Internet of Things privacy protection method based on lattice ring signcryption
By using grid-ring signature technology in the Internet of Things environment to generate and manage keys, the problems of privacy leakage, quantum computing threats and key management complexity in the Internet of Things environment are solved, and a secure and reliable privacy protection method is achieved.
Patent Information
- Application Number
- CN202510469389.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-27
AI Technical Summary
In the IoT environment, it is difficult for the prior art to provide a secure and reliable IoT privacy protection method based on grid-circle signatures to solve problems such as privacy leakage risks, quantum computing threats and key management complexity without the need for secure channels, certificate management and key management.
By setting the system security parameters, selecting prime q, and obtaining matrix A as the system public key through the trap gate generation method, and obtaining the short base on the grid Λ⊥(A) as the master private key. Then, the key generation center generates part of the private keys of the IoT smart device and the third-party server, and the smart device and the server generate the corresponding public and private keys themselves. Based on these keys, IoT smart devices use certificate-free ring signing technology to protect their privacy.
It realizes a secure and reliable privacy protection method in the IoT environment without the need for secure channels, certificate management and key hosting, reducing the risks of forgery, message leakage and quantum computing threats, while improving low computing complexity and quantum security.
Smart Images

Figure CN120050047A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network information security, and in particular relates to a certificateless ring signcryption method. Background Art
[0002] In certificateless cryptography, the user's private key is jointly generated by the key generation center and the user, which prevents the key generation center from completely mastering the private key and eliminates the certificate issuance and revocation process of the public key infrastructure. It is very suitable for use in IoT scenarios to simplify key management and improve security. In ring signcryption technology, the signer hides the real identity from the predefined ring, and external attackers cannot forge legal ciphertext. It is suitable for use in IoT privacy protection scenarios to anonymize the identity of IoT devices and prevent attackers from locating devices through traffic analysis. The development of quantum computing technology threatens the existing public key cryptography system. The anti-quantum cryptography system needs to be based on quantum computing difficult problems, which usually have high computational complexity and need to be optimized to adapt to IoT devices.
[0003] The number of IoT devices is huge, resources are limited, and they are deployed in an open environment. In order to solve the multiple challenges faced by IoT, such as privacy leakage risks, quantum computing threats, and key management complexity, it is necessary to integrate certificateless cryptography, ring signcryption technology, and quantum-resistant cryptographic systems to provide an efficient and privacy-secure solution for IoT. Its technical background covers theoretical breakthroughs in lattice public key cryptography, IoT resource constraint adaptation, and forward-looking designs for quantum computing threats. How to design an IoT privacy protection method based on lattice ring signcryption is a technical problem that needs to be urgently solved in IoT security. Summary of the invention
[0004] The technical problem to be solved by the present invention is to overcome the shortcomings of the above-mentioned prior art and provide a safe and reliable IoT privacy protection method based on lattice ring signcryption without the need for a secure channel, certificate management and key escrow.
[0005] The technical solution adopted to solve the above technical problems consists of the following steps:
[0006] (1) System Settings
[0007] (1-1) Set the system security parameter n, where n is a finite positive integer. The key generation center selects a prime number q, q ≥ 3, and sets the Gaussian parameter σ according to formula (1):
[0008]
[0009] Wherein, t represents the control Gaussian sampling error parameter, m and k represent the number of vectors, and t and k are finite positive integers m≥5nlogq.
[0010] (1-2) The key generation center determines the intermediate parameter s according to formula (2):
[0011]
[0012] Among them, ω represents the time complexity function, Represents the space complexity.
[0013] (1-3) The key generation center selects four collision-resistant hash functions J 1 , J 2 , J 3 , H 4 :
[0014]
[0015] Among them, {0,1} * Represents a bit string of any length consisting of 0s and 1s, {0,1} n represents a bit string of length n consisting of 0s and 1s, represents an n-row, k-column matrix consisting of integers modulo q, represents a k-row, 1-column matrix consisting of integers modulo q, represents a 1-row, k-column matrix consisting of integers modulo q, It is an n-row, 1-column matrix consisting of integers modulo q.
[0016] (1-4) The key generation center obtains the matrix A through the trapdoor generation method. As the system public key, we get the grid Λ ⊥ (A) on the short base As the master private key, the following equation holds:
[0017] A·B=0modq
[0018] ||B||≤O(nlogq)
[0019] in, represents an n-row and m-column matrix consisting of integers modulo q, An m-by-m matrix consisting of integers modulo q, where ||B|| represents the normal form of B.
[0020] (1-5) The key generation center keeps the master key A of the confidential system and publishes the global parameter L of the system:
[0021] L={t,n,m,σ,s,A,H 1 ,H 2 ,H 3 ,H 4}.
[0022] (2) Generate partial private keys for IoT smart devices
[0023] (2-1) The key generation center determines the hash value N according to formula (3) i :
[0024] N i =H 1 (ID i ) (3)
[0025] ID i ={ID 1 ,ID 2 ,…,ID N}
[0026] i={1,2,…,N}
[0027] Among them, ID i is the identity information of the IoT smart device, N is the number of IoT smart devices in the system, and N is a finite positive integer.
[0028] (2-2) The key generation center obtains the matrix D through the original image sampling method i , As part of the private key of the IoT smart device, the following two equations are true:
[0029] A.D i =N i
[0030]
[0031] in, represents an m-row, k-column matrix consisting of integers modulo q, ||D i || means D i paradigm.
[0032] (2-3) The key generation center outputs part of the private key D i For IoT smart devices.
[0033] (3) Generate a partial private key for a third-party server
[0034] (3-1) The key generation center calculates the hash value N y :
[0035] N y =H 1 (ID y )
[0036] Among them, ID y It is the identity information of the third-party server.
[0037] (3-2) The key generation center obtains the matrix D through the original image sampling method y , As part of the private key of the third-party server, the following two equations are true:
[0038] A.D y =N y
[0039]
[0040] Among them, ||D y || means D y paradigm.
[0041] (3-3) The key generation center outputs D y To third-party servers
[0042] (4) Generate public and private keys for IoT smart devices
[0043] (4-1) The IoT smart device selects a matrix C consisting of m rows and k columns composed of integers modulo q i , Determine the intermediate parameter E i 、Private key F of IoT smart device i :
[0044] E i =A·C i
[0045] F i =C i +D i
[0046] And the following two equations hold:
[0047]
[0048] Among them, C i It is the public key of the IoT smart device.
[0049] (4-2) The third-party server selects a matrix C with m rows and k columns consisting of integers modulo q y , Determine the intermediate parameter E y 、Private key F of the third-party server y :
[0050] E y =A·C y
[0051] F y =C y +D y
[0052] And the following two equations hold:
[0053]
[0054] Among them, C y It is the public key of the third-party server.
[0055] (5) Certificateless Ring Signature Cryptography
[0056] (5-1) IoT smart devices select two vectors
[0057] Given an IoT smart device ring member identity set {ID 1 ,ID 2 ,…,ID N} and the message d to be signed, d∈{0,1} n , with identity ID x The IoT smart devices choose two vectors:
[0058]
[0059]
[0060] (5-2) IoT smart devices build intermediate parameters and hash values
[0061] IoT Smart Device ID x The intermediate parameter μ is determined according to formula (4), and the hash value N is determined according to formula (5) x :
[0062] μ=H 2 (d) (4)
[0063] N x =H 1 (ID x ) (5)
[0064] Among them, ID x ∈{ID 1 ,ID 2 ,…,ID N}, N is a finite positive integer.
[0065] (5-3) IoT smart device ID x Determine the partial ciphertext Q as follows 1 , Q 2 :
[0066] Q 1 =A T r 1
[0067] Q 2 =Ar 2 +N x ·μ.
[0068] (5-4) IoT smart device ID x Determine the partial ciphertext c as follows:
[0069]
[0070] N y =H 1 (ID y ).
[0071] (5-5) IoT Smart Device ID x choose Determine the hash value k as follows i :
[0072] k i =H 4 (d,a i ,ID i )
[0073] Where i = 1, 2, ..., N and i ≠ x;
[0074] For i=x, IoT smart device ID x By probability Determine the intermediate parameter k as follows x :
[0075] k x =H 4 (d,a x ,ID x )
[0076]
[0077] E x =A·C x
[0078] Among them, M is a constant that is not 0, C x is a matrix of m rows and k columns consisting of integers modulo q.
[0079] (5-6) IoT smart device ID x Determine the partial ciphertext T as follows 1 :
[0080] T 1 =A(r 2 +F x μ)+E x ·k x .
[0081] (5-7) IoT smart device ID x Output ciphertext γ:
[0082] γ=(Q 1 ,Q 2 ,T 1 ,T x ,c,a 1 ,a 2 ,…,a N ),
[0083] Give an ID y A third-party server, where Y x Is the timestamp.
[0084] (6) Decryption
[0085] (6-1) Given the current timestamp Y x1 , third-party server ID y Verify that the following inequality holds:
[0086] |T x -T x1 |≤ΔT x
[0087] Where, ΔT x is the maximum value of the valid time interval. If it is true, it means that T x Is a valid timestamp, third-party server ID y Confirm message d as follows:
[0088]
[0089] (6-2) Third-party server ID y Determine the intermediate parameter k as follows i :
[0090] k i =H 4 (d,a i ,ID i )
[0091] i=1,2,…,N
[0092] (6-3) Third-party server ID y Determine the intermediate parameter μ as follows:
[0093] μ=H 2 (d);
[0094] (6-4) Third-party server ID y Verify that the following two equations hold:
[0095]
[0096] If both are true, the plain text is valid, otherwise it is invalid.
[0097] In the step (1-1) of the system initialization of the present invention, the system security parameter n is set to 2. 8 or 2 9 or 2 10 , the key generation center selects a prime number q, q takes the value of 3 or 5 or 7 or 11, and sets the Gaussian parameter σ:
[0098]
[0099] Among them, t represents the parameter controlling the Gaussian sampling error, t∈[1,10], m and k represent the number of vectors, k∈[1,10], and m is 5×2 16 or, 5×2 18 or 5×2 20 .
[0100] In the step (1-1) of system initialization of the present invention, the system security parameter n is set, and the value of n is 2 9 , the key generation center selects a prime number q, the best value of q is 7, and sets the Gaussian parameter σ according to formula (1):
[0101]
[0102] Among them, t represents the parameter that controls the Gaussian sampling error, and the optimal value of t is 5. m and k represent the number of vectors, and the optimal value of k is 5, m ≥ 5nlogq, and the optimal value of m is 5×10 18 .
[0103] In the formula (3) of step (2-1) of the step (2) of the present invention in which a partial private key of an IoT smart device is generated, the ID i is the identity information of the IoT smart device, N is the number of devices in the system, N∈[10,600].
[0104] In the formula (3) of step (2-1) of the step (2) of the present invention in which a partial private key of an IoT smart device is generated, the ID i is the identity information of the IoT smart device, N is the number of devices in the system, and the best value of N is 300.
[0105] Since the present invention adopts a quantum computing-resistant certificateless ring signcryption method, it solves the problems of forgery, message leakage, quantum computing, etc. in the IoT environment. In the IoT privacy protection method based on lattice ring signcryption, some private keys of smart devices and third-party servers are generated by the key generation center, and the corresponding public and private keys are generated by themselves. The present invention has the advantages of low computational complexity and quantum security, and has a good application prospect in the field of network information security. BRIEF DESCRIPTION OF THE DRAWINGS
[0106] Figure 1 This is a flow chart of Example 1 of the present invention. DETAILED DESCRIPTION
[0107] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments, but the present invention is not limited to these embodiments.
[0108] Example 1
[0109] The key generation center chooses a large prime number q, such as Figure 1 As shown, the steps of the IoT privacy protection method based on lattice ring signcryption in this embodiment are as follows:
[0110] (1) System initialization
[0111] (1-1) Set the system security parameter n, n is 2 8 or 2 9 or 2 10 In this embodiment, the value of n is 2 9 The key generation center selects a prime number q, where q is 3, 5, 7 or 11. In this embodiment, q is 7. The Gaussian parameter σ is set according to formula (1):
[0112]
[0113] Wherein, t represents the control Gaussian sampling error parameter, t∈[1,10], and the value of t in this embodiment is 5, m and k represent the number of vectors, k∈[1,10], and the value of k in this embodiment is 5, m≥5nlogq, and the value of m is 5×2 16 or 5×2 18 or 5×2 20 In this embodiment, the value of m is 5×2 18 .
[0114] (1-2) The key generation center determines the intermediate parameter s according to formula (2):
[0115]
[0116] Among them, ω represents the time complexity function, Represents space complexity;
[0117] (1-3) The key generation center selects four collision-resistant hash functions J 1 , J 2 , J 3 , H 4 :
[0118]
[0119] Among them, {0,1}* Represents a bit string of any length consisting of 0s and 1s, {0,1} n represents a bit string of length n consisting of 0s and 1s, represents an n-row, k-column matrix consisting of integers modulo q, represents a k-row, 1-column matrix consisting of integers modulo q, represents a 1-row, k-column matrix consisting of integers modulo q, It is an n-row, 1-column matrix consisting of integers modulo q.
[0120] (1-4) The key generation center obtains the matrix A through the trapdoor generation method. As the system public key, we get the grid Λ ⊥ (A) on the short base As the master private key, the following equation holds:
[0121] A·B=0modq
[0122] ||B||≤O(nlogq)
[0123] in, represents an n-row and m-column matrix consisting of integers modulo q, An m-by-m matrix consisting of integers modulo q, where ||B|| represents the normal form of B.
[0124] (1-5) The key generation center encrypts the master key A of the system and publishes the global parameter L of the system:
[0125] L={t,n,m,σ,s,A,H 1 ,H 2 ,H 3 ,H 4}.
[0126] (2) Generate partial private keys for IoT smart devices
[0127] (2-1) The key generation center determines the hash value N according to formula (3) i :
[0128] N i =H 1 (ID i ) (3)
[0129] ID i ={ID 1 ,ID 2 ,…,ID N}
[0130] i=1,2,…,N
[0131] Among them, ID iis the identity information of the IoT smart device, N is the number of IoT smart devices in the system, N∈[10,600], and N in this embodiment is 300.
[0132] (2-2) The key generation center obtains the matrix D through the original image sampling method i , As part of the private key of the IoT smart device, the following two equations are true:
[0133] A.D i =N i
[0134]
[0135] in, represents an m-row, k-column matrix consisting of integers modulo q, ||D i || means D i paradigm.
[0136] (2-3) The key generation center outputs part of the private key D i For IoT smart devices.
[0137] (3) Generate a partial private key for a third-party server
[0138] (3-1) The key generation center calculates the hash value N y :
[0139] N y =H 1 (ID y )
[0140] Among them, ID y It is the identity information of the third-party server;
[0141] (3-2) The key generation center obtains the matrix D through the original image sampling method y , As part of the private key of the third-party server, the following two equations are true.
[0142] A.D y =N y
[0143]
[0144] Among them, ||D y || means D y paradigm.
[0145] (3-3) The key generation center outputs D y To a third-party server.
[0146] (4) Generate public and private keys for IoT smart devices
[0147] (4-1) The IoT smart device selects a matrix C consisting of m rows and k columns composed of integers modulo q i , Determine the intermediate parameter E i 、Private key F of IoT smart device i :
[0148] E i =A·C i
[0149] F i =C i +D i
[0150] And the following two equations hold:
[0151]
[0152] Among them, C i It is the public key of the IoT smart device.
[0153] (4-2) The third-party server selects a matrix C with m rows and k columns consisting of integers modulo q y , Determine the intermediate parameter E y 、Private key F of the third-party server y :
[0154] E y =A·C y
[0155] F y =C y +D y
[0156] And the following two equations hold:
[0157]
[0158] Among them, C y It is the public key of the third-party server.
[0159] (5) Certificateless Ring Signature Cryptography
[0160] (5-1) IoT smart devices select two vectors
[0161] Given an IoT smart device ring member identity set {ID 1 ,ID 2 ,…,ID N} and the message d to be signed, d∈{0,1} n, with identity ID x The IoT smart devices choose two vectors:
[0162]
[0163] (5-2) IoT smart devices build intermediate parameters and hash values
[0164] IoT Smart Device ID x Construct the intermediate parameter μ according to formula (4), and construct the hash value N according to formula (5) x :
[0165] μ=H 2 (d) (4)
[0166] N x =H 1 (ID x ) (5)
[0167] Among them, ID x ∈{ID 1 ,ID 2 ,…,ID N}, N is the number of devices in the system, N∈[10,600], and the value of N in this embodiment is 300.
[0168] (5-3) IoT smart device ID x Determine the partial ciphertext q as follows 1 ,q 2 :
[0169] Q 1 =A T r 1
[0170] Q 2 =Ar 2 +N x ·μ.
[0171] (5-4) IoT smart device ID x Determine the partial ciphertext c as follows:
[0172]
[0173] N y =H 1 (ID y ).
[0174] (5-5) IoT Smart Device ID x choose Determine the hash value k according to the formula i :
[0175] ki =H 4 (d,a i ,ID i )
[0176] Among them, i=1,2,…,N and i≠x.
[0177] For i=x, IoT smart device ID x By probability The intermediate parameter k is determined as follows: x :
[0178] k x =H 4 (d,a x ,ID x )
[0179]
[0180] E x =A·C x
[0181] Among them, M is a constant that is not 0, C x is a matrix of m rows and k columns consisting of integers modulo q.
[0182] (5-6) IoT smart device ID x Determine the partial ciphertext T as follows 1 :
[0183] T 1 =A(r 2 +F x μ)+E x ·k x .
[0184] (5-7) IoT smart device ID x Output ciphertext γ:
[0185] γ=(Q 1 ,Q 2 ,T 1 ,T x ,c,a 1 ,a 2 ,…,a N )
[0186] Give an ID y A third-party server, where T x Is the timestamp.
[0187] (6) Decryption
[0188] (6-1) Given the current timestamp T x1 , third-party server IDy , verify whether the following inequality holds:
[0189] |T x -T x1 |≤ΔT x
[0190] Where, ΔT x is the maximum value of the valid time interval. If it is true, it means that T x Is a valid timestamp, third-party server ID y Confirm message d as follows:
[0191]
[0192] (6-2) Third-party server ID y Determine the intermediate parameter k as follows i :
[0193] k i =H 4 (d,a i ,ID i )
[0194] i=1,2,…,N
[0195] Wherein, N is the number of devices in the system, N∈[10,600]. In this embodiment, the value of N is 300.
[0196] (6-3) Third-party server ID y Determine the intermediate parameter μ:
[0197] μ=H 2 (d).
[0198] (6-4) Third-party server ID y Verify that the following two equations hold:
[0199]
[0200]
[0201] If both are true, the plain text is valid, otherwise it is invalid.
[0202] Complete the IoT privacy protection method based on lattice ring signcryption.
[0203] Example 2
[0204] The steps of the IoT privacy protection method based on Lattice Ring Signature in this embodiment are as follows:
[0205] (1) System initialization
[0206] (1-1) Set the system security parameter n, n is 2 8 or 2 9 or 2 10 In this embodiment, the value of n is 2 8 The key generation center selects a prime number q, where q is 3, 5, 7 or 11. In this embodiment, q is 3. The Gaussian parameter σ is set according to formula (1):
[0207] The expression of formula (1) is the same as that of Example 1.
[0208] In formula (1), t represents the control Gaussian sampling error parameter, t∈[1,10], and the value of t in this embodiment is 1. m and k represent the number of vectors, k∈[1,10], and the value of k in this embodiment is 1. m≥5nlogq, and the value of m is 5×2 16 or, 5×2 18 or 5×2 20 In this embodiment, the value of m is 5×2 16 .
[0209] The other steps of this step are the same as those in Example 1.
[0210] (2) Generate partial private keys for IoT smart devices
[0211] (2-1) The key generation center determines the hash value N according to formula (3) i :
[0212] N i =H 1 (ID i ) (3)
[0213] ID i ={ID 1 ,ID 2 ,…,ID N}
[0214] i=1,2,…,N
[0215] Among them, ID i is the identity information of the IoT smart device, N is the number of IoT smart devices in the system, N∈[10,600], and N in this embodiment is 10.
[0216] The rest of the steps are the same as in Example 1.
[0217] (3) Generate a partial private key for a third-party server
[0218] This step is the same as in Example 1.
[0219] (4) Generate public and private keys for IoT smart devices
[0220] This step is the same as in Example 1.
[0221] (5) Certificateless Ring Signature Cryptography
[0222] (5-1) IoT smart devices select two vectors
[0223] This step is the same as in Example 1.
[0224] (5-2) IoT smart devices build intermediate parameters and hash values
[0225] IoT Smart Device ID x Construct the intermediate parameter μ according to formula (4), and construct the hash value N according to formula (5) x :
[0226] The expressions of formula (4) and formula (5) are the same as those in Example 1.
[0227] In formula (5), ID x ∈{ID 1 ,ID 2 ,…,ID N}, N is the number of devices in the system, N∈[10,600], and the value of N in this embodiment is 10.
[0228] The other steps of this step are the same as those in Example 1.
[0229] The other steps are the same as those in Example 1. The Internet of Things privacy protection method based on lattice ring signcryption is completed.
[0230] Example 3
[0231] The steps of the IoT privacy protection method based on Lattice Ring Signature in this embodiment are as follows:
[0232] (1) System initialization
[0233] (1-1) Set the system security parameter n, n is 2 8 or 2 9 or 2 10 In this embodiment, the value of n is 2 10 The key generation center selects a prime number q, where q is 3, 5, 7 or 11. In this embodiment, q is 11. The Gaussian parameter σ is set according to formula (1):
[0234] The expression of formula (1) is the same as that of Example 1.
[0235] In formula (1), t represents the control Gaussian sampling error parameter, t∈[1,10], the value of t in this embodiment is 10, m and k represent the number of vectors, k∈[1,10], the value of k in this embodiment is 1, m≥5nlogq, and the value of m is 5×2 16 or, 5×218 or 5×2 20 In this embodiment, the value of m is 5×2 20 .
[0236] (1-2) The key generation center determines the intermediate parameter s according to formula (2):
[0237] The other steps of this step are the same as those in Example 1.
[0238] (2) Generate partial private keys for IoT smart devices
[0239] This step is the same as in Example 1.
[0240] (3) Generate a partial private key for a third-party server
[0241] This step is the same as in Example 1.
[0242] (4) Generate public and private keys for IoT smart devices
[0243] This step is the same as in Example 1.
[0244] (5) Certificateless Ring Signature Cryptography
[0245] (5-1) IoT smart devices select two vectors
[0246] This step is the same as in Example 1.
[0247] (5-2) IoT smart devices build intermediate parameters and hash values
[0248] IoT Smart Device ID x Construct the intermediate parameter μ according to formula (4), and construct the hash value N according to formula (5) x :
[0249] The expressions of formula (4) and formula (5) are the same as those in Example 1.
[0250] In formula (5), ID x ∈{ID 1 ,ID 2 ,…,ID N}, N is the number of devices in the system, N∈[10,600], and the value of N in this embodiment is 600.
[0251] The other steps of this step are the same as those in Example 1.
[0252] The other steps are the same as those in Example 1. The Internet of Things privacy protection method based on lattice ring signcryption is completed.
[0253] Example 4
[0254] In the above embodiments 1 to 3, the steps of the IoT privacy protection method based on lattice ring signcryption in this embodiment are as follows:
[0255] (1) System initialization
[0256] (1-1) Set the system security parameter n, n is 2 8 or 2 9 or 2 10 In this embodiment, the value of n is 2 10 The key generation center selects a prime number q, and the value of q is 3 or 5 or 7 or 11. In this embodiment, the value of q is 5.
[0257] The other steps of this step are the same as those in Example 1.
[0258] The other steps are the same as those in the corresponding embodiment. The privacy protection method of the Internet of Things based on lattice ring signcryption is completed.
Claims
1. A privacy protection method for the Internet of Things based on lattice ring signcryption, characterized in that It consists of the following steps: (1) System initialization (1-1) Set the system security parameter n, where n is a finite positive integer. The key generation center selects a prime number q ≥ 3 and sets the Gaussian parameter σ according to formula (1): Where t represents the control Gaussian sampling error parameter, m and k represent the number of vectors, t and k are finite positive integers, m≥5nlogq; (1-2) The key generation center determines the intermediate parameter s according to formula (2): Among them, ω represents the time complexity function, Represents space complexity; (1-3) The key generation center selects four collision-resistant hash functions H1, H2, H3, and H4: Among them, {0,1} * Represents a bit string of any length consisting of 0s and 1s, {0,1} n represents a bit string of length n consisting of 0s and 1s, represents an n-row, k-column matrix consisting of integers modulo q, represents a k-row, 1-column matrix consisting of integers modulo q, represents a 1-row, k-column matrix consisting of integers modulo q, is an n-row, 1-column matrix consisting of integers modulo q; (1-4) The key generation center obtains the matrix A through the trapdoor generation method. As the system public key, we get the grid Λ ⊥ (A) on the short base As the master private key, the following equation holds: A·B=0modq ||B||≤O(nlogq) in, represents an n-row and m-column matrix consisting of integers modulo q, An m-row and m-column matrix consisting of integers modulo q, ||B|| represents the normal form of B; (1-5) The key generation center encrypts the master key A of the system and publishes the global parameter L of the system: L={t,n,m,σ,s,A,H1,H2,H3,H4}; (2) Generate partial private keys for IoT smart devices (2-1) The key generation center determines the hash value N according to formula (3) i : N i =H1(ID i ) (3) ID i ={ID1,ID2,…,ID N } i=1,2,…,N Among them, ID i is the identity information of the IoT smart device, N is the number of IoT smart devices in the system, and N is a finite positive integer; (2-2) The key generation center obtains the matrix D through the original image sampling method i , As part of the private key of the IoT smart device, the following two equations are true: A·D i =N i in, represents an m-row, k-column matrix consisting of integers modulo q, ||D i || means D i paradigm; (2-3) The key generation center outputs part of the private key D i To IoT smart devices; (3) Generate partial private key of third-party server (3-1) The key generation center calculates the hash value N y : N y =H1(ID y ) Among them, ID y It is the identity information of the third-party server; (3-2) The key generation center obtains the matrix D through the original image sampling method y , As part of the private key of the third-party server, the following two equations are true: A·D y =N y Among them, ||D y || means D y paradigm; (3-3) The key generation center outputs D y To third-party servers; (4) Generate public and private keys for IoT smart devices (4-1) The IoT smart device selects a matrix C consisting of m rows and k columns composed of integers modulo q i , Determine the intermediate parameter E i 、Private key F of IoT smart device i : AND i =A·C i F i =C i +D i And the following two equations hold: Among them, C i It is the public key of the IoT smart device; (4-2) The third-party server selects a matrix C with m rows and k columns consisting of integers modulo q y , Determine the intermediate parameter E y 、Private key F of the third-party server y : AND y =A·C y F y =C y +D y And the following two equations hold: Among them, C y It is the public key of the third-party server; (5) Certificateless Ring Signature Cryptography (5-1) IoT smart devices select two vectors Given an identity set of IoT smart device ring members {ID1, ID2, …, ID N } and the message d to be signed, d∈{0,1} n , with identity ID x The IoT smart devices choose two vectors: (5-2) IoT smart devices build intermediate parameters and hash values IoT Smart Device ID x Determine the intermediate parameter μ according to formula (4) and determine the hash value N according to formula (5) x : μ=H2(d) (4) N x =H1(ID x ) (5) Among them, ID x ∈{ID1,ID2,…,ID N }; (5-3) IoT smart device ID x Determine partial ciphertext Q1 and Q2 as follows: Q1=A T r1 Q2=Ar2+N x ·μ; (5-4) IoT smart device ID x Determine the partial ciphertext c as follows: N y =H1(ID y ); (5-5) IoT smart device ID x choose Determine the hash value k according to the formula i : k i =H4(d,a i ,ID i ) Where i = 1, 2, ..., N and i ≠ x; For i=x, IoT smart device ID x By probability Determine the intermediate parameter k as follows x : k x =H4(d,a x ,ID x ) AND x =A·C x Among them, M is a constant that is not 0, C x is a matrix of m rows and k columns consisting of integers modulo q; (5-6) IoT smart device ID x Determine the partial ciphertext T1 as follows: T1=A(r2+F x μ)+E x ·k x (5-7) IoT smart device ID x Output ciphertext γ: γ=(Q1,Q2,T1,T x ,c,a1,a2,…,a N ) Give an ID y A third-party server, where Y x is the timestamp; (6) Decryption (6-1) Given the current timestamp T x1 , third-party server ID y , verify whether the following inequality holds: |T x -T x1 |≤ΔT x Where, ΔT x is the maximum value of the valid time interval. If it is true, it means that T x Is a valid timestamp, third-party server ID y Confirm message d as follows: (6-2) Third-party server ID y Determine the intermediate parameter k as follows i : k i =H4(d,a i ,ID i ) i=1,2,…,N (6-3) Third-party server ID y Determine the intermediate parameter μ as follows: μ=H2(d) (6-4) Third-party server ID y Verify that the following two equations hold: If both are true, the plain text is valid, otherwise it is invalid.
2. The Internet of Things privacy protection method based on lattice ring signcryption according to claim 1 is characterized in that: In step (1) of system initialization (1-1), the system security parameter n is set to 2. 8 or 2 9 or 2 10 , the key generation center selects a prime number q, q takes the value of 3 or 5 or 7 or 11, and sets the Gaussian parameter σ: In the example, t represents the parameter controlling the Gaussian sampling error, t∈[1,10], m and k represent the number of vectors, k∈[1,10], and m is 5×2. 16 or, 5×2 18 or 5×2 20 .
3. The Internet of Things privacy protection method based on lattice ring signcryption according to claim 1 or 2 is characterized in that: In step (1) of system initialization (1-1), the system security parameter n is set, and the value of n is 2 9 , the key generation center selects a prime number q, q takes the value of 7, and sets the Gaussian parameter σ according to formula (1): Among them, t represents the parameter controlling the Gaussian sampling error, t is 5, m and k represent the number of vectors, k is 5, m≥5nlogq, and m is 5×2 18 .
4. The Internet of Things privacy protection method based on lattice ring signcryption according to claim 1 is characterized in that: In the formula (3) of step (2-1) of generating a partial private key of the IoT smart device in step (2), the ID i is the identity information of the IoT smart device, N is the number of devices in the system, N∈[10,600].
5. The Internet of Things privacy protection method based on lattice ring signcryption according to claim 1 or 4, characterized in that: In the formula (3) of step (2-1) of generating a partial private key of the IoT smart device in step (2), the ID i is the identity information of the IoT smart device, N is the number of devices in the system, and the value of N is 300.
Citation Information
Patent Citations
On-grid certificateless signcryption method with post quantum security
CN110176995A
Certificateless ring signcryption method based on multiplication group
CN110995412A
Video service providing method and device, electronic equipment and storage medium
CN111581434A
Certificateless threshold signcryption method under secret sharing mechanism
CN112260830A
Certificateless network coding lattice ring signcryption method
CN113079021A