Identity authentication and privacy data distributed storage method based on lattice password
By adopting grid-based password-based identity authentication and distributed storage methods for private data in the IoT environment, combining secret sharing and grid-based cryptography technology, the challenges of data security and privacy protection in the IoT environment are solved, and the secure storage and transmission of data is achieved, and resource overhead is reduced.
Patent Information
- Application Number
- CN202510188598.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-12-11
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-27
AI Technical Summary
Data in the IoT environment is unsafe and inefficient in transmission of entities, and there is a risk of privacy leakage and various security threats.
The distributed storage method of identity authentication and privacy data based on grid password is adopted, and the secure storage and transmission of data is achieved through key generation, encryption, signature, verification and decryption stages, combined with secret sharing and grid cryptography technology.
It effectively solves the challenges of data security and privacy protection in the IoT environment, can withstand quantum attacks and side channel attacks, reduces computing, communication and storage overhead, improves communication efficiency, and is suitable for IoT devices with limited resources.
Smart Images

Figure CN120050034A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of security authentication and data distributed storage, and particularly relates to an identity authentication and privacy data distributed storage method based on lattice cryptography. Background Art
[0002] With the exponential growth of the use of Internet of Things (IoT) technology, the IoT, as a technology that connects various physical devices through the Internet to achieve information exchange and communication between devices, while providing convenience and intelligence, also faces various threats. Due to the openness and dynamics of the network in the IoT system, during the communication process, there is a risk of privacy leakage when the identity information or sensitive data of the terminal device is transmitted through an open channel. Moreover, the communication entities are not completely trustworthy, and dishonest entities may maliciously disclose the identity information of the device. An attacker can obtain the private key shared between the user and the device and launch various attacks, such as chosen-plaintext attack, chosen-ciphertext attack, malware attack, denial-of-service attack, man-in-the-middle attack, and side-channel attack, etc. In order to address the above security risks and ensure the authenticity and integrity of data during the IoT data sharing process, a series of measures need to be taken to protect the security of data collectors and users. Summary of the Invention
[0003] The present invention provides an identity authentication and privacy data distributed storage method based on lattice cryptography to solve the problems in the prior art that data is insecure and has low transmission efficiency during the entity transmission process.
[0004] The identity authentication and privacy data distributed storage method based on lattice cryptography includes a key generation phase, an encryption phase, a signature phase, a verification phase, and a decryption phase; and is specifically implemented by the following steps:
[0005] Step 1. Key generation phase;
[0006] The certification authority first generates the signature public key PK S required for signature and the encryption public key PK E and publishes them. Then it generates the signature private key SK S required for signing the message and sends it to the data collector. Finally, it generates the decryption private key SK E required for decryption. The signature private key SK S and the decryption private key SK E are stored in the certification authority;
[0007] Step 2. Encryption phase: The data collector encrypts the received data using the encryption public key PK E to obtain the ciphertext message c;
[0008] Step 3, Signature Phase: The data collector uses the signature private key SK to sign the ciphertext message c S to generate a signature message σ;
[0009] Step 4, Verification Phase: The data collector sends the signature message σ and the ciphertext message c to the nearest trusted data unit, and the trusted data unit uses the signature public key PK S to verify the signature message σ. If the verification is successful, the signature is valid and 1 is output; otherwise, the signature is invalid and 0 is output;
[0010] Step 5, The data unit divides the ciphertext message c into n parts and sends them to the n data units closest to the data unit, and assigns polynomial weights for ciphertext recovery according to the distance, that is, the weights of the secret shares;
[0011] Step 6, When the certification authority requests the data of a certain data collector, it sends the data collector's pseudonym to the cloud. Then the cloud queries the n data units that store the ciphertext shares of the data collector in the pseudonym data unit table. The n data units select to present their own secret shares. When the sum of the weights of the collected secret shares is greater than or equal to the threshold t, according to the Chinese Remainder Theorem on the polynomial ring, the ciphertext message c is successfully recovered and sent to the certification authority, and at the same time, the pseudonym data unit list of the data collector is updated. If the sum of the weights is less than the threshold t, the ciphertext recovery fails.
[0012] Advantages of the present invention:
[0013] The storage method of the present invention effectively solves the challenges of data security and privacy protection in the Internet of Things environment. By combining secret sharing and lattice cryptography techniques, it realizes the secure storage and transmission of data and can resist various security threats, including quantum attacks and side-channel attacks. In addition, the storage method of the present invention also considers resource limitations, adopts efficient algorithms and protocols, reduces the computational, communication and storage overheads, improves the communication efficiency, and has wide applicability.
[0014] Experimental tests were conducted using the method described in the present invention. In the signature phase, for a 64-byte seed, the sizes of the generated signature public key and signature private key are 3904 bytes and 8000 bytes respectively, and the size of the final signature message constructed using two lattice-based hard problems, namely the Learning with Errors (LWE) problem and the Short Integer Solution (SIS) problem, is 6586 bytes. In terms of time, the main algorithms used in the signature, such as the Number Theoret Transform, Using 0fHintBits, and Sample In Ball, take 177.6 microseconds, 27.6 microseconds, and 145.5 microseconds respectively, and the times for finally calculating KeyGen, Sign, and Verify are 232 microseconds, 1332 microseconds, and 405 microseconds respectively. Generally speaking, compared with other digital signature methods, the storage method of the present invention has the characteristics of anti-quantum function while reducing the computational, communication, and storage overheads, and is suitable for application in some Internet of Things devices with limited storage resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 Schematic diagram of the identity authentication and privacy data distributed storage method based on lattice cryptography described in the present invention;
[0016] Figure 2 Schematic diagram of the list of pseudonym data units maintained by the cloud in the identity authentication and privacy data distributed storage method based on lattice cryptography described in the present invention;
[0017] Figure 3 Flow chart of the encryption algorithm. DETAILED DESCRIPTION OF THE INVENTION
[0018] DETAILED DESCRIPTION OF THE INVENTION I. In combination with Figure 1 This embodiment is described. The identity authentication and privacy data distributed storage method based on lattice cryptography aims to address the challenges of data security and privacy protection in the Internet of Things environment. By combining secret sharing and lattice cryptography technologies, a secure, efficient, and anti-quantum attack communication scheme is designed. This method consists of a key generation phase, an encryption phase, a signature phase, a verification phase, and a decryption phase; and is specifically implemented by the following steps:
[0019] In this embodiment, before the key generation phase, a preparation phase is further included; as Figure 2 shown.
[0020] The data collector needs to first register with the authentication agency, and the authentication agency assigns a pseudonym to the data collector and uploads the data collector's pseudonym to the list of pseudonym data units in the cloud. The specific list of pseudonym data units is as Figure 2As shown; data collector n, each data collector includes data units 1 to data unit n, and corresponding addresses 1 to address n;
[0021] Step 1, key generation phase;
[0022] The certification authority first generates a signature public key PK S and an encryption public key PK E and publishes them. Then, it generates a signature private key SK S required for signing the message and saves it in the certification authority. At the same time, it sends it to the data collector. Finally, it generates a decryption private key SK E , which is saved in the certification authority.
[0023] In this embodiment, the encryption public key PK E and the decryption private key SK E are obtained by using a key generation algorithm; the specific process is as follows:
[0024] First, select two large prime numbers a and b that are kept secret, and calculate p = a × b, where is the Euler's totient function value of p;
[0025] Then, select an integer u that satisfies gcd() is the greatest common divisor function; then calculate d that satisfies That is, d is the multiplicative inverse of u modulo . Since u and are relatively prime, according to modular arithmetic, its multiplicative inverse must exist. Finally, generate the encryption public key PK E as u and p, and the decryption private key SK E as d and p.
[0026] In this embodiment, the signature public key PK S and the signature private key SK S are obtained by using a signature key generation algorithm, and the specific process is as follows:
[0027] First, select a seed value ρ with a length of 256 bits. Set the secret vector s 0 and the error vector e 0 to be sampled from the secret distribution and the error distribution in the SIS assumption respectively. The standard deviation of its secret distribution l is the column in matrix A, and η E is the standard deviation of the error distribution.
[0028] Set the matrix to be generated using the pseudorandom number generator SHAKE-128 from the ring domain A matrix of row \(l\) and column \(k\) obtained after taking modulo \(q\). Since \(s\) 0 and \(e\) 0 are crucial for subsequent key generation, in order to resist side-channel attacks, \(s\) 0 and \(e\) 0 are masked, and the masked \(s\) 0 and \(e\) 0 are defined as \(s\) and \(e\). Then calculate \(T := As+e\), where \(s\) and \(e\) are the masked vectors of the secret vectors \(s\) 0 and \(e\) 0 . \(T\) is a polynomial matrix and is sampled from the LWE distribution, and we use the polynomial modulus switching algorithm to decompose \(T\) into high-order \(T\) 1 and low-order \(T\) 0 . Finally, the signature public key \(PK\) S is composed of the seed value \(\rho\) and the matrix \(T\) 1 , with a total of 3904 bytes, and the signature private key \(SK\) S is composed of the seed value \(\rho\), the matrix \(T\) 0 , the secret vector \(s\) and the secret vector \(e\), with a total of 8000 bytes.
[0029] Step 2: Encryption phase;
[0030] The data collector encrypts the collected plaintext data \(m\) using the encryption public key \(PK\) E to obtain the ciphertext message \(c\);
[0031] As Figure 3 shown, first the plaintext data \(m\) is grouped so that the decimal number corresponding to each group is less than \(p\), that is, the group length is less than \(\log_2p\). Then, an encryption operation is performed on each group of plaintext data \(m\) i to obtain the encrypted ciphertext message \(c\) for each group i \(\equiv(m\) i u)\(\bmod p\), and finally all ciphertext groups are concatenated to obtain the ciphertext \(c\) and output.
[0032] Step 3: Signature phase;
[0033] The data collector signs the encrypted ciphertext \(c\) using the signature private key \(SK\) S to generate a signature message \(\sigma\); the specific process is as follows:
[0034] Step 3-1: The signer uses the pseudorandom number generator SHAKE-128 to obtain a matrix according to the seed value \(\rho\) Note that the matrix \(A\) here is the same as the matrix \(A\) in the key generation algorithm, because the SHAKE-128 algorithm will obtain the same output for the same seed input. Subsequently, the signature vector \(Z\), the hint \(h\), and the rejection count flag \(\kappa\) are defined.
[0035] Step 32: Use the extended seed function ExpandS to generate the masking vector y and calculate the vector W = Ay; the signer must perform a high-order decomposition to obtain the high-order vector W 1 of the vector W, such that the vector W can be expressed as W = W 1 ·2δ 2 + W 0 , where W 0 is the low-order vector and δ 2 is the low-order truncation range.
[0036] Step 33: Input the ciphertext message c and W 1 to combine and generate the challenge τ. Once the challenge τ is obtained, the signer calculates the signature vector Z := y + τs. When generating the signature vector Z, the rejection sampling technique can ensure that with the minimum probability generate the signature vector Z, where represents the set of all possible polynomials Z, each of which has n coefficients, is a subset of, where the coefficients of each polynomial Z are randomly selected. Using the rejection sampling technique can make the generation of Z independent of the secret vector s.
[0037] Step 34: Use low-order decomposition to generate the low-order vector λ of W - τe 0 . Subsequently, perform the determination and restart of the signature program. Briefly speaking, there are two stages in total.
[0038] The first stage: First, check whether a certain coefficient in the signature vector Z is at least δ 1 - β, or whether a certain coefficient in λ 0 is at least δ 2 . Among them, δ 1 is the effective range of the masking vector y, and β is the signature range. If either condition is satisfied, start calculating the hint vector h and enter the next stage.
[0039] The second stage: In this stage, it is necessary to check whether the condition ||τT 0 || ∞ ≥ δ 2 is satisfied. If this condition holds, it indicates that the signature is valid.
[0040] If in any stage the condition is not satisfied, it is necessary to return to the step of generating the mask vector y, restart the signature generation process, and increase the rejection count marker κ by 1. These two steps are necessary because they ensure that the secret vectors s and e information is not leaked.
[0041] Step 35. Finally, after meeting all conditions, a signature message σ is generated. σ consists of three parts: the signature vector Z, the hint vector h, and the challenge τ, with a total of 6586 bytes.
[0042] Step 4. Verification phase: The data collector sends the signature message σ and the ciphertext message c to the nearest trusted data unit. At this time, the trusted data unit uses the signature public key PK S to verify the signature message σ. In this verification phase, the main purpose is to verify the correctness of the signature. The output verification result of 0 or 1 determines whether the signature is accepted or rejected. The specific process is as follows:
[0043] First, receive the signature message σ = (Z, h, τ). Use the pseudo-random number generator to generate the same matrix A as the above algorithm according to the seed value ρ. Then verify whether the hint vector h contains sufficient hints so that the verifier can correctly calculate the high-order vector W 1 .
[0044] In this embodiment, verify whether the hint vector h correctly indicates the carry situation generated after multiplying the matrix A by the signature vector Z in W 1 . Then use the ciphertext message c and W 1 to perform a hash operation using SHAKE-256 to obtain the challenge τ'. Then verify whether the generated challenge τ' is equal to the challenge τ in the signature message and whether ||Z|| ∞ is greater than or equal to δ 1 -β. If so, the verification is successful, indicating that the signature is valid, and output 1; otherwise, the signature is invalid, and output 0.
[0045] Step 5. After the signature verification in Step 4 is successful, the data unit divides the ciphertext message c into n parts and sends them to the n nearest data units to this data unit, and assigns weights to the secret shares for ciphertext recovery according to the distance;
[0046] After the data collector obtains the ciphertext message c, first select a prime number r and pairwise relatively prime polynomials m 0 (x), m 1 (x), m 2 (x),..., m i (x),..., m j (x),..., m n (x), where m i (x) and m j (x) are relatively prime, 0 ≤ i ≤ n, 0 ≤ j ≤ n, i ≠ j; and use d 0 , d 1 , d 2 ,..., d n to represent the degrees of these polynomials, that is, d i = deg(mi (x)), where These degrees satisfy:
[0047] d 0 ≤ d 1 ≤ d 2 ≤... d i ≤... ≤ d n
[0048] And randomly select a polynomial α(x) whose degree is d α , and require that the degree of the polynomial α(x) is less than t - 2, where t is the minimum threshold for successful secret recovery. And d 0 = 1, because we want all polynomials to become linear functions of a single variable x when performing modulo operation on m i (x). When choosing the degree of the polynomial, it is necessary to satisfy d i = ω i , that is, use the degree of each polynomial to represent the weight of this data unit. Here, the ciphertext message is defined as the polynomial s(x), and calculate the message polynomial f(x):
[0049]
[0050] Define the degree d f = deg(f(x)) and d α = deg(α(x)), and it can be clearly known that:
[0051] d f = d α + d 0 ≤ t - 2 + 1 = t - 1
[0052] Finally, for each user i, calculate s i (x) = f(x) mod m i (x), and use it as the secret share of each user i, and assign s i (x) to the i-th user, where the weight occupied by the i-th user to recover the ciphertext is ω i , that is, the degree d i of m i .
[0053] Step 6: When the certification authority requests data from a certain data collector, it sends the data collector's pseudonym to the cloud. Then the cloud queries the pseudonym table to find the n data units that store the ciphertext shares of the data collector. These data units can then choose to present their secret shares. When the sum of the weights of the collected secret shares is greater than or equal to the threshold t, according to the Chinese Remainder Theorem (CRT) on the polynomial ring, the ciphertext c can be successfully recovered and sent to the certification authority, and at the same time, the list of pseudonym data units of the data collector is updated. If the sum of the weights is less than the threshold t, the ciphertext recovery fails at this time;
[0054] In this embodiment, when ciphertext recovery is to be performed, according to the definition of weight-based secret sharing, only when the sum of the weights of k participants {i 1 ,…,i k}∈[n] is greater than t, can the ciphertext be recovered. Specifically construct the following congruence system according to the Chinese Remainder Theorem CRT:
[0055]
[0056] where represents any k terms of {s 1 ,s 2 ,…,s n}, represents any k terms of {m 1 ,m 2 ,…,m n}. Subsequently, the solution of the expression (x) can be obtained, and then a polynomial solution X(x) can be calculated. Obviously, the degree of this polynomial is less than This is because Finally, the ciphertext message s(x) is recovered through the following formula:
[0057] s(x) = X(x) mod m 0 (x)
[0058] where m 0 (x) is the modulo polynomial. And s(x) is sent to the certification authority, and at the same time, the list of pseudonym data units of the data collector is updated. If the sum of the weights is less than the threshold t, the ciphertext recovery fails at this time;
[0059] Step 7: Decryption phase;
[0060] If the ciphertext message is successfully recovered, use the decryption private key SK E to decrypt the ciphertext message c;
[0061] For the ciphertext message c, group it in the same way as encryption to get c i , and calculate m i ≡ ci d modulo q, and finally m i is concatenated to obtain m. At this time, the certification authority can view the original data collected by the data collector.
[0062] In this embodiment, when allocating shares to data units, they are allocated according to the distance. The specific allocation strategy is shown in Table 1.
[0063] Table 1
[0064]
[0065]
[0066] where the data unit 0 As the data distributor, it does not participate in share allocation.
[0067] For the method described in this embodiment, the algorithms involved in the key generation, signature, and verification processes are tested. In these processes, the execution times of the specific algorithms used, such as masking, ExpandS, high-low bit decomposition, hint, etc., can all be within 200 microseconds. Due to the high efficiency of these algorithms, the total time for the three steps of the key generation phase, signature phase, and verification phase executed by the signature can also be made not to exceed 2000 microseconds. Compared with the existing signature algorithms based on elliptic curves applied to most practical scenarios, the execution efficiency is increased by 10%-20%. Secondly, compared with the post-quantum signature algorithms in the post-quantum world, the execution efficiency is increased by 25%-40%.
[0068] Therefore, this method has a significant performance improvement compared with the existing methods while ensuring post-quantum security.
[0069] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0070] The above-described embodiments only represent several implementation manners of the present invention. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the invention patent should be subject to the appended claims.
Claims
1. An identity authentication and privacy data distributed storage method based on lattice cryptography, characterized by: The method includes a key generation phase, an encryption phase, a signature phase, a verification phase, and a decryption phase; and is specifically implemented by the following steps: Step 1: Key generation phase; The certification authority first generates the signature public key PK required for signing S and encryption public key PK E And publish, and then generate the signature private key SK required to sign the message S Sent to the data collector, and finally generate the decryption private key SK required for decryption E , the signature private key SK S and the decryption private key SK E Keep it at the certification body; Step 2: Encryption phase: The data collector uses the public key PK to encrypt the received data. E Encrypt and obtain the ciphertext message c; Step 3: Signature phase: The data collector uses the signature private key SK to sign the ciphertext message c. S Sign and generate a signature message σ; Step 4: Verification phase: The data collector sends the signed message σ and the ciphertext message c to the nearest trusted data unit, which uses the signature public key PK S Verify the signed message σ. If the verification is successful, the signature is valid and output 1. Otherwise, the signature is invalid and output 0. Step 5: The data unit divides the ciphertext message c into n parts and sends them to the n data units closest to the data unit, and assigns a polynomial weight for ciphertext recovery, i.e., a weight of the secret share, according to the distance; Step 6. When the certification body requests the data of a data collector, it sends the data collector's pseudonym to the cloud. Then the cloud queries the n data units that store the data collector's ciphertext shares in the pseudonym data unit table. The n data units choose to present their own secret shares. When the sum of the weights of the collected secret shares is greater than or equal to the threshold t, according to the Chinese remainder theorem on the polynomial ring, the ciphertext c is successfully recovered and sent to the certification body. At the same time, the pseudonym data unit list of the data collector is updated. If the sum of the weights is less than the threshold t, the ciphertext recovery fails.
2. The identity authentication and privacy data distributed storage method based on lattice cryptography according to claim 1 is characterized by: Prior to step 1, the data collector is also required to register with a certification body, and the certification body assigns a pseudonym to the data collector and uploads the assigned pseudonym to a pseudonym data unit list in the cloud; The pseudonymous data unit list in the cloud stores n data collectors, each of which is composed of data units 1 to data units n and addresses 1 to address n corresponding to each data unit.
3. The identity authentication and privacy data distributed storage method based on lattice cryptography according to claim 1 is characterized by: In step 1, the encryption public key PK is obtained using the key generation algorithm E and the decryption private key SK E ; The specific process is: First, select two confidential large prime numbers a and b and calculate is the value of the Euler function of p; Then, choose an integer u such that Then calculate the variable d, satisfying Finally generate the encrypted public key PK E For u and p, decrypt the private key SK E for d and p; Use the signature key generation algorithm to obtain the signature public key PK S and signature private key SK S , the specific process is: First, a seed value ρ of length 256 bits is selected, and the secret vector s0 and the error vector e0 are set to be respectively from the secret distribution D in the SIS hypothesis. ηS With error distribution D ηE The sample is obtained from A pseudo-random number generator is used to generate a random number from the ring domain according to the seed value ρ A k-row and l-column matrix generated modulo q Perform mask operation on the secret vector s0 and the error vector e0 to obtain the masked secret vector s and the secret vector e; Then, calculate T:=As+e, where T is a polynomial matrix and is taken from the LWE distribution, perform high-low-order decomposition on T to generate a high-order matrix T1 and a low-order matrix T0; Finally, the signature public key PK S It is composed of the seed value ρ and the high-order matrix T1, the signature private key SK S It consists of a seed value ρ, a low-order matrix T0, a secret vector s, and a secret vector e.
4. The identity authentication and privacy data distributed storage method based on lattice cryptography according to claim 3 is characterized by: The specific process of step three is: Step 31: The signer uses a pseudo-random number generator to obtain a matrix A according to a seed value ρ, and defines a signature vector Z, a prompt vector h, and a rejection number mark κ; Step 32: Generate a mask vector y and calculate a vector W=Ay; the signer performs high-order decomposition on the vector W to obtain a high-order vector W1, so that the vector W is expressed as W=W1·2δ2+W0, where W0 is a low-order vector and δ2 is a low-order interception range; Step 3. Input the ciphertext message c and the high-order vector W1 to generate the challenge τ. The signer calculates the signature vector Z:=y+τs, where s is the secret vector. Step 3 and 4: Use low-order decomposition to generate the low-order vector λ0 of W-τe, and determine and restart the signature program, that is, it includes two stages: In the first stage, we first determine whether a coefficient of the signature vector Z is at least δ1-α or a coefficient of λ0 is at least δ2-β. If either condition is met, we calculate the hint vector h and enter the second stage. If both conditions are not met, we return to step 32. Among them, δ1 is the effective range of the mask vector y, β is the signature range, The second stage is to judge ||τT0|| ∞ ≥δ2, if yes, execute step 35; otherwise, return to step 32, and mark the number of rejections as κ+1; Step 35: Generate a signed message σ, where σ consists of a signature vector Z, a hint vector h, and a challenge τ.
5. The identity authentication and privacy data distributed storage method based on lattice cryptography according to claim 4 is characterized in that: In step 4, the data collector receives the signed message σ = (Z, h, τ), uses a pseudo-random number generator to generate the matrix A according to the seed value ρ, and then verifies whether the hint vector h contains enough hints so that the verifier can correctly calculate the high-order vector W1; Verify that the hint vector h correctly indicates the carry in W1 generated by multiplying the matrix A by the signature vector Z; perform a hash operation on the ciphertext message c and W1 to obtain the challenge τ'; then verify that the generated challenge τ' is equal to the challenge τ in the signature message and ||Z|| ∞ Is it greater than or equal to δ1-β? If so, the verification is successful, indicating that the signature is valid, and output 1; otherwise, the signature is invalid and output 0.
6. The identity authentication and privacy data distributed storage method based on lattice cryptography according to claim 5 is characterized by: The specific process of step five is: Step 51: The data unit divides the ciphertext message c into n parts and sends them to the corresponding n data units, and assigns the weight of the secret share of the ciphertext recovery according to the distance; After the data collector obtains the ciphertext message c, he first selects a prime number r and two mutually prime polynomials m0(x), m1(x), m2(x), ..., m i (x),...,m j (x),...,m n (x), where m i (x) and m j (x) are mutually prime, 0≤i≤n, 0≤j≤n, i≠j; and d0, d1, d2, ..., d n Represents the degree of the corresponding polynomial, i.e. d i =deg(m i (x)), where Setting degree meets: d0≤d1≤d2≤...d i ≤...≤d n Randomly select a polynomial α(x) with degree d α , requiring the degree of the polynomial α(x) to be less than t-2, where t is the minimum threshold for successful secret recovery, and d0=1. When selecting the degree of the polynomial, d i =ω i , that is, the degree of each polynomial is used to represent the weight of the data unit; Step 52: Define the ciphertext message c as the polynomial s(x), and calculate the message polynomial f(x): Define the degree d of the message polynomial f(x) f = deg(f(x)) and d α = deg(α(x)), then: d f =d α +d0≤t-2+1=t-1 Finally, for each user i, calculate s i (x) = f(x) mod m i (x), and as the secret share of each user i, assign s to the i-th user i (x), where the secret share weight occupied by user i in recovering the ciphertext is ω i , which is m i Degree d of (x) i .
7. The identity authentication and privacy data distributed storage method based on lattice cryptography according to claim 6 is characterized by: In step 6, when recovering the ciphertext, according to the definition of weight-based secret sharing, only k participants {i1,…,i k When the sum of the weights of}∈[n] is greater than t, the ciphertext can be recovered. According to the Chinese Remainder Theorem CRT, the following congruence system is constructed: in, represents {s1,s2,…,s n }, any k items of represents {m1,m2,…,m n }, and then obtain the solution of expression (x), and calculate a polynomial solution X(x), and recover the ciphertext message s(x) through the following formula: s(x)=X(x)mod m0(x) Among them, m0(x) is a modular polynomial, and s(x) is sent to the certification authority, and the pseudonymous data unit list of the data collector is updated at the same time; if the sum of the weights is less than the threshold t, the ciphertext recovery fails.
8. The identity authentication and privacy data distributed storage method based on lattice cryptography according to claim 1 is characterized by: After step 6, step 7 is also included: decryption phase: using SK E By decrypting the ciphertext message c, the certification authority can view the original data collected by the data collector.
Citation Information
Cited By
Lightweight hybrid encryption transmission method and system capable of resisting quantum attack
CN120675692A