Edge-assisted lightweight encryption method capable of de-weighting

Through edge-assisted hierarchical collaborative architecture and lightweight encryption methods, the data encryption and deduplication problems of resource-constrained AIoT devices are solved, and an efficient and secure data sharing solution is realized. It is adapted to AIoT devices with low computing power and low energy consumption, providing theoretical security and engineering efficient solutions.

CN120498659AActive Publication Date: 2025-08-15GUIZHOU NORMAL UNIVERSITY
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510567510.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-15
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

The prior art is difficult to efficiently implement data encryption and deduplication on resource-constrained AIoT devices, and there are problems such as high computational complexity, high communication overhead, and incomplete privacy protection.

Method used

Build an edge-assisted hierarchical collaborative architecture, offload bilinear paired peer-to-peer computing-intensive operations to the edge server, so that AIoT devices only need to perform lightweight hashing and exclusive OR operations, and the edge server generates deduplication tags to implement ciphertext equivalent testing, and builds a security model using bilinear assumptions to ensure indistinguishability and unidirectionality under plaintext attacks.

Benefits of technology

It significantly reduces the computing complexity of AIoT devices, extends the battery life of the device, realizes an efficient data deduplication process, ensures user data privacy, and provides theoretical security under the selected plaintext attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498659A_ABST
    Figure CN120498659A_ABST
Patent Text Reader

Abstract

The invention discloses an edge-assisted lightweight de-duplication encryption method, which comprises the following steps of: constructing an edge-assisted layered collaborative architecture, and unloading computation-intensive operations such as bilinear pairing to an edge server, so that resource-limited AIoT (Area Internet of Things) equipment only needs to execute lightweight Hash and exclusive or operation; the edge server generates a de-duplication label based on the ciphertext, so that the cloud end realizes efficient de-duplication through a ciphertext equivalence test on the premise of not decrypting; and constructing a security model by adopting a bilinear hypothesis, and realizing selection of an indistinguishable IND-CPA and a unidirectional OW-CPA under plaintext attack through formalized proof, thereby ensuring that the plaintext cannot be reversely deduced even if the edge node is attacked. According to the method, the communication efficiency and the calculation performance are remarkably improved. The innovation of the method is that the edge-assisted encryption function and the de-duplication function are combined, and the advantages which cannot be compared with a traditional scheme are formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of Internet of Things encryption and relates to an edge-assisted lightweight deduplication encryption method. Background Art

[0002] With the rapid development of the Artificial Intelligence of Things (AIoT), intelligent terminal devices are enabling the real-time collection and transmission of massive amounts of sensitive data. This trend presents unprecedented dual challenges for data security. On the one hand, data confidentiality must be ensured during transmission and storage, while on the other hand, the performance constraints of resource-constrained devices must be considered to meet real-time requirements. Traditional data encryption and deduplication technologies are no longer adaptable to this complex scenario.

[0003] In the AIoT landscape, smart end devices such as sensors and wearables are generally limited in computing power, memory capacity, and energy supply. Traditional public-key cryptography schemes, such as RSA and ECC, are difficult to execute efficiently on end devices due to the complex modular exponentiation and key management mechanisms involved. Although some research has attempted to optimize computational efficiency using symmetric encryption, its key distribution mechanism still relies on computationally intensive protocols, significantly increasing energy consumption and latency in end devices and failing to meet real-time requirements. This creates an irreconcilable conflict between resource-constrained devices and traditional encryption schemes.

[0004] While existing cloud-based encrypted storage solutions can ensure data confidentiality, they pose a significant risk of data redundancy after encryption. Traditional deduplication technologies require decrypting data in the cloud to detect duplicate content, a serious violation of privacy protection principles. Client-side encryption deduplication solutions can avoid cloud-based decryption, but require end devices to pre-calculate data fingerprints and manage keys, further increasing resource consumption. This conflict between cloud-based encrypted storage and data redundancy urgently needs to be resolved.

[0005] Existing edge-assisted encryption schemes attempt to alleviate pressure on endpoints by offloading computational tasks to edge servers, but these solutions present trust and privacy risks. Edge servers can directly access plaintext and intermediate states during the assisted encryption process, making sensitive information vulnerable to internal attackers or malicious nodes. Furthermore, existing schemes rely on multiple rounds of data duplication verification between the endpoint and the cloud, significantly increasing communication overhead and making them unsuitable for large-scale concurrent device scenarios.

[0006] Overall, existing technologies suffer from core issues such as an imbalance between efficiency and security, incomplete privacy protection, and insufficient architectural scalability. Lightweight solutions often sacrifice security, while high-security solutions struggle to adapt to resource-constrained devices. Cloud-based deduplication requires data decryption or reliance on trusted third parties, posing privacy risks to edge servers. Existing solutions are mostly based on centralized cloud models, making them difficult to adapt to the dynamic topology and massive terminal access requirements of AIoT. Summary of the Invention

[0007] In order to solve the technical problems existing in the above-mentioned background technology, the present invention provides an edge-assisted lightweight deduplication encryption method, which significantly improves the data security and storage efficiency of the AIoT system by innovatively combining edge computing and ciphertext equivalence testing technology.

[0008] Based on the first main aspect of the present invention, a lightweight edge-assisted deduplication encryption method is provided. The method builds an edge-assisted layered collaborative architecture. By offloading computationally intensive operations such as bilinear pairing to edge servers, resource-constrained AIoT devices only need to perform lightweight hashing and XOR operations.

[0009] Furthermore, the edge server generates deduplication tags based on the ciphertext, enabling the cloud to achieve efficient deduplication through ciphertext equivalence testing without decryption.

[0010] In addition, a bilinear assumption is used to build a security model, and the indistinguishability IND-CPA and one-way OW-CPA under chosen-plaintext attacks are achieved through formal proof, ensuring that even if the edge node is compromised, the plaintext cannot be inferred.

[0011] As a further preferred solution, the aforementioned edge-assisted lightweight deduplication encryption method includes one or a combination of the following steps:

[0012] S1, initialization and key generation: Generate system public parameters based on bilinear pairing, and generate public and private key pairs for AIoT devices and edge servers respectively;

[0013] S2, edge-assisted parameter calculation: The edge server calculates the edge-assisted encryption parameter (Y) based on the user's public key and its own public key. u ,Y s ) and returns it to the AIoT device;

[0014] S3, data encryption: The AIoT device uses edge-assisted encryption parameters and random numbers to perform lightweight encryption on the plaintext and generate ciphertext C = (C1, C2, C3);

[0015] S4, deduplication label generation: The edge server receives two ciphertexts and calculates the edge-assisted deduplication label Update ciphertext;

[0016] S5, cloud-based ciphertext deduplication: The cloud server verifies the deduplication tag, determines whether the ciphertext is duplicated, and performs deduplication without decryption;

[0017] S6, data decryption: The data user uses the private key to recover the plaintext from the ciphertext.

[0018] As a further preferred solution, in the aforementioned edge-assisted lightweight deduplication encryption method, the bilinear pairing Satisfies bilinearity, non-degeneracy and computability, where is the additive cyclic group, is a multiplicative cyclic group of the same factor.

[0019] As a further preferred solution, in the aforementioned edge-assisted lightweight deduplication encryption method, the edge-assisted encryption parameter (Y u ,Y s ), the edge server replaces the AIoT device with high computational complexity operations through bilinear pairing operations, reducing the encryption computation complexity of the AIoT device to O(1) hash and XOR operations.

[0020] As a further preferred solution, in the aforementioned edge-assisted lightweight deduplication encryption method, in the data encryption step, the AIoT device uses an XOR operation to convert the plaintext M into a hash value. Combined to generate C2, the hash value is converted into Combined with H2(M) to generate C3, it avoids complex exponential operations and key management.

[0021] As a further preferred solution, in the aforementioned edge-assisted lightweight deduplication encryption method, the generation of the edge-assisted deduplication label T only relies on the XOR operation of the ciphertext components C3 and C3', without the need to parse the plaintext M and M', ensuring that the deduplication process is completed in the ciphertext domain and does not leak privacy.

[0022] As a further preferred solution, in the aforementioned edge-assisted lightweight deduplication encryption method, in the cloud ciphertext deduplication step, the cloud server uses the edge server private key sk s Perform ciphertext equivalence testing, verify the validity of T through bilinear pairing and hash operations, and achieve zero-knowledge deduplication.

[0023] As a further preferred solution, the aforementioned edge-assisted lightweight deduplication encryption method satisfies the indistinguishability under chosen plaintext attacks (IND-CPA) and one-wayness (OW-CPA), and proves the adversary's advantage by reducing it to the difficulty of the bilinear Diffie-Hellman (DBDH) problem. and are all negligible functions.

[0024] Based on the second main aspect of the present invention, an electronic device is provided, comprising: at least one processor; a memory communicatively connected to the at least one processor; the memory storing a computer program which, when executed by the at least one processor, enables the at least one processor to implement the aforementioned edge-assisted lightweight deduplicated encryption method.

[0025] According to a third main aspect of the present invention, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed, implements the aforementioned edge-assisted lightweight deduplication encryption method.

[0026] Advantages and beneficial effects of the present invention:

[0027] First, compared with the existing technology, the present invention innovatively constructs an edge-assisted layered collaborative architecture, which completely offloads computationally intensive operations such as bilinear pairing to the edge server, fundamentally solving the pain point of insufficient computing power of resource-constrained devices in traditional encryption schemes. Specifically, the edge server pre-calculates edge-assisted parameters based on the user's public key and its own public key, where bilinear pairing is one of the most complex operations in cryptography. AIoT devices only need to receive pre-calculated parameters and complete encryption through simple hash operations and XOR operations, reducing the computational complexity to (O(1) level. This division of labor mode eliminates the need for terminal devices (such as sensors and wearable devices) to integrate high-power encryption modules, significantly extending battery life, and adapting to the low computing power and low energy consumption characteristics of AIoT devices, achieving a perfect balance between "strong security" and "light terminals".

[0028] Secondly, in the data encryption link, the present invention abandons the complex encryption method that relies on exponential operations or elliptic curve multiplication in traditional schemes, and instead adopts a lightweight combination of "hash mask + XOR operation" to build an efficient and secure encryption mechanism. The AIoT device uses edge auxiliary parameters and random numbers to generate hash values, and combines them with plaintext through XOR operations to generate ciphertext components. At the same time, secondary protection of the plaintext summary is achieved through the calculation of the ciphertext component C3. On the one hand, the reversibility of the XOR operation of this design ensures that only one hash and one XOR are required to restore the plaintext during decryption, and the computational overhead is negligible; on the other hand, the combination of random numbers and bilinear pairing parameters makes the ciphertext generated by each encryption of the same plaintext completely different (semantic security), which effectively resists statistical analysis attacks.

[0029] Thirdly, to address the issue of cloud-based data redundancy, this paper proposes edge-assisted ciphertext domain deduplication technology. By generating deduplication tags via edge servers, this technology achieves a key breakthrough in "deduplication without decryption." Traditional cloud-based deduplication requires decrypting data to extract fingerprints, posing a serious risk of privacy breaches. In this approach, however, the edge server performs XOR operations solely on ciphertext components, eliminating the need to parse plaintext. The generated deduplication tags contain only hash value differences. The cloud verifies the deduplication tags for equivalence testing without ever touching the plaintext, ensuring user data privacy.

[0030] Finally, the present invention introduces the bilinear Diffie-Hellman (DBDH) assumption into the edge-assisted encryption scenario for the first time, and ensures the indistinguishability (IND-CPA) and one-wayness (OW-CPA) of the scheme under chosen-plaintext attacks through rigorous formal proofs (Theorem 1, Theorem 2), and constructs a theoretical security boundary. Specifically, the scheme reduces security to the difficulty of the DBDH problem - if the adversary can distinguish ciphertexts or recover plaintexts with a non-negligible advantage, this advantage can be used to solve the DBDH problem, which contradicts the known cryptographic assumptions. This design enables the scheme to ensure the unrecoverability of plaintexts even when the edge nodes are partially trusted (such as in scenarios where an internal attacker obtains the private key of the edge server). At the same time, the scheme of the present invention achieves deep synergy between security proof and engineering efficiency by optimizing the ciphertext structure (containing only three lightweight components (C1, C2, C3)) and the computing process (no pairing operation on the terminal and no decryption operation on the cloud).

[0031] In summary, the present invention outperforms similar solutions in key indicators such as encryption efficiency and communication overhead, providing a complete solution for AIoT data sharing that is "theoretically secure and provable, and engineering efficient and feasible", with significant technological leadership and industrial application value. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, without paying any creative work, other drawings obtained based on these drawings still fall within the scope of the present invention.

[0033] Figure 1 The overall framework layout of the system model in one embodiment of the present invention is shown;

[0034] Figure 2 The figure shows a comparison of communication costs among several solutions in one embodiment of the present invention;

[0035] Figure 3The figure shows a comparison of encryption time in RP of several schemes in one embodiment of the present invention;

[0036] Figure 4 The figure shows the comparison of decryption time in a PC of several schemes in one embodiment of the present invention;

[0037] Figure 5 Shown is a comparison of the total time of several solutions in one embodiment of the present invention;

[0038] Figure 6 The figure shows the comparison of encryption number ratios of several schemes in one embodiment of the present invention. DETAILED DESCRIPTION

[0039] The preferred embodiments of the present invention will be described in detail below so that the purpose, features and advantages of the present invention can be more clearly understood. It should be understood that the following embodiments are not intended to limit the scope of the present invention, but are only intended to illustrate the essential spirit of the technical solution of the present invention.

[0040] In the following description, for the purpose of illustrating the various disclosed embodiments, certain specific details are set forth in order to provide a thorough understanding of the various disclosed embodiments. However, those skilled in the relevant art will recognize that the embodiments may be practiced without one or more of these specific details. In other cases, well-known techniques associated with this application may not be shown or described in detail to avoid unnecessarily obscuring the description of the embodiments.

[0041] Reference throughout this specification to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, the appearances of "in one embodiment" or "in an embodiment" in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any manner in one or more embodiments.

[0042] Example 1:

[0043] The meanings of the parameters that may be involved in the following specific implementation process are as follows:

[0044] K: safety parameter;

[0045] The multiplicative cyclic group of prime order q;

[0046] Bilinear target group;

[0047] e: Bilinear pairing operation, i.e. mapping Mathematical operations;

[0048] The multiplicative group modulo q, i.e., the group consisting of positive integers coprime to q, which in the present invention is the set of positive integers between 1 and q;

[0049] Params: public parameters, i.e. the set of cryptographic parameters disclosed globally by the system;

[0050] g, Q: group The two generators of can generate the entire group through exponentiation Primitive Element;

[0051] H1, H2: Two global collision-resistant hash functions, i.e. cryptographic hash functions that resist collision attacks, acting on the entire system;

[0052] sk u , pk u : The public and private key pair of the data user (DU), where sk u is the private key (SecretKey ofUser), pk u is the public key (PublicKey ofUser);

[0053] sk s , pk s : The public and private key pair of the edge server (ES), where sk s is the edge server private key, pk s is the public key;

[0054] Y u , Y s : Edge auxiliary encryption parameters, i.e., auxiliary encryption parameters generated by the edge server through bilinear pairing;

[0055] M: plaintext message, i.e. the original data to be encrypted;

[0056] T: edge-assisted deduplication parameter, used as a label for ciphertext equivalence testing, generated by the edge server;

[0057] C, C′: Ciphertext used for equivalence testing, that is, encrypted text that supports duplication detection without decryption.

[0058] 1. Definition of Cryptography

[0059] Definition 1 (bilinear pairing): denoted as It involves two groups and Mathematical operations, where is an additive group of order q, and is a multiplicative group of the same order. A function e is called bilinear if it satisfies the following properties:

[0060] 1) Bilinear: For all P, and,

[0061] 2) Non-degeneracy: There exists P, And e(P,Q)≠1.

[0062] 3) Computability: For all P, There exists an efficient algorithm to compute e(P,Q).

[0063] Definition 2 (Decisional Bilinear Diffie-Hellman (BDH) Problem): Let is a bilinear pairing defined above. Given a tuple (P, aP, bP, cP, X), where P is The generator of , and Determine whether

[0064] 2. System Model

[0065] like Figure 1 As shown in the figure, the solution proposed in this invention consists of five entities, including AIoT devices, edge servers (ES), cloud servers (CS), key generation centers (KGC), and data users (DU).

[0066] AIoT devices are responsible for data generation, possessing perception and secure communication capabilities, performing basic encryption, and intelligently offloading complex computations. Edge servers (ES) connect devices to the cloud, handling intensive tasks and initial data deduplication, reducing latency and protecting data privacy. Cloud servers (CS) store data and perform final deduplication. KGC manages system passwords and key distribution. Data users (DUs) securely access and decrypt data in the cloud using their unique private keys.

[0067] 3. Basic Framework of This Example

[0068] The solution proposed in this embodiment includes the following six algorithms or steps:

[0069] Set(K)→Params: Given a security parameter K, the algorithm outputs public key parameters Parms.

[0070] User key generation KeyGen-User(Params)→(pku, sku): Given the public key parameters Parms, the algorithm outputs the public-private key pair of DU.

[0071] Edge server key generation KeyGen-Server(Params)→(pks, sks): Given the public key parameters Parms, the algorithm outputs the ES's public-private key pair.

[0072] Edge-AssistedEncrypt(Parms, pk u , pk s )→(Y u , Y s ): Given public key parameters Parms, DU's public key pk u And ES's public key pk s , the system outputs edge-assisted encryption parameters.

[0073] Encrypt(Params, M, Y u , Y s )→(C): Given public key parameters Params, plaintext message M, DU's public key pk u , and ES's public key pk s , the algorithm outputs the ciphertext C.

[0074] Edge-assisted deduplication AssisteDeduplicate(Params, C, C′)→(T): Given the public key parameters Params and two ciphertexts C and C′ for equality testing, the algorithm outputs the edge-assisted deduplication parameter T.

[0075] Deduplicate(Params, C, C′) → (0, 1): Given public parameters Params and two ciphertexts C and C′, the algorithm determines whether the ciphertexts C and C′ are equal. If they are equal, C′ is deleted and C is retained; otherwise, C′ and C are stored.

[0076] Decrypt(Params, C, sku) → (M): Given the public key parameters Params, the ciphertext M and the DU's private key sk u , the algorithm outputs the plaintext message M.

[0077] 4. Security Model and Implementation of Actual Attacks

[0078] The security model of the solution proposed in this embodiment is introduced through a two-type game, which simulates the adversary's ability to obtain capabilities through different types of queries. There are two types of adversaries: (1) A1 is a malicious external attacker, and (2) A1 is a malicious internal attacker who can obtain the private key sk of the cloud server. s .

[0079] Definition 3 (IND-CPA): The proposed scheme achieves indistinguishability under chosen-plaintext attacks if there exists no probabilistic polynomial-time adversary that can win the following security game with a non-negligible advantage.

[0080] Game 1: The game is defined by the confrontation between challenger C and adversary A1.

[0081] Initialization: After executing the setup algorithm, challenger C obtains (pk u ,sk u ) and (pk s ,sk s ). Challenger C vs. (sk u ,sk s ) is kept secret and provided to the adversary A1 (Parms, pk u , pk s ).

[0082] Query: Adversary A1 adaptively performs polynomially bounded queries as follows:

[0083] Edge Assisted Parameter Query Edge :Adversary A1 submits a tuple (Params, pk u , pk s ), Challenger C returns (Y u , Y s ).

[0084] Encrypted Query O En :Adversary A1 submits a tuple (Params, M, Y u , Y s ), Challenger C

[0085] Returns a ciphertext T.

[0086] Challenge: Adversary A1 submits two messages of equal length (M0, M1) to Challenger C, and Challenger C returns the challenge ciphertext Give adversary A1, where ξ∈{0,1}.

[0087] Guess: A1 outputs a bit value ξ′∈{0,1}, and wins if ξ′=ξ.

[0088] A1's strengths are defined as:

[0089]

[0090] If for all probabilistic polynomial time (PPT) adversaries A 1, is negligible, then the scheme is secure under chosen-plaintext attack (IND-CPA).

[0091] In the above scheme, adversary A1 attempts to guess which message challenger C is encrypting. Winning is determined by comparing its guess with the actual message. A1's advantage is measured by calculating the absolute value of the difference between the probability of the adversary guessing correctly and a random guess (with a probability of 1 / 2). If this advantage is negligible, it means it is difficult for the adversary to distinguish the encrypted message through an attack, indicating that the scheme is highly secure against chosen-plaintext attacks.

[0092] Definition 4 (OW-CPA): If no probabilistic polynomial-time adversary A2 can win the following security game with a non-negligible advantage under a chosen-plaintext attack, then the proposed scheme achieves one-wayness.

[0093] Game 2: This game is defined by the confrontation between challenger C and adversary A2.

[0094] Initialization: After executing the setup algorithm, challenger C obtains (pk u ,sk u ) and (pk s ,sk s ), Challenger C vs. sk u Keep it confidential and (Params, pk u , pk s ) and CS private key sk s Provided to adversary A2.

[0095] Query: Adversary A2 adaptively performs polynomially bounded queries as follows:

[0096] Edge Assisted Parameter Query Edge :Adversary A2 submits a tuple (Params, pk u , pk s ), Challenger C returns (Y u , Y s ).

[0097] Deduplication tag query Dedup-T : Adversary A2 submits a tuple (Params, C, C′), and challenger C returns a ciphertext T.

[0098] Encrypted Query O En :Adversary A2 submits a tuple (Params, M, Y u , Y s ), the challenger C returns a ciphertext T.

[0099] Challenge: Challenger C randomly selects a message M * ∈{0,1} n , and calculate the ciphertext C * , then C* Return to adversary A2.

[0100] Output: Adversary A2 outputs message M′∈{0,1} n , if M′=M * , then win.

[0101] The advantage of adversary A2 is defined as:

[0102]

[0103] If for all probabilistic polynomial time (PPT) adversaries A2, their advantage are all negligible, then the scheme has one-way security under chosen-plaintext attacks (OW-CPA security).

[0104] The following section provides a specific edge-assisted encryption and data deduplication solution of this embodiment.

[0105] The specific implementation process of the plan is as follows:

[0106] Set (K) → Params: Let K be the security parameter in the system. and is a multiplicative cyclic group modulo prime numbers q ≥ 2K, where g and Q are The system selects two globally collision-resistant hash functions:

[0107]

[0108] H2: {0,1}*→{0,1} n .

[0109] Finally, the algorithm publishes the system parameters as follows:

[0110]

[0111] KeyGen-User(Params)→(pk u ,sk u ): The key generation algorithm takes Params as input and selects a random number As the private key sk u , and calculate As the public key pk u ,in Indicates randomly selecting an element from the set. The output public and private key pair is:

[0112] sk u =x u 、pk u =y u .

[0113] KeyGen-Server(Params)→(pk s ,sk s ): This step algorithm takes the system parameter Params as input and selects a random number As the private key sk s , and calculate As the public key pk s . It outputs the public-private key pair as follows:

[0114] sk s =x s 、pk s =y s .

[0115] Edge-assisted encryption (Params, pk u , pk s )→(Y u , Y s ):In order to reduce the computing burden of AIoT devices, ES is responsible for performing pairing calculations. This step uses the public key of DU and ES's public key As input, it outputs the tuple (Y u , Y s )as follows:

[0116]

[0117] Encrypt(Params, M, Yu, Ys) → (C): Received tuple (Y u , Y s ), the AIoT device executes the encryption algorithm. The algorithm uses the message M∈{0,1} n and tuple (Y u , Y s ) as input, and then choose a random number Output tuple C = (C1, C2, C3):

[0118] C1=(g r ),

[0119]

[0120] Among them, C1 provides a randomization factor to ensure the uniqueness of each encrypted ciphertext; C2 implements lightweight mask encryption of plaintext, relying on C1 and Y u The generated hash value; C3 provides support for deduplication function, generates deduplication tag T by XOR with C3', and protects the plaintext summary through double-layer hashing.

[0121] Edge-assisted deduplication (Params, C, C′) → (T): Receive two ciphertexts (C, C′), where C = (C1, C2, C3) and C′ = (C1′, C2′, C3′), ES calculates to replace C3 and C3′. The algorithm then outputs the updated ciphertext:

[0122] C=(C1,C2,T),

[0123] C′=(C1′, C2′, T).

[0124] In calculation It should be noted that if M=M′, the expression is simplified to:

[0125]

[0126] The key point here is that by delegating the deduplication process to ES, the computation avoids directly manipulating the plaintext messages M and M′, thereby significantly enhancing security and protecting sensitive data.

[0127] Deduplication (Params, C, C′) → (0, 1): After receiving the updated ciphertext (C, C′), CS performs the following steps to determine whether deduplication can be performed:

[0128]

[0129] in, If the equality holds, the algorithm deletes C′ and keeps C; otherwise, it saves C and C′.

[0130] Decryption(Params, C, sk u )→(M): Once the data user (DU) downloads the ciphertext C=(C1, C2, C3), the DU’s private key sk u Complete decryption. The algorithm takes the system parameters Params, ciphertext C and private key sku as input, and calculates Get the plaintext M.

[0131] In the above scheme, decryption must rely on the private key sk of the legitimate user u , ensuring that only authorized users can recover the plaintext, resisting external attackers and some internal attacks. In addition, using the mathematical properties of bilinear pairing, the random number r in the ciphertext is combined with the user's private key sk u Combined, they form a hash input consistent with the encryption input, ensuring the correctness of decryption. The decryption process only involves one bilinear pairing, one hash operation, and one XOR operation, with low computational complexity, making it suitable for resource-constrained AIoT devices.

[0132] The solution proposed in this invention is explained below through a formal cryptographic proof.

[0133] Theorem 1: Assuming that the bilinear Diffie-Hellman (DBDH) problem is hard, the proposed scheme is secure under chosen-plaintext attack (IND-CPA).

[0134] Proof: Let (g,g a ,g b ,g c ) is an instance of the BDH problem. When the challenger C simulates a secure game for the adversary A1, he will calculate X=e(g,g) abc .

[0135] Initialization: Set Q = g a , pk u =g b , randomly selected calculate Challenger C executes the system initialization algorithm Setup to obtain the parameters:

[0136]

[0137] And (Params, pk u ,pk s ) is returned to adversary A1.

[0138] Query phase: Adversary A1 adaptively executes the following queries and maintains a list to record the responses.

[0139] Edge Assisted Parameter Query Edge :Adversary A1 submits tuple (Params, pk u , pk s ), Challenger C calculates:

[0140] Y u =e(pk u ,Q)

[0141] Y s =e(pku,Q).

[0142] Then (Y u ,Y s ) is returned to adversary A1.

[0143] Encrypted Query O En :Adversary A1 submits tuple (Params, M, Y u , Y s ), challenger C randomly selects And calculate:

[0144] C1=(gr ),

[0145]

[0146] Then return the ciphertext C = (C1, C2, C3).

[0147] Challenge phase: Adversary A1 submits a message pair (M0, M1) of equal length that meets the requirements of Game 1. Challenger C randomly selects ξ∈{0,1} and calculates the challenge ciphertext C * :

[0148] C1 * =g c ,

[0149]

[0150] Guessing phase: Adversary A1 outputs a guessed bit value ξ′∈{0,1}. If ξ=ξ′, challenger C returns “1”, otherwise it returns “0”.

[0151] Solve the DBDH problem: If X = e(g,g) abc ,but:

[0152]

[0153] Theorem 2. Assuming that the bilinear Diffie-Hellman (DBDH) hypothesis is hard, then the scheme is one-way under chosen-plaintext attacks (OW-CPA security).

[0154] Proof: Let (g,g a ,g b ,g c ) is an instance of the BDH problem. Challenger C will calculate X =

[0155] e(g,g) abc , and simulate a security game against adversary A1.

[0156] Initialization: Challenger C sets Q = g a , pk u =g b ,choose

[0157] calculate Challenger C executes Setup to obtain Then return (Params, pk u , pk s ) and the private key sk of the cloud server s =x s Give your opponent A2.

[0158] Query: Adversary A2 adaptively runs the following queries and maintains corresponding lists to record responses.

[0159] Edge auxiliary parameter query (O Edge ): Adversary A2 submits a tuple (Params, pk u , pk s ), Challenger C calculates:

[0160] Y u =e(pk u ,Q)

[0161] Y s =e(pku,Q).

[0162] Then (Y u ,Y s ) is returned to adversary A2.

[0163] Deduplication tag query (O Dedup-T ): Adversary A2 submits a tuple (Parms, C, C′), and challenger C returns

[0164] Encrypted Query (O En ): Adversary A2 submits a tuple (Params, M, Y u , Y s ), Challenger C from Pick a random number r from And calculate:

[0165] C1=g r ,

[0166]

[0167] Then return the ciphertext C.

[0168] Challenge: Challenger C randomly selects a message M*∈{0,1} n , and calculate the following ciphertext C*.

[0169] C1 * =g c ,

[0170]

[0171] Output: Adversary A2 submits message M′∈{0,1}n. If M′=M*, challenger C returns “1”. Otherwise, it returns “0”.

[0172] Solve the DBDH problem: If X = e(g,g) abc ,but:

[0173]

[0174] The following content analyzes the performance of the solution proposed in the present invention through theoretical analysis and actual simulation experiments in combination with comparison with existing technologies.

[0175] Limited computing power is a significant constraint in secure data sharing systems. To this end, this paper evaluates the performance of the scheme using two key metrics: computational efficiency and communication cost. Four bilinear pairing-based encryption schemes are compared and analyzed: CWJZ (L. Cheng, Q. Wen, Z. Jin, and H. Zhang, “Cryptanalysis and improvement of a certificateless encryption scheme in the standard model,” Frontiers of Computer Science, vol. 8, 2014, pp. 163–173.), CT (S. Canard and VCTrinh, “Certificateless public key cryptography in the standard model,” 2014 Fundamenta informaticae, vol. 161, 2018, pp. 219–248.), and DXH (L. Deng, T. Xia, and X. He, “Provably secure certificateless encryption scheme in the standard model,” KSII Transactions on Internet and Information Systems (TIIS), vol. 14, 2020, pp.

[0176] 2534–2553.) and ZDT (M. Zhao, Y. Ding, S. Tang, H. Liang, C. Yang, and H. Wang, "Dualserver certificateless public key encryption with authorized equality test for outsourced iot data," Journal of Information Security and Applications, vol. 73, 2023, p. 103441.).

[0177] The benchmark evaluates four computationally intensive operations: bilinear pairing (Bp), Group scalar multiplication (Esm), Group Exponential Operation (Psm) and Hash-to-Point Mapping Cryptography parameters are configured as follows: Bilinear group and Using 1024-bit security strength, multiplication group is 160 bits, and the plaintext and hash value |l| are 256 bits.

[0178] like Figure 2-6 As shown, first of all, from the perspective of communication cost comparison, through the analysis of the four schemes, the scheme of the present invention shows significant advantages. In the comparison scheme, the ciphertext size of CWJZ is Byte, CT is Bytes, DXH is Byte, ZDT is In comparison, the solution of the present invention only requires bytes, which is 45% lower than the most efficient ZDT solution. Figure 2 As shown, it is shown that the solution of the present invention has significant advantages in communication overhead.

[0179] Secondly, in terms of computational efficiency, the proposed solution slightly outperforms DXH in encryption efficiency and also adds edge-assisted deduplication. Decryption efficiency is comparable to DXH but significantly higher than ZDT. Simulation experiments show that the proposed solution is 6.3 times faster than ZDT and reduces total computational cost by 89%. While maintaining basic performance, the proposed solution integrates advanced edge deduplication capabilities, providing an optimal solution for AIoT data sharing.

[0180] To verify the performance of our solution in a real-world computing environment, we designed a systematic experimental evaluation. The test platform consisted of a Raspberry Pi 4B (Raspbian system, Cortex-A72 1.5GHz processor, 8GB of RAM) to simulate a resource-constrained AIoT device, and a PC (Intel i5-9500 processor, 8GB of RAM) to simulate a data user. The benchmark test results for each operation on the device are shown in Table 1 below.

[0181] Table 1: Timeline of each operation running on the device (ms)

[0182]

[0183] The experiment used a Raspberry Pi (RP) as the encryption node and a PC as the decryption node to evaluate the performance advantages of the proposed scheme in computationally intensive cryptographic operations. The results showed that after 100 repeated tests, the proposed scheme achieved encryption time of 13.15ms and decryption time of 3.39ms, representing an 89% reduction in encryption overhead compared to the ZDT scheme. Figure 3 and Figure 4The time distribution data further validates the advantages and confirms the practical value of the present invention in resource-constrained environments.

[0184] Performance Results( Figure 5 and Figure 6 ) shows that when the number of ciphertexts increases from 1 to 50, the encryption time ranges for schemes CWJZ, CT, DXH, and ZDT are 30.65–1450ms, 46.78–2289ms, 65.16–3156ms, and 126.96–6315ms, respectively, while the proposed method maintains a linear growth rate (12.08–672ms). The advantage becomes more pronounced with larger data volumes, and this scalability makes the proposed method particularly suitable for large-scale AIoT data encryption scenarios.

[0185] Therefore, the present invention significantly improves both communication efficiency and computing performance. Its innovation lies in combining edge-assisted encryption with deduplication, creating advantages that traditional solutions cannot match.

[0186] Anything not described in detail in the present invention is well known to those skilled in the art.

[0187] The basic principles, main features, and advantages of the present invention are shown and described above. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely illustrative of the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.

Claims

1. An edge-assisted lightweight deduplication encryption method, characterized in that: This method builds an edge-assisted hierarchical collaborative architecture, which offloads computationally intensive operations such as bilinear pairing to edge servers, allowing resource-constrained AIoT devices to only perform lightweight hashing and XOR operations. Furthermore, the edge server generates deduplication tags based on the ciphertext, enabling the cloud to achieve efficient deduplication through ciphertext equivalence testing without decryption. In addition, a bilinear assumption is used to build a security model, and the indistinguishability IND-CPA and one-way OW-CPA under chosen-plaintext attacks are achieved through formal proof, ensuring that even if the edge node is compromised, the plaintext cannot be inferred.

2. The edge-assisted lightweight deduplication encryption method according to claim 1, characterized in that: The method comprises one or a combination of the following steps: S1, initialization and key generation: Generate system public parameters based on bilinear pairing, and generate public and private key pairs for AIoT devices and edge servers respectively; S2, edge-assisted parameter calculation: The edge server calculates the edge-assisted encryption parameter (Y) based on the user's public key and its own public key. u ,Y s ) and returns it to the AIoT device; S3, data encryption: The AIoT device uses edge-assisted encryption parameters and random numbers to perform lightweight encryption on the plaintext and generate ciphertext C = (C1, C2, C3); S4, deduplication label generation: The edge server receives two ciphertexts and calculates the edge-assisted deduplication label Update ciphertext; S5, cloud-based ciphertext deduplication: The cloud server verifies the deduplication tag, determines whether the ciphertext is duplicated, and performs deduplication without decryption; S6, data decryption: The data user uses the private key to recover the plaintext from the ciphertext.

3. The edge-assisted lightweight deduplication encryption method according to claim 2, characterized in that: The bilinear pairing Satisfies bilinearity, non-degeneracy and computability, where is the additive cyclic group, is a multiplicative cyclic group of the same factor.

4. The edge-assisted lightweight deduplication encryption method according to claim 2, characterized in that: The edge-assisted encryption parameter (Y u ,Y s ), the edge server replaces the AIoT device with high computational complexity operations through bilinear pairing operations, reducing the encryption computation complexity of the AIoT device to O(1) hash and XOR operations.

5. The edge-assisted lightweight deduplication encryption method according to claim 2, characterized in that: In the data encryption step, the AIoT device uses an XOR operation to combine the plaintext M with the hash value Combined to generate C2, the hash value is converted into Combined with H2(M) to generate C3, it avoids complex exponential operations and key management.

6. The edge-assisted lightweight deduplication encryption method according to claim 2, characterized in that: The generation of the edge-assisted deduplication label T only relies on the XOR operation of the ciphertext components C3 and C3', without parsing the plaintexts M and M', ensuring that the deduplication process is completed in the ciphertext domain without leaking privacy.

7. The edge-assisted lightweight deduplication encryption method according to claim 2, characterized in that: In the cloud ciphertext deduplication step, the cloud server uses the edge server private key sk s Perform ciphertext equivalence testing, verify the validity of T through bilinear pairing and hash operations, and achieve zero-knowledge deduplication.

8. The edge-assisted lightweight deduplication encryption method according to claim 2, characterized in that: This method satisfies the indistinguishability under chosen plaintext attacks (IND-CPA) and one-way properties (OW-CPA), and proves the adversary's advantage by reducing it to the hardness of the bilinear Diffie-Hellman (DBDH) problem. and are all negligible functions.

9. An electronic device, characterized in that: include: at least one processor; a memory communicatively coupled to the at least one processor; The memory stores a computer program, which, when executed by the at least one processor, enables the at least one processor to implement the edge-assisted lightweight deduplication encryption method according to any one of claims 1 to 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed, the edge-assisted lightweight deduplication encryption method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Efficient deduplication lightweight online file storage method and device

    CN111966649A

  • Cloud data deduplication method based on edge cloud collaboration

    CN114499843A

  • Lightweight certificateless edge-assisted encryption method and system

    CN118764296A

  • Secure hierarchical repeating data processing method for edge-assisted cloud

    CN119885260A

  • Lightweight attribute-based signcryption method for cloud and fog-assisted internet of things

    WO2021190453A1