Communication information security management system and method oriented to computing power resource perception scene
Through China's residual theorem, the group authentication mechanism is built, combined with the dynamic allocation strategy of modular space, the problem of low efficiency of large-scale multi-node authentication is solved, and an efficient, flexible and secure authentication method is realized, which is suitable for multi-node authentication and resource management in computing resource perception scenarios.
Patent Information
- Application Number
- CN202510677918.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-05-26
AI Technical Summary
The existing security authentication mechanism is inefficient and poorly scalable when the large-scale multi-node concurrent authentication requirements are required, and cannot meet the real-time requirements in high-density environments. There are problems such as the authentication delay linearly increasing with the number of nodes, complex key management, and insufficient dynamic adaptation capabilities.
The Chinese residual theorem is used to build a group authentication mechanism, combine it with the dynamic allocation strategy of modular space, generate private keys and public keys through the computing power perception center, establish an elliptical curve and an Abel group, realize single efficient authentication and batch authentication, and support only local parameters updates when dynamic addition and deletion of nodes, avoiding reconstruction of the entire network authentication link.
It significantly improves the authentication efficiency and adaptability in high dynamic scenarios, realizes semantic hiding and lightweight authentication of sensitive information, ensures the confidentiality of resource data transmission, and supports integrated security management of heterogeneous resources and cross-scenario migration applications.
Smart Images

Figure CN120263532A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computing power perception and multi-node communication security, and specifically to a communication information security management system and method for computing power resource perception scenarios. Background Art
[0002] The present invention belongs to the technical field of computing power perception and multi-node communication security, and specifically relates to a communication information security management system and method for computing power resource perception scenarios, which is applicable to system environments with dense deployment of dynamic nodes such as edge computing, Internet of Things terminals, and intelligent network-connected devices.
[0003] With the development of edge computing and computing power network architectures, in order to improve the flexibility of computing power distribution and task response speed, more and more computing nodes such as edge computing devices, intelligent terminals, and embedded nodes are deployed near the data sources close to users, building a computing power perception system with "cloud-edge-end" integrated collaboration. In this system, the computing power perception server, as the core control node, needs to continuously grasp the resource status of each computing node in the network, including computing power, storage capacity, bandwidth utilization, network latency, etc., in order to perform task allocation and resource optimization.
[0004] In actual deployment, especially in large-scale heterogeneous network environments, there are scenarios where a large number of devices access or leave the computing power network. These devices include edge computing nodes, access routers, intelligent switches, industrial control terminals, vehicle network-connected devices, etc. With the continuous expansion of the scale and variety of devices, the scalability and availability of the system face higher challenges. Therefore, before task collaboration or resource sharing, each node needs to report its resource status to the computing power perception server. At the same time, to ensure the overall security of the system, identity authentication and communication channel protection must be carried out to prevent security risks such as malicious device impersonation, resource tampering, and communication interference. In addition, the existing mechanisms generally adopt the plaintext transmission mode of computing power resource information, resulting in sensitive status data such as node computing power, storage capacity, and network load facing the risks of being stolen and analyzed. Attackers can use this information to carry out targeted resource abuse attacks or system vulnerability detections, further exacerbating the security risks of node privacy leakage and computing power network topology exposure.
[0005] However, existing security authentication mechanisms are mostly based on point-to-point interactive authentication protocols (such as TLS, ECDSA, symmetric key authentication, etc.), and there are problems of low authentication efficiency and poor scalability when facing the concurrent authentication requirements of a large number of multi-nodes. Nodes need to establish authentication sessions with the server one by one, and the authentication delay increases linearly with the number of nodes, unable to meet the real-time requirements in high-density environments; the frequent joining and leaving of nodes in the system require continuous updating of authentication keys or reconstruction of session links, increasing the management burden; and they also face problems such as complex certificate maintenance, difficult public key revocation, and public key replacement.
[0006] To address the above problems, some studies have attempted to introduce means such as batch signature and group key negotiation to improve the authentication efficiency, but there are still limitations such as high algorithm complexity, difficult key management, and insufficient dynamic adaptation ability. Summary of the Invention
[0007] Therefore, the present invention proposes a communication information security management system and method for a computing power resource perception scenario to achieve efficient, flexible, and secure authentication of multiple nodes in a computing power perception scenario, and solve the key problems of low authentication efficiency and poor scalability in the prior art.
[0008] To achieve the above object, the present invention provides the following technical solutions: Step S1, establish a computing power perception center, where the computing power perception center is a central server for information calculation, node interaction, and data storage; construct a finite field, select two numbers in the finite field as elliptic curve parameters to generate an elliptic curve, and generate an Abelian group according to the elliptic curve; the computing power perception center generates a private key and a public key, and generates a secret value; calculate the secret factor of the secret value according to the secret value. Step S1-1, the computing power perception center selects a random prime number q to obtain a finite field Z * q , the Z * q contains elements {1, 2,..., q - 1}; select a random prime number p to obtain a multiplicative group Z * p , the Z * p contains elements {1, 2,..., p - 1}, and the operation of the multiplicative group is modular p multiplication, where p > q; select a one-way mapping function as a secure hash function h. Step S1-2, select two numbers a, b in the finite field as elliptic curve parameters to generate an elliptic curve, and the elliptic curve is expressed as y 2 = x 3 + ax + b mod p, where y is the ordinate, x is the abscissa, and mod is the modulo operation; take a point P on the elliptic curve to generate a group G, and the group G is an Abelian group with the points on the elliptic curve as the carrier and the base point P as the generator, and the operation follows the elliptic curve point addition rule. Step S1-3, the computing power perception center generates a private key sk CPC ∈ Z * q and public key information PK CPC = sk CPC ·P; generate a secret value S = {S1, S2,... S n}, S iRepresents any secret value in {S1, S2,... S n}, where S i ∈Z * p , and i ∈ [1, n]. A total of n secret values are generated; calculate the secret factor x i = S 1 ×S 2 ×.....×S n / S i , x i the inverse element of y i ≡ 1 / x i m mod S i , and calculate the product x i ×y i ; The computing power perception center saves {S, {S1, x1×y1},..., {{S n , x n ×y n}}} locally, where S represents all the generated secret values; Step S1-4, the computing power perception center discloses {P, G, q, p, h, PK CPC}, where P is the generator of the point group G, G is the group G, q and p are the selected prime numbers, h is the secure hash function, and PK CPC is the public key information.
[0009] Step S2, the node sends registration information containing the identity identifier and timestamp to the computing power perception center; if the timestamp has expired, the registration information is discarded; if the timestamp has not expired, the computing power perception center registers the node and assigns a secret value; the computing power perception center calculates the broadcast message shard, and the broadcast message shard is the value broadcast by the computing power perception center; Step S2-1, the node ID i sends the registration information {ID i T i} to the computing power perception center, where ID i is the true identity of the node, and T i is the timestamp; Step S2-2, after receiving the registration information {ID i T i}, the computing power perception center first checks whether T i has expired. If it has expired, the registration information is discarded; if it has not expired, the computing power perception center registers the node and selects from S = {S1, S2,.. S nSelect the ID from i The secret value S i , and select the corresponding x i ×y i ; Calculate the computing power perception center and the ID according to the secure hash function h i The shared secret value US i , US i = h(ID i , sk CPC , T e ), where T e Is the defined expiration time; And calculate the broadcast message shard SA i Corresponding to the node ID i = US i ×x i ×y i , Secretly store locally {ID i , x i ×y i , T e}; The computing power perception center returns the secret value S i To the node ID i ; Step S2-3, if m nodes register simultaneously, then the broadcast message shard SA = SA1 + SA2 +.... + SA m = US1×x1×y1 + US2×x2×y2 +... + US m ×x m ×y m , where m < n, and n is the total number of secret values generated in step S2-2; Step S2-4, after the node receives the secret value S i , Save it locally.
[0010] Step S3, after the node registration is completed, the computing power perception center performs a broadcast message shard, and the node calculates the shared secret value after receiving it; Encrypt the resource information according to the shared secret value, generate a pseudonym, a secret value digest, a timestamp, a signature, and the encrypted resource information and send it to the computing power perception center; The computing power perception center verifies the timestamp, calculates the node identity, verifies the node signature, and decrypts the plaintext message; Step S3-1, after all nodes are registered, the computing power perception center broadcasts SA to the area, and the area includes registered nodes and unregistered nodes; Step S3-2, when the node ID i Needs to periodically upload the resource information M i To the computing power perception center, ID i Calculates the shared secret value US i = SA mod Si ; Encrypt the resource message M i to generate the ciphertext C i = US i ⨁M i , where ⨁ represents the exclusive OR operation; ID i Select a communication pseudonym. The selection process is as follows: Randomly select r i ∈Z * q , and calculate the random value R i = r i P, generate the pseudonym PID i = h(r i PK CPC )⨁ID i ; Calculate and generate the sending message C i , and the digest of the secret value: ɑ i = h(C i , US i , ID i , T j ), where T j is the timestamp; Calculate the signature θ = US i + ɑ i r i ; ID i Send the authentication message {C i , θ, PID i , R i , T j} to the computing power perception center, where C i represents the ciphertext, θ represents the signature, PID i is the pseudonym of the node ID i , R i represents the random value, and T j represents the timestamp.
[0011] Step S3-3: After the computing power perception center receives the authentication message {C i , PID i , R i , T j}, first check whether T j is timed out. If it is timed out, discard the authentication message. If it is not timed out, calculate the true identity ID of the node i = PID i ⨁h(sk CPC R i ), and then retrieve the local storage information {ID i , x i ×y i , T e}, and judge whether T e is expired. If it is expired, the node IDi The registration information has expired, discard the message. If it has not expired, calculate the shared secret value US i =h(ID i , sk CPC , T e ), and the digest value ɑ i =h(C i , US i , ID i , T j ), verify whether θP is equal to US i P+ɑ i R i , if they are equal, decrypt the plaintext message; the decryption process is: M i = C i ⨁US i ; If the computing power perception center receives multiple groups of messages at the same time, calculate the signature θ of each group of messages for batch verification. The batch verification process is:
[0012] where m represents a total of m nodes sending m groups of messages, θ i represents the signature of each group of messages, P is the generator of the P point group G, US i represents the shared secret value of each node, ɑ i represents the secret value digest of each node, r i represents the randomly selected value, R i represents the random value.
[0013] Step S4. When a node joins, leaves, or is updated, the computing power perception center calculates a new broadcast message according to the node status, updates the local storage information, and republishes the new broadcast message to the area.
[0014] Step S4-1. When a new node with the identity information ID k1 joins, the computing power perception center selects a new secret value S k1 for ID k1 , and calculates the product of the secret factors x k1 ×y k1 ; Calculate the new broadcast message SA new1 = SA old1 + h(ID k1 , sk CPC , T e )×x k1 ×y k1 , where SAold1 The broadcast message before the addition of the new node; Send S k1 to ID k1 , and announce the new SA to the area new1 ; Step S4-2: When a node with the identity information ID k2 leaves, the computing power perception center queries the ID k2 information {ID k2 , x k2 ×y k2 , T e}, where x k2 ×y k2 is the product of the secret factors of ID k2 , and T e is the defined expiration time; Calculate the new broadcast message SA new2 = SA old2 - h(ID k2 , sk CPC , T e )×x k2 ×y k2 ; where SA old2 is the broadcast message before the node leaves; Delete the {ID k2 , x k2 ×y k2 , T e} information and announce the new SA to the area new2 ; Step S4-3: When a node with the identity information ID k3 needs to update information, the computing power perception center queries the ID k3 information {ID k3 , x k3 ×y k3 , T e}; Select a new S k3 new3 and calculate the corresponding product of secret factors x k3 new3 ×y k3 new3 , and calculate the new broadcast message: SA new3 = SA old3 - h(ID k3 , sk CPC , T e )×x k3 ×y k3 + h(ID k3 , sk CPC, T e new3 ) × x k3 new3 × y k3 new3 , where SA old3 is the broadcast message before node update information, T e new3 is the new expiration time, and send S k new3 to ID k3 , and announce the new SA to the area new3 .
[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. The present invention constructs a group authentication mechanism through the Chinese Remainder Theorem and combines it with the dynamic allocation strategy of the modulo space to achieve single-time efficient authentication and batch authentication capabilities, support local parameter updates only when nodes are dynamically added or deleted without reconstructing the entire network authentication link, and significantly improve the authentication efficiency and adaptation ability in high-dynamic scenarios.
[0016] 2. The present invention designs the parameter anonymization encapsulation of the Chinese Remainder Theorem in cooperation with lightweight encryption, avoids complex computational overhead while ensuring the confidentiality of resource data transmission, realizes the balance of semantic hiding of sensitive information, anti-eavesdropping and lightweight authentication, and achieves the dual advantages of privacy protection and efficiency optimization.
[0017] 3. The present invention deeply couples the authentication protocol with the computing power scheduling process, uses the parameters of the Chinese Remainder Theorem to ensure the integrity and source credibility of resource information, provides a secure data basis for computing power scheduling, and builds a general security framework covering scenarios such as cloud-edge-end collaboration and software-defined networks relying on the scalability of the mathematical structure of the Chinese Remainder Theorem, supporting the integrated security management of heterogeneous resources and cross-scenario migration applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 is a schematic flowchart of a communication information security management method for a computing power resource perception scenario of the present invention; Figure 2 is a schematic diagram of routing computing power scheduling of a communication information security management method for a computing power resource perception scenario of the present invention; Figure 3 is a schematic diagram of the application of a communication information security management method for a computing power resource perception scenario of the present invention in a software-defined network; Figure 4 is a schematic diagram of the application of a communication information security management method for a computing power resource perception scenario of the present invention in a cloud-edge computing network; Figure 5Schematic diagram of the application of a communication information security management method for a computing power resource perception scenario in an edge computing network according to the present invention.
[0019] Figure 6 Schematic diagram of the structure of a communication information security management system for a computing power resource perception scenario according to the present invention; Specific implementation manners
[0020] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0021] Embodiment 1: As Figure 1 shown, the present invention provides a technical solution, a communication information security management method for a computing power resource perception scenario. The communication information security management method includes the following steps: Step S1: Establish a computing power perception center, where the computing power perception center is the central server for implementing a communication information security management method for a computing power resource perception scenario; construct a finite field, select two numbers in the finite field as elliptic curve parameters to generate an elliptic curve, and generate an Abelian group according to the elliptic curve; generate a private key and a public key of the computing power perception center, generate a secret value and calculate the secret factor of the secret value; Step S1-1: The computing power perception center selects a random prime number q to obtain a finite field Z * q , where the Z * q contains elements {1, 2,..., q - 1}; selects a random prime number p to obtain a multiplicative group Z * p , where the Z * p contains elements {1, 2,..., p - 1}, and the operation of the multiplicative group is modular p multiplication, where p > q; selects a one-way mapping function as a secure hash function h; Step S1-2: Select two numbers a and b in the finite field as elliptic curve parameters to generate an elliptic curve, and the elliptic curve is expressed as y 2 = x 3 + ax + b mod p, where y is the ordinate, x is the abscissa, and mod is the modulo operation; take a point P on the elliptic curve to generate a group G, and the group G is an Abelian group with the points on the elliptic curve as the carrier and the base point P as the generator, and the operation follows the elliptic curve point addition rule; Step S1-3, the computing power perception center generates a private key sk CPC ∈ Z * q and public key information PK CPC = sk CPC ·P; Generate a secret value S = {S1, S2,... S n}, where S i ∈Z * p , i ∈ [1, n]; Calculate SM = S 1 ×S 2 ×.....×S n , x i = SM / S i , x i the inverse element of y i ≡ 1 / x i m od S i and the product x i ×y i ; The computing power perception center saves {S, {S1, x1×y1},..., {{S n , x n ×y n}}} to the local; Step S1-4, the computing power perception center publishes {P, G, q, p, h, PK CPC}, where P is the generator of the point group G of P, G is the group G, q and p are selected prime numbers, h is a secure hash function, and PK CPC is the public key information.
[0022] Step S2, the node sends registration information including the identity identifier and timestamp to the computing power perception center; if the timestamp has expired, the registration information is discarded, if the timestamp has not expired, the computing power perception center assigns a secret value to the node; and calculates the broadcast message shard at the computing power perception center, and the broadcast message shard is the value broadcast by the computing power perception center; Step S2-1, the node ID i sends registration information {ID i T i} to the computing power perception center, where ID i is the true identity of the node, and T i is the timestamp; Step S2-2, after the computing power perception center receives the registration information {ID i T i}, it first checks Ti Whether it has expired. If it has expired, discard the registration information. If it has not expired, the computing power perception center performs node registration, selects an ID from S = {S1, S2,.. S n}, and selects the secret value S i of the ID i , and selects the corresponding x i × y i ; Calculate the shared secret value US i between the computing power perception center and the ID i , US i = h(ID i , sk CPC , T e ), where T e is the defined expiration time; and calculate the broadcast message shard SA i corresponding to the node ID i = US i × x i × y i , and locally and secretly store {ID i , x i × y i , T e}; The computing power perception center returns the secret value S i to the node ID i ; Step S2-3: If multiple nodes register simultaneously, the broadcast message shard SA = SA1 + SA2 +.... + SA m = US1 × x1 × y1 + US2 × x2 × y2 +... + US m × x m × y m , where m < n; Step S2-4: After receiving the secret value S i , the node saves it locally.
[0023] Step S3: After the node registration is completed, the computing power perception center performs broadcast message sharding. After receiving it, the node calculates the shared secret value; encrypts the resource information according to the shared secret value, generates a pseudonym, a secret value digest, a timestamp, a signature, and the encrypted resource information and sends them to the computing power perception center; the computing power perception center verifies the timestamp, calculates the node identity, verifies the node signature, and decrypts the plaintext message; Step S3-1: After all nodes are registered, the computing power perception center broadcasts SA to the area, and the area includes registered nodes and unregistered nodes; Step S3-2: When the node ID i needs to periodically upload the resource information M i to the computing power perception center, IDi Calculate the shared secret value US through the broadcast message SA i = SA mod S i ; Encrypt the resource message M i to generate the ciphertext C i = US i ⨁M i , where ⨁ represents the exclusive OR operation; ID i Select a communication pseudonym. The selection process is as follows: Randomly select r i ∈Z * q , and calculate the random value R i =r i P, generate the pseudonym PID i = h(r i PK CPC )⨁ID i ; Calculate and generate the sending message C i , and the digest of the secret value: ɑ i =h(C i , US i , ID i , T j ), where T j is the timestamp; Calculate the signature θ = US i +ɑ i r i ; ID i Send the authentication message {C i , θ, PID i , R i , T j} to the computing power perception center, where C i represents the ciphertext, θ represents the signature, PID i is the pseudonym of the node ID i , R i represents the random value, and T j represents the timestamp.
[0024] Step S3-3. After the computing power perception center receives the authentication message {C i , PID i , R i , T j}, first check whether T j times out. If it times out, discard the authentication message. If it does not time out, calculate the true identity ID of the node i = PID i ⨁h(sk CPC R i ), and then retrieve the local storage information {ID i , x i ×yi , T e}, judge T e Whether it is expired, if it is expired, the node ID i If the registration information is invalid, the message is discarded. If it is not expired, the shared secret value US is calculated. i =h(ID i ,sk CPC , T e ), and the summary value ɑ i =h(C i , US i , ID i , T j ), verify whether θP is equal to US i P+ɑ i R i , if they are equal, the signature authentication is successful and the plaintext message is decrypted; the decryption process is: M i =C i ⨁US i ; If the computing power perception center receives multiple groups of messages at the same time, the signature θ of each group of messages is calculated for batch verification. The batch verification process is:
[0025] in m Representatives share m Nodes send m Group message, θ i represents the signature of each group of messages, P is the generator of P point group G, US i Represents the shared secret value of each node, ɑ i Represents the secret value summary of each node, r i represents the value obtained by random selection, R i Represents the random value.
[0026] Step S4: When a node joins, leaves or is updated, the computing power perception center calculates a new broadcast message based on the node status, updates the local storage information, and re-announces the new broadcast message to the area.
[0027] Step S4-1: When there is new identity information ID k1 When a node joins, the computing power perception center is ID k1 Select an S k1 and x k1 ×y k1 ; Calculate the new broadcast message SA new1 =SA old1 + h(ID k1 ,sk CPC , T e )×xk1 x × y k1 ; Send S k1 to ID k1 , and announce the new SA to the area new1 ; Step S4-2: When a node with identity information ID k2 leaves, the computing power perception center queries the ID k2 information {ID k2 , x k2 × y k2 , T e}; Calculate the new broadcast message SA new2 = SA old2 - h(ID k2 , sk CPC , T e ) × x k2 × y k2 ; Delete the {ID k2 , x k2 × y k2 , T e} information, and announce the new SA to the area new2 ; Step S4-3: When a node with identity information ID k3 needs to update information, the computing power perception center queries the ID k3 information {ID k3 , x k3 × y k3 , T e}; Select new S k3 new3 and x k3 new3 × y k3 new3 , and calculate the new broadcast message: SA new3 = SA old3 - h(ID k3 , sk CPC , T e ) × x k3 × y k3 + h(ID k3 , sk CPC , T e new3 ) × x k3 new3 × y k3 new3 , where T e new3is the new expiration time, send S k new3 to ID k3 , announce the new SA within the area new3 .
[0028] For example: In an edge computing network, there are 3 edge nodes ID1, ID2, and ID3 that need to register with the computing power perception center CPC and report computing power resource information.
[0029] First, initialize the computing power perception center: Select the prime number q = 11, then the finite field Z * 11 contains elements {1, 2,..., 10}, and the prime number p = 23 (multiplicative group Z * 23 , elements {1, 2,..., 22}, p > q.
[0030] The elliptic curve parameters are a = 1, b = 1, and the curve equation is y² = x³ + x + 1 mod 23.
[0031] The base point P = (1, 7) is on the elliptic curve, generating the Abelian group G, and the operation is elliptic curve point addition.
[0032] The private key sk of the computing power perception center CPC = 5 ∈ Z * 11 , and the public key PK CPC = sk CPC ·P = 5·(1, 7), and let the result be the point (18, 12).
[0033] The initial secret value S = {S1 = 3, S2 = 5, S3 = 7}, all ∈ Z * 23 , calculate: Product of secret values SM = 3 × 5 × 7 = 105 x1 =SM / S1 =105 / 3=35, y1 = 35⁻¹ mod 3 = 2, so x1 × y1 =35×2=70 x2 = SM / S2 = 21, y2 = 21⁻¹ mod 5 = 1, so x2 × y2 = 21 × 1 = 21 x3 = SM / S2 = 15, y3 = 15⁻¹ mod 7 = 1, so x3 × y3 = 15 × 1 = 15 The local storage of the computing power perception center {S1 = 3, x1×y1 = 70}, {S2 = 5, x2×y2 = 21}, {S3 = 7, x3×y3 = 15}, and publicly disclose {P, G, q = 11, p = 23, h, PK CPC}.
[0034] Perform node ID1 registration: Node ID1 sends registration information {ID1T1}, and the timestamp T1 has not expired.
[0035] The computing power perception center allocates S1 = 3, calculates the shared secret value US1 = h(ID1, sk CPC = 5, T e = 1 hour), let the output of h be 10, and broadcast the message shard SA1 = US1×x1×y1 = 10×70 = 700.
[0036] Local storage {ID1, x1×y1 = 70, T e = 1 hour}, return S1 = 3 to node ID1.
[0037] Node ID2 registration (simultaneous registration scenario): Node ID2 sends {ID2T2}, and the timestamp is valid.
[0038] Allocate S2 = 5, calculate US2 = h(ID2, sk CPC = 5, T e = 1 hour), let the output of h be 20, SA2 = 20×21 = 420.
[0039] Broadcast the message shard SA = SA1 + SA2 = 700 + 420 = 1120, the current number of registered nodes m = 2, and the total number of nodes n = 3.
[0040] Return S2 = 5 to node ID2.
[0041] Node ID1 reports resource information: The computing power perception center broadcasts SA = 1120 and each node's SA i .
[0042] Node ID1 calculates the shared secret value US1 = SA mod S1 = 1120 mod 3 = 1 Resource information M i = "CPU: 80%, Mem: 60%", after encryption C i = US1⨁M i = 1⨁"CPU: 80%, Mem: 60%".
[0043] Generate pseudonyms: Randomly select r1 = 2 ∈ Z* 11 , calculate R1 = r1·P = 2·(1, 7), and let the result be the point (10, 5).
[0044] Let the h output be a random value, and the pseudonym PID1 = h(r1PK CPC ) ⊕ ID1, which hides the true identity after XOR with ID1.
[0045] Calculate the digest ɑ1 = h(C i , US1 = 1, ID1, T j ), and let the output be 3. The signature θ = US1 + ɑ1r1 = 1 + 3×2 = 7.
[0046] Send the message {C i , θ = 7, PID1, R1 = (10, 5), T j} to the computing power perception center.
[0047] Check the timestamp T j has not timed out, calculate the true identity ID1 = PID1 ⊕ h(sk CPC R1 = 5·(10, 5)).
[0048] Retrieve locally {ID1, x1×y1 = 70, T e = 1 hour}, T e has not expired, recalculate US1 = h(ID1, 5, T e = 1 hour) = 10.
[0049] Verify the signature: θ·P = 7·(1, 7), US1·P + ɑ1·R1 = 10·(1, 7) + 3·(10, 5). If the two are equal on the elliptic curve, the signature passes.
[0050] Decrypt the ciphertext M i = C i ⊕ US1 = 1 ⊕ C i , and obtain the resource information.
[0051] Node dynamic management: New node ID3 joins: The computing power perception center allocates S3, calculates US3 = h(ID5, 5, T e = 1 hour), and let the h output be 15, SA3 = 15×15 = 225.
[0052] New broadcast message SA new = SA old + SA3 = 1120 + 225 = 1345, update the local storage {ID3, x3×y3 = 15, T e = 1 hour}, broadcast SAnew = 1345.
[0053] Node ID2 leaves: The computing power awareness center queries SA2 of ID2 = 420, calculates SA new = SA old - SA2 = 1345 - 420 = 925.
[0054] Delete the registration information of ID2 and broadcast SA new = 925.
[0055] Node ID1 is updated, for example, extend the expiration time: Original T e = Expires in 1 hour. Node ID1 requests an update, and the computing power awareness center allocates a new T e = 2 hours, calculates the new US1 new = h(ID1, 5, T e = 2 hours), and makes the h output 12.
[0056] Calculate SA new = - SA1 + US1 new × x1 × y1 = - 700 + 12 × 70 = 140, the new broadcast message SA new = 925 + 140 = 1065.
[0057] Update the local T e = 2 hours, returns the new S1 = 3 (the secret value can remain unchanged, only the expiration time is updated), and broadcasts SA new = 1065.
[0058] Meanwhile, as Figure 2 , Figure 3 , Figure 4 , Figure 5 , the authentication and privacy communication method proposed by the present invention is not only applicable to the dynamic monitoring and scheduling of node computing power in the scenario of computing power resource awareness, but also can be extended to cross - domain scenarios such as cloud - edge - end collaborative task scheduling, SDN network resource awareness, and distributed storage resource discovery.
[0059] For example: In the scenario of software - defined network resource awareness, the controller needs to perform trusted collection and dynamic orchestration on resources such as the bandwidth and flow table capacity of a large number of forwarding devices; in the cloud - edge - end computing scenario, the computing power collaboration between edge nodes and cloud servers needs to verify the device identity in real - time and encrypt the transmission load status.
[0060] Example 2, as Figure 6As shown in the figure, the present invention provides a communication information security management system for a computing power resource perception scenario. The system includes an initialization module, a node registration module, a security processing module, and a node management module. The initialization module is used to construct a computing power perception center and generate the elliptic curve, Abelian group, public key, private key, secret value, and secret factor of the secret value. The node registration module is used to verify the timestamp of the registration information, generate broadcast message shards, and complete the authentication of the node identity. The security processing module is used to complete the encrypted transmission of node information. The node management module is used to respond to the joining, leaving, and information update of nodes. The output end of the initialization module is electrically connected to the input end of the node registration module. The output end of the node registration module is electrically connected to the input end of the security processing module. The output end of the security processing module is electrically connected to the input end of the node management module.
[0061] The initialization module includes a center establishment unit and a parameter generation unit. The center establishment unit is used to establish the computing power perception center. The parameter generation unit is used to construct a finite field, generate an elliptic curve and an Abelian group, as well as a private key, a public key, a secret value, and a secret factor of the secret value.
[0062] The node registration module includes a request processing unit and a secret value allocation unit. The request processing unit is used to receive the registration information of the node including the real identity and the timestamp, and verify the validity of the timestamp. The secret value allocation unit is used to allocate a secret value to the unexpired node, calculate the broadcast message shards, store the real identity, expiration time, and secret value of the node, and return the secret value to the node.
[0063] The security processing module includes an encrypted communication unit and an information verification unit. The encrypted communication unit is used for the node to encrypt the resource information according to the shared secret value to generate a ciphertext, generate a pseudonym, an intermediate value of the pseudonym, a timestamp, a signature, and send them to the computing power perception center. The information verification unit is used for the computing power perception center to verify the validity of the timestamp, verify the signature, and decrypt the resource information.
[0064] The node management module includes a status monitoring unit and a message update unit. The status monitoring unit is used to monitor the joining, leaving, and information update of nodes. The message update unit is used to recalculate the broadcast message according to the node changes monitored by the status monitoring unit, update the local storage information, and announce the new broadcast message to the region.
[0065] Finally, it should be noted that: for those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.
Claims
1. A communication information security management method for a computing power resource perception scenario, characterized in that: Step S1: Establish a computing power perception center, which is a central server for information calculation, node interaction, and data storage; construct a finite field, select two numbers in the finite field as elliptic curve parameters to generate an elliptic curve, and generate an Abelian group according to the elliptic curve; the computing power perception center generates a private key and a public key, and generates a secret value; calculate the secret factor of the secret value according to the secret value. Step S2: The node sends registration information including an identity identifier and a timestamp to the computing power perception center. If the timestamp has expired, discard the registration information; if the timestamp has not expired, the computing power perception center registers the node and assigns a secret value; the computing power perception center calculates a broadcast message shard, which is a value broadcast by the computing power perception center. Step S3: After the node registration is completed, the computing power perception center broadcasts the message shard, and the node calculates the shared secret value after receiving it; encrypt the resource information according to the shared secret value, generate a pseudonym, a secret value digest, a timestamp, a signature, and the encrypted resource information and send them to the computing power perception center; the computing power perception center verifies the timestamp, calculates the node identity, verifies the node signature, and decrypts the plaintext message. Step S4: When a node joins, leaves, or is updated, the computing power perception center calculates a new broadcast message according to the node status, updates the local storage information, and republishes the new broadcast message to the area.
2. The communication information security management method for a computing power resource perception scenario according to claim 1, characterized in that: The step S1 includes: Step S1-1: The computing power perception center selects a random prime number q to obtain a finite field Z * q , where the Z * q contains elements {1, 2,..., q - 1}; selects a random prime number p to obtain a multiplicative group Z * p , where the Z * p contains elements {1, 2,..., p - 1}, and the operation of the multiplicative group is modular p multiplication, where p > q; selects a one-way mapping function as the secure hash function h; Step S1-2: Select two numbers a and b in the finite field as elliptic curve parameters to generate an elliptic curve, which is expressed as y 2 = x 3 + ax + b mod p, where y is the ordinate, x is the abscissa, and mod is the modulo operation; Take a point P on the elliptic curve to generate a group G. The group G is an Abelian group with the points on the elliptic curve as the carrier and the base point P as the generator, and the operation follows the elliptic curve point addition rule; Step S1-3, the computing power perception center generates a private key sk CPC ∈ Z * q and public key information PK CPC = sk CPC ·P; Generate a secret value S = {S1, S2,... S n}, S i represents any secret value in {S1, S2,... S n}, S i ∈Z * p , i ∈ [1, n], and a total of n secret values are generated; Calculate the secret factor x i = S 1 ×S 2 ×.....×S n / S i , x i the inverse element of y i ≡ 1 / x i m od S i , calculate the product of the secret factors x i ×y i ; The computing power perception center saves {S, {S1, x1×y1},..., {{S n , x n ×y n}}} to the local, where S represents all the generated secret values; Step S1-4, the computing power perception center discloses {P, G, q, p, h, PK CPC}, where P is the generator of the P point group G, G is the group G, q and p are selected prime numbers, h is a secure hash function, and PK CPC is the public key information.
3. A communication information security management method for a computing power resource perception scenario according to claim 1, characterized in that: The step S2 includes: Step S2-1, Node ID i Send the registration information {ID i T i} to the computing power perception center, where ID i is the true identity of the node, and T i is the timestamp; Step S2-2: After the computing power perception center receives the registration information {ID i T i}, it first checks whether T i has expired. If it has expired, the registration information is discarded. If it has not expired, the computing power perception center performs node registration, selects the secret value S n of ID i from S = {S1, S2,..S i}, and selects the corresponding x i ×y i ; calculates the shared secret value US i between the computing power perception center and ID i according to the secure hash function h, US i =h(ID i , sk CPC , T e ), where T e is the defined expiration time; and calculates the broadcast message shard SA i corresponding to the node ID i = US i ×x i ×y i , and secretly stores {ID i , x i ×y i , T e} locally; the computing power perception center returns the secret value S i to the node ID i ; Step S2-3: If m nodes register simultaneously, broadcast the message shard SA = SA1 + SA2 +.... + SA m = US1×x1×y1 + US2×x2×y2 +... + US m ×x m ×y m , where m < n, and n is the total number of secret values generated in step S2-2; Step S2-4: After receiving the secret value S, the node stores it locally. i 4. A communication information security management method for a computing power resource perception scenario according to claim 1, characterized in that: The step S3 includes: Step S3-1: After all nodes are registered, the computing power perception center broadcasts SA to the area, which includes registered nodes and unregistered nodes. Step S3-2: When the node ID i needs to periodically upload the resource information M i to the computing power awareness center, the ID i calculates the shared secret value US i = SA mod S i ; encrypts the resource message M i to generate the ciphertext C i = US i ⨁M i , where ⨁ represents the exclusive-or operation; the ID i selects a communication pseudonym. The selection process is as follows: randomly select r i ∈Z * q , and calculate the random value R i =r i P, generate the pseudonym PID i = h(r i PK CPC )⨁ID i ; calculate and generate the sending message C i , and the digest of the secret value: ɑ i =h(C i , US i , ID i , T j ), where T j is the timestamp; calculate the signature θ = US i +ɑ i r i ; the ID i sends the authentication message {C i , θ, PID i , R i , T j} to the computing power awareness center, where C i represents the ciphertext, θ represents the signature, PID i is the pseudonym of the node ID i , R i represents the random value, and T j represents the timestamp; Step S3-3: After the computing power perception center receives the authentication message {C i , PID i , R i , T j}, it first checks whether T j times out. If it times out, the authentication message is discarded. If it does not time out, the true identity ID of the node is calculated as i = PID i ⨁ h(sk CPC R i ). Then, the local stored information {ID i , x i × y i , T e} is retrieved to determine whether T e has expired. If it has expired, the node ID i registration information becomes invalid and the message is discarded. If it has not expired, the shared secret value US i = h(ID i , sk CPC , T e ) and the digest value ɑ i = h(C i , US i , ID i , T j ) are calculated. It is verified whether θP is equal to US i P + ɑ i R i . If they are equal, the plaintext message is decrypted. The decryption process is: M i = C i ⨁ US i ; If the computing power perception center receives multiple groups of messages at the same time, calculate the signature θ of each group of messages for batch verification. The batch verification process is as follows: ; Among them m represents a total of m nodes sending m groups of messages, θ i represents the signature of each group of messages, P is the generator of the point group G of P, US i represents the shared secret value of each node, ɑ i represents the secret value digest of each node, r i represents the value obtained by the random selection, R i represents the random value.
5. A communication information security management method for a computing power resource perception scenario according to claim 1, characterized in that: The step S4 includes: Step S4-1: When a new node with identity information ID k1 joins, the computing power perception center selects a new secret value S k1 for ID k1 , and calculates the product of the secret factors x k1 ×y k1 ; Calculate the new broadcast message SA new1 = SA old1 + h(ID k1 , sk CPC , T e ) × x k1 × y k1 , where SA old1 is the broadcast message before the new node joins; Send S k1 to ID k1 and announce the new SA within the area new1 ; Step S4-2: When a node with identity information ID k2 leaves, the computing power perception center queries the ID k2 information {ID k2 , x k2 ×y k2 , T e}, where x k2 ×y k2 is the product of the secret factors of ID k2 , and T e is the defined expiration time; Calculate the new broadcast message SA new2 = SA old2 - h(ID k2 , sk CPC , T e ) × x k2 × y k2 ; where SA old2 is the broadcast message before the node leaves; Delete the {ID k2 , x k2 × y k2 , T e} information and announce the new SA to the area new2 ; Step S4-3: When the node with identity information ID k3 needs to update information, the computing power awareness center queries the ID k3 information {ID k3 , x k3 ×y k3 , T e}; Select a new S k3 new3 and calculate the product x of the corresponding secret factors k3 new3 ×y k3 new3 , calculate the new broadcast message: SA new3 = SA old3 - h(ID k3 ,sk CPC ,T e )×x k3 ×y k3 + h(ID k3 ,sk CPC ,T e new3 )×x k3 new3 ×y k3 new3 , where SA old3 is the broadcast message before node update information, and T e new3 is the new expiration time. Send S k new3 to ID k3 to announce the new SA in the area new3 .
6. A communication information security management system for a computing power resource perception scenario, which is applied to a communication information security management method for a computing power resource perception scenario according to any one of claims 1-5, and is characterized in that: The system includes an initialization module, a node registration module, a security processing module, and a node management module; the initialization module is used to construct the computing power perception center, generate the elliptic curve, Abelian group, public key, private key, secret value, and the secret factor of the secret value; the node registration module is used to verify the timestamp of the registration information, generate a broadcast message shard, and complete the authentication of the node identity; the security processing module is used to complete the encrypted transmission of node information; the node management module is used to respond to the joining, leaving, and information update of the node. The output end of the initialization module is electrically connected to the input end of the node registration module; the output end of the node registration module is electrically connected to the input end of the security processing module; the output end of the security processing module is electrically connected to the input end of the node management module.
7. The communication information security management system for the computing power resource perception scenario according to claim 6, characterized in that: The initialization module includes a center establishment unit and a parameter generation unit; the center establishment unit is used to establish the computing power perception center; the parameter generation unit is used to construct a finite field, generate an elliptic curve and an Abelian group, as well as a private key, a public key, a secret value, and the secret factor of the secret value.
8. The communication information security management system for the computing power resource perception scenario according to claim 6, characterized in that: The node registration module includes a request processing unit and a secret value distribution unit; the request processing unit is used to receive the registration information of the node including the real identity and the timestamp, and verify the validity of the timestamp; the secret value distribution unit is used to allocate secret values to the nodes whose expiration time has not passed, calculate the shards of the broadcast message, store the real identity, expiration time and secret value of the node, and return the secret value to the node.
9. The communication information security management system for the computing power resource perception scenario according to claim 6, characterized in that: The security processing module includes an encrypted communication unit and an information verification unit; the encrypted communication unit is used for the node to encrypt the resource information according to the shared secret value to generate ciphertext, generate a pseudonym, an intermediate value of the pseudonym, a timestamp, a signature and send them to the computing power perception center; the information verification unit is used for the computing power perception center to verify the validity of the timestamp, verify the signature and decrypt the resource information.
10. A communication information security management system for a computing power resource perception scenario according to claim 6, characterized in that: The node management module includes a status monitoring unit and a message update unit; the status monitoring unit is used to monitor the joining, leaving and information update of the node; the message update unit is used to recalculate the broadcast message according to the node changes monitored by the status monitoring unit, update the local storage information and announce the new broadcast message to the region.
Citation Information
Patent Citations
Strong privacy protection method suitable for medical scene and based on certificateless signature
CN114884665A
Vehicle identity privacy protection method based on block chain in Internet of Vehicles
CN116527342A
Certificateless anonymous verifiable encryption method based on industrial Internet of Things system
CN118784354A
Random oracles in open networks
US20190253242A1
Traffic accident forensics method based on blockchain
US20240056299A1