Internet of vehicles searchable encryption privacy protection method based on zero knowledge proof

By adopting zero-knowledge proof and fog computing outsourcing tasks in the intelligent Internet of Vehicles system, combining blockchain smart contracts and distributed storage, the problems of data security and privacy protection of Internet of Vehicles are solved, and efficient and secure data sharing and privacy protection are achieved.

CN120263419APending Publication Date: 2025-07-04CHINA UNIV OF MINING & TECH (BEIJING)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510443461.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the intelligent Internet of Vehicles system, the security and privacy protection of vehicle data have not been effectively solved. There is a risk of data leakage in centralized storage methods. Traditional encryption solutions have high computing overhead, which affects the real-time and scalability of the system.

Method used

Using the encryption method based on zero-knowledge proof, the outsourcing proof generation task is used through fog computing, combined with blockchain smart contract record data sharing and access control, and the distributed storage system IPFS is used to realize the security sharing and privacy protection of data.

Benefits of technology

It improves data security and storage efficiency, reduces the computing burden of terminal devices, ensures the transparency and traceability of data access, resists adaptive keyword selection attacks, and improves the usability and fairness of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure BDA0005351818660000032
    Figure BDA0005351818660000032
  • Figure BDA0005351818660000046
    Figure BDA0005351818660000046
Patent Text Reader

Abstract

The invention discloses an Internet of Vehicles searchable encryption privacy protection method based on zero knowledge proof, and the method comprises the steps: encrypting vehicle operation data and driving behavior data obtained by vehicle terminal equipment, and storing the data to an IPFS distributed storage system; keyword search encryption is carried out by utilizing zk-SNARKs, and data access permission verification is realized under the condition that user attributes are not leaked; a data owner is allowed to delegate a zk-SNARKs certification generation task to a fog computing server, so that the computing burden of the Internet of Vehicles equipment is reduced; data sharing and access operations are recorded through a block chain smart contract, and transparency and traceability of an access process are ensured; and the data retrieval efficiency is improved by utilizing an IPFS content addressing mechanism. According to the invention, data sharing security and communication efficiency can be improved while data privacy of the intelligent Internet of Vehicles is protected, a multi-chain architecture is supported, and data security sharing and privacy protection in scenes such as intelligent traffic and automatic driving are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent Internet of Vehicles (IoV), and in particular to a privacy protection method for searchable encryption in IoV based on zero - knowledge proof, which combines non - interactive zero - knowledge proof, fog computing, blockchain and IPFS distributed storage to achieve secure data sharing and privacy protection. Background Art

[0002] With the development of intelligent connected vehicles and IoV technologies, more and more vehicles and traffic infrastructure are interconnected through wireless communication technologies. However, the data generated by the intelligent IoV system mostly contains sensitive personal information, vehicle operation data, and driving behavior privacy data, and the security and privacy protection issues of these data become particularly important.

[0003] In the IoV scenario, driving data not only involves the operating state of the vehicle itself, such as speed, driving route, number of hard brakes, driving habits, etc., but also involves sensitive information such as the identity information of the vehicle owner and the vehicle location. If not effectively protected, it may lead to user privacy leakage and even be exploited by criminals for data abuse, malicious tracking or fraud. Currently, IoV data sharing usually relies on a centralized server storage and access control mechanism, but this method has obvious security risks. The single - point failure of the traditional centralized data storage method faces the risks of data tampering, leakage, or server downtime. Once the central server is attacked or the data is damaged, it will affect the stability of the entire system.

[0004] In IoV application scenarios such as intelligent traffic scheduling, insurance pricing, and in - vehicle entertainment systems, vehicle data usually needs to be shared with third parties. However, the traditional plain - text data sharing method may lead to user privacy leakage, and users cannot control which data is accessed by whom. The traditional security solutions based on complex encryption have high computational overheads, which pose high requirements on the computing power and storage of IoV terminals, affecting the real - time performance and scalability of the system. The privacy protection method for searchable encryption in IoV based on zero - knowledge proof allows IoV terminals with limited computing power to delegate the proof generation task to an untrusted fog server, thereby reducing the computational burden on the terminal device and improving the usability and efficiency of the system, while ensuring data security, optimizing computational efficiency, and hiding user attributes. Summary of the Invention

[0005] The object of the present invention is to provide a privacy protection method for searchable encryption in vehicle-to-everything (V2X) networks based on zero-knowledge proof, which uses non-interactive zero-knowledge proof to hide user attributes, and at the same time introduces fog computing to accelerate the generation of zero-knowledge proof and reduce the computational overhead. In addition, blockchain smart contracts are used to record all data sharing and access control operations to ensure data transparency and traceability. This method can effectively resist adaptive keyword selection attacks, and significantly improve data security, storage efficiency and sharing fairness compared with traditional solutions. A privacy protection method for searchable encryption in vehicle-to-everything (V2X) networks based on zero-knowledge proof specifically includes the following steps:

[0006] (1) Generate a non-interactive zero-knowledge proof of the hidden attributes of the data user DU by the fog server FNs, and the data user DU generates an attribute key based on the non-interactive zero-knowledge proof;

[0007] (2) The data owner DO encrypts the shared data to obtain an encrypted shared file;

[0008] (3) The data owner DO stores the encrypted shared file in the distributed storage system IPFS, and provides the encrypted index, encrypted file key and storage address of the encrypted shared file to the data user DU;

[0009] (4) Based on the response information, the data user DU generates a search trapdoor using the attribute key and sends the search trapdoor to the blockchain center BC;

[0010] (5) The data user DU requests the access permission of the encrypted shared file from the blockchain center BC by submitting the non-interactive zero-knowledge proof;

[0011] (6) The blockchain center BC verifies whether the attributes of the data user DU meet the requirements of the access permission based on the non-interactive zero-knowledge proof. If so, it returns a response message indicating that the access verification is passed to the data user DU;

[0012] (7) The blockchain center BC uses the search trapdoor to match the keyword ciphertext. If the keyword match is successful, it returns the encrypted file related to the keyword ciphertext to the data user DU, and the data user DU decrypts the encrypted file after downloading it from the storage address.

[0013] Optionally, according to the method of the embodiment of the present invention, the generating of the attribute key includes:

[0014] The fog server FNs send the generated file of the hidden attribute non-interactive zero-knowledge proof to the smart contract of the blockchain center BC; the trusted third-party certification authority CA generates a key according to the attributes set for the data user DU after user automation, and the trusted third-party certification authority CA randomly selects elements and calculates the attribute key.

[0015] Optionally, according to the method of an embodiment of the present invention, the fog server FNs are hosted or deployed by a third-party platform, and the fog server FNs use the zkSaaS framework protocol to generate a fast and convenient non-interactive zero-knowledge proof to hide attributes, so as to protect user attribute privacy, and at the same time outsource the hidden attribute non-interactive zero-knowledge proof generation task to a group of untrusted fog servers FNs.

[0016] Optionally, according to the method of an embodiment of the present invention, in step 2, encrypting the shared data includes:

[0017] Step 1: Encrypt the file containing driving behavior data to obtain an encrypted shared file, upload the encrypted shared file to the distributed storage system IPFS, and obtain the storage address of the encrypted shared file in the distributed storage system IPFS;

[0018] Step 2: Extract the keywords in the encrypted shared file, encrypt the keywords in the encrypted shared file to form keyword ciphertext, calculate the root node value according to the keywords in the encrypted shared file, and establish an encrypted index of the keywords;

[0019] Step 3: After encrypting the key and storage address of the encrypted shared file, the data owner DO generates ciphertext and uploads the ciphertext to the blockchain, and the ciphertext includes the encrypted file key and the storage address.

[0020] Optionally, according to the method of an embodiment of the present invention, the shared data is stored in the distributed storage system IPFS and adopts a content addressing mechanism.

[0021] In summary, the present invention provides an efficient, secure and fair intelligent vehicle networking data sharing scheme, which is applicable to fields such as autonomous driving data sharing, fleet management, intelligent traffic scheduling and privacy computing. Brief Description of the Drawings

[0022] Figure 1 is a flowchart of a vehicle networking searchable encryption privacy protection method based on zero-knowledge proof in this application Detailed Embodiments

[0023] To solve the problems in the above background technology, this application provides a privacy protection method for searchable encryption in the vehicle networking based on zero-knowledge proof. To make the purpose, technical solution and advantages of this application clearer, the technical solutions in the embodiments of this application will be described clearly and completely below.

[0024] As Figure 1 shown, the data sharing method of this application includes:

[0025] (1) Generate a non-interactive zero-knowledge proof of the hidden attributes of the data user DU through the fog server FNs, and the data user DU generates an attribute key based on the non-interactive zero-knowledge proof.

[0026] Specifically, the fog server FNs are hosted or deployed by a third-party platform, and use the zkSaaS framework protocol to generate fast and convenient non-interactive zero-knowledge proofs to hide attributes, which can protect the user attribute privacy of the hidden data user DU, and at the same time outsource the non-interactive zero-knowledge proof generation task to a group of untrusted fog servers. These fog servers FNs can jointly generate non-interactive zero-knowledge proofs at a faster speed to reduce the computing overhead of the DU device.

[0027] The system parameters are released by a trusted third-party certification authority CA to ensure system integrity. Given the system public key PK, the master key MK, the system parameter crs, and the number n of input fog servers FNs, this PPT sends information to n FNs fog servers within one cycle. Each fog server FNs is assigned a unique identifier P i , i ∈ [n], and generates relevant random numbers pre1,..., pre n :

[0028] Preprocessing(crs,1 n ) → pre1,..., pre n

[0029] The MPC protocol connects the data owner DO to n fog servers FNs. And processes the user identity data. The data user DU includes the statement φ and the private input s. Then, an interactive protocol is carried out among the fog servers FNs to calculate the zero-knowledge proof π j :

[0030] Π online (crs, φ, s, pre1,..., pre n ) → π j

[0031] S is the attribute set of DU, j ∈ S, the fog server FNs randomly select a secret integer v to generate a private key, G is a point on the elliptic curve, and calculate Q = vG.

[0032] Among them, the fog server FNs randomly selects an integer m belonging to the multiplicative group of modulo prime number p, and then calculates the point P = mG, and uses the hash function H1 to calculate the challenge: σ j = H1(G||Q||P||j), and the fog server FNs calculates the zero-knowledge proof π j for the challenge σ j , π j = m + σ j *v (mod p), which is consistent with the zero-knowledge proof generated above. The trusted third-party certification authority CA generates keys for the attributes set for the data user DU. The trusted third-party certification authority CA randomly selects elements input the system public key PK, the master key MK, K1, K2, K j , K j ' represents a part of the authorization key, and calculates the attribute key SK p :

[0033]

[0034] (2) The data owner DO encrypts the shared data to obtain an encrypted shared file.

[0035] The shared data therein includes: vehicle operation data and driving behavior data, vehicle owner identity information, license plate number, etc.

[0036] (3) The data owner DO stores the encrypted shared file in the distributed storage system IPFS, and provides the encrypted index, encrypted file key and storage address of the encrypted shared file to the data user DU.

[0037] 1) Encrypt and upload the file

[0038] The data owner DO randomly selects a symmetric key, denoted as k, SE is a symmetric encryption algorithm that supports keyword search, and uses it to encrypt the file F containing driving behavior privacy data. The encrypted file is called SE Enc(F). Upload the self-encrypted file to the distributed storage system IPFS, and use M = URL(SE Enc(F)) to obtain the result address.

[0039] 2) Encrypt the file keyword

[0040] The data owner DO randomly selects a value of and then calculates the value of according to the keyword w in the file F. The data owner DO inputs the public key PK and regards t as the root node of the access structure T. For each node x, assuming x is t, the data owner DO randomly selects a q with a specified degree d t = k t -1 valuet , and assign it the value q t (0) = z. For all other non-root nodes x, assign according to the parent node of x. In addition, a set of points is randomly selected for definition, where index(x) represents the parent node of x, and Parent(x) is the left child node of index(x). Define X as the set of terminal nodes in the access structure T, and the data owner DO calculates the ciphertext pair formed after encrypting the leaf node attributes For x ∈ X, establish the encrypted index of the keyword as

[0041] 3) Encrypt the file key and address

[0042] The data owner DO calculates C k = ke(g, g) αs , C' k = g βs , and the encryption key is k. Similar to the previous example, the data owner DO generates the encrypted file key C M = Me(g, g) αs and the encrypted address CT addr , and uploads them to the blockchain center BC

[0043] (4) The data user DU generates a search trapdoor using the attribute key based on the response information and sends the search trapdoor to the blockchain center BC

[0044] DU creates a search trapdoor T w ' and sends the search trapdoor to the blockchain center BC, which performs the search operation. is the set of keywords that DU is interested in. DU randomly selects an element T1 is the keyword ciphertext mapping value, T2 is the part related to the search, T3 is the part for privacy authentication, and T j represents the part corresponding to the key for each attribute j. DU calculates the search trapdoor T w′ :

[0045]

[0046] (5) The data user DU requests the access permission to the encrypted shared file from the blockchain center BC by submitting a non-interactive zero-knowledge proof

[0047] (6) Based on the non-interactive zero-knowledge proof, the blockchain center BC verifies whether the attributes of the data user DU meet the requirements of the access permission. If they meet, it returns a response message indicating that the access verification is passed to the data user DU

[0048] (7) The blockchain center BC uses a search trapdoor to match the keyword ciphertext. If the keyword match is successful, it returns the encrypted file related to the keyword ciphertext to the data user DU. The data user DU downloads the encrypted file from the storage address and then decrypts it.

[0049] Specifically, verify(G, φ, π j ):

[0050] The smart contract uses Q to calculate the point P' = π j G - σ j Q and outputs F x , if P = P', the attribute verification of the data user DU passes and enters the matching process; if P ≠ P', the attribute verification of the data user DU fails and the algorithm terminates. Assume that j is an element of the set S and x is a leaf node. Then calculate, if then F x = ⊥, if x ∈ S,

[0051]

[0052] The attribute set of the data user DU satisfies the access structure rule, thus obtaining e(g, g) rsz , and the calculation formula is as follows:

[0053]

[0054] The data user DU obtains the symmetric key:

[0055]

[0056] Finally, the data user DU uses the symmetric key to decrypt the data ciphertext obtained from the distributed storage system IPFS. The data user DU obtains the encrypted data address stored on the distributed storage system IPFS from the data owner DO. The data owner DO downloads the data from this address and decrypts the data plaintext using the symmetric key. The traffic management center, traffic police, and urban traffic scheduling system can then obtain the driving records.

[0057] The method of this application ensures the security and privacy of data access control to ensure the confidentiality and integrity of data access in different application scenarios.

Claims

1. A privacy protection method for searchable encryption in vehicle networking based on zero-knowledge proof, characterized in that, The method includes: Step 1: Generate a non-interactive zero-knowledge proof of the hidden attributes of the data user DU by the fog server FNs, and the data user DU generates an attribute key based on the non-interactive zero-knowledge proof; Step 2: The data owner DO encrypts the shared data to obtain an encrypted shared file; Step 3: The data owner DO stores the encrypted shared file in the distributed storage system IPFS and provides the encrypted index, encrypted file key and storage address of the encrypted shared file to the data user DU; Step 4: The data user DU generates a search trapdoor using the attribute key based on the response information and sends the search trapdoor to the blockchain center BC; Step 5: The data user DU requests the access permission of the encrypted shared file from the blockchain center BC by submitting the non-interactive zero-knowledge proof; Step 6: The blockchain center BC verifies whether the attributes of the data user DU meet the requirements of the access permission based on the non-interactive zero-knowledge proof. If so, it returns a response message indicating that the access verification is passed to the data user DU; Step 7, the blockchain center BC uses the search trapdoor to match the keyword ciphertext. If the keyword match is successful, it returns the encrypted file related to the keyword ciphertext to the data user DU, and the data user DU decrypts the encrypted file after downloading it from the storage address.

2. The method according to claim 1, wherein The generating of the attribute key includes: The fog server FNs sends the generated file of the non-interactive zero-knowledge proof of the hidden attributes to the smart contract of the blockchain center BC; the trusted third-party certification authority CA generates a key according to the attributes set for the data user DU after user automation, and the trusted third-party certification authority CA randomly selects elements and calculates the attribute key.

3. The method according to claim 2, characterized in that, The fog server FNs is hosted or deployed by a third-party platform. The fog server FNs uses the zkSaaS framework protocol to generate a fast and convenient non-interactive zero-knowledge proof to hide attributes to protect user attribute privacy, and at the same time outsources the task of generating the non-interactive zero-knowledge proof of the hidden attributes to a group of untrusted fog servers FNs.

4. The method according to claim 1, wherein In the step 2, the encrypting of the shared data includes: Step 1: Encrypt the file containing the driving behavior data to obtain an encrypted shared file, upload the encrypted shared file to the distributed storage system IPFS, and obtain the storage address of the encrypted shared file in the distributed storage system IPFS; Step 2: Extract the keywords in the encrypted shared file, encrypt the keywords in the encrypted shared file to form keyword ciphertexts, calculate the root node value according to the keywords in the encrypted shared file, and establish an encrypted index of the keywords; Step 3: After encrypting the key and storage address of the encrypted shared file, the data owner DO generates ciphertexts and uploads the ciphertexts to the blockchain. The ciphertexts include the encrypted file key and the storage address.

5. The method according to claim 1, characterized in that, The shared data is stored in the distributed storage system IPFS and adopts a content addressing mechanism.

6. The method according to claim 1, wherein It also includes: When the search conditions of the traffic management center, traffic police, and urban traffic dispatching system match the indexing conditions, driving records are obtained, and the blockchain center BC checks the matching and non-interactive zero-knowledge proofs.