Distributed space hiding protection method based on self-certification trust
Through the self-prove trust mechanism, the requester and potential collaborators verify historical trust credentials and build an anonymous area, solving the problems of single point failure and inaccurate trust assessment caused by relying on trustworthy parties in the existing technology, and achieving efficient and reliable location privacy protection.
Patent Information
- Application Number
- CN202510825841.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-08-08
AI Technical Summary
The prior art relies on trusted three parties when constructing anonymous areas, resulting in single point failure problems, and the trust model cannot accurately and efficiently evaluate the user's trust value, resulting in user location privacy leakage.
Through the self-prove trust mechanism, the requester and the potential collaborator verify each other's historical trust credentials, combine the interaction verification mechanism to determine whether the interaction is successful or invalid, and select a preset number of collaborators to build an anonymous area by verifying the target collaborator.
It realizes the trustworthy construction of anonymous areas among users, protects location privacy, prevents malicious users from sabotaging, avoids dependence on trusted three parties, and improves the accuracy and flexibility of trust evaluation.
Smart Images

Figure CN120455153A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to, but is not limited to, a distributed space anonymity protection method based on self-proven trust. Background Art
[0002] Location-based services (LBS) leverage user location information to provide users with various value-added services, such as relevant information push and lifestyle service searches. With the promotion of intelligent transportation and smart cities, LBS is widely used in various IoT systems.
[0003] In location-based services (LBS), users need to provide their location information to service providers in order to receive the corresponding services. During this process, service providers have the ability to obtain user location information, which can potentially leak and abuse this information, leading to location privacy breaches and concerns about LBS applications. To address this issue, researchers both domestically and internationally have proposed methods for protecting user location privacy, including fake locations, cryptographic encryption, differential privacy, and spatial anonymity. Among these location privacy protection methods, distributed spatial anonymity not only protects user location privacy but also enables users to control the dissemination of their location information. Users can independently decide whether to participate in the construction of anonymous zones and disseminate their location information. Therefore, distributed spatial anonymity has become one of the most commonly used methods for protecting location privacy.
[0004] However, not all users constructing anonymous regions are trustworthy. During the construction process, malicious users may provide false location information or leak other users' locations to third parties for profit. Existing research attempts to address the location information leakage caused by malicious users during anonymous region construction by establishing trust relationships between users, thereby enabling users to construct anonymous regions reliably. By introducing a trust model, these issues can be effectively addressed. However, current research still suffers from the following two problems: 1) Reliance on trusted third parties or existing infrastructure leads to single point failures and other issues. 2) Due to the mobility of LBS users, existing trust models cannot accurately and efficiently assess user trust values. Summary of the Invention
[0005] In view of this, an embodiment of the present invention provides a distributed space anonymity protection method based on self-proving trust, which aims to overcome the shortcomings of the existing technology and provide a distributed space anonymity protection method based on self-proving trust that is efficient and accurate in trust evaluation and does not rely on trusted third parties.
[0006] The technical solutions of the embodiments of the present invention are as follows: An embodiment of the present invention provides a distributed spatial anonymity protection method based on self-proven trust, comprising: The requester broadcasts a first request to construct an anonymous area; the potential collaborator who receives the first request and the requester verify each other's historical trust credentials and determine whether the interaction is successful or invalid based on a preset interactive verification mechanism; wherein the interactive verification mechanism comprehensively determines the result of the interaction based on the historical trust credential verification results and the verifier's own background knowledge of the other party's identity, and after the determination, the verifier generates a trust credential for the other party's interaction and sends it to the other party; the requester selects a preset number of verified target collaborators to construct an anonymous area.
[0007] In some embodiments of the present invention, the potential collaborator and the requester verify each other's historical trust credentials and determine whether the interaction is successful or invalid based on a preset interactive verification mechanism, including: after receiving the first request, the potential collaborator sends an identity identifier and a trust proof request to the requester; wherein the trust proof request carries a customized trust credential time threshold and a trust credential quantity threshold; the requester queries its own historical trust credentials based on the trust proof request and sends them to the potential collaborator; the potential collaborator verifies the requester's historical trust credentials: when the verification fails, the potential collaborator does not respond to the requester's first request; when the verification passes, the potential collaborator judges the interaction in combination with the interactive verification mechanism, and generates corresponding trust credentials based on different judgment results and sends them to the requester; when the requester confirms that there is no trust credential of failed interaction among the trust credentials sent by the potential collaborator, the interactive verification mechanism is used for judgment, and corresponding trust credentials are generated based on different judgment results and sent to the potential collaborator; otherwise, the interaction is terminated, and an unreliable trust credential is sent to the potential collaborator.
[0008] In some embodiments of the present invention, the requester queries its own historical trust credentials based on the trust proof request, including: the requester queries, based on the trust proof request, multiple historical trust credentials of no less than the trust credential quantity threshold within the trust credential time threshold when the requester acts as an interactive requester; the requester queries, based on the trust proof request, multiple historical trust credentials of the requester as an interactive collaboration party within the trust credential time threshold.
[0009] In some embodiments of the present invention, the potential collaborator verifies the historical trust credentials of the requester, including: the potential collaborator determines a first number of historical trust credentials of the requester as an interactive requesting party and a second number of historical trust credentials as an interactive collaborating party within the trust credential time threshold; determines that the current verification fails when at least one of the following conditions exists, and determines that the current verification passes when all of the following conditions do not hold: the first number is greater than the second number, the first number is lower than the trust credential number threshold, the trust value of the requester as an interactive collaborating party is lower than the average trust value of collaborators in the area, and the generation time of the historical trust credentials of the requester as an interactive requesting party is earlier than the trust credential time threshold.
[0010] In some embodiments of the present invention, when the verification is passed, the potential collaborator combines the interactive verification mechanism to judge the current interaction, and generates corresponding trust credentials based on different judgment results, including: if the result of the interactive verification mechanism is a successful interaction, the potential collaborator responds to the requester's first request, sends its own location information to the requester, and evaluates the requester's first request to generate a trust credential; if the result of the interactive verification mechanism is an invalid interaction, the potential collaborator does not generate a response to the requester and generates an invalid trust credential; if the result of the interactive verification mechanism is a failed interaction, the potential collaborator does not generate a response to the requester and generates a trust credential for failed interaction.
[0011] In some embodiments of the present invention, the requester uses the interactive verification mechanism to make a judgment, and generates corresponding trust credentials based on different judgment results and sends them to the potential collaborator, including: if the result of the interactive verification mechanism is a successful interaction, the requester evaluates the potential collaborator, generates a trust credential and sends it to the other party, and at the same time adds the potential collaborator as a target collaborator to the candidate set for constructing an anonymous area; if the result of the interactive verification mechanism is an invalid interaction, the requester does not respond to the potential collaborator's reply, and at the same time generates a trust credential for the invalid interaction and sends it to the potential collaborator; if the result of the interactive verification mechanism is a failed interaction, the requester does not respond to the potential collaborator's reply, and at the same time generates a trust credential for the failed interaction and sends it to the potential collaborator.
[0012] In some embodiments of the present invention, the format of the trust credential is as follows: ; Among them, CR represents the trust certificate, It is the identity tag of the trust credential owner, and its value is 0 or 1, indicating that the trust credential owner is the requester or the trust credential owner is the collaborator, respectively. and The unique identifiers of the trust credential generator and the trust credential owner respectively; is the evaluation value of the trust credential owner; Is the signature of the trust certificate generated by the trust certificate, The timestamp of the trust credential.
[0013] In some embodiments of the present invention, the trust value is calculated as follows: ; ; in, is the trust value of the trust credential owner, For the The evaluation value of the trust credential generator to the trust credential owner in the trust credential, The number of trust certificates owned by the trust certificate owner; is a consistency parameter, with a value of 0 or 1; is the time decay parameter, and its value is determined by OK, among them and The timestamps for the current timestamp and the timestamp generated by the trust credential, respectively. is the attenuation adjustment factor; It is a similarity parameter with a value range of 0 to 1, which represents the trust strategy of the user who is currently calculating the trust value towards the generator of the unfamiliar trust credential.
[0014] In some embodiments of the present invention, the interactive verification mechanism is specifically as follows: If the requester has: or for collaborators: The result of the interactive verification mechanism is that the interaction is successful; If the requester has: or for collaborators: Then the result of the interactive verification mechanism is invalid interaction; If the requesting user has: , or for collaborative users: , then the result of the interactive verification mechanism is failed interaction; in, is the trust evaluation threshold of the i-th collaborator, It is the trust value set of all collaborators in a certain anonymous region construction. is the trust evaluation value of the i-th collaborator, is the trust evaluation threshold of the requester, represents the trust evaluation threshold set of collaborators, Indicates the trust evaluation value of the requester, represents the requester's own knowledge, It is the requester's judgment of the collaborator based on his own knowledge. represents the self-knowledge of the i-th collaborator, It represents the judgment result of the i-th collaborator on the requester based on his own knowledge, and its value is Indicates that no abnormality is found, and the value is Indicates that an abnormality was found.
[0015] In some embodiments of the present invention, the requester selects a preset number of verified target collaborators to construct an anonymous area, including: The requester randomly selects k-1 target collaborators and constructs an anonymous region Gen(Loc0, Loc i …, Loc k-1 ), and sends the generated anonymous area information and its own service request to the service provider; where Loc0 is the location information of the requester; Loc i is the location information of the i-th target collaborator, i ranges from 1 to k-1; Gen(.) is a safe anonymous region constructor, k is the number of all users in the anonymous region.
[0016] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least: 1) This invention introduces a self-certifying trust mechanism, enabling the reliable construction of anonymous zones between users through the exchange of trust credentials between requesters and collaborators, thereby protecting their location privacy. The core of this approach is the use of trust credentials to bidirectionally authenticate requesters and collaborators, ensuring the trustworthiness of all parties involved in the construction of the anonymous zone. This approach protects privacy while preventing malicious or low-trust users from disrupting the system. By utilizing self-certifying trust technology, this invention eliminates the reliance on trusted parties in the anonymous zone construction process, thus avoiding single points of failure and other issues.
[0017] 2) By combining the consistency of trust evaluation, the time decay of trust value, and the similarity of trust evaluation, the present invention can accurately and efficiently evaluate the trust value of users, thereby improving the reliability of trust evaluation.
[0018] 3) In the process of building an anonymous zone, the trust credential time and quantity thresholds are set, so that the requester of anonymous zone construction can customize the conditions of collaborators and select collaborators more flexibly. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive work, among which: Figure 1 A flowchart of a distributed spatial anonymity protection method based on self-proven trust provided by an embodiment of the present invention; Figure 2 A schematic diagram of a system model of a distributed spatial anonymity protection method based on self-proven trust provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0020] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0021] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0022] It should be pointed out that the terms "first\second\third" involved in the embodiments of the present invention are only used to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present invention described here can be implemented in an order other than that illustrated or described here.
[0023] Those skilled in the art will understand that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by those skilled in the art in the art to which the embodiments of the present invention pertain. It should also be understood that terms such as those defined in common dictionaries should be understood to have meanings consistent with their meanings in the context of the prior art and, unless specifically defined as herein, should not be interpreted in an idealized or overly formal sense.
[0024] Figure 1 A flow chart of a distributed space anonymity protection method based on self-proven trust provided by an embodiment of the present invention is shown as follows: Figure 1 As shown, the method comprises at least the following steps: Step S110 : The requester broadcasts a first request for constructing an anonymous area.
[0025] Here, the first request is used to announce the user's intention to construct an anonymous region to potential collaborators in the surrounding area, so as to recruit collaborators with corresponding conditions and willingness to participate in the subsequent anonymous region construction process. The request information will be received by other users within a certain range.
[0026] In step S120 , the potential collaborator who receives the first request and the requester verify each other's historical trust credentials and determine whether the interaction is successful or invalid according to a preset interaction verification mechanism.
[0027] Here, the interactive verification mechanism combines historical trust credential verification results with the verifier's own background knowledge of the other party's identity to comprehensively determine the results of the current interaction. After the determination, the verifier generates a trust credential for the other party's current interaction and sends it to the other party. If the verifier is the requester, the other party is a potential collaborator. If the verifier is a potential collaborator, the other party is the requester.
[0028] The trust credential is a specific data structure used to verify and evaluate the user's credibility in a distributed system. It usually contains fields such as the identity of the trust credential owner / generator, the evaluation value of the trust credential owner, and the timestamp of the trust credential generation.
[0029] The two-way authentication between potential collaborators and requesters is as follows: After receiving a request from a requester to construct an anonymous region, a potential collaborator must first identify itself to the requester and request their trust credentials. This allows the requester to assess their credibility and decide whether to respond to their initial request to construct an anonymous region. Upon receiving the trust proof request from the potential collaborator, the requester retrieves its historical trust credentials and sends them to the potential collaborator for verification. After verifying the requester's information, the potential collaborator generates the requester's trust credentials for this interaction and sends them to the requester. After the requester verifies and confirms the potential collaborator's trust credentials, it generates and sends the potential collaborator's trust credentials for this interaction, completing the feedback and update of the trust credentials.
[0030] In step S130 , the requester selects a preset number of verified target collaborators to construct an anonymous area.
[0031] Here, after completing a trust assessment of potential collaborators, the requester randomly selects a certain number of target collaborators from the verified candidate set to jointly construct an anonymous region to protect their own location privacy. For example, the requester randomly selects k-1 target collaborators from the candidate set to form an anonymous region with themselves, making it difficult for outsiders to determine the requester's specific location within the region, thus achieving spatial anonymity protection.
[0032] The system model schematic diagram used in the method of the present invention is as follows Figure 2 As shown, after the spatial anonymous area is established, the requester sends a request to the service provider, and the service provider sends services to the requester, such as push of relevant information, life service search, etc.
[0033] The distributed spatial anonymity protection method based on a self-certifying trust mechanism, provided by the embodiments of this invention, aims to construct a secure and reliable anonymous zone to protect the user's location privacy through the exchange of trust credentials between the requester and collaborators. Its core principle is to use trust credentials to bidirectionally authenticate the requester and collaborators, ensuring sufficient trustworthiness among all parties involved in constructing the anonymous zone. This approach protects privacy while preventing malicious or low-trust users from causing damage to the system. By randomly selecting collaborators to construct the distributed anonymous zone, the effectiveness of privacy protection is further enhanced.
[0034] In some embodiments of the present invention, the potential collaborator and the requester verify each other's historical trust credentials and determine whether the interaction is successful or invalid based on a preset interactive verification mechanism, including: after receiving the first request, the potential collaborator sends an identity identifier and a trust proof request to the requester; wherein the trust proof request carries a customized trust credential time threshold and a trust credential quantity threshold; the requester queries its own historical trust credentials based on the trust proof request and sends them to the potential collaborator; the potential collaborator verifies the requester's historical trust credentials: when the verification fails, the potential collaborator does not respond to the requester's first request; when the verification passes, the potential collaborator judges the interaction in combination with the interactive verification mechanism, and generates corresponding trust credentials based on different judgment results and sends them to the requester; when the requester confirms that there is no trust credential of failed interaction among the trust credentials sent by the potential collaborator, the interactive verification mechanism is used for judgment, and corresponding trust credentials are generated based on different judgment results and sent to the potential collaborator; otherwise, the interaction is terminated, and an unreliable trust credential is sent to the potential collaborator.
[0035] Here, the trust credential time threshold limits the time range of historical trust credentials to be considered. The trust credential quantity threshold specifies the minimum number of historical trust credentials required of the requester as the interactive requestor. Users sending trust proof requests can flexibly set the trust credential time threshold and quantity threshold based on their sensitivity to trust timeliness and historical behavior.
[0036] In some implementations, when the user requesting trust proof is sensitive to the timeliness of trust, the time threshold is set to a value close to the current time to ensure that only recent trust behavior is considered, reflecting the latest trust status of the user receiving the trust proof request. In some implementations, when the user requesting trust proof is more concerned with historical behavior, a larger number threshold is set to include more historical trust credentials and comprehensively assess the long-term trustworthiness of the user receiving the trust proof request.
[0037] After receiving a request from a requester to construct an anonymous region, a potential collaborator must first identify itself to the requester and request their trust credentials. This allows the requester to assess the requester's credibility and decide whether to respond to the request. Upon receiving a trust proof request from a collaborator, the requester must search its own stored trust credential database for matching credentials, based on the time and quantity thresholds specified in the request, and provide them to the collaborator for verification.
[0038] After receiving the trust credential information from the requester, the potential collaborator needs to conduct detailed verification and analysis to determine whether the requester meets certain credibility criteria, thereby deciding whether to respond to the requester's first request to construct an anonymous region. When the potential collaborator responds to the first request, it generates the requester's trust credential and sends it to the requester along with its own location information. After receiving the trust credential from the potential collaborator, the requester needs to evaluate the potential collaborator's credibility to decide whether to include the collaborator in the candidate set of collaborators for constructing the anonymous region. It also evaluates the potential collaborator's behavior and generates corresponding trust credentials to improve the entire trust system.
[0039] This interactive verification process, through bidirectional authentication and a pre-defined interactive verification mechanism, ensures that interactions between users in a distributed system are based on trusted historical records and current status. This approach effectively screens out highly trustworthy users while preventing potential threats to the system from malicious or low-trustworthy users. This meticulous verification logic improves the accuracy and reliability of privacy protection and trust assessment in distributed systems.
[0040] In some embodiments of the present invention, the requester queries its own historical trust credentials based on the trust proof request, including: the requester queries, based on the trust proof request, multiple historical trust credentials of no less than the trust credential quantity threshold within the trust credential time threshold when the requester acts as an interactive requester; the requester queries, based on the trust proof request, multiple historical trust credentials of the requester as an interactive collaboration party within the trust credential time threshold.
[0041] Here, the interaction requester refers to the party that actively initiated the request in the past interaction.
[0042] The interaction collaborator refers to the party that the requester has participated in as an interaction collaborator in the past interaction. The same user can be both the interaction requester and the interaction collaborator in different interactions.
[0043] The trust proof request sent by the potential collaborator carries a customized trust credential time threshold and trust credential quantity threshold, which are the screening conditions set by the potential collaborator for the requester.
[0044] Within the trust credential time threshold, the first number of the requester's historical trust credentials as an interactive requesting party is no less than the trust credential number threshold. If the first number is less than the trust credential number threshold, it indicates that the requester's historical record is insufficient to prove their trustworthiness. This ensures that only requesters with sufficient historical records can pass verification, thereby improving system security. Limiting the requester's historical credentials to within the trust credential time threshold ensures that the verification process is based on the most recent trust records, thereby improving the timeliness and accuracy of verification.
[0045] In some embodiments of the present invention, the potential collaborator verifies the historical trust credentials of the requester, including: the potential collaborator determines a first number of historical trust credentials of the requester as an interactive requesting party and a second number of historical trust credentials as an interactive collaborating party within the trust credential time threshold; determines that the current verification fails when at least one of the following conditions exists, and determines that the current verification passes when all of the following conditions do not hold: the first number is greater than the second number, the first number is lower than the trust credential number threshold, the trust value of the requester as an interactive collaborating party is lower than the average trust value of collaborators in the area, and the generation time of the historical trust credentials of the requester as an interactive requesting party is earlier than the trust credential time threshold.
[0046] Here, in the specific conditions of the verification logic, the fact that the first number is greater than the second number indicates that the requester plays the role of the requester more and participates less as an interactive collaborator. In actual operation, the first number is much greater than the second number. What we want to express here is that it is greater than the set standard. For example, the first number is more than twice the second number. The standard can be adjusted according to actual needs. The first number is lower than the trust credential quantity threshold, indicating that the requester's historical record is not enough to prove its credibility. The trust value of the requester as an interactive collaborator is lower than the average trust value of collaborators in the area, indicating that the requester's credibility is lower than the average level. The generation time of the requester's historical trust credentials as an interactive requester is earlier than the trust credential time threshold, indicating that the requester's trust credentials are too old and cannot reflect its current credibility.
[0047] This embodiment assesses the requester's trustworthiness by comprehensively considering the number of historical trust credentials, trust values, and time factors used by the requester in different roles. This approach effectively screens out highly trustworthy requesters while preventing potential threats to the system from malicious or low-trustworthiness users. This meticulous verification logic improves the accuracy and reliability of privacy protection and trust assessment in distributed systems.
[0048] In some embodiments of the present invention, when the verification is passed, the potential collaborator combines the interactive verification mechanism to judge the current interaction, and generates corresponding trust credentials based on different judgment results, including: if the result of the interactive verification mechanism is a successful interaction, the potential collaborator responds to the requester's first request, sends its own location information to the requester, and evaluates the requester's first request to generate a trust credential; if the result of the interactive verification mechanism is an invalid interaction, the potential collaborator does not generate a response to the requester and generates an invalid trust credential; if the result of the interactive verification mechanism is a failed interaction, the potential collaborator does not generate a response to the requester and generates a trust credential for failed interaction.
[0049] If the potential collaborator determines the interaction is successful based on the interaction verification mechanism, they will evaluate the requester's first request and generate a trust credential for this interaction. This trust credential records the success of the interaction, including the potential collaborator's evaluation of the requester and the interaction timestamp. This trust credential serves as a trust reference for the requester in future interactions, enhancing their credibility in the system.
[0050] If a potential collaborator determines the interaction is invalid based on the interaction verification mechanism, it will not respond to the requester and will generate an invalid trust credential. This credential will mark the interaction as invalid and record the reason for the interaction failure (e.g., the requester did not meet certain conditions). This credential will serve as a trust reference for the requester in future interactions, but it will not enhance their credibility and may affect their subsequent interaction requests.
[0051] If the potential collaborator determines that the interaction has failed based on the interaction verification mechanism, the potential collaborator will not respond to the requester. Instead, a trust certificate will be generated, marking the interaction as failed. This certificate will detail the reasons for the interaction failure (e.g., malicious behavior or rule violations by the requester). This certificate will serve as a trust reference for the requester in future interactions, significantly reducing their credibility and potentially causing them to be rejected by the system.
[0052] Through this detailed interactive verification mechanism, potential collaborators can take appropriate action and generate corresponding trust credentials based on different interaction outcomes. This approach not only effectively screens out trustworthy requesters, but also records and provides feedback on invalid or failed interactions, thereby maintaining the overall trust environment of the system and improving the accuracy and reliability of privacy protection and trust assessment in distributed systems.
[0053] In some embodiments of the present invention, the requester uses the interactive verification mechanism to make a judgment, and generates corresponding trust credentials based on different judgment results and sends them to the potential collaborator, including: if the result of the interactive verification mechanism is a successful interaction, the requester evaluates the potential collaborator, generates a trust credential and sends it to the other party, and at the same time adds the potential collaborator as a target collaborator to the candidate set for constructing an anonymous area; if the result of the interactive verification mechanism is an invalid interaction, the requester does not respond to the potential collaborator's reply, and at the same time generates a trust credential for the invalid interaction and sends it to the potential collaborator; if the result of the interactive verification mechanism is a failed interaction, the requester does not respond to the potential collaborator's reply, and at the same time generates a trust credential for the failed interaction and sends it to the potential collaborator.
[0054] Here, the requester uses an interactive verification mechanism to make a judgment. If the interaction is deemed successful, the requester evaluates the potential collaborator, generates a trust credential, and sends it to the potential collaborator. This trust credential records the success of the interaction, including the requester's evaluation of the potential collaborator and the interaction timestamp. This credential serves as a trust reference for the potential collaborator in future interactions, enhancing their credibility in the system. The potential collaborator is also added to the candidate set of collaborators used to construct the anonymous region.
[0055] If the interaction verification mechanism determines that the requester's interaction is invalid, the requester will not respond to the potential collaborator's reply. Instead, the requester will generate a trust certificate indicating an invalid interaction and send it to the potential collaborator. This certificate will mark the interaction as invalid and record the reason for the interaction failure (e.g., the potential collaborator did not meet certain conditions). This certificate will serve as a trust reference for the potential collaborator in future interactions, but it will not enhance their credibility and may affect their subsequent interaction requests.
[0056] If the interaction verification mechanism determines that the requester's interaction has failed, the requester will not respond to the potential collaborator's reply and will generate a trust certificate marked as failed interaction and send it to the potential collaborator. This certificate will detail the reasons for the interaction failure (such as malicious behavior or rule violations by the potential collaborator). This certificate will serve as a trust reference for the potential collaborator in future interactions, significantly reducing their credibility and potentially causing them to be rejected by the system.
[0057] Through this detailed interactive verification mechanism, requesters can take appropriate action and generate corresponding trust credentials based on different interaction results. This approach not only effectively screens trustworthy potential collaborators, but also records and provides feedback on invalid or failed interactions, thereby maintaining the overall trust environment of the system and improving the accuracy and reliability of privacy protection and trust assessment in distributed systems.
[0058] In some embodiments of the present invention, the format of the trust credential is as follows: ; Among them, CR represents the trust certificate, It is the identity tag of the trust credential owner, and its value is 0 or 1, indicating that the trust credential owner is the requester or the trust credential owner is the collaborator, respectively. and The unique identifiers of the trust credential generator and the trust credential owner respectively; is the evaluation value of the trust credential owner; Is the signature of the trust certificate generated by the trust certificate, The timestamp of the trust credential.
[0059] Here, the format of the trust credential includes: an identity tag of the trust credential owner, which is used to distinguish whether the owner of the trust credential is the requester ( =0) or a collaborator ( =1); unique identifiers of the trust credential generator and the trust credential owner, which clearly identify the two parties involved in the trust relationship; the evaluation value of the trust credential owner, which reflects the specific quantification of the generator's trust in the owner; timestamp The time when the trust credential was generated is recorded for subsequent time-related calculations and verifications; the signature is used to ensure the integrity and authenticity of the trust credential and prevent tampering and forgery.
[0060] In some embodiments of the present invention, the trust value is calculated as follows: ; ; in, is the trust value of the trust credential owner, For the The evaluation value of the trust credential generator to the trust credential owner in the trust credential, The number of trust certificates owned by the trust certificate owner; is a consistency parameter, with a value of 0 or 1; is the time decay parameter, and its value is determined by OK, among them and The timestamps for the current timestamp and the timestamp generated by the trust credential, respectively. is the attenuation adjustment factor; It is a similarity parameter with a value range of 0 to 1, which represents the trust strategy of the user who is currently calculating the trust value towards the generator of the unfamiliar trust credential.
[0061] It should be noted that the consistency parameter Used to measure the consistency between the evaluation value of the trust credential and the average of all evaluation values of the user. Based on the trust certificate owner When the absolute value of the difference between the mean values of the evaluated values calculated by the trust credentials is greater than the standard deviation of the evaluated value of the trust credential owner, The value is set to 0 when When the absolute value of the difference between the trust credential owner's evaluated value and the mean value is less than or equal to the standard deviation of the trust credential owner's evaluated value, The value of is set to 1.
[0062] Attenuation adjustment factor in time decay parameter , which is used to adjust the weight of trust credentials over time, so that recent trust credentials have greater influence.
[0063] Similarity parameter There is a certain degree of uncertainty and randomness. If the user currently calculating the trust value (i.e. the trust credential owner) is The trust certificate generators have all evaluated the same user. The value is set to ,in is the evaluation of the corresponding trust credential generator in the previous interaction, is the evaluation of the user whose trust value is currently being calculated in the previous interaction; otherwise, Set to a random number between 0 and 1.
[0064] This embodiment comprehensively considers multiple factors such as consistency, time decay and similarity when calculating the user trust value, making the trust evaluation result more comprehensive, accurate and objective, and better reflecting the user's actual trust status and behavior pattern.
[0065] In some embodiments of the present invention, the interactive verification mechanism is specifically as follows: If the requester has: or for collaborators: The result of the interactive verification mechanism is that the interaction is successful; If the requester has: or for collaborators: Then the result of the interactive verification mechanism is invalid interaction; If the requesting user has: , or for collaborative users: , then the result of the interactive verification mechanism is failed interaction; in, is the trust evaluation threshold of the i-th collaborator, It is the trust value set of all collaborators in a certain anonymous region construction. is the trust evaluation value of the i-th collaborator, is the trust evaluation threshold of the requester, represents the trust evaluation threshold set of collaborators, Indicates the trust evaluation value of the requester, represents the requester's own knowledge, It is the requester's judgment of the collaborator based on his own knowledge. represents the self-knowledge of the i-th collaborator, It represents the judgment result of the i-th collaborator on the requester based on his own knowledge, and its value is Indicates that no abnormality is found, and the value is Indicates that an abnormality was found.
[0066] In some embodiments of the present invention, the requester selects a preset number of verified target collaborators to construct an anonymous area, including: The requester randomly selects k-1 target collaborators and constructs an anonymous region Gen(Loc0, Loc i …, Loc k-1 ), and sends the generated anonymous area information and its own service request to the service provider; where Loc0 is the location information of the requester; Loc i is the location information of the i-th target collaborator, i ranges from 1 to k-1; Gen(.) is a safe anonymous region constructor, k is the number of all users in the anonymous region.
[0067] Here, the requester randomly selects k-1 target collaborators from the collaborator candidate set, and together with itself, they form an anonymous area, making it difficult for the outside world to determine the specific location of the requester in the area, thereby achieving the effect of spatial anonymity protection.
[0068] The above-mentioned distributed spatial anonymity protection method based on self-proven trust is described below with reference to a specific embodiment. However, it should be noted that this specific embodiment is only for better illustrating the present invention and does not constitute an improper limitation of the present invention.
[0069] The distributed spatial anonymity protection method provided by the embodiment of the present invention implements the specific process of bidirectional authentication between potential collaborators and requesters and constructing an anonymous area through the following steps: Step 1: The requester broadcasts the first request to construct an anonymous region; Step 2: The potential collaborator who receives the first request sends its own identity and a trust certification request including a trust credential time threshold and a trust credential quantity threshold to the requester; Step 3: The requester retrieves its own trust credentials, including: Step 3.1. The requester queries the historical trust credentials of itself as the interactive requester within the trust credential time threshold and the trust credential quantity threshold in the trust proof request, wherein the number of the historical trust credential certificates is not less than the trust credential quantity threshold; Step 3.2. After querying the trust credentials of itself as the requester, the requester queries the historical trust credentials of itself as the interactive collaboration party within the trust credential time threshold in the trust proof request, so as to facilitate the subsequent determination in step 4.4. Step 3.3: Send the trust credential information retrieved in steps 3.1 and 3.2 to the potential collaborator who issued the trust certification request; Step 4: Potential collaborators verify the requester's information, including: Step 4.1: Query the trust credential of the requester as the interaction requester within the time threshold; Step 4.2: Verify the trust credentials of the requester as an interactive collaboration party within the time threshold; Step 4.3: If the amount of trust credential information of the requester as the interaction requesting party (i.e., the first amount) is much greater than the amount of trust credential information of the requester as the interaction coordinating party (i.e., the second amount), then the first request is not responded to; Step 4.4: If the trust value of the requester as an interactive collaborator is much lower than the average trust value of the collaborators in the area, then the first request is not responded to; Step 4.5: If the amount of trust credential information of the requester as the interaction requesting party is less than the amount threshold, then the first request is not responded to; Step 4.6: If the generation time of the trust credential information of the requester as the interaction requesting party is earlier than the time threshold, then the first request is not responded to; Step 4.7: If steps 4.3 to 4.6 are not met, then in response to the first request, the collaborator makes a determination in combination with the interactive verification mechanism; Step 4.8: If the interactive verification mechanism results in a successful interaction, the potential collaborator responds to the requester's anonymous region construction request, sends its own location information to the requester, evaluates the requester's anonymous region construction request, and generates a trust credential. Step 4.9: If the result of the interactive verification mechanism is Frustrated Interactive Verification, the potential collaborator does not generate a response to the requester and generates an invalid trust credential.
[0070] Step 4.10. If the interactive verification mechanism results in a rejected interactive verification, the potential collaborator does not respond to the requester, but generates a failed interactive verification trust credential and sends it to the requester. Step 5: Requester confirmation, including: Step 5.1. After receiving the trust credential sent by the collaborator, the requester determines whether there is a trust credential with failed interaction among the multiple trust credential credentials of the potential collaborator; Step 5.2. If the collaborator's trust credentials contain trust credentials that indicate an interaction failure, the requester terminates the interaction. Step 5.3. If the trust credential of the failed interaction does not exist in the collaborator's trust credential, the requester uses the interactive verification mechanism to make a judgment; Step 5.4. If the result of the interactive verification mechanism is a successful interaction, the requester adds the potential collaborator to the candidate set of collaborators for constructing the anonymous region; evaluates the collaborators in the candidate set, generates a certificate, and sends it to the corresponding collaborator.
[0071] Step 5.5. If the result of the interaction verification mechanism is invalid interaction, the requester does not respond to the collaborator's reply. At the same time, the requester generates a trust certificate indicating that this interaction is invalid and sends it to the collaborator. Step 5.6. If the result of the interactive verification mechanism is a failed interaction, the requester does not respond to the collaborator's reply, and generates a trust certificate of interaction failure and sends it to the collaborator.
[0072] Step 6: The requester randomly selects k-1 target collaborators from the candidate set to construct an anonymous region.
[0073] The distributed spatial anonymity protection method based on self-proven trust provided by the embodiments of the present invention has the following outstanding advantages over the prior art: 1) Enhanced privacy protection: By constructing an anonymous area, the requester's location information is hidden within a certain range, preventing it from being accurately located by the outside world, effectively protecting the user's privacy.
[0074] 2) Improve system security: Introduce a trust credential mechanism to conduct two-way verification and evaluation of requesters and collaborators, ensuring that all parties involved in the construction of anonymous zones have sufficient credibility, reducing the risk of malicious users or low-trust users damaging the system or leaking privacy.
[0075] 3) Distributed architecture: A distributed approach is used for interaction and verification of trust credentials, eliminating the need to rely on a central authority. This improves the system's scalability and fault tolerance, and allows it to adapt to large-scale, dynamically changing network environments.
[0076] 4) Flexible threshold settings: Allow users to flexibly define the time threshold and quantity threshold of trust credentials based on their own needs and sensitivity to trust factors, making trust assessment more in line with actual application scenarios and user personalized requirements.
[0077] 5) Comprehensive trust assessment: When calculating user trust values, multiple factors such as consistency, time decay, and similarity are comprehensively considered, making the trust assessment results more comprehensive, accurate, and objective, and better reflecting the user's actual trust status and behavior patterns.
[0078] The distributed spatial anonymity protection method based on self-proven trust proposed in this paper is suitable for distributed environments requiring high trust, such as the Internet of Things and the Internet of Vehicles, where trust between nodes is crucial for privacy protection. The goal is to screen reliable collaborators through a trust mechanism, ensuring the secure and reliable construction of anonymous regions while protecting user privacy.
[0079] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present invention. The serial numbers of the above-mentioned embodiments of the present invention are for description only and do not represent the advantages and disadvantages of the embodiments.
[0080] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.
[0081] In the several embodiments provided herein, it should be understood that the disclosed methods can be implemented in other ways. The methods disclosed in the several method embodiments provided herein can be combined arbitrarily, unless they conflict, to produce new method embodiments. The features disclosed in the several method embodiments provided herein can be combined arbitrarily, unless they conflict, to produce new method embodiments.
[0082] The above description is merely an embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A distributed spatial anonymity protection method based on self-proven trust, characterized in that: include: The requester broadcasts the first request to construct an anonymous region; The potential collaborator who receives the first request and the requester mutually verify each other's historical trust credentials and determine whether the interaction is successful or invalid according to a preset interaction verification mechanism; The interactive verification mechanism combines historical trust credential verification results and the verifier's own background knowledge of the other party's identity to comprehensively determine the results of the current interaction. After the determination, the verifier generates a trust credential for the other party's current interaction and sends it to the other party. The requester selects a preset number of verified target collaborators to construct an anonymous area.
2. The method according to claim 1, characterized in that The potential collaborator and the requester mutually verify each other's historical trust credentials and determine whether the interaction is successful or invalid based on a preset interaction verification mechanism, including: After receiving the first request, the potential collaborator sends an identity identifier and a trust proof request to the requester; wherein the trust proof request carries a customized trust credential time threshold and trust credential quantity threshold; The requester queries its own historical trust credentials based on the trust proof request and sends the historical trust credentials to the potential collaborator; The potential collaborator verifies the requester's historical trust credentials: if the verification fails, the potential collaborator does not respond to the requester's first request; if the verification passes, the potential collaborator determines the current interaction based on the interaction verification mechanism, and generates corresponding trust credentials based on different determination results and sends them to the requester; When the requester confirms that there is no trust credential of interaction failure among the trust credentials sent by the potential collaborator, the interactive verification mechanism is used to make a judgment, and corresponding trust credentials are generated based on different judgment results and sent to the potential collaborator; otherwise, the interaction is terminated and an unreliable trust credential is sent to the potential collaborator.
3. The method according to claim 2, characterized in that The requester queries its own historical trust credentials based on the trust proof request, including: The requester queries, based on the trust proof request, a plurality of historical trust credentials within the trust credential time threshold, which are no less than the trust credential quantity threshold when the requester is the interaction requester; The requester queries, based on the trust proof request, a plurality of historical trust credentials in which the requester serves as an interactive cooperation party within the trust credential time threshold.
4. The method according to claim 2, characterized in that The potential collaborator verifies the requester's historical trust credentials, including: The potential collaborator determines a first number of historical trust credentials of the requester as an interaction requester and a second number of historical trust credentials of the requester as an interaction collaborator within the trust credential time threshold; The current verification is considered to have failed if at least one of the following conditions exists, and is considered to have passed if none of the following conditions exist: The first number is greater than the second number, the first number is lower than the trust credential number threshold, the trust value of the requester as an interactive collaborator is lower than the average trust value of the collaborators in the area, and the generation time of the historical trust credential of the requester as an interactive requester is earlier than the trust credential time threshold.
5. The method according to claim 2, characterized in that When the verification is passed, the potential collaborator judges the current interaction in combination with the interactive verification mechanism and generates corresponding trust credentials based on different judgment results, including: If the result of the interactive verification mechanism is a successful interaction, the potential collaborator responds to the first request of the requester, sends its own location information to the requester, and evaluates the first request of the requester to generate a trust credential; If the result of the interactive verification mechanism is an invalid interaction, the potential collaborator does not generate a response to the requester and generates an invalid trust credential; If the result of the interaction verification mechanism is a failed interaction, the potential collaborator does not generate a response to the requester, and a trust certificate of interaction failure is generated.
6. The method according to claim 2, characterized in that The requester uses the interactive verification mechanism to make a determination, and generates corresponding trust credentials based on different determination results and sends them to the potential collaborator, including: If the result of the interactive verification mechanism is a successful interaction, the requester will evaluate the potential collaborator, generate a trust certificate, and send it to the other party. At the same time, the potential collaborator will be added to the candidate set for constructing the anonymous area as a target collaborator. If the result of the interaction verification mechanism is an invalid interaction, the requester does not respond to the potential collaborator's reply, and generates a trust credential indicating that the interaction is invalid and sends it to the potential collaborator; If the result of the interaction verification mechanism is a failed interaction, the requester does not respond to the reply of the potential collaborator, and at the same time generates a trust certificate for the failed interaction and sends it to the potential collaborator.
7. The method according to any one of claims 1 to 6, characterized in that The format of the trust certificate is as follows: ; Among them, CR represents the trust certificate, It is the identity tag of the trust credential owner, and its value is 0 or 1, indicating that the trust credential owner is the requester or the trust credential owner is the collaborator, respectively. and The unique identifiers of the trust credential generator and the trust credential owner respectively; is the evaluation value of the trust credential owner; Is the signature of the trust certificate generated by the trust certificate, The timestamp of the trust certificate.
8. The method according to any one of claims 1 to 6, characterized in that The trust value is calculated as follows: ; ; in, is the trust value of the trust credential owner, For the The evaluation value of the trust credential generator to the trust credential owner in the trust credential, The number of trust certificates owned by the trust certificate owner; is a consistency parameter, with a value of 0 or 1; is the time decay parameter, and its value is determined by OK, among them and The timestamps for the current timestamp and the trust credential are generated, is the attenuation adjustment factor; It is a similarity parameter with a value range of 0 to 1, which represents the trust strategy of the user who is currently calculating the trust value towards the generator of the unfamiliar trust credential.
9. The method according to any one of claims 1 to 6, characterized in that The interactive verification mechanism is as follows: If the requester has: or for collaborators: The result of the interactive verification mechanism is that the interaction is successful; If the requester has: or for collaborators: Then the result of the interactive verification mechanism is invalid interaction; If the requesting user has: , or for collaborative users: , then the result of the interactive verification mechanism is failed interaction; in, is the trust evaluation threshold of the i-th collaborator, It is the trust value set of all collaborators in a certain anonymous region construction. is the trust evaluation value of the i-th collaborator, is the trust evaluation threshold of the requester, represents the trust evaluation threshold set of collaborators, Indicates the trust evaluation value of the requester, represents the requester's own knowledge, It is the requester's judgment of the collaborator based on his own knowledge. represents the self-knowledge of the i-th collaborator, It represents the judgment result of the i-th collaborator on the requester based on his own knowledge, and its value is Indicates that no abnormality is found, and the value is Indicates that an abnormality was found.
10. The method according to any one of claims 1 to 6, characterized in that The requester selects a preset number of verified target collaborators to build an anonymous area, including: The requester randomly selects k-1 target collaborators and constructs an anonymous region Gen(Loc0, Loc i …, Loc k-1 ), and sends the generated anonymous area information and its own service request to the service provider; where Loc0 is the location information of the requester; Loc i is the location information of the i-th target collaborator, i ranges from 1 to k-1; Gen(.) is a safe anonymous region constructor, k is the number of all users in the anonymous region.
Citation Information
Cited By
RFID tag security protection method and system integrating encryption and identity authentication
CN120856466A