Lightweight data sharing method fusing edge computing and block chain

By adopting the combination of edge computing and blockchain in IoT devices, segmenting the signature private key and performing distributed storage, anonymous identity verification and data proxy signature are implemented, and the privacy data leakage and computing burden of IoT devices is solved, ensuring the security and integrity of data processing.

CN120264268AInactive Publication Date: 2025-07-04XI'AN POLYTECHNIC UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510474744.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing signature verification mechanism cannot achieve anonymous authentication, and the privacy data of IoT devices poses a risk of leakage in traditional cloud computing and edge computing architectures.

Method used

The lightweight data sharing method that integrates edge computing and blockchain is adopted. The signature private key is divided into multiple key shares and stored in the blockchain through KGC. Homomorphic encryption algorithm and ESAS are used to ensure the privacy and security of data processing. Combined with the off-chain storage design, only the key verification information is put on the chain to realize anonymous identity verification and data proxy signature.

Benefits of technology

It significantly reduces the computing burden of IoT devices, ensures privacy and security during data processing, reduces the risk of privacy data leakage, and alleviates the pressure of blockchain storage through off-chain storage design, and supports the integrity and authenticity verification of massive data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264268A_ABST
    Figure CN120264268A_ABST
Patent Text Reader

Abstract

The invention discloses a lightweight data sharing method fusing edge computing and a block chain, and relates to the technical field of block chains, and the method comprises the steps: scanning an unmanned aerial vehicle ad hoc network, and obtaining an authenticated unmanned aerial vehicle node and an unauthenticated unmanned aerial vehicle node; generating a plurality of signature key pairs, and matching the signature key pairs with the nodes; encrypting the signature private key according to a homomorphic encryption algorithm to obtain a ciphertext set; the base station verifies the ciphertext set to obtain a complete signature; a main verification node is obtained, and the main verification node verifies the encrypted information and distributes the encrypted information; shared data and a block chain are separated through an under-chain storage design, only key verification information is chained, the storage pressure of the block chain is effectively relieved, a credible edge node with strong computing power can realize data proxy signature, the integrity and authenticity of mass data are ensured, and the mechanism supports anonymous identity verification and is high in practicability. And the burden of the Internet of Things equipment with limited computing resources is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain, and specifically relates to a lightweight data sharing method integrating edge computing and blockchain. Background Art

[0002] In the big data era, as end-users' expectations for network performance and service quality are getting higher and higher, the traditional cloud computing-based architecture can no longer meet the application requirements of the Internet of Things. In order to further improve the utilization efficiency of devices with limited computing resources in the Internet of Things environment, mobile edge computing technology has emerged. In the drone ad-hoc network, edge nodes not only connect devices, but also process various data generated by drones.

[0003] The emergence of MEC has accelerated the development of drone ad-hoc network technology, but there are still security and privacy issues in this infrastructure. For example, directly uploading data to edge nodes for processing cannot guarantee the integrity and authenticity of the data, and the existing signature verification mechanism cannot achieve anonymous authentication. The traditional cloud computing-based architecture and the traditional edge computing-based architecture need to upload this data to a semi-trusted computing center, which will increase the risk of privacy data leakage. Therefore, the present invention proposes a lightweight data sharing method integrating edge computing and blockchain. Summary of the Invention

[0004] To solve the above technical problems, a lightweight data sharing method integrating edge computing and blockchain is provided, which solves the problems that the existing signature verification mechanism cannot achieve anonymous authentication and increases the risk of privacy data leakage.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A lightweight data sharing method integrating edge computing and blockchain, comprising: Scanning the drone ad-hoc network to obtain authenticated drone nodes and unauthenticated drone nodes; Generating multiple signature key pairs and matching them with nodes; Encrypting the signature private key according to the homomorphic encryption algorithm to obtain a ciphertext set; The base station verifies the ciphertext set to obtain a complete signature; Obtaining a main verification node, and the main verification node verifies the encrypted information and distributes the encrypted information; Performing identity registration on the drone nodes according to the encrypted information; According to the drone nodes, combining with ESAS to obtain homomorphic encryption ciphertext and ciphertext signature; Constructing a new block according to the storage address and combining with the main node.

[0006] Preferably, the generation of multiple signature key pairs and the matching with nodes include the following steps: The KGC randomly selects two unequal prime numbers; According to the Euler's totient function, obtain the value of the Euler's totient function; Randomly select a public key exponent that is relatively prime to the value of the Euler's totient function; Calculate the private key exponent that satisfies the condition; Obtain the public and private key pairs for signature; Match multiple signature key pairs with nodes; Among them, the specific calculation formula for the value of the Euler's totient function is: ; Among them, the specific form of the public key is: ; Among them, the specific form of the private key is: ; In the formula, and are two randomly selected unequal prime numbers, is the private key exponent, is the public key exponent.

[0007] Preferably, the encryption of the signature private key according to the homomorphic encryption algorithm to obtain a ciphertext set includes the following steps: Randomly select two equal-length large prime numbers; Obtain the product and the least common multiple of the two prime numbers; According to the product and the least common multiple, combined with the homomorphic encryption algorithm, obtain the public and private key pairs for homomorphic encryption; Divide the signature private key according to the private key exponent; Construct a first threshold; Extract multiple key shares according to the first threshold; Construct a polynomial according to multiple key shares; Randomly select multiple values, combined with the polynomial, to obtain a ciphertext set; Among them, the specific construction method of the public and private key pairs for homomorphic encryption is: ; Among them, the specific form of the polynomial is: ; Among them, the specific form of the ciphertext set is: ; In the formula, and are two randomly selected equal-length large prime numbers, is the product of two prime numbers, is the least common multiple, , is the public key of homomorphic encryption, is the private key of homomorphic encryption, is the first threshold, , , randomly select numerical values and substitute them into the polynomial to obtain results.

[0008] Preferably, the base station verifies the ciphertext set and obtains the complete signature, including the following steps: Obtain the data set; The base station calculates the hash value according to the data set; Judge the decrypted message according to the hash value; If the hash value is not equal to the hash value obtained in the decrypted message, the verification fails; If the hash value is equal to the hash value obtained in the decrypted message, the verification passes; The base station uses the signature public key, verifies and calculates the data signature, and encrypts the ciphertext set.

[0009] Preferably, the base station uses the signature public key, verifies and calculates the data signature, and encrypts the ciphertext set, including the following steps: The base station uses the signature public key, verifies and calculates the data signature; If the calculation result is equal to the hash value, the data signature is the complete signature; If the calculation result is not equal to the hash value, the data signature is not the complete signature; Extract the public and private key pair of the base station; The base station encrypts the ciphertext set according to the KGC to obtain the first-level encrypted ciphertext; Perform secondary encryption on the first-level encrypted ciphertext according to the base station public key to obtain the secondary encrypted ciphertext.

[0010] Preferably, the steps for obtaining the main verification node, where the main verification node verifies the encrypted information and distributes the encrypted information are as follows: Obtain the regional consensus nodes; According to the Byzantine fault tolerance algorithm, obtain the main verification node; The main verification node verifies the secondary encrypted ciphertext using the base station public key; Bind the secondary encrypted ciphertext with the timestamp to obtain the encapsulated data set; Extract the public and private key pair of the main verification node; Calculate the hash value of the encapsulated data set; Encrypt the encapsulated data set and the hash value of the encapsulated data set using the main verification node private key; Broadcast the signature set to all consensus nodes for verification; The consensus nodes confirm the integrity of the signature set, verify the data legality, construct a new block, and upload it to the blockchain.

[0011] Preferably, the consensus nodes confirm the integrity of the signature set, verify the data legality, construct a new block, and upload it to the blockchain, including the following steps: The consensus nodes verify the concealment status of the message block in the signature document; If the message is not hidden, the node extracts a random number from the extended parameter set and calculates the hash value of the message block; If the message is hidden, the node directly reads the pre-generated hash value from the signature file; The node concatenates the hash values of the extracted data blocks and the hash values of the unextracted message blocks according to the arrangement order of the sub-messages in the original document to generate a global hash chain; The consensus nodes call the public key of the KGC to perform decryption verification on the signature; The consensus nodes calculate the valid signature; If the decryption result is equal to the global hash chain, the signature validity verification passes; If the decryption result is not equal to the global hash chain, it indicates that the document or signature has been tampered with, and the node will trigger an exception handling protocol; Construct a second threshold; If more than the number of consensus nodes of the second threshold agree, the new block is successfully created, and the data will be uploaded to the blockchain.

[0012] Preferably, the identity registration of unauthenticated drone nodes based on the encrypted information includes the following steps: Obtain the real information of the unauthenticated drone; ESAS obtains the drone key sharing set, the drone public key, and the collected data; ESAS decrypts and restores the complete signature private key; Verify the signature private key according to the signature algorithm; If the verification passes, the identity of the unauthenticated drone is registered and marked as a trusted drone; If the verification fails, the unauthenticated drone is marked as a malicious drone.

[0013] Preferably, the drone node, in combination with ESAS, obtains the homomorphic encryption ciphertext and the ciphertext signature, including the following steps: ESAS decrypts the ciphertext of the drone using the private key; Ensure the legality of the drone identity and the accuracy of the data, and decrypt and restore the complete signature private key according to the key share submitted by the drone; ESAS uses the public key of the drone to homomorphically encrypt the data; Sign the data using the signature private key; ESAS submits the data to the base station for processing; The base station verifies the integrity and authenticity of the data; After the base station ensures the accuracy of the data, for the data that needs to be processed in a timely manner, the base station processes it according to the preset allowed operations of the drone, and returns the timely data to the drone.

[0014] Preferably, constructing a new block based on the storage address and in combination with the main node includes the following steps Statistically store the data in the cloud and return the storage address of the statistical data to the drone; The drone submits the received storage address key-sharing ciphertext to ESAS; ESAS decrypts and restores the complete signature private key according to the key share; Use the signature private key to sign the cloud statistical data storage address to generate a signature of the storage address; The base station submits the index to the main node and transmits it to the consensus nodes using the consensus mechanism; The consensus nodes reach a consensus based on the authenticity of the data; Construct a third threshold; If more than the number of consensus nodes of the third threshold agree, construct a new block; If the number of consensus nodes that do not exceed the third threshold agree, do not construct a new block.

[0015] Compared with the prior art, the advantages of the present invention are as follows: The present invention divides the signature private key into multiple key shares through KGC and stores them distributively in different blocks of the blockchain to enhance the fault tolerance ability. At the same time, the content extraction signature algorithm is used to ensure the verifiability of the key shares within a single block. The drone only needs to submit data and randomly allocated key shares to the edge node. The edge node completes data signature and homomorphic encryption processing based on the recovered signature private key, and ensures the privacy and security during the data processing stage through ESAS. The processing result can be immediately returned to the user, significantly reducing the computing burden of IoT devices. For data that needs to be uploaded to the cloud for analysis, a backup upload mechanism is adopted to avoid the risk of data flooding. In addition, through off-chain storage design, the shared data is separated from the blockchain, and only the key verification information is uploaded to the chain, effectively alleviating the storage pressure on the blockchain. The trusted edge node with powerful computing power can implement data proxy signature to ensure the integrity and authenticity of massive data. This mechanism supports anonymous authentication and reduces the burden on IoT devices with limited computing resources. The proxy server can implement homomorphic encryption to ensure that the user's private data will not be leaked during the data processing stage, and the processed data will be returned to the user in a timely manner. For data that needs to be uploaded to the cloud for analysis, backup upload is used to avoid data flooding. The key shares of the signature private key are stored in different blocks of the blockchain to improve the fault tolerance ability, and at the same time, the content extraction signature algorithm is used to ensure that the key shares stored in a single block can be verified. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a schematic flow chart of steps S100 - S800 in a lightweight data sharing method integrating edge computing and blockchain proposed by the present invention; Figure 2 It is a schematic flow chart of steps S201 - S206 in a lightweight data sharing method integrating edge computing and blockchain proposed by the present invention; Figure 3 It is a schematic flow chart of steps S301 - S308 in a lightweight data sharing method integrating edge computing and blockchain proposed by the present invention; Figure 4 It is a schematic flow chart of steps S401 - S406 in a lightweight data sharing method integrating edge computing and blockchain proposed by the present invention; Figure 5 It is a schematic flow chart of steps S4061 - S4066 in a lightweight data sharing method integrating edge computing and blockchain proposed by the present invention; Figure 6 It is a schematic flow chart of steps S501 - S509 in a lightweight data sharing method integrating edge computing and blockchain proposed by the present invention; Figure 7Schematic diagram of the process of steps S5091 - S50910 in a lightweight data sharing method that combines edge computing and blockchain proposed by the present invention; Figure 8 Schematic diagram of the process of steps S601 - S606 in a lightweight data sharing method that combines edge computing and blockchain proposed by the present invention; Figure 9 Schematic diagram of the process of steps S701 - S707 in a lightweight data sharing method that combines edge computing and blockchain proposed by the present invention; Figure 10 Schematic diagram of the process of steps S801 - S809 in a lightweight data sharing method that combines edge computing and blockchain proposed by the present invention. Detailed implementation manners

[0017] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.

[0018] Referring to Figure 1-10 As shown, a lightweight data sharing method that combines edge computing and blockchain includes: S100. Scan the drone ad - hoc network to obtain authenticated drone nodes and unauthenticated drone nodes; S200. Generate multiple signature key pairs and match them with the nodes; S300. Encrypt the signature private key according to the homomorphic encryption algorithm to obtain a set of ciphertexts; S400. The base station verifies the set of ciphertexts to obtain a complete signature; S500. Obtain the main verification node, and the main verification node verifies the encrypted information and distributes the encrypted information; S600. Register the identities of the drone nodes according to the encrypted information; S700. According to the drone nodes, in combination with ESAS, obtain the homomorphic encryption ciphertext and the ciphertext signature; S800. According to the storage address, in combination with the main node, construct a new block; Those skilled in the art can understand that an ad-hoc network of unmanned aerial vehicles (UAVs) consists of a group of UAV nodes that have been pre-authenticated. Through a dynamic clustering mechanism, autonomous and collaborative task execution units are formed. Within each cluster, the cluster head node coordinates resource allocation and communication relay. The cluster member nodes are equipped with sensor modules to perform environmental data collection tasks. UAVs newly joining the target management domain or performing cross-domain collaboration tasks are classified as unauthenticated nodes. They need to first submit a zero-knowledge proof request to the Key Generation Center (KGC) of the target domain to complete anonymous identity binding without exposing physical identity information. There is a unique trusted Key Generation Center (KGC) in each management domain, which serves as the core hub of the security system in that domain. It holds the global signature private key and undertakes the core functions of key shard generation and distribution. The KGC splits the domain signature private key into n key shards. Each shard needs to be encrypted in combination with the temporary session key of the target node. After forming the encrypted shards, they are submitted to the blockchain consensus node network through a smart contract. Relying on the tamper-proof feature of the blockchain, the shards are distributed and stored in multiple blocks to ensure that single-point failures or partial data damage do not affect key recovery. At the same time, the KGC transmits the unencrypted original signature private key to the Edge Security Agent Service (ESAS) through a secure channel. The ESAS performs batch signature operations on the data transmitted by the UAVs based on the threshold signature scheme. This mechanism not only avoids the leakage risk caused by edge nodes directly holding the complete private key but also realizes the auditability of the entire key life cycle through the shard storage and consensus verification mechanism at the blockchain layer. To ensure that a semi-trusted base station cannot tamper with the content or leak user privacy during data processing, the Trusted Edge Security Agent Service (ESAS) uses a homomorphic encryption algorithm to encrypt and transform the original data of the UAVs, enabling the base station to directly perform operations such as aggregation and statistics on the ciphertext without decrypting. At the same time, a digital fingerprint of the data packet is generated in combination with the signature algorithm, and the signature result is bound to the ciphertext and transmitted to the base station. After receiving the encrypted data stream, the base station uses a unified processing framework to complete data parsing and task scheduling: the entire process of secure processing of encrypted data is realized by integrating the Trusted Execution Environment (TEE). For data that needs to be immediately feedback, decryption and logical operations are completed within the TEE, and the result is encrypted and returned to the user terminal through a pre-allocated dedicated communication channel; the remaining data flows are losslessly compressed and integrity-checked, and then uploaded to the cloud server in multiple threads in chunks. At the same time, the data feature hash and transmission path metadata are recorded in the blockchain for subsequent traceability and auditing. To address the problems of blockchain storage capacity limitations and key management complexity, this solution constructs an on-chain and off-chain hybrid storage architecture: only the index information of the shared data stored on the cloud server is stored on the chain to ensure data verifiability through the tamper-proof feature of the blockchain; off-chain, the distributed storage of encrypted data is realized in combination with the IPFS protocol to ensure data recoverability.

[0019] As Figure 2 shown, the generating of multiple signature key pairs and matching with nodes includes the following steps: S201. The KGC randomly selects two unequal prime numbers; S202. According to the Euler's totient function, obtain the value of the Euler's totient function; S203. Randomly select a public key exponent that is relatively prime to the value of the Euler's totient function; S204. Calculate the private key exponent that meets the conditions; S205. Obtain the public-private key pair for signing; S206. Match multiple signature key pairs with the nodes; Among them, the specific calculation formula for the value of the Euler's totient function is: ; Among them, the specific form of the public key is: ; Among them, the specific form of the private key is: ; In the formula, and are two randomly selected unequal prime numbers, is the private key exponent, is the public key exponent; Those skilled in the art can understand that in encryption algorithms such as RSA, the selection of prime numbers plays a decisive role in the encryption strength. By randomly selecting, the unpredictability of key generation is increased, providing an initial security element for the entire encryption system. Due to the randomness of prime numbers, it is difficult for attackers to crack encryption keys through conventional means such as exhaustive enumeration. Different prime number combinations will produce completely different encryption results, increasing the difficulty and complexity of cracking, effectively resisting external illegal attacks, and ensuring data security. In the mathematical principle of the encryption algorithm, the Euler function value participates in the core calculation process of key generation to ensure the validity and security of the public and private key pairs. The key pair generated based on the Euler function conforms to the mathematical logic of the encryption algorithm, ensuring the accuracy and integrity of the encryption and decryption process, and preventing data leakage or inability to decrypt due to key mismatch or unreasonableness. The public key exponent is a key component of the public key, and its relationship with the Euler function value determines the feasibility and security of the encryption operation. The property of being mutually prime with the Euler function value ensures the correctness of mathematical operations in the encryption process and ensures the security and integrity of data during encrypted transmission. The private key exponent corresponds to the public key exponent. The private key exponent and the public key exponent together constitute an asymmetric encryption key pair. The private key is used to sign data, and the public key is used to verify signatures. The two work together to achieve secure data transmission and identity authentication. Only the private key exponent obtained by correct calculation can match the corresponding public key exponent in the encryption and decryption, signing and verification of signatures. The public key is used for external disclosure, and the recipient can use the public key to verify the sender's data signature; the private key is properly kept by the sender and used to sign data. A unique signature key pair is assigned to each node, so that each node can use its own key pair to authenticate and sign data during data interaction, ensuring the traceability of the data source, and also facilitating the management and verification of data from different nodes.

[0020] like Figure 3 As shown, the process of encrypting the signature private key according to the homomorphic encryption algorithm and obtaining the ciphertext set includes the following steps: S301. Randomly select two prime numbers of equal length; S302, obtaining the product and the least common multiple of two prime numbers; S303, according to the product and the least common multiple, combined with the homomorphic encryption algorithm, obtain the public and private key pair for homomorphic encryption; S304, splitting the signature private key according to the private key index; S305, constructing a first threshold; S306, extracting multiple key shares according to the first threshold; S307, constructing a polynomial based on multiple key shares; S308, randomly select multiple values, combine them with the polynomial, and obtain a ciphertext set; Among them, the specific construction method of the public-private key pair for homomorphic encryption is as follows: ; Among them, the specific form of the polynomial is: ; Among them, the specific form of the ciphertext set is: ; In the formula, and are two randomly selected large prime numbers of the same length, is the product of the two prime numbers, is the least common multiple, , is the homomorphic encryption public key, is the homomorphic encryption private key, is the first threshold, , , randomly select numerical values and substitute them into the polynomial to obtain results; Those skilled in the art can understand that in the homomorphic encryption algorithm, the selection of prime numbers is crucial for the encryption strength and the realization of homomorphic properties. The public-private key pair for homomorphic encryption is the core tool for realizing the homomorphic encryption function. The public key is used to encrypt data, so that the data remains confidential during transmission and storage; the private key is used for decryption. Only the legitimate user holding the private key can restore the ciphertext to plaintext. By splitting the private key into multiple parts, the risk brought by the leakage of a single private key is reduced. Different key shares can be held by different entities or modules. Only under certain conditions can multiple key shares be combined to restore the complete private key, thus improving the security of the private key and the fault tolerance of the system. The first threshold is used to determine the minimum number of key shares required to restore the complete signature private key. By setting an appropriate threshold, the security of the key and the convenience of restoration can be balanced. By using multiple key shares as the coefficients or parameters of the polynomial and utilizing the mathematical properties of the polynomial to restore the complete private key, the polynomial has good interpolation and fitting properties and can accurately restore the complete private key according to partial key shares. At the same time, the construction process of the polynomial increases the complexity of key restoration, making it difficult for attackers to obtain the complete private key by analyzing partial key shares, further improving the security of the key. The multiple randomly selected numerical values are combined with the polynomial to generate the ciphertext set. These random numerical values increase the randomness and diversity of the ciphertext, making the ciphertext more difficult to crack. The ciphertext set is the encrypted data form used for transmission or storage in the network to ensure the confidentiality of the data.

[0021] Such as Figure 4As shown, the steps for the base station to verify the ciphertext set and obtain the complete signature are as follows: S401. Obtain the data set; S402. The base station calculates the hash value based on the data set; S403. Judge the decrypted message based on the hash value; S404. If the hash value is not equal to the hash value obtained from the decrypted message, the verification fails; S405. If the hash value is equal to the hash value obtained from the decrypted message, the verification passes; S406. The base station uses the signature public key to verify and calculate the data signature, and encrypts the ciphertext set; Those skilled in the art can understand that the data set contains data transmitted from data sources such as drone nodes. The base station needs to perform subsequent analysis and processing on it to ensure the integrity and accuracy of the data, providing a basis for subsequent data sharing and applications. The hash value is a concise and unique digital digest of the content of the data set. By calculating the hash value, the base station can generate a fixed-length feature code for the data set for subsequent data integrity verification. When receiving the decrypted message, compare its hash value with the hash value calculated based on the original data set before. Through the comparison of the hash values, the authenticity of the data can be clearly judged. If the hash values do not match, it indicates that there are problems in the data transmission or decryption process, which may be network transmission errors, data tampering caused by malicious attacks, etc. Discovering problems in a timely manner helps to take corresponding measures. Using the signature public key to verify the data signature can confirm whether the source of the data is legal, ensuring that the data is sent by a legitimate sender with the corresponding private key. Encrypting the ciphertext set is to protect the confidentiality of the data during data storage and transmission, preventing the data from being illegally obtained or viewed.

[0022] As Figure 5 shown, the steps for the base station to use the signature public key to verify and calculate the data signature, and encrypt the ciphertext set are as follows: S4061. The base station uses the signature public key to verify and calculate the data signature; S4062. If the calculation result is equal to the hash value, the data signature is the complete signature; S4063. If the calculation result is not equal to the hash value, the data signature is not the complete signature; S4064. Extract the public-private key pair of the base station; S4065. The base station encrypts the ciphertext set according to the KGC to obtain the first-level encrypted ciphertext; S4066. Perform secondary encryption on the first-level encrypted ciphertext according to the base station public key to obtain the second-level encrypted ciphertext; Those skilled in the art can understand that the signature public key is used to verify the legality of data signatures, ensuring that data is sent by an authorized entity holding the corresponding private key. By calculating the data signature, the base station can compare the calculation result with the expected hash value to determine whether the data has been tampered with or forged during transmission, thereby confirming the integrity of the data and the reliability of its source. When the calculated data signature is consistent with the hash value, it means that the data has not been tampered with and comes from a legitimate sender. The base station can recognize this data signature as a complete signature, and the data can enter the subsequent security processing process. If the calculation result does not match the hash value, it indicates that the data may have been tampered with during transmission, or the data source is illegal. The base station will refuse to process such data as valid data for subsequent processing to prevent incorrect or malicious data from spreading in the system. The private key is used to sign sensitive data, and the public key is used to allow other nodes to verify the signature. The keys generated by the KGC have high security and authority. Through one-time encryption, even if the ciphertext set is intercepted during transmission or storage, without the corresponding decryption key, it is difficult for attackers to obtain the original data content. Encrypting the one-time encrypted ciphertext again using the base station public key makes the confidentiality of the data stronger during transmission and storage. Moreover, after two-time encryption, the difficulty of cracking the data is greatly increased. Only the receiving party with the correct decryption key can gradually decrypt and obtain the original data.

[0023] As Figure 6 shown, the steps for obtaining the main verification node, where the main verification node verifies the encrypted information and distributes the encrypted information include the following: S501. Obtain regional consensus nodes; S502. Obtain the main verification node according to the Byzantine fault tolerance algorithm; S503. The main verification node verifies the twice-encrypted ciphertext using the base station public key; S504. Bind the twice-encrypted ciphertext with the timestamp to obtain an encapsulated data set; S505. Extract the public-private key pair of the main verification node; S506. Calculate the hash value of the encapsulated data set; S507. Encrypt the encapsulated data set and the hash value of the encapsulated data set using the private key of the main verification node; S508. Broadcast the signature set to all consensus nodes for verification; S509. The consensus nodes confirm the integrity of the signature set, verify the data legality, and construct a new block and upload it to the blockchain; Those skilled in the art can understand that nodes participating in consensus within a region are selected from the entire network nodes. These nodes will jointly participate in processes such as data verification and decision-making to ensure data consistency and consensus within a specific region. The Byzantine fault tolerance algorithm can still ensure the normal operation of the network and the achievement of consensus in the presence of partial node failures or malicious behaviors. Through this algorithm, the primary verification node is selected, and the primary verification node will assume core responsibilities such as key data verification and coordinated data distribution to ensure the fairness and reliability of data processing. Since the base station public key is securely authenticated, verification can ensure that the secondary encrypted ciphertext has not been tampered with during transmission and its source is reliable, meeting the security requirements of the system. The timestamp adds an identifier of the time dimension to the data. After being bound to the secondary encrypted ciphertext, the encapsulated data set not only contains the encrypted data content but also clarifies the time sequence of data generation or processing. The use of the public-private key pair adds a reliable digital signature to the data, enabling other nodes to accurately verify whether the data has been legally processed by the primary verification node. The confidentiality of the private key ensures the uniqueness and security of the signature. Only the primary verification node can sign the data, preventing the risk of data being impersonated for signature and enhancing the credibility of the entire data verification process. The private key of the primary verification node is used to encrypt the encapsulated data set and its hash value to form a signature set, and the signature set is broadcast to all consensus nodes to allow each consensus node to jointly participate in the data verification process. Only when the majority of consensus nodes recognize the legitimacy of the data will a new block be constructed and uploaded to the blockchain.

[0024] As Figure 7 shown, the steps for the consensus node to confirm the integrity of the signature set, verify the data legitimacy, construct a new block, and upload it to the blockchain are as follows: S5091. The consensus node verifies the hidden state of the message block in the signature document; S5092. If the message is not hidden, the node extracts a random number from the extended parameter set and calculates the hash value of the message block; S5093. If the message is hidden, the node directly reads the pre-generated hash value from the signature file; S5094. The node concatenates the hash values of the extracted data blocks and the hash values of the unextracted message blocks according to the arrangement order of the sub-messages in the original document to generate a global hash chain; S5095. The consensus node calls the public key of the KGC to decrypt and verify the signature; S5096. The consensus node calculates the valid signature; S5097. If the decryption result is equal to the global hash chain, the signature validity verification passes; S5098. If the decryption result is not equal to the global hash chain, it indicates that the document or signature has been tampered with, and the node will trigger an exception handling protocol; S5099. Construct a second threshold; S50910. If more than the number of consensus nodes of the second threshold agree, the new block is successfully created and the data will be uploaded to the blockchain; Those skilled in the art can understand that determining whether the message block in the signed document is in a hidden state determines the subsequent method of calculating the hash value. By verifying the hidden state, it is ensured that the node can obtain the hash value using the correct method according to the actual situation of the message block, thereby accurately verifying the integrity and authenticity of the data. For unhidden message blocks, a random number is extracted from the extended parameter set to participate in the hash value calculation, increasing the randomness and unpredictability of the hash value. For hidden message blocks, the pre-generated hash value is directly read to avoid unnecessary decryption operations on the hidden message and improve the data verification efficiency. A global hash chain is constructed according to the arrangement order of the sub-messages in the original document, and the hash values of each message block are integrated in an orderly manner. The global hash chain not only reflects the content characteristics of each message block but also reflects their order relationship in the original document, providing a comprehensive and accurate data basis for subsequent signature verification. The public key of the KGC is used to decrypt the signature to verify the legality of the signature and the reliability of the data source. Through a series of calculation and verification steps, it is determined whether the signature is valid. When the decryption result is consistent with the global hash chain, it indicates that the signature is legal and the data has not been tampered with, and the data can enter the subsequent blockchain creation process, ensuring that only reliable data can be recorded in the blockchain and promptly detecting abnormal situations of the data or signature. Once the decryption result does not match the global hash chain, the exception handling protocol is immediately triggered. The second threshold is 50% of the consensus nodes. Only when the number of consensus nodes agreeing on the data legality exceeds 50% will a new block be created. When the majority of consensus nodes recognize the data legality, a new block is created and the data is uploaded to the blockchain to achieve permanent recording and sharing of the data.

[0025] Such as Figure 8 shown, the identity registration of the unauthenticated drone node based on the encrypted information includes the following steps: S601. Obtain the real information of the unauthenticated drone; S602. The ESAS obtains the drone key sharing set, the drone public key, and the collected data; S603. The ESAS decrypts and restores the complete signature private key; S604. Verify the signature private key according to the signature algorithm; S605. If the verification passes, complete the identity registration of the unauthenticated drone and mark it as a trusted drone; S606. If the verification fails, mark the unauthenticated drone as a malicious drone; Those skilled in the art can understand that collecting relevant real information of uncertified drones, such as model, manufacturer, serial number, etc., provides basic data for subsequent identity verification and registration. The drone key sharing set and public key are important elements to ensure secure data transmission and identity verification. The collected data is business-related information generated or collected during the operation of the drone. ESAS obtains this information to lay a foundation for secure data processing and identity confirmation. Using information such as the key sharing set, ESAS performs decryption operations to restore the complete signature private key. The signature algorithm is based on mathematical principles. By performing a series of calculations and comparisons on the private key, it is confirmed whether the private key meets the security standards and authentication rules of the system, thereby determining whether the identity of the drone is true and reliable. When the signature private key is verified successfully, it indicates that the identity of the drone is legal. The system completes the identity registration of the drone and marks it as a trusted drone, enabling the drone to officially join the drone ad-hoc network, participate in data sharing and other network activities, and at the same time providing an identity authentication basis for subsequent data interaction and business operations. For drones whose signature private key verification fails, the system marks them as malicious drones. This mark is used to alert network administrators and other nodes that the drone may pose a security risk, preventing it from participating in network activities and preventing it from damaging the network or stealing data.

[0026] As Figure 9 shown, the drone node, in combination with ESAS, obtains the homomorphic encryption ciphertext and ciphertext signature, including the following steps: S701. ESAS decrypts the ciphertext of the drone using the private key; S702. Ensure the legality of the drone's identity and the accuracy of the data, and decrypt and restore the complete signature private key according to the key share submitted by the drone; S703. ESAS performs homomorphic encryption on the data using the public key of the drone; S704. Sign the data using the signature private key; S705. ESAS submits the data to the base station for processing; S706. The base station verifies the integrity and authenticity of the data; S707. After ensuring the accuracy of the data, for data that needs to be processed in a timely manner, the base station processes it according to the preset allowed operations of the drone and returns the timely data to the drone; Those skilled in the art can understand that ESAS restores the encrypted data during the UAV transmission process to the plaintext form by using the corresponding private key, enabling the data to be further processed and analyzed in subsequent steps. It emphasizes again the verification of the UAV identity and data accuracy. The signature private key is restored by decrypting the key shares, providing a key element for subsequent data signing and verification. The signature private key is restored through a strict key share decryption process, which not only ensures the reliability of the private key source but also ensures that only legitimate UAVs can perform subsequent data signing operations, further enhancing the security of data during transmission and processing. Homomorphic encryption allows specific operations to be performed on ciphertext, and the result is the same as that obtained by performing the same operation on the plaintext and then encrypting it. The restored signature private key is used to sign the data, adding a unique digital identifier to the data. ESAS submits the data processed by encryption and signature to the base station so that the base station can perform more in-depth analysis, integration, and management of the data. After receiving the data, the base station uses data signatures and related verification algorithms to verify the integrity and authenticity of the data. For the data that has been verified and needs to be processed in a timely manner, the base station operates according to the preset rules of the UAV, such as data calculation, screening, etc., and returns the processing results to the UAV in a timely manner, ensuring that the UAV can obtain useful processed information in a timely manner, meeting the real-time requirements of its business operations, and enabling the UAV to make accurate decisions and actions based on the latest data.

[0027] As Figure 10 shown, constructing a new block based on the storage address in combination with the main node includes the following steps S801. Statistically store the data in the cloud and return the storage address of the statistical data to the UAV; S802. The UAV submits the received storage address key-sharing ciphertext to ESAS; S803. ESAS decrypts according to the key shares and restores the complete signature private key; S804. Use the signature private key to sign the cloud statistical data storage address to generate a signature of the storage address; S805. The base station submits the index to the main node and transmits it to the consensus nodes through the consensus mechanism; S806. The consensus nodes reach a consensus based on the authenticity of the data; S807. Construct a third threshold; S808. If more than the number of consensus nodes of the third threshold agree, construct a new block; S809. If less than the number of consensus nodes of the third threshold agree, do not construct a new block; Those skilled in the art can understand that the statistical data collected by the drone and processed is stored in the cloud. By leveraging the powerful storage capacity of the cloud, long-term data preservation and efficient management can be achieved. To ensure the security of the storage address information, the drone submits it to ESAS in the form of a ciphertext shared with a key. ESAS uses the previously allocated key shares to perform decryption operations, recover the complete signature private key, and use the recovered signature private key to sign the cloud statistical data storage address, adding a unique digital identifier to the storage address. The base station submits the index information related to the cloud statistical data storage address to the master node, and the master node then passes the index to other consensus nodes through the consensus mechanism. Each consensus node judges the authenticity of the cloud statistical data storage address and related data based on the received index information and the previous verification of the data, and reaches a consensus. Only when the majority of consensus nodes recognize the authenticity of the data will the subsequent blockchain operations be advanced. The third threshold is 50% of the consensus nodes. When the number of consensus nodes agreeing to construct a new block exceeds the third threshold, the new block construction operation will be carried out. When the majority of consensus nodes recognize the data authenticity and agree to construct a new block, the relevant information such as the cloud statistical data storage address is recorded in the new block. The construction of the new block enables the data storage information to be permanently and immutably recorded in the blockchain, facilitating subsequent data traceability, query, and management. At the same time, it also provides reliable blockchain support for the data storage and sharing of the drone ad hoc network. The characteristics of the blockchain make it impossible to easily tamper with the information such as the data storage address recorded in the new block once it is successfully constructed, providing a highly reliable basis for data storage management, which is of great significance in aspects such as data recovery, auditing, and long-term storage management, and ensuring the stability and credibility of the data storage system.

[0028] In summary, the advantages of the present invention are as follows: The signature private key is split into multiple key shares by KGC and distributed and stored in different blocks of the blockchain to enhance the fault tolerance ability. At the same time, the content extraction signature algorithm is used to ensure the verifiability of the key shares within a single block. The drone only needs to submit data and randomly assigned key shares to the edge node. The edge node completes data signature and homomorphic encryption processing based on the recovered signature private key, and ensures the privacy and security during the data processing stage through ESAS. The processing result can be immediately returned to the user, significantly reducing the computing burden of IoT devices. For data that needs to be uploaded to the cloud for analysis, a backup upload mechanism is adopted to avoid the risk of data flooding. In addition, through off-chain storage design, the shared data is separated from the blockchain, and only the key verification information is uploaded to the chain, effectively alleviating the storage pressure of the blockchain. The trusted edge node with powerful computing capabilities can implement data proxy signature to ensure the integrity and authenticity of massive data. This mechanism supports anonymous authentication and reduces the burden on IoT devices with limited computing resources. The proxy server can implement homomorphic encryption to ensure that the user's private data will not be leaked during the data processing stage, and the processed data will be returned to the user in a timely manner. For data that needs to be uploaded to the cloud for analysis, backup upload is used to avoid data flooding. The key shares of the signature private key are stored in different blocks of the blockchain to improve the fault tolerance ability. At the same time, the content extraction signature algorithm is used to ensure that the key shares stored in a single block can be verified.

[0029] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only the principles of the present invention. Without departing from the spirit and scope of the present invention, various changes and improvements will occur to the present invention, and all these changes and improvements fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.

Claims

1. A lightweight data sharing method integrating edge computing and blockchain, characterized in that, Including: Scanning the drone ad-hoc network to obtain authenticated drone nodes and unauthenticated drone nodes; Generating multiple signature key pairs and matching them with the nodes; Encrypting the signature private key according to the homomorphic encryption algorithm to obtain a set of ciphertexts; The base station verifies the set of ciphertexts to obtain a complete signature; Obtaining the main verification node, which verifies the encrypted information and distributes the encrypted information; Performing identity registration on the drone nodes according to the encrypted information; According to the drone nodes, combining with ESAS, obtaining homomorphic encryption ciphertexts and ciphertext signatures; Constructing a new block according to the storage address and combining with the main node.

2. The lightweight data sharing method integrating edge computing and blockchain according to claim 1, wherein: The step of generating multiple signature key pairs and matching them with the nodes includes the following steps: KGC randomly selects two unequal prime numbers; Obtaining the Euler's totient function value according to the Euler's totient function; Randomly selecting a public key exponent that is relatively prime to the Euler's totient function value; Calculating the private key exponent that meets the conditions; Obtaining the public and private key pairs for signing; Matching multiple signature key pairs with the nodes; Among them, the specific calculation formula for the Euler's totient function value is: ; Among them, the specific form of the public key is: ; Among them, the specific form of the private key is: ; Wherein, and are two randomly selected unequal prime numbers, is the private key exponent, is the public key exponent.

3. A lightweight data sharing method integrating edge computing and blockchain according to claim 2, characterized in that: The step of encrypting the signature private key according to the homomorphic encryption algorithm to obtain a set of ciphertexts includes the following steps: Randomly selecting two large prime numbers of equal length; Obtaining the product and least common multiple of the two prime numbers; According to the product and least common multiple, combining with the homomorphic encryption algorithm, obtaining the public and private key pairs for homomorphic encryption; Dividing the signature private key according to the private key exponent; Constructing the first threshold; Extracting multiple key shares according to the first threshold; Constructing a polynomial according to the multiple key shares; Randomly selecting multiple values and combining with the polynomial to obtain a set of ciphertexts; Among them, the specific construction method for the public and private key pairs for homomorphic encryption is: ; Among them, the specific form of the polynomial is: ; Among them, the specific form of the set of ciphertexts is: ; Wherein, and are two randomly selected large prime numbers of equal length, is the product of the two prime numbers, is the least common multiple, , is the homomorphic encryption public key, is the homomorphic encryption private key, is the first threshold, , , randomly select numerical values and substitute them into the polynomial to obtain results.

4. A lightweight data sharing method integrating edge computing and blockchain according to claim 1, characterized in that: The step of the base station verifying the set of ciphertexts to obtain a complete signature includes the following steps: Obtaining the data set; The base station calculates the hash value according to the data set; Judging the decrypted message according to the hash value; If the hash value is not equal to the hash value obtained in the decrypted message, the verification fails; If the hash value is equal to the hash value obtained in the decrypted message, the verification passes; The base station uses the signature public key to verify and calculate the data signature and encrypts the set of ciphertexts.

5. A lightweight data sharing method integrating edge computing and blockchain according to claim 1, characterized in that: The step that the base station uses the signature public key to verify and calculate the data signature and encrypts the set of ciphertexts includes the following steps: The base station uses the signature public key to verify and calculate the data signature; If the calculation result is equal to the hash value, the data signature is a complete signature; If the calculation result is not equal to the hash value, the data signature is not a complete signature; Extracting the public and private key pairs of the base station; The base station encrypts the set of ciphertexts according to KGC to obtain the first encrypted ciphertext; Performing secondary encryption on the first encrypted ciphertext according to the base station public key to obtain the second encrypted ciphertext.

6. The lightweight data sharing method integrating edge computing and blockchain according to claim 5, characterized in that: The step of obtaining the main verification node, which verifies the encrypted information and distributes the encrypted information includes the following steps: Obtaining the regional consensus nodes; Obtaining the main verification node according to the Byzantine fault tolerance algorithm; The main verification node verifies the second encrypted ciphertext using the base station public key; Binding the second encrypted ciphertext with the timestamp to obtain the encapsulated data set. Extract the public and private key pairs of the main verification node; Calculate the hash value of the encapsulated dataset; Encrypt the encapsulated dataset and the hash value of the encapsulated dataset using the private key of the main verification node; Broadcast the signature set to all consensus nodes for verification; The consensus nodes confirm the integrity of the signature set, verify the data legality, construct a new block, and upload it to the blockchain.

7. A lightweight data sharing method integrating edge computing and blockchain according to claim 1, characterized in that: The consensus nodes confirm the integrity of the signature set, verify the data legality, construct a new block, and upload it to the blockchain, including the following steps: The consensus nodes verify the hidden state of the message block in the signature document; If the message is not hidden, the node extracts a random number from the extended parameter set and calculates the hash value of the message block; If the message is hidden, the node directly reads the pre-generated hash value from the signature file; The node concatenates the hash values of the extracted data blocks and the hash values of the unextracted message blocks according to the arrangement order of the sub-messages in the original document to generate a global hash chain; The consensus node calls the public key of the KGC to decrypt and verify the signature; The consensus node calculates the valid signature; If the decryption result is equal to the global hash chain, the signature validity verification passes; If the decryption result is not equal to the global hash chain, it indicates that the document or signature has been tampered with, and the node will trigger an exception handling protocol; Construct a second threshold; If more than the second threshold number of consensus nodes agree, the new block is successfully created and the data will be uploaded to the blockchain.

8. A lightweight data sharing method integrating edge computing and blockchain according to claim 7, characterized in that: The identity registration of the unauthenticated drone node based on the encrypted information includes the following steps: Obtain the real information of the unauthenticated drone; ESAS obtains the drone key sharing set, the drone public key, and the collected data; ESAS decrypts and restores the complete signature private key; Verify the signature private key according to the signature algorithm; If the verification passes, the identity of the unauthenticated drone is registered and marked as a trusted drone; If the verification fails, the unauthenticated drone is marked as a malicious drone.

9. A lightweight data sharing method integrating edge computing and blockchain according to claim 7, characterized in that: The drone node, in combination with ESAS, obtains the homomorphic encryption ciphertext and the ciphertext signature, including the following steps: ESAS decrypts the ciphertext of the drone using the private key; Ensure the legality of the drone identity and the accuracy of the data, decrypt and restore the complete signature private key according to the key share submitted by the drone; ESAS homomorphically encrypts the data using the public key of the drone; Sign the data using the signature private key; ESAS submits the data to the base station for processing; The base station verifies the integrity and authenticity of the data; After the base station ensures the accuracy of the data, for the data that needs to be processed in a timely manner, the base station processes it according to the preset allowed operations of the drone and returns the timely data to the drone.

10. A lightweight data sharing method integrating edge computing and blockchain according to claim 7, characterized in that: The construction of a new block based on the storage address, in combination with the main node, includes the following steps Statistically store the data in the cloud and return the storage address of the statistical data to the drone; The drone submits the received storage address key sharing ciphertext to ESAS; ESAS decrypts and restores the complete signature private key according to the key share; Sign the cloud statistical data storage address using the signature private key to generate the signature of the storage address; The base station submits the index to the main node and transmits it to the consensus nodes using the consensus mechanism; The consensus nodes reach a consensus based on the authenticity of the data; Construct a third threshold; If more than the third threshold number of consensus nodes agree, a new block is constructed; If not more than the third threshold number of consensus nodes agree, a new block is not constructed.