Vehicle Opportunistic Computing Attribute Encryption Method and System Based on Dual Hybrid Ciphertext Strategy
By adopting the encryption method of dual hybrid ciphertext policy attributes in the vehicle opportunity computing environment, the data is encrypted twice and the key management is transferred to the data-sharing vehicle, the problems of forward security and computing burden in VOC are solved, and efficient data sharing and secure transmission are achieved.
Patent Information
- Application Number
- CN202310340891.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-31
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2043-03-31
AI Technical Summary
In the existing vehicle opportunity computing (VOC), the encryption algorithm (CP-ABE) based on the ciphertext policy attribute has disadvantages in forward security, and it is difficult to meet the problems of forward security and excessive computing burden when the vehicle shares data.
The encryption method based on the dual-hybrid ciphertext policy attribute is adopted, and the data is encrypted twice through the data sharing tool, and the key generation and management are transferred to the data sharing vehicle. The edge server is used for proxy understanding, avoiding the dependence of trusted authoritatives (TAs).
It realizes the satisfaction of forward security in the vehicle opportunity computing environment, while reducing the computing cost, improving the security and efficiency of data transmission, and reducing the dependence on third-party fully trusted entities.
Smart Images

Figure CN116388988B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle networking technology, and in particular to a vehicle opportunistic computing encryption method and system based on dual hybrid ciphertext strategy attributes. Background Art
[0002] The booming growth of the Internet of Vehicles (IoV) has made it difficult for network paradigms that rely on cloud computing to cope. High latency is a prominent issue due to the long distance from cloud servers. To alleviate these issues, in-vehicle edge computing has been proposed, where servers are deployed near the vehicle. However, the sheer number of vehicles, especially in urban areas, has created a new computing bottleneck. A report indicates that approximately 70% of cars are parked for more than 20 hours per day on average. Therefore, a new computing paradigm, vehicle opportunistic computing (VOC), has been proposed to leverage the idle resources of vehicles connected by opportunistic networks (self-organizing networks that communicate through chance encounters created by vehicle movement). However, this approach presents security issues, as each vehicle has easy access to the shared data used for computation. Furthermore, shared data can be easily eavesdropped or even tampered with by malicious entities during transmission. While traditional encryption methods can ensure the integrity and confidentiality of shared data, encrypting every file in every vehicle and maintaining the encryption key is prohibitively cumbersome for shared vehicle data.
[0003] The concept of attribute-based encryption (ABE) was first introduced in the seminal work of Sahai and Waters. The two most important variants are Cipher Policy Attribute Encryption (CP-ABE) and Key Policy Attribute Encryption (KP-ABE). CP-ABE is more widely used because its decryption is similar to role-based access control. ABE requires a third party acting as a trusted authority (TA) to generate keys for the entity. However, in practice, it is difficult to find a fully trustworthy entity.
[0004] Furthermore, shared data always maps to a single element in a group and has a very limited length, which makes it difficult to apply to VOCs. While some hybrid schemes have been proposed, where ABE encryption is used to encrypt the key for shared data, to address this issue, these schemes fail to achieve forward security because revoked entities can still decrypt the shared data using the symmetric key. Due to these two points, existing schemes cannot be directly deployed in VOCs. Summary of the Invention
[0005] The present invention provides a vehicle opportunistic computing encryption method and system based on dual hybrid ciphertext strategy attributes, which can not only find a completely trustworthy entity, but also be directly deployed in VOC.
[0006] To solve the above-mentioned purpose, the present invention provides the following technical solution: a vehicle opportunity calculation encryption method based on dual hybrid ciphertext strategy attributes, characterized in that the steps include:
[0007] A vehicle opportunity calculation encryption method based on dual hybrid ciphertext strategy attributes, characterized by the steps comprising:
[0008] S1: Initialize the data sharing vehicle system and build an opportunistic network containing idle vehicles with the assistance of the base station;
[0009] S2: Encrypt the data required for calculation and upload the encrypted data to the edge server. Differentiate the attributes and tasks of the encrypted data, distribute the tasks of the data sharing vehicle to adjacent idle vehicles, and generate keys for the idle vehicles.
[0010] S3: The idle vehicle decrypts the data using the key.
[0011] Preferably, in step S1, the data sharing vehicle system is initialized, and an opportunistic network including idle vehicles is constructed with the assistance of the base station, including:
[0012] Initialize the data sharing vehicle system and generate public parameters and master keys for each data D that needs to be encrypted through the data sharing vehicle, including:
[0013] According to the following formula (1), the data sharing vehicle selects the system security parameter k as the function input to generate a group G1 with a prime order of p, and g is the generating element of G1:
[0014] Iinit(κ)→(MSK,Params) (1)
[0015] The data sharing tool randomly selects h1,...,h ∣U∣ ∈G1 and α,a∈Z p . It generates the mapping function M1: {0,1} * →G2; where U represents a set of common attributes; |U| is the size of the set;
[0016] Generate mapping function M1: {0,1} * →G2,M2:G2→{0,1} * and a hash function H1:G1→{0,1} * ; Where M2 is the inverse function of M1;
[0017] parameter Where MSK = g α A master key kept secret for data sharing vehicles.
[0018] Preferably, step S1 further includes:
[0019] The data sharing vehicle generates an outsourcing key and a secret key corresponding to the idle vehicle and its attribute set.
[0020] Preferably, in step S2, encrypting the data required for calculation and uploading the encrypted data to the edge server includes:
[0021] Symmetrically encrypt the data required for calculation and upload the encrypted data to the edge server;
[0022] Encrypt the attributes of the data required for calculation and upload the encrypted data to the edge server.
[0023] Preferably, the attributes and tasks of the encrypted data are differentiated, the tasks of the data sharing vehicle are distributed to adjacent idle vehicles, and keys are generated for the idle vehicles, including:
[0024] According to the following formula (2), the data sharing vehicle randomly selects the symmetric key ssk1:
[0025] SEncrypt(ssk1,D)→(SED) (2)
[0026] The SEncrypt function takes ssk1 and data D as input and outputs SED encrypted by the symmetric algorithm according to the following formula (3):
[0027]
[0028] Upload the SED to the edge server.
[0029] Preferably, the attributes of the data required for calculation are encrypted and the encrypted data is uploaded to the edge server, including:
[0030] According to the following formula (4), a LSSS(M,ρ) is generated for the access structure A, where M is a l×n matrix and ρ is a function that maps each row of M to an underlying attribute;
[0031] Randomly generate s,y2,y3,...,y n ∈Z p , where s is the shared secret, set a vector calculate Then randomly select r1,r2,...,r l ∈Z p , let ssk2 = ssk1; calculate,
[0032]
[0033] Constitute the ciphertext,
[0034] CTA =(C,C′,C1,...,C l ,l,(M,ρ)).
[0035] Data Sharing Vehicle Secret Preservation CT A and upload a copy to the edge server.
[0036] Preferably, in step S3, the idle vehicle decrypts and obtains data using a key, including:
[0037] When an idle vehicle intends to obtain shared data, it sends a request to the edge server;
[0038] After receiving the request, the edge server sends the encrypted data and semi-plaintext to the idle vehicle; the edge server j The list records data that has been accessed by idle vehicle j.
[0039] Preferably, after receiving the request, the edge server sends the symmetrically encrypted data SED and the semi-plaintext SP to the idle vehicle, including:
[0040] Set, IDecript(vsk,SP,SED)→(D), then define a set If the attribute set of the free vehicle does not satisfy the access structure, it returns ⊥; otherwise, due to the construction of LSSS, it can find a constant ω i ∈Z p , so that ∑ i∈I ω i λ i =s; then the edge server calculates,
[0041]
[0042] Let SP = (C, TP), and the edge server sends the semi-plaintext SP and SED to the idle vehicles.
[0043] Preferably, after step S3, the following steps are further included:
[0044] When the idle vehicle state changes to moving state, or the data sharing vehicle has left the base station range, the data sharing vehicle must cancel one or more idle vehicles;
[0045] The edge server receives a revocation command from a data sharing vehicle about an idle vehicle j. For each encrypted data touched by j, the edge server randomly selects β∈Z p , calculate SG = g β and passed to the data sharing vehicle.
[0046] A vehicle opportunity calculation encryption system based on dual hybrid ciphertext strategy attributes, the system is used for the above-mentioned vehicle opportunity calculation encryption method based on dual hybrid ciphertext strategy attributes, the system comprising:
[0047] an initialization module, used to initialize the data sharing vehicle system and build an opportunistic network containing idle vehicles with the assistance of the base station;
[0048] An encryption module is used to encrypt the data required for calculation and upload the encrypted data to the edge server; distinguish the attributes and tasks of the encrypted data, distribute the tasks of the data sharing vehicle to adjacent idle vehicles, and generate keys for the idle vehicles;
[0049] The decryption module is used for the idle vehicle to decrypt and obtain data using the key.
[0050] On the one hand, an electronic device is provided, which includes a processor and a memory, wherein the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the above-mentioned vehicle opportunity computing encryption method based on dual hybrid ciphertext strategy attributes.
[0051] On the one hand, a computer-readable storage medium is provided, wherein the storage medium stores at least one instruction, and the at least one instruction is loaded and executed by a processor to implement the above-mentioned vehicle opportunity computing encryption method based on dual hybrid ciphertext strategy attributes.
[0052] Compared with the prior art, the above technical solution has at least the following beneficial effects:
[0053] The above scheme fixes the shortcomings of the forward security of the existing Cipher Policy Attribute Based Encryption (CP-ABE). The data sharing tool encrypts the data twice using a symmetric key, and the key is encrypted by CP-ABE. Once the computing tool or VOC is revoked, the storage service provider and the data sharing tool will re-encrypt the shared data and symmetric key. Due to the intermittent connectivity of the VOC, we transfer the function of the trusted authority (TA) to the data sharing vehicle, thereby eliminating the TA. That is, the generation of keys and parameters is performed by the data sharing tool, rather than by a third party that must be assumed to be completely secure. Compared with existing typical similar schemes, the DH-CPABE scheme has lower computational cost in encryption, proxy decryption, and decryption under the same conditions. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0055] Figure 1 A schematic flow chart of a vehicle opportunity calculation encryption method based on dual hybrid ciphertext strategy attributes of the present invention;
[0056] Figure 2 4 is a system model diagram of the DH-CPABE scheme in an embodiment of the present invention;
[0057] Figure 3 A diagram of the key generation, encryption, and decryption process in an embodiment of the present invention;
[0058] Figure 4 is a system block diagram in an embodiment of the present invention;
[0059] Figure 5 Schematic diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0060] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the described embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0061] The present invention provides a vehicle opportunity computing encryption algorithm (CP-ABE) with no trust mechanism based on dual hybrid ciphertext strategy attributes, which can not only meet forward security but also encrypt sharded data without restriction, and provides a vehicle opportunity computing encryption method based on dual hybrid ciphertext strategy attributes.
[0062] like Figure 1 As shown, the embodiment of the present invention provides a vehicle opportunity calculation encryption method based on dual hybrid ciphertext strategy attributes, and the process is as follows:
[0063] S101: Initialize the data sharing vehicle system and build an opportunistic network including idle vehicles with the assistance of the base station.
[0064] In one feasible implementation, the data sharing vehicle system is initialized and an opportunistic network including idle vehicles is constructed with the assistance of a base station, including:
[0065] Initialize the data sharing vehicle system and generate public parameters and master keys for each data D that needs to be encrypted through the data sharing vehicle, including:
[0066] According to the following formula (1), the data sharing vehicle selects the system security parameter k as the function input to generate a group G1 with a prime order of p, and g is the generating element of G1:
[0067] Iinit(κ)→(MSK,Params) (1)
[0068] The data sharing tool randomly selects h1,...,h ∣U∣ ∈G1 and α,a∈Z p . It generates the mapping function M1: {0,1} * →G2; where U represents a set of common attributes; |U| is the size of the set;
[0069] Generate mapping function M1: {0,1} * →G2,M2:G2→{0,1} * and a hash function H1:G1→{0,1} * ; Where M2 is the inverse function of M1;
[0070] parameter Where MSK = g α A master key kept secret for data sharing vehicles.
[0071] In a feasible implementation, the present invention is a dual hybrid attribute-based encryption algorithm (DH-CPABE) scheme tailored for vehicular opportunistic computing (VOC), such as Figure 2 Figure 2 shows the system model of the DH-CPABE scheme. The DH-CPABE scheme involves four entities: data-sharing vehicles, idle vehicles, malicious actors, and edge servers. Generally speaking, when a vehicle (the data-sharing vehicle) needs to distribute tasks to neighboring idle vehicles (for task computation), it builds an opportunistic network consisting of these idle vehicles with the assistance of a base station. The data-sharing vehicles then encrypt the data required for computation and upload it to the edge server. Subsequently, keys are generated for these idle vehicles based on the relevant attributes and task distinctions. Finally, the computational tool obtains the encrypted data and decrypts it with the key. Throughout this process, the malicious tool does its best to steal secret data or obtain data that was previously accessible but is now prohibited.
[0072] In one feasible implementation, the embodiment of the present invention, DH-CPABE consists of five parts: initialization, key generation, encryption, decryption, and revocation. To facilitate further discussion, the meaning of the symbols used before the specific structure is given, as shown in Table 1.
[0073] Table 1 Symbol meaning
[0074]
[0075]
[0076] In a feasible implementation, when a data sharing vehicle needs to share data with these idle vehicles involved in opportunistic computing, the data sharing vehicle initializes the system and generates public parameters, master keys and an empty tuple for each encrypted data d. Record the previous symmetric secret. At the same time, the edge server creates an empty list AccessList for each idle vehicle j , records the files visited by vehicle j and creates a file similar to Empty tuple of It is worth emphasizing that and A different symmetric key corresponding to the data d is retained.
[0077] Iinit(κ)→(MSK,Params): The data sharing vehicle selects the system security parameter k as the function input. It generates a group G1 with a prime order of p, and g is the generator of G1. It selects the bilinear pairing relation: Assume U is a set of common attributes and |U| is the size of the set. The data sharing tool randomly selects h1,...,h ∣U∣ ∈G1 and α,a∈Z p . It generates the mapping function M1: {0,1} * →G2,M2:G2→{0,1} * and a hash function H1:G1→{0,1} * , note that M1 maintains the randomness of the input, and M2 is the inverse function of M1 (i.e., x = M2 (M1 (x))). Finally, the parameters are given Where MSK = g α A master key kept secret for data sharing vehicles.
[0078] In a feasible implementation, the present invention further includes:
[0079] The data sharing vehicle generates an outsourcing key and a secret key corresponding to the idle vehicle and its attribute set.
[0080] In one feasible implementation, AKeyGen(Params,MSK,S)→(OSK,vsk): randomly select t,z j ∈Z p ,calculate
[0081]
[0082] Then set the outsourcing key of idle vehicle j and secret key vsk=z j ,The data sharing vehicle sends OSK and vsk to the edge server and idle vehicles, respectively.
[0083] S102: Encrypt the data required for calculation and upload the encrypted data to the edge server; distinguish the attributes and tasks of the encrypted data, distribute the tasks of the data sharing vehicle to adjacent idle vehicles, and generate keys for the idle vehicles.
[0084] In one feasible implementation, encrypting data required for calculation and uploading the encrypted data to an edge server includes:
[0085] Symmetrically encrypt the data required for calculation and upload the encrypted data to the edge server;
[0086] Encrypt the attributes of the data required for calculation and upload the encrypted data to the edge server.
[0087] In a feasible implementation, the encryption phase is divided into two parts: data symmetric encryption and attribute-based encryption, and secret sharing is achieved using a linear secret sharing scheme (LSSS).
[0088] In a feasible implementation, the attributes and tasks of the encrypted data are differentiated, the tasks of the data sharing vehicle are distributed to adjacent idle vehicles, and keys are generated for the idle vehicles, including:
[0089] According to the following formula (2), the data sharing vehicle randomly selects the symmetric key ssk1:
[0090] SEncrypt(ssk1,D)→(SED) (2)
[0091] The SEncrypt function takes ssk1 and data D as input and outputs SED encrypted by the symmetric algorithm according to the following formula (3):
[0092]
[0093] Upload the SED to the edge server.
[0094] In a feasible implementation, attributes of data required for calculation are encrypted and the encrypted data is uploaded to the edge server, including:
[0095] According to the following formula (4), a LSSS(M,ρ) is generated for the access structure A, where M is a l×n matrix and ρ is a function that maps each row of M to an underlying attribute;
[0096] Randomly generate s,y2,y3,...,y n ∈Z p , where s is the shared secret, set a vector calculate Then randomly select r1,r2,...,r l ∈Z p , let ssk2 = ssk1; calculate,
[0097]
[0098] Constitute the ciphertext,
[0099] CT A =(C,C′,C1,...,C l ,l,(M,ρ)).
[0100] Data Sharing Vehicle Secret Preservation CT A and upload a copy to the edge server.
[0101] Among them, there are many parts of the ciphertext (a total of l groups, and l is not fixed), so it is difficult to name the letters of each part.
[0102] S103: The idle vehicle decrypts and obtains data using the key.
[0103] In a feasible implementation, the idle vehicle decrypts and obtains data using a key, including:
[0104] When an idle vehicle intends to obtain shared data, it sends a request to the edge server;
[0105] After receiving the request, the edge server sends the encrypted data and semi-plaintext to the idle vehicle; the edge server j The list records data that has been accessed by idle vehicle j.
[0106] In a feasible implementation, after receiving the request, the edge server sends the symmetrically encrypted data SED and the semi-plaintext SP to the idle vehicle, including:
[0107] Set, IDecript(vsk,SP,SED)→(D), then define a set If the attribute set of the free vehicle does not satisfy the access structure, it returns ⊥; otherwise, due to the construction of LSSS, it can find a constant ω i ∈Z p , so that ∑ i∈I ω i λ i =s; then the edge server calculates,
[0108]
[0109] Let SP = (C, TP), and the edge server sends the semi-plaintext SP and SED to the idle vehicles.
[0110] In a feasible implementation, when an idle vehicle intends to obtain shared data, it sends a request to the edge server. After receiving the request, the edge server sends back the encrypted data and the semi-plaintext. At the same time, the edge server j The list records data that has been accessed by idle vehicle j.
[0111] EDecrypt(Params,CT A ,OSK)→(SP): First define a set If the attribute set of the free vehicle does not satisfy the access structure, it returns ⊥. Otherwise, due to the construction of LSSS, it can find a constant ω i ∈Z p , so that ∑ i∈I ω i λ i =s. Then the edge server calculates,
[0112]
[0113] Let SP = (C, TP). Finally, the edge server sends SP and SED to the idle vehicles.
[0114] IDecript(vsk,SP,SED)→(D): Input the vsk, SP and SED of the idle vehicle, and calculate the function.
[0115]
[0116] If ssk1=ssk2, we have,
[0117]
[0118] otherwise,
[0119]
[0120] So far, the shared data D has been recovered. Figure 3 Describes all interactions between them.
[0121] In a feasible implementation, Figure 3 , which is a diagram of the key generation, encryption, and decryption process in an embodiment of the present invention.
[0122] In a feasible implementation manner, after step S103, the following steps are further included:
[0123] When the idle vehicle state changes to moving state, or the data sharing vehicle has left the base station range, the data sharing vehicle must cancel one or more idle vehicles;
[0124] The edge server receives a revocation command from a data sharing vehicle about an idle vehicle j. For each encrypted data touched by j, the edge server randomly selects β∈Z p , calculate SG = g β and passed to the data sharing vehicle.
[0125] In a feasible implementation, when the idle vehicle state changes to "moving" state, or the data sharing vehicle has left the base station range, the data sharing vehicle must revoke one or more idle vehicles. When it happens to an idle vehicle j, the edge server first checks the AccessList j , to find the files that the idle vehicle j has touched and the files that it has previously come from Then use the previous symmetric key ssk p Decrypt the double encrypted data and use the new symmetric key ssk n The data sharing tool then re-encrypts the CT A Finally, it rekeys the non-revoked idle vehicles.
[0126] EReEncrypt(ssk p ,SED)→(ssk n ,SED′): Once the edge server receives the revocation command from the data sharing vehicle about the idle vehicle j, for each encrypted data touched by j, the edge server randomly selects β∈Z p , calculate SG = g β And pass it to the data sharing vehicle. Let ssk n =H1(g aβ ), ensure ssk n ≠ssk p , the server processes as follows: If ssk1=ssk2,
[0127]
[0128] otherwise,
[0129]
[0130] Let SED = SED′, use ssk n replace SSK p .
[0131] IReEncrypt(ssk n ,CT A ,MSK)→(CT′ A ,z′ j ): After the data sharing vehicle receives SG from the edge server, the data sharing vehicle calculates a new symmetric key ssk n =H1(SG a ), and from the tuple Find ssk1 in . Then form T=ssk1||ssk n , and re-encrypt where z' is from Z p Randomly select from . The new ciphertext is,
[0132] CT′ A =(C,C′,(C′1,D1),...,(C′ l ,D l ),(M,ρ))
[0133] Set CT A =CT′ A , the data sharing vehicle saves it locally and sends a copy to the edge server. Then, it updates the key z′ of each idle vehicle except the revoked idle vehicle j =z j z′ and send it to them.
[0134] Finally, a proof of correctness is given, which states that IDecrypt(vsk,SP,SED)=D. The proof is as follows:
[0135]
[0136] Then get,
[0137]
[0138] Therefore, we get IDecrypt(vsk, SP, SED) = D, which proves its correctness.
[0139] Throughout this embodiment of the present invention, the malicious tool makes every effort to steal secret data or obtain data that was previously accessible but is now prohibited. The malicious vehicle's computing power is limited, but more powerful than that of an ordinary vehicle. This can be understood as a probabilistic polynomial-time Turing machine (PPT). It attempts to obtain shared data through illegal means (such as stealing data packets and performing impersonation attacks), which DH-CPABE prohibits.
[0140] The edge server provides powerful computing power to perform proxy decryption and huge storage space to save the encrypted shared data. Let the edge server be semi-honest, which means that the edge server will faithfully perform operations as required, but it will try to obtain the secret.
[0141] In an embodiment of the present invention, the shortcomings of the forward security of the existing Cipher Policy Attribute Based Encryption (CP-ABE) are fixed. The data sharing tool encrypts the data twice using a symmetric key, and the key is encrypted by CP-ABE. Once the computing tool or VOC is revoked, the storage service provider and the data sharing tool will re-encrypt the shared data and symmetric key. Due to the intermittent connection of the VOC, we transfer the function of the trusted authority (TA) to the data sharing vehicle, thereby eliminating the TA. That is, the generation of keys and parameters is performed by the data sharing tool, rather than by a third party that must be assumed to be completely secure. Compared with existing typical similar schemes, the DH-CPABE scheme has lower computational cost in encryption, proxy decryption, and decryption under the same conditions.
[0142] Figure 4 Schematic diagram of a vehicle opportunity calculation encryption system based on dual hybrid ciphertext strategy attributes of the present invention. The system 200 is used for the vehicle opportunity calculation encryption based on dual hybrid ciphertext strategy attributes. The system 200 includes:
[0143] an initialization module 210 for initializing the data sharing vehicle system and constructing an opportunistic network including idle vehicles with the assistance of the base station;
[0144] The encryption module 220 is used to encrypt the data required for calculation and upload the encrypted data to the edge server; distinguish the attributes and tasks of the encrypted data, distribute the tasks of the data sharing vehicle to adjacent idle vehicles, and generate keys for the idle vehicles;
[0145] The decryption module 230 is used for the idle vehicle to decrypt and obtain data using the key.
[0146] Preferably, the initialization module 210 is used to initialize the data sharing vehicle system and generate public parameters and a master key for each data D to be encrypted through the data sharing vehicle, including:
[0147] According to the following formula (1), the data sharing vehicle selects the system security parameter k as the function input to generate a group G1 with a prime order of p, and g is the generating element of G1:
[0148] Iinit(κ)→(MSK,Params) (1)
[0149] The data sharing tool randomly selects h1,...,h ∣U∣ ∈G1 and α,a∈Z p . It generates the mapping function M1: {0,1} * →G2; where U represents a set of common attributes; |U| is the size of the set;
[0150] Generate mapping function M1: {0,1} * →G2,M2:G2→{0,1} * and a hash function H1:G1→{0,1} * ; Where M2 is the inverse function of M1;
[0151] parameter Where MSK = g α A master key kept secret for data sharing vehicles.
[0152] Preferably, the initialization module 210 is further configured for the data sharing vehicle to generate an outsourcing key and a secret key corresponding to the idle vehicle and its attribute set.
[0153] Preferably, the encryption module 220 is used to perform data symmetrical encryption on the data required for calculation and upload the encrypted data to the edge server;
[0154] Encrypt the attributes of the data required for calculation and upload the encrypted data to the edge server.
[0155] Preferably, the encryption module 220 is used to
[0156] According to the following formula (2), the data sharing vehicle randomly selects the symmetric key ssk1:
[0157] SEncrypt(ssk1,D)→(SED) (2)
[0158] The SEncrypt function takes ssk1 and data D as input and outputs SED encrypted by the symmetric algorithm according to the following formula (3):
[0159]
[0160] Upload the SED to the edge server.
[0161] Preferably, the encryption module 220 is configured to generate a LSSS(M,ρ) for the access structure A according to the following formula (4), where M is an l×n matrix and ρ is a function that maps each row of M to an underlying attribute;
[0162] Randomly generate s,y2,y3,...,y n ∈Z p , where s is the shared secret, set a vector calculate Then randomly select r1,r2,...,r l ∈Z p , let ssk2 = ssk1; calculate,
[0163]
[0164] Constitute the ciphertext,
[0165] CT A =(C,C′,C1,...,C l ,l,(M,ρ)).
[0166] Data Sharing Vehicle Secret Preservation CT A and upload a copy to the edge server.
[0167] Preferably, the decryption module 230 is configured to send a request to the edge server when the idle vehicle intends to obtain shared data;
[0168] After receiving the request, the edge server sends the encrypted data and semi-plaintext to the idle vehicle; the edge server j The list records data that has been accessed by idle vehicle j.
[0169] Preferably, the decryption module 230 is used to set IDecript(vsk,SP,SED)→(D), then define a set If the attribute set of the free vehicle does not satisfy the access structure, it returns ⊥; otherwise, due to the construction of LSSS, it can find a constant ω i ∈Z p , so that ∑ i∈I ω i λ i =s; then the edge server calculates,
[0170]
[0171] Let SP = (C, TP), and the edge server sends the semi-plaintext SP and SED to the idle vehicles.
[0172] Preferably, the system further comprises a revocation module for:
[0173] When the idle vehicle state changes to moving state, or the data sharing vehicle has left the base station range, the data sharing vehicle must cancel one or more idle vehicles;
[0174] The edge server receives a revocation command from a data sharing vehicle about an idle vehicle j. For each encrypted data touched by j, the edge server randomly selects β∈Z p , calculate SG = g β and passed to the data sharing vehicle.
[0175] In the embodiments of the present invention, the shortcomings of the forward security of the existing Cipher Policy Attribute Based Encryption (CP-ABE) are fixed. The data sharing tool encrypts the data twice using a symmetric key, and the secret is encrypted by CP-ABE. Once the computing tool or VOC is revoked, the storage service provider and the data sharing tool will re-encrypt the shared data and the symmetric key. Due to the intermittent connection of the VOC, we transfer the function of the trusted authority (TA) to the data sharing vehicle, thereby eliminating the TA. That is, the generation of keys and parameters is performed by the data sharing tool, rather than by a third party that must be assumed to be completely secure. Compared with existing typical similar schemes, the DH-CPABE scheme has lower computational cost in encryption, proxy decryption, and decryption under the same conditions.
[0176] Figure 5 3 is a schematic diagram of the structure of an electronic device 300 provided in an embodiment of the present invention. The electronic device 300 may have relatively large differences due to different configurations or performances, and may include one or more processors (central processing units, CPUs) 301 and one or more memories 302, wherein the memories 302 store at least one instruction, and the at least one instruction is loaded and executed by the processor 301 to implement the following steps of the method for labeling virtual scene data:
[0177] S1: Initialize the data sharing vehicle system and build an opportunistic network containing idle vehicles with the assistance of the base station;
[0178] S2: Encrypt the data required for calculation and upload the encrypted data to the edge server; distinguish the attributes and tasks of the encrypted data, distribute the tasks of the data sharing vehicle to adjacent idle vehicles, and generate keys for the idle vehicles;
[0179] S3: The idle vehicle decrypts and obtains data using the key.
[0180] In an exemplary embodiment, a computer-readable storage medium, such as a memory device, is also provided. The instructions are executable by a processor in a terminal to implement the vehicle opportunistic computation encryption method based on dual hybrid ciphertext strategy attributes. For example, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, or optical data storage device.
[0181] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.
Claims
1. A vehicle opportunity computing encryption method based on dual hybrid ciphertext strategy attributes, characterized in that: The steps include: S1: Initialize the data sharing vehicle system and generate public parameters and master keys for each data D that needs to be encrypted; Initialize the data sharing vehicle system and generate public parameters and master keys for each data D that needs to be encrypted through the data sharing vehicle, including: The system is initialized according to the following formula (1), and the data sharing vehicle selection system security parameter k is used as the function input to generate a group G1 with a prime order of p. g is the generator of G1: linit(κ)→(MSK,Params) (1) Among them, MSK represents the master key, Params represents the system parameters; the data sharing vehicle selects the random number and in, Represents a set of global attributes of a vehicle; is the size of the set; Generate mapping function Mapping Function and a hash function Among them, M2 is the inverse function of M1; the generated parameters Where the master key MSK = g α Secretly saved by the data sharing vehicle, é is a bilinear operation, and H1 is a hash algorithm; S2: Encrypt the data D required for calculation by the data sharing vehicle and upload the encrypted data to the edge server; use the linear secret sharing scheme LSSS to share data between the data sharing vehicle and adjacent idle vehicles, and generate a key for the idle vehicle; S3: The idle vehicle decrypts and obtains data using the key, completing vehicle opportunistic computation encryption based on dual hybrid ciphertext strategy attributes.
2. The method according to claim 1, characterized in that The step S1 further includes: The data sharing vehicle generates an outsourcing key and a secret key corresponding to an idle vehicle attribute set for the idle vehicle.
3. The method according to claim 2, characterized in that In step S2, the data D required for data sharing vehicle calculation is encrypted and the encrypted data is uploaded to the edge server, including: Symmetrically encrypt the data required for calculation and upload the encrypted data to the edge server; Encrypt the attributes of the data required for calculation and upload the encrypted data to the edge server.
4. The method according to claim 3, characterized in that The step of symmetrically encrypting the data required for the calculation and uploading the encrypted data to the edge server includes: According to the following formula (2), the data sharing vehicle randomly selects the symmetric key SEncrypt(ssk1,D)→(SED) (2) The SEncrypt function takes the data symmetric key 1ssk1 and data D as input and outputs the symmetric encrypted data SED encrypted by the symmetric algorithm En according to the following formula (3): Upload the symmetrically encrypted data SED to the edge server.
5. The method according to claim 4, characterized in that Encrypt the attributes of the data required for calculation and upload the encrypted data to the edge server, including: According to the following formula (4), the access structure Generate a LSSS(M,ρ), where M is a l×n access structure matrix and ρ is a function that maps each row of M to an underlying attribute; Randomly generate s,y2,y3,..., Where s is the shared secret, set a vector Computing Sharing Select random numbers r1, r2, ..., Let the symmetric key 2ssk2 = ssk1; calculate the ciphertext according to the following formula (4): The ciphertext of the following formula (5) Data sharing vehicle secret storage ciphertext And upload a copy to the edge server.
6. The method according to claim 5, characterized in that In step S3, the idle vehicle decrypts and obtains data using the key, including: When an idle vehicle needs to obtain shared data, the idle vehicle sends a request to the edge server; After the edge server receives the request, the edge server sends the encrypted data SED and the semi-plaintext SP to the idle vehicle; the edge server enters the access list AccessList of the idle vehicle j. j The data recorded in is accessed by idle vehicle j.
7. The method according to claim 6, characterized in that After receiving the request, the edge server sends the symmetrically encrypted data SED and the semi-plaintext SP to the idle vehicle, including: Set, IDecript(vsk,SP,SED)→(D), then define a set S represents the vehicle attribute set; if the attribute set of the idle vehicle does not satisfy the access structure, the decryption fails; otherwise, due to the construction of the linear secret sharing scheme LSSS, a constant is found So that ∑ i∈I ω i λ i =s; the edge server calculates the semi-plaintext, Let SP = (C, TP), and the edge server sends the semi-plaintext SP and SED to the idle vehicles.
8. The method according to claim 1, characterized in that After step S3, the following steps are also included: When the idle vehicle state changes to moving state, or the data sharing vehicle has left the base station range, the data sharing vehicle must cancel one or more idle vehicles; The edge server receives the revocation command from the data sharing vehicle about the idle vehicle j. For each encrypted data touched by the idle vehicle j, the edge server generates a random number Calculate the key seed SG = g β and passed to the data sharing vehicle.
9. A vehicle opportunistic computing encryption system based on dual hybrid ciphertext strategy attributes, characterized in that: The system is used for the vehicle opportunity calculation encryption method based on dual hybrid ciphertext strategy attributes according to any one of claims 1 to 8, and the system includes: Initialization module, used to initialize the data sharing vehicle system and generate public parameters and master keys for each data D that needs to be encrypted; An encryption module is used to encrypt the data D required for calculation by the data sharing vehicle and upload the encrypted data to the edge server; the data sharing vehicle shares data with adjacent idle vehicles through the linear secret sharing scheme LSSS, and a key is generated for the idle vehicle; The decryption module is used for the idle vehicle to decrypt and obtain data through the key, and complete the vehicle opportunity calculation encryption based on the dual hybrid ciphertext strategy attribute.