A Location Service Task Allocation Method Based on Homomorphic Encryption

By using BGN homomorphic encryption technology to encrypt user data in location service task allocation, and perform distance calculation and sorting in ciphertext state, the problem of location information leakage and calculation accuracy in the prior art is solved, and efficient and secure task allocation is achieved.

CN116170191BActive Publication Date: 2025-05-30XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310065898.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-16
Publication Date
2025-05-30
Estimated Expiration
2043-01-16

AI Technical Summary

Technical Problem

When realizing location service tasks allocation, it is difficult to ensure data privacy and calculation accuracy in the ciphertext state, and most solutions cannot flexibly adapt to distance measurements in different scenarios, and there is a risk of location information leakage.

Method used

The method based on homomorphic encryption is adopted to encrypt user data through BGN homomorphic encryption technology, distance calculation and sorting are performed in the ciphertext state, ensuring the privacy of location information, and is suitable for a variety of distance measurement scenarios.

Benefits of technology

It realizes the calculation and sorting of multiple distance measurements in the ciphertext state, ensuring the privacy of location data and the success rate of task allocation, avoiding the leakage of location information, and reducing the computing cost of the user side.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116170191B_ABST
    Figure CN116170191B_ABST
Patent Text Reader

Abstract

The present invention provides a location service task allocation method based on homomorphic encryption. Distance calculations under various mainstream distance metrics are performed in the ciphertext state, which can be flexibly applied to different scenarios while ensuring that the distribution of distances will not be leaked, achieving the privacy of location data itself and the security of queries. Secure sorting is performed in the ciphertext state of the distance, avoiding the leakage of distance distribution caused by sorting in the plaintext state or the computational cost of screening the minimum distance, and improving efficiency while ensuring security. For users, they only need to periodically upload their location ciphertexts, without having to calculate the prefix family of distances locally and then encrypt and upload, reducing the computational cost of users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a method for allocating location service tasks based on homomorphic encryption. Background Art

[0002] The powerful computing power and huge storage space of cloud computing provide an excellent environment for the processing and calculation of big data, and can effectively manage and quickly deploy. By offloading the calculation of data to the cloud, cloud customers can easily and conveniently use computing resources without being restricted by resource devices. With the continuous development of mobile devices and the strengthening of cloud computing capabilities, location-based data services (such as smart cities, etc.) have gradually shifted to rely on cloud servers for processing and calculation, and spatial crowdsourcing computing platforms have emerged, assisting users in task allocation from a global perspective. However, the data stored in the cloud may contain some sensitive or proprietary information, so it faces a great risk of privacy leakage. Once the sensitive information is leaked, it will lead to catastrophic consequences. Therefore, it is very necessary to encrypt the data participating in the calculation. However, it is not as easy to implement relevant data calculations in the ciphertext state as in the plaintext state. How to balance the availability and privacy of data and achieve the target algorithm task in the ciphertext state is a very challenging problem.

[0003] In 2020, Song Han et al. combined the BGN homomorphic encryption technology and the prefix membership verification method to efficiently determine the members of the working group. In this scheme, for different distance metrics corresponding to different scenarios, users upload the ciphertext of the location information itself or the ciphertext of the prefix family of the location information, and the server calculates the distance in plaintext form using the ciphertext and sorts it, and finally selects the worker with the closest distance to allocate tasks. However, since the calculated distance is in plaintext form, to a certain extent, it exposes the location distribution of the workers. And directly using the data prefix will provide the adversary with an opportunity to guess the bit decomposition of the data through numerical analysis. The following year, Feng Lin et al. proposed the LDPDW scheme based on the differential privacy method for task allocation for dynamic worker locations. This scheme first performs noise processing on highly correlated locations based on the LDPCG algorithm, and then proposes a DSLDP algorithm for obscuring worker locations and a DCGLO algorithm for realizing the confusion of dynamic worker locations to ensure worker location privacy. In addition, this scheme uses a linear acceptance model (LAM) to allocate tasks to nearby workers to improve the success rate. However, this scheme does not consider the location privacy of the task (or the task publisher). If the task location is leaked, more sensitive information about the task publisher itself will be exposed.

[0004] Most of the currently proposed task allocation schemes for location privacy usually use differential privacy or add false data for obfuscation. However, differential privacy generally cannot guarantee the comprehensive privacy of workers and task locations, or does not consider relevant privacy; while introducing pseudo-data for obfuscation will cause a decrease in the accuracy and authenticity of distance calculation, affecting the success rate of task allocation; some other schemes will calculate the distance under plaintext and sort it, and this method will disclose the distance distribution information and indirectly disclose information about the location. In addition, many schemes only target a certain type of medium distance metric (such as Euclidean distance) and cannot be flexibly applied to different scenarios. Summary of the Invention

[0005] To solve the above problems existing in the prior art, the present invention provides a location service task allocation method based on homomorphic encryption. The technical problems to be solved by the present invention are realized through the following technical solutions:

[0006] 1. A location service task allocation method based on homomorphic encryption, which is applied to a cloud service system. The cloud service system includes a trusted server, a location server, two cloud computing parties, and multiple user terminals. The user terminals are divided into task submitters and workers. The method is characterized in that the location service task allocation method based on homomorphic encryption includes:

[0007] Step 1, the trusted server generates a public-private key pair for encryption and shares the private key with the two cloud computing parties; each cloud computing party obtains a part of the private key.

[0008] Step 2, the user terminal registers with the location server. After the registration is completed, the location coordinates are encrypted using the public key to obtain location ciphertext, and the location ciphertext is uploaded to the location server.

[0009] Among them, when the user terminal is a task submitter, the location coordinates are the destination location coordinates; when the user terminal is a worker, the location coordinates are the location coordinates of the worker.

[0010] Step 3, after receiving the location ciphertext, the location server verifies the legality of the location ciphertext using the public key. If it is legal, the location ciphertext is stored.

[0011] Step 4, the two cloud computing parties jointly calculate the bit decomposition ciphertext and prefix family ciphertext of the legal location ciphertext, and the initiating party obtains the bit decomposition ciphertext and prefix family ciphertext of the location ciphertext.

[0012] Step 5, the first cloud computing party for summarization determines the workgroup where the worker is located according to the prefix family ciphertext.

[0013] Step 6, the first cloud computing party calculates the distance ciphertext between the workers in the same workgroup and the destination location coordinates corresponding to the workgroup, and feeds back the distance ciphertext to the second cloud computing party.

[0014] Step 7: The second cloud computing party jointly with the first cloud computing party calculates the bit decomposition ciphertext and prefix family ciphertext of the distance ciphertext; wherein, the second cloud computing party holds the bit decomposition ciphertext and prefix family ciphertext of the distance ciphertext.

[0015] Step 8: The two cloud computing parties perform aggregated decryption on the prefix family ciphertext of the distance ciphertext, and perform collaborative sorting in combination with the bit decomposition ciphertext to obtain the sorting result of the distance ciphertext, and decrypt the sorting result according to the respective private keys held and send it back to the location server.

[0016] Step 9: The location server restores the sorting result according to the received and decrypted sorting result, and asks the worker whether to receive the work task according to the sorting result.

[0017] Advantages of the present invention:

[0018] 1. The solution of the present invention performs distance calculations under various mainstream distance metrics in the ciphertext state, can be flexibly applied to different scenarios while ensuring that the distribution of distances will not be leaked, and realizes the privacy of location data itself and the security of queries.

[0019] 2. The solution of the present invention performs secure sorting in the ciphertext state of the distance, avoiding the leakage of distance distribution caused by sorting in the plaintext state or the calculation cost of screening the minimum distance, and improving the efficiency while ensuring security.

[0020] 3. The user side only needs to periodically upload its own location ciphertext, without having to calculate the prefix family of distances locally and then encrypt and upload, reducing the calculation cost of the user side.

[0021] The following will further elaborate on the present invention in conjunction with the accompanying drawings and embodiments. Description of the Drawings

[0022] Figure 1 is a schematic diagram of the cloud service system provided by the present invention;

[0023] Figure 2 is a schematic flow diagram of a location service task allocation method based on homomorphic encryption provided by the present invention. Detailed Embodiments

[0024] The following further describes the present invention in detail with specific embodiments, but the implementation manners of the present invention are not limited thereto.

[0025] Before introducing the present invention, first a brief introduction to the application background of the present invention is given.

[0026] Location-based data service (LBS) is a value-added service that first obtains the location information of mobile terminal users and then provides corresponding services to users with the support of a Geographic Information System (GIS) platform. As the main carrier and application form of emerging technologies such as mobile Internet, geospatial information, artificial intelligence, and cyberspace security, LBS is closely connected with all aspects of national economic and social development. At the same time, with the development of mobile Internet technology and the rapid popularization of intelligent mobile devices, LBS has gradually penetrated into people's daily life and work. Therefore, LBS has received extensive attention and rapid development. To use LBS, users can download location-based applications through intelligent mobile devices. These applications first obtain the user's location through methods such as GPS or the network, and then send the user's location information and the services the user hopes to obtain to the spatial crowdsourcing computing platform in the form of a query request. The LBS server in the platform assists the user in making corresponding queries from a global perspective and returns the query results to the user. It is estimated that hundreds of millions of smartphones, in-vehicle navigation and other devices around the world send more than 100 million location information per second. Currently, location services cover all walks of life and are applied in different fields, such as health, work, personal life, etc.

[0027] In recent years, relevant laws and regulations have been successively announced and implemented, and the country has paid more and more attention to data security supervision. During the location service process, the spatial data generated by users has big data characteristics such as complexity, heterogeneity, real-time, and huge volume. Through open sharing and intelligent management, these data can not only provide convenience for personal life (such as traffic route navigation, surrounding point of interest query, etc.), but also provide precise services for government decision-making (such as major event emergency response, residential community planning, etc.) and enterprise production (such as advertising placement, commercial site selection, etc.). From a technical perspective, the seamless integration of indoor and outdoor positioning technologies, the breakthrough of information platform and big data mining technologies, and the rapid maturity of geofencing technologies will all promote the further development of location-based data services. However, during the process of users efficiently obtaining these services, a large number of user records will be left on the data server, and the context information attached to these records can disclose personal sensitive information such as users' living habits, hobbies, daily activities, social relationships, and physical conditions. Therefore, how to provide high-quality data analysis and decision-making services for users while protecting user privacy is an important technical issue that must be solved in the spatial data service process.

[0028] In this context, privacy computing technology has gradually become the focus of attention for location-based data service practitioners. At the same time, establishing a data security and privacy technology platform also meets the requirements of the country's future development and will be of great help to location data governance. Encryption is an effective method for protecting data privacy. As one of the main technical means of privacy computing, homomorphic encryption technology allows sensitive information to be stored on a remote server, which can not only prevent leakage from the local host side but also ensure the use and search of information. Its feature of being able to perform calculations on ciphertext without decrypting it is of great significance for protecting information security.

[0029] A relatively common location-based data service can be reduced to a task allocation problem based on location information, with the distance between the task publisher and the worker as the task cost. Considering the success rate of task allocation, the overall strategy tends to preferentially select the worker with the lowest task cost, that is, the closest worker. For example, when a user needs to query nearby pharmacies or errand services, neither the user nor the worker wants to disclose information related to their current location to avoid revealing personal sensitive information, while also hoping to match with suitable workers and tasks. Therefore, it is very important to complete task allocation while ensuring the security of location data.

[0030] Combined with homomorphic encryption technology, we propose a location service task allocation method. This scheme encrypts user data through BGN homomorphic encryption, calculates the distance in the ciphertext state for different distance metrics, then sorts the distance ciphertexts, and finally returns the sorting result. The server can allocate the requester's tasks to suitable workers according to the sorting result. Compared with existing schemes, this scheme does not add noise or pseudo-data to the location dataset, improving the accuracy and success rate of task allocation; in addition, this scheme calculates the distance ciphertext and sorts it in the ciphertext state, without revealing the distance distribution of workers, ensuring query privacy. This location service task allocation method based on homomorphic encryption can not only ensure the location privacy and query privacy of the user itself, effectively improving security, but also ensure a high success rate of task allocation, enhancing the system's ability to resist adversary attacks and making it more secure and reliable. In addition, users only need to update the ciphertext of their location according to their needs without any other processing, effectively reducing the user's computing cost and improving convenience.

[0031] The open and complex network environment poses new requirements and challenges for data privacy protection. In the context of the information age, all aspects of people's daily work and life are converted into data and stored and circulated in the network. The huge amount of user information in the network contains great commercial value and economic prospects. Although the analysis and calculation of data bring great convenience and benefits, the direct use of plaintext data also causes great privacy leakage problems. With the popularization of the importance of privacy security by the state, it has become a consensus to protect, store and transmit sensitive data on public networks in ciphertext form. Therefore, how to complete complex computing tasks in the ciphertext state has become an increasingly urgent social need. Our invention improves the security of location-based data services, enables the system to flexibly adapt to different scenarios, be more secure and reliable, and can also meet the needs of users who require higher security levels of location services.

[0032] The present invention provides a method for allocating location service tasks based on homomorphic encryption, which is applied to a cloud service system. Referring to Figure 1 as shown, the cloud service system includes a trusted server, a location server, two cloud computing parties, and multiple user terminals. The user terminals are divided into task submitters and workers.

[0033] Embodiment 1

[0034] As Figure 2 shown, the present invention provides a method for allocating location service tasks based on homomorphic encryption, including:

[0035] Step 1, the trusted server generates a public-private key pair for encryption and shares the private key with the two cloud computing parties; each cloud computing party obtains a part of the private key.

[0036] Step 2, the user terminal registers with the location server. After the registration is completed, the location coordinates are encrypted using the public key to obtain location ciphertext, and the location ciphertext is uploaded to the location server;

[0037] Among them, when the user terminal is a task submitter, the location coordinates are the destination location coordinates; when the user terminal is a worker, the location coordinates are the location coordinates of the worker.

[0038] The user terminals (including task submitters and workers) under each base station register and upload the encrypted horizontal and vertical location coordinates. After the location server authenticates and verifies the data legality, it stores them.

[0039] Step 3, after receiving the location ciphertext, the location server verifies the legality of the location ciphertext using the public key. If it is legal, it stores the location ciphertext;

[0040] Step 4: The two cloud computing parties jointly calculate the bit decomposition ciphertext and prefix family ciphertext of the legal location ciphertext, and the initiating party for the calculation obtains the bit decomposition ciphertext and prefix family ciphertext of the location ciphertext.

[0041] Step 5: The first cloud computing party for summarization determines the workgroup where the worker is located according to the prefix family ciphertext.

[0042] Step 6: The first cloud computing party calculates the distance ciphertext between the workers in the same workgroup and the destination location coordinates corresponding to the workgroup, and feeds back the distance ciphertext to the second cloud computing party.

[0043] Step 7: The second cloud computing party jointly with the first cloud computing party calculates the bit decomposition ciphertext and prefix family ciphertext of the distance ciphertext; among them, the second cloud computing party holds the bit decomposition ciphertext and prefix family ciphertext of the distance ciphertext.

[0044] Among them, the second cloud computing party uses the bit decomposition protocol to cooperate with the first cloud computing party to calculate the bit decomposition ciphertext of the distance ciphertext and the prefix ciphertext.

[0045] Step 8: The two cloud computing parties perform summary decryption on the prefix family ciphertext of the distance ciphertext, and perform collaborative sorting in combination with the upper bit decomposition ciphertext to obtain the sorting result of the distance ciphertext, and decrypt the sorting result according to the private keys they hold and send it back to the location server.

[0046] Step 9: The location server restores the sorting result according to the received and decrypted sorting result, and asks the worker whether to receive the work task according to the sorting result.

[0047] Embodiment 2

[0048] In a specific embodiment, Step 1 includes:

[0049] Step 11: The trusted server uses the BGN homomorphic encryption algorithm to generate the public and private key pair {PK, SK} required for encryption.

[0050] Step 12: The trusted server shares the private key SK = p with the two cloud computing parties, where p is a large prime number.

[0051] Step 13: The trusted server generates w + 1 random numbers for all numbers or the prefix family of the working interval, and encrypts the w + 1 random numbers using the public key to obtain the random number ciphertext.

[0052] Step 14: The random number ciphertext is made public to the location server and the two cloud computing parties.

[0053] Among them, w is the maximum bit length of the user's location data, and the horizontal and vertical coordinates x, y of the location data ∈ {0, 1,..., 2 w-1}; All the numbers refer to the position coordinates and the distance data calculated between the position coordinates, and the working range refers to the range formed by the horizontal and vertical coordinates of the position coordinates.

[0054] Embodiment III

[0055] In a specific embodiment, step 4 includes:

[0056] Step 41, the location server uploads the legal location ciphertext to any one of the two cloud computing parties;

[0057] Among them, the location server uploads the location ciphertexts of the task submitter and the workers in the base station where the task submitter is located to any one of the two cloud servers.

[0058] Step 42, the cloud computing party that receives the location ciphertext calculates the bit decomposition ciphertext of the location ciphertext using the bit decomposition protocol;

[0059] The computing server calculates the bit decomposition ciphertext of the user location ciphertext using the bit decomposition protocol, where the bit decomposition ciphertext of the task submitter's location is expressed as:

[0060] {E(x ta,τ,w-1 ),E(x ta,τ,w-2 ),...,E(x ta,τ,0 ),E(y ta,τ,w-1 ),E(y ta,τ,w-2 ),...,E(y ta,τ,0 )},

[0061] Among them, E(x ta,τ,k-1 )(k = w,..., 1) represents the k-th bit of the abscissa of the task submitter's location, and E(y ta,τ,k-1 )(k = w,..., 1) represents the k-th bit of the ordinate of the task submitter's location. represents the k-th bit of the abscissa of the i-th worker's location, represents the k-th bit of the ordinate of the i-th worker's location.

[0062] And the bit decomposition ciphertext of the i-th worker in this base station can be expressed as:

[0063]

[0064] Step 43, the cloud computing party that receives the location ciphertext calculates the prefix family ciphertext using the bit decomposition protocol.

[0065] It is known that a data with a length of w bits has w + 1 prefixes, which are collectively called the prefix family of this data. The ciphertext calculation method is as follows. Taking x ta,τ as an example:

[0066] for j = w downto 0:

[0067] if j == w:

[0068] s ta,x,τ,j = E(2 w )·E(r w )

[0069] elif j == w - 1:

[0070] t ta,x,τ,j = E(x ta,x,τ,j )

[0071]

[0072] else:

[0073]

[0074]

[0075] wherein, the encrypted prefix family E(Ω(F(x ta,τ ))) = {s ta,τ ,..., s ta,x,τ,w ,..., s ta,x,τ,0}. After processing each position ciphertext in this way, each position ciphertext has a corresponding bit decomposition ciphertext and prefix family ciphertext. E(r j )(j = w,..., 0) are the ciphertexts corresponding to the w + 1 random numbers generated by the trusted server for all numbers or the prefix family of the working interval in step 13. t ta,x,τ,j (j = w - 1,..., 0) is an intermediate result involved in the calculation and has no actual application significance. Its main purpose is to calculate the ciphertext corresponding to the weighted sum of all bit decompositions involved in this and previous loops.

[0076] Example 4

[0077] In a specific embodiment, step 5 includes:

[0078] Step 51, each cloud computing party determines a maximum travel distance MTD;

[0079] Step 52, each cloud computing party determines the prefix family ciphertext of the working interval according to MTD;

[0080] Step 53, each cloud computing party uses the private key it knows to partially decrypt the prefix family ciphertext of the working interval to obtain a first decryption result;

[0081] Step 54: Each cloud computing party uses its own known private key to partially decrypt the prefix family ciphertext of the worker's location ciphertext to obtain a second decryption result.

[0082] The cloud computing party determines a maximum travel distance MTD. Within a square range centered on task ta with a side length of 2MTD determined by this distance, there is a high probability that the worker will accept the task. The cloud computing party first calculates the horizontal and vertical coordinate intervals of the workgroup, that is, the working interval, which is expressed as:

[0083] [x ta,τ -MTD, x ta,τ +MTD], [y ta,τ -MTD, y ta,τ +MTD].

[0084] Among them, [x ta,τ -MTD, x ta,τ +MTD] is the horizontal coordinate interval of the workgroup, and [y ta,τ -MTD, y ta,τ +MTD]

[0085] is the vertical coordinate interval of the workgroup.

[0086] The ciphertext of the prefix family of the working interval is partially decrypted to obtain:

[0087]

[0088]

[0089] Among them, R([x ta,τ -MTD, x ta,τ +MTD]) represents the unquantified prefix family of the interval [x ta,τ -MTD, x ta,τ +MTD], and Ω(R([x ta,τ -MTD, x ta,τ +MTD])) represents the quantified prefix family of the interval [x ta,τ -MTD, x ta,τ +MTD]. The symbols in the following formula are the same by analogy.

[0090] Step 55: The cloud computing party for summarization obtains the decryption results of the other party, and summarizes its own decryption result and the decryption result of the other party to obtain the complete first decryption result and second decryption result, and determines whether there is an intersection between the complete first decryption result and the complete second decryption result, so as to determine whether the worker is within the working interval;

[0091] Step 56: The cloud computing party for summarization divides the workers located within the working interval into workgroups corresponding to the working interval.

[0092] The cloud computing party determines whether there is an intersection between the prefix family of the partially decrypted working group interval and the worker position prefix family. If and it indicates that the worker is within the scope of this working group. Thus, the d workers included in the working group can be determined.

[0093] The present invention proposes a prefix-based encrypted state comparison scheme. After generating the encrypted state prefix family for two location data, the highest different bit position is found by comparing the prefix situations of the two location data, thereby obtaining the encrypted state data comparison result.

[0094] Embodiment 5

[0095] In a specific embodiment, step 6 includes:

[0096] The first cloud computing party, according to the regional characteristics where the working group is located, selects different distance calculation methods to calculate the distance ciphertext between the workers in the same working group and the destination position coordinates corresponding to the working group, and feeds back the distance ciphertext to the second cloud computing party.

[0097] Select a suitable distance metric according to the terrain characteristics and specific service conditions of the current location. Euclidean distance is suitable for locations with sparse block distributions; Manhattan distance is applicable to locations with neat and dense block distributions; and Chebyshev distance can be selected when the worker cannot directly reach the destination but can receive tasks nearby, such as when a user takes a taxi and needs to wait by the roadside nearby.

[0098] (1) Euclidean distance: For the i-th worker in the working group, the cloud server calculates the ciphertext of the position coordinate difference and Then, the two cloud computing parties cooperate, and the secure multiplication protocol is denoted by the symbol SM(·,·). The secure multiplication protocol is called to calculate the square of the coordinate difference. The general process is as follows, taking the calculation of as an example.

[0099] is the difference in the abscissa between the destination position and the i-th worker w i in the working group, the difference in the ordinate between the destination position and the i-th worker w i in the working group.

[0100] Cloud computing party 1 selects two random numbers r a , r b , and calculates and The result after the two parties jointly decrypt is collected by cloud service 2 and calculated as Here, due to the additive homomorphic property, it is the ciphertext of the sum of the plaintexts corresponding to the ciphertexts. is the ciphertext corresponding to the sum of the difference between the destination position and the abscissa of the i-th worker w in the working group and the random number r i The difference between the abscissas a and the random number r is the ciphertext corresponding to the sum of the difference between the destination position and the abscissa of the i-th worker w in the working group i The difference between the abscissas b and the random number r is the product of and

[0101] Subsequently, the cloud server 2 encrypts it and sends it to the cloud server 1. After the cloud server 1 obtains it calculates

[0102] where is the square of the difference between the destination position and the abscissa of the i-th worker w in the working group i ; similarly is the square of the difference between the destination position and the ordinate of the i-th worker w in the working group i The ordinate difference squared

[0103] And so on, the cloud computing party 1 can also calculate According to the additive homomorphic property of the BGN encryption method, the ciphertext of the square of the Euclidean distance between the i-th worker in the working group and the task ta can be obtained Here, dit i is the square of the Euclidean distance between the i-th worker in the working group and the task ta, and E(dit i ) is its corresponding ciphertext; is the ciphertext corresponding to the sum of the square of the difference between the destination position and the abscissa of the i-th worker w in the working group i and the square of the difference between the ordinates

[0104] (2) Manhattan distance: The Manhattan distance is the sum of the absolute values of the differences between the abscissa and the ordinate. The cloud computing party first needs to compare the position coordinates of the workers in the working group with the position coordinates of the task ta. The specific process is that the cloud computing party partially decrypts the prefix families of the position coordinates of the workers in the working group and the position coordinates of the task ta to obtain:

[0105] and is the unquantified prefix family of the abscissa of the i-th worker in the working group ; is the quantified prefix family of is the corresponding ciphertext of the former It is the result of partial decryption of the former. Similarly for others.

[0106] For the i-th worker in the working group, compare the prefix families of its horizontal and vertical coordinates in sequence. Let the first different prefix be If the prefix families are the same, then we get:

[0107]

[0108] is one used to represent whether it is less than x ta,τ of a ciphertext corresponding to one bit. When is less than x ta,τ at this time, On the contrary, j 1 is the first different prefix corresponding serial number, is the j-th ta,τ bit of x 1 . E(0) is the ciphertext of 0 (encrypted with the public key PK).

[0109] After obtaining the ciphertext of the size relationship, the two cloud computing parties cooperate to call the secure multiplication protocol, and then we can calculate: E(1) is the ciphertext of 1 (encrypted with the public key PK). SM is the secure multiplication protocol mentioned in the section of Euclidean distance.

[0110] Similarly, we can get Finally, we can calculate the Manhattan distance:

[0111]

[0112] represents the absolute value of the difference between the destination position and the horizontal coordinate of the i-th worker w in the working group. Similarly, we can get i represents the absolute value of the difference between the destination position and the vertical coordinate of the i-th worker w in the working group. represents the absolute value of the difference between the destination position and the horizontal coordinate of the i-th worker w in the working group. i of the vertical coordinate.

[0113] (3) Chebyshev distance: The Chebyshev distance refers to the maximum value between the absolute value of the difference in the horizontal coordinates and the absolute value of the difference in the vertical coordinates. The cloud computing parties can calculate the absolute values of the differences in the horizontal and vertical coordinates as described in the Manhattan distance and Then the two cloud computing parties can calculate and the bit decomposition ciphertext and the prefix family ciphertext as described in steps 42 and 43, and then perform a secure comparison as described to obtain the first different prefix and The Chebyshev distance ciphertext is as follows:

[0114]

[0115] SM is the secure multiplication protocol mentioned in the section on Euclidean distance.j 2 is the first different prefix and is the serial number of the corresponding prefix. represents the absolute value of the difference in abscissas of the j 2 th bit, and is its corresponding ciphertext; similarly, it can be obtained that represents the absolute value of the difference in ordinates of the j 2 th bit, and is its corresponding ciphertext.

[0116] Example 6

[0117] In a specific embodiment, step 8 includes:

[0118] Step 81, two cloud computing parties, according to their respective private keys, cooperate to partially decrypt the ciphertext of the prefix family of the distance ciphertext; the first cloud computing party aggregates the partial decryption results of both parties and holds the aggregated decryption result of the prefix family ciphertext;

[0119] Step 82, the second cloud computing party compares one prefix family in the aggregated decryption result with other prefix families to obtain the distance length ciphertext;

[0120] Step 83, the second cloud computing party combines the bit decomposition ciphertext of the distance ciphertext and sorts the distance length ciphertext to obtain the sorted result ciphertext;

[0121] Step 84, the two cloud computing parties cooperate to decrypt the sorted result ciphertext through their respective private keys and send it back to the location server.

[0122] The cloud computing party holding the distance ciphertext hands over the ciphertext to the other cloud computing party, and the other party initiates the calculation of the bit decomposition ciphertext and the prefix family ciphertext as described in 3.2). Then the two cloud computing parties cooperate to partially decrypt the prefix family ciphertext. For the i-th worker in the workgroup, the prefix family of the partial decryption of its distance ciphertext E(dit i ) is compared with the prefix families of the other d - 1 ciphertexts in the workgroup. Suppose the serial number of the first different prefix in the d - 1 comparisons is Then its sorted serial number ciphertext is where is the distance dit of the i-th worker i of the j k is the ciphertext of the bit decomposition.

[0123] The present invention proposes a solution for securely sorting encrypted data. Each piece of data in the encrypted dataset is compared pairwise. The highest different bit position is found through the prefix, and the encrypted sorting situation is finally obtained by accumulating the situations of the highest different bit positions. After decryption, the sorting state in plaintext can be known.

[0124] Embodiment Seven

[0125] In a specific embodiment, step 9 includes:

[0126] Step 91, the location server restores the sorting result according to the received and decrypted sorting result;

[0127] Step 92, according to the restored sorting result, ask the corresponding worker whether to accept the work task in the order from the front to the back. If the worker in the front does not accept, then ask the next worker.

[0128] The cloud computing party decrypts the sorting result and returns it to the location server. The location server restores the specific sorting situation and asks the worker whether to accept the task in ascending order of the sorting serial number. If the task is accepted, the task is assigned to the worker, otherwise the next worker is asked.

[0129] The present invention is applicable to multiple scenarios, realizes encrypted distance calculation and encrypted sorting under multiple metrics, and ensures the privacy of location information and the success rate.

[0130] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality" means two or more unless otherwise specifically defined.

[0131] Although the present application has been described in conjunction with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the accompanying drawings, the disclosed content, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality of situations.

[0132] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A location service task allocation method based on homomorphic encryption, which is applied to a cloud service system. The cloud service system includes a trusted server, a location server, two cloud computing parties, and multiple client terminals. The client terminals are divided into task submitters and workers. Characterized in that, The location service task allocation method based on homomorphic encryption includes: Step 1, the trusted server generates a public-private key pair for encryption and shares the private key with the two cloud computing parties; each cloud computing party obtains a part of the private key. Step 2, the client terminal registers with the location server. After the registration is completed, the location coordinates are encrypted using the public key to obtain location ciphertext, and the location ciphertext is uploaded to the location server. Among them, when the client terminal is a task submitter, the location coordinates are the destination location coordinates, and when the client terminal is a worker, the location coordinates are the location coordinates of the worker. Step 3, after receiving the location ciphertext, the location server uses the public key to verify the legality of the location ciphertext. If it is legal, the location ciphertext is stored. Step 4, the two cloud computing parties jointly calculate the bit decomposition ciphertext and the prefix family ciphertext of the legal location ciphertext. Among them, the initiating party obtains the bit decomposition ciphertext and the prefix family ciphertext of the location ciphertext. Step 5, the first cloud computing party for summarization determines the work group where the worker is located according to the prefix family ciphertext. Step 6, the first cloud computing party calculates the distance ciphertext between the workers in the same work group and the corresponding destination location coordinates of the work group, and feeds back the distance ciphertext to the second cloud computing party. Step 7, the second cloud computing party jointly with the first cloud computing party calculates the bit decomposition ciphertext and the prefix family ciphertext of the distance ciphertext; among them, the second cloud computing party holds the bit decomposition ciphertext and the prefix family ciphertext of the distance ciphertext. Step 8, the two cloud computing parties perform summarization decryption on the prefix family ciphertext of the distance ciphertext, and perform collaborative sorting in combination with the upper bit decomposition ciphertext to obtain the sorting result of the distance ciphertext, and decrypt the sorting result according to the respective private keys they possess and send it back to the location server. Step 9, the location server restores the sorting result according to the received and decrypted sorting result, and asks the worker whether to receive the work task according to the sorting result.

2. A location service task allocation method based on homomorphic encryption according to claim 1, Characterized in that, Step 1 includes: Step 11, the trusted server uses the BGN homomorphic encryption algorithm to generate a public-private key pair {PK, SK} for encryption. Step 12, the trusted server shares the private key SK = p with the two cloud computing parties, where p is a large prime number. Step 13, the trusted server generates w + 1 random numbers for all numbers or the prefix family of the working interval, and encrypts the w + 1 random numbers using the public key to obtain random number ciphertext. Step 14, the random number ciphertext is made public to the location server and the two cloud computing parties. where w is the maximum bit length of the user's position data, and the horizontal and vertical coordinates x, y of the position data belong to {0, 1,..., 2 w - 1}; all the numbers refer to the position coordinates and the distance data calculated between the position coordinates, and the working range refers to the range formed by the horizontal and vertical coordinates of the position coordinates.

3. A location service task allocation method based on homomorphic encryption according to claim 1, Characterized in that, Step 4 includes: Step 41, the location server uploads the legal location ciphertext to any one of the two cloud computing parties. Step 42: The cloud computing party that receives the location ciphertext uses the bit decomposition protocol to calculate the bit decomposition ciphertext of the location ciphertext; Step 43: The cloud computing party that receives the location ciphertext uses the bit decomposition protocol to calculate the prefix family ciphertext.

4. A location service task allocation method based on homomorphic encryption according to claim 1, characterized in that, Step 5 includes: Step 51: Each cloud computing party determines a maximum travel distance MTD; Step 52: Each cloud computing party determines the prefix family ciphertext of the working interval according to the MTD; Step 53: Each cloud computing party uses its own known private key to partially decrypt the prefix family ciphertext of the working interval to obtain a first decryption result; Step 54: Each cloud computing party uses its own known private key to partially decrypt the prefix family ciphertext of the location ciphertext of the worker to obtain a second decryption result; Step 55: The cloud computing party for summarization obtains the decryption results of the other party, and summarizes its own decryption result and the decryption result of the other party to obtain a complete first decryption result and a second decryption result, and determines whether there is an intersection between the complete first decryption result and the complete second decryption result, so as to determine whether the worker is located within the working interval; Step 56: The cloud computing party for summarization divides the workers located within the working interval into the working groups corresponding to the working interval.

5. A location service task allocation method based on homomorphic encryption according to claim 1, characterized in that, Step 6 includes: The first cloud computing party, according to the regional characteristics of the working group, selects different distance calculation methods to calculate the distance ciphertext between the workers located in the same working group and the destination location coordinates corresponding to the working group, and feeds back the distance ciphertext to the second cloud computing party.

6. A location service task allocation method based on homomorphic encryption according to claim 1, characterized in that, Step 7 includes: The second cloud computing party uses the bit decomposition protocol to cooperate with the first cloud computing party to calculate the bit decomposition ciphertext and the prefix ciphertext of the distance ciphertext.

7. A location service task allocation method based on homomorphic encryption according to claim 6, characterized in that, Step 8 includes: Step 81: The two cloud computing parties cooperate to partially decrypt the prefix family ciphertext of the distance ciphertext according to their respective possessed private keys; the first cloud computing party summarizes the partial decryption results of both parties and holds the summary decryption result of the prefix family ciphertext; Step 82: The second cloud computing party compares one prefix family in the summary decryption result with other prefix families to obtain the distance length ciphertext; Step 83: The second cloud computing party combines the bit decomposition ciphertext of the distance ciphertext to sort the distance length ciphertext to obtain the sorted result ciphertext; Step 84: The two cloud computing parties cooperate to decrypt the sorted result ciphertext through their respective possessed private keys and send it back to the location server.

8. A location service task allocation method based on homomorphic encryption according to claim 7, characterized in that, Step 9 includes: Step 91: The location server restores the sorted result according to the received and decrypted sorted result; Step 92: According to the restored sorting result, ask the corresponding worker whether to accept the work task in the order from the front to the back. If the worker in the front does not accept, ask the next worker.

Citation Information

Patent Citations

  • Spatial crowdsourcing task allocation system and method constructed through utilization of partial homomorphic crypto scheme

    CN107222302A

  • Location privacy protection method based on the cloud server

    CN107347096A