Communication Network Information Authorized Sharing Method and System Based on Equality Testing

Through the communication network information sharing system based on equality test, the security and efficiency of information sharing in the communication network are solved using encryption algorithms and edge computing, and low overhead and efficient information sharing is realized, which is suitable for communication network equipment with low computing and low communication.

CN119652666BActive Publication Date: 2025-07-11BEIJING UNIV OF POSTS & TELECOMM
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510161307.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-07-11
Estimated Expiration
2045-02-13

AI Technical Summary

Technical Problem

The existing communication network information sharing solutions have high costs, privacy data leakage and information sharing limitations, and lack a secure and efficient data sharing solution.

Method used

Using a communication network information-authorized sharing system based on equality tests, information sharing is shared using encryption algorithms, trap gates and temporary re-encryption keys through the collaboration of cloud servers, edge proxy servers and information reporting groups, combined with edge computing to reduce the computing pressure of cloud servers and improve security and efficiency.

Benefits of technology

It improves the security and efficiency of information sharing, reduces computing and communication overhead, and is suitable for communication network equipment with low computing and low communication, ensuring the privacy and reliability of information sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652666B_ABST
    Figure CN119652666B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for authorized sharing of communication network information based on equality testing. The system includes: a cloud server, an edge proxy server, an information reporting party, and a group of information receiving parties; the information reporting party generates an information message according to the information of the geographical location where it is located, encrypts the information message through an encryption algorithm to obtain an information ciphertext, and performs equality testing; the cloud server forwards the information ciphertext that passes the equality testing to the edge proxy server, and at the same time sends a temporary authorization request to the information reporting party; after receiving the temporary authorization request, the information reporting party generates a temporary re-encryption key and sends the temporary re-encryption key to the edge proxy server; the edge proxy server performs proxy re-encryption on the information ciphertext by using the temporary re-encryption key and sends the re-encrypted ciphertext to the group of information receiving parties; the group of information receiving parties decrypts the re-encrypted ciphertext and obtains the information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information sharing in communication networks, and in particular to a method and system for authorized sharing of communication network information based on equality testing. Background Art

[0002] A communication network is a network technology that interconnects various communication devices. It plays a crucial role in intelligent communication systems. Information reporting and sharing, as one of the core applications of communication networks, aims to enhance communication security, optimize communication traffic, and improve communication experience through real-time data exchange. However, while enjoying the convenience brought by information sharing, attention should also be paid to the risk of leakage of numerous sensitive data brought by intelligent networked devices. When reporting and sharing information, sensitive data including the real-time location information of communication devices will be uploaded to cloud servers of third-party institutions, etc. If these data are improperly obtained and used, it may lead to the tracking of users' whereabouts; in addition, by analyzing the behavior data of communication devices, attackers may build user profiles, understand users' various habits and private activities, thereby further threatening users' personal security.

[0003] In existing information sharing solutions, it mainly relies on specialized communication devices and uses third-party platforms for pushing, without considering a secure, efficient, and reliable data sharing solution in the communication network scenario. On the one hand, the information reporting party needs to rely on specialized communication devices (such as the traffic information reporting device, warning sign, and traffic information processing system disclosed in Chinese Patent CN215814522U), which greatly increases the cost of information sharing, and for specialized communication devices, their reliability is also questionable. On the other hand, using third-party platforms for pushing (such as a public transportation information sharing platform disclosed in Chinese Patent CN107977474A) will lead to problems such as the leakage of personal privacy data of the information reporting party. At the same time, due to the variety of third-party platforms and the inability to achieve information sharing and data interconnection between platforms, it will lead to limitations in information sharing, and the reliability of its solution will also be greatly reduced. Summary of the Invention

[0004] In order to overcome the above defects in the prior art, the present invention provides a method and system for authorized sharing of communication network information based on equality testing, which improves the security and efficiency of information sharing.

[0005] To achieve the above object, the present invention adopts the following technical solutions, including:

[0006] A system for authorized sharing of communication network information based on equality testing, including: a cloud server, an edge proxy server, an information reporting party, and a group of information receiving parties;

[0007] The information reporting party generates an information message according to the information of its geographical location, encrypts the information message through an encryption algorithm to obtain an information ciphertext, and sends the trapdoor calculated based on the private key of the information reporting party and the information ciphertext to the cloud server and authorizes the cloud server to perform an equality test;

[0008] The cloud server forwards the information ciphertext that passes the equality test to the edge proxy server, and at the same time sends a temporary authorization request to the information reporting party;

[0009] After receiving the temporary authorization request, the information reporting party generates a temporary re-encryption key and sends the temporary re-encryption key to the edge proxy server;

[0010] The edge proxy server uses the temporary re-encryption key to perform proxy re-encryption on the information ciphertext and sends the re-encrypted ciphertext to the information receiving party group;

[0011] The information receiving party group decrypts the re-encrypted ciphertext and obtains the information.

[0012] Adopting the above solution, this solution uses an attribute-based trapdoor, and at the same time uses a shorter key. With the support of edge computing, on the one hand, it can reduce the computing pressure of the cloud server, so as to better cope with the numerous operations of future communication networks; on the other hand, the edge nodes are closer to the data receiving side, with a shorter spatial distance, greatly improving the efficiency of data sharing. Compared with the solutions of the prior art, it has lower computing overhead and communication overhead, and improves the security and efficiency of information sharing. And the solution of the present invention has higher applicability to most communication network devices with low computing and low communication.

[0013] In an embodiment of the present invention, the cloud server forwards the information ciphertext to the edge proxy server at the geographical location of the information reporting party; the information reporting party sends the temporary re-encryption key to the edge proxy server at the geographical location of the information reporting party; the edge proxy server sends the re-encrypted ciphertext to the information receiving party group within the coverage of the edge proxy server.

[0014] In an embodiment of the present invention, the system further includes a trusted authority; the trusted authority is communicatively connected to all participants in the system and is used to distribute keys to the participants in the system and provide global public parameters.

[0015] In an embodiment of the present invention, in the process of the information reporting party generating an information message according to the information of its geographical location, encrypting the information message through an encryption algorithm to obtain an information ciphertext, and sending the trapdoor calculated based on the private key of the information reporting party and the information ciphertext to the cloud server and authorizing the cloud server to perform an equality test:

[0016] The information reporting party connects the information of its geographical location with the information to be sent to obtain an information message;

[0017] Calculate a temporary authorization code through a first hash function, and use an encryption algorithm to calculate an information ciphertext through the information message, the public key of the information reporting party, and the temporary authorization code;

[0018] Calculate a trapdoor based on the private key of the information reporting party through a trapdoor function.

[0019] In an embodiment of the present invention, in the process of sending the trapdoor calculated based on the private key of the information reporting party and the information ciphertext to the cloud server and authorizing the cloud server to perform an equality test:

[0020] The cloud server performs an equality test on the received information ciphertext and trapdoor with all the information ciphertexts and corresponding trapdoors stored in the cloud server. If the test result is 1, it means that the two information ciphertext contents are the same, that is, the information has been reported and no subsequent information sharing operation is required; if the test result is 0, it means that no information ciphertext with the same content as the received information ciphertext is found, that is, the information has not been reported and subsequent information sharing operations are required, and the information ciphertext is forwarded to the edge proxy server.

[0021] In an embodiment of the present invention, the steps for the information reporting party to generate a temporary re-encryption key after receiving a temporary authorization request include:

[0022] The information reporting party calculates a first sub-key through the public key of the edge proxy server and the private key of the information reporting party based on a re-encryption key generation function, uses the calculation method of the temporary authorization code as the second sub-key, and uses the information ciphertext as the third sub-key, and combines the first sub-key, the second sub-key, and the third sub-key to obtain a re-encryption key.

[0023] In an embodiment of the present invention, in the process of the edge proxy server using the temporary re-encryption key to perform proxy re-encryption on the information ciphertext and sending the re-encrypted ciphertext to the information receiving party group, a proxy re-encryption function is used to calculate the re-encrypted ciphertext through the information ciphertext, the first sub-key, and the second sub-key, and the re-encrypted ciphertext and the third sub-key are sent to the information receiving party group.

[0024] In an embodiment of the present invention, in the process of the information receiving party group decrypting the re-encrypted ciphertext and obtaining the information, the re-encrypted ciphertext is decrypted based on the private key of the edge proxy server to obtain geographical location information and information.

[0025] In an embodiment of the present invention, the communication network is a vehicle-to-everything network, the information is traffic information, and both the information reporting party and the information receiving party are vehicles.

[0026] The present invention also provides a method for authorized sharing of communication network information based on equality testing, including an initialization phase, a registration phase of communication terminals, an information reporting phase of information reporting parties, an equality testing phase of a cloud server, a temporary re-encryption key generation phase of information reporting parties, a proxy re-encryption phase of edge proxy servers, and a decryption phase of information receiving parties;

[0027] The initialization phase includes step S1, where a trusted authority selects an asymmetric encryption algorithm, a decryption algorithm, a public-private key pair of the trusted authority, a first hash function, a second hash function, and outputs global public parameters including the first hash function, the second hash function, and the public key in the public-private key pair of the trusted authority;

[0028] The registration phase of communication terminals includes step S21, where a communication terminal registers with a trusted authority. The trusted authority obtains the unique identity information of the communication terminal, and the trusted authority uses its own quantum random number generator to generate a true random number and generates a pseudonym for the communication terminal using an encryption algorithm;

[0029] Step S22, the trusted authority selects a public-private key pair for the communication terminal and sends information including the public-private key pair information of the communication terminal and the pseudonym of the communication segment to the communication terminal;

[0030] Step S23, the communication terminal registers with the nearest edge proxy server. After registration, the communication terminal obtains the public key and node information of the edge proxy server. At the same time, the edge proxy server puts the pseudonym of information reporting party i into the registry;

[0031] The information reporting phase of information reporting parties includes step S31, where the information reporting party connects the information of its location with the information to be sent to obtain an information message;

[0032] Step S32, calculate a temporary authorization code through the first hash function; use an encryption algorithm through the information message, the public key of the information reporting party, and the temporary authorization code;

[0033] Step S33, calculate the information ciphertext. Use an encryption algorithm through the information message, the public key of the information reporting party, and the temporary authorization code to calculate the information ciphertext;

[0034] Step S34, calculate a trapdoor based on the private key of the information reporting party through a trapdoor function;

[0035] Step S35, the information reporting party uploads a message including the information ciphertext, the trapdoor, the pseudonym of the information reporting party, and the node information of the edge proxy server closest to the information reporting party to the server;

[0036] The equality test phase of the cloud server includes step S41. After the cloud server receives the message uploaded by the information reporting party, it authenticates the identity of the information reporting party and checks whether the message has been tampered with; calculates the verification value based on the second hash function through the information ciphertext, trapdoor, and pseudonym of the information reporting party, and performs signature verification based on the verification signature function through the public key of the information reporting party, verification value, and digital signature of the information ciphertext; if the signature verification is successful, it proceeds to the next step, otherwise, it directly discards the message:

[0037] Step S42, the cloud server performs an equality test on the received information ciphertext and trapdoor with all the information ciphertexts and corresponding trapdoors stored in the cloud server. If the test result is 1, it means that the two information ciphertext contents are the same, that is, the information has been reported, and there is no need to perform subsequent information sharing operations; if the test result is 0, it means that no information ciphertext with the same content as the received information ciphertext is found, that is, the information has not been reported, and subsequent information sharing operations need to be performed, and it proceeds to the next step;

[0038] Step S43, the cloud server sends a request for temporary authorization message to the information reporting party; the server sends the ciphertext to be shared to the edge proxy server according to the node information of the edge proxy server provided by the information reporting party. At the same time, the cloud server also stores the current information ciphertext and the corresponding trapdoor;

[0039] The temporary re-encryption key generation phase of the information reporting party includes step S51. The information reporting party calculates the first sub-key based on the re-encryption key generation function through the public key of the edge proxy server and the private key of the information reporting party, uses the calculation method of the temporary authorization code as the second sub-key, and uses the information ciphertext as the third sub-key, and combines the first sub-key, the second sub-key, and the third sub-key to obtain the re-encryption key;

[0040] Step S52, send the re-encryption key to the edge proxy server closest to the information reporting party;

[0041] The proxy re-encryption phase of the edge proxy server includes step S61. After the edge proxy server receives the ciphertext to be shared sent by the cloud server and the re-encryption key sent by the information reporting party, it verifies whether the second sub-key in the re-encryption key is equal to the temporary authorization code. If so, it proceeds to the next step, otherwise, it discards the re-encryption key;

[0042] Step S62, calculate the re-encrypted ciphertext through the information ciphertext, the first sub-key, and the second sub-key using the proxy re-encryption function;

[0043] Step S63, the edge proxy server sends the re-encrypted ciphertext and the third sub-key to the information receiving party group;

[0044] The decryption phase of the information recipient includes step S71 of decrypting the re-encrypted ciphertext based on the private key of the edge proxy server;

[0045] Step S72 of decrypting to obtain the geographical location information

[0046] Step S73 of decrypting to obtain the information.

[0047] The information authorization sharing method and system based on equality testing proposed by the present invention have lower computational overhead and communication overhead, and improve the security and efficiency of information sharing. And the solution of the present invention has higher applicability to most communication network devices with low computing and low communication.

[0048] The additional advantages, objects, and features of the present invention will be partially described below and will become partially apparent to those of ordinary skill in the art after studying the following. Or they can be learned according to the practice of the present invention. The objects and other advantages of the present invention can be achieved and obtained by the structures specifically pointed out in the specification and the drawings.

[0049] Those skilled in the art will understand that the objects and advantages that can be achieved by the present invention are not limited to the above specifically described, and the above and other objects that the present invention can achieve will be more clearly understood according to the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The drawings described herein are used to provide a further understanding of the present invention, form a part of this application, and do not limit the present invention.

[0051] Figure 1 It is a schematic diagram of a communication network information authorization sharing system based on equality testing in an embodiment of the present invention.

[0052] Figure 2 It is a schematic diagram of a communication network information authorization sharing method based on equality testing in an embodiment of the present invention.

[0053] Figure 3 It is a comparison chart of the computational time consumption of each solution in different stages. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0054] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0055] The relevant technical explanations in the present invention are as follows:

[0056] Equality Test: Equality test is an important tool in cryptography. It is used to verify the equality of data items while maintaining data privacy, providing strong support for privacy protection and secure computing. When outsourcing data to a cloud server to obtain powerful storage and computing capabilities, to further prevent information leakage from the not fully trusted cloud server, the data uploader will encrypt the data before outsourcing it to the cloud. This phenomenon poses a challenge to the cloud server, that is, how to perform calculations and retrievals on the encrypted outsourced data without decrypting it. Scientists have conducted a lot of research on it, such as searchable encryption that supports searching for encrypted data, fully homomorphic encryption that supports addition and multiplication on encrypted data, and public key encryption with equality test that supports equality testing on encrypted data. These methods have their own advantages. For example, the first two methods focus more on cloud computing, while the last method focuses on "testing". For example, in the application scenario of the present invention, it is necessary to test the ciphertext of the reported information and the ciphertext of the information stored in the cloud server to query whether there are equal ciphertexts of information, so as to better share information. Searchable encryption can also achieve this function, but its disadvantage is that the calculation is cumbersome and key management is required. When the key is leaked, the data security will be damaged. On the other hand, in the information reporting scenario, the message format is highly standardized and the message is short, which is more suitable for equality testing.

[0057] Trapdoor: In equality test, trapdoor is an important technical means. It can simplify the equality verification process by providing specific secret information while ensuring data privacy. Using a trapdoor can make the calculation of verifying whether two data are equal simpler in some cases. For example, through a specific secret key, it is possible to quickly verify whether two encrypted data are equal without directly decrypting them. Without using a trapdoor, under the same conditions, it will be very difficult to verify whether two data are equal. Therefore, using the trapdoor technology can also be regarded as a kind of authorization for the organization performing the equality test. That is, only by holding both the ciphertext of the information and the corresponding trapdoor can the equality test be performed.

[0058] Temporary Delegation: Temporary delegation is a permission management mechanism that allows users to obtain permissions to access resources or perform specific operations within a limited period of time. Under the premise of ensuring security and flexibility, this mechanism facilitates users to obtain necessary access rights in specific scenarios. In an information system, authorization refers to granting users the permission to access resources. Traditional authorization methods are usually valid for a long time, but in some cases, only short-term permissions are required. For example, access permissions for temporary projects, temporary access for customers or third-party suppliers, etc. Temporary delegation allows access permissions to be granted within a specific time range and automatically revoked after the time expires, thereby enhancing the security and flexibility of the system. In the present invention, a true random number generated by a quantum random generator and the communication end pseudonym PID are jointly used to generate a temporary authorization code. This temporary authorization code can only be used once, and a new temporary authorization code will be generated each time a new information message is reported. Through this design, the privacy data of the information reporting party will not be easily leaked.

[0059] Proxy Re-encryption: Proxy re-encryption is a cryptographic technique that allows a proxy to convert encrypted data from one key to encrypted data with another key without decrypting the data. This technique has important applications in data sharing and distributed systems, and can achieve secure data forwarding and re-encryption while maintaining data privacy. In traditional encryption systems, if encrypted data needs to be transferred from one user to another, the data usually needs to be decrypted first and then encrypted with a new key. This method has security risks because the plaintext data in the intermediate process may be leaked. Proxy re-encryption solves this problem. By using proxy re-encryption, the data owner can authorize a proxy to convert the encrypted data into encrypted data with another set of keys without decrypting the data. The proxy cannot obtain the plaintext content of the data during this process, ensuring the security and privacy of the data.

[0060] Re-encryption Key: The re-encryption key is a special key used in a proxy re-encryption system. This key is generated by the information sender and is used to authorize the proxy to re-encrypt its encrypted message for the receiver. At the same time, only the information sender can generate a valid re-encryption key, and this key can only be used for this ciphertext. During the re-encryption process, the proxy and other third parties cannot obtain the message content, and only the authorized receiver can decrypt the final ciphertext.

[0061] Edge Computing: Edge computing is a distributed computing architecture that moves computing, storage, and data processing functions from a central data center to edge nodes closer to the data source. This computing method aims to reduce data transmission latency, improve real-time performance and processing efficiency, and is applicable to scenarios such as the Internet of Things, smart devices, and industrial automation that require low latency and high bandwidth. In a traditional cloud computing architecture, data is transmitted from devices (such as sensors and smart devices) to a central data center for processing and storage. This model may result in high latency and bandwidth consumption, especially in applications that require real-time response, such as autonomous driving, intelligent manufacturing, and telemedicine. Edge computing decentralizes data processing capabilities to edge nodes closer to the data source, reducing the data transmission path and time, and enabling faster response and processing of data.

[0062] As Figure 1 shown, the communication network information authorized sharing system based on equality testing in this embodiment includes: a cloud server, an edge proxy server, an information reporting party, and an information receiving party group;

[0063] The information reporting party generates an information message based on the information of its geographical location, encrypts the information message through an encryption algorithm to obtain an information ciphertext, and sends the trapdoor calculated based on the private key of the information reporting party and the information ciphertext to the cloud server and authorizes the cloud server to perform equality testing;

[0064] The cloud server forwards the information ciphertext that passes the equality testing to the edge proxy server, and at the same time sends a temporary authorization request to the information reporting party;

[0065] After receiving the temporary authorization request, the information reporting party generates a temporary re-encryption key and sends the temporary re-encryption key to the edge proxy server;

[0066] The edge proxy server performs proxy re-encryption on the information ciphertext using the temporary re-encryption key and sends the re-encrypted ciphertext to the information receiving party group;

[0067] The information receiving party group decrypts the re-encrypted ciphertext and obtains the information.

[0068] Adopting the above solution, this solution uses an attribute-based trapdoor, and at the same time uses a shorter key. With the support of edge computing, on the one hand, it can relieve the computing pressure of the cloud server, so as to better cope with the numerous operations of future communication networks; on the other hand, the edge nodes are closer to the data receiving party side, with a shorter spatial distance, greatly improving the efficiency of data sharing. Compared with the solutions of the prior art, it has lower computing overhead and communication overhead, and improves the security and efficiency of information sharing. And the solution of the present invention has higher applicability to most communication network devices with low computing and low communication.

[0069] In an embodiment of the present invention, the cloud server forwards the information ciphertext to the edge proxy server at the geographical location where the information reporting party is located; the information reporting party sends the temporary re-encryption key to the edge proxy server at the geographical location where the information reporting party is located; the edge proxy server sends the re-encrypted ciphertext to the group of information recipients within the coverage area of the edge proxy server.

[0070] In the specific implementation process, the cloud server, as a semi-trusted institution, is mainly responsible for storing the information data reported by the communication terminals, performing equality tests on the information ciphertext, and forwarding the information ciphertext to the edge proxy server; the edge proxy server combines the advantages of edge computing and edge proxy servers, and provides efficient, low-latency, and secure services by processing and managing data at the network edge. It is mainly responsible for registering the information of the communication terminals operating within the service area into the registry List, proxy re-encrypting the information message sent by the cloud server, and sending it to the group of information recipients.

[0071] In the specific implementation process, for the communication terminal of the information reporting party: when the information reporting party wants to report the information at the geographical location where the current information reporting party is located (such as road condition information: communication traffic, congestion situation, etc. on the current road; accident information: location, time, severity, etc. of the communication accident; road construction information: construction section, construction time, impact on communication, etc.; communication control information: communication control measures such as traffic restrictions, road closures, detours, etc.), the driver or passenger selects the corresponding type of information and automatically obtains the geographical location data of the information reporting party, thus forming an information reporting message. Through a specified encryption algorithm, the message is encrypted and a corresponding trapdoor is generated to authorize the cloud server to perform an equality test. After receiving the temporary authorization request from the cloud server, the information reporting party needs to generate a temporary re-encryption key and send it to the edge proxy server, thereby achieving a one-time authorization for this data sharing.

[0072] In the specific implementation process, for the communication terminals of the group of information recipients: this group is mainly determined by the edge proxy server. For the information provided by the information reporting party, the communication terminals in the same area as the information reporting party should be the group that receives the information first. To determine which communication terminals are in the same area as the information reporting party, the registry of the edge proxy server can be used. All communication terminals driving on the road need to register with the nearest edge proxy server to obtain relevant services. Therefore, the communication terminals in the registry of the edge proxy server mean that they are currently within the service area of the edge proxy server. For communication terminals not in the same service area, the current edge proxy server can spread the message to the surrounding edge proxy servers.

[0073] In an embodiment of the present invention, the system further includes a trusted authority; the trusted authority is communicatively connected to all participants within the system and is used to distribute keys to the participants within the system and provide global public parameters.

[0074] In the specific implementation process, the trusted authority refers to a third-party entity trusted by all participants within the system, and its main responsibility is to help manage and maintain the security and integrity of the system. In this system, the trusted authority is mainly responsible for system initialization, distributing keys to the participants within the system, generating pseudonyms (Pseudonymous ID, PID) for each communication end, and at the same time generating node information (NID, Node ID) for the edge proxy server.

[0075] In an embodiment of the present invention, in the process where the information reporting party generates an information message according to the information of its geographical location, encrypts the information message through an encryption algorithm to obtain an information ciphertext, and sends the trapdoor calculated based on the private key of the information reporting party and the information ciphertext to the cloud server and authorizes the cloud server to perform equality test:

[0076] The information reporting party connects the information of its geographical location with the information to be sent to obtain an information message;

[0077] In the specific implementation process, the information reporting party i generates an information message m i = Kw||Loc, where Kw is the information, Loc is the geographical location information where the information reporting party i is located, and || is the connection symbol;

[0078] Calculate a temporary authorization code through a first hash function, and use an encryption algorithm to calculate an information ciphertext through the information message, the public key of the information reporting party, and the temporary authorization code;

[0079] In the specific implementation process, calculate the temporary authorization code v = H1(PID i ||y), where PID i is the pseudonym of the information reporting party i, y is a random number generated by the information reporting party i, and H1 is the first hash function; use the encryption algorithm Enc to encrypt the information message m i to obtain the information ciphertext CT i = Enc(m i , v, pk i ), where pk i is the public key of the information reporting party i;

[0080] Calculate a trapdoor based on the trapdoor function through the private key of the information reporting party.

[0081] In the specific implementation process, calculate the trapdoor td i = Aut(ski ), where Aut is a trapdoor function; the information reporting party i sends the information ciphertext CT i and the corresponding trapdoor td i to the cloud server.

[0082] In an embodiment of the present invention, in the process of sending the trapdoor calculated based on the private key of the information reporting party and the information ciphertext to the cloud server and authorizing the cloud server to perform the equality test:

[0083] The cloud server performs an equality test on the received information ciphertext and trapdoor with all the information ciphertexts and the corresponding trapdoors stored in the cloud server. If the test result is 1, it means that the two information ciphertext contents are the same, that is, the information has been reported and no subsequent information sharing operation is required; if the test result is 0, it means that no information ciphertext with the same content as the received information ciphertext is found, that is, the information has not been reported and subsequent information sharing operations are required, and the information ciphertext is forwarded to the edge proxy server.

[0084] In a specific implementation process, after the cloud server receives the information ciphertext CTi and the corresponding trapdoor tdi sent by the information reporting party i, it performs an equality test Test(CTi, tdi, CTj, tdj) with all the information ciphertexts CTj and the corresponding trapdoors tdj stored in the cloud server. Test is an equality test function, and the test result is 0 or 1; the test result of 1 means that the two ciphertexts CTi and CTj have the same content, that is, the information has been reported and no subsequent information sharing operation is required; the test result of 0 means that no ciphertext with the same content as the ciphertext CTi is found, that is, the information has not been reported and subsequent information sharing operations are required, and the information ciphertext is forwarded to the edge proxy server.

[0085] In an embodiment of the present invention, the steps for the information reporting party to generate a temporary re-encryption key after receiving a temporary authorization request include:

[0086] The information reporting party calculates the first sub-key based on the re-encryption key generation function through the public key of the edge proxy server and the private key of the information reporting party, uses the calculation method of the temporary authorization code as the second sub-key, and uses the information ciphertext as the third sub-key, and combines the first sub-key, the second sub-key, and the third sub-key to obtain the re-encryption key.

[0087] In a specific implementation process, the information reporting party i calculates Rk1 = ReKeyGen(sk i , pk N ), Rk2 = v = H1(PID i ||y), Rk3 = Enc(Loc, pk N ), to obtain the temporary re-encryption key Rk = (Rk1, Rk2, Rk3); where pk Nis the public key of the edge proxy server; ReKeyGen is the re-encryption key generation function, Rk1 represents the first sub-key, Rk2 represents the second sub-key, and Rk3 represents the third sub-key.

[0088] In an embodiment of the present invention, in the process that the edge proxy server uses the temporary re-encryption key to perform proxy re-encryption on the information ciphertext and sends the re-encrypted ciphertext to the information recipient group, the proxy re-encryption function is used to calculate the re-encrypted ciphertext through the information ciphertext, the first sub-key and the second sub-key, and send the re-encrypted ciphertext and the third sub-key to the information recipient group.

[0089] In the specific implementation process, the edge proxy server receives the information ciphertext CT i sent by the cloud server and the temporary re-encryption key Rk sent by the information reporting party, and calculates the re-encrypted ciphertext C N =ReEnc(CT i , Rk1, Rk2), and sends the re-encrypted ciphertext C N and Rk3 to the information recipient group; where ReEnc is the proxy re-encryption function.

[0090] In an embodiment of the present invention, in the process that the information recipient group decrypts the re-encrypted ciphertext and obtains the information, the re-encrypted ciphertext is decrypted based on the private key of the edge proxy server to obtain the geographical location information and the information.

[0091] In the specific implementation process, the information recipient receives the re-encrypted ciphertext C N sent by the edge proxy server and uses the private key sk N of the edge proxy server to decrypt it to obtain the information message m i =Dec(C N , sk N ); where Dec is the decryption algorithm;

[0092] Decrypt Rk3 to obtain the geographical location information Loc = Dec(Rk3, pk N ), and obtain the information Kw according to the information message m i =Kw||Loc.

[0093] In an embodiment of the present invention, the communication network is a vehicle-to-everything network, the information is traffic information, and both the information reporting party and the information receiving party are vehicles.

[0094] Such as Figure 2As shown in the figure, the present invention also provides a method for authorized sharing of communication network information based on equality testing, including an initialization stage, a registration stage of a communication end, an information reporting stage of an information reporting party, an equality testing stage of a cloud server, a temporary re-encryption key generation stage of the information reporting party, a proxy re-encryption stage of an edge proxy server, and a decryption stage of an information receiving party;

[0095] The initialization stage includes step S1, where a trusted authority selects an asymmetric encryption algorithm, a decryption algorithm, a public-private key pair of the trusted authority, a first hash function, a second hash function, and outputs global public parameters including the first hash function, the second hash function, and the public key in the public-private key pair of the trusted authority;

[0096] Specifically, the trusted authority selects a matching asymmetric encryption algorithm Enc k and decryption algorithm Dec k , where the public-private key pair of the trusted authority is (pk T , sk T ), and selects two one-way collision-free hash functions H1 and H2. Finally, the global public parameters par = {H1, H2, pk T} are output.

[0097] Both the first hash function H1 and the second hash function H2 are one-way collision-free hash functions;

[0098] In an embodiment of the present invention, the trusted authority selects a security parameter of 128 bits, the corresponding asymmetric encryption algorithm is RSA-OAEP, the hash function is selected as SHA-256, and the trusted authority generates a public-private key pair of RSA-OAEP.

[0099] The input of the registration stage of the communication end is the unique identity information ID of the communication end; the output is the public key pk, the private key sk, the pseudonym information PID of the communication end, the public key pk N of the edge proxy server, and the edge proxy server identification information NID. The communication end can be the information reporting party.

[0100] The registration stage of the communication end includes:

[0101] Step S21, the communication end registers with the trusted authority. The trusted authority obtains the unique identity information of the communication end. The trusted authority uses its own quantum random number generator to generate a true random number and uses the encryption algorithm to generate a pseudonym for the communication end;

[0102] Specifically, the communication end registers with the trusted authority. The trusted authority obtains the unique identity information ID of the communication end. The trusted authority uses its own quantum random number generator to generate a true random number x = RandGen(par) and uses the encryption algorithm Enc kGenerate a pseudonym PID = Enc for the communication terminal k (ID || x); where RandGen is a true random number generation function.

[0103] In step S21, each communication terminal registers with a trusted authority (such as offline registration), and the trusted authority obtains the unique identity information ID of the communication terminal, such as "Car001". Subsequently, the trusted authority uses a quantum random number generator to generate a true random number x = RandGen(par) according to the security parameter k, such as x = "123456", and uses the encryption algorithm Enck to generate pseudonym information PID = Enck(ID || x) for the communication terminal, such as ID || x = "Car001123456".

[0104] Step S22, the trusted authority selects a public-private key pair for the communication terminal and sends information including the public-private key pair information of the communication terminal and the pseudonym of the communication segment to the communication terminal;

[0105] Specifically, the trusted authority selects a public-private key pair (pk, sk) for the communication terminal and sends the information (pk, sk, PID) to the communication terminal;

[0106] Step S23, the communication terminal registers with the edge proxy server closest to it. After registration, the communication terminal obtains the public key and node information of the edge proxy server. At the same time, the edge proxy server puts the pseudonym of the information reporting party i into the registration table;

[0107] Specifically, the communication terminal registers with the edge proxy server closest to it. After registration, the communication terminal obtains the public key pk N and node information NID of the edge proxy server. At the same time, the edge proxy server puts the pseudonym PID of the information reporting party i into the registration table List;

[0108] The input of the information reporting phase of the information reporting party is the global public parameter par, information Kw, geographical location Loc, the public-private key pair (pk i , sk i ) of the information reporting party i, the pseudonym PID of the information reporting party i i , and the edge proxy server information NID; the output is the upload message C = (CT i , td i , PID i , S, NID). Among them, CT i , td i , PID i , S, NID respectively represent the information ciphertext of the information reporting party i, the trapdoor value calculated by the reporting party i using the trapdoor function, the pseudonym of the communication terminal, the digital signature generated by the information reporting party i, and the edge proxy server information NID;

[0109] The information reporting phase of the information reporting party includes: Step S31, the information reporting party connects the information of the geographical location where it is located with the information to be sent to obtain an information message;

[0110] Specifically, the information reporting party i generates information Kw, and combines the geographical location information Loc of the information reporting party i to generate an information message m i = Kw || Loc; where, || is the connection symbol;

[0111] For example, the information Kw = "congested", the geographical location information Loc = "Third Ring Road", and the information reporting message m i = "The Third Ring Road is congested."

[0112] Step S32, calculate a temporary authorization code through the first hash function; use an encryption algorithm with the information message, the public key of the information reporting party, and the temporary authorization code;

[0113] Specifically, the information reporting party i uses its own quantum random number generator to generate a true random number y = RandGen(par), and calculates the temporary authorization code v = H1(PID i || y); where, PID i is the pseudonym of the information reporting party i;

[0114] Specifically, obtain a true random number y = RandGen(par) based on the on-vehicle random number generator, such as y = "654321", and calculate the temporary authorization code v = H1(PID i || y).

[0115] Step S33, calculate the information ciphertext, use an encryption algorithm with the information message, the public key of the information reporting party, and the temporary authorization code to calculate the information ciphertext;

[0116] Specifically, the information reporting party i uses the encryption algorithm Enc to i encrypt the information message m i to obtain the information ciphertext CT i = Enc(m i , v, pk i ); where, pk

[0117] is the public key of the information reporting party i;

[0118] Step S34, calculate a trapdoor based on the trapdoor function through the private key of the information reporting party; i Specifically, calculate the trapdoor td i = Aut(sk i ), and further calculate the ciphertext m = H2(CT i || td i||PID i ), and generate a digital signature S = Sign(sk i , m) for the ciphertext m; where Sign is the signature function; Aut is the trapdoor function;

[0119] Step S35, the information reporting party uploads a message including the information ciphertext, the trapdoor, the pseudonym of the information reporting party, and the node information of the edge proxy server closest to the information reporting party to the server;

[0120] Specifically, the information reporting party i uploads the message C = (CT i , td i , PID i , S, NID) to the cloud server; where NID is the node information of the edge proxy server closest to the information reporting party i.

[0121] The input of the equality test phase of the cloud server is the information reporting ciphertext C’ = (CT i , td i , PID i , S, NID), the ciphertext C’’ = (CT j , td j ) that has been stored in the cloud server, and the public key pk i of the information reporting party; the output is the request for temporary authorization message R and the ciphertext C s = (CT i , v).

[0122] The equality test phase of the cloud server includes Step S41. After the cloud server receives the message uploaded by the information reporting party, it authenticates the identity of the information reporting party and checks whether the message has been tampered with; calculates the verification value based on the second hash function through the information ciphertext, the trapdoor, and the pseudonym of the information reporting party, and verifies the signature based on the verification signature function through the public key of the information reporting party, the verification value, and the digital signature of the information ciphertext; if the signature verification is successful, it proceeds to the next step, otherwise it directly discards the message:

[0123] Specifically, after the cloud server receives the message C’ uploaded by the information reporting party i, it authenticates the identity of the information reporting party i and checks whether the message has been tampered with: calculates the verification value m’ = H2(CT i || td i || PID i ), and verifies the signature through Verify(pk i , m’, S), where Verify is the verification signature function; if the signature verification is successful, it proceeds to the next step, otherwise it directly discards the message C’;

[0124] Step S42: The cloud server performs an equality test on the received ciphertext of the information and the trapdoor with all the ciphertexts of the information and the corresponding trapdoors stored in the cloud server. If the test result is 1, it means that the two ciphertexts of the information are the same, that is, the information has been reported, and there is no need to perform subsequent information sharing operations. If the test result is 0, it means that no ciphertext of the information that is the same as the received ciphertext of the information is found, that is, the information has not been reported, and subsequent information sharing operations need to be performed, and proceed to the next step;

[0125] Specifically, the cloud server extracts the ciphertext CT of the information in the message C'. i and the corresponding trapdoor td i , and performs an equality test Test(CT j and the corresponding trapdoor td j ) with all the ciphertexts CT i and the corresponding trapdoors td i stored in the cloud server. Test is an equality test function, and the test result is 0 or 1. If the test result is 1, it means that the two ciphertexts CT j , CT j are the same, that is, the information has been reported, and there is no need to perform subsequent information sharing operations. If the test result is 0, it means that no ciphertext that is the same as the ciphertext CT i , CT j is found, that is, the information has not been reported, and subsequent information sharing operations need to be performed, and proceed to the next step; i

[0126] Step S43: The cloud server sends a request for temporary authorization message to the information reporting party; the server sends the ciphertext to be shared to the edge proxy server according to the node information of the edge proxy server provided by the information reporting party. At the same time, the cloud server also stores the current ciphertext of the information and the corresponding trapdoor;

[0127] Specifically, on the one hand, the cloud server sends a request for temporary authorization message R to the information reporting party i. On the other hand, the cloud server sends the ciphertext C s =(CT i , v) to the edge proxy server according to the node information NID of the edge proxy server provided by the information reporting party i. At the same time, the cloud server also stores the current ciphertext CT i and the corresponding trapdoor td i ;

[0128] The input of the temporary re-encryption key generation stage of the information reporting party is the request for temporary authorization message R, the private key sk i of the information reporting party, the public key pk N of the edge proxy server, and the temporary authorization code v; the output is the temporary re-encryption key Rk;

[0129] The temporary re-encryption key generation phase of the information reporting party includes step S51. The information reporting party calculates a first sub-key based on the public key of the edge proxy server and the private key of the information reporting party through a re-encryption key generation function, uses the calculation method of the temporary authorization code as the second sub-key, and uses the information ciphertext as the third sub-key, and combines the first sub-key, the second sub-key, and the third sub-key to obtain the re-encryption key;

[0130] Specifically, after the information reporting party i receives the request for temporary authorization message R, it calculates Rk1 = ReKeyGen(sk i , pk N ), Rk2 = v = H1(PID i ||y), Rk3 = Enc(Loc, pk N ); where pk N is the public key of the edge proxy server closest to the information reporting party i; ReKeyGen is the re-encryption key generation function; v is the temporary authorization code generated in the third phase, and Loc is the geographical location information of the communication end;

[0131] Step S52, sending the re-encryption key to the edge proxy server closest to the information reporting party;

[0132] Specifically, the temporary re-encryption key Rk = (Rk1, Rk2, Rk3) is obtained and sent to the edge proxy server closest to the information reporting party i;

[0133] The input of the proxy re-encryption phase of the edge proxy server is the temporary re-encryption key Rk, and the ciphertext to be shared Cs = (CTi, v); the output is the ciphertext CTN = (CN, Rk3);

[0134] The proxy re-encryption phase of the edge proxy server includes step S61. After the edge proxy server receives the ciphertext to be shared sent by the cloud server and the re-encryption key sent by the information reporting party, it verifies whether the second sub-key in the re-encryption key is equal to the temporary authorization code. If so, it proceeds to the next step; otherwise, it discards the re-encryption key;

[0135] Specifically, after the edge proxy server receives the ciphertext C s =(CT i , v) sent by the cloud server and the temporary re-encryption key Rk = (Rk1, Rk2, Rk3) sent by the information reporting party i, it verifies whether Rk2 is equal to v. If so, it proceeds to the next step; otherwise, it discards the temporary re-encryption key;

[0136] The edge proxy server first receives the ciphertext C s =(CT i, v), and then receives the temporary re-encryption key Rk sent by the information reporting party. First, it is necessary to compare whether the temporary re-encryption key corresponds to the ciphertext. Therefore, it is necessary to first verify whether Rk2 is equal to the temporary authorization code v sent by the cloud server. If they are equal, go to S62; if not, discard the temporary re-encryption key. Step S62, use the proxy re-encryption function to calculate the re-encrypted ciphertext through the information ciphertext, the first sub-key, and the second sub-key;

[0137] Specifically, the edge proxy server performs proxy re-encryption operation to obtain the re-encrypted ciphertext C N =ReEnc(CT i , Rk1, Rk2); where ReEnc is the proxy re-encryption function;

[0138] Step S63, the edge proxy server sends the re-encrypted ciphertext and the third sub-key to the information receiving party group;

[0139] Specifically, the edge proxy server sends the re-encrypted ciphertext C N and Rk3 to all other communication endpoints in the registration list List, that is, the information receiving party group;

[0140] After the temporary re-encryption key and the ciphertext match, the proxy server performs proxy re-encryption operation to obtain the re-encrypted ciphertext C N =ReEnc(CT i , Rk1, Rk2). After the re-encrypted ciphertext at this time undergoes re-encryption transformation, it can be decrypted using the public key pk of the proxy server N . At the same time, since the proxy server and the information receiving party group use symmetric key encryption, this message can be shared for use by this group.

[0141] The input in the decryption stage of the information receiving party is the re-encrypted ciphertext C N , the private key sk of the edge proxy server N and the public key pk N; The output is the information Kw;

[0142] The decryption stage of the information receiving party includes step S71, decrypting the re-encrypted ciphertext based on the private key of the edge proxy server;

[0143] Specifically, after the information receiving party receives the re-encrypted ciphertext C N and Rk3 sent by the edge proxy server, it decrypts the re-encrypted ciphertext C N to obtain the information message m i =Dec(C N , sk N ); where Dec is the decryption algorithm;

[0144] Step S72, decrypt to obtain the geographical location information; the geographical location information Loc = Dec(Rk3, pk N ) needs to be decrypted from Rk3;

[0145] Step S73, decrypt to obtain the information; according to m i = Kw||Loc, obtain the information Kw.

[0146] Specifically, the information receiver decrypts Rk3 to obtain the geographical location information Loc = Dec(Rk3, pk N ); the information receiver obtains the information Kw according to the geographical location information Loc and the information message m i = Kw||Loc.

[0147] Through the above steps, an information sharing method based on equality testing is realized, ensuring the privacy protection and secure sharing of information.

[0148] The information authorization sharing method and system based on equality testing of the present invention at least have the following advantages:

[0149] 1. By performing temporary authorization processing on the re-encryption key, the present invention improves the security of the solution. The temporary re-encryption key allows the information to be re-encrypted by a semi-trusted agency only within a specific time range, and the re-encryption permission is automatically revoked after the expiration of this time, thereby ensuring the privacy security of the information reporting party.

[0150] 2. By using edge computing technology for the proxy server, the present invention improves the efficiency of the solution. With the support of edge computing, on the one hand, the computing pressure on the cloud server can be reduced, so as to better handle the numerous operations of future communication networks; on the other hand, the edge nodes are closer to the data receiver side, with a shorter spatial distance, greatly improving the efficiency of data sharing. At the same time, since the edge nodes are responsible for sending the re-encrypted ciphertext, the cloud server and other third-party groups do not know the information of the information receiver, thus better concealing the privacy data security of the information receiver.

[0151] 3. The present invention proposes an information reporting and sharing solution in the communication network scenario based on equality testing, improving the security of the solution. Equality testing can ensure data retrieval without decrypting the reported information, thus avoiding the problem of privacy data leakage of the information reporting party.

[0152] 4. An efficient and secure information reporting solution in traffic scenarios (such as vehicle networking, V2X, etc.) can optimize communication management and enhance the communication service experience. On the one hand, while providing high-quality services for drivers and passengers, it also ensures that the privacy data of relevant personnel is not leaked; on the other hand, in some emergency situations, sharing road conditions and accident information can remind drivers to avoid dangerous sections, reduce the accident rate, and reduce casualties.

[0153] 5. Perform temporary authorization for proxy re-encryption, cleverly using quantum random numbers to generate a one-time re-encryption key, increasing the difficulty for third parties to crack information, and enhancing the security of information sharing.

[0154] 6. An information sharing scheme based on efficient equality testing creatively solves the problem of leakage of personal geographical location information generated when reporting information and improves the efficiency of information sharing.

[0155] 7. Utilize edge computing to improve the computing efficiency in the re-encryption process, thereby further enhancing the efficiency of information sharing.

[0156] To verify the efficiency of the present invention in the information sharing process, this embodiment is compared with five existing information sharing schemes, and the computing overheads of each scheme are analyzed. The detailed analysis results are shown below.

[0157] The five existing information sharing schemes compared in this embodiment are as follows:

[0158] Scheme 1: H. T. Lee, S. Ling, J. H. Seo, H. Wang, and T.-Y. Youn, “Public key encryption with equality test in the standard model,” Information Sciences, vol. 516, pp. 89–108, 2020.

[0159] Scheme 2: L. Wu, Y. Zhang, K.-K. R. Choo, and D. He, “Efficient identity-based encryption scheme with equality test in smart city,” IEEE Transactions on Sustainable Computing, vol. 3, no. 1, pp. 44–55, 2017.

[0160] Solution 3: S. Ma, Y. Zhong, and Q. Huang, “Efficient public key encryption with outsourced equality test for cloud-based iot environments,” IEEE Transactions on Information Forensics and Security, vol. 17, pp. 3758–3772, 2022.

[0161] Solution 4: Y. Bao, W. Qiu, and X. Cheng, “Secure and lightweight fine-grained searchable data sharing for iot-oriented and cloud-assisted smart healthcare system,” IEEE Internet Things J., vol. 9, no. 4, pp. 2513–2526, 2022.

[0162] Solution 5: Y. Hou, Y. Cao, H. Xiong, Y. Song, and L. Xu, “An efficient online / offline heterogeneous signcryption scheme with equality test for iovs,” IEEE Transactions on Vehicular Technology, 2023.

[0163] The computational cost of the information authorization sharing scheme based on equality test proposed in this invention is 47.279 milliseconds. The computational cost of Solution 1 is 402.731 milliseconds, the computational cost of Solution 2 is 111.418 milliseconds, the computational cost of Solution 3 is 189.519 milliseconds, the computational cost of Solution 4 is 70.937 milliseconds, and the computational cost of Solution 5 is 100.905. The comparison of the computational time-consuming of each solution at different stages is as follows Figure 3As shown, although the solution proposed by the present invention has deficiencies in the encryption stage (Encryption) and is only better than Solution 1 in terms of time consumption, it is significantly better than all the comparison solutions in the equality test stage (Test) and the decryption stage (Decryption). Therefore, it is better than the comparison solutions in terms of the total time consumption (Total) of the solution. After calculation, it is found that the performance improvement of the solution of the present invention is about 33.35% - 88.26%.

[0164] On the other hand, the communication overhead of the information authorization sharing solution based on equality test proposed by the present invention is 5|G| + |Z|, the communication overhead of Solution 1 is (2λ + 23)|G| + |Z|, the communication overhead of Solution 2 is 5|G| + 2|Z|, the communication overhead of Solution 3 is 14|G| + 2|G T |, the communication overhead of Solution 4 is (9s + 4)|G| + 2|G T | + |Z|, and the communication overhead of Solution 5 is 7|G| + 3|Z|. Among them, |G| represents the bit length of the elements in group G, λ represents the bit length of the security parameter, |Z| represents the bit length of the elements in the finite field Z, and |G T | represents the bit length of the elements in group G T and s represents the number of attributes. The comparison of the communication overheads of each solution in different parts is shown in Table 1. It can be seen from this that the solution proposed by the present invention is better than other solutions in terms of the trapdoor length and the key length, and is second only to Solution 2 in terms of the ciphertext length. Through comprehensive analysis, it can be obtained that the communication overhead of the solution proposed by the present invention is smaller than that of the comparison solutions. This solution

[0165] Table 1. Comparison of communication overheads

[0166]

[0167] Through the above data, it can be proved that the information authorization sharing solution based on equality test proposed by the present invention has lower computational overhead and communication overhead than other related solutions. Therefore, the solution of the present invention has higher applicability to most communication network devices with low computing and low communication, and has the potential to be popularized and applied to the entire communication network field.

[0168] It should be clear that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, the detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present invention.

[0169] In the present invention, features described and / or illustrated for one embodiment can be used in the same way or in a similar way in one or more other embodiments, and / or combined with the features of other embodiments or replace the features of other embodiments.

[0170] The foregoing are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, various changes and modifications can be made to the embodiments of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A communication network information authorized sharing system based on equality testing, characterized in that The system includes: a cloud server, an edge proxy server, an information reporting party, and a group of information receiving parties; The information reporting party generates an information message based on the information of its geographical location, encrypts the information message through an encryption algorithm to obtain an information ciphertext, and sends the information ciphertext and a trapdoor calculated based on the private key of the information reporting party to the cloud server and authorizes the cloud server to perform an equality test. The cloud server performs an equality test on the received information ciphertext and trapdoor with all the information ciphertexts and the corresponding trapdoors stored in the cloud server. If the test result is 1, it means that the contents of the two information ciphertexts are the same, that is, the information has been reported and no subsequent information sharing operation is required; if the test result is 0, it means that no information ciphertext with the same content as the received information ciphertext is found, that is, the information has not been reported and subsequent information sharing operations need to be performed, and the information ciphertext is forwarded to the edge proxy server; The cloud server forwards the information ciphertext that passes the equality test to the edge proxy server and sends a temporary authorization request to the information reporting party at the same time; After receiving the temporary authorization request, the information reporting party generates a temporary re-encryption key and sends the temporary re-encryption key to the edge proxy server; The edge proxy server performs proxy re-encryption on the information ciphertext using the temporary re-encryption key and sends the re-encrypted ciphertext to the group of information receiving parties; The group of information receiving parties decrypts the re-encrypted ciphertext and obtains the information.

2. The communication network information authorized sharing system based on equality test according to claim 1, characterized in that The cloud server forwards the information ciphertext to the edge proxy server at the geographical location of the information reporting party; the information reporting party sends the temporary re-encryption key to the edge proxy server at the geographical location of the information reporting party; the edge proxy server sends the re-encrypted ciphertext to the group of information receiving parties within the coverage of the edge proxy server.

3. The communication network information authorized sharing system based on equality test according to claim 1, characterized in that The system further includes a trusted authority; the trusted authority is communicatively connected to all participants in the system and is used to distribute keys and provide global public parameters for the participants in the system.

4. The communication network information authorized sharing system based on equality test according to claim 1, wherein In the process of the information reporting party generating an information message based on the information of its geographical location, encrypting the information message through an encryption algorithm to obtain an information ciphertext, and sending the information ciphertext and a trapdoor calculated based on the private key of the information reporting party to the cloud server and authorizing the cloud server to perform an equality test: The information reporting party connects the information of its geographical location with the information to be sent to obtain an information message; Calculates a temporary authorization code through a first hash function, and uses an encryption algorithm to calculate an information ciphertext through the information message, the public key of the information reporting party, and the temporary authorization code; Calculates a trapdoor based on the private key of the information reporting party through a trapdoor function.

5. The communication network information authorization sharing system based on equality testing according to claim 4, characterized in that The steps for the information reporting party to generate a temporary re-encryption key after receiving the temporary authorization request include: The information reporting party calculates a first sub-key based on the re-encryption key generation function through the public key of the edge proxy server and the private key of the information reporting party, uses the calculation method of the temporary authorization code as the second sub-key, uses the information ciphertext as the third sub-key, and combines the first sub-key, the second sub-key, and the third sub-key to obtain the re-encryption key.

6. The communication network information authorized sharing system based on equality test according to claim 5, characterized in that In the process that the edge proxy server uses the temporary re-encryption key to proxy re-encrypt the information ciphertext and sends the re-encrypted ciphertext to the information recipient group, the proxy re-encryption function is used to calculate the re-encrypted ciphertext through the information ciphertext, the first sub-key and the second sub-key, and the re-encrypted ciphertext and the third sub-key are sent to the information recipient group.

7. The communication network information authorization sharing system based on equality testing according to claim 6, characterized in that In the process that the information recipient group decrypts the re-encrypted ciphertext and obtains the information, the re-encrypted ciphertext is decrypted based on the private key of the edge proxy server to obtain the geographical location information and the information.

8. The communication network information authorized sharing system based on equality test according to any one of claims 1-7, characterized in that The communication network is a vehicle network, the information is traffic information, and both the information reporting party and the information receiving party are vehicles.

9. A method for authorized sharing of communication network information based on equality testing, characterized in that, Applied to the communication network information authorized sharing system based on equality testing described in any one of the above claims 1-8, the method includes an initialization stage, a registration stage of the communication end, an information reporting stage of the information reporting party, an equality testing stage of the cloud server, a temporary re-encryption key generation stage of the information reporting party, a proxy re-encryption stage of the edge proxy server, and a decryption stage of the information recipient. The initialization stage includes: Step S1, the trusted institution selects an asymmetric encryption algorithm, a decryption algorithm, the public and private key pairs of the trusted institution, a first hash function, a second hash function, and outputs the global public parameters including the first hash function, the second hash function, and the public key in the public and private key pairs of the trusted institution. The registration stage of the communication end includes: Step S21, the communication end registers with the trusted institution. The trusted institution obtains the unique identity information of the communication end. The trusted institution uses its own quantum random number generator to generate a true random number and uses the encryption algorithm to generate a pseudonym for the communication end. Step S22, the trusted institution selects a public and private key pair for the communication end and sends the information including the public and private key pair information of the communication end and the pseudonym of the communication segment to the communication end. Step S23, the communication end registers with the nearest edge proxy server. After registration, the communication end obtains the public key and node information of the edge proxy server. At the same time, the edge proxy server puts the pseudonym of the information reporting party i into the registration table. The information reporting stage of the information reporting party includes: Step S31, the information reporting party connects the information of the location where it is located with the information to be sent to obtain an information message. Step S32, calculate the temporary authorization code through the first hash function; use the encryption algorithm through the information message, the public key of the information reporting party, and the temporary authorization code. Step S33, calculate the information ciphertext. Use the encryption algorithm through the information message, the public key of the information reporting party, and the temporary authorization code to calculate the information ciphertext. Step S34, calculate the trapdoor based on the private key of the information reporting party through the trapdoor function. Step S35, the information reporting party uploads a message including the information ciphertext, the trapdoor, the pseudonym of the information reporting party, and the node information of the edge proxy server closest to the information reporting party to the server. The equality testing stage of the cloud server includes: Step S41: After the cloud server receives the message uploaded by the information reporting party, it authenticates the identity of the information reporting party and checks whether the message has been tampered with. It calculates the verification value based on the second hash function through the information ciphertext, the trapdoor, and the pseudonym of the information reporting party, and verifies the signature based on the verification signature function through the public key of the information reporting party, the verification value, and the digital signature of the information ciphertext. If the signature verification is successful, it proceeds to the next step; otherwise, it directly discards the message. Step S42: The cloud server performs an equality test on the received information ciphertext and the trapdoor with all the information ciphertexts and the corresponding trapdoors stored in the cloud server. If the test result is 1, it means that the two information ciphertexts have the same content, that is, the information has been reported, and there is no need to perform subsequent information sharing operations. If the test result is 0, it means that no information ciphertext with the same content as the received information ciphertext is found, that is, the information has not been reported, and subsequent information sharing operations need to be performed, and it proceeds to the next step. Step S43: The cloud server sends a request for temporary authorization message to the information reporting party. The server sends the ciphertext to be shared to the edge proxy server according to the node information of the edge proxy server provided by the information reporting party. At the same time, the cloud server also stores the current information ciphertext and the corresponding trapdoor. The temporary re-encryption key generation stage of the information reporting party includes: Step S51: The information reporting party calculates the first sub-key based on the re-encryption key generation function through the public key of the edge proxy server and the private key of the information reporting party, uses the calculation method of the temporary authorization code as the second sub-key, and uses the information ciphertext as the third sub-key, and combines the first sub-key, the second sub-key, and the third sub-key to obtain the re-encryption key. Step S52: Send the re-encryption key to the edge proxy server closest to the information reporting party. The proxy re-encryption stage of the edge proxy server includes: Step S61: After the edge proxy server receives the ciphertext to be shared sent by the cloud server and the re-encryption key sent by the information reporting party, it verifies whether the second sub-key in the re-encryption key is equal to the temporary authorization code. If so, it proceeds to the next step; otherwise, it discards the re-encryption key. Step S62: Calculate the re-encrypted ciphertext through the proxy re-encryption function using the information ciphertext, the first sub-key, and the second sub-key. Step S63: The edge proxy server sends the re-encrypted ciphertext and the third sub-key to the information receiving party group. The decryption stage of the information receiver includes: Step S71: Decrypt the re-encrypted ciphertext based on the private key of the edge proxy server. Step S72: Decrypt to obtain the geographical location information. Step S73: Decrypt to obtain the information.

Citation Information

Patent Citations

  • Trolley clip

    CA123456A

  • Public transport information sharing platform

    CN107977474A

  • Traffic information reporting device, warning board and traffic information processing system

    CN215814522U

  • Proxy re-encryption method and system supporting equality judgment in cloud computing environment

    CN111786786A