Edge computing metadata privacy protection method based on searchable encryption and zero-knowledge proof
By using searchable encryption and zero-knowledge proof methods, the problem of metadata privacy protection in edge computing is solved, and the resource allocation process is completed without leaking metadata content, preventing malicious nodes from destroying the confidentiality of encrypted metadata and ensuring user privacy security.
Patent Information
- Application Number
- CN202410534668.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-30
- Publication Date
- 2025-07-11
AI Technical Summary
The prior art cannot effectively protect metadata privacy in edge computing, especially it cannot prevent malicious edge nodes from destroying the confidentiality of encrypted metadata. At the same time, the edge gateway may obtain user privacy information.
Using a method based on searchable encryption and zero-knowledge proof, through system initialization, registration, group generation, keyword generation, message encapsulation and resource allocation, zero-knowledge proof is used to resist malicious edge nodes, use searchable encryption to protect metadata privacy, and avoid edge gateways from obtaining metadata-related information.
It realizes the resource allocation process without revealing metadata content, protects user privacy, prevents malicious edge nodes from destroying the confidentiality of encrypted metadata, and ensures the privacy and security of metadata in edge computing.
Smart Images

Figure CN120296753A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of edge computing privacy protection, and particularly to a method for protecting the privacy of edge computing metadata based on searchable encryption and zero-knowledge proof. Background Art
[0002] The problem of resource allocation optimization is the core problem of edge computing. In order to optimize the resource allocation process, an edge gateway needs to be equipped in the edge system to allocate an appropriate one or a group of edge nodes to process different types of task data. In this process, users need to attach necessary metadata to the edge data to help the edge gateway complete the decision-making. However, the metadata without any protection will expose the user's privacy information. Research shows that one can learn about a person's detailed private relationships and hobbies only by relying on the metadata. Therefore, how to effectively protect the privacy information of metadata in edge computing has become one of the key factors in solving the problem of edge computing privacy protection.
[0003] There are many methods to protect the privacy information of metadata, and encryption is a very effective measure among them. However, although simple symmetric or asymmetric encryption measures can prevent eavesdroppers from obtaining user privacy, they still cannot prevent the edge gateway from obtaining relevant information of the metadata. Searchable encryption provides a solution to search encrypted data without knowing any information related to the keywords. With this feature, the confidentiality of encrypted metadata for the edge gateway can be achieved.
[0004] Although the current searchable encryption technology can guarantee the privacy of metadata in edge computing to a certain extent, in the initialization stage of the searchable encryption scheme, malicious edge nodes may generate some carefully designed malicious parameters, making the encrypted metadata decryptable, thus destroying the user's privacy. Therefore, it is necessary to provide a method for protecting the privacy of metadata that can resist malicious edge nodes. Summary of the Invention
[0005] To solve the problems of the existing technology, the purpose of the present invention is to overcome the deficiencies of the existing technology and provide a privacy protection method for edge computing metadata based on searchable encryption and zero-knowledge proof. Since a large amount of privacy information is contained in edge computing metadata, this information may be used for side-channel attacks to obtain user privacy. At the same time, edge nodes in the edge system may generate malicious parameters to undermine the confidentiality of encrypted keywords in traditional searchable encryption-based solutions. Therefore, the present invention proposes a privacy protection method for edge computing metadata based on searchable encryption and zero-knowledge proof. This method protects metadata privacy through searchable encryption to prevent malicious edge gateways and eavesdroppers from obtaining metadata-related information; this method uses zero-knowledge proof to resist malicious edge nodes and prevent malicious edge nodes from undermining the confidentiality of encrypted metadata by generating carefully designed malicious parameters, thereby compromising user privacy.
[0006] Specifically, a privacy protection method for edge computing metadata based on searchable encryption and zero-knowledge proof of the present invention includes the following steps:
[0007] Step 1: System initialization. A trusted authority generates the necessary parameters for the system at this stage and publishes the required system parameters.
[0008] Step 2: Registration stage. Edge nodes complete the registration process at the trusted authority at this stage, and the authority generates a private key for them.
[0009] Step 3: Group generation stage. A group of edge nodes intending to build an edge computing system negotiate at this stage to obtain a group public key. At this stage, when each edge node generates group-related parameters, it needs to use zero-knowledge proof technology to attach a proof related to the parameter, so as to prevent edge nodes from maliciously generating designed parameters to undermine the confidentiality of encrypted metadata.
[0010] Step 4: Keyword generation stage. This stage is completed by negotiation among edge nodes in the edge computing system. To resist keyword guessing attacks, the edge computing system needs to select a random string as the keyword, and the end user needs to record the correspondence between the keyword and the required factors.
[0011] Step 5: Message encapsulation stage. This stage is executed by edge nodes to calculate the corresponding encrypted keyword for the metadata keyword.
[0012] Step 6: Test authorization stage. This stage is executed by edge nodes to calculate partial traps for a group of keywords respectively, and send the partial traps and the flag indicating whether they are willing to execute the corresponding tasks to the edge gateway through a secure channel. After receiving the partial traps, the edge gateway performs operations to obtain the corresponding complete trap. This complete trap can be used to determine whether the corresponding keyword exists in the encrypted metadata.
[0013] Step 7: Resource allocation phase, which is performed by the edge gateway, which uses the complete trapdoor obtained in the test authorization phase to calculate the received encrypted metadata to determine whether the encrypted metadata contains the corresponding keyword. Subsequently, the edge gateway can complete the resource allocation process according to the corresponding label of the keyword of each edge node.
[0014] The beneficial effects of the present invention are as follows:
[0015] The present invention provides an edge computing metadata privacy protection method based on searchable encryption and zero-knowledge proof. The method ensures that the terminal user metadata is encrypted, so that the edge gateway can smoothly determine whether a certain keyword exists in the encrypted metadata, thereby completing the resource allocation process; in addition, the method uses zero-knowledge proof technology when generating parameters in the group generation stage to avoid malicious edge nodes from generating designed parameters to destroy the confidentiality of the encrypted metadata. Since the edge computing metadata contains a lot of user privacy information, this information is directly transmitted in plain text in the communication channel, which will directly affect the privacy security of the user. If the metadata is encrypted and then transmitted, when the edge gateway is malicious or hacked, the private key stored at the edge gateway will also be leaked, eventually causing the user's privacy to be leaked. Therefore, the present invention provides an edge computing metadata privacy protection method based on searchable encryption and zero-knowledge proof, using searchable encryption to ensure that the edge gateway can complete the resource allocation process without learning any metadata-related information, and using zero-knowledge proof to resist malicious edge nodes from generating malicious parameters to destroy the confidentiality of encrypted metadata, thereby protecting the privacy information of user metadata in the edge computing resource allocation process. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 This is a system model diagram used in the present invention;
[0017] Figure 2 It is the overall flow chart of the present invention. DETAILED DESCRIPTION
[0018] The specific implementation methods provided by the present invention are described in detail below in conjunction with the embodiments and drawings.
[0019] Figure 1It is the system model diagram of the searchable encryption of the present invention. There are mainly four types of entities in the system, namely the trusted authority, the end user, the edge gateway, and the edge node. The authority completes the initialization process for the system and provides registration services for the edge nodes. The edge nodes use the system parameters to negotiate and generate a group public key and a keyword list. Each edge node needs to generate partial trapdoors for each keyword in the keyword list. The edge gateway uses the complete trapdoor obtained by aggregating these partial trapdoors to determine whether the keyword exists in the encrypted metadata, and finally completes the resource allocation process.
[0020] Figure 2 It is the flowchart of a method for protecting the privacy of edge computing metadata based on searchable encryption and zero-knowledge proof proposed by the present invention, which includes the following steps:
[0021] Step 1: The trusted relevant authority selects two multiplicative cyclic groups and generates the corresponding bilinear pairing. Subsequently, the authority randomly selects s as the system master key and calculates the corresponding system public key. Finally, the authority selects three hash functions h1, h2, h3 to generate the corresponding common reference string for the system, and publicly discloses all parameters except the master key as the system parameters.
[0022] Step 2: Each edge node sends its identity ID to the authority through a secure channel i , and the authority uses h1, s, and ID i to calculate the private key for this edge node.
[0023] Step 3: The edge nodes in the edge system jointly negotiate to generate a unique group ID. At the same time, each edge node needs to maintain a set S containing the subscripts of all valid edge nodes. For 1 ≤ i ≤ k, the i-th edge node selects a random number x i and calculates where g is the generator of group 1. Subsequently, the edge node calculates the corresponding proof for r i . Finally, the edge node sends r i and the corresponding proof to other edge nodes through a secure channel. After receiving the message, each edge node first verifies the validity of the verification. If it is invalid, it is considered that this edge node is malicious and the corresponding subscript is deleted from S. Finally, the group ID and group public key are calculated and publicly disclosed using the received information.
[0024] Step 4: The edge nodes in the edge computing system negotiate a keyword list. In order to resist keyword guessing attacks, the edge computing system needs to select random strings as keywords, and the end user needs to record the correspondence between the keywords and the required factors.
[0025] Step 5: For keyword m, the vehicle selects a random number and uses this random number and the group encryption public key to calculate the corresponding encrypted keyword.
[0026] Step 6: To authorize the edge gateway to test a group of keywords, the edge node uses the private key and x i to calculate the corresponding partial trapdoor for this keyword. And the partial trapdoor is sent to the gateway through a secure channel together with the flag of whether it is willing to execute the corresponding task. The gateway aggregates these partial trapdoors using the product operation to obtain the complete trapdoor.
[0027] Step 7: After receiving the encrypted keyword in the encrypted metadata, the edge gateway performs an operation through the complete trapdoor to determine whether this keyword exists in the encrypted metadata, thus completing the corresponding resource allocation process.
[0028] The preferred embodiments of the present invention have been specifically described above, but the present invention is not limited to the described embodiments. Those skilled in the art can also make various equivalent variations or substitutions without departing from the spirit of the present invention, and these equivalent variations or substitutions are all included within the scope defined by the claims of this application.
Claims
1. A method for protecting metadata privacy in edge computing based on searchable encryption and zero-knowledge proof, characterized in that, It includes the following steps: Step 1: System initialization. In this stage, a trusted authority generates the necessary parameters for the system and publishes the required system parameters; Step 2: Registration stage. In this stage, the edge nodes complete the registration process with the trusted authority, and the authority generates a private key for each of them; Step 3: Group generation stage. A group of edge nodes intending to build an edge computing system negotiate in this stage to obtain the group public key; In this stage, when each edge node generates group-related parameters, it needs to use zero-knowledge proof technology to attach the proof related to the parameter, so as to prevent edge nodes from maliciously generating designed parameters to destroy the confidentiality of encrypted metadata; Step 4: Keyword generation stage. This stage is completed by the negotiation of edge nodes in the edge computing system. To resist keyword guessing attacks, the edge computing system needs to select a random string as the keyword, and the end user needs to record the correspondence between the keyword and the required factors; Step 5: Message encapsulation stage. This stage is executed by the edge nodes to calculate the corresponding encrypted keyword for the metadata keyword; Step 6: Test authorization stage. This stage is executed by the edge nodes to calculate partial trapdoors for a group of keywords respectively, and send the partial trapdoors and the flag indicating whether they are willing to execute the corresponding tasks together to the edge gateway through a secure channel; after receiving the partial trapdoors, the edge gateway performs operations to obtain the corresponding complete trapdoor; this complete trapdoor can be used to judge whether the corresponding keyword exists in the encrypted metadata; Step 7: Resource allocation stage. This stage is executed by the edge gateway, and the gateway uses the complete trapdoor obtained in the test authorization stage to perform operations with the received encrypted metadata to judge whether the encrypted metadata contains the corresponding keyword; Subsequently, the edge gateway can complete the resource allocation process according to the corresponding tags of each edge node for the keyword.