A selective aggregation and authentication method based on multi-type dense state data

By constructing selection and verification keys and combining them with a super-incrementing sequence strategy, selective aggregation and authentication of multiple types of encrypted data can be achieved. This solves the problem of efficient classification and aggregation of multiple types of data in the Internet of Things environment, and improves the flexibility and security of data processing.

CN120546896BActive Publication Date: 2025-10-28GUIZHOU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511044669.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-29
Publication Date
2025-10-28
Estimated Expiration
2045-07-29

AI Technical Summary

Technical Problem

Existing technologies struggle to efficiently classify and aggregate various types of data while ensuring data privacy. This is especially true in resource-constrained IoT environments, where the lack of selective aggregation capabilities and efficient signature mechanisms leads to inefficient aggregation verification.

Method used

By constructing a selection key, a verification key, a super-incremental sequence aggregation strategy, and a verifiable signature mechanism, a selective aggregation and authentication method based on multi-type encrypted data is designed to achieve independent encryption and differentiated processing of different data types. Edge nodes are used for data filtering and aggregation, and the central server performs final verification and decryption.

Benefits of technology

It enhances the flexibility and security of data aggregation, achieves aggregation of multiple types of ciphertext through super-incrementing sequences, ensures the security of the aggregation results, and improves the efficiency of signature and verification, making it suitable for resource-constrained IoT environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120546896B_ABST
    Figure CN120546896B_ABST
Patent Text Reader

Abstract

This application discloses a selective aggregation and authentication method based on multi-type encrypted data, relating to the field of network and information security technology. The method includes: each IoT device encrypting and signing acquired sensing data, and calculating a selection key based on the data type; each secondary edge server verifying the selection key of each IoT device using its own verification key to determine encrypted data conforming to its expected type, and performing a first aggregation using multiplication; a primary edge server performing a second aggregation on all first-aggregated encrypted data and first-aggregated signed data; and a central server verifying the second-aggregated signed data, and upon successful verification, decrypting and restoring the second-aggregated encrypted data, and using a recursive algorithm to determine the aggregated plaintext corresponding to each data type. This application enables efficient aggregation and authentication based on different data types.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network and information security technology, and in particular to a selective aggregation and authentication method based on multi-type encrypted data. Background Technology

[0002] With the rapid development of the Internet of Things (IoT), cloud computing, and big data technologies, distributed data acquisition systems based on wireless sensor networks (WSNs) have been widely used in fields such as smart healthcare, smart grids, and intelligent transportation. IoT terminal devices continuously generate massive amounts of heterogeneous data. How to achieve efficient data classification and aggregation processing while ensuring data privacy has become a critical issue that urgently needs to be addressed. Summary of the Invention

[0003] The purpose of this application is to provide a selective aggregation and authentication method based on multi-type dense state data, which can achieve efficient aggregation and authentication based on different data types, facilitate data classification and processing, enable more rational allocation of system computing resources, and improve system flexibility.

[0004] To achieve the above objectives, this application provides the following solution:

[0005] Firstly, this application provides a selective aggregation and authentication method based on multi-type dense state data, including:

[0006] Each IoT device encrypts and signs the sensing data it acquires based on the central server's public key and shared private key, resulting in encrypted data and signed data. It also calculates and selects a key based on the data type of the sensing data. The shared private key is used by all IoT devices.

[0007] Each IoT device sends the calculated selection key, encrypted data, and signature data to all secondary edge servers;

[0008] Each secondary edge server verifies the selected key sent by each IoT device based on its own verification key to determine the encrypted data that conforms to its expected type;

[0009] Each secondary edge server performs an aggregation operation using multiplication on all encrypted data and corresponding signature data that meet its expected type, resulting in aggregated encrypted data and aggregated signature data. It then sends the aggregated encrypted data and aggregated signature data to the primary edge server.

[0010] The first-level edge server performs secondary aggregation on all received primary aggregated encrypted data using a super-incrementing sequence to obtain secondary aggregated encrypted data, and performs secondary aggregation on all received primary aggregated signature data using multiplication operations to obtain secondary aggregated signature data.

[0011] The primary edge server sends the secondary aggregated encrypted data and secondary aggregated signature data to the central server;

[0012] The central server verifies the secondary aggregated signature data, and when the verification is successful, it decrypts and restores the secondary aggregated encrypted data according to its own private key to obtain the plaintext aggregated value corresponding to all data types.

[0013] The central server calculates the aggregated plaintext for each data type using a recursive algorithm based on the aggregated plaintext values ​​corresponding to all data types.

[0014] According to the specific embodiments provided in this application, this application has the following technical effects:

[0015] This application provides a selective aggregation and authentication method based on multi-type encrypted data. First, each IoT device (based on the central server's public key and the IoT device's shared private key) encrypts and signs the acquired sensing data, calculates a selection key based on the data type, and sends it to all secondary edge servers. Each secondary edge server verifies the selection key of each IoT device using its own verification key to determine encrypted data matching its expected type. For all encrypted data matching its expected type and their corresponding signature data, it performs a first aggregation using multiplication and sends the first aggregation result to the primary edge server. The primary edge server performs a second aggregation using a super-increasing sequence on all received first-aggregated encrypted data to obtain second-aggregated encrypted data. It also performs a second aggregation using multiplication on all received first-aggregated signature data to obtain second-aggregated signature data, and sends both to the central server. Finally, the central server verifies the second-aggregated signature data. If verification is successful, it decrypts and recovers the second-aggregated encrypted data to obtain the plaintext aggregation value corresponding to all data types. Then, a recursive algorithm is used to calculate the aggregated plaintext corresponding to each data type. Based on the above scheme, this application realizes differentiated processing of perceived data of different data types (such as independent encryption, signing, and single aggregation), which improves the flexibility of data aggregation. Furthermore, by assigning aggregation tasks of different data types to different edge nodes, it achieves reasonable allocation of system computing resources. In addition, by introducing a super-incrementing sequence during secondary aggregation, it is possible to aggregate multiple types of ciphertext (all data types) without decryption, ensuring the efficiency and security of the overall aggregation. And by using aggregation signing and verification based on shared private keys, it ensures the efficiency of signing and verification (authentication). Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 A flowchart illustrating a selective aggregation and authentication method based on multi-type dense state data, provided as an embodiment of this application;

[0018] Figure 2 A system architecture diagram of a selective aggregation and authentication method based on multi-type dense state data provided in an embodiment of this application;

[0019] Figure 3 A flowchart of a data type selection algorithm provided in an embodiment of this application;

[0020] Figure 4 A flowchart of a data aggregation algorithm provided in one embodiment of this application;

[0021] Figure 5 A comparison diagram of device-side computational overhead provided in an embodiment of this application;

[0022] Figure 6 A comparison chart of edge layer computation overhead provided for an embodiment of this application;

[0023] Figure 7 A comparison chart of central server computational overhead provided in an embodiment of this application;

[0024] Figure 8 A comparison chart of the overall computational overhead of a solution provided in an embodiment of this application. Detailed Implementation

[0025] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0027] Current solutions attempt to achieve aggregation verification while ensuring data privacy, but they still have the following shortcomings: First, data encryption methods often cannot support differentiated processing of various data types and lack selective aggregation capabilities; second, the data verification and merging process at the edge aggregation nodes lacks efficient structural design, resulting in low aggregation verification efficiency; third, signature mechanisms are often highly coupled with the ciphertext aggregation process, lacking flexibility and failing to effectively support efficient authentication of multi-dimensional data. Furthermore, many current solutions do not consider the efficiency constraints caused by limited resources on the underlying devices during signature aggregation and verification, making them unsuitable for resource-constrained real-world IoT environments.

[0028] The purpose of this application is to propose a selective aggregation and authentication method based on multi-type encrypted data to achieve encrypted aggregation and signature verification of multi-source heterogeneous data, thereby improving the data processing efficiency and security of the entire Internet of Things (IoT) system. This method constructs a trusted and efficient data aggregation and authentication system by establishing a selection key, a verification key, a super-incrementing sequence aggregation strategy, and a verifiable signature mechanism.

[0029] In one exemplary embodiment, such as Figure 1 As shown, a selective aggregation and authentication method based on multi-type dense state data is provided, including the following steps 101 to 108. Wherein:

[0030] Step 101: Each IoT device encrypts and signs the sensing data it acquires based on the central server's public key and shared private key, obtaining encrypted data and signed data, and calculates and selects a key based on the data type of the sensing data; the shared private key is used by all IoT devices.

[0031] Step 102: Each IoT device sends the calculated selection key, encrypted data, and signature data to all secondary edge servers.

[0032] Step 103: Each secondary edge server verifies the selection key sent by each IoT device based on its own verification key to determine the encrypted data that matches its expected type.

[0033] Step 104: Each secondary edge server performs an aggregation operation using multiplication on all encrypted data and corresponding signature data that conform to its expected type, to obtain aggregated encrypted data and aggregated signature data, and sends the aggregated encrypted data and aggregated signature data to the primary edge server.

[0034] Step 105: The first-level edge server performs secondary aggregation on all received primary aggregated encrypted data using a super-incrementing sequence to obtain secondary aggregated encrypted data, and performs secondary aggregation on all received primary aggregated signature data using multiplication operations to obtain secondary aggregated signature data.

[0035] Step 106: The primary edge server sends the secondary aggregated encrypted data and the secondary aggregated signature data to the central server.

[0036] Step 107: The central server verifies the secondary aggregated signature data. When the verification is successful, it decrypts and restores the secondary aggregated encrypted data using its own private key to obtain the plaintext aggregated value corresponding to all data types.

[0037] Step 108: The central server calculates the aggregated plaintext for each data type using a recursive algorithm based on the aggregated plaintext values ​​for all data types.

[0038] As an optional implementation method, the first Types of data The corresponding selection key is ,in,

[0039] ;

[0040] ;

[0041] ;

[0042] ;

[0043] ;

[0044] ;

[0045] in, , For model The set of remaining classes, for Large prime numbers in the middle, Modulus multiplication group This is the default value; , Represents the set of positive integers; ; ; , Modulus an integer ring; express The corresponding coefficients of the Chinese Remainder Theorem; This represents a strongly collision-resistant hash function; , This represents the modulo operation; ; .

[0046] As an optional implementation method, the first Types of data The corresponding verification key is ,in,

[0047] ;

[0048] ;

[0049] ;

[0050] ;

[0051] ;

[0052] ;

[0053] in, To meet The parameters, express The corresponding coefficients of the Chinese Remainder Theorem; To meet Parameters; To meet The parameters, express The corresponding coefficients of the Chinese Remainder Theorem; To meet The parameters, express The corresponding coefficients of the Chinese Remainder Theorem; ; ; ; .

[0054] As an optional implementation, the encrypted data is represented as follows:

[0055] ;

[0056] in, Indicates Internet of Things (IoT) devices and the Encrypted data corresponding to each data type; Indicates encrypted data The first part; Indicates encrypted data Part Two; ; ; ; , Modulus The multiplication group; , Modulus The multiplication group; This represents the modulo operation; ; This represents the public key of the central server; Indicates Internet of Things (IoT) devices and the Perceptual data corresponding to data types.

[0057] As an optional implementation, the signature data is represented as follows:

[0058] ;

[0059] in, Indicates Internet of Things (IoT) devices and the The signature data corresponding to each data type; Represents signature data The first part; Represents signature data Part Two; Indicates Internet of Things (IoT) devices and the The timestamps corresponding to the various data types; It is based on IoT devices For the first The timing for signing perceived data of various data types is determined; This represents the shared private key for IoT devices.

[0060] As an optional implementation, each secondary edge server verifies the selection key sent by each IoT device based on its own verification key to determine encrypted data that conforms to its expected type, specifically including:

[0061] Each secondary edge server determines its own authentication key. and the selection key sent to each IoT device If the first verification formula is satisfied, then it is determined that the encrypted data sent by the corresponding IoT device conforms to its expected type; the first verification formula is:

[0062] ;

[0063] in, Represents a bilinear pairing function. Input , Output ; and To have the same prime order cyclic group; The generator is ; Indicates the first Types of data The corresponding selection key.

[0064] Since the data type of the selection key sent by the IoT device may differ from the data type of the verification key sent by the edge node, two different symbols are used here. and The key is used to identify the data types of both, and the selection key does not follow the previous method of "..." This way of expressing it.

[0065] As an optional implementation, the secondary aggregated encrypted data is represented as follows:

[0066] ;

[0067] in, Indicates secondary aggregation of encrypted data The first part; Indicates secondary aggregation of encrypted data The second part; the symbol ∏ represents multiplication; Indicates the first One-time aggregated encrypted data corresponding to each data type The first part; Indicates the first One-time aggregated encrypted data corresponding to each data type Part Two; Indicates a super-increasing sequence The first in One element; , , Equal to the number of data types.

[0068] As an optional implementation, the central server verifies the secondary aggregated signature data, specifically including:

[0069] The central server determines whether the secondary aggregated signature data satisfies the second verification formula, and determines that the verification is successful when the secondary aggregated signature data satisfies the second verification formula; the second verification formula is:

[0070] ;

[0071] in, Indicates secondary aggregation of encrypted data The first part; Indicates secondary aggregation of encrypted data Part Two; Indicates connection with IoT devices and the The timestamps corresponding to the various data types; Indicates all The product of two products, Less than or equal to the total number of IoT devices The total number of data types less than or equal to; This represents the summary of all data types corresponding to the perceived data (i.e., all...). (and) Indicates the first A summary of sensory data corresponding to various data types. ,Right now For the The sum of the sensed data of all IoT devices corresponding to this data type.

[0072] As an optional implementation, the central server decrypts and recovers the secondary aggregated encrypted data using its own private key to obtain the plaintext aggregated values ​​corresponding to all data types, specifically including:

[0073] The central server decrypts the secondary aggregated encrypted data using its private key and a decryption formula; the decryption formula is:

[0074] ;

[0075] in, The result of the decryption; The private key for the central server; Indicates the first A summary of sensory data corresponding to various data types;

[0076] The central server uses a recovery formula to recover the decryption result, obtaining the plaintext aggregate value corresponding to all data types; the recovery formula is:

[0077] ;

[0078] in, This is the aggregated plaintext value for all data types. The recovery formula utilizes... The function is determined.

[0079] As an optional implementation, the shared private key of the IoT device is determined through secret sharing, specifically as follows:

[0080] Step 201: The trusted and authoritative center randomly generates a set of polynomial coefficients. and the secret value set of IoT devices participating in secret sharing ; Threshold values ​​for IoT devices participating in secret recovery; The number of IoT devices participating in the secret sharing.

[0081] Step 202, the trusted authority center, based on the polynomial coefficient set, the IoT device secret value set, and preset... The polynomial of degree is used to calculate the polynomial value corresponding to the secret value of each IoT device, and all IoT device secret values ​​and their corresponding polynomial values ​​are distributed to those participating in secret sharing. One IoT device.

[0082] Step 203: Upon receiving the IoT device secret value and the corresponding polynomial value, any participating IoT device sends a message to... Other IoT devices participating in the secret sharing send requests to obtain... The other IoT devices participating in the secret sharing receive the IoT device secret value and the corresponding polynomial value.

[0083] Step 204: Each of the IoT devices participating in secret sharing, based on the IoT device secret value and corresponding polynomial value it received, and... The other IoT devices participating in secret sharing receive the IoT device secret value and the corresponding polynomial value, and then, using the reconstruction formula, [the following is used to]... Reconstruct the polynomial of degree n by degree n to obtain the reconstructed polynomial. Polynomial of degree.

[0084] Step 205: When any of the IoT devices calculates the reconstructed value when the independent variable is 0. The value of the polynomial of degree 1, and the reconstructed polynomial when the independent variable is 0. The value of the polynomial is determined as the shared private key for the IoT device.

[0085] In other words, the selective aggregation and transmission scheme for general IoT application scenarios provided in this embodiment mainly includes the following three types of related entities: a Trust Authority (TA), underlying IoT devices, network edge servers, and a central server.

[0086] The network edge server, also referred to as the edge server or edge node in this article, and the underlying IoT devices, also referred to as IoT devices in this article, are all part of the same concept.

[0087] The overall system architecture is as follows Figure 2 As shown, the specific job responsibilities of the relevant entities are briefly described below:

[0088] (1) The Trusted Authority Center is responsible for system initialization, parameter generation, and distribution of system public and private keys.

[0089] (2) IoT devices are used to generate ciphertext and signatures to ensure the privacy and integrity of device data.

[0090] (3) After receiving ciphertext of relevant data types from IoT devices, the edge server filters the data and aggregates the required encrypted data and signature. Finally, the aggregated data and signature are sent to the central server for further decryption and verification.

[0091] (4) The central server receives the aggregation results sent by the edge server and verifies and decrypts them.

[0092] The technical solution described above in this embodiment will be further explained below from the perspective of the functions of each entity.

[0093] First, system key generation.

[0094] With safety parameters As input, the trusted and authoritative center first randomly selects two large prime numbers. Calculate large prime numbers At the same time, the trusted center selects random numbers. ,calculate Finally, the trust center chooses a large prime number. Construct a superincreasing sequence .

[0095] Safety parameters It was selected randomly.

[0096] Next, the credible and authoritative center selected two prime numbers of the same order. Cyclic group and , generator This makes the bilinear mapping hold. At the same time, choose a hash function. As a hash function with strong collision resistance, four prime numbers are then randomly selected. and two integers .

[0097] Finally, the Trusted Authority Center publishes public parameters. ,in, It is a cyclic group Elements in; and , express The corresponding coefficients of the Chinese Remainder Theorem.

[0098] Second, key distribution.

[0099] Trusted Authority Center Computing and select one satisfy and choices Use the private key of the central server to generate a public key. . express The number of digits in Within a defined integer range. Then, the trusted authority center will... The data is transmitted to the central server. Finally, the central server publishes the public key. .

[0100] Assuming the central server can receive Types of data, and represent them as The central server is randomly selected. Calculate the first The verification keys for each data type are detailed above.

[0101] Then, the central server uploads the verification key and super-incrementing sequence of the data types that need to be aggregated to the first... edge nodes Perform data selection and filtering.

[0102] Third, secret sharing.

[0103] For each participating underlying IoT device, the trusted authority center randomly generates a set of polynomial coefficients. and the secret value set of IoT devices participating in secret sharing The credible and authoritative center has confirmed this. polynomial of degree Then calculated and the secret value and They are jointly distributed to the corresponding data sending devices (underlying IoT devices).

[0104] IoT devices receive secret values ​​and Afterwards, a clandestine recovery was carried out, in which the number of devices participating in the clandestine recovery was at least [number missing]. And this The sub-secrets of each device are as follows: The secret value is recovered according to the following reconstruction formula:

[0105] ;

[0106] when hour, That is, the shared private key of the underlying IoT devices. Calculate the public key Then, the public key and shared private key are distributed to all IoT devices through a secure channel.

[0107] Fourth, data encryption.

[0108] IoT device selection Calculate the first Selection key for each data type For details, please refer to the previous text. Shared by all IoT devices.

[0109] IoT devices select two random numbers Data Encrypt and sign to obtain and For details, please refer to the previous text. Shared by all IoT devices.

[0110] Ultimately, IoT devices broadcast to edge nodes. .

[0111] In other words, IoT devices divide various types of raw sensing data into multiple data types, generate selection keys for each type, and then call the Paillier encryption algorithm, which supports additive homomorphism, to generate ciphertext. Before generating a signature, the IoT device performs a hash mapping on the current timestamp.

[0112] Fifth, selective data aggregation.

[0113] See the process of selective encryption of encrypted data. Figure 3 First, edge nodes It is necessary to distinguish the data types received. Is it the expected data type, therefore the edge node? Perform bilinear pairing computation on the selection key and the verification key:

[0114] ;

[0115] Furthermore, edge nodes We need to verify whether the following equation (i.e., the first verification formula) holds true:

[0116] ;

[0117] As mentioned earlier, since the data type of the selection key sent by the IoT device may differ from the data type of the verification key sent by the edge node, two different symbols are used here ( and () is used to identify the data types of both.

[0118] If the equation does not hold true, the encrypted data (ciphertext) is discarded. If the equation holds true, the ciphertext and signature of the data are aggregated separately. The proof of the equation's correctness is as follows:

[0119] ;

[0120] That is, when the data types of the two are the same ( = When ), the first verification formula holds true.

[0121] Figure 3 middle, , , This process is a flowchart for the data type selection algorithm. Before the algorithm performs the verification operation, it first needs to initialize the known ciphertext and signature.

[0122] After verifying that the equation holds true, the data aggregation process can be found in [link to relevant documentation]. Figure 4 For the filtered ciphertext and signature, each is composed of two sub-parts forming a complete ciphertext and signature. During the aggregation process, for the first... The encrypted text of data type is expressed in the form of . If the filtered ciphertext data types are of the same type, then all filtered ciphertexts can be processed. The two components are aggregated separately using multiplication: The final result Indicates the first A collection of all ciphertexts corresponding to a certain data type, consisting of multiple ciphertexts from different IoT devices. Aggregation structure; the principle of signature aggregation is the same, for signatures of the same data type. The aggregation is performed as follows: .

[0123] Subsequently, edge nodes Aggregate all encrypted messages using super-incrementing sequences That is, the ciphertext aggregation results of all data types are subjected to secondary aggregation as follows: , , For the number of data types, The item expansion process is similar. Simultaneously, the signature also undergoes a corresponding secondary aggregation, since IoT devices obtain the secret value (i.e., the public / private key) through a secret sharing scheme. Therefore, the signatures can be aggregated as: , , For the number of data types, The item expansion process is similar. After completing the secondary aggregation, the edge nodes... Send to the central server and The central server ultimately processes the aggregation results. and Decrypt and analyze.

[0124] In the secondary aggregation process, the elements in the super-increasing sequence are used as the exponents of each type of ciphertext (i.e., the first-time aggregated encrypted data) for operation, and then the homomorphic encryption property is used to multiply them to generate the ciphertext aggregation result (i.e., the second-time aggregated encrypted data).

[0125] Sixth, signature verification and data decryption.

[0126] The central server receives the time period Aggregation results within and Next, the aggregate signature is verified first. The verification equation (i.e., the second verification formula) is as follows:

[0127] ;

[0128] The integrity verification process for aggregated data is as follows:

[0129] ;

[0130] After the aggregated data passes integrity verification, the encrypted aggregated result is decrypted. First, the private key is used. ( The data type to be decrypted is The aggregation result and decryption process are described above.

[0131] Then execute The function recovers the plaintext result. Because the plaintext result obtained after decryption Instead of being plaintext aggregated values ​​of a single data type, these are quadratic aggregated values ​​combining super-increasing sequences. Therefore, a recursive algorithm is needed to recover the aggregated results for each data type. The detailed process is as follows:

[0132] The plaintext result obtained after decryption Modulo operation is performed on it to obtain Based on the properties of super-increasing sequences, the th... Single aggregate plaintext of various data types By repeating the above operations, a single aggregated plaintext sequence of all data types can eventually be obtained. This method enables the splitting of super-incrementing sequences and plaintext values ​​to obtain the final aggregated plaintext data of a single data type.

[0133] The above-mentioned solutions in this application can be summarized as follows:

[0134] 1) Verification Key Generation and Secret Sharing: The central server can receive various data types from underlying IoT devices. After parameter generation and key distribution are completed at the trusted center, the central server calculates the verification key for each receivable data type. Simultaneously, for each underlying IoT device, the public and private keys are fragmented through secret sharing to enhance security. IoT devices participating in secret recovery recover the secret value according to the reconstruction formula and obtain the public and private keys.

[0135] 2) Data classification and homomorphic encryption: The underlying IoT devices classify the multidimensional raw data they sense according to data type, calculate the selection key for different data types, and then use the improved Paillier encryption algorithm to encrypt each type of plaintext data to generate ciphertext and signature, and broadcast it to the edge nodes.

[0136] 3) Selective Data Aggregation with the Auxiliary Super-Incrementing Sequence: Edge nodes need to distinguish whether the received data type is the expected data type (each edge node is only responsible for processing a specific data type). Therefore, edge nodes verify the data type by calculating a bilinear pair function. If the verification fails, the encrypted data is discarded; if the verification passes, the data type is aggregated. The edge node aggregates all encrypted messages of the same type and their corresponding signatures from multiple IoT devices, and then uses a super-incrementing sequence to aggregate all encrypted messages and signatures to achieve multi-dimensional ciphertext fusion and ordered identification. Finally, the edge node sends the aggregated ciphertext and signature results to the central server.

[0137] 4) Central server signature verification and data decryption: After verifying the legality of the aggregated signature through bilinear pairing, the central server completes the decryption operation of the aggregated ciphertext based on Paillier's private key (the central server's private key) to obtain the plaintext aggregated value, and further obtains the single data type aggregated plaintext value through the algorithm of recovering the aggregation results of each data type.

[0138] This application proposes a selective aggregation and authentication method based on multi-type encrypted data, constructing a multi-dimensional encrypted data processing scheme suitable for the Internet of Things (IoT) environment. Taking multi-type sensing data as the research object, this scheme forms a "data encryption—data filtering—data aggregation—verification and decryption" processing flow through multiple sub-modules, including key design, data encryption, super-incrementing sequence aggregation, and bilinear verification and decryption, achieving selective aggregation, authentication, and secure decryption of multi-type encrypted data. Compared with existing technologies, this scheme supports independent encryption and differentiated processing of different data types, significantly improving the flexibility and security of data aggregation. Secondly, the introduced super-incrementing sequence mechanism enables the aggregation of multi-type encrypted data without decryption, ensuring the security of the aggregation result. Finally, aggregated signature and batch verification improve the efficiency of signature and verification.

[0139] The following are the test results of the proposed solution (this solution) and its comparison with existing solutions.

[0140] This solution is compared with three other secure data aggregation solutions (LVPDA, VMEMDA, and PFDAM) in terms of communication and computing costs.

[0141] For the computational cost assessment, the number of encryption operations at each stage is first calculated, and then the overall cost of comparison is calculated. Since the computational cost of addition is less than that of bilinear pairing and other operations, its calculation is omitted here. The evaluation process is based on the JPBC library, JDK 1.8, and JNA, and the designed algorithm is verified using Java code. The measurement results mainly consider some costly operations, including modular exponentiation, bilinear pairing, and hash operations. All experimental results were obtained using an average of 30 trials. The specific test results are shown in Table 1 below.

[0142] Table 1. Main Operation Time Costs

[0143]

[0144] In Table 1, express The time overhead of modular exponentiation; express The time overhead of modular exponentiation; This represents the time cost of bilinear pairing operations; express The time overhead of modular multiplication operations; Represents a strongly collision-resistant hash function Time expenditure.

[0145] Based on the time cost measurements of each cryptographic primitive provided in Table 1, a comparative analysis of the computational costs of this scheme, as well as LVPDA, VMEMDA, and PFDAM, is conducted. The computational costs of the four schemes at the device-level encryption stage are compared as follows: Figure 5 As shown, compared to the VMEMDA solution, this solution reduces the computational cost of concurrent 1000 IoT devices by at least 50% during data encryption. Although it requires more computational cost than LVPDA and PFDAM solutions, this solution supports more complex and diverse data encryption. The computational cost in the edge layer data aggregation stage is compared to... Figure 6 As shown, this scheme achieves the lowest computational cost in this process, assuming the maximum polymerization amount of the PFDAM scheme is... . Figure 7 The comparison of computational costs for verification and decryption operations performed by the central server is shown. Because the edge servers share some of the data verification work, the computational cost of this solution is also the lowest at this stage. The total computational cost of the above three stages is compared as follows: Figure 8 As shown, this solution can maintain the lowest computing cost as the number of IoT devices increases.

[0146] Regarding communication costs, the total communication overhead of this scheme is 6176 bits. The total communication overheads of VMEMDA, PFDAM, and LVPDA are 6368 bits, 8736 bits, and 4608 bits, respectively. Among them, the PFDAM scheme has the largest aggregation dimension in the communication overhead analysis process. Assuming a value of 5. Compared to the communication overhead of VMEMDA and PFDAM, this solution achieves lower communication overhead, reducing it by approximately 3% and 29.3%, respectively.

[0147] This application provides a secure encrypted data aggregation and transmission method for general IoT scenarios. To improve data transmission efficiency and achieve selective data aggregation, a secure transmission scheme with data classification and aggregation capabilities is constructed by encrypting data based on an improved Paillier encryption algorithm and combining bilinear pairing operations, the Chinese Remainder Theorem, and the Shamir secret sharing mechanism. This method establishes a flexible data filtering and aggregation mechanism by constructing multiple types of verification keys and corresponding encrypted data. The data sender uses system parameters issued by a trusted institution to encrypt and sign the data. Edge nodes filter specific types of data based on the verification keys and aggregate them. Finally, the central server decrypts the data and verifies its authenticity. This application effectively protects data privacy, improves the efficiency of data transmission and aggregation, and has good security and practicality, making it suitable for IoT data processing needs in various complex network environments.

[0148] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0149] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A selective aggregation and authentication method based on multi-type dense state data, characterized in that, include: Each IoT device encrypts and signs the sensing data it acquires based on the central server's public key and shared private key, resulting in encrypted data and signed data. It also calculates and selects a key based on the data type of the sensing data. The shared private key is used by all IoT devices. Each IoT device sends the calculated selection key, encrypted data, and signature data to all secondary edge servers; Each secondary edge server verifies the selected key sent by each IoT device based on its own verification key to determine the encrypted data that conforms to its expected type; Each secondary edge server performs an aggregation operation using multiplication on all encrypted data and corresponding signature data that meet its expected type, resulting in aggregated encrypted data and aggregated signature data. It then sends the aggregated encrypted data and aggregated signature data to the primary edge server. The first-level edge server performs secondary aggregation on all received primary aggregated encrypted data using a super-incrementing sequence to obtain secondary aggregated encrypted data, and performs secondary aggregation on all received primary aggregated signature data using multiplication operations to obtain secondary aggregated signature data. The primary edge server sends the secondary aggregated encrypted data and secondary aggregated signature data to the central server; The central server verifies the secondary aggregated signature data, and when the verification is successful, it decrypts and restores the secondary aggregated encrypted data according to its own private key to obtain the plaintext aggregated value corresponding to all data types. The central server calculates the aggregated plaintext for each data type using a recursive algorithm based on the aggregated plaintext values ​​corresponding to all data types.

2. The selective aggregation and authentication method based on multi-type dense state data according to claim 1, characterized in that, No. Types of data The corresponding selection key is ,in, ; ; ; ; ; ; in, , For model The set of remaining classes, for Large prime numbers in the middle, Modulus multiplication group This is the default value; , Represents the set of positive integers; ; ; , Modulus an integer ring; express The corresponding coefficients of the Chinese Remainder Theorem; This represents a strongly collision-resistant hash function; , This represents the modulo operation; ; .

3. The selective aggregation and authentication method based on multi-type dense state data according to claim 2, characterized in that, No. Types of data The corresponding verification key is ,in, ; ; ; ; ; ; in, To meet The parameters, express The corresponding coefficients of the Chinese Remainder Theorem; To meet The parameters, express The corresponding coefficients of the Chinese Remainder Theorem; To meet The parameters, express The corresponding coefficients of the Chinese Remainder Theorem; To meet The parameters, express The corresponding coefficients of the Chinese Remainder Theorem; ; ; ; .

4. The selective aggregation and authentication method based on multi-type dense state data according to claim 3, characterized in that, The encrypted data is represented as follows: ; in, Indicates Internet of Things (IoT) devices and the Encrypted data corresponding to each data type; Indicates encrypted data The first part; Indicates encrypted data Part Two; ; ; ; , Modulus The multiplication group; , Modulus The multiplication group; ; This represents the public key of the central server; Indicates Internet of Things (IoT) devices and the Perceptual data corresponding to data types.

5. The selective aggregation and authentication method based on multi-type dense state data according to claim 4, characterized in that, The signature data is represented as follows: ; in, Indicates Internet of Things (IoT) devices and the The signature data corresponding to each data type; Represents signature data The first part; Represents signature data Part Two; Indicates Internet of Things (IoT) devices and the The timestamps corresponding to the various data types; It is based on IoT devices For the first The timing for signing perceived data of various data types is determined; ; This represents the shared private key for IoT devices.

6. The selective aggregation and authentication method based on multi-type dense state data according to claim 3, characterized in that, Each secondary edge server verifies the selected key sent by each IoT device using its own verification key to determine the encrypted data that conforms to its expected type, specifically including: Each secondary edge server determines its own authentication key. and the selection key sent to each IoT device If the first verification formula is satisfied, then the encrypted data sent by the corresponding IoT device is determined to be of the expected type. The first verification formula is: ; in, Represents a bilinear pairing function. Input , Output ; and To have the same prime order cyclic group; The generator is ; Indicates the first Types of data The corresponding selection key.

7. The selective aggregation and authentication method based on multi-type dense state data according to claim 4, characterized in that, The secondary aggregated encrypted data is represented as follows: ; in, Indicates secondary aggregation of encrypted data The first part; Indicates secondary aggregation of encrypted data The second part; the symbol ∏ represents multiplication; Indicates the first One-time aggregated encrypted data corresponding to each data type The first part; Indicates the first One-time aggregated encrypted data corresponding to each data type Part Two; Indicates a super-increasing sequence The first in One element; , , Equal to the number of data types.

8. The selective aggregation and authentication method based on multi-type dense state data according to claim 5, characterized in that, The central server verifies the secondary aggregated signature data, specifically including: The central server determines whether the secondary aggregated signature data satisfies the second verification formula, and determines that the verification is successful when the secondary aggregated signature data satisfies the second verification formula; the second verification formula is: ; in, Indicates secondary aggregation of encrypted data The first part; Indicates secondary aggregation of encrypted data Part Two; Indicates Internet of Things (IoT) devices and the The timestamps corresponding to the various data types; Indicates all The product of two products, Less than or equal to the total number of IoT devices The total number of data types is less than or equal to the total number of data types; This represents a summary of the perceived data corresponding to all data types. Indicates the first A summary of the sensing data corresponding to each data type.

9. The selective aggregation and authentication method based on multi-type dense state data according to claim 7, characterized in that, The central server decrypts and recovers the secondary aggregated encrypted data using its own private key, obtaining the plaintext aggregated values ​​corresponding to all data types, specifically including: The central server decrypts the secondary aggregated encrypted data using its private key and a decryption formula; the decryption formula is: ; in, The result of the decryption; The private key for the central server; Indicates the first A summary of sensory data corresponding to various data types; The central server uses a recovery formula to recover the decryption result, obtaining the plaintext aggregate value corresponding to all data types; the recovery formula is: ; in, This is the aggregated plaintext value for all data types.

10. The selective aggregation and authentication method based on multi-type dense state data according to claim 1, characterized in that, The shared private key of the IoT device is determined through secret sharing, specifically as follows: A trusted and authoritative center randomly generates a set of polynomial coefficients. and the secret value set of IoT devices participating in secret sharing ; Threshold values ​​for IoT devices participating in secret recovery; The number of IoT devices participating in the secret sharing; The trusted authority center uses a set of polynomial coefficients, a set of secret values ​​for IoT devices, and preset parameters. The polynomial of degree is used to calculate the polynomial value corresponding to the secret value of each IoT device, and all IoT device secret values ​​and their corresponding polynomial values ​​are distributed to those participating in secret sharing. One IoT device; When any IoT device participating in the secret sharing receives the IoT device secret value and the corresponding polynomial value, it respectively sends to... Other IoT devices participating in the secret sharing send requests to obtain... The IoT device secret value and the corresponding polynomial value received by each of the other IoT devices participating in the secret sharing; Each IoT device participating in the secret sharing receives its own IoT device secret value and corresponding polynomial value, and The other IoT devices participating in secret sharing receive the IoT device secret value and the corresponding polynomial value, and then, using the reconstruction formula, [the following is used to]... Reconstruct the polynomial of degree n by degree n to obtain the reconstructed polynomial. Polynomial of degree; When any of the IoT devices calculates the reconstructed value when the independent variable is 0, The value of the polynomial of degree 1, and the reconstructed polynomial when the independent variable is 0. The value of the polynomial is determined as the shared private key for the IoT device.

Citation Information

Patent Citations

  • Enterprise cloud ERP system data statistical analysis method and system based on homomorphic encryption

    CN113114451A

  • Safe and efficient fine-grained data analysis method for power distribution network

    CN118797744A