Privacy-protecting 6G offshore intelligent transportation monitoring system and operation method thereof
By organizing drones and underwater sensors in a 6G maritime intelligent transportation monitoring system, and using dual-layer aggregate signature technology, multi-task synchronization and editable signature mechanism, the system's challenges in high public key overhead, replay and Sybil attack vulnerability, and data privacy protection are solved, and efficient, secure and privacy-protected data transmission and storage are achieved.
Patent Information
- Application Number
- CN202411906596.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-23
- Publication Date
- 2025-05-13
AI Technical Summary
6G maritime intelligent transportation monitoring system faces challenges in high public key overhead, replay and Sybil attack vulnerability, and data privacy protection during data transmission and storage.
A 6G maritime intelligent transportation monitoring system that protects privacy is proposed. By organizing drones and underwater sensors into clusters, using two-layer aggregation signature technology, it reduces the communication and storage overhead related to public keys, and introduces a multi-task synchronization and editable signature mechanism to enhance the security and privacy protection of the system.
It effectively reduces the transmission and storage costs of MTMS, improves the efficiency of 6G communication, enhances the resistance to playback and Sybil attacks, and ensures data privacy protection.
Smart Images

Figure CN119997000A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of maritime transport monitoring systems, and in particular to a privacy-protecting 6G maritime intelligent transport monitoring system and a working method thereof. Background Art
[0002] The rapid development of the sixth-generation (6G) communication technology has spawned many promising network services and applications. Based on emerging technologies such as satellite communications, edge computing and artificial intelligence, 6G communications have achieved higher data rates, lower transmission latency, and a global integrated network covering the sky, earth and sea. Among them, the Maritime Transportation Monitoring System (MTMS) has become one of the most promising application areas of 6G technology. With the help of drones and underwater sensors, MTMS can monitor environmental factors such as weather patterns, ocean currents, coral reefs, and marine life, provide early warnings for ships, and assist fleets in planning safer routes, effectively reducing navigation risks. However, traditional MTMS faces severe challenges in intelligence and real-time performance due to limited network coverage, insufficient data transmission capacity, and high latency. With the advent of 6G technology, MTMS can rely on global seamless connectivity and advanced network architecture to achieve more efficient and reliable data transmission. This technological breakthrough has greatly improved the ability to monitor real-time ocean data, while promoting the intelligent development of maritime transportation in areas such as trajectory monitoring, transportation communication, and path optimization.
[0003] Due to the openness of wireless networks, 6G-enabled MTMS systems are vulnerable to multiple security threats such as data tampering, spoofing attacks, and unauthorized access. Digital signatures, as a widely used cryptographic mechanism, can effectively ensure the authenticity and integrity of data. With this technology, each relevant entity can verify the source of the monitoring report and ensure the credibility of its content. However, the marine working environment poses severe challenges to the transmission of data and signatures. Specifically, the bandwidth of underwater acoustic communications is usually tens to hundreds of kbps, which makes the transmission of a large number of features more time-consuming compared to terrestrial environments. During the transmission to ground data centers, these signatures also impose a heavy bandwidth burden on 6G infrastructure such as communication satellites and edge nodes. In addition, the limited power and storage capacity of drones and underwater sensors make it impractical to store and verify a large number of signatures. To address this problem, aggregate signature technology has been introduced. By merging multiple signatures into one, aggregate signatures significantly reduce the resource consumption associated with signature transmission, storage, and verification. However, integrating aggregate signature technology into 6G-enabled MTMS still faces complex technical challenges.
[0004] A major challenge is the high storage and transmission overhead associated with public keys. Existing aggregate signature schemes require the verifier to store the public keys of all relevant signers in order to verify the aggregate signature. When applied to MTMS, the verifier must store the public keys of all drones and sensor nodes, which will lead to huge storage requirements. One solution is to implement a Public Key Infrastructure (PKI), in which drones and sensors send their public keys and corresponding digital certificates to the verifier in real time. However, this approach will significantly increase the communication overhead and bring additional burden to certificate verification.
[0005] In addition, the use of aggregated signatures in MTMS makes it more complicated to detect replay attacks and Sybil attacks. Determining whether a signature has expired, whether there has been a replay or multiple submissions (such as a Sybil attack) requires cross-comparison with historical records, which poses a huge challenge for drones and underwater sensors with limited storage capacity. This problem is exacerbated by the aggregation process, in which multiple signatures are combined into one signature and transmitted to space and ground 6G networks. This aggregation masks malicious signatures, making it more difficult for data centers to identify such attacks and may hide harmful activities, posing serious security risks.
[0006] Finally, while real-time access to ground data centers via 6G networks makes smart maritime transport management possible, it also raises serious concerns about data privacy protection. Once the monitoring data arrives at the data center, it needs to be shared among multiple data analysts, so sensitive information must be removed before sharing. Editable signatures provide a promising solution to this privacy issue. This technology allows editors to remove sensitive parts of the signed data report without invalidating the signature. However, current editable signature schemes are only applicable to single signatures and are not suitable for aggregated signatures. Therefore, these schemes cannot be applied to MTMS because in this system, signatures are aggregated before data sharing.
[0007] In view of this, the present invention proposes a privacy-protecting 6G maritime intelligent transportation monitoring system and a working method thereof. Summary of the invention
[0008] The purpose of the present invention is to propose a privacy-preserving 6G maritime intelligent transport monitoring system and its working method, while addressing key challenges such as high public key overhead, vulnerability to replay and Sybil attacks, and privacy protection.
[0009] To achieve the above object, the technical solution of the present invention is as follows:
[0010] A privacy-preserving 6G maritime intelligent transport monitoring system, including three heterogeneous 6G networks: marine network, land network and space network;
[0011] The marine network includes drones, underwater sensors, autonomous underwater vehicles AUVs and sink nodes Sink; the drones and underwater sensors are organized into different drone clusters and underwater sensor clusters according to their geographical locations, and each cluster consists of a cluster head CH and multiple cluster members CM;
[0012] The CM is responsible for performing maritime monitoring tasks and regularly submitting maritime monitoring data and signatures to the CH within the cluster;
[0013] After receiving the monitoring data and signatures from the CMs in the cluster, the CH performs first-layer signature aggregation and sends the monitoring data and first-layer aggregated signatures to the AUVs close to the cluster;
[0014] The AUV navigates between different clusters, receives monitoring data and aggregated signatures sent by different CHs and verifies the aggregated signatures, performs second-layer signature aggregation to aggregate first-layer aggregated signatures from different clusters, and sends the collected monitoring data and second-layer aggregated signatures to the Sink when navigating close to the Sink node;
[0015] The Sink is responsible for receiving the monitoring data and signatures sent by the AUV and transmitting them to the DC via satellite communication;
[0016] The terrestrial network includes a key generation center KGC, a data center DC and several data analysts DA; used for data storage, utilization and transmission management;
[0017] KGC is responsible for generating and distributing sensor key pairs and broadcasting public keys to AUV, DC, and DA. The key generation process is organized by cluster. Each CH and CM in the same cluster has a unique private key but shares a common public key.
[0018] DC is responsible for verifying and storing maritime monitoring data. After deleting sensitive data in the monitoring data and deriving the corresponding verifiable signature, DC shares the monitoring data with DA and implements intelligent transportation management based on DA’s feedback.
[0019] DA is responsible for analyzing maritime monitoring data; submitting data requests to DC, verifying received monitoring data and signatures, and providing feedback to DC after performing data analysis based on its expertise;
[0020] The space network includes communication satellites and satellite signal receiving facilities to connect ocean networks and terrestrial networks.
[0021] A method for operating a privacy-preserving 6G maritime intelligent transport monitoring system includes the following stages:
[0022] System initialization phase: The key generation center KGC first executes the Setup algorithm to generate the public parameter PP; then, KGC runs the KeyGen algorithm for each cluster, and the algorithm outputs the private key (SK i,0 ,SK i,1 ,…,SK i,M ), public key (PK i,1 ,PK i,2 );wherein, the private key SK i,0 is secretly distributed to the cluster head CH i , private key SK i,j Distributed secretly to cluster members CM i,j , public key (PK i,1 ,PK i,2 ) is broadcasted to other entities as the public key of the cluster; i represents the cluster head of the ith cluster, CM i,j represents the j-th member of cluster i;
[0023] Data collection phase: multiple monitoring tasks are executed concurrently. First, the system divides geographically close drones and underwater sensors into clusters. Within the same cluster, each drone and underwater sensor is assigned a different monitoring task to simultaneously collect different maritime data, including atmospheric conditions, ship positions, and ocean current information. The working time is divided into multiple time periods, each of which corresponds to an identifier tp. Each cluster member CM i,j Collect monitoring data according to the assigned tasks and package the data report into DATA i,j , calculate m i,j =H1(tp||ID i,j ||DATA i,j ); then, CM i,j Run the Sign algorithm to i,j Generate a signature σ i,j ; Monitoring data DATA i,j and signature σ i,j is sent periodically to the cluster head CH i ;
[0024] The first layer aggregation stage: When receiving the i,1 ,…,CM i,M )’s signature (σ i,1 ,…,σ i,M ),the cluster head CH i Execute the AggSingleCluster algorithm to aggregate the signatures and output an aggregate signature σ i ; Then AUV runs the algorithm VerifySingleCluster to verify the signature σ i ; Where M represents the number of cluster members;
[0025] Second-layer aggregation stage: The autonomous underwater vehicle AUV is responsible for collecting the data of each cluster and transmitting it to the surface aggregation node; the AUV runs the AggMultiCluster algorithm to perform the second-layer aggregation to collect the collected signatures ({σ i} i∈[N] ) into a more compact composite signature σ; after receiving the data and signature, the ground data center DC runs VerifyMultiCluster to verify the signature σ;
[0026] Data utilization phase: DC shares the collected maritime monitoring data reports with DA; before data sharing, DC needs to disclose the data according to the disclosure policy set for each DA point. Eliminate sensitive information from the data; DC executes the Redact algorithm to generate an edited signature The DA then runs the RedactVerify algorithm to verify the signature.
[0027] Preferably, the key generation center KGC first executes the Setup algorithm to generate the public parameter PP, as follows:
[0028] Setup(1 κ )→PP: With safety parameter 1 κ As input, KGC defines a collision-resistant hash function and Run the Swarm Generator Get the bilinear group, select Algorithm Output
[0029] in, is the set {1,2,…,p-1}; is a bilinear group; g and Respectively represent the and Randomly select elements from .
[0030] Preferably, the following hardness assumption is made in the bilinear group Established on:
[0031] SDL Assumptions: Given an SDL tuple SDL assumes that the adversary The probability of outputting index a is negligible, i.e. If the opponent Advantages is negligible, then the SDL hypothesis is considered to be established;
[0032] PS Assumption: Given a PS tuple With a Fable Machine that has unlimited access For any definition by For input, select Output(h,h a+b·m ); PS assumes that Under the condition that the adversary has searched m′, Output tuple (h′,h′ a+b·m′ ) is negligible, that is If the opponent Advantages can be ignored, then the PS hypothesis is considered to be in the group established on.
[0033] Preferably, the KGC runs the KeyGen algorithm for each cluster, and the algorithm outputs a private key (SK i,0 ,SK i,1 ,…,SK i,M ), public key (PK i,1 ,PK i,2 ); specifically as follows:
[0034] Keygen(CID i ,M)→(SK i,0 ,SK i,1 ,…,SK i,M ,PK i,1 ,PK i,2 ): KGC selection calculate For j∈[M], KGC calculates w i,j =(y i ) j +z i , For k∈[M]∪[M+2,2M], KGC calculates Finally, KGC outputs SK i,0 =z i , S.K. i,j =(x i,j ,w i,j ), PK i,1 =Z i ,
[0035] Among them, {x i,j} j∈[M] ,y i ,z i Represents from the set Randomly select elements from .
[0036] Preferably, the CM i,j Run the Sign algorithm to i,j Generate a signature σ i,j , as follows:
[0037] Sign(SK i,j ,m i,j ,tp)→σ i,j :CM i,j Calculate b i,j =x i,j +w i,j ·m i,j , Output
[0038] σ i,j =(b i,j ,B i,j ).
[0039] Preferably, the cluster head CH i Execute the AggSingleCluster algorithm to aggregate the signatures and output an aggregate signature σ i ; The details are as follows:
[0040] AggSingleCluster(SK i,0 ,σ i,1 ,…,σ i,M )→σ i :CH i calculate Next, CH i Calculate a knowledge signature Output σ i =(b i ,C i ,D i ,Π i ).
[0041] Preferably, the AUV runs the algorithm VerifySingleCluster to verify the signature σ i , as follows:
[0042] VerifySingleCluster(PK i,1 ,tp,m i,1 ,…,m i,M ,σ i )→0 / 1: After parsing the signature, we get σ i =(b i ,C i ,D i ,Π i), the AUV performs the following verifications:
[0043] (1) Whether tp is the current time period;
[0044] (2) Knowledge Signature Π i Is it effective?
[0045] (3) Equation whether it is established;
[0046] If the above verification passes, the AUV outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
[0047] Preferably, the AUV runs the AggMultiCluster algorithm to perform the second layer aggregation to collect the signatures ({σ i} i∈[N] ) into a more compact composite signature σ; after receiving the data and signature, the ground data center DC runs VerifyMultiCluster to verify the signature σ; the details are as follows:
[0048] AggMultiCluster({σ i} i∈[N] )→σ: AUV parses each signature σ i =(b i ,C i ,D i ,Π i ),calculate Output σ = D;
[0049] VerifyMultiCluster({PK i,2} i[N] ,tp,{m i,j} i[N],j[M] ,σ)→0 / 1: DC verification equation Is it true? If the equation is true, DC outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
[0050] Preferably, the DC executes the Redact algorithm to generate an edited signature The DA then runs the RedactVerify algorithm to verify the signature. The details are as follows:
[0051] For the disclosure strategy definition For i∈[N], DC is calculated
[0052] Output
[0053]
[0054] DA Verification Equation Is it true? If the equation is true, DC outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
[0055] Compared with the prior art, the present invention has the following beneficial effects:
[0056] (1) Optimizing 6G communication based on aggregate signatures: The present invention proposes a composite aggregate signature scheme to reduce the transmission and storage costs of MTMS. By organizing drones and underwater sensors into clusters, the present invention significantly reduces the communication and storage overhead associated with public keys. The present invention designs a two-layer aggregation mechanism, which can not only aggregate signatures generated under the same public key (i.e., signatures from the same cluster), but also further aggregate these already aggregated signatures. This two-layer aggregation structure further reduces the communication overhead between different transmission levels, while improving the efficiency of 6G communication.
[0057] (2) Support for concurrent monitoring tasks and multi-task synchronization: The present invention allows drones and sensors in the same cluster to perform different ocean monitoring tasks and achieve concurrent data collection. In order to resist replay attacks and Sybil attacks, the present invention introduces the concept of multi-task synchronization. This concept is an extension of synchronous aggregate signatures, allowing verifiers to confirm that all submitted data reports are generated in the same time period and ensure that each cluster submits no more than M data reports, where M corresponds to the number of tasks.
[0058] (3) Intelligent and privacy-preserving maritime data utilization: The present invention uses 6G communication technology to connect the marine network with the ground data center to achieve real-time data analysis and intelligent maritime transport management. In order to ensure privacy protection during data use, the present invention designs an editing mechanism that allows the data center to delete sensitive monitoring data before sharing the data with data analysts, while retaining the validity of the corresponding signature to maintain the authenticity of the data. Unlike traditional editable signature schemes, the proposed editing mechanism is designed for aggregated signatures, and the privacy of sensitive information is guaranteed even after signature aggregation. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 This is a system architecture diagram of the present invention. DETAILED DESCRIPTION
[0060] The technical solution of the present invention is described in detail below in conjunction with the accompanying drawings.
[0061] The present invention proposes a privacy-protecting 6G maritime intelligent transportation monitoring system and a working method thereof; it has optimized bandwidth, supports synchronous processing and data editing functions. The 6G-based MTMS architecture proposed in the present invention integrates marine networks, space networks and land networks, and uses ground data centers and data analysts to achieve real-time and intelligent maritime monitoring and transportation management. In order to ensure the authenticity and integrity of data while optimizing transmission overhead, the present invention introduces the concept of aggregate signatures and proposes a composite aggregate signature with double-layer aggregation. In addition, the present invention supports the execution of concurrent maritime monitoring tasks and intelligent data utilization, while providing strong resistance to replay attacks, Sybil attacks and privacy leaks. A detailed description of the technical solution created by the present invention is as follows.
[0062] In terms of communication bandwidth optimization, the present invention proposes a composite aggregate signature scheme to reduce the transmission and storage costs of MTMS. By organizing drones and underwater sensors into clusters, the present invention significantly reduces the communication and storage overhead associated with public keys. The present invention designs a two-layer aggregation mechanism that not only aggregates signatures generated under the same public key (i.e., signatures from the same cluster), but also further aggregates these already aggregated signatures. This two-layer aggregation structure further reduces the communication overhead between different transmission levels, while improving the efficiency of 6G communications.
[0063] At the level of multi-task concurrent execution, the present invention allows drones and sensors in the same cluster to perform different ocean monitoring tasks and achieve concurrent data collection. In order to resist replay attacks and Sybil attacks, the present invention introduces the concept of multi-task synchronization. This concept is an extension of synchronous aggregate signatures, allowing verifiers to confirm that all submitted data reports are generated in the same time period and ensure that each cluster submits no more than M data reports, where M corresponds to the number of tasks.
[0064] In terms of intelligent management and privacy protection, the present invention uses 6G communication technology to connect the marine network with the ground data center to achieve real-time data analysis and intelligent maritime transport management. In order to ensure privacy protection during data use, the present invention designs an editing mechanism that allows the data center to delete sensitive monitoring data before sharing the data with data analysts, while retaining the validity of the corresponding signature to maintain the authenticity of the data. Unlike traditional editable signature schemes, the proposed editing mechanism is designed for aggregated signatures, and the privacy of sensitive information is guaranteed even after signature aggregation.
[0065] 1. System Model
[0066] The system architecture of the present invention is as follows Figure 1As shown in the figure, the system consists of three heterogeneous 6G networks: ocean network, land network and space network. The ocean network is the working environment of drones, underwater sensors and autonomous underwater vehicles (AUV). Specifically, drones and underwater sensors are organized into different clusters according to their geographical locations, and each cluster consists of a cluster head (CH) and multiple cluster members (CM). The land network includes a key generation center (KGC), a data center (DC) and several data analysts (DA). Its main functions include data storage, utilization and transmission management. The space network is a bridge connecting the ocean and land networks, mainly including communication satellites and satellite signal receiving facilities.
[0067] (1) Key Generation Center (KGC)
[0068] The KGC is a trusted entity, usually operated by a security agency. The KGC is responsible for generating and distributing sensor key pairs and broadcasting public keys to AUVs, DCs, and DAs. The key generation process is organized by cluster, where each sensor within the same cluster has a unique private key but shares a common public key.
[0069] (2) Cluster Head (CH)
[0070] CH is a drone or underwater sensor that acts as a cluster manager. CH is usually a high-performance device that is allocated higher capabilities and computing power than CM, enabling it to process large amounts of data and receive frequent communications. CH is responsible for receiving maritime monitoring data and corresponding signatures from CM, and performing the first layer of signature aggregation (i.e., aggregating signatures within the same cluster). When the AUV approaches the cluster, CH communicates with the AUV and sends data reports and aggregated signatures. Assuming that there are N sensor or drone clusters in the MTMS system, the cluster head of the i-th cluster is defined as CH i .
[0071] (3) Cluster Member (CM)
[0072] CM is a surface drone or underwater sensor responsible for performing maritime monitoring tasks. CM is usually low-power, low-computing, and designed for specific tasks to achieve the longest possible service life. In MTMS, each cluster usually contains multiple CM nodes, each of which performs different tasks and submits monitoring data reports regularly. Assuming that there are at most M CMs in a cluster, the jth member of cluster i is defined as CM i,j .
[0073] (4) Autonomous Underwater Vehicle (AUV)
[0074] AUV is an autonomous vehicle used for autonomous navigation and communication in underwater environments. AUV navigates between different clusters, receives data and signatures sent by CH, and verifies the aggregated signatures. In addition, AUV is responsible for performing the second layer of aggregation, aggregating the aggregated signatures from different clusters to further reduce storage and communication overhead. When approaching the Sink node, AUV packages the collected data and aggregated signatures and sends them to the Sink, then returns to the original route to repeat the above process.
[0075] (5) Sink
[0076] Sink is a surface communication buoy or a ship equipped with communication equipment. In MTMS, Sink is usually a bridge between the ocean network and the ground network, responsible for receiving monitoring data and signatures sent by AUV and transmitting them to DC via satellite communication.
[0077] (6) Data Center (DC)
[0078] DC is a high-performance data platform for data storage and maritime transport management, usually operated by government agencies. DC's mission is to verify and store maritime monitoring data, and then implement intelligent transport management based on DA's feedback. Before sharing data reports with DA, DC is responsible for removing sensitive data and deriving corresponding verifiable signatures.
[0079] (7) Data Analyst (DA)
[0080] DAs are responsible for analyzing maritime monitoring data and are usually research institutions or government consultants that provide intelligent advice for maritime transport management. DAs usually focus on specific areas of expertise, such as route planning, logistics optimization, environmental and water flow analysis, or marine biology analysis. DAs are responsible for submitting data requests to DCs, verifying received data and signatures, and utilizing data based on their expertise.
[0081] 1.1 Variable Symbols
[0082] Table 1: Symbolic variables
[0083]
[0084]
[0085] 1.2 Formal Definition of the System
[0086] The system of the present invention includes the following algorithm.
[0087] ·Setup(1 κ )→PP. The algorithm is executed by KGC with security parameter 1 κ is the input and the output is the system public parameter PP.
[0088] Keygen(CID i ,M)→(SK i,0 ,SK i,1 ,…,SK i,M ,PK i,1 ,PK i,2 The algorithm is executed by KGC, with the identifier CID of the i-th cluster i and the number of cluster members M as input to generate its private key-public key pair (SK i,0 ,SK i,1 ,…,SK i,M ,PK i,1 ,PK i,2 ). Among them, SK i,0 CH i The private key, SK i,j For CM i,j The private key (PK i,1 ,PK i,2 ) is the public key of this cluster.
[0089] ·Sign(SK i,j ,m i,j ,tp)→σ i,j .The algorithm is provided by CM i,j Execute with private key SK i,j 、Monitoring report i,j and the current time period tp as input to generate a signature σ i,j .
[0090] ·AggSingleCluster(SK i,0 ,σ i,1 ,…,σ i,M )→σ i .The algorithm is provided by CH i Execute with private key SK i,0 , the signature sent by the cluster member (σ i,1 ,…,σ i,M ) is input and outputs an aggregated signature σ i .
[0091] VerifySingleCluster(PK i,1 ,tp,m i,1 ,…,m i,M ,σ i )→0 / 1. The algorithm is executed by AUV with cluster public key PK i,1 , current time period tp, monitoring report (m i,1 ,…,m i,M ) and the aggregate signature σ iIf the signature is valid, the algorithm outputs 1; otherwise, the algorithm outputs 0.
[0092] ·AggMultiCluster({σ i} i∈[N] )→σ. The algorithm is executed by AUV to further aggregate the aggregated signatures from different clusters. Algorithm signature set ({σ i} i∈[N] ) is input and outputs a composite signature σ.
[0093] VerifyMultiCluster({PK i,2} i[N] ,tp,{m i,j} i[N],j[M] ,σ)→0 / 1. The algorithm is executed by DC with the cluster public key {PK i,2} i∈[N] , time period tp, as input, collected monitoring reports {m i,j} i[N],j[M] and the composite signature σ are input. If the signature is valid, the algorithm outputs 1; otherwise, the algorithm outputs 0.
[0094] · The algorithm is executed by the DC to monitor the reported {m i,j} i[N],j[M] , revealing strategies and signature σ as input, and output an edited signature This signature can be used to authenticate a subset of the message authenticity and effectiveness.
[0095] · The algorithm is executed by DA with the cluster public key {PK i,2} i∈[N] , message subset and the edited signature If the signature is valid, the algorithm outputs 1; otherwise, the algorithm outputs 0.
[0096] 1.3 System initialization phase
[0097] During the system initialization phase, the key generation center KGC first executes the Setup algorithm to generate the public parameters PP. Then, KGC runs the KeyGen algorithm for each cluster, and the algorithm outputs the private key (SK i,0 ,SK i,1 ,…,SK i,M ), public key (PK i,1 ,PK i,2 ). Among them, the private key SK i,0 is secretly distributed to the cluster head CH i , private key SKi,j Distributed secretly to cluster members CM i,j , public key (PK i,1 ,PK i,2 ) is broadcast to other entities as the public key of the cluster.
[0098] ·Setup(1 κ )→PP. With safety parameter 1 κ As input, KGC defines a collision-resistant hash function and Run the Swarm Generator Get the bilinear group, select Algorithm Output
[0099] Keygen(CID i ,M)→(SK i,0 ,SK i,1 ,…,SK i,M ,PK i,1 ,PK i,2 ).KGC selection calculate For j∈[M], KGC calculates w i,j =(y i ) j +z i , For k∈[M]∪[M+2,2M], KGC calculates Finally, KGC outputs SK i,0 =z i , S.K. i,j =(x i,j ,w i,j ), PK i,1 =Z i ,
[0100] 1.4 Data Collection Phase
[0101] This stage involves the concurrent execution of multiple monitoring tasks. First, the system divides geographically close drones and underwater sensors into clusters. Within the same cluster, each drone and underwater sensor is assigned a different monitoring task, so that various maritime data such as atmospheric conditions, ship positions, and ocean current information can be collected simultaneously. In order to achieve synchronous processing, the present invention divides the working time into multiple time periods, each of which corresponds to an identifier tp. Each cluster member CM i,j Collect monitoring data according to the assigned tasks and package the data report into DATA i,j , calculate m i,j =H1(tp||IDi,j ||DATA i,j ). Then, CM i,j Run the Sign algorithm to i,j Generate a signature σ i,j Monitoring data DATA i,j and signature σ i,j is sent periodically to the cluster head CH i .
[0102] ·Sign(SK i,j ,m i,j ,tp)→σ i,j .CM i,j Calculate b i,j =x i,j +w i,j ·m i,j , Output σ i,j =(b i,j ,B i,j ).
[0103] 1.5 First Layer Aggregation Stage
[0104] In the present invention, signature aggregation is divided into two parts: first-layer aggregation and second-layer aggregation. The first-layer aggregation occurs within each cluster. i,1 ,…,CM i,M )’s signature (σ i,1 ,…,σ i,M ),the cluster head CH i Execute the AggSingleCluster algorithm to aggregate the signatures and output an aggregate signature σ i The AUV then runs the algorithm VerifySingleCluster to verify the signature σ i .
[0105] ·AggSingleCluster(SK i,0 ,σ i,1 ,…,σ i,M )→σ i .CH i calculate Next, CH i Calculate a knowledge signature Output σ i =(b i ,C i ,D i ,Π i ).
[0106] VerifySingleCluster(PKi,1 ,tp,m i,1 ,…,m i,M ,σ i )→0 / 1. After parsing the signature, we get σ i =(b i ,C i ,D i ,Π i ), the AUV performs the following verifications:
[0107] (1) Whether tp is the current time period.
[0108] (2) Knowledge Signature Π i Is it effective?
[0109] (3) Equation Is it true?
[0110] If the above verification passes, the AUV outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
[0111] 1.6 Second Layer Aggregation Stage
[0112] In MTMS, the autonomous underwater vehicle AUV is responsible for collecting the data of each cluster and transmitting it to the surface aggregation node. In order to reduce the storage requirements of AUV, the present invention introduces the concept of composite aggregation signature: AUV runs the AggMultiCluster algorithm to perform the second layer of aggregation to collect the collected signatures ({σ i} i∈[N] ) into a more compact "composite signature" σ. After receiving the data and signature, the ground data center DC runs VerifyMultiCluster to verify the signature σ.
[0113] ·AggMultiCluster({σ i} i∈[N] )→σ.AUV parses each signature σ i =(b i ,C i ,D i ,Π i ),calculate Output σ=D.
[0114] VerifyMultiCluster({PK i,2} i[N] ,tp,{m i,j} i[N],j[M] ,σ)→0 / 1.DC verifies the equation If the equation is true, DC outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
[0115] 1.7 Data Utilization Phase
[0116] At this stage, DCs share the collected maritime monitoring data reports with DAs. By analyzing ocean and environmental data, DAs can help DCs gain insights into real-time conditions such as weather, ocean currents, and ship locations, and provide recommendations for route optimization and risk mitigation. Before data sharing, DCs need to share data based on the disclosure policy set for each DA point. Eliminate sensitive information from the data. To ensure that DA can verify the authenticity and integrity of the edited data, DC executes the Redact algorithm to generate an edited signature The DA then runs the RedactVerify algorithm to verify the signature
[0117] · For the disclosure strategy definition For i∈[N], DC is calculated Output
[0118] · DA Verification Equation If the equation is true, DC outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
[0119] 2. Bilinear Groups and the Hardness Hypothesis
[0120] Swarm Generator With safety parameter 1 κ is the input and the output order is p cyclic group With bilinear mapping For any and The mapping e satisfies the following properties: (1) Bilinearity: e(g a ,h b )=e(g,h) ab (2) Non-degenerate: (3) Computability: e(g,h) can be efficiently computed. At the same time, the present invention requires the following difficulty assumptions in the group established on.
[0121] Assumption 1 (SDL Assumption): Given an SDL tuple SDL assumes that the adversary The probability of outputting index a is negligible, i.e. If the opponent Advantages is negligible, then the SDL hypothesis is considered to be established on.
[0122] Assumption 2 (PS Assumption): Given a PS tuple With a Fable Machine that has unlimited access For any definition by For input, select Output(h,h a+b·m ). PS assumes that Under the condition that the adversary has searched m′, Output tuple (h′,h′ a+b·m′ ) is negligible, that is If the opponent Advantages can be ignored, then we believe that the PS hypothesis is in the group established on.
[0123] 3.PS Signature
[0124] PS signature is an efficient and scalable digital signature scheme proposed by Pointcheval and Sanders. The PS signature scheme consists of the following algorithms: (1) Setup (1 κ )→pp: The algorithm uses security parameter 1 κ As input, it outputs the system public parameter pp. (2) Keygen(pp)→(sk,pk): The algorithm takes the public parameter pp as input, and outputs the signature private key sk and the verification public key pk. (3) Sign(sk,m)→σ: The algorithm takes the signature private key sk and the message m as input, and outputs a signature σ. (4) Verify(pk,m,σ)→0 / 1: The algorithm takes the public key pk, the message m and the signature σ as input, and outputs 1 to indicate that the signature is valid, and outputs 0 to indicate that the signature is invalid.
[0125] 4. Editable signature
[0126] Editable signature is a multi-message signature scheme that allows the user to delete parts of the signed message without invalidating the signature. The editable signature scheme consists of the following algorithms: (1) Setup (1 κ )→pp: The algorithm uses security parameter 1 κ As input, it outputs the system public parameter pp. (2) Keygen(pp,n)→(sk,pk): The algorithm takes the public parameter pp and the number of messages n in the signature as input, and outputs the signature private key sk and the verification public key pk. (3) Sign(sk,{m i} i∈[n] )→σ: The algorithm uses the signature private key sk and the message set {m i} i∈[n]As input, it outputs an editable signature σ. (4)Verify(pk,{m i} i∈[n] ,σ)→0 / 1: The algorithm uses the public key pk, the message set {m i} i∈[n] and signature σ as input. If the signature is valid, the algorithm outputs 1; otherwise, the algorithm outputs 0. (5) The algorithm uses the signature private key sk, the message set {m i} i∈[n] , editable signature σ and message editing strategy Takes as input, outputs an edited signature Used to verify a subset of messages (6) The algorithm uses the public key pk, information subset and the edited signature If the signature is valid, the algorithm outputs 1; otherwise, the algorithm outputs 0.
[0127] 5. Knowledge Signature
[0128] Signature of knowledge (SoK) is a cryptographic primitive that combines digital signatures with proof of knowledge. The SoK protocol involves two parties, a signer and a verifier, where the signer proves to the verifier that he possesses specific knowledge related to a public commitment without revealing the knowledge itself, and binds this proof to a specific message to generate a signature. For example, given a secret knowledge and public commitment X = g x , knowledge signature SoK{x:X=g x}(m) represents a signature on message m, whose signer holds the commitment X = g x The protocol can be instantiated as follows: (1) The signer chooses calculate where H(·) is a collision-resistant hash function. Next, the prover converts the tuple Sent to the verifier. (2) Verifier calculates And verify the equation If the equation is true, output 1 to indicate that the signature is valid, otherwise output 0.
[0129] In summary, the present invention proposes a secure and intelligent maritime transport monitoring system that supports 6G, and optimizes bandwidth, security and privacy issues. By integrating 6G communication infrastructure, MTMS can connect ocean, space and land networks, and realize intelligent traffic management through ground data centers and data analysts. In order to reduce the communication overhead in different transmission stages, the present invention proposes a composite aggregation signature with double-layer aggregation, which can effectively reduce the transmission cost in the communication process between cluster heads, AUVs and aggregation nodes. The present invention includes several key functions of 6G-MTMS, including concurrent execution of monitoring tasks and intelligent data utilization, while solving key challenges such as high public key overhead, vulnerability to replay and Sybil attacks, and privacy protection.
[0130] The above are preferred embodiments of the present invention. Any changes made according to the technical solution of the present invention, as long as the resulting functions do not exceed the scope of the technical solution of the present invention, belong to the protection scope of the present invention.
Claims
1. A privacy-protected 6G maritime intelligent transport monitoring system, characterized in that: Including three heterogeneous 6G networks: marine network, land network and space network; The marine network includes drones, underwater sensors, autonomous underwater vehicles AUVs and sink nodes Sink; the drones and underwater sensors are organized into different drone clusters and underwater sensor clusters according to their geographical locations, and each cluster consists of a cluster head CH and multiple cluster members CM; The CM is responsible for performing maritime monitoring tasks and regularly submitting maritime monitoring data and signatures to the CH within the cluster; After receiving the monitoring data and signatures from the CMs in the cluster, the CH performs first-layer signature aggregation and sends the monitoring data and first-layer aggregated signatures to the AUVs close to the cluster; The AUV navigates between different clusters, receives monitoring data and aggregated signatures sent by different CHs and verifies the aggregated signatures, performs second-layer signature aggregation to aggregate first-layer aggregated signatures from different clusters, and sends the collected monitoring data and second-layer aggregated signatures to the Sink when navigating close to the Sink node; The Sink is responsible for receiving the monitoring data and signatures sent by the AUV and transmitting them to the DC via satellite communication; The terrestrial network includes a key generation center KGC, a data center DC, and several data analysts DA; For data storage, utilization and transmission management; KGC is responsible for generating and distributing sensor key pairs and broadcasting public keys to AUV, DC, and DA. The key generation process is organized by cluster. Each CH and CM in the same cluster has a unique private key but shares a common public key. DC is responsible for verifying and storing maritime monitoring data. After deleting sensitive data in the monitoring data and deriving the corresponding verifiable signature, DC shares the monitoring data with DA and implements intelligent transportation management based on DA’s feedback. DA is responsible for analyzing maritime monitoring data; Submit data requests to DC, verify received monitoring data and signatures, and provide feedback to DC after performing data analysis based on their expertise; The space network includes communication satellites and satellite signal receiving facilities to connect ocean networks and terrestrial networks.
2. The method for operating a privacy-protecting 6G maritime intelligent transportation monitoring system according to claim 1, characterized in that: The following phases are included: System initialization phase: The key generation center KGC first executes the Setup algorithm to generate the public parameter PP; then, KGC runs the KeyGen algorithm for each cluster, and the algorithm outputs the private key (SK i,0 ,SK i,1 ,…,SK i,M ), public key (PK i,1 ,PK i,2 );wherein, the private key SK i,0 is secretly distributed to the cluster head CH i , private key SK i,j Distributed secretly to cluster members CM i,j , public key (PK i,1 ,PK i,2 ) is broadcasted to other entities as the public key of the cluster; i represents the cluster head of the ith cluster, CM i,j represents the j-th member of cluster i; Data collection phase: multiple monitoring tasks are executed concurrently. First, the system divides geographically close drones and underwater sensors into clusters. Within the same cluster, each drone and underwater sensor is assigned a different monitoring task to simultaneously collect different maritime data, including atmospheric conditions, ship positions, and ocean current information. The working time is divided into multiple time periods, each of which corresponds to an identifier tp. Each cluster member CM i,j Collect monitoring data according to the assigned tasks and package the data report into DATA i,j , calculate m i,j =H1(tp||ID i,j ||DATA i,j ); then, CM i,j Run the Sign algorithm to i,j Generate a signature σ i,j ; Monitoring data DATA i,j and signature σ i,j is sent periodically to the cluster head CH i ; The first layer aggregation stage: When receiving the i,1 ,…,CM i,M )’s signature (σ i,1 ,…,σ i,M ),the cluster head CH i Execute the AggSingleCluster algorithm to aggregate the signatures and output an aggregate signature σ i ; Then AUV runs the algorithm VerifySingleCluster to verify the signature σ i ; Where M represents the number of cluster members; Second-layer aggregation stage: The autonomous underwater vehicle AUV is responsible for collecting the data of each cluster and transmitting it to the surface aggregation node; the AUV runs the AggMultiCluster algorithm to perform the second-layer aggregation to collect the collected signatures ({σ i } i∈[N] ) into a more compact composite signature σ; after receiving the data and signature, the ground data center DC runs VerifyMultiCluster to verify the signature σ; Data utilization phase: DC shares the collected maritime monitoring data reports with DA; before data sharing, DC needs to disclose the data according to the disclosure policy set for each DA point. Eliminate sensitive information from the data; DC executes the Redact algorithm to generate an edited signature The DA then runs the RedactVerify algorithm to verify the signature.
3. The method for operating a privacy-protecting 6G maritime intelligent transportation monitoring system according to claim 2, characterized in that: The key generation center KGC first executes the Setup algorithm to generate the public parameter PP, as follows: Setup(1 κ )→PP: With safety parameter 1 κ As input, KGC defines a collision-resistant hash function and Run the Swarm Generator Get the bilinear group, select Algorithm Output in, is the set {1,2,…,p-1}; is a bilinear group; g and Respectively represent the and Randomly select elements from .
4. The method for operating a privacy-preserving 6G maritime intelligent transport monitoring system according to claim 3, characterized in that: The following difficulty assumptions are made in the bilinear group Established on: SDL Assumptions: Given an SDL tuple SDL assumes that the adversary The probability of outputting index a is negligible, i.e. If the opponent Advantages is negligible, then the SDL hypothesis is considered to be established; PS Assumption: Given a PS tuple With a Fable Machine that has unlimited access For any definition by For input, select Output(h,h a+b·m ); PS assumes that Under the condition that the adversary has searched m′, Output tuple (h′,h′ a+b·m′ ) is negligible, that is If the opponent Advantages can be ignored, then the PS hypothesis is considered to be in the group established on.
5. The method for operating a privacy-protecting 6G maritime intelligent transport monitoring system according to claim 3, characterized in that: The KGC runs the KeyGen algorithm for each cluster, and the algorithm outputs the private key (SK i,0 ,SK i,1 ,…,SK i,M ), public key (PK i,1 ,PK i,2 ); specifically as follows: Keygen(CID i ,M)→(SK i,0 ,SK i,1 ,…,SK i,M ,PK i,1 ,PK i,2 ): KGC selects {x i,j } j∈[M] ,y i , calculate For j∈[M], KGC calculates w i,j =(y i ) j +z i , For k∈[M]∪[M+2,2M], KGC calculates Finally, KGC outputs SK i,0 =z i , S.K. i,j =(x i,j ,w i,j ), PK i,1 =Z i , Among them, {x i,j } j∈[M] ,y i ,z i Represents from the set Randomly select elements from .
6. The method for operating a privacy-protecting 6G maritime intelligent transport monitoring system according to claim 2, characterized in that: The CM i,j Run the Sign algorithm to i,j Generate a signature σ i,j , as follows: Sign(SK i,j ,m i,j ,tp)→σ i,j :CM i,j Calculate b i,j =x i,j +w i,j ·m i,j , Output σ i,j =(b i,j ,B i,j ).
7. The method for operating a privacy-protecting 6G maritime intelligent transportation monitoring system according to claim 2, characterized in that: The cluster head CH i Execute the AggSingleCluster algorithm to aggregate the signatures and output an aggregate signature σ i ; The details are as follows: AggSingleCluster(SK i,0 ,σ i,1 ,…,σ i,M )→σ i :CH i calculate Next, CH i Calculate a knowledge signature Output σ i =(b i ,C i ,D i ,Π i ).
8. The method for operating a privacy-protecting 6G maritime intelligent transport monitoring system according to claim 7, characterized in that: The AUV runs the algorithm VerifySingleCluster to verify the signature σ i , as follows: VerifySingleCluster(PK i,1 ,tp,m i,1 ,…,m i,M ,σ i )→0 / 1: After parsing the signature, we get σ i =(b i ,C i ,D i ,Π i ), the AUV performs the following verifications: (1) Whether tp is the current time period; (2) Knowledge Signature Π i Is it effective? (3) Equation whether it is established; If the above verification passes, the AUV outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
9. The method for operating a privacy-preserving 6G maritime intelligent transport monitoring system according to claim 2, characterized in that: The AUV runs the AggMultiCluster algorithm to perform the second layer of aggregation to collect the signatures ({σ i } i∈[N] ) into a more compact composite signature σ; after receiving the data and signature, the ground data center DC runs VerifyMultiCluster to verify the signature σ; the details are as follows: AggMultiCluster({σ i } i∈[N] )→σ: AUV parses each signature σ i =(b i ,C i ,D i ,Π i ),calculate Output σ = D; VerifyMultiCluster({PK i,2 } i[N] ,tp,{m i,j } i[N],j[M] ,σ)→0 / 1: DC verification equation Is it true? If the equation is true, DC outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.
10. The method for operating a privacy-protecting 6G maritime intelligent transportation monitoring system according to claim 2, characterized in that: The DC executes the Redact algorithm to generate an edited signature The DA then runs the RedactVerify algorithm to verify the signature. The details are as follows: For the disclosure strategy definition For i∈[N], DC is calculated Output DA Verification Equation and Is it true? If the equation is true, DC outputs 1 to indicate that the signature is valid; otherwise, it outputs 0.