A ranging and positioning privacy protection method and system based on inner product function encryption in a cloud environment
By using inner product function encryption technology in a cloud environment, converting the ranging positioning algorithm into inner product calculation and combining multiplication transformation and translation transformation, the privacy protection problem of indoor positioning services in a cloud environment is solved, and efficient and secure positioning services are achieved.
Patent Information
- Application Number
- CN202411039620.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-31
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-07-31
AI Technical Summary
In a cloud environment, existing technologies make it difficult to effectively protect user location information, measurement information, and the positioning service provider's positioning database information while providing indoor positioning services. Traditional methods have low computational efficiency and are not suitable for cloud environments.
The inner product function encryption technology is used to transform the ranging positioning algorithm into the inner product calculation process between the anchor point information and the measurement information. Multiplication and translation transformations are used to protect the anchor point database and measurement information. The positioning calculation is completed through the inner product function encryption mechanism to hide the user's true location.
It realizes privacy-protected indoor positioning services in a cloud environment, reduces the computing overhead on the user side and the deployment and maintenance costs of positioning service providers, improves computing efficiency, protects the information security of all parties, and reduces positioning errors and communication overhead.
Smart Images

Figure CN118764294B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security protection, and specifically relates to a ranging and positioning privacy protection method and system based on inner product function encryption, which can be used to provide safe and efficient ranging-based indoor positioning services in a cloud environment. Background Art
[0002] Indoor positioning technology is experiencing rapid development, and ranging positioning technology, a common technical approach in indoor positioning services, is increasingly being used. Furthermore, with the development of cloud computing, outsourcing positioning resources and algorithms to cloud environments is becoming a mainstream trend in indoor positioning. Cloud positioning not only reduces deployment and maintenance costs for Indoor Positioning Service Providers (IPSPs), providing seamless, flexible, and scalable positioning services, but also reduces computing and storage overhead on the user side. However, the highly open cloud environment exacerbates privacy concerns in cloud positioning. Cloud Service Providers (CSPs), responsible for positioning computations, are inherently untrustworthy entities, often "honest but curious." In the process of providing positioning services, they not only obtain user location and measurement information, potentially leaking more personal information such as age, hobbies, and income levels, but also potentially stealing important positioning resources stored in the cloud by the positioning service provider, resulting in significant financial losses for the service provider. Data privacy leakage has become a prominent security threat in cloud positioning, necessitating solutions to address privacy issues in indoor positioning services in cloud environments.
[0003] In cloud-based indoor positioning services, protecting user location information, measurement information, and the positioning service provider's positioning database information is crucial. Encryption is an effective data security method, but encryption can affect data availability, making it impossible for cloud service providers (CSPs) to perform positioning calculations. Current research on indoor positioning privacy protection focuses primarily on the traditional two-party architecture of user and positioning service provider, typically employing methods such as homomorphic encryption and secure multi-party computation. These methods are computationally inefficient and unsuitable for indoor positioning scenarios in cloud environments. Inner Product Encryption (IPE) is a novel encryption scheme that precisely controls the amount of ciphertext information revealed by the decryptor, ensuring data security while ensuring a certain level of availability of the ciphertext data. Its high computational efficiency makes it suitable for privacy-preserving indoor positioning services in cloud environments. However, there is currently no research on ranging positioning privacy protection based on IPE in cloud environments. Summary of the Invention
[0004] To address the above technical issues, this paper proposes a privacy-preserving method for ranging and positioning services in a cloud environment based on inner product function encryption. This method transforms the ranging algorithm used in indoor positioning into an inner product calculation between anchor point information and measurement information. This method utilizes inner product function encryption to implement the positioning process while protecting the anchor point database and measurement information. Furthermore, it utilizes multiplication and translation transformations to protect the positioning results, addressing the privacy concerns of indoor positioning services in cloud environments.
[0005] The present invention aims to propose a privacy protection method for ranging and positioning based on inner product function encryption, thereby realizing an indoor positioning service that supports privacy protection in a cloud environment. The present invention decomposes the least squares positioning process of ranging and positioning into an inner product calculation process, and utilizes the inner product encryption mechanism to encrypt and protect the anchor point information of the positioning service provider and the user's measurement information. The cloud service provider decrypts the ciphertext data to obtain the required inner product result, completing the position estimation process. At the same time, the cloud service provider is provided with a transformed positioning result by utilizing multiplication and translation transformations, thereby hiding the user's true location from the cloud service provider. This achieves positioning using the cloud service provider without leaking the privacy information of each party and meeting the real-time requirements of online positioning.
[0006] The solution of the present invention is as follows: During the offline phase, the positioning service provider performs a multiplication transformation on the positioning anchor point information, then uses an inner product function encryption algorithm to generate a ciphertext of the anchor point information and upload it to the cloud service provider. During the online phase, the mobile terminal measures the distance vectors to each anchor point, performs multiplication and translation transformations, and uses the inner product function encryption mechanism to generate a ciphertext of the transformed measurement information, which is then sent to the CSP to request positioning. The CSP executes the positioning algorithm on the encrypted measurement information and the encrypted anchor point information, and uses the decryption algorithm of the inner product function encryption mechanism to obtain the inner product of the vectors, completing the position estimation process and obtaining the transformed positioning result. The user then performs an inverse transformation to obtain the actual positioning result. Because inner product function encryption does not leak any information other than the inner product, the encrypted measurement and anchor point information can complete the positioning calculation without leaking the original information. Furthermore, the cloud service provider performs positioning calculations on the transformed data to obtain the transformed positioning result, thereby hiding the positioning result from the cloud service provider. Therefore, this solution ensures the privacy of information of all parties involved in indoor positioning services in a cloud environment.
[0007] The present invention provides a ranging and positioning privacy protection method based on inner product function encryption in a cloud environment. The method involves three parties: users, positioning service providers, and CSPs. The method specifically includes the following three stages:
[0008] During the initialization phase, the positioning service provider generates the parameter information required by the system, including the public parameter pp and two keys msk1 and msk2 of the inner product function encryption mechanism, as well as the pre-transformation factor r used for multiplication transformation;
[0009] In the offline phase, the positioning service provider transforms and encrypts the anchor point information, and uploads the generated ciphertext and key encrypted by the inner product function, as well as the public parameter pp, to the cloud service provider;
[0010] In the online phase, after the mobile terminal measures the distance vector to each anchor point, it performs multiplication and translation transformations, and uses the inner product function encryption mechanism to generate ciphertext for the transformed measurement information, which is then sent to the cloud service provider to request positioning. The cloud service provider executes the positioning algorithm on the encrypted measurement information and encrypted anchor point information, and uses the decryption algorithm of the inner product function encryption mechanism to obtain the inner product of the vector, completing the position estimation process and obtaining the transformed positioning result. The user then obtains the actual positioning result through inverse transformation.
[0011] Furthermore, the initialization phase specifically includes:
[0012] The positioning service provider generates a bilinear group (G1, G2, G T ,e), where G1,G2,G T is a cyclic group, g1 and g2 are the generators of G1 and G2 respectively, and e represents the transition from groups G1 and G2 to G T The bilinear map is randomly sampled twice from the universal linear group to obtain n-level and m-1 reversible matrices B1 and B2 respectively, and the adjoint matrices of B1 and B2 are calculated respectively. and The final public parameters pp and master keys msk1 and msk2 are:
[0013] pp=(G1,G2,G T ,e)
[0014]
[0015] The positioning service provider randomly generates a real number as the pre-transformation factor r.
[0016] Furthermore, in step 2, it is assumed that the positioning database of the positioning service provider is DB={X i =[x i1 ,x i2 ,…,x in ] T |i=1,2,…,m}, where X i is the position coordinate of the i-th anchor point, X m is the coordinate of the reference anchor point, x ij,i=1,2,…,m,j=1,2,…,n is the jth coordinate component of the i-th anchor point coordinate, n is the spatial dimension of the coordinate, and m is the number of anchor points;
[0017] The positioning service provider uses the pre-transformation factor r to multiply the position coordinates of each anchor point to obtain X′i=rX i ,i=1,2,…,m;
[0018] The positioning service provider calculates the coordinate difference vector D of the first m-1 positioning anchor points relative to the reference anchor point i ,i=1,2,…,m-1, component difference vector C of the positioning anchor point relative to the reference anchor point j ,j=1,2,…,n, the 2-normalized square vectors U and V of the anchor point coordinates are calculated as follows:
[0019] D i =X i ′ -X ′ m
[0020] C j =[D1(j),D2(j),…D m-1 (j)] T
[0021]
[0022] Among them D i (j) represents the vector D i The jth element in .
[0023] Furthermore, the positioning service provider uses the key generation algorithm of the inner product function mechanism and the encryption algorithm to generate the vector D i The key and ciphertext, where for the vector D i Use the master key msk1 to generate the key sk encrypted by the inner product function Di and ciphertext ct Di ,Right now
[0024]
[0025] Where det represents the rank of the matrix, the superscript * represents the adjoint matrix of the matrix, IPE.KeyGen is the key generation algorithm, and IPE.Encrypt is the encryption algorithm;
[0026] Using the same method, for vector C j , U and V generate the corresponding key sk Cj ,sk U ,sk V and ciphertext ct Cj ,ctU ,ct V ;Right now:
[0027]
[0028] The positioning service provider will generate the key and ciphertext encrypted by the inner product function {sk Di ,ct Di ,sk Cj ,ct Cj ,sk U ,ct U ,sk V ,ct V |i=1,2,…,m-1,j=1,2,…,n}, and the public parameter pp encrypted by the inner product function are uploaded to the CSP.
[0029] Furthermore, the specific processing process of the online stage is as follows:
[0030] Step 3.1: The user requests a location service from the location service provider. After being authenticated by the location service provider, the user obtains the parameters pp, msk1, msk2 of the inner product encryption mechanism, as well as the pre-transformation factor r of the multiplication transformation.
[0031] Step 3.2: The user obtains the measurement vector W through time measurement or time difference measurement, and generates a random multiplication factor k;
[0032] Step 3.3, the cloud service provider sends sk to the user Di ,i=1,2,…,m-1, at the same time, the user randomly generates a coordinate translation vector X t =[x t1 ,x t2 ,…,x tn ] T , and use msk1 to generate X t The ciphertext ct of the inner product function confidentiality mechanism Xt ;
[0033] Step 3.4, user decrypts sk Di and ct Xt , get the inner product of the vectors associated with the two, and construct the offset vector S = [s1, s2, ..., s m-1 ] T ;
[0034] The user then uses the offset vector S and the multiplication factor k to correct the measurement vector W and obtain the corrected measurement vector W t for:
[0035] W t =k 2 W-2qS
[0036] in
[0037]
[0038] Step 3.5, the user W t Use msk2 to calculate the key of the inner product function encryption mechanism and get:
[0039]
[0040] And sk Wt and q are sent to CSP to request online positioning service;
[0041] In step 3.6, CSP uses the inner product function decryption algorithm to calculate the inner product of the vectors decomposed by the least squares positioning formula. The least squares calculation formula is:
[0042]
[0043] in Represents the least squares positioning result, the matrix A contains the anchor point information, and the vector b contains the user's measurement information; CSP respectively T A and A T b. Perform matrix decomposition and express the result as the inner product of the vector. Then, use the decryption algorithm encrypted by the inner product function to calculate the required inner product value, complete the positioning calculation, and return the positioning result to the user.
[0044] In step 3.7, after receiving the positioning result, the user performs multiplication transformation and inverse transformation of translation transformation to obtain the real positioning result.
[0045] Furthermore, in step 3.3, the ciphertext ct Xt The calculation formula is as follows:
[0046]
[0047] Furthermore, the user uses the following inner product function encryption decryption algorithm to decrypt sk Di and ct Xt , get the inner product of the vectors associated with the two <D i ,X t >,i=1,2,…,m-1;
[0048] s i = <D i ,X t >=dlog(e(sk Di _K1,ct Xt _C1),e(sk Di _K2,ct Xt _C2))
[0049] Where e(g1,g2) represents a bilinear mapping operation, and dlog(g,h) represents a discrete logarithm operation, that is, finding an integer z such that g z =h holds.
[0050] Furthermore, in step 3.6, A T The decomposition and calculation method of A is:
[0051] A T A=[a ij ],i,j=1,2,…n
[0052] a ij =q 2 *dlog(e(sk Ci _K1,ct Cj _C1),e(sk Ci _K2,ct cj _C2))
[0053] A T The decomposition and calculation method of b is:
[0054] A T b=B1-B2-B3
[0055] where B1∈R n , the calculation method of the j-th element B1(j), j=1,2,…,n in B1 is:
[0056] B1(j)=q 3 *dlog(e(sk Cj _K1,ct U _C1),e(sk Cj _K2,ct U _C2))
[0057] B2∈R n , the j-th element B2(j), j=1,2,…,n in B2 is calculated as follows:
[0058] B2(j)=q 3 *dlog(e(sk cj _K1,ct V _C1),e(sk Cj _K2,ct V _C2))
[0059] B3∈R n , the j-th element B3(j), j=1,2,…,n in B3 is calculated as follows:
[0060] B3(j)=q*dlog(e(skWt _K1,ct Cj _C1),e(sk Wt _K2,ct Cj _C2))
[0061] The cloud service provider calculates A through the above decomposition and decryption process T A and A T b. Complete positioning calculation.
[0062] Furthermore, in step 3.7, the user receives the location result returned by the cloud service provider. Then, perform the following inverse transformation to get the true position X u :
[0063]
[0064] The present invention also provides a ranging and positioning privacy protection system based on inner product function encryption in a cloud environment, including a processor and a memory, the memory is used to store program instructions, and the processor is used to call the stored instructions in the memory to execute a ranging and positioning privacy protection method based on inner product function encryption in a cloud environment as described in the above scheme.
[0065] Compared with other methods, the present invention has the following advantages:
[0066] First, the present invention designs a privacy-preserving ranging and positioning solution in a cloud environment. Compared to user-server ranging solutions, this invention effectively leverages the abundant computing resources of the cloud environment, reducing computational overhead on the user side and deployment and maintenance costs for positioning service providers. Second, the present invention proposes a privacy-preserving positioning method based on inner product function encryption and transformation. This method decomposes the least squares positioning algorithm into the basic form of the inner product calculation between measurement information and anchor point information through matrix decomposition. This is encrypted and protected using an inner product function encryption mechanism. The cloud service provider then uses a decryption algorithm to complete positioning without leaking any information other than the inner product, thus protecting the security of the measurement and anchor point information. Furthermore, the anchor point and measurement information are transformed, so that the cloud service provider only obtains the transformed positioning result and cannot obtain the user's actual location, thus protecting the privacy of the user's positioning results. Compared to methods such as homomorphic encryption and secure multi-party computation, the inner product function encryption mechanism ensures security while reducing computational and communication overhead. Compared to location privacy protection methods based on k-anonymity, this transformation-based method offers the security of a "one-time, one-key" algorithm and eliminates the need for k-fold repeated computation, thus achieving a secure and efficient indoor positioning solution in a cloud environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 This is a general schematic diagram of privacy-preserving indoor positioning according to an embodiment of the present invention;
[0068] Figure 2 This is a specific processing flow chart of the offline phase of an embodiment of the present invention;
[0069] Figure 3 This is a flowchart of a specific process of measuring information in the online phase according to an embodiment of the present invention;
[0070] Figure 4 This is a specific processing flow chart of the cloud service provider in the online stage according to an embodiment of the present invention. DETAILED DESCRIPTION
[0071] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings.
[0072] The embodiment of the present invention provides an indoor positioning method based on inner product function encryption in a cloud environment. The specific implementation is divided into three stages. The overall schematic diagram of the scheme is as follows: Figure 1 As shown, the present invention involves three parties: users, positioning service providers (IPSPs) and cloud service providers (CSPs), and specifically includes the following three stages:
[0073] During the initialization phase, the positioning service provider generates the parameter information required by the system, including the public parameter pp and two keys msk1 and msk2 of the inner product function encryption mechanism, as well as the pre-transformation factor r used for multiplication transformation;
[0074] In the offline phase, the positioning service provider transforms and encrypts the anchor point information, and uploads the generated ciphertext and key encrypted by the inner product function, as well as the public parameter pp, to the cloud service provider;
[0075] In the online phase, after the mobile terminal measures the distance vector to each anchor point, it performs multiplication and translation transformations, and uses the inner product function encryption mechanism to generate ciphertext for the transformed measurement information, which is then sent to the cloud service provider to request positioning. The cloud service provider executes the positioning algorithm on the encrypted measurement information and encrypted anchor point information, and uses the decryption algorithm of the inner product function encryption mechanism to obtain the inner product of the vector, completing the position estimation process and obtaining the transformed positioning result. The user then obtains the actual positioning result through inverse transformation.
[0076] The specific implementation process of the three stages is described in detail below.
[0077] Phase 1: Initialization phase.
[0078] Step 1.1: The positioning service provider generates a bilinear group (G1, G2, G T ,e), where G1,G2,G T is a cyclic group, g1 and g2 are the generators of G1 and G2 respectively, and e represents the transition from groups G1 and G2 to G TAccording to the dimension n of the positioning space and the number of anchor points m of the positioning service provider, we randomly sample the n-level and m-1-level reversible matrices B1 and B2 from the universal linear group, and calculate their adjoint matrices respectively. and Finally, we get the public parameter pp=(G1,G2,G T ,e) and master key
[0079]
[0080] In step 1.2, the positioning service provider randomly generates a real number as the pre-transformation factor r.
[0081] Phase 2: Offline phase, the positioning service provider transforms and encrypts the anchor information. The specific processing flow of the offline phase is as follows: Figure 2 Assume that the positioning database of the positioning service provider is DB={X i =[x i1 ,x i2 ,…,x in ] T |i=1,2,…,m}. X i is the position coordinate of the i-th anchor point, X m is the coordinate of the reference anchor point, x ij ,i=1,2,…,m,j=1,2,…,n is the jth coordinate component of the i-th anchor point coordinate, n is the spatial dimension of the coordinate, and m is the number of anchor points.
[0082] Step 2.1: The positioning service provider multiplies the position coordinates of each anchor point using the pre-transformation factor r to obtain X′ i =rX i ,i=1,2,…,m.
[0083] Step 2.2: The positioning service provider calculates the coordinate difference vector D of the first m-1 positioning anchor points relative to the reference anchor point on the transformed anchor point coordinates. i =X′ i -X′ m ,i=1,2,…,m-1, component difference vector C of the positioning anchor point relative to the reference anchor point j =[D1(j),D2(j),…D m-1 (j)] T ,j=1,2,…,n, 2-normalized square vector of anchor point coordinates and
[0084] In step 2.3, the key generation algorithm IPE.KeyGen and the encryption algorithm IPE.Encrypt of the inner product function encryption mechanism are used to obtain the key and ciphertext of the vector in step 2.2, where det represents the rank of the matrix and the superscript * represents the adjoint matrix of the matrix.
[0085]
[0086] in,
[0087] (sk Di _K1,sk Di _K2), (ct Di _C1,ct Di _C2), (sk Cj _K1,sk Cj _K2), (ct Cj _C1,ct Cj _C2), (sk U _K1,sk U _K2), (ct U _C1,ct U _C2), (sk V _K1,sk V _K2), (ct V _C1,ct V _C2) are the first and second parts in the right bracket respectively;
[0088] Step 2.4, the positioning service provider will generate the key and ciphertext {sk Di ,ct Di ,sk Cj ,ct Cj ,sk U ,ct U ,sk V ,ct V |i=1,2,…,m-1,j=1,2,…,n}, and the public parameter pp encrypted by the inner product function are uploaded to the CSP.
[0089] Phase 3: Online phase.
[0090] In step 3.1, the positioning service provider sends the parameters pp, msk1, msk2 of the inner product encryption mechanism and the pre-transformation factor r of the multiplication transformation to the authenticated trusted user.
[0091] Step 3.2: The user measures the distance d between each anchor point i ,i=1,2,…,m, construct distance vector And generate a random real number as the multiplication factor k. Next, the user transforms and encrypts the measurement information. The specific processing flow is as follows: Figure 3 shown.
[0092] Step 3.3, the cloud service provider sends sk to the user Di ,i=1,2,…,m-1. At the same time, the user generates an n-dimensional real vector as the coordinate translation vector X t =[x t1 ,x t2 ,…,x tn ] T , and use msk1 to generate X t The ciphertext ct of the inner product function confidentiality mechanism Xt ,Right now:
[0093]
[0094] Step 3.4, the user uses the decryption algorithm encrypted by the inner product function to decrypt sk Di and ct Xt , get the inner product of the vectors associated with the two <D i ,X t >, i=1,2,…,m-1, construct the offset vector S=[s1,s2,…,s m-1 ] T ,in:
[0095] s i = <D i ,X t >=dlog(e(sk Di _K1,ct Xt _C1),e(sk Di _K2,ct Xt _C2))
[0096] Where e(g1,g2) represents a bilinear mapping operation, and dlog(g,h) represents a discrete logarithm operation, that is, finding an integer z such that g z =h holds; due to the nature of inner product function encryption, the decryption algorithm can only obtain the inner product of the ciphertext and the vector associated with the key, but cannot obtain any other information. Therefore, the user cannot obtain any information about the anchor point position from the inner product function ciphertext of the anchor point information.
[0097] The user uses the offset vector S and the multiplication factor k to correct the measurement vector W and obtain the corrected measurement vector W t for:
[0098] W t =k 2 W-2qS
[0099] in
[0100]
[0101] Step 3.5, the user W t Use msk2 to calculate the key of the inner product function encryption mechanism and get:
[0102]
[0103] Then sk Wt and q are sent to CSP to request online positioning service.
[0104] In step 3.6, the cloud service provider uses the decryption algorithm of the inner product function encryption mechanism to calculate A by calculating the inner product of the decomposed vector. T A and A T b, and then get the positioning result The specific processing procedures are as follows Figure 4 As shown. Among them:
[0105] A T A=[a ij ],i,j=1,2,…n
[0106] a ij =q 2 *dlog(e(sk Ci _K1,ct Cj _C1),e(sk Ci _K2,ct Cj _C2))
[0107] A T b=B1-B2-B3
[0108] where B1, B2, B3∈R n The calculation method of its j-th element B1(j), B2(j), B3(j), j=1,2,…,n is:
[0109] B1(j)=q 3 *dlog(e(sk Cj _K1,ct U _C1),e(sk Cj _K2,ct U _C2))
[0110] B2(j)=q 3 *dlog(e(sk Cj _K1,ct V _C1),e(sk cj _K2,ct V _C2))
[0111] B3(j)=q*dlog(e(sk Wt _K1,ct cj _C1),e(sk Wt _K2,ct Cj _C2))
[0112] The cloud service provider calculates the least squares estimation result of the user's location The inner product function encryption mechanism allows cloud service providers to calculate the inner product of vectors to complete positioning without leaking the user's measurement information or the positioning service provider's anchor database information. Furthermore, the location obtained by the cloud service provider is the result of multiplication and translation transformations, thus ensuring the privacy of the user's positioning results.
[0113] Step 3.7: The user receives the location result returned by the cloud service provider Then, perform the following inverse transformation to get the true position X u :
[0114]
[0115] After the above steps, compared with the method based on homomorphic encryption, the present invention reduces the computational time by 87.72%, the communication overhead by 94.95%, and the positioning error by 17.61%.
[0116] On the other hand, an embodiment of the present invention also provides a ranging and positioning privacy protection system based on inner product function encryption in a cloud environment, including a processor and a memory, the memory being used to store program instructions, and the processor being used to call the stored instructions in the memory to execute a ranging and positioning privacy protection method based on inner product function encryption in a cloud environment as described in the above scheme.
[0117] The above content is a further detailed description of the present invention in conjunction with the preferred embodiment, and the specific implementation of the present invention should not be considered to be limited to these descriptions. Those skilled in the art should understand that various modifications can be made to the details without departing from the scope of the appended claims, and all should be considered to fall within the scope of protection of the present invention.
Claims
1. A ranging and positioning privacy protection method based on inner product function encryption in a cloud environment, characterized by: Involving three parties: users, positioning service providers (IPSPs) and cloud service providers (CSPs), the process includes the following three stages: During the initialization phase, the positioning service provider generates the parameter information required by the system, including the public parameter pp and two keys msk1 and msk2 of the inner product function encryption mechanism, as well as the pre-transformation factor r used for multiplication transformation; In the offline phase, the positioning service provider uses the pre-transformation factor r to perform multiplication and encryption on the anchor point information, and uploads the generated inner product function encrypted ciphertext and key, as well as the public parameter pp, to the cloud service provider; In the online phase, after the mobile terminal measures the distance vector to each anchor point, it performs multiplication and translation transformations. The transformed measurement information is encrypted using the inner product function encryption mechanism to generate ciphertext, which is then sent to the cloud service provider to request positioning. The cloud service provider then executes the positioning algorithm on the encrypted measurement information and the encrypted anchor point information, using the decryption algorithm of the inner product function encryption mechanism to obtain the inner product of the vectors, completing the position estimation process and obtaining the transformed positioning result. The user then obtains the actual positioning result through the inverse transformation. The specific processing process of the online stage is as follows: Step 3.1: The user requests a location service from the location service provider. After being authenticated by the location service provider, the user obtains the parameters pp, msk1, msk2 of the inner product encryption mechanism, as well as the pre-transformation factor r of the multiplication transformation. Step 3.2: The user obtains the measurement vector W through time measurement or time difference measurement, and generates a random multiplication factor k; Step 3.3, the cloud service provider sends sk to the user Di ,i=1,2,…,m-1,sk Di As the key; at the same time, the user randomly generates a coordinate translation vector X t =[x t1 ,x t2 ,…,x tn ] T , and use msk1 to generate X t The ciphertext ct of the inner product function confidentiality mechanism Xt ; Step 3.4, user decrypts sk Di and ct Xt , get the inner product of the vectors associated with the two, and construct the offset vector S = [s1, s2, ..., s m-1 ] T ; The user then uses the offset vector S and the multiplication factor k to correct the measurement vector W and obtain the corrected measurement vector W t for: IN t =k 2 W-2qS in Step 3.5, the user W t Use msk2 to calculate the key of the inner product function encryption mechanism and get: And sk Wt and q are sent to CSP to request online positioning service; In step 3.6, CSP uses the inner product function decryption algorithm to calculate the inner product of the vectors decomposed by the least squares positioning formula. The least squares calculation formula is: in Represents the least squares positioning result, the matrix A contains the anchor point information, and the vector b contains the user's measurement information; CSP respectively T A and A T b. Perform matrix decomposition and express the result as the inner product of the vector. Then, use the decryption algorithm encrypted by the inner product function to calculate the required inner product value, complete the positioning calculation, and return the positioning result to the user. In step 3.7, after receiving the positioning result, the user performs multiplication transformation and inverse transformation of translation transformation to obtain the real positioning result.
2. The method for protecting privacy of ranging and positioning based on inner product function encryption in a cloud environment according to claim 1, characterized in that: The initialization phase specifically includes: The positioning service provider generates a bilinear group (G1, G2, G T ,e), where G1,G2,G T is a cyclic group, g1 and g2 are the generators of G1 and G2 respectively, and e represents the transition from groups G1 and G2 to G T The bilinear map is randomly sampled twice from the universal linear group to obtain n-level and m-1 reversible matrices B1 and B2 respectively, and the adjoint matrices of B1 and B2 are calculated respectively. and The final public parameters pp and master keys msk1 and msk2 are: pp=(G1,G2,G T ,e) The positioning service provider randomly generates a real number as the pre-transformation factor r.
3. The ranging and positioning privacy protection method based on inner product function encryption in a cloud environment according to claim 1, characterized in that: In the offline phase, it is assumed that the positioning database of the positioning service provider is DB={X i =[x i1 ,x i2 ,…,x in ] T |i=1,2,…,m}, where X i is the position coordinate of the i-th anchor point, X m is the coordinate of the reference anchor point, x ij ,i=1,2,…,m,j=1,2,…,n is the jth coordinate component of the i-th anchor point coordinate, n is the spatial dimension of the coordinate, and m is the number of anchor points; The positioning service provider multiplies the position coordinates of each anchor point using the pre-transformation factor r to obtain X i ′ =rX i ,i=1,2,…,m; The positioning service provider calculates the coordinate difference vector D of the first m-1 positioning anchor points relative to the reference anchor point i ,i=1,2,…,m-1, component difference vector C of the positioning anchor point relative to the reference anchor point j ,j=1,2,…,n, the 2-normalized square vectors U and V of the anchor point coordinates are calculated as follows: D i =X′ i -X′ m C j =[D1(j),D2(j),…D m-1 (j)] T Among them D i (j) represents the vector D i The jth element in .
4. The method for protecting privacy of ranging and positioning based on inner product function encryption in a cloud environment according to claim 3, characterized in that: The positioning service provider uses the key generation algorithm of the inner product function mechanism and the encryption algorithm to generate the vector D i The key and ciphertext, where for the vector D i Use the master key msk1 to generate the key sk encrypted by the inner product function Di and ciphertext ct Di ,Right now Where det represents the rank of the matrix, the superscript * represents the adjoint matrix of the matrix, IPE.KeyGen is the key generation algorithm, and IPE.Enctypt is the encryption algorithm; Using the same method, for vector C j , U and V generate the corresponding key sk Cj ,sk U ,sk V and ciphertext ct Cj ,ct U ,ct V ;Right now: The positioning service provider will generate the key and ciphertext encrypted by the inner product function {sk Di ,ct Di ,sk Cj ,ct Cj ,sk U ,ct U ,sk V ,ct V |i=1,2,…,m-1,j=1,2,…,n}, and the public parameter pp encrypted by the inner product function are uploaded to the CSP.
5. The ranging and positioning privacy protection method based on inner product function encryption in a cloud environment according to claim 1, characterized in that: In step 3.3, the ciphertext ct Xt The calculation formula is as follows:
6. The ranging and positioning privacy protection method based on inner product function encryption in a cloud environment according to claim 1, characterized in that: In step 3.4, the user uses the following inner product function encryption decryption algorithm to decrypt sk Di and ct Xt , get the inner product of the vectors associated with the two <D i ,X t >,i=1,2,…,m-1; s i = <D i ,X t >=dlog(e(sk Di _K1,ct xt _C1),e(sk Di _K2,ct Xt _C2)) Where e(g1,g2) represents a bilinear mapping operation, and dlog(g,h) represents a discrete logarithm operation, that is, finding an integer z such that g z =h holds.
7. The method for protecting privacy of ranging and positioning based on inner product function encryption in a cloud environment according to claim 1, characterized in that: In step 3.6, A T The decomposition and calculation method of A is: A T A=[a ij ],i,j=1,2,…n yes ij =q 2 *dlog(e(sk Ci _K1,ct Cj _C1),e9sk ci _K2,ct cj _C2)) A T The decomposition and calculation method of b is: <h2 style=";text-align:left;direction:ltr">A<h2 style=";text-align:left;direction:ltr"> T <h2 style=";text-align:left;direction:ltr"> b=B1-B2-B3 where B1∈R n , the calculation method of the j-th element B1(j), j=1,2,…,n in B1 is: B1(j)=q 3 *dlog(e(sk Cj _K1,ct U _C1),e(sk Cj _K2,ct U _C2)) B2∈R n , the j-th element B2(j), j=1,2,…,n in B2 is calculated as follows: B2(j)=q 3 *dlog(e(sk Cj _K1,ct V _C1),e(sk Cj _K2,ct V _C2)) B3∈R n , the j-th element B3(j), j=1,2,…,n in B3 is calculated as follows: B3(j)=q*dlog(e(sk Wt _K1,ct Cj _C1),e(sk Wt _K2,ct Cj _C2)) The cloud service provider calculates A through the above decomposition and decryption process T A and A T b. Complete positioning calculation.
8. The ranging and positioning privacy protection method based on inner product function encryption in a cloud environment according to claim 1, characterized in that: In step 3.7, the user receives the location result returned by the cloud service provider Then, perform the following inverse transformation to get the true position X u :
9. A ranging and positioning privacy protection system based on inner product function encryption in a cloud environment, characterized by: It includes a processor and a memory, the memory is used to store program instructions, and the processor is used to call the stored instructions in the memory to execute a ranging and positioning privacy protection method based on inner product function encryption in a cloud environment as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Efficient privacy protection method for ranging and locating of anchor node
CN105828432A
Circular range query method and system in cloud environment based on position privacy protection
CN111555861A