An integrity audit method and related device in an edge computing environment
Through edge devices, the digital signature and homomorphic verification tags of files are calculated and sent, combined with the complete query set generated by the verification end, the edge server calculates and transmits audit evidence, and the verification end makes final judgments, solving the problem of difficult data integrity in the edge computing environment, and realizing integrity audit in data transmission and storage processes.
Patent Information
- Application Number
- CN202410968959.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-18
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-07-18
AI Technical Summary
In an edge computing environment, when data sent by edge devices are stored on edge servers, data integrity is difficult to be effectively audited, resulting in the intactness of data during transmission and storage.
The digital signature and homomorphic verification tags of files are calculated by edge devices and send the file, digital signature and homomorphic verification tags to the edge server. The verification side generates a complete query set and sends it to the edge server. The edge server calculates audit evidence based on digital signatures, homomorphic verification tags and complete query sets, and sends the digital signatures and audit evidence to the verification side. The verification side determines whether the edge server stores files intact based on digital signatures and audit evidence.
It realizes an effective audit of whether the edge server completely stores the data sent by the edge device in an edge computing environment, ensuring the integrity of the data during transmission and storage.
Smart Images

Figure CN119011203B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of edge computing technology, and in particular, to an integrity auditing method and related devices in an edge computing environment. Background Art
[0002] In the era of the Internet of Everything, for edge Internet of Things devices (i.e., edge devices) such as smart home appliances, temperature sensors, and humidity sensors, if the data collected is still processed in a centralized manner by a cloud computing center, the following two major problems will be faced: (1) For edge devices with high real-time requirements, the tolerance for data latency is usually less than 5 ms. By using the cloud computing center for processing, the consequences such as result latency caused by channel load problems must be borne. (2) Edge devices often record a large amount of private sensitive information, and the cloud computing center cannot provide absolute security guarantees. Therefore, in the Internet of Things environment, the concept of edge computing is proposed.
[0003] Edge computing is a new computing model that performs computing at the network edge, where data is computed and stored on devices (i.e., edge servers) close to the edge devices, and the computing boundary includes any computing resources and network resources between the edge devices and the cloud computing center path. Currently, with the rapid increase in the types and quantities of Internet of Things devices, in the edge computing environment, the data of edge devices is sent in whole or in part to the edge server for processing and storage via the edge network, and data integrity faces challenges. Therefore, there is an urgent need for an integrity auditing technology that can determine whether the edge server stores the data sent by the edge devices completely. Summary of the Invention
[0004] The purpose of this application is to provide an integrity auditing method and related devices in an edge computing environment, which can complete the integrity auditing of whether the edge server stores the data sent by the edge devices completely.
[0005] To achieve the above purpose, this application provides the following solutions:
[0006] In the first aspect, this application provides an integrity auditing method in an edge computing environment. The integrity auditing method in the edge computing environment includes:
[0007] The edge server obtains the file sent by the edge device, the digital signature of the file, and the homomorphic verification tag, and obtains the integrity query set sent by the verification end; the integrity query set includes a first random number set, a second random number set, and a third random number;
[0008] The edge server calculates audit evidence based on the digital signature, the homomorphic verification tag, and the complete property query set, and sends the digital signature and the audit evidence to the verification end; the audit evidence includes tag evidence, data evidence, and additional evidence; the verification end is used to determine whether the edge server stores the file completely based on the digital signature and the audit evidence.
[0009] In a second aspect, the present application provides an integrity audit method in an edge computing environment. The integrity audit method in the edge computing environment includes:
[0010] The verification end sends a complete property query set to the edge server; the complete property query set includes a first random number set, a second random number set, and a third random number.
[0011] The verification end obtains the digital signature and audit data sent by the edge server; the audit evidence is calculated by the edge server based on the digital signature and the homomorphic verification tag sent by the edge device and the complete property query set, the digital signature and the homomorphic verification tag are calculated by the edge device based on the file sent to the edge server, and the audit evidence includes tag evidence, data evidence, and additional evidence.
[0012] The verification end determines whether the edge server stores the file completely based on the digital signature and the audit evidence.
[0013] In a third aspect, the present application provides an integrity audit system in an edge computing environment. The integrity audit system in the edge computing environment includes:
[0014] An edge device, configured to calculate the digital signature and the homomorphic verification tag of a file, and send the file, the digital signature, and the homomorphic verification tag to the edge server.
[0015] A verification end, configured to generate a complete property query set and send the complete property query set to the edge server; the complete property query set includes a first random number set, a second random number set, and a third random number.
[0016] An edge server, configured to calculate audit evidence based on the digital signature, the homomorphic verification tag, and the complete property query set, and send the digital signature and the audit evidence to the verification end; the audit evidence includes tag evidence, data evidence, and additional evidence.
[0017] The verification end is further configured to determine whether the edge server stores the file completely based on the digital signature and the audit evidence.
[0018] In a fourth aspect, the present application provides a computer device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the integrity audit method in an edge computing environment described above.
[0019] In a fifth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the integrity audit method in an edge computing environment described in any one of the above.
[0020] In a sixth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the integrity audit method in an edge computing environment described in any one of the above.
[0021] According to the specific embodiments provided in this application, this application discloses the following technical effects:
[0022] The present application provides an integrity audit method and related devices in an edge computing environment. The edge device calculates the digital signature and homomorphic verification tag of the file, and sends the file, digital signature and homomorphic verification tag to the edge server. The verification end generates an integrity challenge set and sends the integrity challenge set to the edge server. The edge server calculates the audit evidence based on the digital signature, homomorphic verification tag and integrity challenge set, and sends the digital signature and audit evidence to the verification end. The verification end determines whether the edge server stores the file completely based on the digital signature and audit evidence. Through the cooperation of the edge device, the edge server and the verification end, the integrity audit of whether the edge server stores the data sent by the edge device is completed. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0024] Figure 1 A schematic diagram of a system model of an integrity audit system in an edge computing environment provided in Example 1 of the present application.
[0025] Figure 2 A flowchart of an integrity audit method in an edge computing environment provided in Example 2 of the present application.
[0026] Figure 3 A flowchart of an integrity audit method in an edge computing environment provided in Example 3 of the present application.
[0027] Figure 4 A schematic diagram of the structure of a computer device provided in Example 4 of the present application. DETAILED DESCRIPTION
[0028] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0029] Example 1
[0030] This embodiment provides an integrity audit system in an edge computing environment, such as Figure 1 As shown, the integrity audit system in the edge computing environment includes:
[0031] The edge device is used to calculate the digital signature and homomorphic verification tag of the file, and send the file, digital signature and homomorphic verification tag to the edge server.
[0032] The verification end is used to generate an integrity challenge set and send the integrity challenge set to the edge server, where the integrity challenge set includes a first random number set, a second random number set and a third random number.
[0033] The edge server is used to calculate the audit evidence based on the digital signature, homomorphic verification tag and integrity query set, and send the digital signature and audit evidence to the verification end. The audit evidence includes label evidence, data evidence and additional evidence.
[0034] The verification end is also used to determine whether the edge server stores the file completely based on the digital signature and audit evidence.
[0035] In this embodiment, the edge device first calculates and obtains various keys and system public parameters, including:
[0036] (1) The edge device selects a set of random vectors as follows:
[0037] α=(α1,...,α j ,...,α m ),α j =a j ,j∈[1,m];
[0038] Among them, α is a random vector; α jis the random number corresponding to the jth data slice, m is the number of data slices obtained by dividing the data block, and the data block is obtained by dividing the file (that is, the data sent by the edge device to the edge server); the constant is a prime field containing non-zero elements.
[0039] (2) The edge device sets the key s0 of the pseudo-random permutation function.
[0040] (3) Setting the signature private key on the edge device and private key msk=x, where Sig sk is the signature private key, msk is the private key, constant
[0041] (4) Edge device calculates signature public key and public key mpk=g x , where Sig pk is the signature public key, g is the generator of the multiplication cyclic group G; mpk is the public key.
[0042] (5) The edge device discloses the system public parameters pp = (G, G T ,p,e,g,H1,H,mpk,Sig pk ), and the private key (α, s0, msk, sig sk ) is kept privately, where pp is the system public parameter, G and G T are all multiplicative cyclic groups, and the bilinear map G×G→G T , → represents mapping, p is the order of the multiplication cyclic group G; e is the bilinear mapping function; g is the generator of the multiplication cyclic group G; H1 and H are both hash functions, hash function H:{0,1} * →G represents the operation result of the hash function H in the multiplication cycle group G.
[0043] In order to prevent unencrypted files from being maliciously tampered with during transmission over the network channel and to ensure the integrity of file data during the communication transmission phase, the edge device of this embodiment needs to calculate the digital signature of the file, specifically including:
[0044] (1) The edge device selects two random numbers for signing: sh∈G and Among them, sh and sr are both random numbers.
[0045] (2) The edge device calculates digital signature 1 (i.e., the first signature) and digital signature 2 (i.e., the second signature) based on the signature private key and system public parameters.
[0046] The first signature calculation formula is:
[0047]
[0048] Among them, Sig1 is the first signature; sh is a random number, sh∈G, G is a multiplication cycle group; Sig sk is the signature private key; H1() is the hash function; F is the file; sr is the random number.
[0049] The second signature calculation formula is:
[0050] Sig2=g sr ;
[0051] Among them, Sig2 is the second signature; g is the generator of the multiplication cyclic group G.
[0052] The digital signature includes the first signature and the second signature. The digital signature of file F is expressed as:
[0053] Sig F =(Sig1, Sig2);
[0054] Among them, Sig F For digital signature.
[0055] (3) The edge device sends <F,Sig via the network channel F >To the edge server.
[0056] In this embodiment, the edge device calculates the homomorphic verification tag of the file F, specifically including:
[0057] (1) The edge device uses data sharding technology to shard the file F. After sharding, the file F can be expressed as F = {F1, ..., F i ,...,F n} 1≤i≤n , where n is the number of data blocks obtained by dividing the file F, and the i-th data block F of the file i ={F i1 ,..F ij ,...F im} 1≤i≤n,1≤j≤m , then F={{F 11 ,..F 1j ,...F 1m},...,{F i1 ,..F ij ,...F im}...,{F n1 ,..F nj ,...F nm}} 1≤i≤n,1≤j≤m , m is the number of data slices obtained by dividing the data block, F ijis the jth data slice of the i-th data block of the file. It should be noted that i and j represent the indexes of the data block and data slice respectively, that is, 1≤i≤n, 1≤j≤m.
[0058] (2) Based on the random vector α=(α1,...,α j ,...,α m ) 1≤j≤m , edge device calculates β=(β1,...β i ,...β n ), where β is the pseudo-random vector of file F, β i is a pseudo-random set of the i-th data block of the file, β i =(β i1 ,...β ij ...,β im ) 1≤i≤n,1≤j≤m , β ij The calculation formula is:
[0059]
[0060] Among them, β ij is the permutation result obtained by pseudo-randomly permuting the j-th data slice of the ith data block; is a pseudo-random permutation function, a pseudo-random permutation function Representative execution After that, the permutation result consists of only 0 and 1, and the number of bits is log2(m). key represents the key of the pseudo-random permutation function, and its value is s0. m is the number of data slices obtained by dividing the data block. s0 is the key of the pseudo-random permutation function. || represents connection. α j is the random number corresponding to the j-th data piece.
[0061] (3) For all F = {F1, ..., F i ,...,F n} 1≤i≤n , the edge device calculates the blinded result m obtained by blinding the i-th data block of the file i , the calculation formula is as follows:
[0062]
[0063] Among them, m i is the blinding result obtained by blinding the i-th data block of the file; F i is the i-th data block of the file; β i is a pseudo-random set of the i-th data block of the file; m is the number of data slices obtained by dividing the data block; F ij is the jth data slice of the i-th data block of the file.
[0064] (4) For all m i(1≤i≤n) , the edge device calculates the label σ of the i-th data block of the file i , the calculation formula is as follows:
[0065]
[0066] Among them, σ i is the label of the i-th data block of the file; H() is the hash function; Sig F is a digital signature; Fid is a file identifier.
[0067] At this point, the homomorphic verification tag is:
[0068] Θ={σ i} 1≤i≤n ;
[0069] Among them, Θ is the homomorphic verification label; n is the number of data blocks obtained by dividing the file.
[0070] (5) The edge device sends the homomorphic verification tag Θ to the edge server.
[0071] In this embodiment, considering that the outsourced edge data (i.e., files) of the edge device needs to be transmitted to the edge server through a public network channel, and the edge server completes the calculation and storage processing, security needs to be considered. In addition, due to concerns about the computing power of the edge device, a lightweight digital signature is added as a means to ensure the integrity of the transmitted data. In addition, this embodiment constructs a homomorphic verification tag for the outsourced edge data based on the vector dot product, which is very friendly to edge devices with limited computing performance, thereby enabling lightweight calculation of digital signatures and homomorphic verification tags. After calculating the digital signature and homomorphic verification tag of the file, the edge device sends the file, digital signature and homomorphic verification tag to the edge server.
[0072] In this embodiment, during the integrity verification phase, the verification end initiates an integrity challenge to the edge server, specifically generates an integrity challenge set, and sends the integrity challenge set to the edge server. The generation process of the integrity challenge set specifically includes:
[0073] (1) The verification end obtains the digital signature from the edge server.
[0074] (2) The verification end selects c random numbers to form a first random number set Q that satisfies n is the number of data blocks obtained by dividing the file. This step is equivalent to randomly selecting c labels i of the data blocks obtained by dividing the file. For example, n is 10 and c is 3. In this embodiment, three random numbers (1, 3, 5) of i=1, i=3 and i=5 can be randomly selected to form a first random number set.
[0075] (3) The verification end selects a second random number Where i∈Q, v i is the second random number corresponding to the i-th data block of the file, and c second random numbers constitute a second random number set.
[0076] (4) The verification end selects a third random number
[0077] (5) The verifier sends the integrity query set chal = {(i,v i ) i∈Q ,t} to the edge server, where chal is the integrity challenge set, (i) i∈Q is the first random number set, (v i ) i∈Q is the second random number set, and t is the third random number.
[0078] In this embodiment, the edge server calculates the audit evidence based on the digital signature sent by the edge device, the homomorphic verification tag, and the complete property query set sent by the verification end, specifically including:
[0079] (1) The edge server calculates the label evidence. The calculation formula is as follows:
[0080]
[0081] Where T is the label evidence; Q is the first random number set, including the labels i of the data blocks obtained by randomly selecting c data blocks to divide the file; e() is the bilinear mapping function; σ i is the label of the i-th data block of the file, determined based on the homomorphic verification label; mpk is the public key; δ i is the random number of the i-th data block of the file, δ i =v i t,v i is the second random number corresponding to the i-th data block of the file, c second random numbers constitute a second random number set; t is the third random number.
[0082] (2) The edge server selects a random mask value Among them, r1 is the random mask value.
[0083] (3) The edge server calculates data evidence using the following formula:
[0084] λ=∑ i∈Q m i v i +r1;
[0085] Among them, λ is the data evidence; m i is the blinding result obtained by blinding the i-th data block of the file, determined based on the homomorphic verification label; r1 is the random mask value.
[0086] (4) The edge server calculates additional evidence using the following formula:
[0087]
[0088] Among them, Ω is the additional evidence; H() is the hash function; Sig F is a digital signature; Fid is a file identifier.
[0089] (5) The edge server returns the audit evidence P = {T, λ, Ω} to the verification end, where P is the audit evidence.
[0090] In this embodiment, the verification end This integrity judgment formula verifies the correctness of the audit evidence. The digital signature and the audit evidence are substituted into the integrity judgment formula. If the equality sign of the integrity judgment formula holds, the verification is passed, indicating that the edge server has correctly executed the storage operation. At this time, the edge server has completely stored the file. Otherwise, if the equality sign of the integrity judgment formula does not hold, the verification is not passed. At this time, the edge server has not completely stored the file.
[0091] When all the parameters in the integrity judgment formula are correct, the equality sign in the integrity judgment formula must be valid. The following is the derivation process:
[0092]
[0093]
[0094] During the integrity verification process, this embodiment takes into account the privacy of outsourced edge data and adds means to prevent the verification end from probing data privacy. Specifically, it only needs to send a digital signature and audit evidence to the verification end, and the verification end substitutes the digital signature and audit evidence into the integrity judgment formula for auditing. The verification process is a lightweight verification process and audit privacy protection is implemented at the same time.
[0095] This embodiment provides an integrity audit system that supports privacy protection, lightweight computing and verification in an edge computing environment, including an edge device, an edge server and a verification terminal. In the edge computing environment, it achieves the comprehensive goals of transmission integrity, lightweight computing, lightweight verification and audit privacy protection.
[0096] Example 2
[0097] This embodiment provides an integrity audit method in an edge computing environment, such as Figure 2 As shown, the integrity audit method in the edge computing environment includes:
[0098] S1: The edge server obtains the file sent by the edge device and the digital signature and homomorphic verification tag of the file, and obtains the integrity challenge set sent by the verification end; the integrity challenge set includes a first random number set, a second random number set and a third random number.
[0099] S2: The edge server calculates the audit evidence based on the digital signature, the homomorphic verification tag and the integrity challenge set, and sends the digital signature and the audit evidence to the verification end; the audit evidence includes tag evidence, data evidence and additional evidence; the verification end is used to determine whether the edge server stores the file completely based on the digital signature and the audit evidence.
[0100] In this embodiment, the digital signature includes a first signature and a second signature. The first signature is calculated by the edge device based on a first signature calculation formula, and the second signature is calculated by the edge device based on a second signature calculation formula.
[0101] The first signature calculation formula is:
[0102]
[0103] Among them, Sig1 is the first signature; sh is a random number, sh∈G, G is a multiplication cycle group; Sig sk is the signature private key; H1() is the hash function; F is the file; sr is the random number.
[0104] The second signature calculation formula is:
[0105] Sig2=g sr ;
[0106] Among them, Sig2 is the second signature; g is the generator of the multiplication cyclic group G.
[0107] In this embodiment, the homomorphic verification tag is:
[0108] Θ={σ i} 1≤i≤n ;
[0109] Among them, Θ is the homomorphic verification label; σ i is the label of the i-th data block of the file; n is the number of data blocks obtained by dividing the file.
[0110]
[0111] Where H() is the hash function; Sig F is a digital signature; Fid is a file identifier; m i is the blinding result obtained by blinding the i-th data block of the file.
[0112]
[0113] Among them, F i is the i-th data block of the file; β i is a pseudo-random set of the i-th data block of the file; m is the number of data slices obtained by dividing the data block; F ij is the jth data piece of the i-th data block of the file; β ij is the permutation result obtained by pseudo-randomly permuting the j-th data slice of the ith data block.
[0114]
[0115] in, is a pseudo-random permutation function, s0 is the key of the pseudo-random permutation function; α j is the random number corresponding to the j-th data piece.
[0116] In this embodiment, the edge server calculates the audit evidence based on the digital signature, the homomorphic verification tag and the integrity challenge set, specifically including: the edge server takes the digital signature, the homomorphic verification tag and the integrity challenge set as input, calculates the label evidence using the label evidence calculation formula, calculates the data evidence using the data evidence calculation formula, and calculates the additional evidence using the additional evidence calculation formula.
[0117] The label evidence calculation formula is:
[0118]
[0119] Where T is the label evidence; Q is the first random number set, including the labels i of the data blocks obtained by randomly selecting c data blocks to divide the file; e() is the bilinear mapping function; σ i is the label of the i-th data block of the file, determined based on the homomorphic verification label; mpk is the public key; δ i is the random number of the i-th data block of the file, δ i =v i t,v i is the second random number corresponding to the i-th data block of the file, c second random numbers constitute a second random number set; t is the third random number.
[0120] The formula for calculating data evidence is:
[0121] λ=Σ i∈Q m i v i +r1;
[0122] Among them, λ is the data evidence; m i is the blinding result obtained by blinding the i-th data block of the file, determined based on the homomorphic verification label; r1 is the random mask value.
[0123] The calculation formula for additional evidence is:
[0124]
[0125] Among them, Ω is the additional evidence; H() is the hash function; Sig F is a digital signature; Fid is a file identifier.
[0126] Example 3
[0127] This embodiment provides an integrity audit method in an edge computing environment, such as Figure 3 As shown, the integrity audit method in the edge computing environment includes:
[0128] T1: The verification end sends an integrity challenge set to the edge server; the integrity challenge set includes a first random number set, a second random number set and a third random number.
[0129] T2: The verification end obtains the digital signature and audit data sent by the edge server; the audit evidence is calculated by the edge server based on the digital signature and homomorphic verification tag sent by the edge device and the integrity challenge set, the digital signature and the homomorphic verification tag are calculated by the edge device based on the file sent to the edge server, and the audit evidence includes label evidence, data evidence and additional evidence.
[0130] T3: The verification end determines whether the edge server stores the file completely based on the digital signature and the audit evidence.
[0131] In this embodiment, the verification end determines whether the edge server stores the file completely based on the digital signature and the audit evidence, specifically including: the verification end substitutes the digital signature and the audit evidence into the integrity judgment formula to determine whether the equal sign of the integrity judgment formula holds; if so, the edge server stores the file completely; if not, the edge server does not store the file completely.
[0132] The integrity judgment formula is:
[0133]
[0134] Among them, Ω is additional evidence; T is label evidence; Indicates whether the equality sign holds; e() is a bilinear mapping function; H() is a hash function; Sig F is the digital signature; Fid is the file identifier; λ is the data evidence; mpk is the public key; t is the third random number.
[0135] Example 4
[0136] In an exemplary embodiment, a computer device is provided. The computer device may be a server or a terminal. The internal structure diagram thereof may be as follows: Figure 4 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an integrity audit method in an edge computing environment is implemented.
[0137] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0138] In an exemplary embodiment, a computer device is also provided, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the integrity audit method in the edge computing environment described in Example 2 or the integrity audit method in the edge computing environment described in Example 3.
[0139] Example 5
[0140] An embodiment of the present application provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements the integrity audit method in the edge computing environment described in Example 2 or the integrity audit method in the edge computing environment described in Example 3.
[0141] Example 6
[0142] An embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the integrity audit method in the edge computing environment described in Example 2 or the integrity audit method in the edge computing environment described in Example 3.
[0143] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0144] The technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0145] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, according to the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.
Claims
1. An integrity audit method in an edge computing environment, characterized in that: The integrity audit method in the edge computing environment includes: The edge server obtains the file sent by the edge device and the digital signature and homomorphic verification tag of the file, and obtains the integrity challenge set sent by the verification end; the integrity challenge set includes the first random number set, the second random number set and the third random number; The edge server calculates the audit evidence based on the digital signature, the homomorphic verification tag and the integrity challenge set, and sends the digital signature and the audit evidence to the verification end; the audit evidence includes tag evidence, data evidence and additional evidence; the verification end is used to determine whether the edge server stores the file completely based on the digital signature and the audit evidence; The digital signature includes a first signature and a second signature; the first signature is calculated by the edge device based on a first signature calculation formula, and the second signature is calculated by the edge device based on a second signature calculation formula; The first signature calculation formula is: ; in, Sign for the first one; is a random number, , is a multiplicative cyclic group; Is the signature private key; is the first hash function; For files; is a random number; The second signature calculation formula is: ; in, Sign for the second; is the multiplicative cyclic group The generator of The homomorphic verification tag is: ; in, Verify the label for homomorphism; For the file i The label of each data block; n The number of data blocks obtained by dividing the file; ; in, is a hash function; For digital signature; Represents a connection; is the file identifier; For the file i The blinded result obtained by performing blind calculation on the data blocks; ; in, For the file i data blocks; For the file i A pseudo-random collection of data blocks; m is the number of data slices obtained by dividing the data block; For the file i The first data block j Data slices; For the i The first data block j The permutation result obtained by pseudo-randomly permuting data slices; ; in, is a pseudo-random permutation function, is the key of the pseudo-random permutation function; is the random number corresponding to the j-th data piece.
2. The integrity audit method in the edge computing environment according to claim 1 is characterized in that: The edge server calculates the audit evidence based on the digital signature, the homomorphic verification tag and the integrity challenge set, specifically including: The edge server uses the digital signature, the homomorphic verification tag and the integrity challenge set as input, calculates the tag evidence using the tag evidence calculation formula, calculates the data evidence using the data evidence calculation formula, and calculates the additional evidence using the additional evidence calculation formula; The label evidence calculation formula is: ; in, For label evidence; is the first random number set, including the labels of the c randomly selected data blocks obtained by dividing the file i ; is a bilinear mapping function; For the file i The label of each data block is determined based on the homomorphic verification label; is the public key; For the file i The random number of the data block, , For the file i The second random numbers corresponding to the data blocks, c second random numbers constitute a second random number set; t is the third random number; The data evidence calculation formula is: ; in, For data evidence; For the file i The blinded result obtained by blinding calculation of each data block is determined based on the homomorphic verification label; is a random mask value; The additional evidence calculation formula is: ; in, To provide additional evidence; is a hash function; For digital signature; Represents a connection; Is the file identifier.
3. An integrity audit method in an edge computing environment, characterized in that: The integrity audit method in the edge computing environment includes: The verification end sends an integrity challenge set to the edge server; the integrity challenge set includes a first random number set, a second random number set and a third random number; the edge server is used to return the audit evidence to the verification end; The verification end obtains the digital signature and audit data sent by the edge server; the audit evidence is calculated by the edge server based on the digital signature and homomorphic verification tag sent by the edge device and the integrity challenge set, the digital signature and the homomorphic verification tag are calculated by the edge device based on the file sent to the edge server, and the audit evidence includes label evidence, data evidence and additional evidence; The verification end determines whether the edge server stores the file completely based on the digital signature and the audit evidence; The verification end determines whether the edge server stores the file completely based on the digital signature and the audit evidence, specifically including: The verification end substitutes the digital signature and the audit evidence into the integrity judgment formula to judge whether the equality sign of the integrity judgment formula is established; if established, the edge server completely stores the file; if not established, the edge server does not completely store the file; The integrity judgment formula is: ; in, To provide additional evidence; For label evidence; Indicates whether the equality sign holds; is a bilinear mapping function; is a hash function; For digital signature; Represents a connection; is the file identifier; For data evidence; is the public key; t is the third random number.
4. An integrity audit system in an edge computing environment, characterized in that: The integrity audit system in the edge computing environment includes: an edge device, configured to calculate a digital signature and a homomorphic verification tag of a file, and send the file, the digital signature and the homomorphic verification tag to an edge server; The verification end is used to generate an integrity challenge set and send the integrity challenge set to the edge server; the integrity challenge set includes a first random number set, a second random number set and a third random number; The edge server is used to calculate the audit evidence based on the digital signature, the homomorphic verification tag and the integrity challenge set, and send the digital signature and the audit evidence to the verification end; the audit evidence includes tag evidence, data evidence and additional evidence; The verification end is further used to determine whether the edge server stores the file completely based on the digital signature and the audit evidence; The digital signature includes a first signature and a second signature; the first signature is calculated by the edge device based on a first signature calculation formula, and the second signature is calculated by the edge device based on a second signature calculation formula; The first signature calculation formula is: ; in, Sign for the first one; is a random number, , is a multiplicative cyclic group; Is the signature private key; is the first hash function; For files; is a random number; The second signature calculation formula is: ; in, Sign for the second; is the multiplicative cyclic group The generator of The homomorphic verification tag is: ; in, Verify the label for homomorphism; For the file i The label of each data block; n The number of data blocks obtained by dividing the file; ; in, is a hash function; For digital signature; Represents a connection; is the file identifier; For the file i The blinded result obtained by performing blind calculation on the data blocks; ; in, For the file i data blocks; For the file i A pseudo-random collection of data blocks; m is the number of data slices obtained by dividing the data block; For the file i The first data block j Data slices; For the i The first data block j The permutation result obtained by pseudo-randomly permuting data slices; ; in, is a pseudo-random permutation function, is the key of the pseudo-random permutation function; is the random number corresponding to the j-th data piece.
5. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the integrity audit method in an edge computing environment as described in any one of claims 1 to 2, or to implement the integrity audit method in an edge computing environment as described in claim 3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the integrity audit method in the edge computing environment described in any one of claims 1-2, or implements the integrity audit method in the edge computing environment described in claim 3.
7. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, it implements the integrity audit method in the edge computing environment described in any one of claims 1-2, or implements the integrity audit method in the edge computing environment described in claim 3.
Citation Information
Patent Citations
Blockchain remote data auditing supervision method and system, computer equipment and terminal
CN112152797A
Dynamic cloud auditing method based on homomorphic hash function and virtual index
CN117235342A