Identity-based anonymous social network fuzzy matching encryption method and system
By implementing an identity-based fuzzy matching encryption method for anonymous social networks on anonymous social network platform, the existing solutions have solved the shortcomings in security, scalability and efficiency, and efficient and secure anonymous social network communication is achieved.
Patent Information
- Application Number
- CN202510123012.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-09
AI Technical Summary
The existing identity-based fuzzy matching encryption schemes have shortcomings in terms of security, scalability, and computing storage efficiency, and cannot effectively support one-to-many communication methods, and are not suitable for large-scale system deployment.
An identity-based fuzzy matching encryption method for anonymous social network is proposed, which generates encryption keys and decryption keys through the key generation center, and implements the encryption and decryption of messages on the anonymous social network platform, supporting the expansion of large attribute sets.
This solution improves security, can meet both anonymity and reliability security requirements, supports large-scale system deployment, improves operational efficiency, and reduces the length of encryption and decryption keys and ciphertexts.
Smart Images

Figure CN119966713A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an identity-based anonymous social network fuzzy matching encryption method and system. Background Art
[0002] Online social networking (OSNs) platforms, such as WeChat and QQ, have revolutionized the way people share information and communicate with others. However, privacy leakage and personal information abuse are still urgent problems in social networking platforms, which hinder the development of social networking platforms. To solve these problems, anonymous social networks (ASNs) have emerged to provide users with anonymous and authentic communication platforms. Anonymous social networking platforms are a special type of online social networking platforms that can not only protect personal identity information but also ensure the authenticity of content. With the development of cryptography, there are now many ASNs systems for people to choose from, such as AN.ON, DC-net and Pisces. Dining-Cryptographers Network (DC-net) allows users to share information through encryption protocols. At the beginning of the protocol, the sender first "encrypts the message" (message XOR key), and then all users run the protocol together to recover the information. The encryption process is completed by the user himself, and DC-net only forwards the "ciphertext" to other users in the network.
[0003] Similar to DC-net, some scholars applied matching encryption (ME) scheme to ASNs system to maintain the privacy and authenticity of the platform. The identity-based matching encryption (IB-ME) scheme they proposed provides the key functions required for secure communication of users in the platform. In addition, they also proposed an anonymous bulletin board based on IB-ME, where users can upload and download data from servers in the network for anonymous communication. However, this scheme only supports "one-to-one" communication. If the information needs to be sent to multiple recipients, the sender must encrypt the message multiple times, which is costly and impractical. In order to support the "one-to-many" communication method, an identity-based fuzzy matching encryption (fuzzy IB-ME) scheme is needed. The ASNs system using this scheme can provide individuals with an authenticated and anonymous communication method.
[0004] However, current identity-based fuzzy matching encryption schemes are not practical. First, existing schemes can only prove their security under a selective security model, which may make them unsuitable for some applications. Second, the scalability of existing schemes is also limited because their attribute sets cannot be expanded to arbitrary sizes. Third, the computational and storage efficiency of existing schemes is not ideal. Summary of the invention
[0005] The purpose of the present invention is to provide an identity-based anonymous social network fuzzy matching encryption method and system to achieve efficient anonymous social networking.
[0006] The technical solution adopted by the present invention is:
[0007] The identity-based anonymous social network fuzzy matching encryption method comprises the following steps:
[0008] S1. The key generation center instantiates the identity-based fuzzy matching encryption scheme to generate the master private key and master public key of the system;
[0009] S2, the key generation center generates an encryption key for the sender based on the sender's user identity information;
[0010] S3, the key generation center generates a decryption key for the receiver based on the receiver's identity information and policy information;
[0011] S4, the sender uses the public key to encrypt the plaintext into ciphertext;
[0012] S5, the sender uploads the ciphertext to an anonymous social networking platform;
[0013] S6, the receiver retrieves and downloads the ciphertext;
[0014] S7. After the receiver successfully decrypts the ciphertext, he obtains the plaintext message.
[0015] Furthermore, step S1 specifically includes the following steps:
[0016] S1-1, the key generation center uses security parameter 1 λ Choose a bilinear group in are all multiplicative cyclic groups of p, and g is a group The generator of ; e represents the bilinear mapping function;
[0017] S1-2, select hash function Random Numbers Random Elements Let g1 = g α ; Set the system threshold d and output the system master private key msk = (α, β, h) and the system master public key mpk = (g, g1, e(g, h), 1 λ ,d).
[0018] Furthermore, step S2 specifically includes the following steps:
[0019] S2-1, after receiving the encryption key request from the sender, the key generation center randomly selects a polynomial The polynomial needs to satisfy the conditions q(0) = β, deg(q) = d-1; deg(q) represents the degree of the polynomial q;
[0020] S2-2, the key generation center calculates e(g,h) β , obtain the user identity information (i.e. attribute set) S contained in the request A ={a1,…,a n};
[0021] S2-3, for all a i ∈S A calculate a i represents the identity information of the i-th user, q(a i ) represents the polynomial q(x) in a i The value of H(a i ) means a i The hash function is set to
[0022] S2-4, the encryption key Sent to sender.
[0023] Furthermore, step S3 specifically includes the following steps:
[0024] S3-1, after receiving the receiver's decryption key request, the key generation center randomly selects an element
[0025] S3-2, based on the recipient's identity information S included in the request B ={b1,…,b n} and policy information P A ={a1,…,a n}, for all b i ∈S B calculate
[0026] S3-3, for all a i ∈S A calculate Set the decryption key to:
[0027]
[0028] S3-4, decryption key Send to the receiver.
[0029] Furthermore, step S4 specifically includes the following steps:
[0030] S4-1, the sender selects the ciphertext strategy PB ={b1,…,b n}, then select a random number and a random polynomial of degree d-1 The polynomial needs to satisfy the condition q′(0)=s;
[0031] S4-2, the sender calculates M·(ek0·e(g,h)) based on the message M -s ;ek0 represents the encryption key of the system;
[0032] S4-3, based on the encryption key received by the sender For all a i ∈S A calculate For all b i ∈P B calculate Indicates a in the encryption key i part;
[0033] S4-4, finally set the ciphertext to:
[0034]
[0035] Further, in step S5, the sender uses the encryption key Generate ciphertext After that, the ciphertext Upload to anonymous social network platform through the network. Anonymous social network stores the ciphertext or directly forwards it to the recipient.
[0036] Furthermore, in step S6, the recipient downloads the ciphertext on the anonymous social network platform from the Internet. Or anonymous social networks directly send encrypted Forward to the recipient.
[0037] Furthermore, step S7 specifically includes the following steps:
[0038] S7-1, the sender receives the decryption key and ciphertext Afterwards, the sender selects two subsets U B ,U A , satisfying the conditions where U′ A =S A ∩P A ,U′ B =S B ∩P B ;
[0039] S7-2, the sender receives the decryption key and ciphertext
[0040] S7-3, calculation in is the Lagrange interpolation coefficient, S is an integer set, i,j∈S, and the recovered plaintext M′=C0·K1·K2 is finally calculated.
[0041] The present invention also discloses an identity-based anonymous social network fuzzy matching encryption system, which applies the identity-based anonymous social network fuzzy matching encryption method. The system includes a key generation center, a sender, a receiver and an anonymous social network; the key generation center is responsible for generating a master private key and a master public key of the system, and is also responsible for generating an encryption key for the sender based on the sender's user identity information and generating a decryption key for the receiver based on the receiver's identity information and policy information, and distributing the keys to the corresponding sender and receiver; the sender obtains the encryption key and encrypts the plaintext into ciphertext using the encryption key and policy, and uploads it to the anonymous social network platform; the receiver obtains the decryption key and downloads the ciphertext from the anonymous social network platform, and then decrypts the corresponding ciphertext to obtain the plaintext message.
[0042] The present invention adopts the above technical solution, based on the identity fuzzy matching encryption scheme, that is, when the sender's attribute S A Satisfy the receiver's strategy P A And the receiver's attribute S B Satisfy the sender's policy P B , the message can be correctly recovered M′=M, otherwise, the decryption process will output a random message M′≠M.
[0043] Since most existing online social networking platforms focus on protecting the confidentiality of information, they are unable to balance the anonymity of identity and the reliability of messages. In contrast, the new solution proposed in the present invention has stronger security features and can simultaneously meet the dual security requirements of anonymity and reliability of online social networking platforms. In addition, the present invention supports large attribute sets. When a large-scale ASNs system needs to be deployed, the user's attribute set also needs to be expanded accordingly. The present invention can expand the attribute set at an exponential rate with security parameters, which is sufficient to meet the system scalability requirements. In addition, compared with existing solutions, the new solution proposed in the present invention has higher operating efficiency, and the encryption and decryption keys and ciphertext lengths are shorter. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The present invention is further described in detail below with reference to the accompanying drawings and specific embodiments;
[0045] Figure 1A schematic diagram of a system model involved in the identity-based anonymous social network fuzzy matching encryption method of the present invention;
[0046] Figure 2 It is a flow chart of the identity-based anonymous social network fuzzy matching encryption method of the present invention. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0048] like Figure 1 As shown in or 2, the present invention discloses an identity-based anonymous social network fuzzy matching encryption method, which can be divided into four stages: an initialization stage, a key distribution stage, a message upload stage, and a message retrieval stage. In the initialization stage, the key generation center instantiates the identity-based fuzzy matching encryption scheme and obtains the master private key and the master public key. The master private key is used to generate encryption keys and decryption keys. All entities within the system can use the master public key. In the key distribution stage, the encryption key and the decryption key are transmitted to the corresponding sender or receiver through a secure channel. In the message upload stage, the sender uploads the ciphertext. In the message retrieval stage, the receiver retrieves and decrypts the ciphertext to obtain the plaintext message.
[0049] Please refer to Figure 1 ,The anonymous social network system mainly includes four entities: key generation center, sender, receiver and anonymous social network. The key generation center is responsible for generating encryption keys and decryption keys, and assigning the keys to the corresponding sender and receiver. After the sender obtains the encryption key, it can use the encryption key and strategy to encrypt the plaintext into ciphertext. Then, upload it to the anonymous social network platform. After the receiver obtains the decryption key and downloads the ciphertext, it decrypts the corresponding ciphertext and obtains the plaintext message.
[0050] like Figure 2 As shown, the present invention discloses an identity-based anonymous social network fuzzy matching encryption method, which includes the following steps:
[0051] S1. The key generation center instantiates the identity-based fuzzy matching encryption scheme to generate the master private key and master public key of the system;
[0052] S2, the key generation center generates an encryption key for the sender based on the sender's user identity information;
[0053] S3, the key generation center generates a decryption key for the receiver based on the receiver's identity information and policy information;
[0054] S4, the sender uses the public key to encrypt the plaintext into ciphertext;
[0055] S5, the sender uploads the ciphertext to an anonymous social networking platform;
[0056] S6, the receiver retrieves and downloads the ciphertext;
[0057] S7. After the receiver successfully decrypts the ciphertext, he obtains the plaintext message.
[0058] Furthermore, step S1 specifically includes the following steps:
[0059] S1-1, the key generation center uses security parameter 1 λ Choose a bilinear group in are all multiplicative cyclic groups of g, where g is a group The generator of ; e represents the bilinear mapping function;
[0060] S1-2, select hash function Random Numbers Random Elements Let g1 = g α ; Set the system threshold d and output the system master private key msk = (α, β, h) and the system master public key mpk = (g, g1, e(g, h), 1 λ ,d).
[0061] Furthermore, step S2 specifically includes the following steps:
[0062] S2-1, after receiving the encryption key request from the sender, the key generation center randomly selects a polynomial The polynomial needs to satisfy the conditions q(0) = β, deg(q) = d-1; deg(q) represents the degree of the polynomial q;
[0063] S2-2, the key generation center calculates e(g,h) β , obtain the user identity information (i.e. attribute set) S contained in the request A ={a1,…,a n};
[0064] S2-3, for all a i ∈S A calculate a i represents the identity information of the i-th user, q(a i ) represents the polynomial q(x) in a i The value of H(a i ) means a i The hash function is set to
[0065] S2-4, the encryption key Sent to sender.
[0066] Furthermore, step S3 specifically includes the following steps:
[0067] S3-1, after receiving the receiver's decryption key request, the key generation center randomly selects an element
[0068] S3-2, based on the recipient's identity information S included in the request B ={b1,…,b n} and policy information P A ={a1,…,a n}, for all b i ∈S B calculate
[0069] S3-3, for all a i ∈S A calculate Set the decryption key to:
[0070]
[0071] S3-4, decryption key Send to the receiver.
[0072] Furthermore, step S4 specifically includes the following steps:
[0073] S4-1, the sender selects the ciphertext strategy P B ={b1,…,b n}, then select a random number and a random polynomial of degree d-1 The polynomial needs to satisfy the condition q′(0)=s;
[0074] S4-2, the sender calculates M·(ek0·e(g,h)) based on the message M -s ;ek0 represents the encryption key of the system;
[0075] S4-3, based on the encryption key received by the sender For all a i ∈S A calculate For all b i ∈P B calculate Indicates a in the encryption key i part;
[0076] S4-4, finally set the ciphertext to:
[0077]
[0078] Further, in step S5, the sender uses the encryption key Generate ciphertext After that, the ciphertext Upload to anonymous social network platform through the network. Anonymous social network stores the ciphertext or directly forwards it to the recipient.
[0079] Furthermore, in step S6, the recipient downloads the ciphertext on the anonymous social network platform from the Internet. Or anonymous social networks directly send encrypted Forward to the recipient.
[0080] Furthermore, step S7 specifically includes the following steps:
[0081] S7-1, the sender receives the decryption key and ciphertext Afterwards, the sender selects two subsets U B ,U A , satisfying the condition where U′ A =S A ∩P A ,U′ B =S B ∩P B ;
[0082] S7-2, the sender receives the decryption key and ciphertext
[0083] S7-3, calculation in is the Lagrange interpolation coefficient, S is an integer set, i,j∈S, and the recovered plaintext M′=C0·K1·K2 is finally calculated.
[0084] The present invention adopts the above technical solution, based on the identity fuzzy matching encryption scheme, that is, when the sender's attribute S A Satisfy the receiver's strategy P A And the receiver's attribute S B Satisfy the sender's policy P B , the message can be correctly recovered M′=M, otherwise, the decryption process will output a random message M′≠M.
[0085] Since most existing online social networking platforms focus on protecting the confidentiality of information, they are unable to balance the anonymity of identity and the reliability of messages. In contrast, the new solution proposed in the present invention has stronger security features and can simultaneously meet the dual security requirements of anonymity and reliability of online social networking platforms. In addition, the present invention supports large attribute sets. When a large-scale ASNs system needs to be deployed, the user's attribute set also needs to be expanded accordingly. The present invention can expand the attribute set at an exponential rate with security parameters, which is sufficient to meet the system scalability requirements. In addition, compared with existing solutions, the new solution proposed in the present invention has higher operating efficiency, and the encryption and decryption keys and ciphertext lengths are shorter.
[0086] Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. In the absence of conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present application is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians of the art without making creative work are within the scope of protection of the present application.
Claims
1. Identity-based anonymous social network fuzzy matching encryption method, characterized by: It includes the following steps: S1. The key generation center instantiates the identity-based fuzzy matching encryption scheme to generate the master private key and master public key of the system; S2, the key generation center generates an encryption key for the sender based on the sender's user identity information; S3, the key generation center generates a decryption key for the receiver based on the receiver's identity information and policy information; S4, the sender uses the public key to encrypt the plaintext into ciphertext; S5, the sender uploads the ciphertext to an anonymous social networking platform; S6, the receiver retrieves and downloads the ciphertext; S7. After the receiver successfully decrypts the ciphertext, he obtains the plaintext message.
2. The identity-based anonymous social network fuzzy matching encryption method according to claim 1 is characterized by: Step S1 specifically includes the following steps: S1-1, the key generation center uses security parameter 1 λ Choose a bilinear group in are all multiplicative cyclic groups of p, and g is a group The generator of ; e represents the bilinear mapping function; S1-2, select hash function Random number α, Random Elements Let g1 = g α ; Set the system threshold d and output the system master private key msk = (α, β, h) and the system master public key mpk = (g, g1, e(g, h), 1 λ ,d).
3. The identity-based anonymous social network fuzzy matching encryption method according to claim 2 is characterized by: Step S2 specifically includes the following steps: S2-1, after receiving the encryption key request from the sender, the key generation center randomly selects a polynomial The polynomial needs to satisfy the conditions q(0) = β, deg(q) = d-1; deg(q) represents the degree of the polynomial q; S2-2, the key generation center calculates e(g,h) β , obtain the user identity information (i.e. attribute set) S contained in the request A ={a1,…,a n }; S2-3, for all a i ∈S A calculate a i represents the identity information of the i-th user, q(a i ) represents the polynomial q(x) in a i The value of H(a i ) means a i The hash function is set to S2-4, the encryption key Sent to sender.
4. The identity-based anonymous social network fuzzy matching encryption method according to claim 3 is characterized by: Step S3 specifically includes the following steps: S3-1, after receiving the receiver's decryption key request, the key generation center randomly selects an element S3-2, based on the recipient's identity information S included in the request B ={b1,…,b n } and policy information P A ={a1,…,a n }, for all b i ∈S B calculate S3-3, for all a i ∈S A calculate Set the decryption key to: S3-4, the decryption key Send to the receiver.
5. The identity-based anonymous social network fuzzy matching encryption method according to claim 4 is characterized by: Step S4 The specific steps include: S4-1, the sender selects the ciphertext strategy P B ={b1,…,b n }, then select a random number and a random polynomial of degree d-1 The polynomial needs to satisfy the condition q ′ (0) = s; S4-2, the sender calculates M·(ek0·e(g,h)) based on the message M -s ;ek0 represents the encryption key of the system; S4-3, based on the encryption key received by the sender For all a i ∈S A calculate For all b i ∈P B calculate Indicates a in the encryption key i part; S4-4, finally set the ciphertext to:
6. The identity-based anonymous social network fuzzy matching encryption method according to claim 1 is characterized by: In step S5, the sender uses the encryption key Generate ciphertext After that, the ciphertext Uploaded to anonymous social networking platforms via the Internet.
7. The identity-based anonymous social network fuzzy matching encryption method according to claim 1 is characterized by: In step S6, the recipient downloads the ciphertext on the anonymous social network platform from the Internet Or anonymous social networks directly send encrypted Forward to the recipient.
8. The identity-based anonymous social network fuzzy matching encryption method according to claim 5 is characterized by: Step S7 specifically includes the following steps: S7-1, the sender receives the decryption key and ciphertext Afterwards, the sender selects two subsets U B ,U A , satisfying the conditions Among them U A ′ =S A ∩P A ,U ′ B =S B ∩P B ; S7-2, the sender receives the decryption key and ciphertext S7-3, calculation in is the Lagrange interpolation coefficient, S is an integer set, i,j∈S, and the recovered plaintext M′=C0·K1·K2 is finally calculated.
9. An identity-based anonymous social network fuzzy matching encryption system, which applies the identity-based anonymous social network fuzzy matching encryption method according to any one of claims 1 to 8, characterized in that: The system includes a key generation center, a sender, a receiver, and an anonymous social network; the key generation center is responsible for generating the master private key and master public key of the system, and is also responsible for generating an encryption key for the sender based on the sender's user identity information and a decryption key for the receiver based on the receiver's identity information and policy information, and distributing the keys to the corresponding sender and receiver; The sender obtains the encryption key and uses the encryption key and strategy to encrypt the plaintext into ciphertext and upload it to the anonymous social networking platform; the receiver obtains the decryption key and downloads the ciphertext from the anonymous social networking platform, decrypts the corresponding ciphertext and obtains the plaintext message.