Data aggregation authentication encryption method, device and equipment and computer storage medium

CN116436603BActive Publication Date: 2026-09-18CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310516350.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-09
Publication Date
2026-09-18
Estimated Expiration
2043-05-09

AI Technical Summary

Technical Problem

但是,聚合签名仅能保证数据的完整性和真实性,无法同时实现数据的机密性,适用性差

Benefits of technology

[0101]This disclosure provides a data aggregation authentication encryption method applied to a target participant in an encryption authentication process. The method involves: obtaining the target message to be encrypted transmitted by the encryption aggregator; obtaining elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function; generating a first random number for the target participant based on the order; encrypting the first random number based on the base point to obtain an encrypted random number for the target participant; transmitting the encrypted random number to other participants in the encryption authentication process; obtaining encrypted random numbers from other participants; and obtaining the public key of the message receiver, based on the message... The receiving party's public key and the target random number of the target participant generate the first value of the target participant, and transmit the first value of the target participant to other participants; obtain the first values ​​of other participants, and obtain the aggregation key generated with other participants; encrypt and authenticate the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order value, and the private key of the target participant, to obtain the encrypted authentication fragment of the target participant; transmit the encrypted authentication fragment of the target participant to the encryption aggregator, so that the encryption aggregator can generate the aggregated ciphertext of the target message based on all the encrypted authentication fragments. In this disclosure, the target participant, with the help of elliptic curve parameters, generates each encrypted authentication fragment of the target message together with other participants in the encryption authentication participants, thereby enabling the encryption aggregator to generate the aggregated ciphertext of the target message based on all the encrypted authentication fragments, which can simultaneously satisfy confidentiality and integrity, and has good applicability. The data aggregation authentication encryption device, electronic device, and computer-readable storage medium provided in this disclosure also solve the corresponding technical problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116436603B_ABST
    Figure CN116436603B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data aggregation authentication encryption method and device, equipment and computer storage medium, which is applied to a target participant in an encryption authentication participant, obtains a target message and elliptic curve parameters, generates an encryption random number of the target participant based on an order value and a base point, obtains encryption random numbers of other participants, generates a first value of the target participant based on a public key of a message receiver and a target random number of the target participant, obtains first values of other participants and an aggregation key, encrypts and authenticates the target message based on all encryption random numbers, a first hash function, all first values, the aggregation key, a signature hash function, an order value and a private key of the target participant, obtains an encryption authentication segment of the target participant, and transmits the encryption authentication segment of the target participant to an encryption aggregation party. The present disclosure can simultaneously meet confidentiality and integrity, and has good applicability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of information security technology, and more specifically, to data aggregation authentication encryption methods, apparatus, devices, and computer storage media. Background Technology

[0002] In order to ensure data security during data transmission and storage, data can be authenticated and encrypted. Publicly verifiable authentication and encryption can separate the verification and decryption operations and support public verification of ciphertext.

[0003] Most existing schemes for public verifiability simply combine the ElGamal and Schnorr signature schemes, reducing the confidentiality of the scheme to the security of the ElGamal scheme. However, this simple combination cannot resist known-plaintext attacks; that is, the scheme does not achieve CPA (Chosen-Plaintext Attack) security. Furthermore, Ma Changshe and Chen Kefei proposed a secure, publicly verifiable authentication encryption scheme in 2003, but to achieve public verifiability, the ciphertext needs to be specially transformed, and this scheme has also been pointed out to have flaws, namely, the verifier can reject a valid signature with a non-negligible probability. Moreover, the above schemes only consider the case where the plaintext is encrypted and authenticated by a single party, and do not implement multi-party encryption authentication. Furthermore, a common existing approach is aggregate signatures (or multi-signatures), where multiple participants jointly generate an aggregate signature for the same plaintext. However, aggregate signatures can only guarantee data integrity and authenticity, but cannot simultaneously achieve data confidentiality, resulting in poor applicability.

[0004] In summary, how to provide a data aggregation authentication encryption method with good applicability is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0005] The purpose of this disclosure is to provide a data aggregation authentication encryption method with good applicability. This disclosure also provides a data aggregation authentication encryption device, an electronic device, and a computer-readable storage medium.

[0006] To achieve the above objectives, this disclosure provides the following technical solution:

[0007] According to a first aspect of the present disclosure, a data aggregation authentication encryption method is provided, applied to a target participant in the encryption authentication process, comprising:

[0008] Obtain the target message to be encrypted transmitted by the encryption aggregator;

[0009] Obtain elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function;

[0010] A first random number for the target participant is generated based on the order value. The first random number for the target participant is then encrypted based on the base point to obtain an encrypted random number for the target participant. The encrypted random number for the target participant is then transmitted to the other participants in the encryption authentication participants.

[0011] Obtain the encrypted random number from the other participants;

[0012] Obtain the message recipient's public key, generate a first value for the target participant based on the message recipient's public key and the target random number of the target participant, and transmit the first value of the target participant to the other participants;

[0013] Obtain the first value from the other participants, and obtain the aggregation key generated with the other participants;

[0014] The target message is encrypted and authenticated based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the private key of the target participant to obtain the encrypted authentication fragment of the target participant;

[0015] The encrypted authentication fragments of the target participant are transmitted to the encrypted aggregator, so that the encrypted aggregator generates an aggregated ciphertext of the target message based on all the encrypted authentication fragments.

[0016] Preferably, the elliptic curve parameters include an aggregate hash function;

[0017] Generating the aggregation key with the other participants includes:

[0018] Generate the private key of the target participant based on the order value;

[0019] The target participant's private key is encrypted based on the stated base point to obtain the target participant's public key;

[0020] Obtain the public keys of the other participating parties and use all of the public keys as a set of verification keys;

[0021] Generate a key fragment for the target participant based on the public key of the target participant, the set of verification keys, and the aggregate hash function;

[0022] Obtain the key fragments from the other participating parties;

[0023] The aggregate key is generated based on all the key fragments and all the public keys.

[0024] Preferably, generating the key fragment of the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function includes:

[0025] The key fragment of the target participant is generated based on the public key of the target participant, the verification key set, and the aggregate hash function using the key fragment operation formula.

[0026] The key fragment operation formula includes:

[0027]

[0028] Among them, a j The key fragment representing the target participant; H agg T represents the aggregate hash function; T represents the set of verification keys; The public key of the target participant is represented by ||; concatenation is indicated by ||.

[0029] The process of generating the aggregate key based on all the key fragments and all the public keys includes:

[0030] The aggregated key is generated based on all the key fragments and all the public keys using the aggregated key operation formula.

[0031] The aggregation key operation formula includes:

[0032]

[0033] Among them, pk agg The aggregate key is represented by t; t represents the total number of participants in the cryptographic authentication process. a represents the public key of the i-th participant in the encryption authentication process; i This represents the key fragment of the i-th participant in the encryption authentication process.

[0034] Preferably, the elliptic curve parameters include a second hash function;

[0035] The generation of the first random number for the target participant based on the order value includes:

[0036] Select a random number r j ∈[1,n-1] is used as the first random number for the target participant, where n represents the order value;

[0037] The transmission of the encrypted random number from the target participant to the other participants in the encryption authentication participants includes:

[0038] The second numerical value of the target participant is obtained by encrypting the encrypted random number of the target participant using the second numerical calculation formula and based on the second hash function.

[0039] The second numerical calculation formula includes:

[0040] b j =H com (R j ), R j =[r j G;

[0041] Among them, b j H represents the second numerical value of the target participant; com R represents the second hash function; j The encrypted random number represents the target participant; G represents the base point;

[0042] The second value of the target participant and the encrypted random number of the target participant are transmitted to the other participants, so that the other participants can verify b. j =H com (R j If correct, receive the second value from the target participant.

[0043] Preferably, the step of generating the first value of the target participant based on the message receiver's public key and the target participant's target random number includes:

[0044] The first numerical value of the target participant is generated based on the public key of the message recipient and the target random number of the target participant using the first numerical calculation formula.

[0045] The first numerical calculation formula includes:

[0046] Q j =[r j ]P R ;

[0047] Among them, Q j P represents the first numerical value of the target participant; R This refers to the public key of the message recipient.

[0048] Preferably, the step of encrypting and authenticating the target message based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the target participant's private key to obtain the target participant's encrypted authentication fragment includes:

[0049] By using the encrypted authentication fragment formula, the target message is encrypted and authenticated based on all the encrypted random numbers, the first hash function, all the first values, the aggregate key, the signature hash function, the order value, and the private key of the target participant, to obtain the encrypted authentication fragment of the target participant;

[0050] The encryption authentication fragment formula includes:

[0051] P = R + H(m);

[0052] e = H sig (pk agg ||R||Z);s j =(r j -ea j d j )mod n;

[0053] Among them, R, P, Z, s j The encrypted authentication fragment representing the target participant; R i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the encrypted random number of the ith participant in the encryption authentication process. i H represents the first value of the i-th participant in the encryption authentication process; sig Represents the signature hash function; d j This represents the private key of the target participant; mod represents the modulo operation; P m This indicates that the target message is encoded as the value of a point on an elliptic curve.

[0054] According to a second aspect of the present disclosure, a data aggregation authentication encryption method is provided, applied to an encryption aggregator, comprising:

[0055] Obtain the elliptic curve parameters, including the order value of the base point;

[0056] Retrieve the target message to be encrypted;

[0057] The target message is transmitted to each participating party in the encryption authentication process;

[0058] Receive encrypted authentication fragments transmitted by each of the encrypted authentication participants;

[0059] The aggregated ciphertext of the target message is generated based on the order value and all the encrypted authentication fragments;

[0060] The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function. Based on the order, a first random number is generated for the target participant. This first random number is then encrypted based on the base point to obtain an encrypted random number for the target participant, which is then transmitted to the other participants in the encryption authentication process. The encrypted random numbers of the other participants are then acquired. The public key of the message receiver is acquired, and a first value for the target participant is generated based on the message receiver's public key and the target random number. This first value is then transmitted to the other participants. The first value of the other participants is acquired, and an aggregation key generated with the other participants is also acquired. Finally, the target message is encrypted and authenticated based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order, and the private key of the target participant, resulting in the encrypted authentication fragment of the target participant.

[0061] Preferably, generating the aggregated ciphertext of the target message based on the order value and all the encrypted authentication fragments includes:

[0062] The aggregated ciphertext of the target message is generated based on the order value and all the encrypted authentication fragments using the aggregated ciphertext operation formula.

[0063] The aggregated ciphertext operation formula includes:

[0064] s i =(r i -ea i d i )mod n; e = H sig (pk agg ||R||Z);

[0065]

[0066] Wherein, R, P, Z, and s represent the aggregated ciphertext; R, P, Z, and s i R represents the encrypted authentication fragment of the i-th participant in the encrypted authentication process; i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the encrypted random number of the ith participant in the encryption authentication process. i =[r i ]P R Q iP represents the first value of the i-th participant in the encryption authentication process; R H represents the public key of the message recipient; sig Represents the signature hash function; d i r represents the private key of the i-th participant in the encryption authentication process; i The first random number represents the i-th participant in the encryption authentication process; a i H represents the key fragment of the i-th participant in the encryption authentication process; agg T represents the aggregate hash function; T represents the set of verification keys composed of the public keys of the participating parties in the encryption authentication. H represents the public key of the i-th participant in the encryption authentication process; || represents concatenation; mod represents modulo operation; H sig This refers to the signature hash function; pk agg P represents the aggregation key; m This indicates that the target message is encoded as the value of a point on an elliptic curve.

[0067] According to a third aspect of the present disclosure, a data aggregation authentication encryption method is provided, applied to a verification party, comprising:

[0068] Obtain the aggregated ciphertext of the target message transmitted by the encrypted aggregator;

[0069] Obtain the aggregated key generated by the participants in the encryption authentication process;

[0070] Obtain the elliptic curve parameters, which include the base point and the signature hash function;

[0071] The aggregated ciphertext is verified based on the base point, the signature hash function, and the aggregation key to obtain the verification result;

[0072] The encryption aggregator obtains elliptic curve parameters, including the order value of the base point; obtains the target message to be encrypted; transmits the target message to each encryption authentication participant; receives encryption authentication fragments transmitted by each encryption authentication participant; and generates the aggregated ciphertext of the target message based on the order value and all the encryption authentication fragments.

[0073] The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function. Based on the order, a first random number is generated for the target participant. This first random number is then encrypted based on the base point to obtain an encrypted random number for the target participant, which is then transmitted to the other participants in the encryption authentication process. The encrypted random numbers of the other participants are then acquired. The public key of the message receiver is acquired, and a first value for the target participant is generated based on the message receiver's public key and the target random number. This first value is then transmitted to the other participants. The first value of the other participants is acquired, and an aggregation key generated with the other participants is also acquired. Finally, the target message is encrypted and authenticated based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order, and the private key of the target participant, resulting in the encrypted authentication fragment of the target participant.

[0074] Preferably, the verification of the aggregated ciphertext based on the base point, the signature hash function, and the aggregation key to obtain the verification result includes:

[0075] Based on the aggregated ciphertext, a verification hash value e' = H is generated. sig (pk agg ||R||Z);

[0076] Verify R = s[G] + e'[pk] agg If the condition is true, the verification result indicating that the aggregated ciphertext is correct is obtained; if the condition is false, the verification result indicating that the aggregated ciphertext is incorrect is obtained.

[0077] Wherein, R, P, Z, and s represent the aggregated ciphertext; R, P, Z, and s i R represents the encrypted authentication fragment of the i-th participant in the encrypted authentication process; i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the encrypted random number of the ith participant in the encryption authentication process. i =[r i ]P R Q i P represents the first value of the i-th participant in the encryption authentication process; R H represents the public key of the message recipient; sig Represents the signature hash function; d i r represents the private key of the i-th participant in the encryption authentication process;i The first random number represents the i-th participant in the encryption authentication process; a i H represents the key fragment of the i-th participant in the encryption authentication process; agg T represents the aggregate hash function; T represents the set of verification keys composed of the public keys of the participating parties in the encryption authentication. H represents the public key of the i-th participant in the encryption authentication process; || represents concatenation; mod represents modulo operation; H sig This refers to the signature hash function; pk agg This refers to the aggregation key.

[0078] According to a fourth aspect of the present disclosure, a data aggregation authentication encryption method is provided, applied to a message receiver, comprising:

[0079] Obtain the aggregated ciphertext of the target message;

[0080] The aggregated ciphertext is decrypted using the private key of the message recipient to obtain the target message;

[0081] The encryption aggregator obtains elliptic curve parameters, including the order value of the base point; obtains the target message to be encrypted; transmits the target message to each encryption authentication participant; receives encryption authentication fragments transmitted by each encryption authentication participant; and generates the aggregated ciphertext of the target message based on the order value and all the encryption authentication fragments.

[0082] The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function. Based on the order, a first random number is generated for the target participant. This first random number is then encrypted based on the base point to obtain an encrypted random number for the target participant, which is then transmitted to the other participants in the encryption authentication process. The encrypted random numbers of the other participants are then acquired. The public key of the message receiver is acquired, and a first value for the target participant is generated based on the message receiver's public key and the target random number. This first value is then transmitted to the other participants. The first value of the other participants is acquired, and an aggregation key generated with the other participants is also acquired. Finally, the target message is encrypted and authenticated based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order, and the private key of the target participant, resulting in the encrypted authentication fragment of the target participant.

[0083] Preferably, the step of decrypting the aggregated ciphertext based on the message recipient's private key to obtain the target message includes:

[0084] Based on the message recipient's private key and the aggregated ciphertext, a third numerical value P is generated. m '=Z-[d R ]R;

[0085] The verification message is obtained by decoding the third numerical value;

[0086] Verify whether P = R + H(m') is true. If it is true, then use the verification message as the target message.

[0087] Where m' represents the verification message; R, P, Z, and s represent the aggregated ciphertext; R, P, Z, and s i R represents the encrypted authentication fragment of the i-th participant in the encrypted authentication process; i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the encrypted random number of the ith participant in the encryption authentication process. i =[r i ]P R Q i P represents the first value of the i-th participant in the encryption authentication process; R H represents the public key of the message recipient; sig Represents the signature hash function; d i r represents the private key of the i-th participant in the encryption authentication process; i The first random number represents the i-th participant in the encryption authentication process; a i H represents the key fragment of the i-th participant in the encryption authentication process; agg T represents the aggregate hash function; T represents the set of verification keys composed of the public keys of the participating parties in the encryption authentication. H represents the public key of the i-th participant in the encryption authentication process; || represents concatenation; mod represents modulo operation; H sig This refers to the signature hash function; pk agg This refers to the aggregation key.

[0088] According to a fifth aspect of the present disclosure, a data aggregation authentication encryption device is provided, applied to a target participant in an encryption authentication participant, comprising:

[0089] The first acquisition module is used to acquire the target message to be encrypted transmitted by the encryption aggregator;

[0090] The second acquisition module is used to acquire elliptic curve parameters, which include a base point, the order of the base point, a first hash function, and a signature hash function.

[0091] The first generation module is used to generate a first random number for the target participant based on the order value, encrypt the first random number for the target participant based on the base point to obtain an encrypted random number for the target participant, and transmit the encrypted random number for the target participant to other participants in the encryption authentication participants.

[0092] The third acquisition module is used to acquire the encrypted random number from the other participants;

[0093] The fourth acquisition module is used to acquire the public key of the message recipient, generate a first value of the target participant based on the public key of the message recipient and the target random number of the target participant, and transmit the first value of the target participant to the other participants.

[0094] The fifth acquisition module is used to acquire the first value of the other participants and to acquire the aggregation key generated with the other participants;

[0095] The first authentication module is used to perform encrypted authentication on the target message based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the private key of the target participant, to obtain the encrypted authentication fragment of the target participant;

[0096] The first transmission module is used to transmit the encrypted authentication fragment of the target participant to the encrypted aggregator, so that the encrypted aggregator generates the aggregated ciphertext of the target message based on all the encrypted authentication fragments.

[0097] According to a sixth aspect of the present disclosure, an electronic device is provided, comprising:

[0098] Memory, used to store computer programs;

[0099] A processor for executing the computer program in the memory to implement the steps of any of the methods described above.

[0100] According to a seventh aspect of the present disclosure, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the methods described above.

[0101] This disclosure provides a data aggregation authentication encryption method applied to a target participant in an encryption authentication process. The method involves: obtaining the target message to be encrypted transmitted by the encryption aggregator; obtaining elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function; generating a first random number for the target participant based on the order; encrypting the first random number based on the base point to obtain an encrypted random number for the target participant; transmitting the encrypted random number to other participants in the encryption authentication process; obtaining encrypted random numbers from other participants; and obtaining the public key of the message receiver, based on the message... The receiving party's public key and the target random number of the target participant generate the first value of the target participant, and transmit the first value of the target participant to other participants; obtain the first values ​​of other participants, and obtain the aggregation key generated with other participants; encrypt and authenticate the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order value, and the private key of the target participant, to obtain the encrypted authentication fragment of the target participant; transmit the encrypted authentication fragment of the target participant to the encryption aggregator, so that the encryption aggregator can generate the aggregated ciphertext of the target message based on all the encrypted authentication fragments. In this disclosure, the target participant, with the help of elliptic curve parameters, generates each encrypted authentication fragment of the target message together with other participants in the encryption authentication participants, thereby enabling the encryption aggregator to generate the aggregated ciphertext of the target message based on all the encrypted authentication fragments, which can simultaneously satisfy confidentiality and integrity, and has good applicability. The data aggregation authentication encryption device, electronic device, and computer-readable storage medium provided in this disclosure also solve the corresponding technical problems.

[0102] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit this disclosure. Attached Figure Description

[0103] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0104] Figure 1 This is a flowchart illustrating a data aggregation authentication encryption method according to an exemplary embodiment;

[0105] Figure 2 This is an interactive schematic diagram illustrating a data aggregation authentication encryption method according to an exemplary embodiment;

[0106] Figure 3This is a schematic diagram illustrating the structure of a data aggregation authentication encryption device according to an exemplary embodiment;

[0107] Figure 4 This is a block diagram illustrating an electronic device 900 according to an exemplary embodiment. Detailed Implementation

[0108] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this disclosure.

[0109] Please see Figure 1 and Figure 2 , Figure 1 This is a flowchart illustrating a data aggregation authentication encryption method according to an exemplary embodiment. Figure 2 This is an interactive schematic diagram illustrating a data aggregation authentication encryption method according to an exemplary embodiment.

[0110] This disclosure relates to a data aggregation authentication encryption method, applied to a target participant in an encryption authentication process, and may include the following steps:

[0111] Step S101: Obtain the target message to be encrypted transmitted by the encryption aggregator.

[0112] Understandably, the message type of the target message to be encrypted can be determined based on the application scenario. For example, the target message could be audio data during audio transmission.

[0113] It should be noted that the number of participants in the encryption authentication process can be determined according to the application scenario, and the target participant in this disclosure refers to any one of the encryption authentication participants; in addition, the encryption aggregator can be the holder of the target message, etc., and this disclosure does not make specific limitations here.

[0114] Step S102: Obtain the elliptic curve parameters, which include the base point, the order of the base point, the first hash function, and the signature hash function.

[0115] It is understandable that during the process of aggregating, authenticating, and encrypting the target message, the target participant needs to obtain elliptic curve parameters, which may include the base point, the order of the base point, the first hash function, the signature hash function, etc.

[0116] It should be noted that in application scenarios, the elliptic curve parameters can be generated by a trusted third party, TTP. For example, the trusted third party can select a prime number p > 3, etc., to determine F.p F p Let E be a finite field with p elements; let E be F p An elliptic curve on the x-axis is denoted as E(F). p ):y 2 =x 3 +ax+b(a,b∈F p ), where a and b satisfy 4a 3 +27b 2 ≠0 (mod p); Let the base point of the elliptic curve be G = (x G ,y G )∈E(F p ), G≠O, the order of G is n; choose hash function H, H sig H com H agg Wherein, the image set of the first hash function H is the points on the elliptic curve, and the signature hash function H... sig The second hash function H com Aggregate hash function H agg If the image set is [1, n-1], then the parameters of the elliptic curve generated by the trusted third party can be:

[0117] pp=(p,E,G,n,H,H sig H com H agg ).

[0118] Step S103: Generate a first random number for the target participant based on the order value, encrypt the first random number for the target participant based on the base point to obtain an encrypted random number for the target participant, and transmit the encrypted random number for the target participant to other participants in the encryption authentication participants.

[0119] Step S104: Obtain encrypted random numbers from other participants.

[0120] Understandably, after obtaining the elliptic curve parameters, the target participant can generate a first random number based on the order value, encrypt the first random number based on the base point to obtain the encrypted random number, and transmit the encrypted random number to other participants in the encryption authentication participants to obtain the encrypted random numbers of the other participants in order to process all the encrypted random numbers.

[0121] It should be noted that the process by which other participants generate their own encrypted random numbers is the same as the process by which the target participant generates its own encrypted random number. Both generate their own first random number based on the order value, and then encrypt their own first random number based on the base point to obtain the target participant's encrypted random number.

[0122] Understandably, the elliptic curve parameters can include a second hash function; correspondingly, in the process of generating the first random number for the target participant based on the order value, the target participant can select a random number r. j ∈[1,n-1] is used as the first random number of the target participant, where n represents the order value; during the transmission of the encrypted random number of the target participant to other participants in the encryption authentication participants, the encrypted random number of the target participant can be encrypted using the second numerical calculation formula based on the second hash function to obtain the second numerical value of the target participant.

[0123] The second numerical calculation formula includes:

[0124] b j =H com (R j ), R j =[r j G;

[0125] Among them, b j H represents the second numerical value of the target participant. com Represents the second hash function; R j G represents the target participant's encrypted random number; G represents the base point; the target participant's second value and the target participant's encrypted random number are transmitted to other participants so that the other participants can verify b. j =H com (R j After the result is correct, the second value from the target participant is received. This allows the target participant to securely transmit its second value to other participants using the second hash function. It's easy to understand that other participants can also securely transmit their second values ​​to the target participant using the second hash function. That is, for j∈[1,t], S j Select a random number r j ∈[1,n-1], calculate R j =[r j G,b j =H com (R j ), b j Send to all other participants; for j∈[1,t], S j Received b from all other participants i After (i≠j), R j Send to other participants; for j∈[1,t], S j Received R from all other participants i After (i≠j), verify b. i =H com (R i If the condition is met, then the other participants' b has been correctly received. iIf the condition is met, the encryption process can be terminated.

[0126] Step S105: Obtain the message receiver's public key, generate the target participant's first value based on the message receiver's public key and the target participant's target random number, and transmit the target participant's first value to other participants.

[0127] Step S106: Obtain the first value from other participants and obtain the aggregation key generated with other participants.

[0128] Step S107: Based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the private key of the target participant, perform encrypted authentication on the target message to obtain the encrypted authentication fragment of the target participant.

[0129] Understandably, after obtaining the encrypted random numbers from other participants, the target participant can obtain the message receiver's public key, generate the target participant's first value based on the message receiver's public key and the target participant's target random number, and transmit the target participant's first value to other participants, obtain the other participants' first values, and obtain the aggregation key generated with other participants. Based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the target participant's private key, the target message is encrypted and authenticated to obtain the target participant's encrypted authentication fragment.

[0130] It is understandable that any party involved in the encryption authentication process and the message receiver can generate their own public and private key pairs according to the public and private key generation method, which is as follows:

[0131] Randomly select d∈[1,n-1]; calculate P=[d]G; use (d,P) as a public-private key pair, where the private key is d and the public key is P.

[0132] Understandably, the elliptic curve parameters include the aggregate hash function; correspondingly, in the process of generating an aggregate key with other participants, the target participant can generate its private key based on the order value; encrypt the target participant's private key based on the base point to obtain the target participant's public key; obtain the public keys of other participants and use all public keys as a verification key set; generate the target participant's key fragment based on the target participant's public key, the verification key set, and the aggregate hash function; obtain the key fragments of other participants; and generate the aggregate key based on all key fragments and all public keys.

[0133] In the process of generating the target participant's key fragment based on the target participant's public key, verification key set, and aggregate hash function, the target participant can generate the target participant's key fragment based on the target participant's public key, verification key set, and aggregate hash function through the key fragment operation formula.

[0134] Key fragment operation formulas include:

[0135]

[0136] Among them, a j Represents the key fragment of the target participant; H agg T represents the aggregate hash function; T represents the set of verification keys. Represents the public key of the target participant; || indicates concatenation;

[0137] In the process of generating an aggregate key based on all key fragments and all public keys, the target participant can use the aggregate key operation formula to generate an aggregate key based on all key fragments and all public keys;

[0138] The aggregation key operation formula includes:

[0139]

[0140] Among them, pk agg The aggregate key is represented by t; t represents the total number of participants in the cryptographic authentication process. a represents the public key of the i-th participant in the cryptographic authentication process; i This represents the key fragment of the i-th participant in the cryptographic authentication process.

[0141] In other words, during the generation of the aggregate key, each participant in the cryptographic authentication process can input their own verification key. j∈[1,t], where, Indicates participant S j The public key; let S represents the set of all verification keys; for j∈[1,t], S j calculate and a j Send to other participants; finally, calculate and output the aggregation key.

[0142] It is understandable that, in the process of generating the first value of the target participant based on the message receiver's public key and the target participant's target random number, the target participant can generate the first value of the target participant based on the first value calculation formula.

[0143] The first numerical calculation formula includes:

[0144] Q j =[r j ]P R ;

[0145] Among them, Q j P represents the first numerical value of the target participant. R This represents the message recipient's public key.

[0146] Step S108: Transmit the encrypted authentication fragments of the target participant to the encrypted aggregator, so that the encrypted aggregator generates the aggregated ciphertext of the target message based on all the encrypted authentication fragments.

[0147] Understandably, after the target participant encrypts and authenticates the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order value, and the target participant's private key, and obtains the target participant's encrypted authentication fragment, the target participant can transmit the target participant's encrypted authentication fragment to the encryption aggregator, so that the encryption aggregator can generate the aggregated ciphertext of the target message based on all the encrypted authentication fragments.

[0148] It should be noted that the process by which other participants generate their own encrypted authentication fragments is the same as that of the target participant. Both involve obtaining the message receiver's public key, generating their own first value based on the message receiver's public key and their own target random number, and transmitting their first value to the other participants; obtaining the first values ​​from the other participants and obtaining the aggregation key generated with the other participants; and encrypting and authenticating the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order value, and their own private key to obtain their own encrypted authentication fragment.

[0149] Understandably, in the process of encrypting and authenticating the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order value, and the target participant's private key to obtain the target participant's encrypted authentication fragment, the target participant can obtain the target participant's encrypted authentication fragment by using the encrypted authentication fragment formula, based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order value, and the target participant's private key. The encrypted authentication fragment formula includes:

[0150] P = R + H(m);

[0151] e = H sig (pk agg ||R||Z);s j=(r j -ea j d j )mod n;

[0152] Among them, R, P, Z, s j Represents the encrypted authentication fragment of the target participant; R i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the target message. i H represents the first value of the i-th participant in the encryption authentication process; sig Represents the signature hash function; d j Represents the private key of the target participant; mod represents the modulo operation; P m This indicates that the target message is encoded as the value of a point on an elliptic curve.

[0153] That is, for j∈[1,t], S j Q can be calculated j =[r j ]P R and Q j Send to other participants for calculation P = R + H(m); e = H sig (pk agg ||R||Z);s j =(r j -ea j d j )mod n; and (R,P,Z,s) j () as its own encrypted authentication fragment.

[0154] It should be noted that during the process of generating the aggregated ciphertext of the target message, the encryption aggregator can obtain elliptic curve parameters, including the order of the base point; obtain the target message to be encrypted; transmit the target message to each encryption authentication participant; receive the encryption authentication fragments transmitted by each encryption authentication participant; and generate the aggregated ciphertext of the target message based on the order and all encryption authentication fragments.

[0155] In the process of generating the aggregated ciphertext of the target message based on the order value and all encrypted authentication fragments, the encryption aggregator can generate the aggregated ciphertext of the target message based on the order value and all encrypted authentication fragments through the aggregated ciphertext calculation formula.

[0156] The formulas for ciphertext aggregation include:

[0157] s i =(r i -ea i d i)mod n; e = H sig (pk agg ||R||Z);

[0158] P = R + H(m);

[0159] Where R, P, Z, and s represent aggregated ciphertext.

[0160] It should be noted that during the process of decrypting the aggregated ciphertext to obtain the target message, the message receiver can obtain the aggregated ciphertext of the target message; based on the message receiver's private key, the aggregated ciphertext is decrypted to obtain the target message.

[0161] In the process of decrypting the aggregated ciphertext using the message receiver's private key to obtain the target message, the message receiver can generate a third value P based on the message receiver's private key and the aggregated ciphertext. m '=Z-[d R R; decode the third value to obtain the verification message; verify whether P = R + H(m') is true. If it is true, then use the verification message as the target message; where m' represents the verification message.

[0162] It should be noted that, in order to ensure the secure transmission of the target message, the encryption aggregator can also verify the aggregated ciphertext during the process of sending the aggregated ciphertext to the message receiver. For example, the message receiver can directly verify the aggregated ciphertext, or a verifier can verify the aggregated ciphertext. The verification process can be as follows: obtain the aggregated ciphertext of the target message transmitted by the encryption aggregator; obtain the aggregation key generated by the encryption authentication participants; obtain the elliptic curve parameters, which include the base point and the signature hash function; verify the aggregated ciphertext based on the base point, the signature hash function, and the aggregation key to obtain the verification result.

[0163] In the process of verifying the aggregated ciphertext based on the base point, signature hash function, and aggregate key to obtain the verification result, a verification hash value e' = H can be generated based on the aggregated ciphertext. sig (pk agg ||R||Z); Verify R=s[G]+e'[pk agg If the condition is met, a verification result indicating that the aggregated ciphertext is correct is obtained, and subsequent operations can continue; if the condition is not met, a verification result indicating that the aggregated ciphertext is incorrect is obtained, and the encryption authentication process can be terminated.

[0164] This disclosure provides a data aggregation authentication encryption method applied to a target participant in an encryption authentication process. The method involves: obtaining the target message to be encrypted transmitted by the encryption aggregator; obtaining elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function; generating a first random number for the target participant based on the order; encrypting the first random number based on the base point to obtain an encrypted random number for the target participant; transmitting the encrypted random number to other participants in the encryption authentication process; obtaining encrypted random numbers from other participants; and obtaining the public key of the message receiver, based on the message... The receiving party's public key and the target random number of the target participant generate the target participant's first value, and transmit the target participant's first value to other participants; obtain the first values ​​of other participants, and obtain the aggregation key generated with other participants; encrypt and authenticate the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order value, and the target participant's private key, to obtain the target participant's encrypted authentication fragment; transmit the target participant's encrypted authentication fragment to the encryption aggregator, so that the encryption aggregator can generate the aggregated ciphertext of the target message based on all encrypted authentication fragments. In this disclosure, the target participant, with the help of elliptic curve parameters, generates each encrypted authentication fragment of the target message together with other participants in the encryption authentication participants, thereby enabling the encryption aggregator to generate the aggregated ciphertext of the target message based on all encrypted authentication fragments, which can simultaneously satisfy confidentiality and integrity, and has good applicability.

[0165] This disclosure relates to a data aggregation authentication encryption method, applied to an encryption aggregator, which may include the following steps:

[0166] Obtain the elliptic curve parameters, which include the order of the base point;

[0167] Retrieve the target message to be encrypted;

[0168] Transmit the target message to each participating party in the encryption authentication process;

[0169] Receive encrypted authentication fragments transmitted by each participating party in the encryption authentication process;

[0170] Generate the aggregated ciphertext of the target message based on the order value and all encrypted authentication fragments;

[0171] The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including the base point, the order of the base point, the first hash function, and the signature hash function. Based on the order, a first random number is generated for the target participant. This first random number is then encrypted based on the base point to obtain an encrypted random number for the target participant, which is then transmitted to the other participants in the encryption authentication process. The target participant also acquires encrypted random numbers from the other participants. Furthermore, the target participant acquires the message receiver's public key, generates a first value based on the message receiver's public key and the target random number, and transmits this first value to the other participants. Finally, the target participant acquires the first values ​​from the other participants and obtains the aggregation key generated with the other participants. Finally, the target participant performs encryption authentication on the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order, and the target participant's private key, resulting in an encrypted authentication fragment for the target participant.

[0172] It is understandable that, in the process of generating the aggregated ciphertext of the target message based on the order value and all encrypted authentication fragments, the encryption aggregator can use the aggregation ciphertext calculation formula to generate the aggregated ciphertext of the target message based on the order value and all encrypted authentication fragments.

[0173] The formulas for ciphertext aggregation include:

[0174] s i =(r i -ea i d i )mod n; e = H sig (pk agg ||R||Z);

[0175] P = R + H(m);

[0176] Where R, P, Z, and s represent aggregated ciphertext; R, P, Z, and s i R represents the encrypted authentication fragment of the i-th participant in the encrypted authentication process; i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the target message. i =[r i ]P R Q i P represents the first value of the i-th participant in the encryption authentication process; R H represents the message receiver's public key; sig Represents the signature hash function; d i r represents the private key of the i-th participant in the cryptographic authentication process; iRepresents the first random number of the i-th participant in the encryption authentication process; a i H represents the key fragment of the i-th participant in the cryptographic authentication process; agg T represents the aggregate hash function; T represents the set of verification keys consisting of the public keys of the participants in the cryptographic authentication. Represents the public key of the i-th participant in the encryption authentication; || represents concatenation; mod represents the modulo operation; H sig Represents the signature hash function; pk agg P represents the aggregate key; m This indicates that the target message is encoded as the value of a point on an elliptic curve.

[0177] It should also be noted that when only one party needs to perform encryption authentication on the target message, the data aggregation authentication encryption method can be as follows:

[0178] The cryptographic aggregator encodes the target message m as a point P on the elliptic curve E. m ;

[0179] Choose a random number r∈[1,n-1];

[0180] Calculate the points R = [r]G, P = R + H1(m) on the elliptic curve, and Z = P. m +[r]P R ;

[0181] Calculate the hash value e = H sig (P S ||R||Z);

[0182] Calculate s = (r - ed) S )mod n;

[0183] Output ciphertext C ind :=(R,P,Z,s);

[0184] It can be seen that the aggregated ciphertext C agg The form and size are the same as a single ciphertext C ind The same applies; for plaintext data m, t participants S1,...,S are required. t In the case of joint encryption authentication, if independent authentication and encryption are used, each participant S j Generate their respective ciphertexts The final ciphertext form is Compared to the aggregated ciphertext disclosed herein, the size of this ciphertext has increased by t times. Therefore, in the case of multi-party encryption authentication, the aggregated encryption operation of this disclosure can effectively compress the ciphertext size, thereby reducing the network transmission bandwidth consumption of data, as well as the storage and computational overhead of each party.

[0185] This disclosure relates to a data aggregation authentication encryption method, applied to a verifier, which may include the following steps:

[0186] Obtain the aggregated ciphertext of the target message transmitted by the encrypted aggregator;

[0187] Obtain the aggregated key generated by the participants in the encryption authentication process;

[0188] Obtain the elliptic curve parameters, which include the base point and the signature hash function.

[0189] The aggregated ciphertext is verified based on the base point, signature hash function, and aggregation key to obtain the verification result;

[0190] The process involves the following steps: obtaining elliptic curve parameters, including the order of the base point; obtaining the target message to be encrypted; transmitting the target message to each encryption authentication participant; receiving encryption authentication fragments transmitted by each encryption authentication participant; and generating the aggregated ciphertext of the target message based on the order and all encryption authentication fragments.

[0191] The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including the base point, the order of the base point, the first hash function, and the signature hash function. Based on the order, a first random number is generated for the target participant. This first random number is then encrypted based on the base point to obtain an encrypted random number for the target participant, which is then transmitted to the other participants in the encryption authentication process. The target participant also acquires encrypted random numbers from the other participants. Furthermore, the target participant acquires the message receiver's public key, generates a first value based on the message receiver's public key and the target random number, and transmits this first value to the other participants. Finally, the target participant acquires the first values ​​from the other participants and obtains the aggregation key generated with the other participants. Finally, the target participant performs encryption authentication on the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order, and the target participant's private key, resulting in an encrypted authentication fragment for the target participant.

[0192] Understandably, in the process of verifying the aggregated ciphertext based on the base point, signature hash function, and aggregate key, and obtaining the verification result, the verifier can generate a verification hash value e' = H based on the aggregated ciphertext. sig (pk agg ||R||Z); Verify R=s[G]+e'[pk agg If the condition is true, a verification result indicating that the aggregated ciphertext is correct is obtained; if it is false, a verification result indicating that the aggregated ciphertext is incorrect is obtained.

[0193] Where R, P, Z, and s represent aggregated ciphertext; R, P, Z, and s iR represents the encrypted authentication fragment of the i-th participant in the encrypted authentication process; i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the target message. i =[r i ]P R Q i P represents the first value of the i-th participant in the encryption authentication process; R H represents the message receiver's public key; sig Represents the signature hash function; d i r represents the private key of the i-th participant in the cryptographic authentication process; i Represents the first random number of the i-th participant in the encryption authentication process; a i H represents the key fragment of the i-th participant in the cryptographic authentication process; agg T represents the aggregate hash function; T represents the set of verification keys consisting of the public keys of the participants in the cryptographic authentication. Represents the public key of the i-th participant in the encryption authentication; || represents concatenation; mod represents the modulo operation; H sig Represents the signature hash function; pk agg This represents the aggregate key.

[0194] It should be noted that, due to:

[0195]

[0196] Therefore, R = [s]G + [e]pk is satisfied. agg If so, it can be determined that the correctly generated aggregated ciphertext has passed verification.

[0197] It should also be noted that, due to the ciphertext form s = (k - ed) S The ciphertext mod n has a linear structure, thus enabling batch verification of multiple ciphertexts to be verified. In this case, the verifier R only needs to perform a linear combination of these ciphertexts and then execute a single verification operation, which greatly improves verification efficiency. The specific batch verification operation is as follows:

[0198] Batch verification of encrypted text

[0199] Suppose there are l ciphertexts to be verified in The corresponding verification public key is The verifier R can then perform the following operations:

[0200] Calculate hash value

[0201] Verify whether the following relations hold true:

[0202]

[0203] If true, then prove If all ciphertexts are valid, output 1; otherwise, at least one ciphertext exists. Invalid, output 0.

[0204] According to the verification operation Ver, if we verify one by one... This requires 2l dot product calculations; batch verification Then only some additions (which are almost free in terms of computing power) and (l+1) dot product calculations are needed, which greatly reduces the verification overhead. Therefore, when it is necessary to reduce the verification overhead, the verifier can verify the aggregated ciphertext in batches.

[0205] This disclosure relates to a data aggregation authentication encryption method applied to a message receiver, which may include the following steps:

[0206] Obtain the aggregated ciphertext of the target message;

[0207] The aggregated ciphertext is decrypted using the message receiver's private key to obtain the target message;

[0208] The process involves the following steps: obtaining elliptic curve parameters, including the order of the base point; obtaining the target message to be encrypted; transmitting the target message to each encryption authentication participant; receiving encryption authentication fragments transmitted by each encryption authentication participant; and generating the aggregated ciphertext of the target message based on the order and all encryption authentication fragments.

[0209] The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including the base point, the order of the base point, the first hash function, and the signature hash function. Based on the order, a first random number is generated for the target participant. This first random number is then encrypted based on the base point to obtain an encrypted random number for the target participant, which is then transmitted to the other participants in the encryption authentication process. The target participant also acquires encrypted random numbers from the other participants. Furthermore, the target participant acquires the message receiver's public key, generates a first value based on the message receiver's public key and the target random number, and transmits this first value to the other participants. Finally, the target participant acquires the first values ​​from the other participants and obtains the aggregation key generated with the other participants. Finally, the target participant performs encryption authentication on the target message based on all encrypted random numbers, the first hash function, all first values, the aggregation key, the signature hash function, the order, and the target participant's private key, resulting in an encrypted authentication fragment for the target participant.

[0210] Understandably, during the process of decrypting the aggregated ciphertext using the message receiver's private key to obtain the target message, the message receiver can generate a third value P based on the message receiver's private key and the aggregated ciphertext. m =Z-[d R ]R;

[0211] The verification message is obtained by decoding the third value;

[0212] Verify whether P = R + H(m') is true. If it is true, then use the verification message as the target message.

[0213] Where m' represents the verification message; R, P, Z, and s represent the aggregated ciphertext; R, P, Z, and s represent the aggregated ciphertext. i R represents the encrypted authentication fragment of the i-th participant in the encrypted authentication process; i H represents the encrypted random number of the i-th participant in the encryption authentication process; H represents the first hash function; m represents the target message; Q represents the target message. i =[r i ]P R Q i P represents the first value of the i-th participant in the encryption authentication process; R H represents the message receiver's public key; sig Represents the signature hash function; d i r represents the private key of the i-th participant in the cryptographic authentication process; i Represents the first random number of the i-th participant in the encryption authentication process; a i H represents the key fragment of the i-th participant in the cryptographic authentication process; agg T represents the aggregate hash function; T represents the set of verification keys consisting of the public keys of the participants in the cryptographic authentication. Represents the public key of the i-th participant in the encryption authentication; || represents concatenation; mod represents the modulo operation; H sig Represents the signature hash function; pk agg This represents the aggregate key. It should be noted that, due to...

[0214]

[0215] Therefore, P is satisfied. m =Z-[d R R, decode P m Then the original plaintext m can be obtained.

[0216] It should also be noted that the ciphertext of this disclosure is required to satisfy confidentiality, meaning that the ciphertext does not reveal any information of the plaintext; furthermore, the ciphertext is required to satisfy unforgeability, meaning that no one other than the sender S can forge a valid ciphertext that can pass verification. Using cryptographic security reduction techniques, the confidentiality of this disclosure scheme can be reduced to the decision Diffie-Hellman (DDH) assumption on elliptic curves; the unforgeability can be reduced to the discrete logarithm assumption on elliptic curves. The theorem conclusions are given below:

[0217] Theorem 1: Assume that the Diffie-Hellman (DDH) criterion holds on elliptic curves, H, H sig H com H agg If it is a random oracle, then the proposed scheme satisfies the indistinguishability of ciphertext under chosen-plaintext attacks (IND-CPA security).

[0218] Theorem 2: Assume the discrete logarithm hypothesis holds on elliptic curves, H, H sig H com H agg If it is a random oracle, then the proposed scheme is unforgeable under adaptive chosen message attacks.

[0219] Please see Figure 3 , Figure 3 This is a schematic diagram illustrating the structure of a data aggregation authentication encryption device according to an exemplary embodiment.

[0220] This disclosure relates to a data aggregation authentication encryption device 300, which is applied to a target participant in an encryption authentication participant and may include:

[0221] The first acquisition module 310 is used to acquire the target message to be encrypted transmitted by the encryption aggregator;

[0222] The second acquisition module 320 is used to acquire elliptic curve parameters, which include the base point, the order of the base point, the first hash function, and the signature hash function.

[0223] The first generation module 330 is used to generate a first random number for the target participant based on the order value, encrypt the first random number for the target participant based on the base point to obtain an encrypted random number for the target participant, and transmit the encrypted random number for the target participant to other participants in the encryption authentication participants.

[0224] The third acquisition module 340 is used to acquire encrypted random numbers from other participants;

[0225] The fourth acquisition module 350 is used to acquire the public key of the message receiver, generate the first value of the target participant based on the public key of the message receiver and the target random number of the target participant, and transmit the first value of the target participant to other participants.

[0226] The fifth acquisition module 360 ​​is used to acquire the first value of other participants and the aggregation key generated with other participants;

[0227] The first authentication module 370 is used to perform encrypted authentication on the target message based on all encrypted random numbers, the first hash function, all first values, the aggregate key, the signature hash function, the order value, and the private key of the target participant, so as to obtain the encrypted authentication fragment of the target participant;

[0228] The first transmission module 380 is used to transmit the encrypted authentication fragments of the target participant to the encrypted aggregator, so that the encrypted aggregator can generate the aggregated ciphertext of the target message based on all the encrypted authentication fragments.

[0229] A description of the data aggregation authentication encryption device 300 disclosed herein can be found in the above embodiments, and will not be repeated here.

[0230] Figure 4 This is a block diagram illustrating an electronic device 900 according to an exemplary embodiment. Figure 4 As shown, the electronic device 900 may include a processor 901 and a memory 902. The electronic device 900 may also include one or more of a multimedia component 903, an input / output (I / O) interface 904, and a communication component 905.

[0231] The processor 901 controls the overall operation of the electronic device 900 to complete all or part of the steps in the aforementioned data aggregation authentication encryption method. The memory 902 stores various types of data to support the operation of the electronic device 900. This data may include, for example, instructions for any application or method operating on the electronic device 900, and application-related data such as contact data, sent and received messages, pictures, audio, video, etc. The memory 902 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. Multimedia component 903 may include a screen and an audio component. The screen may be, for example, a touchscreen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signals may be further stored in memory 902 or transmitted via communication component 905. The audio component also includes at least one speaker for outputting audio signals. I / O interface 904 provides an interface between processor 901 and other interface modules, such as a keyboard, mouse, buttons, etc. These buttons may be virtual or physical buttons. Communication component 905 is used for wired or wireless communication between the electronic device 900 and other devices. Wireless communication includes, for example, Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, or 4G, or a combination of these. Therefore, the corresponding communication component 905 may include a Wi-Fi module, a Bluetooth module, or an NFC module.

[0232] In an exemplary embodiment, the electronic device 900 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the data aggregation authentication encryption method described above.

[0233] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided, which, when executed by a processor, implement the steps of the data aggregation authentication encryption method described above. For example, the computer-readable storage medium may be the memory 902 including the program instructions described above, which may be executed by the processor 901 of the electronic device 900 to complete the data aggregation authentication encryption method described above.

[0234] For descriptions of relevant parts of the data aggregation authentication encryption device, electronic device, and computer-readable storage medium provided in this disclosure, please refer to the detailed descriptions of the corresponding parts in the data aggregation authentication encryption method provided in this disclosure, which will not be repeated here. Furthermore, parts of the technical solutions provided in this disclosure that are consistent with the implementation principles of corresponding technical solutions in the prior art are not described in detail to avoid excessive elaboration.

[0235] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0236] The above description of the disclosed embodiments enables those skilled in the art to make or use this disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data aggregation authentication encryption method, characterized in that, The target participants in the cryptographic authentication process include: Obtain the target message to be encrypted transmitted by the encryption aggregator; Obtain elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function; A first random number for the target participant is generated based on the order value. The first random number for the target participant is then encrypted based on the base point to obtain an encrypted random number for the target participant. The encrypted random number for the target participant is then transmitted to the other participants in the encryption authentication participants. Obtain the encrypted random number from the other participants; Obtain the message recipient's public key, generate a first value for the target participant based on the message recipient's public key and the target random number of the target participant, and transmit the first value of the target participant to the other participants; Obtain the first value from the other participants, and obtain the aggregation key generated with the other participants; The target message is encrypted and authenticated based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the private key of the target participant to obtain the encrypted authentication fragment of the target participant; The encrypted authentication fragments of the target participant are transmitted to the encrypted aggregator, so that the encrypted aggregator generates the aggregated ciphertext of the target message based on all the encrypted authentication fragments; The process of generating the aggregate key with the other participants includes: generating a private key for the target participant based on the order value; encrypting the private key of the target participant based on the base point to obtain a public key for the target participant; obtaining the public keys of the other participants and using all the public keys as a verification key set; generating a key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function; obtaining the key fragments of the other participants; and generating the aggregate key based on all the key fragments and all the public keys. The step of generating the key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function includes: generating the key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function using a key fragment operation formula. The key fragment operation formula includes: ; in, The key fragment representing the target participant; This refers to the aggregate hash function; This refers to the set of verification keys; The public key representing the target participant; Indicates splicing; The step of generating the aggregate key based on all the key fragments and all the public keys includes: generating the aggregate key based on all the key fragments and all the public keys using an aggregate key operation formula; the aggregate key operation formula includes: ; in, This represents the aggregation key; This indicates the total number of participants in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates the first party among the participants in the encryption authentication. The key fragment of each participating party.

2. The method according to claim 1, characterized in that, The elliptic curve parameters include the aggregate hash function.

3. The method according to claim 2, characterized in that, The elliptic curve parameters include a second hash function; The generation of the first random number for the target participant based on the order value includes: Select random number The first random number used as the target participant Indicates the order value; The transmission of the encrypted random number from the target participant to the other participants in the encryption authentication participants includes: The second numerical value of the target participant is obtained by encrypting the encrypted random number of the target participant using the second numerical calculation formula and based on the second hash function. The second numerical calculation formula includes: , ; in, The second numerical value represents the target participant; This represents the second hash function; The encrypted random number represents the target participant; Indicates the base point; The second numerical value of the target participant and the encrypted random number of the target participant are transmitted to the other participants, so that the other participants can verify... Once correct, the second value from the target participant is received.

4. The method according to claim 3, characterized in that, The step of generating the first value of the target participant based on the message receiver's public key and the target participant's target random number includes: The first numerical value of the target participant is generated based on the public key of the message recipient and the target random number of the target participant using the first numerical calculation formula. The first numerical calculation formula includes: ; in, The first value represents the target participant; This refers to the public key of the message recipient.

5. The method according to claim 4, characterized in that, The encryption authentication of the target message based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the target participant's private key, to obtain the target participant's encrypted authentication fragment, includes: By using the encrypted authentication fragment formula, the target message is encrypted and authenticated based on all the encrypted random numbers, the first hash function, all the first values, the aggregate key, the signature hash function, the order value, and the private key of the target participant, to obtain the encrypted authentication fragment of the target participant; The encryption authentication fragment formula includes: ; ; ; ; ; in, , , , This refers to the encrypted authentication fragment representing the target participant; Indicates the first party among the participants in the encryption authentication. The encrypted random number for each participant; This represents the first hash function; This refers to the target message; Indicates the first party among the participants in the encryption authentication. The first value of each participating party; This refers to the signature hash function; The private key of the target participant; This represents the modulo operation; This indicates that the target message is encoded as the value of a point on an elliptic curve.

6. A data aggregation authentication encryption method, characterized in that, Applied to cryptographic aggregators, including: Obtain the elliptic curve parameters, including the order value of the base point; Retrieve the target message to be encrypted; The target message is transmitted to each participating party in the encryption authentication process; Receive encrypted authentication fragments transmitted by each of the encrypted authentication participants; The aggregated ciphertext of the target message is generated based on the order value and all the encrypted authentication fragments; The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function; generating a first random number for the target participant based on the order; encrypting the first random number for the target participant based on the base point to obtain an encrypted random number for the target participant, and transmitting the encrypted random number for the target participant to other participants in the encryption authentication process; acquiring the encrypted random numbers for the other participants; acquiring the public key of the message receiver; generating a first value for the target participant based on the public key of the message receiver and the target random number for the target participant, and transmitting the first value for the target participant to the other participants; acquiring the first value for the other participants and acquiring the aggregation key generated with the other participants; and encrypting and authenticating the target message based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order, and the private key of the target participant to obtain the encrypted authentication fragment for the target participant. The process of generating the aggregate key with the other participants includes: generating a private key for the target participant based on the order value; encrypting the private key of the target participant based on the base point to obtain a public key for the target participant; obtaining the public keys of the other participants and using all the public keys as a verification key set; generating a key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function; obtaining the key fragments of the other participants; and generating the aggregate key based on all the key fragments and all the public keys. The step of generating the key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function includes: generating the key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function using a key fragment operation formula. The key fragment operation formula includes: ; in, The key fragment representing the target participant; This refers to the aggregate hash function; This refers to the set of verification keys; The public key representing the target participant; Indicates splicing; The step of generating the aggregate key based on all the key fragments and all the public keys includes: generating the aggregate key based on all the key fragments and all the public keys using an aggregate key operation formula; the aggregate key operation formula includes: ; in, This represents the aggregation key; This indicates the total number of participants in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates the first party among the participants in the encryption authentication. The key fragment of each participating party.

7. The data aggregation authentication encryption method according to claim 6, characterized in that, The generation of the aggregated ciphertext of the target message based on the order value and all the encrypted authentication fragments includes: The aggregated ciphertext of the target message is generated based on the order value and all the encrypted authentication fragments using the aggregated ciphertext operation formula. The aggregated ciphertext operation formula includes: ; ; ; ; ; ; in, , , , This represents the aggregated ciphertext; , , , Indicates the first party among the participants in the encryption authentication. The encrypted authentication fragment of each participating party; Indicates the first party among the participants in the encryption authentication. The encrypted random number for each participant; This represents the first hash function; This refers to the target message; , Indicates the first party among the participants in the encryption authentication. The first value of each participating party; This refers to the public key of the message recipient; This refers to the signature hash function; Indicates the first party among the participants in the encryption authentication. The private key of each participating party; Indicates the first party among the participants in the encryption authentication. The first random number for each participant; , Indicates the first party among the participants in the encryption authentication. Key fragments of each participant; Represents the aggregate hash function; This refers to the set of verification keys composed of the public keys of the participating parties in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates splicing; This represents the modulo operation; This refers to the signature hash function; , This represents the aggregation key; This indicates that the target message is encoded as the value of a point on an elliptic curve.

8. A data aggregation authentication encryption method, characterized in that, Applied to the validator, including: Obtain the aggregated ciphertext of the target message transmitted by the encrypted aggregator; Obtain the aggregated key generated by the participants in the encryption authentication process; Obtain the elliptic curve parameters, which include the base point and the signature hash function; The aggregated ciphertext is verified based on the base point, the signature hash function, and the aggregation key to obtain the verification result; The encryption aggregator obtains elliptic curve parameters, including the order value of the base point; obtains the target message to be encrypted; transmits the target message to each encryption authentication participant; receives encryption authentication fragments transmitted by each encryption authentication participant; and generates the aggregated ciphertext of the target message based on the order value and all the encryption authentication fragments. The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function; generating a first random number for the target participant based on the order; encrypting the first random number for the target participant based on the base point to obtain an encrypted random number for the target participant, and transmitting the encrypted random number for the target participant to other participants in the encryption authentication process; acquiring the encrypted random numbers for the other participants; acquiring the public key of the message receiver; generating a first value for the target participant based on the public key of the message receiver and the target random number for the target participant, and transmitting the first value for the target participant to the other participants; acquiring the first value for the other participants and acquiring the aggregation key generated with the other participants; and encrypting and authenticating the target message based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order, and the private key of the target participant to obtain the encrypted authentication fragment for the target participant. The process of generating the aggregate key with the other participants includes: generating a private key for the target participant based on the order value; encrypting the private key of the target participant based on the base point to obtain a public key for the target participant; obtaining the public keys of the other participants and using all the public keys as a verification key set; generating a key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function; obtaining the key fragments of the other participants; and generating the aggregate key based on all the key fragments and all the public keys. The step of generating the key fragment of the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function includes: generating the key fragment of the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function using a key fragment operation formula; the key fragment operation formula includes: ; in, The key fragment representing the target participant; This refers to the aggregate hash function; This refers to the set of verification keys; The public key representing the target participant; Indicates splicing; The step of generating the aggregate key based on all the key fragments and all the public keys includes: generating the aggregate key based on all the key fragments and all the public keys using an aggregate key operation formula; the aggregate key operation formula includes: ; in, This represents the aggregation key; This indicates the total number of participants in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates the first party among the participants in the encryption authentication. The key fragment of each participating party.

9. The method according to claim 8, characterized in that, The verification of the aggregated ciphertext based on the base point, the signature hash function, and the aggregation key to obtain the verification result includes: A verification hash value is generated based on the aggregated ciphertext. ; verify If the condition is met, a verification result indicating that the aggregated ciphertext is correct is obtained; otherwise, a verification result indicating that the aggregated ciphertext is incorrect is obtained. in, , , , This represents the aggregated ciphertext; , , , Indicates the first party among the participants in the encryption authentication. The encrypted authentication fragment of each participating party; Indicates the first party among the participants in the encryption authentication. The encrypted random number for each participant; This represents the first hash function; This refers to the target message; , Indicates the first party among the participants in the encryption authentication. The first value of each participating party; This refers to the public key of the message recipient; This refers to the signature hash function; Indicates the first party among the participants in the encryption authentication. The private key of each participating party; Indicates the first party among the participants in the encryption authentication. The first random number for each participant; , Indicates the first party among the participants in the encryption authentication. Key fragments of each participant; Represents the aggregate hash function; This refers to the set of verification keys composed of the public keys of the participating parties in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates splicing; This represents the modulo operation; This refers to the signature hash function; , This refers to the aggregation key.

10. A data aggregation authentication encryption method, characterized in that, Applied to the message receiver, including: Obtain the aggregated ciphertext of the target message; The aggregated ciphertext is decrypted using the private key of the message recipient to obtain the target message; The process involves: obtaining elliptic curve parameters, including the order of the base point; obtaining the target message to be encrypted; transmitting the target message to each encryption authentication participant; receiving encryption authentication fragments transmitted by each encryption authentication participant; and generating the aggregated ciphertext of the target message based on the order and all the encryption authentication fragments. The process involves the target participant in the encryption authentication process acquiring elliptic curve parameters, including a base point, the order of the base point, a first hash function, and a signature hash function; generating a first random number for the target participant based on the order; encrypting the first random number for the target participant based on the base point to obtain an encrypted random number for the target participant, and transmitting the encrypted random number for the target participant to other participants in the encryption authentication process; acquiring the encrypted random numbers for the other participants; acquiring the public key of the message receiver; generating a first value for the target participant based on the public key of the message receiver and the target random number for the target participant, and transmitting the first value for the target participant to the other participants; acquiring the first value for the other participants and acquiring the aggregation key generated with the other participants; and encrypting and authenticating the target message based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order, and the private key of the target participant to obtain the encrypted authentication fragment for the target participant. The process of generating the aggregate key with the other participants includes: generating a private key for the target participant based on the order value; encrypting the private key of the target participant based on the base point to obtain a public key for the target participant; obtaining the public keys of the other participants and using all the public keys as a verification key set; generating a key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function; obtaining the key fragments of the other participants; and generating the aggregate key based on all the key fragments and all the public keys. The step of generating the key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function includes: generating the key fragment for the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function using a key fragment operation formula. The key fragment operation formula includes: ; in, The key fragment representing the target participant; This refers to the aggregate hash function; This refers to the set of verification keys; The public key representing the target participant; Indicates splicing; The step of generating the aggregate key based on all the key fragments and all the public keys includes: generating the aggregate key based on all the key fragments and all the public keys using an aggregate key operation formula; the aggregate key operation formula includes: ; in, This represents the aggregation key; This indicates the total number of participants in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates the first party among the participants in the encryption authentication. The key fragment of each participating party.

11. The method according to claim 10, characterized in that, The step of decrypting the aggregated ciphertext based on the message recipient's private key to obtain the target message includes: Based on the message recipient's private key and the aggregated ciphertext, a third numerical value is generated. ; The verification message is obtained by decoding the third numerical value; verify If the condition is met, the verification message will be used as the target message. in, This refers to the verification message; , , , This represents the aggregated ciphertext; , , , Indicates the first party among the participants in the encryption authentication. The encrypted authentication fragment of each participating party; Indicates the first party among the participants in the encryption authentication. The encrypted random number for each participant; This represents the first hash function; This refers to the target message; , Indicates the first party among the participants in the encryption authentication. The first value of each participating party; This refers to the public key of the message recipient; This refers to the signature hash function; Indicates the first party among the participants in the encryption authentication. The private key of each participating party; Indicates the first party among the participants in the encryption authentication. The first random number for each participant; , Indicates the first party among the participants in the encryption authentication. Key fragments of each participant; Represents the aggregate hash function; This refers to the set of verification keys composed of the public keys of the participating parties in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates splicing; This represents the modulo operation; This refers to the signature hash function; , This refers to the aggregation key.

12. A data aggregation authentication encryption device, characterized in that, The target participants in the cryptographic authentication process include: The first acquisition module is used to acquire the target message to be encrypted transmitted by the encryption aggregator; The second acquisition module is used to acquire elliptic curve parameters, which include a base point, the order of the base point, a first hash function, and a signature hash function. The first generation module is used to generate a first random number for the target participant based on the order value, encrypt the first random number for the target participant based on the base point to obtain an encrypted random number for the target participant, and transmit the encrypted random number for the target participant to other participants in the encryption authentication participants. The third acquisition module is used to acquire the encrypted random number from the other participants; The fourth acquisition module is used to acquire the public key of the message recipient, generate a first value of the target participant based on the public key of the message recipient and the target random number of the target participant, and transmit the first value of the target participant to the other participants. The fifth acquisition module is used to acquire the first value of the other participants and to acquire the aggregation key generated with the other participants; The first authentication module is used to perform encrypted authentication on the target message based on all the encrypted random numbers, the first hash function, all the first values, the aggregation key, the signature hash function, the order value, and the private key of the target participant, to obtain the encrypted authentication fragment of the target participant; The first transmission module is used to transmit the encrypted authentication fragment of the target participant to the encrypted aggregator, so that the encrypted aggregator generates the aggregated ciphertext of the target message based on all the encrypted authentication fragments; The data aggregation authentication encryption device is also used for: Generate the private key of the target participant based on the order value; encrypt the private key of the target participant based on the base point to obtain the public key of the target participant; obtain the public keys of the other participants and use all the public keys as a verification key set; generate the key fragment of the target participant based on the public key of the target participant, the verification key set, and the aggregate hash function; obtain the key fragments of the other participants; generate the aggregate key based on all the key fragments and all the public keys; The data aggregation authentication encryption device is also used for: The key fragment of the target participant is generated based on the public key of the target participant, the verification key set, and the aggregate hash function using a key fragment operation formula; the key fragment operation formula includes: ; in, The key fragment representing the target participant; This refers to the aggregate hash function; This refers to the set of verification keys; The public key representing the target participant; Indicates splicing; The step of generating the aggregate key based on all the key fragments and all the public keys includes: generating the aggregate key based on all the key fragments and all the public keys using an aggregate key operation formula; the aggregate key operation formula includes: ; in, This represents the aggregation key; This indicates the total number of participants in the encryption authentication process; Indicates the first party among the participants in the encryption authentication. The public key of each participating party; Indicates the first party among the participants in the encryption authentication. The key fragment of each participating party.

13. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program in the memory to implement the steps of the method according to any one of claims 1 to 11.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Intelligent power grid data aggregation and encryption method with forward security

    CN110489982A

  • Multi-signature method based on blockchain platform

    CN112989436A