A User Collaboration Privacy Protection Method Based on Verifiable Secret Sharing

By constructing anonymous collaboration groups and incentivizing user participation through a reputation value mechanism, and employing multinomial encryption and commitment value verification, the problems of low collaboration efficiency and low security are solved, achieving efficient user privacy protection and enhanced security.

CN118784218BActive Publication Date: 2025-12-02JIAMUSI UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410820578.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-24
Publication Date
2025-12-02
Estimated Expiration
2044-06-24

AI Technical Summary

Technical Problem

Existing privacy protection methods based on collaborative technologies suffer from low collaboration efficiency and low security. Mutual distrust among collaborating users leads to ineffective protection of user privacy, and collusion between collaborating users and service providers may lead to the theft of location information.

Method used

Anonymous collaboration groups are constructed using a verifiable secret sharing method. User participation is incentivized through a reputation value mechanism. The correctness of sub-encrypted information is verified using multinomial encryption and commitment values. When a threshold condition is met, the service provider decrypts and reconstructs the query information and provides rewards to participating users.

Benefits of technology

It improves collaboration efficiency, ensures user privacy and security, reduces server query time, and prevents privacy leaks and collusion attacks among collaborating users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118784218B_ABST
    Figure CN118784218B_ABST
Patent Text Reader

Abstract

This invention discloses a user collaboration privacy protection method based on verifiable secret sharing, relating to the field of collaborative privacy protection. The invention aims to address the problems of low collaboration efficiency and low security in existing privacy protection methods. Specifically, the invention involves: constructing an anonymous collaboration group, requesting user Uq to encrypt query information S' into m encrypted subqueries; Uq then utilizes the polynomial coefficients a in the encrypted subqueries... j The system obtains the commitment value of collaborating users and broadcasts it to them. Uq sends sub-encrypted information and a verification key to the collaborating users, and sends its real location and sub-encrypted information to LSP. When the sub-encrypted information is correct, the collaborating user sends the sub-encrypted information and its real location to LSP. When the number of sub-encrypted messages received by LSP is greater than or equal to the threshold number of collaborating users, LSP decrypts the sub-encrypted information. LSP uses Uq's public key to encrypt the query information and sends the encrypted result to each user in the anonymous collaboration group, while simultaneously assisting users in obtaining rewards. This invention is used to protect user privacy in collaborative settings.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of collaborative privacy protection, and in particular to a method for protecting user collaborative privacy based on verifiable secret sharing. Background Technology

[0002] In recent years, the revolution of 5G networks has driven the widespread application of wireless technology, leading to the boom of location-based services (LBS). Applications providing services through location information are becoming increasingly common, making life more convenient. However, the location information submitted by users contains a large amount of hidden background information. Attackers can use this information to infer users' interests, habits, and other details, posing a threat to them. Therefore, the security of location information is of paramount importance.

[0003] In the field of location-based service (LBS) privacy protection, collaborative technology, as an effective personal privacy protection technique, is primarily proposed to address service bottlenecks and attack targets. Collaborative technology improves the theory and practice of privacy protection in distributed architectures, providing users with better privacy protection services. Existing privacy protection strategies based on collaborative technology typically rely on the trust between collaborating users, assuming that all collaborating users are trustworthy, willing to provide services and transmit query sets to the LBS server, that all queries can be sent to the LBS server within a limited time interval, and that collaborating users cannot collude with untrusted LBS servers, etc. However, the following problems arise in practical applications: 1. Collaborating users may distrust each other and be unwilling to participate in the collaborative user group, resulting in users only being able to send their overall privacy information directly to the server. If the server is curious about user privacy, user privacy security cannot be guaranteed. 2. Users may not submit query sets to the LBS service in a timely manner, which increases the server's query time, leading to low collaboration efficiency. 3. If collaborating users collude with service providers to obtain user location information, they may steal each other's privacy during the collaboration process, thereby endangering user privacy security. Therefore, current privacy protection methods based on collaborative technologies still suffer from low collaboration efficiency and low security. Summary of the Invention

[0004] The purpose of this invention is to address the problems of low collaboration efficiency and low security in existing privacy protection methods, and to propose a user collaboration privacy protection method based on verifiable secret sharing.

[0005] A user collaboration privacy protection method based on verifiable secret sharing is as follows:

[0006] Step 1: Construct an anonymous collaboration group containing one requesting user and m-1 collaborating users. The requesting user Uq uses a polynomial to query the information S′={D,T',E}. kEncrypt the m subqueries into encrypted information;

[0007] Where D is the query content, T' is the time interval between each query, and E k Indicates the requesting user's public key;

[0008] Step 2: Request the user to use the polynomial coefficient 'a' in the encrypted information from the subquery. j Obtain the commitment values ​​of collaborating users in the anonymous collaboration group, and then broadcast the polynomial coefficient 'a' from the encrypted subquery information to the collaborating users in the anonymous collaboration group. j and the corresponding commitment value;

[0009] Step 3: The user requests m-1 sub-encrypted messages and the verification key to send to m-1 collaborating users in the anonymous collaboration group. At the same time, the user requests the real location information L and 1 sub-encrypted message to the service provider LSP. Each collaborating user verifies the correctness of the sub-encrypted message based on the verification key and the collaborating user's commitment value. If the sub-encrypted message is correct, the collaborating user sends the sub-encrypted message and the collaborating user's real location to the LSP. If the sub-encrypted message is incorrect, no operation is performed.

[0010] Step 4: When the number of sub-encrypted messages received by the service provider LSP is greater than or equal to the threshold t of the number of collaborating users, the LSP decrypts the received sub-encrypted messages and reconstructs the query information. The LSP uses the public key of the requesting user to encrypt the reconstructed query information and sends the encrypted result to each user in the anonymous collaborating group. At the same time, the collaborating users receive a reward.

[0011] Furthermore, the construction in step one involves an anonymous collaboration group comprising one requesting user and m-1 collaborating users, specifically as follows:

[0012] User Uq requests collaboration within region R, declaring the required number of collaborating users as m-1 and the number of collaborating users who will receive a reward as t. Users within region R willing to participate in the collaboration return messages to user Uq, obtaining the reputation value of each willing user and the number of users whose reputation values ​​exceed the reputation value threshold. If the number of users whose reputation values ​​exceed the reputation value threshold is greater than or equal to m-1, then the users whose reputation values ​​exceed the reputation value threshold form an anonymous collaboration group. If the number of users whose reputation values ​​exceed the reputation value threshold is less than m-1, then the information of the users whose reputation values ​​exceed the reputation value threshold is stored, and collaboration requests are continued to be initiated until the number of users willing to participate in the collaboration and whose reputation values ​​exceed the reputation value threshold is greater than or equal to m-1.

[0013] The reputation value of a user when they first participate in collaboration is a random value in the range (0, 1). After the collaboration is completed, the reputation value of the collaborating user for their next collaboration is obtained.

[0014] Furthermore, the reputation value of the collaborating user for the next collaboration is specifically as follows:

[0015]

[0016] OTV UqUc =ω DT ×DT UqUc +ω IT ×IT UqUc +ω ET ×ET UqUc

[0017] ω DT +ω IT +ω ET =1

[0018] in, It is the reputation value of user Uc for the next collaboration, DI Uc It is a group of users who have direct trust in UC, OTV UqUc It represents the overall trust of Uq in Uc, where λ is the time decay factor. This represents user Uq's current reputation value, cur is the current time, and nxt is the time of the next collaboration. It is the user's current reputation value (Uc), ET UqUc It is an additional trust value between Uq and Uc, IT UqUc It is the indirect trust value of Uq to Uc, DT UqUc ω is the direct trust value of Uq to Uc. DT It is the weight of the direct trust value, ω IT It is the weight of the indirect trust value, ω ET It is the weight of the additional trust value.

[0019] Furthermore, the direct trust value DT of Uq to Uc UqUc Specifically:

[0020]

[0021] Among them, DT UqUc It is the direct trust value of Uq to Uc, α UqUc β is the number of times Uq participates in the creation of anonymous collaboration groups initiated by Uc. UqUc It represents the number of times Uc did not participate in the anonymous collaboration group established by Uq, where T is the harmonic factor and X is the number of times Uc did not participate in the establishment of the collaboration group. UqUc Z is the communication frequency between Uq and Uc. Uq It is the set of users in the anonymous collaboration group that participated in the request initiated by Uq. It is set Z Uq The highest frequency for communication in China, X UqU' It is the communication frequency between Uq and U', YUqUC It is the communication length between Uq and Uc. It is set Z Uq The maximum length of communication information in Y UqU' It is the communication length between Uq and U', where U' is Z. Uq Users in the middle.

[0022] Furthermore, the indirect trust value IT of Uq to Uc UqUc Specifically

[0023]

[0024] Among them, IT UqUc It is the indirect trust value of Uq to Uc, DI Uc Ur is a set of users who have direct trust in Uc, Ur ≠ Uq, Ur is a DI Uc Users in DT UrUc It is Ur's direct trust value to Uc, SIM UqUr It is the similarity between Uq and Ur when assessing direct trust in other users, Z Ur It is the set of users in the anonymous collaborative group that participates in the construction of the Ur-initiated request, where U is Z. Uq ∩Z Ur In the user group, "U" is Z Ur Users in DT UqU T is the direct trust value of Uq to U. Uq It is the average of historical comprehensive trust values ​​assessed by Uq. It is the average of the historical comprehensive trust scores assessed by Ur, DT UqU' DT is the direct trust value of Uq to U'. UrU” It is Ur's direct trust value for "U".

[0025] Furthermore, Uq has an additional trust value ET for Uc. UqUc Specifically:

[0026]

[0027] in, It is the previous direct trust value of Uq to Uc when the anonymous collaboration was last built, X UqUc It is the communication frequency between Uq and Uc, ET UqUc It is the additional trust value that Uq has for Uc.

[0028] Furthermore, in step one, the requesting user Uq uses a polynomial to query the information S′={D,T',E}. k The encryption is performed on m subqueries. The encrypted information of the i-th subquery is:

[0029] Si '=F(x i )=a0+...+a i-1 x i-1 i-1 +a i x i i

[0030] Where, a0=S', x i It is the identity information of the i-th collaborating user, a 1, ,...,a m-1 ,a m It is a random integer, i∈[1,m], where m is the total number of encrypted subqueries, S' i F(x) i ) is the encrypted information of the i-th subquery, m = 2t-1, and t is the threshold for the number of collaborating users.

[0031] Furthermore, in step one, the requesting user utilizes the polynomial coefficient 'a' in the subquery encrypted information. j The user's commitment value is obtained as follows:

[0032]

[0033] Where j∈[0,t-1], p is a prime number, g is a generator, and a j B is the coefficient of the (j+1)th term in the polynomial of the subquery's encrypted information. j It is the commitment value of the j-th collaborating user.

[0034] Furthermore, in step three, each collaborating user verifies the correctness of the sub-encrypted information based on the verification key and the collaborating user's commitment value, specifically as follows:

[0035] Collaborating users obtain verification keys:

[0036]

[0037] Collaborating users calculate whether the verification key equation holds true based on their commitment value. If true, the sub-encrypted information is correct; otherwise, the sub-encrypted information is incorrect.

[0038] Furthermore, when the number of sub-encrypted messages received by the service provider LSP in step four is greater than or equal to the threshold t of the number of collaborating users, the LSP decrypts the received sub-encrypted messages and reconstructs the query information. The LSP then encrypts the reconstructed query information using the requesting user's public key and sends the encryption result to each user in the anonymous collaborating group, specifically:

[0039] Step 4.1: When the number of sub-encrypted messages received by the service provider LSP is greater than or equal to the threshold t of the number of cooperating users, the LSP decrypts the received sub-encrypted messages to obtain the secret S', specifically as follows:

[0040] First, obtain the decryption formula:

[0041]

[0042] Where i',j'∈[1,t], i',j' are the labels of the sub-encrypted information received by the LSP, and S' j' It is the encrypted subquery information received by LSP, where x is an unknown variable. j' It is the identity of the j'th collaborating user, x i' It is the identity of the i'th collaborating user;

[0043] Then let y i' =F(x) i' ), x = 0, obtain the secret S' = F(0);

[0044] Where F(x) i' ) is the sub-encrypted message sent by the i'th collaborating user;

[0045] Step 42: The LSP combines the secret S', the real location of the cooperating user who sent the sub-encrypted information to the LSP, and the real location of the requesting user into a set S, and uses the public key E. k Encrypt S, and send the encrypted S to each requesting user and the cooperating user who sends the sub-encrypted information to the LSP.

[0046] Step 43: The requesting user decrypts the encrypted S using the key pair to obtain S. If the real locations of both the requesting user and the collaborating user in S are located within R, the requesting user distributes the extra trust value used when building the anonymous group as a reward to the collaborating user corresponding to the location information contained in S.

[0047] The beneficial effects of this invention are as follows:

[0048] This invention proposes a verifiable secret sharing method for user collaboration, introducing a verifiable secret sharing scheme into privacy protection based on a trust mechanism. It utilizes the trust mechanism to construct qualified anonymous collaboration groups and incentivizes collaborative users by increasing competition for submitting query sets. The trust mechanism incentivizes collaborative users to submit query sets within a limited time interval, making users more willing to participate in collaboration. It also enables collaborative users to submit query sets to the LSP server promptly, reducing server query time and improving collaboration efficiency. Furthermore, this invention can construct effective anonymous groups on untrusted servers, addressing privacy leaks and collusion attacks among collaborative users, preventing users from stealing each other's privacy during collaboration, and enhancing the security of privacy protection based on user collaboration. Attached Figure Description

[0049] Figure 1 This is a flowchart of the present invention;

[0050] Figure 2 A graph showing the relationship between collaborative users and reputation scores. Detailed Implementation

[0051] This invention includes two entities: a user and an LSP (Location-Based Service Provider). The user represents a mobile user equipped with positioning and communication devices, capable of providing accurate location information and communicating with others. The LSP is a service provider that stores location-related Points of Interest (POIs) and provides precise services to LBS users. The invention will now be described with reference to specific embodiments.

[0052] Specific implementation method one: as follows Figure 1 As shown, the specific process of a user collaboration privacy protection method based on verifiable secret sharing in this embodiment is as follows:

[0053] Step 1: Request user Uq to set parameter values ​​(t, m, p), then construct an anonymous collaboration group containing one requesting user and m-1 collaborating users, and submit the query information S′={D, T', E k Encrypt the information into m subqueries:

[0054] Where D is the query content, T' is the time interval between each query, and E k This represents the public key of the requesting user, where p is a prime number, t is the threshold for the number of collaborating users, and m is the total number of encrypted messages in the subquery.

[0055] Step 11: Request user Uq to set parameter values ​​(t, m, p), and then create an anonymous collaboration group:

[0056] First, request user Uq to set parameter values ​​(t,m,p);

[0057] Then, user Uq sends a collaboration request within region R, declaring that the number of users required to collaborate is m-1 and the number of users who can receive rewards is t. Users within region R who are willing to participate in the collaboration return a message to user Uq, obtaining the reputation value of each user who is willing to participate in the collaboration, and obtaining the number of users whose reputation value exceeds the reputation value threshold. If the number of users whose reputation value exceeds the reputation value threshold is greater than or equal to m-1, then the users whose reputation value exceeds the reputation value threshold form an anonymous collaboration group. If the number of users whose reputation value exceeds the reputation value threshold is less than m-1, then the information of users whose current reputation value exceeds the reputation value threshold is stored in AG, and collaboration requests are continued to be initiated until the number of users who are willing to participate in the collaboration and whose reputation value exceeds the reputation value threshold is greater than or equal to m-1.

[0058] The user information includes: user ID and reputation score;

[0059] Each user is equipped with positioning and communication devices;

[0060] The relationship between collaborative users and reputation score is as follows: Figure 2 As shown, the user's reputation score is obtained in the following way:

[0061] Generally, trust is divided into direct trust and indirect trust. Direct trust refers to trust determined through direct communication and interaction between two parties. The frequency of communication and the length of the communication messages between the two parties can reflect their trust tendency. This paper assumes that the trust value follows a beta probability distribution. Therefore, the direct trust value of requesting user Uq for user Uc is calculated according to the following formula:

[0062]

[0063] Among them, DT UqUc It is the direct trust value of Uq to Uc, α UqUc β is the number of times Uq participates in the creation of anonymous collaboration groups initiated by Uc. UqUc It represents the number of times Uc did not participate in the anonymous collaboration group established by Uq, where T∈[0,1] and T is the harmonic factor. It is set Z Uq The highest frequency for communication in China, X UqU' It is the communication frequency between Uq and U', X UqUc It is the communication frequency between Uq and Uc. It is set Z Uq The maximum length of communication information in Y UqU' Y is the communication length between Uq and U'. UqUC Z is the communication length between Uq and Uc. Uq It is the set of users in the anonymous collaborative group that participates in the request initiated by Uq, where U' is Z. Uq Users in;

[0064] The purpose of setting the harmonic factor in this step is to adjust the weight of communication frequency and communication message length on the direct trust value, in order to alleviate the data sparsity of direct trust relationships;

[0065] This invention introduces indirect trust, reflecting the trust relationship a user acquires based on other users' direct trust in another user. Therefore, even if a user does not have a direct trust value with a particular user, it can still acquire an indirect trust value. The method for calculating the indirect trust value of Uq to Uc is as follows:

[0066]

[0067] Among them, IT UqUc It is the indirect trust value of Uq to Uc, DI Uc It is a group of users who have direct trust in Uc. Ur ≠ Uq. Ur is the recommending user. Ur is the DI. Uc Users within the system have a direct trust value for UC, DT UrUc It is Ur's direct trust value to Uc, SIM UqUr It is the similarity between Uq and Ur when assessing direct trust in other users, DT UqU It is the direct trust value of Uq to U. It is the average of historical comprehensive trust values ​​assessed by Uq. Z is the average of historical comprehensive trust values ​​assessed by Ur. Ur It is the set of users in the anonymous collaborative group that participates in the construction of the Ur-initiated request, where U is Z. Uq ∩Z Ur In the user group, "U" is Z Ur Users in DT UqU' DT is the direct trust value of Uq to U'. UrU” It is Ur's direct trust value for "U";

[0068] In this step, The initial value is 0;

[0069] To better incentivize users to actively cooperate with queries and reduce the impact of malicious behavior, this invention introduces additional trust, the additional trust value of which is as follows:

[0070]

[0071] in, It is the direct trust value of Uq to Uc when the anonymous collaboration was last built, X UqUc It is the communication frequency between Uq and Uc, ET UqUc It is the additional trust value that Uq has for Uc;

[0072] If Uq is creating an anonymous collaboration group for the first time, then It is 0.

[0073] By combining direct trust values, indirect trust values, and additional trust values ​​with different weights, the overall trust value (OTV) of Uq to Uc is calculated. UqUc As shown in the following formula:

[0074] OTV UqUc =ω DT ×DT UqUc +ω IT ×IT UqUc +ω ET ×ET UqUc (5)

[0075] ω DT +ω IT +ω ET =1(6)

[0076] Where, ω DT It is the weight of the direct trust value, ω IT It is the weight of the indirect trust value, ω ET It is the weight of the additional trust value;

[0077] If Uc participated in the construction between the current time cur and the next time nxt, then the new reputation value is the sum of the average of each aggregate trust value received by Uc during that period and the historical reputation value that decays over time. Otherwise, it is the decayed value of the historical reputation value. The user reputation value for the next collaboration is specifically:

[0078]

[0079] in, It is the reputation value of user Uc for the next collaboration, DI Uc It is a group of users who have direct trust in Uc, where λ is the time decay factor. This is the current reputation value of the collaborating Uq. `cur` is the reputation value of the current collaborating user, `cur` is the current time, and `nxt` is the time of the next collaboration. The user's reputation value is initialized to a random value in (0, 1).

[0080] This invention introduces a time decay factor λ to more accurately reflect user behavior. When a user does not actively cooperate, his or her reputation value will gradually decrease over time, thus affecting or even causing the construction of the user's anonymous group. In addition, some users accumulate high reputation values ​​through several interactions and then stop cooperating, a phenomenon that can be avoided to some extent. Therefore, introducing a decay factor can better stimulate users to actively cooperate. In addition to using reputation value to encourage users to actively cooperate with requesting users and reduce malicious users, querying users give cooperating users an extra trust value. The higher a user's reputation value, the higher their reputation value. When a user needs to perform a query, more users will be willing to cooperate. The initial reputation value of each user is a random value in (0, 1). When a user participates in cooperation for the first time, the initial reputation value is compared with the reputation value threshold to form a cooperation group. After the cooperation is completed, the reputation value of the user for the next cooperation is obtained using formula (7). The reputation value is directly called to complete the current round of cooperation in the next cooperation.

[0081] Steps 1 and 2: Query information S′={D,T,E} k Encrypt the information into m subqueries:

[0082] S i '=F(x i )=a0+...+a i-1 x i-1 i-1 +a i x i i (9)

[0083] Where, a0=S', x i It is the identity of the i-th collaborating user, a 1, ,...,a m-1 ,a m It is a random integer, i ranging from 1 to m, where m is the total number of encrypted subqueries (the number of collaborating users), S' i Here, D is the encrypted information of the i-th subquery, D is the query content, T' is the time interval between each query, and E is the encrypted information of the ith subquery. k This represents the public key of the requesting user, where m = 2t-1, and t is the threshold number of collaborating users.

[0084] In this step, if the requesting user requires at least m-1 collaborating users to summarize the true location, according to the principle of the verifiable threshold scheme, he / she must conceal the reallocation and generate query information. Then, the requesting user encrypts the generated information into m sub-queries and sends them to the collaborating users in the anonymous group, and broadcasts a commitment to the coefficients of the secret shared polynomial to the anonymous group. Simultaneously, to maintain the robustness of the scheme, the number of collaborating users must be sufficiently large to ensure that enough collaborating users are available to accurately transmit the query information.

[0085] Step 2: Request the user to use the polynomial coefficient 'a' in the encrypted information from the subquery. j Obtain the commitment values ​​of collaborating users in the anonymous collaboration group, and then broadcast the polynomial coefficient 'a' from the encrypted subquery information to the collaborating users in the anonymous collaboration group. j The commitment value of collaborating users is as follows:

[0086] Step 21: Obtain the commitment value of each collaborating user using subquery encrypted information:

[0087]

[0088] Where j∈[0,t-1], p is a prime number, and g is a generator;

[0089] Step 22: Request the user in the anonymous group to broadcast a query for the polynomial coefficient 'a' in the encrypted information to all collaborating users. j and the corresponding commitment value B j .

[0090] Step 3: The user is requested to send m-1 sub-encryption messages and the verification key to each of the m-1 collaborating users in the anonymous collaboration group. At the same time, the user is requested to send the real location information L and 1 sub-encryption message to the LSP. Each collaborating user verifies the correctness of the sub-encryption message based on the verification key, polynomial coefficients and corresponding commitment value. If the sub-encryption message is correct, the collaborating user sends the sub-encryption message and the collaborating user's location information to the LSP. If the sub-encryption message is incorrect, no operation is performed.

[0091] Each collaborating user verifies the correctness of the sub-encrypted information based on the verification key and commitment value, specifically as follows:

[0092] Obtain the verification key as follows:

[0093]

[0094] Among them, S' i It is encrypted information;

[0095] If the verification key equation is true, it means that the current sub-encrypted information is correct; if the verification key equation is false, it means that the current sub-encrypted information is incorrect.

[0096] Step 4: When the number of sub-encrypted messages received by the service provider LSP is greater than or equal to t, it begins decrypting the sub-encrypted messages and reconstructing the query information. The LSP uses the requesting user's public key to encrypt the reconstructed query information and sends the encryption result to each collaborating user in the anonymous collaboration group. Simultaneously, the collaborating users receive a reward, specifically:

[0097] Step 4: When the number of sub-encrypted messages received by the service provider LSP is greater than or equal to t, the query information (x) is obtained. i' ,F(x i' The received sub-encrypted information is decrypted, specifically as follows:

[0098] First, obtain the decryption formula:

[0099]

[0100] Where i',j'∈[1,t], i',j' are the labels of the sub-encrypted information received by the LSP, and S' j' It is the encrypted subquery information received by LSP, where x is an unknown variable. It is a Lagrange basis function, x j' It is the identity of the j'th collaborating user, x i' It is the identity of the i'th collaborating user;

[0101] Then let y i' =F(x) i' ), x = 0, obtain the secret S' = F(0);

[0102] Where F(x) i' ) is the sub-encrypted message sent by the i'th collaborating user.

[0103] Step 42: Find the result containing the real location of the requesting user, the real location of the collaborating users, and the decryption information in the dataset stored by the service provider LSP, and form a set S with the real locations of the requesting user, the real locations of the collaborating users, and the secret S'. The service provider LSP then uses the public key E... k Encrypt the set S, and send set S to the requesting user and each cooperating user who sends sub-encrypted information to the LSP;

[0104] Step 43: The requesting user decrypts the encrypted query result set using their private key and obtains the query results. If the precise locations of both the requesting user and collaborating users in the query result set S are both within the publishing region R, the requesting user distributes t rewards to the collaborating users included in the query result set S, specifically as follows:

[0105]

[0106] This invention sets t rewards to incentivize users to participate in anonymous collaboration groups, enabling collaborative users to submit query sets to the LSP server in a timely manner, thereby reducing service string time and improving collaboration efficiency.

Claims

1. A user collaboration privacy protection method based on verifiable secret sharing, characterized in that... The specific process of the method is as follows: Step 1: Construct an anonymous collaboration group containing one requesting user and m-1 collaborating users. The requesting user Uq uses a polynomial to query the information S′={D,T',E}. k Encrypt the m subqueries into encrypted information; Where D is the query content, T' is the time interval between each query, and E k Indicates the requesting user's public key; Step 2: Request the user to use the polynomial coefficient 'a' in the encrypted information from the subquery. j Obtain the commitment values ​​of collaborating users in the anonymous collaboration group, and then broadcast the polynomial coefficient 'a' from the encrypted subquery information to the collaborating users in the anonymous collaboration group. j and the corresponding commitment value; Step 3: The user requests m-1 sub-encrypted messages and the verification key to send to m-1 collaborating users in the anonymous collaboration group. At the same time, the user requests the real location information L and 1 sub-encrypted message to the service provider LSP. Each collaborating user verifies the correctness of the sub-encrypted message based on the verification key and the collaborating user's commitment value. If the sub-encrypted message is correct, the collaborating user sends the sub-encrypted message and the collaborating user's real location to the LSP. If the sub-encrypted message is incorrect, no operation is performed. Step 4: When the number of sub-encrypted messages received by the service provider LSP is greater than or equal to the threshold t of the number of collaborating users, the LSP decrypts the received sub-encrypted messages and reconstructs the query information. The LSP uses the public key of the requesting user to encrypt the reconstructed query information and sends the encrypted result to each user in the anonymous collaborating group. At the same time, the collaborating users receive a reward.

2. The user collaboration privacy protection method based on verifiable secret sharing according to claim 1, characterized in that: The construction in step one involves an anonymous collaboration group comprising one requesting user and m-1 collaborating users, specifically as follows: User Uq requests collaboration within region R, declaring the required number of collaborating users as m-1 and the number of collaborating users who will receive a reward as t. Users within region R willing to participate in the collaboration return messages to user Uq, obtaining the reputation value of each willing user and the number of users whose reputation values ​​exceed the reputation value threshold. If the number of users whose reputation values ​​exceed the reputation value threshold is greater than or equal to m-1, then the users whose reputation values ​​exceed the reputation value threshold form an anonymous collaboration group. If the number of users whose reputation values ​​exceed the reputation value threshold is less than m-1, then the information of the users whose reputation values ​​exceed the reputation value threshold is stored, and collaboration requests are continued to be initiated until the number of users willing to participate in the collaboration and whose reputation values ​​exceed the reputation value threshold is greater than or equal to m-1. The reputation value of a user when they first participate in collaboration is a random value in the range (0, 1). After the collaboration is completed, the reputation value of the collaborating user for their next collaboration is obtained.

3. The user collaboration privacy protection method based on verifiable secret sharing according to claim 2, characterized in that: The reputation value of the collaborating user for the next collaboration is specifically as follows: OTV UqUc =ω DT ×DT UqUc +oh IT ×IT UqUc +oh ET ×ET UqUc oh DT +oh IT +oh ET =1 in, It is the reputation value of user Uc for the next collaboration, DI Uc It is a group of users who have direct trust in UC, OTV UqUc It represents the overall trust of Uq in Uc, where λ is the time decay factor. This represents user Uq's current reputation value, cur is the current time, and nxt is the time of the next collaboration. It is the user's current reputation value (Uc), ET UqUc It is an additional trust value between Uq and Uc, IT UqUc It is the indirect trust value of Uq to Uc, DT UqUc ω is the direct trust value of Uq to Uc. DT It is the weight of the direct trust value, ω IT It is the weight of the indirect trust value, ω ET It is the weight of the additional trust value.

4. The user collaboration privacy protection method based on verifiable secret sharing according to claim 3, characterized in that: Uq's direct trust value DT to Uc UqUc Specifically: Among them, DT UqUc It is the direct trust value of Uq to Uc, α UqUc β is the number of times Uq participates in the creation of anonymous collaboration groups initiated by Uc. UqUc It represents the number of times Uc did not participate in the anonymous collaboration group established by Uq, where T is the harmonic factor and X is the number of times Uc did not participate in the establishment of the collaboration group. UqUc Z is the communication frequency between Uq and Uc. Uq It is the set of users in the anonymous collaboration group that participated in the request initiated by Uq. It is set Z Uq The highest frequency for communication in China, X UqU' It is the communication frequency between Uq and U', Y UqUC It is the communication length between Uq and Uc. It is set Z Uq The maximum length of communication information in Y UqU' It is the communication length between Uq and U', where U' is Z. Uq Users in the middle.

5. The user collaboration privacy protection method based on verifiable secret sharing according to claim 4, characterized in that: The indirect trust value IT of Uq to Uc UqUc Specifically Among them, IT UqUc It is the indirect trust value of Uq to Uc, DI Uc Ur is a set of users who have direct trust in Uc, Ur ≠ Uq, Ur is a DI Uc Users in DT UrUc It is Ur's direct trust value to Uc, SIM UqUr It is the similarity between Uq and Ur when assessing direct trust in other users, Z Ur It is the set of users in the anonymous collaborative group that participates in the construction of the Ur-initiated request, where U is Z. Uq ∩Z Ur In the user group, "U" is Z Ur Users in DT UqU It is the direct trust value of Uq to U. It is the average of historical comprehensive trust values ​​assessed by Uq. It is the average of the historical comprehensive trust values ​​assessed by Ur, DT UqU' DT is the direct trust value of Uq to U'. UrU "is Ur's direct trust value to U".

6. The user collaboration privacy protection method based on verifiable secret sharing according to claim 5, characterized in that: Uq's additional trust value ET over Uc UqUc Specifically: in, It is the previous direct trust value of Uq to Uc when the anonymous collaboration was last built, X UqUc It is the communication frequency between Uq and Uc, ET UqUc It is the additional trust value that Uq has for Uc.

7. The user collaboration privacy protection method based on verifiable secret sharing according to claim 6, characterized in that: In step one, the requesting user Uq uses a polynomial to query the information S′={D,T',E}. k The encryption is performed on m subqueries. The encrypted information of the i-th subquery is: S i '=F(x i )=a0+...+a i-1 x i-1 i-1 +a i x i i Where, a0 = S', x i This is the identity information of the i-th collaborating user, a1,,...,a m-1 ,a m It is a random integer, i∈[1,m], where m is the total number of encrypted subqueries, S' i F(x) i ) is the encrypted information of the i-th subquery, m = 2t-1, and t is the threshold for the number of collaborating users.

8. The user collaboration privacy protection method based on verifiable secret sharing according to claim 7, characterized in that: In step one, the user requests the polynomial coefficient 'a' from the encrypted information in the subquery. j To obtain the user's commitment value, specifically: Where j∈[0,t-1], p is a prime number, g is a generator, and a j B is the coefficient of the (j+1)th term in the polynomial of the subquery's encrypted information. j It is the commitment value of the j-th collaborating user.

9. The user collaboration privacy protection method based on verifiable secret sharing according to claim 8, characterized in that: In step three, each collaborating user verifies the correctness of the sub-encrypted information based on the verification key and the collaborating user's commitment value, specifically as follows: Collaborating users obtain verification keys: Collaborating users calculate whether the verification key equation holds true based on their commitment value. If true, the sub-encrypted information is correct; otherwise, the sub-encrypted information is incorrect.

10. The user collaboration privacy protection method based on verifiable secret sharing according to claim 9, characterized in that: In step four, when the number of sub-encrypted messages received by the service provider LSP is greater than or equal to the threshold t of the number of collaborating users, the LSP decrypts the received sub-encrypted messages and reconstructs the query information. The LSP then encrypts the reconstructed query information using the requesting user's public key and sends the encryption result to each user in the anonymous collaborating group. Specifically: Step 4.1: When the number of sub-encrypted messages received by the service provider LSP is greater than or equal to the threshold t of the number of cooperating users, the LSP decrypts the received sub-encrypted messages to obtain the secret S', specifically as follows: First, obtain the decryption formula: Where i',j'∈[1,t], i',j' are the labels of the sub-encrypted information received by the LSP, and S' j' It is the encrypted subquery information received by LSP, where x is an unknown variable. j' It is the identity of the j'th collaborating user, x i' It is the identity of the i'th collaborating user; Then let y i' =F(x) i' ), x = 0, obtain the secret S' = F(0); Where F(x) i' ) is the sub-encrypted message sent by the i'th collaborating user; Step 42: The LSP combines the secret S', the real location of the cooperating user who sent the sub-encrypted information to the LSP, and the real location of the requesting user into a set S, and uses the public key E. k Encrypt S, and send the encrypted S to each requesting user and the cooperating user who sends the sub-encrypted information to the LSP. Step 43: The requesting user decrypts the encrypted S using the key pair to obtain S. If the real locations of both the requesting user and the collaborating user in S are located within R, the requesting user distributes the extra trust value used when building the anonymous group as a reward to the collaborating user corresponding to the location information contained in S.

Citation Information

Patent Citations

  • Collaborative location privacy protection method based on blockchain

    CN113595738A

  • Location privacy protection method based on user cooperation in distributed environment

    CN115567919A