Persistent group key negotiation method, system and device in digital twin network, and storage medium
By employing a trusted center to generate public parameters and anonymous keys in a digital twin network, and combining TreeKEM and Shamir secret sharing technologies, the issues of identity privacy and persistence in group key negotiation are resolved, enabling secure and reliable group communication.
Patent Information
- Application Number
- CN202510996473.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-10-28
AI Technical Summary
Existing group key negotiation schemes in digital twin networks fail to effectively protect member identity privacy and do not consider the continuity and security of key negotiation during group communication.
A trusted center is used to generate public parameters, digital twins are used to generate anonymous keys and signatures, TreeKEM is used to achieve efficient group key management, and knowledge signature technology and Shamir secret sharing technology are combined to ensure the key security of offline members.
It achieves persistence, forward security, backward security, and identity privacy in group communication, protecting the identity privacy of digital twins and ensuring data integrity and security.
Smart Images

Figure CN120856320A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of information security and relates to a method, system, device and storage medium for continuous group key negotiation in a digital twin network. Background Technology
[0002] The concept of digital twins was proposed by Grieves. Vehicles transmit real-time data via sensors to their corresponding digital twins. These digital twins establish communication in the cloud, mapping the in-vehicle network to a virtual cyberspace. In recent years, digital twin networks have attracted widespread attention from academia and industry due to their efficient data interaction capabilities and strong technical support for transportation systems. Digital twins exchange information and transmit data to vehicles, enabling vehicles to share data in real time with other vehicles or third-party entities (such as trusted centers or roadside units), thereby achieving dynamic resource scheduling and intelligent decision optimization. However, data sharing in digital twin networks faces severe privacy and security challenges. Because digital twins collect users' sensitive information (such as location, behavioral patterns, and device status) in real time through public channels, this information is highly vulnerable to theft or tampering by malicious attackers, thus affecting vehicle operational safety. Simultaneously, attackers can use sensitive information contained in the shared data, such as vehicle routes, stopping locations, speed changes, and driving habits, to analyze and infer driver identity and activity patterns, threatening vehicle user privacy. Furthermore, digital twins are also susceptible to man-in-the-middle attacks or replay attacks, leading to compromised data integrity. Therefore, it is crucial to ensure both efficient data sharing and effective protection of vehicle privacy, as well as the integrity and security of the data.
[0003] Although several group key negotiation schemes have been proposed for digital twin networks, most of them fail to protect the privacy of members' identities and do not take into account the continuity of key negotiation during group communication and the security of group member keys. Summary of the Invention
[0004] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method, system, device and storage medium for continuous group key negotiation in a digital twin network, which ensures the continuity of group communication, forward security, backward security and identity privacy.
[0005] To achieve the above objectives, the present invention employs the following technical solution: A persistent group key negotiation method in a digital twin network includes the following process: S1, the trusted center generates common parameters; S2, the Trusted Center generates a long-term key for each digital twin participating in the group key generation, and each digital twin generates an anonymous key based on the public parameters and the long-term key; S3: Each digital twin generates a group key ciphertext and signature based on public parameters, all anonymous public keys, and its own long-term key. S4, when a digital twin joins or leaves a key group, it updates the group key ciphertext and signature based on public parameters, the TreeKEM node public key, and its own long-term key; S5, online digital twin generation of new anonymous private and public keys; S6 allows multiple online digital twins to secretly share and jointly generate temporary private keys for offline digital twins.
[0006] Preferably, the common parameters include a collision-resistant hash function, a pseudo-random generator, and Order-addition cyclic group and common key.
[0007] Preferably, the signature generation process in S3 is as follows: a digital neighbor selects a random number and calculates the signature according to a knowledge signature method; other digital neighbors in the group receive the signature and verify it using a verification method.
[0008] Preferably, the specific process of S5 is as follows: the online digital twin randomly selects an updated secret value and generates a new group key, and generates a new group key ciphertext and a new signature based on the updated secret value.
[0009] Preferably, the specific process of S6 is as follows: each online digital twin randomly selects a share and constructs a secret sharing method.
[0010] Preferably, it also includes S7, which, after the offline digital twin goes online, obtains the temporary private key generated in S6 and reconstructs a temporary private key itself.
[0011] Preferably, the reconstruction is performed using the Lagrange interpolation method.
[0012] A persistent group key negotiation system in a digital twin network includes: The initialization module is used by the Trusted Center to generate common parameters; The key generation module is used by the Trusted Center to generate a long-term key for each digital twin participating in the group key generation. Each digital twin generates an anonymous key based on the public parameters and the long-term key. The group key negotiation module is used by each digital twin to generate group key ciphertext and signature based on public parameters, all anonymous public keys and its own long-term key; The member update module is used to update the group key ciphertext and signature when a digital twin joins or leaves the key group, based on public parameters, the TreeKEM node public key, and its own long-term key. The online member key update module is used to generate new anonymous private and public keys online using digital twins. The offline member key update module is used for multiple online digital twins to secretly share and jointly generate temporary private keys for offline digital twins.
[0013] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of a persistent group key negotiation method in the digital twin network.
[0014] A computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the persistent group key negotiation method in the digital twin network.
[0015] Compared with the prior art, the present invention has the following beneficial effects: This invention utilizes digital twins to achieve data interaction and group communication. A trusted center distributes long-term keys to the digital twins, who then use these keys to generate pseudonyms and communicate with other digital twins. This protects the identity privacy of both the digital twins and the physical entity, while the trusted center can trace the true identity of the digital twins, achieving traceability. TreeKEM is used for efficient group key management. Knowledge signature technology ensures message integrity without revealing the true identity of the digital twins, achieving authentication. Shamir secret sharing technology allows online members to generate temporary keys for offline members, ensuring the security of offline members' keys. Attached Figure Description
[0016] Figure 1 This is a flowchart of a persistent group key negotiation method in a digital twin network according to an embodiment of the present invention. Figure 2 is a schematic diagram of the TreeKEM key encapsulation mechanism according to an embodiment of the present invention. Detailed Implementation
[0017] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0018] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," and "counterclockwise," etc., indicating orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of the stated features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terms “installation,” “connection,” and “linkage” should be interpreted broadly, for example, as a fixed connection, a detachable connection, or an integral connection; a mechanical connection, an electrical connection, or a connection that allows communication; a direct connection or an indirect connection via an intermediate medium; or a connection within two elements or an interaction between two elements. The term “and / or” as used herein includes any and all combinations of one or more of the associated listed items. Those skilled in the art will understand the specific meaning of the above terms in this invention according to the specific circumstances. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention.
[0020] In the present invention, unless otherwise expressly specified or limited, a first feature being "above" or "below" a second feature may include the first and second features being in direct contact, or may include the first and second features being in contact not directly but through another feature between them. Furthermore, a first feature being "above," "above," and "above" a second feature may include the first feature being directly above or obliquely above the second feature, or may simply mean that the first feature is higher in level than the second feature. A first feature being "below," "below," and "below" a second feature may include the first feature being directly below or obliquely below the second feature, or may simply mean that the first feature is lower in level than the second feature.
[0021] The following disclosure provides many different embodiments or examples for implementing various structures of the invention. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the invention. Furthermore, reference numerals and / or letters may be repeated in different examples; such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed. In addition, examples of various specific processes and materials are provided in this invention, but those skilled in the art will recognize the application of other processes and / or the use of other materials.
[0022] like Figure 1 The diagram illustrates the persistent group key negotiation method in a digital twin network described in this embodiment, which includes the following process: System initialization steps: The Trusted Center generates common parameters based on security parameters and publishes the generated common parameters to the digital twin in the system; Key generation steps: The trusted center generates a long-term key for the digital twins in the system, and each digital twin generates an anonymous key based on public parameters and the long-term key; Group key negotiation steps: Each digital twin generates a group key ciphertext and signature based on public parameters, the anonymous public keys of all digital twins, and its own long-term key; Member update steps: When a digital twin joins or leaves a key group, it generates a member update ciphertext and signature based on public parameters, the TreeKEM node's public key, and its own long-term key. Online member key update steps: A new anonymous private key and anonymous public key are generated using a digital twin; Offline member key update steps: Multiple digital twins secretly share and jointly generate temporary private keys for offline members.
[0023] The following is a detailed description of each step: System initialization steps include: Step 1: Enter security parameters ; The second step is to choose a collision-resistant hash function. Pseudo-random generator ; Third step, select Cyclic group of addition ,in yes Generators; Step 4: Randomly select the master key Public key of computing system ; Step 5: Output common parameters .
[0024] The key generation steps include: The first step is for the Trusted Center to randomly select... ,calculate via secure channel Send to the corresponding digital twin; The second step involves randomly selecting digital twins. ,calculate Anonymous private key and Anonymous public key and Publicly anonymous public keys .
[0025] The group key negotiation steps include: The first step is to create a system with... A group of members ,make The current timestamp indicates the group member status. Record the update time of its anonymous key and define the maximum time without update. ; The second step is to select randomly. ,calculate According to the TreeKEM key encapsulation mechanism in Figure 2(a), Encryption, obtaining ciphertext , public key ,in , ; The third step is to... , ,choose ,calculate , , , and The signature is Publicly accessible encrypted signature pairs ; Step 4, other digital twins receive ,calculate Verify the equation Is it valid? If valid, use your own private key. Decryption The corresponding ciphertext ,get .
[0026] Member update steps include: The first step, when adding members, New members Add to group, set . The status is the current timestamp ,Right now When deleting a member, any digital twin... Will Deleted from the group, obtained ; Step 2, Random selection ,calculate Define the public key for TreeKEM nodes. According to the TreeKEM key encapsulation mechanism in Figures 2(b) and 2(c), Encryption, obtaining ciphertext .make ; The third step, definition , . choose ,calculate , , , and The signature is Publicly accessible encrypted signature pairs ; Step 4, other digital twins receive ,calculate ,verify Does the equation hold true? If the equation holds true, Use your own private key Or TreeKEM node private key decryption The corresponding ciphertext ,get .
[0027] The online member key update steps include: first step, calculate Anonymous private key and Anonymous public key and Publicly anonymous public keys ; The second step is to set the state to the current timestamp. ,Right now . Random selection ,calculate Define the public key for TreeKEM nodes. According to the TreeKEM key encapsulation mechanism in Figure 2(d), the node secret value is... Encryption, obtaining ciphertext .make ; The third step is to define... , . choose ,calculate , , , and The signature is Publicly accessible encrypted signature pairs ; Step 4, other digital twins receive ,calculate Verify the equation If the equation holds true, use Decryption The corresponding ciphertext Obtain the group key .
[0028] The offline member key update steps include: First step, every At that time, Check if group members have not updated their keys for a long time, i.e., verify. ,in This is the current timestamp. If it satisfies... Then it is believed Offline. To ensure the security of its key, Other Initiate secret sharing, for Distribute a temporary key; The second step, each Random selection As a temporary private key share, construct polynomial of degree in . calculate and temporary public key shares ,public . Aggregate them into a temporary public key ; The third step, Will Sent via secure channel ,all calculate ; Fourth step, when After going online, to Request a temporary private key, where indivual Will Sent via secure channel . Reconstruct the temporary private key using Lagrange interpolation polynomials. ,in .
[0029] In the above formula, the parameters have the following meanings: : a large prime number; : Rank Multiplication cyclic group; For the group Generators; : Common parameters; : Secure hash function; Pseudo-random generator; Digital twins participating in group key negotiation; : The long-term key; : Random number; Hash function Number of generated numbers; : Anonymous public key; : Anonymous private key; : An array of group member identity information; Trusted Center Master Key; Trusted center master public key; : The state; : Current timestamp; Random numbers associated with the group key; :Group key; Group key ciphertext; : Ciphertext collection; : Collection of encrypted and group messages; Knowledge signature example; Knowledge signature evidence; : Random number for signature; : Corresponding parameters; Hash function Number of generated numbers; : Combined separately The relevant parameters; : Signature of the group key ciphertext; Temporary private key share; Temporary public key share; Secretly shared polynomial functions; Secretly shared polynomial coefficients; : Each about The share; Lagrange interpolation polynomial parameters; Temporary public key; Temporary private key.
[0030] The following are embodiments of the apparatus of the present invention, which can be used to execute embodiments of the method of the present invention. For details not omitted in the apparatus embodiments, please refer to the embodiments of the method of the present invention.
[0031] In another embodiment of the present invention, a persistent group key negotiation system in a digital twin network is provided. This persistent group key negotiation system in a digital twin network can be used to implement the above-mentioned persistent group key negotiation method in a digital twin network. Specifically, the persistent group key negotiation system in a digital twin network includes a variable initialization module, a key generation module, a group key negotiation module, a member update module, an online member key update module, and an offline member key update module.
[0032] The initialization module is used by the Trust Center to generate common parameters.
[0033] The key generation module is used by the Trusted Center to generate a long-term key for each digital twin participating in the group key generation. Each digital twin generates an anonymous key based on the public parameters and the long-term key.
[0034] The group key negotiation module is used by each digital twin to generate group key ciphertext and signature based on public parameters, all anonymous public keys and its own long-term key.
[0035] The member update module is used by digital twins to update the group key ciphertext and signature based on public parameters, the TreeKEM node public key, and their own long-term key when joining or leaving a key group.
[0036] The online member key update module is used to generate new anonymous private and public keys online for digital twins.
[0037] The offline member key update module is used for multiple online digital twins to secretly share and jointly generate temporary private keys for offline digital twins.
[0038] In another embodiment of the present invention, a terminal device is provided, comprising a processor and a memory. The memory stores a computer program, the computer program including program instructions, and the processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), or field-programmable gate arrays (FPGAs). Gate Array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., are the computing and control core of the terminal. They are suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to realize the corresponding method flow or corresponding function. The processor described in this embodiment of the invention can be used for the operation of a persistent group key negotiation method in a digital twin network, including: S1, the trusted center generates public parameters; S2, the trusted center generates a long-term key for each digital twin participating in group key generation, and each digital twin generates an anonymous key based on the public parameters and the long-term key; S3, each digital twin generates group key ciphertext and signature based on the public parameters, all anonymous public keys and its own long-term key; S4, when a digital twin joins or leaves the key group, it updates the group key ciphertext and signature based on the public parameters, the TreeKEM node public key and its own long-term key; S5, online digital twins generate new anonymous private keys and anonymous public keys; S6, multiple online digital twins secretly share and jointly generate temporary private keys for offline digital twins.
[0039] In another embodiment, the present invention also provides a computer-readable storage medium (Memory), which is a memory device in a terminal device for storing programs and data. It is understood that the computer-readable storage medium here may include both the built-in storage medium in the terminal device and extended storage media supported by the terminal device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for loading and execution by a processor, which may be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, and a read-only memory (ROM).
[0040] One or more instructions stored in a computer-readable storage medium can be loaded and executed by a processor to implement the corresponding steps of the persistent group key negotiation method in the digital twin network described in the above embodiments. One or more instructions in the computer-readable storage medium are loaded by the processor and executed as follows: S1, the trusted center generates public parameters; S2, the trusted center generates a long-term key for each digital twin participating in group key generation, and each digital twin generates an anonymous key based on the public parameters and the long-term key; S3, each digital twin generates group key ciphertext and signature based on the public parameters, all anonymous public keys, and its own long-term key; S4, when a digital twin joins or leaves the key group, it updates the group key ciphertext and signature based on the public parameters, the TreeKEM node public key, and its own long-term key; S5, online digital twins generate new anonymous private keys and anonymous public keys; S6, multiple online digital twins secretly share and jointly generate temporary private keys for offline digital twins.
[0041] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, optical storage, etc.) containing computer-usable program code.
[0042] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0043] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0044] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0045] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0046] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0047] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0048] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0049] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
[0050] It should be understood that the above description is for illustrative purposes and not for limitation. Many embodiments and applications beyond the provided examples will be apparent to those skilled in the art upon reading the above description. Therefore, the scope of this patent should not be determined by reference to the above description, but rather by reference to the foregoing claims and the full scope of their equivalents. For purposes of completeness, all articles and references, including patent applications and publications, are incorporated herein by reference. The omission of any aspect of the subject matter disclosed herein in the foregoing claims is not intended as a waiver of that subject matter, nor should it be construed as an indication that the applicant has not considered that subject matter as part of the disclosed inventive subject matter.
Claims
1. A persistent group key negotiation method in a digital twin network, characterized in that, Includes the following processes: S1, the trusted center generates common parameters; S2, the Trusted Center generates a long-term key for each digital twin participating in the group key generation, and each digital twin generates an anonymous key based on the public parameters and the long-term key; S3: Each digital twin generates a group key ciphertext and signature based on public parameters, all anonymous public keys, and its own long-term key. S4, when a digital twin joins or leaves a key group, it updates the group key ciphertext and signature based on public parameters, the TreeKEM node public key, and its own long-term key; S5, online digital twin generation of new anonymous private and public keys; S6 allows multiple online digital twins to secretly share and jointly generate temporary private keys for offline digital twins.
2. The persistent group key negotiation method in a digital twin network according to claim 1, characterized in that, Public parameters include a collision-resistant hash function, a pseudo-random generator, Additive cyclic group and common key.
3. The persistent group key negotiation method in a digital twin network according to claim 1, characterized in that, The signature generation process in S3 is as follows: a digital neighbor selects a random number and calculates the signature according to a knowledge signature method; other digital neighbors in the group receive the signature and verify it using a verification method.
4. The persistent group key negotiation method in a digital twin network according to claim 1, characterized in that, The specific process of S5 is as follows: the online digital twin randomly selects an updated secret value and generates a new group key, and generates a new group key ciphertext and a new signature based on the updated secret value.
5. The persistent group key negotiation method in a digital twin network according to claim 1, characterized in that, The specific process of S6 is as follows: each online digital twin randomly selects a share and constructs a secret sharing method.
6. The persistent group key negotiation method in a digital twin network according to claim 1, characterized in that, It also includes S7, which, after the offline digital twin is brought online, obtains the temporary private key generated in S6 and reconstructs a temporary private key itself.
7. The persistent group key negotiation method in a digital twin network according to claim 6, characterized in that, Reconstruction was achieved using the Lagrange interpolation technique.
8. A persistent group key negotiation system in a digital twin network, characterized in that, include: The initialization module is used by the Trusted Center to generate common parameters; The key generation module is used by the Trusted Center to generate a long-term key for each digital twin participating in the group key generation. Each digital twin generates an anonymous key based on the public parameters and the long-term key. The group key negotiation module is used by each digital twin to generate group key ciphertext and signature based on public parameters, all anonymous public keys and its own long-term key; The member update module is used to update the group key ciphertext and signature when a digital twin joins or leaves the key group, based on public parameters, the TreeKEM node public key, and its own long-term key. The online member key update module is used to generate new anonymous private and public keys online using digital twins. The offline member key update module is used for multiple online digital twins to secretly share and jointly generate temporary private keys for offline digital twins.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the persistent group key negotiation method in a digital twin network as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the persistent group key negotiation method in a digital twin network as described in any one of claims 1 to 7.