Location confidentiality judgment method for mobile node and elliptical restricted area in Internet of Things

The confidentiality judgment of the relationship between point and ellipse position through homomorphic encryption and Paillier algorithm is achieved, which solves the problems of location privacy leakage and malicious attacks in traditional solutions, and provides an efficient and secure position determination method, which is suitable for the elliptical restricted area judgment of mobile nodes in the Internet of Things.

CN120529314AActive Publication Date: 2025-08-22INNER MONGOLIA UNIV OF SCI & TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510838118.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-08-22
Estimated Expiration
2045-06-23

AI Technical Summary

Technical Problem

Traditional geofences or location determination solutions fail to effectively protect the location privacy of mobile nodes and are vulnerable to malicious attacks, threatening the security and stability of the Internet of Things.

Method used

Homomorphic encryption technology is adopted, and the Paillier encryption algorithm is used to conduct confidential communication of data from mobile nodes and elliptical restriction areas. The confidentiality judgment of the relationship between point and elliptical position is achieved through the polynomial substitution method, and a protocol under semi-honest and malicious models is designed to resist malicious attacks.

Benefits of technology

It realizes accurate determination of the relationship between points and ellipses without leaking location information, effectively resists malicious attacks, improves judgment efficiency and ensures privacy protection, and is suitable for circular and elliptical restricted areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120529314A_ABST
    Figure CN120529314A_ABST
Patent Text Reader

Abstract

The invention discloses a mobile node and elliptical restricted area position secrecy judgment method in the Internet of Things, and belongs to the technical field of restricted area position secrecy judgment. The problem that privacy protection cannot be effectively achieved through a traditional geo-fencing or position judgment scheme is solved. The method comprises the following steps: marking a mobile node in the Internet of Things, which needs to be judged, as Alice, and marking an elliptical restricted area as Bob; alice calculates according to a position point P0 (x0, y0) where Alice is located to obtain # imgabs0 # selection random numbers, encrypts # imgabs1 # imgabs2 # x0, y0, 1 by using a public key of Alice based on homomorphic encryption to obtain parameters c1-c5, and sends the parameters c1-c5 to Bob; based on a homomorphic encryption technology, the Bob realizes secret communication with the Alice by utilizing elliptic equation coefficients A, B, C, D and E of the elliptic confinement area, and further judges whether the position point P0 of the Alice is in an ellipse P corresponding to the elliptic confinement area.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a method for determining the confidentiality of a restricted area position. Background Art

[0002] With the booming Internet of Things (IoT), mobile nodes have become the core hubs for efficient collaboration in various intelligent systems. For example, automated guided vehicles (AGVs) efficiently navigate large warehouses, precisely completing cargo transportation and sorting tasks. Connected vehicles, leveraging V2X communication and edge computing platforms, can perceive the surrounding traffic environment in real time, make collaborative decisions, and execute autonomous driving operations, ensuring safe and reliable road travel. Furthermore, livestock wearing wearable devices integrating GPS, environmental, and vital sign sensors can monitor their location and health in real time, facilitating precise feeding management and electronic fencing control. However, the routes and operating areas of these mobile nodes often involve core corporate secrets or sensitive assets, such as high-value asset storage areas. Leaking their node coordinates and area boundaries poses a serious threat to corporate security and business operations. Especially in specialized scenarios, such as high-end electronic component warehouses, a higher level of confidentiality is required for mobile node location information and the scope of restricted areas.

[0003] However, traditional geofencing or location determination schemes often fail to consider privacy protection. Spatial relationship calculations directly expose the precise coordinates and boundaries of mobile nodes, posing serious security risks. When a mobile node needs to determine its positional relationship with an elliptical restricted area, conventional computation methods can not only leak its own location and area information, but also, due to the lack of effective security mechanisms, allow malicious attackers to falsify determination results or maliciously disrupt normal processes, thereby threatening the stability and security of the entire Internet of Things. Therefore, developing a solution that can accurately determine the positional relationship between a mobile node and an elliptical restricted area while effectively protecting location privacy is of paramount practical significance for the secure and trustworthy development of the Internet of Things. The introduction of secure multi-party computation technology has opened up a new path to address this challenge. Since Yao proposed this concept in 1982, numerous scholars, such as Goldreich and Cramer, have conducted in-depth research on it, driving the field's continued development both theoretically and practically. Currently, its research covers a wide range of key areas, including confidential data mining, computational geometry, set operations, and scientific computing, providing a solid theoretical foundation and technical support for data privacy protection and collaborative computing needs across various industries.

[0004] In the Internet of Things, determining whether a mobile node is within an ellipse-restricted area is essentially a matter of determining the positional relationship between a point and the ellipse. Traditional methods include distance comparison, vector methods, and polynomial algebra. The distance comparison method, based on the first definition of an ellipse, compares the sum of the distances from a point to its two foci with a fixed value. The vector method calculates the vector from the ellipse's center to the point, analyzes its angle with the major and minor axes, and compares its modulus with the axis length. The polynomial algebra method directly substitutes the point coordinates into the ellipse equation. To ensure privacy, the problem is structured as a two-party scenario: one party holds the point coordinates, and the other holds the ellipse parameters. Both parties must perform secure collaborative computation to determine the position without leaking the original data, and the result must not reveal any characteristics of the original data. Li SD et al. calculated the relationship between the distance from a point to the two foci of the ellipse and a fixed value based on the distance comparison method, but the protocol was inefficient. Zhu H et al. constructed a point-circle position determination protocol based on a secure two-party computation framework. This protocol, utilizing a cosine value calculation scheme, achieves a lightweight design, circumventing complex cryptographic operations while also exposing the geometric adaptability limitations of ellipses. Zhang W et al. innovatively established a mapping relationship between spatial distances and solutions to algebraic equations, using an optimized inner product protocol to solve various spatial position relationship determination problems. This scheme, which does not use public-key cryptography, falls within the realm of information-theoretic security, but is vulnerable to attacks by malicious adversaries. Summary of the Invention

[0005] The present invention aims to solve the problem that traditional geo-fencing or location determination solutions cannot effectively protect privacy.

[0006] A method for determining the confidentiality of the position of a mobile node and an elliptical restricted area in an Internet of Things. The mobile node to be determined in the Internet of Things is denoted as Alice, and the elliptical restricted area is denoted as Bob. Alice calculates the confidentiality of the position of a mobile node and an elliptical restricted area based on her own position point P0(x0,y0). Select a random number and encrypt it with your own public key based on homomorphic encryption x0, y0, 1 obtain parameters c1-c5 and send them to Bob; based on homomorphic encryption technology, Bob uses the elliptic equation coefficients A, B, C, D, E of the elliptical restriction area to achieve confidential communication with Alice, and then determine whether Alice's position point P0 is within the ellipse P corresponding to the elliptical restriction area.

[0007] Furthermore, the specific implementation process of the method includes the following steps:

[0008] (a) The mobile node in the Internet of Things that needs to be judged is recorded as Alice, and the elliptical restricted area is recorded as Bob; Alice calculates based on her own position point P0(x0,y0) Select a random number r and encrypt it with your own public key based on homomorphic encryption x0, y0, 1 get parameters c1-c5 and send them to Bob;

[0009] (b) Bob calculates Send to Alice;

[0010] (c) Alice decrypts c6 to obtain And send it to Bob; if d<0, then point P0 is inside the ellipse P; if d=0, then point P0 is on the boundary of the ellipse P; if d>0, then point P0 is outside the ellipse P.

[0011] Furthermore, in step (a), Alice selects a random number r and encrypts it with her public key based on homomorphic encryption. The process of x0, y0, and 1 is encrypted using the Paillier encryption algorithm, and the obtained parameters c1-c5 are as follows:

[0012] c5=g 1 r N modN 2 ; N is the public key modulus in the Paillier encryption algorithm.

[0013] Alternatively, the specific implementation process of the method includes the following steps:

[0014] (1) The mobile node in the Internet of Things that needs to be judged is recorded as Alice, and the elliptical restricted area is recorded as Bob; Alice calculates based on her own position point P0(x0,y0) Select a random number r1 and encrypt it with your own public key based on homomorphic encryption x0, y0, 1 get parameters c1-c5 and send them to Bob; Bob selects a random number r2 and encrypts the elliptic equation coefficients A, B, C, D, E of the elliptic restriction area with his own public key based on homomorphic encryption to get parameters c6-c 10 Alice and Bob use the same homomorphic encryption method.

[0015] (2) Alice’s calculation Send to Bob, Bob calculates Send to Alice;

[0016] (3) Alice decrypts c 12 Obtaining d1, Bob decrypts c 11 Get d2;

[0017] (4) Alice and Bob each select n random numbers a i ,b i , i=1,...,n, and calculated using the public key of their respective homomorphic encryption algorithms and publish it;

[0018] (5) Using the split-selection method, Alice and Bob each select n groups of and Select n / 2 groups each and After Bob and Alice announce b i d2 and a i After d1, both parties verify. If both parties pass the verification, the protocol will continue to execute. If one party verifies differently, the protocol will be terminated.

[0019] (6) Alice and Bob each choose from the remaining n / 2 groups and Randomly select one and And select a, b;

[0020] (7) Alice uses ad1 to obtain c based on the homomorphic encryption algorithm b , sent to the other party; Bob uses bd2 based on the homomorphic encryption algorithm to obtain c a , sent to the other party;

[0021] (8) Alice obtains m through the decryption process based on the homomorphic encryption algorithm. a And announced that Bob obtains m through the decryption process based on the homomorphic encryption algorithm b and publish;

[0022] (9) Alice and Bob use zero-knowledge proof to verify and If one party cannot provide a valid proof, it will be judged as a malicious participant and the protocol will be terminated; λ a is Alice’s private key in the Paillier encryption algorithm, λ b The private key in the Paillier encryption algorithm corresponding to Bob;

[0023] (10) If the proof passes, Alice and Bob obtain the calculated values ​​d1 and d2; if d1 = d2 < 0, then point P0 is inside the ellipse P; if d1 = d2 = 0, then point P0 is on the boundary of the ellipse P; if d1 = d2 > 0, then point P0 is outside the ellipse P.

[0024] Furthermore, in step (1), Alice selects a random number r1 and encrypts it with her own public key based on homomorphic encryption. The process of x0, y0, and 1 is encrypted using the Paillier encryption algorithm, and the obtained parameters c1-c5 are as follows:

[0025] g a The module in the public key of the Paillier encryption algorithm corresponding to Alice The elements of the multiplication group under a is the modulus of the public key in the Paillier encryption algorithm corresponding to Alice. Alice’s public key is (g a ,N a ), λ a It is the private key in the Paillier encryption algorithm corresponding to Alice.

[0026] Furthermore, in step (1), Bob selects a random number r2 and encrypts the coefficients A, B, C, D, and E of the elliptical equation of the elliptical restricted area with his own public key based on homomorphic encryption. The Paillier encryption algorithm is used to encrypt the obtained parameters c6-c 10 as follows:

[0027] g b The module in the public key of the Paillier encryption algorithm corresponding to Bob The elements of the multiplication group under b is the modulus of the public key in the Paillier encryption algorithm corresponding to Bob. Bob’s public key is (g b ,N b ), λ b It is Bob's private key in the Paillier encryption algorithm.

[0028] Furthermore, in step (4), Alice and Bob each select n random numbers a i ,b i , and calculated using the public key of their respective homomorphic encryption algorithms

[0029] Furthermore, in step (5), after Bob and Alice announce b i d2 and a i After d1, both parties verify and

[0030] Furthermore, in step (7), Alice uses ad1 to obtain c b and c obtained by Bob using bd2 a as follows:

[0031]

[0032] Furthermore, in step (8), Alice obtains m through the decryption process based on the homomorphic encryption algorithm.a , Bob obtains m through the decryption process based on the homomorphic encryption algorithm b The process is as follows:

[0033] Alice and Bob use λ a and λ b calculate and λ a is Alice’s private key in the Paillier encryption algorithm, λ b It is Bob's private key in the Paillier encryption algorithm.

[0034] Beneficial effects:

[0035] This paper proposes a scheme for determining the confidentiality of the positional relationship between a point and an arbitrary ellipse. This scheme can effectively solve the problem of determining the confidentiality of the positional relationship between a mobile node and an arbitrary elliptical restricted area in the Internet of Things. Furthermore, since a circle is a special case of an ellipse, this scheme is also applicable to determining the confidentiality of circular restricted areas.

[0036] This paper designs an efficient confidentiality determination protocol for the positional relationship between a point and an ellipse under a semi-honest model. This protocol, based on the polynomial substitution method, improves determination efficiency. A confidentiality determination protocol for the positional relationship between a point and an ellipse under a malicious model is also designed. This protocol effectively resists attacks from malicious adversaries, avoids privacy leaks and misjudgments, and provides correctness analysis and security proof for the protocol. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 Schematic diagram of P0 inside the ellipse P.

[0038] Figure 2 Schematic diagram of P0 on the boundary of ellipse P.

[0039] Figure 3 Schematic diagram of P0 outside the ellipse P.

[0040] Figure 4 The logical diagram of the ellipse position relationship confidentiality determination protocol. DETAILED DESCRIPTION

[0041] To address the issues raised in the background technology, this paper proposes an efficient and concise confidentiality determination protocol for the positional relationship between a point and an ellipse in a semi-honest model based on the polynomial substitution method. This protocol is also designed to be resistant to malicious adversary attacks. Before proceeding with the detailed explanation, we first explain the basics.

[0042] Paillier encryption algorithm:

[0043] The Paillier encryption algorithm is constructed as follows: select two large prime numbers p and q. Calculate N = pq, λ = lcm(p-1,q-1), and select the one that satisfies gcd(L(g λ modN 2 ),N)=1g, where The public key is (g,N) and the private key is λ.

[0044] When encrypting a message m∈Z N , select a random number to calculate c=g m r N modN 2 .

[0045] When decrypting ciphertext calculate

[0046] The Paillier encryption algorithm is a probabilistic cryptographic algorithm with semantic security, that is, each plaintext m can be encrypted into different ciphertexts, and there is no polynomial time algorithm that can determine whether these ciphertexts correspond to the same plaintext.

[0047] Its important property is additive homomorphism. Given any two ciphertexts: Right now

[0048] Zero-knowledge proof:

[0049] A zero-knowledge proof (ZKP) is an interactive verification mechanism in which a prover exchanges data with a verifier to convince the verifier of the correctness of their conclusion, without revealing any other useful information to the verifier. An interaction is considered a zero-knowledge proof only when the verifier receives only the correctness of the conclusion.

[0050] Split-Select Method:

[0051] The cut-and-choose method is a cryptographic tool widely used in protocols to counteract malicious actors. Its basic process is: one party generates and sends multiple circuits to the other party. The recipient randomly selects half of these circuits for inspection and requires the other party to publish these circuits to verify their correctness. The unselected circuits are used for subsequent confidential computations. For example:

[0052] Input stage:

[0053] (1) Alice inputs a vector consisting of s pairs Right now There are l in total, and input s is used to check X1, X2, ..., X s Is the value of {0,1} n middle;

[0054] (2) Bob inputs σ1, σ2,…, σ∈{0,1} and parameters

[0055] Output phase: When the sender has no output, the receiver obtains:

[0056] (1) Vector The jth pair, that is

[0057] (2) From vector In each pair of i ,Right now where i=1,2,…,l,j∈ξ, Final output X k .

[0058] Security Definition:

[0059] In the field of secure multi-party computation, participants are categorized as semi-honest and malicious. Semi-honest participants honestly input data and strictly follow the protocol's prescribed steps to process intermediate results during the computation, but they may attempt to infer information about the other party from the computational process. Malicious participants, on the other hand, not only attempt to obtain information but also forge and transmit false information within the protocol. The protocol design of this invention is based on the scenario of two participants.

[0060] The ideal-actual paradigm is an effective way to prove the security of a protocol under a malicious model. In this malicious model, at least one party is honest, otherwise the security of the protocol cannot be guaranteed.

[0061] Ideal protocol: Alice has information x, Bob has information y, and they jointly compute the function f(x, y) = (f1(x, y), f2(x, y)). After the protocol is complete, Alice only obtains f1(x, y), and Bob only obtains f2(x, y), without any other information.

[0062] (1) Data sent by participants to the TTP: Alice and Bob each have information x and y, which they send to the TTP (trusted third party). Honest participants input real data to the TTP, while malicious participants may not execute the protocol or input false data x′ or y′ to the TTP.

[0063] (2) Output sent by TTP to Alice: TTP calculates the function f(x,y). If Alice is an honest participant, it will send f1(x,y) to Alice, otherwise it will send a special symbol ⊥.

[0064] (3) Output result sent by TTP to Bob: If Alice is a malicious participant and does not execute the protocol after receiving f1(x,y), TTP will send ⊥ to Bob after realizing Alice’s malicious behavior; otherwise, it will send f2(x,y) to Bob.

[0065] If the execution result under the malicious model is that both parties can only obtain their own results and cannot obtain any other information, it is consistent with the ideal model, which proves that the protocol under the malicious model is secure.

[0066] Definition 1. There exists a strategy pair in an ideal protocol There are corresponding strategies in the actual protocol Make The protocol is said to be secure. are the probability polynomials under the actual protocol and the ideal protocol respectively, x and y are the information owned by both parties, and F is {0,1} * ×{0,1} * →{0,1} * ×{0,1} * The time function of z is the auxiliary input information. In the ideal model, the participants use the auxiliary input information z to use the strategy Calculate F(x,y), and Represents the output pair produced by the interaction of A1=(x,z) and A2=(y,z).

[0067] Based on the above description, the present invention is described in detail in combination with the confidentiality determination protocol of the position relationship between a point and an ellipse under a semi-honest model and the confidentiality determination protocol of the position relationship between a point and an ellipse under a malicious model. Specific implementation method one:

[0069] This embodiment is a method for determining the confidentiality of the position of a mobile node and an elliptical restricted area in the Internet of Things, which is implemented through a confidentiality determination protocol for the position relationship between a point and an ellipse under a semi-honest model.

[0070] In the Internet of Things, determining the location relationship between mobile nodes and restricted areas is a key security issue. When a mobile node is operating, the system must determine whether it is within the restricted area based on its location and restricted area data. If the mobile node is within the restricted area, the system must issue a warning and take appropriate action; otherwise, the mobile node is allowed to continue operating. However, malicious attackers could tamper with the mobile node's location information or forge prohibited entry data, interfering with the determination and threatening warehouse safety.

[0071] To solve the above problem, the present invention transforms it into a confidentiality determination problem of the position relationship between a point and an ellipse. Specifically, the mobile node location information is abstracted as a point on a two-dimensional plane, and the restricted area is represented as an ellipse on the plane.

[0072] Theorem 1. The general equation is Ax 2 +By 2 +Cx+Dy+E=0 (A>0, B>0 and A≠B) can represent any ellipse whose center is not at the origin and whose major axis is not parallel to the coordinate axes. When A=B=1, it is a circle, which is a special case of an ellipse.

[0073] The mobile node in the Internet of Things that needs to be judged is denoted as Alice, and the elliptical restricted area is denoted as Bob. Alice has a point P0(x0,y0), and Bob has an ellipse P. Without revealing the privacy of both parties, Alice and Bob can determine the positional relationship between P0 and P based on the general equation of the ellipse.

[0074] For the sake of clarity, we give three diagrams to illustrate the positional relationship between the point and the ellipse. Figure 1 Indicates that point P0 is inside the ellipse P, Figure 2 Indicates that point P0 is on the boundary of ellipse P, Figure 3 Indicates that point P0 is outside the ellipse P.

[0075] Substitute the coordinates of point P0 into the general equation of ellipse P, and determine the positional relationship between the point and any ellipse using the result d. If d<0, the point is inside the ellipse; if d=0, the point is on the boundary of the ellipse; if d>0, the point is outside the ellipse.

[0076] The plaintext space of the Paillier encryption algorithm is Z N . (Z N ,+) form an additive group, which does not distinguish between positive and negative numbers. The actual plaintext to be processed can be limited to m∈{0,...,N / 2-1}. Similarly, N is the public key modulus in the Paillier encryption algorithm; for Z NFor the elements x and y in it, if x + y = 0 mod N and 0 < x < N / 2, then it must be that y > N / 2. At this time, y is the additive inverse of x. If we consider x ≥ 0, then y can be regarded as a negative number. Further assume that x, y < N / 2. If (x - y) mod N < N / 2, then x > y; conversely, if (x - y) mod N > N / 2, it means that x < y.

[0077] The confidentiality determination protocol for the elliptical position relationship is as Figure 4 shown.

[0078] Table 1

[0079]

[0080] [[ID=1%]]

[0081] Analysis of correctness and security:

[0082] (1) Protocol 1 aims to substitute the point P0(x0, y0) into the general equation of the ellipse Ax 2 + By <000006Q>+ Cx + Dy + E = 0 (A > 0, B > 0 and A ≠ V). The specific operation is that Alice encrypts x0, y0, 1 and sends them to Bob. After receiving the ciphertext, Bob uses homomorphic operations to multiply the ciphertext with the coefficients A, B, C, D, E of the general equation of the ellipse respectively, and returns the result to Alice. After Alice decrypts, she gets the result d, so as to judge the position relationship between the point P0 and the ellipse. If d > 0, the point is outside the ellipse; if d < 0, the point is inside the ellipse; if d = 0, the point is on the ellipse boundary. This protocol can correctly judge the position relationship between the point and the ellipse.

[0083] (2) In the first step of Protocol 1, Alice calculates the value of , then encrypts x0, y0, 1, and sends the ciphertext to Bob. In the second step, Bob performs homomorphic operations on the ciphertext sent by Alice, and then sends the calculation result to Alice. In the third step, Alice decrypts the calculation result and makes it public. During the execution of Protocol 1, both Alice and Bob can obtain the correct result, and since both sides perform interactive operations with 5 unknowns and 1 equation, it is impossible to deduce the data of the other party based on the information they each have. The protocol is secure. Specific implementation method 2:

[0085] This implementation method is a method for determining the confidentiality of the position of a mobile node and an elliptical restricted area in the Internet of Things. This implementation method is realized through the confidentiality determination protocol for the position relationship between a point and an ellipse under a malicious model.

[0086] When designing a protocol for a malicious model, one typically first constructs the protocol for a semi-honest model. Then, potential malicious attacks are analyzed, and preventative measures are designed to ensure that the adversary's malicious actions are impossible to carry out or detect, ultimately allowing the protocol to participate in a semi-honest manner. It's important to note that malicious actions such as refusing to participate, providing false inputs, and terminating the protocol midway are unpreventable in ideal protocols, and actual protocols don't consider these scenarios. Furthermore, while other malicious actions by both parties during the protocol's execution cannot be completely prevented, they must be detectable.

[0087] In Protocol 1, in step 1, Alice encrypts data and sends it to Bob. In step 2, Bob performs a homomorphic operation on the ciphertext and returns the result. In step 3, Alice decrypts the data and publicly displays the resulting symbolic value. Steps 1-3 are all susceptible to attacks by malicious adversaries, and Alice and Bob may provide false information during the data exchange.

[0088] In order to resist attacks from these malicious behaviors, cryptographic tools such as zero-knowledge proof and split-selection method are used to improve Protocol 1.

[0089] Table 2

[0090]

[0091]

[0092] Correctness analysis:

[0093] (1) In the first three steps of Protocol 2, since Alice and Bob may provide false information during their interactive operations, the Socialist Millionaires' Problem (SMP) is called to determine whether both parties are malicious participants.

[0094] (2) When applying the Paillier encryption algorithm, to ensure correctness, the parameters must satisfy a i |d1-d2| <N a / 2 and b i |d1-d2| <N b / 2. Theoretically, d1, d2, a i ,b i No more than τ bits, only N a , N b The number of bits exceeds 2τ + 1 bits. Steps 4 and 5 of the protocol are designed to ensure that the above conditions are met. If the protocol execution is not terminated, it indicates that Alice and Bob are executing the protocol in a semi-honest manner, thus ensuring the correctness of the protocol.

[0095] (3) Alice’s cheating is successful when she chooses a which does not meet the requirements. i , which is not selected in step 5 but is selected in step 6, leading Bob to a wrong conclusion. The maximum probability of successful deception is: If one group does not meet the requirements, the maximum probability is 1 / n; if 1 / 2 of the data does not meet the requirements, the probability of successful deception is If more than 1 / 2 of the data do not meet the requirements, the probability of successful deception will drop to 0. The probability of success of Bob's malicious behavior is the same.

[0096] Security Analysis:

[0097] The security of Protocol 2 is demonstrated using a widely accepted ideal-realistic paradigm under a malicious model.

[0098] Theorem 2 Protocol 2 (denoted as Protocol Π) is secure in the presence of malicious participants.

[0099] Proof. According to Definition 1, when executing protocol π, the calculation time function F requires the strategy pair in the actual protocol and the strategy pair in the ideal protocol exists and is computationally indistinguishable. To ensure the security of the protocol, at least one party must be honest, otherwise the protocol cannot be implemented:

[0100] Scenario 1: A1 is honest and A2 is dishonest.

[0101] When A1 honestly executes the protocol π, then: Where S is the sequence message received by A2 through zero-knowledge proof.

[0102] At this point, B1 is determined, and we only need to prove that A2 and B2 are computationally indistinguishable. To do this, we need to find a strategy for Make its output Computationally indistinguishable. Since A2 is the actual executor of the protocol, the correctness of the protocol must be verified based on A2(d2).

[0103] (1) If A1 is honest, B1 will send the real input information d1 to TTP.

[0104] (2) If A1 is dishonest, B2 will send input information A2 (d2) to TTP.

[0105] (3) TTP obtains input information (d1, A2(d2)) and calculates F(d1, A2(d2)).

[0106] (4) B2 receives F(d1, A2(d2)) sent by TTP and uses it to generate and compare it with the one obtained by A2. computationally indistinguishable And send it to A2 to get the output of A2. B2 selects d'1 to simulate the protocol so that F(d'1, A2(d2)) = F(d1, A2(d2)).

[0107] During the execution of the agreement by B2, the following situations occur:

[0108]

[0109] In steps 4-9 of the protocol, if the protocol uses the same encryption algorithm, then And zero-knowledge proof guarantees therefore:

[0110] Case 2: A1 is dishonest, and A2 is honest. In this case, there are two possibilities:

[0111] If Alice ignores TTP after receiving the message, TTP will send ⊥ to Bob. At this time, the actual output of the protocol is:

[0112] On the contrary, TTP sends the correct information F2(A1(d1),d2) to Bob, then the actual protocol output is:

[0113]

[0114] Among them, S is the sequence message received by A1 through zero-knowledge proof.

[0115] At this point, B2 is determined. It is necessary to prove that A1 and B1 are computationally indistinguishable. To do this, a strategy must be found for Make its output Computationally indistinguishable. Since A1 is the actual protocol executor, the correctness of the protocol must be verified based on A1(d1).

[0116] (1) A1 is dishonest, and B1 will send the input information A1(d1) to TTP.

[0117] (2) A2 is honest, and B2 will send real input information d2 to TTP.

[0118] (3) TTP receives the input information (A1(d1), d2) and calculates F(A1(d1), d2).

[0119] (4) B1 receives F(A1(d1),d2) sent by TTP and generates the actual protocol obtained by executing the protocol with A1. computationally indistinguishable And send it to a1 to get the output of a1. B1 selects d'2 to simulate the protocol so that F(A1(d1), d'2) = F(A1(d1), d2).

[0120] During B1's execution of the agreement, there are two situations:

[0121] (1) When A1 receives the message and ignores TTP, it gets:

[0122] (2) On the contrary, we get

[0123] If the same encryption algorithm is used in steps 4-9 of the protocol, then Zero-knowledge proof guarantees therefore:

[0124] In summary, Protocol 2 (Protocol Π) is safe under the malicious model.

[0125] The protocols 1 and 2 of the present invention are implemented based on the Paillier encryption algorithm. The computational complexity analysis only considers the main overhead of the protocol - modular exponential operation (M m The communication complexity is compared with the number of protocol rounds.

[0126] A. Computational complexity:

[0127] During the execution of protocol 3 of "Secure two-party computational geometry", OT protocol was executed twice and random number encryption was performed twice, with a total computational cost of (32m+28)M m .

[0128] During the execution of protocol 1, encryption was performed 5 times and decryption was performed once, with a total computational cost of 12M. m .

[0129] During the execution of Protocol 2, encryption was performed 10 times and decryption was performed 2 times, involving 24 modular exponential operations. 2n sets of modular exponents were generated, and n modular exponents were verified, requiring a total of 5n modular exponential operations. Two zero-knowledge proofs of discrete logarithms were performed, requiring a total of 12 modular exponential operations. The total computational overhead is (5n+36)M. m .

[0130] B. Communication complexity:

[0131] During the execution of Protocol 3 of "Secure two-party computational geometry", the OT protocol interacted for 16 rounds and the mutual information exchanged for 10 rounds, with a total communication overhead of 26 rounds.

[0132] During the execution of Protocol 1, the total communication overhead is 3 rounds.

[0133] During the execution of Protocol 2, the first three steps of exchanging messages took 4 rounds, and the Socialist Millionaire Protocol used took 3 rounds, with a total communication overhead of 7 rounds.

[0134] Table 3 Comparison of protocol efficiency

[0135]

[0136] As shown in Table 3, Protocol 3 of "Secure two-party computational geometry" is inferior to Protocols 1 and 2 of the present invention in terms of communication complexity and computational complexity, and cannot resist attacks from malicious adversaries. Preprocessing or service outsourcing can be used to improve the protocol efficiency under the malicious model.

[0137] The present invention aims at the problem of confidentiality determination of the position relationship between mobile nodes and elliptical restricted areas in the Internet of Things environment, proposes a method based on secure multi-party computing, and uses the Paillier encryption algorithm to realize confidentiality determination of the position relationship. A confidentiality determination protocol for the position relationship between points and ellipses under a semi-honest model is designed, and the malicious attacks it may be subjected to are deeply analyzed. Then, a protocol to resist malicious adversaries is designed, and the correctness, security, success probability of malicious adversary attacks and efficiency of the two protocols are analyzed. The analysis shows that the efficiency of the scheme of the present invention is greatly improved compared with the existing scheme, and it effectively balances privacy protection and computational efficiency. It provides an efficient and secure solution to the problem of privacy protection of the positions of mobile nodes and elliptical restricted areas in the Internet of Things, and has important theoretical and application value.

[0138] The present invention may have many other embodiments. Without departing from the spirit and essence of the present invention, those skilled in the art may make various corresponding changes and modifications based on the present invention, but these corresponding changes and modifications should all fall within the scope of protection of the claims attached to the present invention.

Claims

1. A method for determining the confidentiality of the position of a mobile node and an elliptical restricted area in an Internet of Things, characterized by: The mobile node in the Internet of Things that needs to be judged is recorded as Alice, and the elliptical restricted area is recorded as Bob; Alice calculates based on her own position point P0(x0,y0) Select a random number and encrypt it with your own public key based on homomorphic encryption x0, y0, 1 obtain parameters c1-c5 and send them to Bob; based on homomorphic encryption technology, Bob uses the elliptic equation coefficients a, B, C, D, E of the elliptical restriction area to achieve confidential communication with Alice, and then determine whether Alice's position point P0 is within the ellipse P corresponding to the elliptical restriction area.

2. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in an Internet of Things according to claim 1, wherein: The specific implementation process of the method includes the following steps: (a) The mobile node in the Internet of Things that needs to be judged is recorded as Alice, and the elliptical restricted area is recorded as Bob; Alice calculates based on her own position point P0(x0,y0) Select a random number r and encrypt it with your own public key based on homomorphic encryption x0, y0, 1 get parameters c1-c5 and send them to Bob; (b) Bob calculates Send to Alice; (c) Alice decrypts c6 to obtain And send it to Bob; if d<0, then point P0 is inside the ellipse P; if d=0, then point P0 is on the boundary of the ellipse P; if d>0, then point P0 is outside the ellipse P.

3. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in an Internet of Things according to claim 2, wherein: In step (a), Alice selects a random number r and encrypts it with her public key based on homomorphic encryption. The process of x0, y0, and 1 is encrypted using the Paillier encryption algorithm, and the obtained parameters c1-c5 are as follows: c5=g 1 r N modN 2 ; N is the public key modulus in the Paillier encryption algorithm.

4. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in an Internet of Things according to claim 1, wherein: The specific implementation process of the method includes the following steps: (1) The mobile node in the Internet of Things that needs to be judged is recorded as Alice, and the elliptical restricted area is recorded as Bob; Alice calculates based on her own position point P0(x0,y0) Select a random number r1 and encrypt it with your own public key based on homomorphic encryption x0, y0, 1 get parameters c1-c5 and send them to Bob; Bob selects a random number r2 and encrypts the elliptic equation coefficients A, B, C, D, E of the elliptic restriction area with his own public key based on homomorphic encryption to get parameters c6-c 10 Alice and Bob use the same homomorphic encryption method. (2) Alice’s calculation Send to Bob, Bob calculates Send to Alice; (3) Alice decrypts c 12 Obtaining d1, Bob decrypts c 11 Get d2; (4) Alice and Bob each select n random numbers a i ,b i , i=1,...,n, and calculated using the public key of their respective homomorphic encryption algorithms and publish it; (5) Using the split-selection method, Alice and Bob each select n groups of and Select n / 2 groups each and After Bob and Alice announce b i d2 and a i After d1, both parties verify. If both parties pass the verification, the protocol will continue to execute. If one party verifies differently, the protocol will be terminated. (6) Alice and Bob each choose from the remaining n / 2 groups and Randomly select one and And select a, b; (7) Alice uses ad1 to obtain c based on the homomorphic encryption algorithm b , sent to the other party; Bob uses bd2 based on the homomorphic encryption algorithm to obtain c a , sent to the other party; (8) Alice obtains m through the decryption process based on the homomorphic encryption algorithm. a And announced that Bob obtains m through the decryption process based on the homomorphic encryption algorithm b and publish; (9) Alice and Bob use zero-knowledge proof to verify and If one party cannot provide a valid proof, it will be judged as a malicious participant and the protocol will be terminated; λ a is Alice’s private key in the Paillier encryption algorithm, λ b The private key in the Paillier encryption algorithm corresponding to Bob; (10) If the proof passes, Alice and Bob obtain the calculated values ​​d1 and d2; if d1 = d2 < 0, then point P0 is inside the ellipse P; if d1 = d2 = 0, then point P0 is on the boundary of the ellipse P; if d1 = d2 > 0, then point P0 is outside the ellipse P.

5. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in an Internet of Things according to claim 4, wherein: In step (1), Alice selects a random number r1 and encrypts it with her public key based on homomorphic encryption. The process of x0, y0, and 1 is encrypted using the Paillier encryption algorithm, and the obtained parameters c1-c5 are as follows: g a The module in the public key of the Paillier encryption algorithm corresponding to Alice The elements of the multiplication group under a is the modulus of the public key in the Paillier encryption algorithm corresponding to Alice. Alice’s public key is (g a ,N a ), λ a It is the private key in the Paillier encryption algorithm corresponding to Alice.

6. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in the Internet of Things according to claim 5, wherein: In step (1), Bob selects a random number r2 and encrypts the coefficients A, B, C, D, and E of the elliptical equation in the elliptical restricted area with his own public key based on homomorphic encryption. The Paillier encryption algorithm is used to encrypt the obtained parameters c6-c 10 as follows: g b The module in the public key of the Paillier encryption algorithm corresponding to Bob The elements of the multiplication group under b is the modulus of the public key in the Paillier encryption algorithm corresponding to Bob. Bob’s public key is (g b ,N b ), λ b It is Bob's private key in the Paillier encryption algorithm.

7. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in an Internet of Things according to claim 6, wherein: In step (4), Alice and Bob each select n random numbers a i ,b i , and calculated using the public key of their respective homomorphic encryption algorithms 8. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in an Internet of Things according to claim 7, wherein: In step (5), after Bob and Alice announce b i d2 and a i After d1, both parties verify and 9. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in the Internet of Things according to claim 8, wherein: In step (7), Alice uses ad1 to obtain c b and c obtained by Bob using bd2 a as follows:

10. The method for determining the location confidentiality of a mobile node and an elliptical restricted area in the Internet of Things according to claim 9, wherein: In step (8), Alice obtains m through the decryption process based on the homomorphic encryption algorithm. a , Bob obtains m through the decryption process based on the homomorphic encryption algorithm b The process is as follows: Alice and Bob use λ a and λ b calculate and λ a is Alice’s private key in the Paillier encryption algorithm, λ b It is Bob's private key in the Paillier encryption algorithm.

Citation Information

Patent Citations

  • Privacy preserving method for location proximity detection based on polygon range

    CN109151715A

  • Anti-malicious opponent confidential bidding auction method based on block chain

    CN117763572A

  • Privacy preserving geofencing system and method thereof

    US20240221508A1

  • Solution to millionaires' problem based on homomorphic encryption

    WO2020258373A1