present invention, adding disturbance to the private image comprises the steps of: obtaining a model function h(x) and a loss function L(x) in an identity feature recognition model from the server; constructing a first optimization objective function based on the model function h(x) and the loss function L(x), and adding constraints to the first optimization objective function; solving the first optimization objective function after adding constraints using a gradient descent optimization algorithm to obtain a disturbance δ; adding the disturbance δ to the private image to obtain the private image with the private information desensitized; wherein the first optimization objective function is: Among them, the xi represents the private image, δ represents the disturbance added to the private image, and y i Represents the target feature of the privacy image; wherein the constraint condition is: ‖δ‖≤∈; wherein ∈ is the disturbance limit.
[0019] According to some embodiments of the present invention, the step of adding disturbance to the privacy image comprises the steps of: obtaining a feature extractor Φ from the server θ (x); wherein the feature extractor Φ θ (x) is a face feature extractor pre-trained by the server according to the face information data set; based on the feature extractor Φ θ (x) constructing a second optimization objective function and adding constraints to the second optimization objective function; using a gradient descent optimization algorithm to solve the second optimization objective function after adding constraints to obtain a disturbance δ; adding the disturbance δ to the private image to obtain the private image with the privacy information desensitized; wherein the second optimization objective function is: Among them, the x i represents the privacy image, δ represents the perturbation added to the privacy image, and Dist(x) represents the L2 distance or the universal image metric function; wherein the constraint condition is: ‖δ‖≤∈; wherein ∈ is the perturbation limit.
[0020] According to some embodiments of the present invention, disturbance is added to the privacy image by means of image compression reconstruction, image super-resolution reconstruction, or discrete cosine transform coefficient modification and then restoration.
[0021] In a second aspect, an embodiment of the present invention provides a cloud-based image privacy protection system based on trusted hardware, including:
[0022] A server, configured to create a trusted execution module through trusted hardware and provide system parameters to the trusted execution module;
[0023] The user end is used to send a first request message for requesting a public key to the trusted execution module, and to send a private image encrypted by the public key to the trusted execution module; the private image carries the user's private information;
[0024] A trusted execution module is used to generate a public key and a private key according to the system parameters, and send the public key to the user end according to the first request information, and use the private key to decrypt the private image, add disturbance to the private image, and send the private image with disturbance added to the user end.
[0025] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following is achieved:
[0026] The cloud-based image privacy protection method based on trusted hardware as described in the first aspect.
[0027] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute:
[0028] The cloud-based image privacy protection method based on trusted hardware as described in the first aspect.
[0029] It can be understood that the beneficial effects of the second to fourth aspects compared with the related art are the same as the beneficial effects of the first aspect compared with the related art. Please refer to the relevant description in the first aspect, and no further details will be given here.
[0030] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0032] Figure 1 A flowchart of a cloud image privacy protection method based on trusted hardware provided by an embodiment of the present invention;
[0033] Figure 2 A schematic diagram of the initialization interaction process between a server and a trusted execution module of a cloud image privacy protection method based on trusted hardware provided by an embodiment of the present invention;
[0034] Figure 3 A schematic diagram of the interaction process between a user and a trusted execution module of a cloud image privacy protection method based on trusted hardware provided by an embodiment of the present invention;
[0035] Figure 4 A schematic diagram of a user remotely authenticating a trusted execution module in a cloud image privacy protection method based on trusted hardware provided by an embodiment of the present invention;
[0036] Figure 5 A schematic diagram of the structure of a cloud-based image privacy protection system based on trusted hardware provided by an embodiment of the present invention;
[0037] Figure 6A schematic diagram of the structure of a computer device provided in an embodiment of the present invention;
[0038] Figure 7 A schematic diagram of the structure of a computer-readable storage medium provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0039] The following will fully describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0040] Unless otherwise defined, all technical and scientific terms used in the present invention have the same meanings as those commonly understood by those skilled in the art of the present invention. The terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention.
[0041] Embodiment 1
[0042] Reference Figure 1 , an embodiment of the present invention provides a cloud image privacy protection method based on trusted hardware, comprising the following steps:
[0043] Step S110: Obtain system parameters from the server, and generate a public key and a private key according to the system parameters;
[0044] Step S120: receiving a first request message from a user terminal requesting to send a public key, and sending the public key to the user terminal according to the first request message;
[0045] Step S130: receiving a private image encrypted by a public key from a user end, decrypting the private image by using a private key, and adding disturbance to the private image;
[0046] Step S140: sending the disturbed private image to the user end.
[0047] Reference Figure 2 In step S110, the server creates a trusted execution module based on the trusted hardware and generates system parameters. The trusted execution module obtains system parameters from the server, including the encryption or signature algorithm used and the specified key length. The trusted execution module starts the trusted execution program, generates a public key and a private key according to the above system parameters, and makes the public key public to all users, while providing an interface to receive encrypted image input.
[0048] Reference Figure 3In step S120, the user terminal requests the public key from the trusted execution module to encrypt its own private image. After receiving the request information from the user terminal, the trusted execution module sends the public key to the user terminal. A private image refers to an image that carries the user's private information.
[0049] In step S130, the user end encrypts its own private image using the public key and sends the encrypted image to the public interface of the trusted execution module. After receiving the encrypted private image, the trusted execution module decrypts the private image using the matching private key, and then executes the image privacy protection algorithm to add disturbances to the image to desensitize the personal privacy information.
[0050] In step S140, the trusted execution module sends the disturbed image back to the user end.
[0051] The embodiment of the present invention provides a cloud image privacy protection method based on trusted hardware. By encrypting or adding disturbances to the privacy image to blind the user privacy features in the privacy image, the privacy and security of the privacy image during transmission are guaranteed, and the user privacy feature information in the blinded privacy image cannot be recognized by the current mainstream platform machine learning model. The trusted execution module completes the decryption of the privacy image and the increase of disturbances to the privacy image, and the original privacy image information is not leaked to the server. The variables of the trusted execution module during operation cannot be read and written by the third-party program of the server, which ensures the privacy and security of the privacy image during the increase of disturbances. At the same time, because the trusted execution module is created by the server in the cloud based on the trusted hardware and provides a service interface to the outside, it does not depend on the user's local environment, making the image privacy protection process simpler and more feasible.
[0052] Embodiment 2
[0053] Reference Figure 4 Before the user (user end) sends the private image to the trusted execution module, the user can interact with the trusted execution module, remotely authenticate the trusted execution module, and confirm the identity of the trusted execution module, thereby ensuring that all operations on the private image occur in the trusted execution module. The process is as follows:
[0054] 1. The user initiates a query to the trusted execution module;
[0055] 2. The trusted execution module generates a response to the challenge and signs it using its own authentication private key.
[0056] 3. The trusted execution module sends the response and signature to the user;
[0057] 4. The client receives the response and signature and sends it to the authentication center for verification;
[0058] 5. The authentication center authenticates the signature and obtains the authentication result;
[0059] 6. The authentication center returns the authentication result to the user, so that the user can confirm the identity of the trusted execution module.
[0060] Embodiment 3
[0061] There are many types of system parameters that can generate public keys and private keys, which vary greatly. Taking ElGamal Encryption (an asymmetric encryption method based on Diffie-Hellman key exchange) as an example, this embodiment further defines the system parameters.
[0062] 1. The trusted execution module is initialized and generates system parameters {p, g}, where p is a large prime number and g is Z p The generator on .
[0063] 2. After the trusted execution module obtains {p, g}, it selects a random number x in the range of p-2 as the system private key and saves it.
[0064] 3. The public key parameter y=g of the trusted execution module computing system x , and then make the public parameters and public keys public so that all users who want to protect their privacy can obtain them.
[0065] 4. The trusted execution module starts the trusted execution program with the added disturbance, provides an interface and broadcasts it publicly.
[0066] Embodiment 4
[0067] There are many methods for adding disturbance to a private image. This embodiment divides the methods for adding disturbance into three types.
[0068] The first type: The identity feature recognition model is a white box, and the user interacts with the trusted execution module to protect image privacy. The process is as follows:
[0069] 1. The user requests a public key from the trusted execution module, and the trusted execution module returns the public key y after receiving the request.
[0070] 2. After obtaining the public key, the user selects a random number r within the range of p-1, uses the public key to encrypt the image M, thereby obtaining the ciphertext C, and then sends C to the trusted execution module interface.
[0071] a=g r ,b=My r ,C=(a,b)
[0072] C=(g r ,My r ).
[0073] 3. After the trusted execution program receives the image, it decrypts it using the private key to obtain the private image. The decryption process is as follows:
[0074] M=(b / a x )
[0075] Note that the above operations all occur in the trusted execution module, and the intermediate variables cannot be read or written by the external server process.
[0076] 4. In the case where the identity feature recognition model is a white box, the server can obtain the recognition model. The trusted execution program loads the model function h(x) and loss function L(x) of the recognition model from the server and constructs the optimization target:
[0077]
[0078] At the same time, the optimization process satisfies the constraint condition ‖δ‖≤∈. i represents the image, δ represents the perturbation added to the image, y i Represents the target features of the original private image identified by the model, and the constraints are used to ensure that the disturbance added to the image is within the range that cannot be recognized by the naked eye. The objective function can be solved by various gradient descent optimization algorithms, but is not limited to them.
[0079] Here is a solution example:
[0080] Input: original image x i , perturbation limit ∈, number of iterations T, learning rate α
[0081] Output: The final generated perturbation δ
[0082] The process is as follows:
[0083] 1. Initialize the perturbation δ0
[0084] 2.for N=1 to Tdo
[0085] 3.
[0086] 4.End
[0087] Among them, the function Clip ∈ (x) represents a clipping operation, which clips values greater than ∈ to ∈.
[0088] After the optimization is completed and δ is calculated, the privacy-desensitized image is returned to the user. The trusted execution program can also only send the perturbation δ to the user, and the user can add the perturbation locally to obtain the desensitized image.
[0089] It should be noted that after the trusted execution module obtains the private image with added disturbance, it needs to encrypt it with the user's public key, and then send the encrypted private image to the user. The user uses his own private key to decrypt it to obtain the private image. For example, the user generates its own key pair (public and private key) in the same way as in Example 3, and discloses the public key to the trusted execution module, so that the trusted execution module uses the public key to encrypt the private image with added disturbance. The private key saved by the user is used to decrypt the data (encrypted image) sent by the trusted execution module. The encryption process of the trusted execution module and the decryption process of the user are similar to the above-mentioned steps 2 and 3 of this embodiment, and will not be repeated here. In the subsequent second and third schemes, after obtaining the private image, the trusted execution module also needs to encrypt it with the user's public key, and then the user uses the corresponding private key to decrypt it, which will not be repeated later.
[0090] The second type: The identity feature recognition model is a black box, and the user interacts with the trusted execution module to protect image privacy. The process is as follows:
[0091] 1. The user requests a public key from the trusted execution module, and the trusted execution module returns the public key y after receiving the request.
[0092] 2. After the user obtains the public key, he uses the public key to encrypt the private image (M) and sends the encrypted private image (M) to the trusted execution module interface.
[0093] 3. After the trusted execution program receives the image, it decrypts it with the private key to obtain the private image. Note that the above operations all occur in the trusted execution module, and the intermediate variables cannot be read or written by the external server process. It should be noted that user encryption and trusted execution program decryption can be found in the first case, which will not be repeated here.
[0094] 4. For scenarios where the model is a black box, that is, the model function is unknown, you can train a feature extractor on a public dataset to replace the original identity feature recognition model. For example, there is a public face information dataset on the Internet, and you can train a face feature extractor on it. θ (x), here, a training example is given:
[0095] Input: Dataset {(x1,y1),(x2,y2),……,(x m ,y m )}, where x i Represents the image, y i Represents the image label, the number of iterations T, and the learning rate α.
[0096] Output: Model function Φ θ (x).
[0097] The process is as follows:
[0098] 1. Initialize the model function Φ θ (x)
[0099] 2.for N=1 to Tdo:
[0100] 3.for i=1 to m do:
[0101] 4.
[0102] 5.End
[0103] 6.End
[0104] Among them, L(x) can be the loss function in the classification task, such as the cross entropy loss function.
[0105] Get the face feature extractor Φ on the server θ After (x), the trusted execution module loads the feature extractor Φ θ (x), and construct the following optimization objective:
[0106]
[0107] At the same time, the optimization process satisfies the constraint condition ‖δ‖≤∈. i represents the image, δ represents the disturbance added to the image, Dist(x) can use L2 distance or other general image metric functions, and the objective function can be solved by various gradient descent optimization algorithms but is not limited to them. After the optimization is completed and δ is calculated, the trusted execution module returns the privacy-desensitized image to the user. The trusted execution module may also only send the perturbation δ to the user, and the user may add the perturbation locally to obtain the desensitized image.
[0108] The third type: non-model-specific image changes, the user interacts with the trusted execution module to perform image privacy protection. The process is as follows:
[0109] 1. The user requests a public key from the trusted execution module, and the trusted execution module returns the public key y after receiving the request.
[0110] 2. After the user obtains the public key, he uses the public key to encrypt the private image and then sends it to the trusted execution module interface.
[0111] 3. After the trusted execution program receives the image, it decrypts it using the private key to obtain the private image. Note that the above operations all occur in the trusted execution module, and the intermediate variables cannot be read or written by the external server process.
[0112] 4. In the process of image privacy protection, when the above-mentioned identity feature recognition model is a white box or black box, a model-specific perturbation generation scheme is provided. This scheme can also be replaced by some non-model-specific image change schemes, such as: image compression reconstruction, image super-resolution reconstruction, discrete cosine transform coefficient modification and then restoration of the image, etc. After completing the transformation of the image, the trusted execution module returns the transformed privacy-desensitized image to the user.
[0113] Embodiment 5
[0114] Reference Figure 5 , an embodiment of the present invention provides a cloud image privacy protection system based on trusted hardware, comprising:
[0115] The server 210 is used to create a trusted execution module through trusted hardware and provide system parameters to the trusted execution module;
[0116] The client 220 is used to send a first request message for requesting a public key to the trusted execution module, and to send a private image encrypted by using the public key to the trusted execution module;
[0117] The trusted execution module 230 is used to generate a public key and a private key according to the system parameters, send the public key to the user end according to the first request information, decrypt the private image using the private key, add disturbance to the private image, and send the disturbed private image to the user end.
[0118] The server 210 creates a trusted execution module 230 based on the trusted hardware and generates system parameters. The trusted execution module 230 obtains system parameters from the server 210, including the encryption or signature algorithm used and the specified key length. The trusted execution module 230 starts the trusted execution program, generates a public key and a private key according to the above system parameters, and makes the public key public to all users, while providing an interface to receive encrypted image input.
[0119] The client 220 requests the trusted execution module 230 for a public key to encrypt its own private image. After receiving the request information from the client 220 , the trusted execution module 230 sends the public key to the client 220 .
[0120] The user end 220 uses the public key to encrypt its own private image and sends the encrypted image to the public interface of the trusted execution module 230. After receiving the encrypted private image, the trusted execution module 230 uses the matching private key to decrypt the private image, and then executes the image privacy protection algorithm to add disturbances to the image to desensitize the personal privacy information.
[0121] Finally, the trusted execution module 230 sends the protected image back to the user terminal 220 .
[0122] The embodiment of the present invention provides a cloud-based image privacy protection system based on trusted hardware. The user terminal 220 encrypts the private image and the trusted execution module 230 adds disturbances, thereby ensuring the confidentiality and security of the private image during the transmission process. The trusted execution module 230 completes the private image decryption and the private image addition disturbance operations, and does not leak the original private image information to the server 210, thereby ensuring the confidentiality and security of the private image during the disturbance addition process. At the same time, it does not rely on the user's local environment, making the image privacy protection process simpler and more feasible.
[0123] Since the various functional modules of the system of the exemplary embodiment of the present invention correspond to the steps of the exemplary embodiment of the above-mentioned cloud-based image privacy protection method based on trusted hardware, for details not disclosed in the system embodiment of the present invention, please refer to the above-mentioned embodiment of the cloud-based image privacy protection method based on trusted hardware of the present invention.
[0124] Embodiment 6
[0125] Reference Figure 6 The present application further provides a computer device 301, comprising: a memory 310, a processor 320, and a computer program 311 stored in the memory 310 and executable on the processor, wherein when the processor 320 executes the computer program 311, the following is achieved:
[0126] Such as the cloud image privacy protection method based on trusted hardware mentioned above.
[0127] The processor 320 and the memory 310 may be connected via a bus or in other ways.
[0128] The memory 310, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory 310 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory 310 may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0129] The non-transient software program and instructions required to implement the cloud image privacy protection method based on trusted hardware of the above embodiment are stored in the memory. When executed by the processor, the cloud image privacy protection method based on trusted hardware in the above embodiment is executed, for example, the above described Figure 1 The method comprises steps S110 to S140.
[0130] Embodiment 7
[0131] Reference Figure 7 The present application further provides a computer-readable storage medium 401 storing computer-executable instructions 410, wherein the computer-executable instructions 410 are used to execute:
[0132] Such as the cloud image privacy protection method based on trusted hardware mentioned above.
[0133] The computer-readable storage medium 401 stores computer-executable instructions 410, which are executed by a processor or a controller, for example, by a processor in the above electronic device embodiment, so that the above processor can execute the cloud image privacy protection method based on trusted hardware in the above embodiment, for example, execute the above described Figure 1 The method comprises steps S110 to S140.
[0134] It will be appreciated by those skilled in the art that all or some of the steps and systems in the disclosed method above may be implemented as software, firmware, hardware and appropriate combinations thereof. Some physical components or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or a non-transitory medium) and a communication medium (or a temporary medium). As known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing data (such as computer-readable instructions, data structures, program modules or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that may be used to store desired data and may be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically embodies computer readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any data delivery media.
[0135] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0136] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.
Claims
1. A cloud image privacy protection method based on trusted hardware, characterized in that , used in a trusted execution module created by a server through trusted hardware, the cloud image privacy protection method includes the following steps: Obtaining system parameters from a server, and generating a public key and a private key according to the system parameters; Receiving a first request message from a user terminal requesting to send the public key, and sending the public key to the user terminal according to the first request message; Receiving a private image encrypted by the public key from a user end, decrypting the private image by using the private key, and adding disturbance to the private image; the private image carries the user's private information; Sending the private image after adding disturbance to the user terminal; The step of adding disturbance to the privacy image comprises the following steps: Obtaining a model function h(x) and a loss function L(x) in an identity feature recognition model from the server; Constructing a first optimization objective function based on the model function h(x) and the loss function L(x), and adding constraints to the first optimization objective function; Using a gradient descent optimization algorithm to solve the first optimization objective function after adding constraints, to obtain a disturbance δ; Adding the disturbance δ to the private image to obtain the private image with the private information desensitized; Wherein, the first optimization objective function is: Among them, the x i represents the private image, δ represents the disturbance added to the private image, and y i a target feature representing the private image; The constraints are: ||δ||≤∈; Where ∈ is the perturbation limit.
2. The cloud image privacy protection method based on trusted hardware according to claim 1, characterized in that: Before receiving the private image encrypted by the public key from the user end, the method further includes the following steps: Receiving second request information from a user terminal requesting to authenticate the identity of a trusted execution module; Generate a response according to the second request information and sign it using the authentication private key; The response and the signature are sent to the user terminal, so that the user terminal sends the response and the signature to an authentication center, and the identity of the trusted execution module is authenticated by the authentication center.
3. The cloud image privacy protection method based on trusted hardware according to claim 1, characterized in that: The system parameters are {p, g}, where p is a large prime number and g is a cyclic group Z. p The generator on .
4. The cloud image privacy protection method based on trusted hardware according to claim 3 is characterized in that: The method of generating a public key and a private key according to the system parameters comprises the steps of: Select a random number x in the range of p-2 as the private key, and use the formula y=g x Calculate the public key.
5. The cloud image privacy protection method based on trusted hardware according to claim 1, characterized in that: The step of adding disturbance to the privacy image comprises the following steps: Get the feature extractor Φ from the server θ (x); wherein the feature extractor Φ θ (x) a face feature extractor pre-trained by the server according to a face information dataset; Based on the feature extractor Φ θ (x) constructing a second optimization objective function and adding constraints to the second optimization objective function; Using a gradient descent optimization algorithm to solve the second optimization objective function after adding constraints, to obtain a disturbance δ; Adding the disturbance δ to the private image to obtain the private image with the private information desensitized; Wherein, the second optimization objective function is: Among them, the x i represents the private image, the δ represents the perturbation added to the private image, and the Dist(x) represents the L2 distance or the universal image metric function; The constraints are: ||δ||≤∈; Where ∈ is the perturbation limit.
6. The cloud image privacy protection method based on trusted hardware according to claim 1, characterized in that: The privacy image is disturbed by image compression reconstruction, image super-resolution reconstruction, or discrete cosine transformation of the image to modify coefficients and then restore the image.
7. A cloud-based image privacy protection system based on trusted hardware, characterized in that ,include: A server, configured to create a trusted execution module through trusted hardware and provide system parameters to the trusted execution module; The user end is used to send a first request message for requesting a public key to the trusted execution module, and to send a private image encrypted by the public key to the trusted execution module; the private image carries the user's private information; A trusted execution module, used to generate a public key and a private key according to the system parameters, send the public key to the user end according to the first request information, decrypt the private image using the private key, add a disturbance to the private image, and send the private image after the disturbance to the user end; obtain a model function h(x) and a loss function L(x) in the identity feature recognition model from the server; construct a first optimization objective function based on the model function h(x) and the loss function L(x), and add constraints to the first optimization objective function; use a gradient descent optimization algorithm to solve the first optimization objective function after adding constraints to obtain a disturbance δ; add the disturbance δ to the private image to obtain the private image with the privacy information desensitized; wherein the first optimization objective function is: Among them, the x i represents the private image, δ represents the disturbance added to the private image, and y i Represents the target feature of the privacy image; wherein the constraint condition is: ||δ||≤∈; wherein ∈ is the disturbance limit.
8. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following is achieved: A cloud-based image privacy protection method based on trusted hardware as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: The computer-executable instructions are stored, and the computer-executable instructions are used to perform: A cloud-based image privacy protection method based on trusted hardware as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Privacy protection-based user authenticated outsourcing image denoising method
CN111241561A
Privacy protection method for generating adversarial samples based on projection gradient descent method
CN113515774A
Method and device for protecting privacy information of image sample set
CN114091104A