Certificate-based Internet of Things lightweight authentication searchable encryption method and system, and medium

Through the lightweight authentication searchable encryption method based on certificates, the contradiction between device authentication and data security retrieval in the Internet of Things is solved, efficient and secure end-to-end authentication and data retrieval is achieved, adapting to the distributed deployment needs of IoT devices, and optimizing the computing overhead of encryption algorithms.

CN120455130APending Publication Date: 2025-08-08SOUTH CHINA AGRICULTURAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510748827.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

In the IoT scenario, the contradiction between device identity legitimacy verification, encrypted data security retrieval and resource overhead, traditional searchable encryption technology is difficult to adapt to the needs of distributed deployment of IoT devices, dynamic identity authentication and fine-grained access control, and there are key hosting and distribution problems.

Method used

The lightweight certificate-based authentication searchable encryption method is adopted to generate and match ciphertext and trap doors through certificates, system parameters and public keys issued by the certificate authority, avoid key hosting, simplify certificate management, and realize end-to-end authentication and efficient retrieval.

Benefits of technology

It realizes efficient and secure end-to-end authentication and data retrieval on IoT devices, resists keyword guessing attacks, optimizes encryption methods, reduces computing overhead, supports multi-CA cross-domain authentication, and adapts to large-scale heterogeneous network deployment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455130A_ABST
    Figure CN120455130A_ABST
Patent Text Reader

Abstract

The invention discloses a certificate-based internet of things lightweight authentication searchable encryption method and system and a medium, and the method comprises the steps: receiving a ciphertext sent by a sender device and a trap door sent by a receiver device, the ciphertext is generated by encrypting a to-be-encrypted keyword by the sender equipment according to a certificate issued by a certificate issuing mechanism, system parameters, a private key of a sender, a public key of the sender and a public key of a receiver; the trap door is generated by receiver equipment according to a certificate issued by a certificate issuing mechanism, system parameters, a private key of a receiver, a public key of a sender and a keyword to be queried; and according to the system parameters, the public key of the sender and the public key of the receiver, performing matching operation on the ciphertext and the trap door, and returning a matching result to the receiver equipment. According to the method, the contradiction among equipment identity legality verification, encrypted data security retrieval and resource overhead in an Internet of Things scene can be solved, and the unification of end-to-end authentication, lightweight encryption and efficient retrieval is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a certificate-based lightweight authentication searchable encryption method, system and medium for the Internet of Things, and belongs to the field of information security. Background Art

[0002] In IoT scenarios, the demand for data sharing and retrieval across massive numbers of devices is growing. For example, industrial sensors must submit encrypted logs to the cloud for subsequent audits. Alternatively, a large number of IoT sensors (such as temperature and humidity sensors, air quality monitors, etc.) are deployed in a smart city's environmental monitoring network to collect real-time environmental data and upload it to a cloud server. City management departments need to query encrypted data for specific areas or time periods on demand, while ensuring the legitimacy of device identities, secure communications, and protected data privacy. While traditional searchable encryption technologies can enable ciphertext retrieval, they generally rely on centralized key management architectures, making them difficult to adapt to the distributed deployment, dynamic identity authentication, and fine-grained access control requirements of IoT devices. Furthermore, the resource-constrained nature of IoT terminal devices requires that encrypted retrieval solutions achieve efficient search and strong security with low computational overhead.

[0003] In traditional public key cryptography, both the sender and the receiver possess a pair of public and private keys. Since the key is not linked to the user's identity, a trusted public key infrastructure (PKI) must be used to guarantee the relationship between the public key and the identity through digital certificates. However, the requirement for PKI certificates has always been a major obstacle to the deployment of traditional public key cryptography systems. However, since the entropy value of the keyword space is too small, computers can generate all keyword ciphertexts by exhaustive enumeration to guess the keywords contained in the trapdoor. This method is also called keyword guessing attack (KGA) and has relatively cumbersome certificate management issues, such as Figure 1 shown.

[0004] To eliminate the burden of cumbersome certificate management, identity-based encryption (IBE) was proposed. The advantage of IBE is that it eliminates the need for PKI certificates, as anyone can use their personal identity as their public key. However, this encryption mechanism inherently presents the key escrow problem, as a fully trusted private key generator is used to issue private keys to every user in the system. Furthermore, private keys must be delivered to users via a secure channel, which leads to the private key distribution problem.

[0005] To address the key escrow problem, the concept of certificateless public key cryptography was proposed. In a certificateless public key cryptography system, each user combines a portion of a private key issued by a key generation center with a secret value of their choice to generate their private key. This prevents the key generation center from knowing the user's private key, thus avoiding the key escrow problem. However, the key generation center must secretly distribute the portion of the private key to the user, which presents a key distribution problem with certificateless public key cryptography, leading to the requirement for a secure channel.

[0006] In certificateless searchable encryption, a key generation center may escrow a user's private key, posing a security risk. In certificate-based searchable encryption, however, users generate their own private keys and keep them confidential. Certificate authorities are solely responsible for issuing certificates and do not escrow their private keys, effectively avoiding key escrow issues. Like traditional public-key encryption, certificate-based searchable encryption (CBEKS) uses certificates to bind a user's identity to their public key. However, it offers an interesting implicit authentication feature: the certificate must be used as part of the decryption (or signing) key. This means that only the user's certificate and private key can be used to perform decryption (or signing) operations. Furthermore, others do not need to be aware of the user's certificate status. Therefore, certificate-based encryption eliminates the need to handle third-party inquiries about certificate status, significantly simplifying certificate management. Furthermore, certificate-based encryption eliminates key escrow and distribution issues. Thanks to these favorable properties of certificate-based encryption, CBEKS offers significant advantages over previous searchable public-key encryption methods.

[0007] Certificate-based authenticated encryption is an important research direction in the field of cryptography, but its application in the Internet of Things environment still faces many problems. For example, it is difficult to strike a balance between security and efficiency in lightweight devices. Summary of the Invention

[0008] In view of this, the present invention provides a certificate-based lightweight authentication and searchable encryption method, device, system, computer equipment and storage medium for the Internet of Things, which is safe and efficient, and can solve the contradiction between device identity legitimacy verification, encrypted data security retrieval and resource overhead in the Internet of Things scenario, and realize the unification of end-to-end authentication, lightweight encryption and efficient retrieval.

[0009] The first object of the present invention is to provide a certificate-based lightweight authentication and searchable encryption method for the Internet of Things.

[0010] The second object of the present invention is to provide a certificate-based lightweight authentication and searchable encryption device for the Internet of Things.

[0011] The third object of the present invention is to provide a certificate-based lightweight authentication and searchable encryption system for the Internet of Things.

[0012] A fourth object of the present invention is to provide a computer device.

[0013] A fifth object of the present invention is to provide a computer-readable storage medium.

[0014] The first object of the present invention is achieved by adopting the following technical solutions:

[0015] A certificate-based lightweight authentication and searchable encryption method for the Internet of Things, the method comprising:

[0016] Receiving a ciphertext sent by a sending device and a trapdoor sent by a receiving device, wherein the ciphertext is generated by the sending device by encrypting a keyword to be encrypted based on a certificate issued by a certificate authority, system parameters, a private key of the sender, a public key of the sender, and a public key of the receiver; and the trapdoor is generated by the receiving device based on the certificate issued by the certificate authority, system parameters, a private key of the receiver, a public key of the sender, and the keyword to be queried;

[0017] Based on the system parameters, the sender's public key and the receiver's public key, the ciphertext and the trapdoor are matched, and the matching result is returned to the receiver's device.

[0018] Furthermore, the certificate generation process is as follows:

[0019] Select a random number r and calculate the certificate using the master private key and the user's ID as follows:

[0020]

[0021] Among them, Cert U For the certificate issued to the user, msk is the primary private key, PV R and It constitutes the public key of the recipient, and P is the generator of the cyclic group in the system parameters.

[0022] Furthermore, the ciphertext generation process includes:

[0023] Based on the certificate issued by the certification authority, system parameters, the sender's private key, and the receiver's public key, the values of the shared keys K1 and K2 are calculated as follows:

[0024]

[0025] Among them, SV S is the sender's private key, ID R The ID of the recipient, PV R is the public key of the recipient, is part of the recipient's public key, h1 is the first hash function in the system parameters, Cert S The certificate issued by the certificate authority to the sender;

[0026] Select a random number t, and calculate the first part C1 and the second part C2 of the ciphertext based on the system parameters, the sender's public key, the receiver's public key, and the key to be encrypted, combined with the values of K1 and K2, as follows:

[0027] C1=t

[0028] C2=H(A,PK S ,PK R )

[0029] Where A=h3(t,K), K=h2(w,K1,K2), h3 is the third hash function in the system parameters, is the sender’s public key, is the public key of the recipient, and w is the keyword to be encrypted.

[0030] Furthermore, the trapdoor generation process includes:

[0031] Calculate the shared key K based on the certificate issued by the certificate authority, system parameters, the receiver's private key and the sender's public key 1′ and K 2′ The value is as follows:

[0032]

[0033] Among them, SV R is the recipient's private key, ID R The ID of the recipient, PV S and The public key of the sender is composed, h1 is the first hash function in the system parameters, Cert R The certificate issued by the certificate authority to the recipient;

[0034] According to the query keyword, combined with K 1′ and K 2′ The value of , generates a trapdoor, as follows:

[0035] T w =h2(w′,K 1′ ,K 2′ )

[0036] Among them, T w is a trapdoor, h2 is the second hash function in the system parameters, and w′ is the keyword to be queried.

[0037] Furthermore, the matching operation between the ciphertext and the trapdoor is performed based on the system parameters, the sender's public key, and the receiver's public key, and the matching result is returned to the receiver's device, specifically including:

[0038] According to the system parameters, ciphertext and trapdoor, the value of B is calculated as follows:

[0039] B=h3(C1,T w )

[0040] Among them, h3 is the third hash function in the system parameters, T w is the trapdoor, C1 is the first part of the ciphertext;

[0041] According to the system parameters, the sender's public key and the receiver's public key, combined with the value of B, calculate the C to be matched 2′ , as follows:

[0042] C 2′ =H(B,PK S ,PK R )

[0043] Among them, H is the fourth hash function in the system parameters, PK S is the sender's public key, PK R is the public key of the recipient;

[0044] If C 2′ If the value is equal to the second part C2 of the ciphertext, 1 is returned to the receiving device; otherwise, 0 is returned to the receiving device.

[0045] The second object of the present invention is achieved by adopting the following technical solutions:

[0046] A certificate-based lightweight authentication and searchable encryption device for the Internet of Things, comprising:

[0047] a receiving module, configured to receive a ciphertext sent by a sending device and a trapdoor sent by a receiving device, wherein the ciphertext is generated by the sending device by encrypting a keyword to be encrypted based on a certificate issued by a certificate authority, system parameters, a private key of the sender, a public key of the sender, and a public key of the receiver; and the trapdoor is generated by the receiving device by the receiving device based on a certificate issued by a certificate authority, system parameters, a private key of the receiver, a public key of the receiver, a public key of the sender, and the keyword to be queried;

[0048] The matching query module is used to match the ciphertext and the trapdoor according to the system parameters, the sender's public key and the receiver's public key, and return the matching result to the receiver's device.

[0049] The third object of the present invention is achieved by adopting the following technical solutions:

[0050] A certificate-based lightweight authentication and searchable encryption system for the Internet of Things, comprising a certificate authority, a sender device, a receiver device, and a cloud server, wherein the certificate authority is connected to the sender device and the receiver device, respectively, and the sender device and the receiver device are connected to the cloud server, respectively;

[0051] The certificate issuing authority is used to generate a certificate based on the master private key and the user's ID after obtaining the user ID applying for authentication;

[0052] The sender device is used to apply for a certificate from a certificate authority, and after obtaining the certificate issued by the certificate authority, encrypt the keyword to be encrypted according to the certificate, system parameters, the sender's private key, the sender's public key, and the receiver's public key to obtain a ciphertext;

[0053] The receiving device is used to apply for a certificate from a certificate authority, and after obtaining the certificate issued by the certificate authority, generate a trapdoor based on the certificate, system parameters, the private key of the recipient, the public key of the recipient, the public key of the sender, and the keyword to be queried;

[0054] The cloud server is used to receive the ciphertext sent by the sending device and the trapdoor sent by the receiving device, match the ciphertext and the trapdoor according to the system parameters, the sender's public key and the receiver's public key, and return the matching result to the receiving device.

[0055] The fourth object of the present invention is achieved by adopting the following technical solutions:

[0056] A computer device includes a processor and a memory for storing a program executable by the processor. When the processor executes the program stored in the memory, the above-mentioned lightweight authentication searchable encryption method for the Internet of Things is implemented.

[0057] The fifth object of the present invention is achieved by adopting the following technical solutions:

[0058] A computer-readable storage medium stores a program, which, when executed by a processor, implements the aforementioned lightweight authentication and searchable encryption method for the Internet of Things.

[0059] The present invention has the following beneficial effects compared to the prior art:

[0060] 1. The present invention can achieve indistinguishability of multiple ciphertexts during retrieval, with higher security and enhanced privacy protection, ensuring that the server cannot determine whether two ciphertexts contain the same keywords or data, or how many identical keywords there are in a ciphertext, and can resist keyword guessing attacks.

[0061] 2. The present invention optimizes the encryption method and replaces the elliptic curve bilinear pairing operation. Lightweight IoT devices can also easily execute the encryption algorithm, thereby greatly reducing the encryption and retrieval costs in the system.

[0062] 3. The present invention has high scalability, supports multi-CA cross-domain authentication, and adapts to the deployment requirements of large-scale heterogeneous networks of the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying any creative work.

[0064] Figure 1 Schematic diagram illustrating existing keyword guessing attacks.

[0065] Figure 2 This is a structural block diagram of a certificate-based lightweight authentication and searchable encryption system for the Internet of Things according to Example 1 of the present invention.

[0066] Figure 3 This is a flowchart of a certificate-based lightweight authentication and searchable encryption method for the Internet of Things according to embodiment 1 of the present invention.

[0067] Figure 4 This is a structural block diagram of a certificate-based lightweight authentication and searchable encryption device for the Internet of Things according to embodiment 2 of the present invention.

[0068] Figure 5 This is a structural block diagram of a computer device according to embodiment 3 of the present invention. DETAILED DESCRIPTION

[0069] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0070] Example 1:

[0071] like Figure 2As shown, this embodiment provides a certificate-based lightweight authentication searchable encryption system for the Internet of Things, which includes a certificate authority (CA), a sender device, a receiver device and a cloud server. The certificate authority is connected to the sender device and the receiver device respectively, and the sender device and the receiver device are connected to the cloud server respectively. The system can be applied to intelligent environmental detection in the Internet of Things scenario. In the environmental monitoring network of a smart city, a large number of Internet of Things sensors (such as temperature and humidity sensors, air quality detectors, etc.) are deployed to collect environmental data in real time and upload it to the cloud server. The city data management department needs to query the encrypted data of a specific area or time period on demand, while ensuring that the device identity is legal, the communication process is secure and the data privacy is protected.

[0072] In the environmental monitoring network, after the sender uses the terminal device of the Internet of Things to collect environmental data, it uses the unique identifier of the terminal device (such as MAC address) as the sender ID to apply for a certificate from the certificate authority, and then generates a ciphertext for the encryption keyword (such as time = 2025-03-01, location = Tianhe District), and uploads it to the cloud or edge gateway together with the encrypted data. Because of encryption, there is no need to worry about data leakage during transmission or dishonest behavior of the server. The device used by the sender is the sender device; and the terminal device of the urban management department (such as the monitoring center server, the administrator's mobile phone APP) is the receiver, and the query party uses the user's unique identity as the receiver ID to send a ciphertext to the cloud or edge gateway. The certificate authority applies for a certificate, uses the certificate and private key to generate a corresponding trapdoor for the query keyword, and then sends it to the cloud server, where the device used by the recipient is the recipient device; the cloud server matches the ciphertext with the trapdoor and returns the matching encrypted data. The querying party finally decrypts the data for analysis. In this scenario, the IoT device, as the sender, is responsible for encryption and authentication, and the cloud server provides secure storage and retrieval services. The querying party, as the receiver, achieves privacy-protected data access through certificates and trapdoors. By balancing the resource limitations and security requirements of IoT devices, end-to-end trusted and searchable encryption is ensured. The introduction of a certificate mechanism is more secure and efficient, and can be widely used with confidence in practical applications.

[0073] The specific implementation process of the IoT lightweight authentication and searchable encryption system of this embodiment is as follows:

[0074] (1) Certificate Generation

[0075] After obtaining the user ID of the applicant for authentication, the certificate authority generates a certificate based on the master private key and the user's ID, and then returns the certificate to the user who applied for authorization. The user without the certificate will not be able to generate the corresponding ciphertext and trapdoor, and at the same time generates a partial public key R ID Sent to a user, where the user is the sender or receiver.

[0076] Furthermore, a random number r is selected and the certificate is calculated using the master private key and the user's ID as follows:

[0077]

[0078] Among them, Cert U For the certificate issued to the user, msk is the primary private key, PV U and Consists of the user's public key PK U ,Right now It is calculated and generated by the user's private key. P is the generator of the cyclic group in the system parameters. The system parameters = (q, G, P, P1, h1, h2, h3, H), where G is the cyclic group; q is the prime order of the cyclic group G, and its value is large enough to ensure that the group size is sufficient to resist brute force attacks; P is the generator of the cyclic group, h1, h2, h3 and H are all hash functions, and the outputs of all hash functions are limited to the output domain to ensure compatibility with group operations. In this embodiment, h1, h2, h3 and H are respectively recorded as the first hash function, the second hash function, the third hash function and the fourth hash function.

[0079] (2) Keyword encryption

[0080] The sender uses the sender's device to apply for a certificate from the certificate authority. After obtaining the certificate issued by the certificate authority, the sender encrypts the keyword to be encrypted based on the certificate, system parameters, the sender's private key, the sender's public key, and the receiver's public key to obtain the ciphertext, as follows:

[0081] Based on the certificate issued by the certification authority, system parameters, the sender's private key, and the receiver's public key, the values of the shared keys K1 and K2 are calculated as follows:

[0082]

[0083] Among them, SV S is the sender's private key, ID R The ID of the recipient, PV R and The public key of the recipient is formed, h1 is the first hash function in the system parameters, Cert S The certificate issued to the sender by the certification authority.

[0084] Select a random number t, and calculate the first part C1 and the second part C2 of the ciphertext based on the system parameters, the sender's public key, the receiver's public key, and the key to be encrypted, combined with the values of K1 and K2, as follows:

[0085] C1=t

[0086] C2=H(A,PK S,PK R )

[0087] Where A=h3(t,K), K=h2(w,K1,K2), h3 is the third hash function in the system parameters, is the sender’s public key, is the public key of the recipient, and w is the keyword to be encrypted.

[0088] (3) Trapdoor Generation

[0089] The receiver uses the receiver's device to apply for a certificate from the certificate authority. After obtaining the certificate issued by the certificate authority, the receiver generates a trapdoor based on the certificate, system parameters, the receiver's private key, the sender's public key, and the query keyword. The details are as follows:

[0090] Calculate the shared key K based on the certificate issued by the certificate authority, system parameters and the recipient's private key 1′ and K 2′ The value is as follows:

[0091]

[0092] Among them, SV R is the recipient's private key, ID R The ID of the recipient, PV S and The public key of the sender is composed, h1 is the first hash function in the system parameters, Cert R A certificate issued by a certification authority to a recipient.

[0093] According to the query keyword, combined with K 1′ and K 2′ The value of , generates a trapdoor, as follows:

[0094] T w =h2(w′,K 1′ ,K 2′ )

[0095] Among them, T w is a trapdoor, h2 is the second hash function in the system parameters, and w′ is the keyword to be queried.

[0096] (4) Keyword matching

[0097] The cloud server receives the ciphertext from the sender and the trapdoor from the receiver. Based on the system parameters, the sender's public key, and the receiver's public key, it matches the ciphertext and trapdoor, and returns the matching result to the receiver as follows:

[0098] According to the system parameters, ciphertext and trapdoor, the value of B is calculated as follows:

[0099] B=h3(C1,T w )

[0100] Among them, h3 is the third hash function in the system parameters, T w is the trapdoor, and C1 is the first part of the ciphertext.

[0101] According to the system parameters, the sender's public key and the receiver's public key, combined with the value of B, calculate the C to be matched 2′ , as follows:

[0102] C 2′ =H(B,PK S ,PK R )

[0103] Among them, H is the fourth hash function in the system parameters, PK S is the sender's public key, PK R The public key of the recipient.

[0104] If C 2′ If the value is equal to the second part C2 of the ciphertext, 1 is returned to the receiving device; otherwise, 0 is returned to the receiving device.

[0105] like Figure 3 As shown, this embodiment provides a certificate-based lightweight authentication and searchable encryption method for the Internet of Things. The method is mainly implemented through the above steps (2) to (4), with the cloud server as the execution subject, and is specifically described as follows:

[0106] S301. Receive the ciphertext sent by the sending device and the trapdoor sent by the receiving device, wherein the ciphertext is generated by the sending device by encrypting the keyword to be encrypted according to the certificate issued by the certificate authority, system parameters, the sender's private key, the sender's public key, and the receiver's public key; the trapdoor is generated by the receiving device according to the certificate issued by the certificate authority, system parameters, the receiver's private key, the sender's public key, and the keyword to be queried.

[0107] S302: Match the ciphertext and the trapdoor according to the system parameters, the sender's public key, and the receiver's public key, and return the matching result to the receiver's device.

[0108] It should be noted that although the method operations of the above embodiments are described in a particular order in the accompanying drawings, this does not require or imply that the operations must be performed in this particular order, or that all of the illustrated operations must be performed to achieve the desired results. Rather, the depicted steps may be performed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into a single step, and / or a single step may be broken down into multiple steps.

[0109] Example 2:

[0110] like Figure 4 As shown, this embodiment provides a certificate-based lightweight authentication and searchable encryption device for the Internet of Things, which includes a receiving module 401 and a matching query module 402. The specific functions of each module are as follows:

[0111] Receiving module 401, configured to receive a ciphertext sent by a sending device and a trapdoor sent by a receiving device, wherein the ciphertext is generated by the sending device by encrypting a keyword to be encrypted based on a certificate issued by a certificate authority, system parameters, the sender's private key, the sender's public key, and the receiver's public key; and the trapdoor is generated by the receiving device based on a certificate issued by a certificate authority, system parameters, the receiver's private key, the sender's public key, and the keyword to be queried;

[0112] The matching query module 402 is used to perform a matching operation on the ciphertext and the trapdoor according to the system parameters, the sender's public key and the receiver's public key, and return the matching result to the receiver's device.

[0113] It should be noted that the device provided in the above embodiment is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure can be divided into different functional modules to complete all or part of the functions described above.

[0114] Example 3:

[0115] This embodiment provides a computer device, such as Figure 5 As shown, a processor 502, a memory, an input device 503, a display device 504, and a network interface 505 are connected via a system bus 501. The processor is used to provide computing and control capabilities. The memory includes a non-volatile storage medium 506 and an internal memory 507. The non-volatile storage medium 506 stores an operating system, a computer program, and a database. The internal memory 507 provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. When the processor 502 executes the computer program stored in the memory, the authenticated multi-keyword searchable encryption method of the above-mentioned embodiment 1 is implemented as follows:

[0116] Receive the ciphertext sent by the sending device and the trapdoor sent by the receiving device, wherein the ciphertext is generated by the sending device by encrypting the to-be-encrypted keyword according to the certificate issued by the certificate authority, system parameters, the sender's private key, the sender's public key, and the receiver's public key; and the trapdoor is generated by the receiving device according to the certificate issued by the certificate authority, system parameters, the receiver's private key, the sender's public key, and the to-be-queried keyword; perform a matching operation on the ciphertext and the trapdoor according to the system parameters, the sender's public key, and the receiver's public key, and return the matching result to the receiving device.

[0117] Example 4:

[0118] This embodiment provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the authenticated multi-keyword searchable encryption method of the above-mentioned embodiment 1 is implemented as follows:

[0119] Receive the ciphertext sent by the sending device and the trapdoor sent by the receiving device, wherein the ciphertext is generated by the sending device by encrypting the to-be-encrypted keyword according to the certificate issued by the certificate authority, system parameters, the sender's private key, the sender's public key, and the receiver's public key; and the trapdoor is generated by the receiving device according to the certificate issued by the certificate authority, system parameters, the receiver's private key, the sender's public key, and the to-be-queried keyword; perform a matching operation on the ciphertext and the trapdoor according to the system parameters, the sender's public key, and the receiver's public key, and return the matching result to the receiving device.

[0120] The computer-readable storage medium of the present embodiment can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0121] In summary, the present invention is highly secure, fast, and efficient, and can be widely used in privacy-preserving communication scenarios between resource-constrained IoT devices and cloud servers.

[0122] The above is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes based on the technical solution and inventive concept of the present invention within the scope disclosed by the present invention, which falls within the scope of protection of the present invention.

Claims

1. A certificate-based lightweight authentication and searchable encryption method for the Internet of Things, characterized in that: The method comprises: Receiving a ciphertext sent by a sending device and a trapdoor sent by a receiving device, wherein the ciphertext is generated by the sending device by encrypting a keyword to be encrypted based on a certificate issued by a certificate authority, system parameters, a private key of the sender, a public key of the sender, and a public key of the receiver; and the trapdoor is generated by the receiving device based on the certificate issued by the certificate authority, system parameters, a private key of the receiver, a public key of the sender, and the keyword to be queried; Based on the system parameters, the sender's public key and the receiver's public key, the ciphertext and the trapdoor are matched, and the matching result is returned to the receiver's device.

2. The lightweight authentication searchable encryption method for the Internet of Things according to claim 1, characterized in that: The certificate is generated by a certificate issuing authority based on a master private key and the ID of a user applying for authentication after obtaining the ID of the user applying for authentication. The user is the sender or the receiver.

3. The lightweight authentication searchable encryption method for the Internet of Things according to claim 2, characterized in that: The certificate generation process is as follows: Select a random number r and calculate the certificate using the master private key and the user's ID as follows: Among them, Cert U For the certificate issued to the user, msk is the primary private key, PV U and It constitutes the user's public key, and P is the generator of the cyclic group in the system parameters.

4. The lightweight authentication searchable encryption method for the Internet of Things according to claim 1, characterized in that: The ciphertext generation process includes: Based on the certificate issued by the certification authority, system parameters, the sender's private key, and the receiver's public key, the values of the shared keys K1 and K2 are calculated as follows: Among them, SV S is the sender's private key, ID R The ID of the recipient, PV R and The public key of the recipient is formed, h1 is the first hash function in the system parameters, Cert S The certificate issued by the certificate authority to the sender; Select a random number t, and calculate the first part C1 and the second part C2 of the ciphertext based on the system parameters, the sender's public key, the receiver's public key, and the key to be encrypted, combined with the values of K1 and K2, as follows: C1=t C2=H(A,PK S ,PK R ) Where A=h3(t,K), K=h2(w,K1,K2), h3 is the third hash function in the system parameters, is the sender’s public key, is the public key of the recipient, and w is the keyword to be encrypted.

5. The lightweight authentication searchable encryption method for the Internet of Things according to claim 1, characterized in that: The trapdoor generation process includes: Calculate the shared key K based on the certificate issued by the certificate authority, system parameters, the receiver's private key and the sender's public key 1′ and K 2′ The value is as follows: Among them, SV R is the recipient's private key, ID R The ID of the recipient, PV S and The public key of the sender is composed, h1 is the first hash function in the system parameters, Cert R The certificate issued by the certificate authority to the recipient; According to the query keyword, combined with K 1′ and K 2′ The value of , generates a trapdoor, as follows: T w =h2(w′,K 1′ ,K 2′ ) Among them, T w is a trapdoor, h2 is the second hash function in the system parameters, and w′ is the keyword to be queried.

6. The Internet of Things lightweight authentication searchable encryption method according to claim 1, characterized in that: The matching operation between the ciphertext and the trapdoor is performed based on the system parameters, the sender's public key, and the receiver's public key, and the matching result is returned to the receiver's device, specifically including: According to the system parameters, ciphertext and trapdoor, the value of B is calculated as follows: B=h3(C1,T w ) Among them, h3 is the third hash function in the system parameters, T w is the trapdoor, C1 is the first part of the ciphertext; According to the system parameters, the sender's public key and the receiver's public key, combined with the value of B, calculate the C to be matched 2′ , as follows: C 2′ =H(B,PK S ,PK R ) Among them, H is the fourth hash function in the system parameters, PK S is the sender's public key, PK R is the public key of the recipient; If C 2′ If the value is equal to the second part C2 of the ciphertext, 1 is returned to the receiving device; otherwise, 0 is returned to the receiving device.

7. A certificate-based lightweight authentication and searchable encryption device for the Internet of Things, characterized in that: The device comprises: a receiving module, configured to receive a ciphertext sent by a sending device and a trapdoor sent by a receiving device, wherein the ciphertext is generated by the sending device by encrypting a keyword to be encrypted based on a certificate issued by a certificate authority, system parameters, a private key of the sender, a public key of the sender, and a public key of the receiver; and the trapdoor is generated by the receiving device based on a certificate issued by a certificate authority, system parameters, a private key of the receiver, a public key of the sender, and the keyword to be queried; The matching query module is used to match the ciphertext and the trapdoor according to the system parameters, the sender's public key and the receiver's public key, and return the matching result to the receiver's device.

8. A certificate-based lightweight authentication and searchable encryption system for the Internet of Things, characterized by: The system includes a certificate issuing authority, a sender device, a receiver device and a cloud server, wherein the certificate issuing authority is connected to the sender device and the receiver device respectively, and the sender device and the receiver device are respectively connected to the cloud server; The certificate issuing authority is used to generate a certificate based on the master private key and the user's ID after obtaining the user ID applying for authentication; The sender device is used to apply for a certificate from a certificate authority, and after obtaining the certificate issued by the certificate authority, encrypt the keyword to be encrypted according to the certificate, system parameters, the sender's private key, the sender's public key, and the receiver's public key to obtain a ciphertext; The receiving device is used to apply for a certificate from a certificate authority, and after obtaining the certificate issued by the certificate authority, generate a trapdoor based on the certificate, system parameters, the private key of the recipient, the public key of the recipient, the public key of the sender, and the keyword to be queried; The cloud server is used to receive the ciphertext sent by the sending device and the trapdoor sent by the receiving device, match the ciphertext and the trapdoor according to the system parameters, the sender's public key and the receiver's public key, and return the matching result to the receiving device.

9. A computer device, characterized in that: It comprises a processor and a memory for storing a program executable by the processor, and is characterized in that when the processor executes the program stored in the memory, it implements the public key authentication searchable encryption method described in any one of claims 1-6.

10. A computer-readable storage medium storing a program, characterized in that: When the program is executed by a processor, the public key authentication searchable encryption method according to any one of claims 1 to 6 is implemented.