Data security aggregation method and device for intelligent terminal network

By employing attribute-adaptive dynamic grouping and multi-key homomorphic encryption technologies, the problem of client group adaptability and security in smart terminal networks is solved, achieving efficient and secure data aggregation, and is suitable for smart terminal environments with dynamic topology changes.

CN120915425APending Publication Date: 2025-11-07BEIJING INFORMATION SCI & TECH UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511190210.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In smart terminal scenarios, existing technologies have poor adaptability to dynamic topology changes and cannot provide sufficient security. Furthermore, existing encryption methods have high computational overhead and poor adaptability, making it difficult to meet the requirements of real-time performance and lightweight design.

Method used

Employing attribute-adaptive dynamic grouping and multi-key homomorphic encryption, a global public key is generated using Pedersen distributed keys. Combined with NTRU-RLWE homomorphic encryption, Shamir secret sharing, and Pedersen commitments, and using Hadamard product verification tags for dual verification, multimodal data feature fusion and efficient privacy protection are achieved.

Benefits of technology

It improves the security and adaptability of smart terminal networks, reduces communication overhead, enhances resistance to malicious attacks, ensures the reliability and real-time nature of aggregation results, and is suitable for dynamically changing smart terminal environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915425A_ABST
    Figure CN120915425A_ABST
Patent Text Reader

Abstract

The invention discloses a data security aggregation method and device for an intelligent terminal network, and relates to the technical field of intelligent terminal networks, and the method comprises the steps: carrying out the dynamic grouping of clients in the intelligent terminal network through employing an attribute adaptive dynamic grouping mechanism; and completing data security aggregation based on multi-key homomorphic encryption. According to the invention, by combining the attribute adaptive dynamic grouping technology and the multi-key homomorphic encryption technology, the security and adaptability of terminal aggregation can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of intelligent terminal network, in particular to a data security aggregation method and device of intelligent terminal network. BACKGROUND

[0002] For client grouping and multi-source heterogeneous data security aggregation in the intelligent terminal scenario, there are currently various implementation schemes. For example, clustering algorithms such as K-means clustering method and Density-Based Spatial Clustering of Applications with Noise (DBSCAN) are used to group clients. However, grouping clients based on clustering algorithms has poor adaptability in dynamic topology changes, and cannot provide sufficient security protection. For data privacy protection, the differential privacy method protects privacy by adding noise to the data, but this method usually increases the computational overhead and makes it difficult to efficiently process heterogeneous data. In terms of aggregation calculation, multi-party computation protocol (MPC) can effectively prevent data leakage by collaborative calculation of multiple clients, but its high computational overhead and delay make it difficult to apply in intelligent terminal environments with high real-time requirements. Existing secure aggregation protocols have off-line fault tolerance, but are only applicable to the parameter level and cannot achieve semantic-level aggregation; single-key homomorphic encryption supports ciphertext calculation, but has large computational overhead and poor adaptability, making it difficult to meet the real-time and lightweight requirements of terminals. SUMMARY

[0003] The purpose of the present application is to provide a data security aggregation method and device of intelligent terminal network, which combines attribute adaptive dynamic grouping technology and multi-key homomorphic encryption technology, supports multi-modal data feature fusion during data aggregation, has efficient privacy protection capability, and can improve the security and adaptability of terminal aggregation.

[0004] To achieve the above purpose, the present application provides the following solutions.

[0005] In a first aspect, the present application provides a data security aggregation method of intelligent terminal network, comprising:

[0006] using an attribute adaptive dynamic grouping mechanism to dynamically group clients in the intelligent terminal network;

[0007] determining a global public key; the global public key is generated by all clients in the intelligent terminal network based on Pedersen distributed key cooperation;

[0008] the client extracts multi-dimensional feature data of local data, and maps the multi-dimensional feature data to single-dimensional data using super-increasing encoding;

[0009] The client performs NTRU-RLWE homomorphic encryption on the single-dimensional data using a global public key to obtain first-level encrypted data;

[0010] The client performs random masking processing on the first-level encrypted data using Shamir secret sharing to obtain second-level encrypted data;

[0011] The client performs fragmentation processing on the second-level encrypted data and appends a commitment to the fragments using Pedersen commitment and appends a verification tag generated through Hadamard product to obtain a plurality of fragmented data;

[0012] The fragmented data is transmitted to an intra-group aggregation center through a P2P network;

[0013] The intra-group aggregation center re-encrypts the received plurality of fragmented data using a re-encryption key and performs intra-group aggregation calculation to obtain intra-group aggregation ciphertext;

[0014] The intra-group aggregation center sends the intra-group aggregation ciphertext to a global aggregation center;

[0015] The global aggregation center aggregates the received plurality of intra-group aggregation ciphertexts to obtain global aggregation ciphertext;

[0016] The global aggregation center recovers the global aggregation ciphertext into plaintext data using Lagrange interpolation algorithm;

[0017] The global aggregation center broadcasts the plaintext data;

[0018] After receiving the plaintext data, the client decrypts the plaintext data in cooperation with the global aggregation center to obtain multi-dimensional decrypted data;

[0019] The client performs double verification based on the Hadamard product verification tag, local data and multi-dimensional decrypted data;

[0020] Abnormalities are identified according to the double verification result.

[0021] Optionally, the global public key is determined, specifically including: all clients select random polynomials to generate private key fragments according to Pedersen distributed key generation protocol, and collaboratively calculate the global public key.

[0022] Optionally, the global aggregation center is a client elected in the intelligent terminal network through PBFT consensus protocol.

[0023] Optionally, according to the double verification result, abnormalities are identified, specifically including:

[0024] A first judgment result is obtained by determining whether an untampered condition is met; the untampered condition is that all clients in the intelligent terminal network meet double verification of Pedersen commitment and Hadamard product verification tag.

[0025] If the first determination result is yes, it is determined that the aggregation result is reliable.

[0026] If the first determination result is no, the client that does not meet the double verification triggers an alarm to prompt that an abnormal client participates in data cooperation and aggregation, and it is determined that the aggregation result is abnormal and invalid.

[0027] Optionally, the intelligent terminal network is dynamically grouped by using an attribute adaptive dynamic grouping mechanism, and the grouping mechanism specifically includes the following steps.

[0028] Initializing client grouping: temporarily grouping all clients in the intelligent terminal network according to the states of the clients, and determining an in-group aggregation center of each temporary client group.

[0029] Respectively determining an attribute perception score of each client.

[0030] Respectively determining a comprehensive weighted distance of each client to the in-group aggregation center of the corresponding temporary group according to the Euclidean distance between the clients and the attribute perception score of each client.

[0031] Based on the multiple comprehensive weighted distances, an aggregation center with the minimum comprehensive weighted distance is elected from all temporary groups in the intelligent terminal network, re-grouping is performed, and multiple real-time client groups are obtained.

[0032] Determining whether the in-group entropy value fluctuation of the current real-time client group after re-grouping is less than a set in-group entropy value fluctuation threshold to obtain a second determination result; the current real-time client group is any real-time client group.

[0033] If the second determination result is yes, the current real-time client group is maintained.

[0034] If the second determination result is no, the in-group aggregation center of the current real-time client group is updated.

[0035] When the intelligent terminal network structure changes, the multiple real-time client groups are dynamically adjusted.

[0036] Determining a global change entropy value after the multiple real-time client groups are dynamically adjusted.

[0037] When the global change entropy value exceeds a global threshold, returning to the step of “based on the multiple comprehensive weighted distances, an aggregation center with the minimum comprehensive weighted distance is elected from all temporary groups in the intelligent terminal network, re-grouping is performed, and multiple real-time client groups are obtained”.

[0038] Optionally, the attribute perception score is determined based on state attribute information of the client; and the state attribute information includes stability, communication delay, and resource utilization.

[0039] Optionally, when the intelligent terminal network structure changes, the plurality of real-time client groups are dynamically adjusted, and the method specifically comprises the following steps:

[0040] When a new client joins the intelligent terminal network, a comprehensive weighted distance between the new client and each group internal aggregation center is calculated;

[0041] The real-time client group corresponding to the minimum comprehensive weighted distance is determined as a target real-time client group of the new client;

[0042] The new client is added to the target real-time client group.

[0043] Optionally, when the intelligent terminal network structure changes, the plurality of real-time client groups are dynamically adjusted, and the method further comprises the following steps:

[0044] When a non-group internal aggregation center in the current real-time client group exits, it is judged whether the group internal entropy value fluctuation after the non-group internal aggregation center exits the current real-time client group is less than a set group internal entropy value fluctuation threshold, to obtain a third judgment result;

[0045] If the third judgment result is yes, the current real-time client group is maintained;

[0046] If the third judgment result is no, the group internal aggregation center of the current real-time client group is updated.

[0047] Optionally, when the intelligent terminal network structure changes, the plurality of real-time client groups are dynamically adjusted, and the method further comprises the following steps:

[0048] When a group internal aggregation center in the current real-time client group exits, a new center client with the minimum comprehensive weighted distance is determined as the group internal aggregation center of the current real-time client group.

[0049] In a second aspect, the present application provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor executes the computer program to implement the data security aggregation method of the intelligent terminal network.

[0050] According to the embodiments provided in the present application, the following technical effects are achieved:

[0051] The application provides a data security aggregation method and device of an intelligent terminal network. For the grouping mechanism and data aggregation method of the intelligent terminal, many schemes have limitations in dealing with network topology changes, client dynamics, and heterogeneous data transmission and aggregation. Traditional grouping methods often cannot flexibly adapt to changes in client attributes, easily leading to low communication efficiency or system vulnerability; while common encryption aggregation methods can protect data privacy, but perform poorly in real-time performance and computational overhead. The application designs an attribute adaptive dynamic grouping module, which can dynamically optimize the grouping structure according to the real-time state of the client (such as stability, communication delay, resource utilization, etc.), ensuring efficient and robust data transmission under topology changes. Through the cooperative optimization mechanism of the comprehensive weighted distance and entropy value, the communication overhead is effectively reduced and the resistance to malicious attacks is enhanced, improving the adaptability and security in harsh environments. In addition, for the aggregation of multi-dimensional heterogeneous data, the application combines NTRU-RLWE homomorphic encryption, Shamir secret sharing, and Pedersen commitment technology to ensure privacy and integrity during data transmission. By using the Pedersen commitment and Hadamard product verification tag double verification mechanism, the credibility of the aggregation result is ensured, providing efficient and secure data aggregation without tampering with the data. This method not only meets the requirements of real-time performance and resource consumption in the intelligent terminal scenario, but also effectively improves the security and credibility of the aggregation result. In summary, the application significantly optimizes system performance while ensuring data privacy protection, and improves the adaptability to dynamic changes in the environment, making it more suitable for efficient and secure data aggregation applications in the intelligent terminal environment. BRIEF DESCRIPTION OF DRAWINGS

[0052] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0053] Figure 1 A flow chart of a data security aggregation method of an intelligent terminal network in an embodiment of the application;

[0054] Figure 2 A flow chart of an attribute adaptive dynamic grouping mechanism in an embodiment of the application. DETAILED DESCRIPTION

[0055] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work belong to the scope of protection of the present application.

[0056] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application will be further described in detail below with reference to the drawings and specific embodiments.

[0057] The professional terms involved in the data security aggregation method and device of the intelligent terminal network provided by the present application are as follows:

[0058] Intelligent terminal: An intelligent terminal refers to a device with computing, storage, communication and sensing capabilities, capable of data processing and real-time response in an edge computing environment. Intelligent terminals usually include smartphones, tablet computers, Internet of Things devices, vehicle-mounted terminals, etc., which connect other devices or the cloud through wireless networks for data exchange and collaborative work, and are widely used in Internet of Things, Internet of Vehicles, smart home, etc.

[0059] Multi-source heterogeneous data: Multi-source heterogeneous data refers to a collection of data from different sources, formats, types and structures. In the intelligent terminal scenario, data sources may include sensors, cameras, user behavior, environmental monitoring devices, etc., which usually contain various formats such as text, images, audio and video, etc.

[0060] Euclidean distance: Euclidean distance is the straight-line distance between two points, commonly used to measure the similarity of two points in space. In the client grouping and aggregation problem, Euclidean distance is used to measure the difference or similarity between different nodes (clients), and the distance of each node in the multi-dimensional attribute space is calculated to determine its grouping or cooperation relationship.

[0061] Hyper-incremental encoding: Hyper-incremental encoding is a technique for data compression, aiming to map high-dimensional data into single-dimensional values. In the multi-dimensional data aggregation of intelligent terminals, hyper-incremental encoding converts multi-dimensional feature values into single-dimensional values that are easy to aggregate, thereby reducing computational and storage overhead and improving data processing efficiency.

[0062] NTRU-RLWE homomorphic encryption: NTRU-RLWE (NTRU-based Ring Learning With Errors) homomorphic encryption is a lattice-based encryption algorithm that can support computations on encrypted data without decryption. NTRU-RLWE homomorphic encryption can perform addition and multiplication operations on encrypted data while ensuring data privacy.

[0063] Shamir Secret Sharing: Shamir Secret Sharing is an encryption method that divides a secret into multiple pieces and distributes them to different participants, and only when enough participants cooperate can the original secret be restored. In the secure aggregation of intelligent terminals, Shamir Secret Sharing ensures that the overall data remains secure even if any single node is attacked or compromised by dividing and distributing encrypted data to different nodes, providing data privacy protection.

[0064] Random Masking: Random masking is a method of perturbing data by generating random values, often used for data protection and privacy enhancement. In the process of data aggregation, random masking adds random values to encrypted data, making it impossible for any malicious node to tamper with or infer the aggregated result before decryption. The mask is shared among multiple participants, and the true data is recovered by removing the mask, thus protecting the privacy and integrity of the data.

[0065] Pedersen Commitment: An encryption commitment protocol that ensures the integrity and tamper resistance of data. By combining a hash function and an encryption algorithm to generate a commitment value, the commitment value encrypts and binds certain secret information (such as data or passwords) to a specific value. When data is transmitted or aggregated among multiple participants, Pedersen commitment ensures that each participant can only see the commitment value and cannot know the original data content. Only when multiple commitment parties cooperate can the original data be revealed, thus providing data privacy protection.

[0066] Lagrange Interpolation Algorithm: Lagrange Interpolation Algorithm is a method for constructing a polynomial through given data points. It is based on the interpolation theory of polynomials, which constructs a unique polynomial passing through a set of discrete points. In the process of data aggregation, Lagrange Interpolation Algorithm is often used to recover the plaintext value of fragmented encrypted data. By using Lagrange Interpolation, even if some data fragments are lost or partially tampered with, the correct aggregation result can still be recovered from the remaining valid fragments, ensuring the integrity and accuracy of the data.

[0067] Hadamard Product: A matrix operation that calculates the element-wise product of corresponding elements between two matrices or vectors. Hadamard product is different from matrix multiplication, which is based on the determinant operation, while Hadamard product is based on the multiplication of elements in corresponding positions of two matrices, resulting in a matrix of the same size as the original matrix. That is, if there are two matrices A and B, their Hadamard product C is: C = A·B.

[0068] Practical Byzantine Fault Tolerance (PBFT): A consensus protocol used in distributed systems that can ensure system consistency and reliability even in the presence of a certain proportion of malicious nodes. PBFT protocol through multiple rounds of voting and message exchange, to ensure that even if some nodes fail or behave maliciously, the system can still reach a consensus.

[0069] In one exemplary embodiment, a data security aggregation method of intelligent terminal network is provided, comprising: attribute adaptive dynamic grouping (i.e., step 101) and data security aggregation based on multi-key homomorphic encryption (i.e., steps 102 to 1015).

[0070] Step 101: dynamically group the intelligent terminal network using an attribute adaptive dynamic grouping mechanism.

[0071] Step 101 specifically includes:

[0072] Initialize client grouping: temporarily group all clients in the intelligent terminal network according to their states, and determine the intra-group aggregation center of each temporary client group.

[0073] Determine the attribute-aware score of each client respectively. The attribute-aware score is determined based on the state attribute information of the client. The state attribute information includes stability, communication delay, and resource utilization.

[0074] Determine the comprehensive weighted distance Dist(n q ,n g ) of each non-aggregation center client n q to the corresponding temporary grouping intra-group aggregation center n g , according to the Euclidean distance Δ(n q ,n g ) between the clients and the attribute-aware score of each client.

[0075]

[0076] Where Δ(n q ,n g ) is the spatial Euclidean distance between the node and the center node. is the node attribute-aware score function, which measures the comprehensive data collaboration ability of the node. is a preset weight coefficient, reflecting the importance of different attributes. Stability Sta(n), communication delay Com(n), and resource utilization Res(n). is the maximum physical distance between all node pairs, used for normalizing the distance value. max and min of the node scores, respectively, for normalizing attribute differences. is a balancing factor for adjusting the balance between spatial distance and attribute difference. and are the coordinates of n q and n g , respectively. If g = argmin 1≤g≤G Dist(n q , n g ), then n q is assigned to the group H g , forming the group set H = {H1, H2, …, H G}. G = {n1, n2, …, n G} is the initial set of central nodes.

[0077] Based on multiple comprehensive weighted distances, an aggregated center with the minimum comprehensive weighted distance is elected from all temporary groups in the intelligent terminal network, and the intelligent terminal network is re-grouped to obtain multiple real-time client groups.

[0078] It is determined whether the intra-group entropy value fluctuation of the current real-time client group after re-grouping is less than a set intra-group entropy value fluctuation threshold, to obtain a second determination result. The current real-time client group is any real-time client group.

[0079] If the second determination result is yes, the current real-time client group is maintained.

[0080] If the second determination result is no, the intra-group aggregated center of the current real-time client group is updated.

[0081] When the intelligent terminal network structure changes, the multiple real-time client groups are dynamically adjusted.

[0082] A global change entropy value after the multiple real-time client groups are dynamically adjusted is determined.

[0083] When the global change entropy value exceeds a global threshold, the step of “based on multiple comprehensive weighted distances, an aggregated center with the minimum comprehensive weighted distance is elected from all temporary groups in the intelligent terminal network, and the intelligent terminal network is re-grouped to obtain multiple real-time client groups” is returned.

[0084] The multiple real-time client groups are dynamically adjusted, and specifically include:

[0085] When a new client joins the intelligent terminal network, a comprehensive weighted distance between the new client and each intra-group aggregated center is calculated.

[0086] A real-time client group corresponding to the minimum comprehensive weighted distance is determined as a target real-time client group of the new client.

[0087] The new client is added to the target real-time client group.

[0088] When the non-in-group aggregation center in the current real-time client group exits, it is determined whether the in-group entropy value fluctuation after the non-in-group aggregation center exits the current real-time client group is less than a set in-group entropy value fluctuation threshold, to obtain a third determination result.

[0089] If the third determination result is yes, the current real-time client group is maintained.

[0090] If the third determination result is no, the in-group aggregation center of the current real-time client group is updated.

[0091] When the in-group aggregation center in the current real-time client group exits, a new center client with the minimum comprehensive weighted distance is determined as the in-group aggregation center of the current real-time client group.

[0092] Attribute adaptive dynamic grouping is a grouping mechanism designed for the dynamic change of topology in an intelligent terminal network, which is used to cope with frequent fluctuations in client state and multi-source attribute heterogeneity. This method dynamically constructs a grouping structure based on attributes such as stability, communication delay and resource utilization of the client, and cooperatively optimizes the entropy value and the weighted distance to improve communication efficiency and resist potential attacks.

[0093] Among them, the design of attribute weighted distance is one of the key mechanisms, which comprehensively considers the spatial position and current state attributes of the client, evaluates the cooperative adaptability between each client and the temporary center client, and is used to complete the preliminary grouping and the determination of the temporary center. Then, by minimizing the average cooperative cost in the group, the selection of the center client is dynamically optimized, that is, if there is a client with better cooperative distance, the center is replaced. This process designs an in-group entropy value as a robustness indicator. If the in-group entropy value fluctuation is higher than the set threshold, the in-group center client is updated, otherwise the original structure is maintained, to reduce unnecessary changes.

[0094] In addition, in order to ensure the stability and dynamic adaptability of the grouping, periodic grouping adjustment needs to be performed. When a client joins or exits, the comprehensive weighted distance between it and each center client and the in-group entropy value change are calculated, and if the influence exceeds the threshold, a global update is triggered. The whole mechanism dynamically optimizes the center client and the grouping structure through continuous monitoring of the global change entropy value, ensuring that the intelligent terminal system still has efficient and reliable cooperative aggregation capability in the environment of resource limitation and malicious disturbance.

[0095] As Figure 2 , the specific grouping process is as follows:

[0096] 1) Initialize all clients N={n1, n2, …, n N}, randomly select G nodes as the initial center node set G={n1, n2, …, n G}, and each center node ng identified by index g e [1, G]. The rest of the node set is Q = {n1, n2, …, n Q} (Q e [1, N-G]). Temporary grouping is performed according to their current states, and the central client and group members are preliminarily divided.

[0097] 2) Extract the state attribute information of each client, including stability Sta(n), communication delay Com(n), and resource utilization Res(n), and calculate the corresponding attribute-aware score.

[0098]

[0099] is the node attribute-aware score function, which is used to measure the comprehensive cooperation ability of the node. is the preset weight coefficient, reflecting the importance of different attributes.

[0100] 3) Combine the attribute-aware score and the Euclidean distance between clients to calculate the comprehensive weighted distance of each client to the central client.

[0101] 4) Redivide the client grouping according to the comprehensive weighted distance, and dynamically optimize the central client in each group.

[0102] 5) Determine whether the group entropy fluctuation during grouping adjustment is less than the set threshold. If it is greater, replace the central client. If it is less, maintain the original structure.

[0103] 6) When a new client joins, calculate its comprehensive weighted distance with all central clients, and join the target group with the smallest distance.

[0104] 7) If a central client exits, select a new central client with the smallest comprehensive weighted distance according to the current group clients.

[0105] 8) When a normal client exits, determine whether its influence causes the group entropy fluctuation to be greater than the threshold. If so, perform global update. Otherwise, keep the original grouping unchanged.

[0106] 9) Determine whether the global change entropy value after grouping structure adjustment exceeds the global threshold. If it exceeds, re-execute the central client dynamic optimization and grouping adjustment. If it does not exceed, end the entire process.

[0107] The data security aggregation method based on multi-key homomorphic encryption is mainly used to solve the security problem of multi-dimensional heterogeneous data in the transmission and aggregation process in the intelligent terminal scene. The method effectively prevents data tampering, link hijacking and replay attacks, while protecting the privacy of multi-dimensional data in the transmission process by combining super-increasing encoding, NTRU-RLWE homomorphic encryption, Shamir secret sharing, Pedersen commitment and Hadamard product verification label.

[0108] Firstly, the client super-increasingly encodes the multi-dimensional data parameters, compressing the high-dimensional data into single-dimensional values for subsequent aggregation operations. Then, the client uses NTRU-RLWE homomorphic encryption to encrypt these single-dimensional values, ensuring that sensitive information is not leaked during transmission. In addition, to further protect data security, each client also fragments the encrypted data through Shamir secret sharing and generates Pedersen commitment and Hadamard product verification labels for data integrity verification.

[0109] During aggregation, multiple clients transmit encrypted data fragments to the aggregation center. The aggregation center performs proxy re-encryption operations to convert the encrypted ciphertext into a global public key encryption form. After receiving at least T valid fragments, it performs in-group aggregation and transmits to the global aggregation center (selected by the Practical Byzantine Fault Tolerance (PBFT) consensus protocol). After that, the global aggregation center restores the plaintext data through the Lagrange interpolation algorithm and broadcasts it to all clients for collaborative decryption, ensuring data correctness and integrity.

[0110] To further ensure the credibility of the aggregation result, a Hadamard product verification label and Pedersen commitment double verification mechanism is designed. After data aggregation is complete, the client verifies the aggregation result together with the Hadamard product verification label, and verifies the integrity of the data through Pedersen commitment. If the double verification is successful, it means that the aggregation result has not been tampered with and is credible and complete. If the verification fails, an alarm mechanism is triggered to trace abnormal data participants or fragments, ensuring the security and correctness of the aggregation result.

[0111] Step 102: Determine the global public key. The global public key is generated by all clients in the intelligent terminal network based on the Pedersen distributed key collaboration. All clients select random polynomials to generate private key fragments and collaboratively calculate the global public key according to the Pedersen distributed key generation protocol.

[0112] Step 103: The client extracts the multi-dimensional feature data of local data and maps the multi-dimensional feature data to single-dimensional data using super-increasing encoding.

[0113] Step 104: The client encrypts the single-dimensional data using the global public key to obtain first-level encrypted data.

[0114] Step 105: The client performs random masking processing on the first-level encrypted data using Shamir secret sharing to obtain second-level encrypted data.

[0115] Step 106: The client performs fragmentation processing on the second-level encrypted data, and appends a commitment using Pedersen commitment and an authentication tag generated by Hadamard product to obtain multiple fragmented data.

[0116] Step 107: The fragmented data is transmitted to the in-group aggregation center through the P2P network.

[0117] Step 108: The in-group aggregation center re-encrypts the received multiple fragmented data using the re-encryption key and performs in-group aggregation calculation to obtain in-group aggregation ciphertext.

[0118] Step 109: The in-group aggregation center sends the in-group aggregation ciphertext to the global aggregation center. The global aggregation center is a client elected in the intelligent terminal network through the PBFT consensus protocol.

[0119] Step 1010: The global aggregation center aggregates the received multiple in-group aggregation ciphertexts to obtain global aggregation ciphertext.

[0120] Step 1011: The global aggregation center recovers the global aggregation ciphertext to plaintext data using the Lagrange interpolation algorithm.

[0121] Step 1012: The global aggregation center broadcasts the plaintext data.

[0122] Step 1013: After receiving the plaintext data, the client decrypts the plaintext data in cooperation with the global aggregation center to obtain multi-dimensional decrypted data.

[0123] Step 1014: The client performs double verification based on the Hadamard product authentication tag, local data, and multi-dimensional decrypted data.

[0124] Step 1015: Abnormality is identified according to the double verification result.

[0125] Step 1015 specifically includes: determining whether an unaltered condition is met to obtain a first determination result; the unaltered condition is that all clients in the intelligent terminal network meet double verification of the Pedersen commitment and the Hadamard product authentication tag; if the first determination result is yes, it is determined that the aggregation result is reliable; if the first determination result is no, the client that does not meet the double verification triggers an alarm to prompt that an abnormal client participates in data cooperation and aggregation, and it is determined that the aggregation result is abnormal and invalid.

[0126] As Figure 1 , the specific aggregation process is as follows:

[0127] 1) All clients select random polynomials to generate private key shards according to the Pedersen distributed key generation protocol, and collaboratively calculate the global public key.

[0128] 2) Each client extracts feature parameters according to local data, and maps high-dimensional parameters to single-dimensional values using super-increasing encoding.

[0129] 3) Each client uses the public key to perform NTRU-RLWE homomorphic encryption on the single-dimensional value.

[0130] 4) The client generates random masks and shards through Shamir secret sharing, and simultaneously adds an unforgeable commitment according to the Pedersen commitment and an authentication tag generated by Hadamard product for subsequent result verification. The shard data is transmitted to the group aggregation center through the P2P network.

[0131] 5) The group aggregation center uses the re-encryption key to re-encrypt the ciphertext and performs group aggregation calculation, and then sends it to the global aggregation center elected through the PBFT consensus protocol for aggregation.

[0132] 6) The global aggregation center calculates the aggregated encrypted ciphertext and restores the plaintext data through Lagrange interpolation.

[0133] 7) The client and the aggregation center collaboratively decrypt the aggregated data and restore the original multi-dimensional data.

[0134] 8) The client confirms the decrypted multi-dimensional parameters with the local original parameters, and if it meets the Pedersen commitment verification, it means that it has not been tampered with, otherwise it triggers an alarm to trace the abnormal client or aggregation center.

[0135] 9) Each client verifies the aggregation result through the Hadamard product authentication tag, and if the verification is passed, it means that the aggregation result is reliable, otherwise it is marked as an abnormal client participating in data collaboration and aggregation, the aggregation result is abnormal and invalid, and the whole process is ended.

[0136] There are several solutions to the problem of dynamic grouping and data security aggregation in intelligent terminal networks:

[0137] Grouping method based on traditional clustering algorithm: This method groups clients through common K-means or DBSCAN clustering algorithm; then, performs aggregation operation according to grouping result. Although this method is simple and easy to implement, it has poor adaptability when facing frequent fluctuations in client state and dynamic changes in topology, and it is difficult to provide effective security guarantee, and it may not meet the efficient aggregation demand in large-scale data processing.

[0138] Differential privacy protection method based on encryption domain: This scheme adds noise to disturb data to ensure data privacy and avoid sensitive information leakage. It is suitable for protecting data privacy, but in the process of multi-dimensional data aggregation, due to the addition of noise, the calculation and communication overhead is large, and it cannot effectively handle the collaborative aggregation problem of heterogeneous data. Compared with the scheme combined with multi-key homomorphic encryption and Shamir secret sharing of the present application, the aggregation efficiency and security of this method may be insufficient.

[0139] Scheme based on multi-party computation (MPC) protocol: The aggregation result is calculated by multiple data participants without exposing private data, effectively preventing data leakage. This scheme is suitable for highly sensitive scenarios, but in large-scale distributed systems, due to large calculation and communication overhead, it may cause high latency, making it difficult to adapt to the resource-constrained environment of intelligent terminals.

[0140] Although these alternative solutions have certain advantages, compared with the data security aggregation technology combined with attribute adaptive dynamic grouping and multi-key homomorphic encryption of the present application, the present application can more effectively reduce the calculation and communication overhead, improve the aggregation efficiency, and at the same time ensure the security and privacy of data, and is suitable for dynamic intelligent terminal network environment.

[0141] In an exemplary embodiment, a computer device is provided, which can be a server or a terminal. The computer device includes a processor, a memory, an input / output interface (I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through network connection. The computer program is executed by the processor to implement a data security aggregation method for intelligent terminal network.

[0142] In an exemplary embodiment, a computer readable storage medium storing a computer program is provided, the computer program, when executed by a processor, implements the steps of any of the above method embodiments.

[0143] In an exemplary embodiment, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the steps of any of the above method embodiments.

[0144] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.

[0145] It can be understood by those skilled in the art that all or part of the processes in the above embodiments can be completed by a computer program instructing related hardware, and the computer program can be stored in a non-volatile computer readable storage medium. When the computer program is executed, it can include the processes of the above embodiments. Any reference to memory, database or other medium used in the embodiments provided by the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0146] The database involved in each of the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a blockchain, and the like, without being limited thereto. The processor involved in each of the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, and the like, without being limited thereto.

[0147] The technical features of the above embodiments can be combined in any manner. To make the description concise, all possible combinations of the technical features in the above embodiments are not described, but it should be considered that any combination of the technical features is within the scope of the present disclosure, as long as there is no contradiction.

[0148] The principles and implementation manners of the present application are described by using specific examples herein, and the above embodiments are only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, the specific implementation manners and application ranges can be changed according to the idea of the present application. In summary, the content of the present description should not be understood as a limitation of the present application.

Claims

1. A data security aggregation method of an intelligent terminal network, characterized in that, The application comprises the following steps: dynamically grouping clients in an intelligent terminal network by using an attribute adaptive dynamic grouping mechanism; determining a global public key; the global public key is generated by all clients in the intelligent terminal network based on a Pedersen distributed key cooperation; a client extracts multi-dimensional feature data of local data and maps the multi-dimensional feature data into single-dimensional data by using super-increasing coding; the client performs NTRU-RLWE homomorphic encryption on the single-dimensional data by using the global public key to obtain first-level encrypted data; the client performs random masking processing on the first-level encrypted data by using Shamir secret sharing to obtain second-level encrypted data; the client performs fragmentation processing on the second-level encrypted data, appends a commitment to the fragments by using Pedersen commitment, and appends a verification tag generated by Hadamard product to obtain multiple fragment data; the fragment data is transmitted to an in-group aggregation center through a P2P network; the in-group aggregation center re-encrypts the received multiple fragment data by using a re-encryption key and performs in-group aggregation calculation to obtain in-group aggregation ciphertext; the in-group aggregation center sends the in-group aggregation ciphertext to a global aggregation center; the global aggregation center aggregates the received multiple in-group aggregation ciphertexts to obtain global aggregation ciphertext; the global aggregation center recovers the global aggregation ciphertext into plaintext data by using a Lagrange interpolation algorithm; the global aggregation center broadcasts the plaintext data; after receiving the plaintext data, the client decrypts the plaintext data in cooperation with the global aggregation center to obtain multi-dimensional decrypted data; the client performs double verification based on the Hadamard product verification tag, local data and multi-dimensional decrypted data; abnormalities are identified according to the double verification result.

2. The data security aggregation method of the intelligent terminal network according to claim 1, wherein, The global public key is determined, specifically including: all clients select random polynomials to generate private key fragments according to a Pedersen distributed key generation protocol, and collaboratively calculate the global public key.

3. The data security aggregation method of the intelligent terminal network according to claim 1, wherein, The global aggregation center is a client elected in the intelligent terminal network through a PBFT consensus protocol.

4. The data security aggregation method of the intelligent terminal network according to claim 1, wherein, Abnormalities are identified according to the double verification result, specifically including: determining whether the untampered condition is met to obtain a first judgment result; the untampered condition is that all clients in the intelligent terminal network meet the double verification of the Pedersen commitment and the Hadamard product verification tag; if the first judgment result is yes, it is determined that the aggregation result is reliable; if the first judgment result is no, the client that does not meet the double verification triggers an alarm to prompt that an abnormal client participates in data cooperation and aggregation, and it is determined that the aggregation result is abnormal and invalid.

5. The data security aggregation method of the intelligent terminal network according to claim 1, wherein, The intelligent terminal network is dynamically grouped by using an attribute adaptive dynamic grouping mechanism, specifically including: initializing client grouping: temporarily grouping all clients in the intelligent terminal network according to their states, and determining the in-group aggregation center of each temporary client group; determining the attribute perception score of each client respectively; determining the comprehensive weighted distance of each client to the corresponding in-group aggregation center of the temporary group according to the Euclidean distance between the clients and the attribute perception score of each client; The temporary groups in the intelligent terminal network are re-grouped to obtain a plurality of real-time client groups based on a plurality of comprehensive weighted distances, and an aggregation center with the minimum comprehensive weighted distance is elected from all the temporary groups in the intelligent terminal network; A second determination result is obtained by judging whether the intra-group entropy fluctuation of the current real-time client group after re-grouping is less than a set intra-group entropy fluctuation threshold; the current real-time client group is any real-time client group; If the second determination result is yes, the current real-time client group is maintained; If the second determination result is no, the intra-group aggregation center of the current real-time client group is updated; The plurality of real-time client groups are dynamically adjusted when the intelligent terminal network structure changes; A global change entropy value after the plurality of real-time client groups are dynamically adjusted is determined; When the global change entropy value exceeds a global threshold, the step of re-grouping the temporary groups in the intelligent terminal network based on a plurality of comprehensive weighted distances to obtain a plurality of real-time client groups is returned to.

6. The data security aggregation method of the intelligent terminal network according to claim 5, wherein, The attribute-aware score is determined based on state attribute information of the client; the state attribute information includes stability, communication delay and resource utilization.

7. The data security aggregation method of the intelligent terminal network according to claim 5, wherein, The plurality of real-time client groups are dynamically adjusted when the intelligent terminal network structure changes, and specifically include: When a new client joins the intelligent terminal network, the comprehensive weighted distance between the new client and each intra-group aggregation center is calculated; The real-time client group corresponding to the minimum comprehensive weighted distance is determined as the target real-time client group of the new client; The new client is added to the target real-time client group.

8. The data security aggregation method of the intelligent terminal network according to claim 7, wherein, The plurality of real-time client groups are dynamically adjusted when the intelligent terminal network structure changes, and further include: When a non-intra-group aggregation center in the current real-time client group exits, a third determination result is obtained by judging whether the intra-group entropy fluctuation after the non-intra-group aggregation center exits the current real-time client group is less than a set intra-group entropy fluctuation threshold; If the third determination result is yes, the current real-time client group is maintained; If the third determination result is no, the intra-group aggregation center of the current real-time client group is updated.

9. The data security aggregation method of the intelligent terminal network according to claim 8, wherein, The plurality of real-time client groups are dynamically adjusted when the intelligent terminal network structure changes, and further include: When an intra-group aggregation center in the current real-time client group exits, a new center client with the minimum comprehensive weighted distance is determined as the intra-group aggregation center of the current real-time client group.

10. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor executes the computer program to implement the data security aggregation method of the intelligent terminal network in any one of claims 1-9.