Location privacy protection method based on block chain and threshold cryptography mechanism

Through the location privacy protection method of blockchain and threshold cryptography mechanism, Shamir(n,t) secret sharing and threshold encryption mechanism are used to split the decryption key, combined with the token incentive mechanism, the problem of user privacy information leakage and collaboration failure in location services is solved, and the dual protection of location and query privacy is achieved.

CN120378175APending Publication Date: 2025-07-25CHANGZHOU UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510563096.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the existing location service methods, user privacy information is prone to leak, and collaborative users are unwilling to participate or collaborative information is not sent in time.

Method used

The location privacy protection method based on blockchain and threshold cryptography mechanism is adopted, and the Shamir(n,t) secret sharing and threshold encryption mechanism are used to divide the decryption key into pieces. Through collaborative users, they hide the real location and query content, and introduce a token incentive mechanism to improve the willingness and timeliness of collaborative users' participation and timeliness.

Benefits of technology

It realizes dual protection of user location and privacy query, ensures information security and the success rate of anonymous collaboration, and solves the problems of user privacy information leakage and collaboration failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378175A_ABST
    Figure CN120378175A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of location services, in particular to a location privacy protection method based on a block chain and a threshold cryptography mechanism, and the method comprises the steps: obtaining the query content of a request user; a Shamir (n, t) and threshold encryption mechanism is utilized to encrypt query content of a requesting user, divide a decryption key into fragments, distribute the key fragments and request ciphertext to a cooperative user together, and then send the fragments and the request ciphertext to an LBS server, and the real position and real query content of the requesting user are hidden through the cooperative user; the LBS server recovers the decryption key by using a Lagrange polynomial interpolation algorithm to obtain position information of the request user and the cooperative user; and using a token incentive mechanism to take the Token value as a service request priority response basis of the request user, and carrying out anonymous cooperation on the request user by the cooperation user. According to the method, the problem of privacy leakage caused by untrusted location service, unwilling of collaborative users and untimely sending of collaborative information in the existing method is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of location services, and in particular, to a location privacy protection method based on a blockchain and a threshold cryptography mechanism. Background Art

[0002] Location-based services (LBS) are widely used in fields such as intelligent transportation and travel services, social networks and life services. For example, location check-in services in social networks, etc.

[0003] Existing location privacy protection methods based on k-anonymity methods, differential privacy protection methods, etc. mostly rely on intermediate servers such as third parties for anonymization or noise addition; however, the performance bottleneck and information security transmission problems of the intermediate server make the third-party server not completely reliable, and there is a risk of privacy leakage; but these methods have certain security problems in practical applications;

[0004] On the one hand, collaborative users participating in anonymization may disclose the privacy information of the requesting user. Current privacy protection methods consider the location server to be untrustworthy, but other users participating in anonymization collaboration are considered to be honest and trustworthy. These users can obtain the real location information of the user and also share the real query request content with the user, believing that collaborative users participating in anonymization will not disclose any privacy information of the user; in fact, collaborative users are not completely or fully trustworthy, and they may cause the leakage of the user's privacy information, or an attacker may also disguise as a collaborative user to obtain the privacy information of the requesting user; therefore, directly publishing the real location in the anonymous set or area by the requesting user, as well as sharing the request content with collaborative users, will result in the risk of personal privacy information leakage; at the same time, in current location-based privacy protection methods, either the location trajectory information of the user is protected so that other users participating in anonymization together can know the query content of the user but do not know the specific location information of the user; or the query content of the user is protected so that participating users can know the location information of the user but do not master the query content of the user, and separate privacy protection is achieved through the method of separating location information and query information, and it is impossible to achieve dual protection of the user's location privacy information and query privacy information at the same time;

[0005] On the other hand, when the requesting user constructs an anonymous area, the users nearby who meet the conditions may not necessarily be willing to participate in anonymization collaboration. If the number of collaborative users is insufficient, or the collaborative users who participate in the collaboration do not construct an anonymous area or process anonymous information within the specified time, this anonymization process will fail, resulting in the leakage of the user's privacy information. Summary of the Invention

[0006] In view of the deficiencies of existing methods, the present invention aims to solve the problem of privacy leakage caused by the untrustworthiness of location services, the unwillingness of collaborative users, and the untimely sending of collaborative information in existing methods. It proposes location privacy protection based on blockchain and threshold cryptography mechanisms, which can not only protect the location privacy of users but also protect their query privacy, achieving "absolute security" for users' privacy information.

[0007] The technical solution adopted by the present invention is as follows: A location privacy protection method based on blockchain and threshold cryptography mechanisms includes the following steps:

[0008] Step 1: Obtain the query content of the requesting user;

[0009] Step 2: Use Shamir(n,t) secret sharing and threshold encryption mechanisms to encrypt the query content of the requesting user, split the decryption key into fragments, distribute the key fragments and the request ciphertext to collaborative users together, and then send them to the LBS server. The collaborative users are used to hide the real location and real query content of the requesting user;

[0010] Step 3: The LBS server uses the Lagrange polynomial interpolation algorithm to recover the decryption key and obtain the location information of the requesting user and collaborative users;

[0011] Step 4: Use the token incentive mechanism to take the Token value as the basis for preferentially responding to the service request of the requesting user, and the collaborative users conduct anonymous collaboration with the requesting user.

[0012] As a preferred embodiment of the present invention, the anonymous collaboration includes:

[0013] All users register with the CA to obtain a key pair of public key and private key, and construct a public permission chain through the public key;

[0014] As a preferred embodiment of the present invention, the registration of the requesting user with the CA includes:

[0015] Select a random number r as a temporary encryption key, and encrypt r and the user identity ID u as the CA public key pk CA to generate an application ciphertext, and then send it to the CA, Encrypt(ID u ,r,pk CA )→E(ID u ||r);

[0016] The CA uses the private key to decrypt to obtain the plaintext user information ID u and the temporary key r, Decrypt(E(ID u ||r),sk CA )→(ID u ,r);

[0017] Using the security parameter λ and the private key sk CA , the user identifier ID u To generate a key pair (pk u , sk u ) for the user, KeyGen(λ, sk CA , ID u ) → (pk u , sk u );

[0018] Using r to encrypt the key pair (pk u , sk u ) to generate the ciphertext of the user's key pair Encrypt(pk u , sk u , r) → E(pk u , sk u );

[0019] The user uses r and the ciphertext of the user's key pair to decrypt to obtain the key pair Decrypt(E(pk u , sk u ), r) → (pk u , sk u ).

[0020] The requesting user makes an anonymous request, and the smart contract responds to and judges this request according to the Token value;

[0021] As a preferred embodiment of the present invention, when the requesting user makes an anonymous request, it is necessary to authenticate the user's identity to the CA.

[0022] As a preferred embodiment of the present invention, the user identity authentication includes:

[0023] Using the private key sk u to digitally sign the public key pk u to obtain

[0024] Encrypt the public key pk u , using the CA public key PK CA to generate an authentication request message and send it to the CA; The CA private key SK CA decrypts the user request message and verifies it.

[0025] As a preferred embodiment of the present invention, the anonymous request includes:

[0026] The requesting user makes an anonymous request q, and the smart contract detects the Token value w u of the q reward, and adds w u to the Token list of the currently requesting user;

[0027] If the requesting user is among the top t, allow the requesting user to publish a collaboration request through the public permissioned chain; otherwise, the requesting user waits until the Token value is among the top t.

[0028] As a preferred embodiment of the present invention, the request content includes the number n of users requiring collaboration, the number t of users obtaining incentive points, the anonymous area threshold R, and the Token value w of the reward.

[0029] As a preferred embodiment of the present invention, the Byzantine fault tolerance mechanism is used to set n = 3t + 1.

[0030] The requested user who is responded to sends a collaboration request in the public permissioned chain and constructs a temporary private chain using the collaborating users;

[0031] As a preferred embodiment of the present invention, after the temporary private chain is created, the requesting user encrypts q with the private key sk and divides the public key pk into n fragments pk using Shamir(n, t) i , and sends them to the private chain;

[0032] The requesting user hides the real location in the real query information, regenerates the query information q = {c, T}, and then encrypts q with the private key sk to generate the ciphertext Q;

[0033] The public key p of the user is divided into n public key shards pk using Shamir(n, t) k respectively, and distributed to the collaborating users on the private chain together with the query ciphertext. i The requesting user encrypts and divides the query request and the key, and sends the divided fragments to the collaborating users on the private chain respectively. The requesting user sends the real location and the division information to the LBS server; the collaborating users send the real location and the division information to the LBS server. The users of the first t collaboration requests obtain Token incentives;

[0034] After receiving at least t encrypted messages, the LBS server reconstructs the decryption key, decrypts, verifies, obtains the query request, and generates a query result;

[0035] After encrypting the query result with the recovered key, the LBS server sends it to the temporary private chain. The requesting user obtains the return result from the private chain and decrypts it; the smart contract executes the Token value distribution and rewards the users of the first t collaboration requests with Token values.

[0036]

[0037] ​As a preferred embodiment of the present invention, a location privacy protection system based on blockchain and threshold cryptography mechanism includes: a memory for storing instructions executable by a processor; and a processor for executing the instructions to implement a location privacy protection method based on blockchain and threshold cryptography mechanism.

[0038] As a preferred embodiment of the present invention, a computer-readable medium storing computer program code, the computer program code implementing a location privacy protection method based on blockchain and threshold cryptography mechanism when executed by a processor.

[0039] Advantages of the present invention:

[0040] 1. To solve the problem of the leakage of users' sensitive information caused by untrusted anonymous collaborative users and location servers in location-based services, the present invention constructs a privacy protection system based on secret sharing algorithms and threshold cryptography systems. First, use the asymmetric encryption system to encrypt the user's query request to prevent the leakage of the user's privacy information. Then, with the help of the Shamir(n,t) secret sharing method and the threshold encryption system, split the decryption key into n key fragments, and distribute the key fragments and the encrypted request together to n - 1 collaborative users. Then, the requesting user and the collaborative users each send their real locations, the encrypted request, and a key fragment to the LBS server. When the LBS server receives no less than t request messages, use the Lagrange interpolation algorithm to recover the decryption key, obtain the actual query content of the user, provide the corresponding service, and finally encrypt and send the query result to the requesting user to complete the location-based service, thus protecting the query content of the user and the real location information of the requesting user from being leaked.

[0041] 2. To solve the problem of anonymous collaborative users being unwilling to participate in collaboration and the collaborative users who participate in collaboration not being able to send collaboration requests in time, resulting in the failure of anonymous collaboration, the present invention constructs a distributed privacy protection system based on blockchain. First, use the smart contract method of blockchain to create a private chain and construct a secret set of collaborative users to ensure the confidentiality of the transmitted information. Then, introduce the proof-of-stake and consensus mechanism of blockchain, use the Token value as the basis for whether the user's request can be preferentially responded to, select the main node or leader of the private chain, the requests of users with higher Token values have higher priorities, determine the request response and execution levels, and use the Token value to encourage more users in the public permissioned chain to participate in collaboration. Finally, introduce the token incentive mechanism. The user who proposes an anonymous collaboration request needs to consume a certain amount of Token values, while the first t collaborative users who send collaboration requests will obtain a certain amount of Token values, and use the competition mechanism to encourage collaborative users to send collaboration information in time, and solve the problem of privacy leakage in the process of anonymous collaboration.

[0042] 3. To ensure the integrity and non-forgeability of ciphertext information, the present invention constructs a ciphertext validity verification mechanism; uses key splitting technology to generate verification keys, and utilizes cryptographic key verification algorithms and share combination algorithms to verify the validity of ciphertext fragments sent by collaborative users, ensuring the security and non-forgeability of information; meanwhile, experiments are conducted on real datasets for the method proposed in this paper, verifying the feasibility and effectiveness of the method proposed by the present invention;

[0043] 4. The method of the present invention can be applied to fields such as intelligent transportation and travel services, social networks and life services for location privacy protection to ensure user privacy security. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 is a block diagram of the location privacy protection method based on blockchain and threshold cryptography mechanism of the present invention;

[0045] Figure 2 is a secret sharing instance of the present invention;

[0046] Figure 3 is a threshold encryption flowchart of the present invention;

[0047] Figure 4 is a process diagram for creating a private chain of the present invention;

[0048] Figure 5 is a comparison of execution times for different numbers of collaborative users of the present invention;

[0049] Figure 6 is a comparison of anonymous success rates for different numbers of collaborative users;

[0050] Figure 7 is a comparison of execution times for different threshold values;

[0051] Figure 8 is a comparison of anonymous success rates for different threshold values;

[0052] Figure 9 is a comparison of execution times for different Token values;

[0053] Figure 10 is a comparison of anonymous success rates for different Token values;

[0054] Figure 11 is a comparison of anonymous success rates for different tolerance time thresholds and numbers of collaborative users;

[0055] Figure 12 is a comparison of anonymous success rates for different tolerance time thresholds and threshold values;

[0056] Figure 13 is a comparison of execution times for different methods;

[0057] Figure 14 It is a comparison of the anonymous success rates of different methods. Specific implementation manner

[0058] The present invention will be further described below in conjunction with the accompanying drawings and embodiments. This figure is a simplified schematic diagram, which only illustrates the basic structure of the present invention in a schematic manner. Therefore, it only shows the components related to the present invention.

[0059] As Figure 1 shown, a location privacy protection method based on blockchain and threshold cryptography mechanism includes the following steps:

[0060] Secret Sharing is a way to securely share secrets among multiple participants. It divides the secret S into a certain number of secret shards, and each participant independently holds a secret shard. Only by combining a sufficient number of shards can the secret S be restored; when the number of obtained shards is insufficient, no information about the secret S will be leaked no matter what combination strategy is adopted.

[0061] Shamir(n,t) secret sharing constructs a polynomial of degree t - 1, divides the secret S to be shared into n shards and distributes them to n participants. When the number of shards is not less than t, the secret S can be solved;

[0062] The specific process is as follows:

[0063] 1. Initialization stage: Let n, t be positive integers, and t ≤ n. The secret distributor D randomly selects n different non-zero elements x1, x2,..., x n to respectively identify n participants U r ={U1, U2,..., U n}(r = 1, 2,..., n), and publicly discloses x r and the corresponding U r ;

[0064] 2. Secret distribution stage: The secret S to be distributed ∈ Z q (q is a large prime number) is decomposed into n shards {S1, S2,..., S n}, and then the shard S i (1 ≤ i ≤ n) is respectively distributed to each of the n participants U r one copy; (t - 1) elements a i (i = 1, 2,..., t - 1) are arbitrarily selected within GF(p) to construct a polynomial of degree t - 1. Each shard is a coordinate point (x i , F(x i )) of this polynomial, and the generated polynomial is:

[0065]

[0066] Among them, a0 represents the original secret information, and a i represents the decomposed password shards. p is a large prime number and p > s, and the secret s = F(0) = a0.

[0067] For all U r ∈U, generate n sub-secrets:

[0068]

[0069] Then send s r securely to the corresponding U r .

[0070] 3. Secret recovery process: Any t shard holders {U1, U2,..., U t} combine their shards, and the secret S can be recovered using the Lagrange polynomial interpolation algorithm:

[0071]

[0072] Among them, x l and x v represent any two different shards of the secret.

[0073] For example, when n = 7 and t = 5, construct a polynomial of order t - 1 = 5 - 1 = 4, that is

[0074] F(x) = a0 + a1x + a2x 2 + a3x 3 + a4x 4

[0075] Divide the secret represented by this curve into 7 shards, as Figure 2 shown. When obtaining the points represented by any 5 of the 7 shards, the coefficients of the polynomial F(x) can be deduced inversely, and the constant coefficient a0 can be determined to obtain the secret value it represents.

[0076] Threshold encryption means that any user can use the encryption key to encrypt a message, but the decryption key is divided into multiple shards and distributed to multiple holders. Only when a certain number of secret holders cooperate and aggregate the decryption shards can the decryption key be recovered to decrypt the secret information. The specific process is as Figure 3 shown;

[0077] 1. Initialization: The secret owner obtains a data encryption key pair (PK, SK), where PK is the public key and SK is the private key. Set the number parameter n for private key splitting and the minimum parameter t for key recovery. Then split the private key SK into n key shards sk i , and distribute them to n participants;

[0078] 2. Encryption: The data owner encrypts the plaintext m of the data using the public key PK to generate the ciphertext E(m);

[0079] 3. Generate decryption shards: The participants respectively use their own private key shards sk i to decrypt the ciphertext E(m) and generate decryption shards D i (m).

[0080] 4. Aggregate decryption shards: The participants aggregate the decryption shards D i (m). When the obtained decryption shards D i (m) are not less than t, the aggregate decryption can be completed to obtain the data plaintext m.

[0081] To solve the threats faced by personal location sensitive information such as insufficient trust, collusion attacks by collaborative users, weak willingness to collaborate, and untimely collaborative anonymity in the current privacy protection methods, the location privacy protection method of the present invention based on blockchain and threshold cryptography mechanism can solve the privacy leakage problems caused by unwillingness of collaborative users, untrustworthy location services, and untimely sending of collaborative information, and achieve double protection of users' location privacy information and query privacy information.

[0082] Step 1. Obtain the query content of the requesting user;

[0083] Assume that the true query content of the requesting user is q’ = {lu, c, T}, where lu represents the true location of the user, c represents the query content, and T represents the timestamp of each query;

[0084] To protect the location privacy of the requesting user, hide its true location lu and regenerate the query content q = {c, T}.

[0085] Step 2. Use the Shamir(n, t) secret sharing and threshold encryption mechanism to encrypt the query content of the requesting user, split the decryption key into n shards, distribute the key shards and the request ciphertext to n - 1 collaborative users, and then send them to the LBS server. The n - 1 collaborative users are used to hide the true location and true query content of the user, so that the semi-trusted collaborative users and the LBS server cannot obtain any accurate information about the initial requesting user; each collaborative user sends 1 / n of the encrypted query content and the decryption key, and they cannot obtain the accurate information of the requesting user.

[0086] Step 3: The LBS server can use the Lagrange polynomial interpolation algorithm to recover the decryption key, decrypt the request ciphertext to obtain the user's true query content, and obtain the n location information of the requesting user and the collaborating users. However, it cannot determine which location is the true location of the requesting user, nor can it determine which user sent this query request. Therefore, it cannot obtain the privacy information of the true user.

[0087] Step 4: The present invention uses a token incentive mechanism to take the Token value as the basis for whether the user's service request is preferentially responded to. The t users who successfully participate in the collaboration can obtain a certain number of Token values, so as to improve the priority of their anonymous requests, so that the collaborating users are more willing to participate and can timely send the collaboration information to the LBS server, improving the timeliness and success rate of privacy protection; the collaborating users perform anonymous collaboration on the requesting user;

[0088] As Figure 1 shown, the anonymous collaboration process includes: initialization, user authentication, proposing an anonymous service request, encrypting and splitting the request for sending, reconstructing the request to provide services, and obtaining the result Token reward process;

[0089] All users register with the CA to obtain a key pair of public key and private key. The public key is used as the user's identity identifier, and the private key is secretly saved by the user. Then, a public permission chain is constructed through the public key;

[0090] The requesting user proposes an anonymous request, and the smart contract decides whether to respond to this request according to its Token value;

[0091] The responded requesting user sends a collaboration request in the public permission chain, publishes relevant parameters and the incentive Token value. The collaborating users who meet the conditions and are willing to participate in the collaboration construct a temporary private chain;

[0092] The requesting user encrypts and splits the query request and the key, sends the split fragments to the collaborating users on the private chain respectively, and sends its true location and one of the split information to the LBS server; the collaborating users in the private chain send their true locations and one of the split information to the LBS server. The first t users who send collaboration requests can obtain a certain Token incentive;

[0093] When the LBS server receives at least t encrypted messages, it reconstructs the decryption key, decrypts, verifies these messages, obtains the query request, and generates a query result;

[0094] After encrypting the generated query results with the recovered key, the LBS server sends them to the temporary private chain and requests the user to obtain the LBS return results from the private chain. After decryption, the user can obtain the final query results. The smart contract executes the Token value distribution function and gives corresponding Token value rewards to the first t participants who successfully send collaboration information.

[0095] Among them, the process of user registration is as follows:

[0096] All users register with the CA (including requesting users and collaborating users). Each registered user is assigned a pair of public and private keys, and their identities are stored in the user pool; during the location-based service process, the public key is used instead of the real identity to complete anonymous requests and collaborations, and the registered users jointly form a public permission chain;

[0097] Among them, the process of user service registration is as follows:

[0098] All users register with the CA using their personal information. First, select a random number r as the temporary encryption key, and encrypt r and the user identity ID u and send them to the CA after encrypting with the CA public key; after receiving the user's registration request, the CA decrypts it using its own private key to obtain the user's personal information, and generates a key pair (pk u , sk u ) for the user. Then, encrypt the key pair (pk u , sk u ) using the user's temporary key r and return it to the user; finally, the user decrypts it with r to obtain the key pair (pk u , sk u ); among them, pk u is the user public key, and sk u is the user private key. The specific process is as follows:

[0099] Step1: Input the temporary key r, user identification ID u and the CA public key pk CA , and generate the application ciphertext:

[0100] Encrypt(ID u , r, pk CA ) → E(ID u ||r) (4)

[0101] Step2: Input the user application ciphertext E(ID u ||r) and the CA private key sk CA , and obtain the plaintext ID of the user identification information u and the temporary key r:

[0102] Decrypt(E(IDu ||r), sk CA ) → (ID u , r) (5)

[0103] Step 3: Input the security parameter λ, the private key sk of the CA CA , the user identifier ID u , and generate the public and private key pairs of the user:

[0104] KeyGen(λ, sk CA , ID u ) → (pk u , sk u ) (6)

[0105] Step 4: Input the temporary key r, the public and private key pairs (pk u , sk u ) of the user, and generate the ciphertext of the user's key pair:

[0106] Encrypt(pk u , sk u , r) → E(pk u , sk u ) (7)

[0107] Step 5: Input the temporary key r and the ciphertext of the user's key pair to obtain the public and private key pairs of the user:

[0108] Decrypt(E(pk u , sk u ), r) → (pk u , sk u ) (8)

[0109] Among them, the user identity authentication process is as follows:

[0110] When the requesting user submits an anonymous application, it is necessary to authenticate with the CA; the user first uses his own private key sk u to digitally sign the public key pk u representing his own identity, and obtain Then, the user's public key pk u , the digital signature on ID u are encrypted together using the public key PK of the CA CA to generate an authentication request message and send it to the CA; the CA uses its own private key SK CA to decrypt the user request message and verify it. If the verification is successful, a verification success message is returned.

[0111] Specifically, it includes:

[0112] ​Step1: Input the digital signature of the user public key pk u and the public key PK of the CA CA to generate the ciphertext of the user's authentication application:

[0113]

[0114] Step2: Input the private key sk of the CA CA and the ciphertext of the user's authentication application to obtain the digital signature of the user:

[0115]

[0116] Among them, the process for the user to make an anonymous request is as follows:

[0117] After the user's identity authentication is successful, an anonymous request q is made, and the smart contract detects its Token value w u and adds it to the Token list of the currently requesting user. If the requesting user is among the top t, it is allowed to publish a collaboration request through the public permissioned chain. The request content includes the number n of users required for collaboration, the number t of users who can obtain incentive points, the anonymous area threshold R, and the Token value w of the reward; otherwise, the user needs to wait until its Token value is among the top t.

[0118] To improve the robustness of the method, according to the Byzantine fault tolerance mechanism, n = 3t + 1 is set to ensure that there are enough collaborative users to send collaborative information normally, in a timely manner, and accurately.

[0119] Among them, the process of constructing a temporary private chain based on the collaboration request is as follows:

[0120] When the users in the public permissioned chain meet the anonymous requirements put forward by the requesting user and are willing to participate in anonymous collaboration, they make a request to construct a private chain and become anonymous collaborative users. The smart contract executes a predetermined construction protocol to establish a temporary private chain containing the requesting user and the collaborative users, and ends the execution until the number of collaborative users on the temporary private chain is not less than n - 1; the collaborative users who meet the privacy requirements provide their location information, and the blockchain will create a new block to record the operations of the users; the created private chain is as Figure 4 shown, where all users form the public permissioned chain, and the users in the dotted box are the temporary private chain established to meet the specific anonymous collaboration request of the requesting user.

[0121] Among them, the process for the requesting user to split the collaboration request is as follows:

[0122] After the temporary private chain is created, the requesting user encrypts the request information q with the private key sk and divides the public key pk into n fragments pk using the Shamir(n, t) secret sharing methodi , send it to the private chain; assume the real query information of the requesting user is defined as q’ = {lu, c, T}, where lu represents the real location of the user, c represents the query content, and T represents the timestamp of each query; to protect the user's location privacy, hide the real location lu, regenerate the query information q = {c, T}, and then use the user's private key sk to encrypt the query content q to generate the ciphertext Q; then use the Shamir(n, t) secret sharing method to split the user's public key p k into n public key shards pk i , and distribute them together with the query ciphertext to n - 1 collaborating users on the private chain. The specific process is as follows:

[0123] Step1: Key generation, input the user identity ID u , security parameter λ, secret sharing parameters n and t, and generate the temporary key pair for this service:

[0124] KeyGen(λ, ID u , n, t) → (p k , v k , s k ) (11)

[0125] where p k is the user's public key, s k is the user's private key, and v k is the verification key.

[0126] Step2: Encrypt the query content. The requesting user uses their own private key sk to encrypt the query information q = {c, T} to generate the request ciphertext Q:

[0127] Encrypt(s k , q) → Q (12)

[0128] Step3: Split the user's key. Use the Shamir(t, n) secret sharing method to split the user's public key pk into n shards. The specific process is as follows:

[0129] 1. Let a0 = k, and randomly select t - 1 elements a i (i = 1, 2,..., t - 1) in GF(p) to form a polynomial of degree t - 1, that is

[0130]

[0131] where p is a large prime number and P > S, and the secret S = F(0) = a0.

[0132] 2. Let x j = k i , and n sub - keys can be generated:

[0133]

[0134] Among them, j represents the serial number of the segmented fragment, and j = 1, 2, …, n.

[0135] Finally, the sub-keys (k i , F(k i )) of n segmented fragments are respectively {(k1, F(k1)), (k2, F(k2)), …, (k n , F(k n ))}; K i = (k i , F(k i )) Then the n sub-keys can be respectively expressed as {K1, K2, …, K n};

[0136] 3. Combine them into request data packets, and encapsulate the ciphertext Q of the user query content, the verification key V k and the sub-key K i into n request data packets, namely:

[0137] M = {(Q, V k , K1), (Q, V k , K2), … (Q, V k , K n )} (15)

[0138] Distribute the collaboration request and the collaborating user sends a collaboration request: Number the n - 1 collaborating users on the private chain from 1 to n - 1, and randomly set them as C1, C2, …, C n-1 ; Construct a hash function H(·) with each request data packet as a variable and take its modulus to obtain the collaborating user mapped to the number j. Use the random mapping mechanism to send the data packets {(Q, V k , K1), (Q, V k , K2), … (Q, V k , K n-1 )} to the n - 1 collaborating users respectively;

[0139] C j = H(Q + V k + K i ) mod (n - 1) (16)

[0140] Among them, 1 ≤ i ≤ n, 1 ≤ j ≤ n - 1.

[0141] When different data packets are sent to the same collaborating user, a conflict will occur; therefore, set a hash function to solve the conflict:

[0142] Cj =(H(Q + V k + K i )) + v) mod (n - 1) (17)

[0143] Where v = 1, 2, …, n - 1, and v = v + 1. Initially set v = 1. If there is still a conflict in the obtained collaborative user numbers, increment the value of v until the conflict is resolved.

[0144] The collaborative users on the temporary private chain receive the data packets (Q, V k , K i ), and then combine their real location l i with the received data packets (Q, V k , K i ) to form the data packet (Q, V k , K i , l i ) and send it to the LBS server together; to ensure that collaborative users can send collaborative requests in a timely manner, an incentive competition mechanism is introduced, and it is set that the first t users to send will receive w Token value incentive points; at the same time, the requesting user combines a set of (Q, V k , K i ) query information with his real location to form the data packet (Q, V k , K i , l u ) and send it to the LBS server; at this time, the LBS server will receive n data packets containing the same query content and different location information.

[0145] Among them, the process for the LBS server to obtain the query content is as follows:

[0146] Finally, the LBS server will receive a total of n data packets (Q, V k , K i , l i ) sent by the requesting user and the collaborative users. When the number of received data packets is not less than t, start the partial decryption algorithm and share verification algorithm of threshold encryption, reconstruct the decryption key, decrypt the query information, and obtain a set of query request information.

[0147] Step1: Recover the public key pk of the requesting user. The LBS server aggregates t key shards {K1, K2, …, K t} within time T, that is, {(k1, F(k1)), (k2, F(k2)), …, (k t , F(k t ))}, recover the constructed polynomial of degree t - 1, determine the coefficients a0, a1, a2, …, a t-1 , obtain a polynomial of degree t - 1 with constant coefficients, and thus obtain the decryption key, specifically as follows:

[0148]

[0149] Then the constant coefficient polynomial obtained is:

[0150] F(x) = a0 + a1x + a2x 2 +... + a t-2 x t-2 + a t-1 x t-1 (19)

[0151] Let x = 0, then F(0) = a0, and the constant term a0 is the decryption key pk requested for the user to split.

[0152] Step2: Partial decryption. Input the ciphertext Q and the i-th key fragment k i , and output the decryption share (i, q i ) of the encrypted information. Specifically:

[0153] Decrypt(p ki , i, Q) → (i, q i ) (20)

[0154] Step3: Share verification. Input the decryption key pk, the verification key v k , the ciphertext Q, and the decryption share q i . When it is a valid share of the ciphertext, output "1", otherwise output "0". Specifically:

[0155] Verify(pk, v k , Q, q i ) → (1 / 0) (21)

[0156] Step4: Share combination. In the share combination algorithm, input the decryption key pk, the verification key v k , the ciphertext Q, and t decryption shares {q1, q2,..., q t}, and output the complete requested plaintext q of the user. Specifically:

[0157] Combine(pk, v k , Q, {q1, q2,..., q t}) → (q) (22)

[0158] Among them, the process of querying and feedback query results and Token rewards is:

[0159] After the LBS server decrypts the query request, it first verifies the validity of the timestamp T in the query request. If the time difference between it and the system synchronized clock is within the permitted range, the request is legal and can be processed. Then, the LBS performs a query based on the decrypted query content q and t query locations l i , and obtains t query results R = {r1, r2, …, r t}. After that, it uses the reconstructed user public key p k to encrypt and obtain the ciphertext group Cp, which is sent to the private chain. The formula is:

[0160] Encrypt(R, pk) → Cp (23)

[0161] The requesting user obtains the LBS return result Cp from the private chain, decrypts the query result Cp using its own private key sk, and obtains the final query result based on its own location information. Other collaborating users cannot decrypt the query result Cp because they do not have the private key, and thus cannot obtain the specific query request return content. The formula is:

[0162] Decrypt(CP, lu, sk) → r u (24)

[0163] Finally, the smart contract executes the Token allocation function, gives corresponding Token value rewards to the first t users who successfully send collaboration requests, and the other n - t users get nothing because they did not feedback the results in time. At the same time, the requesting user consumes w t Token values; then the temporary private chain is dissolved, and all users return to the public permissioned chain again.

[0164] Among them, the token incentive system and the consensus mechanism process are as follows:

[0165] Token incentive system: A token is a digital form of equity certificate, which represents a right and can take effect and be used in a specific scenario or time; the method proposed in the present invention introduces a token incentive system, uses the Token value as the basis for whether a user's anonymous collaboration request can be preferentially responded to, and mobilizes users on the public permissioned chain to actively participate in the anonymous collaboration of the requesting user.

[0166] When a user submits a query request, the higher his current Token value, the more likely his request will be prioritized; after the anonymous collaboration is completed, the requesting user will consume a certain amount of Token values, while the users who successfully participate in the anonymous collaboration will receive a certain amount of Token values; when a user submits a query request, the larger the published Token value, the more willing the collaborating users are to participate in the collaboration, but only t successfully participating collaborating users can obtain Token values, thus motivating the collaborating users to compete with each other and process the anonymous collaboration information in a timely manner to ensure the timely sending of collaboration information.

[0167] In the method of the present invention, being able to obtain a certain amount of Token value rewards is an important reason for collaborating users to be willing to participate in anonymous collaboration and be able to send collaboration information in a timely manner. For any user in the consortium permission chain, the more times he assists other users in successfully completing anonymous collaboration, the more Token value rewards he will obtain; and the amount of Token values a user himself has is the key to whether his anonymous collaboration request can be prioritized when he becomes a requesting user; at the same time, the larger the Token value set in the anonymous collaboration request of the requesting user, the more users are willing to participate in the collaboration, making the probability of his successful anonymity greater and the efficiency of anonymous collaboration higher.

[0168] In the initial stage of privacy protection, the Token values have been published in the public permission chain, and each eligible collaborating user can choose whether to participate in the collaboration; then, the requesting user submits the Token value to the temporary private chain, and the collaborating users send collaboration information to the LBS server; finally, when the anonymous collaboration of the requesting user ends, the smart contract is activated and rewards the collaborating users according to the protocol; by introducing an incentive competition mechanism, the anonymous requesting user obtains the required anonymous service in a timely manner, and the collaborating users obtain the Token values for being the first to send requests, and both parties get the required results. Therefore, the method of the present invention can solve the problem of privacy leakage caused by collaborating users being unwilling to collaborate and sending collaboration information untimely.

[0169] Admission mechanism:

[0170] The method of the present invention constructs an admission mechanism for the user public permission chain based on the authentication mechanism of the blockchain. Only users who have passed the registration and review are allowed to join, further ensuring information security; all users register with the CA (including the requesting user and the collaborating users) to obtain a pair of key pairs representing the user's identity. The generated public key is used as the user's identity identifier, replacing the user's identity, and is bound to the Token values the user has. The registered users can form a public permission chain.

[0171] After the user's request is responded to, a temporary private chain for this transaction is created. At the same time, to ensure the confidentiality of each request, when sending each request, the user's private key and the set privacy parameters are used to regenerate the temporary public key, private key, and verification key pair for this service request. After the service ends, all temporary keys are cancelled.

[0172] Consensus mechanism:

[0173] The method of the present invention is based on Proof of Stake (PoS) to establish a consensus mechanism for the private chain. Users prove by providing the ownership of a certain number of Token values and thus obtain the right to request. The equity is reflected in the user's ownership of a specific number of Token values. Therefore, based on the Token values held by the user as message resources, as proof of obtaining the right to request, the requests of users with more Token values are preferentially responded to and obtain the bookkeeping right for this transaction, becoming the main node or leader. For any user in the network, the more times he successfully assists other users in completing anonymous collaboration, the more Token value rewards he obtains. Then, when he sends an anonymous collaboration request as a requesting user, his request may be preferentially responded to. He can set a larger Token value, making more users willing to participate in the collaboration, and increasing the probability of his successful anonymity. Therefore, the method of the present invention can, to a certain extent, encourage more users to actively participate in anonymous collaboration and send collaboration information in a timely manner.

[0174] When the requesting user sends a request, eligible users on the public permissioned chain add the transaction to their own transaction pools. If the Token value of the transaction is greater than the threshold set by the user, the user responds to the request. When the number of responding users is not less than n, a temporary private chain is established with the requester as the main node or leader, and the chain contains the requesting user and n - 1 collaborating users who participate in the response. If the request response times out, the request fails.

[0175] When the user sets the (n, t) secret sharing parameters, to prevent malicious users from causing damage, according to the Byzantine Fault Tolerance mechanism (PBFT), n≥3t + 1 is set to ensure that there are enough collaborating users to send collaboration information normally, timely, and accurately. When this request service ends successfully, the requesting user consumes a certain amount of Token values, while the collaborating users obtain a certain amount of Token values, and the established temporary private chain is dissolved, and all users return to the public permissioned chain again.

[0176] Smart contract method:

[0177] A smart contract is a contract or agreement that is automatically controlled or executed according to pre-set rules, represented as a piece of program code. When the triggering conditions are met, the code will execute automatically without manual intervention. The method of the present invention processes the request for the user to obtain the anonymous collaboration process of the collaborative users as a transaction on the blockchain. The smart contract is deployed and triggered through the transaction. When the user makes a service request, he first creates a transaction locally according to his actual needs. After the transaction is created, the user signs the transaction with his private key, and then uses tools such as Ethereum wallets to broadcast this transaction to the permissioned blockchain. All nodes in the permissioned blockchain will receive the transaction information, but not all nodes will accept this transaction. If the Token value of the transaction is lower than the minimum Token value acceptable to some nodes, then this transaction will be ignored by that node. Each node has its own transaction pool, and the transaction pool undertakes the function of transaction caching. Each node puts the transactions that are interested in participating into the transaction pool and arranges them in descending order according to the Token value. When the transaction pool is full, the transactions with low Token values will be replaced by the transactions with high Token values. Some users who successfully participate in the collaboration will receive Token rewards. When a collaborative user becomes a requesting user next time, the Token value he owns is the basis for whether his request can be responded to. In the method of the present invention, the functions undertaken by the smart contract are to select collaborative users, establish a private chain, record the transaction process and the t users who send requests, and allocate and deduct Token values.

[0178] To hide the real location of the user and protect the query content of the user, the requesting user must establish a private chain with the users who are willing to participate in the collaboration. Therefore, the requesting user must first send a collaboration request, a request location area and a reward Token value to the users in the permissioned blockchain. The requesting user selects collaborative users according to the collaborative anonymous area and ensures that the selected location can generalize his real location. The requesting user sends n - 1 groups of encrypted information parts to the private chain, and each user in the private chain has to send the ciphertext segment and his real location to the LBS server. When the number of collaborative users is large enough, each collaborative user must timely send the received encrypted information to the LBS server, otherwise he will not get the reward. Since only the first t collaborative users who send collaborative information included in the result set will get Token value rewards, this method can ensure that the service request of the requesting user can be timely responded to and assisted.

[0179] The LBS server encrypts the result set with the public key of the requesting user and publishes it on the private chain. All users on the private chain can obtain this result set. Only the requesting user has the corresponding private key to decrypt and extract the results it needs. Other collaborative users on the private chain do not have the decryption private key and cannot decrypt the result set, so they cannot obtain any information about the requesting user. Additionally, when the LBS server receives the locations of t identical query contents, it cannot determine the exact location of the requesting user.

[0180] During the process of the requesting user establishing a private chain with the collaborative users and generalizing and inducing locations with the collaborative users, the smart contract mainly performs two functions. One is to establish a temporary private chain. The initial user sends a request in the public permission chain, and then adds the collaborative users who meet the request to the private chain. The other is to check the result set and reward the first t collaborative users who successfully participate in the collaboration. This process can be described by Algorithm 1.

[0181]

[0182]

[0183] After establishing the temporary private chain, the information of the requesting user and the collaborative users will be recorded. Then the requesting user sends the encrypted information fragments to the collaborative users in the private chain. All collaborative users send the encrypted information fragments and their real locations to the LBS server. After the LBS server completes information verification, reconstruction, query, and encryption, it feeds back the result set to the temporary private chain. This process can be described by Algorithm 2.

[0184]

[0185]

[0186] The smart contract needs to help the requesting user extract the results from the set and reward the collaborative users. Algorithm 3 describes the process of extracting the results and rewarding the collaborative users.

[0187]

[0188] In Algorithm 3, the requesting user obtains the request result, and the collaborative user obtains the reward Token value. These information are recorded in the public permissioned blockchain and cannot be changed. During the process of sending the request and obtaining the result, the location of the requesting user is generalized by the location of the collaborative user. At the same time, the request content is encrypted and the decryption key is split, making it difficult for the collaborative user to obtain any information about the requesting user. In addition, taking the user's Token value as the basis for the priority response of the user's anonymous request, and only some collaborative users can obtain the reward Token value. This competition mechanism will stimulate the enthusiasm of collaborative users to participate, and can timely send the query part to the LBS server, ensuring that the requesting user can obtain the result within a short time.

[0189] Privacy protection effect analysis:

[0190] Information confidentiality: The requesting user encrypts the query request and splits the decryption key and sends it to n - 1 collaborative users. Since the collaborative users cannot restore the decryption key, they cannot obtain the specific query content, ensuring the confidentiality of the user's query content. The real location of the requesting user is directly sent to the LBS server by the requesting user, and the collaborative users cannot obtain the real location information of the requesting user either. When the LBS server can obtain the request information of at least t users, it can reconstruct the decryption key, obtain at least t real location information and accurate query requests, but cannot confirm which location information corresponds to the real user and cannot associate the query request with the real user. Therefore, the probability that the real location of the real requesting user is identified does not exceed 1 / t, ensuring the confidentiality of the real location information of the user. And the parameter t is set to t = (n - 1) / 3 according to the Byzantine fault tolerance mechanism, which can effectively prevent the collusion attack of malicious users and ensure that the user's privacy information will not be leaked. When the LBS server returns the query content, the query return result is encrypted with the public key of the requester, and the collaborative users do not have the decryption key, so the confidentiality of the information can also be ensured.

[0191] Information integrity: The method of the present invention uses the key splitting technology to generate the verification key, and uses the cryptographic key verification algorithm and the share combination algorithm to verify the validity of the ciphertext fragments sent by the collaborative users, ensuring the integrity and non-forgery of the information.

[0192] Key security: The query content of the requesting user is encrypted by asymmetric encryption, and the decryption key is split into n key shards using the Shamir(t,n) secret sharing scheme and distributed to n participants. None of the participants can obtain the specific key alone. Therefore, the decryption key is secure.

[0193] Eavesdropping attack: An eavesdropping attack refers to an attacker listening to the communication channels of both parties to obtain sensitive data that is not encrypted by both parties. In the method of the present invention, the query content of the requesting user and the query results returned by the LBS are both transmitted in an encrypted manner. Even if the attacker obtains the encrypted information through eavesdropping, the specific content cannot be obtained.

[0194] Replay attack: A replay attack refers to a malicious node deceiving the trust of the LBS server by republishing legitimate data packets in the original system. After receiving the request message, the LBS server first verifies whether the difference between the synchronized clock and the timestamp T included in the request information is within the permitted range. Only when the time difference is within the permitted range will the request information be processed. Therefore, it can resist replay attacks.

[0195] Computational complexity analysis: The method of the present invention involves secret sharing, information encryption and decryption, and digital signature operations. The digital signature operation is regarded as a special encryption and decryption operation, and the decryption operation is the inverse operation of the encryption operation. Therefore, O(Sha) is used to represent the computational complexity of key sharing, and O(Enc) is used to represent the computational complexity of encryption, decryption, and digital signature.

[0196] The secret sharing of the method of the present invention requires n public values, constructs t interpolation functions, and needs to solve t equations in the secret recovery stage. Then its computational complexity is O(n + t). Therefore, the computational complexity p1 of secret sharing is:

[0197] p1 = O(Sha) = O(n + t) = O(n) (25)

[0198] In the method of the present invention, before the requesting user sends an anonymous request, identity authentication needs to be performed. When the CA receives the user's request, it first uses its own private key sk CA to perform calculations to verify the correctness of the signature data The computational complexity required at this time is O(Enc). If the verification fails, the anonymous request ends. If the verification passes, a temporary key pair is generated for the user and encrypted and sent to the user. The user obtains the temporary key pair and encrypts the query content, and then broadcasts the encapsulated data packet to the temporary private chain. The time complexity p2 at this time is:

[0199] p2 = O(n - 1) + O(Enc) + O(Enc) + O(Enc) = O(Enc) (26)

[0200] When the collaborative user receives the data packet, the user sends his real location and the data packet to the LBS server together, and the computational complexity required by the collaborative user is O(1); when the LBS receives data packets sent by no less than t users, it starts the key reconstruction and recovery program, obtains the real query request, generates the query result and encrypts it for broadcasting to the private chain, and requests the user to decrypt the data on the private chain and obtain the query result. At this time, the required computational complexity p3 is:

[0201] p3 = O(t) + O(Enc) + O(Enc) + O(Enc) = O(Enc) (27)

[0202] In summary, the upper limit of the computational complexity of the method of the present invention is:

[0203] P = p1 + p2 + p3 = O(n) + O(Enc) + O(Enc) = O(Enc) (28)

[0204] Experimental evaluation

[0205] In this part, different privacy protection parameters are set to verify the performance of the method of the present invention to evaluate the performance of the method of the present invention.

[0206] Experiment and result analysis

[0207] In this part, different privacy protection parameters are set to verify the performance of the method proposed in this paper, including setting different numbers of collaborative users n, secret sharing threshold t, incentive Token value, and tolerance time threshold Δt, and evaluating the performance of the method of the present invention from two aspects of execution time and anonymity success rate. Comparison of execution time and anonymity success rate of different numbers of collaborative users

[0208] The execution time of the method of the present invention increases with the increase of the n value; as Figure 5As shown, the execution time starts from when the user makes a request and ends when the query result is received. The specific process includes: the user makes a collaboration request, an encryption request, splits and sends the request, the collaborating users send collaboration information, the LBS server recovers the key and decrypts it, verifies the request, conducts the query service and returns the service result, and the requesting user obtains the query result. When the value of n increases, more users need to participate in the collaboration, resulting in an increase in the time for selecting collaborating users. As can be seen from the figure, when the Token value remains unchanged, the larger the value of n, the longer the execution time. When the value of n remains unchanged, the larger the Token value, the shorter the execution time. Because when the Token incentive value increases, more users are more willing to participate in anonymous collaboration, so the time for user selection is shorter. When the number of collaborating users is set within a certain reasonable range, the execution time will increase, but the change will not be too large. Since the collaborating users determine whether to participate in the collaboration based on the Token value and its anonymous requirements proposed by the requesting user, and only by comparing whether the relevant thresholds are met, the computational complexity is not high.

[0209] The anonymous success rate of the method of the present invention decreases as the value of n increases, but there will be no obvious change within a certain range (such as n < 18); as Figure 6 As shown, anonymous success means that no less than n - 1 collaborating users participate in the anonymity, so that the real information of the user cannot be identified. When the value of n increases, it means that the number of collaborating users required by the requesting user to participate in the anonymity increases, and it also further improves the privacy protection effect. At this time, more collaborating users need to respond to the anonymity request and participate in the anonymous collaboration. The increase in the value of n makes the anonymity requirement further improve, which to a certain extent increases the difficulty of selecting collaborating users who meet the conditions, thus affecting the anonymous success rate. As can be seen from the figure, when the incentive Token = 40, the anonymous success rate is 100%. When Token ≤ 20 and n ≥ 18, the anonymous success rate will slightly decrease. In the experiment, the response threshold of each collaborating user is randomly set. When the Token value and its anonymous requirements of the user cannot both meet the conditions of the collaborating users, it may lead to anonymous failure. Therefore, when the value of n increases, it will affect the anonymous success rate to a certain extent. This also further illustrates the important role of setting the incentive parameter Token and constructing the incentive mechanism for the privacy protection model.

[0210] Comparison of the execution time and anonymous success rate for different threshold values t:

[0211] The execution time of the method of the present invention increases as the threshold value t of the threshold increases, as Figure 7As shown, the threshold value t represents the minimum number of key fragments required for key recovery using the Shamir secret sharing method. The more fragments are needed, the more users are required to successfully send collaboration requests. The longer the LBS server waits for collaborative users to send collaboration requests, the longer the execution time. It can be seen from the figure that as the threshold value t increases, the execution time also increases. However, when the threshold value t remains unchanged, the execution time increases as the number n of anonymous collaborative users increases, indicating that the proportion of the execution time in the collaborative user response and selection phase is higher than that in the request sending phase. This further demonstrates the effectiveness of the Token incentive mechanism. When collaborative users are willing to participate in anonymous collaboration, in order to obtain a certain number of Token values, they will send collaboration requests in a timely manner. When the value of n is larger, the degree of change in the execution time with respect to the threshold value t is slower.

[0212] The anonymity success rate of the method of the present invention does not change significantly as the threshold value t increases, as Figure 8 shown. The larger the threshold value, the more key fragments are required to recover the decryption key, which will affect the anonymity success rate. When the Token value of the requesting user meets the incentive threshold of the collaborative user, the collaborative user will construct a private chain. As long as the number of participating collaborative users is not less than n, this collaborative anonymity will succeed. It can be seen from the figure that when the threshold value t remains unchanged, the larger the value of n, the higher the anonymity success rate. When n ≥ 20, the anonymity success rate is 100%.

[0213] Comparison of execution time and anonymity success rate for different Token values:

[0214] The execution time of the method of the present invention decreases as the Token value increases; as Figure 9 shown, the Token value is an important incentive mechanism to encourage collaborative users to participate in collaborative anonymity. The larger the Token value the requesting user has, the more likely his anonymous collaboration request will be responded to first. The larger the Token value proposed when sending an anonymous request, the greater the reward the collaborative user will obtain after the anonymous collaboration is successful. Therefore, the participating collaborative users are more willing to participate in collaboration and can send collaborative information in a timely manner to obtain more Token values, which will reduce the execution time. It can be seen from the figure that when Token ≥ 60 and the values of the number n of collaborative users are 10 and 25, the change in the execution time is not significant, because when the Token exceeds the threshold set by most collaborative users, many users are willing to participate in collaboration to obtain a greater reward.

[0215] The anonymity success rate of the method of the present invention increases as the Token value increases, as Figure 10As shown, the larger the Token value the user has, the more likely his anonymous collaboration request will be responded to first, and the higher the anonymous success rate; the larger the Token value proposed when sending an anonymous request, the more collaborative users will be willing to participate in the anonymous collaboration, and the higher the anonymous success rate; it can be seen from the figure that when Token≥50, as long as the value of the number of collaborative users n is reasonable, more users will be willing to participate in the collaboration to obtain greater rewards, and the anonymous success rate is 100%.

[0216] Comparison of the anonymous success rates for different tolerance time thresholds:

[0217] The anonymous success rate of the method of the present invention increases as the tolerance time threshold Δt increases, as Figure 11 shown. During the anonymous process, a maximum tolerance time threshold Δt for anonymous collaboration is set. If the anonymous collaboration has not been completed when the execution time is greater than Δt, it means that this anonymous collaboration fails and the anonymous process will be terminated; the larger the value of the tolerance time threshold Δt, to a certain extent, the anonymous success rate will be improved, but it will not have a huge impact; because the willingness of collaborative users to participate in anonymous collaboration is affected by multiple conditions such as anonymous conditions and Token values. If the Token value does not meet the threshold set by the collaborative user, he will not participate in the collaborative anonymity, and unilaterally increasing the tolerance time will not increase the probability of anonymous success. It can be seen from the figure that when Δt≤0.75s and the set parameter n≥15, the anonymous success rate is less than 100%; when Δt≥1.25s, for the set parameter n, the anonymous success rate is 100%.

[0218] The anonymous success rate of the method of the present invention increases as the tolerance time threshold Δt increases, and is also affected by the threshold t, as Figure 12 shown. It can be seen from the figure that when the tolerance time threshold Δt is the same, increasing the threshold t will reduce the anonymous success rate to a certain extent; when Δt≥1.25s, for the set threshold t, the anonymous success rate is 100%. Because the threshold t represents the minimum number of key fragments required for key recovery using the Shamir secret sharing method. The more shares are required, the more users need to send collaboration requests. Therefore, the longer the LBS server waits for collaborative users to send collaboration requests. If the set tolerance time threshold Δt is unreasonable, the anonymous collaboration will fail.

[0219] Comparison of the execution time and anonymous success rate of different methods

[0220] Compare the execution time of the method of the present invention with that of other 3 methods, as Figure 13As shown, two of the methods (Solution 1 and Solution 2) protect privacy information through anonymous collaboration, and one method (Solution 3) protects privacy information through encryption. It can be seen from the figure that the execution times of the three collaborative anonymous methods, including the method of the present invention, increase with the increase of the n value, while the execution time of the encryption method does not change with the change of the n value, but the execution time is higher than that of the other three methods. When the n value increases, more users need to participate in collaboration, resulting in an increase in the time for selecting collaborative users. Therefore, the execution time of the collaborative anonymous method increases. The execution time of the method of the present invention is roughly equivalent to that of the other two collaborative anonymous methods. The encryption method protects privacy information through information encryption and has nothing to do with the number of collaborative users, but the execution time of the encryption method is relatively long.

[0221] In the method proposed by the present invention, the collaborative users determine whether to participate in collaboration based on the Token value and its anonymous requirements proposed by the requesting user. By simply comparing whether the relevant thresholds are met, the computational complexity is not high. Therefore, the number of collaborative users has little impact on the execution time. Moreover, only the request content of the user is encrypted after the collaborative users are selected, and the data volume is very small. The computational amounts of operations such as encryption, key splitting, and decryption are small. Therefore, compared with the other two collaborative anonymous methods, its execution time will not increase significantly. The encryption method protects its security by encrypting all sensitive information, and the encrypted data volume is relatively large. Therefore, the execution time is relatively long. It can be seen from the figure that the execution time of the method of the present invention is lower than that of the privacy protection method of simple encryption and slightly higher than that of the other two collaborative anonymous methods. With the continuous improvement of the computing performance of hardware devices, the encryption and decryption operations of the method of the present invention are completed by high-performance hardware devices, and the execution efficiency will be greatly improved, and the impact on anonymous users will be smaller than that of traditional privacy protection methods.

[0222] Compare the anonymous success rates of the method of the present invention and the other three methods, as Figure 14 shown. It can be seen from the figure that the anonymous success rates of the two collaborative anonymous methods being compared decrease significantly with the increase of the n value. The anonymous success rate of the method of the present invention decreases slightly with the increase of the n value, and the anonymous success rate of the encryption method does not change with the change of the n value. For the method of the present invention and the other two anonymous collaborative methods, when the n value increases, it means that the number of users that the requesting user needs to participate in anonymity increases. At this time, more collaborative users are required to respond to the anonymous request, which to a certain extent increases the difficulty of selecting collaborative users that meet the conditions. Therefore, it has an impact on the anonymous success rate.

[0223] As can be seen from the figure, the anonymous success rate of the method of the present invention is higher than that of the other two anonymous collaboration methods. Because the present invention introduces a Token value incentive mechanism, more users are willing to participate in anonymous collaboration, and through the competition mechanism, they can send anonymous collaboration requests in a timely manner, further improving the anonymous success rate. However, the anonymous success rate of the method of the present invention is slightly lower than that of the encryption method. Because when the Token value owned by the requester is small, the anonymous request will fail; when the Token value of the incentive published by the requester is small, or the number of collaborating users participating in the response is small, the anonymity will fail. As can be seen from the figure, the larger the n value, the greater the possibility of anonymous collaboration failure of the other two methods; but by constructing an incentive mechanism, the anonymous success rate of the method of the present invention is much higher than that of the other two anonymous collaboration methods and slightly lower than that of the encrypted privacy protection method.

[0224] Taking the ideal embodiments of the present invention described above as an inspiration, through the above description, relevant staff can completely make various changes and modifications without departing from the technical idea of the present invention. The technical scope of the present invention is not limited to the content in the specification, and its technical scope must be determined according to the scope of the claims.

Claims

1. A location privacy protection method based on blockchain and threshold cryptography mechanism, characterized in that, It includes the following steps: Step 1: Obtain the query content of the requesting user; Step 2: Use the Shamir(n,t) and threshold encryption mechanism to encrypt the query content of the requesting user, split the decryption key into fragments, distribute the key fragments and the request ciphertext to the collaborative users together, and then send them to the LBS server. The real location and real query content of the requesting user are hidden through the collaborative users; Step 3: The LBS server uses the Lagrange polynomial interpolation algorithm to recover the decryption key and obtain the location information of the requesting user and the collaborative users; Step 4: Use the token incentive mechanism to take the Token value as the basis for preferentially responding to the service request of the requesting user, and the collaborative users perform anonymous collaboration on the requesting user.

2. The location privacy protection method based on blockchain and threshold cryptography mechanism according to claim 1, wherein Anonymous collaboration includes: All users register with the CA to obtain a key pair of public key and private key, and construct a public permission chain through the public key; The requesting user makes an anonymous request, and the smart contract makes a judgment on the anonymous request according to the Token value; The requesting user whose request is responded makes a collaboration request in the public permission chain and constructs a temporary private chain by using the collaborative users; The requesting user encrypts and splits the query request and the key, and sends the split fragments to the collaborative users on the private chain respectively. The requesting user sends the real location and split information to the LBS server; the collaborative users send the real location and split information to the LBS server. The first t collaborative request users obtain Token incentives; After the LBS server receives at least t encrypted messages, it reconstructs the decryption key, decrypts, verifies, obtains the query request, and generates a query result; The LBS server encrypts the query result with the recovered key and sends it to the temporary private chain. The requesting user obtains the return result from the private chain and decrypts it; the smart contract executes the Token value distribution and gives Token value rewards to the first t collaborative request users.

3. The location privacy protection method based on blockchain and threshold cryptography mechanism according to claim 2, wherein, The requesting user's registration with the CA includes: Select a random number r as the temporary encryption key, and use r and the user identity ID u as the CA public key pk CA to generate the application ciphertext after encryption, and then send it to the CA, Encrypt(ID u , r, pk CA ) → E(ID u ||r); CA decrypts using the private key to obtain the plaintext ID of the user information u and the temporary key r, Decrypt(E(ID u ||r), sk CA ) → (ID u , r); Using security parameter λ, private key sk CA , user identifier ID u Generate a key pair (pk u , sk u ) for the user, KeyGen(λ, sk CA , ID u ) → (pk u , sk u ); Encrypt the key pair (pk u , sk u ) using r to generate the ciphertext of the user's key pair Encrypt(pk u , sk u , r) → E(pk u , sk u ); The user decrypts the ciphertext using r and the user key to obtain the key pair Decrypt(E(pk u ,sk u ),r)→(pk u ,sk u ).

4. The location privacy protection method based on blockchain and threshold cryptography mechanism according to claim 2, characterized in that When the requesting user makes an anonymous request, it is necessary to authenticate the user identity to the CA.

5. The location privacy protection method based on blockchain and threshold cryptography mechanism according to claim 4, wherein, User identity authentication includes: Use the private key sk u for the public key pk u to generate a digital signature, obtaining The public key pk u , is encrypted using the CA public key PK CA to generate an authentication request message and sent to the CA; the CA private key SK CA decrypts the user request message and performs verification.

6. The location privacy protection method based on blockchain and threshold cryptography mechanism according to claim 2, wherein Anonymous requests include: Request the user to submit an anonymous request q, and the smart contract detects the Token value w rewarded by q u , and add w u to the Token list of the currently requesting user; If the requesting user is among the first t, allow the requesting user to publish a collaboration request through the public permission chain; otherwise, the requesting user waits until the Token value is among the first t.

7. The location privacy protection method based on blockchain and threshold cryptography mechanism according to claim 6, wherein, The request content includes the number n of collaborative users required, the number t of users who obtain incentive points, the anonymous area threshold R, and the Token value w of the reward.

8. The location privacy protection method based on blockchain and threshold cryptography mechanism according to claim 6, characterized in that, Use the Byzantine fault tolerance mechanism to set n = 3t + 1.

9. A location privacy protection system based on blockchain and threshold cryptography mechanism, characterized in that, It includes: A memory for storing instructions executable by a processor; A processor for executing instructions to implement the location privacy protection method based on blockchain and threshold cryptography mechanism as described in any one of claims 1-8.

10. A computer-readable medium storing computer program code, characterized in that, The computer program code implements the location privacy protection method based on blockchain and threshold cryptography mechanism as described in any one of claims 1-8 when executed by the processor.