Secure ranging positioning method fusing block chain dynamic trust management and secure multi-party computing
By employing a secure ranging and positioning method based on blockchain dynamic trust management and secure multi-party computation, the problems of user location privacy leakage and insufficient positioning accuracy are solved, achieving efficient and secure positioning services suitable for smart cities and military IoT.
Patent Information
- Application Number
- CN202511096815.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-11-11
AI Technical Summary
Existing indoor positioning technologies suffer from problems such as leakage of user location privacy, insufficient positioning accuracy, high computational and communication overhead, and untrusted nodes, making it difficult to achieve a balance between privacy protection and positioning accuracy.
By employing blockchain dynamic trust management and secure multi-party computation, the device is verified through an edge server, a pseudo-anonymous identity is generated, device behavior is monitored in real time, a scrambled circuit is constructed for data fusion, and location privacy is protected by scrambled sequences and multinomials to achieve secure ranging and positioning.
To ensure the reliability of the positioning system, protect the privacy of users and base station locations, improve positioning accuracy and system efficiency, and provide highly secure and available positioning services for smart cities, connected vehicles, and military IoT.
Smart Images

Figure CN120935554A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of radio ranging and positioning technology, specifically a secure ranging and positioning method that integrates blockchain dynamic trust management and secure multi-party computation. Background Technology
[0002] In recent years, location information services have been widely used in smart cities, connected vehicles, and military IoT scenarios, greatly promoting the development of various location-based data applications. Existing indoor positioning technologies rely on ranging information between base stations and users, but they face two main problems: first, user location may be directly obtained by base stations or servers; second, during the positioning process, base station coordinates are easily intercepted by malicious nodes during exchange. These problems not only affect user privacy and security but also challenge the trust mechanism of positioning systems.
[0003] However, existing ranging and positioning methods typically hide the true coordinates by adding random noise or perturbation mechanisms to enhance location privacy. However, these methods often sacrifice positioning accuracy, making it difficult to strike a balance between user experience and privacy protection. Meanwhile, while some cryptography-based positioning schemes offer stronger privacy protection, their performance often degrades significantly in practical deployments due to computational complexity and high communication overhead. Furthermore, base station-based positioning methods suffer from high deployment costs and concentrated failure points. While crowdsourced collaborative positioning schemes involving user terminals can improve flexibility and coverage, they further introduce new privacy and security risks such as node trustworthiness, data tampering, and behavioral leakage.
[0004] Therefore, researching privacy protection mechanisms and efficient ranging algorithms applicable to cooperative positioning environments, and constructing a solution that can improve positioning accuracy and system operating efficiency while ensuring the location privacy of user terminals and base stations, is of great significance for promoting the development of trusted positioning services. Summary of the Invention
[0005] To address the problems of untrusted nodes, leakage of private coordinates, and high computational and communication overhead in existing positioning systems in crowdsourcing environments, this invention provides a secure ranging and positioning method that integrates blockchain dynamic trust management and secure multi-party computation.
[0006] To achieve the above objectives, the technical solution adopted by this invention is: a secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation, the steps of which are as follows:
[0007] Step 1: The user device submits a registration request to the edge server. The edge server verifies the device and assigns a pseudo-anonymous identity, and monitors the behavior of the registered device in real time.
[0008] Step 1-1: The user equipment submits a registration request to the edge server.
[0009] Imagine a ranging-based indoor positioning system with multiple edge servers forming a consortium blockchain, communicating via IPFS. User equipment obtains information from the base station... The distance measurement information between the points is used for positioning, i = 1, 2, ..., N. The user equipment extracts hardware features to generate a global device identifier H. f and fixed private key SK f :
[0010] SK f =HMAC-SHA256(K1,SK) root ||H f )
[0011] Where K1 is the device key, SK root The root key generated for the Physically Unclonable Function (PUF);
[0012] User equipment constructs a temporary public key PK t and device digital signature Sign SKf Send a registration request packet to the edge server:
[0013] RegReq= <H f PK t Sign SKf (H f ||PK t )>
[0014] Step 1-2: The edge server verifies the device and assigns a pseudo-anonymous identity.
[0015] Let ES ID K is the identifier for the edge server. master The system master key is used, and after the edge server verifies the signature, it checks the H key through the IPFS network. f Uniqueness, generating pseudo-anonymous identities:
[0016] PID = HMAC - SHA256(H f ||ES ID ,K master )
[0017] The edge server writes the PID into the consortium blockchain, and the encrypted version... <PID,H f >Synchronize to IPFS;
[0018] Steps 1-3: Real-time monitoring equipment for edge servers:
[0019] Edge server collects clock stability index σ y Energy consumption characteristics D engand positioning accuracy deviation D loc Calculate the user equipment trust value:
[0020]
[0021] Where γ∈[0,1] is the forgetting factor;
[0022] when Less than the preset value R th When the edge server freezes device permissions, if H(Proof) is a hash digest of malicious event evidence, Sign ES Sign the edge server, and the edge server generates a malicious event record MalAlert= <PID,H(Proof),Sign ES To the consortium blockchain.
[0023] Step 2: The user equipment constructs an obfuscated circuit, generates an obfuscated sequence, and sends it to the edge server;
[0024] Step 2-1: The central server sends pre-processing communication data to each base station.
[0025] Step 2-1: Construct a Boolean circuit for the user equipment:
[0026] User equipment constructs Boolean circuits The circuit calculation is as follows:
[0027]
[0028] Where Φ=[Φ1,...,Φ N ] and Ψ = [Ψ1,...,Ψ N ] is an input list containing N elements;
[0029] Step 2-2 User equipment generates obfuscated sequences
[0030] The user equipment generates N random values τ. i and its obfuscated version structure:
[0031]
[0032] Step 2-3 User equipment will and Send to the edge server.
[0033] Step 3: The edge server allocates public parameters to each base station, and each base station sets a location vector, constructs a polynomial, and sends it to other base stations.
[0034] Step 3-1: Data fusion is performed by each base station.
[0035] Step 3-1: The edge server assigns public parameters to each base station:
[0036] The edge server generates a sequence ∑=[σ1,…,σ] containing N random values. N Stored in the stack and allocated to each base station at the start of a positioning cycle;
[0037] Step 3-2: Set location parameters for each base station:
[0038] Assuming base station The position coordinates are Construct coordinate vectors:
[0039]
[0040] Step 3-3: Construct polynomials for each base station:
[0041] base station Construct an N-1 degree polynomial:
[0042]
[0043] Where j = 1, 2, ..., N and j ≠ i, Let q be a random secret value, and q be a prime number.
[0044] Step 3-4 Base Station Will Send to base station
[0045] Step 4: Each base station performs data fusion on the received polynomial values, sets location obfuscation values, and sends them to the edge server;
[0046] Step 4-1: Each base station performs data fusion on the received polynomial values:
[0047] base station calculate:
[0048]
[0049] in
[0050] Step 4-2: Set location obfuscation values for each base station.
[0051] Assuming base station The distance measurement value with respect to the user equipment is d j Calculate the distance measurement correlation value:
[0052]
[0053] And generate obfuscation values
[0054] Step 4-3: Each base station sends the fused value and the obfuscated value to the edge server.
[0055] base station E j and Send to the edge server.
[0056] Step 5: The edge server constructs a scrambled input sequence, evaluates the scrambling circuit, calculates the sum of the base station location information, and sends the result to the user equipment. The user equipment then solves for its own coordinates.
[0057] Step 5-1: The edge server obtains the obfuscated input sequence.
[0058] The edge server receives the obfuscated value from the base station and constructs it as follows:
[0059]
[0060] Step 5-2: The edge server performs obfuscation circuit calculations.
[0061] Edge servers use input and Execution circuit
[0062]
[0063] Step 5-3: The edge server solves the equation to obtain the total number of base station locations, M.
[0064] The edge server uses Lagrange interpolation to solve the system of equations:
[0065]
[0066] Step 5-4: The edge server sends γ and M to the user equipment;
[0067] Step 5-5 User Equipment Decryption Location Coordinates:
[0068] The user equipment uses the value sent by the edge server and its own random value to calculate:
[0069]
[0070] The user equipment takes X(1) as its own x-coordinate and X(2) as its own y-coordinate.
[0071] The beneficial effects of this invention are as follows: This invention combines blockchain dynamic trust management and secure multi-party computation technology, and realizes real-time monitoring and trust value evaluation of device behavior through blockchain to ensure the credibility of the positioning system. At the same time, it uses obfuscated circuits and data fusion in secure multi-party computation to protect the privacy of user devices and base station locations, effectively preventing information leakage. Furthermore, it significantly improves positioning accuracy and system efficiency by optimizing the computing and communication process, providing highly secure and highly available positioning services for scenarios such as smart logistics and military IoT. Attached Figure Description
[0072] Figure 1 This is a flowchart of the secure ranging and positioning method for private coordinates according to the present invention;
[0073] Figure 2 This is a schematic diagram of the ranging and positioning network communication. Detailed Implementation
[0074] The secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation of the present invention will be described in detail below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0075] Example 1
[0076] like Figure 1-2 This invention proposes a secure ranging and positioning method that integrates blockchain dynamic trust management and secure multi-party computation. Assume a ranging-based smart warehouse positioning system comprising three warehouses. Each warehouse has a spatial layout of 100 meters long and 100 meters wide, with six pre-defined base station nodes evenly distributed, achieving a time measurement accuracy of ±0.5 nanoseconds, located at the four corners and the two center points of the longer side. Three edge servers are deployed in the control centers of each warehouse, collectively forming a lightweight consortium blockchain, and combined with IPFS for distributed data storage. The user device is a logistics drone integrating a ranging module. For security parameter configuration, secp256k1 elliptic curves and integer rings are used. The prime number q is set to 2. 255 -19, Trust Threshold R th Set it to 0.6.
[0077] When a drone first enters the warehouse's network coverage area, it needs to complete a device registration and dynamic trust management process. The drone first extracts identification information from its hardware characteristics, including the flight control system serial number "FCX-9K8Y" and the GPS crystal oscillator clock offset of 0.28ppm. This information is then fused and calculated using the SHA3-256 hash algorithm to generate a unique identifier H. f .
[0078] Subsequently, the drone uses a Physically Unclonable Function (PUF) to generate the root key SK. root And H is converted using the HMAC-SHA256 algorithm. f With SK root By combining these, a fixed private key SK is derived. f =HMAC-SHA256(K1,SK) root ||H f ).
[0079] After key generation is complete, the drone sends a registration request to the edge server ES1, which includes H f A temporary public key PK t And using SK f For H f and PK t Digital signature.
[0080] Upon receiving a request, ES1 verifies the validity of the signature and retrieves the H address via the IPFS network. f This confirms that the user has not been registered twice. If the verification passes, ES1 generates a pseudo-anonymous identity PID, calculated as follows:
[0081] PID = HMAC - SHA256(H f ||ES ID ,K master )
[0082] And record this identity in the consortium blockchain.
[0083] After registration, ES1 will continuously monitor the drone's behavior. Every 10 seconds, the system collects clock stability data, which is then analyzed using Allan variance σ. y Measurements are performed, and energy consumption deviation D is calculated in real time. eng The KL divergence is used as the evaluation index. If σ y More than 1.5×10 -9 The system will trigger an alarm and dynamically update the drone's trust value based on monitoring data. In the current example, the drone's trust value is calculated. The value is 0.62, which is higher than the set trust threshold of 0.6, indicating that its behavior is trustworthy.
[0084] When a drone needs to determine its own position, a confusion circuit is constructed. To achieve secure multi-party computation, the circuit is defined as an addition operation, in the form of... This is then compiled into a garbled circuit. The drone generates six random values τ1 to τ6, which belong to an integer ring. And use Free-XOR technology to generate the corresponding obfuscation values. Thus constructing a confusing sequence Meanwhile, edge server ES1 assigns parameters to six base stations, generating a random sequence ∑=[σ1,…,σ6], where each σ i The range of values is [1, 2]. 32 The data is distributed to each base station via an SSL encrypted channel to ensure the security of the transmission process.
[0085] With base station For example, its coordinates are The base station first constructs its location vector a3 = [-40, -80, 1]. T In order to protect its own location information, Construct polynomials for other base stations. (Base station) For example, Randomly select parameters And calculate the polynomial value:
[0086]
[0087] After the calculation is completed, Using point-to-point encryption Send to Other base stations perform similar operations according to the same logic, forming a collaborative privacy protection mechanism.
[0088] base station Received from other base stations After collecting the data, the data is fused and the sum is calculated:
[0089]
[0090] at the same time, It is necessary to generate obfuscation values for the ranging location. The distance between the drone and the distance measured by the ranging module was found to be d1 = 12.3m, and b1 = 12.3m was calculated. 2 -0 2 -0 2 =151.29. Subsequently, an obfuscation value was generated using One-Time Password Book (OTP) technology. After completing the calculation, E1 and The data is sent to the edge server ES1. Other base stations perform the same process, uploading their respective data to the server.
[0091] After collecting data from all base stations, edge server ES1 begins location calculation. First, it constructs a scrambled input sequence:
[0092]
[0093] Then, the evaluation function of the confusing circuit is used to... and The calculation yields the output value γ, which is 482.7 in this example. Next, ES1 produces the following system of equations:
[0094]
[0095] in
[0096] ES1 obtains M by using Lagrange interpolation and sends γ and M to the UAV.
[0097] Finally, after receiving γ and M, the UAV calculates its position coordinates:
[0098]
[0099] The x-coordinate is 15.2 and the y-coordinate is 22.8, which is very close to the actual position (15.0, 23.1).
[0100] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation, characterized in that, The steps are as follows: Step 1: The user device submits a registration request to the edge server. The edge server verifies the device and assigns a pseudo-anonymous identity, and monitors the behavior of the registered device in real time. Step 2: The user equipment constructs an obfuscated circuit, generates an obfuscated sequence, and sends it to the edge server; Step 3: The edge server allocates public parameters to each base station, and each base station sets a location vector, constructs a polynomial, and sends it to other base stations. Step 4: Each base station performs data fusion on the received polynomial values, sets location obfuscation values, and sends them to the edge server; Step 5: The edge server constructs a scrambled input sequence, evaluates the scrambling circuit, calculates the sum of the base station location information, and sends the result to the user equipment. The user equipment then solves for its own coordinates.
2. A secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation, characterized in that, The specific method in step 1 is as follows: Step 1-1: The user equipment submits a registration request to the edge server. Imagine a ranging-based indoor positioning system with multiple edge servers forming a consortium blockchain, communicating via IPFS. User equipment obtains information from the base station... The distance measurement information between the points is used for positioning, i = 1, 2, ..., N. The user equipment extracts hardware features to generate a global device identifier H. f and fixed private key SK f : SK f =HMAC-SHA256(K1,SK root ||H f ) Where K1 is the device key, SK root The root key generated for the Physically Unclonable Function (PUF); User equipment constructs a temporary public key PK t and device digital signatures Send a registration request packet to the edge server: Step 1-2: The edge server verifies the device and assigns a pseudo-anonymous identity. Let ES ID K is the identifier for the edge server. master The system master key is used, and after the edge server verifies the signature, it checks the H key through the IPFS network. f Uniqueness, generating pseudo-anonymous identities: PID=HMAC-SHA256(H f ||ES ID ,K master ) The edge server writes the PID into the consortium blockchain, and the encrypted version... <PID,H f >Synchronize to IPFS; Steps 1-3: Real-time monitoring of edge server equipment: Edge server collects clock stability index σ y Energy consumption characteristics D eng and positioning accuracy deviation D loc Calculate the user equipment trust value: Where γ∈[0,1] is the forgetting factor; when Less than the preset value R th When the edge server freezes device permissions, if H(Proof) is a hash digest of malicious event evidence, Sign ES Sign the edge server, and the edge server generates a malicious event record MalAlert= <PID,H(Proof),Sign ES To the consortium blockchain.
3. A secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation, characterized in that, The specific method in step 2 is as follows: Step 2-1: The central server sends pre-processing communication data to each base station. Step 2-1: Construct a Boolean circuit for the user equipment: User equipment constructs Boolean circuits The circuit calculation is as follows: Where Φ=[Φ1,...,Φ N ] and Ψ = [Ψ1,...,Ψ N ] is an input list containing N elements; Step 2-2 User equipment generates obfuscated sequences The user equipment generates N random values τ. i and its obfuscated version structure: Step 2-3 User equipment will and Send to the edge server.
4. A secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation, characterized in that, The specific method in step 3 is as follows: Step 3-1: Data fusion is performed by each base station. Step 3-1: The edge server assigns public parameters to each base station: The edge server generates a sequence ∑=[σ1,…,σ] containing N random values. N Stored in the stack and allocated to each base station at the start of a positioning cycle; Step 3-2: Set location parameters for each base station: Assuming base station The position coordinates are Construct coordinate vectors: Step 3-3: Construct polynomials for each base station: base station Construct an N-1 degree polynomial: Where j = 1, 2, ..., N and j ≠ i, Let q be a random secret value, and q be a prime number. Step 3-4 Base Station Will Send to base station 5. A secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation, characterized in that, The specific method in step 4 is as follows: Step 4-1: Each base station performs data fusion on the received polynomial values: base station calculate: in Step 4-2: Set location obfuscation values for each base station. Assuming base station The distance measurement value with respect to the user equipment is d j Calculate the distance measurement correlation value: And generate obfuscation values Step 4-3: Each base station sends the fused value and the obfuscated value to the edge server. base station E j and Send to the edge server.
6. A secure ranging and positioning method integrating blockchain dynamic trust management and secure multi-party computation, characterized in that, The specific method in step 5 is as follows: Step 5-1: The edge server obtains the obfuscated input sequence. The edge server receives the obfuscated value from the base station and constructs it as follows: Step 5-2: The edge server performs obfuscation circuit calculations. Edge servers use input and Execution circuit Step 5-3: The edge server solves the equation to obtain the total number of base station locations, M. The edge server uses Lagrange interpolation to solve the system of equations: Step 5-4: The edge server sends γ and M to the user equipment; Step 5-5 User Equipment Decryption Location Coordinates: The user equipment uses the value sent by the edge server and its own random value to calculate: The user equipment takes X(1) as its own x-coordinate and X(2) as its own y-coordinate.