A method and device for estimating encryption state based on secret sharing

Through fully symmetric multicellular method and secret sharing technology, a member estimator is built and encrypted and decrypted in the cloud, solving the problem of data leakage in wireless communication systems, and achieving efficient security state estimation with low computing volume, suitable for vehicle networking and smart grids.

CN120166396BActive Publication Date: 2025-08-22WUHAN INST OF TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510639814.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-08-22
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

Existing wireless communication systems have a risk of data leakage when facing attackers' eavesdropping, especially in linear discrete systems containing unknown but bounded noise. The Paillier encryption algorithm is computationally expensive and complex to decrypt.

Method used

The encrypted state estimation method based on secret sharing is adopted, and the crew estimator is constructed through a fully symmetric multicellular method, and the preset mapping function is integerized and quantized, and the state estimation set is encrypted and decrypted in a cloud that does not trust each other through secret sharing method to achieve secure transmission of the state estimation set.

Benefits of technology

It effectively prevents attackers from eavesdropping, reduces the probability of secret attacks, has low computational volume, and is suitable for control systems such as the Internet of Vehicles and smart grids, improving the security and efficiency of network transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120166396B_ABST
    Figure CN120166396B_ABST
Patent Text Reader

Abstract

The present invention relates to an encrypted state estimation method and device based on secret sharing, the method comprising: obtaining input and output data of a target communication system; constructing a set membership estimator based on the input and output data using a fully symmetric polytope method; outputting a state estimation set of the target communication system in real time based on the set membership estimator; sequentially integerizing and quantizing each element of the state estimation set using a preset mapping function to obtain a quantized state estimation set; encrypting the quantized state estimation set using a secret sharing method based on at least two mutually distrusting and non-cooperative clouds; receiving and decrypting the encrypted data of each cloud to obtain a state estimation set of the target communication system. The present invention combines the construction of a set membership estimator using the polytope method with the state estimation set, thereby reducing the computational complexity while improving security and reducing the probability of a privacy-reducing attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of wireless communication and encryption technology, and particularly relates to an encryption state estimation method and system based on secret sharing. Background Art

[0002] With the development of network technology, wireless communication is finding increasing application. However, the existence of wireless networks can also lead to attacks from competitors. To launch covert attacks, attackers need to eavesdrop on system input and output data, thereby obtaining relevant system parameters. Therefore, to prevent attackers from obtaining real system data, encrypting data transmitted over the network is essential.

[0003] Aiming at the problem of estimating the encrypted state of a linear discrete system with unknown but bounded noise, an encryption method based on secret sharing is adopted to solve the problems of large data communication volume and large number of encryption and decryption in Paillier encryption. Summary of the Invention

[0004] To solve the problems raised in the background technology, a first aspect of the present invention provides an encrypted state estimation method based on secret sharing, comprising: obtaining input and output data of a target communication system; constructing a set membership estimator according to the input and output data by a fully symmetric polyhedral method; outputting a state estimation set of the target communication system in real time based on the set membership estimator; integerizing and quantizing each element of the state estimation set in turn by a preset mapping function to obtain a quantized state estimation set; encrypting the quantized state estimation set by a secret sharing method based on at least two mutually distrustful and non-cooperative clouds; receiving and decrypting the encrypted data of each cloud to obtain a state estimation set of the target communication system.

[0005] In some embodiments of the present invention, each element of the state estimation set is sequentially integerized and quantized through a preset mapping function to obtain a quantized state estimation set, which includes: integerizing each element in the state estimation set through a preset mapping function; and quantizing each element in the integerized state estimation set through a coefficient matrix determined by a set membership estimator.

[0006] Furthermore, the method also includes constraining the quantization error by presetting multiple parameters in the mapping function.

[0007] In some embodiments of the present invention, based on at least two mutually distrustful and non-cooperative clouds, encrypting the quantized state estimation set through a secret sharing method includes: encrypting each element in the quantized state estimation set through a preset mapping function to obtain multiple encrypted data; and distributing the multiple encrypted data to at least two mutually distrustful and non-cooperative clouds.

[0008] Furthermore, decrypting the encrypted data of each cloud includes: decrypting the encrypted data of each cloud by inverse of a preset mapping function.

[0009] In the above embodiment, constructing a set membership estimator based on the input and output data through the fully symmetric polyhedron method includes: constructing a discrete-time system model based on the input and output data; determining the center and generating matrix of the system model through the fully symmetric polyhedron method; and constructing a set membership estimator based on the center and generating matrix.

[0010] The second aspect of the present invention provides an encrypted state estimation device based on secret sharing, including: an acquisition module for acquiring input and output data of a target communication system; constructing a set membership estimator based on the input and output data through a fully symmetric polyhedral method; outputting a state estimation set of the target communication system in real time based on the set membership estimator; a quantization module for sequentially integerizing and quantizing each element of the state estimation set through a preset mapping function to obtain a quantized state estimation set; an encryption module for encrypting the quantized state estimation set through a secret sharing method based on at least two mutually distrusting and non-cooperative clouds; and a decryption module for receiving and decrypting the encrypted data of each cloud to obtain a state estimation set of the target communication system.

[0011] The third aspect of the present invention provides an electronic device, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the encryption state estimation method based on secret sharing provided in the first aspect of the present invention.

[0012] A fourth aspect of the present invention provides a computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the encryption state estimation method based on secret sharing provided in the first aspect of the present invention is implemented.

[0013] The beneficial effects of the present invention are:

[0014] This paper proposes a design method for an encrypted state estimator based on (2,2)-threshold secret sharing. This method not only handles the presence of unknown but bounded noise sets and initial state sets, but also effectively prevents eavesdropping attacks, thereby reducing the probability of attackers launching stealth attacks. Compared with the Paillier homomorphic encryption algorithm, this method has a lower computational cost and is suitable for control systems transmitted over networks, such as the Internet of Vehicles and smart grid systems, showing high application value. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1Schematic diagram of a basic flow of a secret sharing-based encryption state estimation method in some embodiments of the present invention;

[0016] Figure 2 Schematic diagram of the principle of an encryption state estimation method based on secret sharing in some embodiments of the present invention;

[0017] Figure 3 Schematic diagram of the structure of an encryption state estimation device based on secret sharing in some embodiments of the present invention;

[0018] Figure 4 Schematic diagram of the structure of an electronic device in some embodiments of the present invention. DETAILED DESCRIPTION

[0019] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0020] refer to Figure 1 and Figure 2 In a first aspect of the present invention, a method for estimating an encryption state based on secret sharing is provided, comprising:

[0021] S100. Obtain input and output data of the target communication system; construct a set membership estimator based on the input and output data by a fully symmetric polytope method; based on the set membership estimator, output a state estimation set of the target communication system in real time;

[0022] S200. By using a preset mapping function, each element of the state estimation set is sequentially integerized and quantized to obtain a quantized state estimation set;

[0023] S300. Encrypting the quantized state estimate set by a secret sharing method based on at least two mutually distrusting and non-cooperative clouds;

[0024] S400. Receive and decrypt the encrypted data of each cloud to obtain a state estimation set of the target communication system.

[0025] It should be noted that the target communication systems in this disclosure are typically linear discrete systems with bounded noise. A fully symmetric polytope (zonotope) is a special geometric structure commonly used to describe bounded sets in high-dimensional space. It can be generated from a hypercube via an affine transformation and exhibits both symmetry and convexity. In control theory and system estimation, fully symmetric polytopes are widely used to represent the state set of a system, particularly when dealing with uncertainty and noise.

[0026] In step S100 of some embodiments of the present invention, constructing a set membership estimator using a fully symmetric polytope method based on the input and output data includes:

[0027] S101. Constructing a discrete-time system model based on the input and output data;

[0028] Specifically, the following discrete-time system model is established:

[0029] (1),

[0030] (2),

[0031] in, is the system status, is the output of the sensor, For system interference, is the noise of the sensor, A and C is a known system matrix.

[0032] S102. Determine the center and generator matrix of the system model by a fully symmetric polyhedral method;

[0033] Specifically, and satisfy and ,in and Indicates that the center is at the origin, and the generated matrix is Hω and Hv A fully symmetric polytope, and Hω and Hv is the given matrix.

[0034] S103. Construct a set membership estimator based on the center and the generator matrix.

[0035] Specifically, the initialization parameters: p 0, H 0, Hω and Hv ,in Represents the initial set of estimates. Iteratively solve the estimator:

[0036] (1)

[0037] (2)

[0038] in, for k -1 time state estimation set, Select to make Stable matrix, I Is an identity matrix of appropriate dimension. Estimator output: set of state estimates .

[0039] It can be understood that since the encryption algorithm is based on integers, and data such as system status are real numbers, it is first necessary to map real numbers to integer space.

[0040] Therefore, in step S200 of some embodiments of the present invention, each element of the state estimation set is sequentially integerized and quantized by a preset mapping function to obtain a quantized state estimation set, which includes: S201. Integerizing each element of the state estimation set by a preset mapping function;

[0041] Specifically, the following sets are defined:

[0042] (3)

[0043] in, b , m and r is a natural number, and ; b Represents the base, m Indicates magnitude, r Indicates accuracy. Define mapping function , R represents the set of real numbers, then:

[0044] (4)

[0045] In order to Mapping to a set of integers is done as follows:

[0046] (5)

[0047] definition ,in Q is an integer. Therefore, we can get:

[0048] , in, z 1 and z 2 is an integer.

[0049] definition The partial inverse of:

[0050] (6)

[0051] From the above formula we can get:

[0052] , .

[0053] S202. Quantize each element in the integerized state estimation set using a coefficient matrix determined by a set membership estimator.

[0054] Specifically, based on the above, the estimation result obtained in the first step is transformed to facilitate encryption calculation. First, the estimator is rewritten, and the result is as follows:

[0055] (7)

[0056] in, , , .

[0057] Similarly, , , In order to realize encryption operation, through the quantization algorithm, we can get:

[0058] , (8)

[0059] in, , , , .

[0060] In order to ensure the accuracy of quantization, it is necessary to constrain the error through a constraint function, which also includes: S203. Constraining the quantization error through multiple parameters in a preset mapping function.

[0061] Specifically, if at each moment k there is and , , , then the quantization error satisfies the following constraints:

[0062] , (9)

[0063] in, , .

[0064] In step S300 of some embodiments of the present invention, encrypting the quantized state estimate set by a secret sharing method based on at least two mutually untrusting and non-cooperative clouds includes:

[0065] S301. Encrypt each element in the quantized state estimation set by a preset mapping function to obtain multiple encrypted data;

[0066] Specifically, this disclosure takes (2,2)-threshold secret sharing encryption as an example, Figure 2 As shown, it includes the system part and two independent clouds. It is assumed that the two clouds do not trust each other and are non-cooperative.

[0067] First, system encryption and , the execution process is as follows:

[0068] (10)

[0069] in, , , .

[0070] (11)

[0071] in, , , , q is a matrix The number of columns.

[0072] S302. Distribute the plurality of encrypted data to at least two mutually distrustful and non-cooperative clouds.

[0073] Next, the first cloud performs the following calculations:

[0074] , (12)

[0075] in, nx and ny Represent the dimensions of the state vector and output vector respectively. and After that, the first cloud sends them to the system through a secure network channel.

[0076] The second cloud performs the following calculations:

[0077] , (13)

[0078] Calculated and After that, a second cloud sync sends them to the system through a secure network channel.

[0079] It is understood that although this disclosure divides the quantized data using a (2,2)-threshold, it does not affect its generalization to multiple thresholds, that is, assigning the data to more than two clouds to perform the above calculations. (2,2)-threshold secret sharing can be achieved through a polynomial-based secret sharing scheme, such as the Shamir secret sharing algorithm. Specifically, first select parameters, determine the secret S and a large prime number p. Then construct the polynomial: select a linear polynomial. ,in a0 = S(secret), a1 is a randomly selected coefficient. Then generate the share: calculate f (1) and f (2), distribute these two values ​​as two shares to the two participants. Finally, recover the secret: When the two participants provide their shares, the polynomial can be recovered by Lagrange interpolation. f ( x ), thus obtaining the constant term a0 (i.e. secret S ).

[0080] In step S400 of some embodiments of the present invention, encrypted data of each cloud is received and decrypted to obtain a set of state estimates of the target communication system.

[0081] Specifically, after the system receives the encrypted data sent by the two clouds, it decrypts it to obtain the estimated state set. The process is as follows:

[0082] (14)

[0083] (15)

[0084] in, , .gather That is k The state estimate set at time t.

[0085] If exists , , and , the following conditions can be satisfied:

[0086] (16)

[0087] (17)

[0088] Then, the state estimation set obtained by (14)-(15) and the state estimation set obtained by (8) are equivalent.

[0089] Example 2

[0090] refer to Figure 3According to a second aspect of the present invention, an encrypted state estimation device 1 based on secret sharing is provided, comprising: an acquisition module 11 for acquiring input and output data of a target communication system; constructing a set membership estimator according to the input and output data by a fully symmetric polyhedral method; outputting a state estimation set of the target communication system in real time based on the set membership estimator; a quantization module 12 for sequentially integerizing and quantizing each element of the state estimation set by a preset mapping function to obtain a quantized state estimation set; an encryption module 13 for encrypting the quantized state estimation set by a secret sharing method based on at least two mutually distrusting and non-cooperative clouds; and a decryption module 14 for receiving and decrypting the encrypted data of each cloud to obtain a state estimation set of the target communication system.

[0091] Furthermore, the quantization module 12 includes: an integerization unit for integerizing each element in the state estimation set through a preset mapping function; and a quantization unit for quantizing each element in the integerized state estimation set through a coefficient matrix determined by a set membership estimator.

[0092] Example 3

[0093] refer to Figure 4 According to a third aspect of the present invention, an electronic device is provided, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the encryption state estimation method based on secret sharing according to the first aspect of the present invention.

[0094] The electronic device 500 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. Various programs and data required for the operation of the electronic device 500 are also stored in the RAM 503. The processing device 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0095] Typically, the following devices may be connected to the I / O interface 505: an input device 506 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 508 including, for example, a hard disk, etc.; and a communication device 509. The communication device 509 may allow the electronic device 500 to communicate with other devices wirelessly or by wire to exchange data. Figure 4The electronic device 500 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 4 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0096] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 509, or installed from the storage device 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above-mentioned functions defined in the method of the embodiment of the present disclosure are executed. It should be noted that the computer-readable medium described in the embodiment of the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In embodiments of the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, an electromagnetic signal, an optical signal, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device. Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wire, optical cable, RF (radio frequency), etc., or any suitable combination thereof.

[0097] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more computer programs, which, when executed by the electronic device, cause the electronic device to:

[0098] Computer program code for performing the operations of embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, Python, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0099] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0100] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for estimating an encryption state based on secret sharing, characterized in that: include: Obtain input and output data of the target communication system; Constructing a set membership estimator according to the input and output data by a fully symmetric polytope method includes: constructing a discrete-time system model according to the input and output data: , ;in, is the system status, is the output of the sensor, For system interference, is the noise of the sensor, A and C is a known system matrix; the center and generator matrix of the system model are determined by the fully symmetric polytope method; based on the center and generator matrix, a set membership estimator is constructed; the set membership estimator is expressed as: , ,in, for k -1 time state estimation set, Select to make Stable matrix, I is an identity matrix of appropriate dimension; estimator output: state estimate set Based on the set membership estimator, the state estimation set of the target communication system is output in real time; By using a preset mapping function, each element of the state estimation set is sequentially integerized and quantized to obtain a quantized state estimation set: each element in the state estimation set is integerized by using a preset mapping function; and each element in the integerized state estimation set is quantized by using a coefficient matrix determined by a set membership estimator, including: rewriting the estimator: , in, , , ; , , ; Through the quantization algorithm, we get: , ; in, , , , ; Based on at least two mutually untrusted and non-cooperative clouds, the quantized state estimation set is encrypted by a secret sharing method; Receive and decrypt the encrypted data of each cloud to obtain the state estimation set of the target communication system.

2. The encryption state estimation method based on secret sharing according to claim 1, characterized in that: The method also includes constraining the quantization error by presetting multiple parameters in the mapping function.

3. The encryption state estimation method based on secret sharing according to claim 1, characterized in that: The encrypting of the quantized state estimation set by a secret sharing method based on at least two mutually distrustful and non-cooperative clouds includes: Each element in the quantized state estimation set is encrypted by a preset mapping function to obtain multiple encrypted data; Distribute multiple encrypted data to at least two mutually untrusting and non-cooperative clouds.

4. The encryption state estimation method based on secret sharing according to claim 3, characterized in that: Decrypting the encrypted data of each cloud includes: The encrypted data of each cloud is decrypted by the inverse of the preset mapping function.

5. An encryption state estimation device based on secret sharing, characterized in that: include: An acquisition module, used to obtain input and output data of the target communication system; Constructing a set membership estimator according to the input and output data by a fully symmetric polytope method includes: constructing a discrete-time system model according to the input and output data: , ;in, is the system status, is the output of the sensor, For system interference, is the noise of the sensor, A and C is a known system matrix; the center and generator matrix of the system model are determined by the fully symmetric polytope method; based on the center and generator matrix, a set membership estimator is constructed; the set membership estimator is expressed as: , ,in, for k -1 time state estimation set, Select to make Stable matrix, I is an identity matrix of appropriate dimension; estimator output: state estimate set Based on the set membership estimator, the state estimation set of the target communication system is output in real time; The quantization module is configured to sequentially integerize and quantize each element of the state estimation set using a preset mapping function to obtain a quantized state estimation set: integerizing each element in the state estimation set using a preset mapping function; and quantizing each element in the integerized state estimation set using a coefficient matrix determined by a set membership estimator, including rewriting the estimator: , in, , , ; , , ; Through the quantization algorithm, we get: , ; in, , , , ; An encryption module, configured to encrypt the quantized state estimation set by a secret sharing method based on at least two mutually untrusting and non-cooperative clouds; The decryption module is used to receive and decrypt the encrypted data of each cloud to obtain a state estimation set of the target communication system.

6. An electronic device comprising: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the one or more processors to implement the encryption state estimation method based on secret sharing as described in any one of claims 1 to 4.

7. A computer-readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the encryption state estimation method based on secret sharing according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • State estimation method for event-triggered transmission complex network based on set membership estimation

    CN112260867A